Het is nu do jun 20, 2013 1:06 pm

Alle tijden zijn GMT + 1 uur [ Zomertijd ]




Dit onderwerp is gesloten, je kunt geen berichten wijzigen of nieuwe antwoorden plaatsen  [ 6 berichten ] 
Auteur Bericht
BerichtGeplaatst: vr mei 04, 2012 3:05 pm 
Offline
Lid

Geregistreerd: vr mei 04, 2012 2:41 pm
Berichten: 3
Besturingssysteem: Windows XP H.E.
Bescherming: Norman Antivirus
Beste helpers,
in mijn IE browser krijg ik telkens weer opnieuw search.conduit.com als startpagina, terwijl ik google.nl wil. Dat kan ik eindeloos blijven veranderen, maar het gaat vanzelf weer terug naar dat rotding van conduit. Ook is er een toolbar van conduit aanwezig, die kan ik ook eindeloos blijven weghalen, komt ook steeds terug.

Naar mijn idee vertragen deze twee vreemde gevallen mijn computer enorm. wat heb ik geprobeerd:
> MalwareBytes Antimalware geinstalleerd en laten scannen (snelle scan). Had er stuk of 10 gevonden, die zijn met succes verwijderd
> Norman Antivirus laten scannen, geen hits, dus ook geen succes
> n.a.v. jullie forum DDS laten scannen, geen idee wat voor resultaat dat gegeven heeft, de logs heb ik in ieder geval.

Bijgevoegd mijn twee logs zoals gevraagd, die van MBAM en DDS.
Bijlage:
logs PietroMaster.zip


Ik hoop dat iemand me kan helpen, ik ben wel erg ervaren met computers, maar dit is net even boven mijn pet.

Gr. Peter


Omhoog
 Profiel  
 
BerichtGeplaatst: vr mei 04, 2012 3:06 pm 
Offline
Moderator
Avatar gebruiker

Geregistreerd: wo apr 13, 2005 3:54 pm
Berichten: 30855
Woonplaats: Kotje aan de kust.
Besturingssysteem: Windows 7
Bescherming: Malwarebytes pro
Download OTL naar je Bureaublad
  • Dubbelklik op OTL.com om het programma te openen. Zorg ervoor dat all andere vensters gesloten zijn, en laat het programma ongestoord zijn werk doen.
  • Zet een vinkje bij Scan All Users.
  • Klik op de knop Quick Scan. Verander de instellingen van OTL niet, tenzij ik je hiervoor specifiek instructies geef. De scan zal niet heel erg lang duren.
    • Er zullen twee Kladblok-vensters geopend worden wanneer de scan klaar is. OTL.Txt en Extras.Txt. Deze bestanden zijn opgeslagen in dezelfde locatie als OTL.
    • Kopieer (Bewerken->Alles selecteren, Bewerken->Kopiëren) en plak (Bewerken->Alles selecteren, Bewerken->Plakken) de inhoud van deze twee bestanden één voor één in je volgende bericht.

Niet als zip maar gewoon kopie/pasta

_________________
Afbeelding
Goed geholpen hier, overweeg een donatie:
loglezer worden?
Lid van Team Opleiding.
tips
traagheidtips


Omhoog
 Profiel  
 
BerichtGeplaatst: vr mei 04, 2012 3:35 pm 
Offline
Lid

Geregistreerd: vr mei 04, 2012 2:41 pm
Berichten: 3
Besturingssysteem: Windows XP H.E.
Bescherming: Norman Antivirus
OTL.TXT
OTL logfile created on: 4-5-2012 15:17:02 - Run 1
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000413 | Country: Nederland | Language: NLD | Date Format: d-M-yyyy

1,87 Gb Total Physical Memory | 1,29 Gb Available Physical Memory | 68,60% Memory free
3,72 Gb Paging File | 3,37 Gb Available in Paging File | 90,48% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 116,41 Gb Total Space | 13,11 Gb Free Space | 11,26% Space Free | Partition Type: NTFS
Drive D: | 110,88 Gb Total Space | 100,94 Gb Free Space | 91,04% Space Free | Partition Type: NTFS

Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012-05-04 15:14:09 | 000,595,456 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Eigenaar\Bureaublad\OTL.com
PRC - [2011-12-16 08:55:44 | 000,187,696 | ---- | M] (Blabbers Communications LTD) -- C:\Program Files\BrowserCompanion\BCHelper.exe
PRC - [2011-11-03 02:48:18 | 000,428,912 | ---- | M] (Norman ASA) -- C:\Program Files\Norman\Npm\Bin\Zanda.exe
PRC - [2011-09-30 08:51:08 | 000,090,144 | ---- | M] (Norman ASA) -- C:\Program Files\Norman\Ngs\Bin\nprosec.exe
PRC - [2011-08-26 08:00:22 | 000,292,136 | ---- | M] (CyberLink) -- C:\Program Files\CyberLink\PowerDVD11\Common\MediaServer\CLMSServerForPDVD11.exe
PRC - [2011-08-26 08:00:19 | 000,075,048 | ---- | M] (CyberLink) -- C:\Program Files\CyberLink\PowerDVD11\Common\MediaServer\CLMSMonitorService.exe
PRC - [2011-08-24 03:13:45 | 000,230,696 | ---- | M] (CyberLink Corp.) -- C:\Program Files\CyberLink\PowerDVD11\PDVD11Serv.exe
PRC - [2011-08-24 03:13:43 | 000,083,240 | ---- | M] () -- C:\Program Files\CyberLink\PowerDVD11\Kernel\DMP\CLHNServiceForPowerDVD.exe
PRC - [2011-03-22 16:15:33 | 000,189,824 | ---- | M] (Norman ASA) -- C:\Program Files\Norman\Npm\Bin\Zlh.exe
PRC - [2010-12-17 16:22:48 | 000,288,072 | ---- | M] (Norman ASA) -- C:\Program Files\Norman\Nse\Bin\Nsesvc.exe
PRC - [2010-11-11 13:43:28 | 000,075,104 | ---- | M] (Norman ASA) -- C:\Program Files\Norman\Npm\Bin\elogsvc.exe
PRC - [2010-11-10 14:48:32 | 000,223,000 | ---- | M] (Norman ASA) -- C:\Program Files\Norman\Ngs\Bin\nnf.exe
PRC - [2010-11-08 18:02:27 | 000,096,344 | ---- | M] (Norman ASA) -- C:\Program Files\Norman\Npc\Bin\npc_tray.exe
PRC - [2010-11-08 18:02:27 | 000,084,392 | ---- | M] () -- C:\Program Files\Norman\Npc\Bin\nuaa.exe
PRC - [2010-11-08 17:56:34 | 000,290,472 | ---- | M] (Norman ASA) -- C:\Program Files\Norman\Npf\Bin\npfsvc32.exe
PRC - [2010-11-08 17:56:34 | 000,198,168 | ---- | M] (Norman ASA) -- C:\Program Files\Norman\nvc\bin\Nvcoas.exe
PRC - [2010-11-08 17:56:34 | 000,182,712 | ---- | M] (Norman ASA) -- C:\Program Files\Norman\nvc\bin\Nip.exe
PRC - [2010-11-08 17:56:34 | 000,100,336 | ---- | M] (Norman ASA) -- C:\Program Files\Norman\Npm\Bin\nvoy.exe
PRC - [2010-11-08 17:56:34 | 000,074,592 | ---- | M] (Norman ASA) -- C:\Program Files\Norman\nvc\bin\CClaw.exe
PRC - [2010-07-04 20:13:56 | 000,095,576 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe
PRC - [2010-07-04 20:07:40 | 000,238,952 | ---- | M] (Teruten) -- C:\WINDOWS\system32\FsUsbExService.Exe
PRC - [2010-01-12 18:53:14 | 000,233,472 | ---- | M] (Vodafone Group) -- C:\Program Files\Vodafone\Via The Phone\VodafoneConnectorService.exe
PRC - [2008-04-15 14:00:00 | 001,037,312 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2005-05-11 23:12:54 | 000,049,152 | ---- | M] (Hewlett-Packard Co.) -- C:\HP Software Update\hpwuSchd2.exe
PRC - [2005-03-14 16:05:18 | 000,036,864 | ---- | M] () -- C:\WINDOWS\system32\acs.exe


========== Modules (No Company Name) ==========

MOD - [2011-08-26 06:57:18 | 000,260,096 | ---- | M] () -- C:\Program Files\CyberLink\PowerDVD11\Common\MediaServer\sqlite3.dll
MOD - [2011-08-24 03:13:43 | 000,083,240 | ---- | M] () -- C:\Program Files\CyberLink\PowerDVD11\Kernel\DMP\CLHNServiceForPowerDVD.exe
MOD - [2011-08-07 13:54:44 | 000,362,029 | ---- | M] () -- C:\Program Files\BrowserCompanion\sqlite3.dll
MOD - [2010-11-09 14:23:47 | 000,161,112 | ---- | M] () -- C:\Program Files\Norman\nvc\bin\Ndlg.dll
MOD - [2010-11-08 18:02:27 | 000,084,392 | ---- | M] () -- C:\Program Files\Norman\Npc\Bin\nuaa.exe
MOD - [2010-11-08 17:56:34 | 000,234,760 | ---- | M] () -- C:\Program Files\Norman\Npm\Bin\Noemrc.dll
MOD - [2009-02-27 20:13:06 | 000,311,296 | ---- | M] () -- C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\pdfshell.NLD
MOD - [2008-10-16 21:46:00 | 000,466,944 | ---- | M] () -- C:\WINDOWS\system32\nvshell.dll
MOD - [2008-10-16 15:14:10 | 000,094,720 | ---- | M] () -- C:\Program Files\FileZilla FTP Client\fzshellext.dll
MOD - [2005-03-14 16:05:18 | 000,036,864 | ---- | M] () -- C:\WINDOWS\system32\acs.exe
MOD - [2001-10-28 17:42:30 | 000,116,224 | ---- | M] () -- C:\WINDOWS\system32\pdfcmnnt.dll


========== Win32 Services (SafeList) ==========

SRV - File not found [On_Demand | Stopped] -- C:\Program Files\Norman\Npm\bin\NVCSCHED.EXE -- (NVCScheduler)
SRV - [2011-11-03 02:48:18 | 000,428,912 | ---- | M] (Norman ASA) [Auto | Running] -- C:\Program Files\Norman\Npm\Bin\Zanda.exe -- (Norman ZANDA)
SRV - [2011-09-30 08:51:08 | 000,090,144 | ---- | M] (Norman ASA) [Auto | Running] -- C:\Program Files\Norman\Ngs\Bin\nprosec.exe -- (NPROSECSVC)
SRV - [2011-08-26 08:00:22 | 000,292,136 | ---- | M] (CyberLink) [Auto | Running] -- C:\Program Files\CyberLink\PowerDVD11\Common\MediaServer\CLMSServerForPDVD11.exe -- (CyberLink PowerDVD 11.0 Service)
SRV - [2011-08-26 08:00:19 | 000,075,048 | ---- | M] (CyberLink) [Auto | Running] -- C:\Program Files\CyberLink\PowerDVD11\Common\MediaServer\CLMSMonitorService.exe -- (CyberLink PowerDVD 11.0 Monitor Service)
SRV - [2011-08-24 03:13:43 | 000,083,240 | ---- | M] () [Auto | Running] -- C:\Program Files\CyberLink\PowerDVD11\Kernel\DMP\CLHNServiceForPowerDVD.exe -- (CLHNServiceForPowerDVD)
SRV - [2010-12-21 22:08:10 | 001,045,256 | ---- | M] (Acresso Software Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2010-12-17 16:22:48 | 000,288,072 | ---- | M] (Norman ASA) [On_Demand | Running] -- C:\Program Files\Norman\Nse\Bin\Nsesvc.exe -- (nsesvc)
SRV - [2010-11-11 13:43:28 | 000,075,104 | ---- | M] (Norman ASA) [Auto | Running] -- C:\Program Files\Norman\Npm\Bin\elogsvc.exe -- (eLoggerSvc6)
SRV - [2010-11-10 14:48:32 | 000,223,000 | ---- | M] (Norman ASA) [Auto | Running] -- C:\Program Files\Norman\Ngs\Bin\nnf.exe -- (NNFSVC)
SRV - [2010-11-08 18:02:27 | 000,111,912 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\Norman\Npm\Bin\Njeeves.exe -- (Norman NJeeves)
SRV - [2010-11-08 18:02:27 | 000,099,312 | ---- | M] (Norman ASA) [On_Demand | Stopped] -- C:\Program Files\Norman\Npm\Bin\scheduler.exe -- (Scheduler)
SRV - [2010-11-08 18:02:27 | 000,084,392 | ---- | M] () [On_Demand | Running] -- C:\Program Files\Norman\Npc\Bin\nuaa.exe -- (NUAA)
SRV - [2010-11-08 17:56:34 | 000,290,472 | ---- | M] (Norman ASA) [Auto | Running] -- C:\Program Files\Norman\Npf\Bin\npfsvc32.exe -- (NPFSvc32)
SRV - [2010-11-08 17:56:34 | 000,198,168 | ---- | M] (Norman ASA) [On_Demand | Running] -- C:\Program Files\Norman\nvc\bin\Nvcoas.exe -- (nvcoas)
SRV - [2010-11-08 17:56:34 | 000,100,336 | ---- | M] (Norman ASA) [Auto | Running] -- C:\Program Files\Norman\Npm\Bin\nvoy.exe -- (NVOY)
SRV - [2010-07-04 20:07:40 | 000,238,952 | ---- | M] (Teruten) [Auto | Running] -- C:\WINDOWS\system32\FsUsbExService.Exe -- (FsUsbExService)
SRV - [2010-01-12 18:53:14 | 000,233,472 | ---- | M] (Vodafone Group) [Auto | Running] -- C:\Program Files\Vodafone\Via The Phone\VodafoneConnectorService.exe -- (VodafoneConnectorService)
SRV - [2008-11-11 10:38:06 | 000,620,544 | ---- | M] (Nokia.) [On_Demand | Stopped] -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
SRV - [2005-03-14 16:05:18 | 000,036,864 | ---- | M] () [Auto | Running] -- C:\WINDOWS\system32\acs.exe -- (ACS)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP)
DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)
DRV - File not found [Kernel | On_Demand | Unknown] -- C:\DOCUME~1\Eigenaar\LOCALS~1\Temp\mbr.sys -- (mbr)
DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc)
DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt)
DRV - File not found [Kernel | On_Demand | Stopped] -- System32\drivers\dgderdrv.sys -- (dgderdrv)
DRV - File not found [Kernel | System | Stopped] -- -- (Changer)
DRV - File not found [Kernel | On_Demand | Unknown] -- -- (aq529ajg)
DRV - [2012-01-05 01:01:54 | 000,032,768 | ---- | M] (AnchorFree Inc) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\taphss.sys -- (taphss)
DRV - [2011-09-30 08:51:08 | 000,074,144 | ---- | M] (Norman ASA) [Kernel | System | Running] -- C:\Program Files\Norman\Ngs\Bin\nprosec.sys -- (NPROSEC)
DRV - [2011-08-26 10:53:32 | 000,077,296 | ---- | M] (CyberLink Corp.) [2011/10/27 09:19:36] [Kernel | Auto | Running] -- C:\Program Files\CyberLink\PowerDVD11\Common\NavFilter\000.fcl -- ({329F96B6-DF1E-4328-BFDA-39EA953C1312})
DRV - [2011-08-24 03:13:44 | 000,071,664 | ---- | M] (Cyberlink Corp.) [Kernel | Auto | Running] -- C:\Program Files\CyberLink\PowerDVD11\Kernel\DMP\ntk_PowerDVD.sys -- (ntk_PowerDVD)
DRV - [2011-07-21 15:54:16 | 000,066,944 | ---- | M] (TOSHIBA Corporation) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\thdudf.sys -- (thdudf)
DRV - [2010-12-17 11:17:00 | 000,691,696 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\sptd.sys -- (sptd)
DRV - [2010-11-11 14:01:54 | 000,024,176 | ---- | M] (Norman ASA) [File_System | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nvcw32mf.sys -- (NvcMFlt)
DRV - [2010-11-10 15:48:40 | 000,378,000 | ---- | M] (Norman ASA) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\tdi_nf.sys -- (tdi_nf)
DRV - [2010-11-10 15:48:11 | 000,040,384 | ---- | M] (Norman ASA) [Kernel | Auto | Running] -- C:\Program Files\Norman\Ngs\Bin\nregsec.sys -- (nregsec)
DRV - [2010-10-08 13:28:24 | 000,023,040 | ---- | M] (Norman ASA) [Kernel | On_Demand | Running] -- C:\Program Files\Norman\Ngs\Bin\nnetsecc.sys -- (NNetSecC)
DRV - [2010-06-21 14:54:51 | 000,048,272 | ---- | M] (Norman ASA) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nnetsec.sys -- (nnetsec)
DRV - [2010-06-14 10:32:54 | 000,036,608 | ---- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\FsUsbExDisk.Sys -- (FsUsbExDisk)
DRV - [2010-05-14 13:53:25 | 000,005,632 | ---- | M] () [File_System | System | Running] -- C:\WINDOWS\System32\drivers\StarOpen.sys -- (StarOpen)
DRV - [2010-04-27 04:25:16 | 000,123,648 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ss_bmdm.sys -- (ss_bmdm)
DRV - [2010-04-27 04:25:16 | 000,098,432 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ss_bbus.sys -- (ss_bbus) SAMSUNG USB Mobile Device (WDM)
DRV - [2010-04-27 04:25:16 | 000,014,848 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ss_bmdfl.sys -- (ss_bmdfl) SAMSUNG USB Mobile Modem (Filter)
DRV - [2010-04-27 04:25:14 | 000,132,608 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ssm_mdm.sys -- (ssm_mdm)
DRV - [2010-04-27 04:25:14 | 000,104,448 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ssm_bus.sys -- (ssm_bus) SAMSUNG Mobile USB Device II 1.0 driver (WDM)
DRV - [2010-04-27 04:25:14 | 000,014,848 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ssm_mdfl.sys -- (ssm_mdfl)
DRV - [2010-04-27 04:25:12 | 000,123,776 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ss_mdm.sys -- (ss_mdm)
DRV - [2010-04-27 04:25:12 | 000,098,560 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ss_bus.sys -- (ss_bus) SAMSUNG Mobile USB Device 1.0 driver (WDM)
DRV - [2010-04-27 04:25:12 | 000,014,848 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ss_mdfl.sys -- (ss_mdfl)
DRV - [2010-01-04 14:44:43 | 000,026,744 | ---- | M] (Norman ASA) [Kernel | System | Running] -- c:\Program Files\Norman\Ngs\Bin\ngs.sys -- (NGS)
DRV - [2009-10-09 13:24:40 | 000,022,880 | ---- | M] (Norman ASA) [Kernel | Auto | Running] -- C:\Program Files\Norman\Nse\Bin\Ndiskio.sys -- (Ndiskio)
DRV - [2008-11-25 10:37:50 | 004,952,576 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2008-08-26 10:26:12 | 000,018,816 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\pccsmcfd.sys -- (pccsmcfd)
DRV - [2008-08-24 21:22:40 | 000,014,208 | R--- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nvsmu.sys -- (nvsmu)
DRV - [2008-08-01 05:36:26 | 000,022,016 | R--- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nvnetbus.sys -- (nvnetbus)
DRV - [2008-08-01 05:36:20 | 000,054,784 | R--- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\NVENETFD.sys -- (NVENETFD)
DRV - [2008-04-15 14:00:00 | 000,040,320 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nmnt.sys -- (nm)
DRV - [2008-04-14 02:15:30 | 000,010,624 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\gameenum.sys -- (gameenum)
DRV - [2006-09-24 15:28:46 | 000,005,248 | ---- | M] (Windows (R) 2000 DDK provider) [Kernel | Boot | Running] -- C:\WINDOWS\system32\speedfan.sys -- (speedfan)
DRV - [2005-04-21 04:09:00 | 000,458,208 | R--- | M] (SMC Networks, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\SMCWPCIG.sys -- (SMCWPCIG)
DRV - [2004-08-12 12:56:20 | 000,005,810 | R--- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ASACPI.sys -- (MTsensor)
DRV - [2004-04-21 18:51:00 | 000,016,384 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\wlanndi5.sys -- (wlanndi5)
DRV - [2001-08-17 22:19:34 | 000,040,704 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\es1371mp.sys -- (es1371) Creative AudioPCI (ES1371,ES1373) (WDM)
DRV - [1996-04-03 21:33:26 | 000,005,248 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\system32\giveio.sys -- (giveio)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD2A59}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
IE - HKLM\..\SearchScopes\{CF739809-1C6C-47C0-85B9-569DBB141420}: "URL" = http://toolbar.ask.com/toolbarv/askRedi ... t=&gc=1&q={searchTerms}&crm=1


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-3921166209-81286332-4088324220-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKU\S-1-5-21-3921166209-81286332-4088324220-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
IE - HKU\S-1-5-21-3921166209-81286332-4088324220-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKU\S-1-5-21-3921166209-81286332-4088324220-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource= ... =CT1269415
IE - HKU\S-1-5-21-3921166209-81286332-4088324220-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://nl.msn.com/?ocid=iehp
IE - HKU\S-1-5-21-3921166209-81286332-4088324220-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = nl
IE - HKU\S-1-5-21-3921166209-81286332-4088324220-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 46 3B 38 F5 EF EC CC 01 [binary data]
IE - HKU\S-1-5-21-3921166209-81286332-4088324220-1003\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKU\S-1-5-21-3921166209-81286332-4088324220-1003\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKU\S-1-5-21-3921166209-81286332-4088324220-1003\..\URLSearchHook: {ad708c09-d51b-45b3-9d28-4eba2681febf} - C:\Program Files\Download_Energy\prxtbDow0.dll (Conduit Ltd.)
IE - HKU\S-1-5-21-3921166209-81286332-4088324220-1003\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD2A59}
IE - HKU\S-1-5-21-3921166209-81286332-4088324220-1003\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKU\S-1-5-21-3921166209-81286332-4088324220-1003\..\SearchScopes\{12995981-2FD6-4BEE-9FB0-B1674E8E5E7E}: "URL" = http://websearch.4shared.com/results?q={searchTerms}
IE - HKU\S-1-5-21-3921166209-81286332-4088324220-1003\..\SearchScopes\{2021DD55-8F8C-4399-AB0E-EEA5CF9E62EC}: "URL" = http://www.google.co.uk/search?hl=en&q={searchTerms}&meta=
IE - HKU\S-1-5-21-3921166209-81286332-4088324220-1003\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2A59}: "URL" = http://search.imesh.com/webResults.html?src=ieb&q={searchTerms}
IE - HKU\S-1-5-21-3921166209-81286332-4088324220-1003\..\SearchScopes\{AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB8}: "URL" = http://www.daemon-search.com/search?q={searchTerms}
IE - HKU\S-1-5-21-3921166209-81286332-4088324220-1003\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT1269415
IE - HKU\S-1-5-21-3921166209-81286332-4088324220-1003\..\SearchScopes\{c99fdc39-a1ae-4b24-8d71-e5274f8d7c54}: "URL" = http://search.hotspotshield.com/g/results.php?c=s&q={searchTerms}
IE - HKU\S-1-5-21-3921166209-81286332-4088324220-1003\..\SearchScopes\{CF739809-1C6C-47C0-85B9-569DBB141420}: "URL" = http://toolbar.ask.com/toolbarv/askRedi ... t=&gc=1&q={searchTerms}&crm=1
IE - HKU\S-1-5-21-3921166209-81286332-4088324220-1003\..\SearchScopes\{E08A9998-D98F-476f-8F5C-37C80FE0A4DA}: "URL" = http://search.conduit.com/?SearchSource ... =CT2527944
IE - HKU\S-1-5-21-3921166209-81286332-4088324220-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKU\S-1-5-21-3921166209-81286332-4088324220-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = proxy.kliksafe.nl:8080;local;*.local
IE - HKU\S-1-5-21-3921166209-81286332-4088324220-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = proxy.kliksafe.nl:8080

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: {E9A1DEE0-C623-4439-8932-001E7D17607D}:2.1.0.2
FF - prefs.js..extensions.enabledItems: DTToolbar@toolbarnet.com:1.1.2.0185
FF - prefs.js..extensions.enabledItems: {B7D3E479-CC68-42B5-A338-938ECE35F419}:2.0.0.66311
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0


FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa2,version=2.0.0: C:\Program Files\Picasa2\npPicasa2.dll File not found
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.0.61118.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.12.69: C:\Program Files\Magic 3GP Video Converter\codec\real\browser\plugins\nppl3260.dll File not found
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.69: C:\Program Files\Magic 3GP Video Converter\codec\real\browser\plugins\nprpjplug.dll File not found
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@powerchallenge.com/PowerLoader: C:\DOCUME~1\Eigenaar\APPLIC~1\POWERC~2\nppowerloader.dll (Power Challenge Sweden AB)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\Eigenaar\Local Settings\Application Data\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\Eigenaar\Local Settings\Application Data\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 2.0.0.17\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2012-02-19 00:20:02 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 2.0.0.17\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins [2012-02-19 00:20:41 | 000,000,000 | ---D | M]

[2010-09-27 20:32:38 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Eigenaar\Application Data\Mozilla\Extensions
[2010-09-27 20:32:38 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Eigenaar\Application Data\Mozilla\Extensions\mozswing@mozswing.org
[2012-03-21 08:40:43 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Eigenaar\Application Data\Mozilla\Firefox\Profiles\hl2ye7ym.default\extensions
[2009-10-20 12:43:15 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\Eigenaar\Application Data\Mozilla\Firefox\Profiles\hl2ye7ym.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2012-03-21 08:40:29 | 000,000,000 | ---D | M] (Complitly - Speed up your search with your personal search suggestions tool) -- C:\Documents and Settings\Eigenaar\Application Data\Mozilla\Firefox\Profiles\hl2ye7ym.default\extensions\{33e0daa6-3af3-d8b5-6752-10e949c61516}
[2012-03-21 08:40:43 | 000,000,000 | ---D | M] (Download Energy Community Toolbar) -- C:\Documents and Settings\Eigenaar\Application Data\Mozilla\Firefox\Profiles\hl2ye7ym.default\extensions\{ad708c09-d51b-45b3-9d28-4eba2681febf}
[2010-12-17 11:17:11 | 000,002,055 | ---- | M] () -- C:\Documents and Settings\Eigenaar\Application Data\Mozilla\Firefox\Profiles\hl2ye7ym.default\searchplugins\daemon-search.xml
[2011-08-12 14:55:20 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\EIGENAAR\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\HL2YE7YM.DEFAULT\EXTENSIONS\{E9A1DEE0-C623-4439-8932-001E7D17607D}
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\EIGENAAR\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\HL2YE7YM.DEFAULT\EXTENSIONS\DTTOOLBAR@TOOLBARNET.COM
[2009-03-21 14:57:51 | 000,000,000 | ---D | M] (Java Quick Starter) -- C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
File not found (No name found) -- C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{B7D3E479-CC68-42B5-A338-938ECE35F419}

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms}
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Documents and Settings\Eigenaar\Local Settings\Application Data\Google\Chrome\Application\18.0.1025.162\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\Eigenaar\Local Settings\Application Data\Google\Chrome\Application\18.0.1025.162\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\Eigenaar\Local Settings\Application Data\Google\Chrome\User Data\NPAPIFlash\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: (Enabled) = C:\Documents and Settings\Eigenaar\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\clbfjfbnelcflpgpklppgplejolacbej\1.0.5_0\chromeNPAPI.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.300.12 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java(TM) Platform SE 6 U30 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: Power Challenge Loader (Enabled) = C:\DOCUME~1\Eigenaar\APPLIC~1\POWERC~2\nppowerloader.dll
CHR - plugin: Google Update (Enabled) = C:\Documents and Settings\Eigenaar\Local Settings\Application Data\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: Picasa (Enabled) = C:\Program Files\Google\Picasa3\npPicasa3.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\5.0.61118.0\npctrl.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\WINDOWS\system32\Adobe\Director\np32dsw.dll
CHR - Extension: Download Energy = C:\Documents and Settings\Eigenaar\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\amhlacfinnaffmhfohbpecabbjfhkdji\2.3.4.2_0\
CHR - Extension: Browser Companion Helper = C:\Documents and Settings\Eigenaar\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\clbfjfbnelcflpgpklppgplejolacbej\1.0.5_0\
CHR - Extension: Complitly plugin for chrome = C:\Documents and Settings\Eigenaar\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\dlfienamagdnkekbbbocojppncdambda\1.1_0\

O1 HOSTS File: ([2008-04-15 14:00:00 | 000,000,776 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Chatvibes Browser Helper) - {00cbb66b-1d3b-46d3-9577-323a336acb50} - C:\Program Files\BrowserCompanion\jsloader.dll ( )
O2 - BHO: (Complitly) - {0FB6A909-6086-458F-BD92-1F8EE10042A0} - C:\Documents and Settings\Eigenaar\Application Data\Complitly\Complitly.dll (SimplyGen)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Chatvibes Browser Helper Verifier) - {963B125B-8B21-49A2-A3A8-E37092276531} - C:\Program Files\BrowserCompanion\updatebhoWin32.dll ( )
O2 - BHO: (Download Energy Toolbar) - {ad708c09-d51b-45b3-9d28-4eba2681febf} - C:\Program Files\Download_Energy\prxtbDow0.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Download Energy Toolbar) - {ad708c09-d51b-45b3-9d28-4eba2681febf} - C:\Program Files\Download_Energy\prxtbDow0.dll (Conduit Ltd.)
O3 - HKU\S-1-5-21-3921166209-81286332-4088324220-1003\..\Toolbar\WebBrowser: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found.
O3 - HKU\S-1-5-21-3921166209-81286332-4088324220-1003\..\Toolbar\WebBrowser: (Download Energy Toolbar) - {AD708C09-D51B-45B3-9D28-4EBA2681FEBF} - C:\Program Files\Download_Energy\prxtbDow0.dll (Conduit Ltd.)
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\ALCMTR.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [Browser companion helper] C:\Program Files\BrowserCompanion\BCHelper.exe (Blabbers Communications LTD)
O4 - HKLM..\Run: [HP Software Update] C:\HP Software Update\hpwuSchd2.exe (Hewlett-Packard Co.)
O4 - HKLM..\Run: [Norman ZANDA] C:\Program Files\Norman\Npm\Bin\ZLH.EXE (Norman ASA)
O4 - HKLM..\Run: [NPCTray] C:\Program Files\Norman\npc\bin\npc_tray.exe (Norman ASA)
O4 - HKLM..\Run: [NPSStartup] File not found
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [RemoteControl11] C:\Program Files\CyberLink\PowerDVD11\PDVD11Serv.exe (CyberLink Corp.)
O4 - HKU\S-1-5-21-3921166209-81286332-4088324220-1003..\Run: [AutoStartNPSAgent] C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe (Samsung Electronics Co., Ltd.)
O4 - HKU\S-1-5-21-3921166209-81286332-4088324220-1003..\Run: [EA Core] "C:\Program Files\Electronic Arts\EADM\Core.exe" -silent File not found
O4 - HKU\S-1-5-21-3921166209-81286332-4088324220-1003..\Run: [KiesTrayAgent] File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-3921166209-81286332-4088324220-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 0
O8 - Extra context menu item: &Download All using 4shared Desktop - C:\Program Files\4shared Desktop\down_all.htm File not found
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Norman\ngs\bin\nlf.dll (Norman ASA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Norman\ngs\bin\nlf.dll (Norman ASA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Norman\ngs\bin\nlf.dll (Norman ASA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Program Files\Norman\ngs\bin\nlf.dll (Norman ASA)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shoc ... tor/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {1FEC8B6F-250A-4293-B12C-67A7EF0B758A} http://www.kerkomroep.nl/ocx/sIKNPlayer.cab (sIKN Speler)
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} http://messenger.zone.msn.com/binary/ms ... b56986.cab (Checkers Class)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} http://gfx1.hotmail.com/mail/w3/resources/MSNPUpld.cab (MSN Photo Upload Tool)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://www.update.microsoft.com/windows ... 6394366296 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftup ... 6394444609 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/Me ... b56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/s ... wflash.cab (Shockwave Flash Object)
O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} http://gfx1.hotmail.com/mail/w4/pr01/ph ... NPUpld.cab (Windows Live Hotmail Photo Upload Tool)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{314DAAAF-F9FF-4D06-92B5-ED1DABC9B793}: DhcpNameServer = 172.16.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{7A84989F-FE48-4F11-A328-48A8EF34EDBA}: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\base64 {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} - C:\Program Files\BrowserCompanion\tdataprotocol.dll (Blabbers Communications Ltd)
O18 - Protocol\Handler\chrome {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} - C:\Program Files\BrowserCompanion\tdataprotocol.dll (Blabbers Communications Ltd)
O18 - Protocol\Handler\prox {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} - C:\Program Files\BrowserCompanion\tdataprotocol.dll (Blabbers Communications Ltd)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop Components:0 () - file:///C:/DOCUME~1/Eigenaar/LOCALS~1/Temp/msohtml1/01/clip_image007.gif
O24 - Desktop Components:1 () - http://t0.gstatic.com/images?q=tbn:ANd9 ... Zur9N8&t=1
O24 - Desktop Components:2 () - http://www.ikea.com/ms/nl_NL/img/custom ... 50x250.jpg
O24 - Desktop Components:3 () - http://www.webklik.nl/user_files/2010_0 ... 00x300.png
O24 - Desktop Components:4 (Mijn huidige introductiepagina) - About:Home
O24 - Desktop Components:5 () - http://www.google.com/images
O24 - Desktop Components:6 () - http://www.waldnet.nl/
O24 - Desktop WallPaper: C:\Documents and Settings\Eigenaar\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Eigenaar\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008-09-26 11:27:26 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{819f8af6-1da0-11df-ac5e-002354d83a39}\Shell\AutoRun\command - "" = G:\InstallTomTomHOME.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

========== Files/Folders - Created Within 30 Days ==========

[2012-05-04 15:14:07 | 000,595,456 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Eigenaar\Bureaublad\OTL.com
[2012-05-04 14:49:06 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Eigenaar\Bureaublad\dds
[2012-05-04 14:46:38 | 000,607,260 | ---- | C] (Swearware) -- C:\Documents and Settings\Eigenaar\Bureaublad\dds.scr
[2012-05-03 10:40:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Eigenaar\Application Data\Malwarebytes
[2012-05-03 10:40:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menu Start\Programma's\Malwarebytes' Anti-Malware
[2012-05-03 10:40:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2012-05-03 10:40:13 | 000,022,344 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2012-05-03 10:40:13 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2012-05-02 13:06:37 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Eigenaar\Mijn documenten\Mijn scanafbeeldingen
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[15 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012-05-04 15:14:09 | 000,595,456 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Eigenaar\Bureaublad\OTL.com
[2012-05-04 15:04:15 | 000,005,043 | ---- | M] () -- C:\Documents and Settings\Eigenaar\Bureaublad\logs PietroMaster.zip
[2012-05-04 15:02:06 | 000,001,148 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-3921166209-81286332-4088324220-1003UA.job
[2012-05-04 14:46:40 | 000,607,260 | ---- | M] (Swearware) -- C:\Documents and Settings\Eigenaar\Bureaublad\dds.scr
[2012-05-04 14:20:00 | 000,508,998 | ---- | M] () -- C:\WINDOWS\System32\perfh013.dat
[2012-05-04 14:20:00 | 000,441,112 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2012-05-04 14:20:00 | 000,091,070 | ---- | M] () -- C:\WINDOWS\System32\perfc013.dat
[2012-05-04 14:20:00 | 000,071,430 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2012-05-04 14:18:15 | 000,000,460 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{6D4977DC-112F-4A4F-953F-EA6D02CB97EA}.job
[2012-05-04 14:17:40 | 000,201,151 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml
[2012-05-04 14:14:46 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012-05-04 10:03:41 | 000,012,109 | ---- | M] () -- C:\Documents and Settings\Eigenaar\Bureaublad\cautionwetfloor.jpg
[2012-05-03 10:40:15 | 000,000,821 | ---- | M] () -- C:\Documents and Settings\All Users\Bureaublad\Malwarebytes Anti-Malware.lnk
[2012-05-02 18:02:00 | 000,001,096 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-3921166209-81286332-4088324220-1003Core.job
[2012-04-30 08:18:24 | 000,012,598 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2012-04-19 18:08:59 | 000,100,255 | ---- | M] () -- C:\Documents and Settings\Eigenaar\Bureaublad\248870.pdf
[2012-04-17 12:31:02 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2012-04-16 18:03:42 | 000,002,324 | ---- | M] () -- C:\Documents and Settings\Eigenaar\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2012-04-16 18:03:41 | 000,002,346 | ---- | M] () -- C:\Documents and Settings\Eigenaar\Bureaublad\Google Chrome.lnk
[2012-04-13 06:13:28 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2012-04-12 14:41:44 | 000,141,824 | ---- | M] () -- C:\Documents and Settings\Eigenaar\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012-04-04 15:56:40 | 000,022,344 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[15 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012-05-04 15:04:15 | 000,005,043 | ---- | C] () -- C:\Documents and Settings\Eigenaar\Bureaublad\logs PietroMaster.zip
[2012-05-04 10:03:48 | 000,012,109 | ---- | C] () -- C:\Documents and Settings\Eigenaar\Bureaublad\cautionwetfloor.jpg
[2012-05-03 10:40:15 | 000,000,821 | ---- | C] () -- C:\Documents and Settings\All Users\Bureaublad\Malwarebytes Anti-Malware.lnk
[2012-04-19 18:09:03 | 000,100,255 | ---- | C] () -- C:\Documents and Settings\Eigenaar\Bureaublad\248870.pdf
[2012-02-01 19:35:25 | 000,071,349 | ---- | C] () -- C:\WINDOWS\hpqins04.dat
[2012-02-01 14:40:44 | 000,112,777 | ---- | C] () -- C:\WINDOWS\hpoins07.dat
[2012-02-01 14:40:44 | 000,021,124 | ---- | C] () -- C:\WINDOWS\hpomdl07.dat
[2012-01-31 20:03:06 | 000,000,373 | ---- | C] () -- C:\WINDOWS\SoftWriting.ini
[2012-01-07 10:34:51 | 000,002,528 | ---- | C] () -- C:\Documents and Settings\LocalService\Application Data\$_hpcst$.hpc
[2012-01-03 11:47:28 | 000,144,157 | ---- | C] () -- C:\WINDOWS\hpoins21.dat.temp
[2012-01-03 11:47:28 | 000,007,262 | ---- | C] () -- C:\WINDOWS\hpomdl21.dat.temp
[2011-11-26 11:36:58 | 000,000,675 | ---- | C] () -- C:\WINDOWS\eReg.dat
[2011-10-28 22:50:31 | 000,005,056 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\ctonhhte.rgb
[2011-03-12 19:10:14 | 000,004,155 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\etgxespc.rpo
[2011-03-03 19:29:41 | 000,000,000 | ---- | C] () -- C:\WINDOWS\iPlayer.INI
[2011-02-10 19:41:34 | 000,004,151 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\hnbdehzc.pfe
[2010-12-15 23:18:04 | 003,179,824 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2010-10-15 21:29:27 | 000,354,816 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2010-05-14 13:35:24 | 000,110,592 | ---- | C] () -- C:\WINDOWS\System32\FsUsbExDevice.Dll
[2010-05-14 13:35:24 | 000,036,608 | ---- | C] () -- C:\WINDOWS\System32\FsUsbExDisk.Sys
[2010-05-14 13:35:10 | 000,002,528 | ---- | C] () -- C:\Documents and Settings\Eigenaar\Application Data\$_hpcst$.hpc

========== LOP Check ==========

[2011-12-15 19:27:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\4Sync
[2009-05-20 17:26:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\62DE
[2011-07-20 12:46:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Autodesk
[2012-03-21 08:41:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Babylon
[2010-12-17 11:16:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\DAEMON Tools Lite
[2012-02-16 16:00:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\EasyMP3Downloader
[2011-12-19 06:09:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Electronic Arts
[2009-08-31 16:55:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\F32C
[2011-08-12 14:49:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Hema Album Software Advanced
[2011-10-27 09:17:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\install_clap
[2012-03-21 08:40:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\LimeWire Music
[2009-11-21 18:14:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MSScanAppDataDir
[2012-01-06 19:44:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\NFS Underground Demo
[2011-02-04 15:18:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Oberon Media
[2011-12-19 06:11:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Origin
[2010-05-14 13:36:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PC Suite
[2011-10-27 09:19:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PDVD
[2011-01-04 18:55:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\RosettaStoneLtdServices
[2011-12-21 21:48:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Samsung
[2009-11-21 18:14:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SSScanAppDataDir
[2011-10-27 09:17:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Temp
[2011-01-08 18:41:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Vodafone
[2010-09-27 20:13:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2008-11-08 04:32:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Default User\Application Data\gtk-2.0
[2008-11-08 05:55:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Default User\Application Data\InfraRecorder
[2008-11-08 04:15:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Default User\Application Data\Notepad++
[2008-10-20 06:04:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Default User\Application Data\OpenOffice.org
[2011-03-12 19:28:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eigenaar\Application Data\AnvSoft
[2010-12-21 22:54:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eigenaar\Application Data\Autodesk
[2012-03-21 08:41:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eigenaar\Application Data\Babylon
[2011-10-19 14:53:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eigenaar\Application Data\Belastingdienst
[2011-08-12 14:43:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eigenaar\Application Data\BitTorrent
[2012-03-21 08:40:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eigenaar\Application Data\Complitly
[2010-12-21 21:25:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eigenaar\Application Data\DAEMON Tools Lite
[2012-02-16 16:00:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eigenaar\Application Data\EasyMP3Downloader
[2008-11-08 04:32:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eigenaar\Application Data\gtk-2.0
[2012-01-31 19:45:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eigenaar\Application Data\Image Zone Express
[2008-11-08 05:55:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eigenaar\Application Data\InfraRecorder
[2010-10-05 20:31:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eigenaar\Application Data\Leadertech
[2012-01-12 22:09:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eigenaar\Application Data\LimeWire
[2012-03-21 15:08:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eigenaar\Application Data\LimeWire Music
[2008-11-08 04:15:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eigenaar\Application Data\Notepad++
[2008-10-20 06:04:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eigenaar\Application Data\OpenOffice.org
[2011-12-19 06:11:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eigenaar\Application Data\Origin
[2012-01-11 21:31:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eigenaar\Application Data\Pavtube
[2010-05-14 13:36:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eigenaar\Application Data\PC Suite
[2009-12-24 17:48:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eigenaar\Application Data\PowerChallenge
[2009-04-23 14:38:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eigenaar\Application Data\PowerCinema
[2012-02-10 22:47:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eigenaar\Application Data\Samsung
[2012-05-04 14:18:15 | 000,000,460 | -H-- | M] () -- C:\WINDOWS\Tasks\User_Feed_Synchronization-{6D4977DC-112F-4A4F-953F-EA6D02CB97EA}.job

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 124 bytes -> C:\Documents and Settings\All Users\Application Data\Temp:81405BF2
@Alternate Data Stream - 116 bytes -> C:\Documents and Settings\All Users\Application Data\Temp:661DFA1C

< End of report >
EXTRA'S.TXT
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000413 | Country: Nederland | Language: NLD | Date Format: d-M-yyyy

1,87 Gb Total Physical Memory | 1,29 Gb Available Physical Memory | 68,60% Memory free
3,72 Gb Paging File | 3,37 Gb Available in Paging File | 90,48% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 116,41 Gb Total Space | 13,11 Gb Free Space | 11,26% Space Free | Partition Type: NTFS
Drive D: | 110,88 Gb Total Space | 100,94 Gb Free Space | 91,04% Space Free | Partition Type: NTFS

Computer Name: PC_VISSER | User Name: Eigenaar | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.reg [@ = Regedit.Document] -- c:\Winnt\Regedit.exe %1

[HKEY_USERS\S-1-5-21-3921166209-81286332-4088324220-1003\SOFTWARE\Classes\<extension>]
.html [@ = ChromeHTML] -- Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] -- "%1" %*
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Player Service voor delen via het netwerk
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Player Service voor delen via het netwerk
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Player Service voor delen via het netwerk
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Player Service voor delen via het netwerk
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Player Service voor delen via het netwerk
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Player Service voor delen via het netwerk
"26675:TCP" = 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Player Service voor delen via het netwerk
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Player Service voor delen via het netwerk
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Player Service voor delen via het netwerk
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Player Service voor delen via het netwerk
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Player Service voor delen via het netwerk
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Player Service voor delen via het netwerk
"26675:TCP" = 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\CyberLink\PowerDVD11\PowerDVD11.exe" = C:\Program Files\CyberLink\PowerDVD11\PowerDVD11.exe:*:Enabled:CyberLink PowerDVD 11.0 -- (CyberLink Corp.)
"C:\Program Files\CyberLink\PowerDVD11\PDVD11Serv.exe" = C:\Program Files\CyberLink\PowerDVD11\PDVD11Serv.exe:*:Enabled:CyberLink PowerDVD 11.0 RC Service -- (CyberLink Corp.)
"C:\Program Files\CyberLink\PowerDVD11\Common\MediaServer\CLMSServerForPDVD11.exe" = C:\Program Files\CyberLink\PowerDVD11\Common\MediaServer\CLMSServerForPDVD11.exe:*:Enabled:CyberLink Media Server -- (CyberLink)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\iMesh Applications\iMesh\iMesh.exe" = C:\Program Files\iMesh Applications\iMesh\iMesh.exe:*:Enabled:iMesh
"C:\WINDOWS\system32\dplaysvr.exe" = C:\WINDOWS\system32\dplaysvr.exe:*:Enabled:Microsoft DirectPlay Helper -- (Microsoft Corporation)
"C:\Program Files\Microsoft Games\Age of Empires II\EMPIRES2.ICD" = C:\Program Files\Microsoft Games\Age of Empires II\EMPIRES2.ICD:*:Enabled:Age of Empires II -- (Microsoft Corporation)
"C:\Program Files\Samsung\Samsung New PC Studio\npsasvr.exe" = C:\Program Files\Samsung\Samsung New PC Studio\npsasvr.exe:*:Enabled:KTF MUSIC AoD Server -- (PeeringPortal)
"C:\Program Files\Samsung\Samsung New PC Studio\npsvsvr.exe" = C:\Program Files\Samsung\Samsung New PC Studio\npsvsvr.exe:*:Enabled:KTF MUSIC VoD Server -- (PeeringPortal)
"C:\Documents and Settings\Eigenaar\Mijn documenten\auke\filmpjes\s312\EmuleAc4_Setup.exe" = C:\Documents and Settings\Eigenaar\Mijn documenten\auke\filmpjes\s312\EmuleAc4_Setup.exe:*:Enabled:Emule Accelerator 4.1
"G:\LimeWire\LimeWire.exe" = G:\LimeWire\LimeWire.exe:*:Enabled:LimeWire
"C:\Program Files\LimeWire\LimeWire.exe" = C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire
"C:\WINDOWS\system32\muzapp.exe" = C:\WINDOWS\system32\muzapp.exe:*:Enabled:MUZ AOD APP player
"C:\Program Files\CyberLink\PowerDVD11\PowerDVD11.exe" = C:\Program Files\CyberLink\PowerDVD11\PowerDVD11.exe:*:Enabled:CyberLink PowerDVD 11.0 -- (CyberLink Corp.)
"C:\Program Files\CyberLink\PowerDVD11\PDVD11Serv.exe" = C:\Program Files\CyberLink\PowerDVD11\PDVD11Serv.exe:*:Enabled:CyberLink PowerDVD 11.0 RC Service -- (CyberLink Corp.)
"C:\Program Files\CyberLink\PowerDVD11\Common\MediaServer\CLMSServerForPDVD11.exe" = C:\Program Files\CyberLink\PowerDVD11\Common\MediaServer\CLMSServerForPDVD11.exe:*:Enabled:CyberLink Media Server -- (CyberLink)
"C:\Program Files\Landwirtschafts Simulator 2011\FarmingSimulator2011.exe" = C:\Program Files\Landwirtschafts Simulator 2011\FarmingSimulator2011.exe:*:Enabled:Landwirtschafts Simulator 2011 -- (GIANTS Software GmbH)
"C:\Program Files\Landwirtschafts Simulator 2011\game.exe" = C:\Program Files\Landwirtschafts Simulator 2011\game.exe:*:Enabled:Landwirtschafts Simulator 2011 -- (GIANTS Software GmbH)
"C:\Digital Imaging\bin\hpqtra08.exe" = C:\Digital Imaging\bin\hpqtra08.exe:*:Enabled:hpqtra08.exe -- (Hewlett-Packard Co.)
"C:\Digital Imaging\Unload\HpqDIA.exe" = C:\Digital Imaging\Unload\HpqDIA.exe:*:Enabled:hpqdia.exe -- ( )
"C:\Digital Imaging\bin\hpiscnapp.exe" = C:\Digital Imaging\bin\hpiscnapp.exe:*:Enabled:hpiscnapp.exe
"C:\Documents and Settings\Eigenaar\Mijn documenten\hielke\LimeWire\LimeWire.exe" = C:\Documents and Settings\Eigenaar\Mijn documenten\hielke\LimeWire\LimeWire.exe:*:Enabled:LimeWire -- (Lime Wire, LLC)
"C:\Digital Imaging\bin\hpqste08.exe" = C:\Digital Imaging\bin\hpqste08.exe:*:Enabled:hpqste08.exe -- (Hewlett-Packard Co.)
"C:\Digital Imaging\bin\hpofxm08.exe" = C:\Digital Imaging\bin\hpofxm08.exe:*:Enabled:hpofxm08.exe -- (Hewlett-Packard Co.)
"C:\Digital Imaging\bin\hposfx08.exe" = C:\Digital Imaging\bin\hposfx08.exe:*:Enabled:hposfx08.exe -- (Hewlett-Packard Co.)
"C:\Digital Imaging\bin\hposid01.exe" = C:\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe -- (Hewlett-Packard Co.)
"C:\Digital Imaging\bin\hpqscnvw.exe" = C:\Digital Imaging\bin\hpqscnvw.exe:*:Enabled:hpqscnvw.exe -- ()
"C:\Digital Imaging\bin\hpqkygrp.exe" = C:\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe -- (Hewlett-Packard)
"C:\Digital Imaging\bin\hpqCopy.exe" = C:\Digital Imaging\bin\hpqCopy.exe:*:Enabled:hpqcopy.exe -- (Hewlett-Packard Co.)
"C:\Digital Imaging\bin\hpfccopy.exe" = C:\Digital Imaging\bin\hpfccopy.exe:*:Enabled:hpfccopy.exe -- (Hewlett-Packard)
"C:\Digital Imaging\bin\hpzwiz01.exe" = C:\Digital Imaging\bin\hpzwiz01.exe:*:Enabled:hpzwiz01.exe -- (Hewlett-Packard Co.)
"C:\Digital Imaging\Unload\HpqPhUnl.exe" = C:\Digital Imaging\Unload\HpqPhUnl.exe:*:Enabled:hpqphunl.exe -- ()
"C:\Digital Imaging\bin\hpoews01.exe" = C:\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe -- (Hewlett-Packard Co.)
"C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe" = C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe:*:Enabled:WebKit -- (Apple Inc.)
"C:\Program Files\LimeWire Music\LimeWire Music.exe" = C:\Program Files\LimeWire Music\LimeWire Music.exe:*:Enabled:LimeWire Music -- (ProNetSharing)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}" = PDFCreator
"{03B1B42B-F6DE-41d9-8CFF-DC44E895C7A7}" = PhotoGallery
"{0611BD4E-4FE4-4a62-B0C0-18A4CC463428}" = CP_Package_Variety1
"{09984AEC-6B9F-4ca7-B78D-CB44D4771DA3}" = Destinations
"{09BDEEF0-5590-457D-89A9-5DB2742F9BBF}" = 32 Bit HP CIO Components Installer
"{0B33B738-AD79-4E32-90C5-E67BFB10BBFF}" = AiO_Scan
"{101738D7-D805-37A9-BB91-1F2C351782BF}" = Microsoft .NET Framework 3.5 Language Pack SP1 - nld
"{11202615-E557-4ECF-9B86-F59C81E52909}" = FIFA 10
"{15EE79F4-4ED1-4267-9B0F-351009325D7D}" = HP Software Update
"{168F8BAC-A269-48E9-BB7A-A51B594CF6FF}" = Microsoft .NET Framework 1.1 Dutch Language Pack
"{172975EB-9465-4861-95B5-C7BB6D3DE62A}" = DocumentViewer
"{1BD6AE96-4742-4498-9D03-9451C7E5A214}" = Windows Live aanmeldhulp
"{1C139D7D-9FEA-468d-A9C8-2A6E3BDE564A}" = CP_Package_Variety3
"{1E8F5328-A734-465B-870F-8AC57BFFE8DF}" = CoachJezelf versie 3.0
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live - Hulpprogramma voor uploaden
"{21DB3D90-D816-4092-A260-CA3F6B55A6DD}" = Sonic_PrimoSDK
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{23A7B376-BBEC-4e76-BBD7-0F155E70D74B}" = CP_Panorama1Config
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java(TM) 6 Update 30
"{2CADCEAB-D5DA-44D6-B5FC-7DEE87AB3C0C}" = Unload
"{30C19FF2-7FBA-4d09-B9DE-1659977F64F6}" = TrayApp
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java(TM) 6 Update 7
"{32BDCCB8-9DC8-496d-9DB1-F77510775BDB}" = InstantShareDevices
"{34610DE0-3C13-42CA-8E32-01FFA38AB6E8}" = PC Connectivity Solution
"{34A0FF07-F11A-4157-84A3-92F8AD688CBF}" = Vodafone Mobile Broadband via the phone
"{350C9413-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{36E47DA1-10E1-45d9-8B19-14D19607CDCF}" = CP_CalendarTemplates1
"{3E0D0742-45BF-4438-8CE2-1AAADE878DBD}" = Vodafone Mobile Broadband via the phone
"{43602F34-1AA3-44FB-AEB2-D08C2C73743F}" = Paint.NET v3.36
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4F643D2A-F0B6-447C-95AE-048BB8FC24C5}" = SMCWPCI-G 54Mbps Wireless PCI adapter
"{4FFBB818-B13C-11E0-931D-B2664824019B}_is1" = Complitly
"{53EE9E42-CECB-4C92-BF76-9CA65DAF8F1C}" = FullDPAppQFolder
"{54E3707F-808E-4fd4-95C9-15D1AB077E5D}" = NewCopy
"{56EE8B17-8274-418d-89AC-C057C5DB251E}" = RandMap
"{5A01C58E-B0EC-49b9-AD71-7C0468688087}" = CP_Package_Basic1
"{5B622B7A-60FB-4630-B11D-F121D20BCCD6}" = MarketResearch
"{5B79CFD1-6845-4158-9D7D-6BE89DF2C135}" = HP PSC & OfficeJet 5.3.B
"{5F26311C-B135-4F7F-B11E-8E650F83651E}" = DeviceFunctionQFolder
"{65248369-7CB9-43A9-82C8-C438AE04DED4}" = 1500
"{66BA8C26-AFE4-4408-807B-43E76B57EF53}" = SkinsHP1
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6BB6627C-694F-4FDC-A3E5-C7F4BED4C724}" = DocProc
"{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7850A6D2-CBEA-4728-9877-F1BEDEA9F619}" = AiOSoftware
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{7BE15435-2D3E-4B58-867F-9C75BED0208C}" = QuickTime
"{7C03270C-4FAB-4F5C-B10D-52FEDA190790}" = DocumentViewerQFolder
"{7C9B95B7-B598-4398-B30F-7F6827192E6C}" = ProductContext
"{7E27304E-BAA2-4d90-A34E-76641FAFABB4}" = CP_AtenaShokunin1Config
"{81E06318-EEB9-4D55-8CD5-7AC9148D5E66}" = 1500_Help
"{81F7A77A-09AE-40A9-84B1-6887F8CCD53F}" = Google SketchUp 8
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90110413-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Editie 2003
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{923A7F5A-1E8C-4FBE-8DF6-85940A60A79F}" = Readme
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{951B0F30-9F1A-4BF6-B3DA-99EB0E917B1C}" = FARO LS 1.1.406.58
"{99052DB7-9592-4522-A558-5417BBAD48EE}" = Microsoft ActiveSync
"{9A1027CE-83F6-3CB2-B9BA-9DA38D0907D0}" = Microsoft .NET Framework 2.0 Service Pack 2 Language Pack - NLD
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9DEABCB6-B759-4D52-92F8-51B34A2B4D40}" = Autodesk Material Library 2011
"{A195B13E-A5E3-4BAF-A995-7F70F445CD06}" = ScannerCopy
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A36B158D-8E9D-4BD3-8BDA-4B5EDC9C2E8C}" = Norman Security Suite
"{A48B9CD8-C2BA-4EC9-0081-7260D238C7CF}" = Need for Speed™ Most Wanted
"{A5BB5365-EFB4-44c3-A7E2-EB59B7EFD23D}" = CueTour
"{A83279FD-CA4B-4206-9535-90974DE76654}" = Apple Application Support
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AC54E544-3E42-443C-A91D-A00A6974C592}" = NVIDIA PhysX v8.10.13
"{AC76BA86-7AD7-1043-7B44-A94000000001}" = Adobe Reader 9.4.7 - Nederlands
"{B194272D-1F92-46DF-99EB-8D5CE91CB4EC}" = Adobe AIR
"{B4D279F1-4309-49cc-A4B5-3A0D2E59C7B5}" = PanoStandAlone
"{B824B5C9-849F-4b9e-9EA7-6FD8CD8116DA}" = CP_Package_Variety2
"{BD9F9101-9120-4454-B186-CFD22C64856E}" = Google SketchUp 7
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C20C2630-B3A7-44BA-BDD0-31E256AE490E}" = Windows Live Call
"{C506A18C-1469-4678-B094-F4EC9DAE6DB7}" = Scan
"{C9BED750-1211-4480-B1A5-718A3BE15525}" = REALTEK GbE & FE Ethernet PCI-E NIC Driver
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CBA30674-A242-4531-82B5-586B31F90E04}" = 1500Trb
"{CC38A00D-7EED-46CE-9281-D1D97B81F22A}" = Windows Live Messenger
"{CCA1EEA3-555E-4D05-AC46-4B49C6C5D887}" = Apple Mobile Device Support
"{CD1E078C-A6B9-47DA-B035-6365C85C7832}" = Autodesk Material Library 2011 Base Image library
"{CE24344F-DFD8-40C8-8FD8-C9740B5F25AC}" = Fax
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}" = SAMSUNG USB Driver for Mobile Phones
"{E3F90083-80D4-4b5a-87C7-E97E12F5516D}" = HPProductAssistant
"{E4B7BD2F-FC41-490F-965D-15D93F4FE1A2}" = OpenOffice.org 3.0
"{EA103B64-C0E4-4C0E-A506-751590E1653D}" = SolutionCenter
"{EB5A3E9D-91CF-4C97-B816-72DE0625ACA3}" = Windows Live Essentials
"{ED580C51-0549-43DF-B3D5-953B146E61C3}_is1" = Pavtube MOD Converter Ver 3.7.3.1864
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F193FC0E-9E18-40FC-A974-509A1BDD240A}" = Samsung New PC Studio
"{F232C87C-6E92-4775-8210-DFE90B7777D9}" = CyberLink PowerDVD 11
"{F4C2E5F5-2970-45f4-ABD3-C180C4D961C4}" = Status
"{F73EA8BF-81F5-32AF-8D8A-24F12FD23B79}" = Microsoft .NET Framework 3.0 Service Pack 2 Language Pack - NLD
"{F7828387-C188-4F11-00AB-148CDF607FD6}" = Need For Speed poursuite infernale 2
"{FE64AE29-0883-4C70-8388-DC026019C900}" = HP Image Zone Express
"{FF1C31AE-0CDC-40CE-AB85-406F8B70D643}" = Bonjour
"504244733D18C8F63FF584AEB290E3904E791693" = Windows-stuurprogrammapakket - Nokia pccsmcfd (08/22/2008 7.0.0.0)
"7-Zip" = 7-Zip 9.22beta
"Aangifte inkomstenbelasting 2010" = Aangifte inkomstenbelasting 2010
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player
"Age of Empires 2.0" = Microsoft Age of Empires II
"Ares" = Ares 2.1.6
"Audacity_is1" = Audacity 1.2.6
"AVS Update Manager_is1" = AVS Update Manager 1.0
"AVS4YOU Software Navigator_is1" = AVS4YOU Software Navigator 1.4
"BrowserCompanion" = BrowserCompanion
"CCleaner" = CCleaner (remove only)
"Download_Energy Toolbar" = Download Energy Toolbar
"DVD Shrink_is1" = DVD Shrink 3.2
"FarmingSimulator2011DE_is1" = Landwirtschafts Simulator 2011
"FileZilla Client" = FileZilla Client 3.1.4.1
"Finale NotePad 2008" = Finale NotePad 2008
"HP Document Viewer" = HP Document Viewer 5.3
"HP Imaging Device Functions" = HP Imaging Device Functions 5.3
"HP Photo & Imaging" = HP Image Zone 5.3
"HP Solution Center & Imaging Support Tools" = HP Solution Center & Imaging Support Tools 5.3
"HPExtendedCapabilities" = HP Extended Capabilities 5.3
"Huur- en zorgtoeslag 2011" = Huur- en zorgtoeslag 2011
"HWiNFO32_is1" = HWiNFO32 Version 2.35
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie8" = Windows Internet Explorer 8
"InfraRecorder" = InfraRecorder
"InstallShield_{4F643D2A-F0B6-447C-95AE-048BB8FC24C5}" = SMCWPCI-G 54Mbps Wireless PCI adapter
"InstallShield_{F193FC0E-9E18-40FC-A974-509A1BDD240A}" = Samsung New PC Studio
"InstallShield_{F232C87C-6E92-4775-8210-DFE90B7777D9}" = CyberLink PowerDVD 11
"KigoVideoConverter_is1" = KigoVideoConverter 1.1.1
"LimeWire Music" = LimeWire Music
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware versie 1.61.0.1400
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 Language Pack SP1 - nld" = Taalpakket voor Microsoft .NET Framework 3.5 SP1 - NL
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Thunderbird (2.0.0.17)" = Mozilla Thunderbird (2.0.0.17)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MyFreeCodec" = MyFreeCodec
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"Notepad++" = Notepad++
"NVIDIA Drivers" = NVIDIA Drivers
"Nvu_is1" = Nvu 1.0
"Origin" = Origin
"Picasa 3" = Picasa 3
"PuTTY_is1" = PuTTY version 0.60
"RAY60N" = RAY60N
"RealAlt_is1" = Real Alternative 1.9.0
"SimpleOCR 3.1" = SimpleOCR 3.1
"SopCast" = SopCast 3.3.2
"SpeedFan" = SpeedFan (remove only)
"ST6UNST #1" = ReNamer
"SyncBack_is1" = SyncBack
"Tweak UI 2.10" = Tweak UI
"Uninstall_is1" = Uninstall 1.0.0.1
"VirtualCloneDrive" = VirtualCloneDrive
"VLC media player" = VLC media player 1.1.9
"Windows Live OneCare safety scanner" = Windows Live OneCare safety scanner
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"WinGimp-2.0_is1" = GIMP 2.4.7
"WinLiveSuite_Wave3" = Windows Live Essentials
"winscp3_is1" = WinSCP 4.1.6
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"XPSEPSCLP" = XML Paper Specification Shared Components Language Pack 1.0

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-3921166209-81286332-4088324220-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome
"MyFreeCodec" = MyFreeCodec
"Power Loader" = Power Challenge Game Plugin

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 3-5-2012 9:01:30 | Computer Name = PC_VISSER | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 3-5-2012 9:01:30 | Computer Name = PC_VISSER | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 1969

Error - 3-5-2012 9:01:30 | Computer Name = PC_VISSER | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 1969

[ System Events ]
Error - 17-4-2012 9:21:35 | Computer Name = PC_VISSER | Source = Cdrom | ID = 262151
Description = Beschadigd blok in apparaat \Device\CdRom0.

Error - 24-4-2012 2:33:05 | Computer Name = PC_VISSER | Source = Service Control Manager | ID = 7034
Description = De CyberLink PowerDVD 11.0 Service-service is onverwacht beëindigd.
Dit is nu 1 keer gebeurd.

Error - 24-4-2012 6:50:06 | Computer Name = PC_VISSER | Source = Dhcp | ID = 1000
Description = Uw computer heeft de lease verloren van het IP-adres 192.168.2.236
op de netwerkkaart met netwerkadres 0004E2FAFA24.

Error - 30-4-2012 18:06:44 | Computer Name = PC_VISSER | Source = System Error | ID = 1003
Description = Foutcode; 1000007f, parameter1: 00000008, parameter2: 80042000, parameter3:
00000000, parameter4: 00000000.

Error - 3-5-2012 5:45:42 | Computer Name = PC_VISSER | Source = Service Control Manager | ID = 7026
Description = De volgende opstartstuurprogramma's zijn niet geladen: agp440 IntelIde

Error - 3-5-2012 9:01:29 | Computer Name = PC_VISSER | Source = Service Control Manager | ID = 7034
Description = De CyberLink PowerDVD 11.0 Service-service is onverwacht beëindigd.
Dit is nu 1 keer gebeurd.

Error - 3-5-2012 9:40:43 | Computer Name = PC_VISSER | Source = Dhcp | ID = 1000
Description = Uw computer heeft de lease verloren van het IP-adres 192.168.2.236
op de netwerkkaart met netwerkadres 0004E2FAFA24.

Error - 3-5-2012 9:40:48 | Computer Name = PC_VISSER | Source = Dhcp | ID = 1001
Description = Deze computer heeft geen adres toegewezen gekregen van het netwerk
(door de DHCP-server) voor de netwerkkaart met netwerkadres 0004E2FAFA24. De volgende
fout is opgetreden: %%1223. De computer zal doorgaan om zelf een adres van de server
met netwerkadressen (DHCP-server) proberen te krijgen.

Error - 4-5-2012 8:25:22 | Computer Name = PC_VISSER | Source = Service Control Manager | ID = 7031
Description = De Mobiel Apple apparaat-service is onverwacht gestopt. Dit is 1 keer
gebeurd. De volgende herstelbewerking zal over 60000 milliseconden worden uitgevoerd:
Service opnieuw starten.

Error - 4-5-2012 8:29:00 | Computer Name = PC_VISSER | Source = MRxSmb | ID = 8003
Description = De masterbrowser heeft een servermelding ontvangen van computer ACER-A0B1A665A8
die
meent de masterbrowser voor het domein te zijn op transport NetBT_Tcpip_{7A84989F-FE4.
De masterbrowser wordt gestopt of er wordt een verkiezing afgedwongen.


< End of report >


Omhoog
 Profiel  
 
BerichtGeplaatst: vr mei 04, 2012 3:49 pm 
Offline
Moderator
Avatar gebruiker

Geregistreerd: wo apr 13, 2005 3:54 pm
Berichten: 30855
Woonplaats: Kotje aan de kust.
Besturingssysteem: Windows 7
Bescherming: Malwarebytes pro
Start OTL
  • Plak het volgende onder Custom Scans/Fixes

    Citaat:
    :OTL
    IE - HKU\S-1-5-21-3921166209-81286332-4088324220-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource= ... =CT1269415
    IE - HKU\S-1-5-21-3921166209-81286332-4088324220-1003\..\URLSearchHook: {ad708c09-d51b-45b3-9d28-4eba2681febf} - C:\Program Files\Download_Energy\prxtbDow0.dll (Conduit Ltd.)
    IE - HKU\S-1-5-21-3921166209-81286332-4088324220-1003\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT1269415
    IE - HKU\S-1-5-21-3921166209-81286332-4088324220-1003\..\SearchScopes\{CF739809-1C6C-47C0-85B9-569DBB141420}: "URL" = http://toolbar.ask.com/toolbarv/askRedi ... t=&gc=1&q={searchTerms}&crm=1
    IE - HKU\S-1-5-21-3921166209-81286332-4088324220-1003\..\SearchScopes\{E08A9998-D98F-476f-8F5C-37C80FE0A4DA}: "URL" = http://search.conduit.com/?SearchSource ... =CT2527944
    IE - HKU\S-1-5-21-3921166209-81286332-4088324220-1003\..\SearchScopes\{CF739809-1C6C-47C0-85B9-569DBB141420}: "URL" = http://toolbar.ask.com/toolbarv/askRedi ... t=&gc=1&q={searchTerms}&crm=1


    O2 - BHO: (Download Energy Toolbar) - {ad708c09-d51b-45b3-9d28-4eba2681febf} - C:\Program Files\Download_Energy\prxtbDow0.dll (Conduit Ltd.)
    O3 - HKLM\..\Toolbar: (Download Energy Toolbar) - {ad708c09-d51b-45b3-9d28-4eba2681febf} - C:\Program Files\Download_Energy\prxtbDow0.dll (Conduit Ltd.)
    O3 - HKU\S-1-5-21-3921166209-81286332-4088324220-1003\..\Toolbar\WebBrowser: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found.
    O3 - HKU\S-1-5-21-3921166209-81286332-4088324220-1003\..\Toolbar\WebBrowser: (Download Energy Toolbar) - {AD708C09-D51B-45B3-9D28-4EBA2681FEBF} - C:\Program Files\Download_Energy\prxtbDow0.dll (Conduit Ltd.)
    [2012-03-21 08:40:43 | 000,000,000 | ---D | M] (Download Energy Community Toolbar) -- C:\Documents and Settings\Eigenaar\Application Data\Mozilla\Firefox\Profiles\hl2ye7ym.default\extensions\{ad708c09-d51b-45b3-9d28-4eba2681febf}

    :Services

    :Reg

    :Files
    ipconfig /flushdns /c

    :Commands
    [purity]
    [resethosts]
    [emptytemp]
    [emptyflash]
    [createrestorepoint]
    [reboot]
  • Klik daarna bovenaan op de knop Run Fix
  • Laat het programma ongestoord zijn werk doen. De pc zal na afloop opnieuw opgestart worden.

_________________
Afbeelding
Goed geholpen hier, overweeg een donatie:
loglezer worden?
Lid van Team Opleiding.
tips
traagheidtips


Omhoog
 Profiel  
 
BerichtGeplaatst: vr mei 04, 2012 4:07 pm 
Offline
Lid

Geregistreerd: vr mei 04, 2012 2:41 pm
Berichten: 3
Besturingssysteem: Windows XP H.E.
Bescherming: Norman Antivirus
Met dank! Het euvel is verholpen dankzij je goede tips!

Dit was het laatste rapport wat verscheen na de reboot:


All processes killed
========== OTL ==========
HKU\S-1-5-21-3921166209-81286332-4088324220-1003\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
Registry value HKEY_USERS\S-1-5-21-3921166209-81286332-4088324220-1003\Software\Microsoft\Internet Explorer\URLSearchHooks\\{ad708c09-d51b-45b3-9d28-4eba2681febf} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ad708c09-d51b-45b3-9d28-4eba2681febf}\ deleted successfully.
C:\Program Files\Download_Energy\prxtbDow0.dll moved successfully.
Registry key HKEY_USERS\S-1-5-21-3921166209-81286332-4088324220-1003\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{afdbddaa-5d3f-42ee-b79c-185a7020515b}\ not found.
Registry key HKEY_USERS\S-1-5-21-3921166209-81286332-4088324220-1003\Software\Microsoft\Internet Explorer\SearchScopes\{CF739809-1C6C-47C0-85B9-569DBB141420}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CF739809-1C6C-47C0-85B9-569DBB141420}\ not found.
Registry key HKEY_USERS\S-1-5-21-3921166209-81286332-4088324220-1003\Software\Microsoft\Internet Explorer\SearchScopes\{E08A9998-D98F-476f-8F5C-37C80FE0A4DA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E08A9998-D98F-476f-8F5C-37C80FE0A4DA}\ not found.
Registry key HKEY_USERS\S-1-5-21-3921166209-81286332-4088324220-1003\Software\Microsoft\Internet Explorer\SearchScopes\{CF739809-1C6C-47C0-85B9-569DBB141420}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CF739809-1C6C-47C0-85B9-569DBB141420}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{ad708c09-d51b-45b3-9d28-4eba2681febf}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ad708c09-d51b-45b3-9d28-4eba2681febf}\ not found.
File C:\Program Files\Download_Energy\prxtbDow0.dll not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{ad708c09-d51b-45b3-9d28-4eba2681febf} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ad708c09-d51b-45b3-9d28-4eba2681febf}\ not found.
File C:\Program Files\Download_Energy\prxtbDow0.dll not found.
Registry value HKEY_USERS\S-1-5-21-3921166209-81286332-4088324220-1003\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{32099AAC-C132-4136-9E9A-4E364A424E17} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{32099AAC-C132-4136-9E9A-4E364A424E17}\ not found.
Registry value HKEY_USERS\S-1-5-21-3921166209-81286332-4088324220-1003\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{AD708C09-D51B-45B3-9D28-4EBA2681FEBF} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AD708C09-D51B-45B3-9D28-4EBA2681FEBF}\ not found.
File C:\Program Files\Download_Energy\prxtbDow0.dll not found.
C:\Documents and Settings\Eigenaar\Application Data\Mozilla\Firefox\Profiles\hl2ye7ym.default\extensions\{ad708c09-d51b-45b3-9d28-4eba2681febf}\searchplugin folder moved successfully.
C:\Documents and Settings\Eigenaar\Application Data\Mozilla\Firefox\Profiles\hl2ye7ym.default\extensions\{ad708c09-d51b-45b3-9d28-4eba2681febf}\modules folder moved successfully.
C:\Documents and Settings\Eigenaar\Application Data\Mozilla\Firefox\Profiles\hl2ye7ym.default\extensions\{ad708c09-d51b-45b3-9d28-4eba2681febf}\META-INF folder moved successfully.
C:\Documents and Settings\Eigenaar\Application Data\Mozilla\Firefox\Profiles\hl2ye7ym.default\extensions\{ad708c09-d51b-45b3-9d28-4eba2681febf}\defaults folder moved successfully.
C:\Documents and Settings\Eigenaar\Application Data\Mozilla\Firefox\Profiles\hl2ye7ym.default\extensions\{ad708c09-d51b-45b3-9d28-4eba2681febf}\components folder moved successfully.
C:\Documents and Settings\Eigenaar\Application Data\Mozilla\Firefox\Profiles\hl2ye7ym.default\extensions\{ad708c09-d51b-45b3-9d28-4eba2681febf}\chrome folder moved successfully.
C:\Documents and Settings\Eigenaar\Application Data\Mozilla\Firefox\Profiles\hl2ye7ym.default\extensions\{ad708c09-d51b-45b3-9d28-4eba2681febf} folder moved successfully.
========== SERVICES/DRIVERS ==========
========== REGISTRY ==========
========== FILES ==========
< ipconfig /flushdns /c >
Windows IP-configuratie
De DNS-omzettingscache is leeggemaakt.
C:\Documents and Settings\Eigenaar\Bureaublad\cmd.bat deleted successfully.
C:\Documents and Settings\Eigenaar\Bureaublad\cmd.txt deleted successfully.
========== COMMANDS ==========
C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 508038 bytes
->FireFox cache emptied: 58590330 bytes
->Flash cache emptied: 56992 bytes

User: Eigenaar
->Temp folder emptied: 1499116206 bytes
->Temporary Internet Files folder emptied: 5663788 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 59145450 bytes
->Google Chrome cache emptied: 94316196 bytes
->Flash cache emptied: 57276 bytes

User: LocalService
->Temp folder emptied: 413323969 bytes
->Temporary Internet Files folder emptied: 57075 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 1103210 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 2507326 bytes
%systemroot%\System32 .tmp files removed: 31035677 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 15105175 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 196666828 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33443 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 2.267,00 mb


[EMPTYFLASH]

User: Administrator

User: All Users

User: Default User
->Flash cache emptied: 0 bytes

User: Eigenaar
->Flash cache emptied: 0 bytes

User: LocalService

User: NetworkService

Total Flash Files Cleaned = 0,00 mb

Unable to start System Restore Service. Error code 1056

OTL by OldTimer - Version 3.2.42.2 log created on 05042012_155844

Files\Folders moved on Reboot...
C:\Documents and Settings\Eigenaar\Local Settings\Temp\WCESLog.log moved successfully.
File move failed. C:\Documents and Settings\LocalService\Local Settings\Temp\nvcbin.def.216b6148.tmp scheduled to be moved on reboot.

Registry entries deleted on Reboot...


That's it! Bedankt!


Omhoog
 Profiel  
 
BerichtGeplaatst: vr mei 04, 2012 4:13 pm 
Offline
Moderator
Avatar gebruiker

Geregistreerd: wo apr 13, 2005 3:54 pm
Berichten: 30855
Woonplaats: Kotje aan de kust.
Besturingssysteem: Windows 7
Bescherming: Malwarebytes pro
Mooi zo, dan mag je de tool weer verwijderen. Ik zal het topic sluiten en verplaatsen naar opgelost.

Ccleaner
Download CCleaner Slim
Installeer CCleaner en start CCleaner op.

  • Klik in de linkse kolom op Cleaner.
  • Klik achtereenvolgens op Analyseren en Opschonen.
  • Klik vervolgens in de linkse kolom op Register en klik op Scan naar problemen.
  • Als er fouten gevonden worden klik je op Herstel geselecteerde problemen en OK.
  • Dan krijg je de vraag om een back-up te maken, klik op JA. en kies dan Herstel alle geselecteerde fouten.
  • Sluit hierna CCleaner af.

Om herbesmetting te vermijden, kan je deze tips eens nalezen:
Hoe voorkom ik een nieuwe infectie?

_________________
Afbeelding
Goed geholpen hier, overweeg een donatie:
loglezer worden?
Lid van Team Opleiding.
tips
traagheidtips


Omhoog
 Profiel  
 
Geef de vorige berichten weer:  Sorteer op  
Dit onderwerp is gesloten, je kunt geen berichten wijzigen of nieuwe antwoorden plaatsen  [ 6 berichten ] 

Alle tijden zijn GMT + 1 uur [ Zomertijd ]


Wie is er online

Gebruikers op dit forum: Geen geregistreerde gebruikers. en 2 gasten


Je mag geen nieuwe onderwerpen in dit forum plaatsen
Je mag niet antwoorden op een onderwerp in dit forum
Je mag je berichten in dit forum niet wijzigen
Je mag je berichten niet uit dit forum verwijderen
Je mag geen bijlagen toevoegen in dit forum

Ga naar:  
Powered by phpBB® Forum Software © phpBB Group
phpBB.nl Vertaling