Explorer.exe shuts down after Windows startup

Posted 5/29/2013 10:49 PM
#95681
User avatar

Robin085 Member

Date Joined Nov 2016
Total Posts: 7
Hey guys, <br/> <br/>It seems my Windows 7 PC has somehow been infected with malware of some sort. While searching for a particular piece of software online I've had AVG giving a virus warning, on which I had it blocked. <br/> <br/>Moments later, explorer.exe just seemed to shut down. I only had a blank desktop image, no Windows toolbar whatsoever. I wasn't able to open taskmanager to restart explorer.exe manually so I rebooted. <br/> <br/>After the reboot, explorer.exe similarly would shut down as soon as Windows had fully started. I rebooted in safe mode, which worked fine, and had my PC scanned with AVG, which removed 2 virusses, and Hitman Pro, which didn't find anything. <br/> <br/>After that, still the same trouble so I did a system restore (backup from 4 days earlier), which seems to work for now. Nevertheless I'm not sure whether any infected files in the registry have actually been replaced in the restore, or there's malware of some sort still lurking around somewhere. <br/> <br/>A few hours of searching online didn't result in any useful advice as the only topics I found on this particular issue weren't much helpful. Does it sound familiar to anyone and any suggestions how to get rid of it, if I haven't already?
Posted 5/30/2013 8:26 AM
#95682
User avatar

Touch Advanced member

Date Joined Nov 2016
Total Posts: 12976
Welcome <a name="m95681"></a>Robin085 :smile: </div><br /><br /><br /><br /> <br/> <br/>[color="#0000ff"]http://download.bleepingcomputer.com/farbar/FRST.exe[/color]</a><o:p></o:p></li>[color="#0000ff"]http://download.bleepingcomputer.com/farbar/FRST.exe[/color]</b></a><o:p></o:p></li> <br/> <li class="MsoNormal" style="margin: 0cm 0cm 0pt; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-list: l0 level1 lfo1; tab-stops: list 36.0pt;"><font face="Times New Roman"><span style="mso-spacerun: yes;"> and <br/> save it to a flash drive. <br/> <br/> <br/> <br/> Plug the flashdrive into the infected PC. <br/> <br/> <br/> <br/> Enter System Recovery Options. <br/> <br/> <br/> <br/> To enter System Recovery Options from the Advanced Boot <br/> Options:<o:p></o:p></font></li> <br/> <ul type="circle"> <br/> <li class="MsoNormal" style="margin: 0cm 0cm 0pt; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-list: l0 level2 lfo1; tab-stops: list 72.0pt;"><font face="Times New Roman">Restart the computer.<o:p></o:p></font></li> <br/> <li class="MsoNormal" style="margin: 0cm 0cm 0pt; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-list: l0 level2 lfo1; tab-stops: list 72.0pt;"><span lang="EN" style="mso-ansi-language: EN;"><font face="Times New Roman">As soon as the BIOS is loaded begin tapping <br/> the F8 key until Advanced Boot Options appears.<o:p></o:p></font></li> <br/> <li class="MsoNormal" style="margin: 0cm 0cm 0pt; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-list: l0 level2 lfo1; tab-stops: list 72.0pt;"><span lang="EN" style="mso-ansi-language: EN;"><font face="Times New Roman">Use the arrow keys to select the Repair <br/> your computer menu item.<o:p></o:p></font></li> <br/> <li class="MsoNormal" style="margin: 0cm 0cm 0pt; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-list: l0 level2 lfo1; tab-stops: list 72.0pt;"><span lang="EN" style="mso-ansi-language: EN;"><font face="Times New Roman">Choose your language settings, and then <br/> click Next.<o:p></o:p></font></li> <br/> <li class="MsoNormal" style="margin: 0cm 0cm 0pt; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-list: l0 level2 lfo1; tab-stops: list 72.0pt;"><span lang="EN" style="mso-ansi-language: EN;"><font face="Times New Roman">Select the operating system you want to <br/> repair, and then click Next.<o:p></o:p></font></li> <br/> <li class="MsoNormal" style="margin: 0cm 0cm 0pt; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-list: l0 level2 lfo1; tab-stops: list 72.0pt;"><font face="Times New Roman">Select your user account an click Next.<o:p></o:p></font></li> <br/> </ul> <br/></ul> <br/> <br/> <br/><font face="Times New Roman"> <br/>To enter System Recovery Options by using Windows installation disc:<o:p></o:p></font> <br/> <br/> <br/><ul type="disc"> <br/> <ul type="circle"> <br/> <li class="MsoNormal" style="margin: 0cm 0cm 0pt; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-list: l0 level2 lfo1; tab-stops: list 72.0pt;"><font face="Times New Roman">Insert the installation disc.<o:p></o:p></font></li> <br/> <li class="MsoNormal" style="margin: 0cm 0cm 0pt; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-list: l0 level2 lfo1; tab-stops: list 72.0pt;"><font face="Times New Roman">Restart your computer.<o:p></o:p></font></li> <br/> <li class="MsoNormal" style="margin: 0cm 0cm 0pt; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-list: l0 level2 lfo1; tab-stops: list 72.0pt;"><span lang="EN" style="mso-ansi-language: EN;"><font face="Times New Roman">If prompted, press any key to start Windows <br/> from the installation disc. If your computer is not configured to start <br/> from a CD or DVD, check your BIOS settings.<o:p></o:p></font></li> <br/> <li class="MsoNormal" style="margin: 0cm 0cm 0pt; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-list: l0 level2 lfo1; tab-stops: list 72.0pt;"><font face="Times New Roman">Click Repair your computer.<o:p></o:p></font></li> <br/> <li class="MsoNormal" style="margin: 0cm 0cm 0pt; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-list: l0 level2 lfo1; tab-stops: list 72.0pt;"><span lang="EN" style="mso-ansi-language: EN;"><font face="Times New Roman">Choose your language settings, and then <br/> click Next.<o:p></o:p></font></li> <br/> <li class="MsoNormal" style="margin: 0cm 0cm 0pt; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-list: l0 level2 lfo1; tab-stops: list 72.0pt;"><span lang="EN" style="mso-ansi-language: EN;"><font face="Times New Roman">Select the operating system you want to <br/> repair, and then click Next.<o:p></o:p></font></li> <br/> <li class="MsoNormal" style="margin: 0cm 0cm 0pt; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-list: l0 level2 lfo1; tab-stops: list 72.0pt;"><font face="Times New Roman">Select your user account an click Next.<o:p></o:p></font></li> <br/> </ul> <br/></ul> <br/> <br/><span lang="EN" style="mso-ansi-language: EN;"> <br/> <br/>On the System Recovery Options menu you will get the following <br/>options:<span lang="EN" style="mso-ansi-language: EN;"> <br/><font face="Times New Roman"> <br/>Startup Repair</font> <br/><font face="Times New Roman"> <br/><b>System Restore <br/> <br/>Windows Complete PC Restore <br/> <br/>Windows Memory Diagnostic Tool <br/> <br/>Scan your computer's memory for errors. <br/> <br/>Command Prompt</font></b><o:p></o:p> <br/> <br/> <br/><ul type="disc"> <br/> <li class="MsoNormal" style="margin: 0cm 0cm 0pt; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-list: l0 level1 lfo1; tab-stops: list 36.0pt;"><font face="Times New Roman">Select Command Prompt<o:p></o:p></font></li> <br/> <li class="MsoNormal" style="margin: 0cm 0cm 0pt; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-list: l0 level1 lfo1; tab-stops: list 36.0pt;"><span lang="EN" style="mso-ansi-language: EN;"><font face="Times New Roman">In the command window type in notepad <br/> and press Enter.<o:p></o:p></font></li> <br/> <li class="MsoNormal" style="margin: 0cm 0cm 0pt; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-list: l0 level1 lfo1; tab-stops: list 36.0pt;"><font face="Times New Roman">The notepad opens. Under File menu select Open.<o:p></o:p></font></li> <br/> <li class="MsoNormal" style="margin: 0cm 0cm 0pt; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-list: l0 level1 lfo1; tab-stops: list 36.0pt;"><span lang="EN" style="mso-ansi-language: EN;"><font face="Times New Roman">Select "Computer" and find your <br/> flash drive letter and close the notepad.<o:p></o:p></font></li> <br/> <li class="MsoNormal" style="margin: 0cm 0cm 0pt; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-list: l0 level1 lfo1; tab-stops: list 36.0pt;"><font face="Times New Roman">In the command window type <span style="color: red;">e:\frst.exe (for x64 bit version type e:\frst64) and press Enter <br/> <br/> <br/> Note: Replace letter e <br/> with the drive letter of your flash drive.<o:p></o:p></font></li> <br/> <li class="MsoNormal" style="margin: 0cm 0cm 0pt; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-list: l0 level1 lfo1; tab-stops: list 36.0pt;"><font face="Times New Roman">The tool will start to run.<o:p></o:p></font></li> <br/> <li class="MsoNormal" style="margin: 0cm 0cm 0pt; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-list: l0 level1 lfo1; tab-stops: list 36.0pt;"><font face="Times New Roman">When the tool opens click Yes to disclaimer.<o:p></o:p></font></li> <br/> <li class="MsoNormal" style="margin: 0cm 0cm 0pt; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-list: l0 level1 lfo1; tab-stops: list 36.0pt;"><font face="Times New Roman">Press Scan button.<o:p></o:p></font></li> <br/> <li class="MsoNormal" style="margin: 0cm 0cm 0pt; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-list: l0 level1 lfo1; tab-stops: list 36.0pt;"><span lang="EN" style="mso-ansi-language: EN;"><font face="Times New Roman">It will make a log (FRST.txt) on the flash <br/> drive. Please copy and paste it to your reply.<o:p></o:p></font></li> <br/></ul> <br/> <br/><o:p> </o:p>

[color=black face="Courier New" sab="311">[2]Click here: Before-posting-a-log[/2][/url]

<?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" />
[/color]
Do not PM me with logfiles. They will be deleted.


Posted 5/30/2013 8:41 AM
#95683
User avatar

Robin085 Member

Date Joined Nov 2016
Total Posts: 7
Hi, thanks for the quick and clear reply. I'll do so. Just wondering, would I not be able to just run FRST in safe mode?
Posted 5/30/2013 8:43 AM
#95684
User avatar

Touch Advanced member

Date Joined Nov 2016
Total Posts: 12976
"just run FRST in safe mode?"</div> <br/> <br/> <br/> <br/> <br/>It´s worth a try ;-)

[color=black face="Courier New" sab="311">[2]Click here: Before-posting-a-log[/2][/url]

<?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" />
[/color]
Do not PM me with logfiles. They will be deleted.


Posted 5/30/2013 11:16 AM
#95687
User avatar

Robin085 Member

Date Joined Nov 2016
Total Posts: 7
Okay, as I said, since the system restore, it all seems to work fine. I did the FRST scan anyway, in normal Windows mode. Here's the results: <br/> <br/>Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 28-05-2013 <br/>Ran by Robin (administrator) on 30-05-2013 13:11:15 <br/>Running from C:\Users\Robin\Desktop <br/>Windows 7 Home Premium Service Pack 1 (X64) OS Language: Dutch Standard <br/>Internet Explorer Version 9 <br/>Boot Mode: Normal <br/>==================== Processes (Whitelisted) ================= <br/> <br/>(AVG Technologies CZ, s.r.o.) C:\PROGRA~2\AVG\AVG10\avgchsva.exe <br/>(AVG Technologies CZ, s.r.o.) C:\PROGRA~2\AVG\AVG10\avgrsa.exe <br/>(Andrea Electronics Corporation) C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe <br/>(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe <br/>(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe <br/>(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG10\avgwdsvc.exe <br/>(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe <br/>(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe <br/>(KPN) C:\Program Files\KPN Back-up Online\BackupSC.exe <br/>(Microsoft Corporation) C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe <br/>(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE <br/>(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe <br/>(KPN) C:\Program Files\KPN Back-up Online\BackupFP.exe <br/>(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe <br/>(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe <br/>(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe <br/>(Realtek Semiconductor Corp.) C:\Program Files (x86)\Realtek\Audio\OSD\RtVOsd64.exe <br/>(Spotify Ltd) C:\Users\Robin\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe <br/>(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG10\avgtray.exe <br/>(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG10\avgnsa.exe <br/>(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG10\avgemca.exe <br/>() C:\Program Files (x86)\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe <br/>(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe <br/>(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe <br/>(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe <br/>(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_7_700_202.exe <br/>(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_7_700_202.exe <br/>(Farbar) C:\Users\Robin\Desktop\FRST64.exe <br/> <br/>==================== Registry (Whitelisted) ================== <br/> <br/>HKLM\...\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe [2046760 2010-02-06] (Synaptics Incorporated) <br/>HKLM\...\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe -s [6160928 2010-01-30] (Realtek Semiconductor) <br/>HKLM\...\Run: [RtkOSD] C:\Program Files (x86)\Realtek\Audio\OSD\RtVOsd64.exe [995840 2010-01-13] (Realtek Semiconductor Corp.) <br/>HKCU\...\Run: [AdobeBridge] [x] <br/>HKCU\...\Run: [Spotify Web Helper] "C:\Users\Robin\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" [1105408 2013-05-06] (Spotify Ltd) <br/>MountPoints2: G - G:\LaunchU3.exe -a <br/>MountPoints2: H - H:\LaunchU3.exe -a <br/>MountPoints2: {1b3dc415-eea6-11e1-b8df-c80aa9dec962} - G:\AutoRun.exe <br/>MountPoints2: {2b95a1da-e12c-11e0-bb3b-c80aa9dec962} - H:\AutoRun.exe <br/>MountPoints2: {2b95a1dd-e12c-11e0-bb3b-c80aa9dec962} - G:\AutoRun.exe <br/>MountPoints2: {2b95a20b-e12c-11e0-bb3b-c80aa9dec962} - G:\LaunchU3.exe -a <br/>MountPoints2: {42892036-e1e8-11e0-8d3f-c80aa9dec962} - G:\AutoRun.exe <br/>MountPoints2: {42892094-e1e8-11e0-8d3f-c80aa9dec962} - G:\AutoRun.exe <br/>MountPoints2: {4289209f-e1e8-11e0-8d3f-c80aa9dec962} - H:\AutoRun.exe <br/>MountPoints2: {57eea60d-e12b-11e0-9bfb-c80aa9dec962} - H:\AutoRun.exe <br/>MountPoints2: {6e147d1b-eea0-11e1-b853-c80aa9dec962} - G:\AutoRun.exe <br/>MountPoints2: {946d5d0b-ede8-11e1-9b39-c80aa9dec962} - G:\AutoRun.exe <br/>MountPoints2: {946d5d18-ede8-11e1-9b39-c80aa9dec962} - G:\AutoRun.exe <br/>MountPoints2: {c9684ccb-d566-11df-b07c-c80aa9dec962} - I:\LaunchU3.exe -a <br/>MountPoints2: {ee539afb-20fc-11e2-b84a-c80aa9dec962} - G:\SETUP.EXE -autorun <br/>HKLM-x32\...\Run: [AVG_TRAY] C:\Program Files (x86)\AVG\AVG10\avgtray.exe [2345592 2012-08-01] (AVG Technologies CZ, s.r.o.) <br/>BootExecute: autocheck autochk * bootdeleteC:\PROGRA~2\AVG\AVG10\avgchsva.exe /syncC:\PROGRA~2\AVG\AVG10\avgrsa.exe /sync /restart <br/> <br/>==================== Internet (Whitelisted) ==================== <br/> <br/>HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://websearch.simplespeedy.info/ <br/>HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.uk.msn.com/CQCON/7 <br/>HKLM SearchScopes: DefaultScope {B7971660-A1CE-4FDD-B9E0-2C37D77AFB0B} URL = <br/>SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = <br/>HKLM-x32 SearchScopes: DefaultScope {B7971660-A1CE-4FDD-B9E0-2C37D77AFB0B} URL = <br/>SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = <br/>SearchScopes: HKLM-x32 - {BB74DE59-BC4C-4172-9AC4-73315F71CFFE} URL = http://websearch.simplespeedy.info/?l=1&q={searchTerms} <br/>HKCU SearchScopes: DefaultScope {2CF7FF10-32B1-4D34-9371-D3A29CCC50BF} URL = http://www.google.co.uk/search?hl=en&q={searchTerms}&meta= <br/>SearchScopes: HKCU - {00AFB5EE-A3E4-4E48-9F8B-0950B37B5F9B} URL = http://search.avg.com/?d=4dbd90dc&i=23&tp=chrome&q={searchTerms}&lng={language}&nt=1 <br/>SearchScopes: HKCU - {2CF7FF10-32B1-4D34-9371-D3A29CCC50BF} URL = http://www.google.co.uk/search?hl=en&q={searchTerms}&meta= <br/>SearchScopes: HKCU - {4A2F05AE-7550-483E-8F1A-74D4597E2148} URL = http://websearch.ask.com/redirect?client=ie&tb=ORJ&o=100000027&src=crm&q={searchTerms}&locale=nl_NL&apn_ptnrs=U3&apn_dtid=OSJ000YYNL&apn_uid=815A0F13-CA74-48DD-9E23-022EA62EA7EB&apn_sauid=90ED71C1-CEFA-42B4-AEE4-77DCD313E8F1 <br/>SearchScopes: HKCU - {BB74DE59-BC4C-4172-9AC4-73315F71CFFE} URL = http://websearch.simplespeedy.info/?l=1&q={searchTerms} <br/>BHO: AVG Safe Search - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG10\avgssiea.dll (AVG Technologies CZ, s.r.o.) <br/>BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) <br/>BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.) <br/>BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) <br/>BHO-x32: AVG Safe Search - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG10\avgssie.dll (AVG Technologies CZ, s.r.o.) <br/>BHO-x32: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation) <br/>BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) <br/>BHO-x32: No Name - {7825CFB6-490A-436B-9F26-4A7B5CFC01A9} - No File <br/>BHO-x32: Aanmeldhulp voor Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) <br/>BHO-x32: Skype Browser Helper - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) <br/>BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) <br/>BHO-x32: continuetosave - {F7DD5FF7-AA4B-25E4-8659-F4DF4AB1423A} - C:\ProgramData\continuetosave\512786279cfbf.dll No File <br/>Toolbar: HKCU - No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File <br/>Toolbar: HKCU - No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - No File <br/>Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG10\avgppa.dll (AVG Technologies CZ, s.r.o.) <br/>Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - No File <br/>Handler-x32: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG10\avgpp.dll (AVG Technologies CZ, s.r.o.) <br/>Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) <br/>Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) <br/>Winsock: Catalog5 09 C:\Program Files (x86)\Bonjour\mdnsNSP.dll [20992] (Microsoft Corporation) <br/>Winsock: Catalog5-x64 09 C:\Program Files\Bonjour\mdnsNSP.dll [132968] (Apple Inc.) <br/>Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt <br/>Tcpip\Parameters: [DhcpNameServer] 10.0.0.1 <br/> <br/>FireFox: <br/>======== <br/>FF ProfilePath: C:\Users\Robin\AppData\Roaming\Mozilla\Firefox\Profiles\1sryxlu5.default <br/>FF Homepage: hxxp://www.hotmail.com/ <br/>FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_202.dll () <br/>FF Plugin: @microsoft.com/GENUINE - disabled No File <br/>FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation) <br/>FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_202.dll () <br/>FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.) <br/>FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () <br/>FF Plugin-x32: @java.com/DTPlugin,version=10.7.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) <br/>FF Plugin-x32: @java.com/JavaPlugin,version=10.7.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) <br/>FF Plugin-x32: @microsoft.com/GENUINE - disabled No File <br/>FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation) <br/>FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll No File <br/>FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll No File <br/>FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll No File <br/>FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.) <br/>FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.) <br/>FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) <br/>FF Extension: 503b6c9f609fa - C:\Users\Robin\AppData\Roaming\Mozilla\Firefox\Profiles\1sryxlu5.default\Extensions\503b6c9f609fa@503b6c9f60a33.info.xpi <br/> <br/>Chrome: <br/>======= <br/>CHR Extension: (continuetosave) - C:\Users\Robin\AppData\Local\Google\Chrome\User Data\Default\Extensions\blcjdfdbfabojnoihfadacglilhjlojb\1 <br/>CHR Extension: (continuetosave) - C:\Users\Robin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmpjhchhgecknaeieeemgnfhkmnmmnap\1 <br/> <br/>==================== Services (Whitelisted) ================= <br/> <br/>R2 Akamai; c:\program files (x86)\common files\akamai/netsession_win_ca0e279.dll [4561152 2013-03-26] (Akamai Technologies, Inc.) <br/>R2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe [7391072 2012-01-31] (AVG Technologies CZ, s.r.o.) <br/>R2 avgwd; C:\Program Files (x86)\AVG\AVG10\avgwdsvc.exe [269520 2011-02-08] (AVG Technologies CZ, s.r.o.) <br/>R2 KPN Back-up Online SC; C:\Program Files\KPN Back-up Online\BackupSC.exe [523064 2013-01-30] (KPN) <br/>R2 ezSharedSvc; C:\Windows\System32\ezsvc7.dll [x] <br/> <br/>==================== Drivers (Whitelisted) ==================== <br/> <br/>S3 Apowersoft_AudioDevice; C:\Windows\System32\drivers\Apowersoft_AudioDevice.sys [29288 2010-12-24] (Wondershare) <br/>R3 AVGIDSDriver; C:\Windows\System32\DRIVERS\AVGIDSDriver.Sys [118864 2011-05-27] (AVG Technologies CZ, s.r.o. ) <br/>R0 AVGIDSEH; C:\Windows\System32\DRIVERS\AVGIDSEH.Sys [26704 2011-02-22] (AVG Technologies CZ, s.r.o. ) <br/>R3 AVGIDSFilter; C:\Windows\System32\DRIVERS\AVGIDSFilter.Sys [29264 2011-02-10] (AVG Technologies CZ, s.r.o. ) <br/>R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [312160 2012-11-12] (AVG Technologies CZ, s.r.o.) <br/>R1 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [41552 2011-03-01] (AVG Technologies CZ, s.r.o.) <br/>R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [37456 2011-03-16] (AVG Technologies CZ, s.r.o.) <br/>R1 Avgtdia; C:\Windows\System32\DRIVERS\avgtdia.sys [377936 2011-04-05] (AVG Technologies CZ, s.r.o.) <br/>R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2012-10-28] (DT Soft Ltd) <br/>R0 MxEFUF; C:\Windows\System32\DRIVERS\MxEFUF64.sys [157696 2011-10-20] (Matrox Graphics Inc.) <br/>S3 Serial; C:\Windows\system32\DRIVERS\serial.sys [94208 2009-07-14] (Brother Industries Ltd.) <br/>S3 ew_hwusbdev; system32\DRIVERS\ew_hwusbdev.sys [x] <br/>S3 huawei_cdcacm; system32\DRIVERS\ew_jucdcacm.sys [x] <br/>S3 huawei_enumerator; system32\DRIVERS\ew_jubusenum.sys [x] <br/>S3 hwdatacard; system32\DRIVERS\ewusbmdm.sys [x] <br/> <br/>==================== NetSvcs (Whitelisted) =================== <br/> <br/> <br/>==================== One Month Created Files and Folders ======== <br/> <br/>2030-08-29 15:22 - 2030-08-29 15:22 - 00143872 ____N (Intel Corporation) C:\Windows\SysWOW64\iacenc.dll <br/>2030-08-29 15:22 - 2030-08-29 15:22 - 00056832 ____N C:\Windows\SysWOW64\iyvu9_32.dll <br/>2013-05-30 13:11 - 2013-05-30 13:11 - 00000000 ____D C:\FRST <br/>2013-05-30 13:10 - 2013-05-30 13:10 - 01915774 ____A (Farbar) C:\Users\Robin\Desktop\FRST64.exe <br/>2013-05-29 12:45 - 2013-05-29 16:06 - 95023320 ___AT C:\ProgramData\qgrmj.pad <br/>2013-05-29 12:45 - 2013-05-29 16:06 - 00000000 ____A C:\ProgramData\as98213.txt <br/>2013-05-29 12:44 - 2013-05-29 12:45 - 95023320 ___AT C:\ProgramData\rheo.pad <br/>2013-05-29 12:44 - 2013-05-29 12:44 - 00159744 ____A (?????????? ??????????) C:\ProgramData\oehr.dat <br/>2013-05-29 12:44 - 2013-05-29 12:44 - 00159744 ____A (?????????? ??????????) C:\ProgramData\jmrgq.dat <br/>2013-05-27 22:03 - 2013-05-27 22:39 - 00000000 ____D C:\Users\Robin\Downloads\Chocolat (2000) <br/>2013-05-27 10:01 - 2013-05-27 10:01 - 00000000 ____D C:\Users\Robin\AppData\Local\{C1A388B3-BABA-4480-8693-388271925238} <br/>2013-05-25 17:07 - 2013-05-25 17:07 - 01394590 ____A C:\Users\Robin\Desktop\visuals.psd <br/>2013-05-25 15:14 - 2013-05-25 15:14 - 00277040 ____A C:\Windows\Minidump\052513-43602-01.dmp <br/>2013-05-23 14:16 - 2013-05-23 14:16 - 00000000 ____D C:\Users\Robin\AppData\Local\{D338AD4D-1069-4B70-A27C-0954EEFFA2F5} <br/>2013-05-22 11:17 - 2013-05-22 11:18 - 00000000 ____D C:\Users\Robin\AppData\Local\{55588D7E-1613-418F-A4FC-525AD34F5762} <br/>2013-05-21 23:43 - 2013-05-21 23:43 - 00276984 ____A C:\Windows\Minidump\052113-42915-01.dmp <br/>2013-05-18 20:24 - 2013-05-18 20:24 - 00277040 ____A C:\Windows\Minidump\051813-45302-01.dmp <br/>2013-05-17 10:22 - 2013-04-05 08:52 - 02242048 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll <br/>2013-05-17 10:22 - 2013-04-05 08:52 - 01365504 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll <br/>2013-05-17 10:22 - 2013-04-05 08:52 - 00051712 ____A (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe <br/>2013-05-17 10:22 - 2013-04-05 08:50 - 19231232 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll <br/>2013-05-17 10:22 - 2013-04-05 08:50 - 15404032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll <br/>2013-05-17 10:22 - 2013-04-05 08:50 - 03958784 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll <br/>2013-05-17 10:22 - 2013-04-05 08:50 - 02647552 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll <br/>2013-05-17 10:22 - 2013-04-05 08:50 - 00855552 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll <br/>2013-05-17 10:22 - 2013-04-05 08:50 - 00603136 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll <br/>2013-05-17 10:22 - 2013-04-05 08:50 - 00526336 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll <br/>2013-05-17 10:22 - 2013-04-05 08:50 - 00136704 ____A (Microsoft Corporation) C:\Windows\System32\iesysprep.dll <br/>2013-05-17 10:22 - 2013-04-05 08:50 - 00067072 ____A (Microsoft Corporation) C:\Windows\System32\iesetup.dll <br/>2013-05-17 10:22 - 2013-04-05 08:50 - 00053248 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll <br/>2013-05-17 10:22 - 2013-04-05 08:50 - 00039936 ____A (Microsoft Corporation) C:\Windows\System32\iernonce.dll <br/>2013-05-17 10:22 - 2013-04-05 07:28 - 01767424 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll <br/>2013-05-17 10:22 - 2013-04-05 07:28 - 01130496 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll <br/>2013-05-17 10:22 - 2013-04-05 07:26 - 14323712 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll <br/>2013-05-17 10:22 - 2013-04-05 07:26 - 13760512 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll <br/>2013-05-17 10:22 - 2013-04-05 07:26 - 02877440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll <br/>2013-05-17 10:22 - 2013-04-05 07:26 - 02046976 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll <br/>2013-05-17 10:22 - 2013-04-05 07:26 - 00690688 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll <br/>2013-05-17 10:22 - 2013-04-05 07:26 - 00493056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll <br/>2013-05-17 10:22 - 2013-04-05 07:26 - 00391168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll <br/>2013-05-17 10:22 - 2013-04-05 07:26 - 00109056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll <br/>2013-05-17 10:22 - 2013-04-05 07:26 - 00061440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll <br/>2013-05-17 10:22 - 2013-04-05 07:26 - 00039424 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll <br/>2013-05-17 10:22 - 2013-04-05 07:26 - 00033280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll <br/>2013-05-17 10:22 - 2013-04-05 06:43 - 02706432 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb <br/>2013-05-17 10:22 - 2013-04-05 06:29 - 02706432 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb <br/>2013-05-17 10:22 - 2013-04-05 05:51 - 00089600 ____A (Microsoft Corporation) C:\Windows\System32\RegisterIEPKEYs.exe <br/>2013-05-17 10:22 - 2013-04-05 05:38 - 00071680 ____A (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe <br/>2013-05-16 12:17 - 2013-04-10 08:01 - 00983400 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\dxgkrnl.sys <br/>2013-05-16 12:17 - 2013-04-10 08:01 - 00265064 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\dxgmms1.sys <br/>2013-05-16 12:17 - 2013-04-10 05:30 - 03153920 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys <br/>2013-05-16 12:17 - 2013-03-19 07:53 - 00230400 ____A (Microsoft Corporation) C:\Windows\System32\wwansvc.dll <br/>2013-05-16 12:17 - 2013-03-19 07:53 - 00048640 ____A (Microsoft Corporation) C:\Windows\System32\wwanprotdim.dll <br/>2013-05-16 12:17 - 2013-02-27 08:02 - 00111448 ____A (Microsoft Corporation) C:\Windows\System32\consent.exe <br/>2013-05-16 12:17 - 2013-02-27 07:52 - 14172672 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll <br/>2013-05-16 12:17 - 2013-02-27 07:52 - 00197120 ____A (Microsoft Corporation) C:\Windows\System32\shdocvw.dll <br/>2013-05-16 12:17 - 2013-02-27 07:48 - 01930752 ____A (Microsoft Corporation) C:\Windows\System32\authui.dll <br/>2013-05-16 12:17 - 2013-02-27 07:47 - 00070144 ____A (Microsoft Corporation) C:\Windows\System32\appinfo.dll <br/>2013-05-16 12:17 - 2013-02-27 06:55 - 12872704 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll <br/>2013-05-16 12:17 - 2013-02-27 06:55 - 00180224 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll <br/>2013-05-16 12:17 - 2013-02-27 06:49 - 01796096 ____A (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll <br/>2013-05-16 12:17 - 2011-02-03 13:25 - 00144384 ____A (Microsoft Corporation) C:\Windows\System32\cdd.dll <br/>2013-05-15 20:18 - 2013-05-15 20:18 - 09195912 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe <br/>2013-05-15 14:12 - 2013-05-15 14:12 - 00277040 ____A C:\Windows\Minidump\051513-26098-01.dmp <br/>2013-05-15 11:39 - 2013-05-15 11:40 - 00000000 ____D C:\Users\Robin\AppData\Local\{75D0177D-FC9A-45B6-AB00-A960E6806553} <br/>2013-05-14 20:40 - 2013-05-14 20:41 - 00277040 ____A C:\Windows\Minidump\051413-32822-01.dmp <br/>2013-05-14 11:15 - 2013-05-14 11:15 - 00000000 ____D C:\Users\Robin\AppData\Local\{744C7F61-1CFC-4A71-AE3B-16BFC617436E} <br/>2013-05-14 09:26 - 2013-05-14 09:27 - 00276984 ____A C:\Windows\Minidump\051413-35334-01.dmp <br/>2013-05-11 19:58 - 2013-05-11 19:58 - 00277040 ____A C:\Windows\Minidump\051113-71261-01.dmp <br/>2013-05-10 16:48 - 2013-05-10 16:48 - 00000000 ____D C:\ProgramData\NCH Software <br/>2013-05-10 16:37 - 2013-05-10 16:37 - 00000000 ____D C:\Users\Public\Documents\Adobe <br/>2013-05-10 15:59 - 2013-05-10 16:04 - 00000000 ____D C:\Users\Robin\AppData\Roaming\MAXQDA11 <br/>2013-05-10 15:57 - 2013-05-10 16:46 - 00000000 ____D C:\Users\Public\Documents\MAXQDA11 <br/>2013-05-10 15:56 - 2013-05-10 16:46 - 00000000 ____D C:\ProgramData\MAXQDA11 <br/>2013-05-10 15:56 - 2013-05-10 16:46 - 00000000 ____D C:\Program Files (x86)\MAXQDA11 <br/>2013-05-10 15:56 - 2013-05-10 15:56 - 00000000 ____D C:\Users\Robin\Downloads\MAXQDA v10.4.15.1 (Cracked) <br/>2013-05-10 15:32 - 2013-05-10 15:32 - 00324034 ____A C:\Users\Robin\Documents\speech thesis.prproj <br/>2013-05-10 15:19 - 2013-05-10 15:19 - 00000000 ____D C:\Users\Robin\AppData\Local\IsolatedStorage <br/>2013-05-10 15:16 - 2013-05-10 15:16 - 00000262 _RASH C:\Users\Robin\ntuser.pol <br/>2013-05-10 14:15 - 2013-05-29 16:56 - 00000000 ____D C:\Program Files (x86)\Airfoil <br/>2013-05-10 14:15 - 2013-05-10 14:15 - 00000989 ____A C:\Users\Mcx1-ROBIN-PC\Desktop\Airfoil Speakers.lnk <br/>2013-05-10 14:15 - 2013-05-10 14:15 - 00000925 ____A C:\Users\Mcx1-ROBIN-PC\Desktop\Airfoil.lnk <br/>2013-05-10 14:15 - 2013-05-10 14:15 - 00000000 ____D C:\Users\Robin\AppData\Local\Rogue_Amoeba <br/>2013-05-10 14:15 - 2013-05-10 14:15 - 00000000 ____D C:\users\Mcx1-ROBIN-PC <br/>2013-05-08 13:39 - 2013-05-08 13:39 - 00000000 ____D C:\Program Files (x86)\WeftQDA <br/>2013-05-08 13:38 - 2013-05-08 13:38 - 00001447 ____A C:\Users\Robin\Desktop\Atlasti - Snelkoppeling.lnk <br/>2013-05-08 13:30 - 2013-05-29 21:18 - 00000000 ____D C:\Users\Robin\Downloads\ATLASti <br/>2013-05-08 13:25 - 2013-05-10 16:48 - 00000000 ____D C:\Users\Robin\AppData\Roaming\NCH Software <br/>2013-05-08 12:20 - 2013-05-08 12:20 - 00000000 ____D C:\Users\Robin\AppData\Local\{6D4B1CFF-9CFE-4A2B-8B8E-6936AE9ACC78} <br/>2013-05-07 15:39 - 2013-05-07 15:39 - 00000000 ____D C:\Users\Robin\AppData\Local\{455B4C61-85FD-42A3-8728-EB7136024442} <br/>2013-05-06 18:24 - 2013-05-06 18:24 - 00000000 ____D C:\Users\Robin\AppData\Local\{47770974-5FDD-47ED-B4B5-A3AFD11C3AA1} <br/>2013-05-01 15:42 - 2013-05-01 15:42 - 00000000 ____D C:\Users\Robin\AppData\Local\{506EDB7C-4720-45D7-8C70-D0A75A590E6B} <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 01509376 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 01441280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 01400416 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 01400416 ____A (Microsoft Corporation) C:\Windows\System32\ieapfltr.dat <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 01054720 ____A (Microsoft Corporation) C:\Windows\System32\MsSpellCheckingFacility.exe <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00905728 ____A (Microsoft Corporation) C:\Windows\System32\mshtmlmedia.dll <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00762368 ____A (Microsoft Corporation) C:\Windows\System32\ieapfltr.dll <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00719360 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00629248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00599552 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00523264 ____A (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00452096 ____A (Microsoft Corporation) C:\Windows\System32\dxtmsft.dll <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00441856 ____A (Microsoft Corporation) C:\Windows\System32\html.iec <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00361984 ____A (Microsoft Corporation) C:\Windows\SysWOW64\html.iec <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00357888 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00281600 ____A (Microsoft Corporation) C:\Windows\System32\dxtrans.dll <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00270848 ____A (Microsoft Corporation) C:\Windows\System32\iedkcs32.dll <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00247296 ____A (Microsoft Corporation) C:\Windows\System32\webcheck.dll <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00242200 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00235008 ____A (Microsoft Corporation) C:\Windows\System32\url.dll <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00232960 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00226816 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00226304 ____A (Microsoft Corporation) C:\Windows\System32\elshyph.dll <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00216064 ____A (Microsoft Corporation) C:\Windows\System32\msls31.dll <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00204800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00197120 ____A (Microsoft Corporation) C:\Windows\System32\msrating.dll <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00185344 ____A (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00173568 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00167424 ____A (Microsoft Corporation) C:\Windows\System32\iexpress.exe <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00163840 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00158720 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00150528 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00149504 ____A (Microsoft Corporation) C:\Windows\System32\occache.dll <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00144896 ____A (Microsoft Corporation) C:\Windows\System32\wextract.exe <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00138752 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00137216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00136192 ____A (Microsoft Corporation) C:\Windows\System32\iepeers.dll <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00135680 ____A (Microsoft Corporation) C:\Windows\System32\IEAdvpack.dll <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00125440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00117248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00110592 ____A (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00102912 ____A (Microsoft Corporation) C:\Windows\System32\inseng.dll <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00097280 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00092160 ____A (Microsoft Corporation) C:\Windows\System32\SetIEInstalledDate.exe <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00082432 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00081408 ____A (Microsoft Corporation) C:\Windows\System32\icardie.dll <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00079872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00077312 ____A (Microsoft Corporation) C:\Windows\System32\tdc.ocx <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00073728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00069120 ____A (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00062976 ____A (Microsoft Corporation) C:\Windows\System32\pngfilt.dll <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00061952 ____A (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00057344 ____A (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00052224 ____A (Microsoft Corporation) C:\Windows\System32\msfeedsbs.dll <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00051200 ____A (Microsoft Corporation) C:\Windows\System32\imgutil.dll <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00048640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00048640 ____A (Microsoft Corporation) C:\Windows\System32\mshtmler.dll <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00041984 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00038400 ____A (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00027648 ____A (Microsoft Corporation) C:\Windows\System32\licmgr10.dll <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00023040 ____A (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00013824 ____A (Microsoft Corporation) C:\Windows\System32\mshta.exe <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00012800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00012800 ____A (Microsoft Corporation) C:\Windows\System32\msfeedssync.exe <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00011776 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe <br/>2013-05-01 15:35 - 2013-05-01 15:46 - 00009499 ____A C:\Windows\IE10_main.log <br/> <br/>==================== One Month Modified Files and Folders ======= <br/> <br/>2030-08-29 15:22 - 2030-08-29 15:22 - 00143872 ____N (Intel Corporation) C:\Windows\SysWOW64\iacenc.dll <br/>2030-08-29 15:22 - 2030-08-29 15:22 - 00056832 ____N C:\Windows\SysWOW64\iyvu9_32.dll <br/>2013-05-30 13:11 - 2013-05-30 13:11 - 00000000 ____D C:\FRST <br/>2013-05-30 13:10 - 2013-05-30 13:10 - 01915774 ____A (Farbar) C:\Users\Robin\Desktop\FRST64.exe <br/>2013-05-30 13:07 - 2013-02-22 16:23 - 00000000 ____D C:\ProgramData\continuetosave <br/>2013-05-30 13:07 - 2013-01-16 17:22 - 00001050 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job <br/>2013-05-30 13:06 - 2013-04-09 13:07 - 00000000 ____D C:\ProgramData\boost_interprocess <br/>2013-05-30 13:06 - 2012-08-16 00:41 - 00040891 ____A C:\Windows\setupact.log <br/>2013-05-30 13:06 - 2009-07-14 07:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT <br/>2013-05-29 22:46 - 2010-04-27 02:26 - 01775475 ____A C:\Windows\WindowsUpdate.log <br/>2013-05-29 22:37 - 2013-01-16 17:22 - 00001054 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job <br/>2013-05-29 22:18 - 2013-01-08 18:07 - 00000940 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job <br/>2013-05-29 21:18 - 2013-05-08 13:30 - 00000000 ____D C:\Users\Robin\Downloads\ATLASti <br/>2013-05-29 17:06 - 2009-07-14 06:45 - 00023248 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 <br/>2013-05-29 17:06 - 2009-07-14 06:45 - 00023248 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 <br/>2013-05-29 17:03 - 2010-11-08 13:56 - 00000000 ____D C:\Windows\System32\Drivers\AVG <br/>2013-05-29 16:59 - 2010-10-06 15:10 - 00000000 ____D C:\users\Robin <br/>2013-05-29 16:58 - 2009-07-14 07:08 - 00032636 ____A C:\Windows\Tasks\SCHEDLGU.TXT <br/>2013-05-29 16:56 - 2013-05-10 14:15 - 00000000 ____D C:\Program Files (x86)\Airfoil <br/>2013-05-29 16:56 - 2013-04-09 13:07 - 00000000 ____D C:\Program Files\KPN Back-up Online <br/>2013-05-29 16:56 - 2010-10-06 21:39 - 00000000 ____D C:\Users\Robin\AppData\Roaming\uTorrent <br/>2013-05-29 16:56 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\registration <br/>2013-05-29 16:56 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\AppCompat <br/>2013-05-29 16:06 - 2013-05-29 12:45 - 95023320 ___AT C:\ProgramData\qgrmj.pad <br/>2013-05-29 16:06 - 2013-05-29 12:45 - 00000000 ____A C:\ProgramData\as98213.txt <br/>2013-05-29 12:45 - 2013-05-29 12:44 - 95023320 ___AT C:\ProgramData\rheo.pad <br/>2013-05-29 12:44 - 2013-05-29 12:44 - 00159744 ____A (?????????? ??????????) C:\ProgramData\oehr.dat <br/>2013-05-29 12:44 - 2013-05-29 12:44 - 00159744 ____A (?????????? ??????????) C:\ProgramData\jmrgq.dat <br/>2013-05-28 17:40 - 2010-10-25 21:29 - 00001456 ____A C:\Users\Robin\AppData\Local\Adobe Opslaan voor web 12.0 Prefs <br/>2013-05-28 16:23 - 2011-05-15 16:49 - 00000000 ____D C:\Users\Robin\AppData\Local\Spotify <br/>2013-05-27 22:39 - 2013-05-27 22:03 - 00000000 ____D C:\Users\Robin\Downloads\Chocolat (2000) <br/>2013-05-27 11:16 - 2010-11-01 16:30 - 00000000 ____D C:\Users\Robin\Documents\3voor12 <br/>2013-05-27 10:01 - 2013-05-27 10:01 - 00000000 ____D C:\Users\Robin\AppData\Local\{C1A388B3-BABA-4480-8693-388271925238} <br/>2013-05-25 19:26 - 2013-02-26 19:11 - 00000000 ____D C:\Users\Robin\AppData\Roaming\Spotify <br/>2013-05-25 17:07 - 2013-05-25 17:07 - 01394590 ____A C:\Users\Robin\Desktop\visuals.psd <br/>2013-05-25 15:14 - 2013-05-25 15:14 - 00277040 ____A C:\Windows\Minidump\052513-43602-01.dmp <br/>2013-05-25 15:14 - 2012-09-08 09:56 - 419129752 ____A C:\Windows\MEMORY.DMP <br/>2013-05-25 15:14 - 2011-09-29 19:43 - 00000000 ____D C:\Windows\Minidump <br/>2013-05-25 13:36 - 2013-03-04 13:49 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service <br/>2013-05-24 16:12 - 2013-04-12 12:54 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox <br/>2013-05-24 16:12 - 2013-03-08 17:07 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox.bak <br/>2013-05-23 14:16 - 2013-05-23 14:16 - 00000000 ____D C:\Users\Robin\AppData\Local\{D338AD4D-1069-4B70-A27C-0954EEFFA2F5} <br/>2013-05-22 13:12 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache <br/>2013-05-22 11:18 - 2013-05-22 11:17 - 00000000 ____D C:\Users\Robin\AppData\Local\{55588D7E-1613-418F-A4FC-525AD34F5762} <br/>2013-05-21 23:43 - 2013-05-21 23:43 - 00276984 ____A C:\Windows\Minidump\052113-42915-01.dmp <br/>2013-05-21 16:35 - 2011-09-20 15:15 - 00024206 ____A C:\Users\Robin\Documents\Diary.ods <br/>2013-05-19 19:00 - 2010-03-28 02:31 - 10636238 ____A C:\Windows\System32\perfh013.dat <br/>2013-05-19 19:00 - 2010-03-28 02:31 - 03434972 ____A C:\Windows\System32\perfc013.dat <br/>2013-05-19 19:00 - 2009-07-14 07:13 - 00005214 ____A C:\Windows\System32\PerfStringBackup.INI <br/>2013-05-18 20:24 - 2013-05-18 20:24 - 00277040 ____A C:\Windows\Minidump\051813-45302-01.dmp <br/>2013-05-17 10:53 - 2009-07-14 06:45 - 04957728 ____A C:\Windows\System32\FNTCACHE.DAT <br/>2013-05-17 10:29 - 2010-11-01 22:36 - 75016696 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe <br/>2013-05-15 20:18 - 2013-05-15 20:18 - 09195912 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe <br/>2013-05-15 20:18 - 2012-07-24 09:44 - 00692104 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe <br/>2013-05-15 20:18 - 2011-06-12 15:34 - 00071048 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl <br/>2013-05-15 14:12 - 2013-05-15 14:12 - 00277040 ____A C:\Windows\Minidump\051513-26098-01.dmp <br/>2013-05-15 11:40 - 2013-05-15 11:39 - 00000000 ____D C:\Users\Robin\AppData\Local\{75D0177D-FC9A-45B6-AB00-A960E6806553} <br/>2013-05-14 20:41 - 2013-05-14 20:40 - 00277040 ____A C:\Windows\Minidump\051413-32822-01.dmp <br/>2013-05-14 11:15 - 2013-05-14 11:15 - 00000000 ____D C:\Users\Robin\AppData\Local\{744C7F61-1CFC-4A71-AE3B-16BFC617436E} <br/>2013-05-14 09:27 - 2013-05-14 09:26 - 00276984 ____A C:\Windows\Minidump\051413-35334-01.dmp <br/>2013-05-13 16:46 - 2012-09-30 13:34 - 00000000 ____D C:\Users\Robin\Documents\The Daily Indie <br/>2013-05-11 19:58 - 2013-05-11 19:58 - 00277040 ____A C:\Windows\Minidump\051113-71261-01.dmp <br/>2013-05-11 19:57 - 2010-10-06 15:05 - 00397492 ____A C:\Windows\PFRO.log <br/>2013-05-10 16:48 - 2013-05-10 16:48 - 00000000 ____D C:\ProgramData\NCH Software <br/>2013-05-10 16:48 - 2013-05-08 13:25 - 00000000 ____D C:\Users\Robin\AppData\Roaming\NCH Software <br/>2013-05-10 16:48 - 2012-11-10 21:26 - 00000000 ____D C:\Program Files (x86)\NCH Software <br/>2013-05-10 16:46 - 2013-05-10 15:57 - 00000000 ____D C:\Users\Public\Documents\MAXQDA11 <br/>2013-05-10 16:46 - 2013-05-10 15:56 - 00000000 ____D C:\ProgramData\MAXQDA11 <br/>2013-05-10 16:46 - 2013-05-10 15:56 - 00000000 ____D C:\Program Files (x86)\MAXQDA11 <br/>2013-05-10 16:45 - 2010-03-27 18:53 - 00000000 ____D C:\Program Files (x86)\Adobe <br/>2013-05-10 16:38 - 2010-10-22 17:35 - 00000000 ____D C:\ProgramData\regid.1986-12.com.adobe <br/>2013-05-10 16:37 - 2013-05-10 16:37 - 00000000 ____D C:\Users\Public\Documents\Adobe <br/>2013-05-10 16:37 - 2010-10-15 15:23 - 00000000 ____D C:\Users\Robin\AppData\Local\Adobe <br/>2013-05-10 16:37 - 2010-10-06 17:25 - 00000000 ____D C:\Users\Robin\AppData\Roaming\Adobe <br/>2013-05-10 16:04 - 2013-05-10 15:59 - 00000000 ____D C:\Users\Robin\AppData\Roaming\MAXQDA11 <br/>2013-05-10 15:56 - 2013-05-10 15:56 - 00000000 ____D C:\Users\Robin\Downloads\MAXQDA v10.4.15.1 (Cracked) <br/>2013-05-10 15:40 - 2010-03-27 18:54 - 00000000 ____D C:\ProgramData\Adobe <br/>2013-05-10 15:39 - 2012-03-12 13:05 - 00000000 ____D C:\Users\Robin\AppData\Roaming\Skype <br/>2013-05-10 15:32 - 2013-05-10 15:32 - 00324034 ____A C:\Users\Robin\Documents\speech thesis.prproj <br/>2013-05-10 15:19 - 2013-05-10 15:19 - 00000000 ____D C:\Users\Robin\AppData\Local\IsolatedStorage <br/>2013-05-10 15:16 - 2013-05-10 15:16 - 00000262 _RASH C:\Users\Robin\ntuser.pol <br/>2013-05-10 15:16 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\GroupPolicy <br/>2013-05-10 14:15 - 2013-05-10 14:15 - 00000989 ____A C:\Users\Mcx1-ROBIN-PC\Desktop\Airfoil Speakers.lnk <br/>2013-05-10 14:15 - 2013-05-10 14:15 - 00000925 ____A C:\Users\Mcx1-ROBIN-PC\Desktop\Airfoil.lnk <br/>2013-05-10 14:15 - 2013-05-10 14:15 - 00000000 ____D C:\Users\Robin\AppData\Local\Rogue_Amoeba <br/>2013-05-10 14:15 - 2013-05-10 14:15 - 00000000 ____D C:\users\Mcx1-ROBIN-PC <br/>2013-05-08 13:39 - 2013-05-08 13:39 - 00000000 ____D C:\Program Files (x86)\WeftQDA <br/>2013-05-08 13:38 - 2013-05-08 13:38 - 00001447 ____A C:\Users\Robin\Desktop\Atlasti - Snelkoppeling.lnk <br/>2013-05-08 12:20 - 2013-05-08 12:20 - 00000000 ____D C:\Users\Robin\AppData\Local\{6D4B1CFF-9CFE-4A2B-8B8E-6936AE9ACC78} <br/>2013-05-07 15:39 - 2013-05-07 15:39 - 00000000 ____D C:\Users\Robin\AppData\Local\{455B4C61-85FD-42A3-8728-EB7136024442} <br/>2013-05-06 18:24 - 2013-05-06 18:24 - 00000000 ____D C:\Users\Robin\AppData\Local\{47770974-5FDD-47ED-B4B5-A3AFD11C3AA1} <br/>2013-05-04 19:20 - 2013-04-10 00:47 - 00000000 ____D C:\Users\Robin\Documents\Dirk artikel <br/>2013-05-01 22:27 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\PolicyDefinitions <br/>2013-05-01 15:46 - 2013-05-01 15:35 - 00009499 ____A C:\Windows\IE10_main.log <br/>2013-05-01 15:42 - 2013-05-01 15:42 - 00000000 ____D C:\Users\Robin\AppData\Local\{506EDB7C-4720-45D7-8C70-D0A75A590E6B} <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 01509376 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 01441280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 01400416 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 01400416 ____A (Microsoft Corporation) C:\Windows\System32\ieapfltr.dat <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 01054720 ____A (Microsoft Corporation) C:\Windows\System32\MsSpellCheckingFacility.exe <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00905728 ____A (Microsoft Corporation) C:\Windows\System32\mshtmlmedia.dll <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00762368 ____A (Microsoft Corporation) C:\Windows\System32\ieapfltr.dll <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00719360 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00629248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00599552 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00523264 ____A (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00452096 ____A (Microsoft Corporation) C:\Windows\System32\dxtmsft.dll <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00441856 ____A (Microsoft Corporation) C:\Windows\System32\html.iec <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00361984 ____A (Microsoft Corporation) C:\Windows\SysWOW64\html.iec <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00357888 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00281600 ____A (Microsoft Corporation) C:\Windows\System32\dxtrans.dll <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00270848 ____A (Microsoft Corporation) C:\Windows\System32\iedkcs32.dll <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00247296 ____A (Microsoft Corporation) C:\Windows\System32\webcheck.dll <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00242200 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00235008 ____A (Microsoft Corporation) C:\Windows\System32\url.dll <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00232960 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00226816 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00226304 ____A (Microsoft Corporation) C:\Windows\System32\elshyph.dll <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00216064 ____A (Microsoft Corporation) C:\Windows\System32\msls31.dll <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00204800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00197120 ____A (Microsoft Corporation) C:\Windows\System32\msrating.dll <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00185344 ____A (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00173568 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00167424 ____A (Microsoft Corporation) C:\Windows\System32\iexpress.exe <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00163840 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00158720 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00150528 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00149504 ____A (Microsoft Corporation) C:\Windows\System32\occache.dll <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00144896 ____A (Microsoft Corporation) C:\Windows\System32\wextract.exe <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00138752 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00137216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00136192 ____A (Microsoft Corporation) C:\Windows\System32\iepeers.dll <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00135680 ____A (Microsoft Corporation) C:\Windows\System32\IEAdvpack.dll <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00125440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00117248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00110592 ____A (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00102912 ____A (Microsoft Corporation) C:\Windows\System32\inseng.dll <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00097280 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00092160 ____A (Microsoft Corporation) C:\Windows\System32\SetIEInstalledDate.exe <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00082432 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00081408 ____A (Microsoft Corporation) C:\Windows\System32\icardie.dll <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00079872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00077312 ____A (Microsoft Corporation) C:\Windows\System32\tdc.ocx <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00073728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00069120 ____A (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00062976 ____A (Microsoft Corporation) C:\Windows\System32\pngfilt.dll <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00061952 ____A (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00057344 ____A (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00052224 ____A (Microsoft Corporation) C:\Windows\System32\msfeedsbs.dll <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00051200 ____A (Microsoft Corporation) C:\Windows\System32\imgutil.dll <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00048640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00048640 ____A (Microsoft Corporation) C:\Windows\System32\mshtmler.dll <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00041984 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00038400 ____A (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00027648 ____A (Microsoft Corporation) C:\Windows\System32\licmgr10.dll <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00023040 ____A (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00013824 ____A (Microsoft Corporation) C:\Windows\System32\mshta.exe <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00012800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00012800 ____A (Microsoft Corporation) C:\Windows\System32\msfeedssync.exe <br/>2013-05-01 15:38 - 2013-05-01 15:38 - 00011776 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe <br/> <br/>Other Malware: <br/>=========== <br/>C:\ProgramData\jmrgq.dat <br/>C:\ProgramData\oehr.dat <br/>C:\ProgramData\qgrmj.pad <br/>C:\ProgramData\rheo.pad <br/> <br/>==================== Bamital & volsnap Check ================= <br/> <br/>C:\Windows\System32\winlogon.exe => MD5 is legit <br/>C:\Windows\System32\wininit.exe => MD5 is legit <br/>C:\Windows\SysWOW64\wininit.exe => MD5 is legit <br/>C:\Windows\explorer.exe => MD5 is legit <br/>C:\Windows\SysWOW64\explorer.exe => MD5 is legit <br/>C:\Windows\System32\svchost.exe => MD5 is legit <br/>C:\Windows\SysWOW64\svchost.exe => MD5 is legit <br/>C:\Windows\System32\services.exe => MD5 is legit <br/>C:\Windows\System32\User32.dll => MD5 is legit <br/>C:\Windows\SysWOW64\User32.dll => MD5 is legit <br/>C:\Windows\System32\userinit.exe => MD5 is legit <br/>C:\Windows\SysWOW64\userinit.exe => MD5 is legit <br/>C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit <br/> <br/> <br/>Last Boot: 2013-05-25 19:51 <br/> <br/>==================== End Of Log ============================
Posted 5/30/2013 1:24 PM
#95688
User avatar

Touch Advanced member

Date Joined Nov 2016
Total Posts: 12976
Looks like you have (had) the police virus, as there still are some remnants we'll need to remove.</div> <br/> <br/> <br/>Please work your way through the following steps: <br/>[color="#0000ff"></font>[/b] <br/> <br/><ul]* Open notepad (Start => All Programs => Accessories => Notepad). <br/>* Please copy the content of the below in the codebox. (To do this highlight the contents of the box, right click on it and select copy. <br/>* Right-click in the open notepad and select Paste). <br/>* Save it same place where you have Farbar Tool. <br/></ul><b>start <br/>BHO-x32: No Name - {7825CFB6-490A-436B-9F26-4A7B5CFC01A9} - No File <br/>BHO-x32: continuetosave - {F7DD5FF7-AA4B-25E4-8659-F4DF4AB1423A} - C:\ProgramData\continuetosave\512786279cfbf.dll No File <br/>Toolbar: HKCU - No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File <br/>Toolbar: HKCU - No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - No File <br/>Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - No File <br/>C:\ProgramData\qgrmj.pad <br/>C:\ProgramData\as98213.txt <br/>C:\ProgramData\rheo.pad <br/>C:\ProgramData\oehr.dat <br/>C:\ProgramData\jmrgq.dat <br/>end <br/> <br/></div></b> <br/> <br/>* Run <strong class="bbc">FRST</b><strong class="bbc"><strong class="bbc"> (or FRST64 if you have the 64bit version) and press the <strong class="bbc">Fix button just once and wait.</b></b></b> <br/>* <strong class="bbc"><strong class="bbc"><strong class="bbc"><strong class="bbc"><strong class="bbc">The tool will make a log - <strong class="bbc">Fixlog.txt</b></b></b></b></b></b> <br/>* <strong class="bbc"><strong class="bbc"><strong class="bbc"><strong class="bbc"><strong class="bbc"><strong class="bbc">Please post it in your next reply</b></b></b></b></b></b> <br/>* <strong class="bbc"><strong class="bbc"><strong class="bbc"><strong class="bbc"><strong class="bbc"><strong class="bbc">As soon as you have ran the above script please follow immediately with Combofix:</b></b></b></b></b></b> <br/>* <br/><strong class="bbc"><strong class="bbc"><strong class="bbc"><strong class="bbc"><strong class="bbc"><strong class="bbc"> </b></b></b></b></b></b> <br/><strong class="bbc"><strong class="bbc"><strong class="bbc"><strong class="bbc"><strong class="bbc"><strong class="bbc"> </b></b></b></b></b></b> <br/><strong class="bbc"><strong class="bbc"><strong class="bbc"><strong class="bbc"><strong class="bbc"><strong class="bbc"><span lang="DA">Please download Combofix from: <br/> <br/>http://download.bleepingcomputer.com/sUBs/ComboFix.exe <br/> <br/> <br/><font face="Verdana" size="1"><span lang="EN-GB"> <font size="2">And save to the desktop.[/color] <br/><font size="2"> <br/>  <br/> <br/></font></font><font face="Arial">After the download is complete, perform the following tasks before using the ComboFix tool to scan your PC: <br/> <br/>Exit all windows that are currently open on your computer. <br/> <br/>To prevent interference, temporarily disable your antivirus, antispyware, firewall and other security tools that may be running on your computer. <br/> <br/> <br/> <br/></font><font face="Verdana"><span lang="X-NONE">  <br/> <br/><span lang="EN-GB">Double-click on the combofix icon found on your desktop. <br/> <br/>  <br/> <br/><b>Please note, that once you start combofix you should not click anywhere on the combofix window as it can cause the program to stall. <br/>In fact, when combofix is running, do not touch your computer at all and just take a break as it may take a while for it to complete. <br/> <br/></b> <br/> <br/> When finished, it will produce a logfile located at C:\combofix.txt. <br/> <br/>  <br/> <br/> <br/> <br/>Post the contents of that log in your next reply <br/> <br/> <br/> <br/><span lang="X-NONE">The logs will be reasonably large so you may have to divide them into sections and make several posts to post them. <br/> <br/> <br/></font> <br/> <br/></b></b></b></b></b></b>

[color=black face="Courier New" sab="311">[2]Click here: Before-posting-a-log[/2][/url]

<?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" />
[/color]
Do not PM me with logfiles. They will be deleted.


Posted 6/5/2013 10:42 PM
#95712
User avatar

Robin085 Member

Date Joined Nov 2016
Total Posts: 7
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 28-05-2013 <br/>Ran by Robin at 2013-06-06 00:41:52 Run:1 <br/>Running from C:\Users\Robin\Desktop\Fix <br/>Boot Mode: Normal <br/>============================================== <br/> <br/>HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7825CFB6-490A-436B-9F26-4A7B5CFC01A9} => Key deleted successfully. <br/>HKCR\Wow6432Node\CLSID\{7825CFB6-490A-436B-9F26-4A7B5CFC01A9} => Key not found. <br/>HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F7DD5FF7-AA4B-25E4-8659-F4DF4AB1423A} => Key deleted successfully. <br/>HKCR\Wow6432Node\CLSID\{F7DD5FF7-AA4B-25E4-8659-F4DF4AB1423A} => Key deleted successfully. <br/>HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{21FA44EF-376D-4D53-9B0F-8A89D3229068} => Value deleted successfully. <br/>HKCR\CLSID\{21FA44EF-376D-4D53-9B0F-8A89D3229068} => Key not found. <br/>HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{D4027C7F-154A-4066-A1AD-4243D8127440} => Value deleted successfully. <br/>HKCR\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440} => Key not found. <br/>HKCR\PROTOCOLS\Handler\skype-ie-addon-data => Key deleted successfully. <br/>HKCR\CLSID\{91774881-D725-4E58-B298-07617B9B86A8} => Key not found. <br/>C:\ProgramData\qgrmj.pad => Moved successfully. <br/>C:\ProgramData\as98213.txt => Moved successfully. <br/>C:\ProgramData\rheo.pad => Moved successfully. <br/>C:\ProgramData\oehr.dat => Moved successfully. <br/>C:\ProgramData\jmrgq.dat => Moved successfully. <br/> <br/>==== End of Fixlog ====
Posted 6/5/2013 11:33 PM
#95713
User avatar

Robin085 Member

Date Joined Nov 2016
Total Posts: 7
Hi, above the FRST log. I ran Combofix as well and all went smoothly, but as soon as it finished and created the log, my internet connection was lost. I rebooted my pc and my router, but it doesn't solve it. I do in fact pick up the wifi signal but there's no www connection. My router's fine as I write this from my iPhone and it works fine. A quick google learns more people run into this after using Combofix, what to do? <br/> <br/>EDIT: I ran a system restore and internet is up again. I don't know whether the thing Combofix did, is undone now though? <br/> <br/>This is the Combofix log: <br/> <br/> <br/>ComboFix 13-06-05.05 - Robin 06-06-2013 0:51.1.2 - x64 <br/>Microsoft Windows 7 Home Premium 6.1.7601.1.1252.31.1043.18.3003.1848 [GMT 2:00] <br/>Gestart vanuit: c:\users\Robin\Desktop\ComboFix.exe <br/>AV: AVG Anti-Virus Free Edition 2011 *Disabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0} <br/>SP: AVG Anti-Virus Free Edition 2011 *Disabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D} <br/>SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} <br/>. <br/>. <br/>(((((((((((((((((((((((((((((((((( Andere Verwijderingen ))))))))))))))))))))))))))))))))))))))))))))))))) <br/>. <br/>. <br/>c:\programdata\continuetosave <br/>c:\programdata\continuetosave\512786279cfbf.tlb <br/>c:\programdata\continuetosave\512786797a1e7.tlb <br/>c:\programdata\continuetosave\settings.ini <br/>c:\users\Robin\AppData\Local\Microsoft\Windows\Temporary Internet Files\tbinst <br/>c:\users\Robin\AppData\Roaming\Microsoft\~DFK53e58f.tmp <br/>c:\users\Robin\AppData\Roaming\Microsoft\1eaadjc.dll <br/>c:\users\Robin\AppData\Roaming\Microsoft\bass.dll <br/>c:\users\Robin\AppData\Roaming\Microsoft\engine_vx.dll <br/>c:\users\Robin\AppData\Roaming\Microsoft\kfgresk.dll <br/>c:\users\Robin\AppData\Roaming\Microsoft\mjcriu.dll <br/>c:\users\Robin\AppData\Roaming\Microsoft\peaadje.dll <br/>c:\users\Robin\AppData\Roaming\Microsoft\qwadjb.dll <br/>c:\users\Robin\AppData\Roaming\Microsoft\rsaadjd.dll <br/>. <br/>. <br/>(((((((((((((((((((( Bestanden Gemaakt van 2013-05-05 to 2013-06-05 )))))))))))))))))))))))))))))) <br/>. <br/>. <br/>2030-08-29 13:22 . 2030-08-29 13:22 56832 ------w- c:\windows\SysWow64\iyvu9_32.dll <br/>2030-08-29 13:22 . 2030-08-29 13:22 143872 ------w- c:\windows\SysWow64\iacenc.dll <br/>2013-06-05 23:00 . 2013-06-05 23:00 -------- d-----w- c:\users\Default\AppData\Local\temp <br/>2013-05-30 18:28 . 2013-05-30 18:28 -------- d-----w- c:\users\Robin\AppData\Roaming\Mael <br/>2013-05-30 11:11 . 2013-05-30 11:11 -------- d-----w- C:\FRST <br/>2013-05-24 14:12 . 2013-05-24 14:12 262552 ----a-w- c:\program files (x86)\Mozilla Firefox\browser\components\browsercomps.dll <br/>2013-05-16 10:17 . 2013-04-10 03:30 3153920 ----a-w- c:\windows\system32\win32k.sys <br/>2013-05-15 18:18 . 2013-05-15 18:18 9195912 ----a-w- c:\windows\SysWow64\FlashPlayerInstaller.exe <br/>2013-05-10 14:48 . 2013-05-10 14:48 -------- d-----w- c:\programdata\NCH Software <br/>2013-05-10 14:06 . 2013-05-10 14:06 -------- d-----w- c:\users\Robin\AppData\Local\Programs <br/>2013-05-10 13:59 . 2013-05-10 14:04 -------- d-----w- c:\users\Robin\AppData\Roaming\MAXQDA11 <br/>2013-05-10 13:56 . 2013-05-10 14:46 -------- d-----w- c:\programdata\MAXQDA11 <br/>2013-05-10 13:56 . 2013-05-10 14:46 -------- d-----w- c:\program files (x86)\MAXQDA11 <br/>2013-05-10 13:19 . 2013-05-10 13:19 -------- d-----w- c:\users\Robin\AppData\Local\IsolatedStorage <br/>2013-05-10 13:16 . 2013-05-10 13:18 -------- d-----w- c:\program files (x86)\OApps <br/>2013-05-10 12:15 . 2013-05-10 12:15 -------- d-----w- c:\users\Robin\AppData\Local\Rogue_Amoeba <br/>2013-05-10 12:15 . 2013-05-10 12:15 -------- d-----w- c:\users\Mcx1-ROBIN-PC <br/>2013-05-10 12:15 . 2013-05-31 12:35 -------- d-----w- c:\program files (x86)\Airfoil <br/>2013-05-08 11:39 . 2013-05-30 22:16 -------- d-----w- c:\program files (x86)\WeftQDA <br/>2013-05-08 11:25 . 2013-05-10 14:48 -------- d-----w- c:\users\Robin\AppData\Roaming\NCH Software <br/>. <br/>. <br/>. <br/>((((((((((((((((((((((((((((((((((((((( Find3M Rapport )))))))))))))))))))))))))))))))))))))))))))))))))))) <br/>. <br/>2013-05-17 08:29 . 2010-11-01 20:36 75016696 ----a-w- c:\windows\system32\MRT.exe <br/>2013-05-15 18:18 . 2012-07-24 07:44 692104 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe <br/>2013-05-15 18:18 . 2011-06-12 13:34 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl <br/>2013-05-14 09:15 . 2010-06-24 10:33 22240 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll <br/>2013-05-01 13:38 . 2013-05-01 13:38 1054720 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe <br/>2013-05-01 13:38 . 2013-05-01 13:38 226304 ----a-w- c:\windows\system32\elshyph.dll <br/>2013-05-01 13:38 . 2013-05-01 13:38 185344 ----a-w- c:\windows\SysWow64\elshyph.dll <br/>2013-05-01 13:38 . 2013-05-01 13:38 158720 ----a-w- c:\windows\SysWow64\msls31.dll <br/>2013-05-01 13:38 . 2013-05-01 13:38 73728 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe <br/>2013-05-01 13:38 . 2013-05-01 13:38 719360 ----a-w- c:\windows\SysWow64\mshtmlmedia.dll <br/>2013-05-01 13:38 . 2013-05-01 13:38 523264 ----a-w- c:\windows\SysWow64\vbscript.dll <br/>2013-05-01 13:38 . 2013-05-01 13:38 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll <br/>2013-05-01 13:38 . 2013-05-01 13:38 38400 ----a-w- c:\windows\SysWow64\imgutil.dll <br/>2013-05-01 13:38 . 2013-05-01 13:38 150528 ----a-w- c:\windows\SysWow64\iexpress.exe <br/>2013-05-01 13:38 . 2013-05-01 13:38 138752 ----a-w- c:\windows\SysWow64\wextract.exe <br/>2013-05-01 13:38 . 2013-05-01 13:38 137216 ----a-w- c:\windows\SysWow64\ieUnatt.exe <br/>2013-05-01 13:38 . 2013-05-01 13:38 12800 ----a-w- c:\windows\SysWow64\mshta.exe <br/>2013-05-01 13:38 . 2013-05-01 13:38 110592 ----a-w- c:\windows\SysWow64\IEAdvpack.dll <br/>2013-05-01 13:38 . 2013-05-01 13:38 61952 ----a-w- c:\windows\SysWow64\tdc.ocx <br/>2013-05-01 13:38 . 2013-05-01 13:38 361984 ----a-w- c:\windows\SysWow64\html.iec <br/>2013-05-01 13:38 . 2013-05-01 13:38 23040 ----a-w- c:\windows\SysWow64\licmgr10.dll <br/>2013-05-01 13:38 . 2013-05-01 13:38 1441280 ----a-w- c:\windows\SysWow64\inetcpl.cpl <br/>2013-05-01 13:38 . 2013-05-01 13:38 905728 ----a-w- c:\windows\system32\mshtmlmedia.dll <br/>2013-05-01 13:38 . 2013-05-01 13:38 81408 ----a-w- c:\windows\system32\icardie.dll <br/>2013-05-01 13:38 . 2013-05-01 13:38 762368 ----a-w- c:\windows\system32\ieapfltr.dll <br/>2013-05-01 13:38 . 2013-05-01 13:38 452096 ----a-w- c:\windows\system32\dxtmsft.dll <br/>2013-05-01 13:38 . 2013-05-01 13:38 441856 ----a-w- c:\windows\system32\html.iec <br/>2013-05-01 13:38 . 2013-05-01 13:38 281600 ----a-w- c:\windows\system32\dxtrans.dll <br/>2013-05-01 13:38 . 2013-05-01 13:38 270848 ----a-w- c:\windows\system32\iedkcs32.dll <br/>2013-05-01 13:38 . 2013-05-01 13:38 235008 ----a-w- c:\windows\system32\url.dll <br/>2013-05-01 13:38 . 2013-05-01 13:38 216064 ----a-w- c:\windows\system32\msls31.dll <br/>2013-05-01 13:38 . 2013-05-01 13:38 197120 ----a-w- c:\windows\system32\msrating.dll <br/>2013-05-01 13:38 . 2013-05-01 13:38 1509376 ----a-w- c:\windows\system32\inetcpl.cpl <br/>2013-05-01 13:38 . 2013-05-01 13:38 1400416 ----a-w- c:\windows\system32\ieapfltr.dat <br/>2013-05-01 13:38 . 2013-05-01 13:38 97280 ----a-w- c:\windows\system32\mshtmled.dll <br/>2013-05-01 13:38 . 2013-05-01 13:38 599552 ----a-w- c:\windows\system32\vbscript.dll <br/>2013-05-01 13:38 . 2013-05-01 13:38 27648 ----a-w- c:\windows\system32\licmgr10.dll <br/>2013-05-01 13:38 . 2013-05-01 13:38 247296 ----a-w- c:\windows\system32\webcheck.dll <br/>2013-05-01 13:38 . 2013-05-01 13:38 173568 ----a-w- c:\windows\system32\ieUnatt.exe <br/>2013-05-01 13:38 . 2013-05-01 13:38 167424 ----a-w- c:\windows\system32\iexpress.exe <br/>2013-05-01 13:38 . 2013-05-01 13:38 144896 ----a-w- c:\windows\system32\wextract.exe <br/>2013-05-01 13:38 . 2013-05-01 13:38 102912 ----a-w- c:\windows\system32\inseng.dll <br/>2013-05-01 13:38 . 2013-05-01 13:38 92160 ----a-w- c:\windows\system32\SetIEInstalledDate.exe <br/>2013-05-01 13:38 . 2013-05-01 13:38 77312 ----a-w- c:\windows\system32\tdc.ocx <br/>2013-05-01 13:38 . 2013-05-01 13:38 62976 ----a-w- c:\windows\system32\pngfilt.dll <br/>2013-05-01 13:38 . 2013-05-01 13:38 52224 ----a-w- c:\windows\system32\msfeedsbs.dll <br/>2013-05-01 13:38 . 2013-05-01 13:38 51200 ----a-w- c:\windows\system32\imgutil.dll <br/>2013-05-01 13:38 . 2013-05-01 13:38 48640 ----a-w- c:\windows\system32\mshtmler.dll <br/>2013-05-01 13:38 . 2013-05-01 13:38 149504 ----a-w- c:\windows\system32\occache.dll <br/>2013-05-01 13:38 . 2013-05-01 13:38 13824 ----a-w- c:\windows\system32\mshta.exe <br/>2013-05-01 13:38 . 2013-05-01 13:38 136192 ----a-w- c:\windows\system32\iepeers.dll <br/>2013-05-01 13:38 . 2013-05-01 13:38 135680 ----a-w- c:\windows\system32\IEAdvpack.dll <br/>2013-05-01 13:38 . 2013-05-01 13:38 12800 ----a-w- c:\windows\system32\msfeedssync.exe <br/>2013-04-25 16:11 . 2013-04-25 16:11 23112 ----a-w- c:\windows\system32\drivers\hitmanpro35.sys <br/>2013-04-13 05:49 . 2013-05-16 10:17 135168 ----a-w- c:\windows\apppatch\AppPatch64\AcXtrnal.dll <br/>2013-04-13 05:49 . 2013-05-16 10:17 350208 ----a-w- c:\windows\apppatch\AppPatch64\AcLayers.dll <br/>2013-04-13 05:49 . 2013-05-16 10:17 308736 ----a-w- c:\windows\apppatch\AppPatch64\AcGenral.dll <br/>2013-04-13 05:49 . 2013-05-16 10:17 111104 ----a-w- c:\windows\apppatch\AppPatch64\acspecfc.dll <br/>2013-04-13 04:45 . 2013-05-16 10:17 474624 ----a-w- c:\windows\apppatch\AcSpecfc.dll <br/>2013-04-13 04:45 . 2013-05-16 10:17 2176512 ----a-w- c:\windows\apppatch\AcGenral.dll <br/>2013-04-12 14:45 . 2013-04-24 13:02 1656680 ----a-w- c:\windows\system32\drivers\ntfs.sys <br/>2013-03-19 06:04 . 2013-04-11 09:27 5550424 ----a-w- c:\windows\system32\ntoskrnl.exe <br/>2013-03-19 05:46 . 2013-04-11 09:27 43520 ----a-w- c:\windows\system32\csrsrv.dll <br/>2013-03-19 05:04 . 2013-04-11 09:27 3968856 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe <br/>2013-03-19 05:04 . 2013-04-11 09:27 3913560 ----a-w- c:\windows\SysWow64\ntoskrnl.exe <br/>2013-03-19 04:47 . 2013-04-11 09:27 6656 ----a-w- c:\windows\SysWow64\apisetschema.dll <br/>2013-03-19 03:06 . 2013-04-11 09:27 112640 ----a-w- c:\windows\system32\smss.exe <br/>. <br/>. <br/>((((((((((((((((((((((((((((((((((((( Reg Opstartpunten ))))))))))))))))))))))))))))))))))))))))))))))))))) <br/>. <br/>. <br/>*Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond <br/>REGEDIT4 <br/>. <br/>[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] <br/>@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" <br/>[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] <br/>2012-06-30 04:19 94208 ----a-w- c:\users\Robin\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll <br/>. <br/>[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] <br/>@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" <br/>[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] <br/>2012-06-30 04:19 94208 ----a-w- c:\users\Robin\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll <br/>. <br/>[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] <br/>@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" <br/>[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] <br/>2012-06-30 04:19 94208 ----a-w- c:\users\Robin\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll <br/>. <br/>[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] <br/>"ConsentPromptBehaviorAdmin"= 5 (0x5) <br/>"ConsentPromptBehaviorUser"= 3 (0x3) <br/>"EnableUIADesktopToggle"= 0 (0x0) <br/>. <br/>[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer] <br/>"NoActiveDesktop"= 1 (0x1) <br/>"NoActiveDesktopChanges"= 1 (0x1) <br/>"ForceActiveDesktopOn"= 0 (0x0) <br/>. <br/>[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon] <br/>"Userinit"="c:\windows\system32\userinit.exe" <br/>. <br/>[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] <br/>"LoadAppInit_DLLs"=1 (0x1) <br/>. <br/>[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] <br/>BootExecute REG_MULTI_SZ autocheck autochk *\0bootdelete\0c:\progra~2\AVG\AVG10\avgchsva.exe /sync\0c:\progra~2\AVG\AVG10\avgrsa.exe /sync /restart <br/>. <br/>R2 AVGIDSAgent;AVGIDSAgent;c:\program files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe;c:\program files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe [x] <br/>R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x] <br/>R2 ezSharedSvc;Easybits Shared Services for Windows;c:\windows\system32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x] <br/>R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x] <br/>R3 Apowersoft_AudioDevice;Apowersoft_AudioDevice;c:\windows\system32\drivers\Apowersoft_AudioDevice.sys;c:\windows\SYSNATIVE\drivers\Apowersoft_AudioDevice.sys [x] <br/>R3 ew_hwusbdev;Huawei MobileBroadband USB PNP Device;c:\windows\system32\DRIVERS\ew_hwusbdev.sys;c:\windows\SYSNATIVE\DRIVERS\ew_hwusbdev.sys [x] <br/>R3 huawei_cdcacm;huawei_cdcacm;c:\windows\system32\DRIVERS\ew_jucdcacm.sys;c:\windows\SYSNATIVE\DRIVERS\ew_jucdcacm.sys [x] <br/>R3 huawei_enumerator;huawei_enumerator;c:\windows\system32\DRIVERS\ew_jubusenum.sys;c:\windows\SYSNATIVE\DRIVERS\ew_jubusenum.sys [x] <br/>R3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;c:\windows\system32\DRIVERS\netw5v64.sys;c:\windows\SYSNATIVE\DRIVERS\netw5v64.sys [x] <br/>R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys;c:\windows\SYSNATIVE\Drivers\RtsUStor.sys [x] <br/>R3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL6.SYS;c:\windows\SYSNATIVE\DRIVERS\VSTAZL6.SYS [x] <br/>R3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV6.SYS;c:\windows\SYSNATIVE\DRIVERS\VSTDPV6.SYS [x] <br/>R3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT6.SYS;c:\windows\SYSNATIVE\DRIVERS\VSTCNXT6.SYS [x] <br/>R3 SwitchBoard;SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [x] <br/>R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x] <br/>R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x] <br/>R3 WatAdminSvc;Windows Activation Technologies-service;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x] <br/>R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys;c:\windows\SYSNATIVE\DRIVERS\yk62x64.sys [x] <br/>S0 AVGIDSEH;AVGIDSEH;c:\windows\system32\DRIVERS\AVGIDSEH.Sys;c:\windows\SYSNATIVE\DRIVERS\AVGIDSEH.Sys [x] <br/>S0 Avgrkx64;AVG Anti-Rootkit Driver;c:\windows\system32\DRIVERS\avgrkx64.sys;c:\windows\SYSNATIVE\DRIVERS\avgrkx64.sys [x] <br/>S0 MxEFUF;Matrox Extio Upper Function Filter;c:\windows\system32\DRIVERS\MxEFUF64.sys;c:\windows\SYSNATIVE\DRIVERS\MxEFUF64.sys [x] <br/>S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys;c:\windows\SYSNATIVE\Drivers\PxHlpa64.sys [x] <br/>S1 Avgldx64;AVG AVI Loader Driver;c:\windows\system32\DRIVERS\avgldx64.sys;c:\windows\SYSNATIVE\DRIVERS\avgldx64.sys [x] <br/>S1 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\DRIVERS\avgmfx64.sys;c:\windows\SYSNATIVE\DRIVERS\avgmfx64.sys [x] <br/>S1 Avgtdia;AVG TDI Driver;c:\windows\system32\DRIVERS\avgtdia.sys;c:\windows\SYSNATIVE\DRIVERS\avgtdia.sys [x] <br/>S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x] <br/>S2 AERTFilters;Andrea RT Filters Service;c:\program files\Realtek\Audio\HDA\AERTSr64.exe;c:\program files\Realtek\Audio\HDA\AERTSr64.exe [x] <br/>S2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x] <br/>S2 avgwd;AVG WatchDog;c:\program files (x86)\AVG\AVG10\avgwdsvc.exe;c:\program files (x86)\AVG\AVG10\avgwdsvc.exe [x] <br/>S2 KPN Back-up Online SC;KPN Back-up Online SC;c:\program files\KPN Back-up Online\BackupSC.exe;c:\program files\KPN Back-up Online\BackupSC.exe [x] <br/>S3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\DRIVERS\AVGIDSDriver.Sys;c:\windows\SYSNATIVE\DRIVERS\AVGIDSDriver.Sys [x] <br/>S3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\DRIVERS\AVGIDSFilter.Sys;c:\windows\SYSNATIVE\DRIVERS\AVGIDSFilter.Sys [x] <br/>S3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI;c:\windows\system32\drivers\IntcHdmi.sys;c:\windows\SYSNATIVE\drivers\IntcHdmi.sys [x] <br/>S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x] <br/>S3 rtl8192se;Realtek Wireless LAN 802.11n PCI-E NIC NT Driver;c:\windows\system32\DRIVERS\rtl8192se.sys;c:\windows\SYSNATIVE\DRIVERS\rtl8192se.sys [x] <br/>S3 stdriver;Sound tap driver Upper Class Filter Driver v2.0.0.0;c:\windows\system32\DRIVERS\stdriver64.sys;c:\windows\SYSNATIVE\DRIVERS\stdriver64.sys [x] <br/>. <br/>. <br/>[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost] <br/>Akamai REG_MULTI_SZ Akamai <br/>. <br/>HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs <br/>ezSharedSvc <br/>. <br/>Inhoud van de 'Gedeelde Taken' map <br/>. <br/>2013-06-05 c:\windows\Tasks\Adobe Flash Player Updater.job <br/>- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-07-24 18:18] <br/>. <br/>2013-06-05 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job <br/>- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-01-16 15:22] <br/>. <br/>2013-06-05 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job <br/>- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-01-16 15:22] <br/>. <br/>. <br/>--------- X64 Entries ----------- <br/>. <br/>. <br/>[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] <br/>@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" <br/>[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] <br/>2012-06-30 04:19 97792 ----a-w- c:\users\Robin\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll <br/>. <br/>[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] <br/>@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" <br/>[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] <br/>2012-06-30 04:19 97792 ----a-w- c:\users\Robin\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll <br/>. <br/>[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] <br/>@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" <br/>[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] <br/>2012-06-30 04:19 97792 ----a-w- c:\users\Robin\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll <br/>. <br/>[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4] <br/>@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}" <br/>[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}] <br/>2012-06-30 04:19 97792 ----a-w- c:\users\Robin\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll <br/>. <br/>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] <br/>"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtkNGUI64.exe" [2010-01-29 6160928] <br/>"RtkOSD"="c:\program files (x86)\Realtek\Audio\OSD\RtVOsd64.exe" [2010-01-13 995840] <br/>. <br/>------- Bijkomende Scan ------- <br/>. <br/>uStart Page = hxxp://websearch.simplespeedy.info/ <br/>uLocal Page = c:\windows\system32\blank.htm <br/>mLocal Page = c:\windows\SysWOW64\blank.htm <br/>uInternet Settings,ProxyOverride = 127.0.0.1:9421 <br/>IE: E&xporteren naar Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000 <br/>FF - ProfilePath - c:\users\Robin\AppData\Roaming\Mozilla\Firefox\Profiles\1sryxlu5.default\ <br/>FF - prefs.js: browser.startup.homepage - hxxp://www.hotmail.com/ <br/>FF - user.js: extensions.funmoods.hmpg - false <br/>FF - user.js: extensions.funmoods.hmpgUrl - hxxp://searchfunmoods.com/?f=1&a=fmtgl&chnl=fmtgl&cd=2XzuyEtN2Y1L1Qzu0CzztD0A0Azy0D0E0CzyyCtB0EtA0B0EtN0D0Tzu0CtAtDtBtN1L2XzutBtFtBtFtDtFtAyEyE&cr=686163073 <br/>FF - user.js: extensions.funmoods.dfltSrch - true <br/>FF - user.js: extensions.funmoods.srchPrvdr - Search <br/>FF - user.js: extensions.funmoods.dnsErr - true <br/>FF - user.js: extensions.funmoods_i.newTab - false <br/>FF - user.js: extensions.funmoods.newTabUrl - hxxp://searchfunmoods.com/?f=2&a=fmtgl&chnl=fmtgl&cd=2XzuyEtN2Y1L1Qzu0CzztD0A0Azy0D0E0CzyyCtB0EtA0B0EtN0D0Tzu0CtAtDtBtN1L2XzutBtFtBtFtDtFtAyEyE&cr=686163073 <br/>FF - user.js: extensions.funmoods.tlbrSrchUrl - hxxp://searchfunmoods.com/?f=3&a=fmtgl&chnl=fmtgl&cd=2XzuyEtN2Y1L1Qzu0CzztD0A0Azy0D0E0CzyyCtB0EtA0B0EtN0D0Tzu0CtAtDtBtN1L2XzutBtFtBtFtDtFtAyEyE&cr=686163073&q= <br/>FF - user.js: extensions.funmoods.id - C80AA9DEC962E3BE <br/>FF - user.js: extensions.funmoods.instlDay - 15641 <br/>FF - user.js: extensions.funmoods.vrsn - 1.5.23.22 <br/>FF - user.js: extensions.funmoods.vrsni - 1.5.23.22 <br/>FF - user.js: extensions.funmoods_i.vrsnTs - 1.5.23.2216:48 <br/>FF - user.js: extensions.funmoods.prtnrId - funmoods <br/>FF - user.js: extensions.funmoods.prdct - funmoods <br/>FF - user.js: extensions.funmoods.aflt - fmtgl <br/>FF - user.js: extensions.funmoods_i.smplGrp - none <br/>FF - user.js: extensions.funmoods.tlbrId - base <br/>FF - user.js: extensions.funmoods.instlRef - fmtgl <br/>FF - user.js: extensions.funmoods.dfltLng - <br/>FF - user.js: extensions.funmoods.excTlbr - true <br/>FF - user.js: extensions.funmoods.autoRvrt - false <br/>FF - user.js: extensions.funmoods.envrmnt - production <br/>FF - user.js: extensions.funmoods.isdcmntcmplt - true <br/>FF - user.js: extensions.funmoods.mntrvrsn - 1.3.0 <br/>user_pref('extensions.autoDisableScopes', 0);user_pref('security.csp.enable', false);user_pref('security.OCSP.enabled', 0);user_pref('extensions.blocklist.enabled', false); <br/>. <br/>- - - - ORPHANS VERWIJDERD - - - - <br/>. <br/>HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe <br/>AddRemove-WildTangentGameProvider-hp-genres - c:\program files (x86)\HP Games\Game Explorer Categories - genres\Uninstall.exe <br/>AddRemove-WildTangentGDF-hp-clubpenguin - c:\program files (x86)\HP Games\Web Link - Club Penguin\Uninstall.exe <br/>AddRemove-WildTangentGDF-hp-darkorbit - c:\program files (x86)\HP Games\Web Link - Dark Orbit\Uninstall.exe <br/>AddRemove-WildTangentGDF-hp-runescape - c:\program files (x86)\HP Games\Web Link - RuneScape HD\Uninstall.exe <br/>AddRemove-WildTangentGDF-hp-seafight - c:\program files (x86)\HP Games\Web Link - Seafight\Uninstall.exe <br/>AddRemove-WildTangentGDF-hp-worldofwarcraft - c:\program files (x86)\HP Games\Web Link - World of Warcraft\Uninstall.exe <br/>. <br/>. <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Akamai] <br/>"ServiceDll"="c:\program files (x86)\common files\akamai/netsession_win_ca0e279.dll" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Data] <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking] <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET CLR Networking 4.0.0.0] <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET Data Provider for Oracle] <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NET Data Provider for SqlServer] <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\.NETFramework] <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\1394ohci] <br/>"ImagePath"="\SystemRoot\system32\drivers\1394ohci.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ACPI] <br/>"ImagePath"="system32\drivers\ACPI.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AcpiPmi] <br/>"ImagePath"="\SystemRoot\system32\drivers\acpipmi.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AdobeFlashPlayerUpdateSvc] <br/>"ImagePath"="c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\adp94xx] <br/>"ImagePath"="\SystemRoot\system32\DRIVERS\adp94xx.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\adpahci] <br/>"ImagePath"="\SystemRoot\system32\DRIVERS\adpahci.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\adpu320] <br/>"ImagePath"="\SystemRoot\system32\DRIVERS\adpu320.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\adsi] <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AeLookupSvc] <br/>"ServiceDll"="%SystemRoot%\System32\aelupsvc.dll" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AERTFilters] <br/>"ImagePath"="c:\program files\Realtek\Audio\HDA\AERTSr64.exe" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AFD] <br/>"ImagePath"="\SystemRoot\system32\drivers\afd.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\agp440] <br/>"ImagePath"="\SystemRoot\system32\drivers\agp440.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Akamai] <br/>"ServiceDll"="c:\program files (x86)\common files\akamai/netsession_win_ca0e279.dll" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ALG] <br/>"ImagePath"="%SystemRoot%\System32\alg.exe" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\aliide] <br/>"ImagePath"="\SystemRoot\system32\drivers\aliide.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\amdide] <br/>"ImagePath"="\SystemRoot\system32\drivers\amdide.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AmdK8] <br/>"ImagePath"="\SystemRoot\system32\DRIVERS\amdk8.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AmdPPM] <br/>"ImagePath"="\SystemRoot\system32\DRIVERS\amdppm.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\amdsata] <br/>"ImagePath"="\SystemRoot\system32\drivers\amdsata.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\amdsbs] <br/>"ImagePath"="\SystemRoot\system32\DRIVERS\amdsbs.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\amdxata] <br/>"ImagePath"="system32\drivers\amdxata.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Apowersoft_AudioDevice] <br/>"ImagePath"="system32\drivers\Apowersoft_AudioDevice.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppID] <br/>"ImagePath"="\SystemRoot\system32\drivers\appid.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppIDSvc] <br/>"ServiceDll"="%SystemRoot%\System32\appidsvc.dll" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Appinfo] <br/>"ServiceDll"="%SystemRoot%\System32\appinfo.dll" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Apple Mobile Device] <br/>"ImagePath"="\"c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe\"" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppMgmt] <br/>"ServiceDll"="%SystemRoot%\System32\appmgmts.dll" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\arc] <br/>"ImagePath"="\SystemRoot\system32\DRIVERS\arc.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\arcsas] <br/>"ImagePath"="\SystemRoot\system32\DRIVERS\arcsas.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AsyncMac] <br/>"ImagePath"="system32\DRIVERS\asyncmac.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\atapi] <br/>"ImagePath"="system32\drivers\atapi.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AudioEndpointBuilder] <br/>"ServiceDll"="%SystemRoot%\System32\Audiosrv.dll" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AudioSrv] <br/>"ServiceDll"="%SystemRoot%\System32\Audiosrv.dll" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Avg] <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AVGIDSAgent] <br/>"ImagePath"="\"c:\program files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe\"" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AVGIDSDriver] <br/>"ImagePath"="system32\DRIVERS\AVGIDSDriver.Sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AVGIDSEH] <br/>"ImagePath"="system32\DRIVERS\AVGIDSEH.Sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AVGIDSFilter] <br/>"ImagePath"="system32\DRIVERS\AVGIDSFilter.Sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Avgldx64] <br/>"ImagePath"="system32\DRIVERS\avgldx64.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Avgmfx64] <br/>"ImagePath"="system32\DRIVERS\avgmfx64.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Avgrkx64] <br/>"ImagePath"="system32\DRIVERS\avgrkx64.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Avgtdia] <br/>"ImagePath"="system32\DRIVERS\avgtdia.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\avgwd] <br/>"ImagePath"="\"c:\program files (x86)\AVG\AVG10\avgwdsvc.exe\"" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AxInstSV] <br/>"ServiceDll"="%SystemRoot%\System32\AxInstSV.dll" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\b06bdrv] <br/>"ImagePath"="\SystemRoot\system32\DRIVERS\bxvbda.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\b57nd60a] <br/>"ImagePath"="system32\DRIVERS\b57nd60a.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BattC] <br/>"MofImagePath"="system32\drivers\battc.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BDESVC] <br/>"ServiceDll"="%SystemRoot%\System32\bdesvc.dll" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Beep] <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BFE] <br/>"ServiceDll"="%SystemRoot%\System32\bfe.dll" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BHDrvx64] <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS] <br/>"ServiceDll"="%systemroot%\system32\qmgr.dll" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\blbdrive] <br/>"ImagePath"="\SystemRoot\system32\DRIVERS\blbdrive.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Bonjour Service] <br/>"ImagePath"="\"c:\program files\Bonjour\mDNSResponder.exe\"" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\bowser] <br/>"ImagePath"="system32\DRIVERS\bowser.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BrFiltLo] <br/>"ImagePath"="\SystemRoot\system32\DRIVERS\BrFiltLo.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BrFiltUp] <br/>"ImagePath"="\SystemRoot\system32\DRIVERS\BrFiltUp.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BridgeMP] <br/>"ImagePath"="system32\DRIVERS\bridge.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Browser] <br/>"ServiceDll"="%SystemRoot%\System32\browser.dll" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Brserid] <br/>"ImagePath"="\SystemRoot\System32\Drivers\Brserid.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BrSerWdm] <br/>"ImagePath"="\SystemRoot\System32\Drivers\BrSerWdm.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BrUsbMdm] <br/>"ImagePath"="\SystemRoot\System32\Drivers\BrUsbMdm.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BrUsbSer] <br/>"ImagePath"="\SystemRoot\System32\Drivers\BrUsbSer.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BTHMODEM] <br/>"ImagePath"="\SystemRoot\system32\DRIVERS\bthmodem.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BTHPORT] <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\bthserv] <br/>"ServiceDll"="%SystemRoot%\system32\bthserv.dll" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\catchme] <br/>"ImagePath"="\??\c:\combofix\catchme.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\cdfs] <br/>"ImagePath"="system32\DRIVERS\cdfs.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\cdrom] <br/>"ImagePath"="system32\DRIVERS\cdrom.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CertPropSvc] <br/>"ServiceDll"="%SystemRoot%\System32\certprop.dll" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\circlass] <br/>"ImagePath"="\SystemRoot\system32\DRIVERS\circlass.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CLFS] <br/>"ImagePath"="System32\CLFS.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v2.0.50727_32] <br/>"ImagePath"="%systemroot%\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v2.0.50727_64] <br/>"ImagePath"="%systemroot%\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_32] <br/>"ImagePath"="c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_64] <br/>"ImagePath"="c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CmBatt] <br/>"ImagePath"="\SystemRoot\system32\DRIVERS\CmBatt.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\cmdide] <br/>"ImagePath"="\SystemRoot\system32\drivers\cmdide.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CNG] <br/>"ImagePath"="System32\Drivers\cng.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Compbatt] <br/>"ImagePath"="system32\DRIVERS\compbatt.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CompositeBus] <br/>"ImagePath"="\SystemRoot\system32\drivers\CompositeBus.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\COMSysApp] <br/>"ImagePath"="%SystemRoot%\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235}" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\crcdisk] <br/>"ImagePath"="\SystemRoot\system32\DRIVERS\crcdisk.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\crypt32] <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\CryptSvc] <br/>"ServiceDll"="%SystemRoot%\system32\cryptsvc.dll" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DCLocator] <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DcomLaunch] <br/>"ServiceDll"="%SystemRoot%\system32\rpcss.dll" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\defragsvc] <br/>"ServiceDll"="%Systemroot%\System32\defragsvc.dll" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DfsC] <br/>"ImagePath"="System32\Drivers\dfsc.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dhcp] <br/>"ServiceDll"="%SystemRoot%\system32\dhcpcore.dll" <br/>-- <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\discache] <br/>"ImagePath"="System32\drivers\discache.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Disk] <br/>"ImagePath"="system32\DRIVERS\disk.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Dnscache] <br/>"ServiceDll"="%SystemRoot%\System32\dnsrslvr.dll" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\dot3svc] <br/>"ServiceDll"="%SystemRoot%\System32\dot3svc.dll" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DPS] <br/>"ServiceDll"="%SystemRoot%\system32\dps.dll" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\drmkaud] <br/>"ImagePath"="system32\drivers\drmkaud.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\dtsoftbus01] <br/>"ImagePath"="system32\DRIVERS\dtsoftbus01.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DXGKrnl] <br/>"ImagePath"="\SystemRoot\System32\drivers\dxgkrnl.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EapHost] <br/>"ServiceDll"="%SystemRoot%\System32\eapsvc.dll" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ebdrv] <br/>"ImagePath"="\SystemRoot\system32\DRIVERS\evbda.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EFS] <br/>"ImagePath"="%SystemRoot%\System32\lsass.exe" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ehRecvr] <br/>"ImagePath"="%systemroot%\ehome\ehRecvr.exe" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ehSched] <br/>"ImagePath"="%systemroot%\ehome\ehsched.exe" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\elxstor] <br/>"ImagePath"="\SystemRoot\system32\DRIVERS\elxstor.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ErrDev] <br/>"ImagePath"="\SystemRoot\system32\drivers\errdev.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ESENT] <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\eventlog] <br/>"ServiceDll"="%SystemRoot%\System32\wevtsvc.dll" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EventSystem] <br/>"ServiceDll"="%systemroot%\system32\es.dll" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ewusbnet] <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ew_hwusbdev] <br/>"ImagePath"="system32\DRIVERS\ew_hwusbdev.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\exfat] <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ezntsvc] <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ezSharedSvc] <br/>"ServiceDll"="c:\windows\System32\ezsvc7.dll" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\fastfat] <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Fax] <br/>"ImagePath"="%systemroot%\system32\fxssvc.exe" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\fdc] <br/>"ImagePath"="\SystemRoot\system32\DRIVERS\fdc.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\fdPHost] <br/>"ServiceDll"="%SystemRoot%\system32\fdPHost.dll" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FDResPub] <br/>"ServiceDll"="%SystemRoot%\system32\fdrespub.dll" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FileInfo] <br/>"ImagePath"="system32\drivers\fileinfo.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Filetrace] <br/>"ImagePath"="system32\drivers\filetrace.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\flpydisk] <br/>"ImagePath"="\SystemRoot\system32\DRIVERS\flpydisk.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FltMgr] <br/>"ImagePath"="system32\drivers\fltmgr.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache] <br/>"ServiceDll"="%SystemRoot%\system32\FntCache.dll" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache3.0.0.0] <br/>"ImagePath"="%systemroot%\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FsDepends] <br/>"ImagePath"="System32\drivers\FsDepends.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Fs_Rec] <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\fvevol] <br/>"ImagePath"="System32\DRIVERS\fvevol.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\gagp30kx] <br/>"ImagePath"="\SystemRoot\system32\DRIVERS\gagp30kx.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\GEARAspiWDM] <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\gpsvc] <br/>"ServiceDll"="%SystemRoot%\System32\gpsvc.dll" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\gupdate] <br/>"ImagePath"="\"c:\program files (x86)\Google\Update\GoogleUpdate.exe\" /svc" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\gupdatem] <br/>"ImagePath"="\"c:\program files (x86)\Google\Update\GoogleUpdate.exe\" /medsvc" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hcw85cir] <br/>"ImagePath"="\SystemRoot\system32\drivers\hcw85cir.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HdAudAddService] <br/>"ImagePath"="\SystemRoot\system32\drivers\HdAudio.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HDAudBus] <br/>"ImagePath"="\SystemRoot\system32\drivers\HDAudBus.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HidBatt] <br/>"ImagePath"="\SystemRoot\system32\DRIVERS\HidBatt.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HidBth] <br/>"ImagePath"="\SystemRoot\system32\DRIVERS\hidbth.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HidIr] <br/>"ImagePath"="\SystemRoot\system32\DRIVERS\hidir.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hidserv] <br/>"ServiceDll"="%SystemRoot%\System32\hidserv.dll" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HidUsb] <br/>"ImagePath"="system32\DRIVERS\hidusb.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hkmsvc] <br/>"ServiceDLL"="%SystemRoot%\system32\kmsvc.dll" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupListener] <br/>"ServiceDll"="%SystemRoot%\system32\ListSvc.dll" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupProvider] <br/>"ServiceDll"="%SystemRoot%\system32\provsvc.dll" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HP Health Check Service] <br/>"ImagePath"="\"c:\program files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe\"" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hpqwmiex] <br/>"ImagePath"="\"c:\program files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe\"" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HpSAMD] <br/>"ImagePath"="\SystemRoot\system32\drivers\HpSAMD.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HTTP] <br/>"ImagePath"="system32\drivers\HTTP.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\huawei_cdcacm] <br/>"ImagePath"="system32\DRIVERS\ew_jucdcacm.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\huawei_enumerator] <br/>"ImagePath"="system32\DRIVERS\ew_jubusenum.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hwcdcmdm0] <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hwdatacard] <br/>"ImagePath"="system32\DRIVERS\ewusbmdm.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hwpolicy] <br/>"ImagePath"="System32\drivers\hwpolicy.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hwusbapp] <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hwusbdev] <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hwusbser] <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\i8042prt] <br/>"ImagePath"="\SystemRoot\system32\drivers\i8042prt.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ialm] <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\iaStor] <br/>"ImagePath"="system32\DRIVERS\iaStor.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\iaStorV] <br/>"ImagePath"="\SystemRoot\system32\drivers\iaStorV.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\idsvc] <br/>"ImagePath"="\"%systemroot%\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe\"" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\IDSVia64] <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\igfx] <br/>"ImagePath"="system32\DRIVERS\igdkmd64.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\iirsp] <br/>"ImagePath"="\SystemRoot\system32\DRIVERS\iirsp.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\IKEEXT] <br/>"ServiceDll"="%SystemRoot%\System32\ikeext.dll" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\inetaccs] <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\IntcAzAudAddService] <br/>"ImagePath"="system32\drivers\RTKVHD64.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\IntcHdmiAddService] <br/>"ImagePath"="system32\drivers\IntcHdmi.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\intelide] <br/>"ImagePath"="\SystemRoot\system32\drivers\intelide.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\intelppm] <br/>"ImagePath"="system32\DRIVERS\intelppm.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\IPBusEnum] <br/>"ServiceDll"="%SystemRoot%\system32\ipbusenum.dll" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\IpFilterDriver] <br/>"ImagePath"="system32\DRIVERS\ipfltdrv.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\iphlpsvc] <br/>"ServiceDll"="%SystemRoot%\System32\iphlpsvc.dll" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\IPMIDRV] <br/>"ImagePath"="\SystemRoot\system32\drivers\IPMIDrv.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\IPNAT] <br/>"ImagePath"="System32\drivers\ipnat.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\iPod Service] <br/>"ImagePath"="\"c:\program files\iPod\bin\iPodService.exe\"" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\IRENUM] <br/>"ImagePath"="system32\drivers\irenum.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\isapnp] <br/>"ImagePath"="\SystemRoot\system32\drivers\isapnp.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\iScsiPrt] <br/>"ImagePath"="\SystemRoot\system32\drivers\msiscsi.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\kbdclass] <br/>"ImagePath"="system32\DRIVERS\kbdclass.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\kbdhid] <br/>"ImagePath"="system32\DRIVERS\kbdhid.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KeyIso] <br/>"ImagePath"="%SystemRoot%\system32\lsass.exe" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KPN Back-up Online SC] <br/>"ImagePath"="\"c:\program files\KPN Back-up Online\BackupSC.exe\"" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KSecDD] <br/>"ImagePath"="System32\Drivers\ksecdd.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KSecPkg] <br/>"ImagePath"="System32\Drivers\ksecpkg.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ksthunk] <br/>"ImagePath"="\SystemRoot\system32\drivers\ksthunk.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KtmRm] <br/>"ServiceDll"="%systemroot%\system32\msdtckrm.dll" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\LanmanServer] <br/>"ServiceDll"="%SystemRoot%\System32\srvsvc.dll" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\LanmanWorkstation] <br/>"ServiceDll"="%SystemRoot%\System32\wkssvc.dll" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ldap] <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lltdio] <br/>"ImagePath"="system32\DRIVERS\lltdio.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lltdsvc] <br/>"ServiceDll"="%SystemRoot%\System32\lltdsvc.dll" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lmhosts] <br/>"ServiceDll"="%SystemRoot%\System32\lmhsvc.dll" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Lsa] <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\LSI_FC] <br/>"ImagePath"="\SystemRoot\system32\DRIVERS\lsi_fc.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\LSI_SAS] <br/>"ImagePath"="\SystemRoot\system32\DRIVERS\lsi_sas.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\LSI_SAS2] <br/>"ImagePath"="\SystemRoot\system32\DRIVERS\lsi_sas2.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\LSI_SCSI] <br/>"ImagePath"="\SystemRoot\system32\DRIVERS\lsi_scsi.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\luafv] <br/>"ImagePath"="\SystemRoot\system32\drivers\luafv.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Mcx2Svc] <br/>"ServiceDll"="%SystemRoot%\system32\Mcx2Svc.dll" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\megasas] <br/>"ImagePath"="\SystemRoot\system32\DRIVERS\megasas.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MegaSR] <br/>"ImagePath"="\SystemRoot\system32\DRIVERS\MegaSR.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MMCSS] <br/>"ServiceDll"="%SystemRoot%\system32\mmcss.dll" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Modem] <br/>"ImagePath"="system32\drivers\modem.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\monitor] <br/>"ImagePath"="system32\DRIVERS\monitor.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\mouclass] <br/>"ImagePath"="system32\DRIVERS\mouclass.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\mouhid] <br/>"ImagePath"="system32\DRIVERS\mouhid.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\mountmgr] <br/>"ImagePath"="System32\drivers\mountmgr.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\mpio] <br/>"ImagePath"="\SystemRoot\system32\drivers\mpio.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\mpsdrv] <br/>"ImagePath"="System32\drivers\mpsdrv.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MpsSvc] <br/>"ServiceDll"="%SystemRoot%\system32\mpssvc.dll" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MRxDAV] <br/>"ImagePath"="\SystemRoot\system32\drivers\mrxdav.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\mrxsmb] <br/>"ImagePath"="system32\DRIVERS\mrxsmb.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\mrxsmb10] <br/>"ImagePath"="system32\DRIVERS\mrxsmb10.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\mrxsmb20] <br/>"ImagePath"="system32\DRIVERS\mrxsmb20.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\msahci] <br/>"ImagePath"="system32\drivers\msahci.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\msdsm] <br/>"ImagePath"="\SystemRoot\system32\drivers\msdsm.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSDTC] <br/>"ImagePath"="%SystemRoot%\System32\msdtc.exe" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSDTC Bridge 3.0.0.0] <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSDTC Bridge 4.0.0.0] <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Msfs] <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\mshidkmdf] <br/>"ImagePath"="\SystemRoot\System32\drivers\mshidkmdf.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\msisadrv] <br/>"ImagePath"="system32\drivers\msisadrv.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSiSCSI] <br/>"ServiceDll"="%systemroot%\system32\iscsiexe.dll" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\msiserver] <br/>"ImagePath"="%systemroot%\system32\msiexec.exe /V" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSKSSRV] <br/>"ImagePath"="system32\drivers\MSKSSRV.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSPCLOCK] <br/>"ImagePath"="system32\drivers\MSPCLOCK.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSPQM] <br/>"ImagePath"="system32\drivers\MSPQM.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MsRPC] <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSSCNTRS] <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\mssmbios] <br/>"ImagePath"="\SystemRoot\system32\drivers\mssmbios.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSTEE] <br/>"ImagePath"="system32\drivers\MSTEE.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MTConfig] <br/>"ImagePath"="\SystemRoot\system32\DRIVERS\MTConfig.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Mup] <br/>"ImagePath"="System32\Drivers\mup.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MxEFUF] <br/>"ImagePath"="system32\DRIVERS\MxEFUF64.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent] <br/>"ServiceDLL"="%SystemRoot%\system32\qagentRT.dll" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NativeWifiP] <br/>"ImagePath"="system32\DRIVERS\nwifi.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NDIS] <br/>"ImagePath"="system32\drivers\ndis.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NdisCap] <br/>"ImagePath"="system32\DRIVERS\ndiscap.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NdisTapi] <br/>"ImagePath"="system32\DRIVERS\ndistapi.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Ndisuio] <br/>"ImagePath"="system32\DRIVERS\ndisuio.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NdisWan] <br/>"ImagePath"="system32\DRIVERS\ndiswan.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NDProxy] <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBIOS] <br/>"ImagePath"="system32\DRIVERS\netbios.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetBT] <br/>"ImagePath"="System32\DRIVERS\netbt.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Netlogon] <br/>"ImagePath"="%SystemRoot%\system32\lsass.exe" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Netman] <br/>"ServiceDll"="%SystemRoot%\System32\netman.dll" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\netprofm] <br/>"ServiceDll"="%SystemRoot%\System32\netprofm.dll" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpPortSharing] <br/>"ImagePath"="\"%systemroot%\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe\"" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\netw5v64] <br/>"ImagePath"="system32\DRIVERS\netw5v64.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\nfrd960] <br/>"ImagePath"="\SystemRoot\system32\DRIVERS\nfrd960.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NlaSvc] <br/>"ServiceDll"="%SystemRoot%\System32\nlasvc.dll" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NMSAccess] <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NMSAccessU] <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Npfs] <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\nsi] <br/>"ServiceDll"="%systemroot%\system32\nsisvc.dll" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\nsiproxy] <br/>"ImagePath"="system32\drivers\nsiproxy.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NTDS] <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Ntfs] <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Null] <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\nvraid] <br/>"ImagePath"="\SystemRoot\system32\drivers\nvraid.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\nvstor] <br/>"ImagePath"="\SystemRoot\system32\drivers\nvstor.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\nv_agp] <br/>"ImagePath"="\SystemRoot\system32\drivers\nv_agp.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ohci1394] <br/>"ImagePath"="\SystemRoot\system32\drivers\ohci1394.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2pimsvc] <br/>"ServiceDll"="%SystemRoot%\system32\pnrpsvc.dll" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2psvc] <br/>"ServiceDll"="%SystemRoot%\system32\p2psvc.dll" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Parport] <br/>"ImagePath"="\SystemRoot\system32\DRIVERS\parport.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\partmgr] <br/>"ImagePath"="System32\drivers\partmgr.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PcaSvc] <br/>"ServiceDll"="%SystemRoot%\System32\pcasvc.dll" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\pci] <br/>"ImagePath"="system32\drivers\pci.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\pciide] <br/>"ImagePath"="\SystemRoot\system32\drivers\pciide.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\pcmcia] <br/>"ImagePath"="\SystemRoot\system32\DRIVERS\pcmcia.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\pcw] <br/>"ImagePath"="System32\drivers\pcw.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PEAUTH] <br/>"ImagePath"="system32\drivers\peauth.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PerfDisk] <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PerfHost] <br/>"ImagePath"="%SystemRoot%\SysWow64\perfhost.exe" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PerfNet] <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PerfOS] <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PerfProc] <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\pla] <br/>"ServiceDll"="%systemroot%\system32\pla.dll" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PlugPlay] <br/>"ServiceDll"="%SystemRoot%\system32\umpnpmgr.dll" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PNRPAutoReg] <br/>"ServiceDll"="%SystemRoot%\system32\pnrpauto.dll" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PNRPsvc] <br/>"ServiceDll"="%SystemRoot%\system32\pnrpsvc.dll" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PolicyAgent] <br/>"ServiceDll"="%SystemRoot%\System32\ipsecsvc.dll" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PortProxy] <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Power] <br/>"ServiceDll"="%SystemRoot%\system32\umpo.dll" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PptpMiniport] <br/>"ImagePath"="system32\DRIVERS\raspptp.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Processor] <br/>"ImagePath"="\SystemRoot\system32\DRIVERS\processr.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ProfSvc] <br/>"ServiceDll"="%systemroot%\system32\profsvc.dll" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ProtectedStorage] <br/>"ImagePath"="%SystemRoot%\system32\lsass.exe" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Psched] <br/>"ImagePath"="system32\DRIVERS\pacer.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PxHlpa64] <br/>"ImagePath"="System32\Drivers\PxHlpa64.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ql2300] <br/>"ImagePath"="\SystemRoot\system32\DRIVERS\ql2300.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ql40xx] <br/>"ImagePath"="\SystemRoot\system32\DRIVERS\ql40xx.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\QWAVE] <br/>"ServiceDll"="%windir%\system32\qwave.dll" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\QWAVEdrv] <br/>"ImagePath"="\SystemRoot\system32\drivers\qwavedrv.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasAcd] <br/>"ImagePath"="System32\DRIVERS\rasacd.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasAgileVpn] <br/>"ImagePath"="system32\DRIVERS\AgileVpn.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasAuto] <br/>"ServiceDll"="%SystemRoot%\System32\rasauto.dll" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Rasl2tp] <br/>"ImagePath"="system32\DRIVERS\rasl2tp.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasMan] <br/>"ServiceDll"="%SystemRoot%\System32\rasmans.dll" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasPppoe] <br/>"ImagePath"="system32\DRIVERS\raspppoe.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasSstp] <br/>"ImagePath"="system32\DRIVERS\rassstp.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\rdbss] <br/>"ImagePath"="system32\DRIVERS\rdbss.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\rdpbus] <br/>"ImagePath"="\SystemRoot\system32\DRIVERS\rdpbus.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RDPCDD] <br/>"ImagePath"="System32\DRIVERS\RDPCDD.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RDPDD] <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RDPENCDD] <br/>"ImagePath"="system32\drivers\rdpencdd.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RDPNP] <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RDPREFMP] <br/>"ImagePath"="system32\drivers\rdprefmp.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RDPWD] <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\rdyboost] <br/>"ImagePath"="System32\drivers\rdyboost.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteAccess] <br/>"ServiceDLL"="%SystemRoot%\System32\mprdim.dll" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteRegistry] <br/>"ServiceDll"="%SystemRoot%\system32\regsvc.dll" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcEptMapper] <br/>"ServiceDll"="%SystemRoot%\System32\RpcEpMap.dll" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcLocator] <br/>"ImagePath"="%SystemRoot%\system32\locator.exe" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcSs] <br/>"ServiceDll"="%SystemRoot%\system32\rpcss.dll" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\rspndr] <br/>"ImagePath"="system32\DRIVERS\rspndr.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RSUSBSTOR] <br/>"ImagePath"="System32\Drivers\RtsUStor.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RTL8167] <br/>"ImagePath"="system32\DRIVERS\Rt64win7.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\rtl8192se] <br/>"ImagePath"="system32\DRIVERS\rtl8192se.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SamSs] <br/>"ImagePath"="%SystemRoot%\system32\lsass.exe" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sbp2port] <br/>"ImagePath"="\SystemRoot\system32\drivers\sbp2port.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCardSvr] <br/>"ServiceDll"="%SystemRoot%\System32\SCardSvr.dll" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\scfilter] <br/>"ImagePath"="System32\DRIVERS\scfilter.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Schedule] <br/>"ServiceDll"="%systemroot%\system32\schedsvc.dll" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCPolicySvc] <br/>"ServiceDll"="%SystemRoot%\System32\certprop.dll" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sdbus] <br/>"ImagePath"="\SystemRoot\system32\drivers\sdbus.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SDRSVC] <br/>"ServiceDll"="%Systemroot%\System32\SDRSVC.dll" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SeaPort] <br/>"ImagePath"="\"c:\program files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe\"" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Secdrv] <br/>"ImagePath"="\??\c:\windows\system32\drivers\SECDRV.SYS" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\seclogon] <br/>"ServiceDll"="%windir%\system32\seclogon.dll" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SENS] <br/>"ServiceDll"="%SystemRoot%\system32\sens.dll" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SensrSvc] <br/>"ServiceDll"="%SystemRoot%\system32\sensrsvc.dll" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Serenum] <br/>"ImagePath"="\SystemRoot\system32\DRIVERS\serenum.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Serial] <br/>"ImagePath"="\SystemRoot\system32\DRIVERS\serial.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sermouse] <br/>"ImagePath"="\SystemRoot\system32\DRIVERS\sermouse.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ServiceModelEndpoint 3.0.0.0] <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ServiceModelOperation 3.0.0.0] <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ServiceModelService 3.0.0.0] <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SessionEnv] <br/>"ServiceDLL"="%SystemRoot%\system32\sessenv.dll" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sffdisk] <br/>"ImagePath"="\SystemRoot\system32\drivers\sffdisk.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sffp_mmc] <br/>"ImagePath"="\SystemRoot\system32\drivers\sffp_mmc.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sffp_sd] <br/>"ImagePath"="\SystemRoot\system32\drivers\sffp_sd.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sfloppy] <br/>"ImagePath"="\SystemRoot\system32\DRIVERS\sfloppy.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess] <br/>"ServiceDll"="%SystemRoot%\System32\ipnathlp.dll" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ShellHWDetection] <br/>"ServiceDll"="%SystemRoot%\System32\shsvcs.dll" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SiSRaid2] <br/>"ImagePath"="\SystemRoot\system32\DRIVERS\SiSRaid2.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SiSRaid4] <br/>"ImagePath"="\SystemRoot\system32\DRIVERS\sisraid4.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SkypeUpdate] <br/>"ImagePath"="\"c:\program files (x86)\Skype\Updater\Updater.exe\"" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Smb] <br/>"ImagePath"="system32\DRIVERS\smb.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SMSvcHost 3.0.0.0] <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SMSvcHost 4.0.0.0] <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SNMPTRAP] <br/>"ImagePath"="%SystemRoot%\System32\snmptrap.exe" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\spldr] <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Spooler] <br/>"ImagePath"="%SystemRoot%\System32\spoolsv.exe" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppsvc] <br/>"ImagePath"="%SystemRoot%\system32\sppsvc.exe" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppuinotify] <br/>"ServiceDll"="%SystemRoot%\system32\sppuinotify.dll" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\srv] <br/>"ImagePath"="System32\DRIVERS\srv.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\srv2] <br/>"ImagePath"="System32\DRIVERS\srv2.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SrvHsfHDA] <br/>"ImagePath"="system32\DRIVERS\VSTAZL6.SYS" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SrvHsfV92] <br/>"ImagePath"="system32\DRIVERS\VSTDPV6.SYS" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SrvHsfWinac] <br/>"ImagePath"="system32\DRIVERS\VSTCNXT6.SYS" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\srvnet] <br/>"ImagePath"="System32\DRIVERS\srvnet.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SSDPSRV] <br/>"ServiceDll"="%SystemRoot%\System32\ssdpsrv.dll" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SstpSvc] <br/>"ServiceDll"="%SystemRoot%\system32\sstpsvc.dll" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\stdriver] <br/>"ImagePath"="system32\DRIVERS\stdriver64.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\stexstor] <br/>"ImagePath"="\SystemRoot\system32\DRIVERS\stexstor.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\stisvc] <br/>"ServiceDll"="%SystemRoot%\System32\wiaservc.dll" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\swenum] <br/>"ImagePath"="\SystemRoot\system32\drivers\swenum.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SwitchBoard] <br/>"ImagePath"="\"c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe\"" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\swprv] <br/>"ServiceDll"="%Systemroot%\System32\swprv.dll" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SymDS] <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SymEFA] <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SynTP] <br/>"ImagePath"="system32\DRIVERS\SynTP.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SysMain] <br/>"ServiceDll"="%systemroot%\system32\sysmain.dll" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TabletInputService] <br/>"ServiceDll"="%SystemRoot%\System32\TabSvc.dll" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TapiSrv] <br/>"ServiceDll"="%SystemRoot%\System32\tapisrv.dll" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TBS] <br/>"ServiceDll"="%SystemRoot%\System32\tbssvc.dll" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip] <br/>"ImagePath"="System32\drivers\tcpip.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TCPIP6] <br/>"ImagePath"="system32\DRIVERS\tcpip.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TCPIP6TUNNEL] <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\tcpipreg] <br/>"ImagePath"="System32\drivers\tcpipreg.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TCPIPTUNNEL] <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TDPIPE] <br/>"ImagePath"="system32\drivers\tdpipe.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TDTCP] <br/>"ImagePath"="system32\drivers\tdtcp.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\tdx] <br/>"ImagePath"="system32\DRIVERS\tdx.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TermDD] <br/>"ImagePath"="\SystemRoot\system32\drivers\termdd.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TermService] <br/>"ServiceDll"="%SystemRoot%\System32\termsrv.dll" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Themes] <br/>"ServiceDll"="%SystemRoot%\system32\themeservice.dll" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\THREADORDER] <br/>"ServiceDll"="%SystemRoot%\system32\mmcss.dll" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TrkWks] <br/>"ServiceDll"="%SystemRoot%\System32\trkwks.dll" <br/>-- <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TrustedInstaller] <br/>"ImagePath"="%SystemRoot%\servicing\TrustedInstaller.exe" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TSDDD] <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\tssecsrv] <br/>"ImagePath"="System32\DRIVERS\tssecsrv.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TsUsbFlt] <br/>"ImagePath"="system32\drivers\tsusbflt.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\tunnel] <br/>"ImagePath"="system32\DRIVERS\tunnel.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\uagp35] <br/>"ImagePath"="\SystemRoot\system32\DRIVERS\uagp35.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\udfs] <br/>"ImagePath"="system32\DRIVERS\udfs.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\UGatherer] <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\UGTHRSVC] <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\UI0Detect] <br/>"ImagePath"="%SystemRoot%\system32\UI0Detect.exe" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\uliagpkx] <br/>"ImagePath"="\SystemRoot\system32\drivers\uliagpkx.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\umbus] <br/>"ImagePath"="system32\DRIVERS\umbus.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\UmPass] <br/>"ImagePath"="system32\DRIVERS\umpass.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\upnphost] <br/>"ServiceDll"="%SystemRoot%\System32\upnphost.dll" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\USBAAPL64] <br/>"ImagePath"="System32\Drivers\usbaapl64.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\usbccgp] <br/>"ImagePath"="system32\DRIVERS\usbccgp.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\usbcir] <br/>"ImagePath"="\SystemRoot\system32\drivers\usbcir.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\usbehci] <br/>"ImagePath"="\SystemRoot\system32\drivers\usbehci.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\usbhub] <br/>"ImagePath"="system32\DRIVERS\usbhub.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\usbohci] <br/>"ImagePath"="\SystemRoot\system32\drivers\usbohci.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\usbprint] <br/>"ImagePath"="system32\DRIVERS\usbprint.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\USBSTOR] <br/>"ImagePath"="system32\DRIVERS\USBSTOR.SYS" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\usbuhci] <br/>"ImagePath"="\SystemRoot\system32\drivers\usbuhci.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\usbvideo] <br/>"ImagePath"="System32\Drivers\usbvideo.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\UxSms] <br/>"ServiceDll"="%SystemRoot%\System32\uxsms.dll" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc] <br/>"ImagePath"="%SystemRoot%\system32\lsass.exe" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\vdrvroot] <br/>"ImagePath"="system32\drivers\vdrvroot.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\vds] <br/>"ImagePath"="%SystemRoot%\System32\vds.exe" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\vga] <br/>"ImagePath"="system32\DRIVERS\vgapnp.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VgaSave] <br/>"ImagePath"="\SystemRoot\System32\drivers\vga.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\vhdmp] <br/>"ImagePath"="\SystemRoot\system32\drivers\vhdmp.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\viaide] <br/>"ImagePath"="\SystemRoot\system32\drivers\viaide.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\volmgr] <br/>"ImagePath"="system32\drivers\volmgr.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\volmgrx] <br/>"ImagePath"="System32\drivers\volmgrx.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\volsnap] <br/>"ImagePath"="system32\drivers\volsnap.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\vsmraid] <br/>"ImagePath"="\SystemRoot\system32\DRIVERS\vsmraid.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS] <br/>"ImagePath"="%systemroot%\system32\vssvc.exe" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\vwifibus] <br/>"ImagePath"="system32\DRIVERS\vwifibus.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\vwififlt] <br/>"ImagePath"="system32\DRIVERS\vwififlt.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time] <br/>"ServiceDll"="%systemroot%\system32\w32time.dll" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W3SVC] <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WacomPen] <br/>"ImagePath"="\SystemRoot\system32\DRIVERS\wacompen.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WANARP] <br/>"ImagePath"="system32\DRIVERS\wanarp.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wanarpv6] <br/>"ImagePath"="system32\DRIVERS\wanarp.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WatAdminSvc] <br/>"ImagePath"="%SystemRoot%\system32\Wat\WatAdminSvc.exe" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wbengine] <br/>"ImagePath"="\"%systemroot%\system32\wbengine.exe\"" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WbioSrvc] <br/>"ServiceDll"="%SystemRoot%\System32\wbiosrvc.dll" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wcncsvc] <br/>"ServiceDll"="%SystemRoot%\System32\wcncsvc.dll" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WcsPlugInService] <br/>"ServiceDll"="%SystemRoot%\System32\WcsPlugInService.dll" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wd] <br/>"ImagePath"="\SystemRoot\system32\DRIVERS\wd.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wdf01000] <br/>"ImagePath"="system32\drivers\Wdf01000.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WdiServiceHost] <br/>"ServiceDll"="%SystemRoot%\system32\wdi.dll" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WdiSystemHost] <br/>"ServiceDll"="%SystemRoot%\system32\wdi.dll" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WebClient] <br/>"ServiceDll"="%SystemRoot%\System32\webclnt.dll" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wecsvc] <br/>"ServiceDll"="%SystemRoot%\system32\wecsvc.dll" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wercplsupport] <br/>"ServiceDll"="%SystemRoot%\System32\wercplsupport.dll" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc] <br/>"ServiceDll"="%SystemRoot%\System32\WerSvc.dll" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WfpLwf] <br/>"ImagePath"="system32\DRIVERS\wfplwf.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WIMMount] <br/>"ImagePath"="system32\drivers\wimmount.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinDefend] <br/>"ServiceDll"="%ProgramFiles%\Windows Defender\mpsvc.dll" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Windows Workflow Foundation 3.0.0.0] <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinHttpAutoProxySvc] <br/>"ServiceDll"="winhttp.dll" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Winmgmt] <br/>"ServiceDll"="%SystemRoot%\system32\wbem\WMIsvc.dll" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinRM] <br/>"ServiceDll"="%SystemRoot%\system32\WsmSvc.dll" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Winsock] <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinSock2] <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinUsb] <br/>"ImagePath"="system32\DRIVERS\WinUsb.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wlansvc] <br/>"ServiceDll"="%SystemRoot%\System32\wlansvc.dll" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wlidsvc] <br/>"ImagePath"="\"c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE\"" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WmiAcpi] <br/>"ImagePath"="\SystemRoot\system32\drivers\wmiacpi.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WmiApRpl] <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wmiApSrv] <br/>"ImagePath"="%systemroot%\system32\wbem\WmiApSrv.exe" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WMPNetworkSvc] <br/>"ImagePath"="\"%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe\"" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WPCSvc] <br/>"ServiceDll"="%SystemRoot%\System32\wpcsvc.dll" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WPDBusEnum] <br/>"ServiceDll"="%SystemRoot%\system32\wpdbusenum.dll" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ws2ifsl] <br/>"ImagePath"="\SystemRoot\system32\drivers\ws2ifsl.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc] <br/>"ServiceDll"="%SYSTEMROOT%\system32\wscsvc.dll" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WSearch] <br/>"ImagePath"="%systemroot%\system32\SearchIndexer.exe /Embedding" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WSearchIdxPi] <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv] <br/>"ServiceDll"="%systemroot%\system32\wuaueng.dll" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WudfPf] <br/>"ImagePath"="system32\drivers\WudfPf.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WUDFRd] <br/>"ImagePath"="system32\DRIVERS\WUDFRd.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wudfsvc] <br/>"ServiceDll"="%SystemRoot%\System32\WUDFSvc.dll" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WwanSvc] <br/>"ServiceDll"="%SystemRoot%\System32\wwansvc.dll" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\xmlprov] <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\yukonw7] <br/>"ImagePath"="system32\DRIVERS\yk62x64.sys" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\{06132D06-2B44-48E3-9C0A-4F14FDC77469}] <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\{07171AC2-0D2A-427d-BCE5-B6C2D6C7058B}] <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\{CACB87BA-BD09-4C42-A97E-A8C8258C6339}] <br/>. <br/>--------------------- VERGRENDELDE REGISTER SLEUTELS --------------------- <br/>. <br/>[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] <br/>@Denied: (A 2) (Everyone) <br/>@="FlashBroker" <br/>"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_202_ActiveX.exe,-101" <br/>. <br/>[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] <br/>"Enabled"=dword:00000001 <br/>. <br/>[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] <br/>@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_202_ActiveX.exe" <br/>. <br/>[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] <br/>@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" <br/>. <br/>[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] <br/>@Denied: (A 2) (Everyone) <br/>@="IFlashBroker5" <br/>. <br/>[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] <br/>@="{00020424-0000-0000-C000-000000000046}" <br/>. <br/>[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] <br/>@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" <br/>"Version"="1.0" <br/>. <br/>[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] <br/>@Denied: (A 2) (Everyone) <br/>@="FlashBroker" <br/>"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_202_ActiveX.exe,-101" <br/>. <br/>[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] <br/>"Enabled"=dword:00000001 <br/>. <br/>[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] <br/>@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_202_ActiveX.exe" <br/>. <br/>[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] <br/>@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" <br/>. <br/>[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] <br/>@Denied: (A 2) (Everyone) <br/>@="Shockwave Flash Object" <br/>. <br/>[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] <br/>@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_202.ocx" <br/>"ThreadingModel"="Apartment" <br/>. <br/>[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] <br/>@="0" <br/>. <br/>[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] <br/>@="ShockwaveFlash.ShockwaveFlash.11" <br/>. <br/>[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] <br/>@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_202.ocx, 1" <br/>. <br/>[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] <br/>@="{D27CDB6B-AE6D-11cf-96B8-444553540000}" <br/>. <br/>[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] <br/>@="1.0" <br/>. <br/>[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] <br/>@="ShockwaveFlash.ShockwaveFlash" <br/>. <br/>[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] <br/>@Denied: (A 2) (Everyone) <br/>@="Macromedia Flash Factory Object" <br/>. <br/>[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] <br/>@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_202.ocx" <br/>"ThreadingModel"="Apartment" <br/>. <br/>[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] <br/>@="FlashFactory.FlashFactory.1" <br/>. <br/>[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] <br/>@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_202.ocx, 1" <br/>. <br/>[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] <br/>@="{D27CDB6B-AE6D-11cf-96B8-444553540000}" <br/>. <br/>[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] <br/>@="1.0" <br/>. <br/>[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] <br/>@="FlashFactory.FlashFactory" <br/>. <br/>[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] <br/>@Denied: (A 2) (Everyone) <br/>@="IFlashBroker5" <br/>. <br/>[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] <br/>@="{00020424-0000-0000-C000-000000000046}" <br/>. <br/>[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] <br/>@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" <br/>"Version"="1.0" <br/>. <br/>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] <br/>@Denied: (Full) (Everyone) <br/>. <br/>Voltooingstijd: 2013-06-06 01:06:54 <br/>ComboFix-quarantined-files.txt 2013-06-05 23:06 <br/>. <br/>Pre-Run: 249.362.341.888 bytes beschikbaar <br/>Post-Run: 254.750.056.448 bytes beschikbaar <br/>. <br/>- - End Of File - - 14BE3AB8A88AD51FA322B0EFA9D2E57E
Posted 6/6/2013 10:43 AM
#95715
User avatar

Touch Advanced member

Date Joined Nov 2016
Total Posts: 12976
I don't know whether the thing Combofix did, is undone now though? <br/> <br/></div><br /><br /><br /><br />It looks fine to me, the most important thing was that the rootkit was removed with FRST tool. <br/> <br/> <br/>However, it looks like you have some potentialy unwanted program (PUP) installed which I suggest we remove. <br/> <br/> <br/>Please download: <br/>http://general-changelog-team.fr/fr/downloads/finish/20-outils-de-xplode/2-adwcleaner <br/><br /><br /> <br/> Double click on AdwCleaner.exe to run the tool. <br/>***Note: Windows Vista and Windows 7 users: <br/>Right click in the adwCleaner.exe and select – Run as admin <br/> Click Delete. <br/> Everything that was found will be deleted. <br/> Save any open files and approve the reboot. A text file will open after the restart. <br/><br /><br />Next - <br/>Junkware Removal Tool by thisisu <br/>Download: http://www.bleepingcomputer.com/download/junkware-removal-tool/ <br/> <br/>Disable your Antivirus program if required <br/>For vista and windows 7 right click on the tool and select run as administrator. <br/><br /><br /> <br/>After the scan is completed, post the generated log here, along with Adwcleaner log. <br/> <br/><br /><br />

[color=black face="Courier New" sab="311">[2]Click here: Before-posting-a-log[/2][/url]

<?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" />
[/color]
Do not PM me with logfiles. They will be deleted.


Posted 6/6/2013 6:20 PM
#95719
User avatar

Robin085 Member

Date Joined Nov 2016
Total Posts: 7
# AdwCleaner v2.301 - Verslag gemaakt op 06/06/2013 om 20:14:19 <br/># Geactualiseerd op 16/05/2013 door Xplode <br/># Besturingssysteem : Windows 7 Home Premium Service Pack 1 (64 bits) <br/># Gebruiker : Robin - ROBIN-PC <br/># Opstarten Modus : Normale modus <br/># Gelanceerd vanaf : C:\Users\Robin\Desktop\adwcleaner.exe <br/># Optie [Verwijderen] <br/> <br/> <br/>***** [Diensten] ***** <br/> <br/> <br/>***** [Files / Mappen] ***** <br/> <br/>File Verwijdert : C:\Users\Robin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_bbjciahceamgodcoidkjpchnokgfpphh_0.localstorage <br/>File Verwijdert : C:\Users\Robin\AppData\Roaming\Mozilla\Firefox\Profiles\1sryxlu5.default\searchplugins\Askcom.xml <br/>File Verwijdert : C:\Users\Robin\AppData\Roaming\Mozilla\Firefox\Profiles\1sryxlu5.default\searchplugins\WebSearch.xml <br/>Map Verwijdert : C:\Program Files (x86)\continuetosave <br/>Map Verwijdert : C:\Program Files (x86)\OApps <br/>Map Verwijdert : C:\ProgramData\Ask <br/>Map Verwijdert : C:\ProgramData\continuetosave <br/>Map Verwijdert : C:\ProgramData\InstallMate <br/>Map Verwijdert : C:\ProgramData\SoftSafe <br/>Map Verwijdert : C:\Users\Robin\AppData\Local\Google\Chrome\User Data\Default\Extensions\blcjdfdbfabojnoihfadacglilhjlojb <br/>Verwijdert bij het opstarten : C:\ProgramData\boost_interprocess <br/> <br/>***** [Register] ***** <br/> <br/>Sleutel Verwijdert : HKCU\Software\APN PIP <br/>Sleutel Verwijdert : HKCU\Software\AppDataLow\SProtector <br/>Sleutel Verwijdert : HKCU\Software\Conduit <br/>Sleutel Verwijdert : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{75EBB0AA-4214-4CB4-90EC-E3E07ECD04F7} <br/>Sleutel Verwijdert : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C} <br/>Sleutel Verwijdert : HKCU\Software\Softonic <br/>Sleutel Verwijdert : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE} <br/>Sleutel Verwijdert : HKLM\Software\AVG Secure Search <br/>Sleutel Verwijdert : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB} <br/>Sleutel Verwijdert : HKLM\SOFTWARE\Classes\TypeLib\{E2343056-CC08-46AC-B898-BFC7ACF4E755} <br/>Sleutel Verwijdert : HKLM\Software\Conduit <br/>Sleutel Verwijdert : HKLM\SOFTWARE\Microsoft\Tracing\ConduitInstaller_RASAPI32 <br/>Sleutel Verwijdert : HKLM\SOFTWARE\Microsoft\Tracing\ConduitInstaller_RASMANCS <br/>Sleutel Verwijdert : HKLM\SOFTWARE\Microsoft\Tracing\wajam_install_RASAPI32 <br/>Sleutel Verwijdert : HKLM\SOFTWARE\Microsoft\Tracing\wajam_install_RASMANCS <br/>Sleutel Verwijdert : HKLM\SOFTWARE\Microsoft\Tracing\WajamUpdater_RASAPI32 <br/>Sleutel Verwijdert : HKLM\SOFTWARE\Microsoft\Tracing\WajamUpdater_RASMANCS <br/>Sleutel Verwijdert : HKLM\Software\PIP <br/>Sleutel Verwijdert : HKLM\Software\SP Global <br/>Sleutel Verwijdert : HKLM\Software\SProtector <br/>Sleutel Verwijdert : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla <br/>Sleutel Verwijdert : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE} <br/> <br/>***** [Browsers] ***** <br/> <br/>-\\ Internet Explorer v10.0.9200.16576 <br/> <br/>Vervangen : [HKCU\Software\Microsoft\Internet Explorer\Main - Start Page] = hxxp://websearch.simplespeedy.info/ --> hxxp://www.google.com <br/> <br/>-\\ Mozilla Firefox v21.0 (nl) <br/> <br/>File : C:\Users\Robin\AppData\Roaming\Mozilla\Firefox\Profiles\1sryxlu5.default\prefs.js <br/> <br/>C:\Users\Robin\AppData\Roaming\Mozilla\Firefox\Profiles\1sryxlu5.default\user.js ... Verwijdert ! <br/> <br/>Verwijdert : user_pref("extensions.funmoods.aflt", "fmtgl"); <br/>Verwijdert : user_pref("extensions.funmoods.autoRvrt", false); <br/>Verwijdert : user_pref("extensions.funmoods.dfltLng", ""); <br/>Verwijdert : user_pref("extensions.funmoods.dfltSrch", true); <br/>Verwijdert : user_pref("extensions.funmoods.dnsErr", true); <br/>Verwijdert : user_pref("extensions.funmoods.envrmnt", "production"); <br/>Verwijdert : user_pref("extensions.funmoods.excTlbr", true); <br/>Verwijdert : user_pref("extensions.funmoods.hmpg", false); <br/>Verwijdert : user_pref("extensions.funmoods.hmpgUrl", "hxxp://searchfunmoods.com/?f=1&a=fmtgl&chnl=fmtgl&cd=2Xzuy[...] <br/>Verwijdert : user_pref("extensions.funmoods.id", "C80AA9DEC962E3BE"); <br/>Verwijdert : user_pref("extensions.funmoods.instlDay", "15641"); <br/>Verwijdert : user_pref("extensions.funmoods.instlRef", "fmtgl"); <br/>Verwijdert : user_pref("extensions.funmoods.isdcmntcmplt", true); <br/>Verwijdert : user_pref("extensions.funmoods.mntrvrsn", "1.3.0"); <br/>Verwijdert : user_pref("extensions.funmoods.newTabUrl", "hxxp://searchfunmoods.com/?f=2&a=fmtgl&chnl=fmtgl&cd=2Xz[...] <br/>Verwijdert : user_pref("extensions.funmoods.prdct", "funmoods"); <br/>Verwijdert : user_pref("extensions.funmoods.prtnrId", "funmoods"); <br/>Verwijdert : user_pref("extensions.funmoods.srchPrvdr", "Search"); <br/>Verwijdert : user_pref("extensions.funmoods.tlbrId", "base"); <br/>Verwijdert : user_pref("extensions.funmoods.tlbrSrchUrl", "hxxp://searchfunmoods.com/?f=3&a=fmtgl&chnl=fmtgl&cd=2[...] <br/>Verwijdert : user_pref("extensions.funmoods.vrsn", "1.5.23.22"); <br/>Verwijdert : user_pref("extensions.funmoods.vrsni", "1.5.23.22"); <br/>Verwijdert : user_pref("extensions.funmoods_i.newTab", false); <br/>Verwijdert : user_pref("extensions.funmoods_i.smplGrp", "none"); <br/>Verwijdert : user_pref("extensions.funmoods_i.vrsnTs", "1.5.23.2216:48:31"); <br/> <br/>-\\ Google Chrome v [Onmogelijk de versie te verkrijgen] <br/> <br/>File : C:\Users\Robin\AppData\Local\Google\Chrome\User Data\Default\Preferences <br/> <br/>[OK] De file bevat geen enkele ongeoorloofde invoer. <br/> <br/>************************* <br/> <br/>AdwCleaner[S1].txt - [5416 octets] - [06/06/2013 20:14:19] <br/> <br/>########## EOF - C:\AdwCleaner[S1].txt - [5476 octets] ##########
Posted 6/6/2013 6:32 PM
#95720
User avatar

Robin085 Member

Date Joined Nov 2016
Total Posts: 7
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ <br/>Junkware Removal Tool (JRT) by Thisisu <br/>Version: 4.9.4 (05.06.2013:1) <br/>OS: Windows 7 Home Premium x64 <br/>Ran by Robin on do 06-06-2013 at 20:25:28,24 <br/>~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ <br/> <br/> <br/> <br/> <br/>~~~ Services <br/> <br/> <br/> <br/>~~~ Registry Values <br/> <br/> <br/> <br/>~~~ Registry Keys <br/> <br/>Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{00AFB5EE-A3E4-4E48-9F8B-0950B37B5F9B} <br/>Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{4A2F05AE-7550-483E-8F1A-74D4597E2148} <br/> <br/> <br/> <br/>~~~ Files <br/> <br/> <br/> <br/>~~~ Folders <br/> <br/>Failed to delete: [Folder] "C:\ProgramData\boost_interprocess" <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{002F5C20-0F8F-4FA6-93D5-FBD07D08DD66} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{0116E789-FEBE-4ACF-921D-F05C1839259D} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{01832A22-FA35-4DD3-B2B6-FFC64C0F1FE3} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{01963357-0BC4-400C-BF5D-7EC13351D926} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{019FA9F3-DBE1-4EFB-AFEF-01F083319618} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{01CD429D-09BB-4412-8E6E-ED44969BC5EC} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{026DB60B-CACD-40E8-BD63-1ABAFE76E521} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{0289C6EE-7D70-4E3E-B4FB-DCA1C661FE57} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{028B4876-B018-4E59-808F-D74736E75C35} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{02A00EAC-45F4-454C-8DB3-3A0FB7695727} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{03453A9B-C47F-4A1A-92DA-BEC31212D69C} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{03609397-D958-41D2-8BC5-A86F8A866CF1} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{03923D3A-EA63-4FEA-B7F7-77C8B7990328} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{039E73F8-24F4-4916-9610-9F6DFEEE42A3} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{04E06EB8-404D-414B-AE9D-0D4208B169F4} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{0578FBCC-2124-448C-8274-FDA122FF1178} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{06244917-82F5-4B53-BAE6-F7F84F99BD41} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{06334EFE-C36E-4919-9D63-AF65A0EFAD1A} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{0673899D-4CDD-4791-A74B-A60F94D0F607} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{06FED00C-B6C4-4EBE-94D2-0BC4193AAD38} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{07092354-A01A-4B01-B558-6DD627967E13} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{0714544D-59A1-4077-9144-EF86EC3BF6B2} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{081F8AED-26CB-43DC-BE0B-DD1417DC4746} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{0A4486D5-C209-4D89-8C07-ED4E7A57DFF9} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{0AC59001-02B2-4202-9692-9280F203B096} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{0BC5DEA5-9508-4F3B-A1C6-9989EBB126F0} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{0BE9E799-CA84-4893-8B05-8E73207D43C4} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{0C13BD36-F7F6-4814-BF80-35A58DE67E62} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{0C29F918-FFF8-4B1A-BD6C-CC87754F529C} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{0CD35DB4-1CD3-4657-B445-12196A6B904B} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{0CDA2050-A100-462C-9AC7-CFAFA2693396} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{0D5825A8-19E7-4E85-AC09-9A4E23F54408} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{0E7B0651-EED0-4F7F-BBE5-181402A66E0D} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{10C58400-A150-4234-BDCD-60C5442B124D} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{11A3962F-77DC-43DC-8F00-0D3CDD945117} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{121DD44B-62F7-4795-85FE-4749144EFAFE} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{12F076FA-6971-4189-AF19-4A364586F148} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{139CA7BD-D57A-4B1B-8124-57080CA2DF83} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{147B106A-6507-4410-B532-CF47BEE89F3B} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{14807402-2EAA-427A-9304-A0FEB1E716D5} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{14FE5BC6-CF4D-42DB-871C-549869529208} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{153E40B4-7185-480E-A94E-A8B515934384} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{168E9832-67BC-4770-8931-7A64D20F6541} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{169EB68F-8A20-474A-BAE6-0A9C34664E0E} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{16C1C73C-DE83-43A3-924B-70B2B180B024} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{16D3017D-79F5-4AA9-A867-DFAF3509CBAA} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{182C1BA4-990B-4C33-A9E9-32D3346ED605} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{1849424B-7DE6-4963-8B03-8DAAB992F8D0} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{19719667-BC59-40A1-852F-600C88C7F512} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{19976C70-B9D9-4D7A-A5B1-66A9C2CA0526} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{19A036F4-00D7-470A-BD8D-75502A506D2B} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{19B7CD50-BA9D-4367-8A90-33BCB33BB309} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{19BB6437-CF15-4FDD-9E13-42BBDD930C27} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{1A683CDA-8472-4053-BBA0-413DA95A9434} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{1AECD216-D6D7-45B8-B724-BD28DC2C9341} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{1BBA6BBE-BD86-41BD-A95C-851C298E6EC9} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{1CCE1871-CE0F-406C-B13B-79A327873F44} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{1E9518D0-8386-4724-9FAC-63795C2B7001} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{1E99D814-75B3-46B8-8656-48EDDC913F85} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{1EBC09AA-3BA2-484B-A45A-6FB3D9BB24AB} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{20CC1A22-7647-41DF-AC0A-355AF2BA2314} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{22830C00-6473-44A4-BE35-808804D43BFC} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{228F6990-1E3E-46F8-AF4A-4E110C61367D} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{22EE6970-2332-4C7D-BE3A-044AD312B7A4} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{244C4724-F5B9-4D1C-87CA-3DDF58D4D2C0} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{258F5A61-9A4A-417A-BDF8-6B087CDEB078} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{25FF8A7B-3727-499D-BA92-0FBD059F5635} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{26080F03-F7A4-4122-9137-6DF5D55EA047} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{270F5814-548F-4283-8731-0608F24BADB2} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{27F16278-FC42-42D8-8D76-5612CA1FCBC6} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{29D33F9B-265F-48F3-BB93-20B3139F51B3} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{2ABECD59-A648-41B9-A641-BC18B58C4AF2} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{2BC15935-0095-4961-B96D-1ABF0F6775AF} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{2C614C2C-CB33-49D5-8254-C3E01711D115} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{2CC82E25-5BEA-434C-B5EC-6921352BA302} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{2D797A8B-C9E9-46CB-98D6-A762B90512EE} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{2DD5944A-31D5-42C4-99DD-C865B68C4F63} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{2E0DBC75-A76E-40DC-9BE2-6556E35033E5} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{2EA614E6-9FF2-422D-881E-41F4C51F9C64} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{2F28614A-1D99-4232-BB92-1EA117FCC74D} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{30708499-13FA-4526-8DE3-8E1B7502618B} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{3173C98C-6CEF-4A1F-905B-C3FF6F581D07} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{31E8299E-5BF6-4BF2-BE37-3473560C53A1} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{324328A1-E5D1-4188-9E2C-DD72B7F7C946} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{33250BF7-C1C0-4641-8B85-AD110936CE9F} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{338A8F6C-F441-4458-A54B-3C9DAA44B411} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{33FABA13-D1E5-4B80-A4C0-521164347D02} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{344AAA60-F220-4AF8-8E51-FFC7BDAEA197} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{34D2F091-006D-4234-8D54-00143FF7797F} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{3657887D-73FD-4454-85A9-3B3EF8DA1914} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{367354FF-0A0A-4741-BD40-B13455EFEA27} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{38080757-01EC-4ADA-94E3-ACF60B8DFDCC} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{381CF8B6-DDC1-4E89-B4A4-9161A8B9EACE} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{3895C4E0-6E20-4C08-AE9C-8199A24244C9} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{393F28F7-61C4-4B61-8ECA-6F27233A26D0} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{3983F141-4EE7-453E-A07B-A0D42C119A38} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{39C0167E-3B02-4C60-BEDF-E0690519CF28} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{3C35FF91-67F5-416B-A499-F81DBCA8EBC3} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{3DDFF032-5E7C-4F15-B9A2-D5021F479FA5} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{3E4E75E5-BF6D-42D0-86FB-2A9886460D1C} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{3EC36E81-3274-4F5F-9300-37362634FE7F} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{3F4D223E-0ACF-4E55-8990-6CB2EFED2702} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{40009145-AFF1-4A2B-B88B-24E427BEC3D1} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{423284B4-E82D-444E-9AF5-63BD2CFC5281} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{428D9BBE-E12E-45EE-8AA8-8DE8A696BB43} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{42FDCE64-7C82-448D-A740-EBCD54FE45B5} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{433687CB-B0D3-4921-B586-6BA05ECDD584} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{43A8C6B4-499A-42C1-BA25-12DE787B35E8} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{43D29B5D-5219-4ADB-9B77-485B29C1AF70} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{4501F2CE-EA8E-4F96-B66E-81673C6CFB2F} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{455B4C61-85FD-42A3-8728-EB7136024442} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{457DC43B-21DA-4548-B17B-4218883177C0} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{45A83641-F91A-45C3-A390-6682F5AAD522} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{47770974-5FDD-47ED-B4B5-A3AFD11C3AA1} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{477D7F28-45F3-4986-A295-5D9C3E48F6EE} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{477F331B-6B89-4094-A4B6-2BCD1A1FFAD3} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{47B6ABA6-CB88-4BB6-A8E6-A4DDA3FE3E71} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{47D4FB10-9FB2-493E-88FB-ABD21133552C} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{4845452C-029F-41ED-A8F3-D1F963EB32CD} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{488FEEF1-870A-4084-A37C-35696514DB5F} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{493EA7A1-B1EC-44D4-8387-43CE26C2BFAA} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{49B11D8A-E4D4-402B-B9DE-F43DF05D720D} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{4B107819-87C1-4B04-BB43-961640798FCB} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{4C46DB88-CC02-486C-94A9-D249657B280B} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{4C94D539-F92E-471C-AEDE-D82F51AD973A} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{4CA11F4D-577E-4398-96EF-1A8458716E89} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{4D028AC0-CF28-43B2-BFC5-954639E4461F} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{4D3D7A5C-9322-4414-95E2-4861AD991E80} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{4D6F2BD8-3B89-48A8-BB96-57AB6B5F9005} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{4D89F918-B3B0-4FF6-A642-DAF9E2D57C4B} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{4DC5237B-63DC-497B-AD02-8CC161F7C98C} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{4DD262CA-29E6-4998-AF59-3051A37621DC} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{4EF0C8E6-EC09-4C65-AAB3-200B587DFE5C} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{4F122539-D6B7-4FF1-BEDF-F703B7F6F5B4} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{50248711-5E8E-4E5D-BC10-A1542AA28DAB} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{506EDB7C-4720-45D7-8C70-D0A75A590E6B} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{5097FC00-BDC7-4F6F-9471-D44186A0711E} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{527D9766-53BA-4B07-8D6A-F83360B1501E} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{531AE739-6EDC-4DC9-973A-DA75F52E909A} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{533E510B-3AB6-4E04-ABB1-133B01B7053A} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{547D51CF-2444-4526-879D-ADDB62F0157E} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{55588D7E-1613-418F-A4FC-525AD34F5762} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{5573C80E-5B4A-472B-BC0B-302F1BD25078} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{5582EF60-E53D-4AE2-8B60-9B29F7E13DBA} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{577D7F21-14E4-473B-B306-F3E34DD27E3E} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{57F7A463-F303-495C-8CAC-90671441768C} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{59395F72-6FCD-4851-B55C-E6C4997B6F49} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{5941641E-06F7-4DFC-888C-BAF309874D38} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{594933BF-8FFB-4EA7-81BF-A88E9324FD13} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{59DF26CE-8D11-41DA-915E-D535DB8457CC} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{5AA202FA-265A-43AD-B8CF-847E017BC776} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{5CF3F74E-94D9-4F9A-92E4-27795F48CA8D} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{5F43D5CC-8969-4AAE-A1A1-E973EC751DDF} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{5F50A415-13AC-4164-A155-DFF58DA488F0} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{604EEC63-3BB2-4CAC-BAC5-4777D916BCC8} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{6053D5E1-3747-4B44-ABEC-3AE5C1384485} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{60595BAC-A5C4-4150-A600-3E24DA372160} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{6239C832-3DE5-4FD8-83D7-610647CD1BC4} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{63C67B8C-4DC1-4D69-9C86-AC99BDAB474C} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{640227EF-6F27-4BDE-851F-9157BAFE4601} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{65108C9E-5B04-42F4-9F48-30887102B05D} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{6545B603-D0C0-48B8-BF50-570BE4056CDC} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{65A9BC93-51A6-479F-9B72-97320FA0973C} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{665E6FCA-2ABE-46F8-BA06-CA9A7808A396} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{668CEC6B-F9C6-4870-AD2D-6E329BDE2BD8} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{6703210A-0955-4B83-98A7-A3E38F0632EA} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{673C202E-0E67-4E95-83E2-8F874A5794FF} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{6C0CBE5E-F9C5-4214-AF2B-F0993EE609DC} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{6D4B1CFF-9CFE-4A2B-8B8E-6936AE9ACC78} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{6E653407-21EA-44FC-BF66-A0DB0AE180F7} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{6F95DFF0-B631-4EF2-8E66-84760FB1E276} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{6FA30EF0-3752-4463-9D7D-2CC83BDFAB8B} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{7010D07A-C341-41FA-8EC1-C044AC6F99A9} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{7049A0CC-E467-4EC5-BB62-AAEAD7C96483} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{709FBB10-E62E-479E-AC5C-80561A96C3F4} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{71AF54BE-8605-4E7D-AE56-96B1CB953495} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{71C170C4-4732-4EAB-A875-1C46D2196A26} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{73083A85-A359-4C8A-9C07-098ECF0F041B} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{730F399F-34C4-44D0-9A5E-5FAC0FBCA9FE} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{740A1E65-BB9E-49BF-8786-0B7049E07F98} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{744C7F61-1CFC-4A71-AE3B-16BFC617436E} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{748392CC-413A-454E-9C0D-31E4D9CAF019} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{74C691DF-975D-4377-B553-F06E365267CD} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{74FA463F-28E4-4C71-BA55-1BD7DF002751} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{75D0177D-FC9A-45B6-AB00-A960E6806553} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{75ED2CFD-ED22-456B-902B-B9DE3704707E} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{763035DF-D37C-473E-939E-A0DFEB949CAC} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{76426598-501F-4F19-A9C3-2C8B4C1BE72C} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{7676DFAC-C1CB-4257-BDCD-F14C31BF3A8D} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{76D87E10-F55D-448F-9C57-710BA1FF8324} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{7769F2C4-441E-4064-A46C-849EA7DAE835} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{78F3AE44-F881-42D7-BADF-8941952087A8} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{7933B5EA-958E-49DE-A156-805A7C2333BB} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{7972818B-32AD-42D2-9C67-762FF3024E33} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{7B168315-FFAC-49A0-9EE0-9356C3D10B1E} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{7C39A994-2828-4C98-A363-659AF9A585EA} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{7C6973D0-88D4-4104-B1C1-83AB1D5256E3} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{7D2B5804-7A3B-4681-A599-5DBA7C949B2A} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{7DB810F1-53BF-4650-990A-8B1B5240E513} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{7FD0510E-95F8-4106-928C-F89C3AA3324F} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{8048DDAA-1801-4E3E-9B24-28D714212621} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{80BD2C17-BA74-4D08-94BF-8118512AFBEE} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{811DCB32-7212-4792-8E33-CFC6BB79A363} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{81DEC592-F853-4965-AD9C-CA46265E4057} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{8220D477-7121-44C2-BB16-5A89B0A44C96} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{82E60B56-8BC7-4DB7-BD78-2D3D0D0A6853} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{83548883-C7BE-40F1-ACFD-0144A982C1DB} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{83709E14-0823-481C-923D-E53ED30B85D6} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{84A62F6A-EB2B-4F9D-B29C-4AD0A38FE6D8} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{870B17AD-8694-4B60-9C57-18C418FEAE42} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{872B9F9A-C98D-44D4-B85A-EEBEC11F30CF} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{88F0D6DF-FAA5-42B3-9C74-10705E7B41F3} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{89BA8501-C4A8-4579-9120-5B4D5790D7D5} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{8A26FF28-0E57-46B6-A73B-6451CE297544} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{8B083979-F445-47FD-A667-3E4768B936C1} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{8B5BF9F6-8DDB-46AA-83E8-4DA3C25FDC53} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{8D37BA46-AB48-462E-96C5-60D0B3418107} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{8ED5CEE9-823D-489F-8B3A-5927E787BB24} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{9077C2FD-390A-4EB8-8039-47560034DAF2} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{9095AC97-400A-4E6A-9E4A-57DE0CFF8BC8} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{91073BD4-907E-4DCA-8F9E-4FDC09D1D9B6} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{91840547-4FEF-45E0-B713-74B9A5FEA8BF} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{922A6F5E-5E67-4210-88AD-0BE8D64D816C} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{92612F5A-8F32-4EC4-97A7-6EDD94E2D40E} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{92B26CAE-BBBF-4AEF-837E-F9BDCBB4FE9A} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{9346D344-4708-4C11-81CC-1916934E9DE7} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{94E9028D-DEEA-4753-83C5-41FEB97A3F07} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{95094EB3-F904-4585-885C-8C2DE1DCF2FF} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{953A0AE4-1D6D-45A8-B8E3-800576D7BD6D} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{95EDF56C-7462-42EE-9DED-386D62215DB8} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{96E02777-9DDF-4979-ADAE-BE0C132F785F} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{97805523-DAD6-4FC9-B7F3-1B9486A76E75} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{97850C16-EE2A-470C-AA01-8577C6FA21EF} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{99451257-48E1-45E3-A1D9-99B7B2C71E18} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{994BC187-87A4-4DFB-9722-8001699102EA} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{99EE8152-59F0-4A80-B128-4970A098B50B} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{9B37633D-4E18-4B86-90C0-7EC60FE91F3E} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{9BA3ABDE-9047-4685-9806-C77416F3284B} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{9C651803-B06C-454C-BBA9-23E34AB968AD} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{9C91A542-345E-47F6-8D03-CA8E3D0AFDCA} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{9E32BA96-776A-46E9-BC32-5291D5C4BA49} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{A065FE43-C94E-4392-9116-7509FF79F270} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{A0A3658E-2629-40DF-9C59-BF3CA136187E} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{A0AC8C93-CEAD-46D6-AF45-1598653BBA59} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{A0B6E762-DF50-4D1C-B83E-7114B3D65A82} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{A0F670C4-97EB-47E3-BEBC-831239E4AEBA} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{A14E8279-3773-4658-B06B-55982219969F} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{A16A39F9-66E3-42D8-92D7-9DDD09A7686F} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{A1BCD1FB-6656-4A4E-9543-AC2F27BFF617} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{A26FB9F1-E90A-4B28-B50A-9D8A92852A06} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{A27E485D-35A1-4EC1-B924-F780F0C6BF7D} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{A30F3249-0F10-4E5C-B919-AC89E99FD80D} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{A357414A-B340-410C-BC00-BC3D1DD981A4} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{A4215FD9-51CD-4972-BB6D-44CBA89C2CD6} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{A59E0E66-CD14-4377-92BC-30F56846D979} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{A5DED67E-3DED-4903-AA34-6F4350E162D2} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{A62FD38C-E225-496B-AB75-865B635769EA} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{AB75A163-D336-44C8-BDFD-BA706ADDE0EC} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{AB96AC0C-AFA5-4BC2-8E0F-17927253C3A1} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{AD88E338-BEC0-42FF-99DD-B9FBA9DF5E8D} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{AD8BEFBA-0A61-4853-9FC6-182CDE04F243} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{AF21D35E-3E0D-4394-8999-0DDC8E85B66A} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{B0636CC2-C0F3-4CEF-A063-BC92949F3528} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{B12A47C7-0F79-47E3-976D-715D8D36D8FA} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{B15CE60A-67D7-4356-B519-2123D43D2B52} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{B4B6B3E8-9EC7-4CF9-A893-6A87B952C309} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{B4C06B2F-4B46-4ABE-B25A-E9B7925A5D63} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{B8C106E1-A50B-4EAA-B2AE-B8AE57A2CB2D} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{B94D1E52-5F7F-46C7-8502-F9412470536A} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{BB944719-3AEF-4365-9018-88E6845AB032} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{BBDC4A43-BDF1-462B-9E1D-6797437FFA2B} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{BC72AA78-B475-47C5-9A8F-C3E2B9D0D78C} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{BCC1DEE7-811C-427E-A682-32C18D320647} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{BD9F4ACA-5D20-4EFC-8FB5-AB16099C44BF} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{BE76261E-FD9E-4E7A-8F0B-9D37CE52DE0F} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{BFFD10BE-7E0C-458B-A148-E74C46AB47E1} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{C0DE697D-4321-494D-84C3-101FEF1CCEAD} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{C1657676-1E13-46AF-B1A5-4B72A6C469F7} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{C1A388B3-BABA-4480-8693-388271925238} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{C4654CA3-0677-4254-B12B-41876699C3DC} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{C718ED6F-E3D9-4BC0-83B9-07B97A31B63A} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{C76B74AB-9791-46AB-98D5-9C98C454ECB8} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{C7F033B0-5D67-4B92-984B-115D11DB42CE} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{C8282C62-A920-4ECB-B527-5556A8285DEF} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{C860BA65-EC28-4F70-9CB4-EF80616E9DBD} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{C9D616B7-7824-4D36-BD16-B60EFD363115} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{CCA34FB4-3B38-4C34-8A35-1A686ED51762} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{CDD81BA7-9BB1-4BA4-82F1-8262D1F4BD5E} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{CED85AEC-4832-4F08-97D8-855E0D73EA91} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{CEE4A592-A4C0-44D4-9411-D3FD4C525451} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{CF3E55AB-1AD2-4972-97D3-19F349A06B69} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{D05EB8FD-043A-4B04-B247-57A1F24FF0A9} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{D1425202-23A7-4CD0-9B12-49B334331ABD} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{D227B1CA-393A-49AC-BA72-873A29DEB787} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{D2A19982-8A71-4391-B0BB-BEB57F8EB8C6} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{D338AD4D-1069-4B70-A27C-0954EEFFA2F5} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{D3C1F07C-CF97-429B-89F8-6DB852717CDE} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{D48818A8-04A7-43DF-AE2D-CAE42316A833} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{D5362636-34DB-409C-AF77-FF725B8DE2A8} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{D638DA13-D1F1-4DEE-9605-1FC0F38DA200} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{D6659E9C-C910-4FC1-A42C-4C964269CEE6} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{D6C17213-8204-4180-AF82-29DA335094B0} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{D72CFF3F-75AD-4C29-8598-F672E1184CEF} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{D8E61CEE-E4B9-4133-9B67-9C65AA3BD1DE} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{D911BD70-FBCB-41C2-A74B-E6B33ADA398B} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{DB4CA4D4-32E0-4E01-9BA1-367F2847DB62} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{DD1215A2-984D-4A65-AFF7-52626E078AAE} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{DDC91DC3-49D8-4239-821E-361ABB4392F0} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{DF684868-FD87-423C-933A-3D25BF22DA56} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{DF7FBA30-904A-4115-8F6F-38302B66EE2A} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{E084171E-0F38-4A56-93EC-C84483FF084C} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{E09E249F-1650-403A-9125-2BC0BF9287F5} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{E10964CF-0D4B-4FAB-A5B9-12FE5D673F4A} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{E2AEC35E-1002-4E4E-9B6D-19002389D47D} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{E2F5B71F-4A8A-4351-B729-3D5B24EF1EE9} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{E34FA9AB-3AC3-4020-ADC2-614BECEED81B} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{E398D608-8CE7-41E9-9FF0-B64D60B49C2C} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{E3A1427E-FD7F-452A-B955-7976B8E54C12} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{E4BFDAB6-4338-4237-AF56-C3C1897E8A6D} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{E5AEFD7C-049C-42AD-AA71-2214BDF3C618} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{E62EE511-8100-434C-B88C-D942F7FF9693} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{E6B91043-F912-416D-93D2-0908C4909FD8} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{E90A8AB1-7B63-4EF7-A510-74C2F5D88359} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{E90FC638-63CB-41CC-BEA2-FEB641ABB5E5} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{E9DBB0DD-C3BF-4F54-9B89-16A76337C035} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{E9FA23A3-6BFE-42BB-8D5C-96C34362C30B} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{EC8333BC-FD10-496C-A01A-70E95C8D4E06} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{EC843C66-93C9-42F8-8D5D-F2EA09C03600} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{ED8011B6-B0EF-48FB-9E23-04BC7D87B2C2} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{EE874BC3-31AF-422D-B2D3-1B439436BE8B} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{EED77C57-08EB-4E3C-A3AE-7805777DCF16} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{EEE859FE-63D3-426D-890F-F331113DE78E} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{EEFA4A04-5801-4C21-AD6F-D776C46CA466} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{F1F9798C-C510-4989-AF5B-45308F4EE4EB} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{F2641632-A84F-4502-9C6F-9623AD2CB1C2} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{F26AF65B-2CE1-48BD-AFFB-AC0EE8DF8957} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{F286039B-B1CC-48E2-8184-F43DFD1AA362} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{F2BDC12A-8B5B-4A55-A590-70A9D4B107C0} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{F3831173-7D36-4524-903C-4A78633061E3} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{F3C5D3F9-AAFD-4ACA-8EE6-560E49AA7FDC} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{F444C41C-AA94-4F61-B311-DC9FA1414261} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{F50D3B26-ACF4-4379-9E7D-4F82C3C3E02D} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{F518C9F3-089D-4ADA-86DF-F6C16709AB20} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{F5580B68-DC4C-465A-B627-4E79CAE85376} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{F57B3EE1-739F-4704-B8AB-7814D6E0EEFD} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{F58EC7C3-FEC0-4DCB-8364-AEBCCE3F7380} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{F72DC7DB-D324-4D37-BE38-4392C85AE5A1} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{F790D17D-2A75-47E6-A1EF-D45218250FCE} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{F92EEADD-6F55-45B1-A86D-0B0A4B844A86} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{FA5B85C5-6039-4133-91EE-204E49A58FD2} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{FA854CAB-33E7-44FB-B1BB-EE209E408FCF} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{FB91FC56-9F63-4343-8656-405F0DE71BF5} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{FC4BD25A-DF4D-4A4D-A3C4-75AD56D8092D} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{FC5DF3FB-3ED2-4331-B62F-070F07C82467} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{FDA4FF75-9A17-4844-BDE7-75459CB1E7F4} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{FDF815A5-876C-44AD-A76E-7C299AC9882A} <br/>Successfully deleted: [Empty Folder] C:\Users\Robin\appdata\local\{FF9C63BB-E384-4E31-A941-3A2E7BCEFFBD} <br/> <br/> <br/> <br/>~~~ FireFox <br/> <br/>Successfully deleted: [File] "C:\Users\Robin\AppData\Roaming\mozilla\firefox\profiles\1sryxlu5.default\extensions\503b6c9f609fa@503b6c9f60a33.info.xpi" <br/>Emptied folder: C:\Users\Robin\AppData\Roaming\mozilla\firefox\profiles\1sryxlu5.default\minidumps [537 files] <br/> <br/> <br/> <br/>~~~ Event Viewer Logs were cleared <br/> <br/> <br/> <br/> <br/> <br/>~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ <br/>Scan was completed on do 06-06-2013 at 20:31:14,16 <br/>End of JRT log <br/>~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Posted 6/7/2013 7:55 AM
#95722
User avatar

Touch Advanced member

Date Joined Nov 2016
Total Posts: 12976
<span lang="DA">  <br/> <br/>Download Ccleaner: <br/>[color="#0066cc"><span]http://www.filehippo.com/download_ccleaner[/color] <br/> <br/>Click on -> <br/> <br/>“Download[color="#008080"> <br/>[/color]Latest Version” <br/> <br/>[color="#0066cc">[/color]</div>[color="#0066cc"><span][/color]<span lang="EN-GB"> <br/> <br/>to your desktop. <br/> <br/> <br/> <br/>Double-click mbam-setup  and follow the prompts to install the program. <br/> <br/>At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish. <br/> <br/>If an update is found, it will download and install the latest version. <br/> <br/>Once the program has loaded, select Perform full scan, then click Scan. <br/> <br/>When the scan is complete, click OK, then Show Results to view the results. <br/> <br/>Be sure that everything is checked, and click Remove Selected. <br/> <br/> When completed, a log will open in Notepad. Please save it to a convenient location. <br/> <br/>[color="#0066cc"]http://sourceforge.net/projects/hjt/[/color]</a></div> <br/><span lang="EN-GB"> <br/> <br/>to download HJTinstall.exe <br/> <br/>Save HJTinstall.exe to your desktop. <br/> <br/>Double click on the HJTinstall.exe icon on your desktop. <br/> <br/>By default it will install to C:\Program Files\Trend Micro\Hijack This. <br/> <br/>Click I accept <br/> <br/>Click on the Do a system scan and save a log file button. It will scan and then ask you to save the log. <br/> <br/>Click Save to save the log file and then the log will open in notepad. <br/> <br/>Click on "Edit > Select All" then click on "Edit > Copy" to copy the entire contents of the log. <br/> <br/><span lang="DA">  <br/> <br/><span lang="EN-GB">Post hijackthis log along with Malwarebytes' Anti-Malware log, and tell how things are running ? <br/> <br/><span lang="DA">

[color=black face="Courier New" sab="311">[2]Click here: Before-posting-a-log[/2][/url]

<?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" />
[/color]
Do not PM me with logfiles. They will be deleted.


  • Unread posts or replies
  • No unread posts or replies
  • Unread Posts (Read Only Forum)
  • No Unread Posts (Read Only Forum)

Forum Information

Currently it is Saturday, December 10, 2016, 3:35 PM (GMT +1)
There are a total of 61,164 posts in 13,450 threads.
In the last 3 days there were 1 new threads and 4 reply posts.

Who's online

This forum has 37,970 registered members. Please welcome our newest member, MJD.
There are currently no users on-line.