Ga naar inhoud

opstarten programma's trager dan gewoonlijk


Aanbevolen berichten

Download zoek.exe naar het bureaublad.

  • Schakel je antivirus- en antispywareprogramma's uit, mogelijk kunnen ze conflicteren met zoek.exe
    (hier of hier) kan je lezen hoe je dat doet.
  • Dubbelklik op Zoek.exe om de tool te starten.
  • Windows Vista, 7 en 8 gebruikers dienen de tool als "administrator" uit te voeren door middel van de rechtermuisknop en kiezen voor Als Administrator uitvoeren.
  • Kopieer nu onderstaande code en plak die in het grote invulvenster:
  • Note: Dit script is speciaal bedoeld voor deze PC, gebruik dit dan ook niet op andere PC's met een gelijkaardig probleem.

 
startupall; 
filesrcm; 
uninstall-list; 

  • Klik op de knop "Options" en vink nu de onderstaande opties aan.

    • Running processes
    • Installed Programs
    • HijackThis Log
    • System Specs
    • Silent Runners
    • Firefox Defaults
    • Reset Chrome
    • Reset IE proxy
    • Reset Hosts
    • Auto Clean

    [*] Klik daarna op de knop "Run script".

    [*] Wacht nu geduldig af tot er een logje opent (dit kan na een herstart zijn als deze benodigd is).

    [*] Mocht na de herstart geen logje verschijnen, start zoek.exe dan opnieuw, de log verschijnt dan alsnog.

    [*] Post nu de inhoud van het geopende logje in het volgende bericht.

Link naar reactie
Delen op andere sites

Geplaatst: (aangepast)

Zoek.exe Version 4.0.0.2 Updated 06-May-2013

Tool run by rwema on do 09/05/2013 at 21:57:51,22.

Microsoft® Windows Vista™ Home Premium 6.0.6002 Service Pack 2 x64

Running in: Normal Mode Internet Access Detected

==== Running Processes ======================

C:\Windows\system32\csrss.exe

C:\Windows\system32\wininit.exe

C:\Windows\system32\csrss.exe

C:\Windows\system32\services.exe

C:\Windows\system32\lsass.exe

C:\Windows\system32\lsm.exe

C:\Windows\system32\winlogon.exe

C:\Windows\system32\svchost.exe -k DcomLaunch

C:\Windows\system32\svchost.exe -k rpcss

C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted

C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted

C:\Windows\system32\svchost.exe -k netsvcs

C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_15f4e438\STacSV64.exe

C:\Windows\system32\svchost.exe -k GPSvcGroup

C:\Windows\system32\SLsvc.exe

C:\Windows\system32\svchost.exe -k LocalService

C:\Windows\system32\svchost.exe -k NetworkService

C:\Windows\System32\WLTRYSVC.EXE

C:\Windows\System32\bcmwltry.exe

C:\Program Files\AVAST Software\Avast\AvastSvc.exe

C:\Windows\system32\WLANExt.exe

C:\Windows\System32\spoolsv.exe

C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork

C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe

C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_15f4e438\AESTSr64.exe

C:\Program Files (x86)\Nero\Update\NASvc.exe

C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted

C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe

C:\Windows\system32\svchost.exe -k imgsvc

C:\Windows\System32\svchost.exe -k WerSvcGroup

C:\Windows\system32\SearchIndexer.exe

C:\Windows\system32\taskeng.exe

C:\Windows\system32\Dwm.exe

C:\Windows\Explorer.EXE

C:\Windows\system32\taskeng.exe

C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

C:\Windows\PixArt\Pac207\Monitor.exe

C:\Windows\System32\WLTRAY.EXE

C:\Windows\System32\igfxtray.exe

C:\Windows\System32\igfxpers.exe

C:\Windows\System32\wpcumi.exe

C:\Program Files\Windows Sidebar\sidebar.exe

C:\Windows\ehome\ehtray.exe

C:\Windows\system32\igfxsrvc.exe

C:\Program Files (x86)\Ulead Systems\Ulead Photo Explorer 7.0\Monitor.exe

C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe

C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell.exe

C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe

C:\Program Files\AVAST Software\Avast\AvastUI.exe

C:\Windows\ehome\ehmsas.exe

C:\Windows\system32\wbem\wmiprvse.exe

C:\Program Files\Synaptics\SynTP\SynTPHelper.exe

C:\Windows\system32\wbem\unsecapp.exe

C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation

C:\Program Files\Windows Media Player\wmpnetwk.exe

C:\Windows\system32\wuauclt.exe

C:\Users\rwema\Downloads\zoek.exe

C:\Windows\SysWOW64\conime.exe

C:\Windows\system32\wbem\wmiprvse.exe

==== Reset Hosts File ======================

# Copyright © 1993-2006 Microsoft Corp.

#

# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.

#

# This file contains the mappings of IP addresses to host names. Each

# entry should be kept on an individual line. The IP address should

# be placed in the first column followed by the corresponding host name.

# The IP address and the host name should be separated by at least one

# space.

#

# Additionally, comments (such as these) may be inserted on individual

# lines or following the machine name denoted by a '#' symbol.

#

# For example:

#

# 102.54.94.97 rhino.acme.com # source server

# 38.25.63.10 x.acme.com # x client host

127.0.0.1 localhost

::1 localhost

==== Deleting CLSID Registry Keys ======================

HKEY_USERS\S-1-5-21-3916401253-1491523390-1999398694-1000\Software\Microsoft\Internet Explorer\SearchScopes\{4EA3530E-2812-47CE-8711-198817838C18} deleted successfully

HKEY_USERS\S-1-5-21-3916401253-1491523390-1999398694-1000\Software\Microsoft\Internet Explorer\SearchScopes\{AAAD3490-D972-4ECF-8487-DBAE9FECFCFD} deleted successfully

HKEY_USERS\S-1-5-21-3916401253-1491523390-1999398694-1000\Software\Microsoft\Internet Explorer\SearchScopes\{E67A2456-43CB-49B3-A147-6FB8A1E71F7C} deleted successfully

==== Deleting CLSID Registry Values ======================

==== Installed Programs ======================

æTorrent

Acrobat.com

Adobe AIR

Adobe Flash Player 11 Plugin

Adobe Reader X (10.1.6) - Nederlands

Adobe Shockwave Player 12.0

Advanced Audio FX Engine

avast Free Antivirus

Banctec Service Agreement

CCleaner

Cisco EAP-FAST Module

Cisco LEAP Module

Cisco PEAP Module

CPUID CPU-Z 1.52.2

DAEMON Tools Pro

Dell Edoc Viewer

Dell Getting Started Guide

Dell Touchpad

Dell Video Chat

Dell Webcam Central

Dell Wireless WLAN Card Utility

DVD Flick 1.3.0.7

Feedback Tool

Free MP3 Cutter 1.01

Google Chrome

Google Update Helper

GoogleÿEarth

GTA San Andreas

GTA2

High-Definition Video Playback

HiJackThis

Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)

Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)

HyperCam 3

Integrated Webcam Driver (1.02.02.0106)

Intel® Graphics Media Accelerator Driver

Java 7 (64-bit)

K-Lite Codec Pack 9.6.5 (Full)

League of Legends

LibreOffice 3.6

Malwarebytes Anti-Malware versie 1.75.0.1300

Microsoft .NET Framework 1.1

Microsoft .NET Framework 1.1 Security Update (KB2656353)

Microsoft .NET Framework 1.1 Security Update (KB2656370)

Microsoft .NET Framework 1.1 Security Update (KB979906)

Microsoft .NET Framework 3.5 SP1

Microsoft .NET Framework 4 Client Profile

Microsoft .NET Framework 4 Client Profile NLD Language Pack

Microsoft .NET Framework 4 Extended

Microsoft .NET Framework 4 Extended NLD Language Pack

Microsoft Office File Validation Add-In

Microsoft Office Outlook Connector

Microsoft Office Professional Edition 2003

Microsoft Search Enhancement Pack

Microsoft Silverlight

Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053

Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053

Microsoft Visual C++ 2005 Redistributable

Microsoft Visual C++ 2005 Redistributable (x64) - KB2467175

Microsoft Visual C++ 2005 Redistributable (x64)

Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148

Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570

Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570

Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17

Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161

Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219

Microsoft Works

Mozilla Maintenance Service

Nero 11

Nero 11 Disc Menus Basic

Nero 11 Effects Basic

Nero 11 Image Samples

Nero 11 Kwik Themes Basic

Nero 11 PiP Effects Basic

Nero Audio Pack 1

Nero BackItUp 11

Nero BackItUp 11 Help (CHM)

Nero Backup Drivers

Nero Burning ROM 11

Nero Burning ROM 11 Help (CHM)

Nero ControlCenter 11

Nero ControlCenter 11 Help (CHM)

Nero Core Components 11

Nero CoverDesigner 11

Nero CoverDesigner 11 Help (CHM)

Nero Express 11

Nero Express 11 Help (CHM)

Nero Kwik Media

Nero Kwik Media Help (CHM)

Nero Recode 11

Nero Recode 11 Help (CHM)

Nero RescueAgent 11

Nero RescueAgent 11 Help (CHM)

Nero SharedVideoCodecs

Nero SoundTrax 11

Nero SoundTrax 11 Help (CHM)

Nero Update

Nero Video 11

Nero Video 11 Help (CHM)

Nero WaveEditor 11

Nero WaveEditor 11 Help (CHM)

nero.prerequisites.msi

NVIDIA PhysX

Opera 12.15

Paint.NET v3.5.10

PowerDVD

Quickset

Razer Game Booster

RealPlayer

RealUpgrade 1.0

RollerCoaster Tycoon 2

Security Update for Microsoft .NET Framework 3.5 SP1 (KB2604111)

Security Update for Microsoft .NET Framework 3.5 SP1 (KB2657424)

Security Update for Microsoft .NET Framework 3.5 SP1 (KB2736416)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2160841)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2729449)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2736428)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2737019)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2742595)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2789642)

Security Update for Microsoft .NET Framework 4 Extended (KB2487367)

Security Update for Microsoft .NET Framework 4 Extended (KB2656351)

Security Update for Microsoft .NET Framework 4 Extended (KB2736428)

Security Update for Microsoft .NET Framework 4 Extended (KB2742595)

Skype Click to Call

Speccy

swMSM

Taalpakket voor Microsoft .NET Framework 4 Client Profile - NLD

Taalpakket voor Microsoft .NET Framework 4 Extended - NLD

Ulead Photo Explorer 7.0 SE

Update for Microsoft .NET Framework 3.5 SP1 (KB963707)

Update for Microsoft .NET Framework 4 Client Profile (KB2468871)

Update for Microsoft .NET Framework 4 Client Profile (KB2533523)

Update for Microsoft .NET Framework 4 Client Profile (KB2600217)

Update for Microsoft .NET Framework 4 Extended (KB2468871)

Update for Microsoft .NET Framework 4 Extended (KB2533523)

Update for Microsoft .NET Framework 4 Extended (KB2600217)

Visual C++ 2008 x86 Runtime - (v9.0.30729)

Visual C++ 2008 x86 Runtime - v9.0.30729.01

Visual C++ 8.0 Runtime Setup Package (x64)

VLC media player 2.0.2

Welcome App (Start-up experience)

Winamp

Windows Live Mesh - ActiveX-besturingselement voor externe verbindingen

Windows Live Mesh ActiveX Control for Remote Connections

Windows Live Sync

Windows Media Player Firefox Plugin

WinRAR 4.01 (32-bit)

==== FireFox Fix ======================

Deleted from C:\Users\rwema\AppData\Roaming\Mozilla\Firefox\Profiles\38l0tsrw.Standaardgebruiker\prefs.js:

user_pref("browser.startup.homepage", "about:home");

user_pref("browser.newtab.url", "about:newtab");

Added to C:\Users\rwema\AppData\Roaming\Mozilla\Firefox\Profiles\38l0tsrw.Standaardgebruiker\prefs.js:

user_pref("browser.startup.homepage", "http://www.google.com");

user_pref("browser.search.defaulturl", "http://www.google.com/search?btnG=Google+Search&q=");

user_pref("browser.newtab.url", "http://www.google.com/");

user_pref("browser.search.defaultengine", "Google");

user_pref("browser.search.defaultenginename", "Google");

user_pref("browser.search.selectedEngine", "Google");

user_pref("browser.search.order.1", "Google");

user_pref("keyword.URL", "http://www.google.com/search?btnG=Google+Search&q=");

user_pref("browser.search.suggest.enabled", true);

user_pref("browser.search.useDBForOrder", true);

ProfilePath: C:\Users\rwema\AppData\Roaming\Mozilla\Firefox\Profiles\38l0tsrw.Standaardgebruiker

user.js not found

---- Lines 33e0daa6-3af3-d8b5-6752-10e949c61516 removed from prefs.js ----

---- Lines 33e0daa6-3af3-d8b5-6752-10e949c61516 modified from prefs.js ----

---- Lines 1FD91A9C-410C-4090-BBCC-55D3450EF433 removed from prefs.js ----

---- Lines 1FD91A9C-410C-4090-BBCC-55D3450EF433 modified from prefs.js ----

user_pref("extensions.installCache", "[{\"name\":\"winreg-app-global\",\"addons\":{\"{20a82645-c095-46ed-80e3-08825760534b}\":{\"descriptor\":\"c:\\\\Windows\\\\Microsoft.NET\\\\Framework\\\\v3.5\\\\Windows Presentation Foundation\\\\DotNetAssistantExtension\",\"mtime\":1250961781223},\"{ABDE892B-13A8-4d1b-88E6-365A6E755758}\":{\"descriptor\":\"C:\\\\ProgramData\\\\Real\\\\RealPlayer\\\\BrowserRecordPlugin\\\\Firefox\\\\Ext\",\"mtime\":1279385194290},\"wrc@avast.com\":{\"descriptor\":\"C:\\\\Program Files\\\\AVAST Software\\\\Avast\\\\WebRep\\\\FF\",\"mtime\":1345929712758}}},{\"name\":\"app-global\",\"addons\":{\"{1FD91A9C-410C-4090-BBCC-55D3450EF433}\":{\"descriptor\":\"C:\\\\Program Files (x86)\\\\Windows iLivid Toolbar\\\\Datamngr\\\\FirefoxExtension\",\"mtime\":1324149852926},\"{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}\":{\"descriptor\":\"C:\\\\Program Files (x86)\\\\Mozilla Firefox\\\\extensions\\\\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}\",\"mtime\":1319752886293},\"{972ce4c6-7e08-4474-a285-3208198ce6fd}\":{\"descriptor\":\"C:\\\\Program Files (x86)\\\\Mozilla Firefox\\\\extensions\\\\{972ce4c6-7e08-4474-a285-3208198ce6fd}\",\"mtime\":1350774361752}}}]");

---- FireFox user.js and prefs.js backups ----

prefs_20130905_2308_.backup

==== Deleting Files \ Folders ======================

"C:\Users\rwema\AppData\Roaming\Mozilla\Extensions\{1FD91A9C-410C-4090-BBCC-55D3450EF433}" deleted

"C:\Program Files (x86)\Mozilla Firefox\extensions\{1FD91A9C-410C-4090-BBCC-55D3450EF433}" deleted

"C:\Users\rwema\AppData\Local\Google\Chrome\User Data\Default\BrowserMngrPreferences" deleted

"C:\Windows\Launcher.exe" deleted

"C:\Program Files (x86)\AutocompletePro" deleted

"C:\Program Files (x86)\NCH_EN" deleted

"C:\Program Files (x86)\Babylon" deleted

"C:\Program Files (x86)\myBabylon_English" deleted

"C:\Program Files (x86)\DVDVideoSoftTB" deleted

"C:\Program Files (x86)\uTorrentBar_NL" deleted

"C:\Program Files (x86)\Windows iLivid Toolbar" deleted

"C:\Program Files (x86)\Protected Search" deleted

"C:\Program Files (x86)\mixidj" deleted

"C:\Program Files (x86)\OApps" deleted

"C:\Program Files (x86)\Conduit" deleted

"C:\Program Files (x86)\ConduitEngine" deleted

"C:\ProgramData\boost_interprocess" deleted

"C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Protected Search" deleted

"C:\Users\rwema\AppData\Local\CRE" deleted

"C:\Users\rwema\AppData\LocalLow\DataMngr" deleted

"C:\Windows\SysWow64\searchplugins" deleted

"C:\Windows\SysWow64\Extensions" deleted

"C:\Users\rwema\AppData\Roaming\Mozilla\Firefox\Profiles\38l0tsrw.Standaardgebruiker\extensions\{33e0daa6-3af3-d8b5-6752-10e949c61516}" deleted

==== System Specs ======================

Windows: Windows Vista Home Premium Edition (64-bit) Service Pack 2 (Build 6002)

Internet Explorer: 9.0.8112.16421

Memory (RAM): 4054 MB

CPU Info: Intel® Core2 Duo CPU T6500 @ 2.10GHz

CPU Speed: 1263,4 MHz

Sound Card: Speakers / Headphones (IDT High |

Independent (R.T.C.) Headphones |

Display Adapters: Mobile Intel® 4 Series Express Chipset Family | Mobile Intel® 4 Series Express Chipset Family | RDPDD Chained DD | RDP Encoder Mirror Driver

Monitors: 1x; Generic PnP Monitor |

Screen Resolution: 1366 X 768 - 32 bit

Network: Network Present

Network Adapters: Dell Wireless 1397 WLAN Mini-Card | Broadcom NetLink Gigabit Ethernet

CD / DVD Drives: 2x (E: | F: | ) E: TSSTcorpDVD+-RW TS-T633A | F: DTSOFT BDROM

Ports: COM Ports NOT Present. LPT Port NOT Present.

Mouse: 5 Button Wheel Mouse Present

Hard Disks: C: 283,4GB | D: 14,6GB

Hard Disks - Free: C: 61,8GB | D: 7,8GB

Manufacturer *: Dell Inc.

BIOS Info: AT/AT COMPATIBLE | 04/23/09 | DELL - 6040000

Time Zone: West-Europa (standaardtijd)

Motherboard *: Dell Inc. 0D176M

Sun Java version: niet

Sun Java version: opdracht,

Country: Belgi‰

Language: NLB

==== Files Recently Created / Modified ======================

====== C:\Windows ====

2013-05-09 01:02:43 BC2337716A473568ACF3CF60A4C5D7EC 28156 ----a-w- C:\Windows\SDB7DE2.tmp

2013-05-09 01:02:37 E1201299C5B5E986184C15D1CE614A7A 2332 ----a-w- C:\Windows\MAN65FC.tmp

2013-05-09 01:02:37 C83125DABB93A0EFAE2D73368B6C5EFC 1472 ----a-w- C:\Windows\VWL665B.tmp

2013-05-09 01:02:37 74F5F65F602B2FA3C94FC1C2F53DC066 51450204 ----a-w- C:\Windows\WLF665C.tmp

2013-05-08 01:03:52 BC2337716A473568ACF3CF60A4C5D7EC 28156 ----a-w- C:\Windows\SDBB6D1.tmp

2013-05-08 01:03:47 F6B900501A46C42C20414447CEF861B8 51364710 ----a-w- C:\Windows\WLFA2B4.tmp

2013-05-08 01:03:47 5A87DBB1928B1109E666609B19185C39 2332 ----a-w- C:\Windows\MANA254.tmp

2013-05-08 01:03:47 539BD443FF5F0BD3B26C48378ABD662A 1472 ----a-w- C:\Windows\VWLA2B3.tmp

2013-05-07 00:13:15 46BA8178666CFCD0E8975DDDE9917D06 3243 ----a-w- C:\Windows\DeleteOnReboot.bat

====== C:\Users\rwema\AppData\Local\Temp ====

====== C:\Windows\SysWOW64 =====

====== C:\Windows\SysWOW64\drivers =====

====== C:\Windows\Sysnative =====

2013-05-08 16:13:51 63E4A4FF13932BFE51F209F781714313 377416 ----a-w- C:\Windows\Sysnative\FNTCACHE.DAT

====== C:\Windows\Sysnative\drivers =====

2013-05-04 16:18:55 D41D8CD98F00B204E9800998ECF8427E 0 ---ha-w- C:\Windows\Sysnative\drivers\Msft_User_WpdMtpDr_01_07_00.Wdf

2013-04-18 01:45:06 7E44C2684A6CA779B9D07CB4BD3F649D 178624 ----a-w- C:\Windows\Sysnative\drivers\aswVmm.sys

2013-04-18 01:45:05 DE6759B8D8E62BF0FFF2B05F05AFCEE6 65336 ----a-w- C:\Windows\Sysnative\drivers\aswRvrt.sys

2013-04-10 14:12:07 2ACCAA3C3C55370A32F17B3595E1A217 1513320 ----a-w- C:\Windows\Sysnative\drivers\ntfs.sys

====== C:\Windows\Tasks ======

====== C:\Windows\Temp ======

======= C:\Program Files =====

======= C:\Program Files (x86) =====

2013-05-06 22:46:06 -------- d-----w- C:\Program Files (x86)\SoftwareUpdater

2013-05-03 03:16:48 -------- d-----w- C:\Program Files (x86)\Free MP3 Cutter

2013-05-03 02:38:51 -------- d-----w- C:\Program Files (x86)\Common Files\PX Storage Engine

2013-05-03 02:38:43 -------- d-----w- C:\Program Files (x86)\Winamp

2013-04-22 15:15:05 -------- d-----w- C:\Program Files (x86)\Razer

2013-04-21 21:31:38 -------- d-----w- C:\Program Files (x86)\RaidCall

======= C: =====

====== C:\Users\rwema\AppData\Roaming ======

2013-05-07 01:23:23 -------- d-----w- C:\users\Guest\AppData\Locallow\Google

2013-05-07 01:20:26 -------- d-----w- C:\users\Guest\AppData\Local\Google

2013-05-07 01:18:36 -------- d-s---w- C:\users\Guest\AppData\Locallow\Microsoft

2013-05-07 01:17:42 -------- d-----w- C:\users\Guest\AppData\Roaming\Real

2013-05-07 01:17:42 -------- d-----w- C:\users\Guest\AppData\Local\PowerDVD DX

2013-05-07 01:16:31 BEA07E6D2B8DCE396FE21BAA61B34956 6 --sha-w- C:\users\Guest\AppData\Locallow\desktop.ini

2013-05-07 01:16:31 -------- d-----r- C:\users\Guest\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools

2013-05-07 01:15:32 -------- d-----w- C:\users\Guest\AppData\Roaming\Identities

2013-05-07 01:15:07 -------- d-----w- C:\users\Guest\AppData\Local\VirtualStore

2013-05-07 01:14:31 -------- d-sh--we C:\users\Guest\AppData\Local\Temporary Internet Files

2013-05-07 01:14:31 -------- d-sh--we C:\users\Guest\AppData\Local\Geschiedenis

2013-05-07 01:14:31 -------- d-sh--we C:\users\Guest\AppData\Local\Application Data

2013-05-07 01:14:27 -------- d-s---w- C:\users\Guest\AppData\Roaming\Microsoft

2013-05-07 01:14:27 -------- d-----w- C:\users\Guest\AppData\Roaming\Media Center Programs

2013-05-07 01:14:27 -------- d-----w- C:\users\Guest\AppData\Local\temp

2013-05-07 01:14:27 -------- d-----w- C:\users\Guest\AppData\Local\Microsoft

2013-05-07 01:14:27 -------- d-----r- C:\users\Guest\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup

2013-05-07 01:14:27 -------- d-----r- C:\users\Guest\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance

2013-05-07 01:14:27 -------- d-----r- C:\users\Guest\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories

2013-05-03 02:38:43 -------- d-----w- C:\users\rwema\AppData\Roaming\Winamp

2013-04-26 01:23:49 BC2337716A473568ACF3CF60A4C5D7EC 28156 ----a-w- C:\users\rwema\AppData\Local\SDB56B.tmp

2013-04-26 01:23:49 AA622D653C9A083D9578A8F1E26C4812 136740 ----a-w- C:\users\rwema\AppData\Local\WLF54B.tmp

2013-04-26 01:23:48 53FC4283574D646BBD8B6A1CE96096C3 1506 ----a-w- C:\users\rwema\AppData\Local\VWL54A.tmp

2013-04-26 01:23:48 030FCC6D18D5D40D88546C98427180C5 2400 ----a-w- C:\users\rwema\AppData\Local\MAN4EB.tmp

2013-04-22 17:28:27 -------- d-----w- C:\users\rwema\AppData\Roaming\LolClient

2013-04-22 15:16:17 -------- d-----w- C:\users\rwema\AppData\Local\Razer

2013-04-21 21:33:15 -------- d-----w- C:\users\rwema\AppData\Roaming\raidcall

2013-04-21 21:33:15 -------- d-----w- C:\users\rwema\AppData\Locallow\RCTW

2013-04-21 21:33:15 -------- d-----w- C:\users\rwema\AppData\Locallow\raidcall

2013-04-20 00:20:22 -------- d-----w- C:\users\rwema\AppData\Roaming\Web Page Maker

2013-04-18 02:04:00 -------- d-----w- C:\users\rwema\AppData\Local\Abelssoft

2013-04-16 18:32:12 -------- d-----w- C:\users\rwema\AppData\Local\Nero_AG

2013-04-16 18:31:52 -------- d-----w- C:\users\rwema\AppData\Local\Nero

====== C:\Users\rwema ======

2013-05-07 01:16:31 -------- d-----r- C:\Users\Guest\Searches

2013-05-07 01:15:16 -------- d-----r- C:\Users\Guest\Contacts

2013-05-07 01:14:31 6FC234AD3752E1267B34FB12BCD6718B 20 --sha-w- C:\Users\Guest\ntuser.ini

2013-05-07 01:14:31 -------- d-sh--we C:\Users\Guest\Sjablonen

2013-05-07 01:14:31 -------- d-sh--we C:\Users\Guest\SendTo

2013-05-07 01:14:31 -------- d-sh--we C:\Users\Guest\Recent

2013-05-07 01:14:31 -------- d-sh--we C:\Users\Guest\Netwerkprinteromgeving

2013-05-07 01:14:31 -------- d-sh--we C:\Users\Guest\NetHood

2013-05-07 01:14:31 -------- d-sh--we C:\Users\Guest\Mijn documenten

2013-05-07 01:14:31 -------- d-sh--we C:\Users\Guest\Menu Start

2013-05-07 01:14:31 -------- d-sh--we C:\Users\Guest\Local Settings

2013-05-07 01:14:31 -------- d-sh--we C:\Users\Guest\Cookies

2013-05-07 01:14:31 -------- d-sh--we C:\Users\Guest\Application Data

2013-05-07 01:14:27 -------- d--h--w- C:\Users\Guest\AppData

2013-05-07 01:14:27 -------- d-----r- C:\Users\Guest\Videos

2013-05-07 01:14:27 -------- d-----r- C:\Users\Guest\Saved Games

2013-05-07 01:14:27 -------- d-----r- C:\Users\Guest\Pictures

2013-05-07 01:14:27 -------- d-----r- C:\Users\Guest\Music

2013-05-07 01:14:27 -------- d-----r- C:\Users\Guest\Links

2013-05-07 01:14:27 -------- d-----r- C:\Users\Guest\Favorites

2013-05-07 01:14:27 -------- d-----r- C:\Users\Guest\Downloads

2013-05-07 01:14:27 -------- d-----r- C:\Users\Guest\Documents

2013-05-07 01:14:27 -------- d-----r- C:\Users\Guest\Desktop

2013-05-03 03:16:49 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free MP3 Cutter

2013-05-03 02:39:23 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Winamp

2013-04-24 22:14:43 -------- d-----w- C:\ProgramData\Altova

2013-04-22 16:51:08 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NewFeature1

2013-04-22 15:21:54 -------- d-----w- C:\Users\rwema\.swt

2013-04-22 15:15:22 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Razer

2013-04-22 15:15:05 -------- d-----w- C:\ProgramData\Razer

2013-04-21 21:31:49 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RaidCall

2013-04-20 22:05:28 -------- d-----w- C:\Users\rwema\Nieuwe map

2013-04-20 00:20:22 -------- d-----w- C:\ProgramData\Web Page Maker

====== C: exe-files ==

2013-05-06 22:46:20 035076B10EC9A07E15B8933E1EF589EB 231437 ----a-w- C:\Program Files (x86)\SoftwareUpdater\uninstall.exe

2013-05-06 22:44:55 4CC618BF9E6B126CE1AB24EDFBD592A0 2885968 ----a-w- C:\Users\rwema\Downloads\installer_power_mp3_cutter_5_2_Dutch.exe

2013-05-03 03:16:49 C5A0AA87AEA2D1510DD06747D01F852C 1359872 ----a-w- C:\Program Files (x86)\Free MP3 Cutter\MP3Cutter.exe

2013-05-03 03:16:48 D85A009386E94EF1ED3011337F758B13 695578 ----a-w- C:\Program Files (x86)\Free MP3 Cutter\unins000.exe

2013-05-03 03:16:25 8B72455588523BB2DF7095B744254A5A 919504 ----a-w- C:\Users\rwema\Downloads\FreeMP3Cutter.exe

2013-05-03 03:14:17 D39160AB60A14E420EBDA3C478FDF381 584600 ----a-w- C:\Users\rwema\Downloads\cbsidlm-tr1_13-Free_MP3_Cutter-ORG-75182284.exe

2013-05-03 02:39:23 B3F5F5B4637662196351ED701908EF5A 373238 ----a-w- C:\Program Files (x86)\Winamp\UninstWA.exe

2013-05-03 02:38:52 D2728A10CCD2A675638B016D47B1C254 72176 ------w- C:\Program Files (x86)\Common Files\PX Storage Engine\pxhpinst.exe

2013-05-03 02:38:52 94F95BE2A44C8291132D314582F141F8 126448 ------w- C:\Program Files (x86)\Common Files\PX Storage Engine\pxinsi64.exe

2013-05-03 02:38:52 6D3630B7F27B3643FDE05D1088F84F2F 68592 ------w- C:\Program Files (x86)\Common Files\PX Storage Engine\pxinsa64.exe

2013-05-03 02:38:52 50A76D2D5E4BE94556326C4BF748C758 123888 ------w- C:\Program Files (x86)\Common Files\PX Storage Engine\pxcpyi64.exe

2013-05-03 02:38:52 08D51E037F487F9CA9FD0B0388F4C15A 68080 ------w- C:\Program Files (x86)\Common Files\PX Storage Engine\pxcpya64.exe

2013-05-03 02:37:39 16DBCBB81C031C2FB7C217CF0DB7ADC9 17335648 ----a-w- C:\Users\rwema\Downloads\winamp563_full_emusic-7plus_all.exe

=== C: other files ==

2013-05-07 00:13:15 46BA8178666CFCD0E8975DDDE9917D06 3243 ----a-w- C:\Windows\DeleteOnReboot.bat

==== Startup Registry Enabled ======================

[HKEY_USERS\S-1-5-21-3916401253-1491523390-1999398694-1000\Software\Microsoft\Windows\CurrentVersion\Run]

"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe /autoRun"

"ehTray.exe"="C:\Windows\ehome\ehTray.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Ulead Memory Card Detector"="C:\Program Files (x86)\Ulead Systems\Ulead Photo Explorer 7.0\Monitor.exe"

"PDVDDXSrv"="C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe"

"Dell Webcam Central"="C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell.exe /mode2"

"TkBellExe"="C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe -osboot"

"avast"="C:\Program Files\AVAST Software\Avast\avastUI.exe /nogui"

"Adobe ARM"="C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]

"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe /autoRun"

"ehTray.exe"="C:\Windows\ehome\ehTray.exe"

==== Startup Registry Enabled x64 ======================

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"SysTrayApp"="%ProgramFiles%\IDT\WDM\sttray64.exe"

"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"

"Monitor"="C:\Windows\PixArt\PAC207\Monitor.exe"

"Broadcom Wireless Manager UI"="C:\Windows\system32\WLTRAY.exe"

"IgfxTray"="C:\Windows\system32\igfxtray.exe"

"HotKeysCmds"="C:\Windows\system32\hkcmd.exe"

"Persistence"="C:\Windows\system32\igfxpers.exe"

"WPCUMI"="C:\Windows\system32\WpcUmi.exe"

==== Startup Registry Disabled x64 ======================

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\DAEMON Tools Pro Agent]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="DAEMON Tools Pro Agent"

"hkey"="HKCU"

"command"="\"C:\\Program Files (x86)\\DAEMON Tools Pro\\DTAgent.exe\" -autorun"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\msnmsgr]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="msnmsgr"

"hkey"="HKCU"

"command"="\"C:\\Program Files (x86)\\Windows Live\\Messenger\\msnmsgr.exe\" /background"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\NBAgent]

"key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="NBAgent"

"hkey"="HKLM"

"command"="\"C:\\Program Files (x86)\\Nero\\Nero 11\\Nero BackItUp\\NBAgent.exe\" /WinStart"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\RaidCall]

"key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="RaidCall"

"hkey"="HKLM"

"command"="\"C:\\Program Files (x86)\\RaidCall\\raidcall.exe\""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\TomTomHOME.exe]

"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="TomTomHOME.exe"

"hkey"="HKCU"

"command"="\"C:\\Program Files (x86)\\TomTom HOME 2\\TomTomHOMERunner.exe\""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\WinampAgent]

"key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run"

"item"="WinampAgent"

"hkey"="HKLM"

"command"="\"C:\\Program Files (x86)\\Winamp\\winampa.exe\""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\avg9emc]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\avg9wd]

==== Task Scheduler Jobs ======================

C:\Windows\tasks\Adobe Flash Player Updater.job --a------ C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [19/04/2013 00:42]

C:\Windows\tasks\CheckDriveBackgroundGuard.job --a------ C:\Program Files (x86)\CheckDrive\CheckDriveBackgroundGuard.exe []

C:\Windows\tasks\GoogleUpdateTaskMachineCore.job --a------ [undertermined Task]

C:\Windows\tasks\GoogleUpdateTaskMachineUA.job --a------ C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [16/04/2010 12:29]

==== Firefox Extensions ======================

ProfilePath: C:\Users\rwema\AppData\Roaming\Mozilla\Firefox\Profiles\38l0tsrw.Standaardgebruiker

- AutocompletePro - Your handy search suggestions tool - %ProfilePath%\extensions\support@predictad.com

AppDir: C:\Program Files (x86)\Mozilla Firefox

- Skype Click to Call - %AppDir%\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}

==== Firefox Plugins ======================

Profilepath: C:\Users\rwema\AppData\Roaming\Mozilla\Firefox\Profiles\38l0tsrw.Standaardgebruiker

33E87713C7FE08C5F861E2819ED33A0E - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll - RealPlayer HTML5VideoShim Plug-In (32-bit)

AB87EEFFD18F2BAAFC274E7075EA6C67 - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll - Windows Presentation Foundation / Windows Presentation Foundation

==== Deleting Files \ Folders ======================

"Your handy search suggestions tool - C:\Users\rwema\AppData\Roaming\Mozilla\Firefox\Profiles\38l0tsrw.Standaardgebruiker\extensions\support@predictad.com" not found

"C:\Users\rwema\AppData\Roaming\Mozilla\Firefox\Profiles\38l0tsrw.Standaardgebruiker\extensions\support@predictad.com" deleted

==== Chrome Look ======================

HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions

cjofdnhdkbflacojpfpkchgafjahijbb - C:\Users\rwema\AppData\Local\Temp\ccex.crx[]

icmlaeflemplmjndnaapfdbbnpncnbda - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx[07/03/2013 00:29]

jfmjfhklogoienhpfnppmbcbjfjnkonk - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Chrome\Ext\rphtml5video.crx[17/07/2010 18:46]

jllpjckabhalgdienlngoikeehalibei - C:\Users\rwema\AppData\Local\Temp\tbch.crx[]

lifbcibllhkdhoafpjfnlhfpfgnpldfl - C:\Program Files (x86)\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx[09/04/2012 11:23]

Docs - Guest - Default\Extensions\aohghmighlieiainnegkcijnfilokake

avast WebRep - Guest - Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda

RealPlayer HTML5Video Downloader Extension - Guest - Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk

Skype Click to Call - Guest - Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl

avast WebRep - rwema - Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda

RealPlayer HTML5Video Downloader Extension - rwema - Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk

Skype Click to Call - rwema - Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl

==== Set IE to Default ======================

Old Values:

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]

"Start Page"="http://www.msn.com/"

"Start Page Restore"="http://www.google.be/"

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]

No DefaultScope Set For HKCU

New Values:

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]

"Start Page"="http://www.msn.com/"

"Start Page Restore"="http://www.msn.com/"

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]

"DefaultScope"="{6A1806CD-94D4-4689-BA73-E35EA1EA9990}"

==== All HKCU SearchScopes ======================

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes

{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC"

{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}"

==== Reset Google Chrome ======================

C:\users\Guest\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully

C:\users\rwema\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully

C:\users\Guest\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully

C:\users\rwema\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully

==== Reset IE Proxy ======================

Value(s) before fix:

"ProxyEnable"=dword:00000000

Value(s) after fix:

"ProxyEnable"=dword:00000000

==== Uninstall List x64 ======================

æTorrent [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\uTorrent]

Acrobat.com [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{77DCDCE3-2DED-62F3-8154-05E745472D07}]

Acrobat.com [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1]

Adobe AIR [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{A0087DDE-69D0-11E2-AD57-43CA6188709B}]

Adobe AIR [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Adobe AIR]

Adobe Flash Player 11 Plugin [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Adobe Flash Player Plugin]

Adobe Reader X (10.1.6) - Nederlands [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{AC76BA86-7AD7-1043-7B44-AA1000000001}]

Adobe Shockwave Player 12.0 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Adobe Shockwave Player]

Advanced Audio FX Engine [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Advanced Audio FX Engine]

avast Free Antivirus [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\avast]

Banctec Service Agreement [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{42D68A86-DB1C-4256-B8C9-5D0D92919AF5}]

CCleaner [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\CCleaner]

Cisco EAP-FAST Module [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{415B2719-AD3A-4944-B404-C472DB6085B3}]

Cisco LEAP Module [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{83770D14-21B9-44B3-8689-F7B523F94560}]

Cisco PEAP Module [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{669C7BD8-DAA2-49B6-966C-F1E2AAE6B17E}]

CPUID CPU-Z 1.52.2 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\CPUID CPU-Z_is1]

DAEMON Tools Pro [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\DAEMON Tools Pro]

Dell Edoc Viewer [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{8EBA8727-ADC2-477B-9D9A-1A1836BE4E05}]

Dell Getting Started Guide [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{7DB9F1E5-9ACB-410D-A7DC-7A3D023CE045}]

Dell Touchpad [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\SynTPDeinstKey]

Dell Video Chat [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Dell Video Chat]

Dell Webcam Central [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Dell Webcam Central]

Dell Wireless WLAN Card Utility [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\Broadcom 802.11 Application]

DVD Flick 1.3.0.7 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\DVD Flick_is1]

Feedback Tool [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{13A5E785-5197-4EAD-8EE3-D660271E49BC}]

Feedback Tool [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{90024193-9F13-4877-89D5-A1CDF0CBBF28}]

Free MP3 Cutter 1.01 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{847E0734-4457-4B48-BF49-998D1CF2CFA1}_is1]

Google Chrome [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Google Chrome]

Google Update Helper [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}]

GoogleÿEarth [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{468D22C0-8080-11E2-B86E-B8AC6F98CCE3}]

GTA San Andreas [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{D417C96A-FCC7-4590-A1BB-FAF73F5BC98E}]

GTA2 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{2987EE84-C4EE-4FF5-8160-32DE00D6ABC6}]

High-Definition Video Playback [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{9193490D-5229-4FC4-9BB9-A6D63C09574A}]

HiJackThis [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{45A66726-69BC-466B-A7A4-12FCBA4883D7}]

HyperCam 3 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\HyperCam 3]

Integrated Webcam Driver (1.02.02.0106) [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\Creative OA008]

Intel® Graphics Media Accelerator Driver [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\HDMI]

Java 7 (64-bit) [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{26A24AE4-039D-4CA4-87B4-2F86417000FF}]

K-Lite Codec Pack 9.6.5 (Full) [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\KLiteCodecPack_is1]

League of Legends [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{92606477-9366-4D3B-8AE3-6BE4B29727AB}]

LibreOffice 3.6 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{CBCF6C86-4738-4A84-9C2C-331804DCEB9B}]

Malwarebytes Anti-Malware versie 1.75.0.1300 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Malwarebytes' Anti-Malware_is1]

Microsoft .NET Framework 1.1 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}]

Microsoft .NET Framework 1.1 Security Update (KB2656353) [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\M2656353]

Microsoft .NET Framework 1.1 Security Update (KB2656370) [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\M2656370]

Microsoft .NET Framework 1.1 Security Update (KB979906) [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\M979906]

Microsoft .NET Framework 3.5 SP1 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}]

Microsoft .NET Framework 4 Client Profile [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}]

Microsoft .NET Framework 4 Client Profile NLD Language Pack [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{4567EA14-6BCA-3EF9-859B-92CE48B1D704}]

Microsoft .NET Framework 4 Extended [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{8E34682C-8118-31F1-BC4C-98CD9675E1C2}]

Microsoft .NET Framework 4 Extended NLD Language Pack [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{021B6358-4373-3FC0-A0B4-4709B7E0D3E5}]

Microsoft Office Professional Edition 2003 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{90110409-6000-11D3-8CFE-0150048383C9}]

Microsoft Search Enhancement Pack [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{CFF8B8E8-E086-4DE0-935F-FE22CAB54F80}]

Microsoft Silverlight [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}]

Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{B6E3757B-5E77-3915-866A-CCFC4B8D194C}]

Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{770657D0-A123-3C07-8E44-1C83EC895118}]

Microsoft Visual C++ 2005 Redistributable (x64) - KB2467175 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{aac9fcc4-dd9e-4add-901c-b5496a07ab2e}]

Microsoft Visual C++ 2005 Redistributable (x64) [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{071c9b48-7c32-4621-a0ac-3f809523288f}]

Microsoft Visual C++ 2005 Redistributable (x64) [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}]

Microsoft Visual C++ 2005 Redistributable [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}]

Microsoft Visual C++ 2005 Redistributable [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}]

Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{EE936C7A-EA40-31D5-9B65-8E3E089C3828}]

Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{8338783A-0968-3B85-AFC7-BAAE0A63DC50}]

Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}]

Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{8220EEFE-38CD-377E-8595-13398D740ACE}]

Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}]

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{9A25302D-30C0-39D9-BD6F-21E6EC160475}]

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}]

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{9BE518E6-ECC6-35A9-88E4-87755C07200F}]

Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}]

Microsoft Works [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}]

Mozilla Maintenance Service [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\MozillaMaintenanceService]

Nero 11 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{FC18AB8F-9BA3-423B-91F2-622990F57978}]

Nero 11 Disc Menus Basic [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{F49EF443-B2BD-4F10-8A46-87AFCDB90EDD}]

Nero 11 Effects Basic [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{E51BC4B0-EA5E-49CC-AF3B-93B5C627EC22}]

Nero 11 Image Samples [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{F3743A2C-5D5F-4456-8F98-5DF36A954C50}]

Nero 11 Kwik Themes Basic [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{5A212B2D-140D-46F4-B625-2D1CA5A00594}]

Nero 11 PiP Effects Basic [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{2CA7225D-CB12-462A-9DD1-50319E158BA5}]

Nero Audio Pack 1 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{A7A0BF2E-31CC-49E3-9913-52C503EB969D}]

Nero BackItUp 11 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{AB2BBC64-8AC8-4E66-BBF3-E22D5EACEECA}]

Nero BackItUp 11 Help (CHM) [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{6AB2427E-A18F-4809-9A12-29F5EBABBB3A}]

Nero Backup Drivers [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{D600D357-5CB9-4DE9-8FD4-14E208BD1970}]

Nero Burning ROM 11 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{B1846721-A8E6-46C7-83B6-0DCF7ADB4267}]

Nero Burning ROM 11 Help (CHM) [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{53F7746A-96AA-49A5-86B8-59989680DAC5}]

Nero ControlCenter 11 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{11D3EF85-63E1-4AE4-A7C1-9241BDB16B51}]

Nero ControlCenter 11 Help (CHM) [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{D4D66270-9147-4BDF-9946-FCA2B303AA8F}]

Nero Core Components 11 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{BEBEE34D-84A2-4EDD-8BEA-96CC54371263}]

Nero CoverDesigner 11 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{FF44BCE5-5A18-4051-85F0-BC172D7B4695}]

Nero CoverDesigner 11 Help (CHM) [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{55C2143E-FBA5-442F-9AFA-726FF068F39D}]

Nero Express 11 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{E10AAE4A-98B8-420A-BD93-E0520C23D624}]

Nero Express 11 Help (CHM) [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{D2CBEFA4-F2D3-4E97-A171-8BFD6A31A5EC}]

Nero Kwik Media [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{FAF448F1-4460-440C-9280-07F66A63D6F5}]

Nero Kwik Media Help (CHM) [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{B9B1BA7F-7E07-49DD-A713-5B397A5BB66B}]

Nero Recode 11 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{0320AB41-0926-4218-A8A6-68AC84E6BB93}]

Nero Recode 11 Help (CHM) [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{57F80ECF-E27C-4EEE-AB58-E971BACE2639}]

Nero RescueAgent 11 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{034DCAF9-96E7-4936-9A07-712F80B5181E}]

Nero RescueAgent 11 Help (CHM) [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{D01CE99A-8802-483C-A79F-298B691EB432}]

Nero SharedVideoCodecs [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{2432E589-6256-4513-B0BF-EFA8E325D5F0}]

Nero SoundTrax 11 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{0713D1F9-DD77-42C1-8C7D-54D479E2E743}]

Nero SoundTrax 11 Help (CHM) [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{390757AA-8830-43DC-AEE0-4E5B6F8439EB}]

Nero Update [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{65BB0407-4CC8-4DC7-952E-3EEFDF05602A}]

Nero Video 11 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{0D7A4289-99CF-4B8D-B812-86BE50A54552}]

Nero Video 11 Help (CHM) [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{FAC3C37E-EDAB-4F3A-A173-A7C70CC88F09}]

Nero WaveEditor 11 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{8014FACB-1D1D-48C2-94AA-E29EE2E6B9CE}]

Nero WaveEditor 11 Help (CHM) [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{EB8DED20-A887-4A9C-BB5A-F3E7523DFB44}]

nero.prerequisites.msi [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{01E9B2FF-DAF4-4529-9CC9-2101625517C7}]

NVIDIA PhysX [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{1C4551A6-4743-4093-91E4-1477CD655043}]

Opera 12.15 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Opera 12.15.1748]

Paint.NET v3.5.10 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{529125EF-E3AC-4B74-97E6-F688A7C0F1C0}]

PowerDVD [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}]

Quickset [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{87CF757E-C1F1-4D22-865C-00C6950B5258}]

Razer Game Booster [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{88F0F4FF-B514-4E32-9C17-CAF96D60EAFC}]

RealPlayer [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\RealPlayer 12.0]

RealUpgrade 1.0 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{F4F4F84E-804F-4E9A-84D7-C34283F0088F}]

RollerCoaster Tycoon 2 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{72DF62BD-FF36-424E-AA5F-D89BAFF2C249}]

Skype Click to Call [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{B6CF2967-C81E-40C0-9815-C05774FEF120}]

Speccy [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\Speccy]

swMSM [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{612C34C7-5E90-47D8-9B5C-0F717DD82726}]

Ulead Photo Explorer 7.0 SE [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{7C6D8763-EEB7-433E-A75E-2AB44892FCA2}]

Visual C++ 2008 x86 Runtime - (v9.0.30729) [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{F333A33D-125C-32A2-8DCE-5C5D14231E27}]

Visual C++ 2008 x86 Runtime - v9.0.30729.01 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01]

Visual C++ 8.0 Runtime Setup Package (x64) [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{2FDBBCEA-62DB-45F4-B6E5-0E1FB2A1F29D}]

VLC media player 2.0.2 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\VLC media player]

Welcome App (Start-up experience) [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{51865D9D-8F63-46F2-87AB-9E72F93B618C}]

Winamp [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Winamp]

Windows Live Mesh - ActiveX-besturingselement voor externe verbindingen [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{C32CE55C-12BA-4951-8797-0967FDEF556F}]

Windows Live Mesh ActiveX Control for Remote Connections [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}]

Windows Live Sync [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{B10914FD-8812-47A4-85A1-50FCDE7F1F33}]

Windows Media Player Firefox Plugin [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}]

WinRAR 4.01 (32-bit) [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\WinRAR archiver]

==== Deleting Registry Keys ======================

HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\cjofdnhdkbflacojpfpkchgafjahijbb deleted successfully

HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\jllpjckabhalgdienlngoikeehalibei deleted successfully

==== HijackThis Entries ======================

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN NL: Hotmail, Outlook, Skype, Messenger, het laatste nieuws, entertainment en meer!

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm

O1 - Hosts: ::1 localhost

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll

O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll

O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll

O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll

O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll

O4 - HKLM\..\Run: [ulead Memory Card Detector] C:\Program Files (x86)\Ulead Systems\Ulead Photo Explorer 7.0\Monitor.exe

O4 - HKLM\..\Run: [PDVDDXSrv] "C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe"

O4 - HKLM\..\Run: [Dell Webcam Central] "C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell.exe" /mode2

O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe" -osboot

O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui

O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

O4 - HKCU\..\Run: [sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun

O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe

O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~2\OFFICE11\EXCEL.EXE/3000

O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\rwema\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm

O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll

O9 - Extra 'Tools' menuitem: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\OFFICE11\REFIEBAR.DLL

O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll

O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll

O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll

O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll

O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll

O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll

O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll

O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll

O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll

O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics

O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll

O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll

O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe

O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe

O23 - Service: Andrea ST Filters Service (AESTFilters) - Unknown owner - C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_15f4e438\AESTSr64.exe (file missing)

O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)

O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe

O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)

O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

O23 - Service: Service Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe

O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)

O23 - Service: @C:\Program Files (x86)\Nero\Update\NASvc.exe,-200 (NAUpdate) - Nero AG - C:\Program Files (x86)\Nero\Update\NASvc.exe

O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)

O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)

O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)

O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)

O23 - Service: Audio Service (STacSV) - Unknown owner - C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_15f4e438\STacSV64.exe (file missing)

O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)

O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)

O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)

O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\Windows\System32\WLTRYSVC.EXE (file missing)

O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)

O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

==== Silent Runners ======================

"Silent Runners.vbs", revision 69.2, Silent Runners - Adware? Disinfect, don't reformat!

Output limited to non-default values, except where indicated by "{++}"

Startup items buried in registry:

---------------------------------

HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ {++}

Sidebar = C:\Program Files\Windows Sidebar\sidebar.exe /autoRun [MS]

ehTray.exe = C:\Windows\ehome\ehTray.exe [MS]

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}

SysTrayApp = %ProgramFiles%\IDT\WDM\sttray64.exe [iDT, Inc.]

SynTPEnh = C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [synaptics, Inc.]

Monitor = C:\Windows\PixArt\PAC207\Monitor.exe [PixArt Imaging Incorporation]

Broadcom Wireless Manager UI = C:\Windows\system32\WLTRAY.exe [Dell Inc.]

IgfxTray = C:\Windows\system32\igfxtray.exe [intel Corporation]

HotKeysCmds = C:\Windows\system32\hkcmd.exe [intel Corporation]

Persistence = C:\Windows\system32\igfxpers.exe [intel Corporation]

WPCUMI = C:\Windows\system32\WpcUmi.exe [MS]

HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\ {++}

Ulead Memory Card Detector = C:\Program Files (x86)\Ulead Systems\Ulead Photo Explorer 7.0\Monitor.exe [ulead Systems, Inc.]

PDVDDXSrv = "C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [CyberLink Corp.]

Dell Webcam Central = "C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell.exe" /mode2 [Creative Technology Ltd.]

TkBellExe = "C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe" -osboot [RealNetworks, Inc.]

avast = "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui [AVAST Software]

Adobe ARM = "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [Adobe Systems Incorporated]

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\

{318A227B-5E9F-45bd-8999-7F8F10CA4CF5}\(Default) = (no title provided)

-> {HKLM...CLSID} = avast! WebRep

\InProcServer32\(Default) = C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [AVAST Software]

{DBC80044-A445-435b-BC74-9C25C1C588A9}\(Default) = (no title provided)

-> {HKLM...CLSID} = Java Plug-In 2 SSV Helper

\InProcServer32\(Default) = C:\Program Files\Java\jre7\bin\jp2ssv.dll [Oracle Corporation]

-> {HKLM...Wow...CLSID} = Java Plug-In 2 SSV Helper

\InProcServer32\(Default) = [file not found]

HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\

{18DF081C-E8AD-4283-A596-FA578C2EBDC3}\(Default) = AcroIEHelperStub

-> {HKLM...CLSID} = Adobe PDF Link Helper

\InProcServer32\(Default) = [file not found]

-> {HKLM...Wow...CLSID} = Adobe PDF Link Helper

\InProcServer32\(Default) = C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [Adobe Systems Incorporated]

{3049C3E9-B461-4BC5-8870-4C09146192CA}\(Default) = (no title provided)

-> {HKLM...CLSID} = RealPlayer Download and Record Plugin for Internet Explorer

\InProcServer32\(Default) = [file not found]

-> {HKLM...Wow...CLSID} = RealPlayer Download and Record Plugin for Internet Explorer

\InProcServer32\(Default) = C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll [RealPlayer]

{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}\(Default) = Search Helper

-> {HKLM...Wow...CLSID} = Search Helper

\InProcServer32\(Default) = C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll [MS]

{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}\(Default) = (no title provided)

-> {HKLM...Wow...CLSID} = avast! WebRep

\InProcServer32\(Default) = C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [AVAST Software]

{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}\(Default) = SkypeIEPluginBHO

-> {HKLM...CLSID} = Skype Browser Helper

\InProcServer32\(Default) = [file not found]

-> {HKLM...Wow...CLSID} = Skype Browser Helper

\InProcServer32\(Default) = C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [skype Technologies S.A.]

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\

00avast\(Default) = {472083B0-C522-11CF-8763-00608CC02F24}

-> {HKLM...CLSID} = avast

\InProcServer32\(Default) = C:\Program Files\AVAST Software\Avast\ashShA64.dll [AVAST Software]

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\

{2F603045-309F-11CF-9774-0020AFD0CFF6} = Synaptics Control Panel

-> {HKLM...CLSID} = (no title provided)

\InProcServer32\(Default) = C:\Program Files\Synaptics\SynTP\SynTPCpl.dll [synaptics, Inc.]

{472083B0-C522-11CF-8763-00608CC02F24} = avast

-> {HKLM...CLSID} = avast

\InProcServer32\(Default) = C:\Program Files\AVAST Software\Avast\ashShA64.dll [AVAST Software]

{087B3AE3-E237-4467-B8DB-5A38AB959AC9} = LibreOffice Infotip Handler

-> {HKLM...CLSID} = (no title provided)

\InProcServer32\(Default) = C:\Program Files (x86)\LibreOffice 3.6\program\shlxthdl\shlxthdl_x64.dll [The Document Foundation]

{3B092F0C-7696-40E3-A80F-68D74DA84210} = LibreOffice Thumbnail Viewer

-> {HKLM...CLSID} = (no title provided)

\InProcServer32\(Default) = C:\Program Files (x86)\LibreOffice 3.6\program\shlxthdl\shlxthdl_x64.dll [The Document Foundation]

{63542C48-9552-494A-84F7-73AA6A7C99C1} = LibreOffice Property Sheet Handler

-> {HKLM...CLSID} = (no title provided)

\InProcServer32\(Default) = C:\Program Files (x86)\LibreOffice 3.6\program\shlxthdl\shlxthdl_x64.dll [The Document Foundation]

{AE424E85-F6DF-4910-A6A9-438797986431} = LibreOffice Property Handler

-> {HKLM...CLSID} = LibreOffice Property Handler

\InProcServer32\(Default) = C:\Program Files (x86)\LibreOffice 3.6\program\shlxthdl\propertyhdl_x64.dll [The Document Foundation]

{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396} = LibreOffice Column Handler

-> {HKLM...CLSID} = (no title provided)

\InProcServer32\(Default) = C:\Program Files (x86)\LibreOffice 3.6\program\shlxthdl\shlxthdl_x64.dll [The Document Foundation]

{2C7DDECF-7A8E-48A5-A744-8F45D20FB1A9} = Image Catalog

-> {HKLM...CLSID} = Image Catalog

\InProcServer32\(Default) = C:\Program Files (x86)\DAEMON Tools Pro\DTShl64.dll [DT Soft Ltd]

HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\

{00020d75-0000-0000-c000-000000000046} = Microsoft Office Outlook Desktop Icon Handler

-> {HKLM...Wow...CLSID} = Microsoft Office Outlook

\InProcServer32\(Default) = C:\PROGRA~2\MICROS~2\OFFICE11\MLSHEXT.DLL [MS]

{640167b4-59b0-47a6-b335-a6b3c0695aea} = Portable Media Devices

-> {HKLM...Wow...CLSID} = Portable Media Devices

\InProcServer32\(Default) = C:\Windows\system32\audiodev.dll [file not found]

{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4} = Shell Extensions for RealOne Player

-> {HKLM...Wow...CLSID} = RealOne Player Context Menu Class

\InProcServer32\(Default) = C:\Program Files (x86)\Real\RealPlayer\rpshell.dll [RealNetworks, Inc.]

{0006F045-0000-0000-C000-000000000046} = Microsoft Office Outlook Custom Icon Handler

-> {HKLM...Wow...CLSID} = Outlook File Icon Extension

\InProcServer32\(Default) = C:\PROGRA~2\MICROS~2\OFFICE11\OLKFSTUB.DLL [MS]

{42042206-2D85-11D3-8CFF-005004838597} = Microsoft Office HTML Icon Handler

-> {HKLM...Wow...CLSID} = (no title provided)

\InProcServer32\(Default) = C:\Program Files (x86)\Microsoft Office\OFFICE11\msohev.dll [MS]

{B41DB860-8EE4-11D2-9906-E49FADC173CA} = WinRAR shell extension

-> {HKLM...Wow...CLSID} = WinRAR

\InProcServer32\(Default) = C:\Program Files (x86)\WinRAR\rarext.dll [Alexander Roshal]

{472083B0-C522-11CF-8763-00608CC02F24} = avast

-> {HKLM...Wow...CLSID} = avast

\InProcServer32\(Default) = C:\Program Files\AVAST Software\Avast\ashShell.dll [AVAST Software]

{F764812A-132C-4013-9960-5CBBEB408A0E} = Nero Shell Extension

-> {HKLM...Wow...CLSID} = NeroShellExt Class

\InProcServer32\(Default) = C:\Program Files (x86)\Common Files\Nero\NeroShellExt\\NeroShellExt.dll [Nero AG]

{087B3AE3-E237-4467-B8DB-5A38AB959AC9} = LibreOffice Infotip Handler

-> {HKLM...Wow...CLSID} = (no title provided)

\InProcServer32\(Default) = C:\Program Files (x86)\LibreOffice 3.6\program\shlxthdl\shlxthdl.dll [The Document Foundation]

{3B092F0C-7696-40E3-A80F-68D74DA84210} = LibreOffice Thumbnail Viewer

-> {HKLM...Wow...CLSID} = (no title provided)

\InProcServer32\(Default) = C:\Program Files (x86)\LibreOffice 3.6\program\shlxthdl\shlxthdl.dll [The Document Foundation]

{63542C48-9552-494A-84F7-73AA6A7C99C1} = LibreOffice Property Sheet Handler

-> {HKLM...Wow...CLSID} = (no title provided)

\InProcServer32\(Default) = C:\Program Files (x86)\LibreOffice 3.6\program\shlxthdl\shlxthdl.dll [The Document Foundation]

{AE424E85-F6DF-4910-A6A9-438797986431} = LibreOffice Property Handler

-> {HKLM...Wow...CLSID} = LibreOffice Property Handler

\InProcServer32\(Default) = C:\Program Files (x86)\LibreOffice 3.6\program\shlxthdl\propertyhdl.dll [The Document Foundation]

{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396} = LibreOffice Column Handler

-> {HKLM...Wow...CLSID} = (no title provided)

\InProcServer32\(Default) = C:\Program Files (x86)\LibreOffice 3.6\program\shlxthdl\shlxthdl.dll [The Document Foundation]

{2C7DDECF-7A8E-48A5-A744-8F45D20FB1A9} = Image Catalog

-> {HKLM...Wow...CLSID} = Image Catalog

\InProcServer32\(Default) = C:\Program Files (x86)\DAEMON Tools Pro\DTShl32.dll [DT Soft Ltd]

{c5aec3ec-e812-4677-a9a7-4fee1f9aa000} = Icaros Thumbnail Provider

-> {HKLM...Wow...CLSID} = Icaros Thumbnail Provider

\InProcServer32\(Default) = C:\Program Files (x86)\K-Lite Codec Pack\Icaros\IcarosThumbnailProvider.dll [Tabibito Technology]

HKLM\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\

avast\(Default) = {472083B0-C522-11CF-8763-00608CC02F24}

-> {HKLM...CLSID} = avast

\InProcServer32\(Default) = C:\Program Files\AVAST Software\Avast\ashShA64.dll [AVAST Software]

-> {HKLM...Wow...CLSID} = avast

\InProcServer32\(Default) = C:\Program Files\AVAST Software\Avast\ashShell.dll [AVAST Software]

DaemonShellExtImage\(Default) = {40966797-8FFE-46C8-9EF8-7003F33CCF0F}

-> {HKLM...CLSID} = DaemonShellExtImage Class

\InProcServer32\(Default) = C:\Program Files (x86)\DAEMON Tools Pro\DTShl64.dll [DT Soft Ltd]

-> {HKLM...Wow...CLSID} = DaemonShellExtImage Class

\InProcServer32\(Default) = C:\Program Files (x86)\DAEMON Tools Pro\DTShl32.dll [DT Soft Ltd]

LavasoftShellExt\(Default) = {DCE027F7-16A4-4BEE-9BE7-74F80EE3738F}

-> {HKLM...CLSID} = Lavasoft Shell Extension

\InProcServer32\(Default) = C:\Program Files (x86)\Lavasoft\Ad-Aware\ShellExt_64.dll [Lavasoft Limited]

WinRAR\(Default) = {B41DB860-64E4-11D2-9906-E49FADC173CA}

-> {HKLM...CLSID} = WinRAR

\InProcServer32\(Default) = C:\Program Files (x86)\WinRAR\rarext64.dll [Alexander Roshal]

WinRAR32\(Default) = {B41DB860-8EE4-11D2-9906-E49FADC173CA}

-> {HKLM...Wow...CLSID} = WinRAR

\InProcServer32\(Default) = C:\Program Files (x86)\WinRAR\rarext.dll [Alexander Roshal]

{D2203704-49E1-476F-B118-CFE99115634F}\(Default) = (no title provided)

-> {HKLM...Wow...CLSID} = NBShellHook Class

\InProcServer32\(Default) = C:\Program Files (x86)\Nero\Nero 11\Nero BackItUp\NBShell.dll [Nero AG]

{F764812A-132C-4013-9960-5CBBEB408A0E}\(Default) = (no title provided)

-> {HKLM...Wow...CLSID} = NeroShellExt Class

\InProcServer32\(Default) = C:\Program Files (x86)\Common Files\Nero\NeroShellExt\\NeroShellExt.dll [Nero AG]

HKLM\SOFTWARE\Classes\Wow6432Node\*\shellex\ContextMenuHandlers\

avast\(Default) = {472083B0-C522-11CF-8763-00608CC02F24}

-> {HKLM...CLSID} = avast

\InProcServer32\(Default) = C:\Program Files\AVAST Software\Avast\ashShA64.dll [AVAST Software]

-> {HKLM...Wow...CLSID} = avast

\InProcServer32\(Default) = C:\Program Files\AVAST Software\Avast\ashShell.dll [AVAST Software]

DaemonShellExtImage\(Default) = {40966797-8FFE-46C8-9EF8-7003F33CCF0F}

-> {HKLM...CLSID} = DaemonShellExtImage Class

\InProcServer32\(Default) = C:\Program Files (x86)\DAEMON Tools Pro\DTShl64.dll [DT Soft Ltd]

-> {HKLM...Wow...CLSID} = DaemonShellExtImage Class

\InProcServer32\(Default) = C:\Program Files (x86)\DAEMON Tools Pro\DTShl32.dll [DT Soft Ltd]

LavasoftShellExt\(Default) = {DCE027F7-16A4-4BEE-9BE7-74F80EE3738F}

-> {HKLM...CLSID} = Lavasoft Shell Extension

\InProcServer32\(Default) = C:\Program Files (x86)\Lavasoft\Ad-Aware\ShellExt_64.dll [Lavasoft Limited]

WinRAR\(Default) = {B41DB860-64E4-11D2-9906-E49FADC173CA}

-> {HKLM...CLSID} = WinRAR

\InProcServer32\(Default) = C:\Program Files (x86)\WinRAR\rarext64.dll [Alexander Roshal]

WinRAR32\(Default) = {B41DB860-8EE4-11D2-9906-E49FADC173CA}

-> {HKLM...Wow...CLSID} = WinRAR

\InProcServer32\(Default) = C:\Program Files (x86)\WinRAR\rarext.dll [Alexander Roshal]

{D2203704-49E1-476F-B118-CFE99115634F}\(Default) = (no title provided)

-> {HKLM...Wow...CLSID} = NBShellHook Class

\InProcServer32\(Default) = C:\Program Files (x86)\Nero\Nero 11\Nero BackItUp\NBShell.dll [Nero AG]

{F764812A-132C-4013-9960-5CBBEB408A0E}\(Default) = (no title provided)

-> {HKLM...Wow...CLSID} = NeroShellExt Class

\InProcServer32\(Default) = C:\Program Files (x86)\Common Files\Nero\NeroShellExt\\NeroShellExt.dll [Nero AG]

HKLM\SOFTWARE\Classes\*\shellex\DragDropHandlers\

NBShellHook\(Default) = {D2203704-49E1-476F-B118-CFE99115634F}

-> {HKLM...Wow...CLSID} = NBShellHook Class

\InProcServer32\(Default) = C:\Program Files (x86)\Nero\Nero 11\Nero BackItUp\NBShell.dll [Nero AG]

HKLM\SOFTWARE\Classes\Wow6432Node\*\shellex\DragDropHandlers\

NBShellHook\(Default) = {D2203704-49E1-476F-B118-CFE99115634F}

-> {HKLM...Wow...CLSID} = NBShellHook Class

\InProcServer32\(Default) = C:\Program Files (x86)\Nero\Nero 11\Nero BackItUp\NBShell.dll [Nero AG]

HKLM\SOFTWARE\Classes\AllFilesystemObjects\shellex\ContextMenuHandlers\

00avast\(Default) = {472083B0-C522-11CF-8763-00608CC02F24}

-> {HKLM...CLSID} = avast

\InProcServer32\(Default) = C:\Program Files\AVAST Software\Avast\ashShA64.dll [AVAST Software]

-> {HKLM...Wow...CLSID} = avast

\InProcServer32\(Default) = C:\Program Files\AVAST Software\Avast\ashShell.dll [AVAST Software]

GB3ContextMenu\(Default) = {3A488FE8-9916-4F36-BDFF-3DED559142E5}

-> {HKLM...CLSID} = GBContextMenu Class

\InProcServer32\(Default) = C:\Program Files (x86)\Razer\Razer Game Booster\GBV3ContextMenu.dll [null data]

MBAMShlExt\(Default) = {57CE581A-0CB6-4266-9CA0-19364C90A0B3}

-> {HKLM...CLSID} = MBAMShlExt Class

\InProcServer32\(Default) = C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamext.dll [Malwarebytes Corporation]

HKLM\SOFTWARE\Classes\Wow6432Node\AllFilesystemObjects\shellex\ContextMenuHandlers\

00avast\(Default) = {472083B0-C522-11CF-8763-00608CC02F24}

-> {HKLM...CLSID} = avast

\InProcServer32\(Default) = C:\Program Files\AVAST Software\Avast\ashShA64.dll [AVAST Software]

-> {HKLM...Wow...CLSID} = avast

\InProcServer32\(Default) = C:\Program Files\AVAST Software\Avast\ashShell.dll [AVAST Software]

GB3ContextMenu\(Default) = {3A488FE8-9916-4F36-BDFF-3DED559142E5}

-> {HKLM...CLSID} = GBContextMenu Class

\InProcServer32\(Default) = C:\Program Files (x86)\Razer\Razer Game Booster\GBV3ContextMenu.dll [null data]

MBAMShlExt\(Default) = {57CE581A-0CB6-4266-9CA0-19364C90A0B3}

-> {HKLM...CLSID} = MBAMShlExt Class

\InProcServer32\(Default) = C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamext.dll [Malwarebytes Corporation]

HKLM\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\

WinRAR\(Default) = {B41DB860-64E4-11D2-9906-E49FADC173CA}

-> {HKLM...CLSID} = WinRAR

\InProcServer32\(Default) = C:\Program Files (x86)\WinRAR\rarext64.dll [Alexander Roshal]

WinRAR32\(Default) = {B41DB860-8EE4-11D2-9906-E49FADC173CA}

-> {HKLM...Wow...CLSID} = WinRAR

\InProcServer32\(Default) = C:\Program Files (x86)\WinRAR\rarext.dll [Alexander Roshal]

{F764812A-132C-4013-9960-5CBBEB408A0E}\(Default) = (no title provided)

-> {HKLM...Wow...CLSID} = NeroShellExt Class

\InProcServer32\(Default) = C:\Program Files (x86)\Common Files\Nero\NeroShellExt\\NeroShellExt.dll [Nero AG]

HKLM\SOFTWARE\Classes\Wow6432Node\Directory\shellex\ContextMenuHandlers\

WinRAR\(Default) = {B41DB860-64E4-11D2-9906-E49FADC173CA}

-> {HKLM...CLSID} = WinRAR

\InProcServer32\(Default) = C:\Program Files (x86)\WinRAR\rarext64.dll [Alexander Roshal]

WinRAR32\(Default) = {B41DB860-8EE4-11D2-9906-E49FADC173CA}

-> {HKLM...Wow...CLSID} = WinRAR

\InProcServer32\(Default) = C:\Program Files (x86)\WinRAR\rarext.dll [Alexander Roshal]

{F764812A-132C-4013-9960-5CBBEB408A0E}\(Default) = (no title provided)

-> {HKLM...Wow...CLSID} = NeroShellExt Class

\InProcServer32\(Default) = C:\Program Files (x86)\Common Files\Nero\NeroShellExt\\NeroShellExt.dll [Nero AG]

HKLM\SOFTWARE\Classes\Directory\shellex\DragDropHandlers\

WinRAR\(Default) = {B41DB860-64E4-11D2-9906-E49FADC173CA}

-> {HKLM...CLSID} = WinRAR

\InProcServer32\(Default) = C:\Program Files (x86)\WinRAR\rarext64.dll [Alexander Roshal]

WinRAR32\(Default) = {B41DB860-8EE4-11D2-9906-E49FADC173CA}

-> {HKLM...Wow...CLSID} = WinRAR

\InProcServer32\(Default) = C:\Program Files (x86)\WinRAR\rarext.dll [Alexander Roshal]

HKLM\SOFTWARE\Classes\Wow6432Node\Directory\shellex\DragDropHandlers\

WinRAR\(Default) = {B41DB860-64E4-11D2-9906-E49FADC173CA}

-> {HKLM...CLSID} = WinRAR

\InProcServer32\(Default) = C:\Program Files (x86)\WinRAR\rarext64.dll [Alexander Roshal]

WinRAR32\(Default) = {B41DB860-8EE4-11D2-9906-E49FADC173CA}

-> {HKLM...Wow...CLSID} = WinRAR

\InProcServer32\(Default) = C:\Program Files (x86)\WinRAR\rarext.dll [Alexander Roshal]

HKLM\SOFTWARE\Classes\Directory\Background\shellex\ContextMenuHandlers\

igfxcui\(Default) = {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4}

-> {HKLM...CLSID} = GraphicsShellExt Class

\InProcServer32\(Default) = C:\Windows\system32\igfxpph.dll [intel Corporation]

HKLM\SOFTWARE\Classes\Wow6432Node\Directory\Background\shellex\ContextMenuHandlers\

igfxcui\(Default) = {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4}

-> {HKLM...CLSID} = GraphicsShellExt Class

\InProcServer32\(Default) = C:\Windows\system32\igfxpph.dll [intel Corporation]

HKLM\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\

{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396}\(Default) = LibreOffice Column Handler

-> {HKLM...CLSID} = (no title provided)

\InProcServer32\(Default) = C:\Program Files (x86)\LibreOffice 3.6\program\shlxthdl\shlxthdl_x64.dll [The Document Foundation]

-> {HKLM...Wow...CLSID} = (no title provided)

\InProcServer32\(Default) = C:\Program Files (x86)\LibreOffice 3.6\program\shlxthdl\shlxthdl.dll [The Document Foundation]

{F9DB5320-233E-11D1-9F84-707F02C10627}\(Default) = PDF Column Info

-> {HKLM...Wow...CLSID} = PDF Shell Extension

\InProcServer32\(Default) = C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll [Adobe Systems, Inc.]

HKLM\SOFTWARE\Classes\Wow6432Node\Folder\shellex\ColumnHandlers\

{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396}\(Default) = LibreOffice Column Handler

-> {HKLM...CLSID} = (no title provided)

\InProcServer32\(Default) = C:\Program Files (x86)\LibreOffice 3.6\program\shlxthdl\shlxthdl_x64.dll [The Document Foundation]

-> {HKLM...Wow...CLSID} = (no title provided)

\InProcServer32\(Default) = C:\Program Files (x86)\LibreOffice 3.6\program\shlxthdl\shlxthdl.dll [The Document Foundation]

{F9DB5320-233E-11D1-9F84-707F02C10627}\(Default) = PDF Column Info

-> {HKLM...Wow...CLSID} = PDF Shell Extension

\InProcServer32\(Default) = C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll [Adobe Systems, Inc.]

HKLM\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\

avast\(Default) = {472083B0-C522-11CF-8763-00608CC02F24}

-> {HKLM...CLSID} = avast

\InProcServer32\(Default) = C:\Program Files\AVAST Software\Avast\ashShA64.dll [AVAST Software]

-> {HKLM...Wow...CLSID} = avast

\InProcServer32\(Default) = C:\Program Files\AVAST Software\Avast\ashShell.dll [AVAST Software]

LavasoftShellExt\(Default) = {DCE027F7-16A4-4BEE-9BE7-74F80EE3738F}

-> {HKLM...CLSID} = Lavasoft Shell Extension

\InProcServer32\(Default) = C:\Program Files (x86)\Lavasoft\Ad-Aware\ShellExt_64.dll [Lavasoft Limited]

MBAMShlExt\(Default) = {57CE581A-0CB6-4266-9CA0-19364C90A0B3}

-> {HKLM...CLSID} = MBAMShlExt Class

\InProcServer32\(Default) = C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamext.dll [Malwarebytes Corporation]

WinRAR\(Default) = {B41DB860-64E4-11D2-9906-E49FADC173CA}

-> {HKLM...CLSID} = WinRAR

\InProcServer32\(Default) = C:\Program Files (x86)\WinRAR\rarext64.dll [Alexander Roshal]

WinRAR32\(Default) = {B41DB860-8EE4-11D2-9906-E49FADC173CA}

-> {HKLM...Wow...CLSID} = WinRAR

\InProcServer32\(Default) = C:\Program Files (x86)\WinRAR\rarext.dll [Alexander Roshal]

{D2203704-49E1-476F-B118-CFE99115634F}\(Default) = (no title provided)

-> {HKLM...Wow...CLSID} = NBShellHook Class

\InProcServer32\(Default) = C:\Program Files (x86)\Nero\Nero 11\Nero BackItUp\NBShell.dll [Nero AG]

HKLM\SOFTWARE\Classes\Wow6432Node\Folder\shellex\ContextMenuHandlers\

avast\(Default) = {472083B0-C522-11CF-8763-00608CC02F24}

-> {HKLM...CLSID} = avast

\InProcServer32\(Default) = C:\Program Files\AVAST Software\Avast\ashShA64.dll [AVAST Software]

-> {HKLM...Wow...CLSID} = avast

\InProcServer32\(Default) = C:\Program Files\AVAST Software\Avast\ashShell.dll [AVAST Software]

LavasoftShellExt\(Default) = {DCE027F7-16A4-4BEE-9BE7-74F80EE3738F}

-> {HKLM...CLSID} = Lavasoft Shell Extension

\InProcServer32\(Default) = C:\Program Files (x86)\Lavasoft\Ad-Aware\ShellExt_64.dll [Lavasoft Limited]

MBAMShlExt\(Default) = {57CE581A-0CB6-4266-9CA0-19364C90A0B3}

-> {HKLM...CLSID} = MBAMShlExt Class

\InProcServer32\(Default) = C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamext.dll [Malwarebytes Corporation]

WinRAR\(Default) = {B41DB860-64E4-11D2-9906-E49FADC173CA}

-> {HKLM...CLSID} = WinRAR

\InProcServer32\(Default) = C:\Program Files (x86)\WinRAR\rarext64.dll [Alexander Roshal]

WinRAR32\(Default) = {B41DB860-8EE4-11D2-9906-E49FADC173CA}

-> {HKLM...Wow...CLSID} = WinRAR

\InProcServer32\(Default) = C:\Program Files (x86)\WinRAR\rarext.dll [Alexander Roshal]

{D2203704-49E1-476F-B118-CFE99115634F}\(Default) = (no title provided)

-> {HKLM...Wow...CLSID} = NBShellHook Class

\InProcServer32\(Default) = C:\Program Files (x86)\Nero\Nero 11\Nero BackItUp\NBShell.dll [Nero AG]

HKLM\SOFTWARE\Classes\Folder\shellex\DragDropHandlers\

NBShellHook\(Default) = {D2203704-49E1-476F-B118-CFE99115634F}

-> {HKLM...Wow...CLSID} = NBShellHook Class

\InProcServer32\(Default) = C:\Program Files (x86)\Nero\Nero 11\Nero BackItUp\NBShell.dll [Nero AG]

WinRAR\(Default) = {B41DB860-64E4-11D2-9906-E49FADC173CA}

-> {HKLM...CLSID} = WinRAR

\InProcServer32\(Default) = C:\Program Files (x86)\WinRAR\rarext64.dll [Alexander Roshal]

WinRAR32\(Default) = {B41DB860-8EE4-11D2-9906-E49FADC173CA}

-> {HKLM...Wow...CLSID} = WinRAR

\InProcServer32\(Default) = C:\Program Files (x86)\WinRAR\rarext.dll [Alexander Roshal]

HKLM\SOFTWARE\Classes\Wow6432Node\Folder\shellex\DragDropHandlers\

NBShellHook\(Default) = {D2203704-49E1-476F-B118-CFE99115634F}

-> {HKLM...Wow...CLSID} = NBShellHook Class

\InProcServer32\(Default) = C:\Program Files (x86)\Nero\Nero 11\Nero BackItUp\NBShell.dll [Nero AG]

WinRAR\(Default) = {B41DB860-64E4-11D2-9906-E49FADC173CA}

-> {HKLM...CLSID} = WinRAR

\InProcServer32\(Default) = C:\Program Files (x86)\WinRAR\rarext64.dll [Alexander Roshal]

WinRAR32\(Default) = {B41DB860-8EE4-11D2-9906-E49FADC173CA}

-> {HKLM...Wow...CLSID} = WinRAR

\InProcServer32\(Default) = C:\Program Files (x86)\WinRAR\rarext.dll [Alexander Roshal]

Group Policies {GPedit.msc branch and setting}:

-----------------------------------------------

Note: detected settings may not have any effect.

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System\

LogonHoursAction = (REG_DWORD) dword:0x00000002

{unrecognized setting}

DontDisplayLogonHoursWarnings = (REG_DWORD) dword:0x00000001

{unrecognized setting}

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\

EnableLinkedConnections = (REG_DWORD) dword:0x00000001

{unrecognized setting}

Active Desktop and Wallpaper:

-----------------------------

Active Desktop may be disabled at this entry:

HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState

Displayed if Active Desktop enabled and wallpaper not set by Group Policy:

HKCU\Software\Microsoft\Internet Explorer\Desktop\General\

Wallpaper = C:\Windows\system32\config\systemprofile\Pictures\pedobear_13 (1).jpg

Displayed if Active Desktop disabled and wallpaper not set by Group Policy:

HKCU\Control Panel\Desktop\

Wallpaper = C:\Users\rwema\Pictures\pedobear_13 (1).jpg

Enabled Screen Saver:

---------------------

HKCU\Control Panel\Desktop\

SCRNSAVE.EXE = C:\Windows\system32\logon.scr [MS]

Windows Portable Device AutoPlay Handlers

-----------------------------------------

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\

MSPlayCDAudioOnArrival\

Provider = @wmploc.dll,-6502

InvokeProgID = WMP.AudioCD

InvokeVerb = play

HKLM\SOFTWARE\Classes\WMP.AudioCD\shell\play\command\(Default) = "C:\Program Files (x86)\Windows Media Player\wmplayer.exe" /prefetch:3 /device:AudioCD "%L" [MS]

MSPlayDVDMovieOnArrival\

Provider = @wmploc.dll,-6502

InvokeProgID = WMP.DVD

InvokeVerb = play

HKLM\SOFTWARE\Classes\WMP.DVD\shell\play\command\(Default) = "C:\Program Files (x86)\Windows Media Player\wmplayer.exe" /prefetch:4 /device:DVD "%L" [MS]

MSPlaySuperVideoCDMovieOnArrival\

Provider = @wmploc.dll,-6502

InvokeProgID = WMP.VCD

InvokeVerb = play

HKLM\SOFTWARE\Classes\WMP.VCD\shell\play\command\(Default) = "C:\Program Files (x86)\Windows Media Player\wmplayer.exe" /prefetch:4 /device:VCD "%L" [MS]

MSPlayVideoCDMovieOnArrival\

Provider = @wmploc.dll,-6502

InvokeProgID = WMP.VCD

InvokeVerb = play

HKLM\SOFTWARE\Classes\WMP.VCD\shell\play\command\(Default) = "C:\Program Files (x86)\Windows Media Player\wmplayer.exe" /prefetch:4 /device:VCD "%L" [MS]

MSRipCDAudioOnArrival\

Provider = @wmploc.dll,-6502

InvokeProgID = WMP.RipCD

InvokeVerb = Rip

HKLM\SOFTWARE\Classes\WMP.RipCD\shell\Rip\Command\(Default) = "C:\Program Files (x86)\Windows Media Player\wmplayer.exe" /prefetch:3 /RipAudioCD "%L" [MS]

MSWMPBurnCDOnArrival\

Provider = @wmploc.dll,-6502

InvokeProgID = WMP.BurnCD

InvokeVerb = Burn

HKLM\SOFTWARE\Classes\WMP.BurnCD\shell\Burn\Command\(Default) = "C:\Program Files (x86)\Windows Media Player\wmplayer.exe" /prefetch:3 /Task:CDWrite /Device:"%L" [MS]

MSWMPBurnDataDVDArrival\

Provider = @wmploc.dll,-6502

InvokeProgID = WMP.BurnDVD

InvokeVerb = Burn

HKLM\SOFTWARE\Classes\WMP.BurnDVD\shell\Burn\Command\(Default) = "C:\Program Files (x86)\Windows Media Player\wmplayer.exe" /prefetch:3 /Task:DVDWrite /Device:"%L" [MS]

PDVDDXPlayDVDMovieOnArrival\

Provider = PowerDVD

InvokeProgID = DVD

InvokeVerb = PlayWithPDVDDX

HKLM\SOFTWARE\Classes\DVD\shell\PlayWithPDVDDX\Command\(Default) = "C:\Program Files\CyberLink\PowerDVD DX\PowerDVD.exe" AUTOPLAY MOVIE "%L" [CyberLink Corp.]

PDVDDXPlayVideoCDMovieOnArrival\

Provider = PowerDVD

InvokeProgID = VCD

InvokeVerb = PlayWithPDVDDX

HKLM\SOFTWARE\Classes\VCD\shell\PlayWithPDVDDX\Command\(Default) = "C:\Program Files\CyberLink\PowerDVD DX\PowerDVD.exe" AUTOPLAY MOVIE "%L" [CyberLink Corp.]

RPCDBurningOnArrival\

Provider = RealPlayer

InvokeProgID = RealPlayer.CDBurn.6

InvokeVerb = open

HKCU\Software\Classes\RealPlayer.CDBurn.6\shell\open\command\(Default) = "C:\Program Files (x86)\Real\RealPlayer\RealPlay.exe" /burn "%1" [RealNetworks, Inc.]

RPDeviceOnArrival\

Provider = RealPlayer

ProgID = RealPlayer.HWEventHandler

HKLM\SOFTWARE\Classes\RealPlayer.HWEventHandler\CLSID\(Default) = {67E76F1D-BDE2-4052-913C-2752366192D2}

-> {HKLM...CLSID} = RealNetworks Scheduler

\LocalServer32\(Default) = "C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe" -autoplay [RealNetworks, Inc.]

RPDVDBurningOnArrival\

Provider = RealPlayer

InvokeProgID = RealPlayer.DVDBurn.6

InvokeVerb = open

HKCU\Software\Classes\RealPlayer.DVDBurn.6\shell\open\command\(Default) = "C:\Program Files (x86)\Real\RealPlayer\RealPlay.exe" /burndvd "%1" [RealNetworks, Inc.]

RPPlayCDAudioOnArrival\

Provider = RealPlayer

InvokeProgID = RealPlayer.AudioCD.6

InvokeVerb = play

HKCU\Software\Classes\RealPlayer.AudioCD.6\shell\play\command\(Default) = "C:\Program Files (x86)\Real\RealPlayer\RealPlay.exe" /play %1 [RealNetworks, Inc.]

RPPlayDVDMovieOnArrival\

Provider = RealPlayer

InvokeProgID = RealPlayer.DVD.6

InvokeVerb = play

HKCU\Software\Classes\RealPlayer.DVD.6\shell\play\command\(Default) = "C:\Program Files (x86)\Real\RealPlayer\RealPlay.exe" /dvd %1 [RealNetworks, Inc.]

RPPlayMediaOnArrival\

Provider = RealPlayer

InvokeProgID = RealPlayer.AutoPlay.6

InvokeVerb = open

HKCU\Software\Classes\RealPlayer.AutoPlay.6\shell\open\command\(Default) = "C:\Program Files (x86)\Real\RealPlayer\RealPlay.exe" /autoplay "%1" [RealNetworks, Inc.]

Non-disabled Scheduled Tasks: {++}

-----------------------------

C:\Windows\System32\Tasks

Ad-Aware Update (Weekly) -> launches: C:\Program Files (x86)\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe update all silent repair [file not found]

Adobe Flash Player Updater -> launches: C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [Adobe Systems Incorporated]

avast! Emergency Update -> (HIDDEN!) launches: C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [AVAST Software]

CCleanerSkipUAC -> launches: "C:\Program Files\CCleaner\CCleaner.exe" $(Arg0) [Piriform Ltd]

CheckDriveBackgroundGuard -> launches: C:\Program Files (x86)\CheckDrive\CheckDriveBackgroundGuard.exe -m [file not found]

DealPlyUpdate -> launches: "C:\Program Files (x86)\DealPly\DealPlyUpdate.exe" [file not found]

EPUpdater -> launches: C:\Users\rwema\AppData\Roaming\BABSOL~1\Shared\BabMaint.exe [file not found]

Express FilesUpdate -> launches: C:\Program Files (x86)\ExpressFiles\EFUpdater.exe [file not found]

GoogleUpdateTaskMachineCore -> launches: C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c [Google Inc.]

GoogleUpdateTaskMachineUA -> launches: C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler [Google Inc.]

Launch BCM WLAN Tray -> launches: C:\Windows\system32\WLTRAY.EXE [Dell Inc.]

Razer_Game_Booster_AutoUpdate -> launches: C:\Program Files (x86)\Razer\Razer Game Booster\AutoUpdate.exe /AUTORUN [empty string]

RealUpgradeLogonTaskS-1-5-21-3916401253-1491523390-1999398694-1000 -> launches: C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe /logoncheck [RealNetworks, Inc.]

RealUpgradeScheduledTaskS-1-5-21-3916401253-1491523390-1999398694-1000 -> launches: C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe /scheduledcheck [RealNetworks, Inc.]

User_Feed_Synchronization-{D447659A-5449-4A12-8BC9-5178D1E99BDC} -> (HIDDEN!) launches: C:\Windows\system32\msfeedssync.exe sync [MS]

{1B7C1B3D-835A-41D3-B3F4-ACF7304E83CC} -> launches: C:\Windows\system32\pcalua.exe -a C:\PROGRA~2\BS_PLA~1\UNWISE.EXE -c /U C:\PROGRA~2\BS_PLA~1\INSTALL.LOG [MS]

{2380CFC4-A30F-474A-8F6F-BB156BE2CD61} -> launches: C:\Windows\system32\pcalua.exe -a C:\PROGRA~2\NCH_EN\UNWISE.EXE -c /U C:\PROGRA~2\NCH_EN\INSTALL.LOG [MS]

{7FCE0B38-04E8-4675-B2BC-BB69447DB9DF} -> launches: C:\Windows\system32\pcalua.exe -a "C:\Program Files (x86)\Arthaus Paint & Fotoshop\Uninstall.EXE" -c /u:"Arthaus Paint & Fotoshop" [MS]

C:\Windows\System32\Tasks\Browser Updater

Browser Updater -> launches: "C:\Windows\system32\rundll32.exe" "C:\Program Files (x86)\Browser Updater\TBUpdater.dll",TBCheckForUpdate [MS]

C:\Windows\System32\Tasks\Microsoft\Windows\Active Directory Rights Management Services Client

AD RMS Rights Policy Template Management (Manual) -> launches: {BF5CB148-7C77-4d8a-A53E-D81C70CF743C}

-> {HKLM...CLSID} = AD RMS Rights Policy Template Management (Manual) Task Handler

\InProcServer32\(Default) = C:\Windows\system32\msdrm.dll [MS]

-> {HKLM...Wow...CLSID} = AD RMS Rights Policy Template Management (Manual) Task Handler

\InProcServer32\(Default) = C:\Windows\system32\msdrm.dll [MS]

C:\Windows\System32\Tasks\Microsoft\Windows\Bluetooth

UninstallDeviceTask -> launches: BthUdTask.exe $(Arg0) [MS]

C:\Windows\System32\Tasks\Microsoft\Windows\CertificateServicesClient

SystemTask -> launches: {58fb76b9-ac85-4e55-ac04-427593b1d060}

-> {HKLM...CLSID} = Certificate Services Client Task Handler

\InProcServer32\(Default) = C:\Windows\system32\dimsjob.dll [MS]

-> {HKLM...Wow...CLSID} = Certificate Services Client Task Handler

\InProcServer32\(Default) = C:\Windows\system32\dimsjob.dll [MS]

UserTask -> launches: {58fb76b9-ac85-4e55-ac04-427593b1d060}

-> {HKLM...CLSID} = Certificate Services Client Task Handler

\InProcServer32\(Default) = C:\Windows\system32\dimsjob.dll [MS]

-> {HKLM...Wow...CLSID} = Certificate Services Client Task Handler

\InProcServer32\(Default) = C:\Windows\system32\dimsjob.dll [MS]

UserTask-Roam -> launches: {58fb76b9-ac85-4e55-ac04-427593b1d060}

-> {HKLM...CLSID} = Certificate Services Client Task Handler

\InProcServer32\(Default) = C:\Windows\system32\dimsjob.dll [MS]

-> {HKLM...Wow...CLSID} = Certificate Services Client Task Handler

\InProcServer32\(Default) = C:\Windows\system32\dimsjob.dll [MS]

C:\Windows\System32\Tasks\Microsoft\Windows\Customer Experience Improvement Program

Consolidator -> launches: %SystemRoot%\System32\wsqmcons.exe [MS]

OptinNotification -> launches: %SystemRoot%\System32\wsqmcons.exe -n 0x1C577FA2B69CAD0 [MS]

C:\Windows\System32\Tasks\Microsoft\Windows\Defrag

ScheduledDefrag -> launches: %windir%\system32\defrag.exe -c -i [MS]

C:\Windows\System32\Tasks\Microsoft\Windows\Media Center

ehDRMInit -> launches: %SystemRoot%\ehome\ehPrivJob.exe /DRMInit [MS]

mcupdate -> launches: %SystemRoot%\ehome\mcupdate $(Arg0) -gc [MS]

OCURActivate -> launches: %SystemRoot%\ehome\ehPrivJob.exe /OCURActivate [MS]

OCURDiscovery -> launches: %SystemRoot%\ehome\ehPrivJob.exe /OCURDiscovery [MS]

UpdateRecordPath -> launches: %SystemRoot%\ehome\ehPrivJob.exe /DoUpdateRecordPath $(Arg0) [MS]

C:\Windows\System32\Tasks\Microsoft\Windows\MobilePC

HotStart -> launches: {06DA0625-9701-43da-BFD7-FBEEA2180A1E}

-> {HKLM...CLSID} = HotStart User Agent

\InProcServer32\(Default) = C:\Windows\System32\HotStartUserAgent.dll [MS]

TMM -> launches: {35EF4182-F900-4632-B072-8639E4478A61}

-> {HKLM...CLSID} = Transient Multi-Monitor Manager

\InProcServer32\(Default) = C:\Windows\System32\TMM.dll [MS]

-> {HKLM...Wow...CLSID} = Transient Multi-Monitor Manager

\InProcServer32\(Default) = C:\Windows\System32\TMM.dll [MS]

C:\Windows\System32\Tasks\Microsoft\Windows\Multimedia

SystemSoundsService -> launches: {2DEA658F-54C1-4227-AF9B-260AB5FC3543}

-> {HKLM...CLSID} = Microsoft PlaySoundService Class

\InProcServer32\(Default) = C:\Windows\System32\PlaySndSrv.dll [MS]

-> {HKLM...Wow...CLSID} = Microsoft PlaySoundService Class

\InProcServer32\(Default) = C:\Windows\System32\PlaySndSrv.dll [MS]

C:\Windows\System32\Tasks\Microsoft\Windows\NetworkAccessProtection

NAPStatus UI -> launches: {f09878a1-4652-4292-aa63-8c7d4fd7648f}

-> {HKLM...CLSID} = Nap ITask Handler Implementation

\InProcServer32\(Default) = C:\Windows\System32\QAgent.dll [MS]

-> {HKLM...Wow...CLSID} = Nap ITask Handler Implementation

\InProcServer32\(Default) = C:\Windows\System32\QAgent.dll [MS]

C:\Windows\System32\Tasks\Microsoft\Windows\RAC

RACAgent -> (HIDDEN!) launches: %windir%\system32\RacAgent.exe [MS]

C:\Windows\System32\Tasks\Microsoft\Windows\RemoteAssistance

RemoteAssistanceTask -> (HIDDEN!) launches: %windir%\system32\RAServer.exe /offerraupdate [MS]

C:\Windows\System32\Tasks\Microsoft\Windows\Shell

CrawlStartPages -> launches: {51653423-e62d-4ff7-894a-dabb2b8e21e2}

-> {HKLM...CLSID} = CrawlStartPages Task Handler

\InProcServer32\(Default) = C:\Windows\System32\srchadmin.dll [MS]

-> {HKLM...Wow...CLSID} = CrawlStartPages Task Handler

\InProcServer32\(Default) = C:\Windows\System32\srchadmin.dll [MS]

C:\Windows\System32\Tasks\Microsoft\Windows\SideShow

GadgetManager -> launches: {FF87090D-4A9A-4f47-879B-29A80C355D61}

-> {HKLM...CLSID} = GadgetsManager Class

\InProcServer32\(Default) = C:\Windows\System32\AuxiliaryDisplayServices.dll [MS]

C:\Windows\System32\Tasks\Microsoft\Windows\SystemRestore

SR -> launches: %windir%\system32\rundll32.exe /d srrstr.dll,ExecuteScheduledSPPCreation [MS]

C:\Windows\System32\Tasks\Microsoft\Windows\Tcpip

IpAddressConflict1 -> launches: rundll32 ndfapi.dll,NdfRunDllDuplicateIPOffendingSystem [MS]

IpAddressConflict2 -> launches: rundll32 ndfapi.dll,NdfRunDllDuplicateIPDefendingSystem [MS]

WSHReset -> (HIDDEN!) launches: %systemroot%\system32\netsh.exe interface tcp set heuristic wsh=default [MS]

C:\Windows\System32\Tasks\Microsoft\Windows\TextServicesFramework

MsCtfMonitor -> (HIDDEN!) launches: {01575cfe-9a55-4003-a5e1-f38d1ebdcbe1}

-> {HKLM...CLSID} = MsCtfMonitor task handler

\InProcServer32\(Default) = C:\Windows\system32\MsCtfMonitor.dll [MS]

-> {HKLM...Wow...CLSID} = MsCtfMonitor task handler

\InProcServer32\(Default) = C:\Windows\system32\MsCtfMonitor.dll [MS]

C:\Windows\System32\Tasks\Microsoft\Windows\UPnP

UPnPHostConfig -> launches: sc.exe config upnphost start= auto [MS]

C:\Windows\System32\Tasks\Microsoft\Windows\WDI

ResolutionHost -> (HIDDEN!) launches: {900be39d-6be8-461a-bc4d-b0fa71f5ecb1}

-> {HKLM...CLSID} = DiagnosticInfrastructureCustomHandler

\InProcServer32\(Default) = C:\Windows\System32\wdi.dll [MS]

-> {HKLM...Wow...CLSID} = DiagnosticInfrastructureCustomHandler

\InProcServer32\(Default) = C:\Windows\System32\wdi.dll [MS]

C:\Windows\System32\Tasks\Microsoft\Windows\Windows Error Reporting

QueueReporting -> launches: %windir%\system32\wermgr.exe -queuereporting [MS]

C:\Windows\System32\Tasks\Microsoft\Windows\WindowsCalendar

Reminders - rwema -> launches: C:\Program Files\Windows Calendar\WinCal.exe /reminder [MS]

C:\Windows\System32\Tasks\Microsoft\Windows\Wired

GatherWiredInfo -> launches: %windir%\system32\gatherWiredInfo.vbs [null data]

C:\Windows\System32\Tasks\Microsoft\Windows\Wireless

GatherWirelessInfo -> launches: %windir%\system32\gatherWirelessInfo.vbs [null data]

C:\Windows\System32\Tasks\Microsoft\Windows Defender

MP Scheduled Scan -> (HIDDEN!) launches: c:\program files\windows defender\MpCmdRun.exe Scan -RestrictPrivileges [MS]

C:\Windows\System32\Tasks\ProtectedSearch

Protected Search -> launches: "C:\Program Files (x86)\Protected Search\ProtectedSearch.exe" [file not found]

C:\Windows\System32\Tasks\WPD

SqmUpload_S-1-5-21-3916401253-1491523390-1999398694-1000 -> (HIDDEN!) launches: %windir%\system32\rundll32.exe portabledeviceapi.dll,#1 [MS]

SqmUpload_S-1-5-21-3916401253-1491523390-1999398694-1003 -> (HIDDEN!) launches: %windir%\system32\rundll32.exe portabledeviceapi.dll,#1 [MS]

Winsock2 Service Provider DLLs:

-------------------------------

Namespace Service Providers

HKLM\SYSTEM\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++}

000000000001\LibraryPath = %SystemRoot%\system32\NLAapi.dll [MS]

000000000002\LibraryPath = %SystemRoot%\system32\napinsp.dll [MS]

000000000003\LibraryPath = %SystemRoot%\system32\pnrpnsp.dll [MS]

000000000004\LibraryPath = %SystemRoot%\system32\pnrpnsp.dll [MS]

000000000005\LibraryPath = %SystemRoot%\System32\mswsock.dll [MS]

000000000006\LibraryPath = %SystemRoot%\System32\winrnr.dll [MS]

HKLM\SYSTEM\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\ {++}

000000000001\LibraryPath = %SystemRoot%\system32\NLAapi.dll [MS]

000000000002\LibraryPath = %SystemRoot%\system32\napinsp.dll [MS]

000000000003\LibraryPath = %SystemRoot%\system32\pnrpnsp.dll [MS]

000000000004\LibraryPath = %SystemRoot%\system32\pnrpnsp.dll [MS]

000000000005\LibraryPath = %SystemRoot%\System32\mswsock.dll [MS]

000000000006\LibraryPath = %SystemRoot%\System32\winrnr.dll [MS]

Transport Service Providers

HKLM\SYSTEM\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++}

0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range:

C:\Windows\system32\wpclsp.dll [MS], 01 - 08, 19

%SystemRoot%\system32\mswsock.dll [MS], 09 - 18

HKLM\SYSTEM\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries64\ {++}

0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range:

C:\Windows\system32\wpclsp.dll [MS], 01 - 08, 19

%SystemRoot%\system32\mswsock.dll [MS], 09 - 18

Toolbars, Explorer Bars, Extensions:

------------------------------------

Toolbars

HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\

{318A227B-5E9F-45BD-8999-7F8F10CA4CF5} = (no title provided)

-> {HKLM...CLSID} = avast! WebRep

\InProcServer32\(Default) = C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [AVAST Software]

HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\

{8E5E2654-AD2D-48BF-AC2D-D17F00898D06} = (no title provided)

-> {HKLM...Wow...CLSID} = avast! WebRep

\InProcServer32\(Default) = C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [AVAST Software]

Explorer Bars

HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{FF059E31-CC5A-4E2E-BF3B-96E929D65503}\(Default) = &Research

Implemented Categories\{00021493-0000-0000-C000-000000000046}\ [vertical bar]

InProcServer32\(Default) = C:\PROGRA~2\MICROS~2\OFFICE11\REFIEBAR.DLL [MS]

Extensions (Tools menu items, main toolbar menu buttons)

HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Extensions\

{898EA8C8-E7FF-479B-8935-AEC46303B9E5}\

ButtonText = Skype Click to Call

MenuText = Skype Click to Call

CLSIDExtension = {898EA8C8-E7FF-479B-8935-AEC46303B9E5}

-> {HKLM...Wow...CLSID} = Skype Browser Helper

\InProcServer32\(Default) = C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [skype Technologies S.A.]

{92780B25-18CC-41C8-B9BE-3C9C571A8263}\

ButtonText = Research

BandCLSID = {FF059E31-CC5A-4E2E-BF3B-96E929D65503}

-> {HKLM...Wow...CLSID} = &Research

\InProcServer32\(Default) = C:\PROGRA~2\MICROS~2\OFFICE11\REFIEBAR.DLL [MS]

Running Services (Display Name, Service Name, Path {Service DLL}):

------------------------------------------------------------------

Adobe Acrobat Update Service, AdobeARMservice, "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe" [Adobe Systems Incorporated]

Andrea ST Filters Service, AESTFilters, C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_15f4e438\AESTSr64.exe [Andrea Electronics Corporation]

Audio Service, STacSV, C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_15f4e438\STacSV64.exe [iDT, Inc.]

avast! Antivirus, avast! Antivirus, "C:\Program Files\AVAST Software\Avast\AvastSvc.exe" [AVAST Software]

Dell Wireless WLAN Tray Service, wltrysvc, C:\Windows\System32\WLTRYSVC.EXE C:\Windows\System32\bcmwltry.exe [null data]

Nero Update, NAUpdate, "C:\Program Files (x86)\Nero\Update\NASvc.exe" [Nero AG]

SeaPort, SeaPort, "C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe" [MS]

Print Monitors:

---------------

HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors\

LIDIL hpzll5ha\Driver = hpzll5ha.dll [Hewlett-Packard Company]

==== Empty IE Cache ======================

C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

C:\Users\Guest\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

C:\Windows\serviceprofiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

C:\Windows\serviceprofiles\LocalService\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully

C:\Windows\serviceprofiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

C:\Users\rwema\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot

C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot

==== Empty FireFox Cache ======================

No FireFox Cache found

==== Empty Chrome Cache ======================

C:\users\Guest\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully

C:\users\rwema\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully

==== Empty All Flash Cache ======================

Flash Cache Emptied Successfully

==== Empty All Java Cache ======================

Java Cache cleared successfully

After Reboot

==== Empty Temp Folders ======================

C:\Windows\Temp successfully emptied

C:\Users\rwema\AppData\Local\Temp successfully emptied

==== Empty Recycle Bin ======================

C:\$RECYCLE.BIN successfully emptied

==== Deleting Files / Folders ======================

"C:\Users\rwema\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not found

"C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not deleted

Hier de gevraagde log

aangepast door michael1991
smiley's uitgeschakeld
Link naar reactie
Delen op andere sites

Download zoek.exe naar het bureaublad.

  • Schakel je antivirus- en antispywareprogramma's uit, mogelijk kunnen ze conflicteren met zoek.exe
    (hier of hier) kan je lezen hoe je dat doet.
  • Dubbelklik op Zoek.exe om de tool te starten.
  • Windows Vista, 7 en 8 gebruikers dienen de tool als "administrator" uit te voeren door middel van de rechtermuisknop en kiezen voor Als Administrator uitvoeren.
  • Kopieer nu onderstaande code en plak die in het grote invulvenster:
  • Note: Dit script is speciaal bedoeld voor deze PC, gebruik dit dan ook niet op andere PC's met een gelijkaardig probleem.

 
 [b]C:\users\rwema\AppData\Local\SDB56B.tmp;f[/b]
 [b]C:\users\rwema\AppData\Local\WLF54B.tmp;f[/b]
 [b]C:\users\rwema\AppData\Local\VWL54A.tmp;f[/b]
 [b]C:\users\rwema\AppData\Local\MAN4EB.tmp;f[/b]
 [b]C:\Program Files (x86)\DealPly;fs[/b]
 [b]C:\Windows\System32\Tasks\Browser Updater;fs[/b]

  • Klik daarna op de knop "Run script".
  • Wacht nu geduldig af tot er een logje opent (dit kan na een herstart zijn als deze benodigd is).
  • Mocht na de herstart geen logje verschijnen, start zoek.exe dan opnieuw, de log verschijnt dan alsnog.
  • Post nu de inhoud van het geopende logje in het volgende bericht.

Link naar reactie
Delen op andere sites

Zoek.exe Version 4.0.0.2 Updated 12-May-2013

Tool run by rwema on zo 12/05/2013 at 15:24:20,60.

Microsoft® Windows Vista™ Home Premium 6.0.6002 Service Pack 2 x64

Running in: Normal Mode Internet Access Detected

==== Deleting Files \ Folders ======================

"C:\Program Files (x86)\DealPly" not found

"C:\users\rwema\AppData\Local\SDB56B.tmp" deleted

"C:\users\rwema\AppData\Local\WLF54B.tmp" deleted

"C:\users\rwema\AppData\Local\VWL54A.tmp" deleted

"C:\users\rwema\AppData\Local\MAN4EB.tmp" deleted

Hier de logje

- - - Updated - - -

Ik heb de map ''C:\Windows\System32\Tasks\Browser Updater;fs'' manueel verwijderd aangezien zoek.exe geen actie heeft ondernomen, is dat goed?

Link naar reactie
Delen op andere sites

Problemen van de baan, dan is het tijd voor de “grote schoonmaak” : verwijderen van gebruikte programma’s, een cleaning en het verwijderen van de besmette herstelpunten.

Verwijder zoek.exe van je bureaublad.

Download CCleaner.

Klik op “Download Latest Version” en dan start de download van CCleaner automatisch en gratis op.

Installeer het en start CCleaner op. Klik in de linkse kolom op “Cleaner”. Klik achtereenvolgens op ‘Analyseren’ en 'Schoonmaken'. Soms is 1 analyse niet voldoende. Deze procedure mag je herhalen tot de analyse geen fouten meer aangeeft. Klik vervolgens in de linkse kolom op “Register” en klik op ‘Scan naar problemen”. Als er fouten gevonden worden klik je op ”Herstel geselecteerde problemen” en ”OK”. Dan krijg je de vraag om een back-up te maken. Klik op “JA”. Kies dan “Herstel alle geselecteerde fouten”. Sluit hierna CCleaner terug af.

Wil je dit uitgebreid in beeld bekijken, klik dan hier voor de handleiding.

Indien dit allemaal probleemloos verlopen is en je binnen dit topic verder geen vragen of problemen meer hebt, mag je dit onderwerp afsluiten door een klik op de knop "Markeer als opgelost", die je links onderaan kan terugvinden … zo blijft het voor iedereen overzichtelijk.

aangepast door kape
Link naar reactie
Delen op andere sites

×
×
  • Nieuwe aanmaken...

Belangrijke informatie

We hebben cookies geplaatst op je toestel om deze website voor jou beter te kunnen maken. Je kunt de cookie instellingen aanpassen, anders gaan we er van uit dat het goed is om verder te gaan.