trage pc en heel veel reclame

  • sjaak

    Mijn pc is heel erg traag en er is heel veel reclame in firefox. Wie kan mij helpen?

    Malwarebytes Anti-Malware

    www.malwarebytes.org

    Scan Date: 26-8-2014

    Scan Time: 22:01:53

    Logfile:

    Administrator: No

    Version: 2.00.2.1012

    Malware Database: v2014.08.26.07

    Rootkit Database: v2014.08.21.01

    License: Free

    Malware Protection: Disabled

    Malicious Website Protection: Disabled

    Self-protection: Disabled

    OS: Windows 8.1

    CPU: x64

    File System: NTFS

    User: Imka

    Scan Type: Threat Scan

    Result: Completed

    Objects Scanned: 287125

    Time Elapsed: 40 min, 5 sec

    Memory: Enabled

    Startup: Enabled

    Filesystem: Enabled

    Archives: Enabled

    Rootkits: Disabled

    Heuristics: Enabled

    PUP: Enabled

    PUM: Enabled

    Processes: 0

    (No malicious items detected)

    Modules: 0

    (No malicious items detected)

    Registry Keys: 45

    PUP.Optional.MyScrapNook.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{23119123-0854-469D-807A-171568457991}, Delete-on-Reboot, ,

    PUP.Optional.MyScrapNook.A, HKLM\SOFTWARE\CLASSES\TypeLib\{03119103-0854-469D-807A-171568457991}, Quarantined, ,

    PUP.Optional.CrossRider.A, HKLM\SOFTWARE\CLASSES\CrossriderApp0062846.BHO, Delete-on-Reboot, ,

    PUP.Optional.CrossRider.A, HKLM\SOFTWARE\CLASSES\CrossriderApp0062846.BHO.1, Delete-on-Reboot, ,

    PUP.Optional.CrossRider.A, HKLM\SOFTWARE\CLASSES\CrossriderApp0062846.Sandbox, Delete-on-Reboot, ,

    PUP.Optional.CrossRider.A, HKLM\SOFTWARE\CLASSES\CrossriderApp0062846.Sandbox.1, Delete-on-Reboot, ,

    PUP.Optional.CrossRider.A, HKLM\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\30935, Delete-on-Reboot, ,

    PUP.Optional.HDPlus, HKLM\SOFTWARE\WOW6432NODE\HD+v2.1, Delete-on-Reboot, ,

    PUP.Optional.CrossRider.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CrossriderApp0062846.BHO, Delete-on-Reboot, ,

    PUP.Optional.CrossRider.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CrossriderApp0062846.BHO.1, Delete-on-Reboot, ,

    PUP.Optional.CrossRider.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CrossriderApp0062846.Sandbox, Delete-on-Reboot, ,

    PUP.Optional.CrossRider.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CrossriderApp0062846.Sandbox.1, Delete-on-Reboot, ,

    PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\GLOBALUPDATE\UPDATE, Delete-on-Reboot, ,

    PUP.Optional.CrossRider.A, HKLM\SOFTWARE\WOW6432NODE\INSTALLEDBROWSEREXTENSIONS\30935, Delete-on-Reboot, ,

    PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLAPLUGINS\@staging.google.com/globalUpdate Update;version=10, Delete-on-Reboot, ,

    PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLAPLUGINS\@staging.google.com/globalUpdate Update;version=4, Delete-on-Reboot, ,

    PUP.Optional.GlobalUpdate.T, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\globalUpdate, Delete-on-Reboot, ,

    PUP.Optional.GlobalUpdate.T, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\globalUpdatem, Delete-on-Reboot, ,

    PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\GOOGLEUPDATE.EXE, Delete-on-Reboot, ,

    PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\GOOGLEUPDATE.EXE, Delete-on-Reboot, ,

    PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{5645E0E7-FC12-43BF-A6E4-F9751942B298}, Delete-on-Reboot, ,

    PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\CLASSES\globalUpdate.OneClickCtrl.10, Delete-on-Reboot, ,

    PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdate.OneClickCtrl.10, Delete-on-Reboot, ,

    PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{5645E0E7-FC12-43BF-A6E4-F9751942B298}, Delete-on-Reboot, ,

    PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{5645E0E7-FC12-43BF-A6E4-F9751942B298}, Delete-on-Reboot, ,

    PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}, Delete-on-Reboot, ,

    PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\CLASSES\globalUpdate.Update3WebControl.4, Delete-on-Reboot, ,

    PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdate.Update3WebControl.4, Delete-on-Reboot, ,

    PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}, Delete-on-Reboot, ,

    PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}, Delete-on-Reboot, ,

    PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}, Delete-on-Reboot, ,

    PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{E0ADB535-D7B5-4D8B-B15D-578BDD20D76A}, Delete-on-Reboot, ,

    PUP.Optional.HDPlus, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{11111111-1111-1111-1111-110611281146}, Delete-on-Reboot, ,

    PUP.Optional.HDPlus, HKLM\SOFTWARE\CLASSES\TYPELIB\{44444444-4444-4444-4444-440644284446}, Delete-on-Reboot, ,

    PUP.Optional.HDPlus, HKLM\SOFTWARE\CLASSES\INTERFACE\{55555555-5555-5555-5555-550655285546}, Delete-on-Reboot, ,

    PUP.Optional.HDPlus, HKLM\SOFTWARE\CLASSES\INTERFACE\{66666666-6666-6666-6666-660666286646}, Delete-on-Reboot, ,

    PUP.Optional.HDPlus, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{55555555-5555-5555-5555-550655285546}, Delete-on-Reboot, ,

    PUP.Optional.HDPlus, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{66666666-6666-6666-6666-660666286646}, Delete-on-Reboot, ,

    PUP.Optional.HDPlus, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{44444444-4444-4444-4444-440644284446}, Delete-on-Reboot, ,

    PUP.Optional.HDPlus, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{11111111-1111-1111-1111-110611281146}, Delete-on-Reboot, ,

    PUP.Optional.HDPlus, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{11111111-1111-1111-1111-110611281146}, Delete-on-Reboot, ,

    PUP.Optional.HDPlus, HKLM\SOFTWARE\CLASSES\CLSID\{11111111-1111-1111-1111-110611281146}, Delete-on-Reboot, ,

    PUP.Optional.HDPlus, HKLM\SOFTWARE\CLASSES\CLSID\{22222222-2222-2222-2222-220622282246}, Delete-on-Reboot, ,

    PUP.Optional.HDPlus, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{22222222-2222-2222-2222-220622282246}, Delete-on-Reboot, ,

    PUP.Optional.HDPlus, HKLM\SOFTWARE\CLASSES\CLSID\{11111111-1111-1111-1111-110611281146}\INPROCSERVER32, Delete-on-Reboot, ,

    Registry Values: 1

    PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\GLOBALUPDATE\UPDATE|path, C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe, Delete-on-Reboot,

    Registry Data: 0

    (No malicious items detected)

    Folders: 67

    PUP.Optional.eSafe.A, C:\ProgramData\eSafe\log, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Users\Sjaak\AppData\Roaming\Desk 365, Quarantined, ,

    PUP.Optional.Desk365.A, C:\Users\Sjaak\AppData\Roaming\Desk 365\desk_bkg, Quarantined, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\desk_bkg, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\awp, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\cmn, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\notify, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\tips, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\tips\en_us, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\tips\es_es, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\tips\pt_br, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\tips\tr_tr, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\upgrade, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\language, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\language\en_us, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\language\zh_cn, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\language\zh_tw, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\layout, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\layout\default, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\style, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\uninstaller, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\update, Delete-on-Reboot, ,

    PUP.Optional.FreeHDSport.A, C:\Program Files (x86)\FreeHDSport TV, Delete-on-Reboot, ,

    PUP.Optional.FreeHDSport.A, C:\Program Files (x86)\FreeHDSport.TV, Delete-on-Reboot, ,

    PUP.Optional.337Technologies.A, C:\Program Files (x86)\Common Files\337\libcef, Delete-on-Reboot, ,

    PUP.Optional.337Technologies.A, C:\Program Files (x86)\Common Files\337\libcef\1.1364.1123, Delete-on-Reboot, ,

    PUP.Optional.337Technologies.A, C:\Program Files (x86)\Common Files\337\libcef\1.1364.1123\locales, Delete-on-Reboot, ,

    PUP.Optional.PlusHD.A, C:\Program Files (x86)\Plus-HD-2.2, Delete-on-Reboot, ,

    PUP.Optional.FreeHD.A, C:\Program Files (x86)\FirstRowSportApp.com, Delete-on-Reboot, ,

    PUP.Optional.FreeHD.A, C:\Users\Sjaak\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FirstRowSportApp.com, Quarantined, ,

    PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update, Delete-on-Reboot, ,

    PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\1.3.25.0, Delete-on-Reboot, ,

    PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\Download, Delete-on-Reboot, ,

    PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\Install, Delete-on-Reboot, ,

    PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\Offline, Delete-on-Reboot, ,

    PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\Offline\{CA703833-C3B2-44F5-BFC2-BA78FEE1FF49}, Delete-on-Reboot, ,

    PUP.Optional.GlobalUpdate.A, C:\Users\Sjaak\AppData\Local\Temp\comh.389436, Quarantined, ,

    PUP.Optional.HDPlus, C:\Program Files (x86)\HD+v2.1, Delete-on-Reboot, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\chrome, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\chrome\content, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\chrome\content\api, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\chrome\content\core, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\defaults, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\defaults\preferences, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\extensionData, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\extensionData\plugins, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\extensionData\userCode, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\locale, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\locale\en-US, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\skin, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\chrome, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\chrome\content, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\chrome\content\api, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\chrome\content\core, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\defaults, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\defaults\preferences, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\extensionData, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\extensionData\plugins, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\extensionData\userCode, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\locale, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\locale\en-US, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\skin, Quarantined, ,

  • Sjaak

    Files: 574

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Local\Temp\setup.exe, Quarantined, ,

    PUP.Optional.OpenCandy, C:\Users\Sjaak\AppData\Local\Temp\FreemakeVideoConverter_4.1.1.4.exe, Quarantined, ,

    PUP.Optional.OpenCandy, C:\Users\Imka\Downloads\FreemakeVideoConverterSetup.exe, Quarantined, ,

    PUP.Optional.Softonic.A, C:\Users\Imka\Downloads\SoftonicDownloader_voor_avidemux.exe, Quarantined, ,

    PUP.Optional.Softonic.A, C:\Users\Imka\Downloads\SoftonicDownloader_voor_gimp.exe, Quarantined, ,

    PUP.Optional.Softonic.A, C:\Users\Imka\Downloads\SoftonicDownloader_voor_makeitone-mp3-album-maker.exe, Quarantined, ,

    PUP.Optional.Softonic, C:\Users\Imka\Downloads\SoftonicDownloader_voor_picasa.exe, Quarantined, ,

    PUP.Optional.Softonic.A, C:\Users\Imka\Downloads\SoftonicDownloader_voor_vso-convertxtodvd.exe, Quarantined, ,

    PUP.Optional.Softonic.A, C:\Users\Imka\Downloads\SoftonicDownloader_voor_winrar.exe, Quarantined, ,

    PUP.Optional.Bandoo.A, C:\Users\Imka\Downloads\iMeshSetup-r1484-w-bf.exe, Quarantined, ,

    PUP.Optional.Bandoo.A, C:\Users\Imka\Downloads\iMeshSetup-r1489-w-bf.exe, Quarantined, ,

    PUP.Optional.eSafe.A, C:\ProgramData\eSafe\log\eGdpSvc.LOG, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Users\Sjaak\AppData\Roaming\Desk 365\promote.xml, Quarantined, ,

    PUP.Optional.Desk365.A, C:\Users\Sjaak\AppData\Roaming\Desk 365\accelerate, Quarantined, ,

    PUP.Optional.Desk365.A, C:\Users\Sjaak\AppData\Roaming\Desk 365\desk_bkg_list.xml, Quarantined, ,

    PUP.Optional.Desk365.A, C:\Users\Sjaak\AppData\Roaming\Desk 365\firstrun, Quarantined, ,

    PUP.Optional.Desk365.A, C:\Users\Sjaak\AppData\Roaming\Desk 365\desk_bkg\desk_bkg_1.png, Quarantined, ,

    PUP.Optional.Desk365.A, C:\Users\Sjaak\AppData\Roaming\Desk 365\desk_bkg\desk_bkg_2.png, Quarantined, ,

    PUP.Optional.Desk365.A, C:\Users\Sjaak\AppData\Roaming\Desk 365\desk_bkg\desk_bkg_3.png, Quarantined, ,

    PUP.Optional.Desk365.A, C:\Users\Sjaak\AppData\Roaming\Desk 365\desk_bkg\desk_bkg_4.png, Quarantined, ,

    PUP.Optional.Desk365.A, C:\Users\Sjaak\AppData\Roaming\Desk 365\desk_bkg\desk_bkg_5.png, Quarantined, ,

    PUP.Optional.Desk365.A, C:\Users\Sjaak\AppData\Roaming\Desk 365\desk_bkg\desk_bkg_default.png, Quarantined, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\promote.xml, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\desk_bkg_list.xml, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\desk_list.xml, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\main, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\process_mgr.xml, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\recent.xml, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\svc.conf, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\desk_bkg\desk_bkg_1.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\desk_bkg\desk_bkg_2.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\desk_bkg\desk_bkg_3.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\desk_bkg\desk_bkg_4.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\desk_bkg\desk_bkg_5.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\desk_bkg\desk_bkg_default.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\accelerate_button_bkg.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\add_button.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\add_flash.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\add_shortcut.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\add_shortcut_mouseover.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\app_icon.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\app_menu.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\app_screen.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\arrow_right.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\bg_hover.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\bg_pushed.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\bug.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\button_delete.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\button_selected.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\button_skin.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\change_skin.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\check_checked.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\check_intermediate.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\cloud_flash.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\collectlnkdlg.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\combo_skin.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\combo_skin_op.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\customize.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\customize_bk.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\custom_screen.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\DeskBkgnd.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\deskbtnbk.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\desktopmasks_bk.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\desk_about_bg.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\desk_close.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\desk_cmd_list.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\desk_default_bk.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\desk_edit.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\desk_menu.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\desk_more.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\desk_skin.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\DlgBkgnd.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\edesk_hover.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\edesk_hover_small.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\edesk_normal.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\edit_skin.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\edit_skin_op.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\finding.gif, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\gl_res.xml, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\horizontal_line.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\hscroll.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\icon_Tip.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\improve_arrow.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\indicator.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\arrow_left.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\check_uncheck.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\delete_button.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\desk_fbar.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\installing1.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\large-arrow.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\pic-warning.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\resource.xml, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\SettingBk.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\toolbar_tips_left.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\installing2.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\installing_bg.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\install_back.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\install_button_skin.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\install_check_checked.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\install_check_intermediate.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\install_check_uncheck.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\install_hover.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\install_logo.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\install_normal.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\install_resource.xml, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\large_add_icon.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\line-foot.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\line-top.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\line_ver.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\loading.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\menuitem_selbk.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\menu_bk.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\msg_btn_close.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\msg_center.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\new_icon.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\new_icon_xp.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\nextpage.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\nothing.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\num.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\number.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\PageBtnBkg.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\PageNavigate.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\patch_file_icon.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\percent_sign.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\pic-error.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\pic-info.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\pic-question.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\popup_dialog_bk.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\pop_msg_bk.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\prepage.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\previewdialog.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\progressbar_bk.bmp, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\progressbar_bk.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\progressbar_image.bmp, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\progressbar_image.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\progress_bk.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\progress_meter.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\radio_normal.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\radio_selected.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\resclear_best_tip_bkg.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\resclear_footer_bkg.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\resclear_green_check.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\resclear_main_bkg.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\resclear_tip_bkg.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\resource_usage_progress_bkg.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\resource_usage_progress_green.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\resource_usage_progress_red.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\resource_usage_progress_yellow.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\return_bk.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\rocket_ship.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\sc_button.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\sc_line.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\selected.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\shortcut_Tip.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\shutdown_button_bkg.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\shutdown_more_button_bkg.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\SkinMgr_bg.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\soft_desk.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\spliter_bar_bk_left.bmp, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\spliter_bar_bk_right.bmp, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\spliter_skin.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\start_menu_bk.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\switch_screen.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\sys_close.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\sys_imglist.bmp, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\sys_max.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\sys_min.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\sys_restore.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\sys_setting.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\title_bar.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\toolbar_tips_bottom.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\toolbar_tips_right.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\toolbar_tips_top.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\vertical_border.bmp, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\vertical_line.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\vscroll.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\web_menu.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\web_screen.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\WIN7_bjSmall_X.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\WIN7_bjSmall_Y.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\WIN7_bj_X.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\WIN7_bj_Y.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\wp_bk.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\wp_meter.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\XP_bj_hover.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\XP_bj_normal.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\awp\1.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\awp\2.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\awp\3.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\cmn\game_bk_wnd.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\cmn\game_close.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\cmn\game_hide.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\cmn\game_max.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\cmn\game_min.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\cmn\game_restore.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\cmn\game_system.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\cmn\menu_bg.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\cmn\menu_iconlist.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\cmn\menu_item_over.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\cmn\pic-error.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\cmn\pic-info.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\cmn\pic-question.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\cmn\pic-warning.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\cmn\popup_dialog_bk.bmp, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\cmn\prepare.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\notify\notify_bg.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\notify\notify_close.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\tips\play.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\tips\en_us\desk_tip1.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\tips\en_us\desk_tip2.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\tips\en_us\desk_tip3.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\tips\en_us\help1.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\tips\en_us\help2.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\tips\en_us\help3.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\tips\en_us\start.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\tips\en_us\tips_click_here.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\tips\es_es\desk_tip1.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\tips\es_es\desk_tip2.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\tips\es_es\desk_tip3.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\tips\es_es\help1.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\tips\es_es\help2.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\tips\es_es\help3.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\tips\es_es\start.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\tips\es_es\tips_click_here.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\tips\pt_br\desk_tip1.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\tips\pt_br\desk_tip2.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\tips\pt_br\desk_tip3.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\tips\pt_br\help1.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\tips\pt_br\help2.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\tips\pt_br\help3.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\tips\pt_br\start.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\tips\pt_br\tips_click_here.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\tips\tr_tr\desk_tip1.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\tips\tr_tr\desk_tip2.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\tips\tr_tr\desk_tip3.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\tips\tr_tr\help1.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\tips\tr_tr\help2.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\tips\tr_tr\help3.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\tips\tr_tr\start.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\tips\tr_tr\tips_click_here.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\image\default\upgrade\start.png, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\language\protocol.txt, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\layout\default\desk_helptip.xml, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\layout\default\add_shortcut.xml, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\layout\default\add_shortcut_tip.xml, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\layout\default\auto_start.xml, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\layout\default\bug_report.xml, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\layout\default\delete_tip.xml, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\layout\default\desk.xml, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\layout\default\desk_about.xml, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\layout\default\desk_bkg.xml, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\layout\default\desk_collect_lnk.xml, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\layout\default\desk_help.xml, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\layout\default\desk_hover_dlg.xml, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\layout\default\desk_mgr.xml, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\layout\default\desk_msgbox.xml, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\layout\default\desk_rename.xml, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\layout\default\desk_resclear_besttip.xml, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\layout\default\desk_resclear_main.xml, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\layout\default\desk_resclear_tip.xml, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\layout\default\desk_settings.xml, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\layout\default\desk_set_url.xml, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\layout\default\gamelogin.xml, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\layout\default\gl_game.xml, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\layout\default\gl_newwindow.xml, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\layout\default\import_shortcut.xml, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\layout\default\install_msgbox.xml, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\layout\default\languageSelect.xml, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\layout\default\msgbox.xml, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\layout\default\msg_center.xml, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\layout\default\popMsgBox.xml, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\layout\default\pop_context.xml, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\layout\default\pop_message.xml, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\layout\default\pop_standard.xml, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\layout\default\set_res_used_percent.xml, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\layout\default\shutdown_tip.xml, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\layout\default\uninsteDesk.xml, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\layout\default\uninstgl.xml, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\layout\default\update.xml, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\layout\default\upgrade_guide.xml, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\style\gl_style.xml, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\style\install_style.xml, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\style\style.xml, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\uninstaller\eDesk.inst, Delete-on-Reboot, ,

    PUP.Optional.Desk365.A, C:\Program Files (x86)\Desk 365\uninstaller\gamelogin.inst, Delete-on-Reboot, ,

    PUP.Optional.FreeHDSport.A, C:\Program Files (x86)\FreeHDSport TV\background.html, Delete-on-Reboot, ,

    PUP.Optional.FreeHDSport.A, C:\Program Files (x86)\FreeHDSport TV\Installer.log, Delete-on-Reboot, ,

    PUP.Optional.FreeHDSport.A, C:\Program Files (x86)\FreeHDSport.TV\freehdsporttv10.crx, Delete-on-Reboot, ,

    PUP.Optional.qvo6.A, C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\qvo6.xml, Delete-on-Reboot, ,

    PUP.Optional.CrossRider.T, C:\Windows\Tasks\c7d50b1d-2690-4014-92c0-4801c6396a16-1.job, Delete-on-Reboot, ,

    PUP.Optional.CrossRider.T, C:\Windows\Tasks\c7d50b1d-2690-4014-92c0-4801c6396a16-11.job, Delete-on-Reboot, ,

    PUP.Optional.CrossRider.T, C:\Windows\Tasks\c7d50b1d-2690-4014-92c0-4801c6396a16-2.job, Delete-on-Reboot, ,

    PUP.Optional.CrossRider.T, C:\Windows\Tasks\c7d50b1d-2690-4014-92c0-4801c6396a16-3.job, Delete-on-Reboot, ,

    PUP.Optional.CrossRider.T, C:\Windows\Tasks\c7d50b1d-2690-4014-92c0-4801c6396a16-4.job, Delete-on-Reboot, ,

    PUP.Optional.CrossRider.T, C:\Windows\Tasks\c7d50b1d-2690-4014-92c0-4801c6396a16-5.job, Delete-on-Reboot, ,

    PUP.Optional.CrossRider.T, C:\Windows\Tasks\c7d50b1d-2690-4014-92c0-4801c6396a16-5_user.job, Delete-on-Reboot, ,

    PUP.Optional.CrossRider.T, C:\Windows\Tasks\c7d50b1d-2690-4014-92c0-4801c6396a16-6.job, Delete-on-Reboot, ,

    PUP.Optional.CrossRider.T, C:\Windows\Tasks\c7d50b1d-2690-4014-92c0-4801c6396a16-7.job, Delete-on-Reboot, ,

    PUP.Optional.GlobalUpdate.A, C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job, Delete-on-Reboot, ,

    PUP.Optional.GlobalUpdate.A, C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job, Delete-on-Reboot, ,

    PUP.Optional.CrossRider.A, C:\Windows\Tasks\8c244a42-a8ba-4acf-82d6-f0624865f1a9.job, Delete-on-Reboot, ,

    PUP.Optional.337Technologies.A, C:\Program Files (x86)\Common Files\337\libcef\1.1364.1123\locales\en-US.pak, Delete-on-Reboot, ,

    PUP.Optional.PlusHD.A, C:\Program Files (x86)\Plus-HD-2.2\33036.xpi, Delete-on-Reboot, ,

    PUP.Optional.PlusHD.A, C:\Program Files (x86)\Plus-HD-2.2\background.html, Delete-on-Reboot, ,

    PUP.Optional.PlusHD.A, C:\Program Files (x86)\Plus-HD-2.2\Installer.log, Delete-on-Reboot, ,

    PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe, Delete-on-Reboot, ,

    PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\GoogleCrashHandler.exe, Delete-on-Reboot, ,

    PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\GoogleUpdate.exe, Delete-on-Reboot, ,

    PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\GoogleUpdateBroker.exe, Delete-on-Reboot, ,

    PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\GoogleUpdateHelper.msi, Delete-on-Reboot, ,

    PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\GoogleUpdateOnDemand.exe, Delete-on-Reboot, ,

    PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\goopdate.dll, Delete-on-Reboot, ,

    PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\goopdateres_en.dll, Delete-on-Reboot, ,

    PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll, Delete-on-Reboot, ,

    PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\psmachine.dll, Delete-on-Reboot, ,

    PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\psuser.dll, Delete-on-Reboot, ,

    PUP.Optional.GlobalUpdate.A, C:\Users\Sjaak\AppData\Local\Temp\comh.389436\GoogleCrashHandler.exe, Quarantined, ,

    PUP.Optional.GlobalUpdate.A, C:\Users\Sjaak\AppData\Local\Temp\comh.389436\GoogleUpdate.exe, Quarantined, ,

    PUP.Optional.GlobalUpdate.A, C:\Users\Sjaak\AppData\Local\Temp\comh.389436\GoogleUpdateBroker.exe, Quarantined, ,

    PUP.Optional.GlobalUpdate.A, C:\Users\Sjaak\AppData\Local\Temp\comh.389436\GoogleUpdateHelper.msi, Quarantined, ,

    PUP.Optional.GlobalUpdate.A, C:\Users\Sjaak\AppData\Local\Temp\comh.389436\GoogleUpdateOnDemand.exe, Quarantined, ,

    PUP.Optional.GlobalUpdate.A, C:\Users\Sjaak\AppData\Local\Temp\comh.389436\goopdate.dll, Quarantined, ,

    PUP.Optional.GlobalUpdate.A, C:\Users\Sjaak\AppData\Local\Temp\comh.389436\goopdateres_en.dll, Quarantined, ,

    PUP.Optional.GlobalUpdate.A, C:\Users\Sjaak\AppData\Local\Temp\comh.389436\npGoogleUpdate4.dll, Quarantined, ,

    PUP.Optional.GlobalUpdate.A, C:\Users\Sjaak\AppData\Local\Temp\comh.389436\psmachine.dll, Quarantined, ,

    PUP.Optional.GlobalUpdate.A, C:\Users\Sjaak\AppData\Local\Temp\comh.389436\psuser.dll, Quarantined, ,

    PUP.Optional.HDPlus, C:\Program Files (x86)\HD+v2.1\c7d50b1d-2690-4014-92c0-4801c6396a16-3.exe, Delete-on-Reboot, ,

    PUP.Optional.HDPlus, C:\Program Files (x86)\HD+v2.1\1293297481.mxaddon, Delete-on-Reboot, ,

    PUP.Optional.HDPlus, C:\Program Files (x86)\HD+v2.1\25115276-45d4-4fe3-a1d1-012a2e7656dd.dll, Delete-on-Reboot, ,

    PUP.Optional.HDPlus, C:\Program Files (x86)\HD+v2.1\36dc006b-3137-431c-a778-36a4e1dda23c.crx, Delete-on-Reboot, ,

    PUP.Optional.HDPlus, C:\Program Files (x86)\HD+v2.1\36dc006b-3137-431c-a778-36a4e1dda23c.dll, Delete-on-Reboot, ,

    PUP.Optional.HDPlus, C:\Program Files (x86)\HD+v2.1\4b48c250-d05f-4004-8a8a-900e492e1625.crx, Delete-on-Reboot, ,

    PUP.Optional.HDPlus, C:\Program Files (x86)\HD+v2.1\background.html, Delete-on-Reboot, ,

    PUP.Optional.HDPlus, C:\Program Files (x86)\HD+v2.1\bgNova.html, Delete-on-Reboot, ,

    PUP.Optional.HDPlus, C:\Program Files (x86)\HD+v2.1\c7d50b1d-2690-4014-92c0-4801c6396a16-11.exe, Delete-on-Reboot, ,

    PUP.Optional.HDPlus, C:\Program Files (x86)\HD+v2.1\c7d50b1d-2690-4014-92c0-4801c6396a16-2.exe, Delete-on-Reboot, ,

    PUP.Optional.HDPlus, C:\Program Files (x86)\HD+v2.1\c7d50b1d-2690-4014-92c0-4801c6396a16-4.exe, Delete-on-Reboot, ,

    PUP.Optional.HDPlus, C:\Program Files (x86)\HD+v2.1\c7d50b1d-2690-4014-92c0-4801c6396a16-5.exe, Delete-on-Reboot, ,

    PUP.Optional.HDPlus, C:\Program Files (x86)\HD+v2.1\c7d50b1d-2690-4014-92c0-4801c6396a16-6.exe, Delete-on-Reboot, ,

    PUP.Optional.HDPlus, C:\Program Files (x86)\HD+v2.1\c7d50b1d-2690-4014-92c0-4801c6396a16-64.exe, Delete-on-Reboot, ,

    PUP.Optional.HDPlus, C:\Program Files (x86)\HD+v2.1\c7d50b1d-2690-4014-92c0-4801c6396a16-7.exe, Delete-on-Reboot, ,

    PUP.Optional.HDPlus, C:\Program Files (x86)\HD+v2.1\c7d50b1d-2690-4014-92c0-4801c6396a16.crx, Delete-on-Reboot, ,

    PUP.Optional.HDPlus, C:\Program Files (x86)\HD+v2.1\c7d50b1d-2690-4014-92c0-4801c6396a16.xpi, Delete-on-Reboot, ,

    PUP.Optional.HDPlus, C:\Program Files (x86)\HD+v2.1\c7d50b1d-2690-4014-92c0-4801c6396a16_.xpi, Delete-on-Reboot, ,

    PUP.Optional.HDPlus, C:\Program Files (x86)\HD+v2.1\HD+v2.1-bg.exe, Delete-on-Reboot, ,

    PUP.Optional.HDPlus, C:\Program Files (x86)\HD+v2.1\HD+v2.1-bho.dll, Delete-on-Reboot, ,

    PUP.Optional.HDPlus, C:\Program Files (x86)\HD+v2.1\HD+v2.1-bho64.dll, Delete-on-Reboot, ,

    PUP.Optional.HDPlus, C:\Program Files (x86)\HD+v2.1\HD+v2.1-codedownloader.exe, Delete-on-Reboot, ,

    PUP.Optional.HDPlus, C:\Program Files (x86)\HD+v2.1\HD+v2.1.ico, Delete-on-Reboot, ,

    PUP.Optional.HDPlus, C:\Program Files (x86)\HD+v2.1\utils.exe, Delete-on-Reboot, ,

  • Sjaak

    \Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\chrome.manifest, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\install.rdf, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\chrome\content\1f1e723c31ade644fa6094bc3b0db9b5.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\chrome\content\24c4768e8f30c7952983acc4e077afd4.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\chrome\content\81379979e35206c1f111f24daf97e7f8.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\chrome\content\a2f79120887eaf31a4df1b593f344da8.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\chrome\content\b02f9a7d169f17e2ce92fd2e5798333c.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\chrome\content\background.html, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\chrome\content\browser.xul, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\chrome\content\c26f12610a8e754bfcbbfcf1be1642dd.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\chrome\content\dialog.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\chrome\content\ffCoreFilesIndex.txt, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\chrome\content\options.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\chrome\content\options.xul, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\chrome\content\search_dialog.xul, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\chrome\content\api\68d9137e49c2dcbb0dbdeb76737b72ee.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\chrome\content\api\079e85da657a263f66d0f81400ba8f34.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\chrome\content\api\0fd3b2143c96985a2064c074a4e2ab89.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\chrome\content\api\1c4892c3726697cb2e6744a13ccbeb01.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\chrome\content\api\38085256fcd175754d8aef4c8b16d97f.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\chrome\content\api\4273936d80486ba831261d5d069ec97b.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\chrome\content\api\4cd5962effcdcc0e868832552b02271e.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\chrome\content\api\5a7d2252317966a24a74dcdad99b8d3b.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\chrome\content\api\5b8b3705d1abf2b5d8031fe1be1caf8d.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\chrome\content\api\78b34aa29bddc009ab370870c03f08f9.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\chrome\content\api\840b8596e675f7df74a0ad08f25d5f1b.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\chrome\content\api\840e8d2a7b504734f85c6fbe36355417.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\chrome\content\api\8685778848469edfc73a3cb2239e8c45.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\chrome\content\api\df2ae9144235ef13a3dca9d66b08da14.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\chrome\content\api\e0bae07b9790796c3e98d9646297e68f.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\chrome\content\api\ff2f7ee7cf250abe62c609a431c180f1.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\chrome\content\core\bcb5f3a7ace30d441435f9d14bf93ebe.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\chrome\content\core\000b8058a2b0ab43fbbf92ac8ab6ac96.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\chrome\content\core\02dd917307592e0a95187c8d9510c7bc.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\chrome\content\core\2343d8226da57c1b41bfe2338e1f1d99.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\chrome\content\core\24942bef164f5f141e5a8fc23d6c4265.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\chrome\content\core\2bce667c46c052bd6da8684b21cdecb3.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\chrome\content\core\2c9dc9723bc05a529936c9d471705272.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\chrome\content\core\2d614c60a2ef890bbe0037b9fdb5bab3.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\chrome\content\core\2d979d98622e39913739bbb9e51585b3.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\chrome\content\core\3b4155a623cd3eed8c0ee5bd2a88533a.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\chrome\content\core\69615c5bff0309334f4678d37312062b.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\chrome\content\core\69743d627c85d9fedf1e20dc58979cb4.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\chrome\content\core\a910e344b0f43c87f92c6cce2f6a53c8.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\chrome\content\core\ace67406ee4f337f7a23745daad021c6.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\chrome\content\core\bde0246cde3741fbf946c44e47aef136.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\chrome\content\core\ca939a5d25d114fdd59a3c21d1055a26.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\chrome\content\core\cdc14a86fd56d4070c75cd307580948b.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\chrome\content\core\e763d73311b6875ecefe35322e555b3a.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\chrome\content\core\fd41bf7a39e8ac0491fb06dd1bc5ccf6.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\chrome\content\core\fef724ecac4fe5e3e73ee92991a306c3.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\chrome\content\core\installer.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\defaults\preferences\prefs.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\extensionData\manifest.xml, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\extensionData\plugins.json, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\extensionData\plugins\102.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\extensionData\plugins\104.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\extensionData\plugins\119.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\extensionData\plugins\13.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\extensionData\plugins\14.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\extensionData\plugins\16.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\extensionData\plugins\17.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\extensionData\plugins\178.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\extensionData\plugins\179.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\extensionData\plugins\180.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\extensionData\plugins\184.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\extensionData\plugins\195.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\extensionData\plugins\198.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\extensionData\plugins\199.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\extensionData\plugins\220.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\extensionData\plugins\223.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\extensionData\plugins\226.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\extensionData\plugins\231.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\extensionData\plugins\232.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\extensionData\plugins\244.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\extensionData\plugins\246.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\extensionData\plugins\262.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\extensionData\plugins\263.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\extensionData\plugins\268.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\extensionData\plugins\273.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\extensionData\plugins\275.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\extensionData\plugins\281.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\extensionData\plugins\288.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\extensionData\plugins\289.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\extensionData\plugins\4.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\extensionData\plugins\47.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\extensionData\plugins\64.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\extensionData\plugins\7.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\extensionData\plugins\78.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\extensionData\plugins\9.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\extensionData\plugins\91.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\extensionData\plugins\93.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\extensionData\userCode\background.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\extensionData\userCode\extension.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\locale\en-US\translations.dtd, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\skin\button1.png, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\skin\button2.png, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\skin\button3.png, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\skin\button4.png, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\skin\button5.png, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\skin\crossrider_statusbar.png, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\skin\icon128.png, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\skin\icon16.png, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\skin\icon24.png, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\skin\icon48.png, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\skin\panelarrow-up.png, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\skin\popup.html, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\skin\skin.css, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\extensions\jacobtodd@hotmail.com\skin\update.css, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\chrome.manifest, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\install.rdf, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\chrome\content\4c1e4241f5c1ef10e0b3ea7c629d3c11.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\chrome\content\950a8dd20e6f0c02dc76f6790039496a.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\chrome\content\9805f1fcedcb67e0735d2d96fd00b141.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\chrome\content\background.html, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\chrome\content\bcadc1dd5f861128756bc4ac00dc2853.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\chrome\content\browser.xul, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\chrome\content\c1311e905471ac6017552845e6ae5d68.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\chrome\content\dialog.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\chrome\content\f460040a72a2df01cbfda26d31af9d81.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\chrome\content\ffCoreFilesIndex.txt, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\chrome\content\options.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\chrome\content\options.xul, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\chrome\content\search_dialog.xul, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\chrome\content\api\5f93363f45c7d2420d71fe44aee53ea9.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\chrome\content\api\05b4a50bd6a9472912eee8d96c628cfa.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\chrome\content\api\0d8bfdb2f5c781ae19c5222905d676f2.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\chrome\content\api\14e45be6dd64072c0d6ecd187bb51a43.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\chrome\content\api\1ff88f527426fec094fd541730b4caea.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\chrome\content\api\21606fe958257f6407095962e9dbed16.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\chrome\content\api\3b85d3c769f7301b0149c721ac071ac0.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\chrome\content\api\3ce72413573ae4baf2fb6c9609c05456.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\chrome\content\api\3e5e55e30132e74495fdf827e6616833.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\chrome\content\api\61f5fb53fe6d5dfebeeaa64bbede887c.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\chrome\content\api\6e742a8987dadfe0139f155cf82f960b.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\chrome\content\api\7ee5f677351edd120aeee4116ef9eb87.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\chrome\content\api\901c2d4e02c7fd108b036495c2414400.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\chrome\content\api\b41cb57cece35b74c46eac429308c5d3.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\chrome\content\api\c43b270ce80de5f79a3b636f1eba1866.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\chrome\content\api\cc260383a90c883bfe8caa8f96957855.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\chrome\content\core\7cf3bdbdcd7b5af6f533d5f66d2be76e.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\chrome\content\core\0337f10b5b4b9fac69b3ceb852ac7fc3.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\chrome\content\core\0b5f542d295d84ebcc863f364823a0b9.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\chrome\content\core\0c594ccc2a4ad581a2d468ab253ba961.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\chrome\content\core\1c11a0ee4d7debb10ff5e3e8f06069f7.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\chrome\content\core\21bf0d71ef6819382644179796aeae21.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\chrome\content\core\4c490c178132f57a722bf9b5e538fa56.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\chrome\content\core\4d0904294f76c21d162a9f8e5b16e091.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\chrome\content\core\6f7ea6bf7027873165e0c03dffe3c605.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\chrome\content\core\70252687573d106ae90b43fe91a03e36.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\chrome\content\core\89560ad837ebc03cf2c7f685ecbf0423.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\chrome\content\core\a3323fa61acd32b1db1ccfaa222d6bb9.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\chrome\content\core\a8bd0ae5a96c42f5cf9dc40a30583a23.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\chrome\content\core\ce0d4515ff1eb5df2ab432c275132774.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\chrome\content\core\d8a33eaba9b42ef054d5ff55bb9f9c0e.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\chrome\content\core\ddca4b7dacc0c34fde1bf44abfc8b431.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\chrome\content\core\e3e4f3d05da5212b9c86b21c9b7e0c04.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\chrome\content\core\e961f7d03a67e786c53b5df489da13d1.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\chrome\content\core\eab42e6bafa71e3ced86c925224927d5.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\chrome\content\core\ff5c71cc277ac9ce533afbd780851294.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\chrome\content\core\installer.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\defaults\preferences\prefs.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\extensionData\manifest.xml, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\extensionData\plugins.json, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\extensionData\plugins\1.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\extensionData\plugins\102.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\extensionData\plugins\104.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\extensionData\plugins\119.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\extensionData\plugins\13.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\extensionData\plugins\14.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\extensionData\plugins\16.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\extensionData\plugins\17.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\extensionData\plugins\177.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\extensionData\plugins\178.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\extensionData\plugins\180.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\extensionData\plugins\182.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\extensionData\plugins\183.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\extensionData\plugins\184.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\extensionData\plugins\195.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\extensionData\plugins\207.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\extensionData\plugins\21.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\extensionData\plugins\22.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\extensionData\plugins\220.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\extensionData\plugins\223.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\extensionData\plugins\232.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\extensionData\plugins\244.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\extensionData\plugins\246.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\extensionData\plugins\263.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\extensionData\plugins\268.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\extensionData\plugins\273.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\extensionData\plugins\275.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\extensionData\plugins\28.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\extensionData\plugins\288.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\extensionData\plugins\289.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\extensionData\plugins\300.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\extensionData\plugins\4.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\extensionData\plugins\47.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\extensionData\plugins\64.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\extensionData\plugins\7.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\extensionData\plugins\72.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\extensionData\plugins\78.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\extensionData\plugins\9.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\extensionData\plugins\91.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\extensionData\plugins\93.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\extensionData\plugins\98.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\extensionData\userCode\background.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\extensionData\userCode\extension.js, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\locale\en-US\translations.dtd, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\skin\button1.png, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\skin\button2.png, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\skin\button3.png, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\skin\button4.png, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\skin\button5.png, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\skin\crossrider_statusbar.png, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\skin\icon128.png, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\skin\icon16.png, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\skin\icon24.png, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\skin\icon48.png, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\skin\panelarrow-up.png, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\skin\popup.html, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\skin\skin.css, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\jacobtodd@hotmail.com\skin\update.css, Quarantined, ,

    PUP.Optional.CrossRider.A, C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\prefs.js, Good: (), Bad: (user_pref(“extensions.crossrider.bic”, “147f33cb3e6cbc77d5c4b4ed57266d81”);), Replaced,

    PUP.Optional.CrossRider.A, C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\prefs.js, Good: (), Bad: (user_pref(“extensions.crossrider.bic”, “147f33e1425bc66cac39251a643e0722”);), Replaced,

    Physical Sectors: 0

    (No malicious items detected)

    (end)

  • Sjaak

    Logfile of random's system information tool 1.10 (written by random/random)

    Run by Sjaak at 2014-08-26 22:56:45

    Microsoft Windows 8.1

    System drive C: has 257 GB (37%) free of 693 GB

    Total RAM: 8008 MB (72% free)

    Logfile of Trend Micro HijackThis v2.0.4

    Scan saved at 22:57:07, on 26-8-2014

    Platform: Unknown Windows (WinNT 6.02.1008)

    MSIE: Internet Explorer v11.0 (11.00.9600.17239)

    Boot mode: Normal

    Running processes:

    C:\Program Files (x86)\HTC\HTC Sync Manager\HTC Sync\adb.exe

    C:\Program Files (x86)\Launch Manager\LManager.exe

    C:\Program Files (x86)\Mozilla Firefox\firefox.exe

    C:\Program Files (x86)\CyberLink\MediaEspresso\DeviceDetector\DeviceDetector.exe

    C:\Program Files (x86)\Google\Drive\googledrivesync.exe

    C:\Program Files (x86)\MEDION\MEDION NAS TOOL\MEDION NAS TOOL.exe

    C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe

    C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe

    C:\Program Files (x86)\Twonky\TwonkyServer\twonkytray.exe

    C:\Users\Imka\AppData\Roaming\Dropbox\bin\Dropbox.exe

    C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe

    C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe

    C:\Program Files (x86)\Samsung\AllShare\AllShareAgent.exe

    C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerPlugin_14_0_0_145.exe

    C:\Program Files (x86)\Google\Drive\googledrivesync.exe

    C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe

    C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerPlugin_14_0_0_145.exe

    C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin

    C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuEmailOutlookAgent.exe

    C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuBrowserIEAgent.exe

    C:\Users\Imka\Downloads\RSIT.exe

    C:\Program Files (x86)\trend micro\Sjaak.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://acer13.msn.com

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.nl/

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

    F2 - REG:system.ini: UserInit=userinit.exe

    O4 - HKLM\..\Run: “C:\Dolby PCEE4\pcee4.exe” -autostart

    O4 - HKLM\..\Run: “C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe” /min

    O4 - HKLM\..\Run: “C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe”

    O4 - HKLM\..\Run: wscript.exe "

    O4 - HKLM\..\Run: C:\Program Files (x86)\Samsung\AllShare\AllShareAgent.exe

    O4 - HKCU\..\Run: “C:\Users\Sjaak\AppData\Local\Google\Update\GoogleUpdate.exe” /c

    O4 - HKUS\S-1-5-21-3463471253-882201401-3829445294-1004\..\Run: “C:\Users\Imka\AppData\Local\Citrix\ICA Client\concentr.exe” /startup (User ‘Imka’)

    O4 - HKUS\S-1-5-21-3463471253-882201401-3829445294-1004\..\Run: “C:\Program Files (x86)\Plex\Plex Media Server\Plex Media Server.exe” (User ‘Imka’)

    O4 - HKUS\S-1-5-21-3463471253-882201401-3829445294-1004\..\Run: “C:\Program Files (x86)\Google\Drive\googledrivesync.exe” /autostart (User ‘Imka’)

    O4 - HKUS\S-1-5-21-3463471253-882201401-3829445294-1004\..\Run: C:\Program Files (x86)\MEDION\MEDION NAS TOOL\MEDION NAS TOOL.exe (User ‘Imka’)

    O4 - HKUS\S-1-5-21-3463471253-882201401-3829445294-1004\..\Run: “C:\Users\Imka\AppData\Local\Google\Update\GoogleUpdate.exe” /c (User ‘Imka’)

    O4 - S-1-5-21-3463471253-882201401-3829445294-1004 Startup: Dropbox.lnk = Imka\AppData\Roaming\Dropbox\bin\Dropbox.exe (User ‘Imka’)

    O4 - S-1-5-21-3463471253-882201401-3829445294-1004 Startup: OpenOffice.org 3.4.1.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe (User ‘Imka’)

    O4 - S-1-5-21-3463471253-882201401-3829445294-1004 User Startup: Dropbox.lnk = Imka\AppData\Roaming\Dropbox\bin\Dropbox.exe (User ‘Imka’)

    O4 - S-1-5-21-3463471253-882201401-3829445294-1004 User Startup: OpenOffice.org 3.4.1.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe (User ‘Imka’)

    O4 - Startup: OpenOffice.org 3.4.1.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe

    O4 - Global Startup: Acer Backup Manager Tray.lnk = C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe

    O4 - Global Startup: TwonkyServer.lnk = C:\Program Files (x86)\Twonky\TwonkyServer\twonkytray.exe

    O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200

    O11 - Options group: Accelerated graphics

    O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll

    O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe

    O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe

    O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)

    O23 - Service: Avira Planner (AntiVirSchedulerService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe

    O23 - Service: Avira Real-Time Protection (AntiVirService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe

    O23 - Service: AtherosSvc - Qualcomm Atheros Commnucations - C:\Program Files (x86)\Bluetooth Suite\adminservice.exe

    O23 - Service: Bonjour-service (Bonjour Service) - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe

    O23 - Service: CCDMonitorService - Acer Incorporated - C:\Program Files (x86)\Acer\Acer Cloud\CCDMonitorService.exe

    O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe

    O23 - Service: Device Fast-lane Service (DeviceFastLaneService) - Acer Incorporated - C:\Program Files\Acer\Acer Device Fast-lane\DeviceFastLaneSvc.exe

    O23 - Service: Dritek WMI Service (DsiWMIService) - Dritek System Inc. - C:\Program Files (x86)\Launch Manager\dsiwmis.exe

    O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)

    O23 - Service: EgisTec Ticket Service - Egis Technology Inc. - C:\Program Files (x86)\Common Files\EgisTec\Services\EgisTicketService.exe

    O23 - Service: ePower Service (ePowerSvc) - Acer Incorporated - C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe

    O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)

    O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe

    O23 - Service: GamesAppService - WildTangent, Inc. - C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe

    O23 - Service: Google Update-service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

    O23 - Service: Google Update-service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe

    O23 - Service: HTCMonitorService - Nero AG - C:\Program Files (x86)\HTC\HTC Sync Manager\HSMServiceEntry.exe

    O23 - Service: IconMan_R - Realsil Microelectronics Inc. - C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe

    O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\WINDOWS\system32\IEEtwCollector.exe (file missing)

    O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe

    O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe

    O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)

    O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe

    O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe

    O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)

    O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)

    O23 - Service: NTI IScheduleSvc - NTI Corporation - C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe

    O23 - Service: Internet Pass-Through Service (PassThru Service) - Unknown owner - C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe

    O23 - Service: Dritek RF Button Command Service (RfButtonDriverService) - Dritek System INC. - C:\Windows\RfBtnSvc64.exe

    O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)

    O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)

    O23 - Service: Samsung AllShare PC (SamsungAllShareV2.0) - Samsung Electronics Co., Ltd. - C:\Program Files (x86)\Samsung\AllShare\AllShareDMS\AllShareDMS.exe

    O23 - Service: SimpleSlideShowServer - Samsung Electronics Co., Ltd. - C:\Program Files (x86)\Samsung\AllShare\AllShareSlideShowService.exe

    O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)

    O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)

    O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)

    O23 - Service: TwonkyProxy - Unknown owner - C:\Program Files (x86)\Twonky\TwonkyServer\twonkyproxy.exe

    O23 - Service: TwonkyServer - PacketVideo - C:\Program Files (x86)\Twonky\TwonkyServer\twonkystarter.exe

    O23 - Service: TwonkyWebDav - Unknown owner - C:\Program Files (x86)\Twonky\TwonkyServer\twonkywebdav.exe

    O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)

    O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe

    O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)

    O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)

    O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)

    O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)

    O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)

    O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)

    O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)

    O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

    O23 - Service: ZAtheros Wlan Agent - Atheros - C:\Program Files (x86)\Qualcomm Atheros\Ath_WlanAgent.exe

    End of file - 12769 bytes

    ======Scheduled tasks folder======

    C:\WINDOWS\tasks\8c244a42-a8ba-4acf-82d6-f0624865f1a9.job - C:\Program Files (x86)\HD+v2.1\c7d50b1d-2690-4014-92c0-4801c6396a16-4.exe /qsyeLZ=pN5SU7BYsekU4pLzinuCJt+WcPEbvX2mAf4E2ONNvSepmHb7VWOaP1MaVOeCB/jC4HCvSezuP8JQdbZ49dHTPlGw7e7mvWwHXKS12LpyuI01y62H3qrRbWA90x2v4/p5ZdbmqcqDCPvhGA3TyrFeK1cthhi9NqqcmmrKIN2WZj7FFZTomJIO9VwlaZbyAgrE5FUiWulqWXy9XZIMHePwXnAv08/CeTFHQTIXDn2G8GoGqb8G8LNexpX4D2Ugssv+x3i7GvDXQVgX2eLEspQTPvpBZxM43m4II24BAgxTjDjtoiuf1+U9Aw/j41ulRqmFfV4P0D+Mti9bRGNr5jR/iZJ5VZMiUNME11AQPx+3jen06jyfQL4pDtY8kK5xAnZQNFU7V+XTQDCoDJFbFZe0ODcPIZgQ63sChGnaucNJGZeauZ6NdSyYQjOjk+TK7H9xbaARE14dmBvLMS1k0lYLRmlseCRIQqzsStWrgteCVfj1BSlOCSHLDNdm+6HxG96yAOZLnXagM0qYrM8jylUbjkY1qyceYB8Vap4Oi6XDQI4SbHqo5sBXA7TRaw21msb/lhO/Rdy5Zb4Jz22MCw/OMzMDr+T3WxIlF6RTBKnTEV13apIezEEHOp5seIdHKkQxqBVpsyOvrZd+01hfUR/gmuhV4ocR2DHuAUYzws6zzv17i/mAwInB3t7G5wmYpUF1CuEaB6+vnFq4s1OiMs6ZT+14zkoCLjfDG2/xEj39SH80jIf2rbhK7Hrxi0++CBN3oy7xo70SXYMYwMN/lJ9A8mb3pd8bR5NDqCXe1dc/7SHLS910GzWg9k88MBaOMFNlWEwFeaLIv0P39pgpplT3UX00FHGDu/6/HwI9ZmPV26wwUr9Xk5+GFtGPSAYv5OORHgeEVqQBcRBIil2pmqiqfuYm/i1XJNmU3AZKdHj2rnIQ/YTmVVO8fIWu1KGOktPBA7bMGxnBjPDv6/bht8EB5IpKUCHq3F38UKOVnlrV9tZ2OmrL34iv1CknRCyyT2zLKVHvF0KYhaA7Y5xpD3AQuF/0OpNSQAOruokMSwPB/RnUgsA5aIVdcwmx7tzXm0ybpx/0Zkub56HKaG1JDnHG+WMglsS3sprkwzIzK0b7oawBTcRJlAOtiH+dl2m1kHKtqvN1YI1DUOVm7W08hBSKwgHMENsvzz5kTYB9N//DWbGnq98G5LHOG9Npd1zJVghm8529atkt+Ju60vPsrX/Uon3QHsNyMB9Cdc/zSUg6Ldfr8hPDG4WdYnWFrAefdAh7ysfIT/kYXV21ChMHSZGrnd7Of0Ce4DPR2eHXy6w7c3+S6Wk3w7bbJDP0EzCcZuWd9hrjJziXu+HFY/O1p0174g==

    C:\WINDOWS\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe

    C:\WINDOWS\tasks\c7d50b1d-2690-4014-92c0-4801c6396a16-1.job - C:\Program Files (x86)\HD+v2.1\HD+v2.1-codedownloader.exe /HVQtTCr /ERCWz=task /JmpsI='HD+v2.1' /OqSkPg=62846 /QjYDI='001972' /pASHhU='0' /bkfGzhn='0' /luhuNz=A04155FE9F2642E7B1282A65AF4230ECIE /wonrdLPm=12237e8e00d6c4a68e7623f2c21857c7 /pXMCw=1_34_07_29 /qjMZtD=1.34.7.29 /UgOLjUjM=1408534933 /TbHysNwkL=http://stats.infostatsserv.com /dKAMiS=http://errors.infostatsserv.com /HbpoW=http://js.infostatsserv.com /fJDkTWl=ff /UmOMcNxVS='HD+v2.1' /JNTTuVr=http://js.clientdemocloud.com /DpAdVFL /IqVYez='{“asw”:}' /ZgmofvgLW='http://update.infostatsserv.com/ie_code_agent_updates/{CAMP_ID}/update.json' /ERCWz='task' /PEGOvrfJS=''

    C:\WINDOWS\tasks\c7d50b1d-2690-4014-92c0-4801c6396a16-11.job - C:\Program Files (x86)\HD+v2.1\c7d50b1d-2690-4014-92c0-4801c6396a16-11.exe /qsyeLZ=FH12vNAgNvz23Jr8FK1SKSA2JZe5VCDkw0GPfHOXe9cLMjv+k7g4gKnv4ZUCl4VnPwX8Ka5VVSGlxMPhm8BxuzDv2NAVegfvwrvGNQqZ0IoruIPnsihBrXMn9EMj3dC13Xnn2QcEqlT9iJSPTKPJwoXzM4rfJQdFNzqhSdwkKs9SzhOZdAKCqymS8uR+e0Y78ClRClIiTSEdGq5NzewRlExMnacjZPjLwEGxvWwcuIrN9CEUpUH06DsFqGqiO1ojWj5WwVwRbv5HEAxJqKcCol7TIDoqzb5plOUGGu3WyHiQh6w5DyVtzK8CKrvdnuO5nNMvGxZ9lJwHoD6eg2BKrpLJc3AF6A+iAbQzpBSyVRpKAz+EvXIXl1zj7LheX3sQc9KXEixQyAZ2lqksfYUCZxzOnYfS8HBB4rgkh/SYDspPUrKOJ6ESrgZ8D+XyPkPxgBuRNI34vj9pmjPMnlIwiFQATC0Q572uSkLocOwP93txLDZQ/kaMz5XElByAhRiDs5BMt1ttT52bKkXuo75RlPrY0Q9YbLJ9u6jWIBz3Ld+wFh1nOK+tkSjuOU/3gwWeqyRwDPlmKP9IbNKnGUCfzQjeLue0Y1pj2brWMHGuXN8LCoRMh4tyYhWXf6Hh7xDz2hRjfTjQgJXBcIQw3EM7tI9WreOAK9R3iIFwE4Rw9mqducV0cuQc0RSNrr21bbJLCRWJByxOc1/N2VJluCfiedH4KnAg2oDNPrfnSYaR4ylSsnN1KtkUOxQ7zLPzAZBeR7CZCytQwLJQqnOfL7HdFqPASEv0Q0mrwSmjouzpeqr0+ZW+pGhxP7GnkMo7EprrKwZBfODCf8f/onNWYTcGBmmuZc6EUXg5xtF+qNrDrSonWts/4rwGA21x6HIz46P/6Cb+SvI9zTJxObCXDESGn1RLkr9PlwdvmOzSvp7DE2MH4UZKWOHTp1EDCsDncn4OfXY0Sg06+WlbkoGs11qKXToCByHipIeH1JOjkDxwdvE+Q7CVW8BqejBi/D7DbTtQcJjzdst6A0LYXXwCGhkw7sJrfB1JLRy/h18IGSu0zxalczKA6KXkZZxrtRCiseEa/Zl7c09rZrXwfUbMxi8mr3D+hgqjZPobBlbPDq94ZGJVjICE5elUuVWTDHRfyBIp7M6zrWoo4X51HuyTpofmueUin9fcyI/HbTf/cL3nUPWG/QU3raV8SgBNiXgWIyWTyL5dR2L0mK27VZFVQ1Nq090cOGq8SmXk0XYNpa60xk+JZb0AWYiy4pRMutLVl6+JkuMxQtmxSf6H25ZmJGMWKFcDXv1o61BC6bi35xo4LCfPaZ8VmbN2kxlAkTbGI5HDowiTUtAh/hCkakQg6pSsbj+r5jG4bF13TI7493PAoCGRThv0IFMlGW0qKZBsXsLBXKKRFu6H+ELxzjPwR+x4tbU7IRe3F/T1o8aPvexgS2USxt+BTpbPbO/uKv3o3bSruQ69mvKPMXMBu99B95uVMFuBrorVRJ8fkSwBKR+XmZFm1vQS9NJmLPyJiEnYQtMBNVVhEL+Edp3KENBLhI5HDc+oD+cc+jf8VbWzx9/GPZD0tPoMqVFglyaCJzZViKM2J9J7O9062C7Yy8la0GCflSExm7qZyn7gSXW9gZ0Q4gZFJNgFIjvAD7vis8tLVuop+tNGzWy4YAS20nu5k3X0l+H9WiRNrEOBV06nU82qK0c=

    C:\WINDOWS\tasks\c7d50b1d-2690-4014-92c0-4801c6396a16-2.job - C:\Program Files (x86)\HD+v2.1\c7d50b1d-2690-4014-92c0-4801c6396a16-2.exe /uEJDOqA /JmpsI='HD+v2.1' /OqSkPg=62846 /QjYDI='001972' /pASHhU='0' /bkfGzhn='0' /luhuNz=A04155FE9F2642E7B1282A65AF4230ECIE /wonrdLPm=12237e8e00d6c4a68e7623f2c21857c7 /pXMCw=1_34_07_29 /UgOLjUjM=1408534933 /TbHysNwkL=http://stats.infostatsserv.com /dKAMiS=http://errors.infostatsserv.com /nfwYJ=11111111-1111-1111-1111-110611281146 /fJDkTWl=ff /UWWUeJdN /DpAdVFL /ZgmofvgLW='http://update.infostatsserv.com/ie_enable_agent_updates/{CAMP_ID}/update.json' /ERCWz='task' /PEGOvrfJS=''

    C:\WINDOWS\tasks\c7d50b1d-2690-4014-92c0-4801c6396a16-3.job - C:\Program Files (x86)\HD+v2.1\c7d50b1d-2690-4014-92c0-4801c6396a16-3.exe /qsyeLZ=E8aH0pk8d9KGELUNh4WASS+9yFntrYvDIYW3UIEw4B2yPmyx8JCiZWvG18lbl02ZPNRrvam8w6Us9yyN8v3UNPWcjRERVRtIbZY7W4hziKeIB+Q+7RLDgSXFwKfIAGanIxSTm3kuOilUtvmVJkl5GG/NQv/tHUJRtijhA7kIXqc4GHZmFcgHkhHmXnCsgkKLyJ1eoUcK2H2jtywi3y/XefEp/Swe+WfFjbV1nA7lVBSe9gSmEupIyxBfLrzCBD//j9YG3ACKDC8BkVm6AZvUtljOVq/aVpwBo90RmYEupC8YTBolqUPPJvOjectLCnNtO3YxKy3/6LFKLwdkZ4cztIHk6U0rOJwbyBhrOVwsGVcAeMcbWGJmlScnRu/Bc602zdp1HM73YeD8e7SnwrPalZSsLyLOCWSqRgjcvLY/dGm+lqoWhrJgYeqK+rj8hWV0nlbbq0JjIOr047RquL75olvSm8Tm3yyHcCo1e1NmvZNzrBLSYz84q6nG9aeaUKgHi0ztGsZyMRcJv7hH9Z0xt3JIEFGfjkUz9WrVTVzq7eRwkdCafeENq+kJGQX1dv/LjwNaceshE05atUKLg10B8lMWOAOCdnay2k3CmHylt03EeLMaJSV7MpsYY3vffjRmO2+xsiLexoRSNou7fM5TbtiBn77runQZgbgSkmjz93B/AHc6bB41uKTBsXCmKfUAnPUzY0E3Fzlin1LvcE+Q3UXSrlAAJAheDtGSmfhJnGg4CzzIfcEg4ZBc7whdJna+qzXTyeEWsVF02QQzTIVo0W1VIuCJj6HES0JKtuJQ4OTPK8P6V2AqYtVuiFWwZHozMgxXiQZ0nKwTBuA1IG+0WXP8Ltsyfr/7d1nGPDTz7A91IqbNXS5GDDMX20pzL4bcfzEjHn0J8tCSa3WrYK0o8p/xoqyIwvwHeyqDtdZ6uAZAPGAKO5bwpot9EAQRqa7WHMIqCYK4D/22YfL+vkPL30XnRAtKapbHbIZA2tS3A/k9B3OdZxgT8UcwLuwLVqbY

    C:\WINDOWS\tasks\c7d50b1d-2690-4014-92c0-4801c6396a16-4.job - C:\Program Files (x86)\HD+v2.1\c7d50b1d-2690-4014-92c0-4801c6396a16-4.exe /pBJPSrPn /JmpsI='HD+v2.1' /pxQcN='C:\Program Files (x86)\HD+v2.1\c7d50b1d-2690-4014-92c0-4801c6396a16.xpi' /OqSkPg=62846 /QjYDI='001972' /pASHhU='0' /bkfGzhn='0' /luhuNz=A04155FE9F2642E7B1282A65AF4230ECIE /wonrdLPm=12237e8e00d6c4a68e7623f2c21857c7 /pXMCw=1_34_07_29 /qjMZtD=1.34.7.29 /UgOLjUjM=1408534933 /TbHysNwkL=http://stats.infostatsserv.com /dKAMiS=http://errors.infostatsserv.com /uhAYeUIP=300 /vYyqhDWoI=jacobtodd@hotmail.com /qUQXJYd=0.95 /IhjDMjQg=ajacobtoddhotmailcom62846 /IIEbCjuAQ=https://w9u6a2p6.ssl.hwcdn.net/plugin/ff/update/62846.rdf /WKFFCsu='HD+v2.1' /ThxRkoTtB='Lights out for YouTube' /esUPCZ='HD+v2.1' /fJDkTWl=ff /IqVYez='{“asw”:}' /DpAdVFL /DemfX /GJnzYqU /ZgmofvgLW='http://update.infostatsserv.com/ff_agent_updates/{CAMP_ID}/update.json' /ERCWz='task' /PEGOvrfJS=''

    C:\WINDOWS\tasks\c7d50b1d-2690-4014-92c0-4801c6396a16-5.job - C:\Program Files (x86)\HD+v2.1\c7d50b1d-2690-4014-92c0-4801c6396a16-5.exe /EUVsAE /JmpsI='HD+v2.1' /OqSkPg=62846 /QjYDI='001972' /pASHhU='0' /bkfGzhn='0' /luhuNz=A04155FE9F2642E7B1282A65AF4230ECIE /wonrdLPm=12237e8e00d6c4a68e7623f2c21857c7 /pXMCw=1_34_07_29 /UgOLjUjM=1408534933 /TbHysNwkL=http://stats.infostatsserv.com /dKAMiS=http://errors.infostatsserv.com /qllNi=http://ipgeoapi.com/ /keGJZvSCa=http://update.infostatsserv.com /aoelU=2 /RPWVFeNt=http://logs.infostatsserv.com /ZgmofvgLW='http://update.infostatsserv.com/updater_agent_updates/{CAMP_ID}/update.json' /ERCWz='task' /PEGOvrfJS=''

    C:\WINDOWS\tasks\c7d50b1d-2690-4014-92c0-4801c6396a16-5_user.job - C:\Program Files (x86)\HD+v2.1\c7d50b1d-2690-4014-92c0-4801c6396a16-5.exe /EUVsAE /JmpsI='HD+v2.1' /OqSkPg=62846 /QjYDI='001972' /pASHhU='0' /bkfGzhn='0' /luhuNz=A04155FE9F2642E7B1282A65AF4230ECIE /wonrdLPm=12237e8e00d6c4a68e7623f2c21857c7 /pXMCw=1_34_07_29 /UgOLjUjM=1408534933 /TbHysNwkL=http://stats.infostatsserv.com /dKAMiS=http://errors.infostatsserv.com /qllNi=http://ipgeoapi.com/ /keGJZvSCa=http://update.infostatsserv.com /aoelU=2 /RPWVFeNt=http://logs.infostatsserv.com /ZgmofvgLW='http://update.infostatsserv.com/updater_agent_updates/{CAMP_ID}/update.json' /EHZhHoe /ERCWz='task' /PEGOvrfJS=''

    C:\WINDOWS\tasks\c7d50b1d-2690-4014-92c0-4801c6396a16-6.job - C:\Program Files (x86)\HD+v2.1\c7d50b1d-2690-4014-92c0-4801c6396a16-6.exe /JmpsI='HD+v2.1' /OqSkPg=62846 /QjYDI='001972' /pASHhU='0' /bkfGzhn='0' /luhuNz=A04155FE9F2642E7B1282A65AF4230ECIE /wonrdLPm=12237e8e00d6c4a68e7623f2c21857c7 /pXMCw=1_34_07_29 /qjMZtD=1.34.7.29 /UgOLjUjM=1408534933 /TbHysNwkL=http://stats.infostatsserv.com /dKAMiS=http://errors.infostatsserv.com /HbpoW=http://js.infostatsserv.com /fJDkTWl=ff /RAuobiai /UmOMcNxVS=HD+v2.1 /VJDxZ36dc006b-3137-431c-a778-36a4e1dda23c.dll /kHvhqJwDH25115276-45d4-4fe3-a1d1-012a2e7656dd.dll /ssFJUuHEJc7d50b1d-2690-4014-92c0-4801c6396a16-64.exe /xRKOYKCB='nova' /JNTTuVr=http://js.clientdemocloud.com /IqVYez='{“asw”:}' /ZgmofvgLW='http://update.infostatsserv.com/novarun/{CAMP_ID}/update.json' /ERCWz='task' /PEGOvrfJS=''

    C:\WINDOWS\tasks\c7d50b1d-2690-4014-92c0-4801c6396a16-7.job - C:\Program Files (x86)\HD+v2.1\c7d50b1d-2690-4014-92c0-4801c6396a16-7.exe /xLWKjq /JmpsI='HD+v2.1' /OqSkPg=62846 /QjYDI='001972' /pASHhU='0' /bkfGzhn='0' /luhuNz=A04155FE9F2642E7B1282A65AF4230ECIE /wonrdLPm=12237e8e00d6c4a68e7623f2c21857c7 /pXMCw=1_34_07_29 /qjMZtD=1.34.7.29 /UgOLjUjM=1408534933 /TbHysNwkL=http://stats.infostatsserv.com /dKAMiS=http://errors.infostatsserv.com /HbpoW=http://js.infostatsserv.com /fJDkTWl=ff /RAuobiai /UmOMcNxVS=HD+v2.1 /VJDxZ36dc006b-3137-431c-a778-36a4e1dda23c.dll /kHvhqJwDH25115276-45d4-4fe3-a1d1-012a2e7656dd.dll /ssFJUuHEJc7d50b1d-2690-4014-92c0-4801c6396a16-64.exe /xRKOYKCB='nova' /JNTTuVr=http://js.clientdemocloud.com /IqVYez='{“asw”:}' /ERCWz=task /ZgmofvgLW='http://update.infostatsserv.com/novacode/{CAMP_ID}/update.json' /ERCWz='task' /PEGOvrfJS=''

    C:\WINDOWS\tasks\globalUpdateUpdateTaskMachineCore.job - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe /c

    C:\WINDOWS\tasks\globalUpdateUpdateTaskMachineUA.job - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe /ua /installsource scheduler

    C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c

    C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler

    C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-3463471253-882201401-3829445294-1001Core.job - C:\Users\Sjaak\AppData\Local\Google\Update\GoogleUpdate.exe /c

    C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-3463471253-882201401-3829445294-1001UA.job - C:\Users\Sjaak\AppData\Local\Google\Update\GoogleUpdate.exe /ua /installsource scheduler

    C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-3463471253-882201401-3829445294-1004Core.job - C:\Users\Imka\AppData\Local\Google\Update\GoogleUpdate.exe /c

    C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-3463471253-882201401-3829445294-1004UA.job - C:\Users\Imka\AppData\Local\Google\Update\GoogleUpdate.exe /ua /installsource scheduler

    =========Mozilla firefox=========

    ProfilePath - C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default

    prefs.js - “browser.search.useDBForOrder” - “false”

    prefs.js - “browser.startup.homepage” - “www.google.nl”

    “Description”=Adobe® Flash® Player 14.0.0.145 Plugin

    “Path”=C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_145.dll

    “Description”=Picasa3 plugin

    “Path”=C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll

    “Description”=Intel IPT WebApi plugin

    “Path”=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll

    “Description”=This plugin updates Intel WebAPI component

    “Path”=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll

    “Description”=WLPG Install MIME type

    “Path”=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

    “Description”=globalUpdate Update

    “Path”=C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll

    “Description”=globalUpdate Update

    “Path”=C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll

    “Description”=Google Update

    “Path”=C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll

    “Description”=Google Update

    “Path”=C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll

    “Description”=VLC Multimedia Plugin

    “Path”=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll

    “Description”=VLC Multimedia Plugin

    “Path”=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll

    “Description”=WildTangent Games App V2 Presence Detector Plugin

    “Path”=C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll

    “Description”=Handles PDFs in-place in Firefox

    “Path”=C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll

    ======Registry dump======

    “Dolby Home Theater v4”=C:\Dolby PCEE4\pcee4.exe

    “LManager”=

    “avgnt”=C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe

    “Adobe ARM”=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe

    “TaskMngr”=C:\WINDOWS\system32\wscript.exe

    “AllShareAgent”=C:\Program Files (x86)\Samsung\AllShare\AllShareAgent.exe

    “Google Update”=C:\Users\Sjaak\AppData\Local\Google\Update\GoogleUpdate.exe

    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup

    Acer Backup Manager Tray.lnk - C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe

    TwonkyServer.lnk - C:\Program Files (x86)\Twonky\TwonkyServer\twonkytray.exe

    C:\Users\Sjaak\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup

    OpenOffice.org 3.4.1.lnk - C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe

    “SafeModeBlockNonAdmins”=1

    “NoDriveTypeAutoRun”=145

    “msacm.msgsm610”=msgsm32.acm

    “msacm.msg711”=msg711.acm

    “msacm.l3acm”=C:\Windows\SysWOW64\l3codeca.acm

    “vidc.yuy2”=msyuv.dll

    “vidc.i420”=iyuv_32.dll

    “vidc.cvid”=iccvid.dll

    “vidc.yvyu”=msyuv.dll

    “vidc.yvu9”=tsbyuv.dll

    “wavemapper”=msacm32.drv

    “midimapper”=midimap.dll

    “vidc.uyvy”=msyuv.dll

    “msacm.imaadpcm”=imaadp32.acm

    “msacm.msadpcm”=msadp32.acm

    “vidc.iyuv”=iyuv_32.dll

    “vidc.mrle”=msrle32.dll

    “vidc.msvc”=msvidc32.dll

    “wave”=wdmaud.drv

    “midi”=wdmaud.drv

    “mixer”=wdmaud.drv

    “aux”=wdmaud.drv

    “wave1”=wdmaud.drv

    “midi1”=wdmaud.drv

    “mixer1”=wdmaud.drv

    “aux1”=wdmaud.drv

    “msacm.l3codecp”=l3codecp.acm

    “vidc.dvsd”=pdvcodec.dll

    “vidc.mjpg”=pvmjpg30.dll

    ======File associations======

    .js - edit - C:\Windows\System32\Notepad.exe %1

    .js - open - C:\Windows\System32\WScript.exe “%1” %*

    ======List of files/folders created in the last 1 month======

    2014-08-26 22:56:45 —-D—- C:\rsit

    2014-08-26 22:56:45 —-D—- C:\Program Files (x86)\trend micro

    2014-08-26 21:47:17 —-D—- C:\ProgramData\Malwarebytes

    2014-08-20 13:51:27 —-D—- C:\Users\Sjaak\AppData\Roaming\WinRAR

    2014-08-20 13:42:27 —-D—- C:\Program Files (x86)\globalUpdate

    2014-08-20 13:42:18 —-D—- C:\Program Files (x86)\HD+v2.1

    2014-08-20 13:42:03 —-D—- C:\Users\Sjaak\AppData\Roaming\MakeitOne

    2014-08-20 13:41:49 —-D—- C:\Program Files (x86)\MakeitOne

    2014-08-20 13:27:00 —-D—- C:\Program Files (x86)\Audacity

    2014-08-19 16:01:34 —-SHD—- C:\Config.Msi

    2014-08-17 20:30:21 —-A—- C:\WINDOWS\SysWOW64\rpcrt4.dll

    2014-08-17 20:30:16 —-A—- C:\WINDOWS\SysWOW64\TsWpfWrp.exe

    2014-08-17 20:22:46 —-A—- C:\WINDOWS\SysWOW64\dxgi.dll

    2014-08-17 20:22:44 —-A—- C:\WINDOWS\SysWOW64\Wpc.dll

    2014-08-17 20:22:37 —-A—- C:\WINDOWS\SysWOW64\urlmon.dll

    2014-08-17 20:22:37 —-A—- C:\WINDOWS\SysWOW64\mshtmled.dll

    2014-08-17 20:22:37 —-A—- C:\WINDOWS\SysWOW64\msfeeds.dll

    2014-08-17 20:22:37 —-A—- C:\WINDOWS\SysWOW64\jscript9diag.dll

    2014-08-17 20:22:37 —-A—- C:\WINDOWS\SysWOW64\dxtmsft.dll

    2014-08-17 20:22:36 —-A—- C:\WINDOWS\SysWOW64\mshtml.dll

    2014-08-17 20:22:35 —-A—- C:\WINDOWS\SysWOW64\iertutil.dll

    2014-08-17 20:22:34 —-A—- C:\WINDOWS\SysWOW64\ieframe.dll

    2014-08-17 20:22:34 —-A—- C:\WINDOWS\SysWOW64\dxtrans.dll

    2014-08-17 20:22:32 —-A—- C:\WINDOWS\SysWOW64\jscript9.dll

    2014-08-17 20:22:32 —-A—- C:\WINDOWS\SysWOW64\ieapfltr.dll

    2014-08-17 20:22:24 —-A—- C:\WINDOWS\SysWOW64\iedkcs32.dll

    2014-08-17 20:22:23 —-A—- C:\WINDOWS\SysWOW64\wininet.dll

    2014-08-17 20:22:21 —-A—- C:\WINDOWS\SysWOW64\JavaScriptCollectionAgent.dll

    2014-08-17 20:22:20 —-A—- C:\WINDOWS\SysWOW64\MshtmlDac.dll

    2014-08-17 20:22:19 —-A—- C:\WINDOWS\SysWOW64\vbscript.dll

    2014-08-17 20:21:05 —-A—- C:\WINDOWS\SysWOW64\mfcore.dll

    2014-08-17 20:21:03 —-A—- C:\WINDOWS\SysWOW64\d3d9.dll

    2014-08-17 20:21:01 —-A—- C:\WINDOWS\SysWOW64\ntdll.dll

    2014-08-17 20:21:01 —-A—- C:\WINDOWS\SysWOW64\dhcpcore.dll

    2014-08-17 20:21:00 —-A—- C:\WINDOWS\SysWOW64\SkyDriveShell.dll

    2014-08-17 20:20:59 —-A—- C:\WINDOWS\SysWOW64\WebClnt.dll

    2014-08-17 20:20:59 —-A—- C:\WINDOWS\SysWOW64\ncobjapi.dll

    2014-08-17 20:20:59 —-A—- C:\WINDOWS\SysWOW64\framedynos.dll

    2014-08-17 20:20:59 —-A—- C:\WINDOWS\SysWOW64\dhcpcore6.dll

    2014-08-17 20:20:58 —-A—- C:\WINDOWS\SysWOW64\Robocopy.exe

    2014-08-17 20:20:58 —-A—- C:\WINDOWS\SysWOW64\framedyn.dll

    2014-08-17 20:20:58 —-A—- C:\WINDOWS\SysWOW64\dhcpcsvc6.dll

    2014-08-17 20:20:58 —-A—- C:\WINDOWS\SysWOW64\dhcpcsvc.dll

    2014-08-17 20:20:58 —-A—- C:\WINDOWS\SysWOW64\actxprxy.dll

    2014-08-17 20:20:57 —-A—- C:\WINDOWS\SysWOW64\d3d8thk.dll

    2014-08-17 20:20:32 —-A—- C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll

    2014-08-17 20:20:31 —-A—- C:\WINDOWS\SysWOW64\rsaenh.dll

    2014-08-17 20:20:30 —-A—- C:\WINDOWS\SysWOW64\DaOtpCredentialProvider.dll

    2014-08-17 20:20:23 —-A—- C:\WINDOWS\SysWOW64\msi.dll

    2014-08-17 20:20:23 —-A—- C:\WINDOWS\SysWOW64\authui.dll

    2014-08-17 20:20:22 —-A—- C:\WINDOWS\SysWOW64\msihnd.dll

    ======List of files/folders modified in the last 1 month======

    2014-08-26 22:56:55 —-D—- C:\WINDOWS\Prefetch

    2014-08-26 22:56:49 —-D—- C:\WINDOWS\Temp

    2014-08-26 22:56:45 —-RD—- C:\Program Files (x86)

    2014-08-26 22:56:02 —-D—- C:\ProgramData\TwonkyServer

    2014-08-26 22:47:35 —-A—- C:\WINDOWS\SysWOW64\log.txt

    2014-08-26 22:47:32 —-SHD—- C:\WINDOWS\Installer

    2014-08-26 21:47:17 —-HD—- C:\ProgramData

    2014-08-26 20:20:30 —-D—- C:\WINDOWS\Microsoft.NET

    2014-08-24 11:04:25 —-D—- C:\WINDOWS\Inf

    2014-08-22 21:34:34 —-D—- C:\WINDOWS\System32

    2014-08-20 13:52:59 —-D—- C:\Users\Sjaak\AppData\Roaming\Mozilla

    2014-08-20 13:43:17 —-D—- C:\WINDOWS\Tasks

    2014-08-20 13:42:03 —-D—- C:\WINDOWS\SysWOW64

    2014-08-20 13:41:35 —-SHD—- C:\System Volume Information

    2014-08-19 13:10:55 —-D—- C:\WINDOWS\rescache

    2014-08-19 12:57:03 —-D—- C:\WINDOWS\AppReadiness

    2014-08-19 11:13:31 —-D—- C:\ProgramData\Spotnet

    2014-08-19 10:35:39 —-D—- C:\WINDOWS\WinSxS

    2014-08-18 21:31:28 —-RSD—- C:\WINDOWS\assembly

    2014-08-18 20:43:55 —-D—- C:\Program Files (x86)\Spotnet

    2014-08-18 20:24:12 —-RD—- C:\Users

    2014-08-18 20:13:28 —-D—- C:\Program Files (x86)\Mozilla Maintenance Service

    2014-08-18 20:10:24 —-D—- C:\WINDOWS\SysWOW64\nl-NL

    2014-08-18 20:10:23 —-D—- C:\Program Files (x86)\Internet Explorer

    2014-08-18 20:10:19 —-D—- C:\WINDOWS\PolicyDefinitions

    2014-08-18 20:10:00 —-RD—- C:\WINDOWS\ToastData

    2014-08-18 20:09:54 —-D—- C:\WINDOWS\SysWOW64\migration

    2014-08-18 20:09:54 —-D—- C:\WINDOWS\MediaViewer

    2014-08-18 20:09:53 —-D—- C:\WINDOWS\SysWOW64\wbem

    2014-08-18 20:09:52 —-D—- C:\WINDOWS\FileManager

    2014-08-18 20:09:52 —-D—- C:\WINDOWS\Camera

    2014-08-18 16:57:02 —-D—- C:\WINDOWS\CbsTemp

    2014-08-17 20:15:03 —-A—- C:\WINDOWS\SysWOW64\msrating.dll

    2014-08-17 20:15:00 —-A—- C:\WINDOWS\SysWOW64\jsproxy.dll

    2014-08-17 20:14:37 —-A—- C:\WINDOWS\SysWOW64\ieetwproxystub.dll

    2014-08-17 20:14:34 —-A—- C:\WINDOWS\SysWOW64\ieUnatt.exe

    2014-08-17 20:14:32 —-A—- C:\WINDOWS\SysWOW64\iesetup.dll

    2014-08-17 20:14:32 —-A—- C:\WINDOWS\SysWOW64\iernonce.dll

    2014-08-02 02:17:43 —-A—- C:\WINDOWS\SysWOW64\FlashPlayerApp.exe

    ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

    R0 iaStorA;iaStorA; C:\WINDOWS\System32\drivers\iaStorA.sys

    R1 avipbb;avipbb; C:\WINDOWS\system32\DRIVERS\avipbb.sys

    R1 avkmgr;avkmgr; C:\WINDOWS\system32\DRIVERS\avkmgr.sys

    R1 mwlPSDFilter;mwlPSDFilter; C:\WINDOWS\system32\DRIVERS\mwlPSDFilter.sys

    R1 mwlPSDNServ;mwlPSDNServ; C:\WINDOWS\system32\DRIVERS\mwlPSDNServ.sys

    R1 mwlPSDVDisk;mwlPSDVDisk; C:\WINDOWS\system32\DRIVERS\mwlPSDVDisk.sys

    R1 vwififlt;@%SystemRoot%\System32\drivers\vwififlt.sys,-259; C:\WINDOWS\system32\DRIVERS\vwififlt.sys

    R2 avgntflt;avgntflt; C:\WINDOWS\system32\DRIVERS\avgntflt.sys

    R3 ApfiltrService;@oem33.inf,%Filter.SvcDesc%;Alps Pointing-device Filter Driver; C:\WINDOWS\system32\DRIVERS\Apfiltr.sys

    R3 athr;@athw8x.inf,%ATHR.Service.DispName%;Qualcomm Atheros Extensible Wireless LAN device driver; C:\WINDOWS\system32\DRIVERS\athw8x.sys

    R3 BTATH_BUS;@oem3.inf,%BTATH_BUS.SVCDESC%;Qualcomm Atheros Bluetooth Bus; C:\WINDOWS\System32\drivers\btath_bus.sys

    R3 BtFilter;BtFilter; C:\WINDOWS\system32\DRIVERS\btfilter.sys

    R3 BTHUSB;@bth.inf,%BTHUSB.SvcDesc%;USB-stuurprogramma voor Bluetooth-radio; C:\WINDOWS\System32\Drivers\BTHUSB.sys

    R3 igfx;igfx; C:\WINDOWS\system32\DRIVERS\igdkmd64.sys

    R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RTKVHD64.sys

    R3 IntcDAud;@oem28.inf,%IntcDAud.SvcDesc%;Intel(R) Display Audio; C:\WINDOWS\system32\DRIVERS\IntcDAud.sys

    R3 L1C;@netl1c63x64.inf,%L1C.Service.DispName%;NDIS-minipoortstuurprogramma voor Qualcomm Atheros AR81xx PCI-E Ethernet-controller; C:\WINDOWS\system32\DRIVERS\L1C63x64.sys

    R3 MarvinBus;@oem23.inf,%MarvinBus.SVCDESC%;Pinnacle Marvin Bus 64; C:\WINDOWS\System32\drivers\MarvinBus64.sys

    R3 MEIx64;@oem32.inf,%HECI_SvcDesc%;Intel(R) Management Engine Interface ; C:\WINDOWS\System32\drivers\HECIx64.sys

    R3 NTIDrvr;NTIDrvr; \??\C:\Windows\system32\drivers\NTIDrvr.sys

    R3 Ps2Kb2Hid;@oem8.inf,%Ps2Kb2Hid.SVCDESC%;PS/2 Keyboard to HID Driver; C:\WINDOWS\System32\drivers\aPs2Kb2Hid.sys

    R3 UBHelper;UBHelper; \??\C:\Windows\system32\drivers\UBHelper.sys

    R3 usbvideo;@usbvideo.inf,%USBVideo.SvcDesc%;USB-videoapparaat (WDM); C:\WINDOWS\System32\Drivers\usbvideo.sys

    R3 vwifimp;@%SystemRoot%\System32\drivers\vwifimp.sys,-261; C:\WINDOWS\system32\DRIVERS\vwifimp.sys

    S3 BTATH_LWFLT;@oem17.inf,%BTATH_LWFLT%;Bluetooth LWFLT Device; C:\WINDOWS\system32\DRIVERS\btath_lwflt.sys

    S3 BthEnum;@bth.inf,%BthEnum.SVCDESC%;Bluetooth Enumerator Service; C:\WINDOWS\System32\drivers\BthEnum.sys

    S3 BthLEEnum;@bthleenum.inf,%BthLEEnum.SVCDESC%;Bluetooth Low Energy Driver; C:\WINDOWS\System32\drivers\BthLEEnum.sys

    S3 BthPan;@bthpan.inf,%BthPan.DisplayName%;Bluetooth-apparaat (Personal Area Network); C:\WINDOWS\system32\DRIVERS\bthpan.sys

    S3 BTHPORT;@bth.inf,%BTHPORT.SvcDesc%;Stuurprogramma voor Bluetooth-poort; C:\WINDOWS\System32\Drivers\BTHport.sys

    S3 dg_ssudbus;@oem46.inf,%ssud.Service.DeviceDesc%;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\WINDOWS\system32\DRIVERS\ssudbus.sys

    S3 HtcVCom32;@oem41.inf,%OEMSerialPortName00%;HTC Diagnostic Port; C:\WINDOWS\system32\DRIVERS\HtcVComV64.sys

    S3 MBAMSwissArmy;MBAMSwissArmy; \??\C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys

    S3 RFCOMM;@tdibth.inf,%RFCOMM.DisplayName%;Bluetooth Device (RFCOMM Protocol TDI); C:\WINDOWS\System32\drivers\rfcomm.sys

    S3 RSPCIESTOR;@oem30.inf,%Rts5208%;Realtek PCIE CardReader Driver; C:\WINDOWS\system32\DRIVERS\RtsPStor.sys

    S3 ssudmdm;@oem45.inf,%ssud.Service.Name%;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.); C:\WINDOWS\system32\DRIVERS\ssudmdm.sys

    S3 ssudserd;@oem15.inf,%ssud.Service.Name%;SAMSUNG Mobile USB Diagnostic Serial Port(DEVGURU Ver.); C:\WINDOWS\system32\DRIVERS\ssudserd.sys

    S3 usb_rndisx;@netrndis.inf,%usb_rndis.Service.DispName%;USB RNDIS-adapter; C:\WINDOWS\system32\DRIVERS\usb8023x.sys

    ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

    R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe

    R2 AntiVirSchedulerService;Avira Planner; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe

    R2 AntiVirService;Avira Real-Time Protection; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe

    R2 AtherosSvc;AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe

    R2 Bonjour Service;Bonjour-service; C:\Program Files (x86)\Bonjour\mDNSResponder.exe

    R2 CCDMonitorService;CCDMonitorService; C:\Program Files (x86)\Acer\Acer Cloud\CCDMonitorService.exe

    R2 DsiWMIService;Dritek WMI Service; C:\Program Files (x86)\Launch Manager\dsiwmis.exe

    R2 HTCMonitorService;HTCMonitorService; C:\Program Files (x86)\HTC\HTC Sync Manager\HSMServiceEntry.exe

    R2 IconMan_R;IconMan_R; C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe

    R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe

    R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe

    R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe

    R2 NTI IScheduleSvc;NTI IScheduleSvc; C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe

    R2 PassThru Service;Internet Pass-Through Service; C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe

    R2 RfButtonDriverService;Dritek RF Button Command Service; C:\Windows\RfBtnSvc64.exe

    R2 SamsungAllShareV2.0;Samsung AllShare PC; C:\Program Files (x86)\Samsung\AllShare\AllShareDMS\AllShareDMS.exe

    R2 TwonkyProxy;TwonkyProxy; C:\Program Files (x86)\Twonky\TwonkyServer\twonkyproxy.exe

    R2 TwonkyServer;TwonkyServer; C:\Program Files (x86)\Twonky\TwonkyServer\twonkystarter.exe

    R2 TwonkyWebDav;TwonkyWebDav; C:\Program Files (x86)\Twonky\TwonkyServer\twonkywebdav.exe

    R2 UNS;Intel(R) Management and Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe

    R3 ePowerSvc;ePower Service; C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe

    S2 gupdate;Google Update-service (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

    S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe

    S3 cphs;Intel(R) Content Protection HECI Service; C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe

    S3 DeviceFastLaneService;Device Fast-lane Service; C:\Program Files\Acer\Acer Device Fast-lane\DeviceFastLaneSvc.exe

    S3 EgisTec Ticket Service;EgisTec Ticket Service; C:\Program Files (x86)\Common Files\EgisTec\Services\EgisTicketService.exe

    S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe

    S3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe

    S3 GamesAppService;GamesAppService; C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe

    S3 gupdatem;Google Update-service (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

    S3 gusvc;Google Updater Service; C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe

    S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe

    S3 SimpleSlideShowServer;SimpleSlideShowServer; C:\Program Files (x86)\Samsung\AllShare\AllShareSlideShowService.exe

    —————–EOF—————–

  • Ben

    Hallo,

    Schakel eerst de Antivirussoftware uit voordat je zoek.exe download.

    Schakel je antivirus- en antispywareprogramma's tijdelijk uit, deze kunnen namelijk conflicteren met Zoek.exe.

    Download Zoek.exe naar het bureaublad.

    * Wanneer Internet Explorer of een andere browser of virusscanner melding geeft dat dit bestand onveilig zou zijn kun je negeren, dit is namelijk een onterechte waarschuwing.

    Zoek.exe uitvoeren

    Wanneer u problemen ondervindt bij het uitvoeren van dit programma of bepaalde foutmeldingen te zien krijgt laat dit dan even weten in uw bericht.

    * Dubbelklik vervolgens op Zoek.exe om de tool te starten.

    * Windows Vista, 7 en 8 gebruikers dienen de tool als “administrator” uit te voeren door middel van de rechtermuisknop en kiezen voor Als Administrator uitvoeren.

    * Kopieer nu onderstaande vet gedrukte code en plak die in het grote invulvenster:

    * Note: Dit script is speciaal bedoeld voor deze computer, gebruik dit dan ook niet op andere computers met een gelijkaardig probleem.

    firefoxlook;

    torpigcheck;

    emptyfolderscheck;delete

    C:\WINDOWS\tasks\8c244a42-a8ba-4acf-82d6-f0624865f1a9.job;f

    C:\WINDOWS\tasks\c7d50b1d-2690-4014-92c0-4801c6396a16-1.job;f

    C:\WINDOWS\tasks\c7d50b1d-2690-4014-92c0-4801c6396a16-11.job;f

    C:\WINDOWS\tasks\c7d50b1d-2690-4014-92c0-4801c6396a16-2.job;f

    C:\WINDOWS\tasks\c7d50b1d-2690-4014-92c0-4801c6396a16-3.job;f

    C:\WINDOWS\tasks\c7d50b1d-2690-4014-92c0-4801c6396a16-4.job;f

    C:\WINDOWS\tasks\c7d50b1d-2690-4014-92c0-4801c6396a16-5.job;f

    C:\WINDOWS\tasks\c7d50b1d-2690-4014-92c0-4801c6396a16-5_user.job;f

    C:\WINDOWS\tasks\c7d50b1d-2690-4014-92c0-4801c6396a16-6.job;f

    C:\WINDOWS\tasks\c7d50b1d-2690-4014-92c0-4801c6396a16-7.job;f

    C:\Program Files (x86)\HD+v2.1;fs

    C:\Program Files (x86)\globalUpdate;fs

    chromelook;

    standardsearch;

    filesrcm;

    autoclean;

    startupall;

    * Klik nu op de knop "Run script".

    * Wacht nu geduldig af tot er een logje opent (dit kan na een herstart zijn als deze benodigd is).

    * Mocht na de herstart geen logje verschijnen, start zoek.exe dan opnieuw, de log verschijnt dan alsnog.

    * Post het geopende logje in het volgende bericht.

  • Sjaak

    Hoi Ben,

    bedankt voor je reactie. Hier de log:

    Zoek.exe v5.0.0.0 Updated 27-08-2014

    Tool run by Sjaak on wo 27-08-2014 at 16:47:23,07.

    Microsoft Windows 8.1 6.3.9600 x64

    Running in: Normal Mode Internet Access Detected

    Launched: C:\Users\Sjaak\Desktop\zoek.exe

    ==== System Restore Info ======================

    27-8-2014 16:48:34 Zoek.exe System Restore Point Created Succesfully.

    ==== Torpig Check ======================

    HKEY_CLASSES_ROOT\Directory\shellex\CopyHookHandlers\Ath_CopyHook {8e10a039-fe03-4f9c-b7e1-c5eeeaf53735} C:\Program Files (x86)\Bluetooth Suite\FolderViewImpl.dll

    HKEY_CLASSES_ROOT\Directory\shellex\CopyHookHandlers\ClearfiCopyHook {ED32C084-BABB-11E1-B491-D4D66088709B} C:\Program Files (x86)\Acer\clear.fi plug-in\Clearfishellext_x64.dll

    HKEY_CLASSES_ROOT\Directory\shellex\CopyHookHandlers\FileSystem {217FC9C0-3AEA-1069-A2DB-08002B30309D} %SystemRoot%\system32\shell32.dll

    HKEY_CLASSES_ROOT\Directory\shellex\CopyHookHandlers\Sharing {40dd6e20-7c17-11ce-a804-00aa003ca9f6} %SystemRoot%\system32\ntshrui.dll

    2013-09-24 11:57:41 d—–w- C:\PROGRA~3\4064

    2013-09-24 11:57:41 4 —-a-w- 5A95CF975D10ED1E1B2290737C08AA99 C:\PROGRA~3\4064\541183968.dat

    2013-09-24 11:57:41 4 —-a-w- 5A95CF975D10ED1E1B2290737C08AA99 C:\PROGRA~3\4064\541183968.dll

    2013-09-24 11:57:58 716800 —-a-w- 44EB4E5DB0BFC66D2C59883DB3CB8B68 C:\PROGRA~3\4064\qnud.dat

    2013-09-24 11:57:58 96256 —-a-w- 83230E91794DD90C9215D4B76C69F486 C:\PROGRA~3\4064\xes2.dat

    ==== Empty Folders Check ======================

    C:\PROGRA~2\AVS4YOU deleted successfully

    C:\PROGRA~2\DirectX deleted successfully

    C:\PROGRA~2\FirstRowSportApp.com deleted successfully

    C:\PROGRA~2\Freemake deleted successfully

    C:\PROGRA~2\GUMB8D3.tmp deleted successfully

    C:\PROGRA~3\Freemake deleted successfully

    C:\PROGRA~3\Pinnacle Studio Plus deleted successfully

    C:\Users\Britt\AppData\Roaming\Memeo deleted successfully

    C:\Users\Imka\AppData\Roaming\Memeo deleted successfully

    C:\Users\Imka\AppData\Roaming\Publish Providers deleted successfully

    C:\Users\Sjaak\AppData\Roaming\Vso deleted successfully

    C:\Users\Britt\AppData\Local\VirtualStore deleted successfully

    C:\Users\Imka\AppData\Local\MusicPlayer deleted successfully

    ==== Deleting CLSID Registry Keys ======================

    ==== Deleting CLSID Registry Values ======================

    ==== Running Processes ======================

    C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe

    C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe

    C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe

    C:\Program Files (x86)\Bonjour\mDNSResponder.exe

    C:\Program Files (x86)\Acer\Acer Cloud\CCDMonitorService.exe

    C:\Program Files (x86)\Launch Manager\dsiwmis.exe

    C:\Program Files (x86)\HTC\HTC Sync Manager\HSMServiceEntry.exe

    C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe

    C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe

    C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe

    C:\Program Files (x86)\Twonky\TwonkyServer\twonkyproxy.exe

    C:\Program Files (x86)\Twonky\TwonkyServer\twonkystarter.exe

    C:\Program Files (x86)\Launch Manager\LMutilps32.exe

    C:\Program Files (x86)\Twonky\TwonkyServer\twonkywebdav.exe

    C:\Program Files (x86)\Qualcomm Atheros\Ath_WlanAgent.exe

    C:\Program Files (x86)\Twonky\TwonkyServer\TwonkyServer.exe

    C:\Program Files (x86)\HTC\HTC Sync Manager\HTC Sync\adb.exe

    C:\Program Files (x86)\Launch Manager\LManager.exe

    C:\Program Files (x86)\CyberLink\MediaEspresso\DeviceDetector\DeviceDetector.exe

    C:\Program Files (x86)\Google\Drive\googledrivesync.exe

    C:\Program Files (x86)\MEDION\MEDION NAS TOOL\MEDION NAS TOOL.exe

    C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe

    C:\Program Files (x86)\Twonky\TwonkyServer\twonkytray.exe

    C:\Users\Imka\AppData\Roaming\Dropbox\bin\Dropbox.exe

    C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe

    C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe

    C:\Program Files (x86)\Samsung\AllShare\AllShareAgent.exe

    C:\Program Files (x86)\Google\Drive\googledrivesync.exe

    C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe

    C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin

    C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuEmailOutlookAgent.exe

    C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuBrowserIEAgent.exe

    C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe

    C:\Program Files (x86)\Samsung\AllShare\AllShareDMS\AllShareDMS.exe

    C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe

    C:\Program Files (x86)\Launch Manager\LMutilps32.exe

    C:\Program Files (x86)\Launch Manager\LManager.exe

    C:\Program Files (x86)\Mozilla Firefox\firefox.exe

    C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe

    C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerPlugin_14_0_0_145.exe

    C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerPlugin_14_0_0_145.exe

    C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe

    C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe

    C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe

    C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin

    C:\Program Files (x86)\Samsung\AllShare\AllShareAgent.exe

    C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuBrowserIEAgent.exe

    C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuEmailOutlookAgent.exe

    C:\Users\Sjaak\Desktop\zoek.exe

    C:\WINDOWS\SysWOW64\cmd.exe

    C:\WINDOWS\SysWOW64\cmd.exe

    C:\WINDOWS\SysWOW64\cmd.exe

    ==== Deleting Services ======================

    ==== FireFox Fix ======================

    ProfilePath: C:\Users\Britt\AppData\Roaming\Mozilla\Firefox\Profiles\v0qeeipi.default

    user.js not found

    —- FireFox user.js and prefs.js backups —-

    prefs_27-08-2014_1702_.backup

    ProfilePath: C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184

    user.js not found

    —- Lines wajam removed from prefs.js —-

    user_pref(“extensions.ajacobtoddhotmailcom62846.62846.internaldb.monetization_plugin_bundledUrls.value”, "%7B%22dealply_s%22%3A%7B%22urls%22%3A%5B%22s

    —- Lines crossrider removed from prefs.js —-

    user_pref(“extensions.crossrider.bic”, “147f33cb3e6cbc77d5c4b4ed57266d81”);

    —- Lines ajacobtoddhotmailcom62846 removed from prefs.js —-

    user_pref(“extensions.ajacobtoddhotmailcom62846.62846.active”, true);

    user_pref(“extensions.ajacobtoddhotmailcom62846.62846.addressbar”, “NA”);

    user_pref(“extensions.ajacobtoddhotmailcom62846.62846.addressbarenhanced”, “”);

    user_pref(“extensions.ajacobtoddhotmailcom62846.62846.asyncdb.was_copied”, “true”);

    user_pref(“extensions.ajacobtoddhotmailcom62846.62846.asyncinternaldb.was_copied”, “true”);

    user_pref(“extensions.ajacobtoddhotmailcom62846.62846.backgroundver”, 1);

    user_pref(“extensions.ajacobtoddhotmailcom62846.62846.certdomaininstaller”, “”);

    user_pref(“extensions.ajacobtoddhotmailcom62846.62846.changeprevious”, false);

    user_pref(“extensions.ajacobtoddhotmailcom62846.62846.cookie.InstallationTime.expiration”, “Fri Feb 01 2030 00:00:00 GMT+0100”);

    user_pref(“extensions.ajacobtoddhotmailcom62846.62846.cookie.InstallationTime.value”, “%221408534933%22”);

    user_pref(“extensions.ajacobtoddhotmailcom62846.62846.cookie.InstallerParams.expiration”, “Fri Feb 01 2030 00:00:00 GMT+0100”);

    user_pref(“extensions.ajacobtoddhotmailcom62846.62846.cookie.InstallerParams.value”, "%7B%22source_id%22%3A%22001972%22%2C%22sub_id%22%3A%220%22%2C%22

    user_pref(“extensions.ajacobtoddhotmailcom62846.62846.description”, “Lights out for YouTube”);

    user_pref(“extensions.ajacobtoddhotmailcom62846.62846.domain”, “”);

    user_pref(“extensions.ajacobtoddhotmailcom62846.62846.enablesearch”, false);

    user_pref(“extensions.ajacobtoddhotmailcom62846.62846.homepage”, “”);

    user_pref(“extensions.ajacobtoddhotmailcom62846.62846.iframe”, false);

    user_pref(“extensions.ajacobtoddhotmailcom62846.62846.InstallationThankYouPage”, true);

    user_pref(“extensions.ajacobtoddhotmailcom62846.62846.InstallationTime”, 1408534933);

    user_pref(“extensions.ajacobtoddhotmailcom62846.62846.internaldb.__defualt_browser__.expiration”, “Fri Feb 01 2030 00:00:00 GMT+0100”);

    user_pref(“extensions.ajacobtoddhotmailcom62846.62846.internaldb.__defualt_browser__.value”, “%22ff%22”);

    user_pref(“extensions.ajacobtoddhotmailcom62846.62846.internaldb._installer_additional_info.expiration”, “Fri Feb 01 2030 00:00:00 GMT+0100”);

    user_pref(“extensions.ajacobtoddhotmailcom62846.62846.internaldb._installer_additional_info.value”, “%7B%22asw%22%3A%5B4%2C-2147483643%2C0%5D%7D”);

    user_pref(“extensions.ajacobtoddhotmailcom62846.62846.internaldb.installer.expiration”, “Fri Feb 01 2030 00:00:00 GMT+0100”);

    user_pref(“extensions.ajacobtoddhotmailcom62846.62846.internaldb.installer.value”, "%7B%22InstallerIdentifiers%22%3A%7B%22installer_bic%22%3A%22A04155

    user_pref(“extensions.ajacobtoddhotmailcom62846.62846.internaldb.InstallerIdentifiers.expiration”, “Fri Feb 01 2030 00:00:00 GMT+0100”);

    user_pref(“extensions.ajacobtoddhotmailcom62846.62846.internaldb.InstallerIdentifiers.value”, "%7B%22installer_bic%22%3A%22A04155FE9F2642E7B1282A65AF4

    user_pref(“extensions.ajacobtoddhotmailcom62846.62846.internaldb.InstallerParams.expiration”, “Fri Feb 01 2030 00:00:00 GMT+0100”);

    user_pref(“extensions.ajacobtoddhotmailcom62846.62846.internaldb.InstallerParams.value”, "%7B%22source_id%22%3A%22001972%22%2C%22sub_id%22%3A%220%22%2

    user_pref(“extensions.ajacobtoddhotmailcom62846.62846.internaldb.InstallerParamsCache.expiration”, “Fri Feb 01 2030 00:00:00 GMT+0100”);

    user_pref(“extensions.ajacobtoddhotmailcom62846.62846.internaldb.InstallerParamsCache.value”, "%7B%22source_id%22%3A%22001972%22%2C%22sub_id%22%3A%220

    user_pref(“extensions.ajacobtoddhotmailcom62846.62846.internaldb.InstallerUserIdentifiersCache.expiration”, “Fri Feb 01 2030 00:00:00 GMT+0100”);

    user_pref(“extensions.ajacobtoddhotmailcom62846.62846.internaldb.InstallerUserIdentifiersCache.value”, "%7B%22installer_bic%22%3A%22A04155FE9F2642E7B1

    user_pref(“extensions.ajacobtoddhotmailcom62846.62846.internaldb.monetization_plugin__disable_bi_pixel_.expiration”, "Mon Sep 01 2014 20:09:57 GMT+020

    user_pref(“extensions.ajacobtoddhotmailcom62846.62846.internaldb.monetization_plugin__disable_bi_pixel_.value”, “true”);

    user_pref(“extensions.ajacobtoddhotmailcom62846.62846.internaldb.monetization_plugin_bundledUrls.expiration”, “Fri Feb 01 2030 00:00:00 GMT+0100”);

    user_pref(“extensions.ajacobtoddhotmailcom62846.62846.internaldb.monetization_plugin_bundledWithHash.expiration”, “Fri Feb 01 2030 00:00:00 GMT+0100”)

    user_pref(“extensions.ajacobtoddhotmailcom62846.62846.internaldb.monetization_plugin_bundledWithHash.value”, “null”);

    user_pref(“extensions.ajacobtoddhotmailcom62846.62846.internaldb.monetization_plugin_last_executable_request.expiration”, "Wed Aug 27 2014 09:45:28 GM

    user_pref(“extensions.ajacobtoddhotmailcom62846.62846.internaldb.monetization_plugin_last_executable_request.value”, "%22http%3A//data-cdn.mbamupdates

    user_pref(“extensions.ajacobtoddhotmailcom62846.62846.internaldb.monetization_plugin_notBundledArr_.expiration”, “Fri Feb 01 2030 00:00:00 GMT+0100”);

    user_pref(“extensions.ajacobtoddhotmailcom62846.62846.internaldb.monetization_plugin_notBundledArr_.value”, “%5B%5D”);

    user_pref(“extensions.ajacobtoddhotmailcom62846.62846.internaldb.monetization_plugin_regBundledWithSoftware.expiration”, "Fri Feb 01 2030 00:00:00 GMT

    user_pref(“extensions.ajacobtoddhotmailcom62846.62846.internaldb.monetization_plugin_regBundledWithSoftware.value”, “%7B%7D”);

    user_pref(“extensions.ajacobtoddhotmailcom62846.62846.internaldb.Resources_appVer.expiration”, “Fri Feb 01 2030 00:00:00 GMT+0100”);

    user_pref(“extensions.ajacobtoddhotmailcom62846.62846.internaldb.Resources_appVer.value”, “41”);

    user_pref(“extensions.ajacobtoddhotmailcom62846.62846.internaldb.Resources_lastVersion.expiration”, “Fri Feb 01 2030 00:00:00 GMT+0100”);

    user_pref(“extensions.ajacobtoddhotmailcom62846.62846.internaldb.Resources_lastVersion.value”, “1”);

    user_pref(“extensions.ajacobtoddhotmailcom62846.62846.internaldb.Resources_meta.expiration”, “Fri Feb 01 2030 00:00:00 GMT+0100”);

    user_pref(“extensions.ajacobtoddhotmailcom62846.62846.internaldb.Resources_meta.value”, “%7B%7D”);

    user_pref(“extensions.ajacobtoddhotmailcom62846.62846.internaldb.Resources_nextCheck.expiration”, “Wed Aug 27 2014 02:29:50 GMT+0200”);

    user_pref(“extensions.ajacobtoddhotmailcom62846.62846.internaldb.Resources_nextCheck.value”, “true”);

    user_pref(“extensions.ajacobtoddhotmailcom62846.62846.internaldb.Resources_queue.expiration”, “Fri Feb 01 2030 00:00:00 GMT+0100”);

    user_pref(“extensions.ajacobtoddhotmailcom62846.62846.internaldb.Resources_queue.value”, “%7B%7D”);

    user_pref(“extensions.ajacobtoddhotmailcom62846.62846.jacobtodd@hotmail.comajacobtoddhotmailcom62846_dbWasSet”, true);

    user_pref(“extensions.ajacobtoddhotmailcom62846.62846.jacobtodd@hotmail.comajacobtoddhotmailcom62846_dbWasSet_FF25_FIX”, true);

    user_pref(“extensions.ajacobtoddhotmailcom62846.62846.jacobtodd@hotmail.comasyncdb_dbWasSet”, true);

    user_pref(“extensions.ajacobtoddhotmailcom62846.62846.jacobtodd@hotmail.comasyncdb_dbWasSet_FF25_FIX”, true);

    user_pref(“extensions.ajacobtoddhotmailcom62846.62846.jacobtodd@hotmail.comasyncinternaldb_dbWasSet”, true);

    user_pref(“extensions.ajacobtoddhotmailcom62846.62846.jacobtodd@hotmail.comasyncinternaldb_dbWasSet_FF25_FIX”, true);

    user_pref(“extensions.ajacobtoddhotmailcom62846.62846.lastDailyReport”, “1409077789380”);

    user_pref(“extensions.ajacobtoddhotmailcom62846.62846.lastUpdate”, “1409077788383”);

    user_pref(“extensions.ajacobtoddhotmailcom62846.62846.manifesturl”, “”);

    user_pref(“extensions.ajacobtoddhotmailcom62846.62846.name”, “Cinema-Plus-1.6c”);

    user_pref(“extensions.ajacobtoddhotmailcom62846.62846.newtab”, “”);

    user_pref(“extensions.ajacobtoddhotmailcom62846.62846.opensearch”, “”);

    user_pref(“extensions.ajacobtoddhotmailcom62846.62846.pluginsurl”, “http://js.loadclientinputsrv.com/plugin/apps/62846/plugins/na/ff/plugins.json”);

    user_pref(“extensions.ajacobtoddhotmailcom62846.62846.pluginsversion”, 34);

    user_pref(“extensions.ajacobtoddhotmailcom62846.62846.publisher”, “Cinema Plus”);

    user_pref(“extensions.ajacobtoddhotmailcom62846.62846.searchstatus”, 0);

    user_pref(“extensions.ajacobtoddhotmailcom62846.62846.setnewtab”, false);

    user_pref(“extensions.ajacobtoddhotmailcom62846.62846.thankyou”, “”);

    user_pref(“extensions.ajacobtoddhotmailcom62846.62846.updateinterval”, 360);

    user_pref(“extensions.ajacobtoddhotmailcom62846.62846.ver”, 41);

    user_pref(“extensions.ajacobtoddhotmailcom62846.apps”, “62846”);

    user_pref(“extensions.ajacobtoddhotmailcom62846.bic”, “147f33cb3e6cbc77d5c4b4ed57266d81”);

    user_pref(“extensions.ajacobtoddhotmailcom62846.cid”, 62846);

    user_pref(“extensions.ajacobtoddhotmailcom62846.firstrun”, false);

    user_pref(“extensions.ajacobtoddhotmailcom62846.hadappinstalled”, true);

    user_pref(“extensions.ajacobtoddhotmailcom62846.installationdate”, 1408535147);

    user_pref(“extensions.ajacobtoddhotmailcom62846.installerAdditionalInfo”, “{\”asw\":}");

    user_pref(“extensions.ajacobtoddhotmailcom62846.modetype”, “production”);

    user_pref(“extensions.ajacobtoddhotmailcom62846.reportInstall”, true);

    user_pref(“extensions.ajacobtoddhotmailcom62846.statsDailyCounter”, 14);

    —- FireFox user.js and prefs.js backups —-

    prefs_27-08-2014_1702_.backup

    ProfilePath: C:\Users\Imka\AppData\Roaming\Thunderbird\Profiles\wgawe7qf.default

    user.js not found

    —- FireFox user.js and prefs.js backups —-

    prefs_27-08-2014_1702_.backup

    ProfilePath: C:\Users\Sjaak\AppData\Roaming\AMozilla\AFirefox\Profiles\ff.profile

    user.js not found

    —- FireFox user.js and prefs.js backups —-

    prefs_27-08-2014_1702_.backup

    ProfilePath: C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default

    user.js not found

    —- Lines freehdsp removed from prefs.js —-

    user_pref(“extensions.bootstrappedAddons”, “{\”fhdp3@freehdsp.tv\“:{\”version\“:\”3.0\“,\”type\“:\”extension\“,\”descriptor\“:\”C:\\\\Users\\\\Sjaak\\

    —- Lines freehdsp modified from prefs.js —-

    user_pref(“extensions.installCache”, "[{\“name\”:\“app-global\”,\“addons\”:{\“{972ce4c6-7e08-4474-a285-3208198ce6fd}\”:{\“descriptor\”:\"C:\\\\Program

    —- Lines ajacobtoddhotmailcom62846 removed from prefs.js —-

    user_pref(“extensions.ajacobtoddhotmailcom62846.62846.cookie.InstallationTime.expiration”, “Fri Feb 01 2030 00:00:00 GMT+0100”);

    user_pref(“extensions.ajacobtoddhotmailcom62846.62846.cookie.InstallationTime.value”, “1408535238”);

    user_pref(“extensions.ajacobtoddhotmailcom62846.62846.InstallationTime”, 1408535238);

    user_pref(“extensions.ajacobtoddhotmailcom62846.62846.jacobtodd@hotmail.comajacobtoddhotmailcom62846_dbWasSet”, true);

    user_pref(“extensions.ajacobtoddhotmailcom62846.62846.jacobtodd@hotmail.comajacobtoddhotmailcom62846_dbWasSet_FF25_FIX”, true);

    user_pref(“extensions.ajacobtoddhotmailcom62846.bic”, “147f33e1425bc66cac39251a643e0722”);

    user_pref(“extensions.ajacobtoddhotmailcom62846.installationdate”, 1408535238);

    user_pref(“extensions.ajacobtoddhotmailcom62846.installerAdditionalInfo”, “{\”asw\":}");

    user_pref(“extensions.ajacobtoddhotmailcom62846.reportInstall”, true);

    —- FireFox user.js and prefs.js backups —-

    prefs_27-08-2014_1702_.backup

    ProfilePath: C:\Users\Sjaak\AppData\Roaming\Thunderbird\Profiles\u7j9t04y.default

    user.js not found

    —- FireFox user.js and prefs.js backups —-

    prefs_27-08-2014_1702_.backup

    ==== Deleting Files \ Folders ======================

    C:\Program Files (x86)\HD+v2.1 deleted

    C:\Program Files (x86)\globalUpdate deleted

    C:\PROGRA~3\4064 deleted

    C:\Users\Britt\.android deleted

    C:\Users\Imka\.android deleted

    C:\Users\Sjaak\.android deleted

    C:\PROGRA~2\COMMON~1\337 deleted

    C:\PROGRA~2\FreeHDSport TV deleted

    C:\PROGRA~2\FreeHDSport.TV deleted

    C:\PROGRA~2\Desk 365 deleted

    C:\PROGRA~2\Plus-HD-2.2 deleted

    C:\PROGRA~3\eSafe deleted

    C:\PROGRA~3\boost_interprocess deleted

    C:\Users\Imka\AppData\Local\VideoDownloadConverter_4z deleted

    C:\Users\Sjaak\AppData\Local\globalUpdate deleted

    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Search.lnk deleted

    C:\WINDOWS\Tasks\c7d50b1d-2690-4014-92c0-4801c6396a16-1.job deleted

    C:\WINDOWS\Tasks\c7d50b1d-2690-4014-92c0-4801c6396a16-11.job deleted

    C:\WINDOWS\Tasks\c7d50b1d-2690-4014-92c0-4801c6396a16-2.job deleted

    C:\WINDOWS\Tasks\c7d50b1d-2690-4014-92c0-4801c6396a16-3.job deleted

    C:\WINDOWS\Tasks\c7d50b1d-2690-4014-92c0-4801c6396a16-4.job deleted

    C:\WINDOWS\Tasks\c7d50b1d-2690-4014-92c0-4801c6396a16-5.job deleted

    C:\WINDOWS\Tasks\c7d50b1d-2690-4014-92c0-4801c6396a16-5_user.job deleted

    C:\WINDOWS\Tasks\c7d50b1d-2690-4014-92c0-4801c6396a16-6.job deleted

    C:\WINDOWS\Tasks\c7d50b1d-2690-4014-92c0-4801c6396a16-7.job deleted

    C:\windows\SysNative\Tasks\c7d50b1d-2690-4014-92c0-4801c6396a16-1 deleted

    C:\windows\SysNative\Tasks\c7d50b1d-2690-4014-92c0-4801c6396a16-11 deleted

    C:\windows\SysNative\Tasks\c7d50b1d-2690-4014-92c0-4801c6396a16-2 deleted

    C:\windows\SysNative\Tasks\c7d50b1d-2690-4014-92c0-4801c6396a16-3 deleted

    C:\windows\SysNative\Tasks\c7d50b1d-2690-4014-92c0-4801c6396a16-4 deleted

    C:\windows\SysNative\Tasks\c7d50b1d-2690-4014-92c0-4801c6396a16-5 deleted

    C:\windows\SysNative\Tasks\c7d50b1d-2690-4014-92c0-4801c6396a16-5_user deleted

    C:\windows\SysNative\Tasks\c7d50b1d-2690-4014-92c0-4801c6396a16-6 deleted

    C:\windows\SysNative\Tasks\c7d50b1d-2690-4014-92c0-4801c6396a16-7 deleted

    C:\WINDOWS\tasks\8c244a42-a8ba-4acf-82d6-f0624865f1a9.job deleted

    C:\windows\SysNative\tasks\8c244a42-a8ba-4acf-82d6-f0624865f1a9 deleted

    C:\WINDOWS\tasks\globalUpdateUpdateTaskMachineCore.job deleted

    C:\WINDOWS\tasks\globalUpdateUpdateTaskMachineUA.job deleted

    C:\windows\SysNative\tasks\globalUpdateUpdateTaskMachineCore deleted

    C:\windows\SysNative\tasks\globalUpdateUpdateTaskMachineUA deleted

    C:\WINDOWS\SysNative\config\systemprofile\Searches deleted

    C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\jetpack deleted

    C:\Users\Sjaak\AppData\Roaming\Thunderbird\Profiles\u7j9t04y.default\extensions\staged deleted

    C:\Users\Sjaak\Desktop\Continue 7-Zip Installation.lnk deleted

    C:\PROGRA~2\Mozilla Firefox\browser\searchplugins\qvo6.xml deleted

    “C:\windows\Installer\47a8d.msi” deleted

    “C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default\extensions\fhdp3@freehdsp.tv.xpi” deleted

    ==== System Specs ======================

    Windows: Windows Version 6.2 (Build 9200)

    Memory (RAM): 8009 MB

    CPU Info: Intel(R) Core(TM) i3-2328M CPU @ 2.20GHz

    CPU Speed: 2195,6 MHz

    Sound Card: Speakers (Realtek High Definiti |

    Display Adapters: Intel(R) HD Graphics 3000 | Intel(R) HD Graphics 3000

    Monitors: 1x; Generic PnP Monitor |

    Screen Resolution: 1600 X 900 - 32 bit

    Network: Network Present

    Network Adapters: Microsoft Wi-Fi Direct Virtual Adapter | Qualcomm Atheros AR8151 PCI-E Gigabit Ethernet-controller (NDIS 6.30) | Qualcomm Atheros AR5BWB222 Wireless-netwerkadapter

    CD / DVD Drives: 1x (D: | ) D: MATSHITADVD-RAM UJ8C0

    Ports: COM Ports NOT Present. LPT Port NOT Present.

    Mouse: 5 Button Wheel Mouse Present

    Hard Disks: C: 676,5GB | E: 116,3GB | F: 115,1GB

    Hard Disks - Free: C: 247,9GB | E: 33,1GB | F: 74,4GB

    Manufacturer *: Insyde Corp.

    BIOS Info: AT/AT COMPATIBLE | | ACRSYS - 1

    Time Zone: West-Europa (standaardtijd)

    Motherboard *: Type2 - Board Vendor Name1 VA70_HC

    Country: Nederland

    Language: NLD

    ==== System Specs (Software) ======================

    Anti-Virus: Avira Desktop On-access scanning disabled (Outdated)

    Anti-Virus: Windows Defender On-access scanning disabled (Outdated)

    Anti-Spyware: Avira Desktop disabled (Outdated)

    Anti-Spyware: Windows Defender disabled (Outdated)

    Default Browser: Firefox 31.0

    Internet Explorer Version: 11.0.9600.17239

    Mozilla Firefox version: 31.0 (x86 nl)

    Google Chrome version: 36.0.1985.143

    Adobe Reader version: 11.0.06.70

    Flash Player version: 14.0.0.145

    ==== Files Recently Created / Modified ======================

    ====== C:\WINDOWS ====

    ====== C:\Users\Sjaak\AppData\Local\Temp ====

    2014-08-26 20:47:25 2CB9E77DBE264277AA11E296DCD204A9 43008 —-a-w- C:\Users\Imka\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpwn4rka.dll

    2014-08-20 11:20:19 5E64F1B60ED01797C643720761CB6DDB 171520 —-a-w- C:\Users\Imka\AppData\Local\Temp\Rar$EXa0.529\fjoiner.exe

    2014-08-20 11:02:25 5E64F1B60ED01797C643720761CB6DDB 171520 —-a-w- C:\Users\Imka\AppData\Local\Temp\Rar$EXa0.126\fjoiner.exe

    2014-08-19 20:46:52 FDADD2809215E1B11F848E270F35665E 184144 —-a-w- C:\Users\Imka\AppData\Local\Temp\{1362E602-9625-42D3-B57F-CDA9D26F9DA8}\PixieTool-SVE.dll

    2014-08-19 20:46:52 C3A9E63ACDFC264AAF49B101D344A728 184656 —-a-w- C:\Users\Imka\AppData\Local\Temp\{1362E602-9625-42D3-B57F-CDA9D26F9DA8}\PixieTool-NON.dll

    2014-08-19 20:46:52 B4751F405396568F2FF9DF69F6BBB41B 184144 —-a-w- C:\Users\Imka\AppData\Local\Temp\{1362E602-9625-42D3-B57F-CDA9D26F9DA8}\PixieTool-RON.dll

    2014-08-19 20:46:52 672A8549CC28C20015EE01267D897757 185680 —-a-w- C:\Users\Imka\AppData\Local\Temp\{1362E602-9625-42D3-B57F-CDA9D26F9DA8}\PixieTool-PTG.dll

    2014-08-19 20:46:52 5AB3C4016102623C51AC109EABA7FB92 185680 —-a-w- C:\Users\Imka\AppData\Local\Temp\{1362E602-9625-42D3-B57F-CDA9D26F9DA8}\PixieTool-RUS.dll

    2014-08-19 20:46:52 4A341F072779F039D1E832C7C0FF5ED3 185680 —-a-w- C:\Users\Imka\AppData\Local\Temp\{1362E602-9625-42D3-B57F-CDA9D26F9DA8}\PixieTool-NLD.dll

    2014-08-19 20:46:52 488861423CD7781B990B240D5D9F2AC1 185168 —-a-w- C:\Users\Imka\AppData\Local\Temp\{1362E602-9625-42D3-B57F-CDA9D26F9DA8}\PixieTool-TUR.dll

    2014-08-19 20:46:52 27206D9714665CEB67ADC7E24A591B3B 186704 —-a-w- C:\Users\Imka\AppData\Local\Temp\{1362E602-9625-42D3-B57F-CDA9D26F9DA8}\PixieTool-POL.dll

    2014-08-19 20:46:52 10F16E04D942BE02A1DB934CDEE587E3 168272 —-a-w- C:\Users\Imka\AppData\Local\Temp\{1362E602-9625-42D3-B57F-CDA9D26F9DA8}\PixieTool-KOR.dll

    2014-08-19 20:46:51 B5C94D2EE456AE68C28ABEE62A22ACB2 187728 —-a-w- C:\Users\Imka\AppData\Local\Temp\{1362E602-9625-42D3-B57F-CDA9D26F9DA8}\PixieTool-ITA.dll

    2014-08-19 20:46:51 A68DAD096125A78ABE3F6F67681ECF93 190288 —-a-w- C:\Users\Imka\AppData\Local\Temp\{1362E602-9625-42D3-B57F-CDA9D26F9DA8}\PixieTool-ELL.dll

    2014-08-19 20:46:51 A67DAA1B719020C1A7D29BEB03171F22 187216 —-a-w- C:\Users\Imka\AppData\Local\Temp\{1362E602-9625-42D3-B57F-CDA9D26F9DA8}\PixieTool-ESP.dll

    2014-08-19 20:46:51 90E0028517DF98A5E8A26641FEEBB8C4 162128 —-a-w- C:\Users\Imka\AppData\Local\Temp\{1362E602-9625-42D3-B57F-CDA9D26F9DA8}\PixieTool-CHS.dll

    2014-08-19 20:46:51 86EE493472BC57B24C06C71BA64ADEA7 162640 —-a-w- C:\Users\Imka\AppData\Local\Temp\{1362E602-9625-42D3-B57F-CDA9D26F9DA8}\PixieTool-CHT.dll

    2014-08-19 20:46:51 6D2D6DCB39CE129763CCF2B392F99137 1623376 —-a-w- C:\Users\Imka\AppData\Local\Temp\{1362E602-9625-42D3-B57F-CDA9D26F9DA8}\HelperDLL.dll

    2014-08-19 20:46:51 676C53F8F2347F71D9923E81A20AD04B 186192 —-a-w- C:\Users\Imka\AppData\Local\Temp\{1362E602-9625-42D3-B57F-CDA9D26F9DA8}\PixieTool-HUN.dll

    2014-08-19 20:46:51 60CBA68B4700DCD5CAE2CBC2A5091C8D 169808 —-a-w- C:\Users\Imka\AppData\Local\Temp\{1362E602-9625-42D3-B57F-CDA9D26F9DA8}\PixieTool-JPN.dll

    2014-08-19 20:46:51 5A3BC78A37465961FFABF9157075D42C 192336 —-a-w- C:\Users\Imka\AppData\Local\Temp\{1362E602-9625-42D3-B57F-CDA9D26F9DA8}\PixieTool-DEU.dll

    2014-08-19 20:46:51 544128797937EB477C3126E5F3EF896E 422224 —-a-w- C:\Users\Imka\AppData\Local\Temp\{1362E602-9625-42D3-B57F-CDA9D26F9DA8}\Pixie.dll

    2014-08-19 20:46:51 4CA1F5BC08315B80FDE6EB72CD6398FA 28672 —-a-w- C:\Users\Imka\AppData\Local\Temp\{1362E602-9625-42D3-B57F-CDA9D26F9DA8}\Translator.dll

    2014-08-19 20:46:51 3B0612714E1DDB6BB06CA39CFB96440F 189776 —-a-w- C:\Users\Imka\AppData\Local\Temp\{1362E602-9625-42D3-B57F-CDA9D26F9DA8}\PixieTool-FRA.dll

    2014-08-19 20:46:51 2533A32711C5922899AE849A14AECBA0 185168 —-a-w- C:\Users\Imka\AppData\Local\Temp\{1362E602-9625-42D3-B57F-CDA9D26F9DA8}\PixieTool-DAN.dll

    2014-08-19 20:46:51 09DA0AE8838393CD9406D762D6362BD9 184656 —-a-w- C:\Users\Imka\AppData\Local\Temp\{1362E602-9625-42D3-B57F-CDA9D26F9DA8}\PixieTool-CSY.dll

    2014-08-19 20:46:51 0305329976394B341EDF927EF18617F5 184144 —-a-w- C:\Users\Imka\AppData\Local\Temp\{1362E602-9625-42D3-B57F-CDA9D26F9DA8}\PixieTool-FIN.dll

    2014-08-19 20:46:50 9DDF685228CE95EFB5E1E07259D9F5F2 1176912 —-a-w- C:\Users\Imka\AppData\Local\Temp\{1362E602-9625-42D3-B57F-CDA9D26F9DA8}\PixieTool.exe

    2014-08-19 14:01:17 5B672B6FA8986959988032DA24480748 24477056 —-a-w- C:\Users\Imka\AppData\Local\Temp\tmpwvqrzl\googledrivesync.exe

    2014-08-18 18:49:22 301A9C8739ED3ED955A1BDC472D26F32 11264 —-a-w- C:\Users\Imka\AppData\Local\Temp\nsi275A.tmp\System.dll

    2014-08-18 18:49:21 6FD02E9C6FCB3E36BDBCC3D99A993083 118784 —-a-w- C:\Users\Imka\AppData\Local\Temp\nsi275A.tmp\NSIS_Picasa_Unicode.dll

    2014-08-17 18:33:33 0AD0FBD0048066261BEB9B422CBA5E74 68096 —-a-w- C:\Users\Imka\AppData\Local\Temp\nsf115F.tmp\DropboxNSISTools.dll

    2014-08-17 18:33:26 FC38D5993EC3C029E2A9D9068D3EB146 30208 —-a-w- C:\Users\Imka\AppData\Local\Temp\nsf115F.tmp\UAC.dll

    ====== Java Cache =====

  • Sjaak

    DEEL 2

    ====== C:\WINDOWS\SysWOW64 =====

    2014-08-20 11:42:03 4BD8F121ACBD27C16696F39E228D818E 194 —-a-w- C:\WINDOWS\SysWOW64\AlbumMakerSettings.mos

    2014-08-17 18:30:21 128EC9879D462F89829E663417FE5DBD 710144 —-a-w- C:\WINDOWS\SysWOW64\rpcrt4.dll

    2014-08-17 18:30:16 38045850ACB96313A1983A8803302906 35480 —-a-w- C:\WINDOWS\SysWOW64\TsWpfWrp.exe

    2014-08-17 18:22:46 2C01D8EA2B0FA834597FCD96AAAE4F52 406400 —-a-w- C:\WINDOWS\SysWOW64\dxgi.dll

    2014-08-17 18:22:44 DB3ED0BA26D7C598481A23E7D06A370E 2344448 —-a-w- C:\WINDOWS\SysWOW64\Wpc.dll

    2014-08-17 18:22:37 E9B28B60C0272E2E1E462E6FB38E6B55 367104 —-a-w- C:\WINDOWS\SysWOW64\dxtmsft.dll

    2014-08-17 18:22:37 6D017C0E499443ACDE3D9B5DCD753F32 1169920 —-a-w- C:\WINDOWS\SysWOW64\urlmon.dll

    2014-08-17 18:22:37 444EB30B1610A35FC99D62A91B2BCAA7 69632 —-a-w- C:\WINDOWS\SysWOW64\mshtmled.dll

    2014-08-17 18:22:37 24FA5F74D3B4BA62539DF87285BA934E 597504 —-a-w- C:\WINDOWS\SysWOW64\jscript9diag.dll

    2014-08-17 18:22:37 1A05CFA45B6AEBFCCC835DCF68CBD1D0 526336 —-a-w- C:\WINDOWS\SysWOW64\msfeeds.dll

    2014-08-17 18:22:36 8453DDF167CE2986AA4AB04BC6824925 17524224 —-a-w- C:\WINDOWS\SysWOW64\mshtml.dll

    2014-08-17 18:22:35 FF4A917DD7C387BD2715A5F67307FED1 2184704 —-a-w- C:\WINDOWS\SysWOW64\iertutil.dll

    2014-08-17 18:22:35 E70C00791A18866BB23B3A652E3390A0 2001920 —-a-w- C:\WINDOWS\SysWOW64\inetcpl.cpl

    2014-08-17 18:22:34 90FF511B751A0327D07C4073760F1578 11772928 —-a-w- C:\WINDOWS\SysWOW64\ieframe.dll

    2014-08-17 18:22:34 239575F9EA0D227516843EEE8B7342CA 239616 —-a-w- C:\WINDOWS\SysWOW64\dxtrans.dll

    2014-08-17 18:22:32 7C1BFC2ABE297BCA1A7BA77A8292C088 4204032 —-a-w- C:\WINDOWS\SysWOW64\jscript9.dll

    2014-08-17 18:22:32 18A3154606E3F8945956948A4E708007 704512 —-a-w- C:\WINDOWS\SysWOW64\ieapfltr.dll

    2014-08-17 18:22:24 030041C8800A1781134B6EC3E3EF3F9C 291840 —-a-w- C:\WINDOWS\SysWOW64\iedkcs32.dll

    2014-08-17 18:22:23 B945BAA81B4805AD6BDDF4D026DCFB47 1792512 —-a-w- C:\WINDOWS\SysWOW64\wininet.dll

    2014-08-17 18:22:21 FEE3E022B00A5165ED645E38C1E6C776 60416 —-a-w- C:\WINDOWS\SysWOW64\JavaScriptCollectionAgent.dll

    2014-08-17 18:22:20 272420427EB96EA052C719AA796C09F2 61952 —-a-w- C:\WINDOWS\SysWOW64\MshtmlDac.dll

    2014-08-17 18:22:19 9D16B568E318F49535AD72539C9997C2 455168 —-a-w- C:\WINDOWS\SysWOW64\vbscript.dll

    2014-08-17 18:21:05 5BD2BD14753D3B0ADDE842CDF25A4C60 2144984 —-a-w- C:\WINDOWS\SysWOW64\mfcore.dll

    2014-08-17 18:21:03 949E0E42DAAD0418513B44C31A697CA5 1797896 —-a-w- C:\WINDOWS\SysWOW64\d3d9.dll

    2014-08-17 18:21:01 E28501E3A241DDC5DC65382E55661B1D 285696 —-a-w- C:\WINDOWS\SysWOW64\dhcpcore.dll

    2014-08-17 18:21:01 1E14463F10B324B02EB2DA7415345D15 1473080 —-a-w- C:\WINDOWS\SysWOW64\ntdll.dll

    2014-08-17 18:21:00 E65B5352AD0743F1F59BDA9466719EFE 265216 —-a-w- C:\WINDOWS\SysWOW64\SkyDriveShell.dll

    2014-08-17 18:20:59 EA15CC7B75A2DE287E3B0C266A35490C 235008 —-a-w- C:\WINDOWS\SysWOW64\framedynos.dll

    2014-08-17 18:20:59 E4783EB6A6B2D04F3B541B378E843617 229888 —-a-w- C:\WINDOWS\SysWOW64\dhcpcore6.dll

    2014-08-17 18:20:59 A750BB0258ECF6265A903905A0B14EB3 198656 —-a-w- C:\WINDOWS\SysWOW64\WebClnt.dll

    2014-08-17 18:20:59 0CCDFED2DFCD4FBA73EE989249379458 52736 —-a-w- C:\WINDOWS\SysWOW64\ncobjapi.dll

    2014-08-17 18:20:58 BEA7A26C2C22381B6DD88758352B9D9B 62976 —-a-w- C:\WINDOWS\SysWOW64\dhcpcsvc.dll

    2014-08-17 18:20:58 BA6E52B0D82682EDE4B49D9CCC7D529B 207360 —-a-w- C:\WINDOWS\SysWOW64\framedyn.dll

    2014-08-17 18:20:58 855D508F0053CEDC3BBAF2CB245A674A 1035264 —-a-w- C:\WINDOWS\SysWOW64\actxprxy.dll

    2014-08-17 18:20:58 57E0A896C38C41C8B5B7F3127F8FD0D9 56320 —-a-w- C:\WINDOWS\SysWOW64\dhcpcsvc6.dll

    2014-08-17 18:20:58 4E07710A2C9EA43E7509BF7D0452430E 106496 —-a-w- C:\WINDOWS\SysWOW64\Robocopy.exe

    2014-08-17 18:20:57 191B7F25BE13D9F9E56B2B4EA595AC62 11776 —-a-w- C:\WINDOWS\SysWOW64\d3d8thk.dll

    2014-08-17 18:20:32 FBE8AE41ED2A9FE4C2DE069C522CA9C0 12711424 —-a-w- C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll

    2014-08-17 18:20:31 854E970293BA92F9BB69FFD1CE051D9C 189016 —-a-w- C:\WINDOWS\SysWOW64\rsaenh.dll

    2014-08-17 18:20:30 684CF6A72A8DF7D66D262AC4A6E07845 270848 —-a-w- C:\WINDOWS\SysWOW64\DaOtpCredentialProvider.dll

    2014-08-17 18:20:23 86DB4BA87BAF3D467D04821602E586A9 3304448 —-a-w- C:\WINDOWS\SysWOW64\msi.dll

    2014-08-17 18:20:23 16CDD058883E38FB43D582FB080F721A 2318336 —-a-w- C:\WINDOWS\SysWOW64\authui.dll

    2014-08-17 18:20:22 F8D0951A75826AD557CFAC323A936AA6 281088 —-a-w- C:\WINDOWS\SysWOW64\msihnd.dll

    ====== C:\WINDOWS\SysWOW64\drivers =====

    ====== C:\WINDOWS\Sysnative =====

    2014-08-17 18:30:21 1BB9CC78C91536CBA7B04B61ED0F85C4 1273184 —-a-w- C:\WINDOWS\Sysnative\rpcrt4.dll

    2014-08-17 18:30:16 6DBE73C09215E281F4283641144110A5 35480 —-a-w- C:\WINDOWS\Sysnative\TsWpfWrp.exe

    2014-08-17 18:22:46 59EAFAE3A34B4925990A2E679CA91C5B 517528 —-a-w- C:\WINDOWS\Sysnative\dxgi.dll

    2014-08-17 18:22:46 454978FB3D24DE5C4199162D5F81FBEE 2133504 —-a-w- C:\WINDOWS\Sysnative\dwmcore.dll

    2014-08-17 18:22:44 E7DE316FEEFC79327CFAD8F527979CC0 3118080 —-a-w- C:\WINDOWS\Sysnative\Wpc.dll

    2014-08-17 18:22:44 E2F4125BFAC99244088324A1841C0B83 3048880 —-a-w- C:\WINDOWS\Sysnative\WpcMon.exe

    2014-08-17 18:22:44 6BC31FB4E24A962C98801D3687A984C0 2861056 —-a-w- C:\WINDOWS\Sysnative\WpcWebSync.dll

    2014-08-17 18:22:35 FE7D99399F7761AA2695A7B1AD30DAAF 1431040 —-a-w- C:\WINDOWS\Sysnative\urlmon.dll

    2014-08-17 18:22:34 F00D0AE7648CA45C6434E2885485BE0B 452096 —-a-w- C:\WINDOWS\Sysnative\dxtmsft.dll

    2014-08-17 18:22:34 1FD1F16C35946BA28FDEB40F18B7729D 631808 —-a-w- C:\WINDOWS\Sysnative\msfeeds.dll

    2014-08-17 18:22:33 39A85C005BCDEEF4092646EBBC2526AA 2087936 —-a-w- C:\WINDOWS\Sysnative\inetcpl.cpl

    2014-08-17 18:22:32 DB382D89D8004F40BD2C55BAE6A15B30 2774528 —-a-w- C:\WINDOWS\Sysnative\iertutil.dll

    2014-08-17 18:22:31 1DE8B71A1C7D8943034188556AF50B07 292864 —-a-w- C:\WINDOWS\Sysnative\dxtrans.dll

    2014-08-17 18:22:30 2639E152D246F2A651F09764807CA153 85504 —-a-w- C:\WINDOWS\Sysnative\mshtmled.dll

    2014-08-17 18:22:30 1B26610C1659EF54ED000233FB96F20C 13547008 —-a-w- C:\WINDOWS\Sysnative\ieframe.dll

    2014-08-17 18:22:29 BAC44396088ECC1C9021ED3E3345337C 846336 —-a-w- C:\WINDOWS\Sysnative\ieapfltr.dll

    2014-08-17 18:22:29 920F690FC7424DE71888AA2E46E917EA 758272 —-a-w- C:\WINDOWS\Sysnative\jscript9diag.dll

    2014-08-17 18:22:29 472C409F9B0FF67C1015F511C73E1889 5824512 —-a-w- C:\WINDOWS\Sysnative\jscript9.dll

    2014-08-17 18:22:27 ECA387DCD57F683C52171C766CF400F0 23645696 —-a-w- C:\WINDOWS\Sysnative\mshtml.dll

    2014-08-17 18:22:24 38D14F3D0A289050CA9BF8E98F37313F 333312 —-a-w- C:\WINDOWS\Sysnative\iedkcs32.dll

    2014-08-17 18:22:23 8E71A5CB5312B8392D4DA4CA37BB5868 2266624 —-a-w- C:\WINDOWS\Sysnative\wininet.dll

    2014-08-17 18:22:22 52D2151908C2A6388B6561A373488F6F 692736 —-a-w- C:\WINDOWS\Sysnative\ie4uinit.exe

    2014-08-17 18:22:21 C02C78DE9BB4E68F6C78B1588ADD6ADC 83968 —-a-w- C:\WINDOWS\Sysnative\MshtmlDac.dll

    2014-08-17 18:22:21 19FA60D3AE1804A559306DE931A5B415 72704 —-a-w- C:\WINDOWS\Sysnative\JavaScriptCollectionAgent.dll

    2014-08-17 18:22:20 6ED6DA2A04F8F0C9BDAD647284BAEFB6 548352 —-a-w- C:\WINDOWS\Sysnative\vbscript.dll

    2014-08-17 18:21:04 C1E44A99F7CF8C3A08CD5ADDF451636C 2125344 —-a-w- C:\WINDOWS\Sysnative\d3d9.dll

    2014-08-17 18:21:03 0CD0356C5BBCFDC1B7BCEEDE74AB348B 2140888 —-a-w- C:\WINDOWS\Sysnative\mfcore.dll

    2014-08-17 18:21:02 EA432A85ABF371E14FB364D5F4405897 403968 —-a-w- C:\WINDOWS\Sysnative\vpnike.dll

    2014-08-17 18:21:02 B6E947CE54A5AAD55484E0D3BC2D5948 1025536 —-a-w- C:\WINDOWS\Sysnative\localspl.dll

    2014-08-17 18:21:01 D71845D255EA3FDC96A2DED98EE4C7D9 2844160 —-a-w- C:\WINDOWS\Sysnative\actxprxy.dll

    2014-08-17 18:21:01 CED9FA1ECCF3E6B7028940FE22C69B40 1726224 —-a-w- C:\WINDOWS\Sysnative\ntdll.dll

    2014-08-17 18:21:01 98D0985521BF8F7086EA9C860898A1EE 721408 —-a-w- C:\WINDOWS\Sysnative\fveapi.dll

    2014-08-17 18:21:01 05DE04005CE0D84D0E6AD21CAEB369C6 353280 —-a-w- C:\WINDOWS\Sysnative\dhcpcore.dll

    2014-08-17 18:21:00 6B374D279DC423FE69DB8DD1401E84FC 301056 —-a-w- C:\WINDOWS\Sysnative\framedynos.dll

    2014-08-17 18:21:00 61FE99A86352AD6E27FA480CDC8B225A 285696 —-a-w- C:\WINDOWS\Sysnative\SkyDriveShell.dll

    2014-08-17 18:20:59 FBB1841434072FFA76E4AD287448E34A 262656 —-a-w- C:\WINDOWS\Sysnative\framedyn.dll

    2014-08-17 18:20:59 E07C80468D0C599BFF01D9D4EC7AEDC3 339456 —-a-w- C:\WINDOWS\Sysnative\bdesvc.dll

    2014-08-17 18:20:59 D261A12A43D33122CB90E70D3BC1CC68 226816 —-a-w- C:\WINDOWS\Sysnative\WebClnt.dll

    2014-08-17 18:20:59 6CDCCD5323EEB8EBD66E02CB8C9C703F 118272 —-a-w- C:\WINDOWS\Sysnative\winbici.dll

    2014-08-17 18:20:59 2616E8E9C8B66A67CFB6197E9517A2F2 123392 —-a-w- C:\WINDOWS\Sysnative\Robocopy.exe

    2014-08-17 18:20:59 20FB137ADDE1255F15F265A7BD9579BE 827392 —-a-w- C:\WINDOWS\Sysnative\BFE.DLL

    2014-08-17 18:20:59 1824052F17B12B5D7B21445B869EE9F2 71168 —-a-w- C:\WINDOWS\Sysnative\ncobjapi.dll

    2014-08-17 18:20:59 10AC9494ECE22A2362E4E4D98C528D01 271872 —-a-w- C:\WINDOWS\Sysnative\dhcpcore6.dll

    2014-08-17 18:20:58 DEA76F90F9777E3427D70E380222B23B 1063424 —-a-w- C:\WINDOWS\Sysnative\IKEEXT.DLL

    2014-08-17 18:20:58 D3883FBCA97D10C8A39632D6CDDC6E85 65024 —-a-w- C:\WINDOWS\Sysnative\dhcpcsvc6.dll

    2014-08-17 18:20:58 CFD6DBED27511D7A5FBE33AFA7E6B669 76800 —-a-w- C:\WINDOWS\Sysnative\BulkOperationHost.exe

    2014-08-17 18:20:58 7E1EBDB3424337ABB553F249A7811D94 87552 —-a-w- C:\WINDOWS\Sysnative\dhcpcsvc.dll

    2014-08-17 18:20:57 B7CC32E00C5C5152D221DF182827F58E 50745 —-a-w- C:\WINDOWS\Sysnative\srms.dat

    2014-08-17 18:20:57 71BAEAFD05B3040173F5BBEA2CFE9607 997888 —-a-w- C:\WINDOWS\Sysnative\reseteng.dll

    2014-08-17 18:20:47 C27B20D9AA9BE41CCBFD512AABB0E6C3 697856 —-a-w- C:\WINDOWS\Sysnative\aepdu.dll

    2014-08-17 18:20:46 2D347489E43FAD4E51FDB51BEEBF13F4 527360 —-a-w- C:\WINDOWS\Sysnative\aeinv.dll

    2014-08-17 18:20:42 BCCFB97B1B68DD18F2BDACFE37409386 716800 —-a-w- C:\WINDOWS\Sysnative\SkyDriveTelemetry.dll

    2014-08-17 18:20:42 11FD8DDAB6014EECCE88F1F581604C30 1120256 —-a-w- C:\WINDOWS\Sysnative\SkyDrive.exe

    2014-08-17 18:20:42 04142EC4BDD7F502922914F65A5EE1D1 4756992 —-a-w- C:\WINDOWS\Sysnative\SyncEngine.dll

    2014-08-17 18:20:36 50A49F3F16EF82E30BFB11E6B6A8F4A6 16871936 —-a-w- C:\WINDOWS\Sysnative\Windows.UI.Xaml.dll

    2014-08-17 18:20:31 B312E157D20E727F30EAB3A250441B6F 284672 —-a-w- C:\WINDOWS\Sysnative\WUDFHost.exe

    2014-08-17 18:20:31 9CDC2059A23E3C9B57696178508777E7 99840 —-a-w- C:\WINDOWS\Sysnative\WUDFSvc.dll

    2014-08-17 18:20:31 42D257559F97B30A94A027EB4555C62F 323584 —-a-w- C:\WINDOWS\Sysnative\DaOtpCredentialProvider.dll

    2014-08-17 18:20:31 313117AE2B0986ED7D3AA6AE10603239 216368 —-a-w- C:\WINDOWS\Sysnative\rsaenh.dll

    2014-08-17 18:20:31 1A54E3DF2CBB8DBE8A17C87BB07E3A7E 209408 —-a-w- C:\WINDOWS\Sysnative\WUDFPlatform.dll

    2014-08-17 18:20:30 08DCA300264238F9AE941302321F3D54 423768 —-a-w- C:\WINDOWS\Sysnative\hal.dll

    2014-08-17 18:20:26 F381B380B7B2704EA4C0F8D8C49C1C50 623616 —-a-w- C:\WINDOWS\Sysnative\MDMAgent.exe

    2014-08-17 18:20:24 00AD15C6BA3C337CB68A476C0AD05338 918528 —-a-w- C:\WINDOWS\Sysnative\MrmCoreR.dll

    2014-08-17 18:20:23 68F887EF33C09CDA957A51ECE871D642 2642944 —-a-w- C:\WINDOWS\Sysnative\authui.dll

    2014-08-17 18:20:23 28E0C3AAA68579ABD9A27B92DFD5F119 2790912 —-a-w- C:\WINDOWS\Sysnative\msi.dll

    2014-08-17 18:20:23 10D8859CF01C1284603582ABD9B0482C 114520 —-a-w- C:\WINDOWS\Sysnative\consent.exe

    2014-08-17 18:20:23 08914C8989AB93F5EC3A452D014E2C8D 356352 —-a-w- C:\WINDOWS\Sysnative\msihnd.dll

    ====== C:\WINDOWS\Sysnative\drivers =====

    2014-08-26 19:47:49 8A50D5304E6AE48664CF5838EC32F647 122584 —-a-w- C:\WINDOWS\Sysnative\drivers\MBAMSwissArmy.sys

    2014-08-26 19:47:17 F92B0E478C0FAA6D6661E6E977247E60 25816 —-a-w- C:\WINDOWS\Sysnative\drivers\mbam.sys

    2014-08-26 19:47:17 9D9ED48F841EA37AA5310D54B9E5D3C7 91352 —-a-w- C:\WINDOWS\Sysnative\drivers\mbamchameleon.sys

    2014-08-26 19:47:17 0664F6335F108F38FE08C3CA747311EE 64216 —-a-w- C:\WINDOWS\Sysnative\drivers\mwac.sys

    2014-08-17 18:22:46 313DCE665B57000B18CB26C6B6A10DFE 1557848 —-a-w- C:\WINDOWS\Sysnative\drivers\dxgkrnl.sys

    2014-08-17 18:21:00 7A1A3F213CDB3363D179D5014272025D 402432 —-a-w- C:\WINDOWS\Sysnative\drivers\mrxsmb.sys

    2014-08-17 18:20:59 674A4702E4E144E8710ED1A2EC6DD049 96768 —-a-w- C:\WINDOWS\Sysnative\drivers\agilevpn.sys

    2014-08-17 18:20:59 65ED7B9CFEA893DF7748D5FF692690DE 38912 —-a-w- C:\WINDOWS\Sysnative\drivers\vwifimp.sys

    2014-08-17 18:20:58 35BF5C5F5E3C9902C98978C7640574DA 71680 —-a-w- C:\WINDOWS\Sysnative\drivers\vwififlt.sys

    2014-08-17 18:20:47 5C42CEE3E2018E1DFC6E3E17240A432A 206848 —-a-w- C:\WINDOWS\Sysnative\drivers\mrxsmb20.sys

    2014-08-17 18:20:31 FE0ADF5028EB8C1339B66B3AEDE3FEF9 440664 -c–a-w- C:\WINDOWS\Sysnative\drivers\usbport.sys

    2014-08-17 18:20:31 D537815E450A149752C15868392AD1F3 110592 —-a-w- C:\WINDOWS\Sysnative\drivers\WUDFPf.sys

    2014-08-17 18:20:31 93435654DCA210298BA0F986EB51C679 419672 -c–a-w- C:\WINDOWS\Sysnative\drivers\usbhub.sys

    2014-08-17 18:20:31 83C9C45D59C72FEFDAE9A5686BE31FEA 467800 -c–a-w- C:\WINDOWS\Sysnative\drivers\USBHUB3.SYS

    2014-08-17 18:20:31 7CCBBCEE408A5DBE3FE47297DB5A6CFC 227840 —-a-w- C:\WINDOWS\Sysnative\drivers\WUDFRd.sys

    2014-08-17 18:20:31 48BA326A3DBA5B5BEB5F2777F4618696 89944 -c–a-w- C:\WINDOWS\Sysnative\drivers\usbehci.sys

    2014-08-17 18:20:31 25AC0B50A71938890970E1508F107196 2518360 —-a-w- C:\WINDOWS\Sysnative\drivers\tcpip.sys

    2014-08-17 18:20:30 D79920BE4E6683D3AB50F71457A4F6C6 27480 -c–a-w- C:\WINDOWS\Sysnative\drivers\usbd.sys

    2014-08-17 18:20:30 064260B3A5868AC894A4943543BC7AB7 37376 -c–a-w- C:\WINDOWS\Sysnative\drivers\usbuhci.sys

    ====== C:\WINDOWS\Tasks ======

    ====== C:\WINDOWS\Temp ======

    ======= C:\Program Files =====

    ======= C:\PROGRA~2 =====

    2014-08-26 20:56:45 ——– d—–w- C:\PROGRA~2\trend micro

    2014-08-20 11:41:49 ——– d—–w- C:\PROGRA~2\MakeitOne

    2014-08-20 11:27:00 ——– d—–w- C:\PROGRA~2\Audacity

    ======= C: =====

    ====== C:\Users\Sjaak\AppData\Roaming ======

    2014-08-20 12:02:52 ——– d—–w- C:\Users\Imka\AppData\Roaming\MakeitOne

    2014-08-20 11:51:27 ——– d—–w- C:\Users\Sjaak\AppData\Roaming\WinRAR

    2014-08-20 11:42:03 ——– d—–w- C:\Users\Sjaak\AppData\Roaming\MakeitOne

    2014-08-20 11:27:24 ——– d—–w- C:\Users\Imka\AppData\Roaming\Audacity

    2014-08-20 11:24:05 ——– d—–w- C:\Users\Sjaak\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MP3 Splitter & Joiner

    2014-08-20 11:24:05 ——– d—–w- C:\Users\Sjaak\AppData\Local\EZSoftMagic

    2014-08-19 09:23:55 ——– d—–w- C:\Users\Imka\AppData\Roaming\Samsung

    ====== C:\Users\Sjaak ======

    2014-08-26 20:56:17 8685FAF50C04F9A9C2F56FF64B0B7ACB 1107968 —-a-w- C:\Users\Imka\Downloads\RSIT.exe

    2014-08-26 19:45:29 E90BF9E1562F40140161573B79CD5720 17292760 —-a-w- C:\Users\Imka\Downloads\mbam-setup-2.0.2.1012.exe

    2014-08-20 11:41:49 ——– d—–w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MakeitOne

    2014-08-20 11:26:39 154B76B778B3F13B7662C824FBB64485 22180353 —-a-w- C:\Users\Imka\Downloads\audacity-win-2.0.5.exe

    2014-08-20 11:23:43 2136DA02D652B9E3705493160479D139 1165480 —-a-w- C:\Users\Imka\Downloads\mp3mate.exe

    2014-08-18 18:25:20 ——– d—–w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spotnet

    2014-08-18 18:24:52 0F00095C28C068C80F5AF04F5F7958FB 11065159 —-a-w- C:\Users\Imka\Downloads\spotnet181.exe

    ====== C: exe-files ==

    2014-08-27 12:18:24 B88B8DA6B88D10319658833BF4C01CFD 62751 —-a-w- C:\Users\Imka\Spotnet\Neighbors (2014) Bad Neighbours 720p HQ AC3 DD51 (Ingebakken Subs)\Name Reverse- Windows and Mac\WINDOWS\Setup.exe

    2014-08-26 20:56:46 9A2347903D6EDB84C10F288BC0578C1C 388608 —-a-w- C:\Program Files (x86)\trend micro\Sjaak.exe

    2014-08-26 20:56:17 8685FAF50C04F9A9C2F56FF64B0B7ACB 1107968 —-a-w- C:\Users\Imka\Downloads\RSIT.exe

    2014-08-26 19:45:29 E90BF9E1562F40140161573B79CD5720 17292760 —-a-w- C:\Users\Imka\Downloads\mbam-setup-2.0.2.1012.exe

    2014-08-24 13:28:33 B88B8DA6B88D10319658833BF4C01CFD 62751 —-a-w- C:\Users\Imka\Spotnet\The Prince (2014) 720P HQ AC3 DD51 (Ingebakken Subs)\Name Reverse- Windows and Mac\WINDOWS\Setup.exe

    === C: other files ==

    2014-08-26 20:46:11 DE0983FE4B830699312D35A990B3AE1B 1945 —-a-w- C:\Users\Imka\AppData\Local\Temp\_MEI43082\resources\chrome_ext\nknebiagdodnminbdpflhpkgfpeijdbf_live.crx

    2014-08-26 20:46:11 82F5C942549405F61A8808D0EA0FA9E2 25575 —-a-w- C:\Users\Imka\AppData\Local\Temp\_MEI43082\resources\chrome_ext\apdfllckaahabafndbhieahigkjlhalf_live.crx

    2014-08-26 19:47:49 8A50D5304E6AE48664CF5838EC32F647 122584 —-a-w- C:\Windows\System32\drivers\MBAMSwissArmy.sys

    2014-08-26 19:47:17 F92B0E478C0FAA6D6661E6E977247E60 25816 —-a-w- C:\Windows\System32\drivers\mbam.sys

    2014-08-26 19:47:17 9D9ED48F841EA37AA5310D54B9E5D3C7 91352 —-a-w- C:\Windows\System32\drivers\mbamchameleon.sys

    2014-08-26 19:47:17 0664F6335F108F38FE08C3CA747311EE 64216 —-a-w- C:\Windows\System32\drivers\mwac.sys

    ==== Startup Registry Enabled ======================

    “Google Update”=“C:\Users\Sjaak\AppData\Local\Google\Update\GoogleUpdate.exe /c”

    “ConnectionCenter”=“C:\Users\Imka\AppData\Local\Citrix\ICA Client\concentr.exe /startup”

    “Plex Media Server”=“C:\Program Files (x86)\Plex\Plex Media Server\Plex Media Server.exe”

    “GoogleDriveSync”=“C:\Program Files (x86)\Google\Drive\googledrivesync.exe /autostart”

    “MEDION NAS TOOL”=“C:\Program Files (x86)\MEDION\MEDION NAS TOOL\MEDION NAS TOOL.exe”

    “Google Update”=“C:\Users\Imka\AppData\Local\Google\Update\GoogleUpdate.exe /c”

    “Dolby Home Theater v4”=“C:\Dolby PCEE4\pcee4.exe -autostart”

    “avgnt”=“C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe /min”

    “Adobe ARM”=“C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe”

    “TaskMngr”=“wscript.exe ”

    “AllShareAgent”=“C:\Program Files (x86)\Samsung\AllShare\AllShareAgent.exe”

    “Google Update”=“C:\Users\Sjaak\AppData\Local\Google\Update\GoogleUpdate.exe /c”

    ==== Startup Registry Enabled x64 ======================

    “Apoint”=“C:\Program Files\Apoint2K\Apoint.exe”

    “RtHDVCpl”=“C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s”

    “RtHDVBg_Dolby”=“C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe /FORPCEE4 ”

    “BtPreLoad”=“C:\Program Files (x86)\Bluetooth Suite\BtPreLoad.exe”

    “Zune Launcher”=“C:\Program Files\Zune\ZuneLauncher.exe”

    “IgfxTray”=“C:\WINDOWS\system32\igfxtray.exe”

    “HotKeysCmds”=“C:\WINDOWS\system32\hkcmd.exe”

    “Persistence”=“C:\WINDOWS\system32\igfxpers.exe”

    ==== Startup Folders ======================

    2013-05-25 08:59:30 1101 —-a-w- C:\Users\Imka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk

    2013-05-27 19:46:54 1239 —-a-w- C:\Users\Imka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk

    2013-06-22 13:30:57 1239 —-a-w- C:\Users\Sjaak\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk

    2012-09-03 06:44:54 2171 —-a-w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Acer Backup Manager Tray.lnk

    2013-08-10 18:01:05 1182 —-a-w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\TwonkyServer.lnk

    ==== Task Scheduler Jobs ======================

    C:\WINDOWS\tasks\Adobe Flash Player Updater.job –a——– C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe

    C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job –a——–

    C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job –a——– C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

    C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-3463471253-882201401-3829445294-1001Core.job –a——– C:\Users\Sjaak\AppData\Local\Google\Update\GoogleUpdate.exe

    C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-3463471253-882201401-3829445294-1001UA.job –a——– C:\Users\Sjaak\AppData\Local\Google\Update\GoogleUpdate.exe

    C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-3463471253-882201401-3829445294-1004Core.job –a——–

    C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-3463471253-882201401-3829445294-1004UA.job –a——–

    ==== Other Scheduled Tasks ======================

    “C:\WINDOWS\SysNative\tasks\Adobe Flash Player Updater”

    “C:\WINDOWS\SysNative\tasks\ALU”

    “C:\WINDOWS\SysNative\tasks\ALUAgent”

    “C:\WINDOWS\SysNative\tasks\CreateChoiceProcessTask”

    “C:\WINDOWS\SysNative\tasks\DeviceDetector”

    “C:\WINDOWS\SysNative\tasks\EgisUpdate”

    “C:\WINDOWS\SysNative\tasks\GoogleUpdateTaskMachineCore”

    “C:\WINDOWS\SysNative\tasks\GoogleUpdateTaskMachineUA”

    “C:\WINDOWS\SysNative\tasks\GoogleUpdateTaskUserS-1-5-21-3463471253-882201401-3829445294-1001Core”

    “C:\WINDOWS\SysNative\tasks\GoogleUpdateTaskUserS-1-5-21-3463471253-882201401-3829445294-1001UA”

    “C:\WINDOWS\SysNative\tasks\GoogleUpdateTaskUserS-1-5-21-3463471253-882201401-3829445294-1004Core”

    “C:\WINDOWS\SysNative\tasks\GoogleUpdateTaskUserS-1-5-21-3463471253-882201401-3829445294-1004UA”

    “C:\WINDOWS\SysNative\tasks\iuBrowserIEAgent”

    “C:\WINDOWS\SysNative\tasks\iuEmailOutlookAgent”

    “C:\WINDOWS\SysNative\tasks\PMMUpdate”

    “C:\WINDOWS\SysNative\tasks\Power Management”

    “C:\WINDOWS\SysNative\tasks\User_Feed_Synchronization-{1175BD51-AF82-4D20-9901-7A5D037AD0EA}”

    “C:\WINDOWS\SysNative\tasks\User_Feed_Synchronization-{3004A679-231B-4CD0-97B7-0113ADD5BA92}”

    “C:\WINDOWS\SysNative\tasks\User_Feed_Synchronization-{7BC573D6-3188-4043-AFCA-E743DF2B1CB6}”

    “C:\WINDOWS\SysNative\tasks\User_Feed_Synchronization-{DD9DB345-CC45-4A43-B691-D2A92ACFCB16}”

    “C:\WINDOWS\SysNative\tasks\Recovery Management\Notification”

    ==== Folders in C:\PROGRA~3 0-6 Months Old ======================

    2014-05-13 19:04:15 ——– d—–w- C:\PROGRA~3\IDM

    2014-06-29 09:25:08 ——– d—–w- C:\PROGRA~3\Sony

    2014-08-26 19:47:17 ——– d—–w- C:\PROGRA~3\Malwarebytes

    ==== Firefox Extensions ======================

    ProfilePath: C:\Users\Imka\AppData\Roaming\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184

    - jid1bpzDizt9E1R7nwjetpack - %ProfilePath%\extensions\jid1-bpzDizt9E1R7nw@jetpack

    - Widevine Media Optimizer - %ProfilePath%\extensions\{2d3fbcf7-be69-4433-8858-c621a8d0e58d}

    - FirefoxAdKiller - %ProfilePath%\extensions\{b1df372d-8b32-4c7d-b6b4-9c5b78cf6fb1}.xpi

    ProfilePath: C:\Users\Sjaak\AppData\Roaming\Thunderbird\Profiles\u7j9t04y.default

    - Instrument Test - %ProfilePath%\extensions\tbtestpilot@labs.mozilla.com.xpi

    AppDir: C:\Program Files (x86)\Mozilla Firefox

    - Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

    ==== Firefox Plugins ======================

    Profilepath: C:\Users\Sjaak\AppData\Roaming\Mozilla\Firefox\Profiles\zja6ntbe.default

    FB5621842FDABF9F8359775573498FBC - C:\Users\Sjaak\AppData\Local\Google\Update\1.3.24.15\npGoogleUpdate3.dll - Google Update

    4390CCD3790F8D9C427C0C29590C62D7 - C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_145.dll - Shockwave Flash

    5CB01CF141E021DAAE96991A5BA57944 - C:\Users\Sjaak\AppData\Roaming\Mozilla\plugins\npo1d.dll - Google Talk Plugin Video Renderer

    DD31F0C436E4F5E6FA9783FF8A80ADC1 - C:\Users\Sjaak\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll - Google Talk Plugin

    7ABE33792F2787D599B6963E71B9E8CD - C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_202.dll - Shockwave Flash

    ==== Chrome Look ======================

    HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions

    jbolfgndggfhhpbnkgnpjkfhinclbigj - No path found

    Google Docs - Britt\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake

    Google Drive - Britt\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf

    YouTube - Britt\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo

    Google Search - Britt\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf

    Freemake Video Converter - Britt\AppData\Local\Google\Chrome\User Data\Default\Extensions\jbolfgndggfhhpbnkgnpjkfhinclbigj

    Google Wallet - Britt\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda

    Gmail - Britt\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia

    Google Docs - Imka\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake

    Google Drive - Imka\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf

    YouTube - Imka\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo

    Google Search - Imka\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf

    HD+v2.1 - Imka\AppData\Local\Google\Chrome\User Data\Default\Extensions\eglmnheeacbdmbfglhdblefapoebeifj

    Google Wallet - Imka\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda

    Gmail - Imka\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia

    Google Docs - Sjaak\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake

    Google Drive - Sjaak\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf

    YouTube - Sjaak\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo

    Google Search - Sjaak\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf

    Google Wallet - Sjaak\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda

    Gmail - Sjaak\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia

    ==== Chrome Fix ======================

    C:\Users\Britt\AppData\Local\Google\Chrome\User Data\Default\Extensions\jbolfgndggfhhpbnkgnpjkfhinclbigj deleted successfully

    C:\Users\Imka\AppData\Local\Google\Chrome\User Data\Default\Extensions\eglmnheeacbdmbfglhdblefapoebeifj deleted successfully

    ==== Set IE to Default ======================

    Old Values:

    “Start Page”=“http://www.google.nl/”

    “DefaultScope”=“{95510FA0-57D2-4E88-8217-F06C07269DF3}”

    New Values:

    “Start Page”=“http://www.google.nl/”

    “DefaultScope”=“{012E1000-F331-11DB-8314-0800200C9A66}”

    ==== All HKCU SearchScopes ======================

    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes

    {012E1000-F331-11DB-8314-0800200C9A66} Google Url=“http://www.google.com/search?q={searchTerms}”

    {0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url=“http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE11SR”

    {95510FA0-57D2-4E88-8217-F06C07269DF3} Unknown Url=“Not_Found”

    ==== Deleting CLSID Registry Keys ======================

    HKEY_USERS\S-1-5-21-3463471253-882201401-3829445294-1001\Software\Microsoft\Internet Explorer\SearchScopes\{95510FA0-57D2-4E88-8217-F06C07269DF3} deleted successfully

    HKEY_USERS\S-1-5-21-3463471253-882201401-3829445294-1004\Software\Microsoft\Internet Explorer\SearchScopes\{95510FA0-57D2-4E88-8217-F06C07269DF3} deleted successfully

    ==== Deleting CLSID Registry Values ======================

    ==== Deleting Registry Keys ======================

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\203E62EEA6789D84098513925E9B9999 deleted successfully

    HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\jbolfgndggfhhpbnkgnpjkfhinclbigj deleted successfully

    HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{7468ACCE-6FA8-4794-90B9-C28BD9CC79DD} deleted successfully

    HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{EE26E302-876A-48D9-9058-3129E5B99999} deleted successfully

    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\203E62EEA6789D84098513925E9B9999 deleted successfully

    ==== HijackThis Entries ======================

    F2 - REG:system.ini: UserInit=userinit.exe

    O4 - HKLM\..\Run: “C:\Dolby PCEE4\pcee4.exe” -autostart

    O4 - HKLM\..\Run: “C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe” /min

    O4 - HKLM\..\Run: “C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe”

    O4 - HKLM\..\Run: wscript.exe "

    O4 - HKLM\..\Run: C:\Program Files (x86)\Samsung\AllShare\AllShareAgent.exe

    O4 - HKCU\..\Run: “C:\Users\Sjaak\AppData\Local\Google\Update\GoogleUpdate.exe” /c

    O4 - HKUS\S-1-5-21-3463471253-882201401-3829445294-1004\..\Run: “C:\Users\Imka\AppData\Local\Citrix\ICA Client\concentr.exe” /startup (User ‘Imka’)

    O4 - HKUS\S-1-5-21-3463471253-882201401-3829445294-1004\..\Run: “C:\Program Files (x86)\Plex\Plex Media Server\Plex Media Server.exe” (User ‘Imka’)

    O4 - HKUS\S-1-5-21-3463471253-882201401-3829445294-1004\..\Run: “C:\Program Files (x86)\Google\Drive\googledrivesync.exe” /autostart (User ‘Imka’)

    O4 - HKUS\S-1-5-21-3463471253-882201401-3829445294-1004\..\Run: C:\Program Files (x86)\MEDION\MEDION NAS TOOL\MEDION NAS TOOL.exe (User ‘Imka’)

    O4 - HKUS\S-1-5-21-3463471253-882201401-3829445294-1004\..\Run: “C:\Users\Imka\AppData\Local\Google\Update\GoogleUpdate.exe” /c (User ‘Imka’)

    O4 - S-1-5-21-3463471253-882201401-3829445294-1004 Startup: Dropbox.lnk = Imka\AppData\Roaming\Dropbox\bin\Dropbox.exe (User ‘Imka’)

    O4 - S-1-5-21-3463471253-882201401-3829445294-1004 Startup: OpenOffice.org 3.4.1.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe (User ‘Imka’)

    O4 - S-1-5-21-3463471253-882201401-3829445294-1004 User Startup: Dropbox.lnk = Imka\AppData\Roaming\Dropbox\bin\Dropbox.exe (User ‘Imka’)

    O4 - S-1-5-21-3463471253-882201401-3829445294-1004 User Startup: OpenOffice.org 3.4.1.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe (User ‘Imka’)

    O4 - Startup: OpenOffice.org 3.4.1.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe

    O4 - Global Startup: Acer Backup Manager Tray.lnk = C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe

    O4 - Global Startup: TwonkyServer.lnk = C:\Program Files (x86)\Twonky\TwonkyServer\twonkytray.exe

    O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200

    O11 - Options group: Accelerated graphics

    O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll

    O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe

    O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe

    O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)

    O23 - Service: Avira Planner (AntiVirSchedulerService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe

    O23 - Service: Avira Real-Time Protection (AntiVirService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe

    O23 - Service: AtherosSvc - Qualcomm Atheros Commnucations - C:\Program Files (x86)\Bluetooth Suite\adminservice.exe

    O23 - Service: Bonjour-service (Bonjour Service) - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe

    O23 - Service: CCDMonitorService - Acer Incorporated - C:\Program Files (x86)\Acer\Acer Cloud\CCDMonitorService.exe

    O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe

    O23 - Service: Device Fast-lane Service (DeviceFastLaneService) - Acer Incorporated - C:\Program Files\Acer\Acer Device Fast-lane\DeviceFastLaneSvc.exe

    O23 - Service: Dritek WMI Service (DsiWMIService) - Dritek System Inc. - C:\Program Files (x86)\Launch Manager\dsiwmis.exe

    O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)

    O23 - Service: EgisTec Ticket Service - Egis Technology Inc. - C:\Program Files (x86)\Common Files\EgisTec\Services\EgisTicketService.exe

    O23 - Service: ePower Service (ePowerSvc) - Acer Incorporated - C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe

    O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)

    O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe

    O23 - Service: GamesAppService - WildTangent, Inc. - C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe

    O23 - Service: Google Update-service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

    O23 - Service: Google Update-service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe

    O23 - Service: HTCMonitorService - Nero AG - C:\Program Files (x86)\HTC\HTC Sync Manager\HSMServiceEntry.exe

    O23 - Service: IconMan_R - Realsil Microelectronics Inc. - C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe

    O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\WINDOWS\system32\IEEtwCollector.exe (file missing)

    O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe

    O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe

    O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)

    O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe

    O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe

    O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)

    O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)

    O23 - Service: NTI IScheduleSvc - NTI Corporation - C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe

    O23 - Service: Internet Pass-Through Service (PassThru Service) - Unknown owner - C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe

    O23 - Service: Dritek RF Button Command Service (RfButtonDriverService) - Dritek System INC. - C:\Windows\RfBtnSvc64.exe

    O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)

    O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)

    O23 - Service: Samsung AllShare PC (SamsungAllShareV2.0) - Samsung Electronics Co., Ltd. - C:\Program Files (x86)\Samsung\AllShare\AllShareDMS\AllShareDMS.exe

    O23 - Service: SimpleSlideShowServer - Samsung Electronics Co., Ltd. - C:\Program Files (x86)\Samsung\AllShare\AllShareSlideShowService.exe

    O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)

    O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)

    O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)

    O23 - Service: TwonkyProxy - Unknown owner - C:\Program Files (x86)\Twonky\TwonkyServer\twonkyproxy.exe

    O23 - Service: TwonkyServer - PacketVideo - C:\Program Files (x86)\Twonky\TwonkyServer\twonkystarter.exe

    O23 - Service: TwonkyWebDav - Unknown owner - C:\Program Files (x86)\Twonky\TwonkyServer\twonkywebdav.exe

    O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)

    O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe

    O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)

    O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)

    O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)

    O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)

    O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)

    O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)

    O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)

    O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

    O23 - Service: ZAtheros Wlan Agent - Atheros - C:\Program Files (x86)\Qualcomm Atheros\Ath_WlanAgent.exe

    ==== Empty IE Cache ======================

    C:\WINDOWS\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

    C:\Users\Britt\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully

    C:\Users\Britt\AppData\Local\Microsoft\Windows\INetCache\Low\Content.IE5 emptied successfully

    C:\Users\Imka\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully

    C:\Users\Imka\AppData\Local\Microsoft\Windows\INetCache\Low\Content.IE5 emptied successfully

    C:\Users\Sjaak\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully

    C:\Users\Sjaak\AppData\Local\Microsoft\Windows\INetCache\Low\Content.IE5 emptied successfully

    C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully

    C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully

    C:\WINDOWS\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully

    ==== Empty FireFox Cache ======================

    C:\Users\Britt\AppData\Local\Mozilla\Firefox\Profiles\v0qeeipi.default\Cache emptied successfully

    C:\Users\Imka\AppData\Local\Mozilla\Firefox\Profiles\vdlrqgvz.default-1388698062184\Cache emptied successfully

    C:\Users\Sjaak\AppData\Local\Mozilla\Firefox\Profiles\zja6ntbe.default\Cache emptied successfully

    ==== Empty Chrome Cache ======================

    C:\Users\Britt\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully

    C:\Users\Imka\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully

    C:\Users\Sjaak\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully

    ==== Empty All Flash Cache ======================

    Flash Cache Emptied Successfully

    ==== Empty All Java Cache ======================

    No Java Cache Found

    ==== C:\zoek_backup content ======================

    C:\zoek_backup (files=442 folders=75 17466014 bytes)

    ==== Empty Temp Folders ======================

    C:\Users\Britt\AppData\Local\Temp emptied successfully

    C:\Users\Default\AppData\Local\Temp emptied successfully

    C:\Users\Default User\AppData\Local\Temp emptied successfully

    C:\Users\Imka\AppData\Local\Temp will be emptied at reboot

    C:\Users\Sjaak\AppData\Local\Temp will be emptied at reboot

    C:\WINDOWS\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully

    C:\WINDOWS\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully

    C:\WINDOWS\Temp will be emptied at reboot

    ==== After Reboot ======================

    ==== Empty Temp Folders ======================

    C:\WINDOWS\Temp successfully emptied

    C:\Users\Sjaak\AppData\Local\Temp successfully emptied

    ==== Empty Recycle Bin ======================

    C:\$RECYCLE.BIN successfully emptied

    ==== Deleting Files / Folders ======================

    “C:\Users\Imka\AppData\Local\Temp\adb.log” not found

    “C:\Users\Imka\AppData\Local\Temp\AdobeARM.log” not found

    “C:\Users\Imka\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpwn4rka.dll” not found

    “C:\Users\Imka\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpwn4rka.lck” not found

    “C:\Users\Imka\AppData\Local\Temp\avgnt.exe” not found

    “C:\Users\Imka\AppData\Local\Temp\scoped_dir5516_3006” not found

    “C:\Users\Imka\AppData\Local\Temp\_MEI43082” not found

    ==== EOF on wo 27-08-2014 at 17:15:11,09 ======================

  • Ben

    Hallo,

    Dat is een beste opruiming je had een Torpig infectie, we doe nog een controle;

    Download Emsisoft Anti-Malware naar het bureaublad.

    * Dubbelklik op "EmsisoftAntiMalwareSetup.exe" om Emsisoft Anti-Malware te installeren.

    * Kies in het volgende scherm de gewenste taal en klik op "OK"

    * Selecteer de optie "Ik accepteer de licentieovereenkomst“ en klik op ”Installeren"

    * Klik in het licentiescherm op de knop "Volgende" .

    * Vink in het volgende scherm de optie "Update extra talen uit" en klik op volgende.

    * Klik nu op de optie "Computer scannen“ en kies de optie ”Slim“ en druk op de knop ”scan"

    * Laat de gevonden items in quarantaine plaatsen en klik op "Rapport bekijken" plaats de inhoud hiervan in het volgende bericht.

    * klik op volgende nogmaals op volgende en daarna op voltooien.

  • Sjaak

    Emsisoft Anti-Malware - Versie 9.0

    Laatste Update: 27-8-2014 20:14:17

    Gebruikersaccount: VANDIJK\Sjaak

    Scaninstellingen:

    Scanmodus: Slimme scan

    Objecten: Rootkits, Geheugen, Sporen, C:\WINDOWS\, C:\Program Files\, C:\Program Files (x86)\

    Detecteer PUPs: Uit

    Scan archieven: Uit

    ADS Scan: Aan

    Bestandsextensiefilter: Uit

    Geavanceerde cache: Aan

    Directe schijftoegang: Uit

    Scan gestart: 27-8-2014 20:16:12

    Key: HKEY_USERS\S-1-5-21-3463471253-882201401-3829445294-1001\SOFTWARE\SOFTONIC Ontdekt: Application.InstallAd (A)

    Key: HKEY_USERS\S-1-5-21-3463471253-882201401-3829445294-1004\SOFTWARE\SOFTONIC Ontdekt: Application.InstallAd (A)

    Gescand: 264324

    Gevonden: 2

    Scan geëindigd: 27-8-2014 21:40:30

    Scantijd: 1:24:18

  • Sjaak

    Hoi Ben,

    bedankt zover voor je hulp. Ik heb de eerste twee logjes gemaakt terwijl ik was ingelogd op gebruiker ‘Imka’ Ik heb de schoonmaaktools gebruikt toen ik was ingelogd onder gebruiker ‘Sjaak’ De reclames op de websites zijn nu zover ik merk niet meer bij gebruiker ‘Sjaak’ maar nog wel bij ‘Imka’ Moet ik de tools bij alle gebruikers doen?

    groeten Sjaak

Dit topic is gesloten, er kunnen geen reacties meer worden geplaatst.