ilivid / piratebrowser

  • jembee

    Allen,

    Onlangs heb ik thepiratebrowser (mozilla) geinstalleerd. Hierbij kreeg ik helemaal gratis malware van Ividi (ilivid) binnen dat ik inmiddels zoveel mogelijk heb verwijderd. Vervolgens heb ik het hele stappenplan kunnen doorlopen (zie logjes hieronder). Naast het verzoek tot het verwijderen van Ividi (ilivid) wil ik ook van de piratebrowser af. Ook dit lukt me niet.

    Iemand ideeen?

    info.txt logfile of random's system information tool 1.09 2013-10-14 22:01:41

    ======Uninstall list======

    Update for Microsoft Office 2007 (KB2508958)–>msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {0C5823AA-7B6F-44E1-8D5B-8FD1FF0E6438}

    –>“C:\Program Files\InstallShield Installation Information\{A644254B-92F6-4970-8635-AB0775371E72}\setup.exe” –u:{A644254B-92F6-4970-8635-AB0775371E72}

    –>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup “C:\Program Files\InstallShield Installation Information\{622E6F16-0904-49B6-BBE1-4CC836314CCF}\setup.exe” -l0x13

    –>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup “C:\Program Files\InstallShield Installation Information\{697AFC77-F318-4CD4-BF16-F50F4C1072DA}\setup.exe” -l0x13

    µTorrent–>“C:\Program Files\uTorrent\uTorrent.exe” /UNINSTALL

    Aangifte inkomstenbelasting 2011–>C:\Program Files\Belastingdienst\Aangifte inkomstenbelasting\2011\ib2011u.exe

    Aangifte inkomstenbelasting 2012–>C:\Program Files\Belastingdienst\Aangifte inkomstenbelasting\2012\ib2012u.exe

    Aangifte loonheffingen 2010–>E:\2010\Belastingdienst\2010\la2010u.exe

    Activation Assistant for the 2007 Microsoft Office suites–>“C:\ProgramData\{174892B1-CBE7-44F5-86FF-AB555EFD73A3}\Microsoft Office Activation Assistant.exe” REMOVE=TRUE MODIFY=FALSE

    Adobe Bridge 1.0–>MsiExec.exe /I{B74D4E10-6884-0000-0000-000000000103}

    Adobe Flash Player 11 ActiveX–>C:\Windows\system32\Macromed\Flash\FlashUtil32_11_9_900_117_ActiveX.exe -maintain activex

    Adobe Flash Player 11 Plugin–>C:\Windows\system32\Macromed\Flash\FlashUtil32_11_9_900_117_Plugin.exe -maintain plugin

    Adobe Reader XI (11.0.05) - Nederlands–>MsiExec.exe /I{AC76BA86-7AD7-1043-7B44-AB0000000001}

    Adobe Shockwave Player 11.5–>“C:\Windows\system32\Adobe\Shockwave 11\uninstaller.exe”

    AVS Document Converter 2.2.5–>“C:\Program Files\AVS4YOU\AVSDocumentConverter\unins000.exe”

    Camera Assistant Software for Toshiba–>C:\Program Files\InstallShield Installation Information\{37C866E4-AA67-4725-9E95-A39968DD7960}\setup.exe -runfromtemp -l0x0013

    CBSquest–>C:\Program Files\StatNeth\CBSquest\Uninstal.exe

    CCleaner–>“C:\Program Files\CCleaner\uninst.exe”

    CDBurnerXP–>“C:\Program Files\CDBurnerXP\unins000.exe”

    CleanUp!–>C:\Program Files\CleanUp!\uninstall.exe

    Compatibiliteitspakket voor het 2007 Microsoft Office system–>MsiExec.exe /X{90120000-0020-0413-0000-0000000FF1CE}

    Core FTP LE–>“C:\Program Files\CoreFTP\uninstall.exe”

    D3DX10–>MsiExec.exe /X{E09C4DB7-630C-4F06-A631-8EA7239923AF}

    DVD MovieFactory for TOSHIBA–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup “C:\Program Files\InstallShield Installation Information\{F214EAA4-A069-4BAF-9DA4-4DB8BEEDE485}\setup.exe” -l0x13

    EVEREST Ultimate Edition v5.02–>“C:\Program Files\Lavalys\EVEREST Ultimate Edition\unins000.exe”

    FileZilla Client 3.3.5.1–>C:\Program Files\FileZilla FTP Client\uninstall.exe

    FormatFactory 3.0.1–>C:\Program Files\FreeTime\FormatFactory\uninst.exe

    Geluiddemper v. cd/dvd-station–>C:\Program Files\InstallShield Installation Information\{9FE35071-CAB2-4E79-93E7-BFC6A2DC5C5D}\setup.exe -runfromtemp -l0x0013 -removeonly

    Google Calendar Sync–>“C:\Program Files\Google\Google Calendar Sync\uninstall.exe”

    Google Chrome–>“C:\Program Files\Google\Chrome\Application\30.0.1599.69\Installer\setup.exe” –uninstall –multi-install –chrome –system-level

    Google Earth–>MsiExec.exe /X{96AD3B61-EAE2-11E2-9E72-B8AC6F98CCE3}

    Google Toolbar for Internet Explorer–>“C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarManager_08875ABF44579E20.exe” /uninstall

    Google Toolbar for Internet Explorer–>MsiExec.exe /I{18455581-E099-4BA8-BC6B-F34B2F06600C}

    Intel(R) Graphics Media Accelerator Driver–>C:\Windows\system32\igxpun.exe -uninstall

    Intel® Matrix Storage Manager–>C:\Windows\system32\imsmudlg.exe -uninstall

    Java 7 Update 25–>MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83217025FF}

    Java(TM) 6 Update 37–>MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216033FF}

    Java(TM) 6 Update 6–>MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160060}

    Java(TM) 6 Update 7–>MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}

    Junk Mail filter update–>MsiExec.exe /I{400C31E4-796F-4E86-8FDC-C3C4FACC6847}

    Logitech Harmony Remote Software–>C:\Program Files\InstallShield Installation Information\{634F79E1-2A41-4C40-9E8D-89EC740AC9D6}\setup.exe -runfromtemp -l0x0009 -removeonly

    Malwarebytes Anti-Malware versie 1.75.0.1300–>“C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe”

    Microsoft .NET Framework 1.1 Security Update (KB953297)–>“C:\Windows\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe” “C:\Windows\Microsoft.NET\Framework\v1.1.4322\Updates\M953297\M953297Uninstall.msp”

    Microsoft .NET Framework 1.1–>msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}

    Microsoft .NET Framework 1.1–>MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}

    Microsoft .NET Framework 4 Client Profile NLD Language Pack–>MsiExec.exe /X{2617FA1F-0C04-3ABB-AF64-7D5B6620C341}

    Microsoft .NET Framework 4 Client Profile–>C:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\Setup.exe /repair /x86 /parameterfolder Client

    Microsoft .NET Framework 4 Client Profile–>MsiExec.exe /X{3C3901C5-3455-3E0A-A214-0B093A5070A6}

    Microsoft Office 2007 Service Pack 3 (SP3)–>msiexec /package {90120000-0015-0409-0000-0000000FF1CE} /uninstall {AAA19365-932B-49BD-8138-BE28CEE9C4B4}

    Microsoft Office 2007 Service Pack 3 (SP3)–>msiexec /package {90120000-0016-0409-0000-0000000FF1CE} /uninstall {AAA19365-932B-49BD-8138-BE28CEE9C4B4}

    Microsoft Office 2007 Service Pack 3 (SP3)–>msiexec /package {90120000-0018-0409-0000-0000000FF1CE} /uninstall {AAA19365-932B-49BD-8138-BE28CEE9C4B4}

    Microsoft Office 2007 Service Pack 3 (SP3)–>msiexec /package {90120000-0019-0409-0000-0000000FF1CE} /uninstall {AAA19365-932B-49BD-8138-BE28CEE9C4B4}

    Microsoft Office 2007 Service Pack 3 (SP3)–>msiexec /package {90120000-001A-0409-0000-0000000FF1CE} /uninstall {AAA19365-932B-49BD-8138-BE28CEE9C4B4}

    Microsoft Office 2007 Service Pack 3 (SP3)–>msiexec /package {90120000-001B-0409-0000-0000000FF1CE} /uninstall {AAA19365-932B-49BD-8138-BE28CEE9C4B4}

    Microsoft Office 2007 Service Pack 3 (SP3)–>msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {6E107EB7-8B55-48BF-ACCB-199F86A2CD93}

    Microsoft Office 2007 Service Pack 3 (SP3)–>msiexec /package {90120000-0044-0409-0000-0000000FF1CE} /uninstall {AAA19365-932B-49BD-8138-BE28CEE9C4B4}

    Microsoft Office 2007 Service Pack 3 (SP3)–>msiexec /package {90120000-006E-0409-0000-0000000FF1CE} /uninstall {98333358-268C-4164-B6D4-C96DF5153727}

    Microsoft Office 2007 Service Pack 3 (SP3)–>msiexec /package {90120000-00A1-0409-0000-0000000FF1CE} /uninstall {AAA19365-932B-49BD-8138-BE28CEE9C4B4}

    Microsoft Office 2007 Service Pack 3 (SP3)–>msiexec /package {90120000-00BA-0409-0000-0000000FF1CE} /uninstall {AAA19365-932B-49BD-8138-BE28CEE9C4B4}

    Microsoft Office 2007 Service Pack 3 (SP3)–>msiexec /package {90120000-0114-0409-0000-0000000FF1CE} /uninstall {AAA19365-932B-49BD-8138-BE28CEE9C4B4}

    Microsoft Office 2007 Service Pack 3 (SP3)–>msiexec /package {90120000-0115-0409-0000-0000000FF1CE} /uninstall {98333358-268C-4164-B6D4-C96DF5153727}

    Microsoft Office 2007 Service Pack 3 (SP3)–>msiexec /package {90120000-0117-0409-0000-0000000FF1CE} /uninstall {AAA19365-932B-49BD-8138-BE28CEE9C4B4}

    Microsoft Office Access MUI (English) 2007–>MsiExec.exe /X{90120000-0015-0409-0000-0000000FF1CE}

    Microsoft Office Access Setup Metadata MUI (English) 2007–>MsiExec.exe /X{90120000-0117-0409-0000-0000000FF1CE}

    Microsoft Office Enterprise 2007–>“C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe” /uninstall ENTERPRISE /dll OSETUP.DLL

    Microsoft Office Enterprise 2007–>MsiExec.exe /X{90120000-0030-0000-0000-0000000FF1CE}

    Microsoft Office Excel MUI (English) 2007–>MsiExec.exe /X{90120000-0016-0409-0000-0000000FF1CE}

    Microsoft Office File Validation Add-In–>MsiExec.exe /I{90140000-2005-0000-0000-0000000FF1CE}

    Microsoft Office FrontPage 2003–>MsiExec.exe /I{90170413-6000-11D3-8CFE-0150048383C9}

    Microsoft Office Groove MUI (English) 2007–>MsiExec.exe /X{90120000-00BA-0409-0000-0000000FF1CE}

    Microsoft Office Groove Setup Metadata MUI (English) 2007–>MsiExec.exe /X{90120000-0114-0409-0000-0000000FF1CE}

    Microsoft Office InfoPath MUI (English) 2007–>MsiExec.exe /X{90120000-0044-0409-0000-0000000FF1CE}

    Microsoft Office Live Add-in 1.5–>MsiExec.exe /I{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}

    Microsoft Office OneNote MUI (English) 2007–>MsiExec.exe /X{90120000-00A1-0409-0000-0000000FF1CE}

    Microsoft Office Outlook Connector–>MsiExec.exe /X{95140000-007A-0413-0000-0000000FF1CE}

    Microsoft Office Outlook MUI (English) 2007–>MsiExec.exe /X{90120000-001A-0409-0000-0000000FF1CE}

    Microsoft Office PowerPoint MUI (English) 2007–>MsiExec.exe /X{90120000-0018-0409-0000-0000000FF1CE}

    Microsoft Office Proof (English) 2007–>MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}

    Microsoft Office Proof (French) 2007–>MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}

    Microsoft Office Proof (Spanish) 2007–>MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}

    Microsoft Office Proofing (English) 2007–>MsiExec.exe /X{90120000-002C-0409-0000-0000000FF1CE}

    Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)–>msiexec /package {90120000-001F-0409-0000-0000000FF1CE} /uninstall {1FF96026-A04A-4C3E-B50A-BB7022654D0F}

    Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)–>msiexec /package {90120000-001F-040C-0000-0000000FF1CE} /uninstall {71F055E8-E2C6-4214-BB3D-BFE03561B89E}

    Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)–>msiexec /package {90120000-001F-0C0A-0000-0000000FF1CE} /uninstall {2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}

    Microsoft Office Publisher MUI (English) 2007–>MsiExec.exe /X{90120000-0019-0409-0000-0000000FF1CE}

    Microsoft Office Shared MUI (English) 2007–>MsiExec.exe /X{90120000-006E-0409-0000-0000000FF1CE}

    Microsoft Office Shared Setup Metadata MUI (English) 2007–>MsiExec.exe /X{90120000-0115-0409-0000-0000000FF1CE}

    Microsoft Office Word MUI (English) 2007–>MsiExec.exe /X{90120000-001B-0409-0000-0000000FF1CE}

    Microsoft Silverlight–>MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}

    Microsoft SQL Server 2005 Compact Edition –>MsiExec.exe /I{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}

    Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053–>MsiExec.exe /X{770657D0-A123-3C07-8E44-1C83EC895118}

    Microsoft Visual C++ 2005 Redistributable–>MsiExec.exe /X{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}

    Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148–>MsiExec.exe /X{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}

    Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570–>MsiExec.exe /X{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}

    Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022–>MsiExec.exe /X{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}

    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17–>MsiExec.exe /X{9A25302D-30C0-39D9-BD6F-21E6EC160475}

    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161–>MsiExec.exe /X{9BE518E6-ECC6-35A9-88E4-87755C07200F}

    Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319–>MsiExec.exe /X{196BB40D-1578-3D01-B289-BEFC77A11A1E}

    Movie Maker–>MsiExec.exe /X{AE8044B5-FCA3-4EBE-AC78-0FB3A6E8DC76}

    Movie Maker–>MsiExec.exe /X{ED6C77F9-4D7E-447C-9EC0-9A212D075535}

    MSVC80_x86_v2–>MsiExec.exe /I{6D3245B1-8DB8-4A23-9CD2-2C90F40ABAF6}

    MSVC80_x86–>MsiExec.exe /I{212748BB-0DA5-46DE-82A1-403736DC9F27}

    MSVC90_x86–>MsiExec.exe /I{AF111648-99A1-453E-81DD-80DBBF6DAD0D}

    MSVCRT–>MsiExec.exe /I{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}

    MSVCRT110–>MsiExec.exe /I{8E14DDC8-EA60-4E18-B3E3-1937104D5BDA}

    MSXML 4.0 SP2 (KB954430)–>MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}

    MSXML 4.0 SP2 (KB973688)–>MsiExec.exe /I{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}

    myphotobook 3.6–>C:\Program Files\myphotobook\uninst.exe

    neroxml–>MsiExec.exe /I{56C049BE-79E9-4502-BEA7-9754A3E60F9B}

    Nvu 1.0–>“C:\Program Files\Nvu\unins000.exe”

    OGA Notifier 2.0.0048.0–>MsiExec.exe /I{B2544A03-10D0-4E5E-BA69-0362FFC20D18}

    PC Connectivity Solution–>MsiExec.exe /I{45DF6D99-666D-41FA-8D62-0E183B6240F3}

    PDF Ripper 2.01–>“C:\Program Files\PDF Ripper\unins000.exe”

    Photo Common–>MsiExec.exe /X{743FD554-A73F-4FE8-BE7B-C283D16297F9}

    Photo Gallery–>MsiExec.exe /X{30F99474-EBE3-4134-A02B-F6CD38CFE243}

    Photo Gallery–>MsiExec.exe /X{F67CA22C-C11F-4573-8406-57F75BA06B51}

    Picasa 3–>“C:\Program Files\Google\Picasa3\Uninstall.exe”

    Realtek 8169 8168 8101E 8102E Ethernet Driver–>C:\Program Files\InstallShield Installation Information\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}\setup.exe -runfromtemp -l0x0013 -removeonly

    Realtek High Definition Audio Driver–>C:\Program Files\Realtek\Audio\HDA\RtlUpd.exe -r -m -nrg2709

    REALTEK RTL8187B Wireless LAN Driver–>C:\Program Files\InstallShield Installation Information\{895722FE-25FE-4854-95AC-B0C42F9DBEDA}\Install.exe -uninst -l0x13

    Realtek USB 2.0 Card Reader–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup “C:\Program Files\InstallShield Installation Information\{DC24971E-1946-445D-8A82-CE685433FA7D}\setup.exe” -l0x9 -removeonly

    Realtek WiFi Protected Setup Library–>C:\Program Files\InstallShield Installation Information\{02CA24DD-C8B0-4280-BE53-7862869C2EB1}\Install.exe -uninst -l0x13

    Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)–>C:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {3E0806DB-3085-378A-840A-F0D3AE3609D1} /parameterfolder Client

    Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)–>C:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {728D9A6A-2206-31E8-9F65-C3EABEFCF53E} /parameterfolder Client

    Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)–>C:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {2CE2EB39-45C8-32D4-8A99-5529C38F1B99} /parameterfolder Client

    Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)–>C:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {7E97AB83-C1FE-38DE-B848-877E0A4BD81E} /parameterfolder Client

    Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)–>C:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {DB31DEDD-BF95-31E7-A9B7-5480561CEFF3} /parameterfolder Client

    Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)–>C:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {67A5F99B-5EBA-3812-8D2E-BC251490DD3F} /parameterfolder Client

    Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870)–>C:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {8DDEFC7E-0C61-3D11-AFC6-5414F2DAFD01} /parameterfolder Client

    Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)–>C:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {4952F442-5C1A-38EB-8C23-B18EFE77E20C} /parameterfolder Client

    Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368)–>C:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {9EC88EA8-4ABE-393C-87BD-90EABB1C4C9B} /parameterfolder Client

    Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2)–>C:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {86BB5A25-8CC3-33CE-A393-CF28901682B2} /parameterfolder Client

    Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405)–>C:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {16EEC04A-B924-37E0-97CF-422DCEFC1B63} /parameterfolder Client

    Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827)–>C:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {C4D978AA-2668-3404-96DE-96E2AFC62FD7} /parameterfolder Client

    Security Update for Microsoft .NET Framework 4 Client Profile (KB2729449)–>C:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {CD6D9B8A-BBC4-3FA7-B24D-D74CE90630CF} /parameterfolder Client

    Security Update for Microsoft .NET Framework 4 Client Profile (KB2737019)–>C:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {ECBEE23D-AB7E-3DAA-B66B-CD52003198F1} /parameterfolder Client

    Security Update for Microsoft .NET Framework 4 Client Profile (KB2742595)–>C:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {788818B1-B191-3217-A210-7ACFDE19CE4A} /parameterfolder Client

    Security Update for Microsoft .NET Framework 4 Client Profile (KB2789642)–>C:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {B7C20E16-9A3A-3F05-A6B5-E15AA09200E0} /parameterfolder Client

    Security Update for Microsoft .NET Framework 4 Client Profile (KB2804576)–>C:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {CF581973-77E0-3093-A1AC-A03130DE990F} /parameterfolder Client

    Security Update for Microsoft .NET Framework 4 Client Profile (KB2835393)–>C:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {576C07F8-777C-3981-B8BF-063A6B57254E} /parameterfolder Client

    Security Update for Microsoft .NET Framework 4 Client Profile (KB2840628)–>C:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {90EA7C4E-7F03-31FD-BE27-B1A9B4AE56BD} /parameterfolder Client

    Security Update for Microsoft .NET Framework 4 Client Profile (KB2840628v2)–>C:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {1E88AFAE-CEF7-3540-8FF6-6D00877B2767} /parameterfolder Client

    Security Update for Microsoft .NET Framework 4 Client Profile (KB2858302v2)–>C:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {8BA4E34D-95C5-3907-87E4-62FBB31A2190} /parameterfolder Client

    Security Update for Microsoft Office 2007 suites (KB2596744) 32-Bit Edition –>msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {D33B9EF5-3801-496A-A2D6-B7F4BE972D75}

    Security Update for Microsoft Office 2007 suites (KB2596754) 32-Bit Edition –>msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {B145DBBB-7778-4A5D-9D2B-DA6569F02391}

    Security Update for Microsoft Office 2007 suites (KB2596792) 32-Bit Edition–>msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {E34960DB-2A93-45DB-A208-02650F7AB09C}

    Security Update for Microsoft Office 2007 suites (KB2596825) 32-Bit Edition –>msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {B7727B4D-5EA3-4C11-9D30-15E47616DCAF}

    Security Update for Microsoft Office 2007 suites (KB2596871) 32-Bit Edition–>msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {293FB6BE-D3EB-4162-B522-F9108040B9FE}

    Security Update for Microsoft Office 2007 suites (KB2597969) 32-Bit Edition–>msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {2B3C041A-A7F2-4A24-968D-4BEB6A123D15}

    Security Update for Microsoft Office 2007 suites (KB2597973) 32-Bit Edition –>msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {EA575F57-C5D1-4B5A-B9F9-F16EEBC6B58C}

    Security Update for Microsoft Office 2007 suites (KB2687309) 32-Bit Edition –>msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {E949D8B9-24FD-4AB7-B427-FC42AA8BB2D9}

    Security Update for Microsoft Office 2007 suites (KB2687439) 32-Bit Edition –>msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {3579CE34-B225-4B19-A3AF-DE5F562A212F}

    Security Update for Microsoft Office 2007 suites (KB2760411) 32-Bit Edition –>msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {79850906-6D2B-4061-8EAF-EAC84173DEC5}

    Security Update for Microsoft Office 2007 suites (KB2760585) 32-Bit Edition –>msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {8907F32C-DF89-4C2F-AEDE-0DB4B65451C0}

    Security Update for Microsoft Office 2007 suites (KB2760591) 32-Bit Edition –>msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {319FC809-3841-4739-A25F-FDBADF073697}

    Security Update for Microsoft Office 2007 suites (KB2827326) 32-Bit Edition –>msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {4CCE0378-386F-4DC2-9CC1-A3710C77057D}

    Security Update for Microsoft Office 2007 suites (KB2827329) 32-Bit Edition –>msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {81352C19-97CF-4365-8EAE-205BCC9A2DC8}

    Security Update for Microsoft Office Excel 2007 (KB2827324) 32-Bit Edition –>msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {686630EC-8033-4031-85C5-D8E5CD62A958}

    Security Update for Microsoft Office InfoPath 2007 (KB2687440) 32-Bit Edition –>msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {8F311D6C-D8DD-4C32-9457-1A129CABD1A5}

    Security Update for Microsoft Office Outlook 2007 (KB2825999) 32-Bit Edition –>msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {7A0E1177-574A-4F26-AD24-B003699C35FA}

    Security Update for Microsoft Office PowerPoint 2007 (KB2596764) 32-Bit Edition–>msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {AEA16A27-0B97-4670-818F-A98D06EC0A6F}

    Security Update for Microsoft Office PowerPoint 2007 (KB2596912) 32-Bit Edition–>msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {0EF0D4FB-BB23-4515-AAEA-1240AC2DA525}

    Security Update for Microsoft Office Publisher 2007 (KB2597971) 32-Bit Edition –>msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {9D689455-5858-4AE4-A3CA-6E4149FE3F70}

    Security Update for Microsoft Office Word 2007 (KB2827330) 32-Bit Edition –>msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {2C57A81A-7534-4DEE-A450-7FBE86F3200D}

    Security Update for Taalpakket voor Microsoft .NET Framework 4 Client Profile - NLD (KB2478663)–>c:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\ClientLP\setup.exe /uninstallpatch {728D9A6A-2206-31E8-9F65-C3EABEFCF53E} /parameterfolder ClientLP

    Security Update for Taalpakket voor Microsoft .NET Framework 4 Client Profile - NLD (KB2518870)–>c:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\ClientLP\setup.exe /uninstallpatch {2CE2EB39-45C8-32D4-8A99-5529C38F1B99} /parameterfolder ClientLP

    Skype™ 5.10–>MsiExec.exe /X{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}

    SnelStart v9.55–>MsiExec.exe /X{8ECA3A3E-7C26-4C53-B7EF-E0231F89B3E9}

    Snelzoekvak van Google–>“C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBoxSetup.exe” /force /standalone /uninstall

    Sophos Anti-Virus–>MsiExec.exe /X{9ACB414D-9347-40B6-A453-5EFB2DB59DFA}

    Sophos AutoUpdate–>MsiExec.exe /X{15C418EB-7675-42BE-B2B3-281952DA014D}

    Spybot - Search & Destroy–>“C:\Program Files\Spybot - Search & Destroy\unins000.exe”

    Synaptics Pointing Device Driver–>rundll32.exe “C:\Program Files\Synaptics\SynTP\SynISDLL.dll”,standAloneUninstall

    Taalpakket voor Microsoft .NET Framework 3.5 SP1 - NL–>C:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 Language Pack SP1 - nld\setup.exe

    Taalpakket voor Microsoft .NET Framework 4 Client Profile - NLD–>C:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\ClientLP\Setup.exe /repair /x86 /lcid 1043 /parameterfolder ClientLP

    TOSHIBA Assist–>C:\Program Files\InstallShield Installation Information\{12B3A009-A080-4619-9A2A-C6DB151D8D67}\setup.exe -runfromtemp -l0x0013 -removeonly

    TOSHIBA DVD PLAYER–>C:\Program Files\InstallShield Installation Information\{6C5F3BDC-0A1B-4436-A696-5939629D5C31}\setup.exe -runfromtemp -l0x0013 -ADDREMOVE -removeonly

    TOSHIBA Extended Tiles for Windows Mobility Center–>C:\Program Files\InstallShield Installation Information\{617C36FD-0CBE-4600-84B2-441CEB12FADF}\setup.exe -runfromtemp -l0x0413

    TOSHIBA Face Recognition–>“C:\Program Files\InstallShield Installation Information\{C730E42C-935A-45BB-A0C5-37E5234D111B}\setup.exe” -runfromtemp -l0x0413 -removeonly

    TOSHIBA Face Recognition–>MsiExec.exe /I{C730E42C-935A-45BB-A0C5-37E5234D111B}

    TOSHIBA Hardware Setup–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup “C:\Program Files\InstallShield Installation Information\{2883F6F5-0509-43F3-868C-D50330DD9DD3}\setup.exe” -l0x13

    Toshiba Online Product Information–>C:\Program Files\InstallShield Installation Information\{2290A680-4083-410A-ADCC-7092C67FC052}\setup.exe -runfromtemp -l0x0013 -removeonly

    TOSHIBA Recovery Disc Creator–>MsiExec.exe /X{B65BBB06-1F8E-48F5-8A54-B024A9E15FDF}

    TOSHIBA Software Modem–>Tosmreg -U

    TOSHIBA Supervisor Password–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup “C:\Program Files\InstallShield Installation Information\{4B1E87C3-00DE-4898-8E39-E390AAEF2391}\setup.exe” -l0x13

    TOSHIBA Value Added Package–>C:\Program Files\InstallShield Installation Information\{FEDD27A0-B306-45EF-BF58-B527406B42C8}\setup.exe -runfromtemp -l0x0413

    TOSHIBA-handleidingen–>C:\Program Files\InstallShield Installation Information\{8A8EECC0-FECF-42BF-B414-D8E2F884E5AF}\setup.exe -runfromtemp -l0x0013 -removeonly

    TRDCReminder–>C:\Program Files\InstallShield Installation Information\{773970F1-5EBA-4474-ADEE-1EA3B0A59492}\setup.exe -runfromtemp -l0x0413

    TRORDCLauncher–>C:\Program Files\InstallShield Installation Information\{E65C7D8E-186D-484B-BEA8-DEF0331CE600}\setup.exe -runfromtemp -l0x0413

    Update for 2007 Microsoft Office System (KB967642)–>msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {C444285D-5E4F-48A4-91DD-47AAAA68E92D}

    Update for Microsoft .NET Framework 4 Client Profile (KB2468871)–>C:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {5E9CF3A4-ADB3-3080-A8BF-976A28340758} /parameterfolder Client

    Update for Microsoft .NET Framework 4 Client Profile (KB2533523)–>C:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {81EBB9D7-173C-32E3-B477-149C8DE075E4} /parameterfolder Client

    Update for Microsoft .NET Framework 4 Client Profile (KB2600217)–>C:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {5D9961AC-7C99-36A2-9EF0-34678AED5384} /parameterfolder Client

    Update for Microsoft .NET Framework 4 Client Profile (KB2836939)–>C:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {0160BA31-409C-3FD0-9C87-C7D95BF46986} /parameterfolder Client

    Update for Microsoft .NET Framework 4 Client Profile (KB2836939v3)–>C:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {D5B80B17-2443-3296-A700-792FAA0748BD} /parameterfolder Client

    Update for Microsoft Office 2007 Help for Common Features (KB963673)–>msiexec /package {90120000-006E-0409-0000-0000000FF1CE} /uninstall {AB365889-0395-4FAD-B702-CA5985D53D42}

    Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition–>msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {A024FC7B-77DE-45DE-A058-1C049A17BFB3}

    Update for Microsoft Office 2007 suites (KB2687493) 32-Bit Edition–>msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {6FAA03BD-2B51-4029-9AD9-64A3B8E3C84C}

    Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition–>msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {CB68A5B0-3508-4193-AEB9-AF636DAECE0F}

    Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition–>msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {E9A82945-BA29-4EE8-8F2A-2F49545E9CF2}

    Update for Microsoft Office Access 2007 Help (KB963663)–>msiexec /package {90120000-0015-0409-0000-0000000FF1CE} /uninstall {6B76A18A-AA1E-42AB-A7AD-6C84BBB43987}

    Update for Microsoft Office Excel 2007 Help (KB963678)–>msiexec /package {90120000-0016-0409-0000-0000000FF1CE} /uninstall {199DF7B6-169C-448C-B511-1054101BE9C9}

    Update for Microsoft Office Infopath 2007 Help (KB963662)–>msiexec /package {90120000-0044-0409-0000-0000000FF1CE} /uninstall {716B81B8-B13C-41DF-8EAC-7A2F656CAB63}

    Update for Microsoft Office OneNote 2007 Help (KB963670)–>msiexec /package {90120000-00A1-0409-0000-0000000FF1CE} /uninstall {2744EF05-38E1-4D5D-B333-E021EDAEA245}

    Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition–>msiexec /package {90120000-001A-0409-0000-0000000FF1CE} /uninstall {ED38F8A3-4F61-494E-8BCA-E3AC7760C924}

    Update for Microsoft Office Outlook 2007 Help (KB963677)–>msiexec /package {90120000-001A-0409-0000-0000000FF1CE} /uninstall {0451F231-E3E3-4943-AB9F-58EB96171784}

    Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2827325) 32-Bit Edition–>msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {11C9B057-27FF-4BC1-82F6-DC4B15E70A2E}

    Update for Microsoft Office Powerpoint 2007 Help (KB963669)–>msiexec /package {90120000-0018-0409-0000-0000000FF1CE} /uninstall {397B1D4F-ED7B-4ACA-A637-43B670843876}

    Update for Microsoft Office Publisher 2007 Help (KB963667)–>msiexec /package {90120000-0019-0409-0000-0000000FF1CE} /uninstall {2E40DE55-B289-4C8B-8901-5D369B16814F}

    Update for Microsoft Office Script Editor Help (KB963671)–>msiexec /package {90120000-006E-0409-0000-0000000FF1CE} /uninstall {CD11C6A2-FFC6-4271-8EAB-79C3582F505C}

    Update for Microsoft Office Word 2007 Help (KB963665)–>msiexec /package {90120000-001B-0409-0000-0000000FF1CE} /uninstall {80E762AA-C921-4839-9D7D-DB62A72C0726}

    Visual C++ 2008 x86 Runtime - (v9.0.30729)–>MsiExec.exe /X{F333A33D-125C-32A2-8DCE-5C5D14231E27}

    Visual C++ 2008 x86 Runtime - v9.0.30729.01–>C:\Windows\system32\msiexec.exe /x {F333A33D-125C-32A2-8DCE-5C5D14231E27} /qb+ REBOOTPROMPT=“”

    VLC media player 1.0.1–>C:\Program Files\VideoLAN\VLC\uninstall.exe

    Vuze–>C:\Program Files\Vuze\uninstall.exe

    Windows Live Communications Platform–>MsiExec.exe /I{0454BB9A-2A7A-4214-BDFF-937F7A711A44}

    Windows Live Essentials–>C:\Program Files\Windows Live\Installer\wlarp.exe

    Windows Live Essentials–>MsiExec.exe /I{B7F31B9C-8775-4500-8E9D-6ABE9AE17CF4}

    Windows Live Family Safety–>MsiExec.exe /I{3D44D783-D027-4135-AC39-81E320ED2D3A}

    Windows Live Family Safety–>MsiExec.exe /X{4926AA2D-3C66-443D-A456-53AE3FA44144}

    Windows Live ID Sign-in Assistant–>MsiExec.exe /I{8256F87F-8554-4457-8C3D-3F3324697D9F}

    Windows Live Installer–>MsiExec.exe /I{C424CD5E-EA05-4D3E-B5DA-F9F149E1D3AC}

    Windows Live Mail–>MsiExec.exe /I{70854FE6-3BF1-4C69-94D0-BEB821102E34}

    Windows Live Mail–>MsiExec.exe /I{FA75723A-BF4A-40A2-BFCB-BBC320C27DC9}

    Windows Live Messenger–>MsiExec.exe /X{83C9377F-5ED1-4AD8-B113-7C876AEAF3AB}

    Windows Live Messenger–>MsiExec.exe /X{F2235E5E-7881-4293-9B6F-04B2609FBFF0}

    Windows Live MIME IFilter–>MsiExec.exe /I{1B947146-366B-42CD-86D5-219993CE3EE2}

    Windows Live Photo Common–>MsiExec.exe /X{C9B6EFD0-4F01-4BBA-8374-39AD99A3ED72}

    Windows Live PIMT Platform–>MsiExec.exe /I{6A8DB215-7BCD-4377-B015-2E4541A3E7C6}

    Windows Live SOXE Definitions–>MsiExec.exe /I{8A642ACD-CE3A-4A23-A8B1-A0F7EB12B214}

    Windows Live SOXE–>MsiExec.exe /I{FE7C0B3D-50B9-4951-BE78-A321CBF86552}

    Windows Live UX Platform Language Pack–>MsiExec.exe /I{4AA2A466-8031-403A-8236-5301B4E391FB}

    Windows Live UX Platform–>MsiExec.exe /I{4CCBD1F4-CEEC-452A-9CB8-46564B501315}

    Windows Live Writer Resources–>MsiExec.exe /X{FEFD91C5-A25D-48D9-89DA-0FB7BB8B3EF7}

    Windows Live Writer–>MsiExec.exe /X{06EED60F-7FFC-43A7-936E-AA4A8BD948B4}

    Windows Live Writer–>MsiExec.exe /X{97C79BEC-43F7-4BD8-A6A7-85C0257E488A}

    Windows Live Writer–>MsiExec.exe /X{D2C146B1-948D-47EF-8387-5D1C6B980F7C}

    Windows Media Encoder 9 Series–>msiexec.exe /I {E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}

    Windows Media Encoder 9 Series–>MsiExec.exe /I{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}

    Windows-stuurprogrammapakket - Nokia pccsmcfd (08/22/2008 7.0.0.0)–>C:\PROGRA~1\DIFX\B4723E9A0713E5B1\dpinst.exe /u C:\Windows\system32\DRVSTORE\pccsmcfd_A3B3916E5D8138F59EE218321B27B044D3B18294\pccsmcfd.inf

    ======Hosts File======

    127.0.0.1 www.007guard.com

    127.0.0.1 007guard.com

    127.0.0.1 008i.com

    127.0.0.1 www.008k.com

    127.0.0.1 008k.com

    127.0.0.1 www.00hq.com

    127.0.0.1 00hq.com

    127.0.0.1 010402.com

    127.0.0.1 www.032439.com

    127.0.0.1 032439.com

    ======System event log======

    Computer Name: PC_van_Olaf

    Event Code: 14206

    Message: Mediaserver ‘PC_VAN_OLAF: Olaf:’ is geïnitialiseerd en er worden media gedeeld met netwerkapparaten.

    Record Number: 260540

    Source Name: Microsoft-Windows-WMPNSS-Service

    Time Written: 20121124111750.000000-000

    Event Type: Informatie

    User:

    Computer Name: PC_van_Olaf

    Event Code: 14206

    Message: Mediaserver ‘PC_VAN_OLAF: Gast:’ is geïnitialiseerd en er worden media gedeeld met netwerkapparaten.

    Record Number: 260539

    Source Name: Microsoft-Windows-WMPNSS-Service

    Time Written: 20121124111750.000000-000

    Event Type: Informatie

    User:

    Computer Name: PC_van_Olaf

    Event Code: 7036

    Message: De Windows Search-service heeft nu de status wordt uitgevoerd.

    Record Number: 260538

    Source Name: Service Control Manager

    Time Written: 20121124111721.832681-000

    Event Type: Informatie

    User:

    Computer Name: PC_van_Olaf

    Event Code: 7036

    Message: De Windows Media Player Network Sharing Service-service heeft nu de status wordt uitgevoerd.

    Record Number: 260537

    Source Name: Service Control Manager

    Time Written: 20121124111713.906867-000

    Event Type: Informatie

    User:

    Computer Name: PC_van_Olaf

    Event Code: 14204

    Message: De service WMPNetworkSvc is gestart.

    Record Number: 260536

    Source Name: Microsoft-Windows-WMPNSS-Service

    Time Written: 20121124111713.000000-000

    Event Type: Informatie

    User:

    =====Application event log=====

    Computer Name: PC_van_Olaf

    Event Code: 1035

    Message: Het product is opnieuw geconfigureerd. Productnaam: Sophos Anti-Virus. Productversie: 9.5.5. Producttaal: 1033. Fabrikant: Sophos Plc. Status van geslaagd/mislukt opnieuw configureren: 0.

    Record Number: 871266

    Source Name: MsiInstaller

    Time Written: 20110323185947.000000-000

    Event Type: Informatie

    User: NT AUTHORITY\SYSTEM

    Computer Name: PC_van_Olaf

    Event Code: 11728

    Message: Product: Sophos Anti-Virus – Configuration completed successfully.

    Record Number: 871265

    Source Name: MsiInstaller

    Time Written: 20110323185947.000000-000

    Event Type: Informatie

    User: NT AUTHORITY\SYSTEM

    Computer Name: PC_van_Olaf

    Event Code: 1040

    Message: De volgende Windows Installer-transactie wordt gestart: C:\ProgramData\Sophos\AutoUpdate\cache\savxp\Sophos Anti-Virus.msi. Id van clientproces: 4772.

    Record Number: 871264

    Source Name: MsiInstaller

    Time Written: 20110323185850.000000-000

    Event Type: Informatie

    User: NT AUTHORITY\SYSTEM

    Computer Name: PC_van_Olaf

    Event Code: 1001

    Message: Foutbucket 2314018194, type 1

    Naam van gebeurtenis: APPCRASH

    Antwoord: Niet beschikbaar

    Id van CAB-bestand: 0

    Handtekening van probleem:

    P1: jaucheck.exe

    P2: 2.0.3.1

    P3: 4ccb415f

    P4: jaucheck.exe

    P5: 2.0.3.1

    P6: 4ccb415f

    P7: c0000005

    P8: 0000c940

    P9:

    P10:

    Bijgevoegde bestanden:

    C:\Users\Olaf\AppData\Local\Temp\WER387D.tmp.WERInternalMetadata.xml

    Deze bestanden zijn mogelijk hier beschikbaar:

    C:\Users\Olaf\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_jaucheck.exe_4ab3c31996f888a88a3599d88606cd98fd1344_0d2344dc

    Analysesymbool:

    Opnieuw zoeken naar oplossing: 0nRapport-id: cbeeb6d3-557e-11e0-94d9-001e33706559

    Rapportstatus: 0

    Record Number: 871263

    Source Name: Windows Error Reporting

    Time Written: 20110323185315.000000-000

    Event Type: Informatie

    User:

    Computer Name: PC_van_Olaf

    Event Code: 1000

    Message: Naam van toepassing met fout: jaucheck.exe, versie: 2.0.3.1, tijdstempel: 0x4ccb415f

    Naam van module met fout: jaucheck.exe, versie: 2.0.3.1, tijdstempel: 0x4ccb415f

    Uitzonderingscode: 0xc0000005

    Foutoffset: 0x0000c940

    Id van proces met fout: 0x1668

    Starttijd van toepassing met fout: 0x01cbe98b8c4c5f71

    Pad naar toepassing met fout: C:\Program Files\Common Files\Java\Java Update\jaucheck.exe

    Pad naar module met fout: C:\Program Files\Common Files\Java\Java Update\jaucheck.exe

    Rapport-id: cbeeb6d3-557e-11e0-94d9-001e33706559

    Record Number: 871262

    Source Name: Application Error

    Time Written: 20110323185310.000000-000

    Event Type: Fout

    User:

    =====Security event log=====

    Computer Name: PC_van_Olaf

    Event Code: 4624

    Message: Er is een account aangemeld.

    Onderwerp:

    Beveiligings-id: S-1-5-18

    Accountnaam: PC_VAN_OLAF$

    Accountdomein: WORKGROUP

    Aanmeldings-id: 0x3e7

    Aanmeldingstype: 7

    Nieuwe aanmelding:

    Beveiligings-id: S-1-5-21-2139203478-4160936748-3187955452-1000

    Accountnaam: Olaf

    Accountdomein: PC_van_Olaf

    Aanmeldings-id: 0x9c87cf5

    Aanmeldings-GUID: {00000000-0000-0000-0000-000000000000}

    Procesgegevens:

    Proces-id: 0x288

    Naam proces: C:\Windows\System32\winlogon.exe

    Netwerkgegevens:

    Naam van werkstation: PC_VAN_OLAF

    Netwerkadres van bron: 127.0.0.1

    Poort van bron: 0

    Gedetailleerde verificatiegegevens:

    Aanmeldingsproces: User32

    Verificatiepakket: Negotiate

    Doorgezette services: -

    Pakketnaam (alleen NTLM): -

    Sleutellengte: 0

    Deze gebeurtenis wordt gegenereerd wanneer een aanmeldingssessie wordt gemaakt. De gebeurtenis wordt gegenereerd op de computer waartoe toegang wordt verkregen.

    De velden Onderwerp bevatten de account op het lokale systeem waardoor de aanmelding is aangevraagd. Dit is meestal een service zoals de Server-service, of een lokaal proces zoals Winlogon.exe of Services.exe.

    In het veld Aanmeldingstype ziet u het type aanmelding. De meest algemene typen zijn 2 (interactief) en 3 (netwerk).

    Het veld Nieuwe aanmelding bevat de account waarvoor de nieuwe aanmelding is gemaakt. Dit is de account waarmee is aangemeld.

    In de netwerkvelden ziet u de bron van een externe aanmeldingsaanvraag. Naam van werkstation is niet altijd beschikbaar en kan in sommige gevallen leeg zijn.

    De velden met verificatiegegevens bevatten gedetailleerde informatie over deze aanmeldingsaanvraag.

    - Aanmeldings-GUID is een unieke id die kan worden gebruikt om deze gebeurtenis af te stemmen met een KDC-gebeurtenis.

    - In Doorgezette services ziet u welke tussentijdse services voor deze aanmeldingsaanvraag zijn gebruikt.

    - Pakketnaam geeft aan welk subprotocol van de NTLM-protocollen is gebruikt.

    - Sleutellengte geeft de lengte van de gegenereerde sessiesleutel aan. Dit veld is 0 als er geen sessiesleutel is aangevraagd.

    Record Number: 77128

    Source Name: Microsoft-Windows-Security-Auditing

    Time Written: 20111026125624.554408-000

    Event Type: Controle geslaagd

    User:

    Computer Name: PC_van_Olaf

    Event Code: 4648

    Message: Poging tot aanmelden met expliciete referenties.

    Onderwerp:

    Beveiligings-id: S-1-5-18

    Accountnaam: PC_VAN_OLAF$

    Accountdomein: WORKGROUP

    Aanmeldings-id: 0x3e7

    Aanmeldings-GUID: {00000000-0000-0000-0000-000000000000}

    Account waarvan de referenties zijn gebruikt:

    Accountnaam: Olaf

    Accountdomein: PC_van_Olaf

    Aanmeldings-GUID: {00000000-0000-0000-0000-000000000000}

    Doelserver:

    Naam van doelserver: localhost

    Aanvullende gegevens: localhost

    Procesgegevens:

    Proces-id: 0x288

    Procesnaam: C:\Windows\System32\winlogon.exe

    Netwerkgegevens:

    Netwerkadres: 127.0.0.1

    Poort: 0

    Deze gebeurtenis wordt gegenereerd wanneer een proces probeert zich op een account aan te melden door expliciet de referenties van die account op te geven. Meestal gebeurt dit in batchconfiguraties zoals geplande taken, of bij gebruik van de opdracht Uitvoeren als.

    Record Number: 77127

    Source Name: Microsoft-Windows-Security-Auditing

    Time Written: 20111026125624.554408-000

    Event Type: Controle geslaagd

    User:

    Computer Name: PC_van_Olaf

    Event Code: 4672

    Message: Speciale bevoegdheden toegewezen aan nieuwe aanmelding.

    Onderwerp:

    Beveiligings-id: S-1-5-18

    Accountnaam: SYSTEM

    Accountdomein: NT AUTHORITY

    Aanmeldings-id: 0x3e7

    Bevoegdheden: SeAssignPrimaryTokenPrivilege

    SeTcbPrivilege

    SeSecurityPrivilege

    SeTakeOwnershipPrivilege

    SeLoadDriverPrivilege

    SeBackupPrivilege

    SeRestorePrivilege

    SeDebugPrivilege

    SeAuditPrivilege

    SeSystemEnvironmentPrivilege

    SeImpersonatePrivilege

    Record Number: 77126

    Source Name: Microsoft-Windows-Security-Auditing

    Time Written: 20111026065558.744687-000

    Event Type: Controle geslaagd

    User:

    Computer Name: PC_van_Olaf

    Event Code: 4624

    Message: Er is een account aangemeld.

    Onderwerp:

    Beveiligings-id: S-1-5-18

    Accountnaam: PC_VAN_OLAF$

    Accountdomein: WORKGROUP

    Aanmeldings-id: 0x3e7

    Aanmeldingstype: 5

    Nieuwe aanmelding:

    Beveiligings-id: S-1-5-18

    Accountnaam: SYSTEM

    Accountdomein: NT AUTHORITY

    Aanmeldings-id: 0x3e7

    Aanmeldings-GUID: {00000000-0000-0000-0000-000000000000}

    Procesgegevens:

    Proces-id: 0x22c

    Naam proces: C:\Windows\System32\services.exe

    Netwerkgegevens:

    Naam van werkstation:

    Netwerkadres van bron: -

    Poort van bron: -

    Gedetailleerde verificatiegegevens:

    Aanmeldingsproces: Advapi

    Verificatiepakket: Negotiate

    Doorgezette services: -

    Pakketnaam (alleen NTLM): -

    Sleutellengte: 0

    Deze gebeurtenis wordt gegenereerd wanneer een aanmeldingssessie wordt gemaakt. De gebeurtenis wordt gegenereerd op de computer waartoe toegang wordt verkregen.

    De velden Onderwerp bevatten de account op het lokale systeem waardoor de aanmelding is aangevraagd. Dit is meestal een service zoals de Server-service, of een lokaal proces zoals Winlogon.exe of Services.exe.

    In het veld Aanmeldingstype ziet u het type aanmelding. De meest algemene typen zijn 2 (interactief) en 3 (netwerk).

    Het veld Nieuwe aanmelding bevat de account waarvoor de nieuwe aanmelding is gemaakt. Dit is de account waarmee is aangemeld.

    In de netwerkvelden ziet u de bron van een externe aanmeldingsaanvraag. Naam van werkstation is niet altijd beschikbaar en kan in sommige gevallen leeg zijn.

    De velden met verificatiegegevens bevatten gedetailleerde informatie over deze aanmeldingsaanvraag.

    - Aanmeldings-GUID is een unieke id die kan worden gebruikt om deze gebeurtenis af te stemmen met een KDC-gebeurtenis.

    - In Doorgezette services ziet u welke tussentijdse services voor deze aanmeldingsaanvraag zijn gebruikt.

    - Pakketnaam geeft aan welk subprotocol van de NTLM-protocollen is gebruikt.

    - Sleutellengte geeft de lengte van de gegenereerde sessiesleutel aan. Dit veld is 0 als er geen sessiesleutel is aangevraagd.

    Record Number: 77125

    Source Name: Microsoft-Windows-Security-Auditing

    Time Written: 20111026065558.744687-000

    Event Type: Controle geslaagd

    User:

    Computer Name: PC_van_Olaf

    Event Code: 4634

    Message: Er is een account afgemeld.

    Onderwerp:

    Beveiligings-id: S-1-5-21-2139203478-4160936748-3187955452-1000

    Accountnaam: Olaf

    Accountdomein: PC_van_Olaf

    Aanmeldings-id: 0x97d7bd6

    Aanmeldingstype: 7

    Deze gebeurtenis wordt gegenereerd wanneer een aanmeldingssessie wordt vernietigd. De gebeurtenis kan met behulp van de aanmeldings-id positief worden afgestemd met een aanmeldingsgebeurtenis. Aanmeldings-id's zijn alleen uniek wanneer de computer opnieuw is opgestart.

    Record Number: 77124

    Source Name: Microsoft-Windows-Security-Auditing

    Time Written: 20111026064619.681258-000

    Event Type: Controle geslaagd

    User:

    ======Environment variables======

    “ComSpec”=%SystemRoot%\system32\cmd.exe

    “FP_NO_HOST_CHECK”=NO

    “OS”=Windows_NT

    “PATHEXT”=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC

    “PROCESSOR_ARCHITECTURE”=x86

    “TEMP”=%SystemRoot%\TEMP

    “TMP”=%SystemRoot%\TEMP

    “USERNAME”=SYSTEM

    “windir”=%SystemRoot%

    “PSModulePath”=%SystemRoot%\system32\WindowsPowerShell\v1.0\Modules\

    “NUMBER_OF_PROCESSORS”=2

    “PROCESSOR_LEVEL”=6

    “PROCESSOR_IDENTIFIER”=x86 Family 6 Model 15 Stepping 13, GenuineIntel

    “PROCESSOR_REVISION”=0f0d

    “DFSTRACINGON”=FALSE

    “Path”=C:\Program Files\Common Files\Microsoft Shared\Windows Live;C:\Program Files\PC Connectivity Solution\;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\PROGRA~1\COMMON~1\ULEADS~1\MPEG;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;C:\Program Files\Windows Live\Shared

    “TRACE_FORMAT_SEARCH_PATH”=\\NTREL202.ntdev.corp.microsoft.com\4F18C3A5-CA09-4DBD-B6FC-219FDD4C6BE0\TraceFormat

    —————–EOF—————–

    # AdwCleaner v3.007 - Report created 13/10/2013 at 22:52:43

    # Updated 09/10/2013 by Xplode

    # Operating System : Windows 7 Home Premium Service Pack 1 (32 bits)

    # Username : Olaf - PC_VAN_OLAF

    # Running from : C:\Users\Olaf\Downloads\adwcleaner.exe

    # Option : Clean

    ***** *****

    ***** *****

    Folder Deleted : C:\ProgramData\Tarma Installer

    Folder Deleted : C:\ProgramData\Trymedia

    Folder Deleted : C:\Program Files\DAEMON Tools Toolbar

    Folder Deleted : C:\Program Files\Windows iLivid Toolbar

    Folder Deleted : C:\Program Files\yourfiledownloader

    Folder Deleted : C:\Users\Olaf\AppData\Local\iac

    Folder Deleted : C:\Users\Olaf\AppData\Local\Ilivid Player

    Folder Deleted : C:\Users\Olaf\AppData\Local\OpenCandy

    Folder Deleted : C:\Users\Olaf\AppData\Local\PackageAware

    Folder Deleted : C:\Users\Olaf\AppData\LocalLow\BabylonToolbar

    Folder Deleted : C:\Users\Olaf\AppData\LocalLow\iac

    Folder Deleted : C:\Users\Olaf\AppData\Roaming\BabSolution

    Folder Deleted : C:\Users\Olaf\AppData\Roaming\Babylon

    Folder Deleted : C:\Users\Olaf\AppData\Roaming\OpenCandy

    Folder Deleted : C:\Users\Olaf\AppData\Roaming\yourfiledownloader

    Folder Deleted : C:\Users\Gast\AppData\Local\VideoDownloadConverter_4z

    Folder Deleted : C:\Users\Gast\AppData\LocalLow\iac

    Folder Deleted : C:\Users\Gast\AppData\LocalLow\VideoDownloadConverter_4z

    Folder Deleted : C:\Users\Olaf\AppData\Roaming\Mozilla\Firefox\Profiles\s7zlkbof.default\Extensions\ffxtlbr@babylon.com

    File Deleted : C:\Users\Olaf\AppData\Roaming\Mozilla\Firefox\Profiles\s7zlkbof.default\searchplugins\Babylon.xml

    File Deleted : C:\Users\Olaf\AppData\Roaming\Mozilla\Firefox\Profiles\s7zlkbof.default\searchplugins\delta.xml

    File Deleted : C:\Users\Olaf\AppData\Roaming\Mozilla\Firefox\Profiles\s7zlkbof.default\user.js

    File Deleted : C:\Windows\System32\Tasks\EPUpdater

    ***** *****

    ***** *****

    Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\jbpkiefagocgkmemidfngdkamloieekf

    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\EPUpdater

    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C1023DE3-85F4-4EE1-B20F-334FF375FC78}

    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{C1023DE3-85F4-4EE1-B20F-334FF375FC78}

    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\grusskartencenter.com

    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\grusskartencenter.com

    Key Deleted : HKLM\SOFTWARE\Classes\AppID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}

    Key Deleted : HKLM\SOFTWARE\Classes\Applications\ilividsetupv1.exe

    Key Deleted : HKLM\SOFTWARE\Classes\bbylntlbr.bbylntlbrHlpr

    Key Deleted : HKLM\SOFTWARE\Classes\bbylntlbr.bbylntlbrHlpr.1

    Key Deleted : HKLM\SOFTWARE\Classes\driverscanner

    Key Deleted : HKLM\SOFTWARE\Classes\Prod.cap

    Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.protectorbho

    Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.protectorbho.1

    Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\AskPIP_FF__RASAPI32

    Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\AskPIP_FF__RASMANCS

    Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\ClickPotatoLiteSA_RASAPI32

    Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\ClickPotatoLiteSA_RASMANCS

    Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\ConduitInstallerStub_RASAPI32

    Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\ConduitInstallerStub_RASMANCS

    Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\iLividSetupV1_RASAPI32

    Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\iLividSetupV1_RASMANCS

    Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASAPI32

    Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASMANCS

    Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SearchquMediaBar_RASAPI32

    Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SearchquMediaBar_RASMANCS

    Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SetupDataMngr_Searchqu_RASAPI32

    Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SetupDataMngr_Searchqu_RASMANCS

    Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_voor_bejeweled-3_RASAPI32

    Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_voor_bejeweled-3_RASMANCS

    Value Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Run

    Key Deleted : HKLM\SOFTWARE\Classes\AppID\{608D3067-77E8-463D-9084-908966806826}

    Key Deleted : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}

    Key Deleted : HKLM\SOFTWARE\Classes\AppID\{EA28B360-05E0-4F93-8150-02891F1D8D3C}

    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{2CE4D4CF-B278-4126-AD1E-B622DA2E8339}

    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D}

    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{2CE4D4CF-B278-4126-AD1E-B622DA2E8339}

    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}

    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{99079A25-328F-4BD4-BE04-00955ACAA0A7}

    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670}

    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{99079A25-328F-4BD4-BE04-00955ACAA0A7}

    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}

    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{9D717F81-9148-4F12-8568-69135F087DB0}

    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}

    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670}

    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EF99BD32-C1FB-11D2-892F-0090271D4F88}

    Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}

    Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}

    Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}

    Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar

    Key Deleted : HKCU\Software\1ClickDownload

    Key Deleted : HKCU\Software\APN PIP

    Key Deleted : HKCU\Software\BabSolution

    Key Deleted : HKCU\Software\Conduit

    Key Deleted : HKCU\Software\Grand Virtual

    Key Deleted : HKCU\Software\ilivid

    Key Deleted : HKCU\Software\InstallCore

    Key Deleted : HKCU\Software\InstalledThirdPartyPrograms

    Key Deleted : HKCU\Software\PIP

    Key Deleted : HKCU\Software\SearchCore for Browsers

    Key Deleted : HKCU\Software\Softonic

    Key Deleted : HKCU\Software\YourFileDownloader

    Key Deleted : HKCU\Software\AppDataLow\Software\Crossrider

    Key Deleted : HKCU\Software\AppDataLow\Software\PricePeep

    Key Deleted : HKLM\Software\Babylon

    Key Deleted : HKLM\Software\Conduit

    Key Deleted : HKLM\Software\Iminent

    Key Deleted : HKLM\Software\InstalledThirdPartyPrograms

    Key Deleted : HKLM\Software\PIP

    Key Deleted : HKLM\Software\Tarma Installer

    Key Deleted : HKLM\Software\Uniblue\DriverScanner

    Key Deleted : HKLM\Software\YourFileDownloader

    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}

    ***** *****

    -\\ Internet Explorer v10.0.9200.16720

    -\\ Mozilla Firefox v

    Line Deleted : user_pref(“extensions.BabylonToolbar_i.aflt”, “babsst”);

    Line Deleted : user_pref(“extensions.BabylonToolbar_i.babExt”, “”);

    Line Deleted : user_pref(“extensions.BabylonToolbar_i.babTrack”, “affID=109867”);

    Line Deleted : user_pref(“extensions.BabylonToolbar_i.hardId”, “701527fb00000000000000225f1e21a2”);

    Line Deleted : user_pref(“extensions.BabylonToolbar_i.id”, “701527fb00000000000000225f1e21a2”);

    Line Deleted : user_pref(“extensions.BabylonToolbar_i.instlDay”, “15419”);

    Line Deleted : user_pref(“extensions.BabylonToolbar_i.instlRef”, “sst”);

    Line Deleted : user_pref(“extensions.BabylonToolbar_i.newTab”, false);

    Line Deleted : user_pref(“extensions.BabylonToolbar_i.prdct”, “BabylonToolbar”);

    Line Deleted : user_pref(“extensions.BabylonToolbar_i.prtnrId”, “babylon”);

    Line Deleted : user_pref(“extensions.BabylonToolbar_i.smplGrp”, “none”);

    Line Deleted : user_pref(“extensions.BabylonToolbar_i.srcExt”, “ss”);

    Line Deleted : user_pref(“extensions.BabylonToolbar_i.tlbrId”, “base”);

    Line Deleted : user_pref(“extensions.BabylonToolbar_i.vrsn”, “1.5.3.17”);

    Line Deleted : user_pref(“extensions.BabylonToolbar_i.vrsnTs”, “1.5.3.1722:55:41”);

    Line Deleted : user_pref(“extensions.BabylonToolbar_i.vrsni”, “1.5.3.17”);

    Line Deleted : user_pref(“extensions.delta.admin”, false);

    Line Deleted : user_pref(“extensions.delta.aflt”, “babsst”);

    Line Deleted : user_pref(“extensions.delta.appId”, “{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}”);

    Line Deleted : user_pref(“extensions.delta.autoRvrt”, “false”);

    Line Deleted : user_pref(“extensions.delta.dfltLng”, “nl”);

    Line Deleted : user_pref(“extensions.delta.excTlbr”, false);

    Line Deleted : user_pref(“extensions.delta.ffxUnstlRst”, true);

    Line Deleted : user_pref(“extensions.delta.id”, “701527fb00000000000000225f1e21a2”);

    Line Deleted : user_pref(“extensions.delta.instlDay”, “15879”);

    Line Deleted : user_pref(“extensions.delta.instlRef”, “sst”);

    Line Deleted : user_pref(“extensions.delta.newTab”, false);

    Line Deleted : user_pref(“extensions.delta.prdct”, “delta”);

    Line Deleted : user_pref(“extensions.delta.prtnrId”, “delta”);

    Line Deleted : user_pref(“extensions.delta.rvrt”, “false”);

    Line Deleted : user_pref(“extensions.delta.smplGrp”, “none”);

    Line Deleted : user_pref(“extensions.delta.tlbrId”, “base”);

    Line Deleted : user_pref(“extensions.delta.tlbrSrchUrl”, “”);

    Line Deleted : user_pref(“extensions.delta.vrsn”, “1.8.21.5”);

    Line Deleted : user_pref(“extensions.delta.vrsnTs”, “1.8.21.512:50:48”);

    Line Deleted : user_pref(“extensions.delta.vrsni”, “1.8.21.5”);

    Line Deleted : user_pref(“extensions.delta_i.babExt”, “”);

    Line Deleted : user_pref(“extensions.delta_i.babTrack”, “affID=119357&tt=180613_ndt5&tsp=4922”);

    Line Deleted : user_pref(“extensions.delta_i.srcExt”, “ss”);

    -\\ Google Chrome v30.0.1599.69

    *************************

    AdwCleaner.txt - -

    AdwCleaner.txt - -

    ########## EOF - C:\AdwCleaner\AdwCleaner.txt - ##########

    Malwarebytes Anti-Malware 1.75.0.1300

    www.malwarebytes.org

    Databaseversie: v2013.10.13.06

    Windows 7 Service Pack 1 x86 NTFS

    Internet Explorer 10.0.9200.16721

    Olaf :: PC_VAN_OLAF

    14-10-2013 18:28:01

    mbam-log-2013-10-14 (18-28-01).txt

    Scan type: Snelle scan

    Ingeschakelde scan opties: Geheugen | Opstartitems | Register | Bestanden en mappen | Heuristiek/Extra | Heuristiek/Shuriken | PUP | PUM

    Uitgeschakelde scan opties: P2P

    Objecten gescand: 231185

    Verstreken tijd: 17 minuut/minuten, 31 seconde(n)

    Geheugenprocessen gedetecteerd: 0

    (Geen kwaadaardige objecten gedetecteerd)

    Geheugenmodulen gedetecteerd: 0

    (Geen kwaadaardige objecten gedetecteerd)

    Registersleutels gedetecteerd: 0

    (Geen kwaadaardige objecten gedetecteerd)

    Registerwaarden gedetecteerd: 0

    (Geen kwaadaardige objecten gedetecteerd)

    Registerdata gedetecteerd: 0

    (Geen kwaadaardige objecten gedetecteerd)

    Mappen gedetecteerd: 0

    (Geen kwaadaardige objecten gedetecteerd)

    Bestanden gedetecteerd: 0

    (Geen kwaadaardige objecten gedetecteerd)

    (einde)

  • fazantje

    Hoi Olaf,

    Download zoek.zip naar het bureaublad.

    Schakel je antivirus- en antispywareprogramma's uit, mogelijk kunnen ze in conflict komen met zoek.zip

    Klik met de rechtermuisknop op Zoek.zip en klik op de optie “Alles uitpakken”.

    Dubbelklik vervolgens op Zoek.exe om de tool te starten.

    Kopieer nu onderstaande code en plak die in het grote invulvenster:

    firefoxlook;

    emptyclsid;

    emptyfolderscheck;delete

    chromelook;

    standardsearch;

    filesrcm;

    autoclean;

    startupall;

    Klik nu op de knop “Run script”.

    Wacht nu geduldig af tot er een logje opent (dit kan na een herstart zijn als het nodig is).

    Mocht na de herstart geen logje verschijnen, start zoek.exe dan opnieuw, de log verschijnt dan alsnog.

    Post nu de inhoud van het geopende logje in het volgende bericht.

    Succes,

    Huib;)

  • Jos H

    Pas je profiel aan zodat je mailadres niet zichtbaar is. Dit is vragen om nog meer ellende zoals spam.

  • jembee

    Hi Huib,

    Dit was grappig. Virusscanner uitgezet. Bestand zoek.zip dowloaden en een foutmelding krijgen. Alleen het .rar bestand werkte. Uiteraard moest ik toen een .rar programmatje downloaden waarna ik gelijk een hoop troep binnen kreeg…Door zoek.exe is die troep volgens mij wel weer gelijk verdwenen. Zo houden we elkaar bezig:)-D. In ieder geval hieronder het rapportje. Is het wat?

    Zoek.exe Version 4.0.0.5 Updated 13-October-2013

    Tool run by Olaf on wo 16-10-2013 at 20:57:42,26.

    Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x86

    Running in: Normal Mode Internet Access Detected

    Launched: C:\Users\Olaf\Downloads\zoek (1)\zoek.scr

    ==== System Restore Info ======================

    16-10-2013 21:00:08 Zoek.exe System Restore Point Created Succesfully.

    ==== Empty Folders Check ======================

    C:\Program Files\Lavasoft deleted successfully

    C:\Program Files\MSXML 4.0 deleted successfully

    C:\Program Files\Video Codec deleted successfully

    C:\Program Files\Common Files\Apple deleted successfully

    C:\Program Files\Common Files\Nero deleted successfully

    C:\ProgramData\4Sync deleted successfully

    C:\ProgramData\DAEMON Tools Lite deleted successfully

    C:\Users\Olaf\AppData\Roaming\Allmyapps deleted successfully

    C:\Users\Olaf\AppData\Roaming\Logitech deleted successfully

    C:\Users\Olaf\AppData\Local\Toshiba deleted successfully

    C:\Users\Olaf\AppData\Local\Yahoo deleted successfully

    ==== Deleting CLSID Registry Keys ======================

    HKEY_USERS\S-1-5-21-2139203478-4160936748-3187955452-1000\Software\Microsoft\Internet Explorer\SearchScopes\{6C4AB786-9FD0-4129-9BFE-5772191C574A} deleted successfully

    HKEY_USERS\S-1-5-21-2139203478-4160936748-3187955452-1000\Software\Microsoft\Internet Explorer\SearchScopes\{cf6e4b1c-dbde-457e-9cef-ab8ecac8a5e8} deleted successfully

    HKEY_USERS\S-1-5-21-2139203478-4160936748-3187955452-1000\Software\Microsoft\Internet Explorer\SearchScopes\{EA3E7060-BA76-4494-B96B-7C6C510423F9} deleted successfully

    HKEY_USERS\S-1-5-21-2139203478-4160936748-3187955452-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8B8B2E80-1444-451D-AC8E-EB9A847F3887} deleted successfully

    HKEY_USERS\S-1-5-21-2139203478-4160936748-3187955452-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{8B8B2E80-1444-451D-AC8E-EB9A847F3887} deleted successfully

    ==== Deleting CLSID Registry Values ======================

    ==== Running Processes ======================

    C:\Windows\System32\smss.exe

    C:\Windows\system32\csrss.exe

    C:\Windows\system32\wininit.exe

    C:\Windows\system32\csrss.exe

    C:\Windows\system32\services.exe

    C:\Windows\system32\lsass.exe

    C:\Windows\system32\lsm.exe

    C:\Windows\system32\winlogon.exe

    C:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe

    C:\Windows\System32\spoolsv.exe

    C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe

    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE

    C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe

    C:\Program Files\Sophos\AutoUpdate\ALsvc.exe

    C:\Program Files\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe

    C:\Program Files\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe

    C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe

    C:\Windows\system32\TODDSrv.exe

    C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe

    C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe

    C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe

    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE

    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe

    C:\Program Files\TOSHIBA\SmartFaceV\SmartFaceVWatchSrv.exe

    C:\Windows\system32\taskhost.exe

    C:\Windows\system32\Dwm.exe

    C:\Windows\Explorer.EXE

    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

    C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe

    C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe

    C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe

    C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe

    C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe

    C:\Program Files\TOSHIBA\Toshiba Online Product Information\TOPI.exe

    C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe

    C:\Windows\System32\igfxtray.exe

    C:\Windows\System32\hkcmd.exe

    C:\Windows\System32\igfxpers.exe

    C:\Program Files\Sophos\AutoUpdate\ALMon.exe

    C:\Windows\system32\igfxsrvc.exe

    C:\Program Files\Common Files\Java\Java Update\jusched.exe

    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

    C:\Program Files\Camera Assistant Software for Toshiba\CEC_MAIN.exe

    C:\Program Files\Google\Google Calendar Sync\GoogleCalendarSync.exe

    C:\Program Files\Synaptics\SynTP\SynTPHelper.exe

    C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE

    C:\Windows\system32\igfxext.exe

    C:\Windows\system32\SearchIndexer.exe

    C:\Program Files\Windows Media Player\wmpnetwk.exe

    C:\Program Files\SearchProtect\bin\CltMngSvc.exe

    C:\Users\Olaf\AppData\Roaming\SearchProtect\bin\cltmng.exe

    C:\Windows\system32\wbem\wmiprvse.exe

    C:\Windows\system32\conhost.exe

    C:\Windows\system32\conhost.exe

    c:\program files\windows defender\MpCmdRun.exe

    C:\Windows\system32\SearchProtocolHost.exe

    C:\Windows\system32\SearchFilterHost.exe

    C:\Windows\system32\svchost.exe -k DcomLaunch

    C:\Windows\system32\svchost.exe -k RPCSS

    C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted

    C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted

    C:\Windows\system32\svchost.exe -k LocalService

    C:\Windows\system32\svchost.exe -k netsvcs

    C:\Windows\system32\svchost.exe -k NetworkService

    C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation

    C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork

    C:\Windows\system32\svchost.exe -k imgsvc

    C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted

    C:\Windows\System32\svchost.exe -k secsvcs

    ==== Deleting Services ======================

    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CltMngSvc deleted successfully

    ==== FireFox Fix ======================

    ProfilePath: C:\Users\Olaf\AppData\Roaming\Mozilla\Firefox\Profiles\s7zlkbof.default

    —- Lines ividi removed from prefs.js —-

    user_pref(“extensions.ividi.admin”, false);

    user_pref(“extensions.ividi.aflt”, “3”);

    user_pref(“extensions.ividi.appId”, “{685F23D9-FCFD-475C-B56A-362645945C5A}”);

    user_pref(“extensions.ividi.autoRvrt”, “false”);

    user_pref(“extensions.ividi.dfltLng”, “”);

    user_pref(“extensions.ividi.dfltSrch”, true);

    user_pref(“extensions.ividi.dnsErr”, true);

    user_pref(“extensions.ividi.excTlbr”, true);

    user_pref(“extensions.ividi.ffxUnstlRst”, false);

    user_pref(“extensions.ividi.hmpg”, true);

    user_pref(“extensions.ividi.hmpgUrl”, “http://search.ividi.org/?src=tbhp&id=701527fb00000000000000225f1e21a2&affilt=3”);

    user_pref(“extensions.ividi.hpOld0”, “”);

    user_pref(“extensions.ividi.id”, “701527fb00000000000000225f1e21a2”);

    user_pref(“extensions.ividi.instlDay”, “15991”);

    user_pref(“extensions.ividi.instlRef”, “”);

    user_pref(“extensions.ividi.kw_url”, “http://search.ividi.org/?src=tbsp&id=701527fb00000000000000225f1e21a2&affilt=3&q=”);

    user_pref(“extensions.ividi.newTab”, true);

    user_pref(“extensions.ividi.newTabUrl”, “http://search.ividi.org/?q={searchTerms}&src=tbnt&id=701527fb00000000000000225f1e21a2&affilt=3”);

    user_pref(“extensions.ividi.prdct”, “ividi”);

    user_pref(“extensions.ividi.prtnrId”, “ividi”);

    user_pref(“extensions.ividi.rvrt”, “false”);

    user_pref(“extensions.ividi.smplGrp”, “none”);

    user_pref(“extensions.ividi.srchPrvdr”, “Search ”);

    user_pref(“extensions.ividi.tlbrId”, “base”);

    user_pref(“extensions.ividi.tlbrSrchUrl”, “http://search.ividi.org/?src=tbsp&id=701527fb00000000000000225f1e21a2&affilt=3&q=”);

    user_pref(“extensions.ividi.vrsn”, “1.8.23.0”);

    user_pref(“extensions.ividi.vrsnTs”, “1.8.23.016:54:06”);

    user_pref(“extensions.ividi.vrsni”, “1.8.23.0”);

    —- Lines ividi modified from prefs.js —-

    —- Lines ividi removed from user.js —-

    user_pref(“extensions.Softonic.hpOld0”, “http://search.ividi.org/?src=tbhp&id=701527fb00000000000000225f1e21a2&affilt=3”);

    —- Lines Softonic removed from prefs.js —-

    user_pref(“browser.search.order.1”, “Search the web (Softonic)”);

    user_pref(“browser.search.selectedEngine”, “Search the web (Softonic)”);

    user_pref(“browser.startup.homepage”, “http://search.softonic.com/MOY00011/tb_v1?SearchSource=13&cc=&mi=701527fb00000000000000225f1e21a2”);

    user_pref(“keyword.URL”, “http://search.softonic.com/MOY00011/tb_v1?SearchSource=2&cc=&mi=701527fb00000000000000225f1e21a2&q=”);

    —- Lines Softonic modified from prefs.js —-

    —- Lines Softonic removed from user.js —-

    user_pref(“extensions.Softonic.tlbrSrchUrl”, “http://search.softonic.com/MOY00011/tb_v1?SearchSource=1&cc=&mi=701527fb00000000000000225f1e21a2&q=”);

    user_pref(“extensions.Softonic.id”, “701527fb00000000000000225f1e21a2”);

    user_pref(“extensions.Softonic.appId”, “{7ABBFE1C-E485-44AA-8F36-353751B4124D}”);

    user_pref(“extensions.Softonic.instlDay”, “15994”);

    user_pref(“extensions.Softonic.vrsn”, “1.8.19.3”);

    user_pref(“extensions.Softonic.vrsni”, “1.8.19.3”);

    user_pref(“extensions.Softonic.vrsnTs”, “1.8.19.320:52:23”);

    user_pref(“extensions.Softonic.prtnrId”, “softonic”);

    user_pref(“extensions.Softonic.prdct”, “Softonic”);

    user_pref(“extensions.Softonic.aflt”, “SD”);

    user_pref(“extensions.Softonic.smplGrp”, “none”);

    user_pref(“extensions.Softonic.tlbrId”, “2013desingbrand”);

    user_pref(“extensions.Softonic.instlRef”, “MOY00011”);

    user_pref(“extensions.Softonic.dfltLng”, “nl”);

    user_pref(“extensions.Softonic.excTlbr”, false);

    user_pref(“extensions.Softonic.ffxUnstlRst”, false);

    user_pref(“extensions.Softonic.admin”, false);

    user_pref(“extensions.Softonic.autoRvrt”, “false”);

    user_pref(“extensions.Softonic.rvrt”, “false”);

    user_pref(“extensions.Softonic.hmpg”, true);

    user_pref(“extensions.Softonic.hmpgUrl”, “http://search.softonic.com/MOY00011/tb_v1?SearchSource=13&cc=&mi=701527fb00000000000000225f1e21a2”);

    user_pref(“extensions.Softonic.dfltSrch”, true);

    user_pref(“extensions.Softonic.srchPrvdr”, “Search the web (Softonic)”);

    user_pref(“extensions.Softonic.kw_url”, “http://search.softonic.com/MOY00011/tb_v1?SearchSource=2&cc=&mi=701527fb00000000000000225f1e21a2&q=”);

    user_pref(“extensions.Softonic.dnsErr”, true);

    user_pref(“extensions.Softonic.newTab”, true);

    user_pref(“extensions.Softonic.newTabUrl”, “http://search.softonic.com/MOY00011/tb_v1/?SearchSource=15&cc=&mi=701527fb00000000000000225f1e21a2”);

    —- Lines Search removed from prefs.js —-

    user_pref(“browser.search.defaultenginename”, “Search ”);

    —- Lines Search modified from prefs.js —-

    —- Lines Torntv removed from prefs.js —-

    —- Lines Torntv modified from prefs.js —-

    user_pref(“extensions.installCache”, "");

    —- FireFox user.js and prefs.js backups —-

    user_16-10-2013_2130_.backup

    prefs_16-10-2013_2130_.backup

    ==== Deleting Files \ Folders ======================

    C:\Windows\system32\appdata deleted

    C:\Program Files\Softonic deleted

    C:\Program Files\Conduit deleted

    C:\Program Files\SearchProtect deleted

    C:\found.000 deleted

    C:\Users\Olaf\AppData\Roaming\LimeWirePlus deleted

    C:\Users\Olaf\AppData\Roaming\Softonic deleted

    C:\Users\Olaf\AppData\Roaming\OpenCandy deleted

    C:\Users\Olaf\AppData\Local\CRE deleted

    C:\Users\Olaf\Downloads\SoftonicDownloader_voor_rar-file-open-knife.exe deleted

    C:\Users\Olaf\AppData\LocalLow\Softonic deleted

    C:\Users\Olaf\AppData\LocalLow\Conduit deleted

    C:\user.js deleted

    C:\END deleted

    “C:\user.js” not found

    “C:\Users\Olaf\AppData\Local\{8AD47D02-D72D-46D7-BE37-328F310CEC47}” deleted

    “C:\Users\Olaf\AppData\Roaming\Mozilla\Firefox\Profiles\s7zlkbof.default\searchplugins\ividi.xml” deleted

    “C:\Users\Olaf\AppData\Roaming\Mozilla\Firefox\Profiles\s7zlkbof.default\searchplugins\softonic.xml” deleted

    “C:\Users\Olaf\AppData\Roaming\Mozilla\Firefox\Profiles\s7zlkbof.default\extensions\torntv@torntv.com.xpi” deleted

    “C:\Users\Olaf\AppData\Roaming\SearchProtect\bin\ChromeModule.dll” deleted

    “C:\Users\Olaf\AppData\Roaming\SearchProtect\bin\cltmng.exe” deleted

    “C:\Users\Olaf\AppData\Roaming\SearchProtect\bin\FirefoxModule.dll” deleted

    “C:\Users\Olaf\AppData\Roaming\SearchProtect\bin\InternetExplorerModule.dll” deleted

    “C:\Users\Olaf\AppData\Roaming\SearchProtect\bin\rep.dat” deleted

    “C:\Users\Olaf\AppData\Roaming\SearchProtect” deleted

    “C:\Users\Olaf\AppData\Roaming\SearchProtect\bin” deleted

    ==== System Specs ======================

    Windows: Windows 7 Home Premium Edition Service Pack 1 (Build 7601)

    Memory (RAM): 2940 MB

    CPU Info: Intel(R) Pentium(R) Dual CPU T3200 @ 2.00GHz

    CPU Speed: 1994,9 MHz

    Sound Card: Luidsprekers (Realtek High Defi |

    Display Adapters: Mobile Intel(R) 4 Series Express Chipset Family | Mobile Intel(R) 4 Series Express Chipset Family | RDPDD Chained DD | RDP Encoder Mirror Driver | RDP Reflector Display Driver

    Monitors: 1x; Algemeen PnP-beeldscherm |

    Screen Resolution: 1440 X 900 - 32 bit

    Network: Network Present

    Network Adapters: Realtek RTL8187B 802.11b/g 54 Mbps draadloze USB 2.0-netwerkadapter | Realtek RTL8102E Family PCI-E Fast Ethernet NIC (NDIS 6.0)

    CD / DVD Drives: 1x (D: | ) D: TSSTcorpCDDVDW TS-L633A

    Ports: COM3 LPT Port NOT Present.

    Mouse: 5 Button Wheel Mouse Present

    Hard Disks: C: 74,4GB | E: 73,2GB

    Hard Disks - Free: C: 27,5GB | E: 51,3GB

    Manufacturer *: INSYDE

    BIOS Info: AT/AT COMPATIBLE | 06/04/09 | TOSINV - 1

    Time Zone: West-Europa (standaardtijd)

    Motherboard *: TOSHIBA Portable PC

    Country: Nederland

    Language: NLD

    ==== System Specs (Software) ======================

    Anti-Virus: Sophos Anti-Virus On-access scanning disabled (Outdated)

    Anti-Spyware: Windows Defender disabled (Outdated)

    Anti-Spyware: Sophos Anti-Virus disabled (Outdated)

    Default Browser: Google Chrome 30.0.1599.101

    Internet Explorer Version: 10.0.9200.16721

    Google Chrome version: 30.0.1599.101

    Adobe Reader version: 11.0.04.63

    Sun Java version: 1.7.0_25 (32-bit)

    Flash Player version: 11.9.900.117

    Shockwave Player version: 11.5.2r602

    ==== Files Recently Created / Modified ======================

    ====== C:\Windows ====

    ====== C:\Users\Olaf\AppData\Local\Temp ====

    2013-10-16 18:53:00 6A0F411CA91A97A709B98E114F4052D5 76344 —-a-w- C:\Users\Olaf\AppData\Local\Temp\ct3281675\statisticsStub.exe

    2013-10-16 18:52:21 4AE5F34AB33261FEB8B94F5FFC8E8F19 73543 —-a-w- C:\Users\Olaf\AppData\Local\Temp\ct3281675\ctbe.exe

    2013-10-16 18:52:18 3D5A9C21A5F482B02F8357E684D8111E 89192 —-a-w- C:\Users\Olaf\AppData\Local\Temp\ct3281675\stub.exe

    2013-10-16 18:51:53 A303F7BDEB2B08EC12D342A9C245DA75 2394184 —-a-w- C:\Users\Olaf\AppData\Local\Temp\Softonic_chr_1-8-19-3.exe

    ====== Java Cache =====

    2013-09-23 19:00:30 8E55CC4BD33181118FE11EEEBEDFEA13 67798 —-a-w- C:\Users\Olaf\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\49\43803bf1-265976b8

    2013-09-23 19:00:32 96550E6114F6739BA1098E02022C69EC 202358 —-a-w- C:\Users\Olaf\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\50\7a74ca72-6453f814

    2013-09-23 19:00:33 21DAD98B5BCFFA4597825E9500BE91C2 332854 —-a-w- C:\Users\Olaf\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\52\7876e634-308ea777

    2013-09-23 19:00:29 492BB615E5FCD996DCE00F86E07D0D72 134152 —-a-w- C:\Users\Olaf\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\60\7fa6017c-31c82d5f

    2013-09-23 19:00:31 7AFF98528F9BE77357128504B487E322 60594 —-a-w- C:\Users\Olaf\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\63\5991e17f-795dddfd

    ====== C:\Windows\system32 =====

    2013-10-10 21:30:10 E02C01EB0ED522327AFF3BE5CBCF6017 690688 —-a-w- C:\Windows\System32\jscript.dll

    2013-10-10 21:30:10 351B1A5B8A02A59DD29D122B0D231FA6 2706432 —-a-w- C:\Windows\System32\mshtml.tlb

    2013-10-10 21:30:08 5A847E98EAF032928E67EE52DE08952D 2876928 —-a-w- C:\Windows\System32\jscript9.dll

    2013-10-10 21:30:07 DC7DB5BC0E2D135103730E08FE1C540D 39424 —-a-w- C:\Windows\System32\jsproxy.dll

    2013-10-10 21:30:06 BE8F3297A0BC3D3E3B66D9A45F64F0B9 61440 —-a-w- C:\Windows\System32\iesetup.dll

    2013-10-10 21:30:05 5E775F0C365F01A8A7382BBEFC4A53A5 391168 —-a-w- C:\Windows\System32\ieui.dll

    2013-10-10 21:30:04 E8433E4E65BDFB35DE5C2BFF745F1386 42496 —-a-w- C:\Windows\System32\ie4uinit.exe

    2013-10-10 21:30:04 883C0D3A22CE87A3203CD5518EBB5758 493056 —-a-w- C:\Windows\System32\msfeeds.dll

    2013-10-10 21:30:04 6E9013E3D112E26A42EC057CAE990649 109056 —-a-w- C:\Windows\System32\iesysprep.dll

    2013-10-10 21:30:04 61DC3F2BE3093FE22CD717260946D7AD 1141248 —-a-w- C:\Windows\System32\urlmon.dll

    2013-10-10 21:30:04 58A43D9DFFF91C1457EC47BDCF969B59 71680 —-a-w- C:\Windows\System32\RegisterIEPKEYs.exe

    2013-10-10 21:30:04 556F70EDECE99CCD64C7D8897F3264F4 33280 —-a-w- C:\Windows\System32\iernonce.dll

    2013-10-10 21:30:03 122B216B091D06F672CC8D331128FB06 2048512 —-a-w- C:\Windows\System32\iertutil.dll

    2013-10-10 21:30:00 E4FEB264B47360B7296AEA4E052F88D8 1767936 —-a-w- C:\Windows\System32\wininet.dll

    2013-10-10 21:29:58 8F5EAAF76A6811332A8C67DB0D4C395F 13761024 —-a-w- C:\Windows\System32\ieframe.dll

    2013-10-10 21:29:54 A7221924181C8EB92B64C5A2D888BEA5 14335488 —-a-w- C:\Windows\System32\mshtml.dll

    2013-10-09 20:26:37 75F5E1FE8D55CF8E577E0EC5F2290D3F 530432 —-a-w- C:\Windows\System32\comctl32.dll

    2013-10-09 20:26:36 E94C583CDE2348950155F2AF2876F34D 231424 —-a-w- C:\Windows\System32\mswsock.dll

    2013-10-09 20:26:32 482C8CD985C727C7C78A5E9B320947F0 3969472 —-a-w- C:\Windows\System32\ntkrnlpa.exe

    2013-10-09 20:26:31 E0B8C6B1EA1EF94747E966E9093FB968 1289096 —-a-w- C:\Windows\System32\ntdll.dll

    2013-10-09 20:26:31 D67472125471784DE7147946EDA25FEB 640512 —-a-w- C:\Windows\System32\advapi32.dll

    2013-10-09 20:26:31 813A7F5A2D6D366EB3FFB643B851BCE5 3914176 —-a-w- C:\Windows\System32\ntoskrnl.exe

    2013-10-09 20:26:31 401D25136E26B237D77DA1BF1198B3BD 619520 —-a-w- C:\Windows\System32\tdh.dll

    2013-10-09 20:26:29 2A01B40C8334A8124001CFAC256FCA83 102608 —-a-w- C:\Windows\System32\PresentationCFFRasterizerNative_v0300.dll

    2013-10-09 20:26:28 5C6B44F9CAAC475B7B9EBBC29CB7F065 295424 —-a-w- C:\Windows\System32\atmfd.dll

    2013-10-09 20:26:27 F632602316001D517F4EF3B53B9A6C33 26112 —-a-w- C:\Windows\System32\lpk.dll

    2013-10-09 20:26:27 8CC4638FA7B5B921B9080CF962582C0B 70656 —-a-w- C:\Windows\System32\fontsub.dll

    2013-10-09 20:26:27 7D27E63B54DB093BB0D9E95F81094D75 34304 —-a-w- C:\Windows\System32\atmlib.dll

    2013-10-09 20:26:27 2342EC9254F4C60CA98441BD65C89E12 10240 —-a-w- C:\Windows\System32\dciman32.dll

    2013-10-09 20:26:23 E2ED66FAF894F545EB083AC5F5763854 434688 —-a-w- C:\Windows\System32\scavengeui.dll

    2013-10-09 20:26:19 445C354D772DFEBF46F73078C8C2C797 2348544 —-a-w- C:\Windows\System32\win32k.sys

    2013-10-09 20:26:14 EAF4712B706936C0B10D3B5319B37E81 81920 —-a-w- C:\Windows\System32\davclnt.dll

    2013-10-09 20:26:14 75E8EBD7040CE238684333F97014762A 205824 —-a-w- C:\Windows\System32\WebClnt.dll

    ====== C:\Windows\system32\drivers =====

    2013-10-09 20:26:36 FC6B21DB4B5B398AB93DBE59CBF11036 36352 —-a-w- C:\Windows\System32\drivers\usbscan.sys

    2013-10-09 20:26:36 F81BB7E487EDCEAB630A7EE66CF23913 338944 —-a-w- C:\Windows\System32\drivers\afd.sys

    2013-10-09 20:26:36 F1B27299F547D452EDAEF01FC187CB91 25728 —-a-w- C:\Windows\System32\drivers\hidparse.sys

    2013-10-09 20:26:36 CA59F7C570AF70BC174F477CFE2D9EE3 1294272 —-a-w- C:\Windows\System32\drivers\tcpip.sys

    2013-10-09 20:26:36 50ABE682EBE752EAF62B18790D6D491C 55808 —-a-w- C:\Windows\System32\drivers\hidclass.sys

    2013-10-09 20:26:32 71BC35067CABC02C9453AEAA42B2E43E 729024 —-a-w- C:\Windows\System32\drivers\dxgkrnl.sys

    2013-10-09 20:26:14 21F4B24ACFC79A483515BD986DD9043F 115712 —-a-w- C:\Windows\System32\drivers\mrxdav.sys

    2013-10-09 20:26:12 DE014425522610BEDCA3821BB8C0F1D5 146816 —-a-w- C:\Windows\System32\drivers\usbvideo.sys

    2013-10-09 20:26:12 25944D2CC49E0A6C581D02A74B7D6645 527064 —-a-w- C:\Windows\System32\drivers\Wdf01000.sys

    2013-10-09 20:26:12 2352AB5F9F8F097BF9D41D5A4718A041 86016 —-a-w- C:\Windows\System32\drivers\usbcir.sys

    ====== C:\Windows\Tasks ======

    2013-10-16 18:58:05 E45B778F29D39F08A54C22A597D12463 3160 —-a-w- C:\Windows\system32\Tasks\{CC8EA935-4764-426B-BE59-8396E05652CF}

    2013-10-13 18:21:03 686D773E8B34CB65B8E3A89070FF0CB0 3144 —-a-w- C:\Windows\system32\Tasks\{386B0800-AB7F-46D2-BC70-D964CE6C88B3}

    ====== C:\Windows\Temp ======

    ======= C:\Program Files =====

    2013-10-16 18:52:13 ——– d—–w- C:\Program Files\RAR File Open Knife - Free Opener

    2013-10-13 18:37:13 ——– d—–w- C:\Program Files\WinDirStat

    2013-10-13 18:22:01 ——– d—–w- C:\Program Files\PirateBrowser 0.6b

    ======= C: =====

    ====== C:\Users\Olaf\AppData\Roaming ======

    2013-10-16 18:52:17 ——– d—–w- C:\Users\Olaf\AppData\Roaming\Philipp Winterberg

    2013-10-13 20:58:09 ——– d—–w- C:\Users\Olaf\AppData\Local\Programs

    2013-10-13 18:37:13 ——– d—–w- C:\Users\Olaf\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinDirStat

    2013-10-13 18:15:38 ——– d—–w- C:\Users\Olaf\AppData\Locallow\Unitech LLC

    ====== C:\Users\Olaf ======

    2013-10-16 18:52:13 ——– d—–w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RAR File Open Knife - Free Opener

    2013-10-16 18:51:53 320B26D2ACB88989528CA998824EB059 1653648 —-a-w- C:\Users\Olaf\Desktop\InstallRARFileOpenKnife.exe

    2013-10-14 20:00:00 69CA82A7482A00D8EE063D2B97FC4338 781383 —-a-w- C:\Users\Olaf\Downloads\RSIT.exe

    2013-10-14 17:13:17 E8D3E34FFDAF21DF7C09CBBBA5763237 2347384 —-a-w- C:\Users\Olaf\Downloads\esetsmartinstaller_enu.exe

    2013-10-13 20:50:17 31E39E9FF261030F71C0209C016580F4 1048960 —-a-w- C:\Users\Olaf\Downloads\adwcleaner.exe

    2013-10-13 18:37:13 ——– d—–w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinDirStat

    2013-10-13 18:36:46 3ABF1C149873E25D4E266225FBF37CBF 645729 —-a-w- C:\Users\Olaf\Downloads\windirstat1_1_2_setup.exe

    2013-10-13 18:30:21 30D0AD41CC60C6A62277BB350A1EBE4E 4369632 —-a-w- C:\Users\Olaf\Downloads\ccsetup406.exe

    2013-10-13 14:28:04 A23B66F7C3FDD5308FC729582A7C8101 31094527 —-a-w- C:\Users\Olaf\Downloads\PirateBrowser_0.6b.exe

    ====== C: exe-files ==

    2013-10-16 18:53:00 6A0F411CA91A97A709B98E114F4052D5 76344 —-a-w- C:\Users\Olaf\AppData\Local\Temp\ct3281675\statisticsStub.exe

    2013-10-16 18:53:00 6A0F411CA91A97A709B98E114F4052D5 76344 —-a-w- C:\Users\Olaf\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\J19C7WP1\statisticsstub.exe

    2013-10-16 18:52:39 12FD3FDD30842B7B335C8B3E984BEC2B 2336800 —-a-w- C:\Users\Olaf\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\J19C7WP1\SPSetup.exe

    2013-10-16 18:52:30 F3ADB29C2F8414BC394837D8FBD3712A 3734240 —-a-w- C:\Users\Olaf\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TDFDTZ3W\entrusted_wpf.exe

    2013-10-16 18:52:21 4AE5F34AB33261FEB8B94F5FFC8E8F19 73543 —-a-w- C:\Users\Olaf\AppData\Local\Temp\ct3281675\ctbe.exe

    2013-10-16 18:52:21 4AE5F34AB33261FEB8B94F5FFC8E8F19 73543 —-a-w- C:\Users\Olaf\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TDFDTZ3W\checktbexist.exe

    2013-10-16 18:52:18 3D5A9C21A5F482B02F8357E684D8111E 89192 —-a-w- C:\Users\Olaf\AppData\Local\Temp\ct3281675\stub.exe

    2013-10-16 18:52:13 D3B583D465B4FD3C684A26710632A75D 90674 —-a-w- C:\Program Files\RAR File Open Knife - Free Opener\uninstall.exe

    2013-10-16 18:51:53 A303F7BDEB2B08EC12D342A9C245DA75 2394184 —-a-w- C:\Users\Olaf\AppData\Local\Temp\Softonic_chr_1-8-19-3.exe

    2013-10-16 18:51:53 320B26D2ACB88989528CA998824EB059 1653648 —-a-w- C:\Users\Olaf\Desktop\InstallRARFileOpenKnife.exe

    2013-10-15 20:28:33 8F101DD2F46E59469FE0F599DA0530F2 2066272 —-a-w- C:\Program Files\Google\Update\Download\{4DC8B4CA-1BDA-483E-B5FA-D3C12E15B62D}\30.0.1599.101\30.0.1599.101_30.0.1599.69_chrome_updater.exe

    2013-10-14 20:01:14 9A2347903D6EDB84C10F288BC0578C1C 388608 —-a-w- C:\Program Files\Trend Micro\Olaf.exe

    2013-10-14 20:00:00 69CA82A7482A00D8EE063D2B97FC4338 781383 —-a-w- C:\Users\Olaf\Downloads\RSIT.exe

    2013-10-14 17:13:17 E8D3E34FFDAF21DF7C09CBBBA5763237 2347384 —-a-w- C:\Users\Olaf\Downloads\esetsmartinstaller_enu.exe

    2013-10-13 20:50:17 31E39E9FF261030F71C0209C016580F4 1048960 —-a-w- C:\Users\Olaf\Downloads\adwcleaner.exe

    2013-10-13 18:37:13 A127E6118B9DD2F9D5A7CC4D697A0105 47846 —-a-w- C:\Program Files\WinDirStat\Uninstall.exe

    2013-10-13 18:36:46 3ABF1C149873E25D4E266225FBF37CBF 645729 —-a-w- C:\Users\Olaf\Downloads\windirstat1_1_2_setup.exe

    2013-10-13 18:30:21 30D0AD41CC60C6A62277BB350A1EBE4E 4369632 —-a-w- C:\Users\Olaf\Downloads\ccsetup406.exe

    2013-10-13 18:22:04 AE15906A1D3AA006A003CD39A9089A6C 26520 —-a-w- C:\Program Files\PirateBrowser 0.6b\FirefoxPortable\App\Firefox\plugin-hang-ui.exe

    2013-10-13 18:22:04 A6FE3BD4E3FC9C5583C92DF311A9C258 276376 —-a-w- C:\Program Files\PirateBrowser 0.6b\FirefoxPortable\App\Firefox\piratefox.exe

    2013-10-13 18:22:04 9EE81D7F73AAC2D31A87CF06E7B62034 2315149 —-a-w- C:\Program Files\PirateBrowser 0.6b\App\tor.exe

    2013-10-13 18:22:04 8AB3A5CD234D2047E0A93830EBC57A40 32782 —-a-w- C:\Program Files\PirateBrowser 0.6b\Start PirateBrowser.exe

    2013-10-13 18:22:04 66BA3032A29B09466408C69CB4190AB7 6239727 —-a-w- C:\Program Files\PirateBrowser 0.6b\App\vidalia.exe

    2013-10-13 18:22:04 4CCDD8FE74C6094D026A15F285489CE8 249958 —-a-w- C:\Program Files\PirateBrowser 0.6b\FirefoxPortable\App\Bin\sqlite3.exe

    2013-10-13 18:22:04 254F08C0E70104FDFD72E58437CB4690 17304 —-a-w- C:\Program Files\PirateBrowser 0.6b\FirefoxPortable\App\Firefox\plugin-container.exe

    2013-10-13 18:22:04 16F7FC83A4E598B02908D9E37FB9C572 92056 —-a-w- C:\Program Files\PirateBrowser 0.6b\FirefoxPortable\App\Firefox\webapprt-stub.exe

    2013-10-13 14:28:04 A23B66F7C3FDD5308FC729582A7C8101 31094527 —-a-w- C:\Users\Olaf\Downloads\PirateBrowser_0.6b.exe

    2013-10-11 21:06:50 EB8EEB98D01B5D31898D8E53C3789832 59784 —-atw- C:\Program Files\Google\Update\1.3.21.165\GoogleUpdateBroker.exe

    2013-10-11 21:06:50 CEFEBDB9E274BD90C12D131ED25CC819 59784 —-atw- C:\Program Files\Google\Update\1.3.21.165\GoogleUpdateOnDemand.exe

    2013-10-11 21:06:50 4AFFF5FE4E69C8E7C5F1E4F3511301CF 818968 —-a-w- C:\Program Files\Google\Update\1.3.21.165\GoogleUpdateSetup.exe

    2013-10-11 21:06:39 CF7B0E597C1F34E528285495721DEEE9 237960 —-atw- C:\Program Files\Google\Update\1.3.21.165\GoogleCrashHandler.exe

    2013-10-11 21:06:39 0DC0DE2966A6DBA4CFBF6639DF44F5BA 319880 —-atw- C:\Program Files\Google\Update\1.3.21.165\GoogleCrashHandler64.exe

    2013-10-11 21:06:38 506708142BC63DABA64F2D3AD1DCD5BF 116648 —-atw- C:\Program Files\Google\Update\1.3.21.165\GoogleUpdate.exe

    2013-10-11 21:06:29 4AFFF5FE4E69C8E7C5F1E4F3511301CF 818968 —-a-w- C:\Program Files\Google\Update\Download\{430FD4D0-B729-4F61-AA34-91526481799D}\1.3.21.165\GoogleUpdateSetup.exe

    2013-10-10 21:38:50 4B78E9AE06F7C310E30EE2FA5B7EBC3C 1721296 —-a-w- C:\Program Files\Google\Google Toolbar\Component\SearchWithGoogleUpdate_C993F490EED40C1B.exe

    2013-10-10 21:38:43 BB4F6465EEB9ACAA5C60C36983740219 310352 —-a-w- C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarUser_32_4814EB429669E41D.exe

    2013-10-10 21:38:39 B9D8842FF3EDAC918039C6F62F322E9A 1073232 —-a-w- C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarManager_08875ABF44579E20.exe

    2013-10-10 21:37:42 A30351F539D71D6199BD2295CC234E96 531424 —-a-w- C:\Program Files\Google\Update\Download\{F69EABDD-A4BB-4555-BE7E-1EA5F59BBA24}\7.5.4601.54\GoogleToolbarInstaller_updater_signed.exe

    2013-10-10 21:30:04 E8433E4E65BDFB35DE5C2BFF745F1386 42496 —-a-w- C:\Windows\System32\ie4uinit.exe

    2013-10-10 21:30:04 58A43D9DFFF91C1457EC47BDCF969B59 71680 —-a-w- C:\Windows\System32\RegisterIEPKEYs.exe

    2013-10-10 21:30:00 D6B7DDB68436F13C3CAE2B92524F1FEC 770648 —-a-w- C:\Program Files\Internet Explorer\iexplore.exe

    2013-10-09 20:26:32 482C8CD985C727C7C78A5E9B320947F0 3969472 —-a-w- C:\Windows\System32\ntkrnlpa.exe

    2013-10-09 20:26:31 813A7F5A2D6D366EB3FFB643B851BCE5 3914176 —-a-w- C:\Windows\System32\ntoskrnl.exe

    === C: other files ==

    2013-10-09 20:26:36 FC6B21DB4B5B398AB93DBE59CBF11036 36352 —-a-w- C:\Windows\System32\DriverStore\FileRepository\sti.inf_x86_neutral_24eb5587941b03fb\usbscan.sys

    2013-10-09 20:26:36 FC6B21DB4B5B398AB93DBE59CBF11036 36352 —-a-w- C:\Windows\System32\drivers\usbscan.sys

    2013-10-09 20:26:36 F81BB7E487EDCEAB630A7EE66CF23913 338944 —-a-w- C:\Windows\System32\drivers\afd.sys

    2013-10-09 20:26:36 F1B27299F547D452EDAEF01FC187CB91 25728 —-a-w- C:\Windows\System32\DriverStore\FileRepository\input.inf_x86_neutral_1436b88c77b8881d\hidparse.sys

    2013-10-09 20:26:36 F1B27299F547D452EDAEF01FC187CB91 25728 —-a-w- C:\Windows\System32\drivers\hidparse.sys

    2013-10-09 20:26:36 CA59F7C570AF70BC174F477CFE2D9EE3 1294272 —-a-w- C:\Windows\System32\drivers\tcpip.sys

    2013-10-09 20:26:36 50ABE682EBE752EAF62B18790D6D491C 55808 —-a-w- C:\Windows\System32\DriverStore\FileRepository\input.inf_x86_neutral_1436b88c77b8881d\hidclass.sys

    2013-10-09 20:26:36 50ABE682EBE752EAF62B18790D6D491C 55808 —-a-w- C:\Windows\System32\drivers\hidclass.sys

    2013-10-09 20:26:34 007C0C8D5B01D82ACEB70431D15083F6 28160 —-a-w- C:\Windows\System32\DriverStore\FileRepository\mdmcpq.inf_x86_neutral_1965855805a8e768\usbser.sys

    2013-10-09 20:26:32 71BC35067CABC02C9453AEAA42B2E43E 729024 —-a-w- C:\Windows\System32\drivers\dxgkrnl.sys

    2013-10-09 20:26:19 445C354D772DFEBF46F73078C8C2C797 2348544 —-a-w- C:\Windows\System32\win32k.sys

    2013-10-09 20:26:14 21F4B24ACFC79A483515BD986DD9043F 115712 —-a-w- C:\Windows\System32\drivers\mrxdav.sys

    2013-10-09 20:26:12 DE014425522610BEDCA3821BB8C0F1D5 146816 —-a-w- C:\Windows\System32\DriverStore\FileRepository\usbvideo.inf_x86_neutral_b63436395ec126b7\usbvideo.sys

    2013-10-09 20:26:12 DE014425522610BEDCA3821BB8C0F1D5 146816 —-a-w- C:\Windows\System32\drivers\usbvideo.sys

    2013-10-09 20:26:12 A1977C315BF5691DA99235AA4A6907AF 80896 —-a-w- C:\Windows\System32\DriverStore\FileRepository\wdma_usb.inf_x86_neutral_8583111d879ac65d\USBAUDIO.sys

    2013-10-09 20:26:12 25944D2CC49E0A6C581D02A74B7D6645 527064 —-a-w- C:\Windows\System32\drivers\Wdf01000.sys

    2013-10-09 20:26:12 2352AB5F9F8F097BF9D41D5A4718A041 86016 —-a-w- C:\Windows\System32\DriverStore\FileRepository\usbcir.inf_x86_neutral_1a7503cad201feda\usbcir.sys

    2013-10-09 20:26:12 2352AB5F9F8F097BF9D41D5A4718A041 86016 —-a-w- C:\Windows\System32\drivers\usbcir.sys

    ==== Startup Registry Enabled ======================

    “Sidebar”=“%ProgramFiles%\Windows\Sidebar.exe /autoRun”

    “Sidebar”=“%ProgramFiles%\Windows\Sidebar.exe /autoRun”

    “ehTray.exe”=“C:\Windows\ehome\ehTray.exe”

    “SpybotSD TeaTimer”=“C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe”

    “TOSHIBA Online Product Information”=“C:\Program Files\TOSHIBA\Toshiba Online Product Information\TOPI.exe”

    “swg”=“C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe”

    “ConduitFloatingPlugin_kdfbddbdpnahdahmamlolacimfdbeckk”=“C:\Windows\system32\Rundll32.exe C:\Program Files\Conduit\CT3281675\plugins\TBVerifier.dll,RunConduitFloatingPlugin kdfbddbdpnahdahmamlolacimfdbeckk”

    “SearchProtect”=“C:\Users\Olaf\AppData\Roaming\SearchProtect\bin\cltmng.exe”

    “mctadmin”=“C:\Windows\System32\mctadmin.exe”

    “mctadmin”=“C:\Windows\System32\mctadmin.exe”

    “SynTPEnh”=“C:\Program Files\Synaptics\SynTP\SynTPEnh.exe”

    “RtHDVCpl”=“C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe”

    “Camera Assistant Software”=“C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe /start”

    “Google EULA Launcher”=“c:\Program Files\Google\Google EULA\GoogleEULALauncher.exe IE PA”

    “Google Quick Search Box”=“C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe /autorun”

    “GrooveMonitor”=“C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe”

    “Skytel”=“C:\Program Files\Realtek\Audio\HDA\Skytel.exe”

    “topi”=“C:\Program Files\TOSHIBA\Toshiba Online Product Information\topi.exe -startup”

    “IgfxTray”=“C:\Windows\system32\igfxtray.exe”

    “HotKeysCmds”=“C:\Windows\system32\hkcmd.exe”

    “Persistence”=“C:\Windows\system32\igfxpers.exe”

    “Sophos AutoUpdate Monitor”=“C:\Program Files\Sophos\AutoUpdate\almon.exe”

    “Malwarebytes Anti-Malware (reboot)”=“C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe /runcleanupscript”

    “Adobe ARM”=“C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe”

    “SunJavaUpdateSched”=“C:\Program Files\Common Files\Java\Java Update\jusched.exe”

    “SearchProtectAll”=“C:\Program Files\SearchProtect\bin\cltmng.exe”

    “00TCrdMain”=“%ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe ”

    “HSON”=“%ProgramFiles%\TOSHIBA\TBS\HSON.exe ”

    “SmoothView”=“%ProgramFiles%\Toshiba\SmoothView\SmoothView.exe ”

    “TPwrMain”=“%ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE”

    “ehTray.exe”=“C:\Windows\ehome\ehTray.exe”

    “SpybotSD TeaTimer”=“C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe”

    “TOSHIBA Online Product Information”=“C:\Program Files\TOSHIBA\Toshiba Online Product Information\TOPI.exe”

    “swg”=“C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe”

    “ConduitFloatingPlugin_kdfbddbdpnahdahmamlolacimfdbeckk”=“C:\Windows\system32\Rundll32.exe C:\Program Files\Conduit\CT3281675\plugins\TBVerifier.dll,RunConduitFloatingPlugin kdfbddbdpnahdahmamlolacimfdbeckk”

    “SearchProtect”=“C:\Users\Olaf\AppData\Roaming\SearchProtect\bin\cltmng.exe”

    “AppInit_DLLs”=“DLL, C:\\PROGRA~1\\Sophos\\SOPHOS~1\\SOPHOS~1.DLL”

    ==== Startup Folders ======================

    2008-08-19 11:40:54 1835 —-a-w- C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk

    2008-08-19 11:40:54 1835 —-a-w- C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk

    2010-07-18 07:11:29 1998 —-a-w- C:\Users\Gast\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk

    2010-04-18 06:45:21 1285 —-a-w- C:\Users\Olaf\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk

    2011-05-20 11:52:48 2165 —-a-w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Google Calendar Sync.lnk

    ==== Task Scheduler Jobs ======================

    C:\Windows\tasks\Ad-Aware Update (Weekly).job –a—— C:\Program Files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe

    C:\Windows\tasks\Adobe Flash Player Updater.job –a—— C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe

    C:\Windows\tasks\GoogleUpdateTaskMachineCore.job –a——

    C:\Windows\tasks\GoogleUpdateTaskMachineUA.job –a—— C:\Program Files\Google\Update\GoogleUpdate.exe

    ==== Other Scheduled Tasks ======================

    “C:\Windows\system32\tasks\0”

    “C:\Windows\system32\tasks\4567”

    “C:\Windows\system32\tasks\Ad-Aware Update (Weekly)”

    “C:\Windows\system32\tasks\Adobe Flash Player Updater”

    “C:\Windows\system32\tasks\CCleanerSkipUAC”

    “C:\Windows\system32\tasks\CreateChoiceProcessTask”

    “C:\Windows\system32\tasks\GoogleUpdateTaskMachineCore”

    “C:\Windows\system32\tasks\GoogleUpdateTaskMachineUA”

    “C:\Windows\system32\tasks\RunAsStdUser Task”

    “C:\Windows\system32\tasks\Your File Updater”

    “C:\Windows\system32\tasks\{EEAFE583-73C1-4497-8B1A-0D2BDD0EE94B}”

    ==== Firefox Extensions Registry ======================

    “{20a82645-c095-46ed-80e3-08825760534b}”=“C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension”

    ==== Firefox Extensions ======================

    ==== Firefox Plugins ======================

    Profilepath: C:\Users\Olaf\AppData\Roaming\Mozilla\Firefox\Profiles\s7zlkbof.default

    CFAF7B67C78D09D79688AEDCA3D090E2 - C:\Program Files\Google\Update\1.3.21.165\npGoogleUpdate3.dll - Google Update

    4BF70B35B943BD73BD6E13EB7C1BA4B3 - C:\Windows\system32\Macromed\Flash\NPSWF32_11_9_900_117.dll - Shockwave Flash

    69AA47F09AA281C7D3C7716CA7E283B4 - C:\Program Files\Adobe\Reader 11.0\Reader\browser\nppdf32.dll - Adobe Acrobat

    380F9A643A149B9030142E7171EFA91B - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll - Adobe Acrobat

    BE501CBC29B2025A263D80D399F1797A - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll - Silverlight Plug-In

    ABCB4A6EAB701C629378255ABCB308E5 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll - Java(TM) Platform SE 7 U25

    D7324EB1EDCB8990F8522DE0311359E9 - C:\Windows\system32\npdeployJava1.dll - Java Deployment Toolkit 7.0.250.17

    7550FC1ADE982582D5920BEA6430E3D4 - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll - Google Earth Plugin

    3B00376AE69AC2E815425E54DEBFF750 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll - Photo Gallery

    54BC55D3D9BD33A6CE38F811CF836794 - C:\Program Files\Google\Picasa3\npPicasa3.dll - Picasa

    24E990B1E6D55428001843CF7217DD81 - C:\Program Files\Microsoft\Office Live\npOLW.dll - Microsoft Office Live Plug-in for Firefox / Microsoft Office Live Plug-in for Firefox

    955C1332235A008ADF975D56A81507C1 - C:\Program Files\Logitech\Harmony Remote Driver\NprtHarmonyPlugin.dll - Harmony Firefox Plugin

    8DDF0253E783E740BF053E0FE7D8B6FE - C:\Windows\system32\Adobe\Director\np32dsw.dll - Shockwave for Director / Shockwave for Director

    625D0A824F513CE1CABB8861E97F2142 - C:\Program Files\Google\Picasa3\npPicasa2.dll - Picasa

    AB87EEFFD18F2BAAFC274E7075EA6C67 - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll - Windows Presentation Foundation / Windows Presentation Foundation

    3CB231F12674D3CB0AC1F5EDE9578E85 - C:\Windows\system32\npwmsdrm.dll - Microsoft® Windows Media Services

    B27CCB1168B1960AEC6E9D3E0E0F0D2A - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrlui.dll - Microsoft® Silverlight

    15E298B5EC5B89C5994A59863969D9FF - C:\Windows\system32\npmproxy.dll - Microsoft® Windows® Operating System

    ==== Chrome Look ======================

    HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions

    elchiiiejkobdbblfejjkbphbddgmljf - C:\Program Files\Softonic\Softonic\1.8.19.3\Softonic.crx

    kdfbddbdpnahdahmamlolacimfdbeckk - C:\Users\Olaf\AppData\Local\CRE\kdfbddbdpnahdahmamlolacimfdbeckk.crx

    HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\Extensions

    kdfbddbdpnahdahmamlolacimfdbeckk - C:\Users\Olaf\AppData\Local\CRE\kdfbddbdpnahdahmamlolacimfdbeckk.crx

    Google Docs - Olaf - Default\Extensions\aohghmighlieiainnegkcijnfilokake

    Google Drive - Olaf - Default\Extensions\apdfllckaahabafndbhieahigkjlhalf

    YouTube - Olaf - Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo

    Google Search - Olaf - Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf

    Softonic Chrome Toolbar - Olaf - Default\Extensions\elchiiiejkobdbblfejjkbphbddgmljf

    entrusted - Olaf - Default\Extensions\kdfbddbdpnahdahmamlolacimfdbeckk

    Chrome In-App Payments service - Olaf - Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda

    Gmail - Olaf - Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia

    ==== Chrome Fix ======================

    C:\Users\Olaf\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_app.mam.conduit.com_0.localstorage deleted successfully

    C:\Users\Olaf\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_app.mam.conduit.com_0.localstorage-journal deleted successfully

    C:\Users\Olaf\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_twitter.conduitapps.com_0.localstorage deleted successfully

    C:\Users\Olaf\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_twitter.conduitapps.com_0.localstorage-journal deleted successfully

    C:\Users\Olaf\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_nl.softonic.com_0.localstorage deleted successfully

    C:\Users\Olaf\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_nl.softonic.com_0.localstorage-journal deleted successfully

    C:\Users\Olaf\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_rar-file-open-knife.nl.softonic.com_0.localstorage deleted successfully

    C:\Users\Olaf\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_rar-file-open-knife.nl.softonic.com_0.localstorage-journal deleted successfully

    C:\Users\Olaf\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_search.softonic.com_0.localstorage deleted successfully

    C:\Users\Olaf\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_search.softonic.com_0.localstorage-journal deleted successfully

    C:\Users\Olaf\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_winrar.nl.softonic.com_0.localstorage deleted successfully

    C:\Users\Olaf\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_winrar.nl.softonic.com_0.localstorage-journal deleted successfully

    C:\Users\Olaf\AppData\Local\Google\Chrome\User Data\Default\Extensions\elchiiiejkobdbblfejjkbphbddgmljf deleted successfully

    C:\Users\Olaf\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_elchiiiejkobdbblfejjkbphbddgmljf_0.localstorage deleted successfully

    C:\Users\Olaf\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_elchiiiejkobdbblfejjkbphbddgmljf_0.localstorage-journal deleted successfully

    C:\Users\Olaf\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdfbddbdpnahdahmamlolacimfdbeckk deleted successfully

    C:\Users\Olaf\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_kdfbddbdpnahdahmamlolacimfdbeckk_0.localstorage deleted successfully

    C:\Users\Olaf\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_kdfbddbdpnahdahmamlolacimfdbeckk_0.localstorage-journal deleted successfully

    C:\Users\Olaf\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_kdfbddbdpnahdahmamlolacimfdbeckk_0 deleted successfully

    ==== Set IE to Default ======================

    Old Values:

    “Start Page”=“http://search.softonic.com/MOY00011/tb_v1?SearchSource=10&cc=&mi=701527fb00000000000000225f1e21a2”

    “Default_Page_URL”=“http://www.google.com/ig/redirectdomain?brand=TSEA&bmod=TSEA;”

    “Tabs”=“http://search.softonic.com/MOY00011/tb_v1/?SearchSource=15&cc=&mi=701527fb00000000000000225f1e21a2”

    New Values:

    “Default_Page_URL”=“http://go.microsoft.com/fwlink/?LinkId=69157”

    “Start Page”=“http://www.google.com”

    “Tabs”=“res://ieframe.dll/tabswelcome.htm”

    ==== All HKCU SearchScopes ======================

    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes

    “DefaultScope”=“{E6170430-8493-488C-BF9E-AF9759A852F4}”

    {0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url=“http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE10SR”

    {6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url=“http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}”

    {E6170430-8493-488C-BF9E-AF9759A852F4} Google Url=“http://www.google.com/search?source=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7GPEA_nl”

    ==== Reset Google Chrome ======================

    C:\Users\Olaf\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully

    C:\Users\Olaf\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully

    ==== Deleting CLSID Registry Keys ======================

    HKEY_CLASSES_ROOT\CLSID\{5018CFD2-804D-4C99-9F81-25EAEA2769DE} deleted successfully

    HKEY_CLASSES_ROOT\CLSID\{E87806B5-E908-45FD-AF5E-957D83E58E68} deleted successfully

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E87806B5-E908-45FD-AF5E-957D83E58E68} deleted successfully

    ==== Deleting CLSID Registry Values ======================

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{5018CFD2-804D-4C99-9F81-25EAEA2769DE} deleted successfully

    ==== Deleting Registry Keys ======================

    HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\elchiiiejkobdbblfejjkbphbddgmljf deleted successfully

    HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\kdfbddbdpnahdahmamlolacimfdbeckk deleted successfully

    HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\Extensions\kdfbddbdpnahdahmamlolacimfdbeckk deleted successfully

    ==== HijackThis Entries ======================

    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

    O1 - Hosts: ::1 localhost

    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll

    O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll

    O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll

    O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll

    O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll

    O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll

    O4 - HKLM\..\Run: C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

    O4 - HKLM\..\Run: C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe

    O4 - HKLM\..\Run: %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe

    O4 - HKLM\..\Run: “C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe” /start

    O4 - HKLM\..\Run: c:\Program Files\Google\Google EULA\GoogleEULALauncher.exe IE PA

    O4 - HKLM\..\Run: “C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe” /autorun

    O4 - HKLM\..\Run: “C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe”

    O4 - HKLM\..\Run: %ProgramFiles%\TOSHIBA\TBS\HSON.exe

    O4 - HKLM\..\Run: C:\Program Files\Realtek\Audio\HDA\Skytel.exe

    O4 - HKLM\..\Run: %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe

    O4 - HKLM\..\Run: C:\Program Files\TOSHIBA\Toshiba Online Product Information\topi.exe -startup

    O4 - HKLM\..\Run: %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE

    O4 - HKLM\..\Run: C:\Windows\system32\igfxtray.exe

    O4 - HKLM\..\Run: C:\Windows\system32\hkcmd.exe

    O4 - HKLM\..\Run: C:\Windows\system32\igfxpers.exe

    O4 - HKLM\..\Run: C:\Program Files\Sophos\AutoUpdate\almon.exe

    O4 - HKLM\..\Run: “C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe” /runcleanupscript

    O4 - HKLM\..\Run: “C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe”

    O4 - HKLM\..\Run: “C:\Program Files\Common Files\Java\Java Update\jusched.exe”

    O4 - HKLM\..\Run: C:\Program Files\SearchProtect\bin\cltmng.exe

    O4 - HKCU\..\Run: C:\Windows\ehome\ehTray.exe

    O4 - HKCU\..\Run: C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

    O4 - HKCU\..\Run: C:\Program Files\TOSHIBA\Toshiba Online Product Information\TOPI.exe

    O4 - HKCU\..\Run: “C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe”

    O4 - HKCU\..\Run: “C:\Windows\system32\Rundll32.exe” “C:\Program Files\Conduit\CT3281675\plugins\TBVerifier.dll”,RunConduitFloatingPlugin kdfbddbdpnahdahmamlolacimfdbeckk

    O4 - HKCU\..\Run: C:\Users\Olaf\AppData\Roaming\SearchProtect\bin\cltmng.exe

    O4 - HKUS\S-1-5-19\..\Run: %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User ‘LOCAL SERVICE’)

    O4 - HKUS\S-1-5-19\..\RunOnce: C:\Windows\System32\mctadmin.exe (User ‘LOCAL SERVICE’)

    O4 - HKUS\S-1-5-20\..\Run: %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User ‘NETWORK SERVICE’)

    O4 - HKUS\S-1-5-20\..\RunOnce: C:\Windows\System32\mctadmin.exe (User ‘NETWORK SERVICE’)

    O4 - .DEFAULT User Startup: TRDCReminder.lnk = C:\Program Files\TOSHIBA\TRDCReminder\TRDCReminder.exe (User ‘Default user’)

    O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE

    O4 - Global Startup: Google Calendar Sync.lnk = C:\Program Files\Google\Google Calendar Sync\GoogleCalendarSync.exe

    O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200

    O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll

    O9 - Extra ‘Tools’ menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll

    O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll

    O9 - Extra ‘Tools’ menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll

    O9 - Extra button: eBay - {76577871-04EC-495E-A12B-91F7C3600AFA} - http://www.webtip.ch/cgi-bin/toshiba/tracker_url2.pl?NL (file missing)

    O9 - Extra button: Amazon.co.uk - {8A918C1D-E123-4E36-B562-5C1519E434CE} - http://www.amazon.co.uk/exec/obidos/redirect-home?tag=Toshibaukbholink-21&site=home (file missing)

    O9 - Extra button: Onderzoek - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL

    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll

    O9 - Extra ‘Tools’ menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll

    O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll

    O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll

    O10 - Unknown file in Winsock LSP: c:\programdata\sophos\web intelligence\swi_ifslsp.dll

    O10 - Unknown file in Winsock LSP: c:\programdata\sophos\web intelligence\swi_ifslsp.dll

    O10 - Unknown file in Winsock LSP: c:\programdata\sophos\web intelligence\swi_ifslsp.dll

    O10 - Unknown file in Winsock LSP: c:\programdata\sophos\web intelligence\swi_ifslsp.dll

    O10 - Unknown file in Winsock LSP: c:\programdata\sophos\web intelligence\swi_ifslsp.dll

    O10 - Unknown file in Winsock LSP: c:\programdata\sophos\web intelligence\swi_ifslsp.dll

    O10 - Unknown file in Winsock LSP: c:\programdata\sophos\web intelligence\swi_ifslsp.dll

    O10 - Unknown file in Winsock LSP: c:\programdata\sophos\web intelligence\swi_ifslsp.dll

    O10 - Unknown file in Winsock LSP: c:\programdata\sophos\web intelligence\swi_ifslsp.dll

    O11 - Options group: Accelerated graphics

    O13 - Gopher Prefix:

    O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - http://download.eset.com/special/eos/OnlineScanner.cab

    O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game.zylom.com/activex/zylomgamesplayer.cab

    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab

    O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll

    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL

    O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll

    O20 - AppInit_DLLs: DLL, C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL

    O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe

    O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe

    O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe

    O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe

    O23 - Service: Google Update-service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe

    O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

    O23 - Service: Sophos Anti-Virus status reporter (SAVAdminService) - Sophos Limited - C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe

    O23 - Service: Sophos Anti-Virus (SAVService) - Sophos Limited - C:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe

    O23 - Service: ServiceLayer - Nokia - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe

    O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe

    O23 - Service: SmartFaceVWatchSrv - Toshiba - C:\Program Files\TOSHIBA\SmartFaceV\SmartFaceVWatchSrv.exe

    O23 - Service: Sophos AutoUpdate Service - Sophos Limited - C:\Program Files\Sophos\AutoUpdate\ALsvc.exe

    O23 - Service: Sophos Web Control Service - Sophos Limited - C:\Program Files\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe

    O23 - Service: Sophos Web Intelligence Service (swi_service) - Sophos Limited - C:\Program Files\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe

    O23 - Service: Sophos Web Intelligence Update (swi_update) - Sophos Limited - C:\ProgramData\Sophos\Web Intelligence\swi_update.exe

    O23 - Service: TOSHIBA Navi Support Service (TNaviSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe

    O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe

    O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe

    O23 - Service: TOSHIBA SMART Log Service - TOSHIBA Corporation - C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe

    O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe

    ==== Empty IE Cache ======================

    C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

    C:\Users\Gast\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

    C:\Users\Gast\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully

    C:\Users\Olaf\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

    C:\Users\Olaf\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully

    C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

    C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

    C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

    C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully

    C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

    ==== Empty FireFox Cache ======================

    C:\Users\Olaf\AppData\Local\Mozilla\Firefox\Profiles\s7zlkbof.default\Cache emptied successfully

    ==== Empty Chrome Cache ======================

    C:\Users\Olaf\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully

    ==== Empty All Flash Cache ======================

    Flash Cache Emptied Successfully

    ==== Empty All Java Cache ======================

    Java Cache cleared successfully

    ==== After Reboot ======================

    ==== Empty Temp Folders ======================

    C:\Windows\Temp successfully emptied

    C:\Users\Olaf\AppData\Local\Temp successfully emptied

    ==== Empty Recycle Bin ======================

    C:\$RECYCLE.BIN successfully emptied

    ==== EOF on wo 16-10-2013 at 21:48:42,28 ======================

  • jembee

    @ Jos

    Check! "D

  • Jos H

    Opgelost je profiel. (tu)

  • fazantje

    Hoi Olaf,

    Dit was al een hele flinke opruiming qua ividi en de bekende besmettingssite softsonic.

    Hoe staat het nu met het probleem?

    Groetjes Huib;)

  • jembee

    Was inderdaad een grote stap! het lijkt erop dat ik ervan verlost ben.

    Wel krijg ik sindsdien bij het opstarten elke keer de volgende foutmelding:

    "Er is een probleem opgetreden tijdens het starten van C:\programfiles\Conduit\CT3281675\plugins\TBVerifier.dll

    Kan opgegeven module niet vinden."

    Zegt dit jou iets?

  • Ben

    Hallo,

    Voer zoek.exe nogmaals uit:

    Schakel je antivirus- en antispywareprogramma's uit, mogelijk kunnen ze in conflict komen met zoek.zip

    Klik met de rechtermuisknop op Zoek.zip en klik op de optie “Alles uitpakken”.

    Dubbelklik vervolgens op Zoek.exe om de tool te starten.

    Kopieer nu onderstaande code en plak die in het grote invulvenster:

    ;r

    “ConduitFloatingPlugin_kdfbddbdpnahdahmamlolacimfdbeckk”=-;r

    “SearchProtect”=-;r

    C:\Users\Olaf\AppData\Roaming\SearchProtect;fs

    C:\Program Files\Conduit;fs

    ;r

    “ConduitFloatingPlugin_kdfbddbdpnahdahmamlolacimfdbeckk”=-;r

    “SearchProtect”=-;r

    C:\Program Files\PirateBrowser 0.6b;fs

    C:\Users\Olaf\Downloads\PirateBrowser_0.6b.exe;f

    emptyfolderscheck;delete

    autoclean;

    resethosts;

    Klik nu op de knop “Run script”.

    Wacht nu geduldig af tot er een logje opent (dit kan na een herstart zijn als het nodig is).

    Mocht na de herstart geen logje verschijnen, start zoek.exe dan opnieuw, de log verschijnt dan alsnog.

    Post nu de inhoud van het geopende logje in het volgende bericht en vertel hoe het is.

  • jembee

    Ik was het afgelopen weekend…en de komende dagen niet in staat om dit verder op te pakken. Dit is geen desinteresse. Dit is een leuk, druk leven hebben. haha. Ik laat van de week weer horen hoe het gegaan is!

Dit topic is gesloten, er kunnen geen reacties meer worden geplaatst.