Zoek.exe v5.0.0.0 Updated 04-May-2015 Tool run by Sven on vr 19/06/2015 at 18:51:13,97. Microsoft Windows 8.1 6.3.9600 x64 Running in: Normal Mode Internet Access Detected Launched: C:\Users\Sven\Downloads\zoek (2).exe [Scan all users] [Script inserted] [Checkboxes used] ==== Older Logs ====================== C:\zoek-results2015-06-19-164432.log 256785 bytes ==== Running Processes ====================== C:\WINDOWS\system32\wininit.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe -k DcomLaunch C:\WINDOWS\system32\svchost.exe -k RPCSS C:\WINDOWS\system32\dwm.exe C:\WINDOWS\system32\atiesrxx.exe C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted C:\WINDOWS\system32\svchost.exe -k netsvcs C:\WINDOWS\system32\svchost.exe -k LocalService C:\WINDOWS\system32\atieclxx.exe C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Program Files\IDT\WDM\STacSV64.exe C:\Windows\System32\WUDFHost.exe C:\WINDOWS\system32\svchost.exe -k NetworkService C:\WINDOWS\System32\spoolsv.exe C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\taskhostex.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\GWX\GWX.exe C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe C:\WINDOWS\system32\svchost.exe -k apphost C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe C:\WINDOWS\System32\svchost.exe -k utcsvc C:\WINDOWS\system32\dashost.exe c:\Program Files\Intel\iCLS Client\HeciServer.exe C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe C:\Program Files (x86)\SMART Technologies\Education Software\SMARTHelperService.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\Program Files (x86)\WordShark_1.10.0.17\Service\wssvc.exe C:\WINDOWS\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20856_x64__8wekyb3d8bbwe\LiveComm.exe C:\WINDOWS\system32\SearchIndexer.exe C:\Windows\System32\skydrive.exe C:\Windows\System32\RuntimeBroker.exe C:\Program Files\IDT\WDM\Beats64.exe C:\Program Files\IDT\WDM\sttray64.exe C:\Windows\System32\cpuminer-gw64.exe C:\WINDOWS\system32\conhost.exe C:\Program Files\HP\HP ENVY 4500 series\Bin\ScanToPCActivationApp.exe C:\Program Files\HP\HP ENVY 4500 series\Bin\HPNetworkCommunicatorCom.exe C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe C:\Program Files (x86)\SMART Technologies\Education Software\FloatingTools.exe C:\Program Files (x86)\SMART Technologies\Education Software\SMARTNotification.exe C:\Program Files (x86)\SMART Technologies\Education Software\SMARTSystemMenu.exe C:\Program Files (x86)\SMART Technologies\Education Software\SMARTBoardService.exe C:\Program Files (x86)\SMART Technologies\Education Software\SMARTInk.exe C:\Program Files (x86)\Mindjet\MindManager 15\MmReminderService.exe C:\Program Files (x86)\SMART Technologies\Education Software\sbsdk-server\SBWDKService.exe C:\WINDOWS\system32\conhost.exe C:\Program Files (x86)\SMART Technologies\Education Software\Office\SMARTInk-SBSDKProxy.exe C:\Program Files (x86)\SMART Technologies\Education Software\SMARTInkPrivilegedAccess.exe C:\Program Files\Windows Defender\MpCmdRun.exe C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe C:\Program Files (x86)\Hewlett-Packard\HP Connected Remote\HPConnectedRemoteService.exe C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe C:\Program Files (x86)\Norton Internet Security\Engine\20.6.0.27\ccSvcHst.exe C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe C:\Program Files (x86)\Norton Internet Security\Engine\20.6.0.27\ccSvcHst.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Windows\System32\SettingSyncHost.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Hewlett-Packard\HP Connected Remote\HPConnectedRemoteUser.exe C:\WINDOWS\System32\svchost.exe -k LocalServicePeerNet C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\WINDOWS\system32\wbem\wmiprvse.exe C:\WINDOWS\system32\DllHost.exe C:\WINDOWS\system32\taskeng.exe svchost.exe C:\WINDOWS\sysWOW64\wbem\wmiprvse.exe C:\Users\Sven\AppData\Local\Dropbox\Update\DropboxUpdate.exe C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Users\Sven\Downloads\zoek (2).exe C:\WINDOWS\system32\conhost.exe C:\Users\Sven\AppData\Roaming\Dropbox\bin\Dropbox.exe C:\WINDOWS\system32\wbem\wmiprvse.exe ==== Windows Installer Info ====================== Adobe AIR [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\E22677B709EDAE842B7C22B7D15EA810]C:\WINDOWS\Installer\2febf648.msi Adobe Flash Player 12 Plugin [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\70DC23D9C5AE97A49B670C7C9F57DE4E]C:\WINDOWS\Installer\1ca665f3.msi Adobe Reader XI (11.0.11) - Nederlands [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\68AB67CA7DA73401B744BA0000000010]C:\windows\Installer\e3084fa3.msi Adobe Refresh Manager [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\68AB67CA408033019195008120111403]C:\WINDOWS\Installer\ab6b2a4.msi AMD APP SDK Runtime [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\D276F30548C6A844F8F8B43CA58C4314]C:\windows\Installer\303e6.msi AMD Catalyst Install Manager [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\390128FB3DFCB1CE3B758671EE435E7C]C:\windows\Installer\3034f.msi Belgium e-ID middleware 4.0.7 (build 7466) [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\ED365428DA576614D90C6B84F2024766]C:\WINDOWS\Installer\1e63430b.msi Belgium e-ID middleware 4.1.3 (build 1554) [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\AEA249BD6D394EF4882681D0537A5145]C:\WINDOWS\Installer\1e5cfb61.msi Camtasia Studio 8 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\FBAFD474B55E5094BAAA0497A1A67CF7]C:\WINDOWS\Installer\35e03290.msi Catalyst Control Center - Branding [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\29E12B39A783DA64182A8B769C5D1D57]C:\windows\Installer\30354.msi Catalyst Control Center [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\7488F7BBB820C663B34CABB36CA5D663]C:\windows\Installer\303dc.msi Catalyst Control Center Graphics Previews Common [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\D0718D6ABF517371F1A5BD90FC89F505]C:\windows\Installer\30359.msi Catalyst Control Center InstallProxy [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\401A7DAC70FA990BDB7DBF9B43093DA4]C:\windows\Installer\30349.msi Catalyst Control Center Localization All [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\3D63915543EA6C177B0EE94F6E28BB4C]C:\windows\Installer\303cc.msi Catalyst Control Center Profiles Desktop [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\356AADC2EEA80BCA135394E1ACC35AAC]C:\windows\Installer\303d1.msi ccc-utility64 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\7EA6C0F103982E5CF78B0420B6307F06]C:\windows\Installer\303d6.msi CCC Help Chinese Standard [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\BFFBA0367A70391D6DA65B147DE15CAB]C:\windows\Installer\303c2.msi CCC Help Chinese Traditional [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\B0193A2ECE032641C7E21A2C63A5DB37]C:\windows\Installer\303c7.msi CCC Help Czech [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\917253278A3A779827DDD814DBF629BB]C:\windows\Installer\3035e.msi CCC Help Danish [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\658C54A7A3FCC2E92D0458C2A979C279]C:\windows\Installer\30363.msi CCC Help Dutch [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\922BCB2F274FA31DF35791FA04502126]C:\windows\Installer\3039a.msi CCC Help English [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\98F5C9D6AAD19094C9A867180CFC3C3F]C:\windows\Installer\30372.msi CCC Help Finnish [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\58DA2CC16B22BDBB980EEE4D74253E37]C:\windows\Installer\3037c.msi CCC Help French [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\1869D2E80505417D3EEE1E2DC783BA1B]C:\windows\Installer\30381.msi CCC Help German [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\63C23F51C5ECEA1FD4509B5E4DF5E5FB]C:\windows\Installer\30368.msi CCC Help Greek [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A441A3999111FBF01F75FE4951BC327B]C:\windows\Installer\3036d.msi CCC Help Hungarian [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\EEF6150A3FDED561D75DB57CD115BD6E]C:\windows\Installer\30386.msi CCC Help Italian [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\72CBA09863DD21A0554DE87DC32F7BE2]C:\windows\Installer\3038b.msi CCC Help Japanese [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\6BEF443B56C6B66A3A60EA38CCF820B9]C:\windows\Installer\30390.msi CCC Help Korean [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\23CEBE2462E7BB027FB35004608D29D4]C:\windows\Installer\30395.msi CCC Help Norwegian [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\1725410167F3D385AADA2057E306C4EC]C:\windows\Installer\3039f.msi CCC Help Polish [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\E689AC2436D1368BE27566FCB11ACEFE]C:\windows\Installer\303a4.msi CCC Help Portuguese [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\7292A855CB59AC737E090A346CEE0A46]C:\windows\Installer\303a9.msi CCC Help Russian [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\94FEF5F833F406FD65794A801CDE4074]C:\windows\Installer\303ae.msi CCC Help Spanish [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\F27F8EE35B11E56742C1DC26B8745F6A]C:\windows\Installer\30377.msi CCC Help Swedish [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\72DDBE74E2EFF66DF3906D6479224F49]C:\windows\Installer\303b3.msi CCC Help Thai [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\69335412536C92120F5C8D604E4DA1C1]C:\windows\Installer\303b8.msi CCC Help Turkish [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\7546545A4054B3AC0A82B0D034C2EEE7]C:\windows\Installer\303bd.msi D3DX10 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\7BD4C90EC03660F46A13E87A329932FA]C:\windows\Installer\304b0.msi Galerie de photos Windows Live [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\7430F8847A4C4734197A0318B8DE7A01]C:\windows\Installer\30562.msi Garmin BaseCamp [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\4DF8CABECE827F64FBE9986D6E760310]C:\WINDOWS\Installer\1c689f4e.msi Garmin USB Drivers [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\CFC6D5D37903A524D8F8E7FAD57546D1]C:\WINDOWS\Installer\1c689f46.msi Google Earth [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\AF057718A6CED58499106038EAF6DF1F]C:\WINDOWS\Installer\6405ec2b.msi Google Update Helper [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\93BAD29AC2E44034A96BCB446EB8552E]C:\WINDOWS\Installer\8f92a49f.msi Google Update Helper [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A089CE062ADB6BC44A720BA745894BAC]C:\WINDOWS\Installer\2c90b8a7.msi Gynzy [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\D6C1049AAF7E46B9D0149876EB131735]C:\WINDOWS\Installer\2febf64d.msi Hewlett-Packard ACLM.NET v1.2.2.3 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\701043F6AA9F6C745BC43C1AF91155F3]C:\WINDOWS\Installer\3a1eb400.msi HP Connected Remote [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\B43A342FF7BA56047B078BB567C742C7]C:\WINDOWS\Installer\146c0b.msi HP Customer Experience Enhancements [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\0694AF70830BBE9498B1F95939A05A44]C:\windows\Installer\303f6.msi HP ENVY 4500 series Basic Device Software [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\643F9632ED9780D49899AAFC6F4FA1F6]C:\WINDOWS\Installer\5e71d258.msi HP Postscript Converter [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\6D6E41E65713A1E49B43AC5B8A3676DC]C:\windows\Installer\3042c.msi HP Registration Service [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2FCC6D4EFAA0C9B4D95E98E3CDB9B4AA]c:\windows\Installer\30331.msi HP Support Assistant [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\31B3A53EDC877694A88CAAF9AD96E3ED]C:\WINDOWS\Installer\3a1eb3fb.msi HP Support Information [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\8C1B7B2BB8C7C674EBC24079135C9529]C:\windows\Installer\30637.msi HydraVision [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\904A9913A9EE544E22077598BF64D19A]C:\windows\Installer\303e1.msi Intel© Trusted Connect Service Client [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\DFA4044F3FE21C04C890925E3F6B79B2]c:\windows\Installer\30344.msi Java 8 Update 31 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\4EA42A62D9304AC4784BF2381208130F]C:\WINDOWS\Installer\eccf4cb.msi LabelPrint [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\C971C95CD8669A946BAE1012CCCF2134]c:\windows\Installer\3040d.msi Media Suite [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\42C6FBF1Df1C10144AB2C065F4E9E897]c:\windows\Installer\30408.msi Microsoft Application Error Reporting [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\000021599B0090400100000000F01FEC]C:\windows\Installer\30449.msi Microsoft Office Access MUI (Dutch) 2010 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109510031400000000000F01FEC]C:\windows\Installer\98e3250.msi Microsoft Office Excel MUI (Dutch) 2010 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109610031400000000000F01FEC]C:\windows\Installer\98e3222.msi Microsoft Office Office 64-bit Components 2010 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109A20000000100000000F01FEC]C:\windows\Installer\98e3261.msi Microsoft Office OneNote MUI (Dutch) 2010 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\000041091A0031400000000000F01FEC]C:\windows\Installer\98e324a.msi Microsoft Office Outlook MUI (Dutch) 2010 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109A10031400000000000F01FEC]C:\windows\Installer\98e322c.msi Microsoft Office PowerPoint MUI (Dutch) 2010 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109810031400000000000F01FEC]C:\windows\Installer\98e321c.msi Microsoft Office Proof (Dutch) 2010 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10031400000000000F01FEC]C:\windows\Installer\98e3231.msi Microsoft Office Proof (English) 2010 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10090400000000000F01FEC]C:\windows\Installer\98e3240.msi Microsoft Office Proof (French) 2010 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F100C0400000000000F01FEC]C:\windows\Installer\98e323b.msi Microsoft Office Proof (German) 2010 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10070400000000000F01FEC]C:\windows\Installer\98e3236.msi Microsoft Office Proofing (Dutch) 2010 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109C20031400000000000F01FEC]C:\windows\Installer\98e3245.msi Microsoft Office Publisher MUI (Dutch) 2010 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109910031400000000000F01FEC]C:\windows\Installer\98e3255.msi Microsoft Office Shared 64-bit MUI (Dutch) 2010 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109A20031400100000000F01FEC]C:\windows\Installer\98e3227.msi Microsoft Office Shared MUI (Dutch) 2010 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109E60031400000000000F01FEC]C:\windows\Installer\98e3217.msi Microsoft Office Single Image 2010 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000000000000F01FEC]C:\windows\Installer\98e3268.msi Microsoft Office Word MUI (Dutch) 2010 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109B10031400000000000F01FEC]C:\windows\Installer\98e325b.msi Microsoft SQL Server 2005 Compact Edition [ENU] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\1D034B0FAA6BD374B960AAD30DF10D8B]C:\windows\Installer\304f4.msi Microsoft SQL Server Compact 3.5 SP2 ENU [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\D30CF9A3586C138449FCE4FD3D474979]C:\WINDOWS\Installer\146c10.msi Microsoft SQL Server Compact 3.5 SP2 x64 ENU [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\DA93DA4DE19033D4BBB2956FCF8BDA3C]C:\WINDOWS\Installer\146c1a.msi Microsoft Visual C++ 2005 Redistributable [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\3e43b73803c7c394f8a6b2f0402e19c2]C:\windows\Installer\30418.msi Microsoft Visual C++ 2005 Redistributable [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\b25099274a207264182f8181add555d0]C:\WINDOWS\Installer\5e4e37ab.msi Microsoft Visual C++ 2005 Redistributable [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\c1c4f01781cc94c4c8fb1542c0981a2a]C:\windows\Installer\30404.msi Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\1007C6B46D7C017319E3B52CF3EC196E]c:\windows\Installer\30632.msi Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\67D6ECF5CD5FBA732B8B22BAC8DE1B4D]c:\windows\Installer\5bce8ab.msi Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\D20352A90C039D93DBF6126ECE614057]c:\windows\Installer\30431.msi Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\CFD2C1F142D260E3CB8B271543DA9F98]C:\windows\Installer\3041d.msi Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\6E815EB96CCE9A53884E7857C57002F0]c:\windows\Installer\5bce8b1.msi Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\1926E8D15D0BCE53481466615F760A7F]c:\windows\Installer\25add.msi Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\1D5E3C0FEDA1E123187686FED06E995A]c:\windows\Installer\24031.msi Microsoft Visual Studio 2010 Tools for Office Runtime (x64) [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\4BEA594979BAED93C82408E6FE57CE7A]c:\WINDOWS\Installer\2d77def8.msi Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - NLD [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\64A95FF38022A7A3CBE8D50CBBABA178]c:\WINDOWS\Installer\2d77df23.msi Mindjet MindManager 15 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\C97619357E26AED428CFF177EA76762E]C:\WINDOWS\Installer\5e4e37ae.msi MSVCRT [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A6C64DD86500CEF47BA082BB611A1FF1]C:\windows\Installer\304ad.msi Office 15 Click-to-Run Extensibility Component [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00005109C80000000000000000F01FEC]C:\WINDOWS\Installer\1cedf6a4.msi Office 15 Click-to-Run Licensing Component [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00005109F80000000100000000F01FEC]C:\WINDOWS\Installer\1cedf700.msi Office 15 Click-to-Run Localization Component [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00005109C80031400000000000F01FEC]C:\WINDOWS\Installer\1cedf73b.msi PhotoDirector [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A4432684C93A7984CA4D1AEB5D61C3A5]c:\windows\Installer\30421.msi Power2Go [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\D84D78A2FDF3df1479DC1A3E07FEFF2E]c:\windows\Installer\30435.msi PowerDirector [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2D6F4B0BEA2FA1544969F6F2A698B723]c:\windows\Installer\3043a.msi PowerDVD [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\DE532CED4A8571542A874CE1D8EABAB3]c:\windows\Installer\30442.msi PowerRecover [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\BA0A2B44E214C8F40B851D8EEACCFD5F]c:\windows\Installer\303fa.msi SMART-productstuurprogramma's [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\1809021B28D5A8F43881EB57386B2E56]C:\WINDOWS\Installer\1ca6659c.msi SMART Dutch Language Pack [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\3D23AE77CEEF21B46A5C1F3ED6BC0835]C:\WINDOWS\Installer\1ca665b9.msi SMART Ink [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\873D5F4B4879B244795D42ACFA2399AA]C:\WINDOWS\Installer\1ca665a4.msi SMART Notebook [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\58C27FD45C3379240AEDCFD67B6696D5]C:\WINDOWS\Installer\1ca665b4.msi Steam [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9C8928403D4AB094F99FBA20A329833F]C:\windows\Installer\1398bc.msi Windows Live [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\F1F913432FC79CC43B75A17E2DFFA35C]C:\windows\Installer\30491.msi Windows Live Communications Platform [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\3D04254D3B6B9FF42B3445CE3E1E0066]C:\windows\Installer\304bd.msi Windows Live Essentials [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\032440EF5AC97F34B985A55C2AA8F133]C:\windows\Installer\305f5.msi Windows Live Essentials [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\0EE4E59FE6C037246B9B19DFF670D167]C:\windows\Installer\304a3.msi Windows Live Essentials [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\B53C70A248384AD4A95944B2C6980A37]C:\windows\Installer\3047e.msi Windows Live Fotogalerie [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\C81D311B0B767BF43B928EB96691A46E]C:\windows\Installer\3053f.msi Windows Live Installer [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\F132F0B0A6ECD384AA32773B467F9571]C:\windows\Installer\30468.msi Windows Live Language Selector [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\BAF5E720674195C4AA4B23FE82253099]C:\windows\Installer\3044c.msi Windows Live Movie Maker [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\4314AE291D01A814191EA5403531A183]C:\windows\Installer\30526.msi Windows Live Movie Maker [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\45B88E4E7774956469A7E2DEE1A6DF38]C:\windows\Installer\3054d.msi Windows Live Movie Maker [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\5DB8CED64757AF740B0894B2BB2EEF3A]C:\windows\Installer\30570.msi Windows Live Movie Maker [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\7F80AB91827CC964A853FBDB6333EB80]C:\windows\Installer\3061a.msi Windows Live Movie Maker [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9D4227BCACD61F34F838B6E1930AF029]C:\windows\Installer\30593.msi Windows Live Photo Common [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\0C8D398C0AB171541BC18EB9567EF207]C:\windows\Installer\30555.msi Windows Live Photo Common [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\0D262DB9887B64540A5A4F5FE63C38B4]C:\windows\Installer\30578.msi Windows Live Photo Common [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\4CD7BA2CE9849EB488A72562F2ABBD0E]C:\windows\Installer\30532.msi Windows Live Photo Common [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\775F634D5961F2D4B844CA679CE90020]C:\windows\Installer\305ff.msi Windows Live Photo Common [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\B6ACDB9A3563B764CA384963D73AFB3E]C:\windows\Installer\304d5.msi Windows Live Photo Gallery [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\0FB3B06AB459FA248B8DC2D1436B31AA]C:\windows\Installer\30585.msi Windows Live Photo Gallery [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\4A9D4F432C248434EB4F5E358C54947E]C:\windows\Installer\3060c.msi Windows Live Photo Gallery [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\766F6333940964D4896BC447E3BE5C1B]C:\windows\Installer\304f7.msi Windows Live PIMT Platform [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\7B292C385A83B0447A137070E0186AF4]C:\windows\Installer\304cb.msi Windows Live SOXE [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\F4E3B286A696ED244AC1C470AE61874B]C:\windows\Installer\304b6.msi Windows Live SOXE Definitions [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\26CEF00243C306D4C98ECE73E2100CF8]C:\windows\Installer\304b3.msi Windows Live UX Platform [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\E97A59ECCF4EFFF4A857920FB449F22F]C:\windows\Installer\3044f.msi Windows Live UX Platform Language Pack [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\4A4869755DDD3AC4E98AB77E9D95D34B]C:\windows\Installer\305ed.msi Windows Live UX Platform Language Pack [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\61B33B7353527E949809236678800A3A]C:\windows\Installer\3049b.msi Windows Live UX Platform Language Pack [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9FC52F6D78E4BE343B421CB29EDC6D86]C:\windows\Installer\30460.msi Windows Live UX Platform Language Pack [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\CC973E50626FD7E438456483563B30FB]C:\windows\Installer\30489.msi Windows Live Writer [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\076CFAAAB965F2A4284B2449E5D03EFE]C:\windows\Installer\3059b.msi Windows Live Writer [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2204D958D67BED0469FE9CC0AD62F344]C:\windows\Installer\305ca.msi Windows Live Writer [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\329710E78F6123E449FEA051B01D69EF]C:\windows\Installer\305e6.msi Windows Live Writer [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\60EA627A3AAA1D34783E075F0113F440]C:\windows\Installer\305b7.msi Windows Live Writer [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\AD29A9B3473627846B6452F38126D4F5]C:\windows\Installer\305d8.msi Windows Live Writer [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\CF454FAAAC2892F4BA13A60149587EE6]C:\windows\Installer\30629.msi Windows Live Writer Resources [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\11B786265B8581A4B93CD94FEC301F49]C:\windows\Installer\305d1.msi Windows Live Writer Resources [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\4A59BDD1B7DF71543B1FB2AC9A86976E]C:\windows\Installer\305c2.msi Windows Live Writer Resources [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\7B144B41D477071489AE1A6376EA2681]C:\windows\Installer\305df.msi Windows Live Writer Resources [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\EEDB8CDDCACDD4042875E3D8B4874276]C:\windows\Installer\30622.msi ==== Checking Systemdrive for Symlinks ====================== Volume in drive C is OS Volume Serial Number is 98CE-AC2C Directory of C:\ 22/08/2013 16:45 Documents and Settings [C:\Users] 0 File(s) 0 bytes Directory of C:\Program Files\Windows NT 23/11/2013 19:40 Bureau-accessoires [C:\Program Files\Windows NT\Accessories] 0 File(s) 0 bytes Directory of C:\ProgramData 22/08/2013 16:45 Application Data [C:\ProgramData] 22/01/2013 14:11 Bureaublad [C:\Users\Public\Desktop] 22/08/2013 16:45 Desktop [C:\Users\Public\Desktop] 22/01/2013 14:11 Documenten [C:\Users\Public\Documents] 22/08/2013 16:45 Documents [C:\Users\Public\Documents] 22/01/2013 14:11 Menu Start [C:\ProgramData\Microsoft\Windows\Start Menu] 22/01/2013 14:11 Sjablonen [C:\ProgramData\Microsoft\Windows\Templates] 22/08/2013 16:45 Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu] 22/08/2013 16:45 Templates [C:\ProgramData\Microsoft\Windows\Templates] 0 File(s) 0 bytes Directory of C:\ProgramData\Microsoft\Windows\Start Menu 22/01/2013 14:11 Programma's [C:\ProgramData\Microsoft\Windows\Start Menu\Programs] 0 File(s) 0 bytes Directory of C:\ProgramData\Oracle\Java\javapath 29/01/2015 16:17 java.exe [C:\Program Files (x86)\Java\jre1.8.0_31\bin\java.exe] 29/01/2015 16:17 javaw.exe [C:\Program Files (x86)\Java\jre1.8.0_31\bin\javaw.exe] 29/01/2015 16:17 javaws.exe [C:\Program Files (x86)\Java\jre1.8.0_31\bin\javaws.exe] 3 File(s) 0 bytes Directory of C:\SYSTEM.SAV\LOGS\SymLogs 30/11/2012 15:01 cclog [C:\$SysReset\Image\Users\Public\Symantec\SymSilent\cclog] 0 File(s) 0 bytes Directory of C:\Users 22/08/2013 16:45 All Users [C:\ProgramData] 22/08/2013 16:45 Default User [C:\Users\Default] 0 File(s) 0 bytes Directory of C:\Users\Administrator 23/11/2013 19:30 Application Data [C:\Users\Administrator\AppData\Roaming] 23/11/2013 19:30 Cookies [C:\Users\Administrator\AppData\Local\Microsoft\Windows\INetCookies] 23/11/2013 19:30 Local Settings [C:\Users\Administrator\AppData\Local] 23/11/2013 19:30 Menu Start [C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu] 23/11/2013 19:30 Mijn documenten [C:\Users\Administrator\Documents] 23/11/2013 19:30 NetHood [C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Network Shortcuts] 23/11/2013 19:30 Netwerkprinteromgeving [C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Printer Shortcuts] 23/11/2013 19:30 Recent [C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Recent] 23/11/2013 19:30 SendTo [C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\SendTo] 23/11/2013 19:30 Sjablonen [C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Templates] 0 File(s) 0 bytes Directory of C:\Users\Administrator\AppData\Local 23/11/2013 19:30 Application Data [C:\Users\Administrator\AppData\Local] 23/11/2013 19:30 Geschiedenis [C:\Users\Administrator\AppData\Local\Microsoft\Windows\History] 23/11/2013 19:30 Temporary Internet Files [C:\Users\Administrator\AppData\Local\Microsoft\Windows\INetCache] 0 File(s) 0 bytes Directory of C:\Users\Administrator\AppData\Local\Microsoft\Windows 23/11/2013 19:30 Temporary Internet Files [C:\Users\Administrator\AppData\Local\Microsoft\Windows\INetCache] 0 File(s) 0 bytes Directory of C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu 23/11/2013 19:30 Programma's [C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs] 0 File(s) 0 bytes Directory of C:\Users\Administrator\Documents 23/11/2013 19:30 Mijn afbeeldingen [C:\Users\Administrator\Pictures] 23/11/2013 19:30 Mijn muziek [C:\Users\Administrator\Music] 23/11/2013 19:30 Mijn video's [C:\Users\Administrator\Videos] 0 File(s) 0 bytes Directory of C:\Users\All Users 22/08/2013 16:45 Application Data [C:\ProgramData] 22/01/2013 14:11 Bureaublad [C:\Users\Public\Desktop] 22/08/2013 16:45 Desktop [C:\Users\Public\Desktop] 22/01/2013 14:11 Documenten [C:\Users\Public\Documents] 22/08/2013 16:45 Documents [C:\Users\Public\Documents] 22/01/2013 14:11 Menu Start [C:\ProgramData\Microsoft\Windows\Start Menu] 22/01/2013 14:11 Sjablonen [C:\ProgramData\Microsoft\Windows\Templates] 22/08/2013 16:45 Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu] 22/08/2013 16:45 Templates [C:\ProgramData\Microsoft\Windows\Templates] 0 File(s) 0 bytes Directory of C:\Users\All Users\Microsoft\Windows\Start Menu 22/01/2013 14:11 Programma's [C:\ProgramData\Microsoft\Windows\Start Menu\Programs] 0 File(s) 0 bytes Directory of C:\Users\All Users\Oracle\Java\javapath 29/01/2015 16:17 java.exe [C:\Program Files (x86)\Java\jre1.8.0_31\bin\java.exe] 29/01/2015 16:17 javaw.exe [C:\Program Files (x86)\Java\jre1.8.0_31\bin\javaw.exe] 29/01/2015 16:17 javaws.exe [C:\Program Files (x86)\Java\jre1.8.0_31\bin\javaws.exe] 3 File(s) 0 bytes Directory of C:\Users\Default 22/08/2013 16:45 Application Data [C:\Users\Default\AppData\Roaming] 22/08/2013 16:45 Cookies [C:\Users\Default\AppData\Local\Microsoft\Windows\INetCookies] 22/08/2013 16:45 Local Settings [C:\Users\Default\AppData\Local] 23/11/2013 19:40 Menu Start [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu] 23/11/2013 19:40 Mijn documenten [C:\Users\Default\Documents] 22/08/2013 16:45 My Documents [C:\Users\Default\Documents] 22/08/2013 16:45 NetHood [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Network Shortcuts] 23/11/2013 19:40 Netwerkprinteromgeving [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Printer Shortcuts] 22/08/2013 16:45 PrintHood [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Printer Shortcuts] 22/08/2013 16:45 Recent [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Recent] 22/08/2013 16:45 SendTo [C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo] 23/11/2013 19:40 Sjablonen [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Templates] 22/08/2013 16:45 Start Menu [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu] 22/08/2013 16:45 Templates [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Templates] 0 File(s) 0 bytes Directory of C:\Users\Default\AppData\Local 22/08/2013 16:45 Application Data [C:\Users\Default\AppData\Local] 23/11/2013 19:40 Geschiedenis [C:\Users\Default\AppData\Local\Microsoft\Windows\History] 22/08/2013 16:45 History [C:\Users\Default\AppData\Local\Microsoft\Windows\History] 22/08/2013 16:45 Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\INetCache] 0 File(s) 0 bytes Directory of C:\Users\Default\AppData\Local\Microsoft\Windows 22/08/2013 16:45 Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\INetCache] 0 File(s) 0 bytes Directory of C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu 23/11/2013 19:40 Programma's [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs] 0 File(s) 0 bytes Directory of C:\Users\Default\Documents 23/11/2013 19:40 Mijn afbeeldingen [C:\Users\Default\Pictures] 23/11/2013 19:40 Mijn muziek [C:\Users\Default\Music] 23/11/2013 19:40 Mijn video's [C:\Users\Default\Videos] 22/08/2013 16:45 My Music [C:\Users\Default\Music] 22/08/2013 16:45 My Pictures [C:\Users\Default\Pictures] 22/08/2013 16:45 My Videos [C:\Users\Default\Videos] 0 File(s) 0 bytes Directory of C:\Users\Default.migrated 22/01/2013 14:11 Menu Start [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu] 22/01/2013 14:11 Mijn documenten [C:\Users\Default\Documents] 22/01/2013 14:11 Netwerkprinteromgeving [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Printer Shortcuts] 22/01/2013 14:11 Sjablonen [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Templates] 0 File(s) 0 bytes Directory of C:\Users\Default.migrated\AppData\Local 22/01/2013 14:11 Geschiedenis [C:\Users\Default\AppData\Local\Microsoft\Windows\History] 0 File(s) 0 bytes Directory of C:\Users\Default.migrated\AppData\Roaming\Microsoft\Windows\Start Menu 22/01/2013 14:11 Programma's [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs] 0 File(s) 0 bytes Directory of C:\Users\Default.migrated\Documents 22/01/2013 14:11 Mijn afbeeldingen [C:\Users\Default\Pictures] 22/01/2013 14:11 Mijn muziek [C:\Users\Default\Music] 22/01/2013 14:11 Mijn video's [C:\Users\Default\Videos] 26/07/2012 09:22 My Music [C:\$SysReset\Image\Users\Default\Music] 26/07/2012 09:22 My Pictures [C:\$SysReset\Image\Users\Default\Pictures] 26/07/2012 09:22 My Videos [C:\$SysReset\Image\Users\Default\Videos] 0 File(s) 0 bytes Directory of C:\Users\Public\Documents 22/01/2013 14:11 Mijn afbeeldingen [C:\Users\Public\Pictures] 22/01/2013 14:11 Mijn muziek [C:\Users\Public\Music] 22/01/2013 14:11 Mijn video's [C:\Users\Public\Videos] 22/08/2013 16:45 My Music [C:\Users\Public\Music] 22/08/2013 16:45 My Pictures [C:\Users\Public\Pictures] 22/08/2013 16:45 My Videos [C:\Users\Public\Videos] 0 File(s) 0 bytes Directory of C:\Users\Sven 23/11/2013 19:30 Application Data [C:\Users\Sven\AppData\Roaming] 23/11/2013 19:30 Cookies [C:\Users\Sven\AppData\Local\Microsoft\Windows\INetCookies] 23/11/2013 19:30 Local Settings [C:\Users\Sven\AppData\Local] 23/11/2013 19:30 Menu Start [C:\Users\Sven\AppData\Roaming\Microsoft\Windows\Start Menu] 23/11/2013 19:30 Mijn documenten [C:\Users\Sven\Documents] 23/11/2013 19:30 NetHood [C:\Users\Sven\AppData\Roaming\Microsoft\Windows\Network Shortcuts] 23/11/2013 19:30 Netwerkprinteromgeving [C:\Users\Sven\AppData\Roaming\Microsoft\Windows\Printer Shortcuts] 23/11/2013 19:30 Recent [C:\Users\Sven\AppData\Roaming\Microsoft\Windows\Recent] 23/11/2013 19:30 SendTo [C:\Users\Sven\AppData\Roaming\Microsoft\Windows\SendTo] 23/11/2013 19:30 Sjablonen [C:\Users\Sven\AppData\Roaming\Microsoft\Windows\Templates] 0 File(s) 0 bytes Directory of C:\Users\Sven\AppData\Local 23/11/2013 19:30 Application Data [C:\Users\Sven\AppData\Local] 23/11/2013 19:30 Geschiedenis [C:\Users\Sven\AppData\Local\Microsoft\Windows\History] 23/11/2013 19:30 Temporary Internet Files [C:\Users\Sven\AppData\Local\Microsoft\Windows\INetCache] 0 File(s) 0 bytes Directory of C:\Users\Sven\AppData\Local\Microsoft\Windows 23/11/2013 19:30 Temporary Internet Files [C:\Users\Sven\AppData\Local\Microsoft\Windows\INetCache] 0 File(s) 0 bytes Directory of C:\Users\Sven\AppData\Roaming\Microsoft\Windows\Start Menu 23/11/2013 19:30 Programma's [C:\Users\Sven\AppData\Roaming\Microsoft\Windows\Start Menu\Programs] 0 File(s) 0 bytes Directory of C:\Users\Sven\Documents 23/11/2013 19:30 Mijn afbeeldingen [C:\Users\Sven\Pictures] 23/11/2013 19:30 Mijn muziek [C:\Users\Sven\Music] 23/11/2013 19:30 Mijn video's [C:\Users\Sven\Videos] 0 File(s) 0 bytes Directory of C:\Users\Sven\SkyDrive\Afbeeldingen\Camera-album\jaynoke 15/05/2014 09:17 (178ÿ768) SVEN - PA220011.JPG 1 File(s) 178ÿ768 bytes Total Files Listed: 7 File(s) 178ÿ768 bytes 105 Dir(s) 892ÿ950ÿ310ÿ912 bytes free ==== Deleting CLSID Registry Keys ====================== HKEY_USERS\S-1-5-21-3112560457-1514034208-837128029-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{6FE6A929-59D1-4763-91AD-29B61CFFB35B} deleted successfully HKEY_USERS\S-1-5-21-3112560457-1514034208-837128029-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{6FE6A929-59D1-4763-91AD-29B61CFFB35B} deleted successfully HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{6FE6A929-59D1-4763-91AD-29B61CFFB35B} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6FE6A929-59D1-4763-91AD-29B61CFFB35B} deleted successfully ==== Deleting CLSID Registry Values ====================== ==== Installed Programs ====================== Adobe AIR Adobe Flash Player 12 Plugin Adobe Reader XI (11.0.11) - Nederlands Adobe Refresh Manager AMD APP SDK Runtime AMD Catalyst Install Manager Belgium e-ID middleware 4.0.7 (build 7466) Belgium e-ID middleware 4.1.3 (build 1554) Camtasia Studio 8 Catalyst Control Center - Branding Catalyst Control Center Catalyst Control Center Graphics Previews Common Catalyst Control Center InstallProxy Catalyst Control Center Localization All Catalyst Control Center Profiles Desktop ccc-utility64 CCC Help Chinese Standard CCC Help Chinese Traditional CCC Help Czech CCC Help Danish CCC Help Dutch CCC Help English CCC Help Finnish CCC Help French CCC Help German CCC Help Greek CCC Help Hungarian CCC Help Italian CCC Help Japanese CCC Help Korean CCC Help Norwegian CCC Help Polish CCC Help Portuguese CCC Help Russian CCC Help Spanish CCC Help Swedish CCC Help Thai CCC Help Turkish Connected Music powered by Universal Music Group version 1.0 CyberLink LabelPrint CyberLink Media Suite 10 CyberLink PhotoDirector CyberLink Power2Go 8 CyberLink PowerDirector 10 CyberLink PowerDVD D3DX10 Definition Update for Microsoft Office 2010 (KB3054883) 32-Bit Edition Dropbox Elite Unzip Football Manager 2013 Football Manager 2015 Galerie de photos Windows Live Garmin BaseCamp Garmin USB Drivers Google Chrome Google Earth Google Update Helper Gynzy Hewlett-Packard ACLM.NET v1.2.2.3 HP Connected Music (Meridian - installer) HP Connected Remote HP Customer Experience Enhancements HP ENVY 4500 series Basic Device Software HP Postscript Converter HP Registration Service HP Support Assistant HP Support Information HydraVision IDT Audio Intel(R) Management Engine Components Intel© Trusted Connect Service Client Java 8 Update 31 Java Auto Updater McAfee Security Scan Plus Microsoft Application Error Reporting Microsoft Office 365 ProPlus - nl-nl Microsoft Office Access MUI (Dutch) 2010 Microsoft Office Excel MUI (Dutch) 2010 Microsoft Office Home and Student 2010 Microsoft Office Office 64-bit Components 2010 Microsoft Office OneNote MUI (Dutch) 2010 Microsoft Office Outlook MUI (Dutch) 2010 Microsoft Office PowerPoint MUI (Dutch) 2010 Microsoft Office Proof (Dutch) 2010 Microsoft Office Proof (English) 2010 Microsoft Office Proof (French) 2010 Microsoft Office Proof (German) 2010 Microsoft Office Proofing (Dutch) 2010 Microsoft Office Publisher MUI (Dutch) 2010 Microsoft Office Shared 64-bit MUI (Dutch) 2010 Microsoft Office Shared MUI (Dutch) 2010 Microsoft Office Single Image 2010 Microsoft Office Word MUI (Dutch) 2010 Microsoft SQL Server 2005 Compact Edition [ENU] Microsoft SQL Server Compact 3.5 SP2 ENU Microsoft SQL Server Compact 3.5 SP2 x64 ENU Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - NLD Mindjet MindManager 15 MSVCRT Norton Internet Security Office 15 Click-to-Run Extensibility Component Office 15 Click-to-Run Licensing Component Office 15 Click-to-Run Localization Component OpenFietsMap (BNLv03-05-2014) Opera Stable 30.0.1835.59 oursurfing uninstall PokerStars.be Ralink RT5390R 802.11bgn Wi-Fi Adapter Recovery Manager Security Update for Microsoft Excel 2010 (KB3054845) 32-Bit Edition Security Update for Microsoft Office 2010 (KB2687423) 32-Bit Edition Security Update for Microsoft Office 2010 (KB2760781) 32-Bit Edition Security Update for Microsoft Office 2010 (KB2810073) 32-Bit Edition Security Update for Microsoft Office 2010 (KB2850016) 32-Bit Edition Security Update for Microsoft Office 2010 (KB2863817) 32-Bit Edition Security Update for Microsoft Office 2010 (KB2880971) 32-Bit Edition Security Update for Microsoft Office 2010 (KB2881071) 32-Bit Edition Security Update for Microsoft Office 2010 (KB2920748) 32-Bit Edition Security Update for Microsoft Office 2010 (KB2956076) 32-Bit Edition Security Update for Microsoft Office 2010 (KB3054834) 32-Bit Edition Security Update for Microsoft Office 2010 (KB3054848) 32-Bit Edition Security Update for Microsoft PowerPoint 2010 (KB2920812) 32-Bit Edition Security Update for Microsoft PowerPoint 2010 (KB3054835) 32-Bit Edition Security Update for Microsoft Word 2010 (KB2553428) 32-Bit Edition Security Update for Microsoft Word 2010 (KB3054842) 32-Bit Edition Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition SMART-productstuurprogramma's SMART Dutch Language Pack SMART Ink SMART Notebook Steam Stuurprogrammapakket voor Windows - Fedict SmartCard (04/30/2014 4.0.7.5) Taalpakket voor Microsoft Visual Studio 2010 Tools for Office Runtime (x64) - NLD Update for Microsoft Access 2010 (KB2837601) 32-Bit Edition Update for Microsoft Excel 2010 (KB2956084) 32-Bit Edition Update for Microsoft Filter Pack 2.0 (KB2881026) 32-Bit Edition Update for Microsoft InfoPath 2010 (KB2817369) 32-Bit Edition Update for Microsoft Office 2010 (KB2553140) 32-Bit Edition Update for Microsoft Office 2010 (KB2589298) 32-Bit Edition Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition Update for Microsoft Office 2010 (KB2589375) 32-Bit Edition Update for Microsoft Office 2010 (KB2589386) 32-Bit Edition Update for Microsoft Office 2010 (KB2597087) 32-Bit Edition Update for Microsoft Office 2010 (KB2687275) 32-Bit Edition Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition Update for Microsoft Office 2010 (KB2794737) 32-Bit Edition Update for Microsoft Office 2010 (KB2825635) 32-Bit Edition Update for Microsoft Office 2010 (KB2883019) 32-Bit Edition Update for Microsoft Office 2010 (KB2889828) 32-Bit Edition Update for Microsoft Office 2010 (KB2965291) 32-Bit Edition Update for Microsoft Office 2010 (KB2965296) 32-Bit Edition Update for Microsoft Office 2010 (KB2965301) 32-Bit Edition Update for Microsoft Office 2010 (KB3054875) 32-Bit Edition Update for Microsoft OneNote 2010 (KB2956075) 32-Bit Edition Update for Microsoft OneNote 2010 (KB2965297) 32-Bit Edition Update for Microsoft Outlook 2010 (KB3054881) 32-Bit Edition Update for Microsoft Outlook Social Connector 2010 (KB2553308) 32-Bit Edition Update for Microsoft SharePoint Workspace 2010 (KB2760601) 32-Bit Edition Update for Microsoft Visio 2010 (KB2965292) 32-Bit Edition Update for Microsoft Visio Viewer 2010 (KB2881021) 32-Bit Edition Wild West Windows Driver Package - Garmin (grmnusb) GARMIN Devices (04/19/2012 2.3.1.0) Windows Live Communications Platform Windows Live Essentials Windows Live Fotogalerie Windows Live Installer Windows Live Language Selector Windows Live Movie Maker Windows Live Photo Common Windows Live Photo Gallery Windows Live PIMT Platform Windows Live SOXE Windows Live SOXE Definitions Windows Live UX Platform Windows Live UX Platform Language Pack Windows Live Writer Windows Live Writer Resources WordShark 1.10.0.17 ==== Deleting Services ====================== ==== Registry Fix Code x64 ====================== Windows Registry Editor Version 5.00 \Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F139C416-945A-4D59-8913-9B305AAA119D}] \wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6FE6A929-59D1-4763-91AD-29B61CFFB35B}] \wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A0D79FFA-6FC4-40E4-B71F-5BFEFD91EE92}] \wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A536E6A1-65A1-46CE-9019-57CA64C12664}] [-HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F139C416-945A-4D59-8913-9B305AAA119D}] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"=- ==== Deleting Files \ Folders ====================== C:\Program Files (x86)\Funn2Saave not found C:\Program Files (x86)\bestadblocker not found C:\ProgramData\ihpjifodjcookbpalclfljccncgfcmmf not found C:\Program Files (x86)\StatEdit not found C:\ProgramData\hpmoinaafchebndaincifapfmoffiaio not found C:\ProgramData\ifmacpgfbihbfamhfoapklbdahlbdpbk not found C:\ProgramData\10613982973089727609 not found C:\Program Files (x86)\UniDeals not found C:\ProgramData\{92a1b8d7-a5fd-d3bd-92a1-1b8d7a5fe35e} not found "C:\Program Files (x86)\Mindjet\MindManager 15\BCGCBPRO2310u.dll" deleted "C:\Program Files (x86)\Mindjet\MindManager 15\MmReminderService.exe" deleted "C:\Program Files (x86)\Mindjet\MindManager 15\MmServiceUtilities.dll" deleted "C:\Program Files (x86)\Mindjet\MindManager 15\MmUtilities.dll" deleted "C:\Program Files (x86)\Mindjet\MindManager 15\Vic32.dll" deleted "C:\Program Files (x86)\Mindjet\MindManager 15\zlib.dll" deleted "C:\Program Files (x86)\Mindjet" deleted "C:\Program Files (x86)\Mindjet\MindManager 15" deleted ==== System Specs ====================== Windows: Windows Version 6.2 (Build 9200) Memory (RAM): 6100 MB CPU Info: Intel(R) Core(TM) i5-3330 CPU @ 3.00GHz CPU Speed: 3013,3 MHz Sound Card: Speakers / Headphones (IDT High | Display Adapters: AMD Radeon HD 7400 Series | AMD Radeon HD 7400 Series Monitors: 1x; SyncMaster 206BW,SyncMaster Magic CX206BW(Analog) | Screen Resolution: 1680 X 1050 - 32 bit Network: Network Present Network Adapters: Microsoft Wi-Fi Direct Virtual Adapter | Ralink RT5390R 802.11bgn Wi-Fi Adapter | Realtek PCIe GBE Family-controller CD / DVD Drives: 1x (E: | ) E: hp DVD-RAM GH82N Ports: COM Ports NOT Present. LPT Port NOT Present. Mouse: 3 Button Wheel Mouse Present Hard Disks: C: 918,1GB | D: 11,9GB Hard Disks - Free: C: 831,6GB | D: 1,4GB Manufacturer *: AMI BIOS Info: AT/AT COMPATIBLE | | HPQOEM - 1072009 Time Zone: Romance (standaardtijd) Motherboard *: Foxconn 2ADA Country: Belgi‰ Language: NLB ==== System Specs (Software) ====================== Anti-Virus: Norton Internet Security On-access scanning disabled (Outdated) Anti-Virus: Windows Defender On-access scanning disabled (Outdated) Anti-Spyware: Windows Defender disabled (Outdated) Anti-Spyware: Norton Internet Security disabled (Outdated) Firewall: Norton Internet Security disabled Default Browser: Google Chrome 43.0.2357.124 Internet Explorer Version: 11.0.9600.17842 Google Chrome version: 43.0.2357.124 Adobe Reader version: 11.0.11.18 Sun Java version: 1.8.0_31 (32-bit) Sun Java version: 1.8.0_31 (64-bit) Flash Player version: 12.0.0.77 ==== Files Recently Created / Modified ====================== ====== C:\WINDOWS ==== ====== C:\Users\Sven\AppData\Local\Temp ==== 2015-06-19 16:51:13 D9348DB92AB4E5B94F005F0F651DE2B1 43008 ----a-w- C:\Users\Sven\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpwi5tyz.dll ====== Java Cache ===== ====== C:\WINDOWS\SysWOW64 ===== 2015-06-10 08:58:14 BD7E7AC5639FFE7CDDAA5A3F7A05D4A7 2483712 ----a-w- C:\WINDOWS\SysWOW64\msftedit.dll 2015-06-10 08:58:12 7F78583D91D0FCA9678778F45328C99F 367104 ----a-w- C:\WINDOWS\SysWOW64\puiobj.dll 2015-06-10 08:58:10 02BE9F037101364A565D224194337B0C 207872 ----a-w- C:\WINDOWS\SysWOW64\rastapi.dll 2015-06-10 08:58:01 33BC1A74FA72C3B0EE04A23FDE1045FC 158720 ----a-w- C:\WINDOWS\SysWOW64\rgb9rast.dll 2015-06-10 08:57:58 E9A91A0A589AED5328E30D8C7E59E5AE 2749952 ----a-w- C:\WINDOWS\SysWOW64\tquery.dll 2015-06-10 08:57:58 8D4CEAEE747097A70342B80EA32E018D 710144 ----a-w- C:\WINDOWS\SysWOW64\SearchIndexer.exe 2015-06-10 08:57:58 5027CAF4BFB31E4CD2918B2C2DFFC4CB 1920000 ----a-w- C:\WINDOWS\SysWOW64\mssrch.dll 2015-06-10 08:57:57 B95D112E19CFEC74692F7791ABBB03BE 391680 ----a-w- C:\WINDOWS\SysWOW64\mssph.dll 2015-06-10 08:57:57 50B6B1D4EFCB81298DE7F9415879C51B 699392 ----a-w- C:\WINDOWS\SysWOW64\mssvp.dll 2015-06-10 08:57:57 14B5D6506A366585F8D6B6097530F7F2 272896 ----a-w- C:\WINDOWS\SysWOW64\SearchProtocolHost.exe 2015-06-10 08:57:56 00ED6F8562702A00D8AEC9F70CA7DDFE 1018880 ----a-w- C:\WINDOWS\SysWOW64\UIAutomationCore.dll 2015-06-10 08:57:53 CF6502529F3819C984A26BBD83ED3C8E 180224 ----a-w- C:\WINDOWS\SysWOW64\authz.dll 2015-06-10 08:57:51 B0EDCA1168C874812A180EBCD1A43EB5 549888 ----a-w- C:\WINDOWS\SysWOW64\comctl32.dll 2015-06-10 08:57:47 975421AC32F9F6E27A58F75DAB4B5871 19607040 ----a-w- C:\WINDOWS\SysWOW64\mshtml.dll 2015-06-10 08:57:45 DB254D50B4527C2821C537E0587B44E8 12829696 ----a-w- C:\WINDOWS\SysWOW64\ieframe.dll 2015-06-10 08:57:44 E4EB138060BAE0DBAB1A3B71A3141FE7 1950720 ----a-w- C:\WINDOWS\SysWOW64\wininet.dll 2015-06-10 08:57:43 3FD7E6DB5D81FE400DB4D81D278596E6 4305920 ----a-w- C:\WINDOWS\SysWOW64\jscript9.dll 2015-06-10 08:57:42 927E38A35E4DFC4E294BD130BAA6F759 2278912 ----a-w- C:\WINDOWS\SysWOW64\iertutil.dll 2015-06-10 08:57:42 7DBCBB1647B7CD71E2039C1B50A12717 620032 ----a-w- C:\WINDOWS\SysWOW64\jscript9diag.dll 2015-06-10 08:57:42 53E9614ADFA6A40A452BA014CEF6F261 1309696 ----a-w- C:\WINDOWS\SysWOW64\urlmon.dll 2015-06-10 08:57:40 EF853EA2A6A7BD891CCF31B0C2915352 341504 ----a-w- C:\WINDOWS\SysWOW64\html.iec 2015-06-10 08:57:40 C27C8CACEBC712BE2AD791715E9734EC 664064 ----a-w- C:\WINDOWS\SysWOW64\jscript.dll 2015-06-10 08:57:40 96837E5864777688477AF6DE2332C06D 503808 ----a-w- C:\WINDOWS\SysWOW64\vbscript.dll 2015-06-10 08:57:40 2DED8A99E45053C42DD21D6937D3960C 689152 ----a-w- C:\WINDOWS\SysWOW64\msfeeds.dll 2015-06-10 08:57:39 F26680AF396F89F7ABFDA1D1D6B62011 285696 ----a-w- C:\WINDOWS\SysWOW64\dxtrans.dll 2015-06-10 08:57:39 B6D8148C1C697A7BF04EE0FE82408B6A 710144 ----a-w- C:\WINDOWS\SysWOW64\ieapfltr.dll 2015-06-10 08:57:39 AE8F02C9B1DC7364A94ABEB6E396611C 327168 ----a-w- C:\WINDOWS\SysWOW64\iedkcs32.dll 2015-06-10 08:57:39 4ABEEF30EA5B9F4718312DCB60B6C9BC 2052608 ----a-w- C:\WINDOWS\SysWOW64\inetcpl.cpl 2015-06-10 08:57:38 6B7210618D7E2CE0404ECF748701253A 76288 ----a-w- C:\WINDOWS\SysWOW64\mshtmled.dll 2015-06-10 08:57:38 3B850134010B7CCC546C29D51405C9DA 1042944 ----a-w- C:\WINDOWS\SysWOW64\actxprxy.dll 2015-06-10 08:57:35 7467B0605897898F8F32B4B9B9041F51 128000 ----a-w- C:\WINDOWS\SysWOW64\iepeers.dll 2015-06-10 08:57:34 8AE1E22527BC203BAD89212F6D09F038 880128 ----a-w- C:\WINDOWS\SysWOW64\inetcomm.dll ====== C:\WINDOWS\SysWOW64\drivers ===== ====== C:\WINDOWS\Sysnative ===== 2015-06-17 19:53:24 444DD55F8DF4A8D314E44E4E4619D15A 1413400 ----a-w- C:\WINDOWS\Sysnative\cpuminer-gw64.exe 2015-06-17 19:29:32 B6058064B034271A447E957F7B9E15BE 230 ----a-w- C:\WINDOWS\Sysnative\cpuminer-conf.json 2015-06-10 08:58:14 3F8C7B8A4C345D0378AC79746E927158 3097600 ----a-w- C:\WINDOWS\Sysnative\msftedit.dll 2015-06-10 08:58:12 9DF4C369F556A4FBAE7E1D86F1AA5593 309760 ----a-w- C:\WINDOWS\Sysnative\compstui.dll 2015-06-10 08:58:12 4DC765353D890B9813AC809C0EFF488A 477184 ----a-w- C:\WINDOWS\Sysnative\puiobj.dll 2015-06-10 08:58:12 4A5D524C19BEB337797D6448020025B4 1091072 ----a-w- C:\WINDOWS\Sysnative\localspl.dll 2015-06-10 08:58:11 574F2184043FAF24B588BA12B3CC99CC 410336 ----a-w- C:\WINDOWS\Sysnative\ApnDatabase.xml 2015-06-10 08:58:10 D044FD35EEC3BF683B963DE10A5E00C3 222208 ----a-w- C:\WINDOWS\Sysnative\rastapi.dll 2015-06-10 08:58:08 B0B46D29B9F34D19B819B48E208871A5 36864 ----a-w- C:\WINDOWS\Sysnative\UtcResources.dll 2015-06-10 08:58:08 3ECB752A6963B1CBC9AD65ED89C8ACED 1430528 ----a-w- C:\WINDOWS\Sysnative\diagtrack.dll 2015-06-10 08:58:00 6CCC851608DD076C13E37737BB75A9DC 4177920 ----a-w- C:\WINDOWS\Sysnative\win32k.sys 2015-06-10 08:57:59 F2CBC74E403A4251279D0BA9D0ECFBDB 2551808 ----a-w- C:\WINDOWS\Sysnative\mssrch.dll 2015-06-10 08:57:58 F52C9F18BE8899CF503D7D40E62C47C3 903168 ----a-w- C:\WINDOWS\Sysnative\SearchIndexer.exe 2015-06-10 08:57:58 3B8D14C7D33E3991090C726DD4CF7088 468480 ----a-w- C:\WINDOWS\Sysnative\mssph.dll 2015-06-10 08:57:58 279C2DB5C56A3674DCB98165E85237CF 3633664 ----a-w- C:\WINDOWS\Sysnative\tquery.dll 2015-06-10 08:57:57 98D0A8C3BF81774D76EAAB5977B69AB3 337408 ----a-w- C:\WINDOWS\Sysnative\SearchProtocolHost.exe 2015-06-10 08:57:57 62B3D51F60859F595317D7C3AEC5E5F2 248832 ----a-w- C:\WINDOWS\Sysnative\mssphtb.dll 2015-06-10 08:57:57 42FFA34D6A1ABBC6064E0D8A452039D3 774144 ----a-w- C:\WINDOWS\Sysnative\mssvp.dll 2015-06-10 08:57:56 3C03E08CBB76B7081173924C52D329EE 1249280 ----a-w- C:\WINDOWS\Sysnative\UIAutomationCore.dll 2015-06-10 08:57:53 CD7DC91A7F84B4C81A06B511545DE867 275968 ----a-w- C:\WINDOWS\Sysnative\authz.dll 2015-06-10 08:57:51 0341BF7622E0D547446DB254868EF965 653824 ----a-w- C:\WINDOWS\Sysnative\comctl32.dll 2015-06-10 08:57:48 A29BAFC1543F9D2234AFFFEA9BCE76C8 24917504 ----a-w- C:\WINDOWS\Sysnative\mshtml.dll 2015-06-10 08:57:46 CFA52E2FE8E623042A1EEF96EB1B9481 6026240 ----a-w- C:\WINDOWS\Sysnative\jscript9.dll 2015-06-10 08:57:45 417F80E4AFBA1AA9EBBD618F1C6D9165 2426880 ----a-w- C:\WINDOWS\Sysnative\wininet.dll 2015-06-10 08:57:44 AE5A2843B4A2E1E558B9EE13EF62CCE5 14404096 ----a-w- C:\WINDOWS\Sysnative\ieframe.dll 2015-06-10 08:57:43 6E295C7364DAEB151CC0E98434B6AC92 2885632 ----a-w- C:\WINDOWS\Sysnative\iertutil.dll 2015-06-10 08:57:43 6ABFC5736EC920C4436F32111F5CBCEE 1545728 ----a-w- C:\WINDOWS\Sysnative\urlmon.dll 2015-06-10 08:57:41 7B4A7D55E905ED9A0A4B1263BA7C6944 2865152 ----a-w- C:\WINDOWS\Sysnative\actxprxy.dll 2015-06-10 08:57:40 FF84182188CA8F0DC28CFED06C9B7816 2125824 ----a-w- C:\WINDOWS\Sysnative\inetcpl.cpl 2015-06-10 08:57:40 83781DF625A4448B39410D7FA2BDC48D 816640 ----a-w- C:\WINDOWS\Sysnative\jscript.dll 2015-06-10 08:57:40 33B5F1A727FACDEA7CDA0E35FFAADDCF 584192 ----a-w- C:\WINDOWS\Sysnative\vbscript.dll 2015-06-10 08:57:40 2BC2D3A41BB755487FD55C09938F00BC 417792 ----a-w- C:\WINDOWS\Sysnative\html.iec 2015-06-10 08:57:40 083BCA14FCE290D682D8DAC9372CBF23 801280 ----a-w- C:\WINDOWS\Sysnative\msfeeds.dll 2015-06-10 08:57:39 86FDFEA67833DB261EC01A777594EDCF 316928 ----a-w- C:\WINDOWS\Sysnative\dxtrans.dll 2015-06-10 08:57:39 7F8F9AE03D1BA4354671E05F07A40F1A 800768 ----a-w- C:\WINDOWS\Sysnative\ieapfltr.dll 2015-06-10 08:57:39 614604C8D322D0779E426917CAFE4F3E 262144 ----a-w- C:\WINDOWS\Sysnative\webcheck.dll 2015-06-10 08:57:39 3854BFE1C0F14872C94501421CC40813 814080 ----a-w- C:\WINDOWS\Sysnative\jscript9diag.dll 2015-06-10 08:57:38 ACD6FE6C82B93813F023FC01A51CB940 92160 ----a-w- C:\WINDOWS\Sysnative\mshtmled.dll 2015-06-10 08:57:38 9EFAF10AF9BFA6CDBDDE3D8C5EDC3453 145408 ----a-w- C:\WINDOWS\Sysnative\iepeers.dll 2015-06-10 08:57:37 35622F5A652C4E16774234DCA0026E74 633856 ----a-w- C:\WINDOWS\Sysnative\ieui.dll 2015-06-10 08:57:37 1E31F06BE53F11CF5E660284E68587AC 374272 ----a-w- C:\WINDOWS\Sysnative\iedkcs32.dll 2015-06-10 08:57:35 11E5CD954CC38080471E7CC2CA1558AE 1032704 ----a-w- C:\WINDOWS\Sysnative\inetcomm.dll 2015-06-05 19:39:14 F0CACB26E37A19A8049F7C4448ECC2F5 1119232 ----a-w- C:\WINDOWS\Sysnative\aeinv.dll 2015-06-05 19:39:14 E87D4371B24BC9E5BAE95AEA60FFD959 193536 ----a-w- C:\WINDOWS\Sysnative\aepic.dll 2015-06-05 19:39:14 ACDA86BD8FE54376586173BD55F678F9 756736 ----a-w- C:\WINDOWS\Sysnative\invagent.dll 2015-06-05 19:39:14 2C14C7A76B728DF9F2A0425166FDEE8F 422912 ----a-w- C:\WINDOWS\Sysnative\devinv.dll 2015-06-05 19:39:14 16D44C27EE81892ED918DA21544665DC 1020928 ----a-w- C:\WINDOWS\Sysnative\appraiser.dll 2015-06-05 19:39:14 009FD5658121B32791D55D0F34B63883 700416 ----a-w- C:\WINDOWS\Sysnative\generaltel.dll 2015-06-05 19:39:13 FC504D3310BBDABA4449C598C3F8113B 45568 ----a-w- C:\WINDOWS\Sysnative\acmigration.dll 2015-06-05 19:39:13 90BFB92CF2AB75A01BF40D22BD1670A8 227328 ----a-w- C:\WINDOWS\Sysnative\aepdu.dll ====== C:\WINDOWS\Sysnative\drivers ===== 2015-06-10 08:57:55 44603DA5A87FB491EF59C889EBBB4DDB 325464 -c--a-w- C:\WINDOWS\Sysnative\drivers\USBXHCI.SYS 2015-06-01 22:45:04 137735D9E7152EFDA4EC3B6EC72D7272 58240 ----a-w- C:\WINDOWS\Sysnative\drivers\wsfd_1_10_0_17.sys ====== C:\WINDOWS\Tasks ====== 2015-06-19 16:49:39 1007278CCEFFB35EBA50EAA850C2D0EF 978 ----a-w- C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-3112560457-1514034208-837128029-1001Core.job 2015-06-19 15:57:29 5D1AA99828408EFC3B8BDA310E38A5EB 4174 ----a-w- C:\WINDOWS\Sysnative\Tasks\WordShark Auto Updater 1.10.0.17 Pending Update 2015-06-19 15:57:28 3FA83321EC93C1F3D8893D403B2AAADD 4164 ----a-w- C:\WINDOWS\Sysnative\Tasks\WordShark Auto Updater 1.10.0.17 Core 2015-06-19 15:57:18 623335C59F1D8D3BE363DBA8FD3AE897 348 ----a-w- C:\WINDOWS\Tasks\Bidaily Synchronize Task[3c32].job 2015-06-19 15:56:54 F59EF62507DE73592D5F020C0384CF65 3810 ----a-w- C:\WINDOWS\Sysnative\Tasks\Opera scheduled Autoupdate 1434729400 2015-06-19 15:56:19 680FFA435D8162F2E35F2E8ECE8D4941 348 ----a-w- C:\WINDOWS\Tasks\Bidaily Synchronize Task[74c7].job 2015-06-19 15:56:16 A404DD3FE80DEBE4A33C40196119C802 3974 ----a-w- C:\WINDOWS\Sysnative\Tasks\LaunchPreSignup ====== C:\WINDOWS\Temp ====== ======= C:\Program Files ===== 2015-06-14 17:30:05 -------- d-----w- C:\Program Files\trend micro ======= C:\PROGRA~2 ===== 2015-06-19 15:59:48 -------- d-----w- C:\PROGRA~2\MiuiTab 2015-06-19 15:57:37 -------- d-----w- C:\PROGRA~2\Optimizer Pro 3.97 2015-06-19 15:56:31 -------- d-----w- C:\PROGRA~2\WordShark_1.10.0.17 2015-06-14 17:33:05 -------- d-----w- C:\PROGRA~2\trend micro ======= C: ===== ====== C:\Users\Sven\AppData\Roaming ====== 2015-06-19 16:50:39 -------- d-----w- C:\Users\Sven\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2015-06-19 16:49:38 -------- d-----w- C:\Users\Sven\AppData\Local\Dropbox 2015-06-19 16:40:50 -------- d-----w- C:\WINDOWS\serviceprofiles\Localservice\AppData\Local\Temp 2015-06-19 16:40:49 -------- d-----w- C:\Users\Sven\AppData\Local\Temp 2015-06-19 16:40:49 -------- d-----w- C:\Users\Default\AppData\Local\Temp 2015-06-19 16:40:49 -------- d-----w- C:\Users\Default User\AppData\Local\Temp 2015-06-19 16:40:49 -------- d-----w- C:\Users\Administrator\AppData\Local\Temp 2015-06-19 15:56:58 -------- d-----w- C:\Users\Sven\AppData\Roaming\Opera Software 2015-06-19 15:56:58 -------- d-----w- C:\Users\Sven\AppData\Local\Opera Software 2015-06-19 15:56:32 -------- d-----w- C:\Users\Sven\AppData\Roaming\cpuminer 2015-06-19 15:56:24 -------- d-----w- C:\Users\Sven\AppData\Local\Programs 2015-06-13 12:24:05 -------- d-----w- C:\Users\Sven\AppData\Local\GWX 2015-05-25 18:54:18 -------- d-sh--w- C:\Users\Sven\AppData\Locallow\EmieUserList 2015-05-25 18:54:18 -------- d-sh--w- C:\Users\Sven\AppData\Locallow\EmieSiteList 2015-05-25 18:54:18 -------- d-sh--w- C:\Users\Sven\AppData\Locallow\EmieBrowserModeList 2015-05-25 11:30:36 D41D8CD98F00B204E9800998ECF8427E 0 ----a-w- C:\Users\Sven\AppData\Local\Temp.dat ====== C:\Users\Sven ====== 2015-06-19 16:49:38 -------- d-----w- C:\ProgramData\Dropbox 2015-06-19 08:50:08 FEC2F27B4177267AE6CD92D71A42FCC1 45874680 ----a-w- C:\Users\Sven\Downloads\eID-QuickInstaller-407-7466-signed_tcm227-258853 (1).exe 2015-06-19 08:45:25 FEC2F27B4177267AE6CD92D71A42FCC1 45874680 ----a-w- C:\Users\Sven\Downloads\eID-QuickInstaller-407-7466-signed_tcm227-258853.exe 2015-06-19 08:38:38 CE0EEB94883B5DB139C6291E42D52430 26172504 ----a-w- C:\Users\Sven\Downloads\Belgium eID-QuickInstaller 4.1.3.1554_tcm227-266505.exe 2015-06-14 17:32:54 8685FAF50C04F9A9C2F56FF64B0B7ACB 1107968 ----a-w- C:\Users\Sven\Downloads\RSIT.exe 2015-06-14 17:29:23 8045ABB21A3BDD66A48E1ED5C0F0EF6A 1222144 ----a-w- C:\Users\Sven\Downloads\RSITx64.exe 2015-06-12 13:50:37 -------- d-----w- C:\WINDOWS\serviceprofiles\Localservice\winhttp 2015-05-25 11:28:53 -------- d-----w- C:\Users\Sven\.freemind ====== C: exe-files == 2015-06-19 16:50:32 A660847EC6AC5FA286BEFB5A2D7061B7 49664 ----a-w- C:\Users\Sven\AppData\Roaming\Dropbox\bin\w9xpopen.exe 2015-06-19 16:49:42 512533E01D85CC199129BFA42DC5D814 50020776 ----atw- C:\Users\Sven\AppData\Local\Dropbox\Update\Download\{CC46080E-4C33-4981-859A-BBA2F780F31E}\3.6.7\DropboxClientInstaller.exe 2015-06-19 16:49:39 885A26AA151BA44C68AE640374F5A915 80240 ----atw- C:\Users\Sven\AppData\Local\Dropbox\Update\1.3.27.29\DropboxUpdateBroker.exe 2015-06-19 16:49:39 856308D93BAEB0455CB2FF6D830EC702 80752 ----atw- C:\Users\Sven\AppData\Local\Dropbox\Update\1.3.27.29\DropboxUpdateOnDemand.exe 2015-06-19 16:49:39 7C6D524C78A1722AD987B9E47AC1FEE2 134512 ----atw- C:\Users\Sven\AppData\Local\Dropbox\Update\DropboxUpdate.exe 2015-06-19 16:49:38 7C6D524C78A1722AD987B9E47AC1FEE2 134512 ----atw- C:\Users\Sven\AppData\Local\Dropbox\Update\1.3.27.29\DropboxUpdate.exe 2015-06-19 16:49:38 7C6D524C78A1722AD987B9E47AC1FEE2 134512 ----atw- C:\Users\Sven\AppData\Local\Dropbox\Update\1.3.27.29\DropboxCrashHandler.exe 2015-06-19 16:00:54 CFCDA211980E83E3D47336E4A6D8EE0F 125148 ----a-w- C:\Program Files (x86)\MiuiTab\uninstall.exe 2015-06-19 15:57:40 D342702FCCB16E984C55EAA015C1AC6C 148112 ----a-w- C:\Program Files (x86)\Optimizer Pro 3.97\OptProLauncher.exe 2015-06-19 15:57:40 D0EFD22F211D13C274C0AC4050E0BBA5 419984 ----a-w- C:\Program Files (x86)\Optimizer Pro 3.97\OptProSchedule.exe 2015-06-19 15:57:40 605083F7A76406C892C3324E941AFD22 302224 ----a-w- C:\Program Files (x86)\Optimizer Pro 3.97\OptProCashier.exe 2015-06-19 15:57:40 13B8FCB6D77000F35F3E1086AFA997AA 544400 ----a-w- C:\Program Files (x86)\Optimizer Pro 3.97\OptProUninstaller.exe 2015-06-19 15:57:39 9D457C153D512F036A1BA4F76E82132D 893072 ----a-w- C:\Program Files (x86)\Optimizer Pro 3.97\OptProReminder.exe 2015-06-19 15:57:39 7C87C43F134BC21DD7254958BF0E87FF 889488 ----a-w- C:\Program Files (x86)\Optimizer Pro 3.97\OptProGuard.exe 2015-06-19 15:57:39 308E987E82C8A0B7F774DF9A3FD1E368 423056 ----a-w- C:\Program Files (x86)\Optimizer Pro 3.97\OptProSmartScan.exe 2015-06-19 15:57:38 D04947BB20891A34F9C5C11FB95E7CE8 655504 ----a-w- C:\Program Files (x86)\Optimizer Pro 3.97\OptProStart.exe 2015-06-19 15:57:37 E1CE9FA4B0F424708C56B3EEF7AA0F65 3645584 ----a-w- C:\Program Files (x86)\Optimizer Pro 3.97\OptimizerPro.exe 2015-06-19 15:57:37 CB579ADCC74875562F212015237282CD 1176040 ----a-w- C:\Program Files (x86)\Optimizer Pro 3.97\unins000.exe 2015-06-19 15:57:33 00ADAA0B8D3D4F0056EFDE924897033D 55909 ----a-w- C:\Users\Sven\AppData\Roaming\cpuminer\sgminer-uninst.exe 2015-06-19 15:56:46 64B3DEB2CA4A01D8EDDD3A29662D44B3 2740224 ----a-w- C:\Users\Sven\AppData\Roaming\cpuminer\sgminer\sgminer.exe 2015-06-19 15:56:32 DCEF2ED108AE7D53BEF3D155A5DDD51E 56931 ----a-w- C:\Users\Sven\AppData\Roaming\cpuminer\cpuminer-uninst.exe 2015-06-19 15:56:26 2CDD85286C5531557F3F20A7CAFA7291 29727656 ----a-w- C:\Users\Sven\Documents\Java\jre-8u25-windows-i586.exe 2015-06-19 08:50:08 FEC2F27B4177267AE6CD92D71A42FCC1 45874680 ----a-w- C:\Users\Sven\Downloads\eID-QuickInstaller-407-7466-signed_tcm227-258853 (1).exe 2015-06-19 08:45:25 FEC2F27B4177267AE6CD92D71A42FCC1 45874680 ----a-w- C:\Users\Sven\Downloads\eID-QuickInstaller-407-7466-signed_tcm227-258853.exe 2015-06-19 08:38:38 CE0EEB94883B5DB139C6291E42D52430 26172504 ----a-w- C:\Users\Sven\Downloads\Belgium eID-QuickInstaller 4.1.3.1554_tcm227-266505.exe 2015-06-17 19:53:24 444DD55F8DF4A8D314E44E4E4619D15A 1413400 ----a-w- C:\Windows\System32\cpuminer-gw64.exe 2015-06-16 09:31:50 6B556D3D4392A2A3762DA41F3968BAC0 125112 ----a-w- C:\Program Files (x86)\MiuiTab\ProtectService.exe 2015-06-16 09:31:48 A87370F1B306891063B57491988B2C98 29368 ----a-w- C:\Program Files (x86)\MiuiTab\CmdShell.exe 2015-06-16 09:31:48 416F4BEAA28501F4D1269E520216A32D 673976 ----a-w- C:\Program Files (x86)\MiuiTab\HPNotify.exe 2015-06-14 17:33:05 9A2347903D6EDB84C10F288BC0578C1C 388608 ----a-w- C:\Program Files (x86)\trend micro\Sven.exe 2015-06-14 17:32:54 8685FAF50C04F9A9C2F56FF64B0B7ACB 1107968 ----a-w- C:\Users\Sven\Downloads\RSIT.exe 2015-06-14 17:30:06 9A2347903D6EDB84C10F288BC0578C1C 388608 ----a-w- C:\Program Files\trend micro\Sven.exe 2015-06-14 17:29:23 8045ABB21A3BDD66A48E1ED5C0F0EF6A 1222144 ----a-w- C:\Users\Sven\Downloads\RSITx64.exe === C: other files == 2015-06-19 08:46:15 888DFE4137F626CEA9CCE3BD47941B64 44672 ----a-w- C:\drivers\a38usbx64.sys 2015-06-19 08:46:15 8378A77DFAF832A7ACBE90F59066FF9A 14080 ----a-w- C:\drivers\acr38svr.sys 2015-06-19 08:46:15 5F92E1E98EC2F4E6FE13D19AA3E24AD7 37632 ----a-w- C:\drivers\a38usb.sys 2015-06-19 08:46:15 2DD63DBA58D76D3B500EEC1EF77B97EC 43392 ----a-w- C:\drivers\apg8201z.sys 2015-06-19 08:46:15 0FA03F53C0A635513F34B3D85BA1D361 17674 ----a-w- C:\drivers\a38usb98.sys 2015-06-19 08:46:15 0F39961D10D4DE80C95BE441E42D9C23 50688 ----a-w- C:\drivers\apg8201zx64.sys ======== System Restore Points ======== RP89: 31/05/2015 14:31:33 - WinThruster zo, mei 31, 15 14:31 RP90: 6/06/2015 3:46:52 - Windows Update RP91: 11/06/2015 4:17:56 - Windows Update RP92: 18/06/2015 6:27:55 - Gepland controlepunt RP93: 19/06/2015 18:20:58 - zoek.exe restore point ==== Startup Registry Enabled ====================== [HKEY_USERS\S-1-5-21-3112560457-1514034208-837128029-1001\Software\Microsoft\Windows\CurrentVersion\Run] "Steam"="C:\Program Files (x86)\Steam\Steam.exe -silent" "HP ENVY 4500 series (NET)"="C:\Program Files\HP\HP ENVY 4500 series\Bin\ScanToPCActivationApp.exe -deviceID CN39U2V70M05X4:NW -scfn HP ENVY 4500 series (NET) -AutoStart 1" "Super Optimizer"="C:\Program Files (x86)\Super Optimizer\SupOptLauncher.exe" "Optimizer Pro"="C:\Program Files (x86)\Optimizer Pro 3.97\OptProLauncher.exe" "Dropbox Update"="C:\Users\Sven\AppData\Local\Dropbox\Update\DropboxUpdate.exe /c" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "StartCCC"="C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe MSRun" "CLMLServer_For_P2G8"="c:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe" "CLVirtualDrive"="c:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe /R" "beid"="C:\Program Files (x86)\Belgium Identity Card\beid35gui.exe /startup" "SMART Floating Tools"="C:\Program Files (x86)\SMART Technologies\Education Software\FloatingTools.exe" "SMARTNotification"="C:\Program Files (x86)\SMART Technologies\Education Software\SMARTNotification.exe" "SMART Tray Tools"="C:\Program Files (x86)\SMART Technologies\Education Software\SMARTSystemMenu.exe" "SMART Board Service"="C:\Program Files (x86)\SMART Technologies\Education Software\SMARTBoardService.exe -d" "sbsdk-server"="C:\Program Files (x86)\SMART Technologies\Education Software\sbsdk-server\NodeLauncher.exe" "SMART Ink"="C:\Program Files (x86)\SMART Technologies\Education Software\SMARTInk.exe -a" "MMReminderService"="C:\Program Files (x86)\Mindjet\MindManager 15\MMReminderService.exe" "Adobe ARM"="C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "Steam"="C:\Program Files (x86)\Steam\Steam.exe -silent" "HP ENVY 4500 series (NET)"="C:\Program Files\HP\HP ENVY 4500 series\Bin\ScanToPCActivationApp.exe -deviceID CN39U2V70M05X4:NW -scfn HP ENVY 4500 series (NET) -AutoStart 1" "Super Optimizer"="C:\Program Files (x86)\Super Optimizer\SupOptLauncher.exe" "Optimizer Pro"="C:\Program Files (x86)\Optimizer Pro 3.97\OptProLauncher.exe" "Dropbox Update"="C:\Users\Sven\AppData\Local\Dropbox\Update\DropboxUpdate.exe /c" ==== Startup Registry Enabled x64 ====================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "cpuminer"="C:\WINDOWS\system32\cpuminer-gw64.exe" "BeatsOSDApp"="C:\Program Files\IDT\WDM\beats64.exe" "SysTrayApp"="C:\Program Files\IDT\WDM\sttray64.exe" ==== Startup Folders ====================== 2015-01-05 15:09:39 1182 ----a-w- C:\Users\Sven\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ==== Task Scheduler Jobs ====================== C:\WINDOWS\tasks\Adobe Flash Player Updater.job --a-------- C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [03/05/2014 00:36] C:\WINDOWS\tasks\Bidaily Synchronize Task[3c32].job --a-------- C:\programdata\63f8c106-f188-f122-63f8-8c106f18041b\hqghumeaylnlf.exe [] C:\WINDOWS\tasks\Bidaily Synchronize Task[74c7].job --a-------- C:\programdata\b7c74d30-c3a6-7966-b7c7-74d30c3a34c3\hqghumeaylnlf.exe [] C:\WINDOWS\tasks\Bidaily Synchronize Task[pr].job --a-------- C:\programdata\92a1b8d7-a5fd-d3bd-92a1-1b8d7a5fe35e\the big bang theory theme song and lyrics.mov.exe [] C:\WINDOWS\tasks\DropboxUpdateTaskUserS-1-5-21-3112560457-1514034208-837128029-1001Core.job --a-------- C:\Users\Sven\AppData\Local\Dropbox\Update\DropboxUpdate.exe [19/06/2015 18:49] C:\WINDOWS\tasks\HPCeeScheduleForSVEN$.job --a-------- C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [14/09/2010 00:15] C:\WINDOWS\tasks\HPCeeScheduleForSven.job --a-------- C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [14/09/2010 00:15] ==== Other Scheduled Tasks ====================== "C:\WINDOWS\SysNative\tasks\Adobe Acrobat Update Task" [C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe] "C:\WINDOWS\SysNative\tasks\Adobe Flash Player Updater" [C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe] "C:\WINDOWS\SysNative\tasks\HP AR Program Upload - 1b7290d6a2624619a5af7bce7d7819c5a7be059c304d4a6b92fdb0e47f7e0ae4" [C:\Program Files\HP\HP ENVY 4500 series\bin\HPRewards.exe] "C:\WINDOWS\SysNative\tasks\HP AR Program Upload - 28562f7ad734406b996538af99da88a86fcbf70972ad46d2a9eac8494a216482" [C:\Program Files\HP\HP ENVY 4500 series\bin\HPRewards.exe] "C:\WINDOWS\SysNative\tasks\HP AR Program Upload - 2c8f2aaf37e6411390c487a75f8e468db76b3cfb40d24da5991a27e4db0cb5af" [C:\Program Files\HP\HP ENVY 4500 series\bin\HPRewards.exe] "C:\WINDOWS\SysNative\tasks\HP AR Program Upload - 4060291cfaf14f2cac717a5608cc5720d921259639004e6a9e143b3b8ef2b1e0" [C:\Program Files\HP\HP ENVY 4500 series\bin\HPRewards.exe] "C:\WINDOWS\SysNative\tasks\HP AR Program Upload - 4102dd13c7a54c09976069d49ce0d10c5aab11ae958a4f77ac9905da9a5a41ca" [C:\Program Files\HP\HP ENVY 4500 series\bin\HPRewards.exe] "C:\WINDOWS\SysNative\tasks\HP AR Program Upload - 5bfbddad599641dbb14db6a0110dff275d41485911b841a4939169f001a3a508" [C:\Program Files\HP\HP ENVY 4500 series\bin\HPRewards.exe] "C:\WINDOWS\SysNative\tasks\HP AR Program Upload - 6295289190a145fe9f075725f1c0bab3cfa5aa425469491fb24a9ec399c3e121" [C:\Program Files\HP\HP ENVY 4500 series\bin\HPRewards.exe] "C:\WINDOWS\SysNative\tasks\HP AR Program Upload - 6b8c5b6bf5ee49548348a5bd61bca62d47c9e6e2cf1749759e4773fca79bd6ca" [C:\Program Files\HP\HP ENVY 4500 series\bin\HPRewards.exe] "C:\WINDOWS\SysNative\tasks\HP AR Program Upload - 6e612ae1449343f8ac4bcd3832dfda11e340f2022f804761b3c4e94a14649edb" [C:\Program Files\HP\HP ENVY 4500 series\bin\HPRewards.exe] "C:\WINDOWS\SysNative\tasks\HP AR Program Upload - 902532a7208e433780d76e5663e4a9fa37773d4ade5047359149591b2324e35d" [C:\Program Files\HP\HP ENVY 4500 series\bin\HPRewards.exe] "C:\WINDOWS\SysNative\tasks\HP AR Program Upload - a6bd08f9c7fa4442a5a0b5ad59ce03145cb0840c937b48de9976a38d4b1b0fcc" [C:\Program Files\HP\HP ENVY 4500 series\bin\HPRewards.exe] "C:\WINDOWS\SysNative\tasks\HP AR Program Upload - a8712e011ef1496da4e17795884c8f5de3e83f69ecb94289b7c9873e6f2850d7" [C:\Program Files\HP\HP ENVY 4500 series\bin\HPRewards.exe] "C:\WINDOWS\SysNative\tasks\HP AR Program Upload - ab6add7986e4431d8821c3445cbc8ebb18e3425076c8496cbbdee6db88f3404c" [C:\Program Files\HP\HP ENVY 4500 series\bin\HPRewards.exe] "C:\WINDOWS\SysNative\tasks\HP AR Program Upload - cb4ed32455094240a8b314b1d79915d0bce9f667d0da4197ae0ea3717aa77ec1" [C:\Program Files\HP\HP ENVY 4500 series\bin\HPRewards.exe] "C:\WINDOWS\SysNative\tasks\HP AR Program Upload - d240834d36be497ab1d57ce5068d93221e933e1938ac4720b4a4ea08993512dc" [C:\Program Files\HP\HP ENVY 4500 series\bin\HPRewards.exe] "C:\WINDOWS\SysNative\tasks\HP AR Program Upload - db013d8b8f874b92a8c4379a734369b982ac6dbded394567ab96cf2e4a553d33" [C:\Program Files\HP\HP ENVY 4500 series\bin\HPRewards.exe] "C:\WINDOWS\SysNative\tasks\HP AR Program Upload - dd8c62206da84a0bb4cafdf081cae254f53ffa70fd5647c0a37a5457dea39d19" [C:\Program Files\HP\HP ENVY 4500 series\bin\HPRewards.exe] "C:\WINDOWS\SysNative\tasks\HPCeeScheduleForSVEN$" [C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe] "C:\WINDOWS\SysNative\tasks\LaunchPreSignup" [C:\Program Files (x86)\OLBPre\OLBPre.exe] "C:\WINDOWS\SysNative\tasks\Norton WSC Integration" ["C:\Program Files (x86)\Norton Internet Security\Engine\20.6.0.27\WSCStub.exe"] "C:\WINDOWS\SysNative\tasks\Opera scheduled Autoupdate 1434729400" [C:\Program Files (x86)\Opera\launcher.exe] "C:\WINDOWS\SysNative\tasks\User_Feed_Synchronization-{ED6F0338-2F0F-4B7C-B622-5FE5564C8BAE}" [C:\WINDOWS\system32\msfeedssync.exe] "C:\WINDOWS\SysNative\tasks\WordShark Auto Updater 1.10.0.17 Core" [C:\Program Files (x86)\WordShark_1.10.0.17\Update\WordSharkAutoUpdateClient.exe] "C:\WINDOWS\SysNative\tasks\WordShark Auto Updater 1.10.0.17 Pending Update" [C:\Program Files (x86)\WordShark_1.10.0.17\Update\WordSharkAutoUpdateClient.exe] "C:\WINDOWS\SysNative\tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start" [C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe] "C:\WINDOWS\SysNative\tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis" [C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe] "C:\WINDOWS\SysNative\tasks\Hewlett-Packard\HP Support Assistant\Update Check" [C:\ProgramData\Hewlett-Packard\HP Support Framework\Resources\Updater7\HPSFUpdater.exe] "C:\WINDOWS\SysNative\tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker" [C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe] "C:\WINDOWS\SysNative\tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_CN39U2V70M" [C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe] "C:\WINDOWS\SysNative\tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_DeviceScan" [C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe] "C:\WINDOWS\SysNative\tasks\Norton Internet Security\Norton Error Analyzer" [C:\Program Files (x86)\Norton Internet Security\Engine\20.6.0.27\SymErr.exe] "C:\WINDOWS\SysNative\tasks\Norton Internet Security\Norton Error Processor" [C:\Program Files (x86)\Norton Internet Security\Engine\20.6.0.27\SymErr.exe] "C:\WINDOWS\SysNative\tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask" [%systemroot%\system32\sc.exe start osppsvc] ==== Firefox Extensions Registry ====================== [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions] "belgiumeid@eid.belgium.be"="C:\Program Files\Mozilla Firefox\extensions\belgiumeid@eid.belgium.be" [] ==== Chromium Look ====================== Google Chrome Version: 43.0.2357.124 HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions aaaaahlfahldnilidgnlikdckbfehhca - No path found[] bejnhdlplbjhffionohbdnpcbobfejcc - C:\Program Files (x86)\Norton Internet Security\Engine\20.6.0.27\Exts\Chrome.crx[28/11/2014 13:03] bopakagnckmlgajfccecajhnimjiiedh - No path found[] iikflkcanblccfahdhdonehdalibjnif - No path found[] Search Extension by Ask v3 - Sven\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaaaahlfahldnilidgnlikdckbfehhca Google Slides - Sven\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek Docs - Sven\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake Google Drive - Sven\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf Norton Security Toolbar - Sven\AppData\Local\Google\Chrome\User Data\Default\Extensions\bejnhdlplbjhffionohbdnpcbobfejcc YouTube - Sven\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo Google Search - Sven\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf Google Sheets - Sven\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap Norton Identity Safe - Sven\AppData\Local\Google\Chrome\User Data\Default\Extensions\iikflkcanblccfahdhdonehdalibjnif Gmail - Sven\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia ==== Chromium Startpages ====================== C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Preferences {"browser":{"last_known_google_url":"https://www.google.be/","window_placement":{"bottom":1000,"left":10,"maximized":false,"right":835,"top":10,"work_area_bottom":1010,"work_area_left":0,"work_area_right":1680,"work_area_top":0}},"countryid_at_install":16965,"default_apps_install_state":3,"download":{"directory_upgrade":true},"extensions":{"alerts":{"initialized":true},"autoupdate":{"next_check":"13079223231825588"},"chrome_url_overrides":{"bookmarks":["chrome-extension://eemcgdkfndhakfknompkggombfjjjeno/main.html"]}},"intl":{"accept_languages":"nl-NL,nl,en-US,en"},"invalidator":{"client_id":"BRaETsKQnFpdOUGvhDKDBA=="},"media":{"device_id_salt":"7HEJeT3z6IXhPsC+cXHkfg=="},"net":{"http_server_properties":{"servers":{"accounts.google.com:443":{"supports_spdy":true},"ad.atdmt.com:443":{"supports_spdy":true},"ad.doubleclick.net:443":{"supports_spdy":true},"ajax.googleapis.com:443":{"supports_spdy":true},"albumsuper.info:443":{"supports_spdy":true},"analytics.twitter.com:443":{"supports_spdy":true},"apis.google.com:443":{"supports_spdy":true},"bookhome.info:443":{"supports_spdy":true},"cdnjs.cloudflare.com:443":{"supports_spdy":true},"chrome.google.com:443":{"supports_spdy":true},"clients1.google.com:443":{"supports_spdy":true},"clients2.google.com:443":{"supports_spdy":true},"clients2.googleusercontent.com:443":{"supports_spdy":true},"code.jquery.com:443":{"supports_spdy":true},"csi.gstatic.com:443":{"supports_spdy":true},"fonts.googleapis.com:443":{"supports_spdy":true},"fonts.gstatic.com:443":{"supports_spdy":true},"googleads4.g.doubleclick.net:443":{"supports_spdy":true},"i.ytimg.com:443":{"supports_spdy":true},"milkyboxrangeronline.net:443":{"supports_spdy":true},"mnh.winnermore.com:443":{"supports_spdy":true},"mymatrixinner.net:443":{"supports_spdy":true},"oauth.googleusercontent.com:443":{"supports_spdy":true},"pagead2.googlesyndication.com:443":{"supports_spdy":true},"plus.google.com:443":{"supports_spdy":true},"s.ytimg.com:443":{"supports_spdy":true},"s0.2mdn.net:443":{"supports_spdy":true},"s1.2mdn.net:443":{"supports_spdy":true},"sepx.matrixinner.info:443":{"supports_spdy":true},"ssl.google-analytics.com:443":{"supports_spdy":true},"ssl.gstatic.com:443":{"supports_spdy":true},"stats.g.doubleclick.net:443":{"supports_spdy":true},"syndication.twitter.com:443":{"supports_spdy":true},"winnering.info:443":{"supports_spdy":true},"www.facebook.com:443":{"supports_spdy":true},"www.google-analytics.com:443":{"supports_spdy":true},"www.google.be:443":{"supports_spdy":true},"www.google.com:443":{"supports_spdy":true},"www.gstatic.com:443":{"supports_spdy":true},"www.youtube.com:443":{"supports_spdy":true}},"version":3}},"plugins":{"migrated_to_pepper_flash":true,"plugins_list":[],"removed_old_component_pepper_flash_settings":true},"profile":{"avatar_bubble_tutorial_shown":2,"avatar_index":0,"content_settings":{"exceptions":{"app_banner":{},"auto_select_certificate":{},"automatic_downloads":{},"cookies":{},"fullscreen":{},"geolocation":{},"images":{},"javascript":{},"media_stream":{},"media_stream_camera":{},"media_stream_mic":{},"metro_switch_to_desktop":{},"midi_sysex":{},"mixed_script":{},"mouselock":{},"notifications":{},"plugins":{},"popups":{},"ppapi_broker":{},"protocol_handlers":{},"push_messaging":{},"ssl_cert_decisions":{}},"pattern_pairs":{},"pref_version":1},"created_by_version":"43.0.2357.124","exit_type":"Crashed","exited_cleanly":true,"icon_version":3,"managed_user_id":"","migrated_content_settings_exceptions":true,"migrated_default_content_settings":true,"migrated_default_media_stream_content_settings":true,"name":"Rosiers","per_host_zoom_levels":{}},"protection":{"macs":{}},"session":{"restore_on_startup_migrated":true,"startup_urls_migration_time":"13079206001075596"},"translate_accepted_count":{"en":0},"translate_blocked_languages":["nl"],"translate_denied_count":{"en":2},"translate_last_denied_time":1434732466535.624,"translate_too_often_denied":true,"translate_whitelists":{}} ==== Chromium Fix ====================== C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.boostsaves.com_0.localstorage deleted successfully C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.boostsaves.com_0.localstorage-journal deleted successfully C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.boostsaves.com_0.localstorage deleted successfully C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.boostsaves.com_0.localstorage-journal deleted successfully C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.re-markable00.re-markable.net_0.localstorage deleted successfully C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.re-markable00.re-markable.net_0.localstorage-journal deleted successfully ==== Set IE to Default ====================== Old Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://www.oursurfing.com/?type=hp&ts=1434729380&z=f0e0c1f9b5f5fc9119f43d8g3zecdz5m8oat8c4m1w&from=pjr&uid=WDCXWD10EZEX-60ZF5A0_WD-WMC1S199798597985" New Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://www.oursurfing.com/?type=hp&ts=1434729380&z=f0e0c1f9b5f5fc9119f43d8g3zecdz5m8oat8c4m1w&from=pjr&uid=WDCXWD10EZEX-60ZF5A0_WD-WMC1S199798597985" ==== All HKCU SearchScopes ====================== HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes "DefaultScope"="{2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0}" {012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}" {0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.oursurfing.com/web/?utm_source=b&utm_medium=pjr&utm_campaign=install_ie&utm_content=ds&from=pjr&uid=WDCXWD10EZEX-60ZF5A0_WD-WMC1S199798597985&ts=1434729589&type=default&q={searchTerms}" {2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} e Url="http://www.oursurfing.com/web/?utm_source=b&utm_medium=pjr&utm_campaign=install_ie&utm_content=ds&from=pjr&uid=WDCXWD10EZEX-60ZF5A0_WD-WMC1S199798597985&ts=1434729589&type=default&q={searchTerms}" {33BB0A4E-99AF-4226-BDF6-49120163DE86} oursurfing Url="http://www.oursurfing.com/web/?utm_source=b&utm_medium=pjr&utm_campaign=install_ie&utm_content=ds&from=pjr&uid=WDCXWD10EZEX-60ZF5A0_WD-WMC1S199798597985&ts=1434729589&type=default&q={searchTerms}" {D944BB61-2E34-4DBF-A683-47E505C587DC} eBay Url="http://www.oursurfing.com/web/?utm_source=b&utm_medium=pjr&utm_campaign=install_ie&utm_content=ds&from=pjr&uid=WDCXWD10EZEX-60ZF5A0_WD-WMC1S199798597985&ts=1434729589&type=default&q={searchTerms}" {E733165D-CBCF-4FDA-883E-ADEF965B476C} Google Url="http://www.oursurfing.com/web/?utm_source=b&utm_medium=pjr&utm_campaign=install_ie&utm_content=ds&from=pjr&uid=WDCXWD10EZEX-60ZF5A0_WD-WMC1S199798597985&ts=1434729589&type=default&q={searchTerms}" ==== Reset Google Chrome ====================== C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences was reset successfully C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Web Data-journal was reset successfully ==== Deleting CLSID Registry Keys ====================== ==== Deleting CLSID Registry Values ====================== ==== shortcuts on Users Desktops ====================== C:\Users\Sven\Desktop\Autogene training Schultz - Snelkoppeling.lnk - G:\Autogene training Schultz.mp4 C:\Users\Sven\Desktop\Dropbox.lnk - C:\Users\Sven\AppData\Roaming\Dropbox\bin\Dropbox.exe /home C:\Users\Sven\Desktop\HP Support Assistant.lnk - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe ==== shortcuts on All Users Desktop ====================== C:\Users\Public\Desktop\Adobe Reader XI.lnk - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AcroRd32.exe C:\Users\Public\Desktop\Bezoek eBay.be.lnk - C:\Program Files (x86)\Hewlett-Packard\Shared\WizLink.exe C:\Users\Public\Desktop\Connected Music powered by Universal Music Group.lnk - C:\Program Files (x86)\Connected Music powered by Universal Music Group\Connected Music powered by Universal Music Group.exe C:\Users\Public\Desktop\Connected Remote.lnk - C:\Program Files (x86)\Hewlett-Packard\HP Connected Remote\HPConnectedRemoteMgmtUI.exe C:\Users\Public\Desktop\eID Viewer.lnk - C:\Program Files (x86)\Belgium Identity Card\EidViewer\eID Viewer.exe C:\Users\Public\Desktop\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Users\Public\Desktop\Gynzy.lnk - C:\Program Files (x86)\Gynzy\Gynzy\Gynzy.exe C:\Users\Public\Desktop\HP ENVY 4500 series.lnk - C:\Program Files (x86)\HP\HP ENVY 4500 series\Bin\HP ENVY 4500 series.exe -Start UDCDevicePage C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk - C:\Program Files\McAfee Security Scan\3.8.150\McUICnt.exe SecurityScanner.dll C:\Users\Public\Desktop\Mindjet MindManager 15.lnk - C:\WINDOWS\Installer\{5391679C-62E7-4DEA-82FC-1F77AE6767E2}\Desktop_MindManager6_C4D150117314479F90CAEF8478756B79.exe C:\Users\Public\Desktop\Norton Internet Security.lnk - C:\Program Files (x86)\Norton Internet Security\Engine64\20.6.0.27\uistub.exe C:\Users\Public\Desktop\PokerStars.be.lnk - C:\Program Files (x86)\PokerStars.BE\PokerStarsUpdate.exe C:\Users\Public\Desktop\Shop for Supplies - HP ENVY 4500 series.lnk - C:\Program Files (x86)\HP\HP ENVY 4500 series\Bin\hpqDTSS.exe C:\Users\Public\Desktop\SMART Notebook 14.lnk - C:\Program Files (x86)\SMART Technologies\Education Software\Notebook.exe C:\Users\Public\Desktop\Snapfish foto's.lnk - C:\Program Files (x86)\Hewlett-Packard\Shared\WizLink.exe C:\Users\Public\Desktop\Steam.lnk - C:\Program Files (x86)\Steam\Steam.exe C:\Users\Public\Desktop\Viewer SMART Ink-document.lnk - C:\Program Files (x86)\SMART Technologies\Education Software\SMARTInkDocumentViewer.exe ==== shortcuts in Users Start Menu ====================== C:\Users\Sven\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk - C:\Program Files\Internet Explorer\iexplore.exe C:\Users\Sven\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox\Dropbox.lnk - C:\Users\Sven\AppData\Roaming\Dropbox\bin\Dropbox.exe /home C:\Users\Sven\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk - C:\Users\Sven\AppData\Roaming\Dropbox\bin\Dropbox.exe /systemstartup ==== shortcuts in All Users Start Menu ====================== C:\ProgramData\Microsoft\Windows\Start Menu\Mindjet MindManager 15.lnk - C:\WINDOWS\Installer\{5391679C-62E7-4DEA-82FC-1F77AE6767E2}\StartMenu_MindManage_C4D150117314479F90CAEF8478756B79.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk - C:\WINDOWS\Installer\{AC76BA86-7AD7-1043-7B44-AB0000000001}\SC_Reader.ico C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth.lnk - C:\Program Files (x86)\Google\Google Earth\client\googleearth.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk - C:\Program Files (x86)\Opera\launcher.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Belgium - eID\eID Viewer.lnk - C:\Program Files (x86)\Belgium Identity Card\EidViewer\eID Viewer.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Belgium - eID\Utilities\MS Office 2010 XAdES XL signature configuration.lnk - C:\Program Files (x86)\Belgium Identity Card\beidoffice2010_XAdES_XL.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Belgium - eID\Utilities\MS Outlook registry configuration.lnk - C:\Program Files (x86)\Belgium Identity Card\beidoutlooksnc.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013\Skype for Business 2015.lnk - C:\Program Files (x86)\Microsoft Office 15\root\office15\lync.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013\Hulpprogramma's van Office 2013\Skype voor Bedrijven opnamebeheer.lnk - C:\Program Files (x86)\Microsoft Office 15\root\office15\ocpubmgr.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mindjet MindManager 15\Mindjet MindManager 15.lnk - C:\WINDOWS\Installer\{5391679C-62E7-4DEA-82FC-1F77AE6767E2}\ProgramGroup_MindMan_C4D150117314479F90CAEF8478756B79.exe ==== shortcuts in Quick Launch ====================== C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk - C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk - C:\Users\Default User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk - C:\Users\Default User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk - C:\Users\Sven\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Users\Sven\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk - C:\Program Files\Internet Explorer\iexplore.exe C:\Users\Sven\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Mindjet MindManager 15.lnk - C:\WINDOWS\Installer\{5391679C-62E7-4DEA-82FC-1F77AE6767E2}\QuickLaunch_MindMana_C4D150117314479F90CAEF8478756B79.exe C:\Users\Sven\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\PokerStars.be.lnk - C:\Program Files (x86)\PokerStars.BE\PokerStarsUpdate.exe C:\Users\Sven\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk - C:\Users\Sven\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk - C:\Users\Sven\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\b1695d4f5a951d9d\PokerStars.BE.lnk - C:\Program Files (x86)\PokerStars.BE\PokerStarsUpdate.exe C:\Users\Sven\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\CyberLink Media Suite.lnk - C:\Program Files (x86)\CyberLink\Media Suite\PS.exe C:\Users\Sven\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\File Explorer.lnk - C:\Users\Sven\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Users\Sven\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk - C:\Program Files\Internet Explorer\iexplore.exe ==== Uninstall List x64 ====================== Adobe AIR [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{7B77622E-DE90-48EA-B2C7-227B1DE58A01}] Adobe AIR [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Adobe AIR] Adobe Flash Player 12 Plugin [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{9D32CD07-EA5C-4A79-B976-C0C7F975EDE4}] Adobe Reader XI (11.0.11) - Nederlands [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{AC76BA86-7AD7-1043-7B44-AB0000000001}] Adobe Refresh Manager [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{AC76BA86-0804-1033-1959-001802114130}] AMD APP SDK Runtime [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{503F672D-6C84-448A-8F8F-4BC35AC83441}] AMD Catalyst Install Manager [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{BF821093-CFD3-EC1B-B357-6817EE34E5C7}] Belgium e-ID middleware 4.0.7 (build 7466) [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{824563DE-75AD-4166-9DC0-B6482F207466}] Belgium e-ID middleware 4.1.3 (build 1554) [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{DB942AEA-93D6-4FE4-8862-180D35A71554}] Camtasia Studio 8 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{474DFABF-E55B-4905-ABAA-40791A6AC77F}] Catalyst Control Center - Branding [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{93B21E92-387A-46AD-81A2-B867C9D5D175}] Catalyst Control Center [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{BB7F8847-028B-366C-3BC4-BA3BC65A6D36}] Catalyst Control Center Graphics Previews Common [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{A6D8170D-15FB-1737-1F5A-DB09CF985F50}] Catalyst Control Center InstallProxy [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{CAD7A104-AF07-B099-BDD7-FBB93490D34A}] Catalyst Control Center Localization All [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{551936D3-AE34-71C6-B7E0-9EF4E682BBC4}] Catalyst Control Center Profiles Desktop [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{2CDAA653-8AEE-ACB0-3135-491ECA3CA5CA}] ccc-utility64 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{1F0C6AE7-8930-C5E2-7FB8-40026B03F760}] CCC Help Chinese Standard [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{630ABFFB-07A7-D193-D66A-B541D71EC5BA}] CCC Help Chinese Traditional [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{E2A3910B-30EC-1462-7C2E-A1C2365ABD73}] CCC Help Czech [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{72352719-A3A8-8977-72DD-8D41BD6F92BB}] CCC Help Danish [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{7A45C856-CF3A-9E2C-D240-852C9A972C97}] CCC Help Dutch [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{F2BCB229-F472-D13A-3F75-19AF40051262}] CCC Help English [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{6D9C5F89-1DAA-4909-9C8A-7681C0CFC3F3}] CCC Help Finnish [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{1CC2AD85-22B6-BBDB-89E0-EED44752E373}] CCC Help French [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{8E2D9681-5050-D714-E3EE-E1D27C38ABB1}] CCC Help German [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{15F32C36-CE5C-F1AE-4D05-B9E5D45F5EBF}] CCC Help Greek [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{993A144A-1119-0FBF-F157-EF9415CB23B7}] CCC Help Hungarian [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{A0516FEE-EDF3-165D-7DD5-5BC71D51DBE6}] CCC Help Italian [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{890ABC27-DD36-0A12-55D4-8ED73CF2B72E}] CCC Help Japanese [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{B344FEB6-6C65-A66B-A306-AE83CC8F029B}] CCC Help Korean [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{42EBEC32-7E26-20BB-F73B-054006D8924D}] CCC Help Norwegian [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{10145271-3F76-583D-AAAD-02753E604CCE}] CCC Help Polish [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{42CA986E-1D63-B863-2E57-66CF1BA1ECEF}] CCC Help Portuguese [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{558A2927-95BC-37CA-E790-A043C6EEA064}] CCC Help Russian [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{8F5FEF49-4F33-DF60-5697-A408C1ED0447}] CCC Help Spanish [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{3EE8F72F-11B5-765E-241C-CD628B47F5A6}] CCC Help Swedish [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{47EBDD27-FE2E-D66F-3F09-D6469722F494}] CCC Help Thai [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{21453396-C635-2129-F0C5-D806E4D41A1C}] CCC Help Turkish [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{A5456457-4504-CA3B-A028-0B0D432CEE7E}] Connected Music powered by Universal Music Group version 1.0 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{46037DC7-F927-46DF-935F-D6F122BDD34B}_is1] CyberLink LabelPrint [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{C59C179C-668D-49A9-B6EA-0121CCFC1243}] CyberLink LabelPrint [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}] CyberLink Media Suite 10 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{1FBF6C24-C1fD-4101-A42B-0C564F9E8E79}] CyberLink Media Suite 10 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\InstallShield_{1FBF6C24-C1fD-4101-A42B-0C564F9E8E79}] CyberLink PhotoDirector [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{4862344A-A39C-4897-ACD4-A1BED5163C5A}] CyberLink PhotoDirector [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\InstallShield_{4862344A-A39C-4897-ACD4-A1BED5163C5A}] CyberLink Power2Go 8 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{2A87D48D-3FDF-41fd-97CD-A1E370EFFFE2}] CyberLink Power2Go 8 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\InstallShield_{2A87D48D-3FDF-41fd-97CD-A1E370EFFFE2}] CyberLink PowerDirector 10 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{B0B4F6D2-F2AE-451A-9496-6F2F6A897B32}] CyberLink PowerDirector 10 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\InstallShield_{B0B4F6D2-F2AE-451A-9496-6F2F6A897B32}] CyberLink PowerDVD [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}] CyberLink PowerDVD [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}] D3DX10 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{E09C4DB7-630C-4F06-A631-8EA7239923AF}] Dropbox [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Dropbox] Elite Unzip [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Mindspark Elite Unzip] Football Manager 2013 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Steam App 207890] Football Manager 2015 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Steam App 295270] Galerie de photos Windows Live [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{488F0347-C4A7-4374-91A7-30818BEDA710}] Garmin BaseCamp [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{EBAC8FD4-28EC-46F7-BF9E-89D6E6673001}] Garmin USB Drivers [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{3D5D6CFC-3097-425A-8D8F-7EAF5D57641D}] Google Chrome [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Google Chrome] Google Earth [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{817750FA-EC6A-485D-9901-0683AE6FFDF1}] Google Update Helper [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}] Google Update Helper [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}] Gynzy [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{A9401C6D-E7FA-9B64-0D41-8967BE317153}] Gynzy [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\com.gynzy.air.loader.gynzy.nl] Hewlett-Packard ACLM.NET v1.2.2.3 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{6F340107-F9AA-47C6-B54C-C3A19F11553F}] HP Connected Music (Meridian - installer) [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\StartHPConnectedMusic] HP Connected Remote [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{F243A34B-AB7F-4065-B770-B85B767C247C}] HP Customer Experience Enhancements [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{07FA4960-B038-49EB-891B-9F95930AA544}] HP ENVY 4500 series Basic Device Software [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{2369F346-79DE-4D08-8999-AACFF6F41A6F}] HP Postscript Converter [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{6E14E6D6-3175-4E1A-B934-CAB5A86367CD}] HP Registration Service [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{E4D6CCF2-0AAF-4B9C-9DE5-893EDC9B4BAA}] HP Support Assistant [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{E35A3B13-78CD-4967-8AC8-AA9FDA693EDE}] HP Support Information [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{B2B7B1C8-7C8B-476C-BE2C-049731C55992}] HydraVision [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{3199A409-EE9A-E445-2270-5789FB461DA9}] IDT Audio [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}] Intel(R) Management Engine Components [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}] Intel© Trusted Connect Service Client [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{F4404AFD-2EF3-40C1-8C09-29E5F3B6972B}] Java 8 Update 31 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{26A24AE4-039D-4CA4-87B4-2F83218031F0}] McAfee Security Scan Plus [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\McAfee Security Scan] Microsoft Office 365 ProPlus - nl-nl [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\O365ProPlusRetail - nl-nl] Microsoft Office Home and Student 2010 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Office14.SingleImage] Microsoft SQL Server 2005 Compact Edition [ENU] [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}] Microsoft SQL Server Compact 3.5 SP2 ENU [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{3A9FC03D-C685-4831-94CF-4EDFD3749497}] Microsoft SQL Server Compact 3.5 SP2 x64 ENU [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{D4AD39AD-091E-4D33-BB2B-59F6FCB8ADC3}] Microsoft Visual C++ 2005 Redistributable [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}] Microsoft Visual C++ 2005 Redistributable [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{7299052b-02a4-4627-81f2-1818da5d550d}] Microsoft Visual C++ 2005 Redistributable [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}] Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}] Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}] Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{9A25302D-30C0-39D9-BD6F-21E6EC160475}] Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}] Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{9BE518E6-ECC6-35A9-88E4-87755C07200F}] Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}] Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}] Microsoft Visual Studio 2010 Tools for Office Runtime (x64) [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{9495AEB4-AB97-39DE-8C42-806EEF75ECA7}] Microsoft Visual Studio 2010 Tools for Office Runtime (x64) [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)] Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - NLD [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{3FF59A46-2208-3A7A-BC8E-5DC0BBBA1A87}] Mindjet MindManager 15 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{5391679C-62E7-4DEA-82FC-1F77AE6767E2}] MSVCRT [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}] Norton Internet Security [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\NIS] OpenFietsMap (BNLv03-05-2014) [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\OpenFietsMap (BNL)] Opera Stable 30.0.1835.59 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Opera 30.0.1835.59] oursurfing uninstall [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\oursurfing uninstall] PokerStars.be [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\PokerStars.be] Ralink RT5390R 802.11bgn Wi-Fi Adapter [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{8FC4F1DD-F7FD-4766-804D-3C8FF1D309AF}] Recovery Manager [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{44B2A0AB-412E-4F8C-B058-D1E8AECCDFF5}] SMART-productstuurprogramma's [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{B1209081-5D82-4F8A-8318-BE7583B6E265}] SMART Dutch Language Pack [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{77EA32D3-FEEC-4B12-A6C5-F1E36DCB8053}] SMART Ink [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{B4F5D378-9784-442B-97D5-24CAAF3299AA}] SMART Notebook [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{4DF72C85-33C5-4297-A0DE-FC6DB766695D}] Steam [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{048298C9-A4D3-490B-9FF9-AB023A9238F3}] Stuurprogrammapakket voor Windows - Fedict SmartCard (04/30/2014 4.0.7.5) [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\C5357B4AD7C02B3F6EF45765A07E5B725E50BBF7] Taalpakket voor Microsoft Visual Studio 2010 Tools for Office Runtime (x64) - NLD [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - NLD] Wild West [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\Wild West] Windows Driver Package - Garmin (grmnusb) GARMIN Devices (04/19/2012 2.3.1.0) [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\98157A226B40B173301B0F53C8E98C47805D5152] Windows Live [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{34319F1F-7CF2-4CC9-B357-1AE7D2FF3AC5}] Windows Live Communications Platform [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{D45240D3-B6B3-4FF9-B243-54ECE3E10066}] Windows Live Essentials [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{2A07C35B-8384-4DA4-9A95-442B6C89A073}] Windows Live Essentials [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{F95E4EE0-0C6E-4273-B6B9-91FD6F071D76}] Windows Live Essentials [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}] Windows Live Essentials [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\WinLiveSuite] Windows Live Fotogalerie [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{B113D18C-67B0-4FB7-B329-E89B66194AE6}] Windows Live Installer [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{0B0F231F-CE6A-483D-AA23-77B364F75917}] Windows Live Language Selector [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{027E5FAB-1476-4C59-AAB4-32EF28520399}] Windows Live Movie Maker [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{19BA08F7-C728-469C-8A35-BFBD3633BE08}] Windows Live Movie Maker [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{6DEC8BD5-7574-47FA-B080-492BBBE2FEA3}] Windows Live Movie Maker [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{92EA4134-10D1-418A-91E1-5A0453131A38}] Windows Live Movie Maker [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{CB7224D9-6DCA-43F1-8F83-6B1E39A00F92}] Windows Live Movie Maker [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{E4E88B54-4777-4659-967A-2EED1E6AFD83}] Windows Live Photo Common [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{9BD262D0-B788-4546-A0A5-F4F56EC3834B}] Windows Live Photo Common [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}] Windows Live Photo Common [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{C2AB7DC4-489E-4BE9-887A-52262FBADBE0}] Windows Live Photo Common [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{C893D8C0-1BA0-4517-B11C-E89B65E72F70}] Windows Live Photo Common [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{D436F577-1695-4D2F-8B44-AC76C99E0002}] Windows Live Photo Gallery [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{3336F667-9049-4D46-98B6-4C743EEBC5B1}] Windows Live Photo Gallery [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{34F4D9A4-42C2-4348-BEF4-E553C84549E7}] Windows Live Photo Gallery [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{A60B3BF0-954B-42AF-B8D8-2C1D34B613AA}] Windows Live PIMT Platform [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{83C292B7-38A5-440B-A731-07070E81A64F}] Windows Live SOXE [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{682B3E4F-696A-42DE-A41C-4C07EA1678B4}] Windows Live SOXE Definitions [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{200FEC62-3C34-4D60-9CE8-EC372E01C08F}] Windows Live UX Platform [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}] Windows Live UX Platform Language Pack [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{05E379CC-F626-4E7D-8354-463865B303BF}] Windows Live UX Platform Language Pack [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{37B33B16-2535-49E7-8990-32668708A0A3}] Windows Live UX Platform Language Pack [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}] Windows Live UX Platform Language Pack [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{D6F25CF9-4E87-43EB-B324-C12BE9CDD668}] Windows Live Writer [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{3B9A92DA-6374-4872-B646-253F18624D5F}] Windows Live Writer [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{7E017923-16F8-4E32-94EF-0A150BD196FE}] Windows Live Writer [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{859D4022-B76D-40DE-96EF-C90CDA263F44}] Windows Live Writer [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{A726AE06-AAA3-43D1-87E3-70F510314F04}] Windows Live Writer [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}] Windows Live Writer [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{AAF454FC-82CA-4F29-AB31-6A109485E76E}] Windows Live Writer Resources [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{14B441B7-774D-4170-98EA-A13667AE6218}] Windows Live Writer Resources [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{1DDB95A4-FD7B-4517-B3F1-2BCAA96879E6}] Windows Live Writer Resources [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{62687B11-58B5-4A18-9BC3-9DF4CE03F194}] Windows Live Writer Resources [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}] WordShark 1.10.0.17 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\WordShark_1.10.0.17] ==== Deleting Registry Keys ====================== HKEY_LOCAL_MACHINE\Software\wow6432node\Policies\Google deleted successfully ==== HijackThis Entries ====================== F2 - REG:system.ini: UserInit=userinit.exe O2 - BHO: LuckyTab Class - {51D26BB4-4D2C-4AE4-9873-5FF41B6DED1F} - C:\Program Files (x86)\MiuiTab\SupTab.dll O2 - BHO: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\20.6.0.27\coIEPlg.dll O2 - BHO: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\20.6.0.27\IPS\IPSBHO.DLL O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL O2 - BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll O2 - BHO: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\20.6.0.27\coIEPlg.dll O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun O4 - HKLM\..\Run: [CLMLServer_For_P2G8] "c:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe" O4 - HKLM\..\Run: [CLVirtualDrive] "c:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe" /R O4 - HKLM\..\Run: [beid] "C:\Program Files (x86)\Belgium Identity Card\beid35gui.exe" /startup O4 - HKLM\..\Run: [SMART Floating Tools] "C:\Program Files (x86)\SMART Technologies\Education Software\FloatingTools.exe" O4 - HKLM\..\Run: [SMARTNotification] "C:\Program Files (x86)\SMART Technologies\Education Software\SMARTNotification.exe" O4 - HKLM\..\Run: [SMART Tray Tools] "C:\Program Files (x86)\SMART Technologies\Education Software\SMARTSystemMenu.exe" O4 - HKLM\..\Run: [SMART Board Service] "C:\Program Files (x86)\SMART Technologies\Education Software\SMARTBoardService.exe" -d O4 - HKLM\..\Run: [sbsdk-server] "C:\Program Files (x86)\SMART Technologies\Education Software\sbsdk-server\NodeLauncher.exe" O4 - HKLM\..\Run: [SMART Ink] "C:\Program Files (x86)\SMART Technologies\Education Software\SMARTInk.exe" -a O4 - HKLM\..\Run: [MMReminderService] C:\Program Files (x86)\Mindjet\MindManager 15\MMReminderService.exe O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" O4 - HKCU\..\Run: [Steam] "C:\Program Files (x86)\Steam\Steam.exe" -silent O4 - HKCU\..\Run: [HP ENVY 4500 series (NET)] "C:\Program Files\HP\HP ENVY 4500 series\Bin\ScanToPCActivationApp.exe" -deviceID "CN39U2V70M05X4:NW" -scfn "HP ENVY 4500 series (NET)" -AutoStart 1 O4 - HKCU\..\Run: [Super Optimizer] C:\Program Files (x86)\Super Optimizer\SupOptLauncher.exe O4 - HKCU\..\Run: [Optimizer Pro] C:\Program Files (x86)\Optimizer Pro 3.97\OptProLauncher.exe O4 - HKCU\..\Run: [Dropbox Update] "C:\Users\Sven\AppData\Local\Dropbox\Update\DropboxUpdate.exe" /c O4 - Startup: Dropbox.lnk = Sven\AppData\Roaming\Dropbox\bin\Dropbox.exe O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra button: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-103 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-102 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe O9 - Extra button: Verzenden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll O9 - Extra 'Tools' menuitem: &Verzenden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll O9 - Extra button: Send to MindManager - {2F72393D-2472-4F82-B600-ED77F354B7FF} - (no file) O9 - Extra button: Skype for Business Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll O9 - Extra 'Tools' menuitem: Skype for Business Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll O9 - Extra button: &Gekoppelde notities van OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll O9 - Extra 'Tools' menuitem: &Gekoppelde notities van OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll O9 - Extra button: PokerStars.be - {878AC5FC-BE78-4bae-896C-7F75B790A71E} - C:\Program Files (x86)\PokerStars.BE\PokerStarsUpdate.exe O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing) O23 - Service: AMD External Events Utility - Unknown owner - C:\WINDOWS\system32\atiesrxx.exe (file missing) O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing) O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing) O23 - Service: FlexNet Licensing Service - Flexera Software LLC - C:\Program Files (x86)\Common Files\Macrovision Shared\FlexNet Publisher\FNPLicensingService.exe O23 - Service: Google Update-service (gupdate) (gupdate) - Unknown owner - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe (file missing) O23 - Service: Google Update-service (gupdatem) (gupdatem) - Unknown owner - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe (file missing) O23 - Service: HP Support Assistant Service - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe O23 - Service: HP Connected Remote Service (HPConnectedRemote) - Hewlett-Packard - C:\Program Files (x86)\Hewlett-Packard\HP Connected Remote\HPConnectedRemoteService.exe O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\WINDOWS\system32\IEEtwCollector.exe (file missing) O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - c:\Program Files\Intel\iCLS Client\HeciServer.exe O23 - Service: Intel(R) ME Service - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing) O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing) O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing) O23 - Service: Norton Internet Security (NIS) - Symantec Corporation - C:\Program Files (x86)\Norton Internet Security\Engine\20.6.0.27\ccSvcHst.exe O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing) O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing) O23 - Service: SMART Helper Service (SMARTHelperService) - SMART Technologies - C:\Program Files (x86)\SMART Technologies\Education Software\SMARTHelperService.exe O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing) O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing) O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing) O23 - Service: @%SystemRoot%\system32\stlang64.dll,-10101 (STacSV) - IDT, Inc. - C:\Program Files\IDT\WDM\STacSV64.exe O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing) O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing) O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing) O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing) O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing) O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing) O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing) O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing) O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing) O23 - Service: WS 1.10.0.17 Client Service (wssvc_1.10.0.17) - WS - C:\Program Files (x86)\WordShark_1.10.0.17\Service\wssvc.exe ==== Silent Runners ====================== "Silent Runners.vbs", revision 69.2, http://www.silentrunners.org/ Output limited to non-default values, except where indicated by "{++}" Startup items buried in registry: --------------------------------- HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ {++} Steam = "C:\Program Files (x86)\Steam\Steam.exe" -silent [Valve Corporation] HP ENVY 4500 series (NET) = "C:\Program Files\HP\HP ENVY 4500 series\Bin\ScanToPCActivationApp.exe" -deviceID "CN39U2V70M05X4:NW" -scfn "HP ENVY 4500 series (NET)" -AutoStart 1 [Hewlett-Packard Co.] Super Optimizer = C:\Program Files (x86)\Super Optimizer\SupOptLauncher.exe [file not found] Optimizer Pro = C:\Program Files (x86)\Optimizer Pro 3.97\OptProLauncher.exe [null data] Dropbox Update = "C:\Users\Sven\AppData\Local\Dropbox\Update\DropboxUpdate.exe" /c [Dropbox, Inc.] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++} BeatsOSDApp = C:\Program Files\IDT\WDM\beats64.exe SysTrayApp = C:\Program Files\IDT\WDM\sttray64.exe gpuminer = C:\Users\Sven\AppData\Roaming\cpuminer\sgminer\sgminer.cmd [null data] cpuminer = C:\WINDOWS\system32\cpuminer-gw64.exe [null data] HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\ {++} StartCCC = "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun [Advanced Micro Devices, Inc.] CLMLServer_For_P2G8 = "c:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe" [CyberLink] CLVirtualDrive = "c:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe" /R [CyberLink Corp.] beid = "C:\Program Files (x86)\Belgium Identity Card\beid35gui.exe" /startup [file not found] SMART Floating Tools = "C:\Program Files (x86)\SMART Technologies\Education Software\FloatingTools.exe" [SMART Technologies ULC] SMARTNotification = "C:\Program Files (x86)\SMART Technologies\Education Software\SMARTNotification.exe" [SMART Technologies] SMART Tray Tools = "C:\Program Files (x86)\SMART Technologies\Education Software\SMARTSystemMenu.exe" [SMART Technologies] SMART Board Service = "C:\Program Files (x86)\SMART Technologies\Education Software\SMARTBoardService.exe" -d [SMART Technologies] sbsdk-server = "C:\Program Files (x86)\SMART Technologies\Education Software\sbsdk-server\NodeLauncher.exe" [SMART Technologies] SMART Ink = "C:\Program Files (x86)\SMART Technologies\Education Software\SMARTInk.exe" -a [null data] MMReminderService = C:\Program Files (x86)\Mindjet\MindManager 15\MMReminderService.exe [file not found] Adobe ARM = "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [Adobe Systems Incorporated] HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ {51D26BB4-4D2C-4AE4-9873-5FF41B6DED1F}\(Default) = (no title provided) -> {HKLM...Wow...CLSID} = LuckyTab Class \InProcServer32\(Default) = C:\Program Files (x86)\MiuiTab\SupTab.dll [Thinknice Co. Limited] {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}\(Default) = Norton Identity Protection -> {HKLM...Wow...CLSID} = Norton Identity Protection \InProcServer32\(Default) = C:\Program Files (x86)\Norton Internet Security\Engine\20.6.0.27\coIEPlg.dll [Symantec Corporation] {6D53EC84-6AAE-4787-AEEE-F4628F01010C}\(Default) = Norton Vulnerability Protection -> {HKLM...Wow...CLSID} = Norton Vulnerability Protection \InProcServer32\(Default) = C:\Program Files (x86)\Norton Internet Security\Engine\20.6.0.27\IPS\IPSBHO.DLL [Symantec Corporation] {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\(Default) = (no title provided) -> {HKLM...Wow...CLSID} = Java(tm) Plug-In SSV Helper \InProcServer32\(Default) = C:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll [Oracle Corporation] {B4F3A835-0E21-4959-BA22-42B3008E02FF}\(Default) = URLRedirectionBHO -> {HKLM...CLSID} = Office Document Cache Handler \InProcServer32\(Default) = C:\PROGRA~1\MICROS~1\Office14\URLREDIR.DLL [MS] -> {HKLM...Wow...CLSID} = Office Document Cache Handler \InProcServer32\(Default) = C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL [MS] {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}\(Default) = (no title provided) -> {HKLM...CLSID} = Microsoft SkyDrive Pro Browser Helper \InProcServer32\(Default) = C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL [MS] -> {HKLM...Wow...CLSID} = Microsoft SkyDrive Pro Browser Helper \InProcServer32\(Default) = C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [MS] {DBC80044-A445-435b-BC74-9C25C1C588A9}\(Default) = (no title provided) -> {HKLM...Wow...CLSID} = Java(tm) Plug-In 2 SSV Helper \InProcServer32\(Default) = C:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll [Oracle Corporation] {E76FD755-C1BA-4DCB-9F13-99BD91223ADE}\(Default) = HP Network Check Helper -> {HKLM...CLSID} = HP Network Check Helper \InProcServer32\(Default) = C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll [Hewlett-Packard] -> {HKLM...Wow...CLSID} = HP Network Check Helper \InProcServer32\(Default) = C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [Hewlett-Packard] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ SkyDrivePro1 (ErrorConflict)\(Default) = {8BA85C75-763B-4103-94EB-9470F12FE0F7} -> {HKLM...CLSID} = Microsoft SkyDrive Pro Icon Overlay 1 (ErrorConflict) \InProcServer32\(Default) = C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL [MS] SkyDrivePro2 (SyncInProgress)\(Default) = {CD55129A-B1A1-438E-A425-CEBC7DC684EE} -> {HKLM...CLSID} = Microsoft SkyDrive Pro Icon Overlay 2 (SyncInProgress) \InProcServer32\(Default) = C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL [MS] SkyDrivePro3 (InSync)\(Default) = {E768CD3B-BDDC-436D-9C13-E1B39CA257B1} -> {HKLM...CLSID} = Microsoft SkyDrive Pro Icon Overlay 3 (InSync) \InProcServer32\(Default) = C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL [MS] "DropboxExt1"\(Default) = {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} -> {HKCU...CLSID} = DropboxExt1 Class \InProcServer32\(Default) = C:\Users\Sven\AppData\Roaming\Dropbox\bin\DropboxExt64.26.dll [Dropbox, Inc.] "DropboxExt2"\(Default) = {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} -> {HKCU...CLSID} = DropboxExt2 Class \InProcServer32\(Default) = C:\Users\Sven\AppData\Roaming\Dropbox\bin\DropboxExt64.26.dll [Dropbox, Inc.] "DropboxExt3"\(Default) = {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} -> {HKCU...CLSID} = DropboxExt5 Class \InProcServer32\(Default) = C:\Users\Sven\AppData\Roaming\Dropbox\bin\DropboxExt64.26.dll [Dropbox, Inc.] "DropboxExt4"\(Default) = {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} -> {HKCU...CLSID} = DropboxExt6 Class \InProcServer32\(Default) = C:\Users\Sven\AppData\Roaming\Dropbox\bin\DropboxExt64.26.dll [Dropbox, Inc.] "DropboxExt5"\(Default) = {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} -> {HKCU...CLSID} = DropboxExt3 Class \InProcServer32\(Default) = C:\Users\Sven\AppData\Roaming\Dropbox\bin\DropboxExt64.26.dll [Dropbox, Inc.] "DropboxExt6"\(Default) = {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} -> {HKCU...CLSID} = DropboxExt7 Class \InProcServer32\(Default) = C:\Users\Sven\AppData\Roaming\Dropbox\bin\DropboxExt64.26.dll [Dropbox, Inc.] "DropboxExt7"\(Default) = {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} -> {HKCU...CLSID} = DropboxExt4 Class \InProcServer32\(Default) = C:\Users\Sven\AppData\Roaming\Dropbox\bin\DropboxExt64.26.dll [Dropbox, Inc.] "DropboxExt8"\(Default) = {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} -> {HKCU...CLSID} = DropboxExt8 Class \InProcServer32\(Default) = C:\Users\Sven\AppData\Roaming\Dropbox\bin\DropboxExt64.26.dll [Dropbox, Inc.] HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ SkyDrivePro1 (ErrorConflict)\(Default) = {8BA85C75-763B-4103-94EB-9470F12FE0F7} -> {HKLM...Wow...CLSID} = Microsoft SkyDrive Pro Icon Overlay 1 (ErrorConflict) \InProcServer32\(Default) = C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [MS] SkyDrivePro2 (SyncInProgress)\(Default) = {CD55129A-B1A1-438E-A425-CEBC7DC684EE} -> {HKLM...Wow...CLSID} = Microsoft SkyDrive Pro Icon Overlay 2 (SyncInProgress) \InProcServer32\(Default) = C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [MS] SkyDrivePro3 (InSync)\(Default) = {E768CD3B-BDDC-436D-9C13-E1B39CA257B1} -> {HKLM...Wow...CLSID} = Microsoft SkyDrive Pro Icon Overlay 3 (InSync) \InProcServer32\(Default) = C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [MS] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\ {872A9397-E0D6-4e28-B64D-52B8D0A7EA35} = Display CPL Extension -> {HKLM...CLSID} = DisplayCplExt Class \InProcServer32\(Default) = C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\atiama64.dll [Advanced Micro Devices, Inc.] {5E2121EE-0300-11D4-8D3B-444553540000} = Catalyst Context Menu extension -> {HKLM...CLSID} = SimpleShlExt Class \InProcServer32\(Default) = C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\atiacm64.dll [Advanced Micro Devices, Inc.] {5FCD4425-CA3A-48F4-A57C-B8A75C32ACB1} = NSE_WithSubFld -> {HKLM...CLSID} = NSE_WithSubFld \InProcServer32\(Default) = C:\Program Files (x86)\Hewlett-Packard\Recovery\Protect.dll [null data] {42042206-2D85-11D3-8CFF-005004838597} = Microsoft Office HTML Icon Handler -> {HKLM...CLSID} = (no title provided) \InProcServer32\(Default) = C:\Program Files\Microsoft Office\Office14\MSOHEVI.DLL [MS] {7CCA70DB-DE7A-4FB7-9B2B-52E2335A3B5A} = Nameext -> {HKLM...CLSID} = Ondernemingsprojecten \InProcServer32\(Default) = C:\Program Files\Microsoft Office\Office14\NAMEEXT.DLL [MS] {0006F045-0000-0000-C000-000000000046} = Microsoft Outlook Custom Icon Handler -> {HKLM...CLSID} = (no title provided) \InProcServer32\(Default) = C:\Program Files\Microsoft Office\Office14\OLKFSTUB.DLL [MS] {8BA85C75-763B-4103-94EB-9470F12FE0F7} = Microsoft SkyDrive Pro Icon Overlay 1 (ErrorConflict) -> {HKLM...CLSID} = Microsoft SkyDrive Pro Icon Overlay 1 (ErrorConflict) \InProcServer32\(Default) = C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL [MS] {CD55129A-B1A1-438E-A425-CEBC7DC684EE} = Microsoft SkyDrive Pro Icon Overlay 2 (SyncInProgress) -> {HKLM...CLSID} = Microsoft SkyDrive Pro Icon Overlay 2 (SyncInProgress) \InProcServer32\(Default) = C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL [MS] {E768CD3B-BDDC-436D-9C13-E1B39CA257B1} = Microsoft SkyDrive Pro Icon Overlay 3 (InSync) -> {HKLM...CLSID} = Microsoft SkyDrive Pro Icon Overlay 3 (InSync) \InProcServer32\(Default) = C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL [MS] {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} = Microsoft SkyDrive Pro Browser Helper -> {HKLM...CLSID} = Microsoft SkyDrive Pro Browser Helper \InProcServer32\(Default) = C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL [MS] {0875DCB6-C686-4243-9432-ADCCF0B9F2D7} = Microsoft OneNote Namespace Extension for Windows Desktop Search -> {HKLM...CLSID} = Microsoft OneNote Namespace Extension for Windows Desktop Search \InProcServer32\(Default) = C:\Program Files\Microsoft Office\Office14\ONFILTER.DLL [MS] {993BE281-6695-4BA5-8A2A-7AACBFAAB69E} = Microsoft Office Metadata Handler -> {HKLM...CLSID} = Microsoft Office Metadata Handler \InProcServer32\(Default) = C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesCommonX64\Microsoft Shared\Office15\msoshext.dll [MS] {C41662BB-1FA0-4CE0-8DC5-9B7F8279FF97} = Microsoft Office Thumbnail Handler -> {HKLM...CLSID} = Microsoft Office Thumbnail Handler \InProcServer32\(Default) = C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesCommonX64\Microsoft Shared\Office15\msoshext.dll [MS] {506F4668-F13E-4AA1-BB04-B43203AB3CC0} = {506F4668-F13E-4AA1-BB04-B43203AB3CC0} -> {HKLM...CLSID} = ImageExtractorShellExt Class \InProcServer32\(Default) = C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\VISSHE.DLL [MS] {D66DC78C-4F61-447F-942B-3FB6980118CF} = {D66DC78C-4F61-447F-942B-3FB6980118CF} -> {HKLM...CLSID} = CInfoTipShellExt Class \InProcServer32\(Default) = C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\VISSHE.DLL [MS] HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\ {00F33137-EE26-412F-8D71-F84E4C2C6625} = (no title provided) -> {HKLM...Wow...CLSID} = Windows Live Photo Gallery Viewer Autoplay Shim \InProcServer32\(Default) = C:\Program Files (x86)\Windows Live\Photo Gallery\PhotoViewerShim.dll [MS] {00F346CB-35A4-465B-8B8F-65A29DBAB1F6} = Windows Live Photo Gallery Viewer Drop Target Shim -> {HKLM...Wow...CLSID} = Windows Live Photo Gallery Viewer Shim \InProcServer32\(Default) = C:\Program Files (x86)\Windows Live\Photo Gallery\PhotoViewerShim.dll [MS] {00F3712A-CA79-45B4-9E4D-D7891E7F8B9D} = Windows Live Photo Gallery Editor Drop Target Shim -> {HKLM...Wow...CLSID} = Windows Live Photo Gallery Editor Shim \InProcServer32\(Default) = C:\Program Files (x86)\Windows Live\Photo Gallery\PhotoViewerShim.dll [MS] {00F30F90-3E96-453B-AFCD-D71989ECC2C7} = Windows Live Photo Gallery Autoplay Drop Target Shim -> {HKLM...Wow...CLSID} = Windows Live Photo Gallery Viewer Autoplay Shim \InProcServer32\(Default) = C:\Program Files (x86)\Windows Live\Photo Gallery\PhotoViewerShim.dll [MS] {42042206-2D85-11D3-8CFF-005004838597} = Microsoft Office HTML Icon Handler -> {HKLM...Wow...CLSID} = (no title provided) \InProcServer32\(Default) = C:\Program Files (x86)\Microsoft Office\Office14\msohevi.dll [MS] {506F4668-F13E-4AA1-BB04-B43203AB3CC0} = {506F4668-F13E-4AA1-BB04-B43203AB3CC0} -> {HKLM...Wow...CLSID} = ImageExtractorShellExt Class \InProcServer32\(Default) = C:\Program Files\Microsoft Office 15\root\Office15\VISSHE.DLL [MS] {D66DC78C-4F61-447F-942B-3FB6980118CF} = {D66DC78C-4F61-447F-942B-3FB6980118CF} -> {HKLM...Wow...CLSID} = CInfoTipShellExt Class \InProcServer32\(Default) = C:\Program Files\Microsoft Office 15\root\Office15\VISSHE.DLL [MS] {0875DCB6-C686-4243-9432-ADCCF0B9F2D7} = Microsoft OneNote Namespace Extension for Windows Desktop Search -> {HKLM...Wow...CLSID} = Microsoft OneNote Namespace Extension for Windows Desktop Search \InProcServer32\(Default) = C:\Program Files (x86)\Microsoft Office\Office14\ONFILTER.DLL [MS] {993BE281-6695-4BA5-8A2A-7AACBFAAB69E} = Microsoft Office Metadata Handler -> {HKLM...Wow...CLSID} = Microsoft Office Metadata Handler \InProcServer32\(Default) = C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesCommonX86\Microsoft Shared\Office15\msoshext.dll [MS] {C41662BB-1FA0-4CE0-8DC5-9B7F8279FF97} = Microsoft Office Thumbnail Handler -> {HKLM...Wow...CLSID} = Microsoft Office Thumbnail Handler \InProcServer32\(Default) = C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesCommonX86\Microsoft Shared\Office15\msoshext.dll [MS] {8BA85C75-763B-4103-94EB-9470F12FE0F7} = Microsoft SkyDrive Pro Icon Overlay 1 (ErrorConflict) -> {HKLM...Wow...CLSID} = Microsoft SkyDrive Pro Icon Overlay 1 (ErrorConflict) \InProcServer32\(Default) = C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [MS] {CD55129A-B1A1-438E-A425-CEBC7DC684EE} = Microsoft SkyDrive Pro Icon Overlay 2 (SyncInProgress) -> {HKLM...Wow...CLSID} = Microsoft SkyDrive Pro Icon Overlay 2 (SyncInProgress) \InProcServer32\(Default) = C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [MS] {E768CD3B-BDDC-436D-9C13-E1B39CA257B1} = Microsoft SkyDrive Pro Icon Overlay 3 (InSync) -> {HKLM...Wow...CLSID} = Microsoft SkyDrive Pro Icon Overlay 3 (InSync) \InProcServer32\(Default) = C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [MS] {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} = Microsoft SkyDrive Pro Browser Helper -> {HKLM...Wow...CLSID} = Microsoft SkyDrive Pro Browser Helper \InProcServer32\(Default) = C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [MS] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\Credential Providers\ {1ee7337f-85ac-45e2-a23c-37c753209769}\(Default) = Smartcard WinRT Provider -> {HKLM...CLSID} = Smartcard WinRT Provider \InProcServer32\(Default) = C:\WINDOWS\system32\SmartcardCredentialProvider.dll [MS] {3D4B745B-F01D-435E-9444-7796235996DA}\(Default) = (no title provided) -> {HKLM...CLSID} = SSOCredentialProvider \InProcServer32\(Default) = C:\Program Files (x86)\Hewlett-Packard\HP Connected Remote\amd64\SSOCredentialProvider.dll [null data] HKLM\SOFTWARE\Classes\PROTOCOLS\Filter\ <> text/xml\CLSID = {807573E5-5146-11D5-A672-00B0D022E945} -> {HKLM...CLSID} = Microsoft Office InfoPath XML Mime Filter \InProcServer32\(Default) = C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL [MS] HKCU\Software\Classes\*\shellex\ContextMenuHandlers\ DropboxExt\(Default) = {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} -> {HKCU...CLSID} = ContextMenuHandler Class \InProcServer32\(Default) = C:\Users\Sven\AppData\Roaming\Dropbox\bin\DropboxExt64.26.dll [Dropbox, Inc.] -> {HKCU...Wow...CLSID} = ContextMenuHandler Class \InProcServer32\(Default) = C:\Users\Sven\AppData\Roaming\Dropbox\bin\DropboxExt.26.dll [Dropbox, Inc.] HKLM\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\ CLVDShellExt\(Default) = {3E2A0A32-6E14-4BAD-AA87-BBB6A75EBFF2} -> {HKLM...CLSID} = (no title provided) \InProcServer32\(Default) = C:\Program Files (x86)\Common Files\CyberLink\ShellExtComponent\CLVDShellExt.dll [Cyberlink] Symantec.Norton.Antivirus.IEContextMenu\(Default) = {FAD61B3D-699D-49B2-BE16-7F82CB4C59CA} -> {HKLM...CLSID} = IEContextMenu Class \InProcServer32\(Default) = "C:\Program Files (x86)\Norton Internet Security\Engine64\20.6.0.27\NavShExt.dll" [Symantec Corporation] WorkFolders\(Default) = {E61BF828-5E63-4287-BEF1-60B1A4FDE0E3} -> {HKLM...CLSID} = Work Folders Context Menu Handler \InProcServer32\(Default) = C:\Windows\System32\WorkfoldersShell.dll [MS] HKCU\Software\Classes\Directory\shellex\ContextMenuHandlers\ DropboxExt\(Default) = {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} -> {HKCU...CLSID} = ContextMenuHandler Class \InProcServer32\(Default) = C:\Users\Sven\AppData\Roaming\Dropbox\bin\DropboxExt64.26.dll [Dropbox, Inc.] -> {HKCU...Wow...CLSID} = ContextMenuHandler Class \InProcServer32\(Default) = C:\Users\Sven\AppData\Roaming\Dropbox\bin\DropboxExt.26.dll [Dropbox, Inc.] HKLM\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\ WorkFolders\(Default) = {E61BF828-5E63-4287-BEF1-60B1A4FDE0E3} -> {HKLM...CLSID} = Work Folders Context Menu Handler \InProcServer32\(Default) = C:\Windows\System32\WorkfoldersShell.dll [MS] HKCU\Software\Classes\Directory\Background\shellex\ContextMenuHandlers\ DropboxExt\(Default) = {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} -> {HKCU...CLSID} = ContextMenuHandler Class \InProcServer32\(Default) = C:\Users\Sven\AppData\Roaming\Dropbox\bin\DropboxExt64.26.dll [Dropbox, Inc.] -> {HKCU...Wow...CLSID} = ContextMenuHandler Class \InProcServer32\(Default) = C:\Users\Sven\AppData\Roaming\Dropbox\bin\DropboxExt.26.dll [Dropbox, Inc.] HKLM\SOFTWARE\Classes\Directory\Background\shellex\ContextMenuHandlers\ ACE\(Default) = {5E2121EE-0300-11D4-8D3B-444553540000} -> {HKLM...CLSID} = SimpleShlExt Class \InProcServer32\(Default) = C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\atiacm64.dll [Advanced Micro Devices, Inc.] WorkFolders\(Default) = {E61BF828-5E63-4287-BEF1-60B1A4FDE0E3} -> {HKLM...CLSID} = Work Folders Context Menu Handler \InProcServer32\(Default) = C:\Windows\System32\WorkfoldersShell.dll [MS] HKLM\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\ {F9DB5320-233E-11D1-9F84-707F02C10627}\(Default) = PDF Column Info -> {HKLM...Wow...CLSID} = PDF Shell Extension \InProcServer32\(Default) = C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll [Adobe Systems, Inc.] HKLM\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\ Symantec.Norton.Antivirus.IEContextMenu\(Default) = {FAD61B3D-699D-49B2-BE16-7F82CB4C59CA} -> {HKLM...CLSID} = IEContextMenu Class \InProcServer32\(Default) = "C:\Program Files (x86)\Norton Internet Security\Engine64\20.6.0.27\NavShExt.dll" [Symantec Corporation] Group Policies {GPedit.msc branch and setting}: ----------------------------------------------- Note: detected settings may not have any effect. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\ EnableCursorSuppression = (REG_DWORD) dword:0x00000001 {unrecognized setting} Active Desktop and Wallpaper: ----------------------------- Active Desktop may be disabled at this entry: HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState Displayed if Active Desktop disabled and wallpaper not set by Group Policy: HKCU\Control Panel\Desktop\ Wallpaper = C:\Windows\Web\Wallpaper\HP\HP_Metro_Sky.jpg Windows Portable Device AutoPlay Handlers ----------------------------------------- HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\ CyberLink Media Suite10HandleCDBurningOnArrival\ Provider = Media Suite 10 InvokeProgID = BlankCD InvokeVerb = PlayWithCyberLink Media Suite10 HKLM\SOFTWARE\Classes\BlankCD\shell\PlayWithCyberLink Media Suite10\Command\(Default) = "c:\Program Files (x86)\CyberLink\Media Suite\PS.exe" "%L" [CyberLink Corp.] CyberLink Media Suite10HandleDVDBurningOnArrival\ Provider = Media Suite 10 InvokeProgID = BlankDVD InvokeVerb = PlayWithCyberLink Media Suite10 HKLM\SOFTWARE\Classes\BlankDVD\shell\PlayWithCyberLink Media Suite10\Command\(Default) = "c:\Program Files (x86)\CyberLink\Media Suite\PS.exe" "%L" [CyberLink Corp.] CyberLink Media Suite10MixedContentOnArrival\ Provider = Media Suite 10 InvokeProgID = MixedContent InvokeVerb = PlayWithCyberLink Media Suite10 HKLM\SOFTWARE\Classes\MixedContent\shell\PlayWithCyberLink Media Suite10\Command\(Default) = "c:\Program Files (x86)\CyberLink\Media Suite\PS.exe" "%L" [CyberLink Corp.] CyberLink Media Suite10PlayMusicFilesOnArrival\ Provider = Media Suite 10 InvokeProgID = MusicFiles InvokeVerb = PlayWithCyberLink Media Suite10 HKLM\SOFTWARE\Classes\MusicFiles\shell\PlayWithCyberLink Media Suite10\Command\(Default) = "c:\Program Files (x86)\CyberLink\Media Suite\PS.exe" "%L" [CyberLink Corp.] CyberLink Media Suite10PlayVideoFilesOnArrival\ Provider = Media Suite 10 InvokeProgID = VideoFiles InvokeVerb = PlayWithCyberLink Media Suite10 HKLM\SOFTWARE\Classes\VideoFiles\shell\PlayWithCyberLink Media Suite10\Command\(Default) = "c:\Program Files (x86)\CyberLink\Media Suite\PS.exe" "%L" [CyberLink Corp.] CyberLink Media Suite10ShowPicturesOnArrival\ Provider = Media Suite 10 InvokeProgID = Picture InvokeVerb = PlayWithCyberLink Media Suite10 HKLM\SOFTWARE\Classes\Picture\shell\PlayWithCyberLink Media Suite10\Command\(Default) = "c:\Program Files (x86)\CyberLink\Media Suite\PS.exe" "%L" [CyberLink Corp.] MSFhConfigBackup\ Provider = @C:\WINDOWS\system32\fhautoplay.dll,-100 InvokeProgID = FHConfig.AutoPlayHandler InvokeVerb = config HKLM\SOFTWARE\Classes\FHConfig.AutoPlayHandler\shell\config\command\(Default) = fhmanagew -autoplay [MS] MSLivePhotoAcquireDropHandler\ Provider = @%ProgramFiles(x86)%\Windows Live\Photo Gallery\regres.dll,-10 InvokeProgID = Microsoft.LivePhotoAcqDTShim.1 InvokeVerb = open HKLM\SOFTWARE\Classes\Microsoft.LivePhotoAcqDTShim.1\shell\open\DropTarget\CLSID = {00F33137-EE26-412F-8D71-F84E4C2C6625} -> {HKLM...CLSID} = Windows Live Photo Gallery Viewer Autoplay Shim \InProcServer32\(Default) = C:\Program Files (x86)\Windows Live\Photo Gallery\PhotoViewerShimx64.dll [MS] MSLiveShowPicturesOnArrival\ Provider = @%ProgramFiles(x86)%\Windows Live\Photo Gallery\regres.dll,-10 InvokeProgID = Microsoft.Photos.LiveAutoplayShim.1 InvokeVerb = open HKLM\SOFTWARE\Classes\Microsoft.Photos.LiveAutoplayShim.1\shell\open\DropTarget\CLSID = {00F30F90-3E96-453B-AFCD-D71989ECC2C7} -> {HKLM...CLSID} = Windows Live Photo Gallery Viewer Autoplay Shim \InProcServer32\(Default) = C:\Program Files (x86)\Windows Live\Photo Gallery\PhotoViewerShimx64.dll [MS] MSPlayCDAudioOnArrival\ Provider = @wmploc.dll,-6502 InvokeProgID = WMP.AudioCD InvokeVerb = play HKLM\SOFTWARE\Classes\WMP.AudioCD\shell\play\command\(Default) = "C:\Program Files (x86)\Windows Media Player\wmplayer.exe" /prefetch:3 /device:AudioCD "%L" [MS] MSPlayDVDMovieOnArrival\ Provider = @wmploc.dll,-6502 InvokeProgID = WMP.DVD InvokeVerb = play HKLM\SOFTWARE\Classes\WMP.DVD\shell\play\command\(Default) = "C:\Program Files (x86)\Windows Media Player\wmplayer.exe" /prefetch:4 /device:DVD "%L" [MS] MSPlaySuperVideoCDMovieOnArrival\ Provider = @wmploc.dll,-6502 InvokeProgID = WMP.VCD InvokeVerb = play HKLM\SOFTWARE\Classes\WMP.VCD\shell\play\command\(Default) = "C:\Program Files (x86)\Windows Media Player\wmplayer.exe" /prefetch:4 /device:VCD "%L" [MS] MSPlayVideoCDMovieOnArrival\ Provider = @wmploc.dll,-6502 InvokeProgID = WMP.VCD InvokeVerb = play HKLM\SOFTWARE\Classes\WMP.VCD\shell\play\command\(Default) = "C:\Program Files (x86)\Windows Media Player\wmplayer.exe" /prefetch:4 /device:VCD "%L" [MS] MSPromptEachTime\ Provider = @C:\WINDOWS\system32\shell32.dll,-17411 ProgID = Shell.Autoplay InitCmdLine = PromptEachTime HKLM\SOFTWARE\Classes\Shell.Autoplay\CLSID\(Default) = {995C996E-D918-4a8c-A302-45719A6F4EA7} -> {HKLM...CLSID} = Shell Hardware Mixed Content Handler \LocalServer32\(Default) = C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {995C996E-D918-4a8c-A302-45719A6F4EA7} [MS] MSPromptEachTimeNoContent\ Provider = @C:\WINDOWS\system32\shell32.dll,-17411 ProgID = Shell.Autoplay InitCmdLine = PromptEachTimeNoContent HKLM\SOFTWARE\Classes\Shell.Autoplay\CLSID\(Default) = {995C996E-D918-4a8c-A302-45719A6F4EA7} -> {HKLM...CLSID} = Shell Hardware Mixed Content Handler \LocalServer32\(Default) = C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {995C996E-D918-4a8c-A302-45719A6F4EA7} [MS] MSWMPBurnCDOnArrival\ Provider = @wmploc.dll,-6502 InvokeProgID = WMP.BurnCD InvokeVerb = Burn HKLM\SOFTWARE\Classes\WMP.BurnCD\shell\Burn\Command\(Default) = "C:\Program Files (x86)\Windows Media Player\wmplayer.exe" /prefetch:3 /Task:CDWrite /Device:"%L" [MS] PDirDVArrival\ Provider = PowerDirector ProgID = Shell.HWEventHandlerShellExecute InitCmdLine = "c:\Program Files (x86)\CyberLink\PowerDirector10\PDR10.exe" /DV HKLM\SOFTWARE\Classes\Shell.HWEventHandlerShellExecute\CLSID\(Default) = {FFB8655F-81B9-4fce-B89C-9A6BA76D13E7} -> {HKLM...CLSID} = Shell Execute Hardware Event Handler \LocalServer32\(Default) = C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {FFB8655F-81B9-4fce-B89C-9A6BA76D13E7} [MS] PDVD10PlayCDAudioOnArrival\ Provider = PowerDVD InvokeProgID = AudioCD InvokeVerb = PlayWithPowerDVD10 HKLM\SOFTWARE\Classes\AudioCD\shell\PlayWithPowerDVD10\Command\(Default) = "c:\Program Files (x86)\CyberLink\PowerDVD10\PDVDLaunchPolicy.exe" "%L" [CyberLink Corp.] PDVD10PlayDVDMovieOnArrival\ Provider = PowerDVD InvokeProgID = DVD InvokeVerb = PlayWithPowerDVD10 HKLM\SOFTWARE\Classes\DVD\shell\PlayWithPowerDVD10\Command\(Default) = "c:\Program Files (x86)\CyberLink\PowerDVD10\PDVDLaunchPolicy.exe" "%L" [CyberLink Corp.] PDVD10PlaySVCDOnArrival\ Provider = PowerDVD InvokeProgID = SVCD InvokeVerb = PlayWithPowerDVD10 HKLM\SOFTWARE\Classes\SVCD\shell\PlayWithPowerDVD10\Command\(Default) = "c:\Program Files (x86)\CyberLink\PowerDVD10\PDVDLaunchPolicy.exe" "%L" [CyberLink Corp.] PDVD10PlayVCDMovieOnArrival\ Provider = PowerDVD InvokeProgID = VCD InvokeVerb = PlayWithPowerDVD10 HKLM\SOFTWARE\Classes\VCD\shell\PlayWithPowerDVD10\Command\(Default) = "c:\Program Files (x86)\CyberLink\PowerDVD10\PDVDLaunchPolicy.exe" "%L" [CyberLink Corp.] PhotoDirector2.0ShowPicturesOnArrival\ Provider = PhotoDirector 2 InvokeProgID = Picture InvokeVerb = PlayWithPhotoDirector2.0 HKLM\SOFTWARE\Classes\Picture\shell\PlayWithPhotoDirector2.0\Command\(Default) = "c:\Program Files (x86)\CyberLink\PhotoDirector\PhotoDirector.exe" -importDlg "%L" [CyberLink Corp.] Power2Go8.0HandleBDBurningOnArrival\ Provider = Power2Go 8 InvokeProgID = BlankBD InvokeVerb = PlayWithPower2Go8.0 HKLM\SOFTWARE\Classes\BlankBD\shell\PlayWithPower2Go8.0\Command\(Default) = "c:\Program Files (x86)\CyberLink\Power2Go8\Power2Go8.exe" "%L" [CyberLink Corp.] Power2Go8.0HandleCDBurningOnArrival\ Provider = Power2Go 8 InvokeProgID = BlankCD InvokeVerb = PlayWithPower2Go8.0 HKLM\SOFTWARE\Classes\BlankCD\shell\PlayWithPower2Go8.0\Command\(Default) = "c:\Program Files (x86)\CyberLink\Power2Go8\Power2Go8.exe" "%L" [CyberLink Corp.] Power2Go8.0HandleDVDBurningOnArrival\ Provider = Power2Go 8 InvokeProgID = BlankDVD InvokeVerb = PlayWithPower2Go8.0 HKLM\SOFTWARE\Classes\BlankDVD\shell\PlayWithPower2Go8.0\Command\(Default) = "c:\Program Files (x86)\CyberLink\Power2Go8\Power2Go8.exe" "%L" [CyberLink Corp.] Power2Go8.0PlayCDAudioOnArrival\ Provider = Power2Go 8 InvokeProgID = AudioCD InvokeVerb = PlayWithPower2Go8.0 HKLM\SOFTWARE\Classes\AudioCD\shell\PlayWithPower2Go8.0\Command\(Default) = "c:\Program Files (x86)\CyberLink\Power2Go8\Power2Go8.exe" /AudioRipper "%L" [CyberLink Corp.] Startup items in "Sven" & "All Users" startup folders: ------------------------------------------------------ C:\Users\Sven\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup {++} Dropbox -> shortcut to: C:\Users\Sven\AppData\Roaming\Dropbox\bin\Dropbox.exe /systemstartup [Dropbox, Inc.] Non-disabled Scheduled Tasks: {++} ----------------------------- C:\Windows\System32\Tasks Adobe Acrobat Update Task -> launches: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [Adobe Systems Incorporated] Adobe Flash Player Updater -> launches: C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [Adobe Systems Incorporated] HP AR Program Upload - 1b7290d6a2624619a5af7bce7d7819c5a7be059c304d4a6b92fdb0e47f7e0ae4 -> launches: C:\Program Files\HP\HP ENVY 4500 series\bin\HPRewards.exe -N 1b7290d6a2624619a5af7bce7d7819c5a7be059c304d4a6b92fdb0e47f7e0ae4 -mode Scheduled [TODO: ] HP AR Program Upload - 28562f7ad734406b996538af99da88a86fcbf70972ad46d2a9eac8494a216482 -> launches: C:\Program Files\HP\HP ENVY 4500 series\bin\HPRewards.exe -N 28562f7ad734406b996538af99da88a86fcbf70972ad46d2a9eac8494a216482 -mode Scheduled [TODO: ] HP AR Program Upload - 2c8f2aaf37e6411390c487a75f8e468db76b3cfb40d24da5991a27e4db0cb5af -> launches: C:\Program Files\HP\HP ENVY 4500 series\bin\HPRewards.exe -N 2c8f2aaf37e6411390c487a75f8e468db76b3cfb40d24da5991a27e4db0cb5af -mode Scheduled [TODO: ] HP AR Program Upload - 4060291cfaf14f2cac717a5608cc5720d921259639004e6a9e143b3b8ef2b1e0 -> launches: C:\Program Files\HP\HP ENVY 4500 series\bin\HPRewards.exe -N 4060291cfaf14f2cac717a5608cc5720d921259639004e6a9e143b3b8ef2b1e0 -mode Scheduled [TODO: ] HP AR Program Upload - 4102dd13c7a54c09976069d49ce0d10c5aab11ae958a4f77ac9905da9a5a41ca -> launches: C:\Program Files\HP\HP ENVY 4500 series\bin\HPRewards.exe -N 4102dd13c7a54c09976069d49ce0d10c5aab11ae958a4f77ac9905da9a5a41ca -mode Scheduled [TODO: ] HP AR Program Upload - 5bfbddad599641dbb14db6a0110dff275d41485911b841a4939169f001a3a508 -> launches: C:\Program Files\HP\HP ENVY 4500 series\bin\HPRewards.exe -N 5bfbddad599641dbb14db6a0110dff275d41485911b841a4939169f001a3a508 -mode Scheduled [TODO: ] HP AR Program Upload - 6295289190a145fe9f075725f1c0bab3cfa5aa425469491fb24a9ec399c3e121 -> launches: C:\Program Files\HP\HP ENVY 4500 series\bin\HPRewards.exe -N 6295289190a145fe9f075725f1c0bab3cfa5aa425469491fb24a9ec399c3e121 -mode Scheduled [TODO: ] HP AR Program Upload - 6b8c5b6bf5ee49548348a5bd61bca62d47c9e6e2cf1749759e4773fca79bd6ca -> launches: C:\Program Files\HP\HP ENVY 4500 series\bin\HPRewards.exe -N 6b8c5b6bf5ee49548348a5bd61bca62d47c9e6e2cf1749759e4773fca79bd6ca -mode Scheduled [TODO: ] HP AR Program Upload - 6e612ae1449343f8ac4bcd3832dfda11e340f2022f804761b3c4e94a14649edb -> launches: C:\Program Files\HP\HP ENVY 4500 series\bin\HPRewards.exe -N 6e612ae1449343f8ac4bcd3832dfda11e340f2022f804761b3c4e94a14649edb -mode Scheduled [TODO: ] HP AR Program Upload - 902532a7208e433780d76e5663e4a9fa37773d4ade5047359149591b2324e35d -> launches: C:\Program Files\HP\HP ENVY 4500 series\bin\HPRewards.exe -N 902532a7208e433780d76e5663e4a9fa37773d4ade5047359149591b2324e35d -mode Scheduled [TODO: ] HP AR Program Upload - a6bd08f9c7fa4442a5a0b5ad59ce03145cb0840c937b48de9976a38d4b1b0fcc -> launches: C:\Program Files\HP\HP ENVY 4500 series\bin\HPRewards.exe -N a6bd08f9c7fa4442a5a0b5ad59ce03145cb0840c937b48de9976a38d4b1b0fcc -mode Scheduled [TODO: ] HP AR Program Upload - a8712e011ef1496da4e17795884c8f5de3e83f69ecb94289b7c9873e6f2850d7 -> launches: C:\Program Files\HP\HP ENVY 4500 series\bin\HPRewards.exe -N a8712e011ef1496da4e17795884c8f5de3e83f69ecb94289b7c9873e6f2850d7 -mode Scheduled [TODO: ] HP AR Program Upload - ab6add7986e4431d8821c3445cbc8ebb18e3425076c8496cbbdee6db88f3404c -> launches: C:\Program Files\HP\HP ENVY 4500 series\bin\HPRewards.exe -N ab6add7986e4431d8821c3445cbc8ebb18e3425076c8496cbbdee6db88f3404c -mode Scheduled [TODO: ] HP AR Program Upload - cb4ed32455094240a8b314b1d79915d0bce9f667d0da4197ae0ea3717aa77ec1 -> launches: C:\Program Files\HP\HP ENVY 4500 series\bin\HPRewards.exe -N cb4ed32455094240a8b314b1d79915d0bce9f667d0da4197ae0ea3717aa77ec1 -mode Scheduled [TODO: ] HP AR Program Upload - d240834d36be497ab1d57ce5068d93221e933e1938ac4720b4a4ea08993512dc -> launches: C:\Program Files\HP\HP ENVY 4500 series\bin\HPRewards.exe -N d240834d36be497ab1d57ce5068d93221e933e1938ac4720b4a4ea08993512dc -mode Scheduled [TODO: ] HP AR Program Upload - db013d8b8f874b92a8c4379a734369b982ac6dbded394567ab96cf2e4a553d33 -> launches: C:\Program Files\HP\HP ENVY 4500 series\bin\HPRewards.exe -N db013d8b8f874b92a8c4379a734369b982ac6dbded394567ab96cf2e4a553d33 -mode Scheduled [TODO: ] HP AR Program Upload - dd8c62206da84a0bb4cafdf081cae254f53ffa70fd5647c0a37a5457dea39d19 -> launches: C:\Program Files\HP\HP ENVY 4500 series\bin\HPRewards.exe -N dd8c62206da84a0bb4cafdf081cae254f53ffa70fd5647c0a37a5457dea39d19 -mode Scheduled [TODO: ] HPCeeScheduleForSVEN$ -> launches: C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe HPCeeScheduleForSVEN$ (null) [null data] LaunchPreSignup -> launches: C:\Program Files (x86)\OLBPre\OLBPre.exe signup [file not found] Norton WSC Integration -> (HIDDEN!) launches: "C:\Program Files (x86)\Norton Internet Security\Engine\20.6.0.27\WSCStub.exe" /taskschd [Symantec Corporation] Opera scheduled Autoupdate 1434729400 -> launches: C:\Program Files (x86)\Opera\launcher.exe --scheduledautoupdate [file not found] Optimize Start Menu Cache Files-S-1-5-21-3112560457-1514034208-837128029-1001 -> launches: {2D3F8A1B-6DCD-4ED5-BDBA-A096594B98EF} -> {HKLM...CLSID} = (no title provided) \InProcServer32\(Default) = C:\Windows\System32\twinapi.dll [MS] -> {HKLM...Wow...CLSID} = (no title provided) \InProcServer32\(Default) = C:\Windows\SysWOW64\twinapi.dll [MS] User_Feed_Synchronization-{ED6F0338-2F0F-4B7C-B622-5FE5564C8BAE} -> (HIDDEN!) launches: C:\WINDOWS\system32\msfeedssync.exe sync [MS] WordShark Auto Updater 1.10.0.17 Core -> launches: C:\Program Files (x86)\WordShark_1.10.0.17\Update\WordSharkAutoUpdateClient.exe checkupdate [WS] WordShark Auto Updater 1.10.0.17 Pending Update -> launches: C:\Program Files (x86)\WordShark_1.10.0.17\Update\WordSharkAutoUpdateClient.exe update [WS] C:\Windows\System32\Tasks\Hewlett-Packard\HP Support Assistant HP Support Assistant Quick Start -> launches: C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe /taskrestart [null data] PC Health Analysis -> launches: C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe /L Analysis [null data] Update Check -> launches: C:\ProgramData\Hewlett-Packard\HP Support Framework\Resources\Updater7\HPSFUpdater.exe /s /p 1 [null data] WarrantyChecker -> launches: C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [null data] WarrantyChecker_CN39U2V70M -> launches: C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe /ForDevice:CN39U2V70M [null data] WarrantyChecker_DeviceScan -> launches: C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe /DeviceScanR6 [null data] C:\Windows\System32\Tasks\Microsoft\Office Office Automatic Updates -> launches: C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe /update SCHEDULEDTASK displaylevel=False [MS] Office ClickToRun Service Monitor -> launches: C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe /WatchService [MS] Office Subscription Maintenance -> launches: C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonx86\Microsoft Shared\OFFICE15\OLicenseHeartbeat.exe [MS] OfficeTelemetryAgentFallBack -> launches: C:\Program Files\Microsoft Office 15\root\Office15\msoia.exe scan upload mininterval:2880 [MS] OfficeTelemetryAgentLogOn -> launches: C:\Program Files\Microsoft Office 15\root\Office15\msoia.exe scan upload [MS] C:\Windows\System32\Tasks\Microsoft\Windows\.NET Framework .NET Framework NGEN v4.0.30319 -> (HIDDEN!) launches: {84F0FAE1-C27B-4F6F-807B-28CF6F96287D} -> {HKLM...CLSID} = (no title provided) \InProcServer32\(Default) = mscoree.dll [MS] .NET Framework NGEN v4.0.30319 64 -> (HIDDEN!) launches: {429BC048-379E-45E0-80E4-EB1977941B5C} -> {HKLM...CLSID} = (no title provided) \InProcServer32\(Default) = mscoree.dll [MS] C:\Windows\System32\Tasks\Microsoft\Windows\Active Directory Rights Management Services Client AD RMS Rights Policy Template Management (Manual) -> launches: {BF5CB148-7C77-4d8a-A53E-D81C70CF743C} -> {HKLM...CLSID} = AD RMS Rights Policy Template Management (Manual) Task Handler \InProcServer32\(Default) = C:\WINDOWS\system32\msdrm.dll [MS] -> {HKLM...Wow...CLSID} = AD RMS Rights Policy Template Management (Manual) Task Handler \InProcServer32\(Default) = C:\WINDOWS\system32\msdrm.dll [MS] C:\Windows\System32\Tasks\Microsoft\Windows\AppID SmartScreenSpecific -> launches: {9f2b0085-9218-42a1-88b0-9f0e65851666} -> {HKLM...CLSID} = Windows SmartScreen Task Handler \InProcServer32\(Default) = C:\WINDOWS\system32\apprepsync.dll [MS] -> {HKLM...Wow...CLSID} = Windows SmartScreen Task Handler \InProcServer32\(Default) = C:\WINDOWS\system32\apprepsync.dll [MS] C:\Windows\System32\Tasks\Microsoft\Windows\Application Experience AitAgent -> launches: aitagent /increment [MS] Microsoft Compatibility Appraiser -> launches: %windir%\system32\compattel\DiagTrackRunner.exe /UploadEtlFilesOnly [MS] ProgramDataUpdater -> launches: %windir%\system32\rundll32.exe aepdu.dll,AePduRunUpdate [MS] StartupAppTask -> launches: %windir%\system32\rundll32.exe Startupscan.dll,SusRunTask [MS] C:\Windows\System32\Tasks\Microsoft\Windows\ApplicationData CleanupTemporaryState -> launches: %windir%\system32\rundll32.exe Windows.Storage.ApplicationData.dll,CleanupTemporaryState [MS] C:\Windows\System32\Tasks\Microsoft\Windows\Autochk Proxy -> launches: %windir%\system32\rundll32.exe /d acproxy.dll,PerformAutochkOperations [MS] C:\Windows\System32\Tasks\Microsoft\Windows\Bluetooth UninstallDeviceTask -> launches: BthUdTask.exe $(Arg0) [MS] C:\Windows\System32\Tasks\Microsoft\Windows\CertificateServicesClient SystemTask -> launches: {58fb76b9-ac85-4e55-ac04-427593b1d060} -> {HKLM...CLSID} = Certificate Services Client Task Handler \InProcServer32\(Default) = C:\WINDOWS\system32\dimsjob.dll [MS] -> {HKLM...Wow...CLSID} = Certificate Services Client Task Handler \InProcServer32\(Default) = C:\WINDOWS\system32\dimsjob.dll [MS] UserTask -> launches: {58fb76b9-ac85-4e55-ac04-427593b1d060} -> {HKLM...CLSID} = Certificate Services Client Task Handler \InProcServer32\(Default) = C:\WINDOWS\system32\dimsjob.dll [MS] -> {HKLM...Wow...CLSID} = Certificate Services Client Task Handler \InProcServer32\(Default) = C:\WINDOWS\system32\dimsjob.dll [MS] C:\Windows\System32\Tasks\Microsoft\Windows\Chkdsk ProactiveScan -> launches: {cf4270f5-2e43-4468-83b3-a8c45bb33ea1} -> {HKLM...CLSID} = Proactive Scan \InProcServer32\(Default) = C:\Windows\System32\pstask.dll [MS] C:\Windows\System32\Tasks\Microsoft\Windows\Customer Experience Improvement Program BthSQM -> (HIDDEN!) launches: {c8367320-6f85-11e0-a1f0-0800200c9a66} -> {HKLM...CLSID} = BthSQM \InProcServer32\(Default) = C:\WINDOWS\System32\BthSQM.dll [MS] Consolidator -> launches: %SystemRoot%\System32\wsqmcons.exe [MS] KernelCeipTask -> (HIDDEN!) launches: {e7ed314f-2816-4c26-aeb5-54a34d02404c} -> {HKLM...CLSID} = KernelCeipCustomHandler \InProcServer32\(Default) = C:\WINDOWS\System32\kernelceip.dll [MS] Uploader -> launches: %windir%\system32\WSqmCons.exe -u [MS] UsbCeip -> (HIDDEN!) launches: {c27f6b1d-fe0b-45e4-9257-38799fa69bc8} -> {HKLM...CLSID} = UsbCeip \InProcServer32\(Default) = C:\WINDOWS\System32\usbceip.dll [MS] -> {HKLM...Wow...CLSID} = UsbCeip \InProcServer32\(Default) = C:\WINDOWS\System32\usbceip.dll [MS] C:\Windows\System32\Tasks\Microsoft\Windows\Data Integrity Scan Data Integrity Scan for Crash Recovery -> (HIDDEN!) launches: {DCFD3EA8-D960-4719-8206-490AE315F94F} -> {HKLM...CLSID} = Data Integrity Scan \InProcServer32\(Default) = C:\Windows\System32\discan.dll [MS] C:\Windows\System32\Tasks\Microsoft\Windows\Defrag ScheduledDefrag -> launches: %windir%\system32\defrag.exe -c -h -o -$ [MS] C:\Windows\System32\Tasks\Microsoft\Windows\Device Setup Metadata Refresh -> (HIDDEN!) launches: {23C1F3CF-C110-4512-ACA9-7B6174ECE888} -> {HKLM...CLSID} = DsmRefreshTask Class \InProcServer32\(Default) = C:\WINDOWS\System32\DeviceSetupManagerAPI.dll [MS] C:\Windows\System32\Tasks\Microsoft\Windows\Diagnosis Scheduled -> (HIDDEN!) launches: {c1f85ef8-bcc2-4606-bb39-70c523715eb3} -> {HKLM...CLSID} = ScheduledDiagnosticCustomHandler \InProcServer32\(Default) = C:\WINDOWS\System32\sdiagschd.dll [MS] C:\Windows\System32\Tasks\Microsoft\Windows\DiskCleanup SilentCleanup -> launches: %windir%\system32\cleanmgr.exe /autoclean /d %systemdrive% [MS] C:\Windows\System32\Tasks\Microsoft\Windows\DiskFootprint Diagnostics -> launches: {5b6b6834-34f0-49b9-ad4e-81d4994c7a74} -> {HKLM...CLSID} = Disk Footprint Diagnostics Task \InProcServer32\(Default) = C:\WINDOWS\system32\DfpCommon.dll [MS] C:\Windows\System32\Tasks\Microsoft\Windows\FileHistory File History (maintenance mode) -> launches: {89917B7C-A1A6-11DF-8BF6-18A90531A85A} -> {HKLM...CLSID} = FhTaskHandler Class \InProcServer32\(Default) = C:\WINDOWS\System32\fhtask.dll [MS] C:\Windows\System32\Tasks\Microsoft\Windows\Location Notifications -> launches: %windir%\System32\LocationNotifications.exe [MS] C:\Windows\System32\Tasks\Microsoft\Windows\Maintenance WinSAT -> launches: A9A33436-678B-4c9c-A211-7CC38785E79D -> {HKLM...CLSID} = WinSAT Task Manger Task \InProcServer32\(Default) = C:\WINDOWS\system32\WinSATAPI.dll [MS] -> {HKLM...Wow...CLSID} = WinSAT Task Manger Task \InProcServer32\(Default) = C:\WINDOWS\system32\WinSATAPI.dll [MS] C:\Windows\System32\Tasks\Microsoft\Windows\MemoryDiagnostic ProcessMemoryDiagnosticEvents -> (HIDDEN!) launches: {8168e74a-b39f-46d8-adcd-7bed477b80a3} -> {HKLM...CLSID} = MemoryDiagnosticTaskHandler \InProcServer32\(Default) = C:\WINDOWS\System32\MemoryDiagnostic.dll [MS] RunFullMemoryDiagnostic -> (HIDDEN!) launches: {8168e74a-b39f-46d8-adcd-7bed477b80a3} -> {HKLM...CLSID} = MemoryDiagnosticTaskHandler \InProcServer32\(Default) = C:\WINDOWS\System32\MemoryDiagnostic.dll [MS] C:\Windows\System32\Tasks\Microsoft\Windows\Mobile Broadband Accounts MNO Metadata Parser -> launches: %SystemRoot%\System32\MbaeParserTask.exe [MS] C:\Windows\System32\Tasks\Microsoft\Windows\MobilePC HotStart -> launches: {06DA0625-9701-43da-BFD7-FBEEA2180A1E} [InProcServer32 entry not found] C:\Windows\System32\Tasks\Microsoft\Windows\MUI LPRemove -> launches: %windir%\system32\lpremove.exe [MS] C:\Windows\System32\Tasks\Microsoft\Windows\Multimedia SystemSoundsService -> launches: {2DEA658F-54C1-4227-AF9B-260AB5FC3543} -> {HKLM...CLSID} = Microsoft PlaySoundService Class \InProcServer32\(Default) = C:\WINDOWS\System32\PlaySndSrv.dll [MS] -> {HKLM...Wow...CLSID} = Microsoft PlaySoundService Class \InProcServer32\(Default) = C:\WINDOWS\System32\PlaySndSrv.dll [MS] C:\Windows\System32\Tasks\Microsoft\Windows\NetCfg BindingWorkItemQueueHandler -> launches: {5AA199A0-1CED-43A5-9B85-3226086738A3} -> {HKLM...CLSID} = Binding Engine Task Handler \InProcServer32\(Default) = C:\Windows\System32\netcfgx.dll [MS] -> {HKLM...Wow...CLSID} = Binding Engine Task Handler \InProcServer32\(Default) = C:\Windows\SysWOW64\netcfgx.dll [MS] C:\Windows\System32\Tasks\Microsoft\Windows\NetTrace GatherNetworkInfo -> launches: %windir%\system32\gatherNetworkInfo.vbs [null data] C:\Windows\System32\Tasks\Microsoft\Windows\PerfTrack BackgroundConfigSurveyor -> (HIDDEN!) launches: {EA9155A3-8A39-40B4-8963-D3C761B18371} -> {HKLM...CLSID} = PerfTrack TaskHandler class \InProcServer32\(Default) = C:\Windows\System32\perftrack.dll [MS] C:\Windows\System32\Tasks\Microsoft\Windows\PI Secure-Boot-Update -> launches: {5014B7C8-934E-4262-9816-887FA745A6C4} -> {HKLM...CLSID} = TPM Maintenance Task Handler \InProcServer32\(Default) = C:\WINDOWS\system32\TpmTasks.dll [MS] Sqm-Tasks -> launches: {5014B7C8-934E-4262-9816-887FA745A6C4} -> {HKLM...CLSID} = TPM Maintenance Task Handler \InProcServer32\(Default) = C:\WINDOWS\system32\TpmTasks.dll [MS] C:\Windows\System32\Tasks\Microsoft\Windows\Plug and Play Device Install Group Policy -> (HIDDEN!) launches: {60400283-b242-4fa8-8c25-caf695b88209} -> {HKLM...CLSID} = Device Installation Group Policy Task Handler \InProcServer32\(Default) = C:\Windows\System32\pnppolicy.dll [MS] Device Install Reboot Required -> (HIDDEN!) launches: {48794782-6a1f-47b9-bd52-1d5f95d49c1b} -> {HKLM...CLSID} = Device Installation Reboot Dialog Task \InProcServer32\(Default) = C:\Windows\System32\pnpui.dll [MS] Plug and Play Cleanup -> launches: {DEF03232-9688-11E2-BE7F-B4B52FD966FF} -> {HKLM...CLSID} = Plug and Play Maintenance Task \InProcServer32\(Default) = C:\Windows\System32\pnpclean.dll [MS] Sysprep Generalize Drivers -> launches: %SystemRoot%\System32\drvinst.exe 6 [MS] C:\Windows\System32\Tasks\Microsoft\Windows\Power Efficiency Diagnostics AnalyzeSystem -> launches: {927ea2af-1c54-43d5-825e-0074ce028eee} -> {HKLM...CLSID} = (no title provided) \InProcServer32\(Default) = C:\WINDOWS\System32\energytask.dll [MS] C:\Windows\System32\Tasks\Microsoft\Windows\RAC RacTask -> (HIDDEN!) launches: {42060D27-CA53-41f5-96E4-B1E8169308A6} -> {HKLM...CLSID} = ReliabilityAnalysisCustomHandler \InProcServer32\(Default) = C:\WINDOWS\system32\RacEngn.dll [MS] -> {HKLM...Wow...CLSID} = ReliabilityAnalysisCustomHandler \InProcServer32\(Default) = C:\WINDOWS\system32\RacEngn.dll [MS] C:\Windows\System32\Tasks\Microsoft\Windows\Ras MobilityManager -> launches: {c463a0fc-794f-4fdf-9201-01938ceacafa} -> {HKLM...CLSID} = RasMobilityManager \InProcServer32\(Default) = C:\WINDOWS\system32\rasmbmgr.dll [MS] C:\Windows\System32\Tasks\Microsoft\Windows\Registry RegIdleBackup -> (HIDDEN!) launches: {ca767aa8-9157-4604-b64b-40747123d5f2} -> {HKLM...CLSID} = RegistryIdleBackupHandler \InProcServer32\(Default) = C:\WINDOWS\System32\regidle.dll [MS] C:\Windows\System32\Tasks\Microsoft\Windows\RemoteAssistance RemoteAssistanceTask -> (HIDDEN!) launches: %windir%\system32\RAServer.exe /offerraupdate [MS] C:\Windows\System32\Tasks\Microsoft\Windows\RemovalTools MRT_HB -> launches: C:\WINDOWS\system32\MRT.exe /EHB /Q [MS] C:\Windows\System32\Tasks\Microsoft\Windows\Servicing StartComponentCleanup -> launches: 752073A1-23F2-4396-85F0-8FDB879ED0ED [InProcServer32 entry not found] C:\Windows\System32\Tasks\Microsoft\Windows\SettingSync BackgroundUploadTask -> (HIDDEN!) launches: {59B9640B-3F70-4D1C-B159-F26EEB8A4C87} -> {HKLM...CLSID} = Delayed Background Upload Task Handler \InProcServer32\(Default) = C:\WINDOWS\system32\SettingSyncCore.dll [MS] -> {HKLM...Wow...CLSID} = Delayed Background Upload Task Handler \InProcServer32\(Default) = C:\WINDOWS\system32\SettingSyncCore.dll [MS] BackupTask -> (HIDDEN!) launches: {60A4C78C-E2B8-4E6E-876F-DA203B02C05E} -> {HKLM...CLSID} = Backup Upload Task Handler \InProcServer32\(Default) = C:\WINDOWS\system32\SettingSyncCore.dll [MS] -> {HKLM...Wow...CLSID} = Backup Upload Task Handler \InProcServer32\(Default) = C:\WINDOWS\system32\SettingSyncCore.dll [MS] NetworkStateChangeTask -> (HIDDEN!) launches: {A4173A49-F373-4475-9A0F-2D615204DC20} -> {HKLM...CLSID} = Network State Change Task Handler \InProcServer32\(Default) = C:\WINDOWS\system32\SettingSyncCore.dll [MS] -> {HKLM...Wow...CLSID} = Network State Change Task Handler \InProcServer32\(Default) = C:\WINDOWS\system32\SettingSyncCore.dll [MS] C:\Windows\System32\Tasks\Microsoft\Windows\Setup\gwx launchtrayprocess -> launches: %windir%\system32\GWX\GWX.exe /tasklaunch [MS] refreshgwxconfig -> launches: %windir%\system32\GWX\GWXConfigManager.exe /RefreshConfig [MS] C:\Windows\System32\Tasks\Microsoft\Windows\Setup\GWXTriggers Logon -> launches: %windir%\system32\GWX\GWX.exe /event:2 [MS] OutOfIdle -> launches: %windir%\system32\GWX\GWX.exe /event:1 [MS] refreshgwxconfig-B -> launches: schtasks /run /TN "\Microsoft\Windows\Setup\gwx\refreshgwxconfig" [MS] C:\Windows\System32\Tasks\Microsoft\Windows\Shell CreateObjectTask -> (HIDDEN!) launches: {990a9f8f-301f-45f7-8d0e-68c5952dba43} -> {HKLM...CLSID} = Shell Create Object Task Delegate \InProcServer32\(Default) = C:\WINDOWS\system32\shell32.dll [MS] -> {HKLM...Wow...CLSID} = Shell Create Object Task Delegate \InProcServer32\(Default) = C:\WINDOWS\system32\shell32.dll [MS] FamilySafetyMonitor -> launches: %windir%\System32\wpcmon.exe [MS] FamilySafetyRefresh -> launches: {EBF00FCB-0769-4b81-9BEC-6C05514111AA} -> {HKLM...CLSID} = FamilySafety.WebSync \InProcServer32\(Default) = C:\Windows\System32\WpcWebSync.dll [MS] IndexerAutomaticMaintenance -> launches: {3FBA60A6-7BF5-4868-A2CA-6623B3DFFEA6} -> {HKLM...CLSID} = Automatic Maintenance task to enable Windows Search to make progress while in Connected Standby \InProcServer32\(Default) = C:\WINDOWS\System32\srchadmin.dll [MS] -> {HKLM...Wow...CLSID} = Automatic Maintenance task to enable Windows Search to make progress while in Connected Standby \InProcServer32\(Default) = C:\WINDOWS\System32\srchadmin.dll [MS] C:\Windows\System32\Tasks\Microsoft\Windows\SideShow GadgetManager -> launches: {FF87090D-4A9A-4f47-879B-29A80C355D61} [InProcServer32 entry not found] C:\Windows\System32\Tasks\Microsoft\Windows\SkyDrive Idle Sync Maintenance Task -> launches: {bf6c1e47-86ec-4194-9ce5-13c15dcb2001} [InProcServer32 entry not found] Routine Maintenance Task -> launches: {1b1f472e-3221-4826-97db-2c2324d389ae} [InProcServer32 entry not found] C:\Windows\System32\Tasks\Microsoft\Windows\SoftwareProtectionPlatform SvcRestartTask -> (HIDDEN!) launches: {B1AEBB5D-EAD9-4476-B375-9C3ED9F32AFC} -> {HKLM...CLSID} = SppSvcRestartTaskHandler Class \InProcServer32\(Default) = C:\WINDOWS\System32\sppcext.dll [MS] -> {HKLM...Wow...CLSID} = SppSvcRestartTaskHandler Class \InProcServer32\(Default) = C:\WINDOWS\System32\sppcext.dll [MS] C:\Windows\System32\Tasks\Microsoft\Windows\SpacePort SpaceAgentTask -> launches: %windir%\system32\SpaceAgent.exe [MS] C:\Windows\System32\Tasks\Microsoft\Windows\Sysmain WsSwapAssessmentTask -> launches: %windir%\system32\rundll32.exe sysmain.dll,PfSvWsSwapAssessmentTask [MS] C:\Windows\System32\Tasks\Microsoft\Windows\SystemRestore SR -> launches: %windir%\system32\srtasks.exe ExecuteScheduledSPPCreation [MS] C:\Windows\System32\Tasks\Microsoft\Windows\Task Manager Interactive -> (HIDDEN!) launches: {855fec53-d2e4-4999-9e87-3414e9cf0ff4} -> {HKLM...CLSID} = RunTask \InProcServer32\(Default) = C:\WINDOWS\system32\wdc.dll [MS] -> {HKLM...Wow...CLSID} = RunTask \InProcServer32\(Default) = C:\WINDOWS\system32\wdc.dll [MS] C:\Windows\System32\Tasks\Microsoft\Windows\TaskScheduler Idle Maintenance -> launches: {57BFCFDD-EEE4-4DBB-A751-3CDEB169FF44} -> {HKLM...CLSID} = Maintenance Launcher Handler \InProcServer32\(Default) = C:\WINDOWS\system32\msched.dll [MS] Maintenance Configurator -> launches: {645E29EA-4B0A-464C-8B7D-1A6B9F9D92A8} -> {HKLM...CLSID} = Maintenance Configurator \InProcServer32\(Default) = C:\WINDOWS\system32\msched.dll [MS] Manual Maintenance -> launches: {57BFCFDD-EEE4-4DBB-A751-3CDEB169FF44} -> {HKLM...CLSID} = Maintenance Launcher Handler \InProcServer32\(Default) = C:\WINDOWS\system32\msched.dll [MS] Regular Maintenance -> launches: {57BFCFDD-EEE4-4DBB-A751-3CDEB169FF44} -> {HKLM...CLSID} = Maintenance Launcher Handler \InProcServer32\(Default) = C:\WINDOWS\system32\msched.dll [MS] C:\Windows\System32\Tasks\Microsoft\Windows\TextServicesFramework MsCtfMonitor -> (HIDDEN!) launches: {01575cfe-9a55-4003-a5e1-f38d1ebdcbe1} -> {HKLM...CLSID} = MsCtfMonitor task handler \InProcServer32\(Default) = C:\WINDOWS\system32\MsCtfMonitor.dll [MS] -> {HKLM...Wow...CLSID} = MsCtfMonitor task handler \InProcServer32\(Default) = C:\WINDOWS\system32\MsCtfMonitor.dll [MS] C:\Windows\System32\Tasks\Microsoft\Windows\Time Synchronization ForceSynchronizeTime -> launches: {A31AD6C2-FF4C-43D4-8E90-7101023096F9} -> {HKLM...CLSID} = Time Synchronization Task Handler \InProcServer32\(Default) = C:\WINDOWS\system32\TimeSyncTask.dll [MS] SynchronizeTime -> launches: %windir%\system32\sc.exe start w32time task_started [MS] C:\Windows\System32\Tasks\Microsoft\Windows\Time Zone SynchronizeTimeZone -> launches: %windir%\system32\tzsync.exe [MS] C:\Windows\System32\Tasks\Microsoft\Windows\TPM Tpm-Maintenance -> launches: {5014B7C8-934E-4262-9816-887FA745A6C4} -> {HKLM...CLSID} = TPM Maintenance Task Handler \InProcServer32\(Default) = C:\WINDOWS\system32\TpmTasks.dll [MS] C:\Windows\System32\Tasks\Microsoft\Windows\UPnP UPnPHostConfig -> launches: sc.exe config upnphost start= auto [MS] C:\Windows\System32\Tasks\Microsoft\Windows\WDI ResolutionHost -> (HIDDEN!) launches: {900be39d-6be8-461a-bc4d-b0fa71f5ecb1} -> {HKLM...CLSID} = DiagnosticInfrastructureCustomHandler \InProcServer32\(Default) = C:\WINDOWS\System32\wdi.dll [MS] -> {HKLM...Wow...CLSID} = DiagnosticInfrastructureCustomHandler \InProcServer32\(Default) = C:\WINDOWS\System32\wdi.dll [MS] C:\Windows\System32\Tasks\Microsoft\Windows\Windows Defender Windows Defender Cache Maintenance -> launches: C:\Program Files\Windows Defender\MpCmdRun.exe -IdleTask -TaskName WdCacheMaintenance [MS] Windows Defender Cleanup -> launches: C:\Program Files\Windows Defender\MpCmdRun.exe -IdleTask -TaskName WdCleanup [MS] Windows Defender Scheduled Scan -> launches: C:\Program Files\Windows Defender\MpCmdRun.exe Scan -ScheduleJob [MS] Windows Defender Verification -> launches: C:\Program Files\Windows Defender\MpCmdRun.exe -IdleTask -TaskName WdVerification [MS] C:\Windows\System32\Tasks\Microsoft\Windows\Windows Error Reporting QueueReporting -> launches: %windir%\system32\wermgr.exe -queuereporting [MS] C:\Windows\System32\Tasks\Microsoft\Windows\Windows Filtering Platform BfeOnServiceStartTypeChange -> (HIDDEN!) launches: %windir%\system32\rundll32.exe bfe.dll,BfeOnServiceStartTypeChange [MS] C:\Windows\System32\Tasks\Microsoft\Windows\Windows Media Sharing UpdateLibrary -> launches: "%ProgramFiles%\Windows Media Player\wmpnscfg.exe" [MS] C:\Windows\System32\Tasks\Microsoft\Windows\WindowsBackup ConfigNotification -> launches: %systemroot%\System32\sdclt.exe /CONFIGNOTIFICATION [MS] C:\Windows\System32\Tasks\Microsoft\Windows\WindowsUpdate Scheduled Start -> launches: C:\WINDOWS\system32\sc.exe start wuauserv [MS] Scheduled Start With Network -> launches: C:\WINDOWS\system32\sc.exe start wuauserv [MS] C:\Windows\System32\Tasks\Microsoft\Windows\Wininet CacheTask -> launches: {0358b920-0ac7-461f-98f4-58e32cd89148} -> {HKLM...CLSID} = Wininet Cache task object \InProcServer32\(Default) = C:\WINDOWS\system32\wininet.dll [MS] -> {HKLM...Wow...CLSID} = Wininet Cache task object \InProcServer32\(Default) = C:\WINDOWS\system32\wininet.dll [MS] C:\Windows\System32\Tasks\Microsoft\Windows\WOF WIM-Hash-Management -> launches: {B7BFFB5A-EFA8-4D8C-BBDE-C8D5FAAF54A1} -> {HKLM...CLSID} = WOF Task Handler \InProcServer32\(Default) = C:\WINDOWS\system32\WofTasks.dll [MS] C:\Windows\System32\Tasks\Microsoft\Windows\Work Folders Work Folders Logon Synchronization -> launches: {97d47d56-3777-49fb-8e8f-90d7e30e1a1e} -> {HKLM...CLSID} = Work Folder Logon Trigger Class \InProcServer32\(Default) = C:\Windows\System32\WorkFoldersShell.dll [MS] Work Folders Maintenance Work -> launches: {63260bce-a3fb-4a34-aa51-d4d8e877b62b} -> {HKLM...CLSID} = Work Folder Maintenance Task Class \InProcServer32\(Default) = C:\Windows\System32\WorkFoldersShell.dll [MS] C:\Windows\System32\Tasks\Microsoft\Windows\WS Badge Update -> launches: {00CCDDF6-5107-424D-853D-3907AE5502DC} -> {HKLM...CLSID} = WinStore Tile Badge Updater \InProcServer32\(Default) = C:\WINDOWS\winstore\WinStoreUI.dll [MS] License Validation -> (HIDDEN!) launches: rundll32.exe WSClient.dll,WSpTLR licensing [MS] Sync Licenses -> launches: {10F591BE-3C84-418A-86DD-BAA002E2F36E} -> {HKLM...CLSID} = WinStore License Sync task \InProcServer32\(Default) = C:\WINDOWS\winstore\WinStoreUI.dll [MS] WSRefreshBannedAppsListTask -> (HIDDEN!) launches: rundll32.exe WSClient.dll,RefreshBannedAppsList [MS] WSTask -> launches: {E52C9A25-F3E8-49E4-BAA7-FAD0EF620129} -> {HKLM...CLSID} = (no title provided) \InProcServer32\(Default) = C:\WINDOWS\System32\WSService.dll [MS] C:\Windows\System32\Tasks\Microsoft\Windows Live\SOXE Extractor Definitions Update Task -> launches: {3519154C-227E-47F3-9CC9-12C3F05817F1} -> {HKLM...Wow...CLSID} = Windows Live Social Object Extractor Engine Definition Updater \InProcServer32\(Default) = C:\Program Files (x86)\Windows Live\SOXE\wlsoxe.dll [MS] C:\Windows\System32\Tasks\Norton Internet Security Norton Error Analyzer -> launches: C:\Program Files (x86)\Norton Internet Security\Engine\20.6.0.27\SymErr.exe /analyze [Symantec Corporation] Norton Error Processor -> launches: C:\Program Files (x86)\Norton Internet Security\Engine\20.6.0.27\SymErr.exe /submit [Symantec Corporation] C:\Windows\System32\Tasks\WPD SqmUpload_S-1-5-21-3112560457-1514034208-837128029-1001 -> (HIDDEN!) launches: %windir%\system32\rundll32.exe portabledeviceapi.dll,#1 [MS] Winsock2 Service Provider DLLs: ------------------------------- Namespace Service Providers HKLM\SYSTEM\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++} 000000000001\LibraryPath = %SystemRoot%\system32\napinsp.dll [MS] 000000000002\LibraryPath = %SystemRoot%\system32\pnrpnsp.dll [MS] 000000000003\LibraryPath = %SystemRoot%\system32\pnrpnsp.dll [MS] 000000000004\LibraryPath = %SystemRoot%\system32\NLAapi.dll [MS] 000000000005\LibraryPath = %SystemRoot%\System32\mswsock.dll [MS] 000000000006\LibraryPath = %SystemRoot%\System32\winrnr.dll [MS] HKLM\SYSTEM\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\ {++} 000000000001\LibraryPath = %SystemRoot%\system32\napinsp.dll [MS] 000000000002\LibraryPath = %SystemRoot%\system32\pnrpnsp.dll [MS] 000000000003\LibraryPath = %SystemRoot%\system32\pnrpnsp.dll [MS] 000000000004\LibraryPath = %SystemRoot%\system32\NLAapi.dll [MS] 000000000005\LibraryPath = %SystemRoot%\System32\mswsock.dll [MS] 000000000006\LibraryPath = %SystemRoot%\System32\winrnr.dll [MS] Transport Service Providers HKLM\SYSTEM\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++} 0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range: %SystemRoot%\system32\mswsock.dll [MS], 01 - 10 HKLM\SYSTEM\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries64\ {++} 0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range: %SystemRoot%\system32\mswsock.dll [MS], 01 - 10 Toolbars, Explorer Bars, Extensions: ------------------------------------ Toolbars HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\ {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} = Norton Toolbar -> {HKLM...Wow...CLSID} = Norton Toolbar \InProcServer32\(Default) = C:\Program Files (x86)\Norton Internet Security\Engine\20.6.0.27\coIEPlg.dll [Symantec Corporation] Extensions (Tools menu items, main toolbar menu buttons) HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\ {25510184-5A38-4A99-B273-DCA8EEF6CD08}\ ButtonText = @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll,-103 MenuText = @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll,-102 Exec = C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe [null data] {2670000A-7350-4F3C-8081-5663EE0C6C49}\ ButtonText = Verzenden naar OneNote MenuText = &Verzenden naar OneNote CLSIDExtension = {48E73304-E1D6-4330-914C-F5F514E3486C} -> {HKLM...CLSID} = Send to OneNote from Internet Explorer button \InProcServer32\(Default) = C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll [MS] {31D09BA0-12F5-4CCE-BE8A-2923E76605DA}\ ButtonText = Skype for Business Click to Call MenuText = Skype for Business Click to Call CLSIDExtension = {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> {HKLM...CLSID} = Skype for Business Browser Helper \InProcServer32\(Default) = C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll [MS] {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA}\ ButtonText = &Gekoppelde notities van OneNote MenuText = &Gekoppelde notities van OneNote CLSIDExtension = {FFFDC614-B694-4AE6-AB38-5D6374584B52} -> {HKLM...CLSID} = Linked Notes button \InProcServer32\(Default) = C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll [MS] HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Extensions\ {219C3416-8CB2-491A-A3C7-D9FCDDC9D600}\ ButtonText = @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 MenuText = @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 CLSIDExtension = {5F7B1267-94A9-47F5-98DB-E99415F33AEC} -> {HKLM...Wow...CLSID} = BlogThisToolbarButton Class \InProcServer32\(Default) = C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll [MS] {25510184-5A38-4A99-B273-DCA8EEF6CD08}\ ButtonText = @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-103 MenuText = @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-102 Exec = C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe [null data] {2670000A-7350-4F3C-8081-5663EE0C6C49}\ ButtonText = Verzenden naar OneNote MenuText = &Verzenden naar OneNote CLSIDExtension = {48E73304-E1D6-4330-914C-F5F514E3486C} -> {HKLM...Wow...CLSID} = Send to OneNote from Internet Explorer button \InProcServer32\(Default) = C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll [MS] {2F72393D-2472-4F82-B600-ED77F354B7FF}\ ButtonText = Send to MindManager CLSIDExtension = {6FE6A929-59D1-4763-91AD-29B61CFFB35B} {31D09BA0-12F5-4CCE-BE8A-2923E76605DA}\ ButtonText = Skype for Business Click to Call MenuText = Skype for Business Click to Call CLSIDExtension = {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> {HKLM...Wow...CLSID} = Skype for Business Browser Helper \InProcServer32\(Default) = C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll [MS] {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA}\ ButtonText = &Gekoppelde notities van OneNote MenuText = &Gekoppelde notities van OneNote CLSIDExtension = {FFFDC614-B694-4AE6-AB38-5D6374584B52} -> {HKLM...Wow...CLSID} = Linked Notes button \InProcServer32\(Default) = C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll [MS] {878AC5FC-BE78-4BAE-896C-7F75B790A71E}\ ButtonText = PokerStars.be Exec = C:\Program Files (x86)\PokerStars.BE\PokerStarsUpdate.exe [PokerStars] Running Services (Display Name, Service Name, Path {Service DLL}): ------------------------------------------------------------------ Adobe Acrobat Update Service, AdobeARMservice, "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe" [Adobe Systems Incorporated] AMD External Events Utility, AMD External Events Utility, C:\WINDOWS\system32\atiesrxx.exe [AMD] Audio Service, STacSV, C:\Program Files\IDT\WDM\STacSV64.exe [IDT, Inc.] Diagnostics Tracking Service, DiagTrack, C:\WINDOWS\System32\svchost.exe -k utcsvc {C:\WINDOWS\system32\diagtrack.dll [MS]} HP Connected Remote Service, HPConnectedRemote, "C:\Program Files (x86)\Hewlett-Packard\HP Connected Remote\HPConnectedRemoteService.exe" [null data] HP Support Assistant Service, HP Support Assistant Service, "C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe" [null data] Hulpservice voor toepassingshost, AppHostSvc, C:\WINDOWS\system32\svchost.exe -k apphost {C:\WINDOWS\system32\inetsrv\apphostsvc.dll [MS]} Intel(R) Capability Licensing Service Interface, Intel(R) Capability Licensing Service Interface, "c:\Program Files\Intel\iCLS Client\HeciServer.exe" [Intel(R) Corporation] Intel(R) Dynamic Application Loader Host Interface Service, jhi_service, C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [Intel Corporation] Intel(R) Management and Security Application Local Management Service, LMS, C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [Intel Corporation] Intel(R) Management and Security Application User Notification Service, UNS, "C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe" [Intel Corporation] Intel(R) ME Service, Intel(R) ME Service, C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [Intel Corporation] Microsoft Office ClickToRun Service, ClickToRunSvc, "C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe" /service [MS] Network Connection Broker, NcbService, C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted {C:\WINDOWS\System32\ncbservice.dll [MS]} Norton Internet Security, NIS, "C:\Program Files (x86)\Norton Internet Security\Engine\20.6.0.27\ccSvcHst.exe" /s "NIS" /m "C:\Program Files (x86)\Norton Internet Security\Engine\20.6.0.27\diMaster.dll" /prefetch:1 [Symantec Corporation] SMART Helper Service, SMARTHelperService, "C:\Program Files (x86)\SMART Technologies\Education Software\SMARTHelperService.exe" [SMART Technologies] Windows Defender Network Inspection Service, WdNisSvc, "C:\Program Files\Windows Defender\NisSrv.exe" [MS] WS 1.10.0.17 Client Service, wssvc_1.10.0.17, "C:\Program Files (x86)\WordShark_1.10.0.17\Service\wssvc.exe" [WS] Safe Mode Drivers & Services (subkey name, subkey default value): ----------------------------------------------------------------- HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal\ <> SystemEventsBroker, Service <> PEVSystemStart, Service HKLM\System\CurrentControlSet\Control\SafeBoot\Network\ <> SystemEventsBroker, Service <> PEVSystemStart, Service Print Monitors: --------------- HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors\ CL31C Langmon\Driver = cl31cl6.dll [empty string] HP C511 Status Monitor\Driver = hpinkstsC511LM.dll [Hewlett-Packard Co.] HP Discovery Port Monitor (HP ENVY 4500 series)\Driver = HPDiscoPMC511.dll [Hewlett-Packard Co.] HP Universal Port Monitor\Driver = hpbprtmon.dll [Hewlett-Packard] SMART Local Port\Driver = C:\WINDOWS\system32\smrtlocalmon.dll [SMART Technologies ULC] ==== Empty IE Cache ====================== C:\WINDOWS\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Sven\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\Users\Sven\AppData\Local\Microsoft\Windows\INetCache\Low\Content.IE5 emptied successfully C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\WINDOWS\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\Users\Sven\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully C:\Users\Sven\AppData\Local\Microsoft\Windows\INetCache\Low\IE emptied successfully C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully ==== Empty FireFox Cache ====================== No FireFox Profiles found ==== Empty Chrome Cache ====================== C:\Users\Sven\AppData\Local\Opera Software\Opera Stable\Cache emptied successfully C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully ==== Empty All Flash Cache ====================== Flash Cache Emptied Successfully ==== Empty All Java Cache ====================== Java Cache cleared successfully ==== C:\zoek_backup content ====================== C:\zoek_backup (files=1054 folders=228 216205485 bytes) ==== Empty Temp Folders ====================== C:\Users\Administrator\AppData\Local\Temp emptied successfully C:\Users\Default\AppData\Local\Temp emptied successfully C:\Users\Default User\AppData\Local\Temp emptied successfully C:\Users\Sven\AppData\Local\Temp will be emptied at reboot C:\WINDOWS\serviceprofiles\networkservice\AppData\Local\Temp will be emptied at reboot C:\WINDOWS\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully C:\WINDOWS\Temp will be emptied at reboot ==== After Reboot ====================== ==== Empty Temp Folders ====================== C:\WINDOWS\Temp successfully emptied C:\Users\Sven\AppData\Local\Temp successfully emptied ==== Empty Recycle Bin ====================== C:\$RECYCLE.BIN successfully emptied ==== Deleting Files / Folders ====================== "C:\WINDOWS\serviceprofiles\networkservice\AppData\Local\Temp\MpCmdRun.log" not deleted ==== EOF on vr 19/06/2015 at 19:41:39,71 ======================