Ga naar inhoud

anke marquetecken

Lid
  • Items

    67
  • Registratiedatum

  • Laatst bezocht

Alles dat geplaatst werd door anke marquetecken

  1. hey, ik heb het weer zitten, browser is normaal chrome, maar nu iets van do-search, pagina's laden niet meer, pop-up's, etc geraak niet meer op mail
  2. ik download op torrent films, heeft dat er iets mee te maken?
  3. ja, das trug in orde, maar 2 dagen later begint dat terug opnieuw
  4. Zoek.exe Version 4.0.0.4 Updated 26-October-2013 Tool run by Anke on vr 01/11/2013 at 15:21:34,91. Microsoft Windows 7 Professional 6.1.7601 Service Pack 1 x86 Running in: Normal Mode Internet Access Detected Launched: C:\Users\Anke\Documents\zoek (3)\zoek.exe [script inserted] ==== Older Logs ====================== C:\zoek-results2013-10-31-155356.log 15477 bytes ==== Deleting CLSID Registry Keys ====================== ==== Deleting CLSID Registry Values ====================== ==== Deleting Services ====================== ==== FireFox Fix ====================== ProfilePath: C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default user.js not found ---- Lines browser.startup.page removed from prefs.js ---- user_pref("browser.startup.page", 3); ---- FireFox user.js and prefs.js backups ---- user_20132808_1146_.backup prefs_20130111_1531_.backup prefs_20132808_1146_.backup ==== Deleting Files \ Folders ====================== C:\Program Files\DVDVideoSoft not found C:\Windows\system32\Tasks\{EEF05FBB-D888-49BA-A9FF-F0C1686F15E8} deleted C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\staged deleted C:\Users\Anke\AppData\Local\avgchrome deleted C:\Users\Anke\AppData\Local\WebPlayer\AppsHat deleted C:\Users\Anke\AppData\Local\AppsHat Mobile Apps deleted C:\Users\Anke\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtab.crx deleted C:\Users\Anke\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AppsHat deleted C:\Users\Anke\Downloads\SoftonicDownloader_voor_free-youtube-to-mp3-converter (1).exe deleted C:\Users\Anke\Downloads\SoftonicDownloader_voor_free-youtube-to-mp3-converter (2).exe deleted C:\Users\Anke\Downloads\SoftonicDownloader_voor_free-youtube-to-mp3-converter (3).exe deleted C:\Users\Anke\Downloads\SoftonicDownloader_voor_free-youtube-to-mp3-converter (4).exe deleted C:\Users\Anke\Downloads\SoftonicDownloader_voor_free-youtube-to-mp3-converter.exe deleted C:\Windows\system32\sasnative32.exe deleted C:\Users\Anke\Desktop\Search.lnk deleted C:\Users\Anke\Downloads\Les-Miserables-2012-DVDSCR-EDAW2013-srt.exe deleted "C:\Users\Anke\Downloads\Embrase of the vampire (1).exe" deleted ==== Firefox Extensions ====================== ==== Firefox Plugins ====================== ==== Chrome Look ====================== LyricsViewer-2 - Anke - Default\Extensions\gnbbmjlpkhenbefmmdjodjfmcamegmpd Docs - Anke - Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake ==== Chrome Fix ====================== C:\Users\Anke\AppData\Local\Google\Chrome\User Data\Default\Extensions\gnbbmjlpkhenbefmmdjodjfmcamegmpd deleted successfully C:\Users\Anke\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_gnbbmjlpkhenbefmmdjodjfmcamegmpd_0.localstorage deleted successfully C:\Users\Anke\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_gnbbmjlpkhenbefmmdjodjfmcamegmpd_0 deleted successfully ==== Set IE to Default ====================== Old Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://www.google.com" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://www.google.com" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes] No DefaultScope Set For HKCU New Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://www.google.com" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes] "DefaultScope"="{6A1806CD-94D4-4689-BA73-E35EA1EA9990}" ==== All HKCU SearchScopes ====================== HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes {0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE10SR" {6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}" ==== Deleting Registry Keys ====================== HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{69CC23EF-2ADA-7D26-A2DF-91346C9740C6} deleted successfully HKEY_LOCAL_MACHINE\Software\Policies\Google\Chrome\ExtensionInstallForcelist deleted successfully HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\Doko Chrome Toolbar deleted successfully HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\dokotoolbar deleted successfully HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AppsHat deleted successfully ==== Empty IE Cache ====================== C:\Users\Anke\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Anke\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully ==== Empty FireFox Cache ====================== No FireFox Cache found ==== Empty Chrome Cache ====================== C:\Users\Anke\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully C:\Users\Anke\AppData\Local\Google\Chrome\User Data\Profile 1\Cache emptied successfully ==== Empty All Flash Cache ====================== Flash Cache Emptied Successfully ==== Empty All Java Cache ====================== Java Cache cleared successfully ==== After Reboot ====================== ==== Empty Temp Folders ====================== C:\Windows\Temp successfully emptied C:\Users\Anke\AppData\Local\Temp successfully emptied ==== Empty Recycle Bin ====================== C:\$RECYCLE.BIN successfully emptied ==== EOF on vr 01/11/2013 at 15:38:17,53 ======================
  5. Zoek.exe Version 4.0.0.4 Updated 26-October-2013 Tool run by Anke on do 31/10/2013 at 16:41:51,76. Microsoft Windows 7 Professional 6.1.7601 Service Pack 1 x86 Running in: Normal Mode Internet Access Detected Launched: C:\Users\Anke\Documents\zoek (3)\zoek.exe [script inserted] ==== System Restore Info ====================== 31/10/2013 16:42:37 Zoek.exe System Restore Point Created Succesfully. ==== Deleting Files \ Folders ====================== C:\Program Files\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\fmdownloader@gmail.com deleted C:\ProgramData\SummerSoft deleted C:\Program Files\ss helper deleted C:\Users\Anke\AppData\Roaming\DVDVideoSoft deleted "C:\DelFix.txt" deleted "C:\Windows\865537E164904193A4B6669C62711852.TMP\WiseCustomCall.dll" deleted "C:\Windows\865537E164904193A4B6669C62711852.TMP\WiseCustomCalla.dll" deleted "C:\Windows\865537E164904193A4B6669C62711852.TMP\WiseCustomCalla17.dll" deleted "C:\Windows\865537E164904193A4B6669C62711852.TMP\WiseCustomCalla18.exe" deleted "C:\Windows\865537E164904193A4B6669C62711852.TMP\WiseCustomCalla19.dll" deleted "C:\Windows\865537E164904193A4B6669C62711852.TMP\WiseCustomCalla2.dll" deleted "C:\Windows\865537E164904193A4B6669C62711852.TMP\WiseCustomCalla20.dll" deleted "C:\Windows\865537E164904193A4B6669C62711852.TMP\WiseCustomCalla22.dll" deleted "C:\Windows\865537E164904193A4B6669C62711852.TMP\WiseCustomCalla22.exe" deleted "C:\Windows\865537E164904193A4B6669C62711852.TMP\WiseData.ini" deleted "C:\Program Files\DVDVideoSoft\Free YouTube to DVD Converter\DVDVideoSoft.DVSVideoDownloader.dll" deleted "C:\Program Files\DVDVideoSoft\Free YouTube to DVD Converter\DVDVideoSoft.Presets.dll" deleted "C:\Program Files\DVDVideoSoft\Free YouTube to DVD Converter\DVDVideoSoft.Resources.dll" deleted "C:\Program Files\DVDVideoSoft\Free YouTube to DVD Converter\FreeYouTubeToDVDConverter.exe" deleted "C:\Windows\865537E164904193A4B6669C62711852.TMP" deleted "C:\Program Files\DVDVideoSoft" not deleted "C:\Program Files\DVDVideoSoft\Free YouTube to DVD Converter" not deleted ==== Files Recently Created / Modified ====================== ====== C:\Windows ==== 2013-10-31 08:58:56 FAE2C1567875ACD7E709AD36DB281FFE 579 ----a-w- C:\Windows\hegames.ini 2013-10-02 18:35:40 2A66E81AE941E54A237490FC35D387C8 1945 ----a-w- C:\Windows\epplauncher.mif ====== C:\Users\Anke\AppData\Local\Temp ==== ====== Java Cache ===== 2013-10-22 10:06:35 0F08A8F6BA89A7E31BD59FE8189B97BC 193418 ----a-w- C:\Users\Anke\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\32\474b93a0-1e91598d 2013-10-22 10:06:36 E035E0B09BCADCCD3FBAD1CD731585A4 469 ----a-w- C:\Users\Anke\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\38\4de63de6-337c0836 2013-10-04 09:01:57 A98998FB8CF1C95844FC05EFFB8A6C76 1040305 ----a-w- C:\Users\Anke\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\54\5530fcf6-4ed5e94e ====== C:\Windows\system32 ===== 2013-10-21 19:42:53 0065E911F966A71A115D9A52FF3DFC99 17136 ----a-w- C:\Windows\System32\sasnative32.exe ====== C:\Windows\system32\drivers ===== 2013-10-09 05:07:49 71D97F1A3CC47A56728F7A400A3F8295 76288 ----a-w- C:\Windows\System32\drivers\usbccgp.sys 2013-10-09 05:07:48 FDA6F2BB7FA034D95863ED8788B4E416 284672 ----a-w- C:\Windows\System32\drivers\usbport.sys 2013-10-09 05:07:48 DCDF9855145A14DFCA0AB32308871961 20480 ----a-w- C:\Windows\System32\drivers\usbohci.sys 2013-10-09 05:07:48 C4FB8E7ADEA9B5CEEA885A1B504B7E40 43008 ----a-w- C:\Windows\System32\drivers\usbehci.sys 2013-10-09 05:07:48 8E51D04175BAA14C4F79AA5F6D248770 24064 ----a-w- C:\Windows\System32\drivers\usbuhci.sys 2013-10-09 05:07:48 86AA95ACB611001E26CD2C0145F2225A 258560 ----a-w- C:\Windows\System32\drivers\usbhub.sys 2013-10-09 05:07:48 6FB17D7A2E76B838886E5E8C60239DAE 6016 ----a-w- C:\Windows\System32\drivers\usbd.sys 2013-10-09 05:07:47 F1B27299F547D452EDAEF01FC187CB91 25728 ----a-w- C:\Windows\System32\drivers\hidparse.sys 2013-10-09 05:07:47 50ABE682EBE752EAF62B18790D6D491C 55808 ----a-w- C:\Windows\System32\drivers\hidclass.sys 2013-10-09 05:07:46 CA59F7C570AF70BC174F477CFE2D9EE3 1294272 ----a-w- C:\Windows\System32\drivers\tcpip.sys 2013-10-09 05:07:45 F81BB7E487EDCEAB630A7EE66CF23913 338944 ----a-w- C:\Windows\System32\drivers\afd.sys 2013-10-09 05:07:42 71BC35067CABC02C9453AEAA42B2E43E 729024 ----a-w- C:\Windows\System32\drivers\dxgkrnl.sys 2013-10-09 05:07:29 21F4B24ACFC79A483515BD986DD9043F 115712 ----a-w- C:\Windows\System32\drivers\mrxdav.sys 2013-10-09 05:07:27 2352AB5F9F8F097BF9D41D5A4718A041 86016 ----a-w- C:\Windows\System32\drivers\usbcir.sys 2013-10-09 05:07:26 25944D2CC49E0A6C581D02A74B7D6645 527064 ----a-w- C:\Windows\System32\drivers\Wdf01000.sys 2013-10-02 18:29:02 DDCE686D76C2B4DB435A3AF5BD0E691D 133056 ----a-w- C:\Windows\System32\drivers\ataport.sys 2013-10-02 14:46:49 05A0C2744CEAC6F1B723EC469B650EF0 47632 ----a-w- C:\Windows\System32\drivers\PSKMAD.sys ====== C:\Windows\Tasks ====== 2013-10-30 15:03:39 C8D0925440C072062DF56F275CC545FF 3038 ----a-w- C:\Windows\system32\Tasks\{EEF05FBB-D888-49BA-A9FF-F0C1686F15E8} 2013-10-21 09:58:31 1D63C72B24927B7CC5629434AF27568B 3490 ----a-w- C:\Windows\system32\Tasks\AdobeAAMUpdater-1.0-Zot_geval-Anke 2013-10-21 09:47:48 27B7CF5B01174A689320ADBAB583C408 3246 ----a-w- C:\Windows\system32\Tasks\SomotoUpdateCheckerAutoStart ====== C:\Windows\Temp ====== ======= C:\Program Files ===== 2013-10-21 09:47:57 -------- d-----w- C:\Program Files\Free Zip 2013-10-02 18:49:14 -------- d-----w- C:\Program Files\Webteh 2013-10-02 18:30:45 -------- d-----w- C:\Program Files\tixati 2013-10-02 13:04:31 -------- d-----w- C:\Program Files\GridinSoft Trojan Killer 2013-10-02 12:30:58 -------- d-----w- C:\Program Files\Enigma Software Group 2013-10-02 12:30:24 -------- d-----w- C:\Program Files\Common Files\Wise Installation Wizard ======= C: ===== 2013-10-31 08:58:56 D41D8CD98F00B204E9800998ECF8427E 0 --sha-r- C:\MSDOS.SYS 2013-10-31 08:58:56 D41D8CD98F00B204E9800998ECF8427E 0 --sha-r- C:\IO.SYS ====== C:\Users\Anke\AppData\Roaming ====== 2013-10-21 10:51:10 -------- d-----w- C:\Users\Anke\AppData\Roaming\PDAppFlex 2013-10-09 16:29:12 -------- d-----w- C:\Users\Anke\AppData\Local\avgchrome 2013-10-02 18:49:28 -------- d-----w- C:\Users\Anke\AppData\Roaming\BSplayer Pro 2013-10-02 18:49:28 -------- d-----w- C:\Users\Anke\AppData\Roaming\BSplayer 2013-10-02 18:30:59 -------- d-----w- C:\Users\Anke\AppData\Roaming\tixati 2013-10-02 18:30:49 -------- d-----w- C:\Users\Anke\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Tixati ====== C:\Users\Anke ====== 2013-10-31 08:26:45 69CA82A7482A00D8EE063D2B97FC4338 781383 ----a-w- C:\Users\Anke\Downloads\RSIT.exe 2013-10-27 14:39:42 6D35AFCD77A1F498C72FC1511CAF6E70 311048 ----a-w- C:\Users\Anke\Downloads\Embrase of the vampire (1).exe 2013-10-27 14:39:31 6D35AFCD77A1F498C72FC1511CAF6E70 311048 ----a-w- C:\Users\Anke\Downloads\Embrase of the vampire.exe 2013-10-21 19:39:28 E423CB96C400DBB600DE5FD91F2937A6 611648 ----a-w- C:\Users\Anke\Downloads\the-wolverine-dut-5160271.exe 2013-10-21 10:50:46 -------- d-----w- C:\ProgramData\regid.1986-12.com.adobe 2013-10-21 09:54:25 E44FC2615F6C32C663F7D13B121B850A 2832256 ----a-w- C:\Users\Anke\Downloads\CreativeCloudSet-Up.exe 2013-10-21 09:48:01 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free Zip 2013-10-21 09:47:12 32409777B3EB2BF508E677FA945C37D1 166632 ----a-w- C:\Users\Anke\Downloads\FreeZipSetup.exe 2013-10-18 18:28:45 84FEC64CF1DB849FE26968CDF11EB030 329048 ----a-w- C:\Users\Anke\Downloads\Les-Miserables-2012-DVDSCR-EDAW2013-srt.exe 2013-10-18 18:15:06 -------- d---a-w- C:\ProgramData\TEMP 2013-10-18 18:07:52 A7E6BB3D12BD7D2558C4C0AA769E19DF 611648 ----a-w- C:\Users\Anke\Downloads\les-miserables-dut-4863346.exe 2013-10-02 18:50:24 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BS.Player ====== C: exe-files == 2013-10-31 08:26:45 69CA82A7482A00D8EE063D2B97FC4338 781383 ----a-w- C:\Users\Anke\Downloads\RSIT.exe 2013-10-27 14:39:42 6D35AFCD77A1F498C72FC1511CAF6E70 311048 ----a-w- C:\Users\Anke\Downloads\Embrase of the vampire (1).exe 2013-10-27 14:39:31 6D35AFCD77A1F498C72FC1511CAF6E70 311048 ----a-w- C:\Users\Anke\Downloads\Embrase of the vampire.exe 2013-10-25 18:30:04 9A2347903D6EDB84C10F288BC0578C1C 388608 ----a-w- C:\Program Files\Trend Micro\Anke.exe === C: other files == 2013-10-31 08:58:56 D41D8CD98F00B204E9800998ECF8427E 0 --sha-r- C:\MSDOS.SYS 2013-10-31 08:58:56 D41D8CD98F00B204E9800998ECF8427E 0 --sha-r- C:\IO.SYS ==== Startup Registry Enabled ====================== [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun" [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun" [HKEY_USERS\S-1-5-21-766547166-3330058944-3535508039-1000\Software\Microsoft\Windows\CurrentVersion\Run] "swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" "AGupdate"="C:\Program Files\AppGraffiti\AGupdate.exe" [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce] "SPReview"="C:\Windows\System32\SPReview\SPReview.exe /sp:1 /errorfwlink:Troubleshoot problems installing Service Pack 1 (SP1) for Windows 7 and Windows Server 2008 R2 /build:7601" [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce] "mctadmin"="C:\Windows\System32\mctadmin.exe" [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce] "mctadmin"="C:\Windows\System32\mctadmin.exe" [HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\RunOnce] "SPReview"="C:\Windows\System32\SPReview\SPReview.exe /sp:1 /errorfwlink:Troubleshoot problems installing Service Pack 1 (SP1) for Windows 7 and Windows Server 2008 R2 /build:7601" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "MSC"="c:\Program Files\Microsoft Security Client\msseces.exe -hide -runkey" "AdobeAAMUpdater-1.0"="C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" "Adobe Creative Cloud"="C:\Program Files\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe --showwindow=false --onOSstartup=true" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" "AGupdate"="C:\Program Files\AppGraffiti\AGupdate.exe" ==== Startup Registry Disabled ====================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\AppsHat] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="AppsHat" "hkey"="HKCU" "command"="C:\\Users\\Anke\\AppData\\Local\\WebPlayer\\AppsHat\\WebPlayer.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\BearShare] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="BearShare" "hkey"="HKCU" "command"="\"C:\\Program Files\\BearShare Applications\\BearShare\\BearShare.exe\" --lightmode" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^McAfee Security Scan Plus.lnk] "item"="McAfee Security Scan Plus" "path"="C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\McAfee Security Scan Plus.lnk" "backup"="C:\\Windows\\pss\\McAfee Security Scan Plus.lnk.CommonStartup" "backupExtension"=".CommonStartup" "command"="C:\\PROGRA~1\\MCAFEE~1\\307523~1.318\\SSSCHE~1.EXE" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run-] "Adobe ARM"="\"C:\\Program Files\\Common Files\\Adobe\\ARM\\1.0\\AdobeARM.exe\"" "SunJavaUpdateSched"="\"C:\\Program Files\\Common Files\\Java\\Java Update\\jusched.exe\"" ==== Task Scheduler Jobs ====================== C:\Windows\tasks\Adobe Flash Player Updater.job --a------ C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [08/10/2013 20:18] C:\Windows\tasks\GoogleUpdateTaskMachineCore.job --a------ :C:\Program Files\Google\Update\GoogleUpdate.exe [] C:\Windows\tasks\GoogleUpdateTaskMachineUA.job --a------ C:\Program Files\Google\Update\GoogleUpdate.exe [28/03/2013 21:31] ==== Other Scheduled Tasks ====================== "C:\Windows\system32\tasks\Adobe Flash Player Updater" [C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe] "C:\Windows\system32\tasks\Adobe online update program" [C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe] "C:\Windows\system32\tasks\AdobeAAMUpdater-1.0-Zot_geval-Anke" [C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe] "C:\Windows\system32\tasks\CCleanerSkipUAC" ["C:\Program Files\CCleaner\CCleaner.exe"] "C:\Windows\system32\tasks\CreateChoiceProcessTask" [C:\Windows\System32\browserchoice.exe] "C:\Windows\system32\tasks\GoogleUpdateTaskMachineCore" [C:\Program Files\Google\Update\GoogleUpdate.exe] "C:\Windows\system32\tasks\GoogleUpdateTaskMachineUA" [C:\Program Files\Google\Update\GoogleUpdate.exe] "C:\Windows\system32\tasks\Java Update Scheduler" [C:\Program Files\Common Files\Java\Java Update\jusched.exe] "C:\Windows\system32\tasks\SomotoUpdateCheckerAutoStart" [C:\Users\Anke\AppData\Local\FilesFrog Update Checker\update_checker.exe] "C:\Windows\system32\tasks\NCH Software\VideoPadDowngrade" [C:\Program Files\NCH Software\VideoPad\videopad.exe] ==== Firefox Extensions Registry ====================== [HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions] "fmdownloader@gmail.com"="C:\Program Files\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\fmdownloader@gmail.com" [] ==== Firefox Extensions ====================== ProfilePath: C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default - Undetermined - %ProfilePath%\extensions\staged ==== Firefox Plugins ====================== ==== Chrome Look ====================== Google Docs - Anke - Default\Extensions\aohghmighlieiainnegkcijnfilokake Google Drive - Anke - Default\Extensions\apdfllckaahabafndbhieahigkjlhalf YouTube - Anke - Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo Google Search - Anke - Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf LyricsViewer-2 - Anke - Default\Extensions\gnbbmjlpkhenbefmmdjodjfmcamegmpd Chrome In-App Payments service - Anke - Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda Gmail - Anke - Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia Docs - Anke - Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake Google Drive - Anke - Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf YouTube - Anke - Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo Google Search - Anke - Profile 1\Extensions\coobgpohoikkiipiblmjeljniedjpjpf Select City - Anke - Profile 1\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo Gmail - Anke - Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia undetermined - Anke - Default\Extensions\newtab.crx ==== Deleting CLSID Registry Keys ====================== ==== Deleting CLSID Registry Values ====================== HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\fmdownloader@gmail.com deleted successfully ==== After Reboot ====================== ==== Deleting Files / Folders ====================== "C:\Program Files\DVDVideoSoft" not found ==== EOF on do 31/10/2013 at 16:53:56,05 ======================
  6. Logfile of random's system information tool 1.09 (written by random/random) Run by Anke at 2013-10-31 09:27:08 Microsoft Windows 7 Professional Service Pack 1 System drive C: has 9 GB (11%) free of 76 GB Total RAM: 1528 MB (41% free) Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 9:27:16, on 31/10/2013 Platform: Windows 7 SP1 (WinNT 6.00.3505) MSIE: Internet Explorer v10.0 (10.00.9200.16720) Boot mode: Normal Running processes: C:\Windows\system32\taskhost.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files\Microsoft Security Client\msseces.exe C:\Program Files\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe C:\Program Files\Common Files\Adobe\CEPServiceManager4\CEPServiceManager.exe C:\Program Files\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe C:\Windows\system32\wbem\unsecapp.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Windows\system32\SearchFilterHost.exe C:\Users\Anke\Downloads\RSIT.exe C:\Program Files\trend micro\Anke.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = Preserve R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = Bing R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN NL: Hotmail, Outlook, Skype, Messenger, het laatste nieuws, entertainment en meer! R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll O4 - HKLM\..\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey O4 - HKLM\..\Run: [AdobeAAMUpdater-1.0] "C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" O4 - HKLM\..\Run: [Adobe Creative Cloud] "C:\Program Files\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe" --showwindow=false --onOSstartup=true O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" O4 - HKCU\..\Run: [AGupdate] C:\Program Files\AppGraffiti\AGupdate.exe O4 - HKUS\S-1-5-19\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-18\..\RunOnce: [sPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\RunOnce: [sPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'Default user') O8 - Extra context menu item: Free YouTube Download - C:\Program Files\Common Files\DVDVideoSoft\plugins\freeytvdownloader.htm O8 - Extra context menu item: Free YouTube to DVD Converter - C:\Users\Anke\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetodvdconverter.htm O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Program Files\Common Files\DVDVideoSoft\plugins\freeytmp3downloader.htm O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics O17 - HKLM\System\CCS\Services\Tcpip\..\{9057084B-A503-4EB9-8C3F-42833D5AE6B1}: NameServer = 208.67.222.222,208.67.220.220 O17 - HKLM\System\CS1\Services\Tcpip\..\{9057084B-A503-4EB9-8C3F-42833D5AE6B1}: NameServer = 208.67.222.222,208.67.220.220 O17 - HKLM\System\CS2\Services\Tcpip\..\{9057084B-A503-4EB9-8C3F-42833D5AE6B1}: NameServer = 208.67.222.222,208.67.220.220 O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe O23 - Service: Freemake Improver - Freemake - C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe O23 - Service: FreemakeVideoCapture - Ellora Assets Corp. - C:\Program Files\Freemake\CaptureLib\CaptureLibService.exe O23 - Service: Google Update-service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe O23 - Service: Google Update-service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: HitmanPro Scheduler (HitmanProScheduler) - SurfRight B.V. - C:\Program Files\HitmanPro\hmpsched.exe O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- End of file - 5482 bytes ======Scheduled tasks folder====== C:\Windows\tasks\Adobe Flash Player Updater.job C:\Windows\tasks\GoogleUpdateTaskMachineCore.job C:\Windows\tasks\GoogleUpdateTaskMachineUA.job =========Mozilla firefox========= ProfilePath - C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default "fmdownloader@gmail.com"=C:\Program Files\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\fmdownloader@gmail.com\ [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=10.25.2] "Description"=Java™ Deployment Toolkit "Path"=C:\Windows\system32\npDeployJava1.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=10.25.2] "Description"=Oracle® Next Generation Java™ Plug-In "Path"=C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE] "Description"= "Path"=disabled [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0] "Description"=Ag Player Plugin "Path"=c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3] "Description"=Google Update "Path"=C:\Program Files\Google\Update\1.3.21.165\npGoogleUpdate3.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9] "Description"=Google Update "Path"=C:\Program Files\Google\Update\1.3.21.165\npGoogleUpdate3.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@UtilityChest_49.com/Plugin] "Description"=Utility Chest Plugin "Path"= [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader] "Description"=Handles PDFs in-place in Firefox "Path"=C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\adobe.com/AdobeAAMDetect] "Description"= "Path"=C:\Program Files\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll C:\Program Files\Mozilla Firefox\components\ binary.manifest browsercomps.dll C:\Program Files\Mozilla Firefox\searchplugins\ bing.xml bolcom-nl.xml google.xml marktplaats-nl.xml wikipedia-nl.xml C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ staged ======Registry dump====== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] {2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2013-10-09 194640] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] "MSC"=c:\Program Files\Microsoft Security Client\msseces.exe [2013-08-12 995176] "AdobeAAMUpdater-1.0"=C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2013-06-13 472984] "Adobe Creative Cloud"=C:\Program Files\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2013-09-03 2237328] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2013-03-28 39408] "AGupdate"=C:\Program Files\AppGraffiti\AGupdate.exe [] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AppsHat] C:\Users\Anke\AppData\Local\WebPlayer\AppsHat\WebPlayer.exe [2012-10-26 202752] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BearShare] C:\Program Files\BearShare Applications\BearShare\BearShare.exe [2013-06-24 31164992] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^McAfee Security Scan Plus.lnk] C:\PROGRA~1\MCAFEE~1\307523~1.318\SSSCHE~1.EXE [] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad] WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders] "SecurityProviders"=credssp.dll [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37.sys] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HitmanPro37Crusader] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HitmanPro37CrusaderBoot] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\hitmanpro37] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\hitmanpro37.sys] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\HitmanPro37Crusader] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\HitmanPro37CrusaderBoot] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System] "ConsentPromptBehaviorAdmin"=5 "ConsentPromptBehaviorUser"=3 "EnableUIADesktopToggle"=0 "dontdisplaylastusername"=0 "legalnoticecaption"= "legalnoticetext"= "shutdownwithoutlogon"=1 "undockwithoutlogon"=1 [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list] [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32] "vidc.mrle"=msrle32.dll "vidc.msvc"=msvidc32.dll "msacm.imaadpcm"=imaadp32.acm "msacm.msg711"=msg711.acm "msacm.msgsm610"=msgsm32.acm "msacm.msadpcm"=msadp32.acm "midimapper"=midimap.dll "wavemapper"=msacm32.drv "vidc.uyvy"=msyuv.dll "vidc.yuy2"=msyuv.dll "vidc.yvyu"=msyuv.dll "vidc.iyuv"=iyuv_32.dll "vidc.i420"=iyuv_32.dll "vidc.yvu9"=tsbyuv.dll "msacm.l3acm"=C:\Windows\System32\l3codeca.acm "vidc.cvid"=iccvid.dll "wave"=wdmaud.drv "midi"=wdmaud.drv "mixer"=wdmaud.drv ======File associations====== .js - edit - C:\Windows\System32\Notepad.exe %1 .js - open - C:\Windows\System32\WScript.exe "%1" %* ======List of files/folders created in the last 1 month====== 2013-10-31 09:27:08 ----D---- C:\rsit 2013-10-30 12:35:21 ----D---- C:\hegames 2013-10-28 11:04:51 ----D---- C:\AdwCleaner 2013-10-26 08:25:13 ----D---- C:\zoek_backup 2013-10-21 20:42:53 ----A---- C:\Windows\system32\sasnative32.exe 2013-10-21 11:51:10 ----D---- C:\Users\Anke\AppData\Roaming\PDAppFlex 2013-10-21 11:50:46 ----D---- C:\ProgramData\regid.1986-12.com.adobe 2013-10-21 10:47:57 ----D---- C:\Program Files\Free Zip 2013-10-18 19:29:49 ----D---- C:\ProgramData\SummerSoft 2013-10-18 19:29:31 ----D---- C:\Program Files\ss helper 2013-10-18 19:15:06 ----AD---- C:\ProgramData\TEMP 2013-10-10 02:07:06 ----A---- C:\Windows\system32\jscript.dll 2013-10-10 02:07:05 ----A---- C:\Windows\system32\jscript9.dll 2013-10-10 02:07:04 ----A---- C:\Windows\system32\jsproxy.dll 2013-10-10 02:07:03 ----A---- C:\Windows\system32\ieui.dll 2013-10-10 02:07:03 ----A---- C:\Windows\system32\iesetup.dll 2013-10-10 02:07:01 ----A---- C:\Windows\system32\RegisterIEPKEYs.exe 2013-10-10 02:07:01 ----A---- C:\Windows\system32\msfeeds.dll 2013-10-10 02:07:01 ----A---- C:\Windows\system32\iernonce.dll 2013-10-10 02:07:01 ----A---- C:\Windows\system32\ie4uinit.exe 2013-10-10 02:07:00 ----A---- C:\Windows\system32\urlmon.dll 2013-10-10 02:07:00 ----A---- C:\Windows\system32\iesysprep.dll 2013-10-10 02:06:59 ----A---- C:\Windows\system32\iertutil.dll 2013-10-10 02:06:57 ----A---- C:\Windows\system32\wininet.dll 2013-10-10 02:06:56 ----A---- C:\Windows\system32\ieframe.dll 2013-10-10 02:06:52 ----A---- C:\Windows\system32\mshtml.dll 2013-10-09 06:07:49 ----A---- C:\Windows\system32\drivers\usbccgp.sys 2013-10-09 06:07:49 ----A---- C:\Windows\system32\comctl32.dll 2013-10-09 06:07:48 ----A---- C:\Windows\system32\drivers\usbuhci.sys 2013-10-09 06:07:48 ----A---- C:\Windows\system32\drivers\usbport.sys 2013-10-09 06:07:48 ----A---- C:\Windows\system32\drivers\usbohci.sys 2013-10-09 06:07:48 ----A---- C:\Windows\system32\drivers\usbhub.sys 2013-10-09 06:07:48 ----A---- C:\Windows\system32\drivers\usbehci.sys 2013-10-09 06:07:48 ----A---- C:\Windows\system32\drivers\usbd.sys 2013-10-09 06:07:47 ----A---- C:\Windows\system32\drivers\hidparse.sys 2013-10-09 06:07:47 ----A---- C:\Windows\system32\drivers\hidclass.sys 2013-10-09 06:07:46 ----A---- C:\Windows\system32\drivers\tcpip.sys 2013-10-09 06:07:45 ----A---- C:\Windows\system32\mswsock.dll 2013-10-09 06:07:45 ----A---- C:\Windows\system32\drivers\afd.sys 2013-10-09 06:07:42 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys 2013-10-09 06:07:41 ----A---- C:\Windows\system32\ntoskrnl.exe 2013-10-09 06:07:41 ----A---- C:\Windows\system32\ntkrnlpa.exe 2013-10-09 06:07:40 ----A---- C:\Windows\system32\tdh.dll 2013-10-09 06:07:40 ----A---- C:\Windows\system32\ntdll.dll 2013-10-09 06:07:39 ----A---- C:\Windows\system32\advapi32.dll 2013-10-09 06:07:38 ----A---- C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll 2013-10-09 06:07:37 ----A---- C:\Windows\system32\lpk.dll 2013-10-09 06:07:37 ----A---- C:\Windows\system32\fontsub.dll 2013-10-09 06:07:37 ----A---- C:\Windows\system32\dciman32.dll 2013-10-09 06:07:37 ----A---- C:\Windows\system32\atmlib.dll 2013-10-09 06:07:37 ----A---- C:\Windows\system32\atmfd.dll 2013-10-09 06:07:35 ----A---- C:\Windows\system32\scavengeui.dll 2013-10-09 06:07:33 ----A---- C:\Windows\system32\win32k.sys 2013-10-09 06:07:29 ----A---- C:\Windows\system32\WebClnt.dll 2013-10-09 06:07:29 ----A---- C:\Windows\system32\drivers\mrxdav.sys 2013-10-09 06:07:29 ----A---- C:\Windows\system32\davclnt.dll 2013-10-09 06:07:27 ----A---- C:\Windows\system32\drivers\usbcir.sys 2013-10-09 06:07:26 ----A---- C:\Windows\system32\drivers\Wdf01000.sys 2013-10-02 19:49:28 ----D---- C:\Users\Anke\AppData\Roaming\BSplayer Pro 2013-10-02 19:49:28 ----D---- C:\Users\Anke\AppData\Roaming\BSplayer 2013-10-02 19:49:14 ----D---- C:\Program Files\Webteh 2013-10-02 19:34:53 ----D---- C:\Program Files\Microsoft Security Client 2013-10-02 19:30:59 ----D---- C:\Users\Anke\AppData\Roaming\tixati 2013-10-02 19:30:45 ----D---- C:\Program Files\tixati 2013-10-02 19:30:20 ----D---- C:\Windows\pss 2013-10-02 19:29:02 ----A---- C:\Windows\system32\drivers\ataport.sys 2013-10-02 19:15:48 ----D---- C:\Program Files\CCleaner 2013-10-02 15:46:49 ----A---- C:\Windows\system32\drivers\PSKMAD.sys 2013-10-02 14:04:31 ----D---- C:\Program Files\GridinSoft Trojan Killer 2013-10-02 13:30:58 ----D---- C:\Program Files\Enigma Software Group 2013-10-02 13:30:25 ----D---- C:\Windows\865537E164904193A4B6669C62711852.TMP 2013-10-02 13:30:24 ----D---- C:\Program Files\Common Files\Wise Installation Wizard ======List of files/folders modified in the last 1 month====== 2013-10-31 09:27:16 ----D---- C:\Windows\Prefetch 2013-10-31 09:27:12 ----D---- C:\Program Files\Trend Micro 2013-10-31 09:26:53 ----D---- C:\Windows\Temp 2013-10-31 08:43:37 ----D---- C:\Windows\system32\config 2013-10-31 08:32:06 ----SHD---- C:\System Volume Information 2013-10-31 08:07:21 ----D---- C:\Windows\system32\drivers 2013-10-31 08:03:19 ----D---- C:\Windows\System32 2013-10-31 08:03:19 ----A---- C:\Windows\system32\PerfStringBackup.INI 2013-10-31 08:03:18 ----D---- C:\Windows\inf 2013-10-31 07:56:26 ----D---- C:\Windows 2013-10-30 16:03:39 ----D---- C:\Windows\system32\Tasks 2013-10-30 10:39:56 ----HD---- C:\ProgramData 2013-10-28 21:36:46 ----A---- C:\DelFix.txt 2013-10-28 11:06:27 ----RD---- C:\Program Files 2013-10-26 08:36:36 ----D---- C:\Program Files\Common Files 2013-10-26 08:28:07 ----D---- C:\Windows\Tasks 2013-10-24 18:57:10 ----SHD---- C:\Windows\Installer 2013-10-24 12:21:08 ----D---- C:\Windows\Panther 2013-10-24 12:21:07 ----D---- C:\Windows\debug 2013-10-21 20:43:28 ----D---- C:\Windows\winsxs 2013-10-21 12:22:39 ----D---- C:\Program Files\Common Files\Adobe 2013-10-21 12:19:33 ----D---- C:\Program Files\Adobe 2013-10-21 11:51:32 ----D---- C:\Users\Anke\AppData\Roaming\Adobe 2013-10-21 11:23:44 ----D---- C:\ProgramData\Adobe 2013-10-21 11:21:05 ----RSD---- C:\Windows\Fonts 2013-10-21 10:56:46 ----D---- C:\Program Files\Common Files\microsoft shared 2013-10-20 09:02:11 ----D---- C:\ProgramData\HitmanPro 2013-10-20 00:58:16 ----D---- C:\Windows\system32\catroot 2013-10-18 08:01:44 ----D---- C:\Windows\system32\catroot2 2013-10-11 19:38:39 ----D---- C:\Users\Anke\AppData\Roaming\DVDVideoSoft 2013-10-11 19:34:38 ----D---- C:\Program Files\DVDVideoSoft 2013-10-11 19:34:17 ----RSD---- C:\Windows\assembly 2013-10-10 17:32:07 ----D---- C:\Windows\system32\NDF 2013-10-10 03:12:10 ----D---- C:\Windows\rescache 2013-10-10 02:43:44 ----D---- C:\Windows\Microsoft.NET 2013-10-10 02:34:23 ----D---- C:\Program Files\Microsoft Silverlight 2013-10-10 02:32:52 ----D---- C:\Windows\system32\en-US 2013-10-10 02:32:52 ----D---- C:\Program Files\Internet Explorer 2013-10-10 02:32:50 ----D---- C:\Windows\system32\DriverStore 2013-10-10 02:12:21 ----D---- C:\Windows\system32\MRT 2013-10-10 02:09:09 ----A---- C:\Windows\system32\MRT.exe 2013-10-08 20:18:11 ----A---- C:\Windows\system32\FlashPlayerApp.exe 2013-10-02 19:47:59 ----D---- C:\Windows\Logs 2013-10-02 19:35:03 ----SD---- C:\ProgramData\Microsoft 2013-10-02 19:08:41 ----D---- C:\Windows\system32\appmgmt ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R0 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2013-06-18 211560] R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 173440] R0 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\drivers\vmbus.sys [2010-11-20 175360] R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-20 388096] R2 NisDrv;Microsoft Network Inspection System; C:\Windows\system32\DRIVERS\NisDrvWFP.sys [2013-06-18 107392] R2 npf;NetGroup Packet Filter Driver; C:\Windows\system32\drivers\npf.sys [2011-02-11 35088] R2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704] R3 aeaudio;aeaudio; C:\Windows\system32\drivers\aeaudio.sys [2003-10-23 100384] R3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-13 229888] R3 smwdm;smwdm; C:\Windows\system32\drivers\smwdm.sys [2004-04-15 612416] S3 aic78xx;aic78xx; C:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720] S3 amdagp;AMD AGP Bus Filter Driver; C:\Windows\system32\drivers\amdagp.sys [2009-07-14 53312] S3 AVFSFilter;AVFSFilter; C:\Windows\system32\DRIVERS\avfsfilter.sys [] S3 esgiguard;esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [] S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12368] S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-20 133632] S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-20 5632] S3 sisagp;SIS AGP Bus Filter; C:\Windows\system32\drivers\sisagp.sys [2009-07-14 52304] S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-20 28032] S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2010-11-20 52224] S3 viaagp;VIA AGP Bus Filter; C:\Windows\system32\drivers\viaagp.sys [2009-07-14 53328] S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736] S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-20 17920] S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 35968] ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [2013-05-11 65640] R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 20992] R2 Freemake Improver;Freemake Improver; C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe [2013-08-26 101888] R2 FreemakeVideoCapture;FreemakeVideoCapture; C:\Program Files\Freemake\CaptureLib\CaptureLibService.exe [2013-08-26 9216] R2 HitmanProScheduler;HitmanPro Scheduler; C:\Program Files\HitmanPro\hmpsched.exe [2013-10-20 106280] R2 MsMpSvc;Microsoft Antimalware Service; c:\Program Files\Microsoft Security Client\MsMpEng.exe [2013-08-12 22208] R3 NisSrv;@c:\Program Files\Microsoft Security Client\MpAsDesc.dll,-243; c:\Program Files\Microsoft Security Client\NisSrv.exe [2013-08-12 295376] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] S2 gupdate;Google Update-service (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2013-03-28 136176] S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-10-08 257416] S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 20992] S3 gupdatem;Google Update-service (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2013-03-28 136176] S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2013-03-28 194032] S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2013-03-07 115608] S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 20992] S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 20992] S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 20992] S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2013-03-28 1343400] -----------------EOF----------------- - - - Updated - - - merci he
  7. hey, ik dacht met dat dit een ander probleem was, een nieuw topic moest zijn. ikzelf zit ook geen uren op het internet.
  8. ik had deze week last van traag internet en veel pop-ups. dit was opgelost in een vorige forum. nadat deze discussie klaar was, de volgende dag zat alles terug vol pop-ups. wreed lastig. ik krijg ze niet weg, ik moet toch iets verkeerd doen, als ze zo snel terug komen... wat kan ik doen om pop-ups te vermijden? merci
  9. hey, ik heb weer last van die pup-ups, de ccleaner en delfix helpen niet. is er een andere mogelijkheid? mvg
  10. # AdwCleaner v3.010 - Report created 28/10/2013 at 11:06:25 # Updated 20/10/2013 by Xplode # Operating System : Windows 7 Professional Service Pack 1 (32 bits) # Username : Anke - ZOT_GEVAL # Running from : C:\Users\Anke\Downloads\adwcleaner.exe # Option : Clean ***** [ Services ] ***** [#] Service Deleted : BackupStack ***** [ Files / Folders ] ***** Folder Deleted : C:\ProgramData\eSafe Folder Deleted : C:\ProgramData\DowiNLoad keepeR Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced System Protector Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AppGraffiti Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\optimizer pro v3.2 Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RegClean Pro Folder Deleted : C:\Program Files\AppGraffiti Folder Deleted : C:\Program Files\goforfiles Folder Deleted : C:\Users\Anke\AppData\Local\Bundled software uninstaller Folder Deleted : C:\Users\Anke\AppData\Local\FilesFrog Update Checker Folder Deleted : C:\Users\Anke\AppData\Local\Minibar Folder Deleted : C:\Users\Anke\AppData\Local\torch Folder Deleted : C:\Users\Anke\AppData\LocalLow\AppGraffiti Folder Deleted : C:\Users\Anke\AppData\LocalLow\Delta Folder Deleted : C:\Users\Anke\AppData\LocalLow\Minibar Folder Deleted : C:\Users\Anke\AppData\Roaming\goforfiles Folder Deleted : C:\Users\Anke\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BitGuard Folder Deleted : C:\Users\Anke\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FilesFrog Update Checker Folder Deleted : C:\Users\Anke\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MyPC Backup Folder Deleted : C:\Users\Anke\Documents\optimizer pro File Deleted : C:\Users\Public\Desktop\Advanced System Protector.lnk File Deleted : C:\Users\Public\Desktop\RegClean Pro.lnk File Deleted : C:\Windows\system32\roboot.exe File Deleted : C:\Users\Anke\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MyPC Backup.lnk File Deleted : C:\Users\Anke\Desktop\MyPC Backup.lnk File Deleted : C:\Users\Anke\Desktop\Optimizer Pro.lnk File Deleted : C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\bprotector_extensions.sqlite File Deleted : C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\bprotector_prefs.js File Deleted : C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\user.js File Deleted : C:\Windows\System32\Tasks\Advanced System Protector_startup File Deleted : C:\Windows\System32\Tasks\EPUpdater File Deleted : C:\Windows\System32\Tasks\GoforFilesUpdate ***** [ Shortcuts ] ***** Shortcut Disinfected : C:\Users\Public\Desktop\Mozilla Firefox.lnk Shortcut Disinfected : C:\Users\Anke\Desktop\Search.lnk Shortcut Disinfected : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk Shortcut Disinfected : C:\Users\Anke\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk Shortcut Disinfected : C:\Users\Anke\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AppsHat\Uninstall.lnk Shortcut Disinfected : C:\Users\Anke\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk Shortcut Disinfected : C:\Users\Anke\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk Shortcut Disinfected : C:\Users\Anke\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk Shortcut Disinfected : C:\Users\Anke\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk ***** [ Registry ] ***** Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo [#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Advanced System Protector_startup [#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FE1315F1-B215-42DE-97FA-4BFE83CB801F} [#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{FE1315F1-B215-42DE-97FA-4BFE83CB801F} [#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\BitGuard [#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{31126F9A-EDD3-4B6A-96AC-5D419DF180BA} [#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{31126F9A-EDD3-4B6A-96AC-5D419DF180BA} [#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\EPUpdater [#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{02F4C37F-7C30-49FF-9D91-CA9A166A2741} [#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{02F4C37F-7C30-49FF-9D91-CA9A166A2741} [#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoforFilesUpdate [#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5B7CA2A0-6ECB-4A54-B0BC-4348386FEBD8} [#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{5B7CA2A0-6ECB-4A54-B0BC-4348386FEBD8} [#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\RegClean Pro [#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C2276FF4-674C-471D-B62B-D023B8B9E7CA} [#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{C2276FF4-674C-471D-B62B-D023B8B9E7CA} Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Main [bprotector start page] Value Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes [bProtectorDefaultScope] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\bProtectSettings Key Deleted : HKLM\SOFTWARE\Classes\AppGraffiti.AppGraffitiJS Key Deleted : HKLM\SOFTWARE\Classes\AppID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3} Key Deleted : HKLM\SOFTWARE\Classes\AppID\escort.DLL Key Deleted : HKLM\SOFTWARE\Classes\AppID\escortApp.DLL Key Deleted : HKLM\SOFTWARE\Classes\AppID\escortEng.DLL Key Deleted : HKLM\SOFTWARE\Classes\AppID\escorTlbr.DLL Key Deleted : HKLM\SOFTWARE\Classes\AppID\esrv.EXE Key Deleted : HKLM\SOFTWARE\Classes\AppID\Launcher.EXE Key Deleted : HKLM\SOFTWARE\Classes\AppID\WMHelper.DLL Key Deleted : HKLM\SOFTWARE\Classes\delta.deltaappCore Key Deleted : HKLM\SOFTWARE\Classes\delta.deltaappCore.1 Key Deleted : HKLM\SOFTWARE\Classes\escort.escortIEPane Key Deleted : HKLM\SOFTWARE\Classes\escort.escortIEPane.1 Key Deleted : HKLM\SOFTWARE\Classes\esrv.deltaESrvc Key Deleted : HKLM\SOFTWARE\Classes\esrv.deltaESrvc.1 Key Deleted : HKLM\SOFTWARE\Classes\Prod.cap Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.protectorbho Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.protectorbho.1 Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\mypc backup Key Deleted : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WsysSvc Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SP_360582d7 Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SP_b0285714 Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0041962.BHO Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0041962.BHO.1 Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0041962.Sandbox Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0041962.Sandbox.1 Key Deleted : HKCU\Software\5e55dfdbbc68eb10 Key Deleted : HKLM\SOFTWARE\5e55dfdbbc68eb10 Key Deleted : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{39CB8175-E224-4446-8746-00566302DF8D} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{756C097C-6BDB-45DE-A8F1-83E01AB86BA4} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{A7DDCBDE-5C86-415C-8A37-763AE183E7E4} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{261DD098-8A3E-43D4-87AA-63324FA897D8} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{27BF8F8D-58B8-D41C-F913-B7EEB57EF6F6} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{4FCB4630-2A1C-4AA1-B422-345E8DC8A6DE} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{539F76FD-084E-4858-86D5-62F02F54AE86} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{60EACC1A-33FA-443D-9846-17B28E2C9BDB} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{6F6A5334-78E9-4D9B-8182-8B41EA8C39EF} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{86838207-681D-469D-9511-D0DCC6F19F9B} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AA74D58F-ACD0-450D-A85E-6C04B171C044} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CC99A798-FD3D-4AB4-969E-6071612524F9} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E97A663B-81A6-49C5-A6D3-BCB05BA1DE26} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{022C9F90-2E96-47D6-A971-107650154563} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{06E50566-0AB7-431C-841D-62794727DAF9} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{1231839B-064E-4788-B865-465A1B5266FD} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{26E7211D-0650-43CF-8498-4C81E83AEAAA} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{2DAC2231-CC35-482B-97C5-CED1D4185080} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{31E3BC75-2A09-4CFF-9C92-8D0ED8D1DC0F} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3F1CD84C-04A3-4EA0-9EA1-7D134FD66C82} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3F83A9CA-B5F0-44EC-9357-35BB3E84B07F} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{47E520EA-CAD2-4F51-8F30-613B3A1C33EB} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{57C91446-8D81-4156-A70E-624551442DE9} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{70AFB7B2-9FB5-4A70-905B-0E9576142E1D} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{7AD65FD1-79E0-406D-B03C-DD7C14726D69} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{97DD820D-2E20-40AD-B01E-6730B2FCE630} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{B177446D-54A4-4869-BABC-8566110B4BE0} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{B37B4BA6-334E-72C1-B57E-6AFE8F8A5AF3} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{B77AD4AC-C1C2-B293-7737-71E13A11FFEA} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D9D1DFC5-502D-43E4-B1BB-4D0B7841489A} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E0B07188-A528-4F9E-B2F7-C7FDE8680AE4} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E773F2CF-5E6E-FF2B-81A1-AC581A26B2B2} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{F05B12E1-ADE8-4485-B45B-898748B53C37} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{39CB8175-E224-4446-8746-00566302DF8D} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{4599D05A-D545-4069-BB42-5895B4EAE05B} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{96F7FABC-5789-EFA4-B6ED-1272F4C1D27B} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{DB02BC6B-B0F0-4074-99E6-884B70FCB6AE} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{E2343056-CC08-46AC-B898-BFC7ACF4E755} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{F13D3582-1359-4F8F-9A48-EF3AE9F5701C} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{6F6A5334-78E9-4D9B-8182-8B41EA8C39EF} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AA74D58F-ACD0-450D-A85E-6C04B171C044} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CC99A798-FD3D-4AB4-969E-6071612524F9} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{6F6A5334-78E9-4D9B-8182-8B41EA8C39EF} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AA74D58F-ACD0-450D-A85E-6C04B171C044} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{6F6A5334-78E9-4D9B-8182-8B41EA8C39EF} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{6F6A5334-78E9-4D9B-8182-8B41EA8C39EF} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{348C2DF3-1191-4C3E-92A6-B3A89A9D9C85} Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9} Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE} Key Deleted : HKCU\Software\AppGraffiti Key Deleted : HKCU\Software\BabSolution Key Deleted : HKCU\Software\BI Key Deleted : HKCU\Software\Conduit Key Deleted : HKCU\Software\CToolbar Key Deleted : HKCU\Software\DataMngr [#] Key Deleted : HKCU\Software\DataMngr_Toolbar Key Deleted : HKCU\Software\Delta Key Deleted : HKCU\Software\Doko-Toolbar Key Deleted : HKCU\Software\InstallCore Key Deleted : HKCU\Software\installedbrowserextensions Key Deleted : HKCU\Software\InstalledThirdPartyPrograms Key Deleted : HKCU\Software\lollipop Key Deleted : HKCU\Software\Optimizer Pro Key Deleted : HKCU\Software\Softonic Key Deleted : HKCU\Software\Somoto Key Deleted : HKCU\Software\systweak Key Deleted : HKCU\Software\torch Key Deleted : HKCU\Software\Webplayer Key Deleted : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F} Key Deleted : HKCU\Software\AppDataLow\SProtector Key Deleted : HKCU\Software\AppDataLow\Software\Crossrider Key Deleted : HKCU\Software\AppDataLow\Software\smartbar Key Deleted : HKLM\Software\{1146AC44-2F03-4431-B4FD-889BC837521F} Key Deleted : HKLM\Software\{6791A2F3-FC80-475C-A002-C014AF797E9C} Key Deleted : HKLM\Software\AppGraffiti Key Deleted : HKLM\Software\Conduit Key Deleted : HKLM\Software\CToolbar Key Deleted : HKLM\Software\DataMngr Key Deleted : HKLM\Software\Delta Key Deleted : HKLM\Software\Doko-Toolbar Key Deleted : HKLM\Software\eSafeSecControl Key Deleted : HKLM\Software\InstalledThirdPartyPrograms Key Deleted : HKLM\Software\Minibar Key Deleted : HKLM\Software\qone8Software Key Deleted : HKLM\Software\SP Global Key Deleted : HKLM\Software\SProtector Key Deleted : HKLM\Software\systweak Key Deleted : HKLM\Software\torch Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{6F6A5334-78E9-4D9B-8182-8B41EA8C39EF}_is1 Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\00212D92-C5D8-4ff4-AE50-B20F0F85C40A_Systweak_Ad~B9F029BF_is1 Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\bi_uninstaller Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Delta Chrome Toolbar Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Delta Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FilesFrog Update Checker Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MyPC Backup Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Optimizer Pro_is1 Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\RegClean Pro_is1 ***** [ Browsers ] ***** -\\ Internet Explorer v10.0.9200.16720 Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [start Page] Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [start Page] -\\ Mozilla Firefox v19.0.2 (nl) [ File : C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\prefs.js ] Line Deleted : user_pref("browser.newtab.url", "hxxp://www.doko-search.com/?babsrc=NT_ss&mntrId=5C120012795EDD2D&affID=125836&tsp=5039"); Line Deleted : user_pref("browser.search.defaultenginename", "WebSearch"); Line Deleted : user_pref("browser.search.selectedEngine", "WebSearch"); Line Deleted : user_pref("browser.startup.homepage", "hxxp://websearch.wisesearch.info/?pid=357&r=2013/10/18&hid=10612048198043085368&lg=EN&cc=BE&unqvl=39"); Line Deleted : user_pref("browser.search.order.1", "WebSearch"); Line Deleted : user_pref("browser.search.defaulturl", "hxxp://websearch.wisesearch.info/?pid=357&r=2013/10/18&hid=10612048198043085368&lg=EN&cc=BE&unqvl=39&l=1&q="); Line Deleted : user_pref("browser.search.order.1,S", "WebSearch"); Line Deleted : user_pref("browser.search.defaultenginename,S", "WebSearch"); Line Deleted : user_pref("browser.search.selectedEngine,S", "WebSearch"); Line Deleted : user_pref("keyword.URL", "hxxp://websearch.wisesearch.info/?pid=357&r=2013/10/18&hid=10612048198043085368&lg=EN&cc=BE&unqvl=39&l=1&q="); -\\ Google Chrome v30.0.1599.101 [ File : C:\Users\Anke\AppData\Local\Google\Chrome\User Data\Default\preferences ] Deleted : homepage Deleted : icon_url Deleted : search_url Deleted : keyword Deleted : urls_to_restore_on_startup ************************* AdwCleaner[R0].txt - [18482 octets] - [28/10/2013 11:05:04] AdwCleaner[s0].txt - [17728 octets] - [28/10/2013 11:06:25] ########## EOF - C:\AdwCleaner\AdwCleaner[s0].txt - [17789 octets] ##########
  11. is er misschien een manier om die pop-ups in de toekomst te vermijden?
  12. veel beter, heb nog last van 1 enkele pop-up. nl: als k een keer of 5 iets aanklik, of wil inloggen bv, komt er ineens altijd een nieuw internet scherm apart op, en gaat de gevraagde pagina niet open, pas na een 2de keer. maar voor de rest ben ik eigelijk heel content, dus da 1 dingske ist nu ni echt. merci he
  13. Zoek.exe Version 4.0.0.4 Updated 26-October-2013 Tool run by Anke on za 26/10/2013 at 20:11:32,73. Microsoft Windows 7 Professional 6.1.7601 Service Pack 1 x86 Running in: Normal Mode Internet Access Detected Launched: C:\Users\Anke\Desktop\zoek.exe [script inserted] ==== Older Logs ====================== C:\zoek-results2013-10-26-073718.log 45312 bytes C:\zoek-results2013-10-26-131829.log 32021 bytes ==== Registry Fix Code ====================== Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions] "ytfmdownloader@gmail.com"=- ==== Deleting Files \ Folders ====================== "C:\Users\Anke\AppData\Roaming\BabSolution\CR\Doko.crx" not found "C:\Users\Anke\AppData\Roaming\BabSolution\CR\Delta.crx" not found "C:\Program Files\diamondata\hendmekoldfacfhlojkjcnbjegkahclb.crx" not found C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\{97A78363-B868-4B48-AC91-A783A31215AF} deleted C:\Program Files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} deleted "C:\Program Files\Freemake\Freemake Video Downloader\BrowserPlugin\Chrome\Freemake.Plugin.Chrome.crx" deleted "C:\Program Files\Freemake\Freemake Video Downloader\BrowserPlugin\Chrome\ChromeYoutubePlugin.crx" deleted "C:\Program Files\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\ytfmdownloader@gmail.com\chrome.manifest" deleted "C:\Program Files\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\ytfmdownloader@gmail.com\install.rdf" deleted "C:\Program Files\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\ytfmdownloader@gmail.com\modules\jQuery.js" deleted "C:\Program Files\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\ytfmdownloader@gmail.com\modules\youtube_com.js" deleted "C:\Program Files\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\ytfmdownloader@gmail.com\chrome\content\downloader.js" deleted "C:\Program Files\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\ytfmdownloader@gmail.com\chrome\content\downloader.xul" deleted "C:\Program Files\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\ytfmdownloader@gmail.com\chrome\content\icons\32freemake.png" deleted "C:\Program Files\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\ytfmdownloader@gmail.com\chrome\content\icons\icon.png" deleted "C:\Program Files\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\ytfmdownloader@gmail.com\chrome\locale\de-DE\main.properties" deleted "C:\Program Files\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\ytfmdownloader@gmail.com\chrome\locale\en-US\main.properties" deleted "C:\Program Files\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\ytfmdownloader@gmail.com\chrome\locale\es-ES\main.properties" deleted "C:\Program Files\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\ytfmdownloader@gmail.com\chrome\locale\fr-FR\main.properties" deleted "C:\Program Files\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\ytfmdownloader@gmail.com\chrome\locale\it-IT\main.properties" deleted "C:\Program Files\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\ytfmdownloader@gmail.com\chrome\locale\jp-JP\main.properties" deleted "C:\Program Files\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\ytfmdownloader@gmail.com\chrome\locale\ru-RU\main.properties" deleted "C:\Program Files\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\ytfmdownloader@gmail.com" deleted "C:\Program Files\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\ytfmdownloader@gmail.com\chrome" deleted "C:\Program Files\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\ytfmdownloader@gmail.com\modules" deleted "C:\Program Files\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\ytfmdownloader@gmail.com\chrome\content" deleted "C:\Program Files\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\ytfmdownloader@gmail.com\chrome\locale" deleted "C:\Program Files\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\ytfmdownloader@gmail.com\chrome\content\icons" deleted "C:\Program Files\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\ytfmdownloader@gmail.com\chrome\locale\de-DE" deleted "C:\Program Files\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\ytfmdownloader@gmail.com\chrome\locale\en-US" deleted "C:\Program Files\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\ytfmdownloader@gmail.com\chrome\locale\es-ES" deleted "C:\Program Files\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\ytfmdownloader@gmail.com\chrome\locale\fr-FR" deleted "C:\Program Files\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\ytfmdownloader@gmail.com\chrome\locale\it-IT" deleted "C:\Program Files\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\ytfmdownloader@gmail.com\chrome\locale\jp-JP" deleted "C:\Program Files\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\ytfmdownloader@gmail.com\chrome\locale\ru-RU" deleted ==== Chrome Look ====================== HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions bpegkgagfojjbcpkihigfmkojdmmimdf - C:\Program Files\Freemake\Freemake Video Downloader\BrowserPlugin\Chrome\Freemake.Plugin.Chrome.crx[] ehgldbbpchgpcfagfpfjgoomddhccfgh - C:\Program Files\Freemake\Freemake Video Downloader\BrowserPlugin\Chrome\ChromeYoutubePlugin.crx[] ifohbjbgfchkkfhphahclmkpgejiplfo - C:\Users\Anke\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtab.crx[02/10/2013 14:22] Google Docs - Anke - Default\Extensions\aohghmighlieiainnegkcijnfilokake Google Drive - Anke - Default\Extensions\apdfllckaahabafndbhieahigkjlhalf YouTube - Anke - Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo Google Search - Anke - Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf Chrome In-App Payments service - Anke - Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda Gmail - Anke - Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia Docs - Anke - Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake Google Drive - Anke - Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf YouTube - Anke - Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo Freemake Video Downloader - Anke - Profile 1\Extensions\bpegkgagfojjbcpkihigfmkojdmmimdf Google Search - Anke - Profile 1\Extensions\coobgpohoikkiipiblmjeljniedjpjpf Freemake Youtube Download Button - Anke - Profile 1\Extensions\ehgldbbpchgpcfagfpfjgoomddhccfgh Select City - Anke - Profile 1\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo Gmail - Anke - Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia undetermined - Anke - Default\Extensions\newtab.crx ==== Chrome Fix ====================== C:\Users\Anke\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\bpegkgagfojjbcpkihigfmkojdmmimdf deleted successfully C:\Users\Anke\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ehgldbbpchgpcfagfpfjgoomddhccfgh deleted successfully C:\Users\Anke\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_gnbbmjlpkhenbefmmdjodjfmcamegmpd_0.localstorage deleted successfully ==== Deleting Registry Keys ====================== HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\bpegkgagfojjbcpkihigfmkojdmmimdf deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\ehgldbbpchgpcfagfpfjgoomddhccfgh deleted successfully ==== EOF on za 26/10/2013 at 20:12:44,30 ======================
  14. Zoek.exe Version 4.0.0.4 Updated 26-October-2013 Tool run by Anke on za 26/10/2013 at 15:15:05,73. Microsoft Windows 7 Professional 6.1.7601 Service Pack 1 x86 Running in: Normal Mode Internet Access Detected Launched: C:\Users\Anke\Desktop\zoek.exe [script inserted] ==== Older Logs ====================== C:\zoek-results2013-10-26-073718.log 45312 bytes ==== Registry Fix Code ====================== Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions] "{ACAA314B-EEBA-48e4-AD47-84E31C44796C}"=- ==== Deleting Files \ Folders ====================== C:\Program Files\MyPC Backup not found C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} not found C:\Program Files\RegClean Pro not found "C:\Program Files\Common Files\DVDVideoSoft\plugins\DVDVideoSoftBrowserExtension.crx" not found C:\Windows\system32\tasks\BitGuard deleted C:\Windows\system32\tasks\RegClean Pro deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\firefox@diamondata.net.xpi" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\chrome.manifest" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\install.rdf" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\extensionData\manifest.xml" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\extensionData\plugins.json" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\skin\button1.png" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\skin\button2.png" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\skin\button3.png" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\skin\button4.png" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\skin\button5.png" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\skin\crossrider_statusbar.png" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\skin\icon128.png" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\skin\icon16.png" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\skin\icon24.png" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\skin\icon48.png" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\skin\panelarrow-up.png" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\skin\popup.html" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\skin\skin.css" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\skin\update.css" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\chrome\content\api.js" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\chrome\content\background.html" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\chrome\content\baseObject.js" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\chrome\content\browser.xul" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\chrome\content\dialog.js" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\chrome\content\main.js" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\chrome\content\options.js" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\chrome\content\options.xul" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\chrome\content\search_dialog.xul" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\chrome\content\api\asyncDB.js" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\chrome\content\api\background.js" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\chrome\content\api\browserAction.js" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\chrome\content\api\contextMenu.js" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\chrome\content\api\dbManager.js" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\chrome\content\api\dom_bg.js" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\chrome\content\api\fileManager.js" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\chrome\content\api\firefox.js" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\chrome\content\api\firefoxNotifications.js" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\chrome\content\api\firefoxOmnibox.js" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\chrome\content\api\message.js" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\chrome\content\api\pageAction.js" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\chrome\content\api\request.js" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\chrome\content\api\tabs.js" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\chrome\content\api\webRequest.js" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\chrome\content\core\console.js" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\chrome\content\core\consts.js" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\chrome\content\core\delegate.js" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\chrome\content\core\extensionDataStore.js" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\chrome\content\core\folderIOWrapper.js" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\chrome\content\core\httpObserver.js" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\chrome\content\core\IDBWrapper.js" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\chrome\content\core\installer.js" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\chrome\content\core\logFile.js" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\chrome\content\core\prefs.js" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\chrome\content\core\progressListenerObserver.js" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\chrome\content\core\registry.js" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\chrome\content\core\reloadObserver.js" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\chrome\content\core\reports.js" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\chrome\content\core\requestObject.js" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\chrome\content\core\searchSettings.js" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\chrome\content\core\uninstallObserver.js" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\chrome\content\core\updateManager.js" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\chrome\content\core\utils.js" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\chrome\content\core\xhr.js" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\defaults\preferences\prefs.js" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\extensionData\plugins\101_cortica_m.js" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\extensionData\plugins\102_dealply_m.js" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\extensionData\plugins\103_intext_5_m.js" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\extensionData\plugins\104_jollywallet_m.js" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\extensionData\plugins\105_corticas_m.js" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\extensionData\plugins\107_coupish_m.js" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\extensionData\plugins\108_icm_m.js" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\extensionData\plugins\116_ads_only_5_m.js" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\extensionData\plugins\117_coupons_intext_ads_5_m.js" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\extensionData\plugins\119_similar_web_m.js" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\extensionData\plugins\120_luck_m.js" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\extensionData\plugins\123_intext_adv_m.js" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\extensionData\plugins\124_superfish_no_search_no_coupons_m.js" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\extensionData\plugins\125_arcadi2_m.js" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\extensionData\plugins\126_revizer_ws_m.js" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\extensionData\plugins\127_revizer_p_m.js" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\extensionData\plugins\128_superfish_pricora_m.js" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\extensionData\plugins\129_widdit_m.js" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\extensionData\plugins\135_arcadi3_m.js" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\extensionData\plugins\138_getdeal_m.js" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\extensionData\plugins\13_CrossriderAppUtils.js" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\extensionData\plugins\141_corticas_ru_m.js.js" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\extensionData\plugins\142_intext_fa_m.js" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\extensionData\plugins\14_CrossriderUtils.js" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\extensionData\plugins\155_ibario_pops_m.js" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\extensionData\plugins\158_50onred_ads_only_no_fb_m.js" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\extensionData\plugins\159_cortica_rollover_m.js" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\extensionData\plugins\16_FFAppAPIWrapper.js" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\extensionData\plugins\17_jQuery.js" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\extensionData\plugins\1_base.js" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\extensionData\plugins\21_debug.js" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\extensionData\plugins\22_resources.js" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\extensionData\plugins\28_initializer.js" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\extensionData\plugins\47_resources_background.js" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\extensionData\plugins\4_jquery_1_7_1.js" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\extensionData\plugins\64_appApiMessage.js" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\extensionData\plugins\72_appApiValidation.js" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\extensionData\plugins\78_CrossriderInfo.js" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\extensionData\plugins\87_ginyas_wrapper.js" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\extensionData\plugins\91_monetizationLoader.js.js" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\extensionData\plugins\92_superfish_m.js" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\extensionData\plugins\93_superfish_no_coupons_m.js" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\extensionData\plugins\98_omniCommands.js" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\extensionData\userCode\background.js" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\extensionData\userCode\extension.js" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\locale\en-US\translations.dtd" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\chrome" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\defaults" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\extensionData" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\locale" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\skin" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\chrome\content" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\chrome\content\api" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\chrome\content\core" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\defaults\preferences" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\extensionData\plugins" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\extensionData\userCode" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com\locale\en-US" deleted ==== Firefox Extensions Registry ====================== [HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions] "ytfmdownloader@gmail.com"="C:\Program Files\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\ytfmdownloader@gmail.com" [04/09/2013 20:51] ==== Firefox Extensions ====================== ProfilePath: C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default - Undetermined - %ProfilePath%\extensions\staged - AppsHat - %ProfilePath%\extensions\{97A78363-B868-4B48-AC91-A783A31215AF} AppDir: C:\Program Files\Mozilla Firefox - Default - %AppDir%\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} ==== Firefox Plugins ====================== ==== Chrome Look ====================== HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions bpegkgagfojjbcpkihigfmkojdmmimdf - C:\Program Files\Freemake\Freemake Video Downloader\BrowserPlugin\Chrome\Freemake.Plugin.Chrome.crx[16/08/2013 07:36] edcikfknpchdehdlmjpbofgkoaonaijg - C:\Users\Anke\AppData\Roaming\BabSolution\CR\Doko.crx[] ehgldbbpchgpcfagfpfjgoomddhccfgh - C:\Program Files\Freemake\Freemake Video Downloader\BrowserPlugin\Chrome\ChromeYoutubePlugin.crx[16/08/2013 07:36] eooncjejnppfjjklapaamhcdmjbilmde - C:\Users\Anke\AppData\Roaming\BabSolution\CR\Delta.crx[] hendmekoldfacfhlojkjcnbjegkahclb - C:\Program Files\diamondata\hendmekoldfacfhlojkjcnbjegkahclb.crx[] ifohbjbgfchkkfhphahclmkpgejiplfo - C:\Users\Anke\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtab.crx[02/10/2013 14:22] HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\Extensions nikpibnbobmbdbheedjfogjlikpgpnhp - C:\Program Files\Common Files\DVDVideoSoft\plugins\DVDVideoSoftBrowserExtension.crx[] Google Docs - Anke - Default\Extensions\aohghmighlieiainnegkcijnfilokake Google Drive - Anke - Default\Extensions\apdfllckaahabafndbhieahigkjlhalf DowiNLoad keepeR - Anke - Default\Extensions\bihdackfdgiogegcokiakmpkbimmommm YouTube - Anke - Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo Google Search - Anke - Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf LyricsViewer-2 - Anke - Default\Extensions\gnbbmjlpkhenbefmmdjodjfmcamegmpd Web Video Solution - Anke - Default\Extensions\lehjhdjciofcglicaidnlfleggadgfpk Helper extension - Anke - Default\Extensions\nchpfiddbhbdnagofhkjlaiaejmkdcla Chrome In-App Payments service - Anke - Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda Gmail - Anke - Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia Docs - Anke - Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake Google Drive - Anke - Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf DowiNLoad keepeR - Anke - Profile 1\Extensions\bihdackfdgiogegcokiakmpkbimmommm YouTube - Anke - Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo Freemake Video Downloader - Anke - Profile 1\Extensions\bpegkgagfojjbcpkihigfmkojdmmimdf Google Search - Anke - Profile 1\Extensions\coobgpohoikkiipiblmjeljniedjpjpf Freemake Youtube Download Button - Anke - Profile 1\Extensions\ehgldbbpchgpcfagfpfjgoomddhccfgh LyricsViewer-2 - Anke - Profile 1\Extensions\gnbbmjlpkhenbefmmdjodjfmcamegmpd Select City - Anke - Profile 1\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo Gmail - Anke - Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia undetermined - Anke - Default\Extensions\newtab.crx ==== Chrome Fix ====================== C:\Users\Anke\AppData\Local\Google\Chrome\User Data\Default\Extensions\gnbbmjlpkhenbefmmdjodjfmcamegmpd deleted successfully C:\Users\Anke\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\gnbbmjlpkhenbefmmdjodjfmcamegmpd deleted successfully C:\Users\Anke\AppData\Local\Google\Chrome\User Data\Default\Extensions\bihdackfdgiogegcokiakmpkbimmommm deleted successfully C:\Users\Anke\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\bihdackfdgiogegcokiakmpkbimmommm deleted successfully C:\Users\Anke\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_bihdackfdgiogegcokiakmpkbimmommm_0.localstorage-journal deleted successfully C:\Users\Anke\AppData\Local\Google\Chrome\User Data\Default\Extensions\lehjhdjciofcglicaidnlfleggadgfpk deleted successfully C:\Users\Anke\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_lehjhdjciofcglicaidnlfleggadgfpk_0.localstorage deleted successfully C:\Users\Anke\AppData\Local\Google\Chrome\User Data\Default\Extensions\nchpfiddbhbdnagofhkjlaiaejmkdcla deleted successfully ==== Deleting Registry Keys ====================== HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\Extensions\Nikpibnbobmbdbheedjfogjlikpgpnhp deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\Edcikfknpchdehdlmjpbofgkoaonaijg deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\Eooncjejnppfjjklapaamhcdmjbilmde deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\Hendmekoldfacfhlojkjcnbjegkahclb deleted successfully ==== After Reboot ====================== ==== Deleting Files / Folders ====================== "C:\Users\Anke\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_gnbbmjlpkhenbefmmdjodjfmcamegmpd_0.localstorage" not deleted "C:\Users\Anke\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_gnbbmjlpkhenbefmmdjodjfmcamegmpd_0" deleted "C:\Users\Anke\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_bihdackfdgiogegcokiakmpkbimmommm_0.localstorage" not deleted "C:\Users\Anke\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_bihdackfdgiogegcokiakmpkbimmommm_0.localstorage" not deleted "C:\Users\Anke\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_gnbbmjlpkhenbefmmdjodjfmcamegmpd_0.localstorage" not deleted "C:\Users\Anke\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_gnbbmjlpkhenbefmmdjodjfmcamegmpd_0" not found ==== EOF on za 26/10/2013 at 15:18:29,78 ======================
  15. Zoek.exe Version 4.0.0.4 Updated 26-October-2013 Tool run by Anke on za 26/10/2013 at 9:21:25,66. Microsoft Windows 7 Professional 6.1.7601 Service Pack 1 x86 Running in: Normal Mode Internet Access Detected Launched: C:\Users\Anke\Desktop\zoek.exe [script inserted] ==== System Restore Info ====================== 26/10/2013 9:23:08 Zoek.exe System Restore Point Created Succesfully. ==== Empty Folders Check ====================== C:\ProgramData\Babylon deleted successfully C:\ProgramData\{C4ABDBC8-1C81-42C9-BFFC-4A68511E9E4F} deleted successfully C:\Users\Anke\AppData\Roaming\Google deleted successfully C:\Users\Anke\AppData\Local\Lollipop deleted successfully C:\Users\Anke\AppData\Local\WMTools Downloaded Files deleted successfully ==== Deleting CLSID Registry Keys ====================== HKEY_USERS\S-1-5-21-766547166-3330058944-3535508039-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{339E1B37-76D3-4A64-A988-E81425DF831C} deleted successfully HKEY_USERS\S-1-5-21-766547166-3330058944-3535508039-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{339E1B37-76D3-4A64-A988-E81425DF831C} deleted successfully HKEY_CLASSES_ROOT\CLSID\{339E1B37-76D3-4A64-A988-E81425DF831C} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{AAA38851-3CFF-475F-B5E0-720D3645E4A5} deleted successfully HKEY_CLASSES_ROOT\CLSID\{AAA38851-3CFF-475F-B5E0-720D3645E4A5} deleted successfully ==== Deleting CLSID Registry Values ====================== HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{339E1B37-76D3-4A64-A988-E81425DF831C} deleted successfully ==== Deleting Services ====================== HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ca82e1a5 deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\ca82e1a5 deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Update diamondata deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Update diamondata deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Eventlog\Application\Update diamondata deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Update diamondata deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Util diamondata deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Util diamondata deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Eventlog\Application\Util diamondata deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Util diamondata deleted successfully ==== Registry Fix Code ====================== Windows Registry Editor Version 5.00 [-HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@VideoDownloadConverter_4z.com/Plugin] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "Optimizer Pro"=- ==== Deleting Files \ Folders ====================== C:\Program Files\VideoDownloadConverter_4z not found C:\ProgramData\Babylon not found "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e...0d3e13631d.com" not found C:\Program Files\Doko-Toolbar deleted C:\Users\Anke\AppData\Roaming\DVDVideoSoftIEHelpers deleted C:\Program Files\Minibar deleted C:\ProgramData\Systweak deleted C:\Users\Anke\AppData\Roaming\Systweak deleted C:\Program Files\RegClean Pro deleted C:\Program Files\WebSearch deleted C:\ProgramData\InstallMate deleted C:\Users\Anke\AppData\Roaming\Optimizer Pro deleted C:\Users\Anke\AppData\Roaming\Doko-Toolbar deleted C:\Program Files\Delta deleted C:\Users\Anke\AppData\Roaming\Delta deleted C:\Users\Anke\AppData\Roaming\BabSolution deleted C:\ProgramData\DSearchLink deleted C:\Program Files\LyricsViewer-2 deleted "C:\Windows\tasks\LyricsViewer-2-chromeinstaller.job" deleted "C:\Windows\tasks\LyricsViewer-2-codedownloader.job" deleted "C:\Windows\tasks\LyricsViewer-2-enabler.job" deleted "C:\Windows\tasks\LyricsViewer-2-firefoxinstaller.job" deleted "C:\Windows\tasks\LyricsViewer-2-updater.job" deleted "C:\Windows\tasks\RegClean Pro_DEFAULT.job" deleted "C:\Windows\tasks\RegClean Pro_UPDATES.job" deleted "C:\Program Files\Mozilla Firefox\searchplugins\qone8.xml" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\searchplugins\babylon.xml" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\searchplugins\dokotoolbar.xml" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\searchplugins\WebSearch.xml" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\AppGraffiti@AppGraffiti.com\chrome.manifest" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\AppGraffiti@AppGraffiti.com\ini.xml" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\AppGraffiti@AppGraffiti.com\install.rdf" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\AppGraffiti@AppGraffiti.com\install.xml" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@delta.com\chrome.manifest" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@delta.com\install.rdf" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@delta.com\uninstall.exe" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@dokotoolbar.com\chrome.manifest" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@dokotoolbar.com\install.rdf" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@dokotoolbar.com\uninstall.exe" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\AppGraffiti@AppGraffiti.com\chrome\AppGraffiti.jar" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@babylon.com\defaults\preferences\dflt.js" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@delta.com\components\FFDisp.dll" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@delta.com\content\delta.css" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@delta.com\content\delta.xul" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@delta.com\content\dpk.htm" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@delta.com\content\hlprs.js" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@delta.com\content\loader.xul" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@delta.com\content\mtstart.js" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@delta.com\content\serp.js" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@delta.com\content\tmplt.js" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@delta.com\content\imgs\arwDwn.gif" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@delta.com\content\imgs\closeo.png" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@delta.com\content\imgs\help_16.gif" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@delta.com\content\imgs\home.gif" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@delta.com\content\imgs\icon_seperator.png" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@delta.com\content\imgs\logo.PNG" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@delta.com\content\imgs\privecy_16_hot.gif" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@delta.com\content\imgs\sign.jpg" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@delta.com\content\imgs\specialoffer.gif" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@delta.com\content\imgs\tellafriend.gif" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@delta.com\content\imgs\uninstall.gif" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@delta.com\content\imgs\flgs\ae.png" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@delta.com\content\imgs\flgs\bg.png" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@delta.com\content\imgs\flgs\ch.png" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@delta.com\content\imgs\flgs\cn.png" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@delta.com\content\imgs\flgs\cz.png" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@delta.com\content\imgs\flgs\de.png" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@delta.com\content\imgs\flgs\eg.png" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@delta.com\content\imgs\flgs\en.png" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@delta.com\content\imgs\flgs\es.png" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@delta.com\content\imgs\flgs\fr.png" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@delta.com\content\imgs\flgs\gr.png" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@delta.com\content\imgs\flgs\he.png" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@delta.com\content\imgs\flgs\il.png" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@delta.com\content\imgs\flgs\it.png" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@delta.com\content\imgs\flgs\ja.png" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@delta.com\content\imgs\flgs\jp.png" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@delta.com\content\imgs\flgs\nl.png" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@delta.com\content\imgs\flgs\no.png" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@delta.com\content\imgs\flgs\pl.png" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@delta.com\content\imgs\flgs\pt.png" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@delta.com\content\imgs\flgs\ro.png" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@delta.com\content\imgs\flgs\ru.png" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@delta.com\content\imgs\flgs\sa.png" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@delta.com\content\imgs\flgs\se.png" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@delta.com\content\imgs\flgs\sv.png" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@delta.com\content\imgs\flgs\tr.png" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@delta.com\content\imgs\flgs\ua.png" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@delta.com\content\imgs\flgs\us.png" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@dokotoolbar.com\components\FFDisp.dll" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@dokotoolbar.com\content\dokotoolbar.css" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@dokotoolbar.com\content\dokotoolbar.xul" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@dokotoolbar.com\content\dpk.htm" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@dokotoolbar.com\content\hlprs.js" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@dokotoolbar.com\content\loader.xul" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@dokotoolbar.com\content\mtstart.js" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@dokotoolbar.com\content\serp.js" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@dokotoolbar.com\content\tmplt.js" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@dokotoolbar.com\content\imgs\arwDwn.gif" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@dokotoolbar.com\content\imgs\closeo.png" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@dokotoolbar.com\content\imgs\help_16.gif" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@dokotoolbar.com\content\imgs\home.gif" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@dokotoolbar.com\content\imgs\icon_seperator.png" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@dokotoolbar.com\content\imgs\logo.png" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@dokotoolbar.com\content\imgs\privecy_16_hot.gif" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@dokotoolbar.com\content\imgs\sign.jpg" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@dokotoolbar.com\content\imgs\specialoffer.gif" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@dokotoolbar.com\content\imgs\tellafriend.gif" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@dokotoolbar.com\content\imgs\uninstall.gif" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@dokotoolbar.com\content\imgs\flgs\ae.png" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@dokotoolbar.com\content\imgs\flgs\bg.png" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@dokotoolbar.com\content\imgs\flgs\ch.png" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@dokotoolbar.com\content\imgs\flgs\cn.png" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@dokotoolbar.com\content\imgs\flgs\cz.png" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@dokotoolbar.com\content\imgs\flgs\de.png" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@dokotoolbar.com\content\imgs\flgs\eg.png" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@dokotoolbar.com\content\imgs\flgs\en.png" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@dokotoolbar.com\content\imgs\flgs\es.png" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@dokotoolbar.com\content\imgs\flgs\fr.png" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@dokotoolbar.com\content\imgs\flgs\gr.png" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@dokotoolbar.com\content\imgs\flgs\he.png" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@dokotoolbar.com\content\imgs\flgs\il.png" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@dokotoolbar.com\content\imgs\flgs\it.png" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@dokotoolbar.com\content\imgs\flgs\ja.png" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@dokotoolbar.com\content\imgs\flgs\jp.png" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@dokotoolbar.com\content\imgs\flgs\nl.png" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@dokotoolbar.com\content\imgs\flgs\no.png" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@dokotoolbar.com\content\imgs\flgs\pl.png" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@dokotoolbar.com\content\imgs\flgs\pt.png" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@dokotoolbar.com\content\imgs\flgs\ro.png" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@dokotoolbar.com\content\imgs\flgs\ru.png" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@dokotoolbar.com\content\imgs\flgs\sa.png" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@dokotoolbar.com\content\imgs\flgs\se.png" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@dokotoolbar.com\content\imgs\flgs\sv.png" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@dokotoolbar.com\content\imgs\flgs\tr.png" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@dokotoolbar.com\content\imgs\flgs\ua.png" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@dokotoolbar.com\content\imgs\flgs\us.png" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@dokotoolbar.com\defaults\preferences\dflt.js" deleted "C:\Program Files\Optimizer Pro\OptProReminder.exe" deleted "C:\Program Files\MyPC Backup\AWSSDK.dll" deleted "C:\Program Files\MyPC Backup\BackupStack.exe" deleted "C:\Program Files\MyPC Backup\GetText.dll" deleted "C:\Program Files\MyPC Backup\MPCBClient.dll" deleted "C:\Program Files\MyPC Backup\MyPC Backup.exe" deleted "C:\Program Files\MyPC Backup\Shared Stack.dll" deleted "C:\Program Files\diamondata\updatediamondata.exe" deleted "C:\Program Files\Advanced System Protector\AdvancedSystemProtector.exe" deleted "C:\Program Files\Advanced System Protector\aspsys.dll" deleted "C:\Program Files\Advanced System Protector\Microsoft.Win32.TaskScheduler.DLL" deleted "C:\Program Files\Advanced System Protector\System.Data.SQLite.dll" deleted "C:\Program Files\Advanced System Protector\unrar.dll" deleted "C:\Program Files\Advanced System Protector\Xceed.Compression.dll" deleted "C:\Program Files\Advanced System Protector\Xceed.FileSystem.dll" deleted "C:\Program Files\Advanced System Protector\Xceed.Zip.dll" deleted "C:\Program Files\Optimizer Pro\OptProReminder.exe" deleted "C:\Program Files\diamondata\updatediamondata.exe" deleted "C:\Program Files\MyPC Backup\Database\mpcb_settings.db" deleted "C:\Program Files\MyPC Backup\Database\mpcb_version_queue.db" deleted "C:\Program Files\MyPC Backup\x86\System.Data.SQLite.dll" deleted "C:\Program Files\MyPC Backup\Resources\keycache\_023c2e8d-b42d-4c64-a874-27ec03d084e7_backupKeyCache.block" not deleted "C:\Program Files\MyPC Backup\Resources\keycache\_023c2e8d-b42d-4c64-a874-27ec03d084e7_backupKeyCache.tree" not deleted "C:\Program Files\MyPC Backup\Resources\keycache\_28f505d4-dc5a-4ff1-908d-a9a2506facfe_backupKeyCache.block" not deleted "C:\Program Files\MyPC Backup\Resources\keycache\_28f505d4-dc5a-4ff1-908d-a9a2506facfe_backupKeyCache.tree" not deleted "C:\Program Files\Common Files\DVDVideoSoft\lib\DVSShellContextMenuExtension.dll" deleted "C:\Program Files\diamondata\bin\sqlite3.dll" deleted "C:\Program Files\diamondata\bin\utildiamondata.exe" deleted "C:\Program Files\diamondata\bin\sqlite3.dll" deleted "C:\Program Files\diamondata\bin\utildiamondata.exe" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\AppGraffiti@AppGraffiti.com" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@babylon.com" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@delta.com" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@dokotoolbar.com" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\AppGraffiti@AppGraffiti.com\chrome" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@babylon.com\defaults" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@babylon.com\defaults\preferences" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@delta.com\components" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@delta.com\content" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@delta.com\content\imgs" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@delta.com\content\imgs\flgs" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@dokotoolbar.com\components" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@dokotoolbar.com\content" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@dokotoolbar.com\defaults" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@dokotoolbar.com\content\imgs" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@dokotoolbar.com\content\imgs\flgs" deleted "C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ffxtlbr@dokotoolbar.com\defaults\preferences" deleted "C:\Program Files\Optimizer Pro" deleted "C:\Program Files\MyPC Backup" not deleted "C:\Program Files\Common Files\DVDVideoSoft" not deleted "C:\Program Files\diamondata" not deleted "C:\Program Files\Advanced System Protector" not deleted "C:\Program Files\Optimizer Pro" deleted "C:\Program Files\diamondata" not deleted "C:\Users\Anke\AppData\Roaming\OpenCandy" deleted "C:\Program Files\MyPC Backup\Database" not deleted "C:\Program Files\MyPC Backup\Resources" not deleted "C:\Program Files\MyPC Backup\x86" not deleted "C:\Program Files\MyPC Backup\Resources\keycache" not deleted "C:\Program Files\Common Files\DVDVideoSoft\lib" not deleted "C:\Program Files\diamondata\bin" not deleted "C:\Program Files\diamondata\bin" not deleted ==== Files Recently Created / Modified ====================== ====== C:\Windows ==== 2013-10-02 18:35:40 2A66E81AE941E54A237490FC35D387C8 1945 ----a-w- C:\Windows\epplauncher.mif ====== C:\Users\Anke\AppData\Local\Temp ==== ====== Java Cache ===== 2013-10-22 10:06:35 0F08A8F6BA89A7E31BD59FE8189B97BC 193418 ----a-w- C:\Users\Anke\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\32\474b93a0-1e91598d 2013-10-22 10:06:36 E035E0B09BCADCCD3FBAD1CD731585A4 469 ----a-w- C:\Users\Anke\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\38\4de63de6-337c0836 2013-10-04 09:01:57 A98998FB8CF1C95844FC05EFFB8A6C76 1040305 ----a-w- C:\Users\Anke\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\54\5530fcf6-4ed5e94e ====== C:\Windows\system32 ===== 2013-10-21 19:42:53 0065E911F966A71A115D9A52FF3DFC99 17136 ----a-w- C:\Windows\System32\sasnative32.exe 2013-10-21 19:42:03 05589174BBE539C14B3F466C33963CA8 18776 ----a-w- C:\Windows\System32\roboot.exe ====== C:\Windows\system32\drivers ===== 2013-10-09 05:07:49 71D97F1A3CC47A56728F7A400A3F8295 76288 ----a-w- C:\Windows\System32\drivers\usbccgp.sys 2013-10-09 05:07:48 FDA6F2BB7FA034D95863ED8788B4E416 284672 ----a-w- C:\Windows\System32\drivers\usbport.sys 2013-10-09 05:07:48 DCDF9855145A14DFCA0AB32308871961 20480 ----a-w- C:\Windows\System32\drivers\usbohci.sys 2013-10-09 05:07:48 C4FB8E7ADEA9B5CEEA885A1B504B7E40 43008 ----a-w- C:\Windows\System32\drivers\usbehci.sys 2013-10-09 05:07:48 8E51D04175BAA14C4F79AA5F6D248770 24064 ----a-w- C:\Windows\System32\drivers\usbuhci.sys 2013-10-09 05:07:48 86AA95ACB611001E26CD2C0145F2225A 258560 ----a-w- C:\Windows\System32\drivers\usbhub.sys 2013-10-09 05:07:48 6FB17D7A2E76B838886E5E8C60239DAE 6016 ----a-w- C:\Windows\System32\drivers\usbd.sys 2013-10-09 05:07:47 F1B27299F547D452EDAEF01FC187CB91 25728 ----a-w- C:\Windows\System32\drivers\hidparse.sys 2013-10-09 05:07:47 50ABE682EBE752EAF62B18790D6D491C 55808 ----a-w- C:\Windows\System32\drivers\hidclass.sys 2013-10-09 05:07:46 CA59F7C570AF70BC174F477CFE2D9EE3 1294272 ----a-w- C:\Windows\System32\drivers\tcpip.sys 2013-10-09 05:07:45 F81BB7E487EDCEAB630A7EE66CF23913 338944 ----a-w- C:\Windows\System32\drivers\afd.sys 2013-10-09 05:07:42 71BC35067CABC02C9453AEAA42B2E43E 729024 ----a-w- C:\Windows\System32\drivers\dxgkrnl.sys 2013-10-09 05:07:29 21F4B24ACFC79A483515BD986DD9043F 115712 ----a-w- C:\Windows\System32\drivers\mrxdav.sys 2013-10-09 05:07:27 2352AB5F9F8F097BF9D41D5A4718A041 86016 ----a-w- C:\Windows\System32\drivers\usbcir.sys 2013-10-09 05:07:26 25944D2CC49E0A6C581D02A74B7D6645 527064 ----a-w- C:\Windows\System32\drivers\Wdf01000.sys 2013-10-02 18:29:02 DDCE686D76C2B4DB435A3AF5BD0E691D 133056 ----a-w- C:\Windows\System32\drivers\ataport.sys 2013-10-02 14:46:49 05A0C2744CEAC6F1B723EC469B650EF0 47632 ----a-w- C:\Windows\System32\drivers\PSKMAD.sys ====== C:\Windows\Tasks ====== 2013-10-21 19:44:58 275154DD1D3A25C63F95BCFE3D1E2116 3108 ----a-w- C:\Windows\system32\Tasks\Advanced System Protector_startup 2013-10-21 19:42:16 BF659580A7F0084F918B449AF1EB9299 3096 ----a-w- C:\Windows\system32\Tasks\RegClean Pro 2013-10-21 09:58:31 1D63C72B24927B7CC5629434AF27568B 3490 ----a-w- C:\Windows\system32\Tasks\AdobeAAMUpdater-1.0-Zot_geval-Anke 2013-10-21 09:47:48 27B7CF5B01174A689320ADBAB583C408 3246 ----a-w- C:\Windows\system32\Tasks\SomotoUpdateCheckerAutoStart 2013-10-11 18:47:33 419BB1F10DA8563CCC6C1804FE6421D4 3420 ----a-w- C:\Windows\system32\Tasks\BitGuard 2013-10-09 14:16:19 6403227901BA34D636F0DB56E75A17C7 3386 ----a-w- C:\Windows\system32\Tasks\EPUpdater 2013-10-09 14:15:12 BEABB0E90908206BB3C58E90370CFFB7 3062 ----a-w- C:\Windows\system32\Tasks\GoforFilesUpdate ====== C:\Windows\Temp ====== ======= C:\Program Files ===== 2013-10-21 19:43:41 -------- d-----w- C:\Program Files\MyPC Backup 2013-10-21 19:42:53 -------- d-----w- C:\Program Files\Advanced System Protector 2013-10-21 09:47:57 -------- d-----w- C:\Program Files\Free Zip 2013-10-18 18:29:31 -------- d-----w- C:\Program Files\ss helper 2013-10-11 18:33:36 -------- d-----w- C:\Program Files\AppGraffiti 2013-10-09 14:16:01 -------- d-----w- C:\Program Files\diamondata 2013-10-09 14:14:48 -------- d-----w- C:\Program Files\GoforFiles 2013-10-02 18:49:14 -------- d-----w- C:\Program Files\Webteh 2013-10-02 18:30:45 -------- d-----w- C:\Program Files\tixati 2013-10-02 13:04:31 -------- d-----w- C:\Program Files\GridinSoft Trojan Killer 2013-10-02 12:30:58 -------- d-----w- C:\Program Files\Enigma Software Group 2013-10-02 12:30:24 -------- d-----w- C:\Program Files\Common Files\Wise Installation Wizard ======= C: ===== ====== C:\Users\Anke\AppData\Roaming ====== 2013-10-21 19:43:50 -------- d-----w- C:\Users\Anke\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MyPC Backup 2013-10-21 10:51:10 -------- d-----w- C:\Users\Anke\AppData\Roaming\PDAppFlex 2013-10-21 09:47:49 -------- d-----w- C:\Users\Anke\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FilesFrog Update Checker 2013-10-21 09:47:41 -------- d-----w- C:\Users\Anke\AppData\Local\FilesFrog Update Checker 2013-10-11 18:38:57 -------- d-----w- C:\Users\Anke\AppData\Locallow\Delta 2013-10-11 18:33:41 -------- d-----w- C:\Users\Anke\AppData\Locallow\AppGraffiti 2013-10-09 16:29:12 -------- d-----w- C:\Users\Anke\AppData\Local\avgchrome 2013-10-09 14:16:36 -------- d-----w- C:\Users\Anke\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BitGuard 2013-10-09 14:14:48 -------- d-----w- C:\Users\Anke\AppData\Roaming\GoforFiles 2013-10-02 18:49:28 -------- d-----w- C:\Users\Anke\AppData\Roaming\BSplayer Pro 2013-10-02 18:49:28 -------- d-----w- C:\Users\Anke\AppData\Roaming\BSplayer 2013-10-02 18:30:59 -------- d-----w- C:\Users\Anke\AppData\Roaming\tixati 2013-10-02 18:30:49 -------- d-----w- C:\Users\Anke\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Tixati ====== C:\Users\Anke ====== 2013-10-25 18:29:30 69CA82A7482A00D8EE063D2B97FC4338 781383 ----a-w- C:\Users\Anke\Downloads\RSIT.exe 2013-10-21 19:43:19 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced System Protector 2013-10-21 19:42:01 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RegClean Pro 2013-10-21 19:39:28 E423CB96C400DBB600DE5FD91F2937A6 611648 ----a-w- C:\Users\Anke\Downloads\the-wolverine-dut-5160271.exe 2013-10-21 10:50:46 -------- d-----w- C:\ProgramData\regid.1986-12.com.adobe 2013-10-21 09:54:25 E44FC2615F6C32C663F7D13B121B850A 2832256 ----a-w- C:\Users\Anke\Downloads\CreativeCloudSet-Up.exe 2013-10-21 09:48:01 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free Zip 2013-10-21 09:47:12 32409777B3EB2BF508E677FA945C37D1 166632 ----a-w- C:\Users\Anke\Downloads\FreeZipSetup.exe 2013-10-18 18:29:49 -------- d-----w- C:\ProgramData\SummerSoft 2013-10-18 18:29:21 -------- d-----w- C:\ProgramData\DowiNLoad keepeR 2013-10-18 18:28:45 84FEC64CF1DB849FE26968CDF11EB030 329048 ----a-w- C:\Users\Anke\Downloads\Les-Miserables-2012-DVDSCR-EDAW2013-srt.exe 2013-10-18 18:15:06 -------- d---a-w- C:\ProgramData\TEMP 2013-10-18 18:09:52 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Optimizer Pro v3.2 2013-10-18 18:07:52 A7E6BB3D12BD7D2558C4C0AA769E19DF 611648 ----a-w- C:\Users\Anke\Downloads\les-miserables-dut-4863346.exe 2013-10-11 18:33:40 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AppGraffiti 2013-10-02 18:50:24 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BS.Player 2013-10-02 12:22:44 -------- d-----w- C:\ProgramData\eSafe ====== C: exe-files == 2013-10-25 18:30:04 9A2347903D6EDB84C10F288BC0578C1C 388608 ----a-w- C:\Program Files\Trend Micro\Anke.exe 2013-10-25 18:29:30 69CA82A7482A00D8EE063D2B97FC4338 781383 ----a-w- C:\Users\Anke\Downloads\RSIT.exe 2013-10-21 19:42:53 0065E911F966A71A115D9A52FF3DFC99 17136 ----a-w- C:\Windows\System32\sasnative32.exe 2013-10-21 19:42:03 05589174BBE539C14B3F466C33963CA8 18776 ----a-w- C:\Windows\System32\roboot.exe 2013-10-21 19:39:28 E423CB96C400DBB600DE5FD91F2937A6 611648 ----a-w- C:\Users\Anke\Downloads\the-wolverine-dut-5160271.exe 2013-10-21 09:54:25 E44FC2615F6C32C663F7D13B121B850A 2832256 ----a-w- C:\Users\Anke\Downloads\CreativeCloudSet-Up.exe 2013-10-21 09:48:05 AC8F7611F353CA9803FAD5FF81900678 228432 ----a-w- C:\Users\Anke\AppData\Local\Bundled software uninstaller\biclient.exe 2013-10-21 09:48:02 B6A40AC93155EC0A6FFDFCF39607CF78 58785 ----a-w- C:\Program Files\Free Zip\Uninstall.exe 2013-10-21 09:47:48 A29AE906C3A3AA83E934E77C8E198C8E 61990 ----a-w- C:\Users\Anke\AppData\Local\FilesFrog Update Checker\uninstall.exe 2013-10-21 09:47:12 32409777B3EB2BF508E677FA945C37D1 166632 ----a-w- C:\Users\Anke\Downloads\FreeZipSetup.exe === C: other files == 2013-10-21 19:40:58 1FC66FDE338E51E765C221E8665BFF40 21570 ----a-w- C:\Users\Anke\Desktop\downloads\the-wolverine-dut-51602.zip 2013-10-21 11:22:45 FF236A1AE6AB3FA7A4DBC5E116749906 13823802 ----a-w- C:\Program Files\Common Files\Adobe\Adobe\AdobePatchFiles\{F096BB83-0493-4882-9796-633B26900066}.zip 2013-10-21 11:22:14 D1E6A222BE84C86B0F198A97C6994D81 9559022 ----a-w- C:\ProgramData\Adobe\CameraRaw\Adobe\AdobePatchFiles\{5F3BB96C-06FC-4A40-A8F9-D0C0470F659B}.zip 2013-10-21 11:21:05 695393F1AAB03066BA0969D7A8F04A32 7152388 ----a-w- C:\Program Files\Adobe\Adobe\AdobePatchFiles\{E6EAFC2D-08C7-4CAF-978D-721FED26BE14}.zip 2013-10-21 11:19:35 484EF5BD232D2A81E6EA0AC191203F1F 5457 ----a-w- C:\Program Files\Adobe\Adobe\AdobePatchFiles\{54945F15-E8F0-4FE6-B549-EA90BBDA8ED2}.zip 2013-10-21 11:18:05 76CDB2BAD9582D23C1F6F4D868218D6C 22 ----a-w- C:\Program Files\Common Files\Adobe\CEPServiceManager4\Adobe\AdobePatchFiles\{81036849-4B6D-4CB8-8D47-31222F3540E3}.zip 2013-10-21 09:57:10 4AB22EB2C58A697F1E63906536DA4A06 216316 ----a-w- C:\Program Files\Common Files\Adobe\CEPServiceManager4\Adobe\AdobePatchFiles\{D6EDED07-FEE0-4C10-B477-95FF3085DF31}.zip ==== Startup Registry Enabled ====================== [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun" [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun" [HKEY_USERS\S-1-5-21-766547166-3330058944-3535508039-1000\Software\Microsoft\Windows\CurrentVersion\Run] "swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" "AGupdate"="C:\Program Files\AppGraffiti\AGupdate.exe" [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce] "SPReview"="C:\Windows\System32\SPReview\SPReview.exe /sp:1 /errorfwlink:Troubleshoot problems installing Service Pack 1 (SP1) for Windows 7 and Windows Server 2008 R2 /build:7601" [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce] "mctadmin"="C:\Windows\System32\mctadmin.exe" [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce] "mctadmin"="C:\Windows\System32\mctadmin.exe" [HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\RunOnce] "SPReview"="C:\Windows\System32\SPReview\SPReview.exe /sp:1 /errorfwlink:Troubleshoot problems installing Service Pack 1 (SP1) for Windows 7 and Windows Server 2008 R2 /build:7601" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "MSC"="c:\Program Files\Microsoft Security Client\msseces.exe -hide -runkey" "AdobeAAMUpdater-1.0"="C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" "Adobe Creative Cloud"="C:\Program Files\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe --showwindow=false --onOSstartup=true" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" "AGupdate"="C:\Program Files\AppGraffiti\AGupdate.exe" ==== Startup Registry Disabled ====================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\AppsHat] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="AppsHat" "hkey"="HKCU" "command"="C:\\Users\\Anke\\AppData\\Local\\WebPlayer\\AppsHat\\WebPlayer.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\BearShare] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="BearShare" "hkey"="HKCU" "command"="\"C:\\Program Files\\BearShare Applications\\BearShare\\BearShare.exe\" --lightmode" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^McAfee Security Scan Plus.lnk] "item"="McAfee Security Scan Plus" "path"="C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\McAfee Security Scan Plus.lnk" "backup"="C:\\Windows\\pss\\McAfee Security Scan Plus.lnk.CommonStartup" "backupExtension"=".CommonStartup" "command"="C:\\PROGRA~1\\MCAFEE~1\\307523~1.318\\SSSCHE~1.EXE" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run-] "Adobe ARM"="\"C:\\Program Files\\Common Files\\Adobe\\ARM\\1.0\\AdobeARM.exe\"" "SunJavaUpdateSched"="\"C:\\Program Files\\Common Files\\Java\\Java Update\\jusched.exe\"" ==== Startup Folders ====================== 2013-10-21 19:43:50 1055 ----a-w- C:\Users\Anke\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MyPC Backup.lnk ==== Task Scheduler Jobs ====================== C:\Windows\tasks\Adobe Flash Player Updater.job --a------ [undetermined Task] C:\Windows\tasks\GoogleUpdateTaskMachineCore.job --a------ C:\Program Files\Google\Update\GoogleUpdate.exe [28/03/2013 22:31] C:\Windows\tasks\GoogleUpdateTaskMachineUA.job --a------ [undetermined Task] ==== Other Scheduled Tasks ====================== "C:\Windows\system32\tasks\Adobe Flash Player Updater" [C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe] "C:\Windows\system32\tasks\Adobe online update program" [C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe] "C:\Windows\system32\tasks\AdobeAAMUpdater-1.0-Zot_geval-Anke" [C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe] "C:\Windows\system32\tasks\Advanced System Protector_startup" [C:\Program Files\Advanced System Protector\AdvancedSystemProtector.exe] "C:\Windows\system32\tasks\BitGuard" [C:\Windows\system32\sc.exe start BitGuard] "C:\Windows\system32\tasks\CCleanerSkipUAC" ["C:\Program Files\CCleaner\CCleaner.exe"] "C:\Windows\system32\tasks\CreateChoiceProcessTask" [C:\Windows\System32\browserchoice.exe] "C:\Windows\system32\tasks\EPUpdater" [C:\Users\Anke\AppData\Roaming\BABSOL~1\Shared\BabMaint.exe] "C:\Windows\system32\tasks\GoforFilesUpdate" [C:\Program Files\GoforFiles\GFFUpdater.exe] "C:\Windows\system32\tasks\GoogleUpdateTaskMachineCore" [C:\Program Files\Google\Update\GoogleUpdate.exe] "C:\Windows\system32\tasks\GoogleUpdateTaskMachineUA" [C:\Program Files\Google\Update\GoogleUpdate.exe] "C:\Windows\system32\tasks\Java Update Scheduler" [C:\Program Files\Common Files\Java\Java Update\jusched.exe] "C:\Windows\system32\tasks\RegClean Pro" [C:\Program Files\RegClean Pro\RegCleanPro.exe] "C:\Windows\system32\tasks\SomotoUpdateCheckerAutoStart" [C:\Users\Anke\AppData\Local\FilesFrog Update Checker\update_checker.exe] "C:\Windows\system32\tasks\NCH Software\VideoPadDowngrade" [C:\Program Files\NCH Software\VideoPad\videopad.exe] ==== Firefox Extensions Registry ====================== [HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions] "{ACAA314B-EEBA-48e4-AD47-84E31C44796C}"="C:\Program Files\Common Files\DVDVideoSoft\plugins\ff" [] ==== Firefox Extensions ====================== ProfilePath: C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default - LyricsViewer-2 - %ProfilePath%\extensions\75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com - Undetermined - %ProfilePath%\extensions\staged - AppsHat - %ProfilePath%\extensions\{97A78363-B868-4B48-AC91-A783A31215AF} - diamondata - %ProfilePath%\extensions\firefox@diamondata.net.xpi AppDir: C:\Program Files\Mozilla Firefox - Default - %AppDir%\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} ==== Firefox Plugins ====================== ==== Chrome Look ====================== HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions bpegkgagfojjbcpkihigfmkojdmmimdf - C:\Program Files\Freemake\Freemake Video Downloader\BrowserPlugin\Chrome\Freemake.Plugin.Chrome.crx[16/08/2013 07:36] edcikfknpchdehdlmjpbofgkoaonaijg - C:\Users\Anke\AppData\Roaming\BabSolution\CR\Doko.crx[] ehgldbbpchgpcfagfpfjgoomddhccfgh - C:\Program Files\Freemake\Freemake Video Downloader\BrowserPlugin\Chrome\ChromeYoutubePlugin.crx[16/08/2013 07:36] eooncjejnppfjjklapaamhcdmjbilmde - C:\Users\Anke\AppData\Roaming\BabSolution\CR\Delta.crx[] hendmekoldfacfhlojkjcnbjegkahclb - C:\Program Files\diamondata\hendmekoldfacfhlojkjcnbjegkahclb.crx[] ifohbjbgfchkkfhphahclmkpgejiplfo - C:\Users\Anke\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtab.crx[02/10/2013 14:22] HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\Extensions nikpibnbobmbdbheedjfogjlikpgpnhp - C:\Program Files\Common Files\DVDVideoSoft\plugins\DVDVideoSoftBrowserExtension.crx[] Google Docs - Anke - Default\Extensions\aohghmighlieiainnegkcijnfilokake Google Drive - Anke - Default\Extensions\apdfllckaahabafndbhieahigkjlhalf DowiNLoad keepeR - Anke - Default\Extensions\bihdackfdgiogegcokiakmpkbimmommm YouTube - Anke - Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo Google Search - Anke - Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf Doko Toolbar - Anke - Default\Extensions\edcikfknpchdehdlmjpbofgkoaonaijg Delta Toolbar - Anke - Default\Extensions\eooncjejnppfjjklapaamhcdmjbilmde LyricsViewer-2 - Anke - Default\Extensions\gnbbmjlpkhenbefmmdjodjfmcamegmpd diamondata - Anke - Default\Extensions\hendmekoldfacfhlojkjcnbjegkahclb Web Video Solution - Anke - Default\Extensions\lehjhdjciofcglicaidnlfleggadgfpk Helper extension - Anke - Default\Extensions\nchpfiddbhbdnagofhkjlaiaejmkdcla DVDVideoSoft - Anke - Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp Chrome In-App Payments service - Anke - Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda Gmail - Anke - Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia Docs - Anke - Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake Google Drive - Anke - Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf DowiNLoad keepeR - Anke - Profile 1\Extensions\bihdackfdgiogegcokiakmpkbimmommm YouTube - Anke - Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo Freemake Video Downloader - Anke - Profile 1\Extensions\bpegkgagfojjbcpkihigfmkojdmmimdf Google Search - Anke - Profile 1\Extensions\coobgpohoikkiipiblmjeljniedjpjpf Freemake Youtube Download Button - Anke - Profile 1\Extensions\ehgldbbpchgpcfagfpfjgoomddhccfgh LyricsViewer-2 - Anke - Profile 1\Extensions\gnbbmjlpkhenbefmmdjodjfmcamegmpd Select City - Anke - Profile 1\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo Gmail - Anke - Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia undetermined - Anke - Default\Extensions\newtab.crx ==== Deleting CLSID Registry Keys ====================== ==== Deleting CLSID Registry Values ====================== HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\4zffxtbr@VideoDownloadConverter_4z.com deleted successfully HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C} deleted successfully ==== After Reboot ====================== ==== Deleting Files / Folders ====================== "C:\Program Files\MyPC Backup\Resources\keycache\_023c2e8d-b42d-4c64-a874-27ec03d084e7_backupKeyCache.block" not found "C:\Program Files\MyPC Backup\Resources\keycache\_023c2e8d-b42d-4c64-a874-27ec03d084e7_backupKeyCache.tree" not found "C:\Program Files\MyPC Backup\Resources\keycache\_28f505d4-dc5a-4ff1-908d-a9a2506facfe_backupKeyCache.block" not found "C:\Program Files\MyPC Backup\Resources\keycache\_28f505d4-dc5a-4ff1-908d-a9a2506facfe_backupKeyCache.tree" not found "C:\Program Files\MyPC Backup" not found "C:\Program Files\Common Files\DVDVideoSoft" not found "C:\Program Files\diamondata" not found "C:\Program Files\Advanced System Protector" not found "C:\Program Files\diamondata" not found ==== EOF on za 26/10/2013 at 9:37:18,36 ======================
  16. Logfile of random's system information tool 1.09 (written by random/random) Run by Anke at 2013-10-25 20:30:03 Microsoft Windows 7 Professional Service Pack 1 System drive C: has 20 GB (27%) free of 76 GB Total RAM: 1528 MB (39% free) Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 20:30:20, on 25/10/2013 Platform: Windows 7 SP1 (WinNT 6.00.3505) MSIE: Internet Explorer v10.0 (10.00.9200.16720) Boot mode: Normal Running processes: C:\Windows\system32\taskhost.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Windows\system32\taskeng.exe C:\Program Files\Advanced System Protector\AdvancedSystemProtector.exe C:\Program Files\Microsoft Security Client\msseces.exe C:\Program Files\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe C:\Program Files\GoforFiles\GFFUpdater.exe C:\Program Files\MyPC Backup\MyPC Backup.exe C:\Program Files\Optimizer Pro\OptProReminder.exe C:\Program Files\Common Files\Adobe\CEPServiceManager4\CEPServiceManager.exe C:\Users\Anke\AppData\Local\FilesFrog Update Checker\update_checker.exe C:\Program Files\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe C:\Windows\system32\wbem\unsecapp.exe C:\Program Files\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe C:\Program Files\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Windows\system32\SearchFilterHost.exe C:\Users\Anke\Downloads\RSIT.exe C:\Program Files\trend micro\Anke.exe C:\Program Files\Google\Chrome\Application\chrome.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = Preserve R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = Bing R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Search R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN NL: Hotmail, Outlook, Skype, Messenger, het laatste nieuws, entertainment en meer! R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = Search R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll O3 - Toolbar: dokotoolbar Toolbar - {339E1B37-76D3-4A64-A988-E81425DF831C} - C:\Program Files\Doko-Toolbar\dokotoolbar\1.8.26.9\dokotoolbarTlbr.dll O4 - HKLM\..\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey O4 - HKLM\..\Run: [AdobeAAMUpdater-1.0] "C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" O4 - HKLM\..\Run: [Adobe Creative Cloud] "C:\Program Files\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe" --showwindow=false --onOSstartup=true O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" O4 - HKCU\..\Run: [AGupdate] C:\Program Files\AppGraffiti\AGupdate.exe O4 - HKCU\..\Run: [Optimizer Pro] C:\Program Files\Optimizer Pro\OptProLauncher.exe O4 - HKUS\S-1-5-19\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-18\..\RunOnce: [sPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\RunOnce: [sPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'Default user') O4 - Startup: MyPC Backup.lnk = C:\Program Files\MyPC Backup\MyPC Backup.exe O8 - Extra context menu item: Free YouTube Download - C:\Program Files\Common Files\DVDVideoSoft\plugins\freeytvdownloader.htm O8 - Extra context menu item: Free YouTube to DVD Converter - C:\Users\Anke\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetodvdconverter.htm O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Program Files\Common Files\DVDVideoSoft\plugins\freeytmp3downloader.htm O9 - Extra button: Visit AppsHat.com - {AAA38851-3CFF-475F-B5E0-720D3645E4A5} - C:\Program Files\Minibar\Minibar.dll O9 - Extra button: Free YouTube Download - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - C:\Program Files\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns.dll O9 - Extra 'Tools' menuitem: Free YouTube Download - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - C:\Program Files\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns.dll O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe O23 - Service: Computer Backup (MyPC Backup) (BackupStack) - Just Develop It - C:\Program Files\MyPC Backup\BackupStack.exe O23 - Service: Optimizer Pro Crash Monitor (ca82e1a5) - Unknown owner - c:\progra~1\optimi~1\OptProCrash.exe O23 - Service: Freemake Improver - Freemake - C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe O23 - Service: FreemakeVideoCapture - Ellora Assets Corp. - C:\Program Files\Freemake\CaptureLib\CaptureLibService.exe O23 - Service: Google Update-service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe O23 - Service: Google Update-service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: HitmanPro Scheduler (HitmanProScheduler) - SurfRight B.V. - C:\Program Files\HitmanPro\hmpsched.exe O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe O23 - Service: Update diamondata - diamondata - C:\Program Files\diamondata\updatediamondata.exe O23 - Service: Util diamondata - diamondata - C:\Program Files\diamondata\bin\utildiamondata.exe -- End of file - 7256 bytes ======Scheduled tasks folder====== C:\Windows\tasks\Adobe Flash Player Updater.job C:\Windows\tasks\GoogleUpdateTaskMachineCore.job C:\Windows\tasks\GoogleUpdateTaskMachineUA.job C:\Windows\tasks\LyricsViewer-2-chromeinstaller.job C:\Windows\tasks\LyricsViewer-2-codedownloader.job C:\Windows\tasks\LyricsViewer-2-enabler.job C:\Windows\tasks\LyricsViewer-2-firefoxinstaller.job C:\Windows\tasks\LyricsViewer-2-updater.job C:\Windows\tasks\RegClean Pro_DEFAULT.job C:\Windows\tasks\RegClean Pro_UPDATES.job =========Mozilla firefox========= ProfilePath - C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default prefs.js - "browser.startup.homepage" - "http://websearch.wisesearch.info/?pid=357&r=2013/10/18&hid=10612048198043085368&lg=EN&cc=BE&unqvl=39" prefs.js - "keyword.URL" - "http://websearch.wisesearch.info/?pid=357&r=2013/10/18&hid=10612048198043085368&lg=EN&cc=BE&unqvl=39&l=1&q=" "4zffxtbr@VideoDownloadConverter_4z.com"=C:\Program Files\VideoDownloadConverter_4z\bar\1.bin "fmdownloader@gmail.com"=C:\Program Files\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\fmdownloader@gmail.com\ "ytfmdownloader@gmail.com"=C:\Program Files\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\ytfmdownloader@gmail.com\ "{ACAA314B-EEBA-48e4-AD47-84E31C44796C}"=C:\Program Files\Common Files\DVDVideoSoft\plugins\ff\ [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=10.25.2] "Description"=Java™ Deployment Toolkit "Path"=C:\Windows\system32\npDeployJava1.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=10.25.2] "Description"=Oracle® Next Generation Java™ Plug-In "Path"=C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE] "Description"= "Path"=disabled [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0] "Description"=Ag Player Plugin "Path"=c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3] "Description"=Google Update "Path"=C:\Program Files\Google\Update\1.3.21.165\npGoogleUpdate3.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9] "Description"=Google Update "Path"=C:\Program Files\Google\Update\1.3.21.165\npGoogleUpdate3.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@UtilityChest_49.com/Plugin] "Description"=Utility Chest Plugin "Path"= [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@VideoDownloadConverter_4z.com/Plugin] "Description"=VideoDownloadConverter Plugin "Path"=C:\Program Files\VideoDownloadConverter_4z\bar\1.bin\NP4zStub.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader] "Description"=Handles PDFs in-place in Firefox "Path"=C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\adobe.com/AdobeAAMDetect] "Description"= "Path"=C:\Program Files\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll C:\Program Files\Mozilla Firefox\extensions\ {972ce4c6-7e08-4474-a285-3208198ce6fd} C:\Program Files\Mozilla Firefox\components\ binary.manifest browsercomps.dll C:\Program Files\Mozilla Firefox\searchplugins\ bing.xml bolcom-nl.xml google.xml marktplaats-nl.xml qone8.xml wikipedia-nl.xml C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\extensions\ 75c7fb8e-ed08-477a-8353-7cf520516d6e@19506253-d4c6-4684-b849-190d3e13631d.com AppGraffiti@AppGraffiti.com ffxtlbr@babylon.com ffxtlbr@delta.com ffxtlbr@dokotoolbar.com staged {97A78363-B868-4B48-AC91-A783A31215AF} C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\ad6ajl7f.default\searchplugins\ babylon.xml dokotoolbar.xml WebSearch.xml ======Registry dump====== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] {2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2013-10-09 194640] {339E1B37-76D3-4A64-A988-E81425DF831C} - dokotoolbar Toolbar - C:\Program Files\Doko-Toolbar\dokotoolbar\1.8.26.9\dokotoolbarTlbr.dll [2013-10-02 293272] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] "MSC"=c:\Program Files\Microsoft Security Client\msseces.exe [2013-08-12 995176] "AdobeAAMUpdater-1.0"=C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2013-06-13 472984] "Adobe Creative Cloud"=C:\Program Files\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2013-09-03 2237328] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2013-03-28 39408] "AGupdate"=C:\Program Files\AppGraffiti\AGupdate.exe [2013-03-19 894048] "Optimizer Pro"=C:\Program Files\Optimizer Pro\OptProLauncher.exe [2013-09-29 135672] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AppsHat] C:\Users\Anke\AppData\Local\WebPlayer\AppsHat\WebPlayer.exe [2012-10-26 202752] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BearShare] C:\Program Files\BearShare Applications\BearShare\BearShare.exe [2013-06-24 31164992] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^McAfee Security Scan Plus.lnk] C:\PROGRA~1\MCAFEE~1\307523~1.318\SSSCHE~1.EXE [] C:\Users\Anke\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup MyPC Backup.lnk - C:\Program Files\MyPC Backup\MyPC Backup.exe [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad] WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders] "SecurityProviders"=credssp.dll [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37.sys] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HitmanPro37Crusader] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HitmanPro37CrusaderBoot] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\hitmanpro37] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\hitmanpro37.sys] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\HitmanPro37Crusader] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\HitmanPro37CrusaderBoot] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System] "ConsentPromptBehaviorAdmin"=5 "ConsentPromptBehaviorUser"=3 "EnableUIADesktopToggle"=0 "dontdisplaylastusername"=0 "legalnoticecaption"= "legalnoticetext"= "shutdownwithoutlogon"=1 "undockwithoutlogon"=1 [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list] [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32] "vidc.mrle"=msrle32.dll "vidc.msvc"=msvidc32.dll "msacm.imaadpcm"=imaadp32.acm "msacm.msg711"=msg711.acm "msacm.msgsm610"=msgsm32.acm "msacm.msadpcm"=msadp32.acm "midimapper"=midimap.dll "wavemapper"=msacm32.drv "vidc.uyvy"=msyuv.dll "vidc.yuy2"=msyuv.dll "vidc.yvyu"=msyuv.dll "vidc.iyuv"=iyuv_32.dll "vidc.i420"=iyuv_32.dll "vidc.yvu9"=tsbyuv.dll "msacm.l3acm"=C:\Windows\System32\l3codeca.acm "vidc.cvid"=iccvid.dll "wave"=wdmaud.drv "midi"=wdmaud.drv "mixer"=wdmaud.drv ======File associations====== .js - edit - C:\Windows\System32\Notepad.exe %1 .js - open - C:\Windows\System32\WScript.exe "%1" %* ======List of files/folders created in the last 1 month====== 2013-10-25 20:30:03 ----D---- C:\rsit 2013-10-21 21:43:41 ----D---- C:\Program Files\MyPC Backup 2013-10-21 21:43:15 ----D---- C:\ProgramData\Systweak 2013-10-21 21:42:53 ----D---- C:\Program Files\Advanced System Protector 2013-10-21 21:42:53 ----A---- C:\Windows\system32\sasnative32.exe 2013-10-21 21:42:06 ----D---- C:\Users\Anke\AppData\Roaming\Systweak 2013-10-21 21:42:03 ----A---- C:\Windows\system32\roboot.exe 2013-10-21 21:41:26 ----D---- C:\Program Files\RegClean Pro 2013-10-21 12:51:10 ----D---- C:\Users\Anke\AppData\Roaming\PDAppFlex 2013-10-21 12:50:46 ----D---- C:\ProgramData\regid.1986-12.com.adobe 2013-10-21 11:47:57 ----D---- C:\Program Files\Free Zip 2013-10-18 20:29:49 ----D---- C:\ProgramData\SummerSoft 2013-10-18 20:29:42 ----D---- C:\Program Files\WebSearch 2013-10-18 20:29:31 ----D---- C:\Program Files\ss helper 2013-10-18 20:29:21 ----D---- C:\ProgramData\DowiNLoad keepeR 2013-10-18 20:28:55 ----D---- C:\ProgramData\InstallMate 2013-10-18 20:15:07 ----D---- C:\Users\Anke\AppData\Roaming\Optimizer Pro 2013-10-18 20:15:06 ----AD---- C:\ProgramData\TEMP 2013-10-18 20:09:51 ----D---- C:\Program Files\Doko-Toolbar 2013-10-18 20:09:37 ----D---- C:\Users\Anke\AppData\Roaming\Doko-Toolbar 2013-10-18 20:09:18 ----D---- C:\Program Files\Optimizer Pro 2013-10-11 20:34:42 ----D---- C:\Users\Anke\AppData\Roaming\DVDVideoSoftIEHelpers 2013-10-11 20:33:36 ----D---- C:\Program Files\AppGraffiti 2013-10-10 03:07:06 ----A---- C:\Windows\system32\jscript.dll 2013-10-10 03:07:05 ----A---- C:\Windows\system32\jscript9.dll 2013-10-10 03:07:04 ----A---- C:\Windows\system32\jsproxy.dll 2013-10-10 03:07:03 ----A---- C:\Windows\system32\ieui.dll 2013-10-10 03:07:03 ----A---- C:\Windows\system32\iesetup.dll 2013-10-10 03:07:01 ----A---- C:\Windows\system32\RegisterIEPKEYs.exe 2013-10-10 03:07:01 ----A---- C:\Windows\system32\msfeeds.dll 2013-10-10 03:07:01 ----A---- C:\Windows\system32\iernonce.dll 2013-10-10 03:07:01 ----A---- C:\Windows\system32\ie4uinit.exe 2013-10-10 03:07:00 ----A---- C:\Windows\system32\urlmon.dll 2013-10-10 03:07:00 ----A---- C:\Windows\system32\iesysprep.dll 2013-10-10 03:06:59 ----A---- C:\Windows\system32\iertutil.dll 2013-10-10 03:06:57 ----A---- C:\Windows\system32\wininet.dll 2013-10-10 03:06:56 ----A---- C:\Windows\system32\ieframe.dll 2013-10-10 03:06:52 ----A---- C:\Windows\system32\mshtml.dll 2013-10-09 16:16:41 ----D---- C:\Program Files\Delta 2013-10-09 16:16:27 ----D---- C:\Users\Anke\AppData\Roaming\Delta 2013-10-09 16:16:16 ----D---- C:\Users\Anke\AppData\Roaming\BabSolution 2013-10-09 16:16:15 ----D---- C:\ProgramData\DSearchLink 2013-10-09 16:16:01 ----D---- C:\Program Files\diamondata 2013-10-09 16:15:33 ----D---- C:\ProgramData\Babylon 2013-10-09 16:14:48 ----D---- C:\Users\Anke\AppData\Roaming\GoforFiles 2013-10-09 16:14:48 ----D---- C:\Program Files\GoforFiles 2013-10-09 07:07:49 ----A---- C:\Windows\system32\drivers\usbccgp.sys 2013-10-09 07:07:49 ----A---- C:\Windows\system32\comctl32.dll 2013-10-09 07:07:48 ----A---- C:\Windows\system32\drivers\usbuhci.sys 2013-10-09 07:07:48 ----A---- C:\Windows\system32\drivers\usbport.sys 2013-10-09 07:07:48 ----A---- C:\Windows\system32\drivers\usbohci.sys 2013-10-09 07:07:48 ----A---- C:\Windows\system32\drivers\usbhub.sys 2013-10-09 07:07:48 ----A---- C:\Windows\system32\drivers\usbehci.sys 2013-10-09 07:07:48 ----A---- C:\Windows\system32\drivers\usbd.sys 2013-10-09 07:07:47 ----A---- C:\Windows\system32\drivers\hidparse.sys 2013-10-09 07:07:47 ----A---- C:\Windows\system32\drivers\hidclass.sys 2013-10-09 07:07:46 ----A---- C:\Windows\system32\drivers\tcpip.sys 2013-10-09 07:07:45 ----A---- C:\Windows\system32\mswsock.dll 2013-10-09 07:07:45 ----A---- C:\Windows\system32\drivers\afd.sys 2013-10-09 07:07:42 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys 2013-10-09 07:07:41 ----A---- C:\Windows\system32\ntoskrnl.exe 2013-10-09 07:07:41 ----A---- C:\Windows\system32\ntkrnlpa.exe 2013-10-09 07:07:40 ----A---- C:\Windows\system32\tdh.dll 2013-10-09 07:07:40 ----A---- C:\Windows\system32\ntdll.dll 2013-10-09 07:07:39 ----A---- C:\Windows\system32\advapi32.dll 2013-10-09 07:07:38 ----A---- C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll 2013-10-09 07:07:37 ----A---- C:\Windows\system32\lpk.dll 2013-10-09 07:07:37 ----A---- C:\Windows\system32\fontsub.dll 2013-10-09 07:07:37 ----A---- C:\Windows\system32\dciman32.dll 2013-10-09 07:07:37 ----A---- C:\Windows\system32\atmlib.dll 2013-10-09 07:07:37 ----A---- C:\Windows\system32\atmfd.dll 2013-10-09 07:07:35 ----A---- C:\Windows\system32\scavengeui.dll 2013-10-09 07:07:33 ----A---- C:\Windows\system32\win32k.sys 2013-10-09 07:07:29 ----A---- C:\Windows\system32\WebClnt.dll 2013-10-09 07:07:29 ----A---- C:\Windows\system32\drivers\mrxdav.sys 2013-10-09 07:07:29 ----A---- C:\Windows\system32\davclnt.dll 2013-10-09 07:07:27 ----A---- C:\Windows\system32\drivers\usbcir.sys 2013-10-09 07:07:26 ----A---- C:\Windows\system32\drivers\Wdf01000.sys 2013-10-02 20:49:28 ----D---- C:\Users\Anke\AppData\Roaming\BSplayer Pro 2013-10-02 20:49:28 ----D---- C:\Users\Anke\AppData\Roaming\BSplayer 2013-10-02 20:49:14 ----D---- C:\Program Files\Webteh 2013-10-02 20:34:53 ----D---- C:\Program Files\Microsoft Security Client 2013-10-02 20:30:59 ----D---- C:\Users\Anke\AppData\Roaming\tixati 2013-10-02 20:30:45 ----D---- C:\Program Files\tixati 2013-10-02 20:30:20 ----D---- C:\Windows\pss 2013-10-02 20:29:02 ----A---- C:\Windows\system32\drivers\ataport.sys 2013-10-02 20:15:48 ----D---- C:\Program Files\CCleaner 2013-10-02 16:46:49 ----A---- C:\Windows\system32\drivers\PSKMAD.sys 2013-10-02 15:04:31 ----D---- C:\Program Files\GridinSoft Trojan Killer 2013-10-02 14:30:58 ----D---- C:\Program Files\Enigma Software Group 2013-10-02 14:30:25 ----D---- C:\Windows\865537E164904193A4B6669C62711852.TMP 2013-10-02 14:30:24 ----D---- C:\Program Files\Common Files\Wise Installation Wizard 2013-10-02 14:22:53 ----D---- C:\Program Files\LyricsViewer-2 2013-10-02 14:22:44 ----D---- C:\ProgramData\eSafe ======List of files/folders modified in the last 1 month====== 2013-10-25 20:30:20 ----D---- C:\Program Files\Trend Micro 2013-10-25 20:30:16 ----D---- C:\Windows\Prefetch 2013-10-25 20:30:06 ----D---- C:\Windows\Temp 2013-10-25 19:00:20 ----D---- C:\Windows\system32\config 2013-10-25 17:46:09 ----HD---- C:\ProgramData 2013-10-25 15:50:22 ----SHD---- C:\System Volume Information 2013-10-25 15:01:29 ----D---- C:\Windows\system32\Tasks 2013-10-25 07:44:00 ----D---- C:\Windows\system32\drivers 2013-10-24 23:28:24 ----D---- C:\Windows 2013-10-24 19:57:10 ----SHD---- C:\Windows\Installer 2013-10-24 13:21:08 ----D---- C:\Windows\Panther 2013-10-24 13:21:08 ----D---- C:\Windows\inf 2013-10-24 13:21:07 ----D---- C:\Windows\debug 2013-10-21 21:43:41 ----RD---- C:\Program Files 2013-10-21 21:43:28 ----D---- C:\Windows\winsxs 2013-10-21 21:42:53 ----D---- C:\Windows\System32 2013-10-21 21:42:28 ----D---- C:\Windows\Tasks 2013-10-21 13:22:39 ----D---- C:\Program Files\Common Files\Adobe 2013-10-21 13:19:33 ----D---- C:\Program Files\Adobe 2013-10-21 12:51:32 ----D---- C:\Users\Anke\AppData\Roaming\Adobe 2013-10-21 12:23:44 ----D---- C:\ProgramData\Adobe 2013-10-21 12:21:05 ----RSD---- C:\Windows\Fonts 2013-10-21 11:56:46 ----D---- C:\Program Files\Common Files\microsoft shared 2013-10-20 10:02:11 ----D---- C:\ProgramData\HitmanPro 2013-10-20 01:58:16 ----D---- C:\Windows\system32\catroot 2013-10-18 16:56:45 ----A---- C:\Windows\system32\PerfStringBackup.INI 2013-10-18 09:01:44 ----D---- C:\Windows\system32\catroot2 2013-10-11 20:38:39 ----D---- C:\Users\Anke\AppData\Roaming\DVDVideoSoft 2013-10-11 20:34:38 ----D---- C:\Program Files\DVDVideoSoft 2013-10-11 20:34:17 ----RSD---- C:\Windows\assembly 2013-10-11 20:34:13 ----D---- C:\Program Files\Common Files\DVDVideoSoft 2013-10-11 20:32:59 ----D---- C:\Users\Anke\AppData\Roaming\OpenCandy 2013-10-10 18:32:07 ----D---- C:\Windows\system32\NDF 2013-10-10 04:12:10 ----D---- C:\Windows\rescache 2013-10-10 03:43:44 ----D---- C:\Windows\Microsoft.NET 2013-10-10 03:34:23 ----D---- C:\Program Files\Microsoft Silverlight 2013-10-10 03:32:52 ----D---- C:\Windows\system32\en-US 2013-10-10 03:32:52 ----D---- C:\Program Files\Internet Explorer 2013-10-10 03:32:50 ----D---- C:\Windows\system32\DriverStore 2013-10-10 03:12:21 ----D---- C:\Windows\system32\MRT 2013-10-10 03:09:09 ----A---- C:\Windows\system32\MRT.exe 2013-10-08 21:18:11 ----A---- C:\Windows\system32\FlashPlayerApp.exe 2013-10-02 20:47:59 ----D---- C:\Windows\Logs 2013-10-02 20:35:03 ----SD---- C:\ProgramData\Microsoft 2013-10-02 20:26:19 ----D---- C:\Program Files\Common Files 2013-10-02 20:08:41 ----D---- C:\Windows\system32\appmgmt 2013-09-26 07:51:21 ----D---- C:\Windows\system32\wdi ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R0 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2013-06-18 211560] R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 173440] R0 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\drivers\vmbus.sys [2010-11-20 175360] R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-20 388096] R2 NisDrv;Microsoft Network Inspection System; C:\Windows\system32\DRIVERS\NisDrvWFP.sys [2013-06-18 107392] R2 npf;NetGroup Packet Filter Driver; C:\Windows\system32\drivers\npf.sys [2011-02-11 35088] R2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704] R3 aeaudio;aeaudio; C:\Windows\system32\drivers\aeaudio.sys [2003-10-23 100384] R3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-14 229888] R3 smwdm;smwdm; C:\Windows\system32\drivers\smwdm.sys [2004-04-15 612416] S3 aic78xx;aic78xx; C:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720] S3 amdagp;AMD AGP Bus Filter Driver; C:\Windows\system32\drivers\amdagp.sys [2009-07-14 53312] S3 AVFSFilter;AVFSFilter; C:\Windows\system32\DRIVERS\avfsfilter.sys [] S3 esgiguard;esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [] S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12368] S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-20 133632] S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-20 5632] S3 sisagp;SIS AGP Bus Filter; C:\Windows\system32\drivers\sisagp.sys [2009-07-14 52304] S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-20 28032] S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2010-11-20 52224] S3 viaagp;VIA AGP Bus Filter; C:\Windows\system32\drivers\viaagp.sys [2009-07-14 53328] S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736] S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-20 17920] S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 35968] ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [2013-05-11 65640] R2 BackupStack;Computer Backup (MyPC Backup); C:\Program Files\MyPC Backup\BackupStack.exe [2013-09-20 38440] R2 ca82e1a5;Optimizer Pro Crash Monitor; c:\progra~1\optimi~1\OptProCrash.exe [2013-10-18 143488] R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 20992] R2 Freemake Improver;Freemake Improver; C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe [2013-08-26 101888] R2 FreemakeVideoCapture;FreemakeVideoCapture; C:\Program Files\Freemake\CaptureLib\CaptureLibService.exe [2013-08-26 9216] R2 HitmanProScheduler;HitmanPro Scheduler; C:\Program Files\HitmanPro\hmpsched.exe [2013-10-20 106280] R2 MsMpSvc;Microsoft Antimalware Service; c:\Program Files\Microsoft Security Client\MsMpEng.exe [2013-08-12 22208] R2 Update diamondata;Update diamondata; C:\Program Files\diamondata\updatediamondata.exe [2013-10-03 65312] R2 Util diamondata;Util diamondata; C:\Program Files\diamondata\bin\utildiamondata.exe [2013-10-10 65312] R3 NisSrv;@c:\Program Files\Microsoft Security Client\MpAsDesc.dll,-243; c:\Program Files\Microsoft Security Client\NisSrv.exe [2013-08-12 295376] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] S2 gupdate;Google Update-service (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2013-03-28 136176] S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-10-08 257416] S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 20992] S3 gupdatem;Google Update-service (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2013-03-28 136176] S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2013-03-28 194032] S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2013-03-07 115608] S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 20992] S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 20992] S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 20992] S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2013-03-28 1343400] -----------------EOF-----------------
  17. mijn internet werkt ineens zo traag, ik geraak zelf niet optijd op homebank. heb een fix van windows gedaan, bracht ni veel op... - - - Updated - - - ow, en heb verschrikkelijk veel last van pop-ups ook
  18. hij start volledig op, maar de moment dat mijn bureaublad zou moeten verschijnen blijft mijn scherm zwart. ik kan echter wel mijn pijl bewegen. soms als ik de computer start, lukt het allemaal vanzelf, maar zoals nu niet en kan ik alleen verder in veilige modus.
  19. alles is groen
  20. logje 2, vergat change parameters TDSSKiller.2.8.16.0_02.09.2013_17.02.53_log.txt
  21. logje TDSSKiller.2.8.16.0_02.09.2013_14.58.09_log.txt
  22. gmer bestand gmer.log
  23. heb nog is herstart, maar ik geraak nu helemaal niet meer op gewone modus. malware lijkt wel weg te zijn. heb terug overal toegang
  24. ja, het duurt tot een kwartier tegen de computer opstart
×
×
  • Nieuwe aanmaken...

Belangrijke informatie

We hebben cookies geplaatst op je toestel om deze website voor jou beter te kunnen maken. Je kunt de cookie instellingen aanpassen, anders gaan we er van uit dat het goed is om verder te gaan.