Ga naar inhoud

Asus N73 S waarvan Windows Verkenner steeds vastloopt


Swoossie

Aanbevolen berichten

Hallo mensen ik heb sinds eind 2011 een Asus N73 S. nu doet het probleem met windows verkenner zich al enige tijd voor. Als ik mijn documenten of foto's of wat dan ook open en ik wil verder klikken dan krijg ik steeds te zien Windows Verkenner werkt niet meer... hoe komt dit en hoe kan ik dit oplossen ?? Ik heb trouwens Zero verstand van computers :). gr Koos

Link naar reactie
Delen op andere sites

  • Reacties 37
  • Aangemaakt
  • Laatste reactie

Beste reacties in dit topic

Beste reacties in dit topic

Dag Koos,

welkom op PCH!

We zullen eerst eens nagaan of malware of virussen de oorzaak zijn van je probleem.

1. Download HijackThis. (klik er op)

Klik op HijackThis.msi en de download start automatisch na 5 seconden.

Bestand HijackThis.msi opslaan. Daarna kiezen voor "uitvoeren".

Hijackthis wordt nu op je PC geïnstalleerd, een snelkoppeling wordt op je bureaublad geplaatst.

Als je geen netwerkverbinding meer hebt, kan je de download doen met een andere pc en het bestand met een usb stick overbrengen

Als je enkel nog in veilige modus kan werken, moet je de executable (HijackThis.exe) downloaden.

Sla deze op in een nieuwe map op de C schijf (bvb C:\\hijackthis) en start hijackthis dan vanaf deze map.

De logjes kan je dan ook in die map terugvinden.


2. Klik op de snelkoppeling om HijackThis te starten. (lees eerst de rode tekst hieronder!)

Klik ofwel op "Do a systemscan and save a logfile", ofwel eerst op "Scan" en dan op "Savelog".

Er opent een kladblokvenster, hou gelijktijdig de CTRL en A-toets ingedrukt, nu is alles geselecteerd. Hou gelijktijdig de CTRL en C-toets ingedrukt, nu is alles gekopieerd. Plak nu het HJT logje in je bericht door CTRL en V-toets.

Krijg je een melding ""For some reason your system denied writing to the Host file ....", klik dan gewoon door op de OK-toets.

Let op : Windows Vista & 7 gebruikers dienen HijackThis als “administrator” uit te voeren via rechtermuisknop “als administrator uitvoeren". Indien dit via de snelkoppeling niet lukt voer je HijackThis als administrator uit in de volgende map : C:\\Program Files\\Trend Micro\\HiJackThis of C:\\Program Files (x86)\\Trend Micro\\HiJackThis. (Bekijk hier de afbeelding ---> Klik hier)


3. Na het plaatsen van je logje wordt dit door een expert nagekeken en hij begeleidt jou verder door het ganse proces.

Tip!

Wil je in woord en beeld weten hoe je een logje met HijackThis maakt en plaatst op het forum, klik dan HIER.

Link naar reactie
Delen op andere sites

hier dan de uitkomst ( abacadabra voor mij _0_ )

Logfile of Trend Micro HijackThis v2.0.4

Scan saved at 18:01:03, on 6-3-2013

Platform: Windows 7 SP1 (WinNT 6.00.3505)

MSIE: Internet Explorer v9.00 (9.00.8112.16464)

Boot mode: Normal

Running processes:

C:\Program Files (x86)\ASUS\ASUS Live Update\ALU.exe

C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe

C:\Program Files (x86)\Skype\Phone\Skype.exe

C:\Users\Koos\AppData\Roaming\Dropbox\bin\Dropbox.exe

C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe

C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe

C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe

C:\ExpressGateUtil\VAWinAgent.exe

C:\Program Files (x86)\CyberLink\MediaEspresso\DeviceDetector\DeviceDetector.exe

C:\Program Files (x86)\Internet Explorer\iexplore.exe

C:\Program Files (x86)\Internet Explorer\iexplore.exe

C:\Program Files (x86)\Internet Explorer\iexplore.exe

C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe

C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe

C:\Windows\SysWOW64\Macromed\Flash\FlashUtil11c_ActiveX.exe

C:\Program Files (x86)\Internet Explorer\iexplore.exe

C:\Program Files (x86)\Norton 360\Engine\20.3.0.36\ccSvcHst.exe

C:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = Hotmail, Messenger, het laatste nieuws en entertainment | MSN.NL

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = Bing

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Google

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = Hotmail, Messenger, het laatste nieuws en entertainment | MSN.NL

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = Hotmail, Messenger, het laatste nieuws en entertainment | MSN.NL

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

R3 - URLSearchHook: (no name) - {87775fdb-6972-41f9-ae51-8326e38cb206} - (no file)

F2 - REG:system.ini: UserInit=userinit.exe

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton 360\Engine\20.3.0.36\coIEPlg.dll

O2 - BHO: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton 360\Engine\20.3.0.36\IPS\IPSBHO.DLL

O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL

O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll

O2 - BHO: IESpeakDoc - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Atheros\Bluetooth Suite\IEPlugIn.dll

O2 - BHO: Aanmeldhulp voor Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll

O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL

O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files (x86)\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll (file missing)

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll

O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine\20.3.0.36\coIEPlg.dll

O4 - HKLM\..\Run: [ASUSPRP] "C:\Program Files (x86)\ASUS\APRP\APRP.EXE"

O4 - HKLM\..\Run: [ASUSWebStorage] C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.84.161\AsusWSPanel.exe /S

O4 - HKLM\..\Run: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe

O4 - HKLM\..\Run: [HControlUser] C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe

O4 - HKLM\..\Run: [FLxHCIm] "C:\Program Files\Fresco Logic Inc\Fresco Logic USB3.0 Host Controller\host\FLxHCIm.exe"

O4 - HKLM\..\Run: [Wireless Console 3] C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe

O4 - HKLM\..\Run: [VAWinAgent] C:\ExpressGateUtil\VAWinAgent.exe

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"

O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

O4 - HKCU\..\Run: [sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun

O4 - HKCU\..\Run: [skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun

O4 - HKUS\S-1-5-19\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-20\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')

O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')

O4 - HKUS\S-1-5-21-3766946001-305601837-3760299784-1000\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'UpdatusUser')

O4 - HKUS\S-1-5-21-3766946001-305601837-3760299784-1000\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'UpdatusUser')

O4 - Startup: Dropbox.lnk = Koos\AppData\Roaming\Dropbox\bin\Dropbox.exe

O8 - Extra context menu item: &Verzenden naar OneNote - res://C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105

O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000

O9 - Extra button: @C:\Program Files (x86)\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll

O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll

O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll

O9 - Extra button: Verzenden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll

O9 - Extra 'Tools' menuitem: &Verzenden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll

O9 - Extra button: (no name) - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files (x86)\Atheros\Bluetooth Suite\IEPlugIn.dll

O9 - Extra 'Tools' menuitem: Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files (x86)\Atheros\Bluetooth Suite\IEPlugIn.dll

O9 - Extra button: &Gekoppelde notities van OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll

O9 - Extra 'Tools' menuitem: &Gekoppelde notities van OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL

O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll

O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll

O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics

O16 - DPF: {AB6633A8-60A9-4F5D-B66C-ABE268CC3227} (SolidWorks Installation Manager Contol) - http://www.solidworks.com/sw/support/subscription/sldimdownload.cab

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL

O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll

O20 - AppInit_DLLs: C:\Windows\SysWOW64\nvinit.dll

O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe

O23 - Service: AFBAgent - Unknown owner - C:\Windows\system32\FBAgent.exe (file missing)

O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)

O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

O23 - Service: ASLDR Service (ASLDRService) - ASUS - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe

O23 - Service: Atheros Bt&Wlan Coex Agent - Atheros - C:\Program Files (x86)\Atheros\Ath_CoexAgent.exe

O23 - Service: AtherosSvc - Atheros Commnucations - C:\Program Files (x86)\Atheros\Bluetooth Suite\adminservice.exe

O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - ASUS - C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe

O23 - Service: Bonjour-service (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe

O23 - Service: SW Distributed TS Coordinator Service (CoordinatorServiceHost) - Dassault Systèmes SolidWorks Corp. - C:\Program Files\SolidWorks Corp\SolidWorks\swScheduler\DTSCoordinatorService.exe

O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)

O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)

O23 - Service: FLEXnet Licensing Service - Flexera Software, Inc. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe

O23 - Service: FLEXnet Licensing Service 64 - Flexera Software, Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe

O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

O23 - Service: Google Update-service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: iPod-service (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe

O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)

O23 - Service: Norton 360 (N360) - Symantec Corporation - C:\Program Files (x86)\Norton 360\Engine\20.3.0.36\ccSvcHst.exe

O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

O23 - Service: NVIDIA Driver Helper Service (NVSvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)

O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe

O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe

O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)

O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe

O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)

O23 - Service: SolidWorks Licensing Service - SolidWorks - C:\Program Files (x86)\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe

O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)

O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)

O23 - Service: Intel® Turbo Boost Technology Monitor (TurboBoost) - Intel® Corporation - C:\Program Files\Intel\TurboBoost\TurboBoost.exe

O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)

O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)

O23 - Service: VideAceWindowsService - Unknown owner - C:\ExpressGateUtil\VAWinService.exe

O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)

O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)

O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)

O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)

O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--

End of file - 14625 bytes

- - - Updated - - -

owjah moet ik dat programma er gewoon op laten staan ? en ik lees ff snel door die tekst hierboven en zie ik wel vaak staan file missing ?? :D

Link naar reactie
Delen op andere sites

Download zoek.exe naar het bureaublad.

  • Schakel je antivirus- en antispywareprogramma's uit, mogelijk kunnen ze conflicteren met zoek.exe
    (hier of hier) kan je lezen hoe je dat doet.
  • Dubbelklik op Zoek.exe om de tool te starten.
  • Windows Vista, 7 en 8 gebruikers dienen de tool als "administrator" uit te voeren door middel van de rechtermuisknop en kiezen voor Als Administrator uitvoeren.
  • Kopieer nu onderstaande code en plak die in het grote invulvenster:
  • Note: Dit script is speciaal bedoeld voor deze PC, gebruik dit dan ook niet op andere PC's met een gelijkwaardig probleem.
    startupall;
    filesrcm;
    


  • Klik op de knop "Options" en vink nu de onderstaande opties aan.


    • Running processes
    • Firefox Look
    • Chrome Look
    • Firefox Defaults
    • Reset Chrome
    • Reset IE proxy
    • Shortcut Fix
    • IE Defaults
    • Auto Clean

    [*] Klik daarna op de knop "Run script".

    [*] Wacht nu geduldig af tot er een logje opent (dit kan na een herstart zijn als deze benodigd is).

    [*] Mocht na de herstart geen logje verschijnen, start zoek.exe dan opnieuw, de log verschijnt dan alsnog.

    [*] Post nu de inhoud van het geopende logje in het volgende bericht.

Link naar reactie
Delen op andere sites

na enig stuntelwerk is het me dan toch gelukt bij deze de gegevens,

Zoek.exe Version 4.0.0.2 Updated 06-March-2013

Tool run by Koos on wo 06-03-2013 at 20:04:23,28.

Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x64

Running in: Normal Mode Internet Access Detected

==== Running Processes ======================

C:\Windows\system32\csrss.exe

C:\Windows\system32\wininit.exe

C:\Windows\system32\services.exe

C:\Windows\system32\lsass.exe

C:\Windows\system32\lsm.exe

C:\Windows\system32\svchost.exe -k DcomLaunch

C:\Windows\system32\nvvsvc.exe

C:\Windows\system32\svchost.exe -k RPCSS

C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted

C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted

C:\Windows\system32\svchost.exe -k LocalService

C:\Windows\system32\svchost.exe -k netsvcs

C:\Windows\system32\svchost.exe -k NetworkService

C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe

C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe

C:\Windows\System32\spoolsv.exe

C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork

C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe

C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

C:\Program Files (x86)\Atheros\Ath_CoexAgent.exe

C:\Program Files (x86)\Atheros\Bluetooth Suite\adminservice.exe

C:\Program Files\Bonjour\mDNSResponder.exe

C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation

C:\Windows\system32\svchost.exe -k imgsvc

C:\Program Files\Intel\TurboBoost\TurboBoost.exe

C:\ExpressGateUtil\VAWinService.exe

C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE

C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe

C:\Windows\system32\svchost.exe -k bthsvcs

C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted

C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe

C:\Windows\system32\SearchIndexer.exe

C:\Windows\system32\svchost.exe -k SDRSVC

C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe

C:\Program Files\Windows Media Player\wmpnetwk.exe

C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE

C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe

C:\Windows\System32\svchost.exe -k LocalServicePeerNet

C:\Windows\system32\DllHost.exe

C:\Windows\system32\csrss.exe

C:\Windows\system32\winlogon.exe

C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe

C:\Windows\system32\nvvsvc.exe

C:\Windows\system32\taskhost.exe

C:\Windows\system32\Dwm.exe

C:\Windows\system32\taskeng.exe

C:\Program Files (x86)\ASUS\ASUS Live Update\ALU.exe

C:\Program Files\P4G\BatteryLife.exe

C:\Windows\system32\taskeng.exe

C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe

C:\Program Files (x86)\ASUS\Splendid\ACMON.exe

C:\Windows\System32\igfxtray.exe

C:\Windows\System32\igfxpers.exe

C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe

C:\Program Files\Elantech\ETDCtrl.exe

C:\Program Files\Windows Sidebar\sidebar.exe

C:\Program Files (x86)\Skype\Phone\Skype.exe

C:\Users\Koos\AppData\Roaming\Dropbox\bin\Dropbox.exe

C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe

C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe

C:\Program Files\Elantech\ETDCtrlHelper.exe

C:\Program Files\Fresco Logic Inc\Fresco Logic USB3.0 Host Controller\host\FLxHCIm.exe

C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe

C:\ExpressGateUtil\VAWinAgent.exe

C:\Windows\SysWOW64\ACEngSvr.exe

C:\Program Files (x86)\CyberLink\MediaEspresso\DeviceDetector\DeviceDetector.exe

C:\Program Files (x86)\Internet Explorer\iexplore.exe

C:\Program Files (x86)\Internet Explorer\iexplore.exe

C:\Program Files (x86)\Internet Explorer\iexplore.exe

C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe

C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe

C:\Windows\SysWOW64\Macromed\Flash\FlashUtil11c_ActiveX.exe

C:\Program Files (x86)\ASUS\SmartLogon\smartlogon.exe

C:\Program Files (x86)\Internet Explorer\iexplore.exe

C:\Windows\explorer.exe

C:\Program Files (x86)\Norton 360\Engine\20.3.0.36\ccSvcHst.exe

C:\Program Files (x86)\Norton 360\Engine\20.3.0.36\ccSvcHst.exe

C:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe

C:\Windows\system32\taskhost.exe

C:\Windows\system32\wbem\wmiprvse.exe

C:\Windows\system32\taskeng.exe

C:\Users\Koos\AppData\Local\Temp\Temp2_zoek.zip\zoek.exe

C:\Windows\system32\conhost.exe

C:\Windows\system32\wbem\wmiprvse.exe

==== Deleting CLSID Registry Keys ======================

HKEY_USERS\S-1-5-21-3766946001-305601837-3760299784-1002\Software\Microsoft\Internet Explorer\SearchScopes\{F716FCC9-A264-4BB5-8F8C-FC109CC07267} deleted successfully

==== Deleting CLSID Registry Values ======================

==== FireFox Fix ======================

Deleted from C:\Users\Koos\AppData\Roaming\Mozilla\Firefox\Profiles\li59hz2c.default\prefs.js:

user_pref("browser.startup.homepage", "Google");

Added to C:\Users\Koos\AppData\Roaming\Mozilla\Firefox\Profiles\li59hz2c.default\prefs.js:

user_pref("browser.startup.homepage", "Google");

user_pref("browser.search.defaulturl", "Google=");

user_pref("browser.newtab.url", "Google");

user_pref("browser.search.defaultengine", "Google");

user_pref("browser.search.defaultenginename", "Google");

user_pref("browser.search.selectedEngine", "Google");

user_pref("browser.search.order.1", "Google");

user_pref("keyword.URL", "Google=");

user_pref("browser.search.suggest.enabled", true);

user_pref("browser.search.useDBForOrder", true);

ProfilePath: C:\Users\Koos\AppData\Roaming\Mozilla\Firefox\Profiles\li59hz2c.default

---- Lines CT2865317 removed from prefs.js ----

user_pref("CT2865317.1000234.TWC_location", "Groningen, Netherlands");

user_pref("CT2865317.1000234.TWC_locId", "NLXX0009");

user_pref("CT2865317.1000234.TWC_region", "OT");

user_pref("CT2865317.1000234.TWC_temp_dis", "c");

user_pref("CT2865317.1000234.TWC_TMP_city", "GRONINGEN");

user_pref("CT2865317.1000234.TWC_TMP_country", "NL");

user_pref("CT2865317.1000234.TWC_wind_dis", "kmh");

user_pref("CT2865317.1000234.weatherData", "{\"icon\":\"26.png\",\"temperature\":\"4°C\",\"temperatureClear\":\"4°C\",\"highTemperature\":\"4°C\",\"lowTemperature\":\"2°C\",\"feelsLike\":\"0°C\",\"condition\":\"Cloudy\",\"tUnit\":\"c\",\"cityName\":\"Groningen, Netherlands\",\"lastUpdated\":\"3/2/13 2:45 PM Local Time\",\"humidity\":\"77%\",\"visibility\":\"6.0 mi\",\"pressure\":\"30.24 in\",\"pressureDescription\":\"falling\",\"windFrom\":\"WNW\",\"windSpeed\":\"19 Km/h\",\"hasCurrentCondition\":true,\"night\":true,\"severaAlertsCount\":0,\"loaded\":true,\"day1\":{\"icon\":\"26.png\",\"highTemperature\":\"6°C\",\"lowTemperature\":\"0°C\",\"condition\":\"Cloudy\",\"precipitation\":\"20%\",\"day\":\"1\",\"sunr\":\"7:17 AM\",\"suns\":\"6:16 PM\",\"humidity\":\"75%\",\"windFrom\":\"NNW\",\"windSpeed\":\"11 Km/h\",\"dayName\":\"Sunday\",\"date\":\"Mar 3, 2013\",\"hourly\":[{\"key\":\"06280000\",\"class\":\"hourlyforecast\",\"dateTime\":\"6 AM\",\"temp\":37,\"feelsLike\":32,\"humid\":89,\"wSpeed\":7,\"wDir\":320,\"pop\":20,\"uv\":0,\"dew\":34,\"icon\":26,\"wDirText\":\"NW\",\"wDesc\":\"Cloudy\",\"precip_type\":\"precip\"},{\"key\":\"06280000\",\"class\":\"hourlyforecast\",\"dateTime\":\"12 PM\",\"temp\":42,\"feelsLike\":38,\"humid\":73,\"wSpeed\":7,\"wDir\":333,\"pop\":0,\"uv\":1,\"dew\":34,\"icon\":26,\"wDirText\":\"NNW\",\"wDesc\":\"Cloudy\",\"precip_type\":\"rain\"},{\"key\":\"06280000\",\"class\":\"hourlyforecast\",\"dateTime\":\"6 PM\",\"temp\":39,\"feelsLike\":36,\"humid\":76,\"wSpeed\":4,\"wDir\":350,\"pop\":0,\"uv\":0,\"dew\":32,\"icon\":26,\"wDirText\":\"N\",\"wDesc\":\"Cloudy\",\"precip_type\":\"precip\"},{\"key\":\"06280000\",\"class\":\"hourlyforecast\",\"dateTime\":\"12 AM\",\"temp\":36,\"feelsLike\":36,\"humid\":85,\"wSpeed\":1,\"wDir\":143,\"pop\":0,\"uv\":0,\"dew\":32,\"icon\":27,\"wDirText\":\"SE\",\"wDesc\":\"Mostly Cloudy\",\"precip_type\":\"precip\"}]},\"day2\":{\"icon\":\"30.png\",\"highTemperature\":\"8°C\",\"lowTemperature\":\"1°C\",\"condition\":\"Partly Cloudy\",\"precipitation\":\"0%\",\"day\":\"2\",\"sunr\":\"7:14 AM\",\"suns\":\"6:17 PM\",\"humidity\":\"72%\",\"windFrom\":\"SE\",\"windSpeed\":\"13 Km/h\",\"dayName\":\"Monday\",\"date\":\"Mar 4, 2013\",\"hourly\":[{\"key\":\"06280000\",\"class\":\"hourlyforecast\",\"dateTime\":\"6 AM\",\"temp\":33,\"feelsLike\":30,\"humid\":89,\"wSpeed\":3,\"wDir\":129,\"pop\":0,\"uv\":0,\"dew\":30,\"icon\":29,\"wDirText\":\"SE\",\"wDesc\":\"Partly Cloudy\",\"precip_type\":\"precip\"},{\"key\":\"06280000\",\"class\":\"hourlyforecast\",\"dateTime\":\"8 AM\",\"temp\":34,\"feelsLike\":29,\"humid\":82,\"wSpeed\":5,\"wDir\":132,\"pop\":0,\"uv\":0,\"dew\":29,\"icon\":30,\"wDirText\":\"SE\",\"wDesc\":\"Partly Cloudy\",\"precip_type\":\"precip\"},{\"key\":\"06280000\",\"class\":\"hourlyforecast\",\"dateTime\":\"10 AM\",\"temp\":37,\"feelsLike\":32,\"humid\":73,\"wSpeed\":6,\"wDir\":138,\"pop\":0,\"uv\":1,\"dew\":29,\"icon\":30,\"wDirText\":\"SE\",\"wDesc\":\"Partly Cloudy\",\"precip_type\":\"precip\"},{\"key\":\"06280000\",\"class\":\"hourlyforecast\",\"dateTime\":\"12 PM\",\"temp\":41,\"feelsLike\":36,\"humid\":70,\"wSpeed\":7,\"wDir\":136,\"pop\":0,\"uv\":1,\"dew\":32,\"icon\":32,\"wDirText\":\"SE\",\"wDesc\":\"Sunny\",\"precip_type\":\"rain\"}]},\"day3\":{\"icon\":\"32.png\",\"highTemperature\":\"12°C\",\"lowTemperature\":\"1°C\",\"condition\":\"Sunny\",\"precipitation\":\"0%\",\"day\":\"3\",\"sunr\":\"7:12 AM\",\"suns\":\"6:19 PM\",\"humidity\":\"71%\",\"windFrom\":\"S\",\"windSpeed\":\"13 Km/h\",\"dayName\":\"Tuesday\",\"date\":\"Mar 5, 2013\"},\"extendedOutlookLink\":\"Groningen Weather, Current Conditions and Temperature - weather.com}");

user_pref("CT2865317.addressBarTakeOverEnabledInHidden", "true");

user_pref("CT2865317.autoDisableScopes", 0);

user_pref("CT2865317.cbcountry_001.enc", "Tkw=");

user_pref("CT2865317.cbfirsttime.enc", "VGh1IE5vdiAwMSAyMDEyIDE0OjEzOjIwIEdNVCswMTAw");

user_pref("CT2865317.CBOpenMAMSettings.enc", "MA==");

user_pref("CT2865317.defaultSearch", "FALSE");

user_pref("CT2865317.embeddedsData", "[{\"appId\":\"129363015615338104\",\"apiPermissions\":{\"crossDomainAjax\":true,\"getMainFrameTitle\":true,\"getMainFrameUrl\":true,\"getSearchTerm\":true,\"instantAlert\":true,\"jsInjection\":true,\"sslGranted\":true},\"onBeforeLoadData\":\"{\\\"view\\\":{\\\"html\\\":\\\"<table id=\\\\\\\"main\\\\\\\" class=\\\\\\\"mainwrapper\\\\\\\" cellpadding=\\\\\\\"0\\\\\\\" cellspacing=\\\\\\\"0\\\\\\\">\\\\n <tbody><tr>\\\\n <!-- don't remove the width=\\\\\\\"100%\\\\\\\" bug in chrome the width become in px-->\\\\n <td id=\\\\\\\"textboxWrapper\\\\\\\" style=\\\\\\\"width: 100%; background: none repeat scroll 0% 0% rgb(255, 255, 255);\\\\\\\" width=\\\\\\\"100%\\\\\\\">\\\\n <!-- take focuse in IE -->\\\\n <!--[if ie]>\\\\n <form onsubmit =\\\\\\\"return false;\\\\\\\" action=\\\\\\\"#\\\\\\\">\\\\n <![endif]-->\\\\n <input style=\\\\\\\"color: rgb(0, 0, 0); background: none repeat scroll 0% 0% rgb(255, 255, 255); min-width: 137px; max-width: 462px; width: 100%;\\\\\\\" id=\\\\\\\"textbox\\\\\\\" type=\\\\\\\"text\\\\\\\">\\\\n <!--[if ie]>\\\\n </form>\\\\n <![endif]-->\\\\n </td>\\\\n <td style=\\\\\\\"background: none repeat scroll 0% 0% rgb(255, 255, 255);\\\\\\\" id=\\\\\\\"infoPopupButtonWrapper\\\\\\\">\\\\n <div id=\\\\\\\"infoPopupButton\\\\\\\" class=\\\\\\\"dropdownButton no-select\\\\\\\"></div>\\\\n </td>\\\\n <td id=\\\\\\\"engineWrapperContainer\\\\\\\">\\\\n <table cellpadding=\\\\\\\"0\\\\\\\" cellspacing=\\\\\\\"0\\\\\\\">\\\\n <tbody><tr>\\\\n <td id=\\\\\\\"imageTextWrapperContainer\\\\\\\">\\\\n <table cellpadding=\\\\\\\"0\\\\\\\" cellspacing=\\\\\\\"0\\\\\\\">\\\\n <tbody><tr>\\\\n <td style=\\\\\\\"display: table-cell;\\\\\\\" id=\\\\\\\"engineWrapper\\\\\\\"><img style=\\\\\\\"display: block\\\\\\\" id=\\\\\\\"engineImage\\\\\\\" alt=\\\\\\\"\\\\\\\" src=\\\\\\\"http://storage.conduit.com/17/286/CT2865317/Images/SearchActivationButton-go_but01.gif-General-634220918830656250.gif\\\\\\\" onerror=\\\\\\\"javascript: this.src='http://storage.conduit.com/images/searchengines/go_btn_new.gif'\\\\\\\"></td>\\\\n <td style=\\\\\\\"display: table-cell;\\\\\\\" id=\\\\\\\"engineTextWrapper\\\\\\\">\\\\n <div title=\\\\\\\"Zoeken\\\\\\\" style=\\\\\\\"color: rgb(0, 0, 0); font-family: Tahoma; font-weight: normal; font-style: normal; font-size: 11px;\\\\\\\" id=\\\\\\\"engineText\\\\\\\">Zoeken</div>\\\\n </td>\\\\n </tr>\\\\n </tbody></table>\\\\n </td>\\\\n <td id=\\\\\\\"enginesPopupButtonWrapper\\\\\\\">\\\\n <div id=\\\\\\\"enginesPopupButton\\\\\\\" class=\\\\\\\"dropdownButton no-select\\\\\\\"></div>\\\\n </td>\\\\n </tr>\\\\n </tbody></table>\\\\n </td>\\\\n </tr>\\\\n</tbody></table>\\\"},\\\"locale\\\":{\\\"alignMode\\\":\\\"LTR\\\",\\\"locale\\\":\\\"nl\\\",\\\"languageAlignMode\\\":\\\"LTR\\\"}}\"},{\"appId\":\"129416029873125873\",\"apiPermissions\":{\"crossDomainAjax\":false,\"getMainFrameTitle\":true,\"getMainFrameUrl\":true,\"getSearchTerm\":true,\"instantAlert\":true,\"jsInjection\":false,\"sslGranted\":false},\"originalHeight\":26},{\"appId\":\"130055909048847312\",\"apiPermissions\":{\"crossDomainAjax\":true,\"getMainFrameTitle\":true,\"getMainFrameUrl\":true,\"getSearchTerm\":false,\"instantAlert\":true,\"jsInjection\":true,\"sslGranted\":false},\"originalHeight\":26}]");

user_pref("CT2865317.ENABALE_HISTORY", "{\"dataType\":\"string\",\"data\":\"true\"}");

user_pref("CT2865317.ENABLE_RETURN_WEB_SEARCH_ON_THE_PAGE", "{\"dataType\":\"string\",\"data\":\"true\"}");

user_pref("CT2865317.enableAlerts", "always");

user_pref("CT2865317.enableFix404ByUser", "FALSE");

user_pref("CT2865317.enableSearchFromAddressBar", "FALSE");

user_pref("CT2865317.FirstTime", "true");

user_pref("CT2865317.firstTimeDialogOpened", "true");

user_pref("CT2865317.FirstTimeFF3", "true");

user_pref("CT2865317.fixPageNotFoundError", "true");

user_pref("CT2865317.fixPageNotFoundErrorByUser", "true");

user_pref("CT2865317.fixPageNotFoundErrorInHidden", "true");

user_pref("CT2865317.fixUrls", true);

user_pref("CT2865317.installId", "fft8218.tmp.exe");

user_pref("CT2865317.installType", "XPE");

user_pref("CT2865317.isCheckedStartAsHidden", true);

user_pref("CT2865317.isEnableAllDialogs", "{\"dataType\":\"string\",\"data\":\"true\"}");

user_pref("CT2865317.isFirstTimeToolbarLoading", "false");

user_pref("CT2865317.isNewTabEnabled", false);

user_pref("CT2865317.isPerformedSmartBarTransition", "true");

user_pref("CT2865317.isToolbarShrinked", "{\"dataType\":\"string\",\"data\":\"false\"}");

user_pref("CT2865317.isWelcomPage", "{\"dataType\":\"boolean\",\"data\":\"true\"}");

user_pref("CT2865317.lastVersion", "10.14.65.43");

user_pref("CT2865317.LoginRevertSettingsEnabled", true);

user_pref("CT2865317.mam_gk_appsData.enc", "eyJhcHBzIjpbeyJpZCI6IlByaWNlR29uZyIsInVybCI6Imh0dHA6Ly9wcmljZWdvbmcuY29uZHVpdGFwcHMuY29tL01BTS92MS9odG1sX2NvbXAuaHRtbCIsIm9wdGlvbnNEaWFsb2ciOnsiZGlzcGxheU5hbWUiOiJQcmljZUdvbmciLCJhcHBEZXNjIjoieW91ciBvbmxpbmUgc2hvcHBpbmcgYXNzaXN0YW50LiBVc2UgUHJpY2VHb25nIHRvIGZpbmQgdGhlIGJlc3Qgb25saW5lIGRlYWxzIGFuZCBnZXQgb25saW5lIGNvdXBvbnMganVzdCB3aGVuIHlvdSBuZWVkIGl0LiIsInByaXZhY3lQb2xpY3lVcmwiOiJodHRwOi8vd3d3LnByaWNlZ29uZy5jb20vUHJpdmFjeVBvbGljeS5hc3B4IiwidGVybXNPZlVzZVVybCI6Imh0dHA6Ly93d3cucHJpY2Vnb25nLmNvbS9UZXJtc29mVXNlLmFzcHgifSwiY29tcGF0aWJpbGl0eSI6W3sicGxhdGZvcm0iOiJJRV9UQiIsIm1heFZlcnNpb24iOiIwLjAuMC4wIn1dLCJIaWRkZW5BcHAiOmZhbHNlfSx7ImlkIjoiQ291cG9uQnVkZHkiLCJ1cmwiOiJodHRwOi8vd3d3LnNvY2lhbGdyb3d0aHRlY2hub2xvZ2llcy5jb20vY291cG9uYnVkZHlfdjAwMy9pbmRleC5waHA/Y3RpZD1FQlRPT0xCQVJJRCIsIm9wdGlvbnNEaWFsb2ciOnsiZGlzcGxheU5hbWUiOiJDb3Vwb25CdWRkeSIsImFwcERlc2MiOiJDb3Vwb24gQnVkZHkgc2F2ZXMgeW91IG1vbmV5IGJ5IHNlcnZpbmcgeW91IHRoZSBiZXN0IGNvdXBvbnMgYW5kIGRlYWxzIGF0IHRob3VzYW5kcyBvZiB0aGUgbGFyZ2VzdCBvbmxpbmUgbWVyY2hhbnRzLiBDb3Vwb24gQnVkZHkgcmVjb2duaXplcyB3aGVyZSB5b3UgYXJlIGJyb3dzaW5nIGFuZCBhbGVydHMgeW91IG9mIHRoZSBiZXN0IGRlYWxzIHJpZ2h0IG9uIHRoZSBzaXRlIHlvdSBhcmUgdmlzaXRpbmcuIiwicHJpdmFjeVBvbGljeVVybCI6Imh0dHA6Ly9jYmFwcC5jb20vcHJpdmFjeXBvbGljeS8iLCJ0ZXJtc09mVXNlVXJsIjoiaHR0cDovL2NiYXBwLmNvbS9wcml2YWN5cG9saWN5LyJ9LCJIaWRkZW5BcHAiOmZhbHNlfV0sIlN0YXR1cyI6InN1Y2NlZWRlZCIsImxhc3RVcGRhdGVUaW1lIjoxMzYyMjMxNjI1Njg1fQ==");

user_pref("CT2865317.mam_gk_appsDefaultEnabled.enc", "bnVsbA==");

user_pref("CT2865317.mam_gk_appStateReportTime.enc", "MTM2MjIzMTYyOTg1OA==");

user_pref("CT2865317.mam_gk_configuration.enc", "eyJjb25maWd1cmF0aW9uIjpbeyJpZCI6IlByaWNlR29uZyIsImNyaXRlcmlhcyI6W3siY3JpdGVyaWFJZCI6IjQzZmVjMDg1LWNkMzktNGQyZi05MDZhLTAyNTdkZjM2YzlhYiIsImRvbWFpbnMiOlsiKiJdfV19LHsiaWQiOiJDb3Vwb25CdWRkeSIsImNyaXRlcmlhcyI6W3siY3JpdGVyaWFJZCI6IjQzZmVjMDg1LWNkMzktNGQyZi05MDZhLTAyNTdkZjM2YzlhYiIsImRvbWFpbnMiOlsiKiJdfV19XSwiU3RhdHVzIjoic3VjY2VlZGVkIiwibGFzdFVwZGF0ZVRpbWUiOjEzNjIyMzE2MjU2NzF9");

user_pref("CT2865317.mam_gk_CouponBuddy_appState.enc", "b24=");

user_pref("CT2865317.mam_gk_currentVersion.enc", "MS40LjMuMQ==");

user_pref("CT2865317.mam_gk_first_time.enc", "MQ==");

user_pref("CT2865317.mam_gk_lastLoginTime.enc", "MTM2MjIzMTYyNjAwMg==");

user_pref("CT2865317.mam_gk_localization.enc", "eyJnYWRnZXRDb250ZW50UG9saWN5Ijp7IlRleHQiOiJDb250ZW50IFBvbGljeSJ9LCJnYWRnZXREZXNjcmlwdGlvblByaW1hcnkiOnsiVGV4dCI6IlZhbHVlIEFwcHMgZW5yaWNoZXMgeW91ciB3ZWIgZXhwZXJpZW5jZSBieSBvZmZlcmluZyB5b3UgZ3JlYXQgZGVhbHMsIGNvdXBvbnMsIHJlbGF0ZWQgY29udGVudCBhbmQgbXVjaCBtb3JlLiJ9LCJnYWRnZXREZXNjcmlwdGlvblNlY29uZGFyeSI6eyJUZXh0IjoiVmFsdWUgQXBwcyBtYXkgcmVxdWlyZSB1c2Ugb2YgeW91ciBwZXJzb25hbCBpbmZvcm1hdGlvbiwgaW5jbHVkaW5nIHlvdXIgSW50ZXJuZXQgUHJvdG9jb2wgYWRkcmVzcywgdGhlIHdlYnBhZ2VzIHlvdSB2aXNpdCBhbmQgdGhlaXIgY29udGVudC4ifSwiZ2FkZ2V0RW5hYmxlIjp7IlRleHQiOiJUcnkgaXQgbm93In0sImdhZGdldE5vVGhhbmtzIjp7IlRleHQiOiJDdXN0b21pemUifSwiZ2FkZ2V0VGVybXNBbmRQcml2YWN5UG9saWN5Ijp7IlRleHQiOiJUZXJtcyAmIFByaXZhY3kgUG9saWNpZXMifSwiZ2FkZ2V0VGVybXNUZXh0Ijp7IlRleHQiOiJCeSBjbGlja2luZyBcIlRyeSBpdCBub3dcIiwgeW91IGFncmVlIHRvIHRoZSBhY2Nlc3MsIGNvbGxlY3Rpb24gYW5kIHVzYWdlIG9mIHlvdXIgaW5mb3JtYXRpb24gYnkgVmFsdWUgQXBwcyBpbiBhY2NvcmRhbmNlIHdpdGggdGhlIHt7e3Rlcm1zQW5kUHJpdmFjeVBvbGljeUhhbmRsZXJ9fX0uIFNlZSBvdXIge3t7Y29udGVudFBvbGljeUhhbmRsZXJ9fX0gZm9yIG1vcmUgaW5mb3JtYXRpb24uIn0sInNldHRpbmdzQ2FuY2VsIjp7IlRleHQiOiJDYW5jZWwifSwic2V0dGluZ3NDb3Vwb25CdWRkeURlc2NyaXB0aW9uIjp7IlRleHQiOiJDb3Vwb24gQnVkZHkgc2F2ZXMgeW91IG1vbmV5IGJ5IHNlcnZpbmcgeW91IHRoZSBiZXN0IGNvdXBvbnMgYW5kIGRlYWxzIGF0IHRob3VzYW5kcyBvZiB0aGUgbGFyZ2VzdCBvbmxpbmUgbWVyY2hhbnRzLiBDb3Vwb24gQnVkZHkgcmVjb2duaXplcyB3aGVyZSB5b3UgYXJlIGJyb3dzaW5nIGFuZCBhbGVydHMgeW91IG9mIHRoZSBiZXN0IGRlYWxzIHJpZ2h0IG9uIHRoZSBzaXRlIHlvdSBhcmUgdmlzaXRpbmcuIn0sInNldHRpbmdzQ291cG9uQnVkZHlOYW1lIjp7IlRleHQiOiJDb3Vwb24gQnVkZHkifSwic2V0dGluZ3NFbmFibGUiOnsiVGV4dCI6IkVuYWJsZSJ9LCJzZXR0aW5nc0VuYWJsZWQiOnsiVGV4dCI6IkVuYWJsZWQifSwic2V0dGluZ3NQcmljZUdvbmdEZXNjcmlwdGlvbiI6eyJUZXh0IjoieW91ciBvbmxpbmUgc2hvcHBpbmcgYXNzaXN0YW50LiBVc2UgUHJpY2VHb25nIHRvIGZpbmQgdGhlIGJlc3Qgb25saW5lIGRlYWxzIGFuZCBnZXQgb25saW5lIGNvdXBvbnMganVzdCB3aGVuIHlvdSBuZWVkIGl0LiJ9LCJzZXR0aW5nc1ByaWNlR29uZ05hbWUiOnsiVGV4dCI6IlByaWNlIEdvbmcifSwic2V0dGluZ3NQcml2YWN5UG9saWN5Ijp7IlRleHQiOiJQcml2YWN5IFBvbGljeSJ9LCJzZXR0aW5nc1NhdmUiOnsiVGV4dCI6IlNhdmUifSwic2V0dGluZ3NUZXJtc09mVXNlIjp7IlRleHQiOiJUZXJtcyBvZiBVc2UifSwibGFzdFVwZGF0ZVRpbWUiOjEzNjIxNTIwODk5ODJ9");

user_pref("CT2865317.mam_gk_pgUnloadedOnce.enc", "dHJ1ZQ==");

user_pref("CT2865317.mam_gk_PriceGong_appState.enc", "b24=");

user_pref("CT2865317.mam_gk_settings1.4.0.4.enc", "eyJTdGF0dXMiOiJzdWNjZWVkZWQiLCJEYXRhIjp7ImludGVydmFsIjoyNDAsInN0YW1wIjoiNjFfLTEiLCJpc1Rlc3QiOmZhbHNlLCJpc1dlbGNvbWVFeHBlcmllbmNlRW5hYmxlZEJ5RGVmYXVsdCI6dHJ1ZSwiSGFkUEciOmZhbHNlLCJ0cmFja2luZyI6eyJnYSI6dHJ1ZSwiZGIiOnRydWV9LCJzZXJ2aWNlcyI6W3sibmFtZSI6ImNvbmZpZ3VyYXRpb24iLCJ1cmwiOiJodHRwOi8vY2xpZW50c2VydmljZS5tYW0uY29uZHVpdC1zZXJ2aWNlcy5jb20vY29uZmlndXJhdGlvbj9jdGlkPUNUMjg2NTMxNyZzdGFtcD02MV8tMSZjb3VudHJ5PU5MJmJyb3dzZXI9RUJCUk9XU0VSJmJyb3dzZXJ2ZXJzaW9uPUVCQlJPV1NFUlZFUlNJT04iLCJpbnRlcnZhbCI6MjQwfSx7Im5hbWUiOiJhcHBzRGF0YSIsInVybCI6Imh0dHA6Ly9jbGllbnRzZXJ2aWNlLm1hbS5jb25kdWl0LXNlcnZpY2VzLmNvbS9hcHBzZGF0YT9jdGlkPUNUMjg2NTMxNyZzdGFtcD02MV8tMSZjb3VudHJ5PU5MJmJyb3dzZXI9RUJCUk9XU0VSJmJyb3dzZXJ2ZXJzaW9uPUVCQlJPV1NFUlZFUlNJT04mJmxvY2FsPUVCTE9DQUxFIiwiaW50ZXJ2YWwiOjI0MH0seyJuYW1lIjoibG9jYWxpemF0aW9uIiwidXJsIjoiaHR0cDovL2xvY2FsaXphdGlvbnNlcnZpY2UubWFtLmNvbmR1aXQuY29tL2dldHByb2R1Y3R0cmFuc2xhdGlvbj9wPW1hbSZsPUVCTE9DQUxFIiwiaW50ZXJ2YWwiOjE0NDB9LHsibmFtZSI6ImxvZ2luIiwidXJsIjoiaHR0cDovL21hbS1hbGl2ZS1tc2cuY29uZHVpdC1kYXRhLmNvbSIsImludGVydmFsIjoyNDB9LHsibmFtZSI6InVzYWdlIiwidXJsIjoiaHR0cDovL21hbS11c2FnZS5jb25kdWl0LWRhdGEuY29tLyIsImludGVydmFsIjoyNDB9XX0sImxhc3RVcGRhdGVUaW1lIjoxMzYyMTMyNzQ2MjQ4fQ==");

user_pref("CT2865317.mam_gk_settings1.4.3.1.enc", "eyJTdGF0dXMiOiJzdWNjZWVkZWQiLCJEYXRhIjp7ImludGVydmFsIjoyNDAsInN0YW1wIjoiNjFfLTEiLCJpc1Rlc3QiOmZhbHNlLCJpc1dlbGNvbWVFeHBlcmllbmNlRW5hYmxlZEJ5RGVmYXVsdCI6dHJ1ZSwiSGFkUEciOmZhbHNlLCJ0cmFja2luZyI6eyJnYSI6dHJ1ZSwiZGIiOnRydWV9LCJzZXJ2aWNlcyI6W3sibmFtZSI6ImNvbmZpZ3VyYXRpb24iLCJ1cmwiOiJodHRwOi8vY2xpZW50c2VydmljZS5tYW0uY29uZHVpdC1zZXJ2aWNlcy5jb20vY29uZmlndXJhdGlvbj9jdGlkPUNUMjg2NTMxNyZzdGFtcD02MV8tMSZjb3VudHJ5PU5MJmJyb3dzZXI9RUJCUk9XU0VSJmJyb3dzZXJ2ZXJzaW9uPUVCQlJPV1NFUlZFUlNJT04iLCJpbnRlcnZhbCI6MjQwfSx7Im5hbWUiOiJhcHBzRGF0YSIsInVybCI6Imh0dHA6Ly9jbGllbnRzZXJ2aWNlLm1hbS5jb25kdWl0LXNlcnZpY2VzLmNvbS9hcHBzZGF0YT9jdGlkPUNUMjg2NTMxNyZzdGFtcD02MV8tMSZjb3VudHJ5PU5MJmJyb3dzZXI9RUJCUk9XU0VSJmJyb3dzZXJ2ZXJzaW9uPUVCQlJPV1NFUlZFUlNJT04mJmxvY2FsPUVCTE9DQUxFIiwiaW50ZXJ2YWwiOjI0MH0seyJuYW1lIjoibG9jYWxpemF0aW9uIiwidXJsIjoiaHR0cDovL2xvY2FsaXphdGlvbnNlcnZpY2UubWFtLmNvbmR1aXQuY29tL2dldHByb2R1Y3R0cmFuc2xhdGlvbj9wPW1hbSZsPUVCTE9DQUxFIiwiaW50ZXJ2YWwiOjE0NDB9LHsibmFtZSI6ImxvZ2luIiwidXJsIjoiaHR0cDovL21hbS1hbGl2ZS1tc2cuY29uZHVpdC1kYXRhLmNvbSIsImludGVydmFsIjoyNDB9LHsibmFtZSI6InVzYWdlIiwidXJsIjoiaHR0cDovL21hbS11c2FnZS5jb25kdWl0LWRhdGEuY29tLyIsImludGVydmFsIjoyNDB9XX0sImxhc3RVcGRhdGVUaW1lIjoxMzYyMjMxNjI1MDg4fQ==");

user_pref("CT2865317.mam_gk_showCloseButton.enc", "dHJ1ZQ==");

user_pref("CT2865317.mam_gk_showWelcomeGadget.enc", "ZmFsc2U=");

user_pref("CT2865317.mam_gk_user_apps_selection.enc", "AA==");

user_pref("CT2865317.mam_gk_userId.enc", "AA==");

user_pref("CT2865317.migrateAppsAndComponents", true);

user_pref("CT2865317.navigationAliasesJson", "{\"EB_MAIN_FRAME_URL\":\"http%3A%2F%2Fwww.google.nl%2F\",\"EB_MAIN_FRAME_TITLE\":\"Google\",\"EB_SEARCH_TERM\":\"\",\"EB_TOOLBAR_SUB_DOMAIN\":\"http://uTorrentBarNL.OurToolbar.com/\",\"EB_TOOLBAR_ID\":\"CT2865317\",\"EB_TOOLBAR_VERSION\":\"10.14.65.43\",\"EB_ORIGINAL_CTID\":\"CT2865317\",\"EB_DOWNLOAD_PAGE\":\"http://uTorrentBarNL.OurToolbar.com/\",\"EB_TOOLBAR_NAME\":\"uTorrentBar_NL\"}");

user_pref("CT2865317.openThankYouPage", "true");

user_pref("CT2865317.openUninstallPage", "FALSE");

user_pref("CT2865317.PG_ENABLE.enc", "ZEhKMVpRPT0=");

user_pref("CT2865317.RevertSettingsEnabled", true);

user_pref("CT2865317.scriptSource", "http://127.0.0.1:10000/gui/");

user_pref("CT2865317.search.searchAppId", "129363015615338104");

user_pref("CT2865317.search.searchCount", "0");

user_pref("CT2865317.searchInNewTabEnabled", "false");

user_pref("CT2865317.searchInNewTabEnabledByUser", "false");

user_pref("CT2865317.searchInNewTabEnabledInHidden", "true");

user_pref("CT2865317.searchProtector.notifyChanges", "{\"dataType\":\"string\",\"data\":\"true\"}");

user_pref("CT2865317.selectToSearchBoxEnabled", "{\"dataType\":\"string\",\"data\":\"true\"}");

user_pref("CT2865317.serviceLayer_service_login_isFirstLoginInvoked", "{\"dataType\":\"boolean\",\"data\":\"true\"}");

user_pref("CT2865317.serviceLayer_service_login_loginCount", "{\"dataType\":\"number\",\"data\":\"4\"}");

user_pref("CT2865317.serviceLayer_service_toolbarGrouping_activeCTID", "{\"dataType\":\"string\",\"data\":\"CT2865317\"}");

user_pref("CT2865317.serviceLayer_service_toolbarGrouping_activeDownloadUrl", "{\"dataType\":\"string\",\"data\":\"http://uTorrentBarNL.OurToolbar.com//xpi\"}");

user_pref("CT2865317.serviceLayer_service_toolbarGrouping_activeToolbarName", "{\"dataType\":\"string\",\"data\":\"uTorrentBar_NL\"}");

user_pref("CT2865317.serviceLayer_service_toolbarGrouping_invoked", "{\"dataType\":\"string\",\"data\":\"true\"}");

user_pref("CT2865317.serviceLayer_service_usage_toolbarUsageCount", "{\"dataType\":\"number\",\"data\":\"2\"}");

user_pref("CT2865317.serviceLayer_services_appsMetadata_lastUpdate", "1362231618750");

user_pref("CT2865317.serviceLayer_services_appTrackingFirstTime_lastUpdate", "1362057986506");

user_pref("CT2865317.serviceLayer_services_gottenAppsContextMenu_lastUpdate", "1362057986318");

user_pref("CT2865317.serviceLayer_services_location_lastUpdate", "1362231615463");

user_pref("CT2865317.serviceLayer_services_login_10.10.27.6_lastUpdate", "1353848668298");

user_pref("CT2865317.serviceLayer_services_login_10.13.40.15_lastUpdate", "1362130126339");

user_pref("CT2865317.serviceLayer_services_login_10.14.65.43_lastUpdate", "1362231605346");

user_pref("CT2865317.serviceLayer_services_otherAppsContextMenu_lastUpdate", "1362057986353");

user_pref("CT2865317.serviceLayer_services_searchAPI_lastUpdate", "1362152081656");

user_pref("CT2865317.serviceLayer_services_serviceMap_lastUpdate", "1362231615463");

user_pref("CT2865317.serviceLayer_services_setupAPI_lastUpdate", "1362132743265");

user_pref("CT2865317.serviceLayer_services_toolbarContextMenu_lastUpdate", "1362057866541");

user_pref("CT2865317.serviceLayer_services_toolbarSettings_lastUpdate", "1362231618721");

user_pref("CT2865317.serviceLayer_services_translation_lastUpdate", "1362152081655");

user_pref("CT2865317.settingsINI", true);

user_pref("CT2865317.shouldFirstTimeDialog", "false");

user_pref("CT2865317.smartbar.CTID", "CT2865317");

user_pref("CT2865317.smartbar.toolbarName", "uTorrentBar_NL ");

user_pref("CT2865317.smartbar.Uninstall", "0");

user_pref("CT2865317.toolbarBornServerTime", "1-11-2012");

user_pref("CT2865317.toolbarCurrentServerTime", "1-3-2013");

user_pref("CT2865317.upgradeFromClearSBVersion", true);

user_pref("CT2865317.url_history0001.enc", "aHR0cDovL3d3dy5wcm9maXRjbGlja2luZy5jb20vbG9nb3V0Ojo6Y2xpY2toYW5kbGVyOjo6MTM1OTY3NzM0NzQ2MiwsLGh0dHA6Ly93d3cucHJvZml0Y2xpY2tpbmcuY29tL2xvZ291dDo6OmNsaWNraGFuZGxlcjo6OjEzNTk2NzczNDc0NjUsLCxodHRwOi8vd3d3LnByb2ZpdGNsaWNraW5nLmNvbS9sb2dvdXQ6OjpjbGlja2hhbmRsZXI6OjoxMzU5Njc3NTE4Mjk1LCwsaHR0cDovL3d3dy5wcm9maXRjbGlja2luZy5jb20vbG9nb3V0Ojo6Y2xpY2toYW5kbGVyOjo6MTM1OTY3NzUxODI5OCwsLGh0dHA6Ly93d3cucHJvZml0Y2xpY2tpbmcuY29tL2xvZ2luOjo6Y2xpY2toYW5kbGVyOjo6MTM1OTY3ODM4MzY2NCwsLGh0dHA6Ly93d3cucHJvZml0Y2xpY2tpbmcuY29tL3dhbGxldC93aXRoZHJhdy5waHA/cHJvY2Vzc29yPWFwOjo6Y2xpY2toYW5kbGVyOjo6MTM1OTY3ODQ1MzY4OCwsLGh0dHA6Ly93d3cucHJvZml0Y2xpY2tpbmcuY29tL3dhbGxldC93aXRoZHJhdy5waHA/cHJvY2Vzc29yPWFwOjo6Y2xpY2toYW5kbGVyOjo6MTM1OTY3ODQ4OTk5OSwsLGh0dHA6Ly93d3cucHJvZml0Y2xpY2tpbmcuY29tL3dhbGxldC93aXRoZHJhdy5waHA/cHJvY2Vzc29yPWFwOjo6Y2xpY2toYW5kbGVyOjo6MTM1OTY3ODUwMzA1OCwsLGh0dHA6Ly93d3cucHJvZml0Y2xpY2tpbmcuY29tL3dhbGxldC93aXRoZHJhdy5waHA/cHJvY2Vzc29yPWFwOjo6Y2xpY2toYW5kbGVyOjo6MTM1OTY3ODUwMzA2MSwsLGh0dHA6Ly93d3cucHJvZml0Y2xpY2tpbmcuY29tL2Rhc2hib2FyZDo6OmNsaWNraGFuZGxlcjo6OjEzNTk2Nzg1MDg3MTAsLCxodHRwOi8vd3d3LnByb2ZpdGNsaWNraW5nLmNvbS9kYXNoYm9hcmQ6OjpjbGlja2hhbmRsZXI6OjoxMzU5Njc4NTA4NzEzLCwsaHR0cDovL3d3dy5wcm9maXRjbGlja2luZy5jb20vZGFzaGJvYXJkOjo6Y2xpY2toYW5kbGVyOjo6MTM1OTY3ODUwODcxNiwsLGh0dHA6Ly93d3cucHJvZml0Y2xpY2tpbmcuY29tL2xvZ291dDo6OmNsaWNraGFuZGxlcjo6OjEzNTk2Nzg1MjE5MDMsLCxodHRwOi8vd3d3LnByb2ZpdGNsaWNraW5nLmNvbS9sb2dvdXQ6OjpjbGlja2hhbmRsZXI6OjoxMzU5Njc4NTIxOTA2LCwsaHR0cDovL3d3dy5wcm9maXRjbGlja2luZy5jb20vbG9nb3V0Ojo6Y2xpY2toYW5kbGVyOjo6MTM1OTY3ODUyMTkwOSwsLGh0dHA6Ly93d3cucHJvZml0Y2xpY2tpbmcuY29tL2xvZ291dDo6OmNsaWNraGFuZGxlcjo6OjEzNTk2Nzg1MjE5MTI=");

user_pref("CT2865317.UserID", "UN14821110981322017");

user_pref("CT2865317_Firefox.csv", "[{\"from\":\"Abs Layer\",\"action\":\"loading toolbar\",\"time\":1362575024444,\"isWithState\":\"\",\"timeFromStart\":0,\"timeFromPrev\":0}]");

---- Lines CT2865317 modified from prefs.js ----

---- Lines CT2865317 removed from user.js ----

---- Lines conduit removed from prefs.js ----

---- Lines conduit modified from prefs.js ----

---- Lines conduit removed from user.js ----

---- Lines 87775fdb-6972-41f9-ae51-8326e38cb206 removed from prefs.js ----

---- Lines 87775fdb-6972-41f9-ae51-8326e38cb206 modified from prefs.js ----

user_pref("extensions.enabledAddons", "{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}:6.0.35,{87775fdb-6972-41f9-ae51-8326e38cb206}:10.14.65.43,{972ce4c6-7e08-4474-a285-3208198ce6fd}:15.0.1");

user_pref("extensions.installCache", "[{\"name\":\"winreg-app-global\",\"addons\":{\"{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}\":{\"descriptor\":\"C:\\\\ProgramData\\\\Norton\\\\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\\\\N360_20.1.0.24\\\\coFFPlgn\",\"mtime\":1362475846219},\"{BBDA0591-3099-440a-AA10-41764D9DB4DB}\":{\"descriptor\":\"C:\\\\ProgramData\\\\Norton\\\\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\\\\N360_20.1.0.24\\\\IPSFFPlgn\",\"mtime\":1362553926415}}},{\"name\":\"app-global\",\"addons\":{\"{972ce4c6-7e08-4474-a285-3208198ce6fd}\":{\"descriptor\":\"C:\\\\Program Files (x86)\\\\Mozilla Firefox\\\\extensions\\\\{972ce4c6-7e08-4474-a285-3208198ce6fd}\",\"mtime\":1347440165427},\"{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}\":{\"descriptor\":\"C:\\\\Program Files (x86)\\\\Mozilla Firefox\\\\extensions\\\\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}\",\"mtime\":1355661712913}}},{\"name\":\"app-profile\",\"addons\":{\"OneClickDownload@OneClickDownload.com\":{\"descriptor\":\"C:\\\\Users\\\\Koos\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\li59hz2c.default\\\\extensions\\\\OneClickDownload@OneClickDownload.com.xpi\",\"mtime\":1362057867674},\"TorrentHandler@TorrentHandler.com\":{\"descriptor\":\"C:\\\\Users\\\\Koos\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\li59hz2c.default\\\\extensions\\\\TorrentHandler@TorrentHandler.com.xpi\",\"mtime\":1353848670349},\"{87775fdb-6972-41f9-ae51-8326e38cb206}\":{\"descriptor\":\"C:\\\\Users\\\\Koos\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\li59hz2c.default\\\\extensions\\\\{87775fdb-6972-41f9-ae51-8326e38cb206}\",\"mtime\":1362233426127}}}]");

---- Lines 87775fdb-6972-41f9-ae51-8326e38cb206 removed from user.js ----

---- Lines OneClickDownload removed from prefs.js ----

user_pref("extensions.bootstrappedAddons", "{\"TorrentHandler@TorrentHandler.com\":{\"version\":\"1.2\",\"type\":\"extension\",\"descriptor\":\"C:\\\\Users\\\\Koos\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\li59hz2c.default\\\\extensions\\\\TorrentHandler@TorrentHandler.com.xpi\"},\"OneClickDownload@OneClickDownload.com\":{\"version\":\"1.3\",\"type\":\"extension\",\"descriptor\":\"C:\\\\Users\\\\Koos\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\li59hz2c.default\\\\extensions\\\\OneClickDownload@OneClickDownload.com.xpi\"}}");

user_pref("extensions.OneClickDownload.filter", "filter:0,3");

---- Lines OneClickDownload modified from prefs.js ----

user_pref("extensions.installCache", "[{\"name\":\"winreg-app-global\",\"addons\":{\"{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}\":{\"descriptor\":\"C:\\\\ProgramData\\\\Norton\\\\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\\\\N360_20.1.0.24\\\\coFFPlgn\",\"mtime\":1362475846219},\"{BBDA0591-3099-440a-AA10-41764D9DB4DB}\":{\"descriptor\":\"C:\\\\ProgramData\\\\Norton\\\\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\\\\N360_20.1.0.24\\\\IPSFFPlgn\",\"mtime\":1362553926415}}},{\"name\":\"app-global\",\"addons\":{\"{972ce4c6-7e08-4474-a285-3208198ce6fd}\":{\"descriptor\":\"C:\\\\Program Files (x86)\\\\Mozilla Firefox\\\\extensions\\\\{972ce4c6-7e08-4474-a285-3208198ce6fd}\",\"mtime\":1347440165427},\"{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}\":{\"descriptor\":\"C:\\\\Program Files (x86)\\\\Mozilla Firefox\\\\extensions\\\\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}\",\"mtime\":1355661712913}}},{\"name\":\"app-profile\",\"addons\":{\"OneClickDownload@OneClickDownload.com\":{\"descriptor\":\"C:\\\\Users\\\\Koos\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\li59hz2c.default\\\\extensions\\\\OneClickDownload@OneClickDownload.com.xpi\",\"mtime\":1362057867674},\"TorrentHandler@TorrentHandler.com\":{\"descriptor\":\"C:\\\\Users\\\\Koos\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\li59hz2c.default\\\\extensions\\\\TorrentHandler@TorrentHandler.com.xpi\",\"mtime\":1353848670349},\"{disabled}\":{\"descriptor\":\"C:\\\\Users\\\\Koos\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\li59hz2c.default\\\\extensions\\\\{disabled}\",\"mtime\":1362233426127}}}]");

---- Lines OneClickDownload removed from user.js ----

---- Lines smartbar removed from prefs.js ----

---- Lines smartbar modified from prefs.js ----

---- Lines smartbar removed from user.js ----

---- FireFox user.js and prefs.js backups ----

user_06-03-2013_2006_.backup

prefs_06-03-2013_2006_.backup

==== Deleting Files \ Folders ======================

"C:\Users\Koos\AppData\Roaming\Mozilla\Firefox\Profiles\li59hz2c.default\extensions\OneClickDownload@OneClickDownload.com.xpi" deleted

"C:\Program Files (x86)\1ClickDownload" deleted

"C:\Program Files (x86)\Conduit" deleted

"C:\ProgramData\Partner" deleted

"C:\ProgramData\InstallMate" deleted

"C:\ProgramData\Premium" deleted

"C:\Users\Koos\AppData\Local\CRE" deleted

"C:\Users\Koos\AppData\Local\Conduit" deleted

"C:\Users\Koos\AppData\LocalLow\PriceGong" deleted

"C:\Users\Koos\AppData\LocalLow\Conduit" deleted

"C:\Users\Koos\AppData\Roaming\Mozilla\Firefox\Profiles\li59hz2c.default\jetpack" deleted

"C:\Users\Koos\AppData\Roaming\Mozilla\Firefox\Profiles\li59hz2c.default\CT2865317" deleted

"C:\Users\Koos\AppData\Roaming\Mozilla\Firefox\Profiles\li59hz2c.default\CT2865317" deleted

"C:\Users\Koos\AppData\Roaming\Mozilla\Firefox\Profiles\li59hz2c.default\extensions\{87775fdb-6972-41f9-ae51-8326e38cb206}" deleted

"C:\Users\Koos\AppData\Roaming\Mozilla\Firefox\Profiles\li59hz2c.default\smartbar" deleted

"C:\Users\Koos\AppData\Roaming\Mozilla\Firefox\Profiles\li59hz2c.default\extensions\{87775fdb-6972-41f9-ae51-8326e38cb206}" deleted

==== Files Recently Created / Modified ======================

====== C:\Windows ====

2013-03-06 12:32:43 D41D8CD98F00B204E9800998ECF8427E 0 ----a-w- C:\Windows\eDrawingOfficeAutomator.INI

2013-03-01 11:34:27 1363812D50F19B484B6C42F64D2ACA2E 39 ----a-w- C:\Windows\vbaddin.ini

2013-03-01 11:33:42 2BE187ADCEE956C1360E7E23D87B89D3 162 ----a-w- C:\Windows\ODBC.INI

====== C:\Users\Koos\AppData\Local\Temp ====

====== C:\Windows\SysWOW64 =====

2013-02-28 09:45:58 8B285BDAB7735FDFB18E6F7122923B77 187392 ----a-w- C:\Windows\SysWOW64\UIAnimation.dll

2013-02-28 09:45:58 600A65F922CCDCBB2D11467914241556 2284544 ----a-w- C:\Windows\SysWOW64\msmpeg2vdec.dll

2013-02-28 09:45:53 545F1BAAADD0BF1F4FE4586293FCA07D 417792 ----a-w- C:\Windows\SysWOW64\WMPhoto.dll

2013-02-28 09:45:52 B3170CCC779B682C3341873EA60CF084 1988096 ----a-w- C:\Windows\SysWOW64\d3d10warp.dll

2013-02-28 09:45:52 6A13B4F3B3F575F1E24B877B9359AABA 10752 ---ha-w- C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l1-1-0.dll

2013-02-28 09:45:52 6951562DC4625EEFC6EACD52AD165866 9728 ---ha-w- C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l1-1-0.dll

2013-02-28 09:45:52 49ACA548B2423F1C67898E6AC719A9A6 3584 ---ha-w- C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l2-1-0.dll

2013-02-28 09:45:52 3C1936A12C62254F914A01BBC6A8DC69 161792 ----a-w- C:\Windows\SysWOW64\d3d10_1.dll

2013-02-28 09:45:52 2E33DFD10F28F86C3FC40EE123CC3904 2560 ---ha-w- C:\Windows\SysWOW64\api-ms-win-downlevel-normaliz-l1-1-0.dll

2013-02-28 09:45:51 FB3F036EF6A467F7AF46C821FF5D198D 220160 ----a-w- C:\Windows\SysWOW64\d3d10core.dll

2013-02-28 09:45:51 D4F264FE23F8953D840904418220C15E 293376 ----a-w- C:\Windows\SysWOW64\dxgi.dll

2013-02-28 09:45:51 D4212AB475A3B25EC4DF574536C3EDC5 249856 ----a-w- C:\Windows\SysWOW64\d3d10_1core.dll

2013-02-28 09:45:51 C7A730AFB80B11F93EFC81B1D6F920D7 364544 ----a-w- C:\Windows\SysWOW64\XpsGdiConverter.dll

2013-02-28 09:45:51 8504944851DF6175CC489A8F3328459E 1080832 ----a-w- C:\Windows\SysWOW64\d3d10.dll

2013-02-28 09:45:51 7ACDFB4CC67F4993DF0E0731576309B2 1504768 ----a-w- C:\Windows\SysWOW64\d3d11.dll

2013-02-28 09:45:51 60F4AEFA103D421EA4A40E31409B4756 3072 ---ha-w- C:\Windows\SysWOW64\api-ms-win-downlevel-shell32-l1-1-0.dll

2013-02-28 09:45:51 589CBC4989F750E1DA35625AB481CF43 4096 ---ha-w- C:\Windows\SysWOW64\api-ms-win-downlevel-user32-l1-1-0.dll

2013-02-28 09:45:51 4FF3EC04CD47DD62181894B71B004E40 604160 ----a-w- C:\Windows\SysWOW64\d3d10level9.dll

2013-02-28 09:45:51 3BE0D923AA45A4DBE091C2D84F0B4FE7 3072 ---ha-w- C:\Windows\SysWOW64\api-ms-win-downlevel-version-l1-1-0.dll

2013-02-28 09:45:51 1C60E09CA1C3A045BC4D367F67C915B7 5632 ---ha-w- C:\Windows\SysWOW64\api-ms-win-downlevel-ole32-l1-1-0.dll

2013-02-28 09:45:51 007863E45F25AA47A4C30D0930BBFD85 5632 ---ha-w- C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l2-1-0.dll

2013-02-28 09:45:50 6A7B5A3EFCCDB53DA41CF6838056990F 1158144 ----a-w- C:\Windows\SysWOW64\XpsPrint.dll

2013-02-28 09:45:41 62A6EB5771580CAE445804389F3F7432 207872 ----a-w- C:\Windows\SysWOW64\WindowsCodecsExt.dll

2013-02-28 09:45:41 4277F5164DE9B7C665BB928B9145BEE0 1247744 ----a-w- C:\Windows\SysWOW64\DWrite.dll

2013-02-28 09:45:41 3BCECD87AB4E6743BFB45B352AD1A529 1230336 ----a-w- C:\Windows\SysWOW64\WindowsCodecs.dll

2013-02-28 09:45:40 9FF8F684BACF326082E5562F7C104A79 3419136 ----a-w- C:\Windows\SysWOW64\d2d1.dll

====== C:\Windows\SysWOW64\drivers =====

====== C:\Windows\Sysnative =====

2013-02-28 09:45:58 E8EEA503870CB6A6DC4E09A2433DF33E 2776576 ----a-w- C:\Windows\Sysnative\msmpeg2vdec.dll

2013-02-28 09:45:58 04CB7C8FDC6D9640DD82A527208F72C4 221184 ----a-w- C:\Windows\Sysnative\UIAnimation.dll

2013-02-28 09:45:53 893E8C1E4A1263EDDB1A6922D0E32201 465920 ----a-w- C:\Windows\Sysnative\WMPhoto.dll

2013-02-28 09:45:52 F5CEF064C7E6D95DA86B9D064A56A969 3584 ---ha-w- C:\Windows\Sysnative\api-ms-win-downlevel-advapi32-l2-1-0.dll

2013-02-28 09:45:52 F49E92B50CED5C9F1725D3C0329FD933 10752 ---ha-w- C:\Windows\Sysnative\api-ms-win-downlevel-advapi32-l1-1-0.dll

2013-02-28 09:45:52 AFC3DB5C6EB8CA8017DDB81D6C0AD02A 9728 ---ha-w- C:\Windows\Sysnative\api-ms-win-downlevel-shlwapi-l1-1-0.dll

2013-02-28 09:45:52 9AE80F6A66B30E3ED8CDF858CF28B11B 194560 ----a-w- C:\Windows\Sysnative\d3d10_1.dll

2013-02-28 09:45:52 64A4AB126E24FD3F58EBE64852773DB5 2560 ---ha-w- C:\Windows\Sysnative\api-ms-win-downlevel-normaliz-l1-1-0.dll

2013-02-28 09:45:51 FB4045578F5180BDB1963AB352B78548 5632 ---ha-w- C:\Windows\Sysnative\api-ms-win-downlevel-shlwapi-l2-1-0.dll

2013-02-28 09:45:51 C498EF41B93986BCBD483597573EB96D 2565120 ----a-w- C:\Windows\Sysnative\d3d10warp.dll

2013-02-28 09:45:51 B2CA1AC17E78D986B22FD6C2261CD84F 1238528 ----a-w- C:\Windows\Sysnative\d3d10.dll

2013-02-28 09:45:51 AFB73882AE41E1629A63E6713FE30FB9 296960 ----a-w- C:\Windows\Sysnative\d3d10core.dll

2013-02-28 09:45:51 9108540E866F75C7AF2B91DD921A8091 3072 ---ha-w- C:\Windows\Sysnative\api-ms-win-downlevel-shell32-l1-1-0.dll

2013-02-28 09:45:51 9094039A00485F71C4DE64BF51F64C46 3072 ---ha-w- C:\Windows\Sysnative\api-ms-win-downlevel-version-l1-1-0.dll

2013-02-28 09:45:51 8DFB5752FCE145A6B295093C0A8BE131 363008 ----a-w- C:\Windows\Sysnative\dxgi.dll

2013-02-28 09:45:51 72723D3E4781BADC62C3180C137E7B23 4096 ---ha-w- C:\Windows\Sysnative\api-ms-win-downlevel-user32-l1-1-0.dll

2013-02-28 09:45:51 6F623BD09CBB4C3F97374F12976E5EA5 522752 ----a-w- C:\Windows\Sysnative\XpsGdiConverter.dll

2013-02-28 09:45:51 63F72417CA38D8FC8F53709649B589E3 333312 ----a-w- C:\Windows\Sysnative\d3d10_1core.dll

2013-02-28 09:45:51 448B02AD260EC3E1E892FCE6DFDDEEBD 1887232 ----a-w- C:\Windows\Sysnative\d3d11.dll

2013-02-28 09:45:51 3834316FE8A653227282196525E07DFE 648192 ----a-w- C:\Windows\Sysnative\d3d10level9.dll

2013-02-28 09:45:51 0E6FBF19D9DFBB77316C23DF91F8A101 5632 ---ha-w- C:\Windows\Sysnative\api-ms-win-downlevel-ole32-l1-1-0.dll

2013-02-28 09:45:50 FA428BDBCFAB9DC3D58F0BD2CCD50EA2 1682432 ----a-w- C:\Windows\Sysnative\XpsPrint.dll

2013-02-28 09:45:41 F1C19F0AA151B90A7416FA1D50DDB582 245248 ----a-w- C:\Windows\Sysnative\WindowsCodecsExt.dll

2013-02-28 09:45:41 C4C183E6551084039EC862DA1C945E3D 1175552 ----a-w- C:\Windows\Sysnative\FntCache.dll

2013-02-28 09:45:41 BDDF242A49E7B7DC5CCEC291BCE53ACB 1424384 ----a-w- C:\Windows\Sysnative\WindowsCodecs.dll

2013-02-28 09:45:41 7E8A672B7B06A6EB11960C22E0360C59 3928064 ----a-w- C:\Windows\Sysnative\d2d1.dll

2013-02-28 09:45:41 63BB89DED1E9104E68D33E54DE4D340D 1643520 ----a-w- C:\Windows\Sysnative\DWrite.dll

====== C:\Windows\Sysnative\drivers =====

2013-02-13 11:55:23 B62A953F2BF3922C8764A29C34A22899 1913192 ----a-w- C:\Windows\Sysnative\drivers\tcpip.sys

2013-02-13 11:55:22 41C67E4205C606A103DEC8651D0B6FE6 288088 ----a-w- C:\Windows\Sysnative\drivers\FWPKCLNT.SYS

====== C:\Windows\Tasks ======

====== C:\Windows\Temp ======

======= C:\Program Files =====

2013-03-06 12:26:55 -------- d-----w- C:\Program Files\SolidWorks Corp

2013-03-06 12:26:55 -------- d-----w- C:\Program Files\Common Files\SolidWorks Shared

2013-03-06 12:26:39 -------- d-----w- C:\Program Files\Common Files\Macrovision Shared

======= C:\Program Files (x86) =====

2013-03-06 16:56:18 -------- d-----w- C:\Program Files (x86)\Trend Micro

2013-03-06 12:26:04 -------- d-----w- C:\Program Files (x86)\Common Files\SolidWorks Shared

2013-03-06 12:25:17 -------- d-----w- C:\Program Files (x86)\Common Files\SolidWorks Installation Manager

2013-02-06 14:16:49 -------- d-----w- C:\Program Files (x86)\Common Files\Skype

2013-02-06 14:16:49 -------- d-----r- C:\Program Files (x86)\Skype

======= C: =====

====== C:\Users\Koos\AppData\Roaming ======

2013-03-06 12:36:45 -------- d-----w- C:\users\Koos\AppData\Roaming\SolidWorks 2012

2013-03-06 12:32:36 -------- d-----w- C:\users\Koos\AppData\Roaming\help_images_otherUI

2013-02-06 14:17:07 -------- d-----w- C:\users\Koos\AppData\Roaming\Skype

====== C:\Users\Koos ======

2013-03-06 12:26:55 -------- d-----w- C:\ProgramData\SolidWorks

2013-02-06 14:16:33 -------- d-----w- C:\ProgramData\Skype

====== C: exe-files ==

2013-03-06 12:26:39 5CEE6CD43AE5844C49300EA0B1E557EE 1431888 ----a-w- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe

2013-03-06 12:26:17 F7364A18D1819E3C9BCF831B850664FB 9849416 ----a-w- C:\Program Files (x86)\Common Files\SolidWorks Installation Manager\CheckForUpdates\sldCheckForUpdates.exe

2013-03-06 12:26:17 CEA9EF5B5E7D030B33392ED569CD7B0F 85576 ----a-w- C:\Program Files (x86)\Common Files\SolidWorks Installation Manager\CheckForUpdates\regval.exe

2013-03-06 12:26:17 7182145D2343EE082EBE5099D6EF3D9D 104448 ----a-w- C:\Program Files (x86)\Common Files\SolidWorks Installation Manager\CheckForUpdates\SwHelpViewer\SwHelpViewer.exe

2013-03-06 12:26:04 4945020BC094C322571184A6E8056B3A 79360 ----a-w- C:\Program Files (x86)\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe

2013-03-06 12:25:56 7182145D2343EE082EBE5099D6EF3D9D 104448 ----a-w- C:\Windows\SolidWorks\IM_20120-40200-1100-100\sldim\SwHelpViewer\SwHelpViewer.exe

2013-03-06 12:25:55 CEA9EF5B5E7D030B33392ED569CD7B0F 85576 ----a-w- C:\Windows\SolidWorks\IM_20120-40200-1100-100\sldim\regval.exe

2013-03-06 12:25:55 A6787B1E5BF249CC84E7989F4508914E 363080 ----a-w- C:\Windows\SolidWorks\IM_20120-40200-1100-100\setup.exe

2013-03-06 12:25:55 90FA26CAAC5C5801178E67DF478FA4D3 10022984 ----a-w- C:\Windows\SolidWorks\IM_20120-40200-1100-100\sldim\sldIM.exe

2013-03-06 12:25:55 4477C3AF800439CE00799AD30BA70D46 5206600 ----a-w- C:\Windows\SolidWorks\IM_20120-40200-1100-100\sldim\sldadminoptioneditor.exe

2013-03-06 12:25:17 180E196C1F96607489DCF9740215B34E 1723976 ----a-w- C:\Program Files (x86)\Common Files\SolidWorks Installation Manager\20.0\sldimdownloader.exe

2013-03-06 11:46:55 4477C3AF800439CE00799AD30BA70D46 5206600 ----a-w- C:\Users\Koos\AppData\Local\Temp\SolidWorks\Installation Manager Data\Remove_20120-40200-1100\sldadminoptioneditor.exe

2013-03-06 11:46:49 7182145D2343EE082EBE5099D6EF3D9D 104448 ----a-w- C:\Users\Koos\AppData\Local\Temp\SolidWorks\Installation Manager Data\Remove_20120-40200-1100\SwHelpViewer\SwHelpViewer.exe

2013-03-06 11:46:46 CEA9EF5B5E7D030B33392ED569CD7B0F 85576 ----a-w- C:\Users\Koos\AppData\Local\Temp\SolidWorks\Installation Manager Data\Remove_20120-40200-1100\regval.exe

2013-03-06 11:46:45 90FA26CAAC5C5801178E67DF478FA4D3 10022984 ----a-w- C:\Users\Koos\AppData\Local\Temp\SolidWorks\Installation Manager Data\Remove_20120-40200-1100\sldIM.exe

2013-03-05 16:18:57 634392F83C27EEF178B8ABA68935A044 320696 ------r- C:\ProgramData\NVIDIA\Updatus\Download\2ED0\updatus.15187451_RUNASUSER.exe

2013-03-02 13:40:38 209EFFE8B0026F0362C100F06DCD346A 320048 ----a-r- C:\ProgramData\NVIDIA\Updatus\Download\2E10\updatus.15170771_RUNASUSER.exe

2013-03-01 11:30:41 5A432A042DAE460ABE7199B758E8606C 145184 ----a-w- C:\MSOCache\All Users\{90120000-0051-0000-0000-0000000FF1CE}-C\ose.exe

2013-03-01 11:30:02 95B8A4245A6CD37D36E56FAE5A23E2B1 463152 ----a-w- C:\MSOCache\All Users\{90120000-0051-0000-0000-0000000FF1CE}-C\setup.exe

=== C: other files ==

2013-03-06 12:31:24 C677B7270F26007A7076E3A487B83D92 20584 ----a-w- C:\Program Files (x86)\Microsoft Visual Studio 8\Common7\IDE\ProjectTemplates\CSharp\SolidWorks_VSTA\1033\solidworks_macro.zip

2013-03-06 12:31:24 45A4D2473D71C5ACD1D8BEF464445309 20677 ----a-w- C:\Program Files (x86)\Microsoft Visual Studio 8\Common7\IDE\ProjectTemplates\VisualBasic\SolidWorks_VSTA\1033\solidworks_macro.zip

==== Startup Registry Enabled ======================

[HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run]

"Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun"

[HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run]

"Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun"

[HKEY_USERS\S-1-5-21-3766946001-305601837-3760299784-1000\Software\Microsoft\Windows\CurrentVersion\Run]

"ISUSPM"="C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe -scheduler"

"Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun"

[HKEY_USERS\S-1-5-21-3766946001-305601837-3760299784-1002\Software\Microsoft\Windows\CurrentVersion\Run]

"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe /autoRun"

"Skype"="C:\Program Files (x86)\Skype\Phone\Skype.exe /minimized /regrun"

[HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce]

"mctadmin"="C:\Windows\System32\mctadmin.exe"

[HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce]

"mctadmin"="C:\Windows\System32\mctadmin.exe"

[HKEY_USERS\S-1-5-21-3766946001-305601837-3760299784-1000\Software\Microsoft\Windows\CurrentVersion\RunOnce]

"mctadmin"="C:\Windows\System32\mctadmin.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"ASUSPRP"="C:\Program Files (x86)\ASUS\APRP\APRP.EXE"

"ASUSWebStorage"="C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.84.161\AsusWSPanel.exe /S"

"ATKMEDIA"="C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe"

"HControlUser"="C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe"

"FLxHCIm"="C:\Program Files\Fresco Logic Inc\Fresco Logic USB3.0 Host Controller\host\FLxHCIm.exe"

"Wireless Console 3"="C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe"

"VAWinAgent"="C:\ExpressGateUtil\VAWinAgent.exe"

"SunJavaUpdateSched"="C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"

"Adobe ARM"="C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]

"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe /autoRun"

"Skype"="C:\Program Files (x86)\Skype\Phone\Skype.exe /minimized /regrun"

==== Startup Registry Enabled x64 ======================

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"IgfxTray"="C:\Windows\system32\igfxtray.exe"

"HotKeysCmds"="C:\Windows\system32\hkcmd.exe"

"Persistence"="C:\Windows\system32\igfxpers.exe"

"IntelTBRunOnce"="wscript.exe //b //nologo C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs"

"RtHDVBg"="C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe /SF3 "

"ETDWare"="%ProgramFiles%\Elantech\ETDCtrl.exe "

==== Startup Registry Disabled x64 ======================

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Adobe ARM]

"key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="Adobe ARM"

"hkey"="HKLM"

"command"="\"C:\\Program Files (x86)\\Common Files\\Adobe\\ARM\\1.0\\AdobeARM.exe\""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\AmIcoSinglun64]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="AmIcoSinglun64"

"hkey"="HKLM"

"command"="C:\\Program Files (x86)\\AmIcoSingLun\\AmIcoSinglun64.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ApplePhotoStreams]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="ApplePhotoStreams"

"hkey"="HKCU"

"command"="C:\\Program Files (x86)\\Common Files\\Apple\\Internet Services\\ApplePhotoStreams.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\APSDaemon]

"key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="APSDaemon"

"hkey"="HKLM"

"command"="\"C:\\Program Files (x86)\\Common Files\\Apple\\Apple Application Support\\APSDaemon.exe\""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ASUS Screen Saver Protector]

"command"="C:\\Windows\\AsScrPro.exe"

"hkey"="HKLM"

"item"="ASUS Screen Saver Protector"

"key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\AthBtTray]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="AthBtTray"

"hkey"="HKLM"

"command"="\"C:\\Program Files (x86)\\Atheros\\Bluetooth Suite\\AthBtTray.exe\""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\AtherosBtStack]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="AtherosBtStack"

"hkey"="HKLM"

"command"="\"C:\\Program Files (x86)\\Atheros\\Bluetooth Suite\\BtvStack.exe\""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\BCSSync]

"key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="BCSSync"

"hkey"="HKLM"

"command"="\"C:\\Program Files (x86)\\Microsoft Office\\Office14\\BCSSync.exe\" /DelayServices"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\CLMLServer]

"command"="\"C:\\Program Files (x86)\\CyberLink\\Power2Go\\CLMLSvc.exe\""

"hkey"="HKLM"

"item"="CLMLServer"

"key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\com.apple.dav.bookmarks.daemon]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="com.apple.dav.bookmarks.daemon"

"hkey"="HKCU"

"command"="C:\\Program Files (x86)\\Common Files\\Apple\\Internet Services\\BookmarkDAV_client.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\iCloudServices]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="iCloudServices"

"hkey"="HKCU"

"command"="C:\\Program Files (x86)\\Common Files\\Apple\\Internet Services\\iCloudServices.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\iTunesHelper]

"key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="iTunesHelper"

"hkey"="HKLM"

"command"="\"C:\\Program Files (x86)\\iTunes\\iTunesHelper.exe\""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\msnmsgr]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="msnmsgr"

"hkey"="HKCU"

"command"="\"C:\\Program Files (x86)\\Windows Live\\Messenger\\msnmsgr.exe\" /background"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\QuickTime Task]

"key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="QuickTime Task"

"hkey"="HKLM"

"command"="\"C:\\Program Files (x86)\\QuickTime\\QTTask.exe\" -atboottime"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\RemoteControl10]

"key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="RemoteControl10"

"hkey"="HKLM"

"command"="\"C:\\Program Files (x86)\\Cyberlink\\PowerDVD10\\PDVD10Serv.exe\""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\RtHDVCpl]

"command"="C:\\Program Files\\Realtek\\Audio\\HDA\\RAVCpl64.exe -s"

"hkey"="HKLM"

"item"="RtHDVCpl"

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Setwallpaper]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="Setwallpaper"

"hkey"="HKLM"

"command"="c:\\programdata\\SetWallpaper.cmd"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\SonicMasterTray]

"key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="SonicMasterTray"

"hkey"="HKLM"

"command"="C:\\Program Files (x86)\\ASUS\\SonicMaster\\SonicMasterTray.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\UpdateLBPShortCut]

"key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="UpdateLBPShortCut"

"hkey"="HKLM"

"command"="\"C:\\Program Files (x86)\\CyberLink\\LabelPrint\\MUITransfer\\MUIStartMenu.exe\" \"C:\\Program Files (x86)\\CyberLink\\LabelPrint\" UpdateWithCreateOnce \"Software\\CyberLink\\LabelPrint\\2.5\""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\UpdateP2GoShortCut]

"key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="UpdateP2GoShortCut"

"hkey"="HKLM"

"command"="\"C:\\Program Files (x86)\\CyberLink\\Power2Go\\MUITransfer\\MUIStartMenu.exe\" \"C:\\Program Files (x86)\\CyberLink\\Power2Go\" UpdateWithCreateOnce \"SOFTWARE\\CyberLink\\Power2Go\\6.0\""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\UpdatePSTShortCut]

"key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="UpdatePSTShortCut"

"hkey"="HKLM"

"command"="\"C:\\Program Files (x86)\\Cyberlink\\DVD Suite\\MUITransfer\\MUIStartMenu.exe\" \"C:\\Program Files (x86)\\Cyberlink\\DVD Suite\" UpdateWithCreateOnce \"Software\\CyberLink\\PowerStarter\""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^AsusVibeLauncher.lnk]

"path"="C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\AsusVibeLauncher.lnk"

"backup"="C:\\Windows\\pss\\AsusVibeLauncher.lnk.CommonStartup"

"backupExtension"=".CommonStartup"

"command"="C:\\PROGRA~2\\ASUS\\AsusVibe\\ASUSVI~2.EXE /start"

"item"="AsusVibeLauncher"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^FancyStart daemon.lnk]

"path"="C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\FancyStart daemon.lnk"

"backup"="C:\\Windows\\pss\\FancyStart daemon.lnk.CommonStartup"

"backupExtension"=".CommonStartup"

"command"="C:\\Windows\\Installer\\{2B81872B-A054-48DA-BE3B-FA5C164C303A}\\_C4A2FC3E3722966204FDD8.exe -d"

"item"="FancyStart daemon"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Users^Koos^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OneNote 2010 Schermopname en Snel starten.lnk]

"path"="C:\\Users\\Koos\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\OneNote 2010 Schermopname en Snel starten.lnk"

"backup"="C:\\Windows\\pss\\OneNote 2010 Schermopname en Snel starten.lnk.Startup"

"backupExtension"=".Startup"

"command"="C:\\PROGRA~2\\MICROS~1\\Office14\\ONENOTEM.EXE /tsr"

"item"="OneNote 2010 Schermopname en Snel starten"

==== Startup Folders ======================

2012-10-19 14:29:31 1056 ----a-w- C:\users\Koos\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk

==== Task Scheduler Jobs ======================

C:\Windows\tasks\GoogleUpdateTaskMachineCore.job --a------ C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [13-04-2011 03:33]

C:\Windows\tasks\GoogleUpdateTaskMachineUA.job --a------ C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [13-04-2011 03:33]

==== Firefox Extensions ======================

ProfilePath: C:\Users\Koos\AppData\Roaming\Mozilla\Firefox\Profiles\li59hz2c.default

- Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}

- Torrent Handler - %ProfilePath%\extensions\TorrentHandler@TorrentHandler.com.xpi

AppDir: C:\Program Files (x86)\Mozilla Firefox

- Default - %AppDir%\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

- Java Console - %AppDir%\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}

==== Firefox Plugins ======================

Profilepath: C:\Users\Koos\AppData\Roaming\Mozilla\Firefox\Profiles\li59hz2c.default

7A1E2AF50DDCDD49C114C1099DBEF6E1 - C:\Windows\SysWOW64\npDeployJava1.dll - Java Deployment Toolkit 7.0.50.255

B16EC84E06F26B8B85800F3B07B8D757 - C:\Windows\system32\Macromed\Flash\NPSWF32.dll - Shockwave Flash

15E298B5EC5B89C5994A59863969D9FF - C:\Windows\SysWOW64\npmproxy.dll - Microsoft® Windows® Operating System

==== Chrome Look ======================

HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions

cjofdnhdkbflacojpfpkchgafjahijbb - C:\Users\Koos\AppData\Local\CRE\cjofdnhdkbflacojpfpkchgafjahijbb.crx[]

hphibigbodkkohoglgfkddblldpfohjl - C:\Program Files (x86)\TorrentHandler\TorrentHandler.crx[04-10-2012 16:57]

mkfokfffehpeedafpekjeddnmnjhmcmk - C:\Program Files (x86)\Norton 360\Engine\20.3.0.36\Exts\Chrome.crx[14-02-2013 04:02]

pmlghpafmmnmmkjdhacccolfgnkiboco - C:\Program Files (x86)\1ClickDownload\oneclickdownloader11.crx[]

HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\Extensions

cjofdnhdkbflacojpfpkchgafjahijbb - C:\Users\Koos\AppData\Local\CRE\cjofdnhdkbflacojpfpkchgafjahijbb.crx[]

==== Set IE to Default ======================

Old Values:

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]

"Start Page"="Google"

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]

"DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}] not found

New Values:

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]

"Start Page"="Google"

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]

"DefaultScope"="{6A1806CD-94D4-4689-BA73-E35EA1EA9990}"

==== All HKCU SearchScopes ======================

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes

{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="{searchTerms} - Bing"

{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="{searchTerms} - Google Search}"

==== Reset Google Chrome ======================

Nothing found to reset

==== Deleting CLSID Registry Keys ======================

HKEY_USERS\S-1-5-21-3766946001-305601837-3760299784-1002\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C84D72FE-E17D-4195-BB24-76C02E2E7C4E} deleted successfully

HKEY_USERS\S-1-5-21-3766946001-305601837-3760299784-1002\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{C84D72FE-E17D-4195-BB24-76C02E2E7C4E} deleted successfully

HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{C84D72FE-E17D-4195-BB24-76C02E2E7C4E} deleted successfully

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C84D72FE-E17D-4195-BB24-76C02E2E7C4E} deleted successfully

==== Deleting CLSID Registry Values ======================

==== shortcuts on Users Desktops ======================

C:\Users\Koos\Desktop\HiJackThis.lnk - C:\Users\Koos\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe

==== shortcuts on All Users Desktop ======================

C:\Users\Public\Desktop\Skype.lnk - C:\Windows\Installer\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}\SkypeIcon.exe

C:\Users\Public\Desktop\SolidWorks 2012 x64 Edition.lnk - C:\Windows\Installer\{4C66F076-D3AB-49C8-85D4-BAA6D82FCAE2}\i386_SldWorks.exe

C:\Users\Public\Desktop\SolidWorks eDrawings 2012 x64 Edition.lnk - C:\Program Files (x86)\SolidWorks Corp\SolidWorks eDrawings\EModelViewer.exe

==== shortcuts in Users Start Menu ======================

C:\Users\Koos\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HiJackThis\HiJackThis.lnk - C:\Users\Koos\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe

==== shortcuts in All Users Start Menu ======================

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office Visio 2007.lnk - C:\Windows\Installer\{90120000-0051-0000-0000-0000000FF1CE}\visicon.exe

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office Tools\Digital Certificate for VBA Projects.lnk - C:\Windows\Installer\{90120000-0051-0000-0000-0000000FF1CE}\misc.exe

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office Tools\Microsoft Clip Organizer.lnk - C:\Windows\Installer\{90120000-0051-0000-0000-0000000FF1CE}\cagicon.exe

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office Tools\Microsoft Office 2007 Language Settings.lnk - C:\Windows\Installer\{90120000-0051-0000-0000-0000000FF1CE}\misc.exe

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office Tools\Microsoft Office Diagnostics.lnk - C:\Windows\Installer\{90120000-0051-0000-0000-0000000FF1CE}\misc.exe

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office Tools\Microsoft Office Picture Manager.lnk - C:\Windows\Installer\{90120000-0051-0000-0000-0000000FF1CE}\oisicon.exe

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton 360 Premier Edition\LiveUpdate.lnk - C:\Program Files (x86)\Norton 360\Engine64\20.3.0.36\uistub.exe /lu

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton 360 Premier Edition\NBRT.lnk -

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton 360 Premier Edition\Norton 360.lnk - C:\Program Files (x86)\Norton 360\Engine64\20.3.0.36\uistub.exe

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton 360 Premier Edition\Support.lnk - C:\Program Files (x86)\Norton 360\Engine\20.3.0.36\symerr.exe /support

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton 360 Premier Edition\Uninstall Norton 360.lnk - C:\Program Files (x86)\NortonInstaller\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360\A5E82D02\20.3.0.36\inststub.exe /X /shortcut

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype\Skype.lnk - C:\Program Files (x86)\Skype\Phone\Skype.exe

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SolidWorks 2012\SolidWorks 2012 x64 Edition.lnk - C:\Windows\Installer\{4C66F076-D3AB-49C8-85D4-BAA6D82FCAE2}\i386_SldWorks.exe

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SolidWorks 2012\SolidWorks eDrawings 2012 x64 Edition.lnk - C:\Program Files (x86)\SolidWorks Corp\SolidWorks eDrawings\EModelViewer.exe

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SolidWorks 2012\SolidWorks Tools\Copy Settings Wizard.lnk - C:\Windows\Installer\{4C66F076-D3AB-49C8-85D4-BAA6D82FCAE2}\CopyOptWiz_6FEB7F8E7C4D4368B04FF4F6C1DAEF89.exe

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SolidWorks 2012\SolidWorks Tools\Property Tab Builder.lnk - C:\Windows\Installer\{4C66F076-D3AB-49C8-85D4-BAA6D82FCAE2}\PropertyTabBuilder_1F40E9F3993E4F02B14BAC3E685DC9D3.exe

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SolidWorks 2012\SolidWorks Tools\SolidNetWork License Manager.lnk - C:\Windows\Installer\{4C66F076-D3AB-49C8-85D4-BAA6D82FCAE2}\swlmwizard_6FEB7F8E7C4D4368B04FF4F6C1DAEF89.exe

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SolidWorks 2012\SolidWorks Tools\SolidWorks Network Monitor.lnk - C:\Windows\Installer\{4C66F076-D3AB-49C8-85D4-BAA6D82FCAE2}\NewShortcut5_0A376A8BDA3444DD9104346D6C513663.exe

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SolidWorks 2012\SolidWorks Tools\SolidWorks Performance Test.lnk - C:\Windows\Installer\{4C66F076-D3AB-49C8-85D4-BAA6D82FCAE2}\NewShortcut8_5A81956D53B84FDF978DC28E95329263.exe "-bm"

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SolidWorks 2012\SolidWorks Tools\SolidWorks Rx.lnk - C:\Windows\Installer\{4C66F076-D3AB-49C8-85D4-BAA6D82FCAE2}\i386_SldRxexe_6FEB7F8E7C4D4368B04FF4F6C1DAEF89.exe

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SolidWorks 2012\SolidWorks Tools\SolidWorks Task Scheduler.lnk - C:\Windows\Installer\{4C66F076-D3AB-49C8-85D4-BAA6D82FCAE2}\i386_SwScheduler_6FEB7F8E7C4D4368B04FF4F6C1DAEF89.exe

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SolidWorks 2012\SolidWorks Tools\Toolbox Settings.lnk - C:\Windows\Installer\{4C66F076-D3AB-49C8-85D4-BAA6D82FCAE2}\SldToolboxConfigur_440C95F65D9047DDB7E9A64881DF8F30.exe

==== shortcuts in Quick Launch ======================

C:\Users\Koos\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\SolidWorks 2012 x64 Edition.lnk - C:\Windows\Installer\{4C66F076-D3AB-49C8-85D4-BAA6D82FCAE2}\i386_SldWorks.exe

==== Reset IE Proxy ======================

Value(s) before fix:

"ProxyOverride"="*.local"

"ProxyEnable"=dword:00000000

Value(s) after fix:

"ProxyEnable"=dword:00000000

==== Deleting Registry Keys ======================

HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\cjofdnhdkbflacojpfpkchgafjahijbb deleted successfully

HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\pmlghpafmmnmmkjdhacccolfgnkiboco deleted successfully

HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\Extensions\cjofdnhdkbflacojpfpkchgafjahijbb deleted successfully

==== Empty IE Cache ======================

C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

C:\Users\Koos\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully

C:\Users\Koos\AppData\Local\Temp\Low\Temporary Internet Files\Content.IE5 emptied successfully

C:\Users\Koos\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully

C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

C:\Windows\serviceprofiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

C:\Users\Koos\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DQKKITYP will be deleted at reboot

C:\Users\Koos\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\W3H4JSCU will be deleted at reboot

C:\Users\Koos\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot

==== Empty FireFox Cache ======================

C:\users\Koos\AppData\Local\Mozilla\Firefox\Profiles\li59hz2c.default\Cache emptied successfully

==== Empty Chrome Cache ======================

No Chrome Cache found

==== Empty All Flash Cache ======================

Flash Cache Emptied Successfully

==== Empty All Java Cache ======================

Java Cache cleared successfully

After Reboot

==== Empty Temp Folders ======================

C:\Windows\Temp successfully emptied

C:\Users\Koos\AppData\Local\Temp successfully emptied

==== Empty Recycle Bin ======================

C:\$RECYCLE.BIN successfully emptied

==== Deleting Files / Folders ======================

"C:\Users\Koos\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not deleted

"C:\Users\Koos\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DQKKITYP" not found

"C:\Users\Koos\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\W3H4JSCU" deleted

aangepast door kape
dubbel log verwijderd
Link naar reactie
Delen op andere sites

Je Java software is verouderd.

Oudere versies hebben lekken die malware de kans geeft om zich te installeren op je systeem.

Ga naar Java SE 7 en download daar de juiste Java versie naar uw bureaublad, 32 of 64 bit. Voor 32 bit download je Windows x86, voor 64 bit download je Windows x64.

  • Sluit alle programma's die eventueel open zijn - Zeker je web browser!
  • Ga dan naar Start > Configuratiescherm > Software en verwijder alle oudere versies van Java uit de Softwarelijst.
  • Vink alles aan met Java Runtime Environment (JRE of J2SE of JAVA) in de naam.
  • Klik dan op Verwijderen of op de Wijzig/Verwijder knop.
  • Herhaal dit tot alle oudere versies verdwenen zijn.
  • Na het verwijderen van alle oudere versies, herstart je pc.
  • Dubbelklik vervolgens op jre-7-windows-x64 / x86 op je Bureaublad om de nieuwste versie van Java te installeren.

Link naar reactie
Delen op andere sites

hij crasht nog steeds. dus nu moet ik hetgeen wat kape heeft gepost even doen neem ik aan.

en ik probeer alles van Java te verwijderen maar ik krijg er 1 niet uit heb meerdere malen op verwijderen gedrukt en de pc opnieuw opgestart maar hij blijft er gewoon in staan

Link naar reactie
Delen op andere sites


×
×
  • Nieuwe aanmaken...

Belangrijke informatie

We hebben cookies geplaatst op je toestel om deze website voor jou beter te kunnen maken. Je kunt de cookie instellingen aanpassen, anders gaan we er van uit dat het goed is om verder te gaan.