Zoek.exe v5.0.0.0 Updated 17-December-2014 Tool run by Gebruiker on wo 17/12/2014 at 13:40:05,70. Microsoft Windows 7 Ultimate 6.1.7601 Service Pack 1 x86 Running in: Normal Mode Internet Access Detected Launched: C:\Users\Gebruiker\Desktop\zoek.exe [Scan all users] [Script inserted] [Checkboxes used] ==== Running Processes ====================== C:\Windows\system32\csrss.exe C:\Windows\system32\csrss.exe C:\Windows\system32\wininit.exe C:\Windows\system32\winlogon.exe C:\Windows\system32\services.exe C:\Windows\system32\lsass.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k RPCSS C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\system32\taskhost.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe C:\PROGRA~1\ALLIN1~2\bar\1.bin\8hbarsvc.exe C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleilCS.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe C:\Program Files\Norton Utilities 15\Tools\Disk Doctor\DiskDoctorSrv.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Common Files\Apple\Internet Services\iCloudServices.exe C:\Program Files\Common Files\Apple\Internet Services\AppleIEDAV.exe C:\Program Files\Norton Utilities 15\Tools\Disk Doctor\DiskDoctorSrvProxy.exe C:\Program Files\Common Files\Apple\Internet Services\iCloudDrive.exe C:\Program Files\Common Files\Apple\Internet Services\ApplePhotoStreams.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Program Files\Norton Identity Safe\Engine\2014.7.8.23\NST.exe C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe C:\Program Files\Norton Utilities 15\Tools\SpeedDisk\SpeedDiskSrv.exe C:\Program Files\Norton Utilities 15\Tools\SpeedDisk\SpeedDiskSrvProxy.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\Program Files\Norton Identity Safe\Engine\2014.7.8.23\NST.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Windows\system32\SearchIndexer.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\IVT Corporation\BlueSoleil\BsHelpCS.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Program Files\Windows Live\Mail\wlmail.exe C:\Program Files\Windows Live\Contacts\wlcomm.exe C:\Program Files\IVT Corporation\BlueSoleil\BtTray.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Adblock Plus for IE\AdblockPlusEngine.exe C:\Users\Gebruiker\Desktop\zoek.exe C:\Windows\system32\conhost.exe C:\Windows\system32\svchost.exe -k SDRSVC C:\Windows\System32\wbem\WmiPrvSE.exe ==== System Restore Info ====================== 17/12/2014 13:47:25 Zoek.exe System Restore Point Created Succesfully. ==== Windows Installer Info ====================== Adblock Plus voor IE (32-bit) [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\248E5074942636044B01D73A2BA4DBDC]C:\Windows\Installer\c2f3b.msi Adobe AIR [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\761B3BDFAF4FD16479F68236405AB7A2]C:\Windows\Installer\a0fdd.msi Adobe Reader XI (11.0.09) - Nederlands [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\68AB67CA7DA73401B744BA0000000010]C:\Windows\Installer\3238b4.msi Apple Application Support [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\ED0FAC38B3D873C46A13B2F861CE0313]C:\Windows\Installer\d6813.msi Apple Mobile Device Support [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\33BBE5321AD3FD64AAED9955214390BC]C:\Windows\Installer\d6a1b.msi Apple Software Update [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\46B5A9879DD95AB419A50FCFA0B1B7EF]C:\Windows\Installer\322bd8.msi BearShare [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\938426F5D749AE64DB36DF48C7A16C1F]C:\Windows\Installer\38135.msi Bluesoleil 5.4.277.0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\389788523F4555F47A5C1922A96DC761]C:\Windows\Installer\d5716.msi Bonjour [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\B2F5519759897D9468219D52080EEDB5]C:\Windows\Installer\322bd2.msi CameraHelperMsi [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\10743651ECAB9444B8525176ADC8F93D]C:\Windows\Installer\33005a.msi Compatibiliteitspakket voor het 2007 Microsoft Office system [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00002109020031400000000000F01FEC]C:\Windows\Installer\11c0cc8.msi D3DX10 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\7BD4C90EC03660F46A13E87A329932FA]C:\Windows\Installer\26ef3b.msi Elevated Installer [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\68A082A912E0A234DB652D6ABCBBC5B6]C:\Windows\Installer\60287.msi Garmin City Navigator Europe NT 2013.40 Update [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\F43EC5426E24B09479D770D0AB069635]C:\Windows\Installer\13e5db4.msi Garmin Communicator Plugin [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\879BB7466782B784B9E0DF7BF3E04A2A]C:\Windows\Installer\92835f.msi Garmin Express Tray [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\5EC727F3E0D696540A18A72620316193]C:\Windows\Installer\60281.msi Garmin MapInstall [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\46E44D0FEE1588841ADF1F13807BA534]C:\Windows\Installer\1194bc.msi Garmin USB Drivers [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\183E5ABA64CEC524685CC51DB5FB4BFB]C:\Windows\Installer\20c6e9.msi Google Update Helper [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\93BAD29AC2E44034A96BCB446EB8552E]C:\Windows\Installer\98481.msi iCloud [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\723BB06737938064588C8861E2F23F6B]C:\Windows\Installer\e29b9.msi iTunes [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\139829D52D1D39A48AD2FB060D7EFC5A]C:\Windows\Installer\d7396.msi Java 7 Update 67 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\4EA42A62D9304AC4784BF230120776FF]C:\Windows\Installer\12f77e.msi Java 8 Update 25 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\4EA42A62D9304AC4784BF2381208520F]C:\Windows\Installer\27823f.msi Junk Mail filter update [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\7E0BA6F1DDC839B4A832AAE92BEFCF4E]C:\Windows\Installer\3a2349.msi Logitech Vid [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\13AECBF481D521242913EDC71FEBD7BB]C:\Windows\Installer\f8989.msi LWS Facebook [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\591761FF4EE90C64C87DBF3A54E788BA]C:\Windows\Installer\33006c.msi LWS Gallery [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\C3CE67F61B43E63479BF845CD8B7DEDC]C:\Windows\Installer\330080.msi LWS Help_main [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\E6121561DA7E0524291ABFE86D31199C]C:\Windows\Installer\33003b.msi LWS Launcher [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\C3AF8C38AE4F4C6438293DEC5373836D]C:\Windows\Installer\330098.msi LWS Motion Detection [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\F3D66E17900ABA447848572E18B94AAB]C:\Windows\Installer\3300af.msi LWS Pictures And Video [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\89201680EA92B5443BD7FEEB50089276]C:\Windows\Installer\3300c3.msi LWS Twitter [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\13B3A47134C4DD3468F6379CBD88B784]C:\Windows\Installer\3300c9.msi LWS Webcam Software [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\472D7398182C4E24C8BD0A2BFD791998]C:\Windows\Installer\330049.msi LWS WLM Plugin [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\B67AEAD9F05E27245A5910428E6255D3]C:\Windows\Installer\3300d3.msi LWS YouTube Plugin [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\4920FD12D9B61474BAF62BBABF2D83E7]C:\Windows\Installer\3300dd.msi Mesh Runtime [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\6116D6C8427B0184F8D20D746E7B6DE8]C:\Windows\Installer\3a23c9.msi Messenger Companion [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\E52D2418A820365468DE755587C30892]C:\Windows\Installer\3a2482.msi Microsoft .NET Framework 4.5.1 (NLD) [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\E68D19A1421347534AFB04761662C5AF]C:\Windows\Installer\1088a7.msi Microsoft .NET Framework 4.5.1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\271D3094BCCDF293393A43ACD974EFD3]C:\Windows\Installer\10c00d0.msi Microsoft Application Error Reporting [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\000021599B0090400000000000F01FEC]C:\Windows\Installer\26ef18.msi Microsoft Office Access MUI (Dutch) 2007 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00002109510031400000000000F01FEC]C:\Windows\Installer\45436d.msi Microsoft Office Access MUI (Dutch) 2010 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109510031400000000000F01FEC]C:\Windows\Installer\34deb2.msi Microsoft Office Excel MUI (Dutch) 2007 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00002109610031400000000000F01FEC]C:\Windows\Installer\454324.msi Microsoft Office Excel MUI (Dutch) 2010 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109610031400000000000F01FEC]C:\Windows\Installer\34de76.msi Microsoft Office File Validation Add-In [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109500200000000000000F01FEC]C:\Windows\Installer\105cf6.msi Microsoft Office InfoPath MUI (Dutch) 2007 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00002109440031400000000000F01FEC]C:\Windows\Installer\454338.msi Microsoft Office OneNote MUI (Dutch) 2010 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\000041091A0031400000000000F01FEC]C:\Windows\Installer\34deb8.msi Microsoft Office Outlook Connector [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004159A70031400000000000F01FEC]C:\Windows\Installer\3a248c.msi Microsoft Office Outlook MUI (Dutch) 2007 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00002109A10031400000000000F01FEC]C:\Windows\Installer\45432b.msi Microsoft Office Outlook MUI (Dutch) 2010 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109A10031400000000000F01FEC]C:\Windows\Installer\34de7e.msi Microsoft Office PowerPoint MUI (Dutch) 2007 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00002109810031400000000000F01FEC]C:\Windows\Installer\454332.msi Microsoft Office PowerPoint MUI (Dutch) 2010 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109810031400000000000F01FEC]C:\Windows\Installer\34de6c.msi Microsoft Office Professional Plus 2007 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00002109110000000000000000F01FEC]C:\Windows\Installer\454375.msi Microsoft Office Proof (Dutch) 2007 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00002109F10031400000000000F01FEC]C:\Windows\Installer\45433e.msi Microsoft Office Proof (Dutch) 2010 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10031400000000000F01FEC]C:\Windows\Installer\34de84.msi Microsoft Office Proof (English) 2007 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00002109F10090400000000000F01FEC]C:\Windows\Installer\454352.msi Microsoft Office Proof (English) 2010 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400000000000F01FEC]C:\Windows\Installer\34de97.msi Microsoft Office Proof (French) 2007 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00002109F100C0400000000000F01FEC]C:\Windows\Installer\45434b.msi Microsoft Office Proof (French) 2010 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100C0400000000000F01FEC]C:\Windows\Installer\34de91.msi Microsoft Office Proof (German) 2007 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00002109F10070400000000000F01FEC]C:\Windows\Installer\454344.msi Microsoft Office Proof (German) 2010 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10070400000000000F01FEC]C:\Windows\Installer\34de8a.msi Microsoft Office Proofing (Dutch) 2007 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00002109C20031400000000000F01FEC]C:\Windows\Installer\454358.msi Microsoft Office Proofing (Dutch) 2010 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109C20031400000000000F01FEC]C:\Windows\Installer\34de9d.msi Microsoft Office Publisher MUI (Dutch) 2007 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00002109910031400000000000F01FEC]C:\Windows\Installer\45435f.msi Microsoft Office Publisher MUI (Dutch) 2010 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109910031400000000000F01FEC]C:\Windows\Installer\34debf.msi Microsoft Office Shared MUI (Dutch) 2007 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00002109E60031400000000000F01FEC]C:\Windows\Installer\45431e.msi Microsoft Office Shared MUI (Dutch) 2010 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109E60031400000000000F01FEC]C:\Windows\Installer\34de60.msi Microsoft Office Single Image 2010 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000000000000F01FEC]C:\Windows\Installer\34ea68.msi Microsoft Office Word MUI (Dutch) 2007 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00002109B10031400000000000F01FEC]C:\Windows\Installer\454366.msi Microsoft Office Word MUI (Dutch) 2010 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109B10031400000000000F01FEC]C:\Windows\Installer\34dee5.msi Microsoft Outlook Social Connector Provider for Windows Live Messenger 32-bit [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004159D70090400000000000F01FEC]C:\Windows\Installer\3a242e.msi Microsoft Silverlight [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\D7314F9862C648A4DB8BE2A5B47BE100]C:\Windows\Installer\cae5.msi Microsoft SQL Server 2005 Compact Edition [ENU] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\1D034B0FAA6BD374B960AAD30DF10D8B]C:\Windows\Installer\3a2379.msi MSVC80_x86_v2 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\1B5423D68BD832A4C92DC2094FA0AB6F]C:\Windows\Installer\1ae535.msi MSVC90_x86 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\846111FA1A99E35418DD08BDFBD6DAD0]C:\Windows\Installer\1ae53b.msi MSVCRT [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A6C64DD86500CEF47BA082BB611A1FF1]C:\Windows\Installer\26ef2c.msi MSXML 4.0 SP2 (KB954430) [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\DDA39468D428E8B4DB27C8D5DC5CA217]C:\Windows\Installer\2f6c75.msi MSXML 4.0 SP2 (KB973688) [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\6E8A266FCD4F2A1409E1C8110F44DBCE]C:\Windows\Installer\2f6c6f.msi Nero 7 Ultra Edition [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\E57C80942E5E7F341BFD20C3AB380134]C:\Windows\Installer\81b8b8.msi Nokia Connectivity Cable Driver [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\10AADF1FC889F324CA21D0F8339334DF]C:\Windows\Installer\1ae541.msi Nokia Ovi Suite [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\F6444B8B1E7832444AA76138C2421A99]C:\Windows\Installer\1ae560.msi Nokia Ovi Suite Software Updater [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\42B5B5EECFEEB8C4FBB852D607B5DA98]C:\Windows\Installer\1ae559.msi OGA Notifier 2.0.0048.0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\30A4452B0D01E5E4AB963026FF2CD081]C:\Windows\Installer\202596.msi Ovi Desktop Sync Engine [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\3B6C21181E190654A89B78D6DAAF735C]C:\Windows\Installer\1ae54d.msi OviMPlatform [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\DDE1A9472C6136C40B313DF8F0599337]C:\Windows\Installer\1ae553.msi PC Connectivity Solution [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\99D6FD54D666AF14D826E081B326043F]C:\Windows\Installer\1ae547.msi PlayReady PC Runtime x86 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\DAAE5ACC4F29A7B45BEE4192C466BA16]C:\Windows\Installer\cadf.msi Security Update for CAPICOM (KB931906) [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9F2FDFE0D6387BE43AD230B83D1FBFA2]C:\Windows\Installer\910de.msi Skype Click to Call [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9A1221D6FB710CE4182F723DE03C7010]C:\Windows\Installer\11a74.msi Skype Web Plugin [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\B39DD15B5BC3D9D4FB2FDF91BDBBDFA9]C:\Windows\Installer\104701.msi SkypeT 6.21 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\0AB19942EE0FDA44C98CE55CA0CE6F7B]C:\Windows\Installer\2ece6.msi Windows Live Communications Platform [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\3D04254D3B6B9FF42B3445CE3E1E0066]C:\Windows\Installer\26ef27.msi Windows Live Essentials [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\B53C70A248384AD4A95944B2C6980A37]C:\Windows\Installer\26ef69.msi Windows Live Family Safety [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\79D3E6D2FDF13994CA57275FE94C545C]C:\Windows\Installer\3a241d.msi Windows Live Family Safety [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\FADF33FDED22E3E4FA7F8A46B8745369]C:\Windows\Installer\3a247e.msi Windows Live ID Sign-in Assistant [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A8D0516CDE683D1478BB3FBB150B7BF7]C:\Windows\Installer\26ef13.msi Windows Live Installer [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\F132F0B0A6ECD384AA32773B467F9571]C:\Windows\Installer\26ef36.msi Windows Live Mail [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A563885D93EA72F4DBEA4B7EC2E809C0]C:\Windows\Installer\3a243c.msi Windows Live Mail [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A57765D93F393A44082948E08362ED03]C:\Windows\Installer\3a2356.msi Windows Live Mesh - ActiveX-besturingselement voor externe verbindingen [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\C55EC23CAB21159478799076DFFE55F6]C:\Windows\Installer\3a2469.msi Windows Live Mesh [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\1A3414F312C911046897B31C10C48668]C:\Windows\Installer\3a2475.msi Windows Live Mesh [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\C7BCDCEDCC85568419FA26F77989EF84]C:\Windows\Installer\3a240e.msi Windows Live Messenger [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\11F12B5E3396B0E42AC597363E0CD711]C:\Windows\Installer\26ef5f.msi Windows Live Messenger [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\59D49284A9EE7734283144CF2456BF72]C:\Windows\Installer\26ef7d.msi Windows Live Messenger Companion Core [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\C4B69A87346AF0D4892C8A1EA666969F]C:\Windows\Installer\3a2421.msi Windows Live MIME IFilter [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\933448FAA8F23954183BF9C44530C8E4]C:\Windows\Installer\3a234d.msi Windows Live Movie Maker [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\4314AE291D01A814191EA5403531A183]C:\Windows\Installer\3a23ad.msi Windows Live Movie Maker [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9D4227BCACD61F34F838B6E1930AF029]C:\Windows\Installer\3a2456.msi Windows Live Photo Common [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\0D262DB9887B64540A5A4F5FE63C38B4]C:\Windows\Installer\26ef73.msi Windows Live Photo Common [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\B6ACDB9A3563B764CA384963D73AFB3E]C:\Windows\Installer\26ef59.msi Windows Live Photo Gallery [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\0FB3B06AB459FA248B8DC2D1436B31AA]C:\Windows\Installer\3a2446.msi Windows Live Photo Gallery [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\766F6333940964D4896BC447E3BE5C1B]C:\Windows\Installer\3a237d.msi Windows Live PIMT Platform [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\7B292C385A83B0447A137070E0186AF4]C:\Windows\Installer\26ef40.msi Windows Live Remote Client [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\099A4A9134357FF43B5BF640C690E1FD]C:\Windows\Installer\3a240a.msi Windows Live Remote Client Resources [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\45EBCC0F23199E4428FDDC63A45D2CD2]C:\Windows\Installer\3a246d.msi Windows Live Remote Service [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2878E7224F2B79E40BEE94EDC91C0C0C]C:\Windows\Installer\3a2345.msi Windows Live Remote Service Resources [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\BCB0E548D8C8BAF45888DAF5DF51C659]C:\Windows\Installer\3a2471.msi Windows Live SOXE [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\F4E3B286A696ED244AC1C470AE61874B]C:\Windows\Installer\26ef22.msi Windows Live SOXE Definitions [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\26CEF00243C306D4C98ECE73E2100CF8]C:\Windows\Installer\26ef1d.msi Windows Live UX Platform [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\E97A59ECCF4EFFF4A857920FB449F22F]C:\Windows\Installer\26ef31.msi Windows Live UX Platform Language Pack [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9FC52F6D78E4BE343B421CB29EDC6D86]C:\Windows\Installer\26ef64.msi Windows Live Writer [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\076CFAAAB965F2A4284B2449E5D03EFE]C:\Windows\Installer\3a2371.msi Windows Live Writer [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\329710E78F6123E449FEA051B01D69EF]C:\Windows\Installer\3a2460.msi Windows Live Writer [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\60EA627A3AAA1D34783E075F0113F440]C:\Windows\Installer\3a23bb.msi Windows Live Writer Resources [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\7B144B41D477071489AE1A6376EA2681]C:\Windows\Installer\3a2432.msi ==== Empty Folders Check ====================== C:\Program Files\DownlOAdd kkeeperi deleted successfully C:\Program Files\MSXML 4.0 deleted successfully C:\Program Files\ParetoLogic deleted successfully C:\Program Files\Reimage deleted successfully C:\Program Files\SearchNewTab deleted successfully C:\Program Files\TROS deleted successfully C:\Program Files\Common Files\LWS deleted successfully C:\Program Files\Common Files\Nero deleted successfully C:\PROGRA~2\Big Fish Games deleted successfully C:\PROGRA~2\PCSettings deleted successfully C:\PROGRA~2\ScreenSeven deleted successfully C:\Users\Gebruiker\AppData\Roaming\DendaGames deleted successfully C:\Users\Gebruiker\AppData\Roaming\SterrenRadio deleted successfully C:\Users\Gebruiker\AppData\Roaming\WiseUpdate deleted successfully C:\Users\Gebruiker\AppData\Local\Screentime deleted successfully C:\Users\Gebruiker\AppData\Local\SupportSoft deleted successfully C:\Users\Gebruiker\AppData\Local\VirtualStore deleted successfully ==== Checking Systemdrive for Symlinks ====================== Het volume in station C heeft geen naam. Het volumenummer is 86D3-D2B3 Map van C:\ 14/07/2009 05:53 Documents and Settings [..] 0 bestand(en) 0 bytes Map van C:\Program Files\Windows NT 11/01/2010 13:22 Bureau-accessoires [C:\Program Files\Windows NT\Accessories] 0 bestand(en) 0 bytes Map van C:\ProgramData 14/07/2009 05:53 Application Data [..] 11/01/2010 13:22 Bureaublad [C:\Users\Public\Desktop] 14/07/2009 05:53 Desktop [..] 11/01/2010 13:22 Documenten [C:\Users\Public\Documents] 14/07/2009 05:53 Documents [..] 11/01/2010 13:22 Favorieten [C:\Users\Public\Favorites] 14/07/2009 05:53 Favorites [..] 11/01/2010 13:22 Menu Start [C:\ProgramData\Microsoft\Windows\Start Menu] 11/01/2010 13:22 Sjablonen [C:\ProgramData\Microsoft\Windows\Templates] 14/07/2009 05:53 Start Menu [..] 14/07/2009 05:53 Templates [..] 0 bestand(en) 0 bytes Map van C:\ProgramData\Documenten 11/01/2010 13:22 Mijn afbeeldingen [C:\Users\Public\Pictures] 11/01/2010 13:22 Mijn muziek [C:\Users\Public\Music] 11/01/2010 13:22 Mijn video's [C:\Users\Public\Videos] 14/07/2009 05:53 My Music [..] 14/07/2009 05:53 My Pictures [..] 14/07/2009 05:53 My Videos [..] 0 bestand(en) 0 bytes Map van C:\ProgramData\Menu Start 11/01/2010 13:22 Programma's [C:\ProgramData\Microsoft\Windows\Start Menu\Programs] 0 bestand(en) 0 bytes Map van C:\ProgramData\Microsoft\Windows\Start Menu 11/01/2010 13:22 Programma's [C:\ProgramData\Microsoft\Windows\Start Menu\Programs] 0 bestand(en) 0 bytes Map van C:\ProgramData\Oracle\Java\javapath 15/11/2014 11:01 java.exe [C:\Program Files\Java\jre1.8.0_25\bin\java.exe] 15/11/2014 11:01 javaw.exe [C:\Program Files\Java\jre1.8.0_25\bin\javaw.exe] 15/11/2014 11:01 javaws.exe [C:\Program Files\Java\jre1.8.0_25\bin\javaws.exe] 3 bestand(en) 0 bytes Map van C:\Users 14/07/2009 05:53 All Users [C:\ProgramData] 14/07/2009 05:53 Default User [..] 0 bestand(en) 0 bytes Map van C:\Users\All Users 14/07/2009 05:53 Application Data [..] 11/01/2010 13:22 Bureaublad [C:\Users\Public\Desktop] 14/07/2009 05:53 Desktop [..] 11/01/2010 13:22 Documenten [C:\Users\Public\Documents] 14/07/2009 05:53 Documents [..] 11/01/2010 13:22 Favorieten [C:\Users\Public\Favorites] 14/07/2009 05:53 Favorites [..] 11/01/2010 13:22 Menu Start [C:\ProgramData\Microsoft\Windows\Start Menu] 11/01/2010 13:22 Sjablonen [C:\ProgramData\Microsoft\Windows\Templates] 14/07/2009 05:53 Start Menu [..] 14/07/2009 05:53 Templates [..] 0 bestand(en) 0 bytes Map van C:\Users\All Users\Documenten 11/01/2010 13:22 Mijn afbeeldingen [C:\Users\Public\Pictures] 11/01/2010 13:22 Mijn muziek [C:\Users\Public\Music] 11/01/2010 13:22 Mijn video's [C:\Users\Public\Videos] 14/07/2009 05:53 My Music [..] 14/07/2009 05:53 My Pictures [..] 14/07/2009 05:53 My Videos [..] 0 bestand(en) 0 bytes Map van C:\Users\All Users\Menu Start 11/01/2010 13:22 Programma's [C:\ProgramData\Microsoft\Windows\Start Menu\Programs] 0 bestand(en) 0 bytes Map van C:\Users\All Users\Microsoft\Windows\Start Menu 11/01/2010 13:22 Programma's [C:\ProgramData\Microsoft\Windows\Start Menu\Programs] 0 bestand(en) 0 bytes Map van C:\Users\All Users\Oracle\Java\javapath 15/11/2014 11:01 java.exe [C:\Program Files\Java\jre1.8.0_25\bin\java.exe] 15/11/2014 11:01 javaw.exe [C:\Program Files\Java\jre1.8.0_25\bin\javaw.exe] 15/11/2014 11:01 javaws.exe [C:\Program Files\Java\jre1.8.0_25\bin\javaws.exe] 3 bestand(en) 0 bytes Map van C:\Users\Default 14/07/2009 05:53 Application Data [..] 14/07/2009 05:53 Cookies [..] 14/07/2009 05:53 Local Settings [..] 11/01/2010 13:22 Menu Start [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu] 11/01/2010 13:22 Mijn documenten [C:\Users\Default\Documents] 14/07/2009 05:53 My Documents [..] 14/07/2009 05:53 NetHood [..] 11/01/2010 13:22 Netwerkprinteromgeving [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Printer Shortcuts] 14/07/2009 05:53 PrintHood [..] 14/07/2009 05:53 Recent [..] 14/07/2009 05:53 SendTo [..] 11/01/2010 13:22 Sjablonen [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Templates] 14/07/2009 05:53 Start Menu [..] 14/07/2009 05:53 Templates [..] 0 bestand(en) 0 bytes Map van C:\Users\Default\AppData\Local 14/07/2009 05:53 Application Data [..] 11/01/2010 13:22 Geschiedenis [C:\Users\Default\AppData\Local\Microsoft\Windows\History] 14/07/2009 05:53 History [..] 14/07/2009 05:53 Temporary Internet Files [..] 0 bestand(en) 0 bytes Map van C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu 11/01/2010 13:22 Programma's [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs] 0 bestand(en) 0 bytes Map van C:\Users\Default\Documents 11/01/2010 13:22 Mijn afbeeldingen [C:\Users\Default\Pictures] 11/01/2010 13:22 Mijn muziek [C:\Users\Default\Music] 11/01/2010 13:22 Mijn video's [C:\Users\Default\Videos] 14/07/2009 05:53 My Music [..] 14/07/2009 05:53 My Pictures [..] 14/07/2009 05:53 My Videos [..] 0 bestand(en) 0 bytes Map van C:\Users\Gebruiker 11/01/2010 13:23 Application Data [..] 11/01/2010 13:23 Cookies [..] 11/01/2010 13:23 Local Settings [..] 11/01/2010 13:23 Menu Start [C:\Users\Gebruiker\AppData\Roaming\Microsoft\Windows\Start Menu] 11/01/2010 13:23 NetHood [..] 11/01/2010 13:23 Netwerkprinteromgeving [C:\Users\Gebruiker\AppData\Roaming\Microsoft\Windows\Printer Shortcuts] 11/01/2010 13:23 Recent [..] 11/01/2010 13:23 SendTo [..] 11/01/2010 13:23 Sjablonen [C:\Users\Gebruiker\AppData\Roaming\Microsoft\Windows\Templates] 0 bestand(en) 0 bytes Map van C:\Users\Gebruiker\AppData\Local 11/01/2010 13:23 Application Data [..] 11/01/2010 13:23 Geschiedenis [C:\Users\Gebruiker\AppData\Local\Microsoft\Windows\History] 11/01/2010 13:23 Temporary Internet Files [..] 0 bestand(en) 0 bytes Map van C:\Users\Gebruiker\AppData\Roaming\Microsoft\Windows\Start Menu 11/01/2010 13:23 Programma's [C:\Users\Gebruiker\AppData\Roaming\Microsoft\Windows\Start Menu\Programs] 0 bestand(en) 0 bytes Map van C:\Users\Gebruiker\Documents 11/01/2010 13:23 Mijn muziek [C:\Users\Gebruiker\Music] 11/01/2010 13:23 Mijn video's [C:\Users\Gebruiker\Videos] 0 bestand(en) 0 bytes Map van C:\Users\Public\Documents 11/01/2010 13:22 Mijn afbeeldingen [C:\Users\Public\Pictures] 11/01/2010 13:22 Mijn muziek [C:\Users\Public\Music] 11/01/2010 13:22 Mijn video's [C:\Users\Public\Videos] 14/07/2009 05:53 My Music [..] 14/07/2009 05:53 My Pictures [..] 14/07/2009 05:53 My Videos [..] 0 bestand(en) 0 bytes Totaal aantal weergegeven bestanden: 6 bestand(en) 0 bytes 88 map(pen) 305.969.664.000 bytes beschikbaar ==== Deleting CLSID Registry Keys ====================== HKEY_USERS\S-1-5-21-2495464155-2157068309-4147718583-1000\Software\Microsoft\Internet Explorer\SearchScopes\{75b4241f-171e-44a3-bf44-23613b6e3e03} deleted successfully HKEY_USERS\S-1-5-21-2495464155-2157068309-4147718583-1000\Software\Microsoft\Internet Explorer\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4} deleted successfully ==== Deleting CLSID Registry Values ====================== ==== Installed Programs ====================== Update for Microsoft Office 2007 (KB2508958) Adblock Plus for IE Adblock Plus voor IE (32-bit) Adobe AIR Adobe Flash Player 16 ActiveX Adobe Reader XI (11.0.09) - Nederlands Apple Application Support Apple Mobile Device Support Apple Software Update BearShare Belkin Wireless USB Utility Bluesoleil 5.4.277.0 Bonjour CameraHelperMsi Classic Menu 3.9x for Office 2007 Compatibiliteitspakket voor het 2007 Microsoft Office system D3DX10 DAMN NFO Viewer 2.10.0031 RC3 Definition Update for Microsoft Office 2010 (KB2910899) 32-Bit Edition Elevated Installer erLT Garmin City Navigator Europe NT 2013.40 Update Garmin Communicator Plugin Garmin Express Tray Garmin MapInstall Garmin USB Drivers Google Chrome Google Update Helper iCloud Intel(R) Graphics Media Accelerator Driver Intel(R) TV Wizard iTunes Java 7 Update 67 Java 8 Update 25 Java Auto Updater Junk Mail filter update K-Lite Codec Pack 3.7.0 Full Logitech-webcamsoftware Logitech Vid Logitech Webcam Software-stuurprogrammapakket LWS Facebook LWS Gallery LWS Help_main LWS Launcher LWS Motion Detection LWS Pictures And Video LWS Twitter LWS Webcam Software LWS WLM Plugin LWS YouTube Plugin Mesh Runtime Messenger Companion Microsoft .NET Framework 4.5.1 Microsoft .NET Framework 4.5.1 (NLD) Microsoft Application Error Reporting Microsoft Office 2007 Service Pack 3 (SP3) Microsoft Office Access MUI (Dutch) 2007 Microsoft Office Access MUI (Dutch) 2010 Microsoft Office Excel MUI (Dutch) 2007 Microsoft Office Excel MUI (Dutch) 2010 Microsoft Office File Validation Add-In Microsoft Office Home and Student 2010 Microsoft Office InfoPath MUI (Dutch) 2007 Microsoft Office OneNote MUI (Dutch) 2010 Microsoft Office Outlook Connector Microsoft Office Outlook MUI (Dutch) 2007 Microsoft Office Outlook MUI (Dutch) 2010 Microsoft Office PowerPoint MUI (Dutch) 2007 Microsoft Office PowerPoint MUI (Dutch) 2010 Microsoft Office Professional Plus 2007 Microsoft Office Proof (Dutch) 2007 Microsoft Office Proof (Dutch) 2010 Microsoft Office Proof (English) 2007 Microsoft Office Proof (English) 2010 Microsoft Office Proof (French) 2007 Microsoft Office Proof (French) 2010 Microsoft Office Proof (German) 2007 Microsoft Office Proof (German) 2010 Microsoft Office Proofing (Dutch) 2007 Microsoft Office Proofing (Dutch) 2010 Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) Microsoft Office Publisher MUI (Dutch) 2007 Microsoft Office Publisher MUI (Dutch) 2010 Microsoft Office Shared MUI (Dutch) 2007 Microsoft Office Shared MUI (Dutch) 2010 Microsoft Office Single Image 2010 Microsoft Office Word MUI (Dutch) 2007 Microsoft Office Word MUI (Dutch) 2010 Microsoft Outlook Social Connector Provider for Windows Live Messenger 32-bit Microsoft Silverlight Microsoft SQL Server 2005 Compact Edition [ENU] Mozilla Firefox 30.0 (x86 nl) Mozilla Maintenance Service MSVC80_x86_v2 MSVC90_x86 MSVCRT MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) Nero 7 Ultra Edition Nokia Connectivity Cable Driver Nokia Ovi Suite Nokia Ovi Suite Software Updater Norton Identity Safe Norton Utilities 15 OGA Notifier 2.0.0048.0 Ovi Desktop Sync Engine OviMPlatform PC Connectivity Solution PlayReady PC Runtime x86 QuickPar 0.9 Revo Uninstaller 1.92 Security Update for CAPICOM (KB931906) Security Update for Microsoft .NET Framework 4.5.1 (KB2894854v2) Security Update for Microsoft .NET Framework 4.5.1 (KB2898869) Security Update for Microsoft .NET Framework 4.5.1 (KB2901126) Security Update for Microsoft .NET Framework 4.5.1 (KB2931368) Security Update for Microsoft .NET Framework 4.5.1 (KB2972107) Security Update for Microsoft .NET Framework 4.5.1 (KB2972216) Security Update for Microsoft .NET Framework 4.5.1 (KB2978128) Security Update for Microsoft .NET Framework 4.5.1 (KB2979578v2) Security Update for Microsoft Excel 2010 (KB2910902) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596744) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596754) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596792) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596825) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596871) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596927) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2597969) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2597973) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2687439) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2760411) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2760415) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2760585) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2760591) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2817330) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2850022) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2878233) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2880507) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2880508) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2881069) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2920790) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2920792) 32-Bit Edition Security Update for Microsoft Office 2010 (KB2553154) 32-Bit Edition Security Update for Microsoft Office 2010 (KB2553284) 32-Bit Edition Security Update for Microsoft Office 2010 (KB2687423) 32-Bit Edition Security Update for Microsoft Office 2010 (KB2760781) 32-Bit Edition Security Update for Microsoft Office 2010 (KB2810073) 32-Bit Edition Security Update for Microsoft Office 2010 (KB2850016) 32-Bit Edition Security Update for Microsoft Office 2010 (KB2880971) 32-Bit Edition Security Update for Microsoft Office 2010 (KB2881071) 32-Bit Edition Security Update for Microsoft Office Excel 2007 (KB2984942) 32-Bit Edition Security Update for Microsoft Office InfoPath 2007 (KB2687440) 32-Bit Edition Security Update for Microsoft Office PowerPoint 2007 (KB2596912) 32-Bit Edition Security Update for Microsoft Office Publisher 2007 (KB2817565) 32-Bit Edition Security Update for Microsoft Office Word 2007 (KB2920793) 32-Bit Edition Security Update for Microsoft Word 2010 (KB2899519) 32-Bit Edition SelectionLinks Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition Skype Click to Call Skype Web Plugin SkypeT 6.21 Update for 2007 Microsoft Office System (KB967642) Update for Microsoft Access 2010 (KB2553446) 32-Bit Edition Update for Microsoft Excel 2010 (KB2589348) 32-Bit Edition Update for Microsoft Filter Pack 2.0 (KB2878281) 32-Bit Edition Update for Microsoft InfoPath 2010 (KB2817369) 32-Bit Edition Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition Update for Microsoft Office 2010 (KB2494150) Update for Microsoft Office 2010 (KB2553140) 32-Bit Edition Update for Microsoft Office 2010 (KB2589298) 32-Bit Edition Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition Update for Microsoft Office 2010 (KB2589375) 32-Bit Edition Update for Microsoft Office 2010 (KB2589386) 32-Bit Edition Update for Microsoft Office 2010 (KB2597087) 32-Bit Edition Update for Microsoft Office 2010 (KB2597089) 32-Bit Edition Update for Microsoft Office 2010 (KB2687275) 32-Bit Edition Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition Update for Microsoft Office 2010 (KB2794737) 32-Bit Edition Update for Microsoft Office 2010 (KB2825635) 32-Bit Edition Update for Microsoft Office 2010 (KB2837581) 32-Bit Edition Update for Microsoft Office 2010 (KB2837602) 32-Bit Edition Update for Microsoft Office 2010 (KB2837606) 32-Bit Edition Update for Microsoft Office 2010 (KB2883019) 32-Bit Edition Update for Microsoft Office 2010 (KB2889818) 32-Bit Edition Update for Microsoft Office 2010 (KB2889828) 32-Bit Edition Update for Microsoft Office 2010 (KB2910896) 32-Bit Edition Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition Update for Microsoft Office Outlook 2007 (KB2863811) 32-Bit Edition Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2920789) 32-Bit Edition Update for Microsoft Office PowerPoint 2007 (KB2597972) 32-Bit Edition Update for Microsoft OneNote 2010 (KB2597088) 32-Bit Edition Update for Microsoft Outlook 2010 (KB2687567) 32-Bit Edition Update for Microsoft PowerPoint 2010 (KB2880517) 32-Bit Edition Update for Microsoft Visio 2010 (KB2880526) 32-Bit Edition Update for Microsoft Visio Viewer 2010 (KB2837587) 32-Bit Edition Update voor Microsoft Office Excel 2007 Help (KB963678) Update voor Microsoft Office Powerpoint 2007 Help (KB963669) Update voor Microsoft Office Word 2007 Help (KB963665) VDSL2 modem tool Windows-stuurprogrammapakket - Nokia pccsmcfd (08/22/2008 7.0.0.0) Windows Driver Package - Garmin (grmnusb) GARMIN Devices (04/19/2012 2.3.1.0) Windows Live Communications Platform Windows Live Essentials Windows Live Family Safety Windows Live ID Sign-in Assistant Windows Live Installer Windows Live Mail Windows Live Mesh - ActiveX-besturingselement voor externe verbindingen Windows Live Mesh Windows Live Messenger Windows Live Messenger Companion Core Windows Live MIME IFilter Windows Live Movie Maker Windows Live Photo Common Windows Live Photo Gallery Windows Live PIMT Platform Windows Live Remote Client Windows Live Remote Client Resources Windows Live Remote Service Windows Live Remote Service Resources Windows Live SOXE Windows Live SOXE Definitions Windows Live UX Platform Windows Live UX Platform Language Pack Windows Live Writer Windows Live Writer Resources WinRAR 5.01 (32-bit) Wise Disk Cleaner 8.36 Wise Registry Cleaner 8.26 ==== Deleting Services ====================== HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Allin1Convert_8hService deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Allin1Convert_8hService deleted successfully ==== FireFox Fix ====================== ProfilePath: C:\Users\GEBRUI~1\AppData\Roaming\Mozilla\Firefox\Profiles\f7wz8tt8.default user.js not found ---- Lines ffxtbr modified from prefs.js ---- user_pref("extensions.installCache", "[{\"name\":\"winreg-app-global\",\"addons\":{\"{A27F3FEF-1113-4cfb-A032-8E12D7D8EE70}\":{\"descriptor\":\"C:\\\\ ---- FireFox user.js and prefs.js backups ---- prefs_20141712_1403_.backup ==== Deleting Files \ Folders ====================== C:\Program Files\Allin1Convert_8h deleted C:\Users\Gebruiker\AppData\Roaming\Allin1Convert_8h deleted C:\Program Files\Common Files\ParetoLogic deleted C:\Program Files\BearShare Applications deleted C:\Users\Gebruiker\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\BearShare.lnk deleted C:\Users\Gebruiker\AppData\Roaming\Uniblue deleted C:\Users\Gebruiker\AppData\Roaming\Smiley.ico deleted C:\Users\Gebruiker\AppData\Roaming\Alawar Entertainment deleted C:\Users\Gebruiker\AppData\Roaming\AlawarEntertainment deleted C:\Users\Gebruiker\AppData\Roaming\YoudaGames deleted C:\Users\Gebruiker\AppData\Roaming\In search of the Lost Temple deleted C:\Users\Gebruiker\AppData\Roaming\Systweak deleted C:\Users\Gebruiker\assembly-csharp-firstpass.dll deleted C:\Users\Gebruiker\assembly-csharp.dll deleted C:\Users\Gebruiker\assembly-unityscript-firstpass.dll deleted C:\PROGRA~2\SnowApp deleted C:\PROGRA~2\ParetoLogic deleted C:\PROGRA~2\InstallMate deleted C:\PROGRA~2\Package Cache deleted C:\Users\Gebruiker\AppData\Local\IAC deleted C:\Users\Gebruiker\AppData\Local\BearShare deleted C:\Users\Gebruiker\AppData\Local\CrashRpt deleted C:\rei deleted C:\Users\Gebruiker\AppData\LocalLow\DataMngr deleted C:\Windows\system32\config\systemprofile\AppData\LocalLow\AVG Security Toolbar deleted C:\Windows\Reimage.ini deleted C:\Windows\tasks\ParetoLogic Update Version3 Startup Task.job deleted C:\Windows\tasks\ParetoLogic Update Version3.job deleted C:\Windows\tasks\ParetoLogic Update Version3_triggeronce.job deleted C:\Windows\tasks\Plus-HD-9.0-codedownloader.job deleted C:\Windows\tasks\Plus-HD-9.0-enabler.job deleted C:\Windows\tasks\Plus-HD-9.0-firefoxinstaller.job deleted C:\Windows\tasks\Plus-HD-9.0-updater.job deleted C:\Windows\system32\tasks\Plus-HD-9.0-codedownloader deleted C:\Windows\system32\tasks\Plus-HD-9.0-enabler deleted C:\Windows\system32\tasks\Plus-HD-9.0-firefoxinstaller deleted C:\Windows\system32\tasks\Plus-HD-9.0-updater deleted C:\Windows\system32\Tasks\Reimage Reminder deleted C:\Windows\system32\GroupPolicy\Machine deleted C:\Windows\system32\GroupPolicy\User deleted C:\Windows\system32\GroupPolicy\gpt.ini deleted C:\Windows\System32\cnmF65F.tmp deleted C:\Windows\System32\RENE475.tmp deleted C:\Windows\System32\AI_RecycleBin deleted C:\Windows\system32\RegistryHelperLM.ocx deleted C:\Windows\System32\searchplugins deleted C:\Windows\System32\Extensions deleted C:\Users\Public\Documents\AlawarWrapper deleted C:\Users\Gebruiker\aq2.exe deleted C:\Users\Gebruiker\buildalotworld.exe deleted C:\Users\Gebruiker\christmas.exe deleted C:\Users\Gebruiker\clockworktales_ofglassandink_ce.exe deleted C:\Users\Gebruiker\darkparables8_tlmatpt_ce.exe deleted C:\Users\Gebruiker\mb-nl.exe deleted C:\Users\GEBRUI~1\AppData\Roaming\Mozilla\Firefox\Profiles\f7wz8tt8.default\extensions\8hffxtbr@Allin1Convert_8h.com deleted "C:\Windows\Installer\1ae559.msi" deleted "C:\PROGRA~2\630e7bb2be8dfd73\{C1A27135-69EB-8D44-7358-34727DD7B820}" deleted "C:\PROGRA~2\630e7bb2be8dfd73\{C1A27135-69EB-8D44-7358-34727DD7B820}.old" deleted "C:\PROGRA~2\630e7bb2be8dfd73\{C670DCAE-E392-AA32-6F42-143C7FC4BDFD}" deleted "C:\PROGRA~2\630e7bb2be8dfd73\{C670DCAE-E392-AA32-6F42-143C7FC4BDFD}.old" deleted "C:\PROGRA~2\630e7bb2be8dfd73" deleted ==== System Specs ====================== Windows: Windows 7 Ultimate Edition Service Pack 1 (Build 7601) Memory (RAM): 2039 MB CPU Info: Intel(R) Celeron(R) CPU E1400 @ 2.00GHz CPU Speed: 2054,0 MHz Sound Card: Luidsprekers (High Definition A | Digitale audio (S/PDIF) (High D | Hoofdtelefoon (High Definition | Display Adapters: Intel(R) G33/G31 Express Chipset Family | RDPDD Chained DD | RDP Encoder Mirror Driver | RDP Reflector Display Driver Monitors: 1x; ACER AL1716 | Screen Resolution: 1280 X 1024 - 32 bit Network: Network Present Network Adapters: Bluetooth PAN Network Adapter | Atheros L1 Gigabit Ethernet 10/100/1000Base-T Controller CD / DVD Drives: 1x (E: | ) E: TSSTcorpCDDVDW SH-S223F Ports: COM1 | COM3 | COM4 | COM5 LPT1 Mouse: 16 Button Wheel Mouse Present Hard Disks: C: 349,3GB | D: 349,3GB Hard Disks - Free: C: 284,9GB | D: 334,5GB Manufacturer *: American Megatrends Inc. BIOS Info: AT/AT COMPATIBLE | 09/03/08 | _ASUS_ - 9000803 Time Zone: West-Europa (standaardtijd) Motherboard *: ASUSTeK Computer INC. V-P5G31 Country: Belgi‰ Language: NLB ==== System Specs (Software) ====================== Anti-Spyware: Windows Defender disabled (Outdated) Default Browser: Google Chrome 36.0.1985.125 Internet Explorer Version: 10.0.9200.17183 Mozilla Firefox version: 30.0 (x86 nl) Google Chrome version: 36.0.1985.125 Adobe Reader version: 11.0.9.29 Sun Java version: 1.8.0_25 (32-bit) ==== Files Recently Created / Modified ====================== ====== C:\Windows ==== ====== C:\Users\GEBRUI~1\AppData\Local\Temp ==== ====== Java Cache ===== ====== C:\Windows\system32 ===== 2014-12-16 17:55:17 0F0C6A4337155CAF0B8CF72222B4F876 408152 ----a-w- C:\Windows\System32\FNTCACHE.DAT 2014-12-15 20:39:58 75CC5FCE27F50B32A25D5D1723EA570D 139816 ---ha-w- C:\Windows\System32\mlfcache.dat 2014-12-11 10:46:36 FF0A6E76FAE624AC74780AB008752F98 3209728 ----a-w- C:\Windows\System32\mf.dll 2014-12-11 10:46:36 D17954CA6343F43B62637F51996B4E95 23040 ----a-w- C:\Windows\System32\mfpmp.exe 2014-12-11 10:46:36 52096F5F476733F2E2725CF346FF373B 2048 ----a-w- C:\Windows\System32\mferror.dll 2014-12-11 10:46:36 20257A0BFB824B49055A6EEC29C72C03 103424 ----a-w- C:\Windows\System32\mfps.dll 2014-12-11 10:46:35 60FBCF033FF42A40C916C01A962A8802 50176 ----a-w- C:\Windows\System32\rrinstaller.exe 2014-12-11 06:31:07 E1456E7396022EBE4E5434188D1AC8B0 1230336 ----a-w- C:\Windows\System32\WindowsCodecs.dll 2014-12-11 06:31:02 50C73E54062BA252350F3F29580E28DA 2048 ----a-w- C:\Windows\System32\tzres.dll 2014-12-11 06:30:39 50F36BAEDF56CCC4367C975451479211 14364672 ----a-w- C:\Windows\System32\mshtml.dll 2014-12-11 06:30:36 727A70DA965A764353985C2FA8082A4F 13758976 ----a-w- C:\Windows\System32\ieframe.dll 2014-12-11 06:30:34 A224B820E7C9C6DAFBF583B9B789A2FC 523264 ----a-w- C:\Windows\System32\vbscript.dll 2014-12-11 06:30:34 924D4E490B8772F4A4D9350F72756784 1181696 ----a-w- C:\Windows\System32\urlmon.dll 2014-12-11 06:30:34 36897C279E22BC5671B6CFB70B86D092 2054656 ----a-w- C:\Windows\System32\iertutil.dll 2014-12-11 06:30:34 2BB8BC3DF1BE3F384931021E7D8331E4 1762816 ----a-w- C:\Windows\System32\wininet.dll 2014-12-11 06:30:33 DEE4ECED282D6F1F067F49E216EBE789 361984 ----a-w- C:\Windows\System32\html.iec 2014-12-11 06:30:33 AE1DFAAA1C6F63458781818FC7B91F5E 1441280 ----a-w- C:\Windows\System32\inetcpl.cpl 2014-12-11 06:30:33 AB6BCCAD359BC856D25DE8E24EDEB28B 109056 ----a-w- C:\Windows\System32\iesysprep.dll 2014-12-11 06:30:33 9C81053094E0E261BEB00F819BF2FD11 2861568 ----a-w- C:\Windows\System32\jscript9.dll 2014-12-11 06:30:32 F47A0D87C71BE0A02AA651631DFD2D19 391168 ----a-w- C:\Windows\System32\ieui.dll 2014-12-11 06:30:32 B2D53AF974D63457079519E85DB0BDCA 690688 ----a-w- C:\Windows\System32\jscript.dll 2014-12-11 06:30:32 B14D3A6181DF913518E118820660EEB8 493056 ----a-w- C:\Windows\System32\msfeeds.dll 2014-12-11 06:30:32 37BE69922168AFB6FE670130DDFB5B89 226816 ----a-w- C:\Windows\System32\iedkcs32.dll 2014-12-11 06:30:31 D212F4FC0125511F78605CA25BCF2118 80384 ----a-w- C:\Windows\System32\mshtmled.dll 2014-12-11 06:30:31 95DB60B7C34D03BF5AD29108DA33B986 39936 ----a-w- C:\Windows\System32\jsproxy.dll 2014-12-11 06:30:31 8CFF3C79C48458398A9B33B85977EF0C 71680 ----a-w- C:\Windows\System32\RegisterIEPKEYs.exe 2014-12-11 06:30:31 7DC8C56ACCB1E924AA280BC4DE36E3A7 357888 ----a-w- C:\Windows\System32\dxtmsft.dll 2014-12-11 06:30:31 54B6FF5C83264E126F452B67C6A6D227 61440 ----a-w- C:\Windows\System32\iesetup.dll 2014-12-11 06:30:31 4A982801D55D2BA46CB449E05419864D 163840 ----a-w- C:\Windows\System32\msrating.dll 2014-12-11 06:30:31 45F9ADEC5CDE7EF2E163456B607A5468 33280 ----a-w- C:\Windows\System32\iernonce.dll 2014-12-11 06:30:31 45F21E19D8439D0921A41E24AC80B159 42496 ----a-w- C:\Windows\System32\ie4uinit.exe 2014-12-11 06:30:31 0E75B6A37993DCF97D1C50C1EABE0EEE 226816 ----a-w- C:\Windows\System32\dxtrans.dll 2014-12-11 06:30:30 A1246471DC24E227A692AAAA1E6E4E19 2706432 ----a-w- C:\Windows\System32\mshtml.tlb 2014-12-11 06:30:14 9EA3783672D21817B9DF1061B54C3B3C 155136 ----a-w- C:\Windows\System32\charmap.exe 2014-12-11 06:30:13 B975C202F590BBC5AA63225FBD148791 198656 ----a-w- C:\Windows\System32\WSManHTTPConfig.exe 2014-12-11 06:30:13 B6AC69FFBAA159DD5CEED814245A286D 214016 ----a-w- C:\Windows\System32\WsmWmiPl.dll 2014-12-11 06:30:13 5D9A1A3E5824CECE65871C60E5A08A1A 145920 ----a-w- C:\Windows\System32\WsmAuto.dll 2014-12-11 06:30:13 2C28FEC61C4AC68480A99CB7AA197FA9 248832 ----a-w- C:\Windows\System32\WSManMigrationPlugin.dll 2014-12-11 06:30:13 1DE9BD23AFA36150586C732D876D9B74 1177088 ----a-w- C:\Windows\System32\WsmSvc.dll ====== C:\Windows\system32\drivers ===== 2014-12-15 18:01:03 185ADA973B5020655CEE342059A86CBB 26840 ----a-w- C:\Windows\System32\drivers\GEARAspiWDM.sys 2014-12-11 06:31:08 7FE680A3DFA421C4A8E4879AE4C5AAB0 74752 ----a-w- C:\Windows\System32\drivers\tdx.sys ====== C:\Windows\Tasks ====== 2014-12-15 20:15:47 E054E108359F40AA9CEB7961CAC67375 3430 ----a-w- C:\Windows\system32\Tasks\Apple Diagnostics 2014-12-15 16:00:49 -------- d-----w- C:\Windows\system32\Tasks\Apple ====== C:\Windows\Temp ====== ======= C:\Program Files ===== 2014-12-16 13:18:53 -------- d-----w- C:\Program Files\trend micro 2014-12-15 16:00:33 -------- d-----w- C:\Program Files\Bonjour ======= C: ===== ====== C:\Users\Gebruiker\AppData\Roaming ====== 2014-12-16 17:56:22 D3B1E19875923638EFCDA30D0311B42D 108816 ----a-w- C:\Users\Gebruiker\AppData\Local\GDIPFONTCACHEV1.DAT 2014-12-15 20:16:58 -------- d-----w- C:\Users\Gebruiker\AppData\Local\B002FD82-592E-4AD2-A1D6-FD075B3E122F.aplzod 2014-12-15 20:16:26 -------- d-----w- C:\Users\Gebruiker\AppData\Local\Apple Inc 2014-11-29 15:45:58 -------- d-----w- C:\Users\Gebruiker\AppData\Locallow\Seven Sails Ltda ====== C:\Users\Gebruiker ====== 2014-12-16 17:22:50 -------- d-----w- C:\ProgramData\RegInOut 2014-12-15 20:16:29 -------- d-----r- C:\Users\Gebruiker\iCloudDrive 2014-12-15 20:07:03 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iCloud 2014-12-15 18:01:23 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes 2014-12-15 17:59:12 -------- d-----w- C:\ProgramData\B0FFCDD9-5261-4e59-B29A-17A4FABDEBAB ====== C: exe-files == 2014-12-16 13:18:53 9A2347903D6EDB84C10F288BC0578C1C 388608 ----a-w- C:\Program Files\trend micro\Gebruiker.exe 2014-12-11 10:46:36 D17954CA6343F43B62637F51996B4E95 23040 ----a-w- C:\Windows\System32\mfpmp.exe 2014-12-11 10:46:35 60FBCF033FF42A40C916C01A962A8802 50176 ----a-w- C:\Windows\System32\rrinstaller.exe 2014-12-11 06:31:02 DEF30B58859FBA3458DCA4057AAABA7A 40448 ----a-w- C:\Windows\servicing\GC32\tzupd.exe 2014-12-11 06:30:33 55F99137468CF692802C7C192C422F2C 770704 ----a-w- C:\Program Files\Internet Explorer\iexplore.exe 2014-12-11 06:30:32 E628EF5D8D8E9ED59E5907540468F9BA 470016 ----a-w- C:\Program Files\Internet Explorer\ieinstal.exe 2014-12-11 06:30:31 8CFF3C79C48458398A9B33B85977EF0C 71680 ----a-w- C:\Windows\System32\RegisterIEPKEYs.exe 2014-12-11 06:30:31 45F21E19D8439D0921A41E24AC80B159 42496 ----a-w- C:\Windows\System32\ie4uinit.exe 2014-12-11 06:30:14 9EA3783672D21817B9DF1061B54C3B3C 155136 ----a-w- C:\Windows\System32\charmap.exe 2014-12-11 06:30:13 B975C202F590BBC5AA63225FBD148791 198656 ----a-w- C:\Windows\System32\WSManHTTPConfig.exe === C: other files == 2014-12-17 11:00:16 56C2811FD0D7B727808A69407B5BFAE0 127064 ----a-r- C:\Windows\System32\drivers\NST\7DE07080.017\ccSetx86.sys 2014-12-15 18:01:03 185ADA973B5020655CEE342059A86CBB 26840 -c--a-w- C:\Windows\System32\DRVSTORE\GEARAspiWD_1E13C24EB2F28CB6915317F7F17F180ECAA0DB1E\x86\GEARAspiWDM.sys 2014-12-15 18:01:03 185ADA973B5020655CEE342059A86CBB 26840 ----a-w- C:\Windows\System32\drivers\GEARAspiWDM.sys 2014-12-11 06:31:08 7FE680A3DFA421C4A8E4879AE4C5AAB0 74752 ----a-w- C:\Windows\System32\drivers\tdx.sys ======== System Restore Points ======== RP804: 19/10/2014 10:35:30 - Revo Uninstaller's restore point - Google Toolbar for Internet Explorer RP805: 1/11/2014 21:33:21 - Windows Back-up RP806: 12/11/2014 15:57:19 - Windows Update RP807: 19/11/2014 11:34:02 - Windows Update RP808: 2/12/2014 13:59:45 - Windows Back-up RP809: 8/12/2014 16:06:22 - Revo Uninstaller's restore point - RegCure Pro RP810: 8/12/2014 19:02:09 - Installed Should I Remove It RP811: 8/12/2014 19:06:38 - Revo Uninstaller's restore point - Plus-HD-9.0 RP812: 8/12/2014 19:09:57 - Revo Uninstaller's restore point - Should I Remove It RP813: 8/12/2014 19:10:32 - Removed Should I Remove It RP814: 11/12/2014 11:00:21 - Windows Update RP815: 15/12/2014 17:01:03 - Installed iCloud RP816: 15/12/2014 18:57:43 - Installed iTunes RP817: 15/12/2014 20:03:48 - Revo Uninstaller's restore point - iCloud RP818: 15/12/2014 20:26:28 - Installed Microsoft Fix it 50123 RP819: 15/12/2014 20:35:24 - Herstelbewerking RP820: 15/12/2014 21:06:06 - Installed iCloud RP821: 16/12/2014 13:39:09 - Removed Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 RP822: 16/12/2014 13:40:09 - Microsoft Visual C++ 2005 Redistributable is verwijderd RP823: 16/12/2014 13:41:16 - Microsoft Visual C++ 2005 Redistributable is verwijderd RP824: 16/12/2014 13:42:15 - Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 RP825: 16/12/2014 13:45:17 - Removed Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 RP826: 16/12/2014 13:46:40 - Removed Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 RP827: 16/12/2014 13:47:21 - Removed Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 RP828: 16/12/2014 16:57:31 - Revo Uninstaller's restore point - Advanced System Optimizer RP829: 16/12/2014 18:40:05 - Revo Uninstaller's restore point - RegInOut System Utilities RP830: 17/12/2014 11:55:44 - Revo Uninstaller's restore point - Norton 360 RP831: 17/12/2014 13:47:09 - zoek.exe restore point ==== Startup Registry Enabled ====================== [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun" [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun" [HKEY_USERS\S-1-5-21-2495464155-2157068309-4147718583-1000\Software\Microsoft\Windows\CurrentVersion\Run] "iCloudServices"="C:\Program Files\Common Files\Apple\Internet Services\iCloudServices.exe" "AppleIEDAV"="C:\Program Files\Common Files\Apple\Internet Services\AppleIEDAV.exe" "iCloudDrive"="C:\Program Files\Common Files\Apple\Internet Services\iCloudDrive.exe" "ApplePhotoStreams"="C:\Program Files\Common Files\Apple\Internet Services\ApplePhotoStreams.exe" [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce] "mctadmin"="C:\Windows\System32\mctadmin.exe" [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce] "mctadmin"="C:\Windows\System32\mctadmin.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" "Adobe ARM"="C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "iCloudServices"="C:\Program Files\Common Files\Apple\Internet Services\iCloudServices.exe" "AppleIEDAV"="C:\Program Files\Common Files\Apple\Internet Services\AppleIEDAV.exe" "iCloudDrive"="C:\Program Files\Common Files\Apple\Internet Services\iCloudDrive.exe" "ApplePhotoStreams"="C:\Program Files\Common Files\Apple\Internet Services\ApplePhotoStreams.exe" ==== Task Scheduler Jobs ====================== C:\Windows\tasks\Adobe Flash Player Updater.job --a------ C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [14/12/2014 09:41] C:\Windows\tasks\GoogleUpdateTaskMachineCore.job --a------ [Undetermined Task] C:\Windows\tasks\GoogleUpdateTaskMachineUA.job --a------ C:\Program Files\Google\Update\GoogleUpdate.exe [25/01/2013 14:12] C:\Windows\tasks\NUSchedule.job --a------ C:\Program Files\Norton Utilities 15\nu.exe [23/12/2011 10:17] ==== Other Scheduled Tasks ====================== "C:\Windows\system32\tasks\0" [c:\program files\internet explorer\iexplore.exe] "C:\Windows\system32\tasks\4802" [wscript.exe C:\Users\GEBRUI~1\AppData\Local\Temp\launchie.vbs //B] "C:\Windows\system32\tasks\Adobe Flash Player Updater" [C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe] "C:\Windows\system32\tasks\Apple Diagnostics" [C:\Program Files\Common Files\Apple\Internet Services\EReporter.exe] "C:\Windows\system32\tasks\CreateChoiceProcessTask" [C:\Windows\System32\browserchoice.exe] "C:\Windows\system32\tasks\GoogleUpdateTaskMachineCore" [C:\Program Files\Google\Update\GoogleUpdate.exe] "C:\Windows\system32\tasks\GoogleUpdateTaskMachineUA" [C:\Program Files\Google\Update\GoogleUpdate.exe] "C:\Windows\system32\tasks\NUSchedule" [C:\Program Files\Norton Utilities 15\nu.exe] "C:\Windows\system32\tasks\SidebarExecute" [C:\Program Files\Windows Sidebar\sidebar.exe] "C:\Windows\system32\tasks\{03A1912B-94E2-4CC0-8566-1F7210D37166}" [C:\Users\Gebruiker\Desktop\Iron Sea Defenders\IronSea.exe] "C:\Windows\system32\tasks\{231B5015-E3E5-4BCD-93C2-86911496CA6F}" [C:\Users\Gebruiker\Desktop\RGC.rar.exe] "C:\Windows\system32\tasks\{2A1154F5-93E3-46BA-A463-21D6BB3F6B55}" [C:\Users\Gebruiker\Desktop\Iron Sea Defenders\IronSea.exe] "C:\Windows\system32\tasks\{3465D962-C786-419C-830C-AE5094EA8E01}" [C:\Users\Gebruiker\Desktop\Iron Sea Defenders\IronSea.exe] "C:\Windows\system32\tasks\{36B42AC9-4B01-4E0E-9E00-7D1AC9C5C6D9}" [C:\Users\Gebruiker\Desktop\Delicious - Emily's Honeymoon Cruise Deluxe\Delicious9.exe] "C:\Windows\system32\tasks\{63BF80E2-E97F-4432-8EF6-E7BB6DFA97FB}" [C:\Users\Gebruiker\Desktop\Royal Defense - Invisible Threat\rd-it.exe] "C:\Windows\system32\tasks\{79311994-1394-40E4-BA97-C826C79A60E8}" [C:\Program Files\Skype\\Phone\Skype.exe] "C:\Windows\system32\tasks\{88653ED6-2029-4576-9E8F-2A43A0A8BA35}" [C:\Users\Gebruiker\Desktop\Royal Defense - Invisible Threat\rd-it.exe] "C:\Windows\system32\tasks\{8C298EB5-040C-45AF-B3A8-EC0C5EBF1FB9}" [C:\Users\Gebruiker\Desktop\Iron Sea Defenders\IronSea.exe] "C:\Windows\system32\tasks\{9662BCA9-2616-4FF0-ADA3-46012AABA07C}" [C:\Users\Gebruiker\Desktop\Iron Sea Defenders\IronSea.exe] "C:\Windows\system32\tasks\{9E2C824D-0BDE-46A3-89D0-EAA0628B7747}" [C:\Users\Gebruiker\Desktop\Royal Defense - Invisible Threat\rd-it.exe] "C:\Windows\system32\tasks\{A6AED555-BFD6-4B4E-87C7-EFC6241A7F21}" [C:\Users\Gebruiker\Desktop\Royal Defense - Invisible Threat\rd-it.exe] "C:\Windows\system32\tasks\{B425817C-AB73-492F-9233-A203BAE276FE}" [C:\Users\Gebruiker\Desktop\Royal Defense - Invisible Threat\rd-it.exe] "C:\Windows\system32\tasks\{D34FC027-EB65-4765-9610-95813EBC76F2}" [C:\Program Files\Skype\\Phone\Skype.exe] "C:\Windows\system32\tasks\{E19EFC41-1D79-4F29-91D4-05947E204B50}" [C:\Users\Gebruiker\Desktop\Royal Defense - Invisible Threat\rd-it.exe] "C:\Windows\system32\tasks\{EE785BE0-1CD7-4ED0-B6E6-DAE894905F17}" [C:\Users\Gebruiker\Desktop\MagicEncyclopedia-Illusions\Magic.exe] "C:\Windows\system32\tasks\Apple\AppleSoftwareUpdate" [C:\Program Files\Apple Software Update\SoftwareUpdate.exe] "C:\Windows\system32\tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask" [%systemroot%\system32\sc.exe start osppsvc] ==== Firefox Extensions Registry ====================== [HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions] "{F04D2D30-776C-4d02-8627-8E4385ECA58D}"="C:\ProgramData\Norton\{92622AAD-05E8-4459-B256-765CE1E929FB}\NST_2014.7.8.23\coFFPlgn" [17/12/2014 13:35] ==== Firefox Extensions ====================== AppDir: C:\Program Files\Mozilla Firefox - Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} - Skype Click to Call - %AppDir%\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi ==== Firefox Plugins ====================== Profilepath: C:\Users\Gebruiker\AppData\Roaming\Mozilla\Firefox\Profiles\f7wz8tt8.default E7006BB5611298DBDD03FE3519C19AC2 - C:\Program Files\Java\jre1.8.0_25\bin\plugin2\npjp2.dll - Java(TM) Platform SE 8 U25 238F239EAEFF7E3E782913D599084E18 - C:\Program Files\Java\jre1.8.0_25\bin\dtplugin\npdeployJava1.dll - Java Deployment Toolkit 8.0.250.18 D2377C9458EFEB094E38B8C874AA214C - C:\Program Files\Google\Update\1.3.25.11\npGoogleUpdate3.dll - Google Update 64C4ADE063A9C93D3BAE09922AD90C27 - C:\Program Files\Adobe\Reader 11.0\Reader\browser\nppdf32.dll - Adobe Acrobat 446BCAE59E26321802E000FC3E0C390A - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll - Adobe Acrobat 893BF7D2261C56C24F813405D9D018E0 - C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll - Silverlight Plug-In 8B748A2C8282CAC6FD0323787D69A3EF - C:\Program Files\SkypeWebPlugin\npSkypeWebPlugin.dll - Skype Web Plugin DA4E83FE6F229C7108EF5E9671B29260 - C:\Program Files\Garmin GPS Plugin\npGarmin.dll - Garmin Communicator Plug-In C517E5EA7CEE783F3681F62D2A362E5B - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll - Windows Live? Photo Gallery 8DA2ED6B04EA33F2EAE8BA883F903729 - C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrlui.dll - Microsoft® Silverlight ==== Chromium Look ====================== Google Chrome Version: 36.0.1985.125 (Possible outdated, latest Stable version: 39.0.2171.95) HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions fmjdjihgmghiemmbhbcjmimimimlifkd - No path found[] iikflkcanblccfahdhdonehdalibjnif - No path found[] lifbcibllhkdhoafpjfnlhfpfgnpldfl - C:\Program Files\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx[14/07/2014 17:22] nppllibpnmahfaklnpggkibhkapjkeob - C:\Program Files\Norton Identity Safe\Engine\2014.7.8.23\Exts\Chrome.crx[20/09/2014 09:52] Last updated at time on date - Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb Plus-HD-9.0 - Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Extensions\cpphaajncbmfohddbgnllfcmcjcbaced DownlOAdd kkeeperi - Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Extensions\fmeainpknjdipcfjmipjkigddadfhljp Norton Identity Safe - Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Extensions\iikflkcanblccfahdhdonehdalibjnif Skype Click to Call - Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl Norton Security Toolbar - Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk SearchNewTab - Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Extensions\ninfmohnpainjnnhfikilpcbaoenahci Google Wallet - Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda ==== Chromium Startpages ====================== C:\Users\Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Preferences "homepage": "http://www.google.com", "startup_urls": [ "http://www.google.com" ], ==== Chromium Fix ====================== C:\Users\Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_www.superfish.com_0.localstorage deleted successfully C:\Users\Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.superfish.com_0.localstorage deleted successfully C:\Users\Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_websearch.searchboxes.info_0.localstorage deleted successfully C:\Users\Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_websearch.wisesearch.info_0.localstorage deleted successfully C:\Users\Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_continuetosave.info_0.localstorage deleted successfully C:\Users\Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.adbutter.net_0.localstorage deleted successfully C:\Users\Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.icmwebserv.com_0.localstorage deleted successfully C:\Users\Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_adblock-plus.nl.softonic.com_0.localstorage deleted successfully C:\Users\Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Extensions\ninfmohnpainjnnhfikilpcbaoenahci deleted successfully C:\Users\Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_ninfmohnpainjnnhfikilpcbaoenahci_0.localstorage deleted successfully C:\Users\Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ninfmohnpainjnnhfikilpcbaoenahci deleted successfully C:\Users\Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Extensions\cpphaajncbmfohddbgnllfcmcjcbaced deleted successfully C:\Users\Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_cpphaajncbmfohddbgnllfcmcjcbaced_0.localstorage deleted successfully C:\Users\Gebruiker\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_cpphaajncbmfohddbgnllfcmcjcbaced_0 deleted successfully C:\Users\Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\cpphaajncbmfohddbgnllfcmcjcbaced deleted successfully C:\Users\Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Extensions\fmeainpknjdipcfjmipjkigddadfhljp deleted successfully C:\Users\Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_fmeainpknjdipcfjmipjkigddadfhljp_0.localstorage deleted successfully C:\Users\Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\fmeainpknjdipcfjmipjkigddadfhljp deleted successfully ==== Set IE to Default ====================== Old Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="https://www.google.be/?gws_rd=cr&ei=ikegu5uqd-r-ygpwxydocg" "Search Page"="http://www.google.nl" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://www.symantec.com/redirects/security_response/fix_homepage/index.jsp?lg=nl&pid=N360&pvid=21.4.0.13" New Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896" "Start Page"="https://www.google.be/?gws_rd=cr&ei=ikegu5uqd-r-ygpwxydocg" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157" ==== All HKCU SearchScopes ====================== HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes "DefaultScope"="{6A1806CD-94D4-4689-BA73-E35EA1EA9990}" {012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}" {0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE11SR" {6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7MXGB_nlBE562" ==== Reset Google Chrome ====================== C:\Users\Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully C:\Users\Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully ==== shortcuts on Users Desktops ====================== C:\Users\Gebruiker\Desktop\BearShare.lnk - C:\Program Files\BearShare Applications\BearShare\BearShare.exe C:\Users\Gebruiker\Desktop\CradleOfEgypt_og.exe.lnk - C:\Users\Gebruiker\Desktop\CradleOfEgypt\CradleOfEgypt_og.exe C:\Users\Gebruiker\Desktop\CradleOfRome2_og.exe.lnk - C:\Users\Gebruiker\Desktop\CradleOfRome2\CradleOfRome2_og.exe C:\Users\Gebruiker\Desktop\garminmapupdater_v3.2.2.exe.lnk - D:\Mijn documenten\garminmapupdater_v3.2.2.exe C:\Users\Gebruiker\Desktop\Microsoft Office.lnk - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office C:\Users\Gebruiker\Desktop\Mijn documenten.lnk - D:\Mijn documenten C:\Users\Gebruiker\Desktop\Norton-installatiebestanden.lnk - C:\Users\Public\Downloads\Norton\{N360P213012-SHPD-FSD40014} C:\Users\Gebruiker\Desktop\QuickPar.lnk - C:\Program Files\QuickPar\QuickPar.exe C:\Users\Gebruiker\Desktop\Revo Uninstaller.lnk - C:\Program Files\VS Revo Group\Revo Uninstaller\Revouninstaller.exe C:\Users\Gebruiker\Desktop\Windows Live Mail.lnk - C:\Program Files\Windows Live\Mail\wlmail.exe ==== shortcuts on All Users Desktop ====================== C:\Users\Public\Desktop\Google Chrome.lnk - C:\Program Files\Google\Chrome\Application\chrome.exe C:\Users\Public\Desktop\iTunes.lnk - C:\Program Files\iTunes\iTunes.exe C:\Users\Public\Desktop\Mozilla Firefox.lnk - C:\Program Files\Mozilla Firefox\firefox.exe C:\Users\Public\Desktop\Nero Home.lnk - C:\Program Files\Nero\Nero 7\Nero Home\NeroHome.exe -ScParameter=8 C:\Users\Public\Desktop\Nero StartSmart.lnk - C:\Program Files\Nero\Nero 7\Nero StartSmart\NeroStartSmart.exe -ScParameter=8 C:\Users\Public\Desktop\Nokia Ovi Suite.lnk - C:\Program Files\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe C:\Users\Public\Desktop\Norton Utilities 15.lnk - C:\Program Files\Norton Utilities 15\nu.exe C:\Users\Public\Desktop\Wise Disk Cleaner.lnk - C:\Program Files\Wise Disk Cleaner\WiseDiskCleaner.exe C:\Users\Public\Desktop\Wise Registry Cleaner.lnk - C:\Program Files\Wise Registry Cleaner\WiseRegCleaner.exe ==== shortcuts in All Users Start Menu ====================== C:\ProgramData\Microsoft\Windows\Start Menu\Programma's\Adobe Reader XI.lnk - C:\Windows\Installer\{AC76BA86-7AD7-1043-7B44-AB0000000001}\SC_Reader.ico C:\ProgramData\Microsoft\Windows\Start Menu\Programma's\Apple Software Update.lnk - C:\Windows\Installer\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}\AppleSoftwareUpdateIco.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programma's\iCloud\Agenda.lnk - C:\Program Files\Common Files\Apple\Internet Services\iCloudWeb.exe calendar C:\ProgramData\Microsoft\Windows\Start Menu\Programma's\iCloud\Contactgegevens.lnk - C:\Program Files\Common Files\Apple\Internet Services\iCloudWeb.exe contacts C:\ProgramData\Microsoft\Windows\Start Menu\Programma's\iCloud\E-mail.lnk - C:\Program Files\Common Files\Apple\Internet Services\iCloudWeb.exe mail C:\ProgramData\Microsoft\Windows\Start Menu\Programma's\iCloud\Herinneringen.lnk - C:\Program Files\Common Files\Apple\Internet Services\iCloudWeb.exe reminders C:\ProgramData\Microsoft\Windows\Start Menu\Programma's\iCloud\iCloud-foto's.lnk - C:\Program Files\Common Files\Apple\Internet Services\ShellStreamsShortcut.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programma's\iCloud\iCloud.lnk - C:\Program Files\Common Files\Apple\Internet Services\iCloud.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programma's\iCloud\Notities.lnk - C:\Program Files\Common Files\Apple\Internet Services\iCloudWeb.exe notes C:\ProgramData\Microsoft\Windows\Start Menu\Programma's\iCloud\Zoek mijn iPhone.lnk - C:\Program Files\Common Files\Apple\Internet Services\iCloudWeb.exe find C:\ProgramData\Microsoft\Windows\Start Menu\Programma's\iTunes\Info iTunes.lnk - C:\Program Files\iTunes\iTunes.Resources\nl.lproj\About iTunes.rtf C:\ProgramData\Microsoft\Windows\Start Menu\Programma's\iTunes\iTunes.lnk - C:\Program Files\iTunes\iTunes.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programma's\Java\About Java.lnk - C:\Program Files\Java\jre1.8.0_25\bin\javacpl.exe -tab about C:\ProgramData\Microsoft\Windows\Start Menu\Programma's\Java\Check For Updates.lnk - C:\Program Files\Java\jre1.8.0_25\bin\javacpl.exe -tab update C:\ProgramData\Microsoft\Windows\Start Menu\Programma's\Java\Configure Java.lnk - C:\Program Files\Java\jre1.8.0_25\bin\javacpl.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programma's\Java\Get Help.lnk - C:\ProgramData\Microsoft\Windows\Start Menu\Programma's\Java\Visit Java.com.lnk - C:\ProgramData\Microsoft\Windows\Start Menu\Programma's\Norton Identity Safe\Norton Identity Safe verwijderen.LNK - C:\ProgramData\Microsoft\Windows\Start Menu\Programma's\Norton Identity Safe\Norton Identity Safe.LNK - C:\Program Files\Norton Identity Safe\Engine\2014.7.8.23\coSAStub.exe /install /force C:\ProgramData\Microsoft\Windows\Start Menu\Programma's\Skype\Skype.lnk - C:\Program Files\Skype\Phone\Skype.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk - C:\Windows\Installer\{AC76BA86-7AD7-1043-7B44-AB0000000001}\SC_Reader.ico C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk - C:\Windows\Installer\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}\AppleSoftwareUpdateIco.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iCloud\Agenda.lnk - C:\Program Files\Common Files\Apple\Internet Services\iCloudWeb.exe calendar C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iCloud\Contactgegevens.lnk - C:\Program Files\Common Files\Apple\Internet Services\iCloudWeb.exe contacts C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iCloud\E-mail.lnk - C:\Program Files\Common Files\Apple\Internet Services\iCloudWeb.exe mail C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iCloud\Herinneringen.lnk - C:\Program Files\Common Files\Apple\Internet Services\iCloudWeb.exe reminders C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iCloud\iCloud-foto's.lnk - C:\Program Files\Common Files\Apple\Internet Services\ShellStreamsShortcut.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iCloud\iCloud.lnk - C:\Program Files\Common Files\Apple\Internet Services\iCloud.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iCloud\Notities.lnk - C:\Program Files\Common Files\Apple\Internet Services\iCloudWeb.exe notes C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iCloud\Zoek mijn iPhone.lnk - C:\Program Files\Common Files\Apple\Internet Services\iCloudWeb.exe find C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes\Info iTunes.lnk - C:\Program Files\iTunes\iTunes.Resources\nl.lproj\About iTunes.rtf C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes\iTunes.lnk - C:\Program Files\iTunes\iTunes.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\About Java.lnk - C:\Program Files\Java\jre1.8.0_25\bin\javacpl.exe -tab about C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\Check For Updates.lnk - C:\Program Files\Java\jre1.8.0_25\bin\javacpl.exe -tab update C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\Configure Java.lnk - C:\Program Files\Java\jre1.8.0_25\bin\javacpl.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\Get Help.lnk - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\Visit Java.com.lnk - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton Identity Safe\Norton Identity Safe verwijderen.LNK - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton Identity Safe\Norton Identity Safe.LNK - C:\Program Files\Norton Identity Safe\Engine\2014.7.8.23\coSAStub.exe /install /force C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype\Skype.lnk - C:\Program Files\Skype\Phone\Skype.exe ==== shortcuts in Quick Launch ====================== C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk - C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk - C:\Users\Default User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk - C:\Users\Default User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk - C:\Users\Gebruiker\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk - C:\Program Files\Google\Chrome\Application\chrome.exe C:\Users\Gebruiker\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk - C:\Program Files\Internet Explorer\iexplore.exe C:\Users\Gebruiker\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Nero Home.lnk - C:\Program Files\Nero\Nero 7\Nero Home\NeroHome.exe -ScParameter=8 C:\Users\Gebruiker\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Nero StartSmart.lnk - C:\Program Files\Nero\Nero 7\Nero StartSmart\NeroStartSmart.exe -ScParameter=8 C:\Users\Gebruiker\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk - C:\Users\Gebruiker\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk - C:\Users\Gebruiker\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Autostart program viewer.lnk - C:\Program Files\AutoRuns\autoruns.exe C:\Users\Gebruiker\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Internet Explorer.lnk - C:\Program Files\Internet Explorer\iexplore.exe C:\Users\Gebruiker\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Media Center.lnk - C:\Windows\ehome\ehshell.exe C:\Users\Gebruiker\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\W7C LogonUI Changer.lnk - C:\Program Files\W7CLogonUIChanger\W7C LogonUI Changer.exe C:\Users\Gebruiker\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Windows Mail.lnk - C:\Program Files\Windows Mail\WinMail.exe C:\Users\Gebruiker\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Windows Media Player.lnk - C:\Program Files\Windows Media Player\wmplayer.exe /prefetch:1 C:\Users\Gebruiker\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Windows Movie Maker.lnk - C:\Program Files\Movie Maker\MOVIEMK.exe C:\Users\Gebruiker\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Windows Update.lnk - C:\Windows\system32\wuapp.exe startmenu C:\Users\Gebruiker\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Windows Verkenner.lnk - C:\Windows\explorer.exe /n, /e, /select, C:\ C:\Users\Gebruiker\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk - C:\Program Files\Internet Explorer\iexplore.exe C:\Users\Gebruiker\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk - C:\Program Files\Mozilla Firefox\firefox.exe C:\Users\Gebruiker\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Windows Explorer.lnk - C:\Windows\explorer.exe /n, /e, /select, C:\ C:\Users\Gebruiker\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Windows Media Player.lnk - C:\Program Files\Windows Media Player\wmplayer.exe /prefetch:1 ==== Uninstall List x86 ====================== Adblock Plus for IE [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{fd97d1e2-368a-4cd9-af63-8eeff938044a}] Adblock Plus voor IE (32-bit) [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{4705E842-6249-4063-B410-7DA3B24ABDCD}] Adobe AIR [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{FDB3B167-F4FA-461D-976F-286304A57B2A}] Adobe AIR [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\Adobe AIR] Adobe Flash Player 16 ActiveX [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\Adobe Flash Player ActiveX] Adobe Reader XI (11.0.09) - Nederlands [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{AC76BA86-7AD7-1043-7B44-AB0000000001}] Apple Application Support [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{83CAF0DE-8D3B-4C37-A631-2B8F16EC3031}] Apple Mobile Device Support [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{235EBB33-3DA1-46DF-AADE-9955123409CB}] Apple Software Update [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}] BearShare [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{5F624839-947D-46EA-BD63-FD847C1AC6F1}] BearShare [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\BearShare] Belkin Wireless USB Utility [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{A6359CCF-215D-43D9-8366-479D231F2A72}] Bluesoleil 5.4.277.0 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{25887983-54F3-4F55-A7C5-91229AD67C16}] Bonjour [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{79155F2B-9895-49D7-8612-D92580E0DE5B}] CameraHelperMsi [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{15634701-BACE-4449-8B25-1567DA8C9FD3}] Classic Menu 3.9x for Office 2007 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{409ECFF1-9CC7-43A8-B28A-B7F0B7CB04D1}_is1] D3DX10 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{E09C4DB7-630C-4F06-A631-8EA7239923AF}] DAMN NFO Viewer 2.10.0031 RC3 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{DA5E6A2D-DEAA-4152-A43A-FDBDE29AA724}] Elevated Installer [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{9A280A86-0E21-432A-BD56-D2A6CBBB5C6B}] erLT [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}] Garmin City Navigator Europe NT 2013.40 Update [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{245CE34F-42E6-490B-977D-070DBA606953}] Garmin Communicator Plugin [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{647BB978-2876-487B-9B0E-FDB73F0EA4A2}] Garmin Express Tray [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{3F727CE5-6D0E-4569-A081-7A6202131639}] Garmin MapInstall [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{F0D44E64-51EE-4888-A1FD-F13108B75A43}] Garmin USB Drivers [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{ABA5E381-EC46-425C-86C5-5CD15BBFB4BF}] Google Chrome [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\Google Chrome] Google Update Helper [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}] iCloud [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{760BB327-3973-4608-85C8-88162E2FF3B6}] Intel(R) Graphics Media Accelerator Driver [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\HDMI] Intel(R) TV Wizard [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\TVWiz] iTunes [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{5D928931-D1D2-4A93-A82D-BF60D0E7CFA5}] Java 7 Update 67 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{26A24AE4-039D-4CA4-87B4-2F03217067FF}] Java 8 Update 25 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{26A24AE4-039D-4CA4-87B4-2F83218025F0}] Junk Mail filter update [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}] K-Lite Codec Pack 3.7.0 Full [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\KLiteCodecPack_is1] Logitech-webcamsoftware [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{D40EB009-0499-459c-A8AF-C9C110766215}] Logitech Vid [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{4FBCEA31-5D18-4212-9231-DE7CF1BE7DBB}] Logitech Webcam Software-stuurprogrammapakket [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\lvdrivers_12.0] LWS Facebook [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{FF167195-9EE4-46C0-8CD7-FBA3457E88AB}] LWS Gallery [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{6F76EC3C-34B1-436E-97FB-48C58D7BEDCD}] LWS Help_main [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{1651216E-E7AD-4250-92A1-FB8ED61391C9}] LWS Launcher [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{83C8FA3C-F4EA-46C4-8392-D3CE353738D6}] LWS Motion Detection [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{71E66D3F-A009-44AB-8784-75E2819BA4BA}] LWS Pictures And Video [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{08610298-29AE-445B-B37D-EFBE05802967}] LWS Twitter [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{174A3B31-4C43-43DD-866F-73C9DB887B48}] LWS Webcam Software [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{8937D274-C281-42E4-8CDB-A0B2DF979189}] LWS WLM Plugin [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{9DAEA76B-E50F-4272-A595-0124E826553D}] LWS YouTube Plugin [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{21DF0294-6B9D-4741-AB6F-B2ABFBD2387E}] Mesh Runtime [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{8C6D6116-B724-4810-8F2D-D047E6B7D68E}] Messenger Companion [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{8142D25E-028A-4563-86ED-5755783C8029}] Microsoft .NET Framework 4.5.1 (NLD) [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{1A91D86E-3124-3574-A4BF-406761265CFA}] Microsoft .NET Framework 4.5.1 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{4903D172-DCCB-392F-93A3-34CA9D47FE3D}] Microsoft Office Home and Student 2010 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\Office14.SingleImage] Microsoft Office Professional Plus 2007 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\PROPLUS] Microsoft Silverlight [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}] Microsoft SQL Server 2005 Compact Edition [ENU] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}] Mozilla Firefox 30.0 (x86 nl) [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\Mozilla Firefox 30.0 (x86 nl)] Mozilla Maintenance Service [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\MozillaMaintenanceService] MSVC80_x86_v2 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{6D3245B1-8DB8-4A23-9CD2-2C90F40ABAF6}] MSVC90_x86 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{AF111648-99A1-453E-81DD-80DBBF6DAD0D}] MSVCRT [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}] MSXML 4.0 SP2 (KB954430) [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}] MSXML 4.0 SP2 (KB973688) [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}] Nero 7 Ultra Edition [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{4908C75E-E5E2-43F7-B1DF-023CBA831043}] Nokia Connectivity Cable Driver [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{F1FDAA01-988C-423F-AC12-0D8F333943FD}] Nokia Ovi Suite [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{B8B4446F-87E1-4423-A47A-16832C24A199}] Nokia Ovi Suite [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\Nokia Ovi Suite] Nokia Ovi Suite Software Updater [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{EE5B5B24-EEFC-4C8B-BF8B-256D705BAD89}] Norton Identity Safe [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\NST] Norton Utilities 15 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\Norton Utilities 15_is1] OGA Notifier 2.0.0048.0 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{B2544A03-10D0-4E5E-BA69-0362FFC20D18}] Ovi Desktop Sync Engine [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{8112C6B3-91E1-4560-8AB9-876DADFA37C5}] OviMPlatform [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{749A1EDD-16C2-4C63-B013-D38F0F953973}] PC Connectivity Solution [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{45DF6D99-666D-41FA-8D62-0E183B6240F3}] PlayReady PC Runtime x86 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{CCA5EAAD-92F4-4B7A-B5EE-14294C66AB61}] QuickPar 0.9 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\QuickPar] Revo Uninstaller 1.92 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\Revo Uninstaller] Security Update for CAPICOM (KB931906) [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}] SelectionLinks [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\sl-dlc] Skype Click to Call [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}] Skype Web Plugin [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{B51DD93B-3CB5-4D9D-BFF2-FD19DBBBFD9A}] SkypeT 6.21 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}] VDSL2 modem tool [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\VDSL2 modem tool] Windows-stuurprogrammapakket - Nokia pccsmcfd (08/22/2008 7.0.0.0) [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\504244733D18C8F63FF584AEB290E3904E791693] Windows Driver Package - Garmin (grmnusb) GARMIN Devices (04/19/2012 2.3.1.0) [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\98157A226B40B173301B0F53C8E98C47805D5152] Windows Live Communications Platform [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{D45240D3-B6B3-4FF9-B243-54ECE3E10066}] Windows Live Essentials [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{2A07C35B-8384-4DA4-9A95-442B6C89A073}] Windows Live Essentials [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\WinLiveSuite] Windows Live Family Safety [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{2D6E3D97-1FDF-4993-AC75-72F59EC445C5}] Windows Live Family Safety [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{DF33FDAF-22DE-4E3E-AFF7-A8648B473596}] Windows Live ID Sign-in Assistant [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{C6150D8A-86ED-41D3-87BB-F3BB51B0B77F}] Windows Live Installer [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{0B0F231F-CE6A-483D-AA23-77B364F75917}] Windows Live Mail [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{9D56775A-93F3-44A3-8092-840E3826DE30}] Windows Live Mail [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{D588365A-AE39-4F27-BDAE-B4E72C8E900C}] Windows Live Mesh - ActiveX-besturingselement voor externe verbindingen [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{C32CE55C-12BA-4951-8797-0967FDEF556F}] Windows Live Mesh [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{3F4143A1-9C21-4011-8679-3BC1014C6886}] Windows Live Mesh [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{DECDCB7C-58CC-4865-91AF-627F9798FE48}] Windows Live Messenger [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{48294D95-EE9A-4377-8213-44FC4265FB27}] Windows Live Messenger [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{E5B21F11-6933-4E0B-A25C-7963E3C07D11}] Windows Live Messenger Companion Core [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{78A96B4C-A643-4D0F-98C2-A8E16A6669F9}] Windows Live MIME IFilter [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{AF844339-2F8A-4593-81B3-9F4C54038C4E}] Windows Live Movie Maker [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{92EA4134-10D1-418A-91E1-5A0453131A38}] Windows Live Movie Maker [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{CB7224D9-6DCA-43F1-8F83-6B1E39A00F92}] Windows Live Photo Common [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{9BD262D0-B788-4546-A0A5-F4F56EC3834B}] Windows Live Photo Common [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}] Windows Live Photo Gallery [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{3336F667-9049-4D46-98B6-4C743EEBC5B1}] Windows Live Photo Gallery [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{A60B3BF0-954B-42AF-B8D8-2C1D34B613AA}] Windows Live PIMT Platform [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{83C292B7-38A5-440B-A731-07070E81A64F}] Windows Live Remote Client [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{19A4A990-5343-4FF7-B3B5-6F046C091EDF}] Windows Live Remote Client Resources [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{F0CCBE54-9132-44E9-82DF-CD364AD5C22D}] Windows Live Remote Service [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{227E8782-B2F4-4E97-B0EE-49DE9CC1C0C0}] Windows Live Remote Service Resources [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{845E0BCB-8C8D-4FAB-8588-AD5FFD156C95}] Windows Live SOXE [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{682B3E4F-696A-42DE-A41C-4C07EA1678B4}] Windows Live SOXE Definitions [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{200FEC62-3C34-4D60-9CE8-EC372E01C08F}] Windows Live UX Platform [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}] Windows Live UX Platform Language Pack [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{D6F25CF9-4E87-43EB-B324-C12BE9CDD668}] Windows Live Writer [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{7E017923-16F8-4E32-94EF-0A150BD196FE}] Windows Live Writer [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{A726AE06-AAA3-43D1-87E3-70F510314F04}] Windows Live Writer [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}] Windows Live Writer Resources [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{14B441B7-774D-4170-98EA-A13667AE6218}] WinRAR 5.01 (32-bit) [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\WinRAR archiver] Wise Disk Cleaner 8.36 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\Wise Disk Cleaner_is1] Wise Registry Cleaner 8.26 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\Wise Registry Cleaner_is1] ==== Deleting Registry Keys ====================== HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\42B5B5EECFEEB8C4FBB852D607B5DA98 deleted successfully HKEY_LOCAL_MACHINE\Software\Policies\Google deleted successfully HKEY_CURRENT_USER\Software\Policies\Google deleted successfully HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\TVWiz deleted successfully HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{EE5B5B24-EEFC-4C8B-BF8B-256D705BAD89} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\42B5B5EECFEEB8C4FBB852D607B5DA98 deleted successfully ==== HijackThis Entries ====================== R3 - URLSearchHook: (no name) - {5bcf818d-78c8-41b8-ba89-65c5fdac4fc4} - (no file) O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.8.0_25\bin\ssv.dll O2 - BHO: (no name) - {a4c2fb10-84c3-44eb-9f9e-860fa1d9a797} - (no file) O2 - BHO: Norton Identity Protection - {AB4C7833-A6EC-433f-B9FE-6B14B1A2F836} - C:\Program Files\Norton Identity Safe\Engine\2014.7.8.23\coIEPlg.dll O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~3\Office14\URLREDIR.DLL O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre1.8.0_25\bin\jp2ssv.dll O2 - BHO: Adblock Plus for IE Browser Helper Object - {FFCB3198-32F3-4E8B-9539-4324694ED664} - C:\Program Files\Adblock Plus for IE\AdblockPlus32.dll O3 - Toolbar: (no name) - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - (no file) O3 - Toolbar: Norton Identity Safe Toolbar - {A13C2648-91D4-4bf3-BC6D-0079707C4389} - C:\Program Files\Norton Identity Safe\Engine\2014.7.8.23\coIEPlg.dll O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKCU\..\Run: [iCloudServices] C:\Program Files\Common Files\Apple\Internet Services\iCloudServices.exe O4 - HKCU\..\Run: [AppleIEDAV] C:\Program Files\Common Files\Apple\Internet Services\AppleIEDAV.exe O4 - HKCU\..\Run: [iCloudDrive] C:\Program Files\Common Files\Apple\Internet Services\iCloudDrive.exe O4 - HKCU\..\Run: [ApplePhotoStreams] C:\Program Files\Common Files\Apple\Internet Services\ApplePhotoStreams.exe O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE') O9 - Extra button: @C:\Program Files\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files\Windows Live\Companion\companioncore.dll O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra 'Tools' menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra button: Verzenden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll O9 - Extra 'Tools' menuitem: &Verzenden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll O9 - Extra button: &Gekoppelde notities van OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll O9 - Extra 'Tools' menuitem: &Gekoppelde notities van OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll O9 - Extra button: Skype Click to Call settings - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics O16 - DPF: Garmin Communicator Plug-In - https://static.garmincdn.com/gcp/ie/4.0.4.0/GarminAxControl_32.CAB O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab O16 - DPF: {44990B00-3C9D-426D-81DF-AAB636FA4345} - https://www-secure.symantec.com/techsupp/asa/ss/sa/sa_cabs/tgctlcm.cab O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab O16 - DPF: {B60CEFE7-2DD0-4B78-951A-509D951DB1F0} (ExtraFilm Uploader Control) - http://belgacom.extrafilm.be/ExtraFilmUploader6.cab O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL O18 - Protocol: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL O22 - SharedTaskScheduler: Windows DreamScene - {E31004D1-A431-41B8-826F-E902F9D95C81} - C:\Windows\System32\DreamScene.dll O23 - Service: ABBYY FineReader 9.0 Sprint Licensing Service (ABBYY.Licensing.FineReader.Sprint.9.0) - ABBYY - C:\Program Files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe O23 - Service: BlueSoleilCS - IVT Corporation - C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleilCS.exe O23 - Service: Bonjour-service (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: BsHelpCS - IVT Corporation - C:\Program Files\IVT Corporation\BlueSoleil\BsHelpCS.exe O23 - Service: Norton Disk Doctor Service (DiskDoctorService) - Symantec Corporation - C:\Program Files\Norton Utilities 15\Tools\Disk Doctor\DiskDoctorSrv.exe O23 - Service: Google Update-service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe O23 - Service: Google Update-service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe O23 - Service: iPod-service (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe O23 - Service: Norton Identity Safe (NCO) - Symantec Corporation - C:\Program Files\Norton Identity Safe\Engine\2014.7.8.23\NST.exe O23 - Service: ServiceLayer - Nokia - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe O23 - Service: Norton SpeedDisk Service (SpeedDiskService) - Symantec Corporation - C:\Program Files\Norton Utilities 15\Tools\SpeedDisk\SpeedDiskSrv.exe O23 - Service: SupportSoft RemoteAssist - SupportSoft, Inc. - C:\Program Files\Common Files\Supportsoft\bin\ssrc.exe ==== Silent Runners ====================== "Silent Runners.vbs", revision 69.2, http://www.silentrunners.org/ Output limited to non-default values, except where indicated by "{++}" Startup items buried in registry: --------------------------------- HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ {++} iCloudServices = C:\Program Files\Common Files\Apple\Internet Services\iCloudServices.exe [Apple Inc.] AppleIEDAV = C:\Program Files\Common Files\Apple\Internet Services\AppleIEDAV.exe [Apple Inc.] iCloudDrive = C:\Program Files\Common Files\Apple\Internet Services\iCloudDrive.exe [Apple Inc.] ApplePhotoStreams = C:\Program Files\Common Files\Apple\Internet Services\ApplePhotoStreams.exe [Apple Inc.] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++} iTunesHelper = "C:\Program Files\iTunes\iTunesHelper.exe" [Apple Inc.] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\(Default) = (no title provided) -> {HKLM...CLSID} = Java(tm) Plug-In SSV Helper \InProcServer32\(Default) = C:\Program Files\Java\jre1.8.0_25\bin\ssv.dll [Oracle Corporation] {AB4C7833-A6EC-433f-B9FE-6B14B1A2F836}\(Default) = Norton Identity Protection -> {HKLM...CLSID} = Norton Identity Protection \InProcServer32\(Default) = C:\Program Files\Norton Identity Safe\Engine\2014.7.8.23\coIEPlg.dll [Symantec Corporation] {AE805869-2E5C-4ED4-8F7B-F1F7851A4497}\(Default) = SkypeIEPluginBHO -> {HKLM...CLSID} = Skype Click to Call for Internet Explorer \InProcServer32\(Default) = C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [MS] {B4F3A835-0E21-4959-BA22-42B3008E02FF}\(Default) = URLRedirectionBHO -> {HKLM...CLSID} = Office Document Cache Handler \InProcServer32\(Default) = C:\PROGRA~1\MICROS~3\Office14\URLREDIR.DLL [MS] {DBC80044-A445-435b-BC74-9C25C1C588A9}\(Default) = (no title provided) -> {HKLM...CLSID} = Java(tm) Plug-In 2 SSV Helper \InProcServer32\(Default) = C:\Program Files\Java\jre1.8.0_25\bin\jp2ssv.dll [Oracle Corporation] {FFCB3198-32F3-4E8B-9539-4324694ED664}\(Default) = (no title provided) -> {HKLM...CLSID} = Adblock Plus for IE Browser Helper Object \InProcServer32\(Default) = C:\Program Files\Adblock Plus for IE\AdblockPlus32.dll [Adblock Plus] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\ {68C471B2-1DC1-4d63-B2DF-682A910668FB} = VMC Property Handler -> {HKLM...CLSID} = VMC Property Handler \InProcServer32\(Default) = C:\Windows\System32\VMCPropertyHandler.dll [MS] {A0F26623-302C-41E1-B00C-04EE54A3188C} = SelectAll Extension -> {HKLM...CLSID} = SelectAllExt Class \InProcServer32\(Default) = C:\Windows\System32\SelectAll_3.0.dll [empty string] {43723C2F-6A55-48BD-8BF9-4B017087D8AE} = UpOneLevel Extension -> {HKLM...CLSID} = UpOneLevelExt Class \InProcServer32\(Default) = C:\Windows\System32\UpOneLevel_3.0.dll [empty string] {42042206-2D85-11D3-8CFF-005004838597} = Microsoft Office HTML Icon Handler -> {HKLM...CLSID} = (no title provided) \InProcServer32\(Default) = C:\Program Files\Microsoft Office\Office14\msohevi.dll [MS] {993BE281-6695-4BA5-8A2A-7AACBFAAB69E} = Microsoft Office Metadata Handler -> {HKLM...CLSID} = Microsoft Office Metadata Handler \InProcServer32\(Default) = C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll [MS] {C41662BB-1FA0-4CE0-8DC5-9B7F8279FF97} = Microsoft Office Thumbnail Handler -> {HKLM...CLSID} = Microsoft Office Thumbnail Handler \InProcServer32\(Default) = C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll [MS] {B327765E-D724-4347-8B16-78AE18552FC3} = NeroDigitalIconHandler -> {HKLM...CLSID} = NeroDigitalIconHandler Class \InProcServer32\(Default) = C:\Program Files\Common Files\Ahead\Lib\NeroDigitalExt.dll [Nero AG] {7F1CF152-04F8-453A-B34C-E609530A9DC8} = NeroDigitalPropSheetHandler -> {HKLM...CLSID} = NeroDigitalPropSheetHandler Class \InProcServer32\(Default) = C:\Program Files\Common Files\Ahead\Lib\NeroDigitalExt.dll [Nero AG] {B41DB860-8EE4-11D2-9906-E49FADC173CA} = WinRAR shell extension -> {HKLM...CLSID} = WinRAR \InProcServer32\(Default) = C:\Program Files\WinRAR\rarext.dll [Alexander Roshal] {506F4668-F13E-4AA1-BB04-B43203AB3CC0} = {506F4668-F13E-4AA1-BB04-B43203AB3CC0} -> {HKLM...CLSID} = ImageExtractorShellExt Class \InProcServer32\(Default) = C:\Program Files\Microsoft Office\Office14\VISSHE.DLL [MS] {D66DC78C-4F61-447F-942B-3FB6980118CF} = {D66DC78C-4F61-447F-942B-3FB6980118CF} -> {HKLM...CLSID} = CInfoTipShellExt Class \InProcServer32\(Default) = C:\Program Files\Microsoft Office\Office14\VISSHE.DLL [MS] {0875DCB6-C686-4243-9432-ADCCF0B9F2D7} = Microsoft OneNote Namespace Extension for Windows Desktop Search -> {HKLM...CLSID} = Microsoft OneNote Namespace Extension for Windows Desktop Search \InProcServer32\(Default) = C:\Program Files\Microsoft Office\Office14\ONFILTER.DLL [MS] {00020D75-0000-0000-C000-000000000046} = Microsoft Outlook Desktop Icon Handler -> {HKLM...CLSID} = Microsoft Outlook \InProcServer32\(Default) = C:\PROGRA~1\MICROS~3\Office14\MLSHEXT.DLL [MS] {0006F045-0000-0000-C000-000000000046} = Microsoft Outlook Custom Icon Handler -> {HKLM...CLSID} = Outlook File Icon Extension \InProcServer32\(Default) = C:\Program Files\Microsoft Office\Office14\OLKFSTUB.DLL [MS] {00F33137-EE26-412F-8D71-F84E4C2C6625} = (no title provided) -> {HKLM...CLSID} = Windows Live Photo Gallery Viewer Autoplay Shim \InProcServer32\(Default) = C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll [MS] {00F346CB-35A4-465B-8B8F-65A29DBAB1F6} = Windows Live Photo Gallery Viewer Drop Target Shim -> {HKLM...CLSID} = Windows Live Photo Gallery Viewer Shim \InProcServer32\(Default) = C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll [MS] {00F3712A-CA79-45B4-9E4D-D7891E7F8B9D} = Windows Live Photo Gallery Editor Drop Target Shim -> {HKLM...CLSID} = Windows Live Photo Gallery Editor Shim \InProcServer32\(Default) = C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll [MS] {00F30F90-3E96-453B-AFCD-D71989ECC2C7} = Windows Live Photo Gallery Autoplay Drop Target Shim -> {HKLM...CLSID} = Windows Live Photo Gallery Viewer Autoplay Shim \InProcServer32\(Default) = C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll [MS] {B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF} = iTunes -> {HKLM...CLSID} = iTunes \InProcServer32\(Default) = C:\Program Files\iTunes\iTunesMiniPlayer.dll [Apple Inc.] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\ <> {E31004D1-A431-41B8-826F-E902F9D95C81} = Windows DreamScene -> {HKLM...CLSID} = Windows DreamScene \InProcServer32\(Default) = C:\Windows\System32\DreamScene.dll [MS] HKLM\SOFTWARE\Classes\PROTOCOLS\Filter\ <> text/xml\CLSID = {807573E5-5146-11D5-A672-00B0D022E945} -> {HKLM...CLSID} = Microsoft Office InfoPath XML Mime Filter \InProcServer32\(Default) = C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL [MS] HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\ <> ms-help\CLSID = {314111c7-a502-11d2-bbca-00c04f8ec294} -> {HKLM...CLSID} = HxProtocol Class \InProcServer32\(Default) = C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll [MS] <> skype4com\CLSID = {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} -> {HKLM...CLSID} = IEProtocolHandler Class \InProcServer32\(Default) = C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL [Skype Technologies] <> skypec2c\CLSID = {91774881-D725-4E58-B298-07617B9B86A8} -> {HKLM...CLSID} = Skype Click to Call IE Pluggable Protocol \InProcServer32\(Default) = C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [MS] <> wlmailhtml\CLSID = {03C514A3-1EFB-4856-9F99-10D7BE1653C0} -> {HKLM...CLSID} = Windows Live Mail HTML Asynchronous Pluggable Protocol Handler \InProcServer32\(Default) = C:\Program Files\Windows Live\Mail\mailcomm.dll [MS] <> wlpg\CLSID = {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} -> {HKLM...CLSID} = Album Download IE Asynchronous Pluggable Protocol Interface \InProcServer32\(Default) = C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll [MS] HKLM\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\ PhotoStreamsExt\(Default) = {89D984B3-813B-406A-8298-118AFA3A22AE} -> {HKLM...CLSID} = ContextMenuHandler Class \InProcServer32\(Default) = C:\Program Files\Common Files\Apple\Internet Services\ShellStreams.dll [Apple Inc.] WinRAR\(Default) = {B41DB860-8EE4-11D2-9906-E49FADC173CA} -> {HKLM...CLSID} = WinRAR \InProcServer32\(Default) = C:\Program Files\WinRAR\rarext.dll [Alexander Roshal] {EB4D3CFE-E2AA-4C6E-B2FE-2A749F95D208}\(Default) = (no title provided) -> {HKLM...CLSID} = NBShellHook Class \InProcServer32\(Default) = C:\Program Files\Nero\Nero 7\Nero BackItUp\NBShell.dll [Nero AG] HKLM\SOFTWARE\Classes\*\shellex\DragDropHandlers\ NBShellHook\(Default) = {EB4D3CFE-E2AA-4C6E-B2FE-2A749F95D208} -> {HKLM...CLSID} = NBShellHook Class \InProcServer32\(Default) = C:\Program Files\Nero\Nero 7\Nero BackItUp\NBShell.dll [Nero AG] HKLM\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\ WinRAR\(Default) = {B41DB860-8EE4-11D2-9906-E49FADC173CA} -> {HKLM...CLSID} = WinRAR \InProcServer32\(Default) = C:\Program Files\WinRAR\rarext.dll [Alexander Roshal] HKLM\SOFTWARE\Classes\Directory\shellex\CopyHookHandlers\ IVTCopyMonitor\(Default) = {F40807E9-BFD1-44F6-AEB0-27E063BD14CA} -> {HKLM...CLSID} = BsFtpCopyHook Class \InProcServer32\(Default) = C:\Windows\system32\BsShell.dll [IVT Corporation] HKLM\SOFTWARE\Classes\Directory\shellex\DragDropHandlers\ WinRAR\(Default) = {B41DB860-8EE4-11D2-9906-E49FADC173CA} -> {HKLM...CLSID} = WinRAR \InProcServer32\(Default) = C:\Program Files\WinRAR\rarext.dll [Alexander Roshal] HKLM\SOFTWARE\Classes\Directory\Background\shellex\ContextMenuHandlers\ DreamScene\(Default) = {BE800AEB-A440-4B63-94CD-AA6B43647DF9} -> {HKLM...CLSID} = Windows DreamScene Shell Extension \InProcServer32\(Default) = C:\Windows\System32\DreamScene.dll [MS] igfxcui\(Default) = {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} -> {HKLM...CLSID} = GraphicsShellExt Class \InProcServer32\(Default) = C:\Windows\system32\igfxpph.dll [Intel Corporation] Search\(Default) = {2559A1F0-21D7-11D4-BDAF-00C04F60B9F0} -> {HKLM...CLSID} = Search \InProcServer32\(Default) = C:\Windows\System32\shdocvw.dll [MS] SelectAllExtension\(Default) = {A0F26623-302C-41E1-B00C-04EE54A3188C} -> {HKLM...CLSID} = SelectAllExt Class \InProcServer32\(Default) = C:\Windows\System32\SelectAll_3.0.dll [empty string] UpOneLevelExtension\(Default) = {43723C2F-6A55-48BD-8BF9-4B017087D8AE} -> {HKLM...CLSID} = UpOneLevelExt Class \InProcServer32\(Default) = C:\Windows\System32\UpOneLevel_3.0.dll [empty string] HKLM\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\ {7D4D6379-F301-4311-BEBA-E26EB0561882}\(Default) = NeroDigitalExt.NeroDigitalColumnHandler -> {HKLM...CLSID} = NeroDigitalColumnHandler Class \InProcServer32\(Default) = C:\Program Files\Common Files\Ahead\Lib\NeroDigitalExt.dll [Nero AG] {F9DB5320-233E-11D1-9F84-707F02C10627}\(Default) = PDF Column Info -> {HKLM...CLSID} = PDF Shell Extension \InProcServer32\(Default) = C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll [Adobe Systems, Inc.] HKLM\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\ WinRAR\(Default) = {B41DB860-8EE4-11D2-9906-E49FADC173CA} -> {HKLM...CLSID} = WinRAR \InProcServer32\(Default) = C:\Program Files\WinRAR\rarext.dll [Alexander Roshal] {EB4D3CFE-E2AA-4C6E-B2FE-2A749F95D208}\(Default) = (no title provided) -> {HKLM...CLSID} = NBShellHook Class \InProcServer32\(Default) = C:\Program Files\Nero\Nero 7\Nero BackItUp\NBShell.dll [Nero AG] HKLM\SOFTWARE\Classes\Folder\shellex\DragDropHandlers\ NBShellHook\(Default) = {EB4D3CFE-E2AA-4C6E-B2FE-2A749F95D208} -> {HKLM...CLSID} = NBShellHook Class \InProcServer32\(Default) = C:\Program Files\Nero\Nero 7\Nero BackItUp\NBShell.dll [Nero AG] WinRAR\(Default) = {B41DB860-8EE4-11D2-9906-E49FADC173CA} -> {HKLM...CLSID} = WinRAR \InProcServer32\(Default) = C:\Program Files\WinRAR\rarext.dll [Alexander Roshal] Group Policies {GPedit.msc branch and setting}: ----------------------------------------------- Note: detected settings may not have any effect. HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\ NoChangingWallpaper = (REG_DWORD) dword:0x00000000 {User Configuration|Administrative Templates|Control Panel|Display| Disable changing wallpaper} HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\ NoLowDiskSpaceChecks = (REG_DWORD) dword:0x00000001 {unrecognized setting} NoResolveTrack = (REG_DWORD) dword:0x00000001 {unrecognized setting} NoResolveSearch = (REG_DWORD) dword:0x00000001 {unrecognized setting} LinkResolveIgnoreLinkInfo = (REG_DWORD) dword:0x00000001 {unrecognized setting} NoInternetOpenWith = (REG_DWORD) dword:0x00000001 {unrecognized setting} HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\ ConsentPromptBehaviorAdmin = (REG_DWORD) dword:0x00000000 {Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options| User Account Control: Behavior Of The Elevation Prompt For Administrators In Admin Approval Mode} ConsentPromptBehaviorUser = (REG_DWORD) dword:0x00000000 {Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options| User Account Control: Behavior Of The Elevation Prompt For Standard Users} EnableLUA = (REG_DWORD) dword:0x00000000 {Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options| User Account Control: Run All Administrators In Admin Approval Mode} Active Desktop and Wallpaper: ----------------------------- Active Desktop may be disabled at this entry: HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState Displayed if Active Desktop disabled and wallpaper not set by Group Policy: HKCU\Control Panel\Desktop\ Wallpaper = C:\Users\Gebruiker\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg Enabled Screen Saver: --------------------- HKCU\Control Panel\Desktop\ SCRNSAVE.EXE = C:\Windows\system32\ssText3d.scr [MS] Windows Portable Device AutoPlay Handlers ----------------------------------------- HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\ BSPlayCDAudioOnArrival\ Provider = BearShare InvokeProgID = BearShare.AudioCD InvokeVerb = play HKLM\SOFTWARE\Classes\BearShare.AudioCD\shell\play\Command\(Default) = "C:\Program Files\BearShare Applications\BearShare\BearShare.exe" --playdrive %L [file not found] BSRipCDAudioOnArrival\ Provider = BearShare InvokeProgID = BearShare.AudioCD InvokeVerb = rip HKLM\SOFTWARE\Classes\BearShare.AudioCD\shell\rip\Command\(Default) = "C:\Program Files\BearShare Applications\BearShare\BearShare.exe" --ripdrive %L [file not found] BSShowCDAudioOnArrival\ Provider = BearShare InvokeProgID = BearShare.AudioCD InvokeVerb = show HKLM\SOFTWARE\Classes\BearShare.AudioCD\shell\show\Command\(Default) = "C:\Program Files\BearShare Applications\BearShare\BearShare.exe" --showdrive %L [file not found] BSShowVolumeOnArrival\ Provider = BearShare InvokeProgID = BearShare.Device InvokeVerb = show HKLM\SOFTWARE\Classes\BearShare.Device\shell\show\Command\(Default) = "C:\Program Files\BearShare Applications\BearShare\BearShare.exe" --showportable = 1 %L [file not found] iTunesBurnCDOnArrival\ Provider = iTunes InvokeProgID = iTunes.BurnCD InvokeVerb = burn HKLM\SOFTWARE\Classes\iTunes.BurnCD\shell\burn\command\(Default) = "C:\Program Files\iTunes\iTunes.exe" /AutoPlayBurn "%L" [Apple Inc.] iTunesImportSongsOnArrival\ Provider = iTunes InvokeProgID = iTunes.ImportSongsOnCD InvokeVerb = import HKLM\SOFTWARE\Classes\iTunes.ImportSongsOnCD\shell\import\command\(Default) = "C:\Program Files\iTunes\iTunes.exe" /AutoPlayImportSongs "%L" [Apple Inc.] iTunesPlaySongsOnArrival\ Provider = iTunes InvokeProgID = iTunes.PlaySongsOnCD InvokeVerb = play HKLM\SOFTWARE\Classes\iTunes.PlaySongsOnCD\shell\play\command\(Default) = "C:\Program Files\iTunes\iTunes.exe" /playCD "%L" [Apple Inc.] iTunesShowSongsOnArrival\ Provider = iTunes InvokeProgID = iTunes.ShowSongsOnCD InvokeVerb = showsongs HKLM\SOFTWARE\Classes\iTunes.ShowSongsOnCD\shell\showsongs\command\(Default) = "C:\Program Files\iTunes\iTunes.exe" /AutoPlayShowSongs "%L" [Apple Inc.] MPCPlayCDAudioOnArrival\ Provider = Media Player Classic InvokeProgID = MediaPlayerClassic.Autorun InvokeVerb = PlayCDAudio HKLM\SOFTWARE\Classes\MediaPlayerClassic.Autorun\shell\PlayCDAudio\command\(Default) = "C:\Program Files\K-Lite Codec Pack\Media Player Classic\mplayerc.exe" %1 /cd [Gabest] MPCPlayDVDMovieOnArrival\ Provider = Media Player Classic InvokeProgID = MediaPlayerClassic.Autorun InvokeVerb = PlayDVDMovie HKLM\SOFTWARE\Classes\MediaPlayerClassic.Autorun\shell\PlayDVDMovie\command\(Default) = "C:\Program Files\K-Lite Codec Pack\Media Player Classic\mplayerc.exe" %1 /dvd [Gabest] MPCPlayMusicFilesOnArrival\ Provider = Media Player Classic InvokeProgID = MediaPlayerClassic.Autorun InvokeVerb = PlayMusicFiles HKLM\SOFTWARE\Classes\MediaPlayerClassic.Autorun\shell\PlayMusicFiles\command\(Default) = "C:\Program Files\K-Lite Codec Pack\Media Player Classic\mplayerc.exe" %1 [Gabest] MPCPlayVideoFilesOnArrival\ Provider = Media Player Classic InvokeProgID = MediaPlayerClassic.Autorun InvokeVerb = PlayVideoFiles HKLM\SOFTWARE\Classes\MediaPlayerClassic.Autorun\shell\PlayVideoFiles\command\(Default) = "C:\Program Files\K-Lite Codec Pack\Media Player Classic\mplayerc.exe" %1 [Gabest] MSLivePhotoAcqHWEventHandler\ Provider = @%ProgramFiles%\Windows Live\Photo Gallery\regres.dll,-10 ProgID = Microsoft.LivePhotoAcqHWEventHandler HKLM\SOFTWARE\Classes\Microsoft.LivePhotoAcqHWEventHandler\CLSID\(Default) = {3BD0ACD1-71CA-4475-92CC-E0AA0AAF843F} -> {HKLM...CLSID} = (no title provided) \LocalServer32\(Default) = C:\Program Files\Windows Live\Photo Gallery\WLXPhotoAcquireWizard.exe [MS] MSLivePhotoAcquireDropHandler\ Provider = @%ProgramFiles%\Windows Live\Photo Gallery\regres.dll,-10 InvokeProgID = Microsoft.LivePhotoAcqDTShim.1 InvokeVerb = open HKLM\SOFTWARE\Classes\Microsoft.LivePhotoAcqDTShim.1\shell\open\DropTarget\CLSID = {00F33137-EE26-412F-8D71-F84E4C2C6625} -> {HKLM...CLSID} = Windows Live Photo Gallery Viewer Autoplay Shim \InProcServer32\(Default) = C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll [MS] MSLiveShowPicturesOnArrival\ Provider = @%ProgramFiles%\Windows Live\Photo Gallery\regres.dll,-10 InvokeProgID = Microsoft.Photos.LiveAutoplayShim.1 InvokeVerb = open HKLM\SOFTWARE\Classes\Microsoft.Photos.LiveAutoplayShim.1\shell\open\DropTarget\CLSID = {00F30F90-3E96-453B-AFCD-D71989ECC2C7} -> {HKLM...CLSID} = Windows Live Photo Gallery Viewer Autoplay Shim \InProcServer32\(Default) = C:\Program Files\Windows Live\Photo Gallery\PhotoViewerShim.dll [MS] MSLiveVideoCameraArrivalCaptureWizard\ Provider = @%ProgramFiles%\Windows Live\Photo Gallery\regres.dll,-10 ProgID = WLXAutoPlayMgr.WLXHWEventHandler InitCmdLine = WLXVideoAcquireWizard HKLM\SOFTWARE\Classes\WLXAutoPlayMgr.WLXHWEventHandler\CLSID\(Default) = {9B5C97F6-B3A5-4A6D-8B03-993EC7291A22} -> {HKLM...CLSID} = WLXWEventHandler Class \LocalServer32\(Default) = "C:\Program Files\Windows Live\Photo Gallery\WLXVideoCameraAutoPlayManager.exe" [MS] NeroAutoPlay7AudioToNeroDigital\ Provider = Nero Burning ROM InvokeProgID = Nero.AutoPlay7 InvokeVerb = AudioToNeroDigital_PlayCDAudioOnArrival HKLM\SOFTWARE\Classes\Nero.AutoPlay7\shell\AudioToNeroDigital_PlayCDAudioOnArrival\command\(Default) = C:\Program Files\Nero\Nero 7\Core\nero.exe /Dialog:SaveTracks %L [Nero AG] NeroAutoPlay7CDAudio\ Provider = Nero Express InvokeProgID = Nero.AutoPlay7 InvokeVerb = CDAudio_HandleCDBurningOnArrival HKLM\SOFTWARE\Classes\Nero.AutoPlay7\shell\CDAudio_HandleCDBurningOnArrival\command\(Default) = C:\Program Files\Nero\Nero 7\Core\nero.exe -w /New:AudioCD [Nero AG] NeroAutoPlay7CopyCD\ Provider = Nero Burning ROM InvokeProgID = Nero.AutoPlay7 InvokeVerb = CopyCD_PlayMusicFilesOnArrival HKLM\SOFTWARE\Classes\Nero.AutoPlay7\shell\CopyCD_PlayMusicFilesOnArrival\command\(Default) = C:\Program Files\Nero\Nero 7\Core\nero.exe /Dialog:DiscCopy %L [Nero AG] NeroAutoPlay7DataDisc\ Provider = Nero Express InvokeProgID = Nero.AutoPlay7 InvokeVerb = DataDisc_HandleCDBurningOnArrival HKLM\SOFTWARE\Classes\Nero.AutoPlay7\shell\DataDisc_HandleCDBurningOnArrival\command\(Default) = C:\Program Files\Nero\Nero 7\Core\nero.exe -w /New:ISODisc [Nero AG] NeroAutoPlay7LaunchNeroStartSmart\ Provider = Nero StartSmart InvokeProgID = Nero.AutoPlay7 InvokeVerb = LaunchNeroStartSmart_HandleCDBurningOnArrival HKLM\SOFTWARE\Classes\Nero.AutoPlay7\shell\LaunchNeroStartSmart_HandleCDBurningOnArrival\command\(Default) = C:\Program Files\Nero\Nero 7\Nero StartSmart\NeroStartSmart.exe /AutoPlay [Nero AG] NeroAutoPlay7PlayAudioCD\ Provider = Nero ShowTime InvokeProgID = Nero.AutoPlay7 InvokeVerb = PlayAudioCD_PlayMusicFilesOnArrival HKLM\SOFTWARE\Classes\Nero.AutoPlay7\shell\PlayAudioCD_PlayMusicFilesOnArrival\command\(Default) = C:\Program Files\Nero\Nero 7\Nero ShowTime\ShowTime.exe /Play %L [Nero AG] NeroAutoPlay7PlayDVD\ Provider = Nero ShowTime InvokeProgID = Nero.AutoPlay7 InvokeVerb = PlayDVD_PlayVideoFilesOnArrival HKLM\SOFTWARE\Classes\Nero.AutoPlay7\shell\PlayDVD_PlayVideoFilesOnArrival\command\(Default) = C:\Program Files\Nero\Nero 7\Nero ShowTime\ShowTime.exe /Play %L [Nero AG] NeroAutoPlay7RipCD\ Provider = Nero Burning ROM InvokeProgID = Nero.AutoPlay7 InvokeVerb = RipCD_PlayCDAudioOnArrival HKLM\SOFTWARE\Classes\Nero.AutoPlay7\shell\RipCD_PlayCDAudioOnArrival\command\(Default) = C:\Program Files\Nero\Nero 7\Core\nero.exe /Dialog:SaveTracks %L [Nero AG] NeroAutoPlay7TranscodeVideo\ Provider = Nero Recode InvokeProgID = Nero.AutoPlay7 InvokeVerb = TranscodeVideo_PlayDVDMovieOnArrival HKLM\SOFTWARE\Classes\Nero.AutoPlay7\shell\TranscodeVideo_PlayDVDMovieOnArrival\command\(Default) = C:\Program Files\Nero\Nero 7\Nero Recode\Recode.exe /New:CopyDVDVideo [Nero AG] NeroAutoPlay7VideoCapture\ Provider = Nero Vision ProgID = Shell.HWEventHandlerShellExecute InitCmdLine = "C:\Program Files\Nero\Nero 7\Nero Vision\NeroVision.exe" /New:VideoCapture HKLM\SOFTWARE\Classes\Shell.HWEventHandlerShellExecute\CLSID\(Default) = {FFB8655F-81B9-4fce-B89C-9A6BA76D13E7} -> {HKLM...CLSID} = Shell Execute Hardware Event Handler \LocalServer32\(Default) = C:\Windows\System32\rundll32.exe shell32.dll,SHCreateLocalServerRunDll {FFB8655F-81B9-4fce-B89C-9A6BA76D13E7} [MS] NeroAutoPlay7ViewPhotos\ Provider = Nero PhotoSnap Viewer InvokeProgID = Nero.AutoPlay7 InvokeVerb = ViewPhotos_ShowPicturesOnArrival HKLM\SOFTWARE\Classes\Nero.AutoPlay7\shell\ViewPhotos_ShowPicturesOnArrival\command\(Default) = C:\Program Files\Nero\Nero 7\Nero PhotoSnap\PhotoSnapViewer.exe / [Nero AG] WIA_{6F03BE90-D9D2-446C-ACD0-ECA58ED4F2E4}\ Provider = Microsoft Publisher CLSID = {A55803CC-4D53-404c-8557-FD63DBA95D24} InitCmdLine = /WiaCmd;C:\Program Files\Microsoft Office\Office14\MSPUB.EXE /IMG_WIA; -> {HKLM...CLSID} = WPDShextAutoplay \LocalServer32\(Default) = C:\Windows\system32\WPDShextAutoplay.exe [MS] WIA_{965FF5C6-1194-486F-A8F7-D71E42AF093C}\ Provider = Microsoft Word CLSID = {A55803CC-4D53-404c-8557-FD63DBA95D24} InitCmdLine = /WiaCmd;C:\Program Files\Microsoft Office\Office14\WINWORD.EXE /IMG_WIA; -> {HKLM...CLSID} = WPDShextAutoplay \LocalServer32\(Default) = C:\Windows\system32\WPDShextAutoplay.exe [MS] WIA_{974B4DC5-7ADF-46A1-9769-B2A315C59518}\ Provider = Microsoft Publisher CLSID = {A55803CC-4D53-404c-8557-FD63DBA95D24} InitCmdLine = /WiaCmd;C:\Program Files\Microsoft Office\Office14\MSPUB.EXE /IMG_STI /StiDevice:%1 /StiEvent:%2; -> {HKLM...CLSID} = WPDShextAutoplay \LocalServer32\(Default) = C:\Windows\system32\WPDShextAutoplay.exe [MS] WIA_{9818AB54-9C11-4467-882C-8B275416F808}\ Provider = Microsoft Office Word CLSID = {A55803CC-4D53-404c-8557-FD63DBA95D24} InitCmdLine = /WiaCmd;C:\Program Files\Microsoft Office\Office12\WINWORD.EXE /IMG_WIA; -> {HKLM...CLSID} = WPDShextAutoplay \LocalServer32\(Default) = C:\Windows\system32\WPDShextAutoplay.exe [MS] WIA_{E33F3488-4463-413A-B119-CAA55B9B5880}\ Provider = ABBYY FineReader CLSID = {A55803CC-4D53-404c-8557-FD63DBA95D24} InitCmdLine = /WiaCmd;C:\Program Files\Common Files\ABBYY\FineReaderSprint\9.00\Integration\AbbyySti.exe /clsid {F1AD37FD-95FA-4A5D-81D6-7F6D88B53109} /StiDevice:%1 /StiEvent:%2; -> {HKLM...CLSID} = WPDShextAutoplay \LocalServer32\(Default) = C:\Windows\system32\WPDShextAutoplay.exe [MS] Non-disabled Scheduled Tasks: {++} ----------------------------- C:\Windows\System32\Tasks 0 -> launches: c:\program files\internet explorer\iexplore.exe [MS] 4802 -> launches: wscript.exe C:\Users\GEBRUI~1\AppData\Local\Temp\launchie.vbs //B [MS] Adobe Flash Player Updater -> launches: C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [Adobe Systems Incorporated] Apple Diagnostics -> launches: C:\Program Files\Common Files\Apple\Internet Services\EReporter.exe [Apple Inc.] CreateChoiceProcessTask -> launches: C:\Windows\System32\browserchoice.exe /launch [MS] GoogleUpdateTaskMachineCore -> launches: C:\Program Files\Google\Update\GoogleUpdate.exe /c [Google Inc.] GoogleUpdateTaskMachineUA -> launches: C:\Program Files\Google\Update\GoogleUpdate.exe /ua /installsource scheduler [Google Inc.] NUSchedule -> launches: C:\Program Files\Norton Utilities 15\nu.exe /F [Symantec Corporation] SidebarExecute -> launches: C:\Program Files\Windows Sidebar\sidebar.exe /addGadget [MS] {03A1912B-94E2-4CC0-8566-1F7210D37166} -> launches: C:\Users\Gebruiker\Desktop\Iron Sea Defenders\IronSea.exe [file not found] {231B5015-E3E5-4BCD-93C2-86911496CA6F} -> launches: C:\Users\Gebruiker\Desktop\RGC.rar.exe [file not found] {282F05F3-57E4-4914-ABB6-A51AB95E9A66} -> launches: C:\Windows\system32\pcalua.exe -a "D:\Mijn documenten\games\vcredist_x86.exe" -d "D:\Mijn documenten\games" [MS] {2A1154F5-93E3-46BA-A463-21D6BB3F6B55} -> launches: C:\Users\Gebruiker\Desktop\Iron Sea Defenders\IronSea.exe [file not found] {2FDDFDD1-B916-476B-8229-01185A0B678E} -> launches: C:\Windows\system32\pcalua.exe -a "D:\Mijn documenten\games\GraveTestimonyNLSetup.exe" -d "D:\Mijn documenten\games" [MS] {3465D962-C786-419C-830C-AE5094EA8E01} -> launches: C:\Users\Gebruiker\Desktop\Iron Sea Defenders\IronSea.exe [file not found] {36B42AC9-4B01-4E0E-9E00-7D1AC9C5C6D9} -> launches: C:\Users\Gebruiker\Desktop\Delicious - Emily's Honeymoon Cruise Deluxe\Delicious9.exe [file not found] {38103395-3084-42A1-9DF0-6BBF6656E577} -> launches: C:\Windows\system32\pcalua.exe -a "D:\Mijn documenten\games\VampireLegendsTheTrueStoryofKisolovaNLSetup.exe" -d C:\Users\Gebruiker\Desktop [MS] {3F9B69F2-9CF5-46FC-9148-77D838B0CBA0} -> launches: C:\Windows\system32\pcalua.exe -a "C:\Users\Gebruiker\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DTLX4TI5\vcredist_x64.exe" -d C:\Users\Gebruiker\Desktop [MS] {419A52C1-8598-47A6-9F45-5856440F429C} -> launches: C:\Windows\system32\pcalua.exe -a E:\MediaHome_4_Essentials_Windows\SetupX.exe -d E:\MediaHome_4_Essentials_Windows [MS] {4FBC8EB3-6C9C-42F6-B6B0-3E165624226C} -> launches: C:\Windows\system32\pcalua.exe -a "D:\Mijn documenten\games\darkdimensionswaxbeautynlsetup.exe" -d "D:\Mijn documenten\games" [MS] {63BF80E2-E97F-4432-8EF6-E7BB6DFA97FB} -> launches: C:\Users\Gebruiker\Desktop\Royal Defense - Invisible Threat\rd-it.exe [file not found] {79311994-1394-40E4-BA97-C826C79A60E8} -> launches: C:\Program Files\Skype\\Phone\Skype.exe [Skype Technologies S.A.] {88653ED6-2029-4576-9E8F-2A43A0A8BA35} -> launches: C:\Users\Gebruiker\Desktop\Royal Defense - Invisible Threat\rd-it.exe [file not found] {8C298EB5-040C-45AF-B3A8-EC0C5EBF1FB9} -> launches: C:\Users\Gebruiker\Desktop\Iron Sea Defenders\IronSea.exe [file not found] {8D71B7B3-8022-4BF1-B13C-F7EB5C690616} -> launches: C:\Windows\system32\pcalua.exe -a "C:\Users\Gebruiker\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UUCCA3J6\GraveTestimonyNLSetup.exe" -d C:\Users\Gebruiker\Desktop [MS] {9662BCA9-2616-4FF0-ADA3-46012AABA07C} -> launches: C:\Users\Gebruiker\Desktop\Iron Sea Defenders\IronSea.exe [file not found] {9E2C824D-0BDE-46A3-89D0-EAA0628B7747} -> launches: C:\Users\Gebruiker\Desktop\Royal Defense - Invisible Threat\rd-it.exe [file not found] {A1F21839-6FEB-460F-A19A-0D2D3DDF5BD3} -> launches: C:\Windows\system32\pcalua.exe -a "C:\Users\Gebruiker\Desktop\Dream Chronicles - The Book of Air Collector's Edition.exe" -d C:\Users\Gebruiker\Desktop [MS] {A6AED555-BFD6-4B4E-87C7-EFC6241A7F21} -> launches: C:\Users\Gebruiker\Desktop\Royal Defense - Invisible Threat\rd-it.exe [file not found] {B3DB091B-2FBB-4DD5-901D-0CA7CCDBFBD1} -> launches: C:\Windows\system32\pcalua.exe -a "C:\Users\Gebruiker\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HK82ZIYR\setup[1].exe" -d C:\Users\Gebruiker\Desktop [MS] {B425817C-AB73-492F-9233-A203BAE276FE} -> launches: C:\Users\Gebruiker\Desktop\Royal Defense - Invisible Threat\rd-it.exe [file not found] {B95D45B4-38DC-4144-A54B-965099A71B24} -> launches: C:\Windows\system32\pcalua.exe -a "D:\Mijn documenten\games\NaturalThreatOminousShoresNLSetup.exe" -d C:\Users\Gebruiker\Desktop [MS] {BEE8F776-FAFC-4776-80F8-77BEB1F93962} -> launches: C:\Windows\system32\pcalua.exe -a "C:\Users\Gebruiker\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7HYQEPFA\flashplayer_9_ax_debug.exe" -d C:\Users\Gebruiker\Desktop [MS] {C8758F69-A610-4349-8012-5145AE6A5FB3} -> launches: C:\Windows\system32\pcalua.exe -a "D:\Mijn documenten\games\HauntedHotel4NLSetup.exe" -d C:\Users\Gebruiker\Desktop [MS] {CE740792-2204-4ABA-B2B6-D733E99E6E7C} -> launches: C:\Windows\system32\pcalua.exe -a "D:\Mijn documenten\NV4content.exe" -d "D:\Mijn documenten" [MS] {D0B3EFF1-E19C-4F9E-8B83-9DBC62428ABF} -> launches: C:\Windows\system32\pcalua.exe -a "F:\D schijf Desktop thuis\Programma's 2007\Belkin\Belkin Wireless Network Utility\Setup.exe" -d "F:\D schijf Desktop thuis\Programma's 2007\Belkin\Belkin Wireless Network Utility" [MS] {D34FC027-EB65-4765-9610-95813EBC76F2} -> launches: C:\Program Files\Skype\\Phone\Skype.exe [Skype Technologies S.A.] {E19EFC41-1D79-4F29-91D4-05947E204B50} -> launches: C:\Users\Gebruiker\Desktop\Royal Defense - Invisible Threat\rd-it.exe [file not found] {EE785BE0-1CD7-4ED0-B6E6-DAE894905F17} -> launches: C:\Users\Gebruiker\Desktop\MagicEncyclopedia-Illusions\Magic.exe [file not found] {EF773418-DE0D-4886-9BB5-58C767D6D934} -> launches: C:\Windows\system32\pcalua.exe -a "D:\Mijn documenten\games\mysticdiary3missingpagesnlsetup.exe" -d "D:\Mijn documenten\games" [MS] C:\Windows\System32\Tasks\Apple AppleSoftwareUpdate -> launches: C:\Program Files\Apple Software Update\SoftwareUpdate.exe -task [Apple Inc.] C:\Windows\System32\Tasks\Microsoft\Windows\Active Directory Rights Management Services Client AD RMS Rights Policy Template Management (Manual) -> launches: {BF5CB148-7C77-4d8a-A53E-D81C70CF743C} -> {HKLM...CLSID} = AD RMS Rights Policy Template Management (Manual) Task Handler \InProcServer32\(Default) = C:\Windows\system32\msdrm.dll [MS] C:\Windows\System32\Tasks\Microsoft\Windows\Application Experience AitAgent -> launches: aitagent [MS] Microsoft Compatibility Appraiser -> launches: %windir%\system32\rundll32.exe aepdu.dll,AePduRunUpdate -nolegacy [MS] ProgramDataUpdater -> launches: %windir%\system32\rundll32.exe aepdu.dll,AePduRunUpdate [MS] C:\Windows\System32\Tasks\Microsoft\Windows\Autochk Proxy -> launches: %windir%\system32\rundll32.exe /d acproxy.dll,PerformAutochkOperations [MS] C:\Windows\System32\Tasks\Microsoft\Windows\Bluetooth UninstallDeviceTask -> launches: BthUdTask.exe $(Arg0) [MS] C:\Windows\System32\Tasks\Microsoft\Windows\CertificateServicesClient SystemTask -> launches: {58fb76b9-ac85-4e55-ac04-427593b1d060} -> {HKLM...CLSID} = Certificate Services Client Task Handler \InProcServer32\(Default) = C:\Windows\system32\dimsjob.dll [MS] UserTask -> launches: {58fb76b9-ac85-4e55-ac04-427593b1d060} -> {HKLM...CLSID} = Certificate Services Client Task Handler \InProcServer32\(Default) = C:\Windows\system32\dimsjob.dll [MS] C:\Windows\System32\Tasks\Microsoft\Windows\Customer Experience Improvement Program Consolidator -> launches: %SystemRoot%\System32\wsqmcons.exe [MS] KernelCeipTask -> (HIDDEN!) launches: {e7ed314f-2816-4c26-aeb5-54a34d02404c} -> {HKLM...CLSID} = KernelCeipCustomHandler \InProcServer32\(Default) = C:\Windows\System32\kernelceip.dll [MS] UsbCeip -> (HIDDEN!) launches: {c27f6b1d-fe0b-45e4-9257-38799fa69bc8} -> {HKLM...CLSID} = UsbCeip \InProcServer32\(Default) = C:\Windows\System32\usbceip.dll [MS] C:\Windows\System32\Tasks\Microsoft\Windows\Diagnosis Scheduled -> (HIDDEN!) launches: {c1f85ef8-bcc2-4606-bb39-70c523715eb3} -> {HKLM...CLSID} = ScheduledDiagnosticCustomHandler \InProcServer32\(Default) = C:\Windows\System32\sdiagschd.dll [MS] C:\Windows\System32\Tasks\Microsoft\Windows\Location Notifications -> launches: %windir%\System32\LocationNotifications.exe [MS] C:\Windows\System32\Tasks\Microsoft\Windows\Maintenance WinSAT -> launches: {A9A33436-678B-4C9C-A211-7CC38785E79D} -> {HKLM...CLSID} = WinSAT Task Manger Task \InProcServer32\(Default) = C:\Windows\system32\WinSATAPI.dll [MS] C:\Windows\System32\Tasks\Microsoft\Windows\Media Center ActivateWindowsSearch -> launches: %SystemRoot%\ehome\ehPrivJob.exe /DoActivateWindowsSearch [MS] ConfigureInternetTimeService -> launches: %SystemRoot%\ehome\ehPrivJob.exe /DoConfigureInternetTimeService [MS] DispatchRecoveryTasks -> launches: %SystemRoot%\ehome\ehPrivJob.exe /DoRecoveryTasks $(Arg0) [MS] ehDRMInit -> launches: %SystemRoot%\ehome\ehPrivJob.exe /DRMInit [MS] InstallPlayReady -> launches: %SystemRoot%\ehome\ehPrivJob.exe /InstallPlayReady $(Arg0) [MS] mcupdate -> launches: %SystemRoot%\ehome\mcupdate $(Arg0) [MS] MediaCenterRecoveryTask -> launches: %SystemRoot%\ehome\mcupdate.exe -MediaCenterRecoveryTask [MS] ObjectStoreRecoveryTask -> launches: %SystemRoot%\ehome\mcupdate.exe -ObjectStoreRecoveryTask [MS] OCURActivate -> launches: %SystemRoot%\ehome\ehPrivJob.exe /OCURActivate [MS] OCURDiscovery -> launches: %SystemRoot%\ehome\ehPrivJob.exe /OCURDiscovery $(Arg0) [MS] PBDADiscovery -> launches: %SystemRoot%\ehome\ehPrivJob.exe /PBDADiscovery [MS] PBDADiscoveryW1 -> launches: %SystemRoot%\ehome\ehPrivJob.exe /wait:7 /PBDADiscovery [MS] PBDADiscoveryW2 -> launches: %SystemRoot%\ehome\ehPrivJob.exe /wait:90 /PBDADiscovery [MS] PvrRecoveryTask -> launches: %SystemRoot%\ehome\mcupdate.exe -PvrRecoveryTask [MS] PvrScheduleTask -> launches: %SystemRoot%\ehome\mcupdate.exe -PvrSchedule [MS] RegisterSearch -> launches: %SystemRoot%\ehome\ehPrivJob.exe /DoRegisterSearch $(Arg0) [MS] ReindexSearchRoot -> launches: %SystemRoot%\ehome\ehPrivJob.exe /DoReindexSearchRoot [MS] SqlLiteRecoveryTask -> launches: %SystemRoot%\ehome\mcupdate.exe -SqlLiteRecoveryTask [MS] StartRecording -> launches: %SystemRoot%\ehome\ehrec /StartRecording [MS] UpdateRecordPath -> launches: %SystemRoot%\ehome\ehPrivJob.exe /DoUpdateRecordPath $(Arg0) [MS] C:\Windows\System32\Tasks\Microsoft\Windows\MemoryDiagnostic CorruptionDetector -> (HIDDEN!) launches: {190BA3F6-0205-4f46-B589-95C6822899D2} -> {HKLM...CLSID} = MemoryDiagnosticCustomHandler \InProcServer32\(Default) = C:\Windows\System32\memdiag.dll [MS] DecompressionFailureDetector -> (HIDDEN!) launches: {190BA3F6-0205-4f46-B589-95C6822899D2} -> {HKLM...CLSID} = MemoryDiagnosticCustomHandler \InProcServer32\(Default) = C:\Windows\System32\memdiag.dll [MS] C:\Windows\System32\Tasks\Microsoft\Windows\MobilePC HotStart -> launches: {06DA0625-9701-43da-BFD7-FBEEA2180A1E} -> {HKLM...CLSID} = HotStart User Agent \InProcServer32\(Default) = C:\Windows\System32\HotStartUserAgent.dll [MS] C:\Windows\System32\Tasks\Microsoft\Windows\MUI LPRemove -> launches: %windir%\system32\lpremove.exe [MS] C:\Windows\System32\Tasks\Microsoft\Windows\Multimedia SystemSoundsService -> launches: {2DEA658F-54C1-4227-AF9B-260AB5FC3543} -> {HKLM...CLSID} = Microsoft PlaySoundService Class \InProcServer32\(Default) = C:\Windows\System32\PlaySndSrv.dll [MS] C:\Windows\System32\Tasks\Microsoft\Windows\NetTrace GatherNetworkInfo -> launches: %windir%\system32\gatherNetworkInfo.vbs [null data] C:\Windows\System32\Tasks\Microsoft\Windows\Power Efficiency Diagnostics AnalyzeSystem -> launches: %SystemRoot%\System32\powercfg.exe -energy -auto [MS] C:\Windows\System32\Tasks\Microsoft\Windows\RAC RacTask -> (HIDDEN!) launches: {42060D27-CA53-41f5-96E4-B1E8169308A6} -> {HKLM...CLSID} = ReliabilityAnalysisCustomHandler \InProcServer32\(Default) = C:\Windows\system32\RacEngn.dll [MS] C:\Windows\System32\Tasks\Microsoft\Windows\Ras MobilityManager -> launches: {c463a0fc-794f-4fdf-9201-01938ceacafa} -> {HKLM...CLSID} = RasMobilityManager \InProcServer32\(Default) = C:\Windows\system32\rasmbmgr.dll [MS] C:\Windows\System32\Tasks\Microsoft\Windows\Registry RegIdleBackup -> (HIDDEN!) launches: {ca767aa8-9157-4604-b64b-40747123d5f2} -> {HKLM...CLSID} = RegistryIdleBackupHandler \InProcServer32\(Default) = C:\Windows\System32\regidle.dll [MS] C:\Windows\System32\Tasks\Microsoft\Windows\RemoteAssistance RemoteAssistanceTask -> (HIDDEN!) launches: %windir%\system32\RAServer.exe /offerraupdate [MS] C:\Windows\System32\Tasks\Microsoft\Windows\SideShow GadgetManager -> launches: {FF87090D-4A9A-4f47-879B-29A80C355D61} -> {HKLM...CLSID} = GadgetsManager Class \InProcServer32\(Default) = C:\Windows\System32\AuxiliaryDisplayServices.dll [MS] C:\Windows\System32\Tasks\Microsoft\Windows\SystemRestore SR -> launches: %windir%\system32\rundll32.exe /d srrstr.dll,ExecuteScheduledSPPCreation [MS] C:\Windows\System32\Tasks\Microsoft\Windows\Task Manager Interactive -> (HIDDEN!) launches: {855fec53-d2e4-4999-9e87-3414e9cf0ff4} -> {HKLM...CLSID} = RunTask \InProcServer32\(Default) = C:\Windows\system32\wdc.dll [MS] C:\Windows\System32\Tasks\Microsoft\Windows\Tcpip IpAddressConflict1 -> launches: %windir%\system32\rundll32.exe ndfapi.dll,NdfRunDllDuplicateIPOffendingSystem [MS] IpAddressConflict2 -> launches: %windir%\system32\rundll32.exe ndfapi.dll,NdfRunDllDuplicateIPDefendingSystem [MS] C:\Windows\System32\Tasks\Microsoft\Windows\TextServicesFramework MsCtfMonitor -> (HIDDEN!) launches: {01575cfe-9a55-4003-a5e1-f38d1ebdcbe1} -> {HKLM...CLSID} = MsCtfMonitor task handler \InProcServer32\(Default) = C:\Windows\system32\MsCtfMonitor.dll [MS] C:\Windows\System32\Tasks\Microsoft\Windows\Time Synchronization SynchronizeTime -> launches: %windir%\system32\sc.exe start w32time task_started [MS] C:\Windows\System32\Tasks\Microsoft\Windows\UPnP UPnPHostConfig -> launches: sc.exe config upnphost start= auto [MS] C:\Windows\System32\Tasks\Microsoft\Windows\WDI ResolutionHost -> (HIDDEN!) launches: {900be39d-6be8-461a-bc4d-b0fa71f5ecb1} -> {HKLM...CLSID} = DiagnosticInfrastructureCustomHandler \InProcServer32\(Default) = C:\Windows\System32\wdi.dll [MS] C:\Windows\System32\Tasks\Microsoft\Windows\Windows Activation Technologies ValidationTask -> (HIDDEN!) launches: %SystemRoot%\system32\Wat\WatAdminSvc.exe /run [MS] ValidationTaskDeadline -> (HIDDEN!) launches: %SystemRoot%\system32\schtasks.exe /run /I /TN "\Microsoft\Windows\Windows Activation Technologies\ValidationTask" [MS] C:\Windows\System32\Tasks\Microsoft\Windows\Windows Error Reporting QueueReporting -> launches: %windir%\system32\wermgr.exe -queuereporting [MS] C:\Windows\System32\Tasks\Microsoft\Windows\Windows Filtering Platform BfeOnServiceStartTypeChange -> (HIDDEN!) launches: %windir%\system32\rundll32.exe bfe.dll,BfeOnServiceStartTypeChange [MS] C:\Windows\System32\Tasks\Microsoft\Windows\Windows Media Sharing UpdateLibrary -> launches: "%ProgramFiles%\Windows Media Player\wmpnscfg.exe" [MS] C:\Windows\System32\Tasks\Microsoft\Windows\WindowsBackup AutomaticBackup -> launches: %systemroot%\system32\rundll32.exe /d sdengin2.dll,ExecuteScheduledBackup [MS] Windows Backup Monitor -> launches: %systemroot%\system32\sdclt.exe /CHECKSKIPPED [MS] C:\Windows\System32\Tasks\Microsoft\Windows\Wininet CacheTask -> launches: {0358b920-0ac7-461f-98f4-58e32cd89148} -> {HKLM...CLSID} = Wininet Cache task object \InProcServer32\(Default) = C:\Windows\system32\wininet.dll [MS] C:\Windows\System32\Tasks\Microsoft\Windows Live\SOXE Extractor Definitions Update Task -> launches: {3519154C-227E-47F3-9CC9-12C3F05817F1} -> {HKLM...CLSID} = Windows Live Social Object Extractor Engine Definition Updater \InProcServer32\(Default) = C:\Program Files\Windows Live\SOXE\wlsoxe.dll [MS] C:\Windows\System32\Tasks\WPD SqmUpload_S-1-5-21-2495464155-2157068309-4147718583-1000 -> (HIDDEN!) launches: %windir%\system32\rundll32.exe portabledeviceapi.dll,#1 [MS] Winsock2 Service Provider DLLs: ------------------------------- Namespace Service Providers HKLM\SYSTEM\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++} 000000000001\LibraryPath = %SystemRoot%\system32\NLAapi.dll [MS] 000000000002\LibraryPath = %SystemRoot%\system32\napinsp.dll [MS] 000000000003\LibraryPath = %SystemRoot%\system32\pnrpnsp.dll [MS] 000000000004\LibraryPath = %SystemRoot%\system32\pnrpnsp.dll [MS] 000000000005\LibraryPath = %SystemRoot%\system32\wshbth.dll [MS] 000000000006\LibraryPath = %SystemRoot%\System32\mswsock.dll [MS] 000000000007\LibraryPath = %SystemRoot%\System32\winrnr.dll [MS] 000000000008\LibraryPath = C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [MS] 000000000009\LibraryPath = C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [MS] 000000000010\LibraryPath = C:\Program Files\Bonjour\mdnsNSP.dll [Apple Inc.] Transport Service Providers HKLM\SYSTEM\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++} 0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range: %SystemRoot%\system32\mswsock.dll [MS], 01 - 35 Toolbars, Explorer Bars, Extensions: ------------------------------------ Toolbars HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\ {A13C2648-91D4-4BF3-BC6D-0079707C4389} -> {HKLM...CLSID} = Norton Identity Safe Toolbar \InProcServer32\(Default) = C:\Program Files\Norton Identity Safe\Engine\2014.7.8.23\coIEPlg.dll [Symantec Corporation] HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\ {A13C2648-91D4-4BF3-BC6D-0079707C4389} = Norton Identity Safe Toolbar -> {HKLM...CLSID} = Norton Identity Safe Toolbar \InProcServer32\(Default) = C:\Program Files\Norton Identity Safe\Engine\2014.7.8.23\coIEPlg.dll [Symantec Corporation] Explorer Bars HKLM\SOFTWARE\Classes\CLSID\{FF059E31-CC5A-4E2E-BF3B-96E929D65503}\(Default) = &Onderzoeken Implemented Categories\{00021493-0000-0000-C000-000000000046}\ [vertical bar] InProcServer32\(Default) = C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL [MS] Extensions (Tools menu items, main toolbar menu buttons) HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\ {0000036B-C524-4050-81A0-243669A86B9F}\ ButtonText = @C:\Program Files\Windows Live\Companion\companionlang.dll,-600 CLSIDExtension = {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} -> {HKLM...CLSID} = Windows Live Messenger Companion Command Bar Button \InProcServer32\(Default) = C:\Program Files\Windows Live\Companion\companioncore.dll [MS] {219C3416-8CB2-491A-A3C7-D9FCDDC9D600}\ ButtonText = @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 MenuText = @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 CLSIDExtension = {5F7B1267-94A9-47F5-98DB-E99415F33AEC} -> {HKLM...CLSID} = BlogThisToolbarButton Class \InProcServer32\(Default) = C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll [MS] {2670000A-7350-4F3C-8081-5663EE0C6C49}\ ButtonText = Verzenden naar OneNote MenuText = &Verzenden naar OneNote CLSIDExtension = {48E73304-E1D6-4330-914C-F5F514E3486C} -> {HKLM...CLSID} = Send to OneNote from Internet Explorer button \InProcServer32\(Default) = C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll [MS] {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA}\ ButtonText = &Gekoppelde notities van OneNote MenuText = &Gekoppelde notities van OneNote CLSIDExtension = {FFFDC614-B694-4AE6-AB38-5D6374584B52} -> {HKLM...CLSID} = Linked Notes button \InProcServer32\(Default) = C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll [MS] {898EA8C8-E7FF-479B-8935-AEC46303B9E5}\ ButtonText = Skype Click to Call settings CLSIDExtension = {898EA8C8-E7FF-479B-8935-AEC46303B9E5} -> {HKLM...CLSID} = Skype Click to Call settings \InProcServer32\(Default) = C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [MS] {92780B25-18CC-41C8-B9BE-3C9C571A8263}\ ButtonText = Research BandCLSID = {FF059E31-CC5A-4E2E-BF3B-96E929D65503} -> {HKLM...CLSID} = &Onderzoeken \InProcServer32\(Default) = C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL [MS] Running Services (Display Name, Service Name, Path {Service DLL}): ------------------------------------------------------------------ ABBYY FineReader 9.0 Sprint Licensing Service, ABBYY.Licensing.FineReader.Sprint.9.0, "C:\Program Files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe" -service [ABBYY] Adobe Acrobat Update Service, AdobeARMservice, "C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe" [Adobe Systems Incorporated] Apple Mobile Device, Apple Mobile Device, "C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe" [Apple Inc.] BlueSoleilCS, BlueSoleilCS, C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleilCS.exe [IVT Corporation] Bonjour-service, Bonjour Service, "C:\Program Files\Bonjour\mDNSResponder.exe" [Apple Inc.] BsHelpCS, BsHelpCS, C:\Program Files\IVT Corporation\BlueSoleil\BsHelpCS.exe [IVT Corporation] iPod-service, iPod Service, "C:\Program Files\iPod\bin\iPodService.exe" [Apple Inc.] Norton Disk Doctor Service, DiskDoctorService, C:\Program Files\Norton Utilities 15\Tools\Disk Doctor\DiskDoctorSrv.exe [Symantec Corporation] Norton Identity Safe, NCO, "C:\Program Files\Norton Identity Safe\Engine\2014.7.8.23\NST.exe" /s "NCO" /m "C:\Program Files\Norton Identity Safe\Engine\2014.7.8.23\diMaster.dll" /prefetch:1 [Symantec Corporation] Norton SpeedDisk Service, SpeedDiskService, C:\Program Files\Norton Utilities 15\Tools\SpeedDisk\SpeedDiskSrv.exe [Symantec Corporation] Skype Click to Call PNR Service, c2cpnrsvc, "C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe" /service [MS] Skype Click to Call Updater, c2cautoupdatesvc, "C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe" /service [MS] Windows Live ID Sign-in Assistant, wlidsvc, "C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE" [MS] Safe Mode Drivers & Services (subkey name, subkey default value): ----------------------------------------------------------------- HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal\ <> PEVSystemStart, Service HKLM\System\CurrentControlSet\Control\SafeBoot\Network\ <> SupportSoft RemoteAssist, Service <> PEVSystemStart, Service Print Monitors: --------------- HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors\ BlueSoleil Print Port\Driver = BsMonSvr [IVT Corporation] Canon BJ Language Monitor iP4200\Driver = CNMLM78.DLL [CANON INC.] EPSON SX430 Series 32MonitorBE\Driver = E_FLBHAE.DLL [SEIKO EPSON CORPORATION] ==== Empty IE Cache ====================== C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Gebruiker\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Gebruiker\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully ==== Empty FireFox Cache ====================== C:\Users\Gebruiker\AppData\Local\Mozilla\Firefox\Profiles\f7wz8tt8.default\Cache emptied successfully ==== Empty Chrome Cache ====================== C:\Users\Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully ==== Empty All Flash Cache ====================== Flash Cache Emptied Successfully ==== Empty All Java Cache ====================== Java Cache cleared successfully ==== C:\zoek_backup content ====================== C:\zoek_backup (files=763 folders=227 285350633 bytes) ==== Empty Temp Folders ====================== C:\Users\Default\AppData\Local\Temp emptied successfully C:\Users\Default User\AppData\Local\Temp emptied successfully C:\Users\Gebruiker\AppData\Local\Temp will be emptied at reboot C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp will be emptied at reboot C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully C:\Windows\Temp will be emptied at reboot ==== After Reboot ====================== ==== Empty Temp Folders ====================== C:\Windows\Temp successfully emptied C:\Users\GEBRUI~1\AppData\Local\Temp successfully emptied ==== Empty Recycle Bin ====================== C:\$RECYCLE.BIN successfully emptied ==== Deleting Files / Folders ====================== "C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp\Low" not found ==== EOF on wo 17/12/2014 at 14:19:29,40 ======================