Ga naar inhoud

Aanbevolen berichten

Geplaatst:

Ik heb een tijd al last van pop-ups van fences en andere programma's die ik ook niet kan openen

die melden dat ik Microsoft .NET Framework 3.5.1 moet aanzetten. ook eigen gemaakte programmas van VB 2008 kan ik niet openen.

Nu heb ik al een tijd gezocht naar het probleem ook andere netframes gedownload nou heeft dit niks te maken met de 3.5.1 ik heb ook in windows-onderdelen gekeken daar stond hij gewoon aan...

nu probeer ik hem uit te zetten net als ik ergens een tijdje terug had gelezen maar ik kon hem niet uitzetten want als ik hem aan en uit zou zetten zou hij opnieuw downloaden.

nu wil ik graag het probleem oplossen iemand tips?

Geplaatst:

Voer de twee onderstaande zaken uit.

 

Download 51a5f5d096dae-icon_RSIT.png RSIT van de onderstaande locaties en sla deze op het bureaublad op.

Hoe je controleert of je met een 32- of 64-bitversie van Windows werkt kan je 
hier bekijken.

Dubbelklik op RSIT.exe om de tool te starten.

  • Windows Vista, 7 en 8 gebruikers dienen de tool als "administrator" uit te voeren door middel van de rechtermuisknop en kiezen voor Als Administrator uitvoeren.
  • Vervolgens wordt de "Disclaimer of warranty" getoond, klik vervolgens op "Continue"
  • Wanneer de tool gereed is worden er twee kladblok bestanden geopend genaamd "Log.txt" en "Info.txt" .

RSIT Logbestanden plaatsen

  • Voeg het logbestand met de naam "Log.txt" als bijlage toe aan het volgende bericht. (Dit logbestand kunt u tevens terug vinden in de map ""C:\\rsit")
  • Het logbestand met de naam "Info.txt" wat geminimaliseerd is hoeft u niet te plaatsen. (Dit logbestand wordt enkel de eerst keer bij het uitvoeren aangemaakt).
  • Hoe u een bijlage kunt toevoegen aan het bericht leest u hier.

De handleiding voor het gebruik van RSIT kan je HIER bekijken en we hebben ook nog een 

.
 

 
Download CCleaner. (Als je het nog niet hebt) 

Installeer het (als je niet wilt dat Google Chrome op je PC als standaard-webbrowser wordt geïnstalleerd, moet je de 2 vinkjes wegdoen !!!) en start CCleaner op. 

Klik in de linkse kolom op “Cleaner”. 
Klik achtereenvolgens op ‘Analyseren’ en na de analyse op 'Schoonmaken'
Klik vervolgens in de linkse kolom op Register” en klik op ‘Scan naar problemen”
Als er fouten gevonden worden klik je op ”Herstel geselecteerde problemen” en ”OK”
Dan krijg je de vraag om een back-up te maken. Klik op “JA”. 
Kies dan Herstel alle geselecteerde fouten”. 
Soms is 1 analyse niet voldoende. Deze procedure mag je herhalen tot de analyse geen fouten meer aangeeft. 
Sluit hierna CCleaner terug af. 

Wil je dit uitgebreid in beeld bekijken, klik dan hier voor de handleiding. 
Geplaatst:

Geachte Clarkie,

 

dank voor uw snelle reactie ik heb gedaan wat u zei ik hoop dat ik het zo goed gedaan zou hebben.

als dit niet het geval is sorry  :blush: .

Ik hoop dat het probleem gevonden kan worden dat ik weer normaal mijn pc kan gebruiken.

Alvast bedankt voor uw hulp!!! :adore:

 

Floww

 

log.txt

Geplaatst:

De experts die het RSIT logje analyseren zijn verwittigd, zodra ze online komen ontvang je verdere instructies.

 

Kan je ook  ccleaner uitvoeren (bericht 2- punt 2) en het logje in je volgend bericht plaatsen?

Geplaatst:

Schakel je antivirus- en antispywareprogramma's uit, mogelijk kunnen ze conflicteren met zoek.exe (hier en hier) kan je lezen hoe je dat doet.

Download Zoek.pngZoek.exe naar het bureaublad (niet de .zip- of .rar-versie)

  • Wanneer Internet Explorer of een andere browser of virusscanner melding geeft dat dit bestand onveilig zou zijn kun je negeren, dit is namelijk een onterechte waarschuwing.
  • Dubbelklik op Zoek.exe om de tool te starten.
  • Windows Vista, 7 en 8 gebruikers dienen de tool als "administrator" uit te voeren door middel van de rechtermuisknop en kiezen voor Als Administrator uitvoeren.
  • Kopieer nu onderstaande code en plak die in het grote invulvenster:
  • Note: Dit script is speciaal bedoeld voor deze PC, gebruik dit dan ook niet op andere PC's met een gelijkaardig probleem.
{D8278076-BC68-4484-9233-6E7F1628B56C};c
{d2ce3e00-f94a-4740-988e-03dc2f38c34f};c
C:\Program Files (x86)\Microsoft\BingBar;fs
{95B7759C-8C7F-4BF1-B163-73684A933233};c
C:\Program Files (x86)\AVG Secure Search\18.5.0.909\AVG Secure Search_toolbar.dll;f
{8dcb7100-df86-4384-8842-8fa844297b3f};c
vProt;s
vToolbarUpdater18.5.0;s
C:\Windows\tasks\AVG-Secure-Search-Update_JUNE2013_HP_rmv.job;f
C:\Windows\TEMP\{DEDDBB6C-E336-4881-9452-2BD99167C4A3}.exe;f
C:\Windows\tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv.job;f
C:\Windows\TEMP\{1A31B983-9AE4-4BAF-9596-33D26A916F34}.exe;f
CHRdefaults;
C:\Program Files (x86)\Mozilla Firefox\extensions\adapter@babylontc.com;fs
C:\Program Files (x86)\Mozilla Firefox\searchplugins\delta-homes.xml;f
C:\Program Files (x86)\Mozilla Firefox\searchplugins\qone8.xml;f
C:\Program Files (x86)\Mozilla Firefox\searchplugins\avg-secure-search.xml;f
C:\Users\Floww\AppData\Roaming\Mozilla\Firefox\Profiles\reblngg7.default\extensions\7@jJph.edu;fs
C:\Users\Floww\AppData\Roaming\Mozilla\Firefox\Profiles\reblngg7.default\extensions\pHJsP@fnc.com;fs
C:\Users\Floww\AppData\Roaming\Mozilla\Firefox\Profiles\reblngg7.default\extensions\tyA@6.net;fs
C:\Users\Floww\AppData\Roaming\Mozilla\Firefox\Profiles\reblngg7.default\searchplugins\bingp.xml;f
C:\Users\Floww\AppData\Roaming\Mozilla\Firefox\Profiles\reblngg7.default\searchplugins\Linkury Smartbar Search.xml;f
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d9f6c18b-da82-401b-be99-9cac6e95ce62}];r64
[-HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d2ce3e00-f94a-4740-988e-03dc2f38c34f}];r64
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ApnUpdater];r64
C:\Program Files (x86)\Ask.com;fs
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BrowserPlugInHelper];r64
C:\Program Files (x86)\Wondershare;fs
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\vProt];r64
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Wondershare Helper Compact.exe];r64
C:\Program Files (x86)\Common Files\Wondershare;fs
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run];r64
""=-,r64
"vProt"=-;r64
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows];r64
"AppInit_DLLs"=-;r64
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\SharedTaskScheduler];r64
C:\Program Files (x86)\Stardock\Fences;fs
{1984DD45-52CF-49cd-AB77-18F378FEA264};c
C:\found.000,fs
C:\ProgramData\86a67f90000021a4;fs
emptyfolderscheck;delete
startupall;
filesrcm;
  • Klik op de knop "More options" en vink nu de onderstaande opties aan.
  • Do a Quick Scan
  • Auto Clean
  • De optie "Scan All Users" staat standaard aangevinkt.
  • Klik nu op de knop "Run script".
  • Wacht nu geduldig af tot er een logje opent (dit kan na een herstart zijn als deze benodigd is).
  • Mocht er geen logje verschijnen, start zoek.exe dan opnieuw en klik op de knop zoek-results.log, de log verschijnt dan alsnog.
  • Post het geopende logje in het volgende bericht als bijlage.
Zoek.exe logbestand plaatsen
  • Voeg het logbestand met de naam "Zoek-results.log" als bijlage toe aan het volgende bericht. (Dit logbestand kunt u tevens terug vinden op de systeemschijf als C:\Zoek-results.log.)
  • Hoe u een bijlage kunt toevoegen aan het bericht leest u hier.
Geplaatst:

 

 

Ten eerste, bedankt dat jullie mij willen helpen
hij gaf steeds de melding hieronder aan.
daarom probeer ik het op de quote manier. hierna volgt CCleaner
  • zoek-results.log

    Upload Overgeslagen (Geen bestand geselecteerd om te uploaden)

Zoek.exe v5.0.0.0 Updated 04-May-2015
Tool run by Floww on wo 27-05-2015 at 18:54:14,41.
Microsoft Windows 7 Home Premium  6.1.7601 Service Pack 1 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Floww\Downloads\zoek.exe [scan all users]   [Quick Scan] [Auto Clean]
 
==== System Restore Info ======================
 
27-5-2015 18:56:31 Zoek.exe System Restore Point Created Successfully.
 
==== Empty Folders Check ======================
 
C:\PROGRA~2\DSPRobotics deleted successfully
C:\PROGRA~2\MSXML 4.0 deleted successfully
C:\PROGRA~2\OpenVPN Technologies deleted successfully
C:\PROGRA~2\RealFogs deleted successfully
C:\PROGRA~2\SecretCity 3DChat deleted successfully
C:\PROGRA~2\SegmentSustainer deleted successfully
C:\PROGRA~2\Windows Live Safety Center deleted successfully
C:\PROGRA~2\Xenocode deleted successfully
C:\PROGRA~2\COMMON~1\EPSON deleted successfully
C:\PROGRA~2\COMMON~1\Symantec Shared deleted successfully
C:\PROGRA~2\COMMON~1\Voyetra deleted successfully
C:\Program Files\Google deleted successfully
C:\Program Files\Image-Line deleted successfully
C:\PROGRA~3\86a67f90000021a4 deleted successfully
C:\PROGRA~3\Oracle deleted successfully
C:\PROGRA~3\xml_param deleted successfully
C:\Users\Floww\AppData\Roaming\Pamela deleted successfully
C:\Users\Floww\AppData\Roaming\Windows Live Writer deleted successfully
C:\Users\Floww\AppData\Roaming\{950EB46C-6AC7-4ACC-AB36-9A6A77C08B6A} deleted successfully
C:\Users\Floww\AppData\Local\2012 deleted successfully
C:\Users\Floww\AppData\Local\PackageAware deleted successfully
C:\Users\Floww\AppData\Local\TSVNCache deleted successfully
 
==== Deleting CLSID Registry Keys ======================
 
HKEY_USERS\S-1-5-21-3501343686-3067846119-1440391343-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8dcb7100-df86-4384-8842-8fa844297b3f} deleted successfully
HKEY_USERS\S-1-5-21-3501343686-3067846119-1440391343-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{d2ce3e00-f94a-4740-988e-03dc2f38c34f} deleted successfully
HKEY_USERS\S-1-5-21-3501343686-3067846119-1440391343-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8} deleted successfully
HKEY_USERS\S-1-5-21-3501343686-3067846119-1440391343-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9421DD08-935F-4701-A9CA-22DF90AC4EA6} deleted successfully
HKEY_USERS\S-1-5-21-3501343686-3067846119-1440391343-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{9421DD08-935F-4701-A9CA-22DF90AC4EA6} deleted successfully
HKEY_USERS\S-1-5-21-3501343686-3067846119-1440391343-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5018CFD2-804D-4C99-9F81-25EAEA2769DE} deleted successfully
HKEY_USERS\S-1-5-21-3501343686-3067846119-1440391343-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{5018CFD2-804D-4C99-9F81-25EAEA2769DE} deleted successfully
HKEY_USERS\S-1-5-21-3501343686-3067846119-1440391343-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E87806B5-E908-45FD-AF5E-957D83E58E68} deleted successfully
HKEY_USERS\S-1-5-21-3501343686-3067846119-1440391343-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{E87806B5-E908-45FD-AF5E-957D83E58E68} deleted successfully
HKEY_USERS\S-1-5-21-3501343686-3067846119-1440391343-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{338B4DFE-2E2C-4338-9E41-E176D497299E} deleted successfully
HKEY_USERS\S-1-5-21-3501343686-3067846119-1440391343-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{338B4DFE-2E2C-4338-9E41-E176D497299E} deleted successfully
HKEY_USERS\S-1-5-21-3501343686-3067846119-1440391343-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2} deleted successfully
HKEY_USERS\S-1-5-21-3501343686-3067846119-1440391343-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2} deleted successfully
HKEY_USERS\S-1-5-21-3501343686-3067846119-1440391343-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E8DE9422-3B2C-4243-BF6F-235DA84D8EF8} deleted successfully
HKEY_USERS\S-1-5-21-3501343686-3067846119-1440391343-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{E8DE9422-3B2C-4243-BF6F-235DA84D8EF8} deleted successfully
HKEY_USERS\S-1-5-21-3501343686-3067846119-1440391343-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{30F9B915-B755-4826-820B-08FBA6BD249D} deleted successfully
HKEY_USERS\S-1-5-21-3501343686-3067846119-1440391343-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{30F9B915-B755-4826-820B-08FBA6BD249D} deleted successfully
HKEY_USERS\S-1-5-21-3501343686-3067846119-1440391343-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{32099AAC-C132-4136-9E9A-4E364A424E17} deleted successfully
HKEY_USERS\S-1-5-21-3501343686-3067846119-1440391343-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{32099AAC-C132-4136-9E9A-4E364A424E17} deleted successfully
HKEY_USERS\S-1-5-21-3501343686-3067846119-1440391343-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{14f0d511-36a2-41ca-ae01-ba4f87282c97} deleted successfully
HKEY_USERS\S-1-5-21-3501343686-3067846119-1440391343-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{57BCA5FA-5DBB-45a2-B558-1755C3F6253B} deleted successfully
HKEY_USERS\S-1-5-21-3501343686-3067846119-1440391343-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8F8DB554-01CE-4ED6-99B9-FD245632E0EE} deleted successfully
HKEY_USERS\S-1-5-21-3501343686-3067846119-1440391343-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E0A900DF-9611-4446-86BD-4B1D47E7DB2A} deleted successfully
HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{8dcb7100-df86-4384-8842-8fa844297b3f} deleted successfully
HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{d2ce3e00-f94a-4740-988e-03dc2f38c34f} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d2ce3e00-f94a-4740-988e-03dc2f38c34f} deleted successfully
 
==== Deleting CLSID Registry Values ======================
 
HKEY_USERS\S-1-5-21-3501343686-3067846119-1440391343-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{338B4DFE-2E2C-4338-9E41-E176D497299E} deleted successfully
HKEY_USERS\S-1-5-21-3501343686-3067846119-1440391343-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{2318C2B1-4965-11D4-9B18-009027A5CD4F} deleted successfully
HKEY_USERS\S-1-5-21-3501343686-3067846119-1440391343-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2} deleted successfully
HKEY_USERS\S-1-5-21-3501343686-3067846119-1440391343-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{E8DE9422-3B2C-4243-BF6F-235DA84D8EF8} deleted successfully
HKEY_USERS\S-1-5-21-3501343686-3067846119-1440391343-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{30F9B915-B755-4826-820B-08FBA6BD249D} deleted successfully
HKEY_USERS\S-1-5-21-3501343686-3067846119-1440391343-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{C424171E-592A-415A-9EB1-DFD6D95D3530} deleted successfully
HKEY_USERS\S-1-5-21-3501343686-3067846119-1440391343-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{32099AAC-C132-4136-9E9A-4E364A424E17} deleted successfully
HKEY_USERS\S-1-5-21-3501343686-3067846119-1440391343-1000\Software\Microsoft\Internet Explorer\URLSearchHooks\{D8278076-BC68-4484-9233-6E7F1628B56C} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{8dcb7100-df86-4384-8842-8fa844297b3f} deleted successfully
HKEY_LOCAL_MACHINE\software\Wow6432Node\mozilla\Firefox\extensions\{3C5F0F00-683D-4847-89C8-E7AF64FD1CFB} deleted successfully
HKEY_LOCAL_MACHINE\software\Wow6432Node\mozilla\Firefox\extensions\quick_start@gmail.com deleted successfully
HKEY_LOCAL_MACHINE\software\Wow6432Node\mozilla\Firefox\extensions\quick_searchff@gmail.com deleted successfully
 
==== Deleting Services ======================
 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\vToolbarUpdater18.5.0 deleted successfully
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\vToolbarUpdater18.5.0 deleted successfully
 
==== FireFox Fix ======================
 
ProfilePath: C:\Users\Floww\AppData\Roaming\Mozilla\Firefox\Profiles\reblngg7.default
 
user.js not found
---- Lines Softonic removed from prefs.js ----
user_pref("browser.search.order.1", "Search the web (Softonic)");
user_pref("extensions.Softonic.admin", false);
user_pref("extensions.Softonic.aflt", "SD");
user_pref("extensions.Softonic.appId", "{7ABBFE1C-E485-44AA-8F36-353751B4124D}");
user_pref("extensions.Softonic.autoRvrt", "false");
user_pref("extensions.Softonic.cntry", "NL");
user_pref("extensions.Softonic.dfltLng", "");
user_pref("extensions.Softonic.dfltSrch", true);
user_pref("extensions.Softonic.dnsErr", true);
user_pref("extensions.Softonic.dpkLst", "3654782829,1334533236,1121012847,231756876,1895130307,603719297,4288797614,3754950497,426401714,3046281807,75
user_pref("extensions.Softonic.excTlbr", false);
user_pref("extensions.Softonic.ffxUnstlRst", false);
user_pref("extensions.Softonic.hdrMd5", "DBFA12F01BFCF5A00C233C49F05412A3");
user_pref("extensions.Softonic.hmpg", true);
user_pref("extensions.Softonic.hpOld0", "http://nl.ask.com/?l=dis&o=102875&gct=hp");
user_pref("extensions.Softonic.id", "82f83645000000000000e0cb4ea85f43");
user_pref("extensions.Softonic.instlDay", "15863");
user_pref("extensions.Softonic.instlRef", "MOY00011");
user_pref("extensions.Softonic.lastVrsnTs", "1.8.19.320:49:11");
user_pref("extensions.Softonic.newTab", true);
user_pref("extensions.Softonic.pnu_BASEirobinhoodActive", "{\"newVrsn\":\"53\",\"lastVrsn\":\"53\",\"vrsnLoad\":\"\",\"showMsg\":\"false\",\"showSilen
user_pref("extensions.Softonic.prdct", "Softonic");
user_pref("extensions.Softonic.prtnrId", "softonic");
user_pref("extensions.Softonic.rvrt", "false");
user_pref("extensions.Softonic.sg", "none");
user_pref("extensions.Softonic.smplGrp", "none");
user_pref("extensions.Softonic.srchPrvdr", "Search the web (Softonic)");
user_pref("extensions.Softonic.storage\\storage\\mpvfloatingwindmutex", "436251860594180@@@Thu Jan 01 1970 01:00:00 GMT+0100");
user_pref("extensions.Softonic.storage\\storage\\mpvinpagemutex", "7f5d449761bc80ffd73f4a77210d15b5@@@Wed Feb 12 2014 20:15:48 GMT+0100");
user_pref("extensions.Softonic.tlbrId", "BASEirobinhoodActive");
user_pref("extensions.Softonic.vrsn", "1.8.19.3");
user_pref("extensions.Softonic.vrsnTs", "1.8.19.320:49:11");
user_pref("extensions.Softonic.vrsni", "1.8.19.3");
user_pref("extensions.asktb.first-launch-url", "file:///C:/Users/Floww/AppData/Local/Temp/mt_ffx/Softonic/Softonic/1.8.19.3/Softonic.xpi");
---- Lines babsrc removed from prefs.js ----
---- Lines WebSearch removed from prefs.js ----
user_pref("extensions.asktb.http-header-whitelist-hosts", "[\"static-dev.en.dev.ask.com\", \"ask.com\", \"www.facebook.com\", \"www.playsushi.com\", \
---- Lines babylon removed from prefs.js ----
user_pref("browser.babylon.HPOnNewTab", "search.babylon.com");
---- Lines ask.com removed from prefs.js ----
user_pref("extensions.asktb.default-channel-url-mask", "http://nl.ask.com/web?q={query}&qsrc={qsrc}&o={o}&l={l}&gct=bar");
user_pref("extensions.asktb.InstallDir", "C:\\Program Files (x86)\\Ask.com\\");
---- Lines ask.com modified from prefs.js ----
 
user_pref("extensions.enabledItems", "helperbar@helperbar.com:1.0,{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20,toolbar@ask.com:3.13.1.18107,{12e4c684
---- Lines quick_start removed from prefs.js ----
user_pref("browser.newtab.url", "chrome://quick_start/content/index.html");
user_pref("extensions.quick_start.enable_search1", false);
user_pref("extensions.quick_start.sd.closeWindowWithLastTab_prev_state", false);
---- Lines asktb removed from prefs.js ----
user_pref("extensions.asktb.apn_dbr", "cr_22.0.1229.94");
user_pref("extensions.asktb.autofill-competitor-query-enabled", true);
user_pref("extensions.asktb.cbid", "^AIT");
user_pref("extensions.asktb.config-updated", true);
user_pref("extensions.asktb.cr-o", "APN10416cr");
user_pref("extensions.asktb.crumb", "2012.11.03+03.58.19-toolbar013iad-NL-QW1zdGVyZGFtLE5ldGhlcmxhbmRz");
user_pref("extensions.asktb.displaybehavior", "");
user_pref("extensions.asktb.displaytext", "");
user_pref("extensions.asktb.dtid", "^zzz003^YY^NL");
user_pref("extensions.asktb.dyn-weather-do-locid-lookup-weatherWidget", false);
user_pref("extensions.asktb.dyn-weather-locid-weatherWidget", "NLXX0002");
user_pref("extensions.asktb.dyn-weather-tempunit-weatherWidget", "C");
user_pref("extensions.asktb.first-restart-after-config-update", true);
user_pref("extensions.asktb.fresh-install", false);
user_pref("extensions.asktb.guid", "1049151b-3e64-45aa-bd1b-25a59a5f756c");
user_pref("extensions.asktb.if", "first");
user_pref("extensions.asktb.keyword-toggled-in-session", false);
user_pref("extensions.asktb.l", "dis");
user_pref("extensions.asktb.last-config-req", "1426422136834");
user_pref("extensions.asktb.locale", "nl_NL");
user_pref("extensions.asktb.location", "Amsterdam,Netherlands");
user_pref("extensions.asktb.lstation", "");
user_pref("extensions.asktb.new-tab-opt-out", true);
user_pref("extensions.asktb.news-native-on", true);
user_pref("extensions.asktb.o", "APN10416");
user_pref("extensions.asktb.overlay-reloaded-using-restart", true);
user_pref("extensions.asktb.pstate", "");
user_pref("extensions.asktb.qsrc", "2871");
user_pref("extensions.asktb.r", "4");
user_pref("extensions.asktb.sa", "NO");
user_pref("extensions.asktb.search-suggestions-enabled", true);
user_pref("extensions.asktb.silent-upgrade-from-pre-newtabs-build", false);
user_pref("extensions.asktb.silent-upgrade", true);
user_pref("extensions.asktb.socialmini-first", true);
user_pref("extensions.asktb.socialmini-interval", "1200000");
user_pref("extensions.asktb.socialmini-max-char-ticker", "33");
user_pref("extensions.asktb.socialmini-max-items", "30");
user_pref("extensions.asktb.socialmini-native-on", true);
user_pref("extensions.asktb.socialmini-speed", "10000");
user_pref("extensions.asktb.socialmini-transition-first-open", false);
user_pref("extensions.asktb.themeid", "");
user_pref("extensions.asktb.timeinstalled", "3-11-2012 11:58:48");
user_pref("extensions.asktb.to", "");
user_pref("extensions.asktb.v", "3.17.7.100013");
user_pref("extensions.asktb.version", "5.17.7.45269");
user_pref("extensions.asktb.volume", "");
---- Lines y2layers removed from prefs.js ----
user_pref("extentions.y2layers.defaultEnableAppsList", "twittube,buzzdock,YontooNewOffers");
user_pref("extentions.y2layers.installId", "32424ba2-7d70-4f89-aa0b-4342d2070076");
---- Lines helperbar modified from prefs.js ----
 
user_pref("extensions.enabledItems", "helperbar@helperbar.com:1.0,{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20,toolbar@disabled:3.13.1.18107,{12e4c68
---- Lines browser.startup.page removed from prefs.js ----
user_pref("browser.startup.page", 1);
---- Lines {3C5F0F00-683D-4847-89C8-E7AF64FD1CFB} modified from prefs.js ----
 
user_pref("extensions.enabledItems", "disabled@disabled.com:1.0,{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20,toolbar@disabled:3.13.1.18107,{12e4c684-
---- Lines quick_searchff@gmail.com modified from prefs.js ----
 
user_pref("extensions.enabledAddons", "desktop@clipconverter.cc:1.0.0,quick_searchff@gmail.com:5.4.10,{972ce4c6-7e08-4474-a285-3208198ce6fd}:14.0.1");
---- FireFox user.js and prefs.js backups ---- 
 
prefs_27-05-2015_1915_.backup
 
==== Deleting Files \ Folders ======================
 
C:\PROGRA~2\DSPRobotics not found
C:\PROGRA~2\OpenVPN Technologies not found
C:\PROGRA~2\RealFogs not found
C:\PROGRA~2\SecretCity 3DChat not found
C:\PROGRA~2\SegmentSustainer not found
C:\PROGRA~2\Windows Live Safety Center not found
C:\PROGRA~2\Xenocode not found
C:\Users\Floww\AppData\Roaming\Mozilla\Firefox\Profiles\reblngg7.default\extensions\quick_searchff@gmail.com not found
C:\PROGRA~2\BeestSoaaVoeFOrYou deleted
C:\PROGRA~2\DigiCouPOn deleted
C:\PROGRA~2\DiscounotExtenssi deleted
C:\PROGRA~2\DoWNNSaeve deleted
C:\PROGRA~2\ExsturaiCoupon deleted
C:\PROGRA~2\RobboiSaVer deleted
C:\PROGRA~2\Shioppi deleted
C:\PROGRA~2\VstPlugins deleted
C:\PROGRA~2\CCheapMei deleted
C:\PROGRA~2\coiNNsavie deleted
C:\PROGRA~2\Facebook Social Plugin deleted
C:\PROGRA~2\MMinimUmPrice deleted
C:\PROGRA~2\Popular Bookmarks deleted
C:\PROGRA~2\ReoGuLarDEals deleted
C:\PROGRA~2\WebCamera360 deleted
C:\Users\Floww\AppData\Roaming\.technic deleted
C:\Users\Floww\AppData\Roaming\nswb deleted
C:\PROGRA~3\{8f7b635f-b06a-b490-8f7b-b635fb068d7e} deleted
C:\PROGRA~3\1149781824708409830 deleted
C:\Users\Floww\.android deleted
C:\PROGRA~2\Mozilla Firefox\browser\searchplugins\avg-secure-search.xml deleted
C:\PROGRA~2\Mozilla Firefox\searchplugins\avg-secure-search.xml deleted
C:\PROGRA~2\Pamela RichMood Editor deleted
C:\PROGRA~2\myBabylon_English4 deleted
C:\PROGRA~2\Wondershare deleted
C:\2280.tmp deleted
C:\found.000 deleted
C:\Users\Floww\AppData\Roaming\appdataFr3.bin deleted
C:\Users\Floww\AppData\Roaming\RSBot Accounts.ini deleted
C:\PROGRA~3\Avg_Update_0814tb deleted
C:\PROGRA~3\Wondershare Video Converter Ultimate deleted
C:\PROGRA~3\C__Users_Floww_Downloads_Hide IP Easy v5082WinAll_FAnTAST_HideIPEasy.exe deleted
C:\PROGRA~3\AVG Secure Search deleted
C:\PROGRA~3\Package Cache deleted
C:\Users\Floww\AppData\Local\AVG Secure Search deleted
C:\Users\Floww\AppData\Local\Wondershare deleted
C:\Users\Floww\AppData\Local\CrashRpt deleted
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wondershare deleted
C:\Users\Floww\AppData\LocalLow\vidtomp3tb deleted
C:\Users\Floww\AppData\LocalLow\ShopperReports3 deleted
C:\Users\Floww\AppData\LocalLow\AVG Secure Search deleted
C:\Users\Floww\AppData\LocalLow\myBabylon_English4 deleted
C:\Users\Floww\AppData\LocalLow\ConduitEngine deleted
C:\Users\Floww\AppData\LocalLow\Toolbar4 deleted
C:\Windows\sysWoW64\config\systemprofile\AppData\LocalLow\AVG Secure Search deleted
C:\AI_RecycleBin deleted
C:\Windows\tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv.job deleted
C:\windows\SysNative\tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv deleted
C:\Windows\tasks\AVG-Secure-Search-Update_JUNE2013_HP_rmv.job deleted
C:\Windows\SysNative\config\systemprofile\Searches deleted
C:\Windows\SysWow64\AI_RecycleBin deleted
C:\Users\Floww\AppData\Roaming\Mozilla\Firefox\Profiles\reblngg7.default\searchplugins\bingp.xml deleted
C:\Users\Floww\AppData\Roaming\Mozilla\Firefox\Profiles\reblngg7.default\searchplugins\Linkury Smartbar Search.xml deleted
C:\Users\Floww\AppData\Roaming\Mozilla\Firefox\Profiles\reblngg7.default\SHOUTcastToolbarData deleted
C:\Users\Floww\crosshair.exe deleted
C:\Users\Floww\HC2Setup.exe deleted
C:\Users\Floww\java_JRE_6_4_5_4.exe deleted
C:\Users\Floww\NortonAV.exe deleted
C:\Users\Floww\AppData\Roaming\Mozilla\Firefox\Profiles\reblngg7.default\extensions\7@jJph.edu deleted
C:\Users\Floww\AppData\Roaming\Mozilla\Firefox\Profiles\reblngg7.default\extensions\pHJsP@fnc.com deleted
C:\Users\Floww\AppData\Roaming\Mozilla\Firefox\Profiles\reblngg7.default\extensions\tyA@6.net deleted
C:\PROGRA~2\Mozilla Firefox\extensions\adapter@babylontc.com deleted
"C:\Users\Floww\AppData\Local\LumaEmu" deleted
"C:\Users\Floww\AppData\Roaming\chrtmp" deleted
"C:\Users\Floww\AppData\Roaming\D2Info0" deleted
"C:\Users\Floww\AppData\Roaming\DofusAppId0_2" deleted
"C:\ProgramData\droidcam-settings" deleted
"C:\PROGRA~2\AVG Secure Search\vprot.exe" deleted
"C:\PROGRA~2\AVG Secure Search\vprot.exe" deleted
"C:\PROGRA~2\COMMON~1\AVG Secure Search\DNTInstaller\18.5.0\avgdttbx.dll" deleted
"C:\PROGRA~2\COMMON~1\AVG Secure Search\SiteSafetyInstaller\18.5.0\SiteSafety.dll" deleted
"C:\PROGRA~2\COMMON~1\AVG Secure Search\vToolbarUpdater\18.5.0\log4cplusU.dll" deleted
"C:\PROGRA~2\AVG Secure Search" deleted
"C:\PROGRA~2\AVG Secure Search" deleted
"C:\PROGRA~2\COMMON~1\AVG Secure Search" deleted
"C:\PROGRA~2\COMMON~1\AVG Secure Search\DNTInstaller" deleted
"C:\PROGRA~2\COMMON~1\AVG Secure Search\SiteSafetyInstaller" deleted
"C:\PROGRA~2\COMMON~1\AVG Secure Search\vToolbarUpdater" deleted
"C:\PROGRA~2\COMMON~1\AVG Secure Search\DNTInstaller\18.5.0" deleted
"C:\PROGRA~2\COMMON~1\AVG Secure Search\SiteSafetyInstaller\18.5.0" deleted
"C:\PROGRA~2\COMMON~1\AVG Secure Search\vToolbarUpdater\18.5.0" deleted
 
==== Files Recently Created / Modified ======================
 
====== C:\Windows ====
====== C:\Users\Floww\AppData\Local\Temp ====
2015-05-27 14:57:35 50754352847B5E71E11ABF4D30407148 441220 ------w- C:\Users\Floww\AppData\Local\Temp\jna\jna2895384403285622079.dll
====== Java Cache =====
====== C:\Windows\SysWOW64 =====
2015-05-25 16:32:06 EE88CADD249395CC12741D88EEA3BC35 154624 ----a-w- C:\Windows\SysWOW64\iisRtl.dll
2015-05-25 16:32:04 D6280BDDB45463C8CA6A647E2CFABA94 50688 ----a-w- C:\Windows\SysWOW64\admwprox.dll
2015-05-25 16:32:03 479B88F7F2AA681060E40A4B01791E80 15360 ----a-w- C:\Windows\SysWOW64\iisreset.exe
2015-05-25 16:32:01 E6DA0BCF9660745FEAB85ED1BE3B092E 26624 ----a-w- C:\Windows\SysWOW64\ahadmin.dll
2015-05-25 16:32:01 9DDC99B7B0A004EE28B2EDE5F9C708D6 8192 ----a-w- C:\Windows\SysWOW64\iisrstap.dll
2015-05-25 16:32:01 41F9727BD583653674A37F1136707480 10752 ----a-w- C:\Windows\SysWOW64\wamregps.dll
2015-05-13 21:23:03 858EB73F68B20A2A5C66B6C000D1C0DD 102608 ----a-w- C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
====== C:\Windows\SysWOW64\drivers =====
====== C:\Windows\Sysnative =====
2015-05-25 16:32:07 54CB2D6909E6CCDC3177E1D2B68D7610 192000 ----a-w- C:\Windows\Sysnative\iisRtl.dll
2015-05-25 16:32:06 EDC5E337D2CCD95150E89AD9E777778F 55296 ----a-w- C:\Windows\Sysnative\admwprox.dll
2015-05-25 16:32:03 AAA1E0A0BC59365370CE1624D9FC23FE 16896 ----a-w- C:\Windows\Sysnative\iisreset.exe
2015-05-25 16:32:02 059A7E2F57BB2668DCDA5880D3A31CFC 60928 ----a-w- C:\Windows\Sysnative\ahadmin.dll
2015-05-25 16:32:01 80CA0CCD8356DD20A82F5DDF32B46AD0 11264 ----a-w- C:\Windows\Sysnative\iisrstap.dll
2015-05-25 16:32:01 8055165FC1D534AB338A2C3E09496B55 14848 ----a-w- C:\Windows\Sysnative\wamregps.dll
2015-05-23 21:06:35 F71D352DE149B7137F631877C831E818 119522 ----a-w- C:\Windows\Sysnative\.crusader
2015-05-13 21:23:03 189FB45D7442083AE8A2E4E612233EF7 124112 ----a-w- C:\Windows\Sysnative\PresentationCFFRasterizerNative_v0300.dll
====== C:\Windows\Sysnative\drivers =====
2015-05-13 02:57:00 8FE94F2EF9BF444E93E35D87E210D02F 155584 ----a-w- C:\Windows\Sysnative\drivers\ksecpkg.sys
2015-05-13 02:56:59 F7DFAE6040AC910B7C64EE208A34157D 95680 ----a-w- C:\Windows\Sysnative\drivers\ksecdd.sys
2015-05-02 18:08:31 91310683D7B6B292B746D60734B59322 206080 ----a-w- C:\Windows\Sysnative\drivers\ssudmdm.sys
2015-05-02 18:08:31 30710AEFCE721CEEE0F35EB6A01C263C 110336 ----a-w- C:\Windows\Sysnative\drivers\ssudbus.sys
2015-05-02 17:49:18 FE9A13534CD7435B574AE82CDDC087DA 33080 ----a-w- C:\Windows\Sysnative\drivers\droidcam.sys
2015-05-02 17:49:18 D8C4AC288142FCAC07E6F501FE963695 228408 ----a-w- C:\Windows\Sysnative\drivers\droidcamvideo.sys
====== C:\Windows\Tasks ======
====== C:\Windows\Temp ======
======= C:\Program Files =====
2015-05-27 15:11:22 -------- d-----w- C:\Program Files\trend micro
2015-05-06 15:03:47 -------- d-----w- C:\Program Files\TAP-Windows
2015-05-02 18:07:38 -------- d-----w- C:\Program Files\SAMSUNG
======= C:\PROGRA~2 =====
2015-05-02 17:49:17 -------- d-----w- C:\PROGRA~2\DroidCam
2015-04-30 18:16:28 -------- d-----w- C:\PROGRA~2\Cheat Engine 6.4
======= C: =====
====== C:\Users\Floww\AppData\Roaming ======
2015-05-27 07:40:33 -------- d-----w- C:\Users\Floww\AppData\Local\Temporary Projects
2015-05-25 13:25:25 05ED2F22552068A78EBD1A1A0D1728A7 131976 ----a-w- C:\Users\DefaultAppPool\AppData\Local\GDIPFONTCACHEV1.DAT
2015-05-25 13:25:22 -------- d-----w- C:\Users\DefaultAppPool\AppData\Roaming\Media Center Programs
2015-05-25 13:25:22 -------- d-----w- C:\Users\DefaultAppPool\AppData\Local\Temp
2015-05-25 13:25:22 -------- d-----w- C:\Users\DefaultAppPool\AppData\Local\Microsoft Help
2015-05-25 13:25:22 -------- d-----w- C:\Users\DefaultAppPool\AppData\Local\Microsoft
2015-05-25 13:25:21 -------- d-s---w- C:\Users\DefaultAppPool\AppData\Roaming\Microsoft
2015-05-25 13:25:21 -------- d-----w- C:\Users\DefaultAppPool\AppData\Roaming\TuneUp Software
2015-05-25 13:25:21 -------- d-----r- C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-05-25 13:25:21 -------- d-----r- C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-05-18 12:15:18 -------- d-----w- C:\Users\Floww\AppData\Roaming\steam.transformice.com
2015-05-02 17:51:22 -------- d-----w- C:\Users\Floww\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DroidCam
2015-04-30 16:53:35 -------- d-sh--w- C:\Users\Floww\AppData\Local\EmieBrowserModeList
====== C:\Users\Floww ======
2015-05-27 15:10:56 8045ABB21A3BDD66A48E1ED5C0F0EF6A 1222144 ----a-w- C:\Users\Floww\Downloads\RSITx64.exe
2015-05-27 09:30:55 EF27474307E194D4192077AB3541EB23 4194304 ----a-w- C:\Windows\serviceprofiles\networkservice\msmqlog.bin
2015-05-27 09:19:02 C626670633DDCC2A66B0D935195CF2A1 2959376 ----a-w- C:\Users\Floww\Downloads\dotnetfx35setup (1).exe
2015-05-27 09:01:55 EE01FC4110C73A8E5EFC7CABDA0F5FF7 69999448 ----a-w- C:\Users\Floww\Downloads\NDP452-KB2901907-x86-x64-AllOS-ENU.exe
2015-05-27 07:31:09 B23B61FF159F036FC0987CF4E24479D1 2729464 ----a-w- C:\Users\Floww\Downloads\vbsetup.exe
2015-05-25 16:43:07 C64FD1F972822ED84378C7058FEA0744 25001480 ----a-w- C:\Users\Floww\Downloads\NetFx20SP2_x86.exe
2015-05-25 16:43:06 AD55AD64B69FED73807429859291DB8C 48524296 ----a-w- C:\Users\Floww\Downloads\NetFx20SP2_x64.exe
2015-05-25 13:25:30 6FC234AD3752E1267B34FB12BCD6718B 20 --sh--w- C:\Users\DefaultAppPool\ntuser.ini
2015-05-25 13:25:21 -------- d--h--w- C:\Users\DefaultAppPool\AppData
2015-05-25 13:25:21 -------- d-----w- C:\Users\DefaultAppPool\Saved Games
2015-05-25 13:25:21 -------- d-----r- C:\Users\DefaultAppPool\Videos
2015-05-25 13:25:21 -------- d-----r- C:\Users\DefaultAppPool\Pictures
2015-05-25 13:25:21 -------- d-----r- C:\Users\DefaultAppPool\Music
2015-05-25 13:25:21 -------- d-----r- C:\Users\DefaultAppPool\Links
2015-05-25 13:25:21 -------- d-----r- C:\Users\DefaultAppPool\Favorites
2015-05-25 13:25:21 -------- d-----r- C:\Users\DefaultAppPool\Downloads
2015-05-25 13:25:21 -------- d-----r- C:\Users\DefaultAppPool\Documents
2015-05-25 13:25:21 -------- d-----r- C:\Users\DefaultAppPool\Desktop
2015-05-24 18:30:19 5A4DFFDB6E779867F0F579CF62C6BF6A 2238600 ----a-w- C:\Users\Floww\Downloads\DefaultPack.EXE
2015-05-24 13:47:29 53406E9988306CBD4537677C5336ABA4 889416 ----a-w- C:\Users\Floww\Downloads\dotNetFx40_Full_setup.exe
2015-05-24 12:09:57 C626670633DDCC2A66B0D935195CF2A1 2959376 ----a-w- C:\Users\Floww\Downloads\dotnetfx35setup.exe
2015-05-23 21:52:38 CB5298F411EBC26DA098B8A7C2D1B901 152206277 ----a-w- C:\Users\Floww\Downloads\18187_06.exe
2015-05-23 20:37:19 -------- d-----w- C:\ProgramData\HitmanPro
2015-05-23 20:37:07 2F82DA89FA41B104E27A3BAA0872B850 11024496 ----a-w- C:\Users\Floww\Downloads\HitmanPro_x64.exe
2015-05-18 12:37:10 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-05-18 12:35:26 90ADE8CC7B6F5D1645BC69B7C7D39094 880208 ----a-w- C:\Users\Floww\Downloads\ChromeSetup.exe
2015-05-02 18:06:48 -------- d-----w- C:\ProgramData\Samsung
2015-04-30 18:16:30 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cheat Engine 6.4
 
====== C: exe-files ==
2015-05-27 15:11:23 9A2347903D6EDB84C10F288BC0578C1C 388608 ----a-w- C:\Program Files\trend micro\Floww.exe
2015-05-26 08:16:21 2D7D54B47ACFAB94671E3C97B2D2E639 1106512 ----a-w- C:\Program Files (x86)\Google\Update\Install\{1990D9E5-9988-45F9-950B-2D370D080FB3}\43.0.2357.81_43.0.2357.65_chrome_updater.exe
2015-05-26 08:16:21 2D7D54B47ACFAB94671E3C97B2D2E639 1106512 ----a-w- C:\Program Files (x86)\Google\Update\Download\{4DC8B4CA-1BDA-483E-B5FA-D3C12E15B62D}\43.0.2357.81\43.0.2357.81_43.0.2357.65_chrome_updater.exe
2015-05-22 11:57:30 BD9535D41C5CCC639BB99DC45A2D3556 259960 ----a-w- C:\download\driver\18187_06\Win64\Inst.exe
2015-05-22 11:57:30 61A5FB191AE2AE876DB31DCCE75E4183 1822520 ----a-w- C:\download\driver\18187_06\Win64\instmsiw.exe
2015-05-22 11:57:30 5E685EE8AB27E9BDE078F4AAE06000B6 10095992 ----a-w- C:\download\driver\18187_06\Win64\Setup.exe
2015-05-22 11:57:30 43F7305C2E5DD4A8F3C5ABEB2FFE4833 1708856 ----a-w- C:\download\driver\18187_06\Win64\instmsia.exe
2015-05-22 11:57:25 C37F27E8D4A9507A4DBEF0B525D79639 8890728 ----a-w- C:\download\driver\18187_06\Setup.exe
2015-05-22 11:57:24 251743DFD3FDA414570524BAC9E55381 50449456 ----a-w- C:\download\driver\18187_06\Custom\dotNetFx40_Full_x86_x64.exe
2015-05-21 19:20:11 F937F6DC6D1A7B9A4B990AB955CC8A43 18562552 ----a-w- C:\$Recycle.Bin\S-1-5-21-3501343686-3067846119-1440391343-1000\$RM7RHLK\releases\0.0.1.30\deploy\League of Legends.exe
2015-05-21 14:18:06 CCAF0DCB4BEF3FCD615E15B46B22F349 6714960 ----a-w- C:\Program Files (x86)\Google\Update\Install\{A765D396-BF9A-48CB-8F36-8A25D7118B6D}\43.0.2357.65_42.0.2311.152_chrome_updater.exe
=== C: other files ==
2015-05-22 11:57:27 EDD953D635F3AA89EF902E3F82D60D22 21544 ----a-w- C:\download\driver\18187_06\Win64\btwrchid.sys
2015-05-22 11:57:27 B6093B9B6A0238CC1239B019357BA5FF 598328 ----a-w- C:\download\driver\18187_06\Win64\btwampfl.sys
2015-05-22 11:57:27 B1ACFD00CDD13B48D86F46BFEC153BF9 39976 ----a-w- C:\download\driver\18187_06\Win64\BTWL2CAP.sys
2015-05-22 11:57:27 AC602E3B6940B48E454D90545D85E8C3 89640 ----a-w- C:\download\driver\18187_06\Win64\btwdpan.sys
2015-05-22 11:57:27 A771078558477068DFD8037B82EB00F8 184144 ----a-w- C:\download\driver\18187_06\Win64\btwaudio.sys
2015-05-22 11:57:27 9FF58F76024D25784755B01F926B00BE 210984 ----a-w- C:\download\driver\18187_06\Win64\btwavdt.sys
2015-05-22 11:57:26 D70CEC0C62FDC1772ACD42EEF467F491 165688 ----a-w- C:\download\driver\18187_06\Win64\bcbtums.sys
2015-05-21 11:21:20 653008B2BC9B2B1711B985DCFE161707 2997389 ----a-w- C:\Users\Floww\Downloads\NodusLauncher.zip
 
==== Startup Registry Enabled ======================
 
[HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun"
 
[HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun"
 
[HKEY_USERS\S-1-5-21-3501343686-3067846119-1440391343-1000\Software\Microsoft\Windows\CurrentVersion\Run]
"Steam"="C:\Program Files (x86)\Steam\steam.exe -silent"
"Skype"="C:\Program Files (x86)\Skype\Phone\Skype.exe /minimized /regrun"
"BitTorrent"="C:\Program Files (x86)\BitTorrent\BitTorrent.exe  /MINIMIZED"
"CyberGhost"="C:\Program Files\CyberGhost 5\CyberGhost.EXE /autostart"
 
[HKEY_USERS\S-1-5-82-3006700770-424185619-1745488364-794895919-4004696415\Software\Microsoft\Windows\CurrentVersion\Run]
"HPADVISOR"="C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe autorun=AUTORUN"
"Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun"
 
[HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"mctadmin"="C:\Windows\System32\mctadmin.exe"
 
[HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"mctadmin"="C:\Windows\System32\mctadmin.exe"
 
[HKEY_USERS\S-1-5-82-3006700770-424185619-1745488364-794895919-4004696415\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"mctadmin"="C:\Windows\System32\mctadmin.exe"
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG_TRAY"="C:\Program Files (x86)\AVG\AVG2012\avgtray.exe"
"vProt"="C:\Program Files (x86)\AVG Secure Search\vprot.exe"
"LogMeIn Hamachi Ui"="C:\Hamachi\hamachi-2-ui.exe --auto-start"
 
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Steam"="C:\Program Files (x86)\Steam\steam.exe -silent"
"Skype"="C:\Program Files (x86)\Skype\Phone\Skype.exe /minimized /regrun"
"BitTorrent"="C:\Program Files (x86)\BitTorrent\BitTorrent.exe  /MINIMIZED"
"CyberGhost"="C:\Program Files\CyberGhost 5\CyberGhost.EXE /autostart"
 
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="c:\\progra~2\\suptab\\search~1.dll"
 
==== Startup Registry Disabled x64 ======================
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Adobe ARM]
"key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="Adobe ARM"
"hkey"="HKLM"
"command"="\"C:\\Program Files (x86)\\Common Files\\Adobe\\ARM\\1.0\\AdobeARM.exe\""
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\AdobeCS4ServiceManager]
"key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="AdobeCS4ServiceManager"
"hkey"="HKLM"
"command"="\"C:\\Program Files (x86)\\Common Files\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe\" -launchedbylogin"
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Aeria Ignite]
"key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="Aeria Ignite"
"hkey"="HKLM"
"command"="\"C:\\Program Files (x86)\\Aeria Games\\Ignite\\aeriaignite.exe\" silent"
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Akamai NetSession Interface]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="Akamai NetSession Interface"
"hkey"="HKCU"
"command"="\"C:\\Users\\Floww\\AppData\\Local\\Akamai\\netsession_win.exe\""
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ApnUpdater]
"key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="ApnUpdater"
"hkey"="HKLM"
"command"="\"C:\\Program Files (x86)\\Ask.com\\Updater\\Updater.exe\""
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\APSDaemon]
"key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="APSDaemon"
"hkey"="HKLM"
"command"="\"C:\\Program Files (x86)\\Common Files\\Apple\\Apple Application Support\\APSDaemon.exe\""
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\BitTorrent]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="BitTorrent"
"hkey"="HKCU"
"command"="\"C:\\Program Files (x86)\\BitTorrent\\BitTorrent.exe\"  /MINIMIZED"
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\BrowserPlugInHelper]
"key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="BrowserPlugInHelper"
"hkey"="HKLM"
"command"="C:\\Program Files (x86)\\Wondershare\\Video Converter Ultimate\\BrowserPlugInHelper.exe"
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\CAHeadless]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="CAHeadless"
"hkey"="HKCU"
"command"="C:\\Program Files (x86)\\Adobe\\Elements 10 Organizer\\CAHeadless\\ElementsAutoAnalyzer.exe"
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\DAEMON Tools Lite]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="DAEMON Tools Lite"
"hkey"="HKCU"
"command"="\"C:\\Program Files (x86)\\DAEMON Tools Lite\\DTLite.exe\" -autorun"
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Easybits Recovery]
"key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="Easybits Recovery"
"hkey"="HKLM"
"command"="C:\\Program Files (x86)\\EasyBits For Kids\\ezRecover.exe"
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\EEventManager]
"key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="EEventManager"
"hkey"="HKLM"
"command"="\"C:\\Program Files (x86)\\Epson Software\\Event Manager\\EEventManager.exe\""
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\FreeCall]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="FreeCall"
"hkey"="HKCU"
"command"="\"C:\\Program Files (x86)\\FreeCall.com\\FreeCall\\freecall.exe\" -nosplash -minimized"
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Google Update]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="Google Update"
"hkey"="HKCU"
"command"="\"C:\\Users\\Floww\\AppData\\Local\\Google\\Update\\GoogleUpdate.exe\" /c"
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\GoogleChromeAutoLaunch_B1956344C3B3A78F4F2C3F2D4A381E17]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="GoogleChromeAutoLaunch_B1956344C3B3A78F4F2C3F2D4A381E17"
"hkey"="HKCU"
"command"="\"C:\\Users\\Floww\\AppData\\Local\\Google\\Chrome\\Application\\chrome.exe\" --no-startup-window"
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\GrooveMonitor]
"key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="GrooveMonitor"
"hkey"="HKLM"
"command"="\"C:\\Program Files (x86)\\Microsoft Office\\Office12\\GrooveMonitor.exe\""
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\HP Remote Solution]
"key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="HP Remote Solution"
"hkey"="HKLM"
"command"="%ProgramFiles%\\Hewlett-Packard\\HP Remote Solution\\HP_Remote_Solution.exe"
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\HP Software Update]
"key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="HP Software Update"
"hkey"="HKLM"
"command"="c:\\Program Files (x86)\\HP\\HP Software Update\\HPWuSchd2.exe"
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\HPADVISOR]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="HPADVISOR"
"hkey"="HKCU"
"command"="C:\\Program Files (x86)\\Hewlett-Packard\\HP Advisor\\HPAdvisor.exe view=DOCKVIEW"
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\hpsysdrv]
"key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="hpsysdrv"
"hkey"="HKLM"
"command"="c:\\program files (x86)\\hewlett-packard\\HP odometer\\hpsysdrv.exe"
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\keyl]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="keyl"
"hkey"="HKCU"
"command"="c://Users//Public//kl.exe"
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\KPeerNexonEU]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="KPeerNexonEU"
"hkey"="HKCU"
"command"="C:\\Nexon\\NEXON_EU_Downloader\\nxEULauncher.exe"
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\LogMeIn Hamachi Ui]
"key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="LogMeIn Hamachi Ui"
"hkey"="HKLM"
"command"="\"C:\\Hamachi\\hamachi-2-ui.exe\" --auto-start"
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ManyCam]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="ManyCam"
"hkey"="HKCU"
"command"="\"C:\\Program Files (x86)\\ManyCam\\Bin\\ManyCam.exe\" /silent"
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\MoodEditor.exe]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="MoodEditor.exe"
"hkey"="HKCU"
"command"="\"C:\\Program Files (x86)\\Pamela RichMood Editor\\MoodEditor.exe\""
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\N0tepad]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="N0tepad"
"hkey"="HKLM"
"command"="C:\\windows\\system32\\n0tepad.exe"
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\NudgeMania]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="NudgeMania"
"hkey"="HKCU"
"command"="C:\\Users\\Floww\\Desktop\\NudgeMania -Installer\\NudgeMania\\NudgeMania.exe"
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ooVoo.exe]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="ooVoo.exe"
"hkey"="HKCU"
"command"="C:\\Program Files (x86)\\ooVoo\\oovoo.exe /minimized"
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\PC-Doctor for Windows localizer]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="PC-Doctor for Windows localizer"
"hkey"="HKLM"
"command"="C:\\Program Files\\PC-Doctor for Windows\\localizer.exe"
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Personal ID]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="Personal ID"
"hkey"="HKCU"
"command"="C:\\PROGRA~2\\COOLSP~1\\PERSON~1\\PID.EXE"
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\QuickTime Task]
"key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="QuickTime Task"
"hkey"="HKLM"
"command"="\"C:\\Program Files (x86)\\QuickTime\\QTTask.exe\" -atboottime"
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\RGSC]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="RGSC"
"hkey"="HKCU"
"command"="C:\\Program Files (x86)\\Rockstar Games\\Rockstar Games Social Club\\RGSCLauncher.exe /silent"
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\SmartMenu]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="SmartMenu"
"hkey"="HKLM"
"command"="C:\\Program Files\\Hewlett-Packard\\HP MediaSmart\\SmartMenu.exe /background"
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Spotify]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="Spotify"
"hkey"="HKCU"
"command"="\"C:\\Users\\Floww\\AppData\\Roaming\\Spotify\\spotify.exe\" /uri spotify:autostart"
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Spotify Web Helper]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="Spotify Web Helper"
"hkey"="HKCU"
"command"="\"C:\\Users\\Floww\\AppData\\Roaming\\Spotify\\Data\\SpotifyWebHelper.exe\""
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Steam]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="Steam"
"hkey"="HKCU"
"command"="\"F:\\steam\\Steam.exe\" -silent"
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\SunJavaUpdateSched]
"key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="SunJavaUpdateSched"
"hkey"="HKLM"
"command"="\"C:\\Program Files (x86)\\Common Files\\Java\\Java Update\\jusched.exe\""
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\swg]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="swg"
"hkey"="HKCU"
"command"="\"C:\\Program Files (x86)\\Google\\GoogleToolbarNotifier\\GoogleToolbarNotifier.exe\""
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\TraySantaCruz]
"key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="TraySantaCruz"
"hkey"="HKLM"
"command"="C:\\Windows\\SysWOW64\\tbctray.exe"
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\TrayServer]
"key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="TrayServer"
"hkey"="HKLM"
"command"="G:\\magix video\\Video_deluxe_15_Version_para_descargar\\TrayServer.exe"
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\vProt]
"key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="vProt"
"hkey"="HKLM"
"command"="\"C:\\Program Files (x86)\\AVG Secure Search\\vprot.exe\""
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\WeatherBugAlert]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="WeatherBugAlert"
"hkey"="HKCU"
"command"="\"C:\\Program Files (x86)\\AWS\\WeatherBug Alert\\WeatherBugAlert.exe\" /st"
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Windows Defender]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="Windows Defender"
"hkey"="HKCU"
"command"="\"C:\\Users\\Floww\\AppData\\Roaming\\WinDefender\\windefender.exe\""
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Wondershare Helper Compact.exe]
"key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="Wondershare Helper Compact.exe"
"hkey"="HKLM"
"command"="C:\\Program Files (x86)\\Common Files\\Wondershare\\Wondershare Helper Compact\\WSHelper.exe"
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\YouCam Tray]
"key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="YouCam Tray"
"hkey"="HKLM"
"command"="\"C:\\Program Files (x86)\\CyberLink\\YouCam\\YouCamTray.exe\" /s"
 
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^GamersFirst LIVE!.lnk]
"path"="C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\GamersFirst LIVE!.lnk"
"backup"="C:\\Windows\\pss\\GamersFirst LIVE!.lnk.CommonStartup"
"backupExtension"=".CommonStartup"
"command"="C:\\PROGRA~2\\GAMERS~1\\LIVE!\\Live.exe /silent"
"item"="GamersFirst LIVE!"
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^McAfee Security Scan Plus.lnk]
"path"="C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\McAfee Security Scan Plus.lnk"
"backup"="C:\\Windows\\pss\\McAfee Security Scan Plus.lnk.CommonStartup"
"backupExtension"=".CommonStartup"
"command"="C:\\PROGRA~2\\MCAFEE~1\\202B13~1.181\\SSSCHE~1.EXE "
"item"="McAfee Security Scan Plus"
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Password.lnk]
"path"="C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\Password.lnk"
"backup"="C:\\Windows\\pss\\Password.lnk.CommonStartup"
"backupExtension"=".CommonStartup"
"command"="C:\\Windows\\Temp\\Password.exe /s /a"
"item"="Password"
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^PrivateTunnel.lnk]
"path"="C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\PrivateTunnel.lnk"
"backup"="C:\\Windows\\pss\\PrivateTunnel.lnk.CommonStartup"
"backupExtension"=".CommonStartup"
"command"="C:\\PROGRA~2\\OPENVP~1\\PRIVAT~1\\PRIVAT~1.EXE "
"item"="PrivateTunnel"
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Users^Floww^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OneNote 2007 Schermopname en Snel starten.lnk]
"path"="C:\\Users\\Floww\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\OneNote 2007 Schermopname en Snel starten.lnk"
"backup"="C:\\Windows\\pss\\OneNote 2007 Schermopname en Snel starten.lnk.Startup"
"backupExtension"=".Startup"
"command"="C:\\PROGRA~2\\MICROS~2\\Office12\\ONENOTEM.EXE /tsr"
"item"="OneNote 2007 Schermopname en Snel starten"
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Users^Floww^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^PalTalk.lnk]
"path"="C:\\Users\\Floww\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\PalTalk.lnk"
"backup"="C:\\Windows\\pss\\PalTalk.lnk.Startup"
"backupExtension"=".Startup"
"command"="C:\\PROGRA~2\\PALTAL~1\\paltalk.exe nas"
"item"="PalTalk"
 
 
==== Startup Folders ======================
 
2015-03-31 14:24:54 853 ----a-w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Password.lnk
 
==== Task Scheduler Jobs ======================
 
C:\Windows\tasks\Adobe Flash Player Updater.job --a------ C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [15-04-2015 16:57]
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job --a------ C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [26-10-2014 16:46]
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job --a------ C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [26-10-2014 16:46]
C:\Windows\tasks\PCDRScheduledMaintenance.job --a------ [undetermined Task]
 
==== Other Scheduled Tasks ======================
 
"C:\Windows\SysNative\tasks\Adobe Flash Player Updater" [C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe]
"C:\Windows\SysNative\tasks\CLMLSvc" [c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe]
"C:\Windows\SysNative\tasks\CreateChoiceProcessTask" [C:\Windows\System32\browserchoice.exe]
"C:\Windows\SysNative\tasks\DVDAgent" [c:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe]
"C:\Windows\SysNative\tasks\GoogleUpdateTaskMachineCore" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe]
"C:\Windows\SysNative\tasks\GoogleUpdateTaskMachineUA" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe]
"C:\Windows\SysNative\tasks\GoogleUpdateTaskUserS-1-5-21-3501343686-3067846119-1440391343-1000Core" [C:\Users\Floww\AppData\Local\Google\Update\GoogleUpdate.exe]
"C:\Windows\SysNative\tasks\GoogleUpdateTaskUserS-1-5-21-3501343686-3067846119-1440391343-1000UA" [C:\Users\Floww\AppData\Local\Google\Update\GoogleUpdate.exe]
"C:\Windows\SysNative\tasks\PCDRScheduledMaintenance" [C:\Program Files\PC-Doctor for Windows\pcdrcui.exe]
"C:\Windows\SysNative\tasks\RecoveryCDWin7" ["C:\Program Files (x86)\Hewlett-Packard\HP Setup\RemEngine.exe"]
"C:\Windows\SysNative\tasks\Registration" ["C:\Program Files (x86)\Hewlett-Packard\HP Setup\RemEngine.exe"]
"C:\Windows\SysNative\tasks\RMCreator" [C:\Program Files (x86)\Hewlett-Packard\Recovery\Reminder.exe]
"C:\Windows\SysNative\tasks\SidebarExecute" [C:\Program Files (x86)\Windows Sidebar\sidebar.exe]
"C:\Windows\SysNative\tasks\{E676DC26-631B-4B39-A88C-EF49DED5B8E1}" [C:\Program Files (x86)\Skype\Phone\Skype.exe]
"C:\Windows\SysNative\tasks\Apple\AppleSoftwareUpdate" [C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe]
"C:\Windows\SysNative\tasks\Hewlett-Packard\HP Assistant\PC Health Analysis" [C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe]
"C:\Windows\SysNative\tasks\Hewlett-Packard\HP Assistant\PC Tuneup" [C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe]
 
==== Firefox Start and Search pages ======================
 
ProfilePath: C:\Users\Floww\AppData\Roaming\Mozilla\Firefox\Profiles\reblngg7.default
user_pref("browser.startup.homepage", "http://www.msn.com/nl-nl/?pc=U270&ocid=U270DHP");
user_pref("browser.search.defaultenginename", "Bing ");
user_pref("browser.search.selectedEngine", "Bing ");
 
==== Firefox Extensions Registry ======================
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions]
"{F53C93F1-07D5-430c-86D4-C9531B27DFAF}"="C:\Program Files (x86)\AVG\AVG2012\Firefox\DoNotTrack" [04-07-2012 04:09]
[HKEY_CURRENT_USER\Software\Mozilla\Firefox\Extensions]
"{8D150B8F-EFE8-45a3-A4A3-053020F48FAC}"="C:\Program Files (x86)\Wondershare\Video Converter Ultimate\SVRFirefoxExt" []
 
==== Firefox Extensions ======================
 
AppDir: C:\Program Files (x86)\Mozilla Firefox
- Default - %AppDir%\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
- Skype Click to Call - %AppDir%\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi
 
==== Firefox Plugins ======================
 
Profilepath: C:\Users\Floww\AppData\Roaming\Mozilla\Firefox\Profiles\reblngg7.default
9AE02005247DA91AB1743F5208DBEF76 - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_169.dll - Shockwave Flash
F2CD1D7524F8E15AAC55568B9F72DE5B - C:\ProgramData\NexonEU\NGM\npnxgameEU.dll - Nexon Game Controller
E37EAD09D28AE19D8A39B6A95F47513A - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1211151.dll - Shockwave for Director / Shockwave for Director
E38F27A1D577015B52EB9C6E7F793684 - C:\Users\Floww\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll - Unity Player
6846D2CA7E1D5937AEE3F99BB7F5464B - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1168638.dll - Shockwave for Director / Shockwave for Director
 
 
==== Chromium Look ======================
 
Google Chrome Version: 43.0.2357.81
 
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
aaaamnjcfigiihfpfilaaiifgdgfogcg - C:\Users\Floww\AppData\Local\APN\GoogleCRXs\aaaamnjcfigiihfpfilaaiifgdgfogcg_7.17.0.0.crx[]
chgdeabpmphfhkoemjjglmilajldekbp - C:\Program Files (x86)\Wondershare\Video Converter Ultimate\SVRChromePlugin.crx[]
elchiiiejkobdbblfejjkbphbddgmljf - C:\Program Files (x86)\Softonic\Softonic\1.8.19.3\Softonic.crx[]
jmfkcklnlgedgbglfkkgedjfmejoahla - C:\Program Files (x86)\AVG\AVG2012\Chrome\safesearch.crx[26-07-2012 03:23]
lifbcibllhkdhoafpjfnlhfpfgnpldfl - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx[01-05-2015 11:17]
mkndcbhcgphcfkkddanakjiepeknbgle - C:\Program Files (x86)\RelevantKnowledge\rlcm.crx[]
ndibdjnfmopecpmkdieinmbadjfpblof - C:\Program Files (x86)\AVG\AVG2012\Chrome\donottrack.crx[20-04-2012 06:18]
 
HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\Extensions
fcfenmboojpjinhpgggodefccipikbpd - No path found[]
 
YouTube - Floww\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo
Google Search - Floww\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf
MSN Homepage Bing Search Engine - Floww\AppData\Local\Google\Chrome\User Data\Default\Extensions\fcfenmboojpjinhpgggodefccipikbpd
AdBlock - Floww\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom
Bookmark Manager - Floww\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmlllbghnfkpflemihljekbapjopfjik
Windows Media Player Extension for HTML5 - Floww\AppData\Local\Google\Chrome\User Data\Default\Extensions\hokdglbhghcebcopdbanieangmcamaak
Google Wallet - Floww\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda
Gmail - Floww\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia
 
==== Chromium Startpages ======================
 
C:\Users\Floww\AppData\Local\Google\Chrome\User Data\Default\Preferences
1FF68B9053A5E633D88BD6281A528096F4F0450DEF954","gfdkimpbcpahaombhbimeihdjnejgicl":"AAD6C98D1F269E75DFC6E70244755E1F32BC5C082DE509BFCB29D419B8ACEF9B","gighmmpiobklfepjocnamgkkbiglidom":"3DBD65BC8B6ADF25E712CB9F957E1D1172A3EE63A732553D22B8FDB7FC962A99","ginepjojjbmfbfiibfdebddmbkjmgfle":"08F4216F8EDAD453EE4917E60B0F212CCC330915DF4C484C5EDE7D9846493A20","gmlllbghnfkpflemihljekbapjopfjik":"E69ED656B907DDFDF3484D4D5A5EE5E63FAB409FD4798891B77D9C63C43A7615","hgnpdbanhfmmdgeogllhocdajiphlkgi":"475F46758EC7EF4C5875234694D8F87A50E7E83ECDB68A6379DAE46242EDF138","hhjkdnopjneggcflhehgahpijehegpbl":"CE42ABF7D0BEAE9E44DC4B156AC60E508AA266FBBD5F120E378FF8BA36000836","hokdglbhghcebcopdbanieangmcamaak":"25EDEEDCFD3874273AB9573BDC00C78D90D74386BCA15C5FFBFC797536A8C53A","icpificlnelnkdegnghidjibpdfhggnc":"A83BEE3FB1542BAB0EE01730BF81CE52007E0AF449C1B85643C69BA734EF0EF3","jmfkcklnlgedgbglfkkgedjfmejoahla":"DC717BF48B7F25CA63266348A752E67C740B1F392C2D06BF52C78F29FA215250","kkagohhgodpbgcddadcmnidnphajkmhm":"11637D16B735AC34448A4FB38EE9CC7643600ACF2560F5D1953BB4990C46FD5C","kmendfapggjehodndflmmgagdbamhnfd":"BC856F123261194DB137E631C218D5478DB85B2F7E67F297EA0EB256A6C6710B","lifbcibllhkdhoafpjfnlhfpfgnpldfl":"ECB69F03D937336AB702FD2FCB47D9964F73DE5271DFAC5B94DA0D5A336BF7ED","lojpenhmoajbiciapkjkiekmobleogjc":"F82AC773E950B41CCA13689A0A0155B61F61BB60E3006D4EDFE54D143112C745","mfehgcgbbipciphmccgaenjidiccnmng":"80FFFE6767B254255FE9114A1D7EA353211813CF849AEE1037C1F238B9819507","mgndgikekgjfcpckkfioiadnlibdjbkf":"7BF93058FFE69144838A35096046B768B9CAAC2C39CF658F66E0807C9FC9B884","mhjfbmdgcfjbbpaeojofohoefgiehjai":"66AED5858DD0395FB951128F9117DF302F86D51D3874C07995FAF3AB0A2CEE9B","mimficccjmogheahaobepphobhpikpie":"02C6D04FDE2205B53CD3B637050526E337DB2F6759B3468F5E25C0471FAD16CE","mnpbfmbldigngiccdgkbikaeifoljngg":"48226806CE2929207819C4286DAC680B2B2A26E973F87F8A79752E5907490A41","naaigfdnmbjjkdbpdbelpaaopjblfkbl":"D7F48A54A5F35D5656207CDA9B85BE36F4DD75ADDB625213DC6D6E5C3B6D08F0","ndibdjnfmopecpmkdieinmbadjfpblof":"7C6EA8B25B72DFD09017E6AE208373D75E3380335C7EE76F19CE31C0FDE2C25D","neajdppkdcdipfabeoofebfddakdcjhd":"356390C42084F5FBFCBEC2CAA42FAEFA0EF641F46F272FCA5512441E2DA719F9","niapdbllcanepiiimjjndipklodoedlc":"FCF0BF202FDF1F1F1E74F5D2FF5914F907C8258179031FE872DCD4750A4C08A2","nkeimhogjdpnpccoofpliimaahmaaome":"20C98827DD06A4106F427D052405BEC59091BBFA3BFCC609D7086EE4E131D88F","nmbfljkmcghmakofbhhgemjhboabdkcn":"B8C61B7464CD5076D64E7067A16E7B59D485B11B367F1BD8DA2275BAD36E9E02","nmmhkkegccagdldgiimedpiccmgmieda":"934E6CA78B58841811F6B573BFC6DE2F39FC69F4E4DA3FD345EE30FC6A777099","oienjamfkkgodanlopcoccgeciiabpbf":"C48EC3E652BE66768585E825A8E6EABBA17F69CA2046B0A192CA1B3F26618E97","okoimcnealmbfnikpfoiddcofdpoamch":"64A5730884A3FE043F282DD189370EFA38DBEDB779C49695AA4D552F334E4CF2","pafkbggdmjlpgkdkcbjmhmfcdpncadgh":"1881444716ADDD83B05A3001463A3F2335550FB05DE2BCEDFB025A8417E22729","pjkljhegncpnkpknbcohdijeoejaedia":"770978703FCC86620135B3615902EB3DD4C71258D94B535037DBF699EEAF12CA"}},"google":{"services":{"last_username":"F16179CAAE39E09108D87FE256BF35BC5461B69FC35C4D96E467EFDB69327A09","username":"B7C5B1B15E96596E26E97A8D26BEBA09EF79E593448CDB6F34AA3E6A01B17A4A"}},"homepage":"66DD8460FAF1A4C65B99810E24B13ACCA66888C304C406D775587C0D5CDFA270","homepage_is_newtabpage":"F329DAE4DE703049A5FA4ECE41B417D71DCDE114945027E8CCD618C1458AAC30","pinned_tabs":"D5DFB67FCE549BFB257D7546CDE79F70F388F5ADC190428E368A9C271FC44EAF","prefs":{"preference_reset_time":"58B841609E2A2FBCEC9FE4E0DA30197C4FCE2973C15BFA9986973166CF507DC2"},"profile":{"reset_prompt_memento":"2E7FABC3CDC1071BEBE4DB622F64C507CCB830C0B1AABEECFA6891C237C4E22F"},"safebrowsing":{"incidents_sent":"8407C94E4729CB7CDAF0960E3531A1C3AB10EB6E20C464AB406E1F28468903BF"},"search_provider_overrides":"1DE44F4629D683825546C8721138D3A26F10A22B7DB5DC3CB43E6F9087EAC5A7","session":{"restore_on_startup":"BBA287C70E169CA240A16352D7C0A54969DB9FF667B289707F82918824AEC9A6","startup_urls":"97A1AF47AB5030AA9C86EE0DD73BC964CE7F804F347D94DB821E366AFC44BAD3"},"software_reporter":{"prompt_reason":"D9670BE88C58AC214FB12BDE20AB89A1F6D701A65182BBED2494ED3E6D43103D","prompt_seed":"0C0811F86B12F8CE10EC9C0C675638AB1A5677FF23477BFA6479D4989D7EDBF1","prompt_version":"E58C3710DE81B938218359340326B4FD9A181F07B9B12C7ECABDBD24A25762E2"},"sync":{"remaining_rollback_tries":"A85066581E14482580B9239316FDDEE988705F2FD305EE3E3DAFF86FB9EF35DF"}},"super_mac":"2070F81D5450AC16E8AA8FB43FDB317F8A93B29316EF83D95BC561159583E9EA"},"safebrowsing":{"incidents_sent":{"1":{"default_search_provider_data.template_url_data":"3744314107"},"2":{"chrome.dll":"3774509266","chrome_child.dll":"3743713718"}}},"session":{"restore_on_startup":4,"startup_urls":["http://google.nl/]},"software_reporter":{"prompt_reason":0,"prompt_version":"2.16.2.0"},"sync":{"remaining_rollback_tries":0}}
 
 
==== Chromium Fix ======================
 
C:\Users\Floww\AppData\Local\Google\Chrome\User Data\Default\Extensions\fcfenmboojpjinhpgggodefccipikbpd deleted successfully
 
==== Set IE to Default ======================
 
Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Use Search Asst"="yes"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchUrl]
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\SearchUrl]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AboutURLs]
"Tabs"="res://ieframe.dll/tabswelcome.htm"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\AboutURLs]
"Tabs"="res://ieframe.dll/tabswelcome.htm"
 
New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Use Search Asst"="no"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchUrl]
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\SearchUrl]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AboutURLs]
"Tabs"="about:newtab"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\AboutURLs]
"Tabs"="about:newtab"
 
==== All HKCU SearchScopes ======================
 
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
"DefaultScope"="{C24F404D-333F-4F02-BC5C-429ED459E796}"
{012E1000-F331-11DB-8314-0800200C9A66} Google  Url="http://www.google.com/search?q={searchTerms}"
 
==== Deleting CLSID Registry Keys ======================
 
HKEY_USERS\S-1-5-21-3501343686-3067846119-1440391343-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233} deleted successfully
HKEY_USERS\S-1-5-21-3501343686-3067846119-1440391343-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{95B7759C-8C7F-4BF1-B163-73684A933233} deleted successfully
HKEY_USERS\S-1-5-21-3501343686-3067846119-1440391343-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FC600575-3013-4E8E-941C-4B00DAFCE730} deleted successfully
HKEY_USERS\S-1-5-21-3501343686-3067846119-1440391343-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FC600575-3013-4E8E-941C-4B00DAFCE730} deleted successfully
HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233} deleted successfully
HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{FC600575-3013-4E8E-941C-4B00DAFCE730} deleted successfully
 
==== Deleting CLSID Registry Values ======================
 
HKEY_USERS\S-1-5-21-3501343686-3067846119-1440391343-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{FC600575-3013-4E8E-941C-4B00DAFCE730} deleted successfully
HKEY_USERS\S-1-5-21-3501343686-3067846119-1440391343-1000\Software\Mozilla\Firefox\Extensions\{8D150B8F-EFE8-45a3-A4A3-053020F48FAC} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{95B7759C-8C7F-4BF1-B163-73684A933233} deleted successfully
HKEY_LOCAL_MACHINE\software\Wow6432Node\mozilla\Firefox\extensions\avg@toolbar deleted successfully
HKEY_LOCAL_MACHINE\software\Wow6432Node\mozilla\Firefox\extensions\{8D150B8F-EFE8-45a3-A4A3-053020F48FAC} deleted successfully
 
==== Deleting Registry Keys ======================
 
HKEY_LOCAL_MACHINE\Software\wow6432node\Policies\Google deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\aaaamnjcfigiihfpfilaaiifgdgfogcg deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\chgdeabpmphfhkoemjjglmilajldekbp deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\elchiiiejkobdbblfejjkbphbddgmljf deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\mkndcbhcgphcfkkddanakjiepeknbgle deleted successfully
HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\Extensions\fcfenmboojpjinhpgggodefccipikbpd deleted successfully
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{12DA0E6F-5543-440C-BAA2-28BF01070AFA}{b0dea870} deleted successfully
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{7426428E-71D4-452C-BA13-B14E5EB52859} deleted successfully
HKEY_CURRENT_USER\Software\Microsoft\Installer\Products\E82462474D17C254AB311BE4E55B8295 deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS4ServiceManager deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aeria Ignite deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Akamai NetSession Interface deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ApnUpdater deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BrowserPlugInHelper deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CAHeadless deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Easybits Recovery deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FreeCall deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GoogleChromeAutoLaunch_B1956344C3B3A78F4F2C3F2D4A381E17 deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPADVISOR deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\keyl deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KPeerNexonEU deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MoodEditor.exe deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\N0tepad deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NudgeMania deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ooVoo.exe deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Personal ID deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RGSC deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TrayServer deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\vProt deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Wondershare Helper Compact.exe deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\YouCam Tray deleted successfully
 
==== Empty IE Cache ======================
 
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\DefaultAppPool\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Floww\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\12ZMCB6E will be deleted at reboot
C:\Users\Floww\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1OFCYH2I will be deleted at reboot
C:\Users\Floww\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7E93GRO0 will be deleted at reboot
C:\Users\Floww\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7EBWOWMT will be deleted at reboot
C:\Users\Floww\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7FS4JCU3 will be deleted at reboot
C:\Users\Floww\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BVLQGF15 will be deleted at reboot
C:\Users\Floww\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JD87PT3Y will be deleted at reboot
C:\Users\Floww\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R4K41R62 will be deleted at reboot
C:\Users\Floww\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T7V3618V will be deleted at reboot
C:\Users\Floww\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UA4PXJI4 will be deleted at reboot
C:\Users\Floww\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\V8C8A3W9 will be deleted at reboot
C:\Users\Floww\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XL19SPA2 will be deleted at reboot
 
==== Empty FireFox Cache ======================
 
No FireFox Cache found
 
==== Empty Chrome Cache ======================
 
C:\Users\Floww\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
 
==== Empty All Flash Cache ======================
 
Flash Cache Emptied Successfully
 
==== Empty All Java Cache ======================
 
Java Cache cleared successfully
 
==== C:\zoek_backup content ======================
 
C:\zoek_backup (files=8524 folders=1757 1236224809 bytes)
 
==== Empty Temp Folders ======================
 
C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\DefaultAppPool\AppData\Local\Temp emptied successfully
C:\Users\Floww\AppData\Local\Temp will be emptied at reboot
C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp will be emptied at reboot
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot
 
==== After Reboot ======================
 
==== Empty Temp Folders ======================
 
C:\Windows\Temp successfully emptied
C:\Users\Floww\AppData\Local\Temp successfully emptied
 
==== Empty Recycle Bin ======================
 
C:\$RECYCLE.BIN successfully emptied
 
==== Deleting Files / Folders ======================
 
"C:\Users\Floww\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\12ZMCB6E" not found
"C:\Users\Floww\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1OFCYH2I" not found
"C:\Users\Floww\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7E93GRO0" not found
"C:\Users\Floww\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7EBWOWMT" not found
"C:\Users\Floww\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7FS4JCU3" not found
"C:\Users\Floww\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BVLQGF15" not found
"C:\Users\Floww\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JD87PT3Y" not found
"C:\Users\Floww\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R4K41R62" not found
"C:\Users\Floww\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T7V3618V" not found
"C:\Users\Floww\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UA4PXJI4" not found
"C:\Users\Floww\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\V8C8A3W9" not found
"C:\Users\Floww\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XL19SPA2" not found
"C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp\Low" not deleted
 
==== EOF on wo 27-05-2015 at 19:40:38,55 ======================
 

 

Geplaatst:

Download adwcleaner.pngAdwCleaner by Xplode naar het bureaublad (verwijder eerst eventuele aanwezige oudere versies van deze tool op je PC, zodat je nu de meest recente database van AdwCleaner kan gebruiken).

Als de link naar AdwCleaner niet werkt, probeer dan deze link.
De download start automatisch na enkele seconden.

  • Sluit alle openstaande vensters.
  • Dubbelklik op AdwCleaner om hem te starten.
  • Windows Vista, 7 en 8 gebruikers dienen de tool als "administrator" uit te voeren,
  • Door middel van de rechtermuisknop en kiezen voor Als Administrator uitvoeren.
  • Klik op Scan.
  • Klik vervolgens op Clean.
  • Klik bij Herstarten Noodzakelijk op OK


Nadat de PC opnieuw is opgestart, opent meestal een logfile.
Anders is het hier terug te vinden C:\AdwCleaner\AdwCleaner[s0].txt.

Logbestand plaatsen

  • Voeg het logbestand met de naam C:\AdwCleaner\AdwCleaner[s0].txt als bijlage toe aan het volgende bericht.
  • Hoe u een bijlage kunt toevoegen aan het bericht leest u hier.

  • 2 weken later...
Geplaatst:

Sorry ... wegens vakantie dit topic even uit het oog verloren. Mijn excuses daarvoor :blush:

 

Het goede nieuws is, dat hiermee (alweer) een behoorlijk bende rotzooi van de PC gehaald is :(

 

Krijg je nu nog meldingen over .NET Framework ? Of andere merkbare problemen ?

×
×
  • Nieuwe aanmaken...

Belangrijke informatie

We hebben cookies geplaatst op je toestel om deze website voor jou beter te kunnen maken. Je kunt de cookie instellingen aanpassen, anders gaan we er van uit dat het goed is om verder te gaan.