Zoek.exe v5.0.0.0 Updated 24-12-2014 Tool run by Peter on wo 24/12/2014 at 14:51:26,62. Microsoft® Windows Vista™ Home Premium 6.0.6002 Service Pack 2 x64 Running in: Normal Mode Internet Access Detected Launched: C:\Users\Peter\Desktop\zoek.exe [Scan all users] [Script inserted] [Checkboxes used] ==== Running Processes ====================== C:\Windows\system32\csrss.exe C:\Windows\system32\wininit.exe C:\Windows\system32\csrss.exe C:\Windows\system32\services.exe C:\Windows\system32\lsass.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASCService.exe C:\Windows\system32\winlogon.exe C:\Windows\system32\nvvsvc.exe C:\Windows\system32\svchost.exe -k rpcss C:\Windows\System32\svchost.exe -k secsvcs C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k GPSvcGroup C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Program Files\AVAST Software\Avast\AvastSvc.exe C:\Program Files\AVAST Software\Avast\afwServ.exe C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe C:\Windows\system32\nvvsvc.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe C:\Windows\Explorer.EXE C:\Windows\system32\taskeng.exe C:\Program Files (x86)\IObit\Smart Defrag 3\SmartDefrag.exe C:\Windows\system32\taskeng.exe C:\Program Files (x86)\IObit\Advanced SystemCare 8\Monitor.exe C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe C:\Windows\SysWOW64\svchost.exe -k netsvcs C:\Program Files\Windows Defender\MSASCui.exe C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD64.exe C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe C:\Program Files\NVIDIA Corporation\Display\nvtray.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Windows\ehome\ehtray.exe C:\Program Files (x86)\IObit\Advanced SystemCare 7\Suo10_SmartRAM.exe C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASCTray.exe C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD64.exe C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe C:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe C:\Program Files\AVAST Software\Avast\avastui.exe C:\Program Files (x86)\VTech\DownloadManager\System\AgentMonitor.exe C:\Program Files (x86)\Brother\ControlCenter3\brccMCtl.exe C:\Program Files (x86)\IObit\IObit Malware Fighter\IMF.exe C:\Windows\ehome\ehmsas.exe C:\Windows\SysWOW64\conime.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe C:\Windows\system32\SearchIndexer.exe C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesApp64.exe C:\Program Files\CCleaner\CCleaner64.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Windows\system32\wbem\unsecapp.exe C:\Windows\system32\wbem\unsecapp.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe C:\Windows\splwow64.exe C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASC.exe C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE C:\Program Files\Windows Mail\WinMail.exe C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe C:\Program Files (x86)\Mozilla Firefox\firefox.exe C:\Users\Peter\Desktop\zoek.exe ==== System Restore Info ====================== 24/12/2014 14:54:34 Zoek.exe System Restore Point Created Succesfully. ==== Windows Installer Info ====================== Activation Assistant for the 2007 Microsoft Office suites [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9CE2AD5624609E74AA2E5B62A71AD457]C:\Windows\Installer\4b42b0b.msi ActiveCheck component for HP Active Support Library [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\AA73C45227B60034486F898A429181E7]C:\Windows\Installer\53cd3e9.msi Adobe AIR [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\74CEABB70CC18BC4DA4B35B187BD1DDD]c:\Windows\Installer\e5c6f.msi Adobe Reader X (10.1.13) - Nederlands [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\68AB67CA7DA73401B744AA0100000010]C:\Windows\Installer\e05caa.msi Ask Toolbar [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\D20594847365A600677A7A857BC07000]C:\Windows\Installer\6f5c1b2.msi AVG 2014 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\98DC12BC3D4A0424A9AA55CD7E3F0D67]C:\Windows\Installer\6602632.msi AVG PC TuneUp 2014 (nl-NL) [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\FDF1E5554FB93494FB577CED897FFCA8]C:\Windows\Installer\1156e6.msi AVG PC TuneUp 2014 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9CF4DB1068F260746AE277B47B9E3D80]C:\Windows\Installer\1156ea.msi Belgium e-ID middleware 4.0.7 (build 7453) [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\ED365428DA576614D90C6B84F2024735]C:\Windows\Installer\11f0ff3.msi calibre [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\B2FB96D706C6A0D4A8C6CBDF20D5D548]C:\Windows\Installer\43b8648.msi Compatibiliteitspakket voor het 2007 Microsoft Office system [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00002109020031400000000000F01FEC]C:\Windows\Installer\8883a4.msi D3DX10 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\7BD4C90EC03660F46A13E87A329932FA]C:\Windows\Installer\1eaeab.msi Google Update Helper [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\93BAD29AC2E44034A96BCB446EB8552E]C:\Windows\Installer\1227932.msi HP [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9B52EE2B00B5FCA4490F2934C3823CE9]c:\Windows\Installer\19187.msi HP Active Support Library [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\F98F5920896F1014A9D7944F70CED228]c:\Windows\Installer\19159.msi HP Advisor [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\24E34A3785639DD45815AFDC3A365283]c:\Windows\Installer\191b7.msi HP Demo [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\C59B728F5FB14B34E962DC5C69CE3EEA]c:\Windows\Installer\191a9.msi HP MediaSmart SmartMenu [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\345F8E2DA32D83A4FACFB4EDFBABF6AD]c:\Windows\Installer\1919a.msi HP Odometer [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\98A1CA8B1DFF79F408155E501A065F26]C:\Windows\Installer\380d7.msi HP Picasso Media Center Add-In [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\1BC5FB30E27B6AC42A876F65080F4502]c:\Windows\Installer\380e5.msi HP Recovery Manager RSS [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2CE0460AE79B1CF4DA4122C7E983B64B]C:\Windows\Installer\191be.msi HP Support Information [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\AF960CC168A1E2047978F3406E256CA7]C:\Windows\Installer\380d0.msi HP Update [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\C4E4AFE2F5B77F841A0CA18A287B9A3C]C:\Windows\Installer\7f75fee.msi HPAsset component for HP Active Support Library [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\53A4D966B6414134981FA13C7D8B3876]C:\Windows\Installer\8fbc27.msi IObit Apps Toolbar v8.8 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\19363A2B9A3A3924882B8A62E37C8F56]C:\Windows\Installer\1bd5416.msi Junk Mail filter update [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\7E0BA6F1DDC839B4A832AAE92BEFCF4E]C:\Windows\Installer\1eaf24.msi LabelPrint [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\C971C95CD8669A946BAE1012CCCF2134]c:\Windows\Installer\19176.msi LightScribe System Software [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\1CF55E0ED35CD8F41BB45BC91372748C]C:\Windows\Installer\5975f7c.msi MediaSmart DVD [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\970DACCDC29FAD442B8526F46C15A7A5]c:\Windows\Installer\1918b.msi Medieval CUE Splitter [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9622D69BB865FBC4392321AF8E1B857F]C:\Windows\Installer\135e8e1.msi Mesh Runtime [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\6116D6C8427B0184F8D20D746E7B6DE8]C:\Windows\Installer\1eb09f.msi Messenger Companion [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\E52D2418A820365468DE755587C30892]C:\Windows\Installer\1eb0db.msi Microsoft .NET Framework 3.5 Language Pack SP1 - nld [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\7D837101508D9A73BB19F1C2537128FB]C:\Windows\Installer\c4c472.msi Microsoft .NET Framework 3.5 SP1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\26DDC2EC4210AC63483DF9D4FCC5B59D]c:\Windows\Installer\bd6f4e.msi Microsoft .NET Framework 4.5.1 (NLD) [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2FA0BBE92DA4ABA359FE79E7EB1ABC90]C:\Windows\Installer\41b4a1d.msi Microsoft .NET Framework 4.5.1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\BE4EBED704B66673BB53C5BB3C58AD73]C:\Windows\Installer\40be156.msi Microsoft Application Error Reporting [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\000021599B0090400100000000F01FEC]C:\Windows\Installer\59e612.msi Microsoft Office Access MUI (Dutch) 2010 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109510031400000000000F01FEC]C:\Windows\Installer\5741bd4.msi Microsoft Office Excel MUI (Dutch) 2010 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109610031400000000000F01FEC]C:\Windows\Installer\5741b91.msi Microsoft Office Groove MUI (Dutch) 2010 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109AB0031400000000000F01FEC]C:\Windows\Installer\5741b98.msi Microsoft Office InfoPath MUI (Dutch) 2010 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109440031400000000000F01FEC]C:\Windows\Installer\5741be2.msi Microsoft Office Office 64-bit Components 2010 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109A20000000100000000F01FEC]C:\Windows\Installer\5741c1b.msi Microsoft Office OneNote MUI (Dutch) 2010 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\000041091A0031400000000000F01FEC]C:\Windows\Installer\5741bdb.msi Microsoft Office Outlook MUI (Dutch) 2010 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109A10031400000000000F01FEC]C:\Windows\Installer\5741ba7.msi Microsoft Office PowerPoint MUI (Dutch) 2010 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109810031400000000000F01FEC]C:\Windows\Installer\5741b86.msi Microsoft Office PowerPoint Viewer 2007 (Dutch) [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00002159FA0031400000000000F01FEC]C:\Windows\Installer\88839e.msi Microsoft Office Professional Plus 2010 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109110000000000000000F01FEC]C:\Windows\Installer\574238f.msi Microsoft Office Proof (Dutch) 2010 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10031400000000000F01FEC]C:\Windows\Installer\5741bae.msi Microsoft Office Proof (English) 2010 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400000000000F01FEC]C:\Windows\Installer\5741bc4.msi Microsoft Office Proof (French) 2010 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100C0400000000000F01FEC]C:\Windows\Installer\5741bbd.msi Microsoft Office Proof (German) 2010 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10070400000000000F01FEC]C:\Windows\Installer\5741bb5.msi Microsoft Office Proofing (Dutch) 2010 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109C20031400000000000F01FEC]C:\Windows\Installer\5741bcb.msi Microsoft Office Publisher MUI (Dutch) 2010 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109910031400000000000F01FEC]C:\Windows\Installer\5741bea.msi Microsoft Office Shared 64-bit MUI (Dutch) 2010 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109A20031400100000000F01FEC]C:\Windows\Installer\5741b9f.msi Microsoft Office Shared MUI (Dutch) 2010 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109E60031400000000000F01FEC]C:\Windows\Installer\5741b78.msi Microsoft Office Word MUI (Dutch) 2010 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109B10031400000000000F01FEC]C:\Windows\Installer\5741c11.msi Microsoft Silverlight [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\D7314F9862C648A4DB8BE2A5B47BE100]c:\Windows\Installer\74109b.msi Microsoft Silverlight 5 Toolkit December 2011 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\E8EE53CE1D78E3E45BCC8D1B4564515F]C:\Windows\Installer\630f02.msi Microsoft SQL Server 2005 Compact Edition [ENU] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\1D034B0FAA6BD374B960AAD30DF10D8B]C:\Windows\Installer\59e661.msi Microsoft Visual C++ 2005 Redistributable (x64) [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\1af2a8da7e60d0b429d7e6453b3d0182]C:\Windows\Installer\492c40.msi Microsoft Visual C++ 2005 Redistributable (x64) [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\84b9c17023c712640acaf308593282f8]C:\Windows\Installer\1ecc9.msi Microsoft Visual C++ 2005 Redistributable (x64) [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\8E58E8E6B4EC5FF4197F4099C9F9EAA6]C:\Windows\Installer\380de.msi Microsoft Visual C++ 2005 Redistributable (x64) [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9eab5ec6ac3d99b498a1d16c1c815acf]C:\Windows\Installer\ad5f838.msi Microsoft Visual C++ 2005 Redistributable [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\3e43b73803c7c394f8a6b2f0402e19c2]C:\Windows\Installer\af1bd3.msi Microsoft Visual C++ 2005 Redistributable [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\c1c4f01781cc94c4c8fb1542c0981a2a]C:\Windows\Installer\492c4d.msi Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\153AA053AF120723B8A73845437E66DA]C:\Windows\Installer\1ecd2.msi Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\8802AFF4713841B339DCC496D93B8734]C:\Windows\Installer\19193.msi Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\EFEE0228DC83E77358593193D847A0EC]c:\Windows\Installer\acc72cd.msi Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\1007C6B46D7C017319E3B52CF3EC196E]C:\Windows\Installer\7a71c35.msi Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\67D6ECF5CD5FBA732B8B22BAC8DE1B4D]C:\Windows\Installer\492fa1.msi Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\6F9E66FF7E38E3A3FA41D89E8A906A4A]C:\Windows\Installer\1ecc2.msi Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\1E4ACFA687B90463F8277AFB33442800]C:\Windows\Installer\1843aa.msi Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\D20352A90C039D93DBF6126ECE614057]C:\Windows\Installer\af1bda.msi Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\CFD2C1F142D260E3CB8B271543DA9F98]C:\Windows\Installer\af1be1.msi Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\6E815EB96CCE9A53884E7857C57002F0]C:\Windows\Installer\492bc9.msi Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\1926E8D15D0BCE53481466615F760A7F]C:\Windows\Installer\5973ad1.msi Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\1D5E3C0FEDA1E123187686FED06E995A]C:\Windows\Installer\5971dfe.msi Microsoft Works [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\5F1F8515B1AF94D45B64555A00B498DB]C:\Windows\Installer\888398.msi MSVCRT [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A6C64DD86500CEF47BA082BB611A1FF1]C:\Windows\Installer\1eaea1.msi MSVCRT_amd64 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\52744B0D6663D294EB6F85A741DBB99D]C:\Windows\Installer\1eaf28.msi MSXML 4.0 SP2 (KB954430) [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\DDA39468D428E8B4DB27C8D5DC5CA217]c:\Windows\Installer\bd6fdc.msi MSXML 4.0 SP2 (KB973688) [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\6E8A266FCD4F2A1409E1C8110F44DBCE]c:\Windows\Installer\bd6fe4.msi Nero 10 ClipartPack [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\87B4DE69E0033304EAC61C51EC4BFD70]C:\Windows\Installer\821d7.msi Nero 10 Menu TemplatePack 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\FD7B8C240BEF15D41B9605B6B6CE7579]C:\Windows\Installer\821e0.msi Nero 10 Menu TemplatePack 2 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\372C217E4657E8C4AA95F01AB93C1571]C:\Windows\Installer\821e9.msi Nero 10 Menu TemplatePack 3 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9146412944EAB8C44AB8A0BBB1E50C62]C:\Windows\Installer\821f2.msi Nero 10 Menu TemplatePack Basic [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\BAE3AA36BB322B84A90D448F87706540]C:\Windows\Installer\82118.msi Nero 10 Movie ThemePack 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\64BABF34969500249985F18FF1EE05F6]C:\Windows\Installer\821fb.msi Nero 10 Movie ThemePack 2 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\40491F07C69BBBE4DAB253478F371679]C:\Windows\Installer\82204.msi Nero 10 Movie ThemePack 3 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\246832DD7C4145D4B87DAF6DED9A99B9]C:\Windows\Installer\8213c.msi Nero 10 Movie ThemePack 4 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\B7C0B07A725335D46A499E94E2ECE91E]C:\Windows\Installer\82145.msi Nero 10 Movie ThemePack Basic [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\F228BC5F563B1D34CB0CF4ADA102717A]C:\Windows\Installer\82121.msi Nero 10 PiP EffectPack 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\EAD4A3FEF61F1CA478BBEF007A4880F4]C:\Windows\Installer\8214e.msi Nero 10 Sample ImagePack [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\FDF51DCA24CF57144B7775F629FF2265]C:\Windows\Installer\8212a.msi Nero 10 Sample Videos [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\D9E01A2900AE64A4F822EE6A0699D216]C:\Windows\Installer\8220d.msi Nero 10 Video TransitionPack 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\6F8CEB583AA9FF345BB628677217733B]C:\Windows\Installer\82157.msi Nero Audio Pack 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\E2FB0A7ACC133E949931255C30BE69D9]C:\Windows\Installer\13ba9f.msi Nero BackItUp 10 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\0396BA86FFB56FF429B315A61989F46E]C:\Windows\Installer\82169.msi Nero BackItUp 10 Help (CHM) [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\B6668C80205C3BA44BBC7DA44CD241EF]C:\Windows\Installer\82216.msi Nero Blu-ray Player [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\48B421222B3930642B214166564E6B1B]C:\Windows\Installer\13bae7.msi Nero Burning ROM 10 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\D137D5A73B4BE0943B9357867521ABBA]C:\Windows\Installer\82133.msi Nero BurningROM 10 Help (CHM) [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\EB42B6B97E084C64F95A1B765D0E3F54]C:\Windows\Installer\8221f.msi Nero BurnRights 10 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\D7DFC3496335FA7449810E42375A5A71]C:\Windows\Installer\82160.msi Nero BurnRights 10 Help (CHM) [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\6C868555BF94F484BB34980856A1B100]C:\Windows\Installer\82231.msi Nero Control Center 10 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\F998BFD62A710F845A33DED88666FC83]C:\Windows\Installer\820f4.msi Nero ControlCenter 10 Help (CHM) [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\B1B2B325BD8D14B409FF4C7D992E57A8]C:\Windows\Installer\82228.msi Nero Core Components 10 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\8A2F6342E7B4C6B4EAE406C448AAA6F4]C:\Windows\Installer\820fd.msi Nero CoverDesigner 10 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\E6A00FCF85BFA774BA9E329270015512]C:\Windows\Installer\82172.msi Nero CoverDesigner 10 Help (CHM) [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\55C3723C4E1EFF14D896108590D08B8D]C:\Windows\Installer\8223a.msi Nero DiscSpeed 10 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\E4F094430D84E29428944BB8CE0F35C7]C:\Windows\Installer\8217b.msi Nero DiscSpeed 10 Help (CHM) [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\8140A81CA2446814FA890DF805452ACF]C:\Windows\Installer\82243.msi Nero Express 10 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\3910550722C1C544F84A65E451D51B7A]C:\Windows\Installer\82184.msi Nero Express 10 Help (CHM) [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\8193463375979384297CAE69BC26A189]C:\Windows\Installer\8224c.msi Nero InfoTool 10 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\FA4B214FC8835FF4B9F233BDC1359635]C:\Windows\Installer\8218d.msi Nero InfoTool 10 Help (CHM) [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\531940669569DAA41996C9AC62E9BBE3]C:\Windows\Installer\82255.msi Nero MediaHub 10 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\F86BF7F16F253A644BF283EC6492A55E]C:\Windows\Installer\82197.msi Nero MediaHub 10 Help (CHM) [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A268764FAC9DDE74D8184B3B9C932927]C:\Windows\Installer\8225e.msi Nero Multimedia Suite 10 Platinum HD [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9551C7727FC4FF44D87089AAC931AADB]C:\Windows\Installer\820ec.msi Nero Recode 10 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\358CECE8D3C501B45B7CFF11FF278470]C:\Windows\Installer\821a9.msi Nero Recode 10 Help (CHM) [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A4D1C7BDAB80E7C48AAA7B9FBB73D2FC]C:\Windows\Installer\82267.msi Nero RescueAgent 10 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\787E733E16FCB7B48BF40529205A0432]C:\Windows\Installer\821a0.msi Nero RescueAgent 10 Help (CHM) [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\83252E293A16DCA44A70C384E0FE747A]C:\Windows\Installer\82270.msi Nero SoundTrax 10 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9335EE1E23D5F854ABBA1BF93610CB2E]C:\Windows\Installer\821bb.msi Nero SoundTrax 10 Help (CHM) [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\99E78961C59C31542993B7440A7AD15B]C:\Windows\Installer\82279.msi Nero StartSmart 10 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\E984D16F44C6CA94DA20D78ACA7AA356]C:\Windows\Installer\821cd.msi Nero StartSmart 10 Help (CHM) [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\C9F7116F5BDA0954B94E217CEB2C7820]C:\Windows\Installer\82282.msi Nero Update [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\7040BB568CC47CD459E2E3FEFD5006A2]C:\Windows\Installer\8229c.msi Nero Vision 10 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\3F7924A915A29DE429ACB4BC380849E7]C:\Windows\Installer\821b2.msi Nero Vision 10 Help (CHM) [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\0A1149233F91047478F47104B021F672]C:\Windows\Installer\8228b.msi Nero WaveEditor 10 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\5DAFDCDE08FD00644A399EAD6D182003]C:\Windows\Installer\821c4.msi Nero WaveEditor 10 Help (CHM) [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\F8D592A7B484BFF498BA1CDF945719EF]C:\Windows\Installer\82294.msi NVIDIA PhysX [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A59E554B408BF9345B3333B66153EA79]C:\Windows\Installer\4b781b.msi OpenOffice 4.1.1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\D419DF982744F4E46883968E758ED29C]C:\Windows\Installer\12268f2.msi PaperPort Image Printer 64-bit [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\1FAF4ABA98369F5429EC93414A5E4C17]C:\Windows\Installer\1633ba47.msi Power2Go [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\38E1FB04BE028D11795C00905C206085]c:\Windows\Installer\19172.msi PowerDirector [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\098990BCF5D15D11E99A0005AB3E711E]c:\Windows\Installer\1917a.msi PowerStarter [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\42C6FBF1DF1C10144AB2C065F4E9E897]c:\Windows\Installer\19183.msi PVSonyDll [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\D366E3D3E7E477545A06E7DCDD5445A8]C:\Windows\Installer\87f8a.msi Samsung Kies [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\1038C85769625584FA5435B4210089A0]C:\Windows\Installer\f6e8ff4.msi Seagate Dashboard 2.0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9D324C346D6E7064DA9CBE5BF496C075]C:\Windows\Installer\35c05b8.msi Segoe UI [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\DBCF4DD51C3A5514E97114167CA0AAAB]C:\Windows\Installer\1eaeaf.msi TuneUp Utilities Language Pack (en-US) [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2FD4EB32D3927704284FF18D2C9672C7]C:\Windows\Installer\28d30d.msi TuneUp Utilities Language Pack (nl-NL) [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\D1B679F1DFC76F440B61D1B3F0AF39A7]C:\Windows\Installer\3e01f0.msi Vista Codec Package [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\EC08DF9F8440F4D4B8DC77CF15C4F399]C:\Windows\Installer\940dfc.msi Visual Studio 2008 x64 Redistributables [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\06AEBDCF0F97EAF4BB8A552AC606A994]C:\Windows\Installer\7d63ffb.msi Visual Studio 2010 x64 Redistributables [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\6D331B1297950F74EBC16F6A3B4096F3]C:\Windows\Installer\1e2fd13.msi Visual Studio 2012 x64 Redistributables [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\07E577C8197A8AD4CB3CA67B31F64448]C:\Windows\Installer\10913b1.msi Visual Studio 2012 x86 Redistributables [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A91FFE89BA03B4E49B340FB6C136BE8F]C:\Windows\Installer\10913aa.msi VSOConvertX [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\8E81314C8B233E54E92AA241B2105174]C:\Windows\Installer\4dc6f0f.msi VTech Download Agent Library [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\1EA380BD4533DAA4DB44F5C24C2BCE6E]C:\Windows\Installer\888251.msi Windows Live Communications Platform [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\3D04254D3B6B9FF42B3445CE3E1E0066]C:\Windows\Installer\1eaec1.msi Windows Live Essentials [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\B53C70A248384AD4A95944B2C6980A37]C:\Windows\Installer\1eb0af.msi Windows Live Family Safety [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\6658C22B225D04B47AFA25F5A5078D23]C:\Windows\Installer\1eb0d7.msi Windows Live Family Safety [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9EBF5A643BDA39441ACC4BFCDF422DA6]C:\Windows\Installer\1eae69.msi Windows Live ID Sign-in Assistant [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\26ABA8B10F47DE741BC84A13825E198B]C:\Windows\Installer\1eae47.msi Windows Live Installer [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\F132F0B0A6ECD384AA32773B467F9571]C:\Windows\Installer\1eae94.msi Windows Live Language Selector [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\BC3F6BE54F64F1540A82F7D6D8537D0D]C:\Windows\Installer\1eae4f.msi Windows Live Mail [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A563885D93EA72F4DBEA4B7EC2E809C0]C:\Windows\Installer\1eb0bf.msi Windows Live Mail [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A57765D93F393A44082948E08362ED03]C:\Windows\Installer\1eaf81.msi Windows Live Mesh - ActiveX-besturingselement voor externe verbindingen [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\C55EC23CAB21159478799076DFFE55F6]C:\Windows\Installer\1eb0cf.msi Windows Live Mesh [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\1A3414F312C911046897B31C10C48668]C:\Windows\Installer\1eb0d3.msi Windows Live Mesh [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\C7BCDCEDCC85568419FA26F77989EF84]C:\Windows\Installer\1eb0a3.msi Windows Live Messenger Companion Core [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\C4B69A87346AF0D4892C8A1EA666969F]C:\Windows\Installer\1eb0a7.msi Windows Live MIME IFilter [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\E08F45ADC1622A148A5545A941F4F295]C:\Windows\Installer\1eae53.msi Windows Live Movie Maker [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\4314AE291D01A814191EA5403531A183]C:\Windows\Installer\1eb097.msi Windows Live Movie Maker [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9D4227BCACD61F34F838B6E1930AF029]C:\Windows\Installer\1eb0c7.msi Windows Live Photo Common [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\0D262DB9887B64540A5A4F5FE63C38B4]C:\Windows\Installer\1eb0b3.msi Windows Live Photo Common [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\B6ACDB9A3563B764CA384963D73AFB3E]C:\Windows\Installer\1eaedd.msi Windows Live Photo Gallery [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\0FB3B06AB459FA248B8DC2D1436B31AA]C:\Windows\Installer\1eb0c3.msi Windows Live Photo Gallery [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\766F6333940964D4896BC447E3BE5C1B]C:\Windows\Installer\1eaff4.msi Windows Live PIMT Platform [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\DFDBABC48F94DF74EBD7CEED270725A5]C:\Windows\Installer\1eaed1.msi Windows Live Remote Client [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A889D6FD0AEE7724AA8B51E880E634B9]C:\Windows\Installer\1eae57.msi Windows Live Remote Client Resources [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\15150F9C9A59B9B45B4371062E0D415A]C:\Windows\Installer\1eae87.msi Windows Live Remote Service [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\8456A20EEDF62E04E89D11D9D7E746F1]C:\Windows\Installer\1eae4b.msi Windows Live Remote Service Resources [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\C3CDFBC612FC20C46ACD5A2A07F7FA55]C:\Windows\Installer\1eae8b.msi Windows Live SOXE [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\F4E3B286A696ED244AC1C470AE61874B]C:\Windows\Installer\1eaeb7.msi Windows Live SOXE Definitions [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\26CEF00243C306D4C98ECE73E2100CF8]C:\Windows\Installer\1eaeb3.msi Windows Live Sync [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A307F43ED9C1F1B4BAEB7D8E08B068D0]C:\Windows\Installer\59e668.msi Windows Live UX Platform [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\E97A59ECCF4EFFF4A857920FB449F22F]C:\Windows\Installer\1eae8f.msi Windows Live UX Platform Language Pack [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\BD4C5EB02AE8D384DB177DBE9040C0ED]C:\Windows\Installer\1eb0ab.msi Windows Live Writer [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\076CFAAAB965F2A4284B2449E5D03EFE]C:\Windows\Installer\1eafb6.msi Windows Live Writer [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\329710E78F6123E449FEA051B01D69EF]C:\Windows\Installer\1eb0cb.msi Windows Live Writer [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\60EA627A3AAA1D34783E075F0113F440]C:\Windows\Installer\1eb09b.msi Windows Live Writer Resources [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\7B144B41D477071489AE1A6376EA2681]C:\Windows\Installer\1eb0bb.msi ==== Empty Folders Check ====================== C:\PROGRA~2\DriverWhiz deleted successfully C:\PROGRA~2\Malwarebytes' Anti-Malware deleted successfully C:\PROGRA~2\SimilarSites deleted successfully C:\Program Files\log deleted successfully C:\PROGRA~3\{BAF091CA-86C4-4627-ADA1-897E2621C1B0} deleted successfully C:\Users\Peter\AppData\Roaming\21384 deleted successfully C:\Users\Peter\AppData\Roaming\BandExtend deleted successfully C:\Users\Peter\AppData\Roaming\HpUpdate deleted successfully C:\Users\Peter\AppData\Roaming\Malwarebytes deleted successfully C:\Users\Peter\AppData\Roaming\Opera Software deleted successfully C:\Users\Peter\AppData\Roaming\Systweak deleted successfully C:\Users\Peter\AppData\Local\Downloaded Installations deleted successfully C:\Users\Peter\AppData\Local\DriverToolkit deleted successfully C:\Users\Peter\AppData\Local\MacGo deleted successfully C:\Users\Peter\AppData\Local\Opera Software deleted successfully C:\Users\Peter\AppData\Local\Unity deleted successfully ==== Checking Systemdrive for Symlinks ====================== De volumenaam van station C is HP Het volumenummer is DC01-E0DA Map van C:\ 11/11/2012 10:23 Documents and Settings [C:\Users] 0 bestand(en) 0 bytes Map van C:\Program Files\Windows NT 11/11/2012 10:23 Bureau-accessoires [C:\Program Files\Windows NT\Accessories] 0 bestand(en) 0 bytes Map van C:\ProgramData 11/11/2012 10:23 Application Data [C:\ProgramData] 11/11/2012 10:23 Bureaublad [C:\Users\Public\Desktop] 11/11/2012 10:23 Documenten [C:\Users\Public\Documents] 11/11/2012 10:23 Favorieten [C:\Users\Public\Favorites] 11/11/2012 10:23 Menu Start [C:\ProgramData\Microsoft\Windows\Start Menu] 11/11/2012 10:23 Sjablonen [C:\ProgramData\Microsoft\Windows\Templates] 0 bestand(en) 0 bytes Map van C:\ProgramData\Microsoft\Windows\Start Menu 11/11/2012 10:23 Programma's [C:\ProgramData\Microsoft\Windows\Start Menu\Programs] 0 bestand(en) 0 bytes Map van C:\Users 11/11/2012 10:23 All Users [C:\ProgramData] 11/11/2012 10:23 Default User [C:\Users\Default] 0 bestand(en) 0 bytes Map van C:\Users\All Users 11/11/2012 10:23 Application Data [C:\ProgramData] 11/11/2012 10:23 Bureaublad [C:\Users\Public\Desktop] 11/11/2012 10:23 Documenten [C:\Users\Public\Documents] 11/11/2012 10:23 Favorieten [C:\Users\Public\Favorites] 11/11/2012 10:23 Menu Start [C:\ProgramData\Microsoft\Windows\Start Menu] 11/11/2012 10:23 Sjablonen [C:\ProgramData\Microsoft\Windows\Templates] 0 bestand(en) 0 bytes Map van C:\Users\All Users\Microsoft\Windows\Start Menu 11/11/2012 10:23 Programma's [C:\ProgramData\Microsoft\Windows\Start Menu\Programs] 0 bestand(en) 0 bytes Map van C:\Users\Default 11/11/2012 10:23 Application Data [C:\Users\Default\AppData\Roaming] 11/11/2012 10:23 Cookies [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Cookies] 11/11/2012 10:23 Local Settings [C:\Users\Default\AppData\Local] 11/11/2012 10:23 Menu Start [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu] 11/11/2012 10:23 Mijn documenten [C:\Users\Default\Documents] 11/11/2012 10:23 NetHood [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Network Shortcuts] 11/11/2012 10:23 Netwerkprinteromgeving [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Printer Shortcuts] 11/11/2012 10:23 Recent [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Recent] 11/11/2012 10:23 SendTo [C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo] 11/11/2012 10:23 Sjablonen [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Templates] 0 bestand(en) 0 bytes Map van C:\Users\Default\AppData\Local 11/11/2012 10:23 Application Data [C:\Users\Default\AppData\Local] 11/11/2012 10:23 Geschiedenis [C:\Users\Default\AppData\Local\Microsoft\Windows\History] 11/11/2012 10:23 Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files] 0 bestand(en) 0 bytes Map van C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu 11/11/2012 10:23 Programma's [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs] 0 bestand(en) 0 bytes Map van C:\Users\Default\Documents 11/11/2012 10:23 Mijn afbeeldingen [C:\Users\Default\Pictures] 11/11/2012 10:23 Mijn muziek [C:\Users\Default\Music] 11/11/2012 10:23 Mijn video's [C:\Users\Default\Videos] 0 bestand(en) 0 bytes Map van C:\Users\Peter 11/11/2012 10:26 Application Data [C:\Users\Peter\AppData\Roaming] 11/11/2012 10:26 Cookies [C:\Users\Peter\AppData\Roaming\Microsoft\Windows\Cookies] 11/11/2012 10:26 Local Settings [C:\Users\Peter\AppData\Local] 11/11/2012 10:26 Menu Start [C:\Users\Peter\AppData\Roaming\Microsoft\Windows\Start Menu] 11/11/2012 10:26 Mijn documenten [C:\Users\Peter\Documents] 11/11/2012 10:26 NetHood [C:\Users\Peter\AppData\Roaming\Microsoft\Windows\Network Shortcuts] 11/11/2012 10:26 Netwerkprinteromgeving [C:\Users\Peter\AppData\Roaming\Microsoft\Windows\Printer Shortcuts] 11/11/2012 10:26 Recent [C:\Users\Peter\AppData\Roaming\Microsoft\Windows\Recent] 11/11/2012 10:26 SendTo [C:\Users\Peter\AppData\Roaming\Microsoft\Windows\SendTo] 11/11/2012 10:26 Sjablonen [C:\Users\Peter\AppData\Roaming\Microsoft\Windows\Templates] 0 bestand(en) 0 bytes Map van C:\Users\Peter\AppData\Local 11/11/2012 10:26 Application Data [C:\Users\Peter\AppData\Local] 11/11/2012 10:26 Geschiedenis [C:\Users\Peter\AppData\Local\Microsoft\Windows\History] 11/11/2012 10:26 Temporary Internet Files [C:\Users\Peter\AppData\Local\Microsoft\Windows\Temporary Internet Files] 0 bestand(en) 0 bytes Map van C:\Users\Peter\AppData\LocalLow 02/08/2013 16:21 PlayReady [C:\ProgramData\Microsoft\PlayReady] 0 bestand(en) 0 bytes Map van C:\Users\Peter\AppData\Roaming\Microsoft\Windows\Start Menu 11/11/2012 10:26 Programma's [C:\Users\Peter\AppData\Roaming\Microsoft\Windows\Start Menu\Programs] 0 bestand(en) 0 bytes Map van C:\Users\Peter\Documents 11/11/2012 10:26 Mijn afbeeldingen [C:\Users\Peter\Pictures] 11/11/2012 10:26 Mijn muziek [C:\Users\Peter\Music] 11/11/2012 10:26 Mijn video's [C:\Users\Peter\Videos] 0 bestand(en) 0 bytes Map van C:\Users\Public\Documents 11/11/2012 10:23 Mijn afbeeldingen [C:\Users\Public\Pictures] 11/11/2012 10:23 Mijn muziek [C:\Users\Public\Music] 11/11/2012 10:23 Mijn video's [C:\Users\Public\Videos] 0 bestand(en) 0 bytes Map van C:\Users\UpdatusUser 22/11/2012 00:11 Application Data [C:\Users\UpdatusUser\AppData\Roaming] 22/11/2012 00:11 Cookies [C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Cookies] 22/11/2012 00:11 Local Settings [C:\Users\UpdatusUser\AppData\Local] 22/11/2012 00:11 Menu Start [C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu] 22/11/2012 00:11 Mijn documenten [C:\Users\UpdatusUser\Documents] 22/11/2012 00:11 NetHood [C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Network Shortcuts] 22/11/2012 00:11 Netwerkprinteromgeving [C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Printer Shortcuts] 22/11/2012 00:11 Recent [C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Recent] 22/11/2012 00:11 SendTo [C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\SendTo] 22/11/2012 00:11 Sjablonen [C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Templates] 0 bestand(en) 0 bytes Map van C:\Users\UpdatusUser\AppData\Local 22/11/2012 00:11 Application Data [C:\Users\UpdatusUser\AppData\Local] 22/11/2012 00:11 Geschiedenis [C:\Users\UpdatusUser\AppData\Local\Microsoft\Windows\History] 22/11/2012 00:11 Temporary Internet Files [C:\Users\UpdatusUser\AppData\Local\Microsoft\Windows\Temporary Internet Files] 0 bestand(en) 0 bytes Map van C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu 22/11/2012 00:11 Programma's [C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs] 0 bestand(en) 0 bytes Map van C:\Users\UpdatusUser\Documents 22/11/2012 00:11 Mijn afbeeldingen [C:\Users\UpdatusUser\Pictures] 22/11/2012 00:11 Mijn muziek [C:\Users\UpdatusUser\Music] 22/11/2012 00:11 Mijn video's [C:\Users\UpdatusUser\Videos] 0 bestand(en) 0 bytes Totaal aantal weergegeven bestanden: 0 bestand(en) 0 bytes 73 map(pen) 203.963.551.744 bytes beschikbaar ==== Deleting CLSID Registry Keys ====================== HKEY_USERS\S-1-5-21-3930024867-1471058179-2470722348-1000\Software\Microsoft\Internet Explorer\SearchScopes\{94CB25CF-F92C-4A49-B568-0917520AF416} deleted successfully ==== Deleting CLSID Registry Values ====================== ==== Installed Programs ====================== Activation Assistant for the 2007 Microsoft Office suites Adobe AIR Adobe Flash Player 16 ActiveX Adobe Flash Player 16 NPAPI Adobe Flash Player Packages Adobe Reader X (10.1.13) - Nederlands Advanced SystemCare 8 Agatha Christie - Death on the Nile Akamai NetSession Interface Avast Internet Security Bejeweled 2 Deluxe Bejeweled Twist Belgium e-ID middleware 4.0.7 (build 7453) Blasterball 3 Brother MFL-Pro Suite DCP-195C Build-a-lot 2 Chocolatier Chuzzle Deluxe Compatibiliteitspakket voor het 2007 Microsoft Office system Definition Update for Microsoft Office 2010 (KB2910899) 32-Bit Edition Diner Dash Diner Dash 2 Restaurant Rescue Driver Booster 2 Farm Frenzy FATE FATE Undiscovered Realms ffdshow x64 v1.3.4531 [2014-06-28] Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) HP Game Console Insaniquarium Deluxe IObit Malware Fighter IObit Uninstaller Jewel Quest 3 K-Lite Codec Pack (64-bit) v4.6.0 Kruidvat fotoservice Magic Academy Mah Jong Quest Mahjongg Artifacts Malwarebytes Anti-Malware versie 2.0.4.1028 Microsoft .NET Framework 3.5 Language Pack SP1 - nld Microsoft .NET Framework 3.5 SP1 Microsoft .NET Framework 4.5.1 Microsoft .NET Framework 4.5.1 (Nederlands) Microsoft .NET Framework 4.5.1 (NLD) Microsoft Application Error Reporting Microsoft Office Access MUI (Dutch) 2010 Microsoft Office Excel MUI (Dutch) 2010 Microsoft Office Groove MUI (Dutch) 2010 Microsoft Office InfoPath MUI (Dutch) 2010 Microsoft Office Office 64-bit Components 2010 Microsoft Office OneNote MUI (Dutch) 2010 Microsoft Office Outlook MUI (Dutch) 2010 Microsoft Office PowerPoint MUI (Dutch) 2010 Microsoft Office PowerPoint Viewer 2007 (Dutch) Microsoft Office Professional Plus 2010 Microsoft Office Proof (Dutch) 2010 Microsoft Office Proof (English) 2010 Microsoft Office Proof (French) 2010 Microsoft Office Proof (German) 2010 Microsoft Office Proofing (Dutch) 2010 Microsoft Office Publisher MUI (Dutch) 2010 Microsoft Office Shared 64-bit MUI (Dutch) 2010 Microsoft Office Shared MUI (Dutch) 2010 Microsoft Office Word MUI (Dutch) 2010 Microsoft Silverlight Microsoft Silverlight 5 Toolkit December 2011 Microsoft SQL Server 2005 Compact Edition [ENU] Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2005 Redistributable (x64) Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729 Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 Microsoft Works Mozilla Firefox 34.0.5 (x86 nl) MyFreeCodec NVIDIA PhysX OpenOffice 4.1.1 Peggle Nights Penguins Polar Bowler Polar Golfer Pineapple Cup Polar Pool Security Update for Microsoft .NET Framework 3.5 SP1 (KB2604111) Security Update for Microsoft .NET Framework 3.5 SP1 (KB2736416) Security Update for Microsoft .NET Framework 3.5 SP1 (KB2840629) Security Update for Microsoft .NET Framework 3.5 SP1 (KB2861697) Security Update for Microsoft .NET Framework 4.5.1 (KB2894854v2) Security Update for Microsoft .NET Framework 4.5.1 (KB2898869) Security Update for Microsoft .NET Framework 4.5.1 (KB2901126) Security Update for Microsoft .NET Framework 4.5.1 (KB2931368) Security Update for Microsoft .NET Framework 4.5.1 (KB2972107) Security Update for Microsoft .NET Framework 4.5.1 (KB2972216) Security Update for Microsoft .NET Framework 4.5.1 (KB2978128) Security Update for Microsoft .NET Framework 4.5.1 (KB2979578v2) Security Update for Microsoft Excel 2010 (KB2910902) 32-Bit Edition Security Update for Microsoft Office 2010 (KB2553154) 32-Bit Edition Security Update for Microsoft Office 2010 (KB2553284) 32-Bit Edition Security Update for Microsoft Office 2010 (KB2687423) 32-Bit Edition Security Update for Microsoft Office 2010 (KB2760781) 32-Bit Edition Security Update for Microsoft Office 2010 (KB2810073) 32-Bit Edition Security Update for Microsoft Office 2010 (KB2850016) 32-Bit Edition Security Update for Microsoft Office 2010 (KB2880971) 32-Bit Edition Security Update for Microsoft Office 2010 (KB2881071) 32-Bit Edition Security Update for Microsoft Word 2010 (KB2899519) 32-Bit Edition Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition Should I Remove It Slingo Deluxe Smart Defrag 3 StoneLoops of Jurassica Stuurprogrammapakket voor Windows - Fedict SmartCard (03/25/2014 4.0.7.4) Surfing Protection Taalpakket voor Microsoft .NET Framework 3.5 SP1 - NL Tradewinds - Caravans Turbo Pizza Unity Web Player Update for Microsoft .NET Framework 3.5 SP1 (KB963707) Update for Microsoft Access 2010 (KB2553446) 32-Bit Edition Update for Microsoft Excel 2010 (KB2589348) 32-Bit Edition Update for Microsoft Filter Pack 2.0 (KB2878281) 32-Bit Edition Update for Microsoft InfoPath 2010 (KB2817369) 32-Bit Edition Update for Microsoft InfoPath 2010 (KB2817396) 32-Bit Edition Update for Microsoft Office 2010 (KB2553140) 32-Bit Edition Update for Microsoft Office 2010 (KB2589298) 32-Bit Edition Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition Update for Microsoft Office 2010 (KB2589375) 32-Bit Edition Update for Microsoft Office 2010 (KB2589386) 32-Bit Edition Update for Microsoft Office 2010 (KB2597087) 32-Bit Edition Update for Microsoft Office 2010 (KB2597089) 32-Bit Edition Update for Microsoft Office 2010 (KB2687275) 32-Bit Edition Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition Update for Microsoft Office 2010 (KB2794737) 32-Bit Edition Update for Microsoft Office 2010 (KB2825635) 32-Bit Edition Update for Microsoft Office 2010 (KB2825640) 32-Bit Edition Update for Microsoft Office 2010 (KB2837581) 32-Bit Edition Update for Microsoft Office 2010 (KB2837602) 32-Bit Edition Update for Microsoft Office 2010 (KB2837606) 32-Bit Edition Update for Microsoft Office 2010 (KB2883019) 32-Bit Edition Update for Microsoft Office 2010 (KB2889818) 32-Bit Edition Update for Microsoft Office 2010 (KB2889828) 32-Bit Edition Update for Microsoft Office 2010 (KB2910896) 32-Bit Edition Update for Microsoft OneNote 2010 (KB2597088) 32-Bit Edition Update for Microsoft Outlook 2010 (KB2687567) 32-Bit Edition Update for Microsoft PowerPoint 2010 (KB2880517) 32-Bit Edition Update for Microsoft SharePoint Workspace 2010 (KB2760601) 32-Bit Edition Update for Microsoft Visio 2010 (KB2880526) 32-Bit Edition Update for Microsoft Visio Viewer 2010 (KB2837587) 32-Bit Edition VASCO Card Reader Plug-In (64-Bit) VASCO Smart Card Reader Plug-In (User) Virtual Villagers - A New Home Virtual Villagers - The Secret City Visual Studio 2008 x64 Redistributables Visual Studio 2010 x64 Redistributables Visual Studio 2012 x64 Redistributables Visual Studio 2012 x86 Redistributables VLC media player VSO ConvertXToDVD Wedding Dash Windows Live Communications Platform Windows Live Essentials Windows Live Family Safety Windows Live ID Sign-in Assistant Windows Live Installer Windows Live Language Selector Windows Live Mail Windows Live Mesh - ActiveX-besturingselement voor externe verbindingen Windows Live Mesh Windows Live Messenger Companion Core Windows Live MIME IFilter Windows Live Movie Maker Windows Live Photo Common Windows Live Photo Gallery Windows Live PIMT Platform Windows Live Remote Client Windows Live Remote Client Resources Windows Live Remote Service Windows Live Remote Service Resources Windows Live SOXE Windows Live SOXE Definitions Windows Live Sync Windows Live UX Platform Windows Live UX Platform Language Pack Windows Live Writer Windows Live Writer Resources Zuma Deluxe ==== Deleting Services ====================== ==== Deleting Files \ Folders ====================== C:\PROGRA~3\{BAF091CA-86C4-4627-ADA1-897E2621C1B0} not found "C:\Windows\Installer\1bd5416.msi" not found C:\Users\Peter\AppData\Local\7145 deleted C:\PROGRA~2\Application Updater deleted C:\PROGRA~2\Microsoft SQL Server Compact Edition deleted C:\PROGRA~2\NVIDIA Corporation deleted C:\PROGRA~2\IObit Apps Toolbar deleted C:\PROGRA~2\PC Speed Up deleted C:\Users\Peter\AppData\Roaming\0F1F1C2Y1H1P1C0I0T deleted C:\Users\Peter\AppData\Roaming\AdvancedSystemProtector deleted C:\PROGRA~3\NVIDIA Corporation deleted C:\PROGRA~3\Allmyapps deleted C:\PROGRA~3\ProductData deleted C:\Users\Peter\AppData\Local\DownloadManager deleted C:\Users\Peter\AppData\Local\CrashRpt deleted C:\Users\Peter\AppData\Local\Cool_Mirage deleted C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced System Optimizer 3 deleted C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Systweak Support Dock deleted C:\Users\Peter\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\1clickmoviedownloader.com deleted C:\Users\Peter\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Start Lollipop deleted C:\Windows\SysNative\roboot64.exe deleted C:\Users\Peter\AppData\LocalLow\IObit Apps deleted C:\Users\Peter\AppData\LocalLow\ADSRemoval deleted C:\Windows\sysWoW64\config\systemprofile\AppData\LocalLow\Application Updater deleted C:\windows\SysNative\tasks\Systweak Support Dock deleted C:\Windows\SysNative\config\systemprofile\Searches deleted C:\Windows\Syswow64\SET1640.tmp deleted C:\Windows\SysWow64\AI_RecycleBin deleted C:\Users\Peter\AppData\Roaming\Mozilla\Firefox\Profiles\xpty6wgq.default-1419366784337\extensions\firefox@ghostery.com.xpi deleted C:\Users\Peter\AppData\Roaming\Mozilla\Firefox\Profiles\xpty6wgq.default-1419366784337\jetpack deleted ==== System Specs ====================== Operating System: Microsoft® Windows Vista™ Home Premium 6.0.6002 Service Pack 2 64-bits Manufacturer: HP-Pavilion - Model: VG135AA-B14 m9780be Install Date: 11/11/2012 7:57:49 Last Boot: 24/12/2014 8:36:55 Processor: Intel(R) Core(TM) i7 CPU 920 @ 2.67GHz Number of Processors: 8 Work Station Bootmode: Normal boot Total RAM: 8182 MB (free 4303 MB - 52) Computername: PC_VAN_PETER Domain: WORKGROUP User: Peter (Non-Administrator account) Local Disk: C:\ - NTFS - 682 GB (free 189 GB) Local Disk: D:\ - NTFS - 16 GB (free 1 GB) Local Disk: E:\ - NTFS - 698 GB (free 241 GB) CD \ DVD Drive: F:\ Bootdevice: \Device\HarddiskVolume1 Windows update: Country: Belgi‰ Language: NLB ==== System Specs (Software) ====================== Anti-Virus: avast! Antivirus On-access scanning disabled (Outdated) Anti-Spyware: Windows Defender disabled (Outdated) Anti-Spyware: IObit Malware Fighter disabled (Outdated) Anti-Spyware: avast! Antivirus disabled (Outdated) Firewall: avast! Antivirus disabled Firewall: AVG update module disabled Default Browser: Firefox 34.0.5 Internet Explorer Version: 9.0.8112.16421 Mozilla Firefox version: 34.0.5 (x86 nl) Adobe Reader version: 10.1.13.16 Flash Player version: 16.0.0.235 ==== Files Recently Created / Modified ====================== ====== C:\Windows ==== ====== C:\Users\Peter\AppData\Local\Temp ==== ====== Java Cache ===== ====== C:\Windows\SysWOW64 ===== ====== C:\Windows\SysWOW64\drivers ===== ====== C:\Windows\Sysnative ===== 2014-12-24 07:39:03 BABB53F473F866A47511CC770FB9E8E4 426280 ----a-w- C:\Windows\Sysnative\FNTCACHE.DAT ====== C:\Windows\Sysnative\drivers ===== ====== C:\Windows\Tasks ====== ====== C:\Windows\Temp ====== ======= C:\Program Files ===== 2014-12-23 15:01:33 -------- d-----w- C:\Program Files\Fotoservice ======= C:\PROGRA~2 ===== ======= C: ===== ====== C:\Users\Peter\AppData\Roaming ====== 2014-12-23 22:53:31 34AC2CF5BE1C82E4B9A1357EE32B1473 239192 ----a-w- C:\Windows\serviceprofiles\Localservice\AppData\Local\FontCache3.0.0.0.dat 2014-12-23 14:16:49 958F634E69430D5DDFF42C7CB6908BD1 116552 ----a-w- C:\Users\Peter\AppData\Local\GDIPFONTCACHEV1.DAT ====== C:\Users\Peter ====== 2014-12-24 14:38:39 -------- d-----w- C:\ProgramData\ProductData 2014-12-19 10:46:18 -------- d-----w- C:\Users\Peter\Start Menu ====== C: exe-files == 2014-12-23 21:28:49 AD6291BCC4766D5FB19665FEDDDEB243 544 ----a-w- C:\$RECYCLE.BIN\S-1-5-21-3930024867-1471058179-2470722348-1000\$IRQORI4.exe 2014-12-23 21:15:54 8045ABB21A3BDD66A48E1ED5C0F0EF6A 1222144 ----a-w- C:\$RECYCLE.BIN\S-1-5-21-3930024867-1471058179-2470722348-1000\$RRQORI4.exe 2014-12-23 20:57:08 1242752DBDFB4C9792A72EF76DD9E788 544 ----a-w- C:\$RECYCLE.BIN\S-1-5-21-3930024867-1471058179-2470722348-1000\$ID9W9FJ.exe 2014-12-23 20:22:03 8045ABB21A3BDD66A48E1ED5C0F0EF6A 1222144 ----a-w- C:\$RECYCLE.BIN\S-1-5-21-3930024867-1471058179-2470722348-1000\$RD9W9FJ.exe 2014-12-23 18:27:26 27A9730A7AE1E6283CCFCE09E6F34F09 68384 ----a-w- C:\Windows\Temp\c4a6b64f-7964-4b8b-afe3-7b984581eec7\vlc.exe 2014-12-23 18:27:26 27A9730A7AE1E6283CCFCE09E6F34F09 68384 ----a-w- C:\Windows\Temp\8090dacc-b2e4-4231-b7b7-3d644fad260c\SearchProtocolHost.exe 2014-12-23 18:27:26 27A9730A7AE1E6283CCFCE09E6F34F09 68384 ----a-w- C:\Windows\Temp\70cd1231-6ac6-4e34-96fa-2be99b672bf3\SearchFilterHost.exe 2014-12-23 18:27:26 27A9730A7AE1E6283CCFCE09E6F34F09 68384 ----a-w- C:\Windows\Temp\5c3564b5-26b4-4692-98ee-9b6cbf7c10b7\DpInstX64.exe 2014-12-23 18:27:26 27A9730A7AE1E6283CCFCE09E6F34F09 68384 ----a-w- C:\Windows\Temp\402547ec-8a14-4322-9c3c-703c035b72ea\UnityWebPlayer_4_6_191.exe 2014-12-23 18:27:26 27A9730A7AE1E6283CCFCE09E6F34F09 68384 ----a-w- C:\Windows\Temp\0aa1054b-f456-41c6-92cf-eff9a87fb914\Uninstall.exe 2014-12-23 18:27:25 27A9730A7AE1E6283CCFCE09E6F34F09 68384 ----a-w- C:\Windows\Temp\e9deb41e-5648-4d5c-bec2-72234e050646\DriverBooster.exe 2014-12-23 18:27:25 27A9730A7AE1E6283CCFCE09E6F34F09 68384 ----a-w- C:\Windows\Temp\d5f9bff4-10e2-417b-8777-25da4d5175be\ehmsas.exe 2014-12-23 18:27:25 27A9730A7AE1E6283CCFCE09E6F34F09 68384 ----a-w- C:\Windows\Temp\d0a44707-b9e8-40fc-b32a-9516bf4c67a3\sidebar.exe 2014-12-23 18:27:25 27A9730A7AE1E6283CCFCE09E6F34F09 68384 ----a-w- C:\Windows\Temp\b2afdb70-d788-4d58-83f6-285caeeb85af\unsecapp.exe 2014-12-23 18:27:25 27A9730A7AE1E6283CCFCE09E6F34F09 68384 ----a-w- C:\Windows\Temp\a994513c-2423-40a5-a9ad-6c6181a8f577\PresentationFontCache.exe 2014-12-23 18:27:25 27A9730A7AE1E6283CCFCE09E6F34F09 68384 ----a-w- C:\Windows\Temp\a67e6198-3a00-473c-a0d4-e8d904da462b\notepad.exe 2014-12-23 18:27:25 27A9730A7AE1E6283CCFCE09E6F34F09 68384 ----a-w- C:\Windows\Temp\a1b9a537-8f23-480e-9f45-9aa0910f9ded\mbam.exe 2014-12-23 18:27:25 27A9730A7AE1E6283CCFCE09E6F34F09 68384 ----a-w- C:\Windows\Temp\9579451b-4587-4038-b192-7f74221f295b\WmiPrvSE.exe 2014-12-23 18:27:25 27A9730A7AE1E6283CCFCE09E6F34F09 68384 ----a-w- C:\Windows\Temp\9371f134-6919-4155-ab9d-c4cb7faae6dd\BrccMCtl.exe 2014-12-23 18:27:25 27A9730A7AE1E6283CCFCE09E6F34F09 68384 ----a-w- C:\Windows\Temp\7311db91-3476-4ce3-bd14-d39a5618fbb3\unsecapp.exe 2014-12-23 18:27:25 27A9730A7AE1E6283CCFCE09E6F34F09 68384 ----a-w- C:\Windows\Temp\65974665-60a6-4f7b-ab8b-f21e28056891\sidebar.exe 2014-12-23 18:27:25 27A9730A7AE1E6283CCFCE09E6F34F09 68384 ----a-w- C:\Windows\Temp\52ad2f90-7fae-4277-aeac-c259656bedfa\msiexec.exe 2014-12-23 18:27:25 27A9730A7AE1E6283CCFCE09E6F34F09 68384 ----a-w- C:\Windows\Temp\3e09ad79-45d6-4453-9bf1-d23b54762baa\conime.exe 2014-12-23 18:27:25 27A9730A7AE1E6283CCFCE09E6F34F09 68384 ----a-w- C:\Windows\Temp\2c9819ee-fe4e-409f-b3da-6b6716576032\firefox.exe 2014-12-23 18:27:25 27A9730A7AE1E6283CCFCE09E6F34F09 68384 ----a-w- C:\Windows\Temp\0d052900-8d59-4bc0-90bf-2f1c4a3bf854\ASC.exe 2014-12-23 18:27:25 27A9730A7AE1E6283CCFCE09E6F34F09 68384 ----a-w- C:\Windows\Temp\064cdbeb-ae47-4d0d-a150-f255ccefd993\IMF.exe 2014-12-23 18:27:24 27A9730A7AE1E6283CCFCE09E6F34F09 68384 ----a-w- C:\Windows\Temp\c988c060-4785-400a-890b-67d8ed1907aa\sidebar.exe 2014-12-23 18:27:24 27A9730A7AE1E6283CCFCE09E6F34F09 68384 ----a-w- C:\Windows\Temp\c723aa74-41d4-44a9-98d1-f078460d73b0\Suo10_SmartRAM.exe 2014-12-23 18:27:24 27A9730A7AE1E6283CCFCE09E6F34F09 68384 ----a-w- C:\Windows\Temp\bf29e73b-28b5-41cb-8294-cd7397aa28dd\TSMAgent.exe 2014-12-23 18:27:24 27A9730A7AE1E6283CCFCE09E6F34F09 68384 ----a-w- C:\Windows\Temp\b7d1831a-7151-440c-8c3b-c7ec59194574\RAVCpl64.exe 2014-12-23 18:27:24 27A9730A7AE1E6283CCFCE09E6F34F09 68384 ----a-w- C:\Windows\Temp\a7d31abc-d450-4866-9642-3cb109a25722\hpsysdrv.exe 2014-12-23 18:27:24 27A9730A7AE1E6283CCFCE09E6F34F09 68384 ----a-w- C:\Windows\Temp\a2b10e7e-a230-4535-9adb-8a571e5519ca\DVDAgent.exe 2014-12-23 18:27:24 27A9730A7AE1E6283CCFCE09E6F34F09 68384 ----a-w- C:\Windows\Temp\9d808534-b6bc-4db2-aa16-375ef2d33b9f\ASCTray.exe 2014-12-23 18:27:24 27A9730A7AE1E6283CCFCE09E6F34F09 68384 ----a-w- C:\Windows\Temp\8a4387ae-63ae-4c74-84dd-8c271e7e99d3\CLMLSvc.exe 2014-12-23 18:27:24 27A9730A7AE1E6283CCFCE09E6F34F09 68384 ----a-w- C:\Windows\Temp\82b9b907-c8ca-4bdd-a435-84d2ed9c21ed\MSASCui.exe 2014-12-23 18:27:24 27A9730A7AE1E6283CCFCE09E6F34F09 68384 ----a-w- C:\Windows\Temp\5757a58b-fe74-493e-b4d0-3b01d644f7b2\WmiPrvSE.exe 2014-12-23 18:27:24 27A9730A7AE1E6283CCFCE09E6F34F09 68384 ----a-w- C:\Windows\Temp\37e426b1-8ef8-4301-a34d-cc504e8d6c6d\avastui.exe 2014-12-23 18:27:24 27A9730A7AE1E6283CCFCE09E6F34F09 68384 ----a-w- C:\Windows\Temp\35ebe940-9333-4828-b1f5-e203adc90550\ehtray.exe 2014-12-23 18:27:24 27A9730A7AE1E6283CCFCE09E6F34F09 68384 ----a-w- C:\Windows\Temp\1e5ceacb-83ca-4373-86c8-66cd2d60e1b7\OSD64.exe 2014-12-23 18:27:24 27A9730A7AE1E6283CCFCE09E6F34F09 68384 ----a-w- C:\Windows\Temp\10ab89da-6688-4bf2-aaf4-6de8f283009a\AgentMonitor.exe 2014-12-23 18:27:24 27A9730A7AE1E6283CCFCE09E6F34F09 68384 ----a-w- C:\Windows\Temp\0848972c-736e-4abc-a80b-f7ec985bd3bf\SmartMenu.exe 2014-12-23 18:27:23 27A9730A7AE1E6283CCFCE09E6F34F09 68384 ----a-w- C:\Windows\Temp\f092f662-1359-4bf9-9bd5-044613cb5139\taskeng.exe 2014-12-23 18:27:23 27A9730A7AE1E6283CCFCE09E6F34F09 68384 ----a-w- C:\Windows\Temp\f088068e-3907-470b-8aef-164051254704\TuneUpUtilitiesApp64.exe 2014-12-23 18:27:23 27A9730A7AE1E6283CCFCE09E6F34F09 68384 ----a-w- C:\Windows\Temp\e7215f8a-e24f-4c62-ab0c-7b7aeff1901e\SmartDefrag.exe 2014-12-23 18:27:23 27A9730A7AE1E6283CCFCE09E6F34F09 68384 ----a-w- C:\Windows\Temp\e33c5061-c5c1-4dee-9871-e38da1229bf9\svchost.exe 2014-12-23 18:27:23 27A9730A7AE1E6283CCFCE09E6F34F09 68384 ----a-w- C:\Windows\Temp\cdd6ef49-f9fa-417e-899e-9d8e5d09e593\mbamservice.exe 2014-12-23 18:27:23 27A9730A7AE1E6283CCFCE09E6F34F09 68384 ----a-w- C:\Windows\Temp\943ff62d-cc7b-4b3b-b5d7-7f0092dd13e3\nvtray.exe 2014-12-23 18:27:23 27A9730A7AE1E6283CCFCE09E6F34F09 68384 ----a-w- C:\Windows\Temp\8b526ed4-a663-4422-93b4-d51767057934\mbamscheduler.exe 2014-12-23 18:27:23 27A9730A7AE1E6283CCFCE09E6F34F09 68384 ----a-w- C:\Windows\Temp\7f60db5f-c0fa-42d2-abf3-3a5fea6d9343\svchost.exe 2014-12-23 18:27:23 27A9730A7AE1E6283CCFCE09E6F34F09 68384 ----a-w- C:\Windows\Temp\76b5d5ec-9b80-4af9-beae-0d23943ce818\Monitor.exe 2014-12-23 18:27:23 27A9730A7AE1E6283CCFCE09E6F34F09 68384 ----a-w- C:\Windows\Temp\6959b247-8b24-4696-b32f-f7de9f1be85d\armsvc.exe 2014-12-23 18:27:23 27A9730A7AE1E6283CCFCE09E6F34F09 68384 ----a-w- C:\Windows\Temp\63d989f8-9859-46f0-8c65-d450bb054f3f\VSSVC.exe 2014-12-23 18:27:23 27A9730A7AE1E6283CCFCE09E6F34F09 68384 ----a-w- C:\Windows\Temp\58b75568-d6c6-4e15-a8c6-245b0d3f37f3\svchost.exe 2014-12-23 18:27:23 27A9730A7AE1E6283CCFCE09E6F34F09 68384 ----a-w- C:\Windows\Temp\535a56e5-d8df-43a1-9be7-8d1003765670\taskeng.exe 2014-12-23 18:27:23 27A9730A7AE1E6283CCFCE09E6F34F09 68384 ----a-w- C:\Windows\Temp\1a181ca2-ea1e-427f-a6dc-946f2eaf39a2\SearchIndexer.exe 2014-12-23 18:27:23 27A9730A7AE1E6283CCFCE09E6F34F09 68384 ----a-w- C:\Windows\Temp\1077719b-5d29-456f-b1f0-ce2a0332cf64\explorer.exe 2014-12-23 18:27:23 27A9730A7AE1E6283CCFCE09E6F34F09 68384 ----a-w- C:\Windows\Temp\0b6b48b9-1e4b-4fd4-9677-3f7d8aa61e7a\TuneUpUtilitiesService64.exe 2014-12-23 18:27:22 27A9730A7AE1E6283CCFCE09E6F34F09 68384 ----a-w- C:\Windows\Temp\e1549abe-edce-453e-b12e-424fa0061cb4\IMFsrv.exe 2014-12-23 18:27:22 27A9730A7AE1E6283CCFCE09E6F34F09 68384 ----a-w- C:\Windows\Temp\d97715de-d5f7-4ab6-8bd6-c9702b7b9246\svchost.exe 2014-12-23 18:27:22 27A9730A7AE1E6283CCFCE09E6F34F09 68384 ----a-w- C:\Windows\Temp\d0cf8baa-aca9-4172-a78a-a6a0574c68af\svchost.exe 2014-12-23 18:27:22 27A9730A7AE1E6283CCFCE09E6F34F09 68384 ----a-w- C:\Windows\Temp\c67b9ce3-50f0-4c96-b9dd-6635483e8c32\svchost.exe 2014-12-23 18:27:22 27A9730A7AE1E6283CCFCE09E6F34F09 68384 ----a-w- C:\Windows\Temp\9141116b-65e7-46a1-917e-17723f316540\svchost.exe 2014-12-23 18:27:22 27A9730A7AE1E6283CCFCE09E6F34F09 68384 ----a-w- C:\Windows\Temp\660b14a4-d60e-46b0-ac76-feeda6e8c13a\nvvsvc.exe 2014-12-23 18:27:22 27A9730A7AE1E6283CCFCE09E6F34F09 68384 ----a-w- C:\Windows\Temp\57378c40-d246-4f4a-b2a9-f3000ae9a984\spoolsv.exe 2014-12-23 18:27:22 27A9730A7AE1E6283CCFCE09E6F34F09 68384 ----a-w- C:\Windows\Temp\4bb8d9e4-1e94-4fb1-97fd-4f0e3555e5aa\svchost.exe 2014-12-23 18:27:22 27A9730A7AE1E6283CCFCE09E6F34F09 68384 ----a-w- C:\Windows\Temp\3a774b5b-4519-4ae9-9023-3207f7e7b67d\SLsvc.exe 2014-12-23 18:27:22 27A9730A7AE1E6283CCFCE09E6F34F09 68384 ----a-w- C:\Windows\Temp\2d34699b-a1fc-43ec-b11f-1a808a36c05e\audiodg.exe 2014-12-23 18:27:22 27A9730A7AE1E6283CCFCE09E6F34F09 68384 ----a-w- C:\Windows\Temp\1f766035-b118-47f7-8139-9ebd842c733c\afwServ.exe 2014-12-23 18:27:22 27A9730A7AE1E6283CCFCE09E6F34F09 68384 ----a-w- C:\Windows\Temp\0b9d290b-409d-4590-b81a-1dd485dbcfd5\taskeng.exe 2014-12-23 18:27:22 27A9730A7AE1E6283CCFCE09E6F34F09 68384 ----a-w- C:\Windows\Temp\0a0bba89-3139-4dc3-82d6-5e464d8e098c\svchost.exe 2014-12-23 18:27:22 27A9730A7AE1E6283CCFCE09E6F34F09 68384 ----a-w- C:\Windows\Temp\067ebb32-32ff-48b2-87e5-34591f4f88eb\AvastSvc.exe 2014-12-23 18:27:22 27A9730A7AE1E6283CCFCE09E6F34F09 68384 ----a-w- C:\Windows\Temp\0111a566-6d9c-463c-9d93-35f4eed6db31\nvxdsync.exe 2014-12-23 18:27:21 27A9730A7AE1E6283CCFCE09E6F34F09 68384 ----a-w- C:\Windows\Temp\b824e256-d0f4-4972-bbc2-c2d11bb91cd7\ASCService.exe 2014-12-23 18:27:21 27A9730A7AE1E6283CCFCE09E6F34F09 68384 ----a-w- C:\Windows\Temp\94b43e47-751f-4806-8f11-dd630b0a2253\csrss.exe 2014-12-23 18:27:21 27A9730A7AE1E6283CCFCE09E6F34F09 68384 ----a-w- C:\Windows\Temp\7e004f70-8dc9-4022-bbf9-00d44857fe96\nvvsvc.exe 2014-12-23 18:27:21 27A9730A7AE1E6283CCFCE09E6F34F09 68384 ----a-w- C:\Windows\Temp\7d72b464-a3ba-4b88-98ad-2c68de740cd0\services.exe 2014-12-23 18:27:21 27A9730A7AE1E6283CCFCE09E6F34F09 68384 ----a-w- C:\Windows\Temp\6f8be331-8872-4256-80ac-5940e38de23e\lsass.exe 2014-12-23 18:27:21 27A9730A7AE1E6283CCFCE09E6F34F09 68384 ----a-w- C:\Windows\Temp\6f618b8e-bfb9-4c96-87a7-0acaa72b63ae\svchost.exe 2014-12-23 18:27:21 27A9730A7AE1E6283CCFCE09E6F34F09 68384 ----a-w- C:\Windows\Temp\504432b1-1fba-450a-a58b-994f3a5eac8c\svchost.exe 2014-12-23 18:27:21 27A9730A7AE1E6283CCFCE09E6F34F09 68384 ----a-w- C:\Windows\Temp\30c7d509-9932-42b8-a9d2-5439c2276db9\lsm.exe 2014-12-23 18:27:21 27A9730A7AE1E6283CCFCE09E6F34F09 68384 ----a-w- C:\Windows\Temp\2cc4d9f9-18f3-414e-993d-fd1f882aadb1\svchost.exe 2014-12-23 18:27:21 27A9730A7AE1E6283CCFCE09E6F34F09 68384 ----a-w- C:\Windows\Temp\2910b9dd-bc76-4383-8bc1-ea74877dee9b\svchost.exe 2014-12-23 18:27:20 27A9730A7AE1E6283CCFCE09E6F34F09 68384 ----a-w- C:\Windows\Temp\8f8a56a1-7b51-4400-b978-463373b692cb\wininit.exe 2014-12-23 18:27:20 27A9730A7AE1E6283CCFCE09E6F34F09 68384 ----a-w- C:\Windows\Temp\6a5f1575-fc59-4454-9261-3179774a3c0d\csrss.exe 2014-12-23 18:27:20 27A9730A7AE1E6283CCFCE09E6F34F09 68384 ----a-w- C:\Windows\Temp\5e8bf57d-9945-4938-b3b4-b0c40e9f0c58\smss.exe 2014-12-23 16:10:53 FC3D936D8B4CD571FE4FFB1E929AF122 544 ----a-w- C:\$RECYCLE.BIN\S-1-5-21-3930024867-1471058179-2470722348-1000\$IU96A2A.exe 2014-12-23 15:03:19 D9C385D878FDC0912441E37045D04D5D 547227 ----a-w- C:\Program Files\Fotoservice\Kruidvat fotoservice\uninstall.exe 2014-12-23 15:01:37 630D75210B325A280C3352F879297ED5 5718872 ----a-w- C:\Program Files\Fotoservice\Kruidvat fotoservice\vcredist2010_x64.exe 2014-12-23 15:01:36 DB0EDDCB0F28BFB7CED8B5CFCA462346 19968 ----a-w- C:\Program Files\Fotoservice\Kruidvat fotoservice\facedetection.exe 2014-12-23 15:01:33 9CE5B727EA51E8089D0A30A4091210B6 1484800 ----a-w- C:\Program Files\Fotoservice\Kruidvat fotoservice\Fotoshow.exe 2014-12-23 15:01:33 64C61255BC1479ED5DFB8AE750352FE7 7412224 ----a-w- C:\Program Files\Fotoservice\Kruidvat fotoservice\Kruidvat fotoservice.exe 2014-12-23 15:01:33 0E16028AF061B5387FFC533FDF2DD959 422912 ----a-w- C:\Program Files\Fotoservice\Kruidvat fotoservice\Fotoimporteerder.exe 2014-12-23 14:55:23 341C33928D21143FC73E682B11A165EA 1558568 ----a-w- C:\Film Downloads\Voor Tom\Setup Kruidvat fotoservice\setup_Kruidvat_fotoservice.exe 2014-12-23 14:53:28 13F1C8D902C3D8FC9B3D9C951F406B7B 544 ----a-w- C:\$RECYCLE.BIN\S-1-5-21-3930024867-1471058179-2470722348-1000\$I7B54PZ.exe 2014-12-22 13:26:16 341C33928D21143FC73E682B11A165EA 1558568 ----a-w- C:\$RECYCLE.BIN\S-1-5-21-3930024867-1471058179-2470722348-1000\$R7B54PZ.exe 2014-12-22 13:25:36 341C33928D21143FC73E682B11A165EA 1558568 ----a-w- C:\$RECYCLE.BIN\S-1-5-21-3930024867-1471058179-2470722348-1000\$RU96A2A.exe 2014-12-21 11:46:26 6B110E925294547A7D288F26DA19D199 179687 ----a-w- C:\Windows\4941BFEB62C047A2801E998FC469CC2C.TMP\WiseCustomCalla18.exe 2014-12-21 11:41:24 6B110E925294547A7D288F26DA19D199 179687 ----a-w- C:\Windows\AF54923662584AC6A0435B5B89C6EB61.TMP\WiseCustomCalla18.exe 2014-12-21 11:40:09 AE8CD7DFA4C4A62C1DE136ABB8615473 180905 ----a-w- C:\Windows\4941BFEB62C047A2801E998FC469CC2C.TMP\WiseCustomCalla21.exe 2014-12-20 08:30:16 2349274E327CAC32501C93AE37E16B48 180934 ----a-w- C:\Windows\AF54923662584AC6A0435B5B89C6EB61.TMP\WiseCustomCalla21.exe 2014-12-19 09:14:41 4DE5DFF9018E26DADE9090049800A805 524288 ------w- C:\Users\Peter\AppData\Local\Package Cache\{c77cb28d-ddd3-46f7-b51a-14a599127ba7}\VASCOSmartCardReaderPlugin.exe === C: other files == 2014-12-24 14:32:51 A29030FB93B2E48EDD124749881406CE 943211 ----a-w- C:\Users\Peter\AppData\Local\Temp\sysspec\SysSpec.zip 2014-12-23 20:35:44 A1B1BC6A14B437C82AC830116979E9F6 979699 ----a-w- C:\Users\Peter\AppData\Roaming\Mozilla\Firefox\Profiles\xpty6wgq.default-1419366784337\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi 2014-12-23 20:33:09 A24624807D91E77E06EEB016D4C2D053 1443602 ----a-w- C:\$RECYCLE.BIN\S-1-5-21-3930024867-1471058179-2470722348-1000\$RHPBCH8\dvrrk3bc.default-1416771273902\extensions\firefox@ghostery.com.xpi 2014-12-23 20:33:09 A1B1BC6A14B437C82AC830116979E9F6 979699 ----a-w- C:\$RECYCLE.BIN\S-1-5-21-3930024867-1471058179-2470722348-1000\$RHPBCH8\dvrrk3bc.default-1416771273902\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi 2014-12-23 18:55:25 AEDA62DF045DD85955566E2C37E629DA 544 ----a-w- C:\$RECYCLE.BIN\S-1-5-21-3930024867-1471058179-2470722348-1000\$IEPI9IJ.zip 2014-12-23 14:55:17 16135FA730C7DD4EDC09B1A8C806784B 10216770 ----a-w- C:\Users\Peter\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\33RXVD7Q\38-svgtemplates-5.1.7_16135fa730c7dd4edc09b1a8c806784b[1].zip 2014-12-23 14:55:17 16135FA730C7DD4EDC09B1A8C806784B 10216770 ----a-w- C:\Film Downloads\Voor Tom\Setup Kruidvat fotoservice\38-svgtemplates-5.1.7_16135fa730c7dd4edc09b1a8c806784b.zip 2014-12-23 14:55:07 3C565D28CB24EB0B6F926FB88E8B12DF 11315979 ----a-w- C:\Users\Peter\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FXL7Y2YI\38-svgcalendars-5.1.7_3c565d28cb24eb0b6f926fb88e8b12df[1].zip 2014-12-23 14:55:07 3C565D28CB24EB0B6F926FB88E8B12DF 11315979 ----a-w- C:\Film Downloads\Voor Tom\Setup Kruidvat fotoservice\38-svgcalendars-5.1.7_3c565d28cb24eb0b6f926fb88e8b12df.zip 2014-12-23 14:54:58 EE9C818B70E620B7FF5714D88CDB26C5 15356670 ----a-w- C:\Users\Peter\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\A8OWF4WW\38-backgrounds-5.1.7_ee9c818b70e620b7ff5714d88cdb26c5[1].zip 2014-12-23 14:54:58 EE9C818B70E620B7FF5714D88CDB26C5 15356670 ----a-w- C:\Film Downloads\Voor Tom\Setup Kruidvat fotoservice\38-backgrounds-5.1.7_ee9c818b70e620b7ff5714d88cdb26c5.zip 2014-12-23 14:54:51 3F2086AA3939A991BA12282159C519AD 8970988 ----a-w- C:\Users\Peter\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X00X6HL1\38-decorations-5.1.7_3f2086aa3939a991ba12282159c519ad[1].zip 2014-12-23 14:54:51 3F2086AA3939A991BA12282159C519AD 8970988 ----a-w- C:\Film Downloads\Voor Tom\Setup Kruidvat fotoservice\38-decorations-5.1.7_3f2086aa3939a991ba12282159c519ad.zip 2014-12-23 14:54:47 86EFA27E1DD1C8CF15168616DE1CDD92 6222676 ----a-w- C:\Users\Peter\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\33RXVD7Q\38-photofun-5.1.7_86efa27e1dd1c8cf15168616de1cdd92[1].zip 2014-12-23 14:54:47 86EFA27E1DD1C8CF15168616DE1CDD92 6222676 ----a-w- C:\Film Downloads\Voor Tom\Setup Kruidvat fotoservice\38-photofun-5.1.7_86efa27e1dd1c8cf15168616de1cdd92.zip 2014-12-23 14:54:40 405EA250FDC7D1D3B6DAD16D86C11DDA 12136575 ----a-w- C:\Users\Peter\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FXL7Y2YI\38-startscreen-5.1.7_405ea250fdc7d1d3b6dad16d86c11dda[1].zip 2014-12-23 14:54:39 405EA250FDC7D1D3B6DAD16D86C11DDA 12136575 ----a-w- C:\Film Downloads\Voor Tom\Setup Kruidvat fotoservice\38-startscreen-5.1.7_405ea250fdc7d1d3b6dad16d86c11dda.zip 2014-12-23 14:54:31 FEB366D41CBBF635D5A3E3E071007020 13207614 ----a-w- C:\Users\Peter\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\A8OWF4WW\38-resources-5.1.7_feb366d41cbbf635d5a3e3e071007020[1].zip 2014-12-23 14:54:31 FEB366D41CBBF635D5A3E3E071007020 13207614 ----a-w- C:\Film Downloads\Voor Tom\Setup Kruidvat fotoservice\38-resources-5.1.7_feb366d41cbbf635d5a3e3e071007020.zip 2014-12-23 14:54:01 3BD94FB2768CEF4561E2B2ABED0EB5AD 48916830 ----a-w- C:\Users\Peter\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X00X6HL1\38-dll64-5.1.7_3bd94fb2768cef4561e2b2abed0eb5ad[1].zip 2014-12-23 14:54:01 3BD94FB2768CEF4561E2B2ABED0EB5AD 48916830 ----a-w- C:\Film Downloads\Voor Tom\Setup Kruidvat fotoservice\38-dll64-5.1.7_3bd94fb2768cef4561e2b2abed0eb5ad.zip 2014-12-23 14:53:32 F66A33C42C4883A5969FF66B866C8356 48280818 ----a-w- C:\Users\Peter\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\33RXVD7Q\38-dll-5.1.7_f66a33c42c4883a5969ff66b866c8356[1].zip 2014-12-23 14:53:31 F66A33C42C4883A5969FF66B866C8356 48280818 ----a-w- C:\Film Downloads\Voor Tom\Setup Kruidvat fotoservice\38-dll-5.1.7_f66a33c42c4883a5969ff66b866c8356.zip 2014-12-23 14:53:28 D2F15EEC27727C6B67A7850A22442CB0 3892124 ----a-w- C:\Users\Peter\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FXL7Y2YI\38-cewe64-5.1.7_d2f15eec27727c6b67a7850a22442cb0[1].zip 2014-12-23 14:53:28 D2F15EEC27727C6B67A7850A22442CB0 3892124 ----a-w- C:\Film Downloads\Voor Tom\Setup Kruidvat fotoservice\38-cewe64-5.1.7_d2f15eec27727c6b67a7850a22442cb0.zip 2014-12-23 14:53:24 17F188FA486364F52AB275226002F914 3398517 ----a-w- C:\Users\Peter\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\A8OWF4WW\38-cewe-5.1.7_17f188fa486364f52ab275226002f914[1].zip 2014-12-23 14:53:23 17F188FA486364F52AB275226002F914 3398517 ----a-w- C:\Film Downloads\Voor Tom\Setup Kruidvat fotoservice\38-cewe-5.1.7_17f188fa486364f52ab275226002f914.zip 2014-12-17 21:49:02 6D7C904CDE8ECBFA8577B1DCEF921761 33372 ----a-w- C:\$RECYCLE.BIN\S-1-5-21-3930024867-1471058179-2470722348-1000\$REPI9IJ.zip ======== System Restore Points ======== RP1043: 10/12/2014 3:23:02 - Windows Update RP1044: 10/12/2014 5:26:11 - Windows Update RP1045: 10/12/2014 20:16:55 - Gepland herstelpunt RP1046: 16/12/2014 13:25:08 - Windows Update RP1047: 17/12/2014 7:56:13 - Gepland herstelpunt RP1048: 18/12/2014 15:44:21 - Gepland herstelpunt RP1049: 19/12/2014 12:36:02 - IObit Uninstaller restore point RP1050: 20/12/2014 9:30:20 - Installed SpyHunter RP1051: 21/12/2014 10:57:20 - Gepland herstelpunt RP1052: 21/12/2014 12:40:12 - Installed SpyHunter RP1053: 21/12/2014 13:02:38 - Removed SpyHunter RP1054: 21/12/2014 14:11:40 - Removed SpyHunter RP1055: 23/12/2014 9:06:22 - Gepland herstelpunt RP1056: 23/12/2014 11:41:22 - Windows Update RP1057: 23/12/2014 19:21:39 - Driver Booster : Unity Web Player RP1058: 23/12/2014 19:25:35 - Installed Microsoft Fix it 50655 RP1059: 24/12/2014 9:35:21 - Gepland herstelpunt RP1060: 24/12/2014 14:53:57 - zoek.exe restore point ==== Startup Registry Enabled ====================== [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run] "WindowsWelcomeCenter"="rundll32.exe oobefldr.dll,ShowWelcomeCenter" "Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /detectMem" [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run] "WindowsWelcomeCenter"="rundll32.exe oobefldr.dll,ShowWelcomeCenter" "Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /detectMem" [HKEY_USERS\S-1-5-21-3930024867-1471058179-2470722348-1000\Software\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe /autoRun" "ehTray.exe"="C:\Windows\ehome\ehTray.exe" "LightScribe Control Panel"="C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden " "Akamai NetSession Interface"="C:\Users\Peter\AppData\Local\Akamai\netsession_win.exe " "CCleaner Monitoring"="C:\Program Files\CCleaner\CCleaner64.exe /MONITOR" "CCleaner"="C:\Program Files\CCleaner\CCleaner64.exe /AUTO" "Uploader"="C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\Seagate.Dashboard.Uploader.exe " "SmartRAM"="C:\Program Files (x86)\IObit\Advanced SystemCare 7\Suo10_SmartRAM.exe /m" "Adobe Reader Synchronizer"="C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AdobeCollabSync.exe" "Advanced SystemCare 8"="C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASCTray.exe /Auto" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "hpsysdrv"="c:\program files (x86)\hewlett-packard\HP odometer\hpsysdrv.exe" "KBD"="C:\Program Files (x86)\Hewlett-Packard\KBD\KbdStub.EXE" "OsdMaestro"="c:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD64.exe" "UpdateP2GoShortCut"="c:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe c:\Program Files (x86)\CyberLink\Power2Go UpdateWithCreateOnce SOFTWARE\CyberLink\Power2Go\6.0 " "UpdateLBPShortCut"="c:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe c:\Program Files (x86)\CyberLink\LabelPrint UpdateWithCreateOnce Software\CyberLink\LabelPrint\2.5 " "UpdatePDIRShortCut"="c:\Program Files (x86)\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe c:\Program Files (x86)\CyberLink\PowerDirector UpdateWithCreateOnce SOFTWARE\CyberLink\PowerDirector\7.0 " "UpdatePSTShortCut"="c:\Program Files (x86)\CyberLink\CyberLink DVD Suite Premium\MUITransfer\MUIStartMenu.exe c:\Program Files (x86)\CyberLink\CyberLink DVD Suite Premium UpdateWithCreateOnce Software\CyberLink\PowerStarter " "TSMAgent"="c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe" "CLMLServer for HP TouchSmart"="c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe" "DVDAgent"="c:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe" "NBAgent"="C:\Program Files (x86)\Nero\Nero 10\Nero BackItUp\NBAgent.exe /WinStart " "BCSSync"="C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe /DelayServices" "DBAgent"="C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\DBAgent.exe /WinStart " "AVG_UI"="C:\Program Files (x86)\AVG\AVG2014\avgui.exe /TRAYONLY" "AvastUI.exe"="C:\Program Files\AVAST Software\Avast\AvastUI.exe /nogui" "AgentMonitor"="C:\Program Files (x86)\VTech\DownloadManager\System\AgentMonitor.exe" "ControlCenter3"="C:\Program Files (x86)\Brother\ControlCenter3\brctrcen.exe /autorun" "IObit Malware Fighter"="C:\Program Files (x86)\IObit\IObit Malware Fighter\IMF.exe /autostart" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe /autoRun" "ehTray.exe"="C:\Windows\ehome\ehTray.exe" "LightScribe Control Panel"="C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden " "Akamai NetSession Interface"="C:\Users\Peter\AppData\Local\Akamai\netsession_win.exe " "CCleaner Monitoring"="C:\Program Files\CCleaner\CCleaner64.exe /MONITOR" "CCleaner"="C:\Program Files\CCleaner\CCleaner64.exe /AUTO" "Uploader"="C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\Seagate.Dashboard.Uploader.exe " "SmartRAM"="C:\Program Files (x86)\IObit\Advanced SystemCare 7\Suo10_SmartRAM.exe /m" "Adobe Reader Synchronizer"="C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AdobeCollabSync.exe" "Advanced SystemCare 8"="C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASCTray.exe /Auto" ==== Startup Registry Enabled x64 ====================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "OsdMaestro"="C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD64.exe" "IAAnotif"="C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe " "RTHDVCPL"="C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s" "Windows Defender"="%ProgramFiles%\Windows Defender\MSASCui.exe -hide" "SmartMenu"="C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe" ==== Startup Registry Disabled ====================== [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run-] "HP Health Check Scheduler"="\"c:\\Program Files (x86)\\Hewlett-Packard\\HP Health Check\\HPHC_Scheduler.exe\"" "HP Software Update"="\"C:\\Program Files (x86)\\HP\\HP Software Update\\HPWuSchd2.exe\"" "Adobe ARM"="\"C:\\Program Files (x86)\\Common Files\\Adobe\\ARM\\1.0\\AdobeARM.exe\"" ==== Startup Registry Disabled x64 ====================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Users^Peter^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^lollipop.lnk] "backup"="C:\\Windows\\pss\\lollipop.lnk.Startup" "backupExtension"=".Startup" "item"="lollipop" ==== Task Scheduler Jobs ====================== C:\Windows\tasks\Adobe Flash Player Updater.job --a------ C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [16/12/2014 23:23] C:\Windows\tasks\HPCeeScheduleForPeter.job --a------ C:\Program Files (x86)\hewlett-packard\sdp\ceement\HPCEE.exe [24/02/2009 17:17] C:\Windows\tasks\PCDRScheduledMaintenance.job --a------ C:\Program Files\PC-Doctor for Windows\pcdr5cuiw32.exe [02/02/2009 19:59] ==== Other Scheduled Tasks ====================== "C:\Windows\SysNative\tasks\Adobe Flash Player Updater" [C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe] "C:\Windows\SysNative\tasks\Adobe online update program" [C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe] "C:\Windows\SysNative\tasks\Adobe-online actualiseringsprogramma" [C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe] "C:\Windows\SysNative\tasks\ASC7_PerformanceMonitor" [C:\Program Files (x86)\IObit\Advanced SystemCare 7\Monitor.exe] "C:\Windows\SysNative\tasks\ASC7_SkipUac_Peter" ["C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASC.exe" /SkipUac] "C:\Windows\SysNative\tasks\ASC8_PerformanceMonitor" [C:\Program Files (x86)\IObit\Advanced SystemCare 8\Monitor.exe] "C:\Windows\SysNative\tasks\ASC8_SkipUac_Peter" ["C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASC.exe" /SkipUac] "C:\Windows\SysNative\tasks\CCleanerSkipUAC" ["C:\Program Files\CCleaner\CCleaner.exe"] "C:\Windows\SysNative\tasks\CreateChoiceProcessTask" [C:\Windows\System32\browserchoice.exe] "C:\Windows\SysNative\tasks\Driver Booster Scan" [C:\Program Files (x86)\IObit\Driver Booster\Scheduler.exe] "C:\Windows\SysNative\tasks\Driver Booster SkipUAC (Peter)" [C:\Program Files (x86)\IObit\Driver Booster\DriverBooster.exe] "C:\Windows\SysNative\tasks\Driver Booster SkipUAC (SYSTEEM)" [C:\Program Files (x86)\IObit\Driver Booster\DriverBooster.exe] "C:\Windows\SysNative\tasks\Driver Booster Update" [C:\Program Files (x86)\IObit\Driver Booster\AutoUpdate.exe] "C:\Windows\SysNative\tasks\FGRun" [C:\Users\Peter\AppData\Roaming\pack.exe] "C:\Windows\SysNative\tasks\Hewlett-Packard online update program" [c:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe] "C:\Windows\SysNative\tasks\HP Health Check" ["c:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe"] "C:\Windows\SysNative\tasks\HP online update program" [c:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe] "C:\Windows\SysNative\tasks\HP-Online updateprogramma" [C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe] "C:\Windows\SysNative\tasks\HPCeeScheduleForPeter" [C:\Program Files (x86)\hewlett-packard\sdp\ceement\HPCEE.exe] "C:\Windows\SysNative\tasks\Java Update Scheduler" [C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe] "C:\Windows\SysNative\tasks\PCDRScheduledMaintenance" [C:\Program Files\PC-Doctor for Windows\pcdr5cuiw32.exe] "C:\Windows\SysNative\tasks\Peter DBAgent 2 0" ["C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\DBAgent.exe"] "C:\Windows\SysNative\tasks\RecoveryCD" ["C:\Program Files (x86)\Hewlett-Packard\HP TCS\RemEngine.exe"] "C:\Windows\SysNative\tasks\ScanSoft Background Update" [C:\Program Files (x86)\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe] "C:\Windows\SysNative\tasks\Seagate_Install_Launch" [C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\Dashboard.exe] "C:\Windows\SysNative\tasks\SmartDefrag3_Startup" [C:\Program Files (x86)\IObit\Smart Defrag 3\SmartDefrag.exe] "C:\Windows\SysNative\tasks\SmartDefrag3_Update" [C:\Program Files (x86)\IObit\Smart Defrag 3\AutoUpdate.exe] "C:\Windows\SysNative\tasks\TuneUpUtilities_Task_BkGndMaintenance2013" [C:\Program Files (x86)\AVG\AVG PC TuneUp\OneClick.exe] "C:\Windows\SysNative\tasks\Uninstaller_SkipUac_Administrator" [C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe] "C:\Windows\SysNative\tasks\Uninstaller_SkipUac_Peter" [C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe] "C:\Windows\SysNative\tasks\Norton Management\Norton Error Analyzer" [C:\Program Files (x86)\Norton Management\Engine\3.2.0.19\SymErr.exe] "C:\Windows\SysNative\tasks\Norton Management\Norton Error Processor" [C:\Program Files (x86)\Norton Management\Engine\3.2.0.19\SymErr.exe] "C:\Windows\SysNative\tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask" [%systemroot%\system32\sc.exe start osppsvc] ==== Firefox Start and Search pages ====================== ProfilePath: C:\Users\Peter\AppData\Roaming\Mozilla\Firefox\Profiles\xpty6wgq.default-1419366784337 user_pref("browser.startup.homepage", "http://www.google.be"); user_pref("browser.search.selectedEngine", "Google"); ==== Firefox Extensions Registry ====================== [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions] "belgiumeid@eid.belgium.be"="C:\Program Files\Mozilla Firefox\extensions\belgiumeid@eid.belgium.be" [] ==== Firefox Extensions ====================== ProfilePath: C:\Users\Peter\AppData\Roaming\Mozilla\Firefox\Profiles\xpty6wgq.default-1419366784337 - Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF - Undetermined - wrc@avast.com - Adblock Plus - %ProfilePath%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi AppDir: C:\Program Files (x86)\Mozilla Firefox - Belgium eID - %AppDir%\extensions\belgiumeid@eid.belgium.be - Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} ==== Firefox Plugins ====================== Profilepath: C:\Users\Peter\AppData\Roaming\Mozilla\Firefox\Profiles\xpty6wgq.default-1419366784337 424899266BA430CCE5DDB6C1B4BE1B99 - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_235.dll - Shockwave Flash 5950D438CD3DDF2DD50D9FA4E07A6C1C - C:\Users\Peter\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll - Unity Player CAF78E18A9E1380A0A38065B3B1210E0 - C:\Users\Peter\AppData\Roaming\VASCO\VascoCardReaderPlugin\3.2.3.4\npVascoCardReaderPlugin.dll - VASCO Card Reader Plugin AB87EEFFD18F2BAAFC274E7075EA6C67 - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll - Windows Presentation Foundation / Windows Presentation Foundation 1CDD28B47D8198F868349BDFBCD1281B - C:\Users\Peter\AppData\Roaming\VASCO\VascoCardReaderPlugin\3.2.3.4\npVascoCardReaderPlugin64.dll - VASCO Card Reader Plugin ==== Chromium Look ====================== HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions gomekmidlodglbbmalcneegieacbdmki - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx[19/11/2014 05:57] Ebay Shopping Assistant by Spigot - Peter\AppData\Local\Chromium\User Data\Default\Extensions\hbcennhacfaagdopikcegfcobcadeocj Domain Error Assistant - Peter\AppData\Local\Chromium\User Data\Default\Extensions\icdlfehblmklkikfigmjhbmmpmkmpooj Slick Savings - Peter\AppData\Local\Chromium\User Data\Default\Extensions\mhkaekfpcppmmioggniknbnbdbcigpkk Google Wallet - Peter\AppData\Local\Chromium\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda Amazon Shopping Assistant by Spigot - Peter\AppData\Local\Chromium\User Data\Default\Extensions\pfndaklgolladniicklehhancnlgocpp Advanced SystemCare Surfing Protection - Peter\AppData\Local\Google\Chrome\User Data\Default\Extensions\bbmegnmpleoagolcnjnejdacakedpcgd Ads Removal - Peter\AppData\Local\Google\Chrome\User Data\Default\Extensions\fopdddcinljmpmioaklghcalngfhbaen Advanced SystemCare Surfing Protection - Peter\AppData\Local\Google\Chrome\User Data\Default\Extensions\nfengeggddojhakldhlpjdlddgkkjkdd Google Wallet - Peter\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda ==== Chromium Fix ====================== C:\Users\Peter\AppData\Local\Chromium\User Data\Default\Extensions\icdlfehblmklkikfigmjhbmmpmkmpooj deleted successfully C:\Users\Peter\AppData\Local\Google\Chrome\User Data\Default\Extensions\fopdddcinljmpmioaklghcalngfhbaen deleted successfully C:\Users\Peter\AppData\Local\Chromium\User Data\Default\Extensions\hbcennhacfaagdopikcegfcobcadeocj deleted successfully C:\Users\Peter\AppData\Local\Chromium\User Data\Default\Extensions\pfndaklgolladniicklehhancnlgocpp deleted successfully C:\Users\Peter\AppData\Local\Chromium\User Data\Default\Extensions\mhkaekfpcppmmioggniknbnbdbcigpkk deleted successfully ==== Set IE to Default ====================== Old Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://www.google.com" "Search Page"="http://www.google.com" "Search Bar"="http://www.google.com" "Use Search Asst"="yes" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl] "(Default)"="http://search.msn.com/results.asp?q=%s" "Default"="www.google.com" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search] "Default_Search_URL"="http://www.google.com" "SearchAssistant"="http://www.google.com" New Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896" "Search Bar"="http://go.microsoft.com/fwlink/?LinkId=54896" "Start Page"="http://www.google.com" "Use Search Asst"="no" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl] "(Default)"="http://search.msn.com/results.asp?q=%s" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search] "Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896" "SearchAssistant"="http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm" ==== All HKCU SearchScopes ====================== HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" {012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}" {0633EE93-D776-472f-A0FF-E1416B8B2E3A} @ieframe.dll,-12512 Url="http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC" {6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}" ==== Reset Google Chrome ====================== C:\Users\Peter\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully C:\Users\Peter\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully ==== Deleting CLSID Registry Keys ====================== ==== Deleting CLSID Registry Values ====================== ==== shortcuts on Users Desktops ====================== C:\Users\Peter\Desktop\Ashampoo Burning Studio 12 Compact Mode.lnk - C:\Program Files (x86)\Ashampoo\Ashampoo Burning Studio 12\burningstudio12.exe -compact C:\Users\Peter\Desktop\Ashampoo Burning Studio 12.lnk - C:\Program Files (x86)\Ashampoo\Ashampoo Burning Studio 12\burningstudio12.exe C:\Users\Peter\Desktop\Ashampoo Burning Studio 2009.lnk - C:\Program Files (x86)\Ashampoo\Ashampoo Burning Studio 2009\burningstudio.exe C:\Users\Peter\Desktop\Ashampoo Photo Optimizer 5.lnk - C:\Program Files (x86)\Portable\Ashampoo Photo Optimizer 5 v5.4.0\Photooptimizer.exe C:\Users\Peter\Desktop\Comical.lnk - C:\Program Files (x86)\Comical\Comical.exe C:\Users\Peter\Desktop\ConvertXtoDVD 4.lnk - C:\Program Files (x86)\VSO\ConvertX\4\ConvertXtoDvd.exe C:\Users\Peter\Desktop\DVDFAB 9.0.6.5..lnk - C:\Program Files (x86)\DVDFab 9\DVDFab.exe C:\Users\Peter\Desktop\E-mail - Snelkoppeling.lnk - C:\Users\Peter\Desktop\Microsoft Office (2010).lnk - C:\Windows\Installer\{90140000-0011-0000-0000-0000000FF1CE}\oisicon.exe C:\Users\Peter\Desktop\Seagate Dashboard 2.0.lnk - C:\Windows\Installer\{43C423D9-E6D6-4607-ADC9-EBB54F690C57}\ScDashBoardDesktop_942064A30E474CC8BCA1C6511C4CD457.exe C:\Users\Peter\Desktop\Should I Remove It.lnk - C:\Program Files (x86)\Reason\Should I Remove It\ShouldIRemoveIt.exe C:\Users\Peter\Desktop\Shows Desktop.lnk - C:\Users\Peter\Desktop\Start Unlocker.lnk - C:\Program Files\Unlocker\Unlocker.exe C:\Users\UpdatusUser\Desktop\Comical.lnk - C:\Program Files (x86)\Comical\Comical.exe ==== shortcuts on All Users Desktop ====================== C:\Users\Public\Desktop\Adobe Reader X .lnk - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AcroRd32.exe C:\Users\Public\Desktop\Advanced SystemCare 8.lnk - C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASC.exe /manual C:\Users\Public\Desktop\Avast Internet Security.lnk - C:\Program Files\AVAST Software\Avast\avastui.exe C:\Users\Public\Desktop\Avast SafeZone.lnk - C:\Program Files\AVAST Software\Avast\avastui.exe /sfzonebrowser C:\Users\Public\Desktop\AVG 1-klik Onderhoud.lnk - C:\Program Files (x86)\AVG\AVG PC TuneUp\OneClick.exe C:\Users\Public\Desktop\AVG PC TuneUp 2014.lnk - C:\Program Files (x86)\AVG\AVG PC TuneUp\Integrator.exe C:\Users\Public\Desktop\Brother Creative Center.lnk - C:\Program Files (x86)\Brother\CreativeCenter\Brother Creative Center.url C:\Users\Public\Desktop\CCleaner.lnk - C:\Program Files\CCleaner\CCleaner64.exe C:\Users\Public\Desktop\Driver Booster 2.lnk - C:\Program Files (x86)\IObit\Driver Booster\DriverBooster.exe C:\Users\Public\Desktop\eID Viewer.lnk - C:\Program Files (x86)\Belgium Identity Card\EidViewer\eID Viewer.exe C:\Users\Public\Desktop\Explor@ Park.lnk - C:\Program Files (x86)\VTech\DownloadManager\System\AgentMonitor.exe lauch C:\Users\Public\Desktop\Fotoshow.lnk - C:\Program Files\Fotoservice\Kruidvat fotoservice\Fotoshow.exe C:\Users\Public\Desktop\GOM Player.lnk - C:\Program Files (x86)\GRETECH\GomPlayer\GOM.exe C:\Users\Public\Desktop\Help and Support.lnk - C:\Users\Public\Desktop\HP MediaSmart.lnk - c:\Windows\Installer\{D2E8F543-D23A-4A38-AFFC-4BDEBFBA6FDA}\_2F0AA623FDE06A97508B91.exe C:\Users\Public\Desktop\Internetbrowser selecteren.lnk - C:\Windows\System32\browserchoice.exe /launch C:\Users\Public\Desktop\IObit Malware Fighter.lnk - C:\Program Files (x86)\IObit\IObit Malware Fighter\IMF.exe C:\Users\Public\Desktop\IObit Uninstaller.lnk - C:\Program Files (x86)\IObit\IObit Uninstaller\Uninstaler_SkipUac.exe C:\Users\Public\Desktop\Kruidvat fotoservice.lnk - C:\Program Files\Fotoservice\Kruidvat fotoservice\Kruidvat fotoservice.exe C:\Users\Public\Desktop\LightScribe.lnk - C:\Program Files (x86)\Common Files\LightScribe\LSLauncher.exe C:\Users\Public\Desktop\Magic Desktop.lnk - C:\Program Files (x86)\EasyBits For Kids\ezSecShield.exe C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe C:\Users\Public\Desktop\Medieval CUE Splitter.lnk - C:\Program Files (x86)\Medieval Software\Medieval CUE Splitter\CUE_Splitter.exe C:\Users\Public\Desktop\Mozilla Firefox.lnk - C:\Program Files (x86)\Mozilla Firefox\firefox.exe C:\Users\Public\Desktop\Nero BackItUp 10.lnk - C:\Windows\Installer\{68AB6930-5BFF-4FF6-923B-516A91984FE6}\BackItUp._AB9F1F47710540918A47B78D2BED5DAD.exe C:\Users\Public\Desktop\Nero Burning ROM 10.lnk - C:\Windows\Installer\{7A5D731D-B4B3-490E-B339-75685712BAAB}\ScBurningROMStartM_7533AE23D677474387D2A66427FA7052.exe C:\Users\Public\Desktop\Nero MediaHub 10.lnk - C:\Windows\Installer\{1F7FB68F-52F6-46A3-B42F-38CE46295AE5}\NeroMediaHub._63C8A7B0BBE5459F9AC436392B2FF50D.exe C:\Users\Public\Desktop\Nero StartSmart 10.lnk - C:\Windows\Installer\{F61D489E-6C44-49AC-AD02-7DA8ACA73A65}\ScStartSmartDeskto_3AF47A4E14DF4546B1449D27245505A0.exe C:\Users\Public\Desktop\Nero Vision 10.lnk - C:\Windows\Installer\{9A4297F3-2A51-4ED9-92CA-4BCB8380947E}\NewShortcut1_28CF345AD4354131AA47B77D4165D813.exe C:\Users\Public\Desktop\OpenOffice 4.1.1.lnk - C:\Program Files (x86)\OpenOffice 4\program\soffice.exe C:\Users\Public\Desktop\Play HP Games.lnk - C:\Program Files (x86)\HP Games\onplay\onplay.exe "C:\Program Files (x86)\HP Games\HP Game Console\GameConsole-wt.exe" /src desktopoem C:\Users\Public\Desktop\Smart Defrag 3.lnk - C:\Program Files (x86)\IObit\Smart Defrag 3\SmartDefrag.exe C:\Users\Public\Desktop\VLC media player.lnk - C:\Program Files (x86)\VideoLAN\VLC\vlc.exe ==== shortcuts in All Users Start Menu ====================== C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X .lnk - C:\Windows\Installer\{AC76BA86-7AD7-1043-7B44-AA1000000001}\SC_Reader.ico C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced SystemCare 8\Advanced SystemCare 8.lnk - C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASC.exe /manual C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced SystemCare 8\Protect.lnk - C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASC.exe /Protect C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced SystemCare 8\Toolbox.lnk - C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASC.exe /toolbox C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced SystemCare 8\Turbo Boost.lnk - C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASC.exe /turboboost C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced SystemCare 8\Verwijder Advanced SystemCare.lnk - C:\Program Files (x86)\IObit\Advanced SystemCare 8\unins000.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software\Avast SafeZone.lnk - C:\Program Files\AVAST Software\Avast\avastui.exe /sfzonebrowser C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Belgium - eID\eID Viewer.lnk - C:\Program Files (x86)\Belgium Identity Card\EidViewer\eID Viewer.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Belgium - eID\Utilities\MS Office 2010 XAdES XL signature configuration.lnk - C:\Program Files (x86)\Belgium Identity Card\beidoffice2010_XAdES_XL.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Belgium - eID\Utilities\MS Outlook registry configuration.lnk - C:\Program Files (x86)\Belgium Identity Card\beidoutlooksnc.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Brother\DCP-195C\ControlCenter3.lnk - C:\Program Files (x86)\Brother\ControlCenter3\BrCtrCen.exe /Model=DCP-195C C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Brother\DCP-195C\Installatie Diagnose.lnk - C:\Program Files (x86)\Brother\Brmfl08k\Brinstck.exe DCP-195C C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Brother\DCP-195C\Installatie ongedaan maken.lnk - C:\Program Files (x86)\InstallShield Installation Information\{6BF66AED-3EA4-4106-B240-5CE96C9B76B0}\setup.exe -runfromtemp -l0x0013 UNINSTALL Reg=BH9e_C1,Brother DCP-195C,USB C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Brother\DCP-195C\Lees Mij.lnk - C:\Program Files (x86)\Brother\Brmfl08k\RM08bDut.rtf C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Brother\DCP-195C\On line registratie.lnk - C:\Program Files (x86)\Brother\Brmfl08k\Brolink\Brolink0.exe OLR_URL /mDCP-195C C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Brother\DCP-195C\Instellingen Scanner\Lees Mij.lnk - C:\Program Files (x86)\Brother\Brmfl08k\ScanRead.txt C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Brother\DCP-195C\Instellingen Scanner\Scanner Toepassing.lnk - C:\Program Files (x86)\Brother\Brmfl08k\BrScUtil.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Driver Booster 2\Driver Booster 2.lnk - C:\Program Files (x86)\IObit\Driver Booster\DriverBooster.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Driver Booster 2\Verwijder Driver Booster 2.lnk - C:\Program Files (x86)\IObit\Driver Booster\unins000.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ffdshow x64\Audio decoder configuration x64.lnk - C:\Windows\System32\rundll32.exe "C:\Program Files\KLCP64\ffdshow\ffdshow.ax",configureAudio C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ffdshow x64\DXVA Video decoder configuration x64.lnk - C:\Windows\System32\rundll32.exe "C:\Program Files\KLCP64\ffdshow\ffdshow.ax",configureDXVA C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ffdshow x64\Uninstall ffdshow.lnk - C:\Program Files\KLCP64\ffdshow\unins000.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ffdshow x64\VFW configuration x64.lnk - C:\Windows\System32\rundll32.exe "C:\Windows\system32\ff_vfw.dll",configureVFW C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ffdshow x64\Video decoder configuration x64.lnk - C:\Windows\System32\rundll32.exe "C:\Program Files\KLCP64\ffdshow\ffdshow.ax",configure C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IObit Malware Fighter\IObit Malware Fighter.lnk - C:\Program Files (x86)\IObit\IObit Malware Fighter\IMF.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IObit Malware Fighter\Verwijder IObit Malware Fighter.lnk - C:\Program Files (x86)\IObit\IObit Malware Fighter\unins000.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IObit Uninstaller\Help.lnk - C:\Program Files (x86)\IObit\IObit Uninstaller\help.html C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IObit Uninstaller\IObit Uninstaller.lnk - C:\Program Files (x86)\IObit\IObit Uninstaller\Uninstaler_SkipUac.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IObit Uninstaller\Uninstall IObit Uninstaller.lnk - C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallDisplay.exe uninstall_start C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\About Java.lnk - C:\Program Files (x86)\Java\jre7\bin\javacpl.exe -tab about C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\Check For Updates.lnk - C:\Program Files (x86)\Java\jre7\bin\javacpl.exe -tab update C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\Configure Java.lnk - C:\Program Files (x86)\Java\jre7\bin\javacpl.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\Get Help.lnk - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\Visit Java.com.lnk - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack x64\Quick Codec Config.lnk - C:\Program Files\KLCP64\Tools\CodecTweakTool.exe /showsections=audio_config,various_tweaks,filter_config,dsfilter_management,sourcefilters C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack x64\Configuration\DirectVobSub (x64).lnk - C:\Windows\system32\rundll32.exe "C:\Program Files\KLCP64\Filters\vsfilter.dll",DirectVobSub C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack x64\Configuration\ffdshow audio decoder (x64).lnk - C:\Windows\system32\rundll32.exe "C:\Program Files\KLCP64\ffdshow\ffdshow.ax",configureAudio C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack x64\Configuration\ffdshow DXVA video decoder (x64).lnk - C:\Windows\system32\rundll32.exe "C:\Program Files\KLCP64\ffdshow\ffdshow.ax",configureDXVA C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack x64\Configuration\ffdshow VFW interface (x64).lnk - C:\Windows\system32\rundll32.exe "C:\Windows\system32\ff_vfw.dll",configureVFW C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack x64\Configuration\ffdshow video decoder (x64).lnk - C:\Windows\system32\rundll32.exe "C:\Program Files\KLCP64\ffdshow\ffdshow.ax",configure C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack x64\Help\FAQ.lnk - C:\Program Files\KLCP64\Info\faq.htm C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack x64\Tools\Codec Tweak Tool.lnk - C:\Program Files\KLCP64\Tools\CodecTweakTool.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack x64\Tools\GraphStudio (x64).lnk - C:\Program Files\KLCP64\Tools\GraphStudio64.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack x64\Uninstall\Uninstall K-Lite Codec Pack x64.lnk - C:\Program Files\KLCP64\unins000.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kruidvat fotoservice\Fotoshow.lnk - C:\Program Files\Fotoservice\Kruidvat fotoservice\Fotoshow.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kruidvat fotoservice\Kruidvat fotoservice Uninstall.lnk - C:\Program Files\Fotoservice\Kruidvat fotoservice\uninstall.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kruidvat fotoservice\Kruidvat fotoservice.lnk - C:\Program Files\Fotoservice\Kruidvat fotoservice\Kruidvat fotoservice.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware\Malwarebytes Anti-Malware.lnk - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware\Verwijder Malwarebytes Anti-Malware.lnk - C:\Program Files (x86)\Malwarebytes Anti-Malware\unins000.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware\Tools\Malwarebytes Anti-Malware Chameleon.lnk - C:\Program Files (x86)\Malwarebytes Anti-Malware\Chameleon\Windows\chameleon.chm C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight\Microsoft Silverlight.lnk - C:\Program Files (x86)\Microsoft Silverlight\5.1.31211.0\Silverlight.Configuration.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 5 Toolkit December 2011\Binaries.lnk - C:\Program Files (x86)\Microsoft SDKs\Silverlight\v5.0\Toolkit\dec11\Bin C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 5 Toolkit December 2011\Documentation.lnk - C:\Program Files (x86)\Microsoft SDKs\Silverlight\v5.0\Toolkit\dec11\Documentation.chm C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 5 Toolkit December 2011\Sample Source Code.lnk - C:\Program Files (x86)\Microsoft SDKs\Silverlight\v5.0\Toolkit\dec11\Source C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 5 Toolkit December 2011\Silverlight Toolkit on CodePlex.lnk - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 5 Toolkit December 2011\Silverlight.net Discussions.lnk - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 5 Toolkit December 2011\Source Code.lnk - C:\Program Files (x86)\Microsoft SDKs\Silverlight\v5.0\Toolkit\dec11\Source C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 5 Toolkit December 2011\Welcome.lnk - C:\Program Files (x86)\Microsoft SDKs\Silverlight\v5.0\Toolkit\dec11\Welcome.htm C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenOffice 4.1.1\OpenOffice Base.lnk - C:\Program Files (x86)\OpenOffice 4\program\sbase.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenOffice 4.1.1\OpenOffice Calc.lnk - C:\Program Files (x86)\OpenOffice 4\program\scalc.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenOffice 4.1.1\OpenOffice Draw.lnk - C:\Program Files (x86)\OpenOffice 4\program\sdraw.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenOffice 4.1.1\OpenOffice Impress.lnk - C:\Program Files (x86)\OpenOffice 4\program\simpress.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenOffice 4.1.1\OpenOffice Math.lnk - C:\Program Files (x86)\OpenOffice 4\program\smath.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenOffice 4.1.1\OpenOffice Writer.lnk - C:\Program Files (x86)\OpenOffice 4\program\swriter.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenOffice 4.1.1\OpenOffice.lnk - C:\Program Files (x86)\OpenOffice 4\program\soffice.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Smart Defrag 3\Smart Defrag 3.lnk - C:\Program Files (x86)\IObit\Smart Defrag 3\SmartDefrag.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Smart Defrag 3\Verwijder Smart Defrag 3.lnk - C:\Program Files (x86)\IObit\Smart Defrag 3\unins000.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN\Documentation.lnk - C:\Program Files (x86)\VideoLAN\VLC\Documentation.url C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN\Release Notes.lnk - C:\Program Files (x86)\VideoLAN\VLC\NEWS.txt C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN\Reset VLC media player preferences and cache files.lnk - C:\Program Files (x86)\VideoLAN\VLC\vlc.exe --reset-config --reset-plugins-cache vlc://quit C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN\VideoLAN Website.lnk - C:\Program Files (x86)\VideoLAN\VLC\VideoLAN Website.url C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN\VLC media player - reset preferences and cache files.lnk - C:\Program Files (x86)\VideoLAN\VLC\vlc.exe --reset-config --reset-plugins-cache vlc://quit C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN\VLC media player skinned.lnk - C:\Program Files (x86)\VideoLAN\VLC\vlc.exe -Iskins C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN\VLC media player.lnk - C:\Program Files (x86)\VideoLAN\VLC\vlc.exe ==== shortcuts in Quick Launch ====================== C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\HP MediaSmart.lnk - c:\Windows\Installer\{D2E8F543-D23A-4A38-AFFC-4BDEBFBA6FDA}\_BD15A4BF3888028F418EC7.exe C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk - C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk - C:\Users\Default User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\HP MediaSmart.lnk - c:\Windows\Installer\{D2E8F543-D23A-4A38-AFFC-4BDEBFBA6FDA}\_BD15A4BF3888028F418EC7.exe C:\Users\Default User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk - C:\Users\Default User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk - C:\Users\Peter\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Advanced SystemCare 8.lnk - C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASC.exe /manual C:\Users\Peter\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Ashampoo Burning Studio 2009.lnk - C:\Program Files (x86)\Ashampoo\Ashampoo Burning Studio 2009\burningstudio.exe C:\Users\Peter\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\AVG PC TuneUp 2014.lnk - C:\Program Files (x86)\AVG\AVG PC TuneUp\Integrator.exe C:\Users\Peter\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\ConvertXtoDVD 4.lnk - C:\Program Files (x86)\VSO\ConvertX\4\ConvertXtoDvd.exe C:\Users\Peter\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Driver Booster 2.lnk - C:\Program Files (x86)\IObit\Driver Booster\DriverBooster.exe C:\Users\Peter\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\DVDFab 9.lnk - C:\Program Files (x86)\DVDFab 9\DVDFab.exe C:\Users\Peter\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\GOM Player.lnk - C:\Program Files (x86)\GRETECH\GomPlayer\GOM.exe C:\Users\Peter\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\HP MediaSmart.lnk - c:\Windows\Installer\{D2E8F543-D23A-4A38-AFFC-4BDEBFBA6FDA}\_BD15A4BF3888028F418EC7.exe C:\Users\Peter\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\IObit Malware Fighter.lnk - C:\Program Files (x86)\IObit\IObit Malware Fighter\IMF.exe C:\Users\Peter\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\IObit Unlocker.lnk - C:\Program Files (x86)\IObit\IObit Unlocker\IObitUnlocker.exe C:\Users\Peter\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk - C:\Program Files\Internet Explorer\iexplore.exe C:\Users\Peter\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk - C:\Program Files (x86)\Mozilla Firefox\firefox.exe C:\Users\Peter\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Smart Defrag 3.lnk - C:\Program Files (x86)\IObit\Smart Defrag 3\SmartDefrag.exe C:\Users\Peter\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk - C:\Users\Peter\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk - C:\Program Files (x86)\Windows Media Player\wmplayer.exe /prefetch:1 C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\GOM Player.lnk - C:\Program Files (x86)\GRETECH\GomPlayer\GOM.exe C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\HP MediaSmart.lnk - c:\Windows\Installer\{D2E8F543-D23A-4A38-AFFC-4BDEBFBA6FDA}\_BD15A4BF3888028F418EC7.exe C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk - C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk - ==== Uninstall List x64 ====================== Activation Assistant for the 2007 Microsoft Office suites [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{65DA2EC9-0642-47E9-AAE2-B5267AA14D75}] Adobe AIR [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{7BBAEC47-1CC0-4CB8-ADB4-531B78DBD1DD}] Adobe AIR [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Adobe AIR] Adobe Flash Player 16 ActiveX [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Adobe Flash Player ActiveX] Adobe Flash Player 16 NPAPI [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Adobe Flash Player NPAPI] Adobe Flash Player Packages [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Adobe Flash Player Packages] Adobe Reader X (10.1.13) - Nederlands [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{AC76BA86-7AD7-1043-7B44-AA1000000001}] Advanced SystemCare 8 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Advanced SystemCare 8_is1] Akamai NetSession Interface [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Akamai] Avast Internet Security [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Avast] Belgium e-ID middleware 4.0.7 (build 7453) [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{824563DE-75AD-4166-9DC0-B6482F207453}] Brother MFL-Pro Suite DCP-195C [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{6BF66AED-3EA4-4106-B240-5CE96C9B76B0}] Driver Booster 2 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Driver Booster_is1] ffdshow x64 v1.3.4531 [2014-06-28] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\ffdshow64_is1] IObit Malware Fighter [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\IObit Malware Fighter_is1] IObit Uninstaller [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\IObitUninstall] K-Lite Codec Pack (64-bit) v4.6.0 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\KLiteCodecPack64_is1] Kruidvat fotoservice [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Kruidvat fotoservice] Malwarebytes Anti-Malware versie 2.0.4.1028 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Malwarebytes Anti-Malware_is1] Microsoft .NET Framework 3.5 Language Pack SP1 - nld [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{101738D7-D805-37A9-BB91-1F2C351782BF}] Microsoft .NET Framework 3.5 SP1 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}] Microsoft .NET Framework 4.5.1 (Nederlands) [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1043] Microsoft .NET Framework 4.5.1 (NLD) [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{9EBB0AF2-4AD2-3ABA-95EF-977EBEA1CB09}] Microsoft .NET Framework 4.5.1 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{7DEBE4EB-6B40-3766-BB35-5CBBC385DA37}] Microsoft .NET Framework 4.5.1 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033] Microsoft Office Professional Plus 2010 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Office14.PROPLUS] Microsoft Silverlight [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}] Microsoft Silverlight 5 Toolkit December 2011 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{EC35EE8E-87D1-4E3E-B5CC-D8B1544615F5}] Microsoft SQL Server 2005 Compact Edition [ENU] [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}] Microsoft Visual C++ 2005 Redistributable (x64) [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{071c9b48-7c32-4621-a0ac-3f809523288f}] Microsoft Visual C++ 2005 Redistributable (x64) [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}] Microsoft Visual C++ 2005 Redistributable (x64) [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{6E8E85E8-CE4B-4FF5-91F7-04999C9FAE6A}] Microsoft Visual C++ 2005 Redistributable (x64) [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}] Microsoft Visual C++ 2005 Redistributable [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}] Microsoft Visual C++ 2005 Redistributable [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}] Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{350AA351-21FA-3270-8B7A-835434E766AD}] Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{4FFA2088-8317-3B14-93CD-4C699DB37843}] Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{8220EEFE-38CD-377E-8595-13398D740ACE}] Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}] Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}] Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}] Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{6AFCA4E1-9B78-3640-8F72-A7BF33448200}] Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{9A25302D-30C0-39D9-BD6F-21E6EC160475}] Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}] Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{9BE518E6-ECC6-35A9-88E4-87755C07200F}] Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}] Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}] Microsoft Works [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{5158F1F5-FA1B-4D49-B546-55A5004B89BD}] Mozilla Firefox 34.0.5 (x86 nl) [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Mozilla Firefox 34.0.5 (x86 nl)] MyFreeCodec [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\MyFreeCodec] NVIDIA PhysX [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{B455E95A-B804-439F-B533-336B1635AE97}] OpenOffice 4.1.1 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{89FD914D-4472-4E4F-8638-69E857E82DC9}] Should I Remove It [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Should I Remove It 1.0.4] Smart Defrag 3 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Smart Defrag 3_is1] Stuurprogrammapakket voor Windows - Fedict SmartCard (03/25/2014 4.0.7.4) [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\B02255EDA75F867B4D85C5A5D23E13D9EF71E8AE] Surfing Protection [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\IObit Surfing Protection_is1] Unity Web Player [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\UnityWebPlayer] VASCO Card Reader Plug-In (64-Bit) [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{47659F12-27AE-6400-9B8A-2BD803020304}] VASCO Smart Card Reader Plug-In (User) [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\{c77cb28d-ddd3-46f7-b51a-14a599127ba7}] Visual Studio 2008 x64 Redistributables [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{FCDBEA60-79F0-4FAE-BBA8-55A26C609A49}] Visual Studio 2010 x64 Redistributables [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{21B133D6-5979-47F0-BE1C-F6A6B304693F}] Visual Studio 2012 x64 Redistributables [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}] Visual Studio 2012 x86 Redistributables [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}] VLC media player [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\VLC media player] VSO ConvertXToDVD [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{CE1F93C0-4353-4C9D-84DA-AB4E7C63ED32}_is1] Windows Live Communications Platform [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{D45240D3-B6B3-4FF9-B243-54ECE3E10066}] Windows Live Essentials [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{2A07C35B-8384-4DA4-9A95-442B6C89A073}] Windows Live Essentials [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\WinLiveSuite] Windows Live Family Safety [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{46A5FBE9-ADB3-4493-A1CC-B4CFFD24D26A}] Windows Live Family Safety [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{B22C8566-D522-4B40-A7AF-525F5A70D832}] Windows Live ID Sign-in Assistant [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{1B8ABA62-74F0-47ED-B18C-A43128E591B8}] Windows Live Installer [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{0B0F231F-CE6A-483D-AA23-77B364F75917}] Windows Live Language Selector [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{5EB6F3CB-46F4-451F-A028-7F6D8D35D7D0}] Windows Live Mail [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{9D56775A-93F3-44A3-8092-840E3826DE30}] Windows Live Mail [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{D588365A-AE39-4F27-BDAE-B4E72C8E900C}] Windows Live Mesh - ActiveX-besturingselement voor externe verbindingen [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{C32CE55C-12BA-4951-8797-0967FDEF556F}] Windows Live Mesh [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{3F4143A1-9C21-4011-8679-3BC1014C6886}] Windows Live Mesh [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{DECDCB7C-58CC-4865-91AF-627F9798FE48}] Windows Live Messenger Companion Core [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{78A96B4C-A643-4D0F-98C2-A8E16A6669F9}] Windows Live MIME IFilter [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{DA54F80E-261C-41A2-A855-549A144F2F59}] Windows Live Movie Maker [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{92EA4134-10D1-418A-91E1-5A0453131A38}] Windows Live Movie Maker [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{CB7224D9-6DCA-43F1-8F83-6B1E39A00F92}] Windows Live Photo Common [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{9BD262D0-B788-4546-A0A5-F4F56EC3834B}] Windows Live Photo Common [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}] Windows Live Photo Gallery [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{3336F667-9049-4D46-98B6-4C743EEBC5B1}] Windows Live Photo Gallery [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{A60B3BF0-954B-42AF-B8D8-2C1D34B613AA}] Windows Live PIMT Platform [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{4CBABDFD-49F8-47FD-BE7D-ECDE7270525A}] Windows Live Remote Client [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{DF6D988A-EEA0-4277-AAB8-158E086E439B}] Windows Live Remote Client Resources [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{C9F05151-95A9-4B9B-B534-1760E2D014A5}] Windows Live Remote Service [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{E02A6548-6FDE-40E2-8ED9-119D7D7E641F}] Windows Live Remote Service Resources [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{6CBFDC3C-CF21-4C02-A6DC-A5A2707FAF55}] Windows Live SOXE [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{682B3E4F-696A-42DE-A41C-4C07EA1678B4}] Windows Live SOXE Definitions [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{200FEC62-3C34-4D60-9CE8-EC372E01C08F}] Windows Live Sync [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{E34F703A-1C9D-4B1F-ABBE-D7E8800B860D}] Windows Live UX Platform [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}] Windows Live UX Platform Language Pack [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{0BE5C4DB-8EA2-483D-BD71-D7EB09040CDE}] Windows Live Writer [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{7E017923-16F8-4E32-94EF-0A150BD196FE}] Windows Live Writer [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{A726AE06-AAA3-43D1-87E3-70F510314F04}] Windows Live Writer [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}] Windows Live Writer Resources [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{14B441B7-774D-4170-98EA-A13667AE6218}] ==== Deleting Registry Keys ====================== HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\19363A2B9A3A3924882B8A62E37C8F56 deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dashboard.exe deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kiesagent.exe deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\lightscribecontrolpanel.exe deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\lslauncher.exe deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\powerstarter.exe deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\setup.exe deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\shell.exe deleted successfully HKEY_CURRENT_USER\Software\Microsoft\Installer\Products\5FF261C146D90F54BB6902845EB93D66 deleted successfully ==== HijackThis Entries ====================== O1 - Hosts: ::1 localhost O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~2\Office14\URLREDIR.DLL O2 - BHO: Advanced SystemCare Surfing Protection - {BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} - C:\PROGRA~2\IObit\SURFIN~1\BROWER~1\ASCPLU~1.DLL O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll O4 - HKLM\..\Run: [hpsysdrv] c:\program files (x86)\hewlett-packard\HP odometer\hpsysdrv.exe O4 - HKLM\..\Run: [KBD] C:\Program Files (x86)\Hewlett-Packard\KBD\KbdStub.EXE O4 - HKLM\..\Run: [OsdMaestro] c:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD64.exe O4 - HKLM\..\Run: [UpdateP2GoShortCut] "c:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "c:\Program Files (x86)\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0" O4 - HKLM\..\Run: [UpdateLBPShortCut] "c:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" "c:\Program Files (x86)\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.5" O4 - HKLM\..\Run: [UpdatePDIRShortCut] "c:\Program Files (x86)\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe" "c:\Program Files (x86)\CyberLink\PowerDirector" UpdateWithCreateOnce "SOFTWARE\CyberLink\PowerDirector\7.0" O4 - HKLM\..\Run: [UpdatePSTShortCut] "c:\Program Files (x86)\CyberLink\CyberLink DVD Suite Premium\MUITransfer\MUIStartMenu.exe" "c:\Program Files (x86)\CyberLink\CyberLink DVD Suite Premium" UpdateWithCreateOnce "Software\CyberLink\PowerStarter" O4 - HKLM\..\Run: [TSMAgent] "c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe" O4 - HKLM\..\Run: [CLMLServer for HP TouchSmart] "c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe" O4 - HKLM\..\Run: [DVDAgent] "c:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe" O4 - HKLM\..\Run: [NBAgent] "C:\Program Files (x86)\Nero\Nero 10\Nero BackItUp\NBAgent.exe" /WinStart O4 - HKLM\..\Run: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices O4 - HKLM\..\Run: [DBAgent] "C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\DBAgent.exe" /WinStart O4 - HKLM\..\Run: [AVG_UI] "C:\Program Files (x86)\AVG\AVG2014\avgui.exe" /TRAYONLY O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui O4 - HKLM\..\Run: [AgentMonitor] "C:\Program Files (x86)\VTech\DownloadManager\System\AgentMonitor.exe" O4 - HKLM\..\Run: [ControlCenter3] "C:\Program Files (x86)\Brother\ControlCenter3\brctrcen.exe" /autorun O4 - HKLM\..\Run: [IObit Malware Fighter] "C:\Program Files (x86)\IObit\IObit Malware Fighter\IMF.exe" /autostart O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden O4 - HKCU\..\Run: [Akamai NetSession Interface] "C:\Users\Peter\AppData\Local\Akamai\netsession_win.exe" O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR O4 - HKCU\..\Run: [CCleaner] "C:\Program Files\CCleaner\CCleaner64.exe" /AUTO O4 - HKCU\..\Run: [Uploader] C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\Seagate.Dashboard.Uploader.exe O4 - HKCU\..\Run: [SmartRAM] "C:\Program Files (x86)\IObit\Advanced SystemCare 7\Suo10_SmartRAM.exe" /m O4 - HKCU\..\Run: [Adobe Reader Synchronizer] "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AdobeCollabSync.exe" O4 - HKCU\..\Run: [Advanced SystemCare 8] "C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASCTray.exe" /Auto O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE') O9 - Extra button: @C:\Program Files (x86)\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file) O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file) O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra button: Verzenden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll O9 - Extra 'Tools' menuitem: &Verzenden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll O9 - Extra button: &Gekoppelde notities van OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll O9 - Extra 'Tools' menuitem: &Gekoppelde notities van OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll O9 - Extra button: Site Finder - {CCC7B152-1D8C-11E3-B2AD-F3EF3D58318D} - (no file) O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Plugin Control) - http://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe O23 - Service: Advanced SystemCare Service 8 (AdvancedSystemCareService8) - IObit - C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASCService.exe O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing) O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe O23 - Service: avast! Firewall - AVAST Software - C:\Program Files\AVAST Software\Avast\afwServ.exe O23 - Service: AVG Firewall (avgfws) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2014\avgfws.exe O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\Windows\SysWOW64\brsvc01a.exe O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing) O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe O23 - Service: HP Easy Backup Button Service (HPBtnSrv) - Unknown owner - C:\Program Files (x86)\Hewlett-Packard\HP Easy Backup\HPBtnSrv.exe O23 - Service: IMF Service (IMFservice) - IObit - C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: LiveUpdate (LiveUpdateSvc) - IObit - C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing) O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing) O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - Unknown owner - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (file missing) O23 - Service: PandoraService (PanService) - Pandora.TV - C:\Program Files (x86)\PANDORA.TV\PanService\PandoraService.exe O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing) O23 - Service: Realtek Audio Service (RtkAudioService) - Realtek Semiconductor - C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing) O23 - Service: Print Spooler (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing) O23 - Service: AVG PC TuneUp Service (TuneUp.UtilitiesSvc) - AVG - C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing) O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing) O23 - Service: Volume Shadow Copy (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing) O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing) ==== Silent Runners ====================== "Silent Runners.vbs", revision 69.2, http://www.silentrunners.org/ Output limited to non-default values, except where indicated by "{++}" Startup items buried in registry: --------------------------------- HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ {++} Sidebar = C:\Program Files\Windows Sidebar\sidebar.exe /autoRun [MS] ehTray.exe = C:\Windows\ehome\ehTray.exe [MS] LightScribe Control Panel = C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden [Hewlett-Packard Company] Akamai NetSession Interface = "C:\Users\Peter\AppData\Local\Akamai\netsession_win.exe" [Akamai Technologies, Inc.] CCleaner Monitoring = "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR [Piriform Ltd] CCleaner = "C:\Program Files\CCleaner\CCleaner64.exe" /AUTO [Piriform Ltd] Uploader = C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\Seagate.Dashboard.Uploader.exe [null data] SmartRAM = "C:\Program Files (x86)\IObit\Advanced SystemCare 7\Suo10_SmartRAM.exe" /m [IObit] Adobe Reader Synchronizer = "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AdobeCollabSync.exe" [Adobe Systems Incorporated] Advanced SystemCare 8 = "C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASCTray.exe" /Auto [IObit] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++} Windows Defender = C:\Program Files\Windows Defender\MSASCui.exe -hide OsdMaestro = "C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD64.exe" [OsdMaestro] SmartMenu = C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe IAAnotif = "C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe" [Intel Corporation] RTHDVCPL = "C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s [Realtek Semiconductor] HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\ {++} hpsysdrv = c:\program files (x86)\hewlett-packard\HP odometer\hpsysdrv.exe [Hewlett-Packard] KBD = C:\Program Files (x86)\Hewlett-Packard\KBD\KbdStub.EXE [null data] OsdMaestro = c:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD64.exe [OsdMaestro] UpdateP2GoShortCut = "c:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "c:\Program Files (x86)\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0" [CyberLink Corp.] UpdateLBPShortCut = "c:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" "c:\Program Files (x86)\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.5" [CyberLink Corp.] UpdatePDIRShortCut = "c:\Program Files (x86)\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe" "c:\Program Files (x86)\CyberLink\PowerDirector" UpdateWithCreateOnce "SOFTWARE\CyberLink\PowerDirector\7.0" [CyberLink Corp.] UpdatePSTShortCut = "c:\Program Files (x86)\CyberLink\CyberLink DVD Suite Premium\MUITransfer\MUIStartMenu.exe" "c:\Program Files (x86)\CyberLink\CyberLink DVD Suite Premium" UpdateWithCreateOnce "Software\CyberLink\PowerStarter" [CyberLink Corp.] TSMAgent = "c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe" [CyberLink Corp.] CLMLServer for HP TouchSmart = "c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe" [CyberLink] DVDAgent = "c:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe" [CyberLink Corp.] NBAgent = "C:\Program Files (x86)\Nero\Nero 10\Nero BackItUp\NBAgent.exe" /WinStart [Nero AG] BCSSync = "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices [MS] DBAgent = "C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\DBAgent.exe" /WinStart [Seagate Technology LLC] (Default) = (empty string) [file not found] AVG_UI = "C:\Program Files (x86)\AVG\AVG2014\avgui.exe" /TRAYONLY [AVG Technologies CZ, s.r.o.] AvastUI.exe = "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui [AVAST Software] AgentMonitor = "C:\Program Files (x86)\VTech\DownloadManager\System\AgentMonitor.exe" [null data] ControlCenter3 = "C:\Program Files (x86)\Brother\ControlCenter3\brctrcen.exe" /autorun [Brother Industries, Ltd.] IObit Malware Fighter = "C:\Program Files (x86)\IObit\IObit Malware Fighter\IMF.exe" /autostart [IObit] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ {10921475-03CE-4E04-90CE-E2E7EF20C814}\(Default) = ExplorerWnd Helper -> {HKLM...CLSID} = ExplorerWnd Helper \InProcServer32\(Default) = C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer64.dll [IObit] {72853161-30C5-4D22-B7F9-0BBC1D38A37E}\(Default) = (no title provided) -> {HKLM...CLSID} = Groove GFS Browser Helper \InProcServer32\(Default) = C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [MS] -> {HKLM...Wow...CLSID} = Groove GFS Browser Helper \InProcServer32\(Default) = C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL [MS] {8E5E2654-AD2D-48bf-AC2D-D17F00898D06}\(Default) = avast! Online Security -> {HKLM...CLSID} = avast! Online Security \InProcServer32\(Default) = C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [AVAST Software] -> {HKLM...Wow...CLSID} = avast! Online Security \InProcServer32\(Default) = C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [AVAST Software] {B4F3A835-0E21-4959-BA22-42B3008E02FF}\(Default) = URLRedirectionBHO -> {HKLM...CLSID} = Office Document Cache Handler \InProcServer32\(Default) = C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL [MS] -> {HKLM...Wow...CLSID} = Office Document Cache Handler \InProcServer32\(Default) = C:\PROGRA~2\MICROS~2\Office14\URLREDIR.DLL [MS] HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ {72853161-30C5-4D22-B7F9-0BBC1D38A37E}\(Default) = (no title provided) -> {HKLM...CLSID} = Groove GFS Browser Helper \InProcServer32\(Default) = C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [MS] -> {HKLM...Wow...CLSID} = Groove GFS Browser Helper \InProcServer32\(Default) = C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL [MS] {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\(Default) = (no title provided) -> {HKLM...CLSID} = Java(tm) Plug-In SSV Helper \InProcServer32\(Default) = [file not found] -> {HKLM...Wow...CLSID} = Java(tm) Plug-In SSV Helper \InProcServer32\(Default) = C:\Program Files (x86)\Java\jre7\bin\ssv.dll [Oracle Corporation] {8E5E2654-AD2D-48bf-AC2D-D17F00898D06}\(Default) = avast! Online Security -> {HKLM...CLSID} = avast! Online Security \InProcServer32\(Default) = C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [AVAST Software] -> {HKLM...Wow...CLSID} = avast! Online Security \InProcServer32\(Default) = C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [AVAST Software] {B4F3A835-0E21-4959-BA22-42B3008E02FF}\(Default) = URLRedirectionBHO -> {HKLM...CLSID} = Office Document Cache Handler \InProcServer32\(Default) = C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL [MS] -> {HKLM...Wow...CLSID} = Office Document Cache Handler \InProcServer32\(Default) = C:\PROGRA~2\MICROS~2\Office14\URLREDIR.DLL [MS] {BA0C978D-D909-49B6-AFE2-8BDE245DC7E6}\(Default) = (no title provided) -> {HKLM...Wow...CLSID} = Advanced SystemCare Surfing Protection \InProcServer32\(Default) = C:\PROGRA~2\IObit\SURFIN~1\BROWER~1\ASCPLU~1.DLL [IObit] {DBC80044-A445-435b-BC74-9C25C1C588A9}\(Default) = (no title provided) -> {HKLM...CLSID} = Java(tm) Plug-In 2 SSV Helper \InProcServer32\(Default) = [file not found] -> {HKLM...Wow...CLSID} = Java(tm) Plug-In 2 SSV Helper \InProcServer32\(Default) = C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [Oracle Corporation] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ 00avast\(Default) = {472083B0-C522-11CF-8763-00608CC02F24} -> {HKLM...CLSID} = avast \InProcServer32\(Default) = C:\Program Files\AVAST Software\Avast\ashShA64.dll [AVAST Software] Groove Explorer Icon Overlay 1 (GFS Unread Stub)\(Default) = {99FD978C-D287-4F50-827F-B2C658EDA8E7} -> {HKLM...CLSID} = Groove Explorer Icon Overlay 1 (GFS Unread Stub) \InProcServer32\(Default) = C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [MS] Groove Explorer Icon Overlay 2 (GFS Stub)\(Default) = {AB5C5600-7E6E-4B06-9197-9ECEF74D31CC} -> {HKLM...CLSID} = Groove Explorer Icon Overlay 2 (GFS Stub) \InProcServer32\(Default) = C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [MS] Groove Explorer Icon Overlay 2.5 (GFS Unread Folder)\(Default) = {920E6DB1-9907-4370-B3A0-BAFC03D81399} -> {HKLM...CLSID} = Groove Explorer Icon Overlay 2.5 (GFS Unread Folder) \InProcServer32\(Default) = C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [MS] Groove Explorer Icon Overlay 3 (GFS Folder)\(Default) = {16F3DD56-1AF5-4347-846D-7C10C4192619} -> {HKLM...CLSID} = Groove Explorer Icon Overlay 3 (GFS Folder) \InProcServer32\(Default) = C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [MS] Groove Explorer Icon Overlay 4 (GFS Unread Mark)\(Default) = {2916C86E-86A6-43FE-8112-43ABE6BF8DCC} -> {HKLM...CLSID} = Groove Explorer Icon Overlay 4 (GFS Unread Mark) \InProcServer32\(Default) = C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [MS] HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ Groove Explorer Icon Overlay 1 (GFS Unread Stub)\(Default) = {99FD978C-D287-4F50-827F-B2C658EDA8E7} -> {HKLM...Wow...CLSID} = Groove Explorer Icon Overlay 1 (GFS Unread Stub) \InProcServer32\(Default) = C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL [MS] Groove Explorer Icon Overlay 2 (GFS Stub)\(Default) = {AB5C5600-7E6E-4B06-9197-9ECEF74D31CC} -> {HKLM...Wow...CLSID} = Groove Explorer Icon Overlay 2 (GFS Stub) \InProcServer32\(Default) = C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL [MS] Groove Explorer Icon Overlay 2.5 (GFS Unread Folder)\(Default) = {920E6DB1-9907-4370-B3A0-BAFC03D81399} -> {HKLM...Wow...CLSID} = Groove Explorer Icon Overlay 2.5 (GFS Unread Folder) \InProcServer32\(Default) = C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL [MS] Groove Explorer Icon Overlay 3 (GFS Folder)\(Default) = {16F3DD56-1AF5-4347-846D-7C10C4192619} -> {HKLM...Wow...CLSID} = Groove Explorer Icon Overlay 3 (GFS Folder) \InProcServer32\(Default) = C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL [MS] Groove Explorer Icon Overlay 4 (GFS Unread Mark)\(Default) = {2916C86E-86A6-43FE-8112-43ABE6BF8DCC} -> {HKLM...Wow...CLSID} = Groove Explorer Icon Overlay 4 (GFS Unread Mark) \InProcServer32\(Default) = C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL [MS] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\ {AE424E85-F6DF-4910-A6A9-438797986431} = OpenOffice Property Handler -> {HKLM...CLSID} = OpenOffice Property Handler \InProcServer32\(Default) = C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\propertyhdl_x64.dll [Apache Software Foundation] {0875DCB6-C686-4243-9432-ADCCF0B9F2D7} = Microsoft OneNote Namespace Extension for Windows Desktop Search -> {HKLM...CLSID} = Microsoft OneNote Namespace Extension for Windows Desktop Search \InProcServer32\(Default) = C:\Program Files\Microsoft Office\Office14\ONFILTER.DLL [MS] HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\ {640167b4-59b0-47a6-b335-a6b3c0695aea} = Portable Media Devices -> {HKLM...Wow...CLSID} = Portable Media Devices \InProcServer32\(Default) = C:\Windows\system32\audiodev.dll [file not found] {7F67036B-66F1-411A-AD85-759FB9C5B0DB} = ShellViewRTF -> {HKLM...Wow...CLSID} = ShellViewRTF \InProcServer32\(Default) = C:\Program Files (x86)\SMINST\ShellvRTF.dll [XSS] {c5aec3ec-e812-4677-a9a7-4fee1f9aa000} = Icaros Thumbnail Provider -> {HKLM...Wow...CLSID} = Icaros Thumbnail Provider \InProcServer32\(Default) = C:\Program Files (x86)\VistaCodecPack\Tools\IcarosThumbnailProvider.dll [Tabibito Technology] {00F33137-EE26-412F-8D71-F84E4C2C6625} = (no title provided) -> {HKLM...Wow...CLSID} = Windows Live Photo Gallery Viewer Autoplay Shim \InProcServer32\(Default) = C:\Program Files (x86)\Windows Live\Photo Gallery\PhotoViewerShim.dll [MS] {00F346CB-35A4-465B-8B8F-65A29DBAB1F6} = Windows Live Photo Gallery Viewer Drop Target Shim -> {HKLM...Wow...CLSID} = Windows Live Photo Gallery Viewer Shim \InProcServer32\(Default) = C:\Program Files (x86)\Windows Live\Photo Gallery\PhotoViewerShim.dll [MS] {00F3712A-CA79-45B4-9E4D-D7891E7F8B9D} = Windows Live Photo Gallery Editor Drop Target Shim -> {HKLM...Wow...CLSID} = Windows Live Photo Gallery Editor Shim \InProcServer32\(Default) = C:\Program Files (x86)\Windows Live\Photo Gallery\PhotoViewerShim.dll [MS] {00F30F90-3E96-453B-AFCD-D71989ECC2C7} = Windows Live Photo Gallery Autoplay Drop Target Shim -> {HKLM...Wow...CLSID} = Windows Live Photo Gallery Viewer Autoplay Shim \InProcServer32\(Default) = C:\Program Files (x86)\Windows Live\Photo Gallery\PhotoViewerShim.dll [MS] {F764812A-132C-4013-9960-5CBBEB408A0E} = Nero Shell Extension -> {HKLM...Wow...CLSID} = NeroShellExt Class \InProcServer32\(Default) = C:\Program Files (x86)\Common Files\Nero\NeroShellExt\\NeroShellExt.dll [Nero AG] {42042206-2D85-11D3-8CFF-005004838597} = Microsoft Office HTML Icon Handler -> {HKLM...Wow...CLSID} = (no title provided) \InProcServer32\(Default) = C:\Program Files (x86)\Microsoft Office\Office14\msohevi.dll [MS] {3D60EDA7-9AB4-4DA8-864C-D9B5F2E7281D} = Groove Namespace Extension -> {HKLM...Wow...CLSID} = Werkruimten \InProcServer32\(Default) = C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL [MS] {0875DCB6-C686-4243-9432-ADCCF0B9F2D7} = Microsoft OneNote Namespace Extension for Windows Desktop Search -> {HKLM...Wow...CLSID} = Microsoft OneNote Namespace Extension for Windows Desktop Search \InProcServer32\(Default) = C:\Program Files (x86)\Microsoft Office\Office14\ONFILTER.DLL [MS] {506F4668-F13E-4AA1-BB04-B43203AB3CC0} = {506F4668-F13E-4AA1-BB04-B43203AB3CC0} -> {HKLM...Wow...CLSID} = ImageExtractorShellExt Class \InProcServer32\(Default) = C:\Program Files (x86)\Microsoft Office\Office14\VISSHE.DLL [MS] {D66DC78C-4F61-447F-942B-3FB6980118CF} = {D66DC78C-4F61-447F-942B-3FB6980118CF} -> {HKLM...Wow...CLSID} = CInfoTipShellExt Class \InProcServer32\(Default) = C:\Program Files (x86)\Microsoft Office\Office14\VISSHE.DLL [MS] {72853161-30C5-4D22-B7F9-0BBC1D38A37E} = Groove GFS Browser Helper -> {HKLM...Wow...CLSID} = Groove GFS Browser Helper \InProcServer32\(Default) = C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL [MS] {6C467336-8281-4E60-8204-430CED96822D} = Groove GFS Context Menu Handler -> {HKLM...Wow...CLSID} = Groove GFS Context Menu Handler \InProcServer32\(Default) = C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL [MS] {2A541AE1-5BF6-4665-A8A3-CFA9672E4291} = Groove GFS Explorer Bar -> {HKLM...Wow...CLSID} = Groove Folder Synchronization \InProcServer32\(Default) = C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL [MS] {16F3DD56-1AF5-4347-846D-7C10C4192619} = Groove Explorer Icon Overlay 3 (GFS Folder) -> {HKLM...Wow...CLSID} = Groove Explorer Icon Overlay 3 (GFS Folder) \InProcServer32\(Default) = C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL [MS] {B5A7F190-DDA6-4420-B3BA-52453494E6CD} = Groove GFS Stub Execution Hook -> {HKLM...Wow...CLSID} = Groove GFS Stub Execution Hook \InProcServer32\(Default) = C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL [MS] {A449600E-1DC6-4232-B948-9BD794D62056} = Groove GFS Stub Icon Handler -> {HKLM...Wow...CLSID} = Groove GFS Stub Icon Handler \InProcServer32\(Default) = C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL [MS] {AB5C5600-7E6E-4B06-9197-9ECEF74D31CC} = Groove Explorer Icon Overlay 2 (GFS Stub) -> {HKLM...Wow...CLSID} = Groove Explorer Icon Overlay 2 (GFS Stub) \InProcServer32\(Default) = C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL [MS] {920E6DB1-9907-4370-B3A0-BAFC03D81399} = Groove Explorer Icon Overlay 2.5 (GFS Unread Folder) -> {HKLM...Wow...CLSID} = Groove Explorer Icon Overlay 2.5 (GFS Unread Folder) \InProcServer32\(Default) = C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL [MS] {2916C86E-86A6-43FE-8112-43ABE6BF8DCC} = Groove Explorer Icon Overlay 4 (GFS Unread Mark) -> {HKLM...Wow...CLSID} = Groove Explorer Icon Overlay 4 (GFS Unread Mark) \InProcServer32\(Default) = C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL [MS] {99FD978C-D287-4F50-827F-B2C658EDA8E7} = Groove Explorer Icon Overlay 1 (GFS Unread Stub) -> {HKLM...Wow...CLSID} = Groove Explorer Icon Overlay 1 (GFS Unread Stub) \InProcServer32\(Default) = C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL [MS] {387E725D-DC16-4D76-B310-2C93ED4752A0} = Groove XML Icon Handler -> {HKLM...Wow...CLSID} = Groove XML Icon Handler \InProcServer32\(Default) = C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL [MS] {00020D75-0000-0000-C000-000000000046} = Microsoft Outlook Desktop Icon Handler -> {HKLM...Wow...CLSID} = Microsoft Outlook \InProcServer32\(Default) = C:\PROGRA~2\MICROS~2\Office14\MLSHEXT.DLL [MS] {0006F045-0000-0000-C000-000000000046} = Microsoft Outlook Custom Icon Handler -> {HKLM...Wow...CLSID} = Outlook File Icon Extension \InProcServer32\(Default) = C:\Program Files (x86)\Microsoft Office\Office14\OLKFSTUB.DLL [MS] {23170F69-40C1-278A-1000-000100020000} = 7-Zip Shell Extension -> {HKLM...Wow...CLSID} = 7-Zip Shell Extension \InProcServer32\(Default) = C:\Program Files (x86)\7-Zip\7-zip.dll [Igor Pavlov] {4858E7D9-8E12-45a3-B6A3-1CD128C9D403} = AVG Shredder Shell Extension -> {HKLM...Wow...CLSID} = AVG Shredder Shell Extension \InProcServer32\(Default) = C:\Program Files (x86)\AVG\AVG PC TuneUp\SDShelEx-win32.dll [AVG] {4838CD50-7E5D-4811-9B17-C47A85539F28} = AVG Disk Space Explorer Shell Extension -> {HKLM...Wow...CLSID} = AVG Disk Space Explorer Shell Extension \InProcServer32\(Default) = C:\Program Files (x86)\AVG\AVG PC TuneUp\DseShExt-x86.dll [AVG] {9F97547E-4609-42C5-AE0C-81C61FFAEBC3} = AVG Shell Extension -> {HKLM...Wow...CLSID} = AVG Shell Extension Class \InProcServer32\(Default) = C:\Program Files (x86)\AVG\AVG2014\avgse.dll [AVG Technologies CZ, s.r.o.] {472083B0-C522-11CF-8763-00608CC02F24} = avast -> {HKLM...Wow...CLSID} = avast \InProcServer32\(Default) = C:\Program Files\AVAST Software\Avast\ashShell.dll [AVAST Software] {AE424E85-F6DF-4910-A6A9-438797986431} = OpenOffice Property Handler -> {HKLM...Wow...CLSID} = OpenOffice Property Handler \InProcServer32\(Default) = C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\propertyhdl.dll [Apache Software Foundation] {C52AF81D-F7A0-4AAB-8E87-F80A60CCD396} = OpenOffice Column Handler -> {HKLM...Wow...CLSID} = (no title provided) \InProcServer32\(Default) = C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\shlxthdl.dll [Apache Software Foundation] {087B3AE3-E237-4467-B8DB-5A38AB959AC9} = OpenOffice Infotip Handler -> {HKLM...Wow...CLSID} = (no title provided) \InProcServer32\(Default) = C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\shlxthdl.dll [Apache Software Foundation] {63542C48-9552-494A-84F7-73AA6A7C99C1} = OpenOffice Property Sheet Handler -> {HKLM...Wow...CLSID} = (no title provided) \InProcServer32\(Default) = C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\shlxthdl.dll [Apache Software Foundation] {3B092F0C-7696-40E3-A80F-68D74DA84210} = OpenOffice Thumbnail Viewer -> {HKLM...Wow...CLSID} = (no title provided) \InProcServer32\(Default) = C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\shlxthdl.dll [Apache Software Foundation] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\ <> {B5A7F190-DDA6-4420-B3BA-52453494E6CD} = Groove GFS Stub Execution Hook -> {HKLM...CLSID} = Groove GFS Stub Execution Hook \InProcServer32\(Default) = C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [MS] HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\ <> {B5A7F190-DDA6-4420-B3BA-52453494E6CD} = Groove GFS Stub Execution Hook -> {HKLM...CLSID} = Groove GFS Stub Execution Hook \InProcServer32\(Default) = C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [MS] HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ <> dashboard.exe\Debugger = "C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe" [AVG] <> kiesagent.exe\Debugger = "C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe" [AVG] <> lightscribecontrolpanel.exe\Debugger = "C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe" [AVG] <> lslauncher.exe\Debugger = "C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe" [AVG] <> powerstarter.exe\Debugger = "C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe" [AVG] <> setup.exe\Debugger = "C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe" [AVG] <> shell.exe\Debugger = "C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe" [AVG] HKLM\SOFTWARE\Classes\PROTOCOLS\Filter\ <> text/xml\CLSID = {807573E5-5146-11D5-A672-00B0D022E945} -> {HKLM...CLSID} = Microsoft Office InfoPath XML Mime Filter \InProcServer32\(Default) = C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL [MS] HKLM\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\ 7-Zip\(Default) = {23170F69-40C1-278A-1000-000100020000} -> {HKLM...Wow...CLSID} = 7-Zip Shell Extension \InProcServer32\(Default) = C:\Program Files (x86)\7-Zip\7-zip.dll [Igor Pavlov] Advanced SystemCare\(Default) = {2803063F-4B8D-4dc6-8874-D1802487FE2D} -> {HKLM...CLSID} = CExtMenu Class \InProcServer32\(Default) = C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASCExtMenu_64.dll [IObit] avast\(Default) = {472083B0-C522-11CF-8763-00608CC02F24} -> {HKLM...CLSID} = avast \InProcServer32\(Default) = C:\Program Files\AVAST Software\Avast\ashShA64.dll [AVAST Software] -> {HKLM...Wow...CLSID} = avast \InProcServer32\(Default) = C:\Program Files\AVAST Software\Avast\ashShell.dll [AVAST Software] AVG Shell Extension\(Default) = {9F97547E-4609-42C5-AE0C-81C61FFAEBC3} -> {HKLM...CLSID} = AVG Shell Extension Class \InProcServer32\(Default) = C:\Program Files (x86)\AVG\AVG2014\avgsea.dll [AVG Technologies CZ, s.r.o.] -> {HKLM...Wow...CLSID} = AVG Shell Extension Class \InProcServer32\(Default) = C:\Program Files (x86)\AVG\AVG2014\avgse.dll [AVG Technologies CZ, s.r.o.] AVG Shredder Shell Extension\(Default) = {4858E7D9-8E12-45a3-B6A3-1CD128C9D403} -> {HKLM...CLSID} = AVG Shredder Shell Extension \InProcServer32\(Default) = C:\Program Files (x86)\AVG\AVG PC TuneUp\SDShelEx-x64.dll [AVG] -> {HKLM...Wow...CLSID} = AVG Shredder Shell Extension \InProcServer32\(Default) = C:\Program Files (x86)\AVG\AVG PC TuneUp\SDShelEx-win32.dll [AVG] Explorer Context Menu\(Default) = {82C63EC5-1B4C-43B7-7AC8-57148B696B95} -> {HKLM...CLSID} = ? \InProcServer32\(Default) = mscoree.dll [MS] IObit Malware Fighter\(Default) = {0BB81440-5F42-4480-A5F7-770A6F439FC8} -> {HKLM...CLSID} = BlueBirdShell Class \InProcServer32\(Default) = C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFShellExt.dll [IObit] IObitUnstaler\(Default) = {B19ED566-D419-470b-B111-3C89040BC027} -> {HKLM...CLSID} = IObitUnstaler Class \InProcServer32\(Default) = C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallMenuRight64.dll [IObit] SmartDefragExtension\(Default) = {189F1E63-33A7-404B-B2F6-8C76A452CC54} -> {HKLM...CLSID} = SmartDefragExtension Class \InProcServer32\(Default) = C:\Windows\system32\IObitSmartDefragExtension.dll [IObit] UnLockerMenu\(Default) = {A6FF0E3A-8437-482C-8E04-4F9E15C57538} -> {HKLM...CLSID} = UnLockerMenu Class \InProcServer32\(Default) = C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallMenuRight64.dll [IObit] WinRAR\(Default) = {B41DB860-64E4-11D2-9906-E49FADC173CA} -> {HKLM...CLSID} = WinRAR \InProcServer32\(Default) = C:\Program Files\WinRAR\rarext.dll [Alexander Roshal] WinRAR32\(Default) = {B41DB860-8EE4-11D2-9906-E49FADC173CA} -> {HKLM...Wow...CLSID} = WinRAR \InProcServer32\(Default) = C:\Program Files\WinRAR\rarext32.dll [Alexander Roshal] XXX Groove GFS Context Menu Handler XXX\(Default) = {6C467336-8281-4E60-8204-430CED96822D} -> {HKLM...CLSID} = Groove GFS Context Menu Handler \InProcServer32\(Default) = C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [MS] -> {HKLM...Wow...CLSID} = Groove GFS Context Menu Handler \InProcServer32\(Default) = C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL [MS] {A4FD8DDB-5800-4414-97F9-7457AC8EE4F0}\(Default) = (no title provided) -> {HKLM...Wow...CLSID} = NBShellHook Class \InProcServer32\(Default) = C:\Program Files (x86)\Nero\Nero 10\Nero BackItUp\NBShell.dll [Nero AG] {F764812A-132C-4013-9960-5CBBEB408A0E}\(Default) = (no title provided) -> {HKLM...Wow...CLSID} = NeroShellExt Class \InProcServer32\(Default) = C:\Program Files (x86)\Common Files\Nero\NeroShellExt\\NeroShellExt.dll [Nero AG] HKLM\SOFTWARE\Classes\Wow6432Node\*\shellex\ContextMenuHandlers\ 7-Zip\(Default) = {23170F69-40C1-278A-1000-000100020000} -> {HKLM...Wow...CLSID} = 7-Zip Shell Extension \InProcServer32\(Default) = C:\Program Files (x86)\7-Zip\7-zip.dll [Igor Pavlov] Advanced SystemCare\(Default) = {2803063F-4B8D-4dc6-8874-D1802487FE2D} -> {HKLM...CLSID} = CExtMenu Class \InProcServer32\(Default) = C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASCExtMenu_64.dll [IObit] avast\(Default) = {472083B0-C522-11CF-8763-00608CC02F24} -> {HKLM...CLSID} = avast \InProcServer32\(Default) = C:\Program Files\AVAST Software\Avast\ashShA64.dll [AVAST Software] -> {HKLM...Wow...CLSID} = avast \InProcServer32\(Default) = C:\Program Files\AVAST Software\Avast\ashShell.dll [AVAST Software] AVG Shell Extension\(Default) = {9F97547E-4609-42C5-AE0C-81C61FFAEBC3} -> {HKLM...CLSID} = AVG Shell Extension Class \InProcServer32\(Default) = C:\Program Files (x86)\AVG\AVG2014\avgsea.dll [AVG Technologies CZ, s.r.o.] -> {HKLM...Wow...CLSID} = AVG Shell Extension Class \InProcServer32\(Default) = C:\Program Files (x86)\AVG\AVG2014\avgse.dll [AVG Technologies CZ, s.r.o.] AVG Shredder Shell Extension\(Default) = {4858E7D9-8E12-45a3-B6A3-1CD128C9D403} -> {HKLM...CLSID} = AVG Shredder Shell Extension \InProcServer32\(Default) = C:\Program Files (x86)\AVG\AVG PC TuneUp\SDShelEx-x64.dll [AVG] -> {HKLM...Wow...CLSID} = AVG Shredder Shell Extension \InProcServer32\(Default) = C:\Program Files (x86)\AVG\AVG PC TuneUp\SDShelEx-win32.dll [AVG] Explorer Context Menu\(Default) = {82C63EC5-1B4C-43B7-7AC8-57148B696B95} -> {HKLM...CLSID} = ? \InProcServer32\(Default) = mscoree.dll [MS] IObit Malware Fighter\(Default) = {0BB81440-5F42-4480-A5F7-770A6F439FC8} -> {HKLM...CLSID} = BlueBirdShell Class \InProcServer32\(Default) = C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFShellExt.dll [IObit] IObitUnstaler\(Default) = {B19ED566-D419-470b-B111-3C89040BC027} -> {HKLM...CLSID} = IObitUnstaler Class \InProcServer32\(Default) = C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallMenuRight64.dll [IObit] SmartDefragExtension\(Default) = {189F1E63-33A7-404B-B2F6-8C76A452CC54} -> {HKLM...CLSID} = SmartDefragExtension Class \InProcServer32\(Default) = C:\Windows\system32\IObitSmartDefragExtension.dll [IObit] UnLockerMenu\(Default) = {A6FF0E3A-8437-482C-8E04-4F9E15C57538} -> {HKLM...CLSID} = UnLockerMenu Class \InProcServer32\(Default) = C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallMenuRight64.dll [IObit] WinRAR\(Default) = {B41DB860-64E4-11D2-9906-E49FADC173CA} -> {HKLM...CLSID} = WinRAR \InProcServer32\(Default) = C:\Program Files\WinRAR\rarext.dll [Alexander Roshal] WinRAR32\(Default) = {B41DB860-8EE4-11D2-9906-E49FADC173CA} -> {HKLM...Wow...CLSID} = WinRAR \InProcServer32\(Default) = C:\Program Files\WinRAR\rarext32.dll [Alexander Roshal] XXX Groove GFS Context Menu Handler XXX\(Default) = {6C467336-8281-4E60-8204-430CED96822D} -> {HKLM...CLSID} = Groove GFS Context Menu Handler \InProcServer32\(Default) = C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [MS] -> {HKLM...Wow...CLSID} = Groove GFS Context Menu Handler \InProcServer32\(Default) = C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL [MS] {A4FD8DDB-5800-4414-97F9-7457AC8EE4F0}\(Default) = (no title provided) -> {HKLM...Wow...CLSID} = NBShellHook Class \InProcServer32\(Default) = C:\Program Files (x86)\Nero\Nero 10\Nero BackItUp\NBShell.dll [Nero AG] {F764812A-132C-4013-9960-5CBBEB408A0E}\(Default) = (no title provided) -> {HKLM...Wow...CLSID} = NeroShellExt Class \InProcServer32\(Default) = C:\Program Files (x86)\Common Files\Nero\NeroShellExt\\NeroShellExt.dll [Nero AG] HKLM\SOFTWARE\Classes\*\shellex\DragDropHandlers\ NBShellHook\(Default) = {A4FD8DDB-5800-4414-97F9-7457AC8EE4F0} -> {HKLM...Wow...CLSID} = NBShellHook Class \InProcServer32\(Default) = C:\Program Files (x86)\Nero\Nero 10\Nero BackItUp\NBShell.dll [Nero AG] HKLM\SOFTWARE\Classes\Wow6432Node\*\shellex\DragDropHandlers\ NBShellHook\(Default) = {A4FD8DDB-5800-4414-97F9-7457AC8EE4F0} -> {HKLM...Wow...CLSID} = NBShellHook Class \InProcServer32\(Default) = C:\Program Files (x86)\Nero\Nero 10\Nero BackItUp\NBShell.dll [Nero AG] HKLM\SOFTWARE\Classes\AllFilesystemObjects\shellex\ContextMenuHandlers\ 00avast\(Default) = {472083B0-C522-11CF-8763-00608CC02F24} -> {HKLM...CLSID} = avast \InProcServer32\(Default) = C:\Program Files\AVAST Software\Avast\ashShA64.dll [AVAST Software] -> {HKLM...Wow...CLSID} = avast \InProcServer32\(Default) = C:\Program Files\AVAST Software\Avast\ashShell.dll [AVAST Software] MBAMShlExt\(Default) = {57CE581A-0CB6-4266-9CA0-19364C90A0B3} -> {HKLM...CLSID} = MBAMShlExt Class \InProcServer32\(Default) = C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamext.dll [Malwarebytes Corporation] UnlockerShellExtension\(Default) = {DDE4BEEB-DDE6-48fd-8EB5-035C09923F83} -> {HKLM...CLSID} = UnlockerShellExtension \InProcServer32\(Default) = C:\Program Files\Unlocker\UnlockerCOM.dll [null data] XXX Groove GFS Context Menu Handler XXX\(Default) = {6C467336-8281-4E60-8204-430CED96822D} -> {HKLM...CLSID} = Groove GFS Context Menu Handler \InProcServer32\(Default) = C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [MS] -> {HKLM...Wow...CLSID} = Groove GFS Context Menu Handler \InProcServer32\(Default) = C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL [MS] HKLM\SOFTWARE\Classes\Wow6432Node\AllFilesystemObjects\shellex\ContextMenuHandlers\ 00avast\(Default) = {472083B0-C522-11CF-8763-00608CC02F24} -> {HKLM...CLSID} = avast \InProcServer32\(Default) = C:\Program Files\AVAST Software\Avast\ashShA64.dll [AVAST Software] -> {HKLM...Wow...CLSID} = avast \InProcServer32\(Default) = C:\Program Files\AVAST Software\Avast\ashShell.dll [AVAST Software] MBAMShlExt\(Default) = {57CE581A-0CB6-4266-9CA0-19364C90A0B3} -> {HKLM...CLSID} = MBAMShlExt Class \InProcServer32\(Default) = C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamext.dll [Malwarebytes Corporation] UnlockerShellExtension\(Default) = {DDE4BEEB-DDE6-48fd-8EB5-035C09923F83} -> {HKLM...CLSID} = UnlockerShellExtension \InProcServer32\(Default) = C:\Program Files\Unlocker\UnlockerCOM.dll [null data] XXX Groove GFS Context Menu Handler XXX\(Default) = {6C467336-8281-4E60-8204-430CED96822D} -> {HKLM...CLSID} = Groove GFS Context Menu Handler \InProcServer32\(Default) = C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [MS] -> {HKLM...Wow...CLSID} = Groove GFS Context Menu Handler \InProcServer32\(Default) = C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL [MS] HKLM\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\ 7-Zip\(Default) = {23170F69-40C1-278A-1000-000100020000} -> {HKLM...Wow...CLSID} = 7-Zip Shell Extension \InProcServer32\(Default) = C:\Program Files (x86)\7-Zip\7-zip.dll [Igor Pavlov] Advanced SystemCare\(Default) = {2803063F-4B8D-4dc6-8874-D1802487FE2D} -> {HKLM...CLSID} = CExtMenu Class \InProcServer32\(Default) = C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASCExtMenu_64.dll [IObit] AVG Disk Space Explorer Shell Extension\(Default) = {4838CD50-7E5D-4811-9B17-C47A85539F28} -> {HKLM...CLSID} = AVG Disk Space Explorer Shell Extension \InProcServer32\(Default) = C:\Program Files (x86)\AVG\AVG PC TuneUp\DseShExt-x64.dll [AVG] -> {HKLM...Wow...CLSID} = AVG Disk Space Explorer Shell Extension \InProcServer32\(Default) = C:\Program Files (x86)\AVG\AVG PC TuneUp\DseShExt-x86.dll [AVG] AVG Shredder Shell Extension\(Default) = {4858E7D9-8E12-45a3-B6A3-1CD128C9D403} -> {HKLM...CLSID} = AVG Shredder Shell Extension \InProcServer32\(Default) = C:\Program Files (x86)\AVG\AVG PC TuneUp\SDShelEx-x64.dll [AVG] -> {HKLM...Wow...CLSID} = AVG Shredder Shell Extension \InProcServer32\(Default) = C:\Program Files (x86)\AVG\AVG PC TuneUp\SDShelEx-win32.dll [AVG] Explorer Context Menu\(Default) = {82C63EC5-1B4C-43B7-7AC8-57148B696B95} -> {HKLM...CLSID} = ? \InProcServer32\(Default) = mscoree.dll [MS] IObit Malware Fighter\(Default) = {0BB81440-5F42-4480-A5F7-770A6F439FC8} -> {HKLM...CLSID} = BlueBirdShell Class \InProcServer32\(Default) = C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFShellExt.dll [IObit] IObitUnstaler\(Default) = {B19ED566-D419-470b-B111-3C89040BC027} -> {HKLM...CLSID} = IObitUnstaler Class \InProcServer32\(Default) = C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallMenuRight64.dll [IObit] UnLockerMenu\(Default) = {A6FF0E3A-8437-482C-8E04-4F9E15C57538} -> {HKLM...CLSID} = UnLockerMenu Class \InProcServer32\(Default) = C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallMenuRight64.dll [IObit] WinRAR\(Default) = {B41DB860-64E4-11D2-9906-E49FADC173CA} -> {HKLM...CLSID} = WinRAR \InProcServer32\(Default) = C:\Program Files\WinRAR\rarext.dll [Alexander Roshal] WinRAR32\(Default) = {B41DB860-8EE4-11D2-9906-E49FADC173CA} -> {HKLM...Wow...CLSID} = WinRAR \InProcServer32\(Default) = C:\Program Files\WinRAR\rarext32.dll [Alexander Roshal] XXX Groove GFS Context Menu Handler XXX\(Default) = {6C467336-8281-4E60-8204-430CED96822D} -> {HKLM...CLSID} = Groove GFS Context Menu Handler \InProcServer32\(Default) = C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [MS] -> {HKLM...Wow...CLSID} = Groove GFS Context Menu Handler \InProcServer32\(Default) = C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL [MS] {F764812A-132C-4013-9960-5CBBEB408A0E}\(Default) = (no title provided) -> {HKLM...Wow...CLSID} = NeroShellExt Class \InProcServer32\(Default) = C:\Program Files (x86)\Common Files\Nero\NeroShellExt\\NeroShellExt.dll [Nero AG] HKLM\SOFTWARE\Classes\Wow6432Node\Directory\shellex\ContextMenuHandlers\ 7-Zip\(Default) = {23170F69-40C1-278A-1000-000100020000} -> {HKLM...Wow...CLSID} = 7-Zip Shell Extension \InProcServer32\(Default) = C:\Program Files (x86)\7-Zip\7-zip.dll [Igor Pavlov] Advanced SystemCare\(Default) = {2803063F-4B8D-4dc6-8874-D1802487FE2D} -> {HKLM...CLSID} = CExtMenu Class \InProcServer32\(Default) = C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASCExtMenu_64.dll [IObit] AVG Disk Space Explorer Shell Extension\(Default) = {4838CD50-7E5D-4811-9B17-C47A85539F28} -> {HKLM...CLSID} = AVG Disk Space Explorer Shell Extension \InProcServer32\(Default) = C:\Program Files (x86)\AVG\AVG PC TuneUp\DseShExt-x64.dll [AVG] -> {HKLM...Wow...CLSID} = AVG Disk Space Explorer Shell Extension \InProcServer32\(Default) = C:\Program Files (x86)\AVG\AVG PC TuneUp\DseShExt-x86.dll [AVG] AVG Shredder Shell Extension\(Default) = {4858E7D9-8E12-45a3-B6A3-1CD128C9D403} -> {HKLM...CLSID} = AVG Shredder Shell Extension \InProcServer32\(Default) = C:\Program Files (x86)\AVG\AVG PC TuneUp\SDShelEx-x64.dll [AVG] -> {HKLM...Wow...CLSID} = AVG Shredder Shell Extension \InProcServer32\(Default) = C:\Program Files (x86)\AVG\AVG PC TuneUp\SDShelEx-win32.dll [AVG] Explorer Context Menu\(Default) = {82C63EC5-1B4C-43B7-7AC8-57148B696B95} -> {HKLM...CLSID} = ? \InProcServer32\(Default) = mscoree.dll [MS] IObit Malware Fighter\(Default) = {0BB81440-5F42-4480-A5F7-770A6F439FC8} -> {HKLM...CLSID} = BlueBirdShell Class \InProcServer32\(Default) = C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFShellExt.dll [IObit] IObitUnstaler\(Default) = {B19ED566-D419-470b-B111-3C89040BC027} -> {HKLM...CLSID} = IObitUnstaler Class \InProcServer32\(Default) = C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallMenuRight64.dll [IObit] UnLockerMenu\(Default) = {A6FF0E3A-8437-482C-8E04-4F9E15C57538} -> {HKLM...CLSID} = UnLockerMenu Class \InProcServer32\(Default) = C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallMenuRight64.dll [IObit] WinRAR\(Default) = {B41DB860-64E4-11D2-9906-E49FADC173CA} -> {HKLM...CLSID} = WinRAR \InProcServer32\(Default) = C:\Program Files\WinRAR\rarext.dll [Alexander Roshal] WinRAR32\(Default) = {B41DB860-8EE4-11D2-9906-E49FADC173CA} -> {HKLM...Wow...CLSID} = WinRAR \InProcServer32\(Default) = C:\Program Files\WinRAR\rarext32.dll [Alexander Roshal] XXX Groove GFS Context Menu Handler XXX\(Default) = {6C467336-8281-4E60-8204-430CED96822D} -> {HKLM...CLSID} = Groove GFS Context Menu Handler \InProcServer32\(Default) = C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [MS] -> {HKLM...Wow...CLSID} = Groove GFS Context Menu Handler \InProcServer32\(Default) = C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL [MS] {F764812A-132C-4013-9960-5CBBEB408A0E}\(Default) = (no title provided) -> {HKLM...Wow...CLSID} = NeroShellExt Class \InProcServer32\(Default) = C:\Program Files (x86)\Common Files\Nero\NeroShellExt\\NeroShellExt.dll [Nero AG] HKLM\SOFTWARE\Classes\Directory\shellex\DragDropHandlers\ 7-Zip\(Default) = {23170F69-40C1-278A-1000-000100020000} -> {HKLM...Wow...CLSID} = 7-Zip Shell Extension \InProcServer32\(Default) = C:\Program Files (x86)\7-Zip\7-zip.dll [Igor Pavlov] WinRAR\(Default) = {B41DB860-64E4-11D2-9906-E49FADC173CA} -> {HKLM...CLSID} = WinRAR \InProcServer32\(Default) = C:\Program Files\WinRAR\rarext.dll [Alexander Roshal] WinRAR32\(Default) = {B41DB860-8EE4-11D2-9906-E49FADC173CA} -> {HKLM...Wow...CLSID} = WinRAR \InProcServer32\(Default) = C:\Program Files\WinRAR\rarext32.dll [Alexander Roshal] HKLM\SOFTWARE\Classes\Wow6432Node\Directory\shellex\DragDropHandlers\ 7-Zip\(Default) = {23170F69-40C1-278A-1000-000100020000} -> {HKLM...Wow...CLSID} = 7-Zip Shell Extension \InProcServer32\(Default) = C:\Program Files (x86)\7-Zip\7-zip.dll [Igor Pavlov] WinRAR\(Default) = {B41DB860-64E4-11D2-9906-E49FADC173CA} -> {HKLM...CLSID} = WinRAR \InProcServer32\(Default) = C:\Program Files\WinRAR\rarext.dll [Alexander Roshal] WinRAR32\(Default) = {B41DB860-8EE4-11D2-9906-E49FADC173CA} -> {HKLM...Wow...CLSID} = WinRAR \InProcServer32\(Default) = C:\Program Files\WinRAR\rarext32.dll [Alexander Roshal] HKLM\SOFTWARE\Classes\Directory\Background\shellex\ContextMenuHandlers\ NvCplDesktopContext\(Default) = {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} -> {HKLM...CLSID} = NVIDIA CPL Context Menu Extension \InProcServer32\(Default) = C:\Windows\system32\nvshext.dll [NVIDIA Corporation] XXX Groove GFS Context Menu Handler XXX\(Default) = {6C467336-8281-4E60-8204-430CED96822D} -> {HKLM...CLSID} = Groove GFS Context Menu Handler \InProcServer32\(Default) = C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [MS] -> {HKLM...Wow...CLSID} = Groove GFS Context Menu Handler \InProcServer32\(Default) = C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL [MS] HKLM\SOFTWARE\Classes\Wow6432Node\Directory\Background\shellex\ContextMenuHandlers\ NvCplDesktopContext\(Default) = {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} -> {HKLM...CLSID} = NVIDIA CPL Context Menu Extension \InProcServer32\(Default) = C:\Windows\system32\nvshext.dll [NVIDIA Corporation] XXX Groove GFS Context Menu Handler XXX\(Default) = {6C467336-8281-4E60-8204-430CED96822D} -> {HKLM...CLSID} = Groove GFS Context Menu Handler \InProcServer32\(Default) = C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [MS] -> {HKLM...Wow...CLSID} = Groove GFS Context Menu Handler \InProcServer32\(Default) = C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL [MS] HKLM\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\ {C52AF81D-F7A0-4AAB-8E87-F80A60CCD396}\(Default) = OpenOffice Column Handler -> {HKLM...CLSID} = (no title provided) \InProcServer32\(Default) = C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\shlxthdl_x64.dll [Apache Software Foundation] -> {HKLM...Wow...CLSID} = (no title provided) \InProcServer32\(Default) = C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\shlxthdl.dll [Apache Software Foundation] {F9DB5320-233E-11D1-9F84-707F02C10627}\(Default) = PDF Column Info -> {HKLM...Wow...CLSID} = PDF Shell Extension \InProcServer32\(Default) = C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll [Adobe Systems, Inc.] HKLM\SOFTWARE\Classes\Wow6432Node\Folder\shellex\ColumnHandlers\ {C52AF81D-F7A0-4AAB-8E87-F80A60CCD396}\(Default) = OpenOffice Column Handler -> {HKLM...CLSID} = (no title provided) \InProcServer32\(Default) = C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\shlxthdl_x64.dll [Apache Software Foundation] -> {HKLM...Wow...CLSID} = (no title provided) \InProcServer32\(Default) = C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\shlxthdl.dll [Apache Software Foundation] {F9DB5320-233E-11D1-9F84-707F02C10627}\(Default) = PDF Column Info -> {HKLM...Wow...CLSID} = PDF Shell Extension \InProcServer32\(Default) = C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll [Adobe Systems, Inc.] HKLM\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\ avast\(Default) = {472083B0-C522-11CF-8763-00608CC02F24} -> {HKLM...CLSID} = avast \InProcServer32\(Default) = C:\Program Files\AVAST Software\Avast\ashShA64.dll [AVAST Software] -> {HKLM...Wow...CLSID} = avast \InProcServer32\(Default) = C:\Program Files\AVAST Software\Avast\ashShell.dll [AVAST Software] AVG Shell Extension\(Default) = {9F97547E-4609-42C5-AE0C-81C61FFAEBC3} -> {HKLM...CLSID} = AVG Shell Extension Class \InProcServer32\(Default) = C:\Program Files (x86)\AVG\AVG2014\avgsea.dll [AVG Technologies CZ, s.r.o.] -> {HKLM...Wow...CLSID} = AVG Shell Extension Class \InProcServer32\(Default) = C:\Program Files (x86)\AVG\AVG2014\avgse.dll [AVG Technologies CZ, s.r.o.] IObit Malware Fighter\(Default) = {0BB81440-5F42-4480-A5F7-770A6F439FC8} -> {HKLM...CLSID} = BlueBirdShell Class \InProcServer32\(Default) = C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFShellExt.dll [IObit] IObitUnstaler\(Default) = {B19ED566-D419-470b-B111-3C89040BC027} -> {HKLM...CLSID} = IObitUnstaler Class \InProcServer32\(Default) = C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallMenuRight64.dll [IObit] MBAMShlExt\(Default) = {57CE581A-0CB6-4266-9CA0-19364C90A0B3} -> {HKLM...CLSID} = MBAMShlExt Class \InProcServer32\(Default) = C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamext.dll [Malwarebytes Corporation] SmartDefragExtension\(Default) = {189F1E63-33A7-404B-B2F6-8C76A452CC54} -> {HKLM...CLSID} = SmartDefragExtension Class \InProcServer32\(Default) = C:\Windows\system32\IObitSmartDefragExtension.dll [IObit] UnLockerMenu\(Default) = {A6FF0E3A-8437-482C-8E04-4F9E15C57538} -> {HKLM...CLSID} = UnLockerMenu Class \InProcServer32\(Default) = C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallMenuRight64.dll [IObit] UnlockerShellExtension\(Default) = {DDE4BEEB-DDE6-48fd-8EB5-035C09923F83} -> {HKLM...CLSID} = UnlockerShellExtension \InProcServer32\(Default) = C:\Program Files\Unlocker\UnlockerCOM.dll [null data] WinRAR\(Default) = {B41DB860-64E4-11D2-9906-E49FADC173CA} -> {HKLM...CLSID} = WinRAR \InProcServer32\(Default) = C:\Program Files\WinRAR\rarext.dll [Alexander Roshal] WinRAR32\(Default) = {B41DB860-8EE4-11D2-9906-E49FADC173CA} -> {HKLM...Wow...CLSID} = WinRAR \InProcServer32\(Default) = C:\Program Files\WinRAR\rarext32.dll [Alexander Roshal] XXX Groove GFS Context Menu Handler XXX\(Default) = {6C467336-8281-4E60-8204-430CED96822D} -> {HKLM...CLSID} = Groove GFS Context Menu Handler \InProcServer32\(Default) = C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [MS] -> {HKLM...Wow...CLSID} = Groove GFS Context Menu Handler \InProcServer32\(Default) = C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL [MS] {A4FD8DDB-5800-4414-97F9-7457AC8EE4F0}\(Default) = (no title provided) -> {HKLM...Wow...CLSID} = NBShellHook Class \InProcServer32\(Default) = C:\Program Files (x86)\Nero\Nero 10\Nero BackItUp\NBShell.dll [Nero AG] HKLM\SOFTWARE\Classes\Wow6432Node\Folder\shellex\ContextMenuHandlers\ avast\(Default) = {472083B0-C522-11CF-8763-00608CC02F24} -> {HKLM...CLSID} = avast \InProcServer32\(Default) = C:\Program Files\AVAST Software\Avast\ashShA64.dll [AVAST Software] -> {HKLM...Wow...CLSID} = avast \InProcServer32\(Default) = C:\Program Files\AVAST Software\Avast\ashShell.dll [AVAST Software] AVG Shell Extension\(Default) = {9F97547E-4609-42C5-AE0C-81C61FFAEBC3} -> {HKLM...CLSID} = AVG Shell Extension Class \InProcServer32\(Default) = C:\Program Files (x86)\AVG\AVG2014\avgsea.dll [AVG Technologies CZ, s.r.o.] -> {HKLM...Wow...CLSID} = AVG Shell Extension Class \InProcServer32\(Default) = C:\Program Files (x86)\AVG\AVG2014\avgse.dll [AVG Technologies CZ, s.r.o.] IObit Malware Fighter\(Default) = {0BB81440-5F42-4480-A5F7-770A6F439FC8} -> {HKLM...CLSID} = BlueBirdShell Class \InProcServer32\(Default) = C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFShellExt.dll [IObit] IObitUnstaler\(Default) = {B19ED566-D419-470b-B111-3C89040BC027} -> {HKLM...CLSID} = IObitUnstaler Class \InProcServer32\(Default) = C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallMenuRight64.dll [IObit] MBAMShlExt\(Default) = {57CE581A-0CB6-4266-9CA0-19364C90A0B3} -> {HKLM...CLSID} = MBAMShlExt Class \InProcServer32\(Default) = C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamext.dll [Malwarebytes Corporation] SmartDefragExtension\(Default) = {189F1E63-33A7-404B-B2F6-8C76A452CC54} -> {HKLM...CLSID} = SmartDefragExtension Class \InProcServer32\(Default) = C:\Windows\system32\IObitSmartDefragExtension.dll [IObit] UnLockerMenu\(Default) = {A6FF0E3A-8437-482C-8E04-4F9E15C57538} -> {HKLM...CLSID} = UnLockerMenu Class \InProcServer32\(Default) = C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallMenuRight64.dll [IObit] UnlockerShellExtension\(Default) = {DDE4BEEB-DDE6-48fd-8EB5-035C09923F83} -> {HKLM...CLSID} = UnlockerShellExtension \InProcServer32\(Default) = C:\Program Files\Unlocker\UnlockerCOM.dll [null data] WinRAR\(Default) = {B41DB860-64E4-11D2-9906-E49FADC173CA} -> {HKLM...CLSID} = WinRAR \InProcServer32\(Default) = C:\Program Files\WinRAR\rarext.dll [Alexander Roshal] WinRAR32\(Default) = {B41DB860-8EE4-11D2-9906-E49FADC173CA} -> {HKLM...Wow...CLSID} = WinRAR \InProcServer32\(Default) = C:\Program Files\WinRAR\rarext32.dll [Alexander Roshal] XXX Groove GFS Context Menu Handler XXX\(Default) = {6C467336-8281-4E60-8204-430CED96822D} -> {HKLM...CLSID} = Groove GFS Context Menu Handler \InProcServer32\(Default) = C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [MS] -> {HKLM...Wow...CLSID} = Groove GFS Context Menu Handler \InProcServer32\(Default) = C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL [MS] {A4FD8DDB-5800-4414-97F9-7457AC8EE4F0}\(Default) = (no title provided) -> {HKLM...Wow...CLSID} = NBShellHook Class \InProcServer32\(Default) = C:\Program Files (x86)\Nero\Nero 10\Nero BackItUp\NBShell.dll [Nero AG] HKLM\SOFTWARE\Classes\Folder\shellex\DragDropHandlers\ NBShellHook\(Default) = {A4FD8DDB-5800-4414-97F9-7457AC8EE4F0} -> {HKLM...Wow...CLSID} = NBShellHook Class \InProcServer32\(Default) = C:\Program Files (x86)\Nero\Nero 10\Nero BackItUp\NBShell.dll [Nero AG] WinRAR\(Default) = {B41DB860-64E4-11D2-9906-E49FADC173CA} -> {HKLM...CLSID} = WinRAR \InProcServer32\(Default) = C:\Program Files\WinRAR\rarext.dll [Alexander Roshal] WinRAR32\(Default) = {B41DB860-8EE4-11D2-9906-E49FADC173CA} -> {HKLM...Wow...CLSID} = WinRAR \InProcServer32\(Default) = C:\Program Files\WinRAR\rarext32.dll [Alexander Roshal] HKLM\SOFTWARE\Classes\Wow6432Node\Folder\shellex\DragDropHandlers\ NBShellHook\(Default) = {A4FD8DDB-5800-4414-97F9-7457AC8EE4F0} -> {HKLM...Wow...CLSID} = NBShellHook Class \InProcServer32\(Default) = C:\Program Files (x86)\Nero\Nero 10\Nero BackItUp\NBShell.dll [Nero AG] WinRAR\(Default) = {B41DB860-64E4-11D2-9906-E49FADC173CA} -> {HKLM...CLSID} = WinRAR \InProcServer32\(Default) = C:\Program Files\WinRAR\rarext.dll [Alexander Roshal] WinRAR32\(Default) = {B41DB860-8EE4-11D2-9906-E49FADC173CA} -> {HKLM...Wow...CLSID} = WinRAR \InProcServer32\(Default) = C:\Program Files\WinRAR\rarext32.dll [Alexander Roshal] Group Policies {GPedit.msc branch and setting}: ----------------------------------------------- Note: detected settings may not have any effect. HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System\ DisableLockWorkstation = (REG_DWORD) dword:0x00000000 {unrecognized setting} DisableTaskMgr = (REG_DWORD) dword:0x00000000 {unrecognized setting} DisableChangePassword = (REG_DWORD) dword:0x00000000 {unrecognized setting} HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\ EnableLinkedConnections = (REG_DWORD) dword:0x00000001 {unrecognized setting} HideFastUserSwitching = (REG_DWORD) dword:0x00000000 {unrecognized setting} SoftwareSASGeneration = (REG_DWORD) dword:0x00000001 {unrecognized setting} Active Desktop and Wallpaper: ----------------------------- Active Desktop may be disabled at this entry: HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState Displayed if Active Desktop enabled and wallpaper not set by Group Policy: HKCU\Software\Microsoft\Internet Explorer\Desktop\General\ Wallpaper = C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows Photo Gallery\Bureaubladachtergrond van Windows Fotogalerie.jpg Displayed if Active Desktop disabled and wallpaper not set by Group Policy: HKCU\Control Panel\Desktop\ Wallpaper = C:\Users\Peter\AppData\Roaming\Microsoft\Windows Photo Gallery\Bureaubladachtergrond van Windows Fotogalerie.jpg Enabled Screen Saver: --------------------- HKCU\Control Panel\Desktop\ SCRNSAVE.EXE = C:\FILMDO~1\zoek.scr [file not found] Windows Portable Device AutoPlay Handlers ----------------------------------------- HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\ Fotoimport1287-38\ Provider = Fotoimporteerder InvokeProgID = Fotoimport1287-38 InvokeVerb = play HKLM\SOFTWARE\Classes\Fotoimport1287-38\shell\play\command\(Default) = "C:\Program Files\Fotoservice\Kruidvat fotoservice\Fotoimporteerder.exe" -startDirectory %1 [null data] Fotoschau1287-38\ Provider = Fotoshow InvokeProgID = Fotoschau1287-38 InvokeVerb = play HKLM\SOFTWARE\Classes\Fotoschau1287-38\shell\play\command\(Default) = "C:\Program Files\Fotoservice\Kruidvat fotoservice\Fotoshow.exe" -d %1 [null data] HPMSDVDPlayBluRayArrival\ Provider = HP MediaSmart DVD InvokeProgID = BD InvokeVerb = PlayWithHPMediaSmartDVD HKLM\SOFTWARE\Classes\BD\shell\PlayWithHPMediaSmartDVD\Command\(Default) = "c:\Program Files (x86)\Hewlett-Packard\Media\DVD\HPDVDSmart.exe" AUTOPLAY MOVIE "%L" [CyberLink Corp.] HPMSDVDPlayDVDMovieOnArrival\ Provider = HP MediaSmart DVD InvokeProgID = DVD InvokeVerb = PlayWithHPMediaSmartDVD HKLM\SOFTWARE\Classes\DVD\shell\PlayWithHPMediaSmartDVD\Command\(Default) = "c:\Program Files (x86)\Hewlett-Packard\Media\DVD\HPDVDSmart.exe" AUTOPLAY MOVIE "%L" [CyberLink Corp.] HPMSDVDPlayVCDMovieOnArrival\ Provider = HP MediaSmart DVD InvokeProgID = VCD InvokeVerb = PlayWithHPMediaSmartDVD HKLM\SOFTWARE\Classes\VCD\shell\PlayWithHPMediaSmartDVD\Command\(Default) = "c:\Program Files (x86)\Hewlett-Packard\Media\DVD\HPDVDSmart.exe" AUTOPLAY MOVIE "%L" [CyberLink Corp.] MSLivePhotoAcqHWEventHandler\ Provider = @%ProgramFiles(x86)%\Windows Live\Photo Gallery\regres.dll,-10 ProgID = Microsoft.LivePhotoAcqHWEventHandler HKLM\SOFTWARE\Classes\Microsoft.LivePhotoAcqHWEventHandler\CLSID\(Default) = {3BD0ACD1-71CA-4475-92CC-E0AA0AAF843F} -> {HKLM...CLSID} = (no title provided) \LocalServer32\(Default) = C:\Program Files (x86)\Windows Live\Photo Gallery\WLXPhotoAcquireWizard.exe [MS] MSLivePhotoAcquireDropHandler\ Provider = @%ProgramFiles(x86)%\Windows Live\Photo Gallery\regres.dll,-10 InvokeProgID = Microsoft.LivePhotoAcqDTShim.1 InvokeVerb = open HKLM\SOFTWARE\Classes\Microsoft.LivePhotoAcqDTShim.1\shell\open\DropTarget\CLSID = {00F33137-EE26-412F-8D71-F84E4C2C6625} -> {HKLM...CLSID} = Windows Live Photo Gallery Viewer Autoplay Shim \InProcServer32\(Default) = C:\Program Files (x86)\Windows Live\Photo Gallery\PhotoViewerShimx64.dll [MS] MSLiveShowPicturesOnArrival\ Provider = @%ProgramFiles(x86)%\Windows Live\Photo Gallery\regres.dll,-10 InvokeProgID = Microsoft.Photos.LiveAutoplayShim.1 InvokeVerb = open HKLM\SOFTWARE\Classes\Microsoft.Photos.LiveAutoplayShim.1\shell\open\DropTarget\CLSID = {00F30F90-3E96-453B-AFCD-D71989ECC2C7} -> {HKLM...CLSID} = Windows Live Photo Gallery Viewer Autoplay Shim \InProcServer32\(Default) = C:\Program Files (x86)\Windows Live\Photo Gallery\PhotoViewerShimx64.dll [MS] MSLiveVideoCameraArrivalCaptureWizard\ Provider = @%ProgramFiles(x86)%\Windows Live\Photo Gallery\regres.dll,-10 ProgID = WLXAutoPlayMgr.WLXHWEventHandler InitCmdLine = WLXVideoAcquireWizard HKLM\SOFTWARE\Classes\WLXAutoPlayMgr.WLXHWEventHandler\CLSID\(Default) = {9B5C97F6-B3A5-4A6D-8B03-993EC7291A22} -> {HKLM...CLSID} = WLXWEventHandler Class \LocalServer32\(Default) = "C:\Program Files (x86)\Windows Live\Photo Gallery\WLXVideoCameraAutoPlayManager.exe" [MS] MSPlayCDAudioOnArrival\ Provider = @wmploc.dll,-6502 InvokeProgID = WMP.AudioCD InvokeVerb = play HKLM\SOFTWARE\Classes\WMP.AudioCD\shell\play\command\(Default) = "C:\Program Files (x86)\Windows Media Player\wmplayer.exe" /prefetch:3 /device:AudioCD "%L" [MS] MSPlayDVDMovieOnArrival\ Provider = @wmploc.dll,-6502 InvokeProgID = WMP.DVD InvokeVerb = play HKLM\SOFTWARE\Classes\WMP.DVD\shell\play\command\(Default) = "C:\Program Files (x86)\Windows Media Player\wmplayer.exe" /prefetch:4 /device:DVD "%L" [MS] MSPlaySuperVideoCDMovieOnArrival\ Provider = @wmploc.dll,-6502 InvokeProgID = WMP.VCD InvokeVerb = play HKLM\SOFTWARE\Classes\WMP.VCD\shell\play\command\(Default) = "C:\Program Files (x86)\Windows Media Player\wmplayer.exe" /prefetch:4 /device:VCD "%L" [MS] MSPlayVideoCDMovieOnArrival\ Provider = @wmploc.dll,-6502 InvokeProgID = WMP.VCD InvokeVerb = play HKLM\SOFTWARE\Classes\WMP.VCD\shell\play\command\(Default) = "C:\Program Files (x86)\Windows Media Player\wmplayer.exe" /prefetch:4 /device:VCD "%L" [MS] MSRipCDAudioOnArrival\ Provider = @wmploc.dll,-6502 InvokeProgID = WMP.RipCD InvokeVerb = Rip HKLM\SOFTWARE\Classes\WMP.RipCD\shell\Rip\Command\(Default) = "C:\Program Files (x86)\Windows Media Player\wmplayer.exe" /prefetch:3 /RipAudioCD "%L" [MS] MSWMPBurnCDOnArrival\ Provider = @wmploc.dll,-6502 InvokeProgID = WMP.BurnCD InvokeVerb = Burn HKLM\SOFTWARE\Classes\WMP.BurnCD\shell\Burn\Command\(Default) = "C:\Program Files (x86)\Windows Media Player\wmplayer.exe" /prefetch:3 /Task:CDWrite /Device:"%L" [MS] MSWMPBurnDataDVDArrival\ Provider = @wmploc.dll,-6502 InvokeProgID = WMP.BurnDVD InvokeVerb = Burn HKLM\SOFTWARE\Classes\WMP.BurnDVD\shell\Burn\Command\(Default) = "C:\Program Files (x86)\Windows Media Player\wmplayer.exe" /prefetch:3 /Task:DVDWrite /Device:"%L" [MS] P2GCDBurningOnArrival\ Provider = Power2Go InvokeProgID = BlankCD InvokeVerb = OpenWithPower2Go HKLM\SOFTWARE\Classes\BlankCD\shell\OpenWithPower2Go\Command\(Default) = "c:\Program Files (x86)\CyberLink\Power2Go\Power2Go.exe" "%L" [CyberLink Corp.] P2GDVDBurningOnArrival\ Provider = Power2Go InvokeProgID = BlankDVD InvokeVerb = OpenWithPower2Go HKLM\SOFTWARE\Classes\BlankDVD\shell\OpenWithPower2Go\Command\(Default) = "c:\Program Files (x86)\CyberLink\Power2Go\Power2Go.exe" "%L" [CyberLink Corp.] PDirDVArrival\ Provider = PowerDirector ProgID = Shell.HWEventHandlerShellExecute InitCmdLine = "c:\Program Files (x86)\CyberLink\PowerDirector\PDR.exe" /DV HKLM\SOFTWARE\Classes\Shell.HWEventHandlerShellExecute\CLSID\(Default) = {FFB8655F-81B9-4fce-B89C-9A6BA76D13E7} -> {HKLM...CLSID} = Shell Execute Hardware Event Handler \LocalServer32\(Default) = C:\Windows\System32\rundll32.exe shell32.dll,SHCreateLocalServerRunDll {FFB8655F-81B9-4fce-B89C-9A6BA76D13E7} [MS] Power2GoPlayCDAudioOnArrival\ Provider = Power2Go InvokeProgID = AudioCD InvokeVerb = PlayWithPower2Go HKLM\SOFTWARE\Classes\AudioCD\shell\PlayWithPower2Go\Command\(Default) = "c:\Program Files (x86)\CyberLink\Power2Go\Power2Go.exe" /AudioRipper "%L" [CyberLink Corp.] PStarterBlankCDArrival\ Provider = DVD Suite Premium InvokeProgID = BlankCD InvokeVerb = OpenWithPowerStarter HKLM\SOFTWARE\Classes\BlankCD\shell\OpenWithPowerStarter\Command\(Default) = "c:\Program Files (x86)\CyberLink\CyberLink DVD Suite Premium\PowerStarter.exe" "%L" [CyberLink] PStarterDVDBurningOnArrival\ Provider = DVD Suite Premium InvokeProgID = BlankDVD InvokeVerb = OpenWithPowerStarter HKLM\SOFTWARE\Classes\BlankDVD\shell\OpenWithPowerStarter\Command\(Default) = "c:\Program Files (x86)\CyberLink\CyberLink DVD Suite Premium\PowerStarter.exe" "%L" [CyberLink] PStarterMixedCDArrival\ Provider = DVD Suite Premium InvokeProgID = MixedContent InvokeVerb = OpenWithPowerStarter HKLM\SOFTWARE\Classes\MixedContent\shell\OpenWithPowerStarter\Command\(Default) = "c:\Program Files (x86)\CyberLink\CyberLink DVD Suite Premium\PowerStarter.exe" "%L" [CyberLink] PStarterMusicFilesArrival\ Provider = DVD Suite Premium InvokeProgID = MusicFiles InvokeVerb = OpenWithPowerStarter HKLM\SOFTWARE\Classes\MusicFiles\shell\OpenWithPowerStarter\Command\(Default) = "c:\Program Files (x86)\CyberLink\CyberLink DVD Suite Premium\PowerStarter.exe" "%L" [CyberLink] PStarterPicturesArrival\ Provider = DVD Suite Premium InvokeProgID = Picture InvokeVerb = OpenWithPowerStarter HKLM\SOFTWARE\Classes\Picture\shell\OpenWithPowerStarter\Command\(Default) = "c:\Program Files (x86)\CyberLink\CyberLink DVD Suite Premium\PowerStarter.exe" "%L" [CyberLink] PStarterVideoFilesArrival\ Provider = DVD Suite Premium InvokeProgID = VideoFiles InvokeVerb = OpenWithPowerStarter HKLM\SOFTWARE\Classes\VideoFiles\shell\OpenWithPowerStarter\Command\(Default) = "c:\Program Files (x86)\CyberLink\CyberLink DVD Suite Premium\PowerStarter.exe" "%L" [CyberLink] WIA_{1885F8BC-188C-4197-AA92-6DA1B8A5DB10}\ Provider = PaperPort CLSID = {A55803CC-4D53-404c-8557-FD63DBA95D24} -> {HKLM...CLSID} = WPDShextAutoplay \LocalServer32\(Default) = C:\Windows\system32\WPDShextAutoplay.exe [MS] WIA_{51015947-B32B-46FA-AE03-6B4F381949FB}\ Provider = ControlCenter3 CLSID = {A55803CC-4D53-404c-8557-FD63DBA95D24} InitCmdLine = /WiaCmd;C:\Program Files (x86)\Brother\ControlCenter3\brctrcen.exe /StiDevice:%1 /StiEvent:%2; -> {HKLM...CLSID} = WPDShextAutoplay \LocalServer32\(Default) = C:\Windows\system32\WPDShextAutoplay.exe [MS] Windows Sidebar Gadgets: {++} ------------------------ C:\Users\Peter\AppData\Local\Microsoft\Windows Sidebar\Settings.ini "C:%5CProgram%20Files%5CWindows%20Sidebar%5CGadgets%5CNorton.Gadget" "C:%5CProgram%20Files%5CWindows%20Sidebar%5CShared%20Gadgets%5CAVG.Gadget" "C:%5CUsers%5CPeter%5CAppData%5CLocal%5CMicrosoft%5CWindows%20Sidebar%5CGadgets%5Cchameleon_email.gadget" "C:%5CProgram%20Files%5CWindows%20Sidebar%5CShared%20Gadgets%5CTuneUpUtilities.gadget" "C:%5CUsers%5CPeter%5CAppData%5CLocal%5CMicrosoft%5CWindows%20Sidebar%5CGadgets%5Cchameleon_onedrive.gadget" "C:%5CUsers%5CPeter%5CAppData%5CLocal%5CMicrosoft%5CWindows%20Sidebar%5CGadgets%5Cchameleon_onedrive.gadget" "C:%5CProgram%20Files%5CWindows%20Sidebar%5CGadgets%5CClock.Gadget" "C:%5CProgram%20Files%5CWindows%20Sidebar%5CGadgets%5CCalendar.Gadget" "C:%5CProgram%20Files%5CWindows%20Sidebar%5CGadgets%5CWeather.Gadget" "C:%5CProgram%20Files%5CWindows%20Sidebar%5CShared%20Gadgets%5CaswSidebar.gadget" Non-disabled Scheduled Tasks: {++} ----------------------------- C:\Windows\System32\Tasks Adobe Flash Player Updater -> launches: C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [Adobe Systems Incorporated] Adobe online update program -> launches: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [Adobe Systems Incorporated] Adobe-online actualiseringsprogramma -> launches: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [Adobe Systems Incorporated] ASC7_PerformanceMonitor -> launches: C:\Program Files (x86)\IObit\Advanced SystemCare 7\Monitor.exe [file not found] ASC7_SkipUac_Peter -> launches: "C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASC.exe" /SkipUac [file not found] ASC8_PerformanceMonitor -> launches: C:\Program Files (x86)\IObit\Advanced SystemCare 8\Monitor.exe /Task [IObit] ASC8_SkipUac_Peter -> launches: "C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASC.exe" /SkipUac [IObit] avast! Emergency Update -> (HIDDEN!) launches: C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [AVAST Software] CCleanerSkipUAC -> launches: "C:\Program Files\CCleaner\CCleaner.exe" $(Arg0) [Piriform Ltd] CreateChoiceProcessTask -> launches: C:\Windows\System32\browserchoice.exe /launch [MS] Driver Booster Scan -> launches: C:\Program Files (x86)\IObit\Driver Booster\Scheduler.exe /scan [IObit] Driver Booster SkipUAC (Peter) -> launches: C:\Program Files (x86)\IObit\Driver Booster\DriverBooster.exe /skipuac [IObit] Driver Booster SkipUAC (SYSTEEM) -> launches: C:\Program Files (x86)\IObit\Driver Booster\DriverBooster.exe /skipuac [IObit] Driver Booster Update -> launches: C:\Program Files (x86)\IObit\Driver Booster\AutoUpdate.exe /auto [IObit] FGRun -> launches: C:\Users\Peter\AppData\Roaming\pack.exe [file not found] Hewlett-Packard online update program -> launches: c:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe [null data] HP Health Check -> launches: "c:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" /Scan [null data] HP online update program -> launches: c:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [Hewlett-Packard] HP-Online updateprogramma -> launches: C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [Hewlett-Packard] HPCeeScheduleForPeter -> launches: C:\Program Files (x86)\hewlett-packard\sdp\ceement\HPCEE.exe HPCeeScheduleForPeter (null) [null data] Java Update Scheduler -> launches: C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [file not found] RecoveryCD -> launches: "C:\Program Files (x86)\Hewlett-Packard\HP TCS\RemEngine.exe" RecoveryCD ShowMessageTask [null data] ScanSoft Background Update -> launches: C:\Program Files (x86)\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe -Embedding -boot [file not found] SmartDefrag3_Startup -> launches: C:\Program Files (x86)\IObit\Smart Defrag 3\SmartDefrag.exe /STARTUP [IObit] SmartDefrag3_Update -> launches: C:\Program Files (x86)\IObit\Smart Defrag 3\AutoUpdate.exe /autorun [IObit] TuneUpUtilities_Task_BkGndMaintenance2013 -> launches: C:\Program Files (x86)\AVG\AVG PC TuneUp\OneClick.exe $(Arg0) [AVG] Uninstaller_SkipUac_Administrator -> launches: C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe /UninstallExplorer [IObit] Uninstaller_SkipUac_Peter -> launches: C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe /UninstallExplorer [IObit] {5A0D79F9-6C53-473D-AE9F-0FF6F1A41052} -> launches: C:\Windows\system32\pcalua.exe -a "C:\Program Files (x86)\VSO\pcsetup\PcSetup.exe" -d "C:\Program Files (x86)\VSO\pcsetup" -c /remove /removeatip " Start compatibiliteits modus voor branden. Gelieve nadien te herstarten" [MS] C:\Windows\System32\Tasks\Microsoft\Windows\Active Directory Rights Management Services Client AD RMS Rights Policy Template Management (Manual) -> launches: {BF5CB148-7C77-4d8a-A53E-D81C70CF743C} -> {HKLM...CLSID} = AD RMS Rights Policy Template Management (Manual) Task Handler \InProcServer32\(Default) = C:\Windows\system32\msdrm.dll [MS] -> {HKLM...Wow...CLSID} = AD RMS Rights Policy Template Management (Manual) Task Handler \InProcServer32\(Default) = C:\Windows\system32\msdrm.dll [MS] C:\Windows\System32\Tasks\Microsoft\Windows\Bluetooth UninstallDeviceTask -> launches: BthUdTask.exe $(Arg0) [MS] C:\Windows\System32\Tasks\Microsoft\Windows\CertificateServicesClient SystemTask -> launches: {58fb76b9-ac85-4e55-ac04-427593b1d060} -> {HKLM...CLSID} = Certificate Services Client Task Handler \InProcServer32\(Default) = C:\Windows\system32\dimsjob.dll [MS] -> {HKLM...Wow...CLSID} = Certificate Services Client Task Handler \InProcServer32\(Default) = C:\Windows\system32\dimsjob.dll [MS] UserTask -> launches: {58fb76b9-ac85-4e55-ac04-427593b1d060} -> {HKLM...CLSID} = Certificate Services Client Task Handler \InProcServer32\(Default) = C:\Windows\system32\dimsjob.dll [MS] -> {HKLM...Wow...CLSID} = Certificate Services Client Task Handler \InProcServer32\(Default) = C:\Windows\system32\dimsjob.dll [MS] UserTask-Roam -> launches: {58fb76b9-ac85-4e55-ac04-427593b1d060} -> {HKLM...CLSID} = Certificate Services Client Task Handler \InProcServer32\(Default) = C:\Windows\system32\dimsjob.dll [MS] -> {HKLM...Wow...CLSID} = Certificate Services Client Task Handler \InProcServer32\(Default) = C:\Windows\system32\dimsjob.dll [MS] C:\Windows\System32\Tasks\Microsoft\Windows\Customer Experience Improvement Program Uploader -> launches: %windir%\system32\WSqmCons.exe -u [MS] C:\Windows\System32\Tasks\Microsoft\Windows\Media Center ehDRMInit -> launches: %SystemRoot%\ehome\ehPrivJob.exe /DRMInit [MS] OCURActivate -> launches: %SystemRoot%\ehome\ehPrivJob.exe /OCURActivate [MS] OCURDiscovery -> launches: %SystemRoot%\ehome\ehPrivJob.exe /OCURDiscovery [MS] UpdateRecordPath -> launches: %SystemRoot%\ehome\ehPrivJob.exe /DoUpdateRecordPath $(Arg0) [MS] C:\Windows\System32\Tasks\Microsoft\Windows\MobilePC HotStart -> launches: {06DA0625-9701-43da-BFD7-FBEEA2180A1E} -> {HKLM...CLSID} = HotStart User Agent \InProcServer32\(Default) = C:\Windows\System32\HotStartUserAgent.dll [MS] TMM -> launches: {35EF4182-F900-4632-B072-8639E4478A61} -> {HKLM...CLSID} = Transient Multi-Monitor Manager \InProcServer32\(Default) = C:\Windows\System32\TMM.dll [MS] -> {HKLM...Wow...CLSID} = Transient Multi-Monitor Manager \InProcServer32\(Default) = C:\Windows\System32\TMM.dll [MS] C:\Windows\System32\Tasks\Microsoft\Windows\MUI Lpksetup -> launches: C:\Windows\System32\lpksetup.exe -v [MS] LPRemove -> launches: %windir%\system32\lpremove.exe [MS] Mcbuilder -> launches: C:\Windows\System32\mcbuilder.exe [MS] C:\Windows\System32\Tasks\Microsoft\Windows\Multimedia SystemSoundsService -> launches: {2DEA658F-54C1-4227-AF9B-260AB5FC3543} -> {HKLM...CLSID} = Microsoft PlaySoundService Class \InProcServer32\(Default) = C:\Windows\System32\PlaySndSrv.dll [MS] -> {HKLM...Wow...CLSID} = Microsoft PlaySoundService Class \InProcServer32\(Default) = C:\Windows\System32\PlaySndSrv.dll [MS] C:\Windows\System32\Tasks\Microsoft\Windows\NetworkAccessProtection NAPStatus UI -> launches: {f09878a1-4652-4292-aa63-8c7d4fd7648f} -> {HKLM...CLSID} = Nap ITask Handler Implementation \InProcServer32\(Default) = C:\Windows\System32\QAgent.dll [MS] -> {HKLM...Wow...CLSID} = Nap ITask Handler Implementation \InProcServer32\(Default) = C:\Windows\System32\QAgent.dll [MS] C:\Windows\System32\Tasks\Microsoft\Windows\PLA\System ConvertLogEntries -> (HIDDEN!) launches: %windir%\system32\rundll32.exe %windir%\system32\pla.dll,PlaConvertLogEntries [MS] C:\Windows\System32\Tasks\Microsoft\Windows\RAC RACAgent -> (HIDDEN!) launches: %windir%\system32\RacAgent.exe [MS] C:\Windows\System32\Tasks\Microsoft\Windows\RemoteAssistance RemoteAssistanceTask -> (HIDDEN!) launches: %windir%\system32\RAServer.exe /offerraupdate [MS] C:\Windows\System32\Tasks\Microsoft\Windows\SideShow GadgetManager -> launches: {FF87090D-4A9A-4f47-879B-29A80C355D61} -> {HKLM...CLSID} = GadgetsManager Class \InProcServer32\(Default) = C:\Windows\System32\AuxiliaryDisplayServices.dll [MS] C:\Windows\System32\Tasks\Microsoft\Windows\SystemRestore SR -> launches: %windir%\system32\rundll32.exe /d srrstr.dll,ExecuteScheduledSPPCreation [MS] C:\Windows\System32\Tasks\Microsoft\Windows\Tcpip IpAddressConflict1 -> launches: rundll32 ndfapi.dll,NdfRunDllDuplicateIPOffendingSystem [MS] IpAddressConflict2 -> launches: rundll32 ndfapi.dll,NdfRunDllDuplicateIPDefendingSystem [MS] WSHReset -> (HIDDEN!) launches: %systemroot%\system32\netsh.exe interface tcp set heuristic wsh=default [MS] C:\Windows\System32\Tasks\Microsoft\Windows\TextServicesFramework MsCtfMonitor -> (HIDDEN!) launches: {01575cfe-9a55-4003-a5e1-f38d1ebdcbe1} -> {HKLM...CLSID} = MsCtfMonitor task handler \InProcServer32\(Default) = C:\Windows\system32\MsCtfMonitor.dll [MS] -> {HKLM...Wow...CLSID} = MsCtfMonitor task handler \InProcServer32\(Default) = C:\Windows\system32\MsCtfMonitor.dll [MS] C:\Windows\System32\Tasks\Microsoft\Windows\UPnP UPnPHostConfig -> launches: sc.exe config upnphost start= auto [MS] C:\Windows\System32\Tasks\Microsoft\Windows\WDI ResolutionHost -> (HIDDEN!) launches: {900be39d-6be8-461a-bc4d-b0fa71f5ecb1} -> {HKLM...CLSID} = DiagnosticInfrastructureCustomHandler \InProcServer32\(Default) = C:\Windows\System32\wdi.dll [MS] -> {HKLM...Wow...CLSID} = DiagnosticInfrastructureCustomHandler \InProcServer32\(Default) = C:\Windows\System32\wdi.dll [MS] C:\Windows\System32\Tasks\Microsoft\Windows\WindowsCalendar Reminders - Peter -> launches: C:\Program Files\Windows Calendar\wincal.exe /reminder [MS] C:\Windows\System32\Tasks\Microsoft\Windows\Wired GatherWiredInfo -> launches: %windir%\system32\gatherWiredInfo.vbs [null data] C:\Windows\System32\Tasks\Microsoft\Windows\Wireless GatherWirelessInfo -> launches: %windir%\system32\gatherWirelessInfo.vbs [null data] C:\Windows\System32\Tasks\Microsoft\Windows Defender MP Scheduled Scan -> (HIDDEN!) launches: c:\program files\windows defender\MpCmdRun.exe Scan -RestrictPrivileges [MS] MP Scheduled Signature Update -> (HIDDEN!) launches: c:\program files\windows defender\MpCmdRun.exe SignatureUpdate [MS] C:\Windows\System32\Tasks\Microsoft\Windows Live\SOXE Extractor Definitions Update Task -> launches: {3519154C-227E-47F3-9CC9-12C3F05817F1} -> {HKLM...Wow...CLSID} = Windows Live Social Object Extractor Engine Definition Updater \InProcServer32\(Default) = C:\Program Files (x86)\Windows Live\SOXE\wlsoxe.dll [MS] C:\Windows\System32\Tasks\Norton Management Norton Error Analyzer -> launches: C:\Program Files (x86)\Norton Management\Engine\3.2.0.19\SymErr.exe /analyze [file not found] Norton Error Processor -> launches: C:\Program Files (x86)\Norton Management\Engine\3.2.0.19\SymErr.exe /submit [file not found] C:\Windows\System32\Tasks\WPD SqmUpload_S-1-5-21-3930024867-1471058179-2470722348-1000 -> (HIDDEN!) launches: %windir%\system32\rundll32.exe portabledeviceapi.dll,#1 [MS] Winsock2 Service Provider DLLs: ------------------------------- Namespace Service Providers HKLM\SYSTEM\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++} 000000000001\LibraryPath = %SystemRoot%\system32\NLAapi.dll [MS] 000000000002\LibraryPath = %SystemRoot%\system32\napinsp.dll [MS] 000000000003\LibraryPath = %SystemRoot%\system32\pnrpnsp.dll [MS] 000000000004\LibraryPath = %SystemRoot%\system32\pnrpnsp.dll [MS] 000000000005\LibraryPath = %SystemRoot%\System32\mswsock.dll [MS] 000000000006\LibraryPath = %SystemRoot%\System32\winrnr.dll [MS] HKLM\SYSTEM\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\ {++} 000000000001\LibraryPath = %SystemRoot%\system32\NLAapi.dll [MS] 000000000002\LibraryPath = %SystemRoot%\system32\napinsp.dll [MS] 000000000003\LibraryPath = %SystemRoot%\system32\pnrpnsp.dll [MS] 000000000004\LibraryPath = %SystemRoot%\system32\pnrpnsp.dll [MS] 000000000005\LibraryPath = %SystemRoot%\System32\mswsock.dll [MS] 000000000006\LibraryPath = %SystemRoot%\System32\winrnr.dll [MS] Transport Service Providers HKLM\SYSTEM\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++} 0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range: %SystemRoot%\system32\mswsock.dll [MS], 01 - 10 HKLM\SYSTEM\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries64\ {++} 0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range: %SystemRoot%\system32\mswsock.dll [MS], 01 - 10 Toolbars, Explorer Bars, Extensions: ------------------------------------ Explorer Bars HKLM\SOFTWARE\Classes\CLSID\{2A541AE1-5BF6-4665-A8A3-CFA9672E4291}\(Default) = Groove Folder Synchronization Implemented Categories\{00021493-0000-0000-C000-000000000046}\ [vertical bar] InProcServer32\(Default) = C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [MS] HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{2A541AE1-5BF6-4665-A8A3-CFA9672E4291}\(Default) = Groove Folder Synchronization Implemented Categories\{00021493-0000-0000-C000-000000000046}\ [vertical bar] InProcServer32\(Default) = C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL [MS] Extensions (Tools menu items, main toolbar menu buttons) HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\ {2670000A-7350-4F3C-8081-5663EE0C6C49}\ ButtonText = Verzenden naar OneNote MenuText = &Verzenden naar OneNote CLSIDExtension = {48E73304-E1D6-4330-914C-F5F514E3486C} -> {HKLM...CLSID} = Send to OneNote from Internet Explorer button \InProcServer32\(Default) = C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll [MS] {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA}\ ButtonText = &Gekoppelde notities van OneNote MenuText = &Gekoppelde notities van OneNote CLSIDExtension = {FFFDC614-B694-4AE6-AB38-5D6374584B52} -> {HKLM...CLSID} = Linked Notes button \InProcServer32\(Default) = C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll [MS] HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Extensions\ {0000036B-C524-4050-81A0-243669A86B9F}\ ButtonText = @C:\Program Files (x86)\Windows Live\Companion\companionlang.dll,-600 CLSIDExtension = {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} -> {HKLM...Wow...CLSID} = Windows Live Messenger Companion Command Bar Button \InProcServer32\(Default) = C:\Program Files (x86)\Windows Live\Companion\companioncore.dll [MS] {08B0E5C0-4FCB-11CF-AAA5-00401C608501}\ MenuText = Sun Java Console CLSIDExtension = {CAFEEFAC-001067-0002-0067-ABCDEFFEDCBC} {219C3416-8CB2-491A-A3C7-D9FCDDC9D600}\ ButtonText = @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 MenuText = @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 CLSIDExtension = {5F7B1267-94A9-47F5-98DB-E99415F33AEC} -> {HKLM...Wow...CLSID} = BlogThisToolbarButton Class \InProcServer32\(Default) = C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll [MS] {2670000A-7350-4F3C-8081-5663EE0C6C49}\ ButtonText = Verzenden naar OneNote MenuText = &Verzenden naar OneNote CLSIDExtension = {48E73304-E1D6-4330-914C-F5F514E3486C} -> {HKLM...Wow...CLSID} = Send to OneNote from Internet Explorer button \InProcServer32\(Default) = C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll [MS] {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA}\ ButtonText = &Gekoppelde notities van OneNote MenuText = &Gekoppelde notities van OneNote CLSIDExtension = {FFFDC614-B694-4AE6-AB38-5D6374584B52} -> {HKLM...Wow...CLSID} = Linked Notes button \InProcServer32\(Default) = C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll [MS] {CCC7B152-1D8C-11E3-B2AD-F3EF3D58318D}\ ButtonText = Site Finder CLSIDExtension = {CCC7B151-1D8C-11E3-B2AD-F3EF3D58318D} Running Services (Display Name, Service Name, Path {Service DLL}): ------------------------------------------------------------------ Adobe Acrobat Update Service, AdobeARMservice, "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe" [Adobe Systems Incorporated] Advanced SystemCare Service 8, AdvancedSystemCareService8, C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASCService.exe [IObit] avast! Antivirus, avast! Antivirus, "C:\Program Files\AVAST Software\Avast\AvastSvc.exe" [AVAST Software] avast! Firewall, avast! Firewall, "C:\Program Files\AVAST Software\Avast\afwServ.exe" [AVAST Software] AVG PC TuneUp Service, TuneUp.UtilitiesSvc, "C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe" [AVG] AVG Thema-uitbreiding, UxTuneUp, C:\Windows\System32\svchost.exe -k netsvcs {C:\Windows\System32\uxtuneup.dll [AVG]} Easybits Shared Services for Windows, ezSharedSvc, C:\Windows\system32\svchost.exe -k netsvcs {C:\Windows\System32\ezsvc7.dll [file not found]} IMF Service, IMFservice, C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe [IObit] MBAMScheduler, MBAMScheduler, "C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe" [Malwarebytes Corporation] MBAMService, MBAMService, "C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe" [Malwarebytes Corporation] NVIDIA Display Driver Service, nvsvc, "C:\Windows\system32\nvvsvc.exe" [NVIDIA Corporation] Office Software Protection Platform, osppsvc, "C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE" [MS] Windows Presentation Foundation Font Cache 3.0.0.0, FontCache3.0.0.0, C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [MS] Safe Mode Drivers & Services (subkey name, subkey default value): ----------------------------------------------------------------- HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal\ <> IMFservice, Service <> PEVSystemStart, Service HKLM\System\CurrentControlSet\Control\SafeBoot\Network\ <> PEVSystemStart, Service Keyboard Driver Filters: ------------------------ HKLM\SYSTEM\CurrentControlSet\Control\Class\{4D36E96B-E325-11CE-BFC1-08002BE10318}\ <> UpperFilters = <> aswKbd [AVAST Software],kbdclass [MS],<> [file not found] Print Monitors: --------------- HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors\ LEADTOOLS ePrint 5 Monitor\Driver = C:\Windows\system32\LPPMN05X.DLL [LEAD Technologies, Inc.] ==== Empty IE Cache ====================== C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Peter\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully C:\Users\UpdatusUser\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Peter\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot ==== Empty FireFox Cache ====================== No FireFox Cache found ==== Empty Chrome Cache ====================== C:\Users\Peter\AppData\Local\Chromium\User Data\Default\Cache emptied successfully C:\Users\Peter\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully ==== Empty All Flash Cache ====================== Flash Cache Emptied Successfully ==== Empty All Java Cache ====================== Java Cache cleared successfully ==== C:\zoek_backup content ====================== ==== Empty Temp Folders ====================== C:\Users\Default\AppData\Local\Temp emptied successfully C:\Users\Default User\AppData\Local\Temp emptied successfully C:\Users\Peter\AppData\Local\Temp will be emptied at reboot C:\Users\UpdatusUser\AppData\Local\Temp emptied successfully C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully C:\Windows\Temp will be emptied at reboot ==== After Reboot ====================== ==== Empty Temp Folders ====================== C:\Windows\Temp successfully emptied C:\Users\Peter\AppData\Local\Temp successfully emptied ==== Empty Recycle Bin ====================== C:\$RECYCLE.BIN successfully emptied ==== Deleting Files / Folders ====================== "C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" deleted "C:\Users\Peter\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not deleted "C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not deleted ==== EOF on do 25/12/2014 at 8:34:07,41 ======================