Amycite-opgelost

Spyware is software die in het geheim op je computer wordt geplaatst en die persoonlijke gegevens doorstuurt, reclame toont, enz. Stel hier vragen, leer hoe je ervan af kan komen en hoe het te voorkomen.

meme-rietje
Lid geworden op: 13 okt 2003, 19:51
Locatie: Zuid-West-Vl.

24 feb 2017, 11:38

beste PC dokters ik heb al een tijdje problemen met mijn laptop
ik ben geduiveld met amicite en vind het nergens om te verwijderen
mijn logje:
Logfile of Trend Micro HijackThis v2.0.5
Scan saved at 11:30:32, on 24/02/2017
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.14393.0000)

FIREFOX: 51.0.1 (x86 nl)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe
C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe
C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe
C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudPhotos.exe
C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe
C:\Program Files (x86)\Common Files\Apple\Apple Application Support\secd.exe
C:\Program Files (x86)\Spy Cleaner Gold\SpyWatcher.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Firefox\Firefox.exe
C:\Program Files (x86)\Firefox\Firefox.exe
C:\Users\Rita\Documents\Mijn Downloads\Hijackthislog mapje\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.amisites.com/?type=hp&ts=148 ... 2_W3P2FY58
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = www.google.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.amisites.com/?type=hp&ts=148 ... 2_W3P2FY58
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.amisites.com/?type=hp&ts=148 ... 2_W3P2FY58
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.amisites.com/search/?type=ds ... earchTerms}
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.amisites.com/search/?type=ds ... earchTerms}
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.amisites.com/?type=hp&ts=148 ... 2_W3P2FY58
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = www.google.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = www.google.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://g.uk.msn.com/HPCON14/2
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: 0.0.0.1 mssplus.mcafee.com
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_121\bin\ssv.dll
O2 - BHO: AVG Web TuneUp - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Web TuneUp\4.3.1.831\AVG Web TuneUp.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_121\bin\jp2ssv.dll
O2 - BHO: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll
O2 - BHO: Adblock Plus for IE Browser Helper Object - {FFCB3198-32F3-4E8B-9539-4324694ED664} - C:\Program Files\Adblock Plus for IE\AdblockPlus32.dll
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [beid] "C:\Program Files (x86)\Belgium Identity Card\beid35gui.exe" /startup
O4 - HKLM\..\Run: [Spy Watcher] "C:\PROGRA~2\SPYCLE~1\SPYWAT~1.EXE" -S
O4 - HKLM\..\Run: [vProt] "C:\Program Files (x86)\AVG Web TuneUp\vprot.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [Corel Photo Downloader] "c:\Program Files (x86)\Common Files\Corel\Corel PhotoDownloader\Corel Photo Downloader.exe" -startup
O4 - HKCU\..\Run: [iCloudServices] C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
O4 - HKCU\..\Run: [iCloudDrive] C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe
O4 - HKCU\..\Run: [iCloudPhotos] C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudPhotos.exe
O4 - HKCU\..\Run: [uTorrent] "C:\Users\Rita\AppData\Roaming\uTorrent\uTorrent.exe" /MINIMIZED
O4 - HKCU\..\Run: [SpybotPostWindows10UpgradeReInstall] "C:\Program Files\Common Files\AV\Spybot - Search and Destroy\Test.exe"
O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\Program Files (x86)\Microsoft Office\Office12\EXCEL.EXE/3000
O9 - Extra button: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-103 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-102 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - (no file)
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: http://*.webcompanion.com
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Protocol: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Andrea RT Filters Service (AERTFilters) - Andrea Electronics Corporation - C:\Program Files\Realtek\Audio\HDA\AERTSr64.EXE
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\WINDOWS\system32\atiesrxx.exe (file missing)
O23 - Service: Apple Mobile Device Service - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour-service (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: HP SimplePass Cachedrv Service (Cachedrv server) - Unknown owner - C:\Program Files\Hewlett-Packard\SimplePass\cachesrvr.exe
O23 - Service: CyberLink PowerDVD 12 Media Server Monitor Service - CyberLink - C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSMonitorServicePDVD12.exe
O23 - Service: CyberLink PowerDVD 12 Media Server Service - CyberLink - C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe
O23 - Service: @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000 (diagnosticshub.standardcollector.service) - Unknown owner - C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe (file missing)
O23 - Service: ed2k idle service (ed2kidle) - Unknown owner - C:\Program Files (x86)\amuleCe\ed2k.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: Update Service(FirefoxU) (FirefoxU) - Unknown owner - C:\Program Files (x86)\Firefox\bin\FirefoxUpdate.exe
O23 - Service: HP Support Assistant Service - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: @oem17.inf,%hpservice_desc%;HP Service (hpsrv) - Unknown owner - C:\WINDOWS\system32\Hpservice.exe (file missing)
O23 - Service: HPWMISVC - Hewlett-Packard Development Company, L.P. - C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPWMISVC.exe
O23 - Service: iPod-service (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: iThemes5 - Unknown owner - rundll32.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Program Files\McAfee Security Scan\3.11.474\McCHSvc.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: Realtek Audio Service (RtkAudioService) - Realtek Semiconductor - C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SensorDataService.exe,-101 (SensorDataService) - Unknown owner - C:\WINDOWS\System32\SensorDataService.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: SynTPEnh Caller Service (SynTPEnhService) - Synaptics Incorporated - C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
O23 - Service: @%SystemRoot%\system32\TieringEngineService.exe,-702 (TieringEngineService) - Unknown owner - C:\WINDOWS\system32\TieringEngineService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: Update service - Popcorn Time - C:\Program Files (x86)\Popcorn Time\Updater.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: vToolbarUpdater40.3.1 - Unknown owner - C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\40.3.1\ToolbarUpdater.exe
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: WtuSystemSupport - Unknown owner - C:\Program Files (x86)\AVG Web TuneUp\WtuSystemSupport.exe

--
End of file - 13194 bytes

ik weet dat ik de details van mijn laptop moet geven maar waar vind ik dat?sorry
Groetjes van meme-rietje,
het is gemakkelijker op te geven dan door te gaan

verhaegen
Support SeniorenNet
Lid geworden op: 03 apr 2003, 20:48
Locatie: kapellen

24 feb 2017, 12:16

klik eens op onderstaande link
http://www.seniorennet.be/forum/viewtopic.php?t=197112
en voer eens uit wat daar staat
en plak de log die het tool maakt dan alhier als nieuw antwoord

abbs zal u dan verder helpen

om te zien of u een 32 of 64 nodig hebt staat der op de link een blauwe "hier" dan ga je kunnen zien welke u nodig hebt

meme-rietje
Lid geworden op: 13 okt 2003, 19:51
Locatie: Zuid-West-Vl.

24 feb 2017, 12:56

Extra scanresultaten van Farbar Recovery Scan Tool (x64) Versie: 23-02-2017 01
Gestart door Rita (24-02-2017 12:34:38)
Gestart vanaf C:\Users\Rita\Documents\Mijn Downloads\Hijackthislog mapje
Windows 10 Home Versie 1607 (X64) (2016-09-25 09:40:17)
Boot Modus: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-2370912473-469425822-2799426420-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-2370912473-469425822-2799426420-503 - Limited - Disabled)
Gast (S-1-5-21-2370912473-469425822-2799426420-501 - Limited - Disabled)
Rita (S-1-5-21-2370912473-469425822-2799426420-1002 - Administrator - Enabled) => C:\Users\Rita

==================== Security Center ========================

(Als een item is opgenomen in de fixlist, zal het worden verwijderd.)

AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Geïnstalleerde programma's ======================

(Alleen de adware-programma's met 'verborgen' vlag zou kunnen worden toegevoegd aan de fixlist om ze zichtbaar te maken. De adware-programma's moeten handmatig gedeinstallerd worden.)

µTorrent (HKU\S-1-5-21-2370912473-469425822-2799426420-1002\...\uTorrent) (Version: 3.4.9.43295 - BitTorrent Inc.)
7-Zip 9.20 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov)
Ad-Aware Browsing Protection (HKLM-x32\...\Ad-Aware Browsing Protection) (Version: 1.0.1.124 - )
Adblock Plus voor IE (32-bit en 64-bit) (HKLM\...\{3156E6CF-341C-4BAB-BF93-DCE3B598C80D}) (Version: 1.4 - Eyeo GmbH)
Adobe Acrobat Reader DC - Nederlands (HKLM-x32\...\{AC76BA86-7AD7-1043-7B44-AC0F074E4100}) (Version: 15.023.20070 - Adobe Systems Incorporated)
Adobe Flash Player 24 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 24.0.0.221 - Adobe Systems Incorporated)
AMD Catalyst Install Manager (HKLM\...\{E825A27F-01E0-1BB8-6A7D-DD769D57E4B0}) (Version: 8.0.915.0 - Advanced Micro Devices, Inc.)
amuleC (HKLM-x32\...\{B2EFFD4E-D098-4845-9D56-DE75BEB35913}) (Version: 1.0.1 - amuleC) <==== AANDACHT
Apple Application Support (32-bit) (HKLM-x32\...\{9BA1A894-B42F-4805-BC8C-349C905A3930}) (Version: 5.3.1 - Apple Inc.)
Apple Application Support (64-bit) (HKLM\...\{7EAC8A42-9FAC-4F6B-AABF-C08C9F2E0F13}) (Version: 5.3.1 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{55BB2110-FB43-49B3-93F4-945A0CFB0A6C}) (Version: 10.0.1.3 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{56EC47AA-5813-4FF6-8E75-544026FBEA83}) (Version: 2.2.0.150 - Apple Inc.)
AVG Web TuneUp (HKLM-x32\...\AVG Web TuneUp) (Version: 4.3.1.831 - AVG Technologies)
Belgium e-ID middleware 4.1.10 (build 1698) (HKLM\...\{DB942AEA-93D6-4FE4-8862-180D35A71698}) (Version: 4.1.1698 - Belgian Government)
Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)
Canon MP Navigator 3.1 (HKLM-x32\...\MP Navigator 3.1) (Version: - )
Canon MP140 series (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP140_series) (Version: - )
Catalyst Control Center Next Localization BR (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization BR (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization BR (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization BR (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CHS (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CHS (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CHS (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CHS (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CHT (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CHT (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CHT (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CHT (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CS (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CS (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CS (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CS (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization DA (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization DA (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization DA (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization DA (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization DE (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization DE (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization DE (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization DE (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization EL (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization EL (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization EL (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization EL (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization ES (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization ES (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization ES (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization ES (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization FI (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization FI (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization FI (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization FI (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization FR (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization FR (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization FR (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization FR (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization HU (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization HU (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization HU (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization HU (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization IT (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization IT (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization IT (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization IT (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization JA (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization JA (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization JA (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization JA (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization KO (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization KO (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization KO (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization KO (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization NL (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization NL (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization NL (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization NL (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization NO (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization NO (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization NO (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization NO (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization PL (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization PL (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization PL (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization PL (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization RU (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization RU (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization RU (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization RU (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization SV (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization SV (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization SV (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization SV (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization TH (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization TH (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization TH (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization TH (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization TR (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization TR (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization TR (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization TR (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Corel Paint Shop Pro X (HKLM-x32\...\{1A15507A-8551-4626-915D-3D5FA095CC1B}) (Version: 10.0 - Corel Inc)
Corel PaintShop Photo Pro X3 (x32 Version: 1.00.0000 - Corel Corporation) Hidden
CyberLink LabelPrint (HKLM-x32\...\InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}) (Version: 2.5.4.6515 - CyberLink Corp.)
CyberLink Media Suite 10 (HKLM-x32\...\InstallShield_{1FBF6C24-C1fD-4101-A42B-0C564F9E8E79}) (Version: 10.0.4.2928 - CyberLink Corp.)
Cyberlink PhotoDirector (HKLM-x32\...\InstallShield_{39337565-330E-4ab6-A9AE-AC81E0720B10}) (Version: 3.0.2.4128 - CyberLink Corp.)
CyberLink Power2Go 8 (HKLM-x32\...\InstallShield_{2A87D48D-3FDF-41fd-97CD-A1E370EFFFE2}) (Version: 8.0.4.3202 - CyberLink Corp.)
CyberLink PowerDirector 10 (HKLM-x32\...\InstallShield_{B0B4F6D2-F2AE-451A-9496-6F2F6A897B32}) (Version: 10.0.4.3122 - CyberLink Corp.)
CyberLink PowerDVD 12 (HKLM-x32\...\InstallShield_{B46BEA36-0B71-4A4E-AE41-87241643FA0A}) (Version: 12.0.1.3212 - CyberLink Corp.)
CyberLink YouCam (HKLM-x32\...\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 5.0.1.3201 - CyberLink Corp.)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Energy Star (HKLM-x32\...\{FC0ADA4D-8FA5-4452-8AFF-F0A0BAC97EF7}) (Version: 1.0.9 - Hewlett-Packard Company)
Fotogalerie (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Galerie de photos (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Google Earth (HKLM-x32\...\{4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google)
Hewlett-Packard ACLM.NET v1.2.2.3 (x32 Version: 1.00.0000 - Hewlett-Packard Company) Hidden
HP 3D DriveGuard (HKLM-x32\...\{07F6DC37-0857-4B68-A675-4E35989E85E3}) (Version: 6.0.15.1 - Hewlett-Packard Company)
HP Connected Music (Meridian - installer) (HKLM-x32\...\StartHPConnectedMusic) (Version: 1.0 - Meridian Audio Ltd)
HP Connected Music (Meridian - player) (HKU\S-1-5-21-2370912473-469425822-2799426420-1002\...\HPConnectedMusic) (Version: 1.1 (build 112) hp - Meridian Audio Ltd)
HP CoolSense (HKLM-x32\...\{59F8C5AA-91BD-423D-BF05-09A80F39898F}) (Version: 2.10.62 - Hewlett-Packard Company)
HP Documentation (HKLM-x32\...\{F5120027-B9BF-4A48-86E9-63F7F79A5263}) (Version: 1.1.0.0 - Hewlett-Packard)
HP Registration Service (HKLM\...\{D1E8F2D7-7794-4245-B286-87ED86C1893C}) (Version: 1.2.7045.4591 - Hewlett-Packard)
HP SimplePass (HKLM-x32\...\InstallShield_{314FAD12-F785-4471-BCE8-AB506642B9A1}) (Version: 8.00.49 - Hewlett-Packard)
HP System Event Utility (HKLM-x32\...\{23EF407B-E7D0-4CB6-8916-43E5B9EEFDED}) (Version: 1.0.9 - Hewlett-Packard Company)
HP Utility Center (HKLM\...\{AED1C141-3AFC-47FE-AE90-C820AA60B103}) (Version: 2.2.5 - Hewlett-Packard Company)
HP Wireless Button Driver (HKLM-x32\...\{30B2D1D8-0A07-4B71-9553-0710C5D31E35}) (Version: 1.1.2.1 - Hewlett-Packard Company)
ICA (x32 Version: 1.6.1.242 - Corel Corporation) Hidden
iCloud (HKLM\...\{0493048C-CB1A-44B7-8BB3-8467AF7BA9E4}) (Version: 6.1.2.13 - Apple Inc.)
Image Resizer for Windows (64 bit) (Version: 3.0.4802.35565 - Brice Lambson) Hidden
Image Resizer for Windows (HKLM-x32\...\{69d72156-6582-4556-8637-06f40aa7f85b}) (Version: 3.0.4802.35565 - Brice Lambson)
Inst5675 (Version: 8.00.49 - Softex Inc.) Hidden
Inst5676 (Version: 8.00.49 - Softex Inc.) Hidden
IPM_PSP_CL (x32 Version: 1.00.0000 - Your Company Name) Hidden
IPM_PSP_COM (x32 Version: 1.00.0000 - Your Company Name) Hidden
iTunes (HKLM\...\{554C62C7-E6BB-40F1-892B-F0AE02D3C135}) (Version: 12.5.3.17 - Apple Inc.)
Jasc Animation Shop 3 (HKLM-x32\...\{7C4196CA-CA41-4F34-9C08-7724E7705D52}) (Version: 3.11 - Jasc Software Inc)
Java 8 Update 121 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180121F0}) (Version: 8.0.1210.13 - Oracle Corporation)
McAfee Security Scan Plus (HKLM\...\McAfee Security Scan) (Version: 3.11.474.2 - McAfee, Inc.)
Microsoft Games for Windows 8 x64 (HKLM\...\{B6047A78-062F-4C6F-A82D-B94DAF72FB73}) (Version: 1.2 - Microsoft)
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft)
Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office Professional Plus 2007 (HKLM-x32\...\PROPLUS) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50901.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 (HKLM\...\{350AA351-21FA-3270-8B7A-835434E766AD}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\...\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\...\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Works 6-9 Converter (HKLM-x32\...\{95140000-0137-0413-0000-0000000FF1CE}) (Version: 14.0.6120.5002 - Microsoft Corporation)
Movie Maker (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Mozilla Firefox 51.0.1 (x86 nl) (HKLM-x32\...\Mozilla Firefox 51.0.1 (x86 nl)) (Version: 51.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 51.0.1.6234 - Mozilla)
MYDIGIPASS Card Reader Plug-In (64-Bit) (Version: 3.2.3.6 - VASCO Data Security) Hidden
MYDIGIPASS Smart Card Reader Plug-In (User) (HKU\S-1-5-21-2370912473-469425822-2799426420-1002\...\{dffbad8e-f7e1-4339-9c64-0f0803d32b83}) (Version: 3.2.3.6 - VASCO Data Security)
OEM Application Profile (HKLM-x32\...\{70D5F822-F4C4-33D9-7EEC-2A4AF4EA7BDC}) (Version: 1.00.0000 - Uw bedrijfsnaam)
PSPPContent (x32 Version: 1.00.0000 - Corel Corporation) Hidden
PSPPRO_DCRAW (x32 Version: 13.0.0 - Corel Corporation) Hidden
QuickTime (HKLM-x32\...\{8DC42D05-680B-41B0-8878-6C14D24602DB}) (Version: 7.55.90.70 - Apple Inc.)
Ralink Bluetooth Stack64 (HKLM\...\{8A2E2A41-B814-407E-2F96-4E433C42AB78}) (Version: 11.0.739.0 - Mediatek)
Ralink RT3290 802.11bgn Wi-Fi Adapter (HKLM-x32\...\{8FC4F1DD-F7FD-4766-804D-3C8FF1D309AF}) (Version: 5.0.29.8105 - Mediatek)
Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 6.2.9200.29068 - Realtek Semiconductor Corp.)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.20.815.2013 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7004 - Realtek Semiconductor Corp.)
Setup (x32 Version: 1.6.1.242 - Corel Corporation) Hidden
Skype™ 7.31 (HKLM-x32\...\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.31.104 - Skype Technologies S.A.)
Spy Cleaner Gold 9.5 Full Version (HKLM-x32\...\Spy Cleaner Gold 9.5 Full Version) (Version: - Topdownloads Networks)
Stuurprogrammapakket voor Windows - Fedict SmartCard (08/08/2015 4.1.5) (HKLM\...\9F46F7AB1E3B1B5F5482EA8D97F401B04FBF7958) (Version: 08/08/2015 4.1.5 - Fedict)
swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 19.2.4.10 - Synaptics Incorporated)
Ultimate Mahjongg 15 (HKLM-x32\...\Ultimate Mahjongg 15) (Version: 15.0 - ValuSoft, Inc.)
Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft)
Update voor Microsoft Office Excel 2007 Help (KB963678) (HKLM-x32\...\{90120000-0016-0413-0000-0000000FF1CE}_PROPLUS_{5CF7002F-6F49-4482-9564-5614FBE560FA}) (Version: - Microsoft)
Update voor Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM-x32\...\{90120000-0018-0413-0000-0000000FF1CE}_PROPLUS_{15D84E79-1ED7-42C5-B2FD-745C3FBDDDC5}) (Version: - Microsoft)
Update voor Microsoft Office Word 2007 Help (KB963665) (HKLM-x32\...\{90120000-001B-0413-0000-0000000FF1CE}_PROPLUS_{A66AE6A1-8D8C-4102-BC18-38CBDE40F809}) (Version: - Microsoft)
VASCO Card Reader Plug-In (64-Bit) (Version: 3.2.3.4 - VASCO Data Security) Hidden
VASCO Smart Card Reader Plug-In (User) (HKU\S-1-5-21-2370912473-469425822-2799426420-1002\...\{c77cb28d-ddd3-46f7-b51a-14a599127ba7}) (Version: 3.2.3.4 - VASCO Data Security)
Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
Visual Studio 2012 x86 Redistributables (HKLM-x32\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.4 - VideoLAN)
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3508.0205 - Microsoft Corporation)
WinSnare (HKLM-x32\...\{C881D603-277F-4056-918D-654844EF2B37}) (Version: 4.1.6 - WinSnare) <==== AANDACHT

==================== Aangepaste CLSID (gefilterd): ==========================

(Als een item is opgenomen in de fixlist, wordt uit het register verwijderd. Het bestand zal niet worden verplaatst tenzij apart vermeld.)

HKU\S-1-5-21-2370912473-469425822-2799426420-1002\...\ChromeHTML: -> C:\Program Files (x86)\Mapbob\Application\chrome.exe (Google Inc.) <==== AANDACHT
CustomCLSID: HKU\S-1-5-21-2370912473-469425822-2799426420-1002_Classes\CLSID\{1BF42E4C-4AF4-4CFD-A1A0-CF2960B8F63E}\InprocServer32 -> C:\Users\Rita\AppData\Local\Microsoft\OneDrive\17.3.6798.0207\amd64\FileSyncShell64.dll => Geen best (de data item heeft 3 mee tekens).
CustomCLSID: HKU\S-1-5-21-2370912473-469425822-2799426420-1002_Classes\CLSID\{32DA5519-330F-58A4-85D4-D58B97CA7EF9}\InprocServer32 -> C:\Users\Rita\AppData\Roaming\VASCO\MDPCardReaderPlugin\3.2.3.6\npMDPCardReaderPlugin64.dll (VASCO Data Security)
CustomCLSID: HKU\S-1-5-21-2370912473-469425822-2799426420-1002_Classes\CLSID\{7AFDFDDB-F914-11E4-8377-6C3BE50D980C}\InprocServer32 -> C:\Users\Rita\AppData\Local\Microsoft\OneDrive\17.3.6798.0207\amd64\FileSyncShell64.dll => Geen best (de data item heeft 3 mee tekens).
CustomCLSID: HKU\S-1-5-21-2370912473-469425822-2799426420-1002_Classes\CLSID\{82CA8DE3-01AD-4CEA-9D75-BE4C51810A9E}\InprocServer32 -> C:\Users\Rita\AppData\Local\Microsoft\OneDrive\17.3.6798.0207\amd64\FileSyncShell64.dll => Geen best (de data item heeft 3 mee tekens).
CustomCLSID: HKU\S-1-5-21-2370912473-469425822-2799426420-1002_Classes\CLSID\{9E436272-69C3-5FBA-9C1D-15694337F4AC}\InprocServer32 -> C:\Users\Rita\AppData\Roaming\VASCO\VascoCardReaderPlugin\3.2.3.4\npVascoCardReaderPlugin64.dll (VASCO Data Security)

==================== Geplande Taken (gefilterd) =============

(Als een item is opgenomen in de fixlist, wordt uit het register verwijderd. Het bestand zal niet worden verplaatst tenzij apart vermeld.)

Task: {01CB5FCE-3F38-41DD-A429-021B3F56B2F4} - System32\Tasks\Microsoft\Windows\Multimedia\Manager => C:\Users\Rita\AppData\Roaming\Adobe\Manager.exe
Task: {03526C99-3349-4342-B3DF-AEFFF442C319} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> Geen bestand <==== AANDACHT
Task: {03F96509-2417-4F67-A882-902FFC1C1765} - System32\Tasks\Milimili => C:\Program Files (x86)\MIO\MIO.exe [2016-12-28] ()
Task: {062BC3FF-F516-4E49-9D33-FCDCC6252C74} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: {0E75CA79-DB69-41BC-8445-3985CFA07DC1} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2016-12-19] (Adobe Systems Incorporated)
Task: {106522E5-EDCE-4114-A448-9F2478D92023} - System32\Tasks\Driver Booster SkipUAC (Rita) => C:\Program Files (x86)\IObit\Driver Booster\4.1.0\DriverBooster.exe
Task: {1083B94B-A02A-46A5-970E-F99837D421E2} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> Geen bestand <==== AANDACHT
Task: {114068E4-0381-410A-A43F-A8834FF30654} - System32\Tasks\{EEFF7C6B-EC68-48EB-887B-6FFBED543F17} => launchwinapp.exe hxxp://www.skype.com/go/downloading?source=lig ... tError=404
Task: {2241621C-050F-4AD6-8814-BB4C061740C7} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2017-01-11] (Microsoft Corporation)
Task: {28096E47-B52C-42C5-8A61-F85C12913536} - \globalUpdateUpdateTaskMachineUA1cffdf5c420f8f5 -> Geen bestand <==== AANDACHT
Task: {28F0F7D1-EDF3-4F39-ACDF-26C722B40DC1} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: {2FD81ED9-F0E7-4DC6-B7F2-6096B8BE6278} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2017-02-17] (Adobe Systems Incorporated)
Task: {3014E785-AC78-4C3E-A41B-7899280DCA83} - \Super Optimizer Schedule -> Geen bestand <==== AANDACHT
Task: {33AD713F-8F54-4C0C-9A4F-A00F4DF10E00} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2016-02-23] (Apple Inc.)
Task: {352E6CA0-7314-4DF4-89C4-682368D80D57} - System32\Tasks\Microsoft\Windows\Workplace Join\Automatic-Workplace-Join => %SystemRoot%\System32\AutoWorkplace.exe
Task: {39276186-E80B-457B-AF92-864E28C87DAE} - System32\Tasks\WinTOOL => C:\ProgramData\wintools\WintoolUprI.exe [2017-01-18] ()
Task: {3F2FEEA1-7F02-4F0B-9D9D-D7939400EA5A} - System32\Tasks\{6FE9B310-0CE2-4C7A-8B77-B2A6498B0700} => pcalua.exe -a "C:\Program Files (x86)\Linkey\uninstall.exe"
Task: {41537B8D-4567-48C6-9936-5FE174FFE0BC} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> Geen bestand <==== AANDACHT
Task: {458DB6B1-33B3-4338-B1C7-672407A405C7} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> Geen bestand <==== AANDACHT
Task: {4A4A53D2-3BBD-4D1E-8E7C-A8444F89D393} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> Geen bestand <==== AANDACHT
Task: {4B1AACB4-6418-4760-8438-7882E2D068BE} - \globalUpdateUpdateTaskMachineCore1cffdf5c112f5ab -> Geen bestand <==== AANDACHT
Task: {4C0F23CB-E397-4CE9-AD31-5DB89D5D807E} - \Winsta Update -> Geen bestand <==== AANDACHT
Task: {5A57B9D7-782B-4527-B5C5-C9A04FA56E5B} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\Program Files\Windows Defender\\MpCmdRun.exe [2016-07-16] (Microsoft Corporation)
Task: {6899014E-CA68-4A6F-A666-467CDE279DB3} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\Program Files\Windows Defender\\MpCmdRun.exe [2016-07-16] (Microsoft Corporation)
Task: {691B09AB-282A-4FB9-B4C1-868B147681CA} - System32\Tasks\CLVDLauncher => C:\Program Files (x86)\CyberLink\Power2Go8\CLVDLauncher.exe [2013-03-12] (CyberLink Corp.)
Task: {6BBD8582-61DE-4342-8057-C5C1B2CDDEC6} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\Program Files\Windows Defender\\MpCmdRun.exe [2016-07-16] (Microsoft Corporation)
Task: {7145D40F-2436-4E75-8C18-1E207FE177E2} - \CCleanerSkipUAC -> Geen bestand <==== AANDACHT
Task: {7369E587-F550-47EB-AB33-91C2306C5602} - System32\Tasks\ZRHPV => C:\Users\Rita\AppData\Roaming\ZRHPV.exe <==== AANDACHT
Task: {75AC10D5-0669-4607-8F81-5BF046FD355E} - System32\Tasks\{0A980255-710E-41CD-8095-32DD0395EABF} => pcalua.exe -a C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_17_0_0_190_Plugin.exe -c -maintain plugin
Task: {7947E20D-FAC4-4E1A-A134-A9B1A64DADCD} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2013-08-29] (Hewlett-Packard Company)
Task: {7BFC02F4-9B90-493B-AC56-71421B39F84E} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> Geen bestand <==== AANDACHT
Task: {7E20600D-2749-4E84-9A46-D375B7D81FBE} - System32\Tasks\CreateChoiceProcessTask => C:\Windows\BrowserChoice\browserchoice.exe
Task: {877F2F0E-8972-4C7A-B9DD-AE24FF9C01E6} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> Geen bestand <==== AANDACHT
Task: {8A339CF0-0682-4B7B-9A9B-CA08BD513BE2} - System32\Tasks\{333C6AAA-9F58-4052-86B9-DCDD45E49298} => pcalua.exe -a "c:\Program Files (x86)\Corel\Corel PaintShop Photo Pro\X3\Setup\{DEAEB5DB-04FA-489D-94EF-8600898B93EE}\SetupARP.exe" -c /arp
Task: {8CFA4A49-191C-442A-AEB0-65B1FB8874CB} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [2014-08-04] (Hewlett-Packard)
Task: {951D9930-592C-41A4-9939-95C5246F6F88} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Update Check => C:\ProgramData\Hewlett-Packard\HP Support Framework\Resources\Updater7\HPSFUpdater.exe [2012-11-29] (Hewlett-Packard Company)
Task: {B6616827-4055-4908-99EC-B9848D7F2222} - \Tempo Runner osizdvoo -> Geen bestand <==== AANDACHT
Task: {BCA31B11-C400-472F-A138-D3BB036401C7} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> Geen bestand <==== AANDACHT
Task: {BD2C1E53-7248-4A59-AED7-94C4BB5AA297} - System32\Tasks\Ananoward Server => C:\Program Files (x86)\Ocecult\fafiied.exe
Task: {BFD50D19-B0C7-4254-863C-76DFEB8F50B6} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> Geen bestand <==== AANDACHT
Task: {C2ED3488-4F65-4EF8-AD68-8A5DD104044D} - System32\Tasks\zTt => C:\ProgramData\Convertor\Convertor.exe <==== AANDACHT
Task: {C7514129-5B16-42B2-BB83-D3AD0F7C6CF5} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> Geen bestand <==== AANDACHT
Task: {CD1BE264-CE5C-446A-A592-7ABD7521C974} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\Program Files\Windows Defender\\MpCmdRun.exe [2016-07-16] (Microsoft Corporation)
Task: {D316CF50-92B6-4722-9441-7188A0A1FBB7} - System32\Tasks\{7AD7F214-FA81-40D2-8A5A-6B3E3088D8FA} => pcalua.exe -a C:\Users\Rita\AppData\Roaming\mystartsearch\UninstallManager.exe -c -ptid=cmi
Task: {DC21DD65-3673-445F-8CDB-60B91E69C071} - System32\Tasks\CLMLSvc_P2G8 => C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe [2013-08-05] (CyberLink)
Task: {E049875B-58C3-44D5-848F-D0A5374017C5} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> Geen bestand <==== AANDACHT
Task: {E3EFF77B-7AC3-4248-B302-B246302240D1} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_DeviceScan => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [2014-08-04] (Hewlett-Packard)
Task: {EF6B3364-6C46-48E2-B66E-0E54C30EA344} - System32\Tasks\{5777954B-8B4F-45A4-83BB-2F7B590AE52C} => pcalua.exe -a C:\Users\Rita\AppData\Local\PriceMeter\uninst.exe -c /uninstall
Task: {F813AB52-E070-4C8D-A0A2-2A7824ED6A0D} - System32\Tasks\CNPMUIBY => C:\Users\Rita\AppData\Roaming\CNPMUIBY.exe <==== AANDACHT
Task: {F97A1C67-B5A7-4C95-B393-EC00D0A4C64F} - System32\Tasks\Hewlett-Packard\HP CoolSense\HP CoolSense Start at Logon => C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe [2013-06-07] (Hewlett-Packard Development Company, L.P.)

(Als een item is opgenomen in de fixlist, de taak (job) bestand wordt verplaatst. Het bestand dat wordt uitgevoerd door de taak zal niet worden verplaatst.)

Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\CNPMUIBY.job => C:\Users\Rita\AppData\Roaming\CNPMUIBY.exe <==== AANDACHT
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\Synaptics TouchPad Enhancements.job => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
Task: C:\WINDOWS\Tasks\ZRHPV.job => C:\Users\Rita\AppData\Roaming\ZRHPV.exe <==== AANDACHT

==================== Snelkoppelingen =============================

(De items kunnen worden opgenomen in de fixlist.txt om hersteld of verwijderd te worden.)

ShortcutWithArgument: C:\Users\Rita\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk -> C:\Program Files (x86)\Firefox\Firefox.exe (Mozilla Corporation) -> hxxp://www.amisites.com/?type=sc&ts=1486373569 ... 2_W3P2FY58
ShortcutWithArgument: C:\Users\Rita\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://www.amisites.com/?type=sc&ts=1486373569 ... 2_W3P2FY58
ShortcutWithArgument: C:\Users\Rita\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.amisites.com/?type=sc&ts=1486373569 ... 2_W3P2FY58
ShortcutWithArgument: C:\Users\Rita\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.amisites.com/?type=sc&ts=1486373569 ... 2_W3P2FY58
ShortcutWithArgument: C:\Users\Rita\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Sparta.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://www.amisites.com/?type=sc&ts=1486373569 ... 2_W3P2FY58
ShortcutWithArgument: C:\Users\Rita\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk -> C:\Program Files (x86)\Firefox\Firefox.exe (Mozilla Corporation) -> hxxp://www.amisites.com/?type=sc&ts=1486373569 ... 2_W3P2FY58
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk -> C:\Program Files (x86)\Mapbob\Application\chrome.exe (Google Inc.) -> hxxp://www.amisites.com/?type=sc&ts=1486373569 ... 2_W3P2FY58
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk -> C:\Program Files (x86)\Firefox\Firefox.exe (Mozilla Corporation) -> hxxp://www.amisites.com/?type=sc&ts=1486373569 ... 2_W3P2FY58
ShortcutWithArgument: C:\Users\Public\Desktop\Mozilla Firefox.lnk -> C:\Program Files (x86)\Firefox\Firefox.exe (Mozilla Corporation) -> hxxp://www.amisites.com/?type=sc&ts=1486373569 ... 2_W3P2FY58

==================== Geladen Modules (gefilterd) ==============

2016-07-16 12:42 - 2016-07-16 12:42 - 00231424 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll
2016-12-14 20:21 - 2016-12-09 11:29 - 02681200 _____ () C:\WINDOWS\system32\CoreUIComponents.dll
2016-06-08 20:09 - 2016-06-18 08:56 - 00972872 ____N () C:\Program Files (x86)\AVG Web TuneUp\WtuSystemSupport.exe
2013-08-23 00:08 - 2013-08-23 00:08 - 00109568 _____ () C:\Program Files\Hewlett-Packard\SimplePass\cachesrvr.exe
2013-08-23 00:13 - 2013-08-23 00:13 - 00627200 _____ () C:\Program Files\Hewlett-Packard\SimplePass\cachedrv.dll
2013-08-23 00:09 - 2013-08-23 00:09 - 02508800 _____ () C:\Program Files\Hewlett-Packard\SimplePass\autheng.dll
2013-08-23 00:07 - 2013-08-23 00:07 - 00035328 _____ () C:\Program Files\Hewlett-Packard\SimplePass\ssplogon.dll
2013-08-23 00:07 - 2013-08-23 00:07 - 00055296 _____ () C:\Program Files\Hewlett-Packard\SimplePass\RandomPass.dll
2016-09-01 17:12 - 2016-09-01 17:12 - 00092472 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2017-01-13 13:56 - 2017-01-13 13:56 - 01353528 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2016-12-14 20:21 - 2016-12-09 11:29 - 02681200 _____ () C:\WINDOWS\SYSTEM32\CoreUIComponents.dll
2016-09-25 10:16 - 2016-09-25 10:16 - 00134656 _____ () C:\Windows\ShellExperiences\Windows.UI.Shell.SharedUtilities.dll
2017-02-11 11:14 - 2016-12-21 08:09 - 00474112 _____ () C:\Windows\ShellExperiences\QuickActions.dll
2017-02-11 11:12 - 2016-12-21 07:54 - 09760768 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2017-02-11 11:13 - 2016-12-21 07:48 - 01401856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2017-02-11 11:13 - 2016-12-21 07:48 - 00757248 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CSGSuggestLib.dll
2017-02-11 11:13 - 2016-12-21 07:48 - 02424320 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
2017-02-11 11:13 - 2016-12-21 07:53 - 04853760 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
2013-08-23 00:12 - 2013-08-23 00:12 - 00064000 _____ () C:\Program Files\Hewlett-Packard\SimplePass\opvapp.exe
2017-02-05 08:33 - 2017-02-03 05:52 - 00160432 _____ () C:\Program Files (x86)\Firefox\bin\FirefoxUpdate.exe
2017-02-22 12:03 - 2017-02-22 12:04 - 00073728 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.11.110.0_x64__kzf8qxf38zg5c\SkypeHost.exe
2017-02-22 12:03 - 2017-02-22 12:04 - 00179712 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.11.110.0_x64__kzf8qxf38zg5c\SkypeBackgroundTasks.dll
2017-02-22 12:03 - 2017-02-22 12:04 - 42895360 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.11.110.0_x64__kzf8qxf38zg5c\SkyWrap.dll
2017-02-06 08:37 - 2017-02-06 08:38 - 02215424 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.11.110.0_x64__kzf8qxf38zg5c\roottools.dll
2017-02-24 12:31 - 2017-02-22 03:29 - 00112640 _____ () C:\WINDOWS\TEMP\rew994D.tmp\firstu71\Testc.exe
2017-02-13 13:04 - 2017-02-13 04:31 - 00459264 _____ () C:\Program Files (x86)\Common Files\Services\iThemes.dll
2017-02-03 15:05 - 2017-02-10 15:18 - 00760320 _____ () c:\program files (x86)\winarcher\archer.dll
2017-01-10 22:11 - 2017-02-10 03:57 - 00109568 _____ () c:\program files (x86)\winarcher\Packet.dll
2017-02-14 14:37 - 2017-02-14 19:16 - 00122880 _____ () c:\program files (x86)\bilibili\bilibili.dll
2017-02-03 15:05 - 2017-02-04 04:06 - 00118272 _____ () c:\program files (x86)\gubed\gubedzl.dll
2017-02-06 10:19 - 2017-02-09 17:52 - 00122880 _____ () c:\program files (x86)\gub\gubzl.dll
2017-02-05 08:34 - 2017-02-04 06:20 - 00486912 _____ () c:\programdata\microsoft\office\office_update.dll
2013-12-12 14:34 - 2013-08-05 08:49 - 00627672 _____ () C:\Program Files (x86)\CyberLink\Power2Go8\CLMediaLibrary.dll
2013-08-05 15:48 - 2013-08-05 15:48 - 00016856 _____ () C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvcPS.dll
2017-01-13 13:56 - 2017-01-13 13:56 - 01041720 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2017-01-13 13:56 - 2017-01-13 13:56 - 00189752 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxslt.dll
2016-09-01 17:13 - 2016-09-01 17:13 - 00080184 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll

==================== Alternate Data Streams (gefilterd) =========

(Als een item is opgenomen in de fixlist, alleen de ADS wordt verwijderd.)


==================== Veilige Modus (gefilterd) ===================

(Als een item is opgenomen in de fixlist, wordt uit het register verwijderd. De "AlternateShell" waarde wordt hersteld.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"

==================== Bestandskoppeling (gefilterd) ===============

(Als een item is opgenomen in de fixlist, het registry item zal worden teruggezet naar de standaardwaarden of verwijderd.)


==================== Internet Explorer vertrouwde/beperkte toegang ===============

(Als een item is opgenomen in de fixlist, wordt uit het register verwijderd.)

IE trusted site: HKU\.DEFAULT\...\amazon.com -> hxxps://amazon.com
IE trusted site: HKU\S-1-5-21-2370912473-469425822-2799426420-1002\...\amazon.com -> hxxps://amazon.com
IE trusted site: HKU\S-1-5-21-2370912473-469425822-2799426420-1002\...\localhost -> localhost
IE trusted site: HKU\S-1-5-21-2370912473-469425822-2799426420-1002\...\webcompanion.com -> hxxp://webcompanion.com

==================== Hosts inhoud: ===============================

(Als nodig Hosts: opdracht kan worden opgenomen in de fixlist om Hosts te resetten.)

2013-08-22 14:25 - 2017-01-15 12:10 - 00000857 ____N C:\WINDOWS\system32\Drivers\etc\hosts


0.0.0.1 mssplus.mcafee.com

==================== Andere gebieden ============================

(Momenteel is er geen automatische fix voor dit onderdeel.)

HKU\S-1-5-21-2370912473-469425822-2799426420-1002\Control Panel\Desktop\\Wallpaper -> C:\Users\Rita\Pictures\FAMILIE DEBEUF_VOSSAERT\14-09-03 Nieuwpoort\5 corry.jpg
DNS Servers: 195.130.130.5 - 195.130.131.5
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 0) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is ingeschakeld.

==================== MSCONFIG/TASK MANAGER Uitgeschakelde items ==

HKLM\...\StartupApproved\Run: => "RTHDVCPL"
HKLM\...\StartupApproved\Run: => "SimplePass"
HKLM\...\StartupApproved\Run: => "OPBHOBroker"
HKLM\...\StartupApproved\Run: => "OPBHOBrokerDesktop"
HKLM\...\StartupApproved\Run: => "SynTPEnh"
HKLM\...\StartupApproved\Run: => "StartCCC"
HKLM\...\StartupApproved\Run32: => "StartCCC"
HKLM\...\StartupApproved\Run32: => "YouCam Service"
HKLM\...\StartupApproved\Run32: => "HPMessageService"
HKLM\...\StartupApproved\Run32: => "Adobe ARM"
HKLM\...\StartupApproved\Run32: => "SynTPEnh"
HKLM\...\StartupApproved\Run32: => "QuickTime Task"
HKU\S-1-5-21-2370912473-469425822-2799426420-1002\...\StartupApproved\StartupFolder: => "Download App.lnk"
HKU\S-1-5-21-2370912473-469425822-2799426420-1002\...\StartupApproved\StartupFolder: => "legend-of-the-seeker-prophecy-dut-3435066.lnk"
HKU\S-1-5-21-2370912473-469425822-2799426420-1002\...\StartupApproved\Run: => "BrowserChoice"
HKU\S-1-5-21-2370912473-469425822-2799426420-1002\...\StartupApproved\Run: => "Corel Photo Downloader"
HKU\S-1-5-21-2370912473-469425822-2799426420-1002\...\StartupApproved\Run: => "OneDrive"

==================== Firewall regels (gefilterd) ===============

(Als een item is opgenomen in de fixlist, wordt uit het register verwijderd. Het bestand zal niet worden verplaatst tenzij apart vermeld.)

FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [{D8154FDA-B514-4D08-91AD-4D7AFE2D4B54}] => (Block) C:\users\rita\appdata\local\popcorn-time\nw.exe
FirewallRules: [{0D3454EE-82D7-4816-8F15-90CF1CC2E85D}] => (Block) C:\users\rita\appdata\local\popcorn-time\nw.exe
FirewallRules: [UDP Query User{981C9D39-0223-481D-9AEF-FA2C80785DE7}C:\users\rita\appdata\local\popcorn-time\nw.exe] => (Allow) C:\users\rita\appdata\local\popcorn-time\nw.exe
FirewallRules: [TCP Query User{3040EFF6-6E9D-4DF6-913A-DCFF00BDEFB8}C:\users\rita\appdata\local\popcorn-time\nw.exe] => (Allow) C:\users\rita\appdata\local\popcorn-time\nw.exe
FirewallRules: [{C195A728-EBB4-4CA1-BD11-F137D44B9F41}] => (Allow) C:\Program Files (x86)\AVG\Av\avgmfapx.exe
FirewallRules: [{6B2DB299-813E-492E-B60D-2F61FDD225AC}] => (Allow) C:\Program Files (x86)\AVG\Av\avgmfapx.exe
FirewallRules: [UDP Query User{42B1FFFB-356F-4694-82B2-B36DD4B0BE4B}C:\users\rita\appdata\local\popcorn time ce yify\nw.exe] => (Allow) C:\users\rita\appdata\local\popcorn time ce yify\nw.exe
FirewallRules: [TCP Query User{BD84E35D-05B7-42D8-AA83-FA373593CD0E}C:\users\rita\appdata\local\popcorn time ce yify\nw.exe] => (Allow) C:\users\rita\appdata\local\popcorn time ce yify\nw.exe
FirewallRules: [{808F8183-5944-4DDF-82EB-44B6BB5F535D}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{12F02FF9-4974-4C08-9EAC-43CA7F82B071}] => (Allow) LPort=2869
FirewallRules: [{50914653-547A-4CE5-A9A0-EB6E111F7836}] => (Allow) LPort=1900
FirewallRules: [{C9A345F5-E18E-47A6-8ACC-FBDF4DB36476}] => (Allow) C:\Program Files (x86)\HPConnectedMusic\HPConnectedMusic.exe
FirewallRules: [{A8DB175A-8E5C-41C4-990B-4CE92FB2A2C6}] => (Allow) C:\Program Files (x86)\HPConnectedMusic\HPConnectedMusic.exe
FirewallRules: [{459C0248-9B57-4D15-9DF0-031DC9393ACB}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{786D4CAD-B811-4237-8898-C1A3E35A5279}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{3361CD1B-572C-4539-AC8C-EEEE5AADB340}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{860F4E19-5C8E-4E07-9EE2-38907BA159E8}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{A40EA73F-92B5-43B0-BD73-89810543BEF4}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12.exe
FirewallRules: [{5DE672FC-CD94-457E-AA1A-F22F7DFEE334}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe
FirewallRules: [{EC586DB5-72CF-4EA3-BBEC-21560D4FE358}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12ML.exe
FirewallRules: [{06BCCB9F-8654-4003-A455-EDDAD9FD1CA6}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\Movie\PowerDVD.exe
FirewallRules: [{21A27B46-F7D3-4505-8962-8CE667C1E4CE}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDirector10\PDR10.EXE
FirewallRules: [{90CC8885-E47B-4203-BD16-E6C17D82DEFA}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{8D5DE789-813F-4A7C-ACD9-54F48B88AB18}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [TCP Query User{53168752-D04F-4FCF-AC8C-55826CD91545}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [UDP Query User{3C4C8356-6A4E-4459-988B-BC8F8041C363}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [{331E6220-E5D5-4F46-A9C3-3B65763A4688}] => (Allow) C:\Program Files (x86)\Popcorn Time\Updater.exe
FirewallRules: [{286222D5-FD2D-459D-843F-7A9135954934}] => (Allow) C:\Program Files (x86)\Popcorn Time\Updater.exe
FirewallRules: [{79100A6F-E542-4EC9-80D3-4ED1A960C701}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{C0EF9725-2DF3-4797-A8A3-8310A620A2D2}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{75E6C6BE-3C7F-40C3-8F1B-6B29CCA82052}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{D85511EE-4C33-4D24-94D4-AC42E8B78858}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{6E10CC49-B46F-4EBF-86D3-A2855833EBEA}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{BFEA8DC1-CDD1-4A60-BCE4-D4C03EA48716}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{49C68195-5670-4594-AE1D-76B794D924E6}] => (Allow) C:\Users\Rita\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{88074D0F-8063-40CD-A37E-40ADC0EC1F88}] => (Allow) C:\Users\Rita\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{3ADD356D-50F5-4B5B-B0EA-E7D7AB8C18FC}] => (Allow) C:\Users\Rita\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{F67FF069-6DF8-4ACB-8A6B-699ABA035BA8}] => (Allow) C:\Users\Rita\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{6B3DE786-F17E-43BC-B210-B50D882860D6}] => (Allow) C:\Users\Rita\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{C36BFDAE-28AA-4A29-BCDB-44AFFD924F35}] => (Allow) C:\Users\Rita\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{031568F6-7BCD-4957-86BA-4F314474313E}] => (Allow) C:\Program Files\iTunes\iTunes.exe
FirewallRules: [{D4134D47-7479-449C-9D02-AF7D843495B6}] => (Allow) C:\WINDOWS\system32\rundll32.exe
FirewallRules: [{80371D04-BE89-4130-B4F2-EFE915D7C688}] => (Allow) C:\Windows\System32\rundll32.exe
FirewallRules: [{40CD9D43-CE12-412B-B214-9FF92CEBC9AA}] => (Allow) C:\Windows\System32\rundll32.exe
FirewallRules: [{2D6FEA83-1737-4E16-90A2-50440BFAF243}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{E3EE5E20-631E-45AB-AF8E-6EDE0C73594A}] => (Allow) C:\Program Files (x86)\Firefox\bin\FirefoxUpdate.exe
FirewallRules: [{66F3B3C0-1AAE-4ED8-A79F-7BE8F4A048EF}] => (Allow) C:\Program Files (x86)\Firefox\Firefox.exe
FirewallRules: [{19A9B286-B9C3-40D1-94C9-ACD15BB459BC}] => (Allow) C:\Program Files (x86)\Mapbob\Application\chrome.exe
FirewallRules: [{B2C9E244-2811-4E73-AFE1-3DA94164966F}] => (Allow) C:\Program Files (x86)\MIO\loader\st500lt012-1dg142_w3p2fy58.exe
FirewallRules: [{519A9BD3-C66C-44AD-99EE-8434C32C6EE4}] => (Allow) C:\Program Files (x86)\MIO\loader\st500lt012-1dg142_w3p2fy58.exe
FirewallRules: [{EB2F1E7B-3F81-4C2D-B629-D20632D6D72B}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPDeviceDetection3.exe

==================== Herstelpunten =========================

14-02-2017 19:24:17 Removed amuleC
20-02-2017 14:44:47 Removed amuleC
22-02-2017 12:49:31 Removed amuleC

==================== Defecte Apparaatbeheer Apparaten =============


==================== Eventlog fouten: =========================

Applicatiefouten:
==================
Error: (02/24/2017 10:25:58 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 1672

Error: (02/24/2017 10:25:58 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 1672

Error: (02/24/2017 10:25:58 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (02/24/2017 10:15:41 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2484) (User: RVO001)
Description: Het pakket windows.immersivecontrolpanel_6.2.0.0_neutral_neutral_cw5n1h2txyewy+microsoft.windows.immersivecontrolpanel is beëindigd omdat het onderbreken te lang duurde.

Error: (02/24/2017 09:24:40 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2484) (User: RVO001)
Description: Het pakket Microsoft.Windows.ShellExperienceHost_10.0.14393.693_neutral_neutral_cw5n1h2txyewy+App is beëindigd omdat het onderbreken te lang duurde.

Error: (02/24/2017 09:24:17 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2484) (User: RVO001)
Description: Het pakket Microsoft.Windows.ShellExperienceHost_10.0.14393.693_neutral_neutral_cw5n1h2txyewy+App is beëindigd omdat het onderbreken te lang duurde.

Error: (02/24/2017 09:24:15 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2484) (User: RVO001)
Description: Het pakket Microsoft.Windows.Cortana_1.7.0.14393_neutral_neutral_cw5n1h2txyewy+CortanaUI is beëindigd omdat het onderbreken te lang duurde.

Error: (02/24/2017 09:23:53 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2484) (User: RVO001)
Description: Het pakket Microsoft.Windows.ShellExperienceHost_10.0.14393.693_neutral_neutral_cw5n1h2txyewy+App is beëindigd omdat het onderbreken te lang duurde.

Error: (02/24/2017 09:23:41 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2484) (User: RVO001)
Description: Het pakket Microsoft.Windows.Cortana_1.7.0.14393_neutral_neutral_cw5n1h2txyewy+CortanaUI is beëindigd omdat het onderbreken te lang duurde.

Error: (02/24/2017 09:23:29 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2484) (User: RVO001)
Description: Het pakket Microsoft.Windows.ShellExperienceHost_10.0.14393.693_neutral_neutral_cw5n1h2txyewy+App is beëindigd omdat het onderbreken te lang duurde.


Systeemfouten:
=============
Error: (02/24/2017 11:42:18 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: De CyberLink PowerDVD 12 Media Server Service-service is onverwacht beëindigd. Dit is nu 2 keer gebeurd.

Error: (02/24/2017 10:25:56 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: De CyberLink PowerDVD 12 Media Server Service-service is onverwacht beëindigd. Dit is nu 1 keer gebeurd.

Error: (02/24/2017 10:21:27 AM) (Source: DCOM) (EventID: 10016) (User: RVO001)
Description: In de machtigingsinstellingen toepassingsspecifiek wordt de machtiging Activeren niet verleend aan Lokaal voor de COM-servertoepassing met CLSID
{0C0A3666-30C9-11D0-8F20-00805F2CD064}
en APPID
{9209B1A6-964A-11D0-9372-00A0C9034910}
aan de gebruiker RVO001\Rita SID (S-1-5-21-2370912473-469425822-2799426420-1002) met het adres LocalHost (via LRPC) die wordt uitgevoerd in de toepassingscontainer Niet beschikbaar SID (Niet beschikbaar). Deze beveiligingsmachtiging kan worden gewijzigd met het beheerprogramma van Component Services.

Error: (02/24/2017 10:21:27 AM) (Source: DCOM) (EventID: 10016) (User: RVO001)
Description: In de machtigingsinstellingen toepassingsspecifiek wordt de machtiging Activeren niet verleend aan Lokaal voor de COM-servertoepassing met CLSID
{0C0A3666-30C9-11D0-8F20-00805F2CD064}
en APPID
{9209B1A6-964A-11D0-9372-00A0C9034910}
aan de gebruiker RVO001\Rita SID (S-1-5-21-2370912473-469425822-2799426420-1002) met het adres LocalHost (via LRPC) die wordt uitgevoerd in de toepassingscontainer Niet beschikbaar SID (Niet beschikbaar). Deze beveiligingsmachtiging kan worden gewijzigd met het beheerprogramma van Component Services.

Error: (02/24/2017 10:19:35 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: De ed2k idle service-service kan vanwege de volgende fout niet worden gestart:
Het systeem kan het opgegeven bestand niet vinden.

Error: (02/24/2017 10:19:23 AM) (Source: DCOM) (EventID: 10016) (User: RVO001)
Description: In de machtigingsinstellingen toepassingsspecifiek wordt de machtiging Activeren niet verleend aan Lokaal voor de COM-servertoepassing met CLSID
{943B6A75-BB5E-41A7-A6D3-A1A5E892B33B}
en APPID
{9209B1A6-964A-11D0-9372-00A0C9034910}
aan de gebruiker RVO001\Rita SID (S-1-5-21-2370912473-469425822-2799426420-1002) met het adres LocalHost (via LRPC) die wordt uitgevoerd in de toepassingscontainer Niet beschikbaar SID (Niet beschikbaar). Deze beveiligingsmachtiging kan worden gewijzigd met het beheerprogramma van Component Services.

Error: (02/24/2017 10:19:11 AM) (Source: DCOM) (EventID: 10016) (User: RVO001)
Description: In de machtigingsinstellingen toepassingsspecifiek wordt de machtiging Activeren niet verleend aan Lokaal voor de COM-servertoepassing met CLSID
{943B6A75-BB5E-41A7-A6D3-A1A5E892B33B}
en APPID
{9209B1A6-964A-11D0-9372-00A0C9034910}
aan de gebruiker RVO001\Rita SID (S-1-5-21-2370912473-469425822-2799426420-1002) met het adres LocalHost (via LRPC) die wordt uitgevoerd in de toepassingscontainer Niet beschikbaar SID (Niet beschikbaar). Deze beveiligingsmachtiging kan worden gewijzigd met het beheerprogramma van Component Services.

Error: (02/24/2017 10:19:11 AM) (Source: DCOM) (EventID: 10016) (User: RVO001)
Description: In de machtigingsinstellingen toepassingsspecifiek wordt de machtiging Activeren niet verleend aan Lokaal voor de COM-servertoepassing met CLSID
{943B6A75-BB5E-41A7-A6D3-A1A5E892B33B}
en APPID
{9209B1A6-964A-11D0-9372-00A0C9034910}
aan de gebruiker RVO001\Rita SID (S-1-5-21-2370912473-469425822-2799426420-1002) met het adres LocalHost (via LRPC) die wordt uitgevoerd in de toepassingscontainer Niet beschikbaar SID (Niet beschikbaar). Deze beveiligingsmachtiging kan worden gewijzigd met het beheerprogramma van Component Services.

Error: (02/24/2017 10:18:45 AM) (Source: DCOM) (EventID: 10016) (User: RVO001)
Description: In de machtigingsinstellingen toepassingsspecifiek wordt de machtiging Activeren niet verleend aan Lokaal voor de COM-servertoepassing met CLSID
{943B6A75-BB5E-41A7-A6D3-A1A5E892B33B}
en APPID
{9209B1A6-964A-11D0-9372-00A0C9034910}
aan de gebruiker RVO001\Rita SID (S-1-5-21-2370912473-469425822-2799426420-1002) met het adres LocalHost (via LRPC) die wordt uitgevoerd in de toepassingscontainer Niet beschikbaar SID (Niet beschikbaar). Deze beveiligingsmachtiging kan worden gewijzigd met het beheerprogramma van Component Services.

Error: (02/24/2017 10:18:45 AM) (Source: DCOM) (EventID: 10016) (User: RVO001)
Description: In de machtigingsinstellingen toepassingsspecifiek wordt de machtiging Activeren niet verleend aan Lokaal voor de COM-servertoepassing met CLSID
{943B6A75-BB5E-41A7-A6D3-A1A5E892B33B}
en APPID
{9209B1A6-964A-11D0-9372-00A0C9034910}
aan de gebruiker RVO001\Rita SID (S-1-5-21-2370912473-469425822-2799426420-1002) met het adres LocalHost (via LRPC) die wordt uitgevoerd in de toepassingscontainer Niet beschikbaar SID (Niet beschikbaar). Deze beveiligingsmachtiging kan worden gewijzigd met het beheerprogramma van Component Services.


CodeIntegrity:
===================================
Date: 2017-02-22 13:02:58.644
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

Date: 2017-02-22 13:02:58.609
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

Date: 2017-02-22 13:02:35.430
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

Date: 2017-02-22 13:02:35.393
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

Date: 2017-02-22 13:02:35.028
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

Date: 2017-02-22 13:02:34.525
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

Date: 2017-02-22 13:02:34.235
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

Date: 2017-02-22 13:02:34.162
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

Date: 2017-02-22 13:02:34.096
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

Date: 2017-02-22 13:02:34.036
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.


==================== Geheugen info ===========================

Processor: AMD A4-5000 APU with Radeon(TM) HD Graphics
Percentage geheugen in gebruik: 30%
Totaal fysiek RAM-geheugen: 7643.95 MB
Beschikbaar fysiek RAM-geheugen: 5328.93 MB
Totaal Virtueel geheugen: 8859.95 MB
Beschikbaar Virtual geheugen: 6360.82 MB

==================== Schijven ================================

Drive c: (Windows) (Fixed) (Total:448.26 GB) (Free:349.48 GB) NTFS
Drive d: (RECOVERY) (Fixed) (Total:15.87 GB) (Free:1.55 GB) NTFS ==>[systeem met boot componenten (verkregen van schijf)]

==================== MBR & Partitietabel ======
Groetjes van meme-rietje,
het is gemakkelijker op te geven dan door te gaan

meme-rietje
Lid geworden op: 13 okt 2003, 19:51
Locatie: Zuid-West-Vl.

24 feb 2017, 12:59

Scanresultaten van Farbar Recovery Scan Tool (FRST) (x64) Versie: 23-02-2017 01
Gestart door Rita (Beheerder) op RVO001 (24-02-2017 12:31:42)
Gestart vanaf C:\Users\Rita\Documents\Mijn Downloads\Hijackthislog mapje
Geladen Profielen: Rita (Beschikbare Profielen: Rita)
Platform: Windows 10 Home Versie 1607 (X64) Taal: Nederlands (Nederland)
Internet Explorer Versie 11 (Standaardbrowser: "C:\Program Files (x86)\Firefox\Firefox.exe" -osint -url "%1")
Boot Modus: Normal
Handleiding voor Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processen (gefilterd) =================

(Als een item is opgenomen in de fixlist, het proces zal worden gesloten. Het bestand zal niet worden verplaatst.)

() C:\Program Files (x86)\AVG Web TuneUp\WtuSystemSupport.exe
() C:\Program Files\Hewlett-Packard\SimplePass\cachesrvr.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
(Hewlett-Packard Company) C:\Windows\System32\hpservice.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RTKAUDIOSERVICE64.EXE
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(Andrea Electronics Corporation) C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
(CyberLink) C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSMonitorServicePDVD12.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPWMISVC.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
(Protexis Inc.) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
(Popcorn Time) C:\Program Files (x86)\Popcorn Time\Updater.exe
(AVG Secure Search) C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\40.3.1\ToolbarUpdater.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
() C:\Program Files\Hewlett-Packard\SimplePass\opvapp.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudPhotos.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe
(Apple, Inc.) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\secd.exe
(Topdownloads Networks) C:\Program Files (x86)\Spy Cleaner Gold\SpyWatcher.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
() C:\Program Files (x86)\Firefox\bin\FirefoxUpdate.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
() C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.11.110.0_x64__kzf8qxf38zg5c\SkypeHost.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
(Trend Micro Inc.) C:\Users\Rita\Documents\Mijn Downloads\Hijackthislog mapje\HijackThis.exe
(Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
(Mozilla Corporation) C:\Program Files (x86)\Firefox\Firefox.exe
(Mozilla Corporation) C:\Program Files (x86)\Firefox\Firefox.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files\Hewlett-Packard\HP Utility Center\HPPU.exe
(CyberLink) C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Kunshan Aunbox software co.,Ltd) C:\Windows\Temp\rew994D.tmp\ArcherBox.exe
(Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
() C:\Windows\Temp\rew994D.tmp\firstu71\Testc.exe

==================== Register (gefilterd) ====================

(Als een item is opgenomen in de fixlist, het registry item zal worden teruggezet naar de standaardwaarden of verwijderd. Het bestand zal niet worden verplaatst.)

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7194840 2013-07-27] (Realtek Semiconductor)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [176440 2016-11-01] (Apple Inc.)
HKLM\...\Run: [WindowsDefender] => C:\Program Files\Windows Defender\MSASCuiL.exe [631808 2016-09-25] (Microsoft Corporation)
HKLM-x32\...\Run: [StartCCC] => "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun
HKLM-x32\...\Run: [beid] => "C:\Program Files (x86)\Belgium Identity Card\beid35gui.exe" /startup
HKLM-x32\...\Run: [Spy Watcher] => C:\Program Files (x86)\Spy Cleaner Gold\SpyWatcher.exe [557056 2005-04-07] (Topdownloads Networks)
HKLM-x32\...\Run: [vProt] => C:\Program Files (x86)\AVG Web TuneUp\vprot.exe [1941064 2016-06-18] ()
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2016-12-12] (Oracle Corporation)
HKU\S-1-5-21-2370912473-469425822-2799426420-1002\...\Run: [Corel Photo Downloader] => c:\Program Files (x86)\Common Files\Corel\Corel PhotoDownloader\Corel Photo Downloader.exe [526992 2010-07-28] (Corel, Inc.)
HKU\S-1-5-21-2370912473-469425822-2799426420-1002\...\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [67384 2017-01-17] (Apple Inc.)
HKU\S-1-5-21-2370912473-469425822-2799426420-1002\...\Run: [iCloudDrive] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe [110392 2017-01-17] (Apple Inc.)
HKU\S-1-5-21-2370912473-469425822-2799426420-1002\...\Run: [iCloudPhotos] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudPhotos.exe [356664 2017-01-17] (Apple Inc.)
HKU\S-1-5-21-2370912473-469425822-2799426420-1002\...\Run: [uTorrent] => C:\Users\Rita\AppData\Roaming\uTorrent\uTorrent.exe [2143936 2017-02-02] (BitTorrent Inc.)
HKU\S-1-5-21-2370912473-469425822-2799426420-1002\...\Run: [SpybotPostWindows10UpgradeReInstall] => C:\Program Files\Common Files\AV\Spybot - Search and Destroy\Test.exe [1011200 2015-07-28] (Safer-Networking Ltd.)
HKU\S-1-5-21-2370912473-469425822-2799426420-1002\...\MountPoints2: {583e1dd6-abae-11e3-8266-543530614a20} - "C:\WINDOWS\system32\RunDLL32.EXE" Shell32.DLL,ShellExec_RunDLL G:\index.html
HKU\S-1-5-21-2370912473-469425822-2799426420-1002\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\Ribbons.scr [151040 2016-07-16] (Microsoft Corporation)
ShellExecuteHooks: Geen Naam - {0914E00A-CAAF-11E6-B429-64006A5CFC23} - C:\Users\Rita\AppData\Roaming\Tlosparamerk\Kudidom.dll -> Geen bestand
BootExecute: autocheck autochk * sdnclean64.exe
CHR HKLM\SOFTWARE\Policies\Google: Restrictie <======= AANDACHT

==================== Internet (gefilterd) ====================

(Als een item is opgenomen in de fixlist, als het een registry item is wordt verwijderd of hersteld naar de standaard.)

Hosts: 0.0.0.1 mssplus.mcafee.com
Tcpip\Parameters: [DhcpNameServer] 195.130.130.5 195.130.131.5
Tcpip\..\Interfaces\{cced7564-9850-421a-8c18-165cc91f63b6}: [DhcpNameServer] 195.130.130.5 195.130.131.5

Internet Explorer:
==================
HKU\S-1-5-21-2370912473-469425822-2799426420-1002\SOFTWARE\Policies\Microsoft\Internet Explorer: Restrictie <======= AANDACHT
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.amisites.com/?type=hp&ts=1486373569 ... 2_W3P2FY58
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.amisites.com/?type=hp&ts=1486373569 ... 2_W3P2FY58
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.amisites.com/search/?type=ds&ts=148 ... earchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.amisites.com/search/?type=ds&ts=148 ... earchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.amisites.com/?type=hp&ts=1486373569 ... 2_W3P2FY58
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.amisites.com/?type=hp&ts=1486373569 ... 2_W3P2FY58
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.amisites.com/search/?type=ds&ts=148 ... earchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.amisites.com/search/?type=ds&ts=148 ... earchTerms}
HKU\S-1-5-21-2370912473-469425822-2799426420-1002\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.amisites.com/?type=hp&ts=1486373569 ... 2_W3P2FY58
HKU\S-1-5-21-2370912473-469425822-2799426420-1002\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.amisites.com/?type=hp&ts=1486373569 ... 2_W3P2FY58
SearchScopes: HKLM -> {25C97E8F-8EAA-45AE-B37F-4AE0F315EC73} URL = hxxp://www.amazon.co.uk/s/ref=azs_osd_ieauk?ie ... earchTerms}
SearchScopes: HKLM -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/1553-29906-12136-18/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms}
SearchScopes: HKU\S-1-5-21-2370912473-469425822-2799426420-1002 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.amisites.com/search/?type=ds&ts=148 ... earchTerms}
SearchScopes: HKU\S-1-5-21-2370912473-469425822-2799426420-1002 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.amisites.com/search/?type=ds&ts=148 ... earchTerms}
SearchScopes: HKU\S-1-5-21-2370912473-469425822-2799426420-1002 -> {BDF61FAE-9D19-40F0-8F34-688DEB334CA9} URL = hxxp://search.lavasoft.com/results.php?search={searchTerms}&category=web&partner=WCYID10140&campaign=default&d=150628
SearchScopes: HKU\S-1-5-21-2370912473-469425822-2799426420-1002 -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL =
BHO: AVG Web TuneUp -> {95B7759C-8C7F-4BF1-B163-73684A933233} -> C:\Program Files\AVG Web TuneUp\4.3.1.831\AVG Web TuneUp.dll [2016-06-18] (AVG)
BHO: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll [2013-08-28] (Hewlett-Packard)
BHO: Adblock Plus for IE Browser Helper Object -> {FFCB3198-32F3-4E8B-9539-4324694ED664} -> C:\Program Files\Adblock Plus for IE\AdblockPlus64.dll [2015-02-25] (Eyeo GmbH)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\ssv.dll [2017-02-24] (Oracle Corporation)
BHO-x32: AVG Web TuneUp -> {95B7759C-8C7F-4BF1-B163-73684A933233} -> C:\Program Files (x86)\AVG Web TuneUp\4.3.1.831\AVG Web TuneUp.dll [2016-06-18] (AVG)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\jp2ssv.dll [2017-02-24] (Oracle Corporation)
BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2013-08-28] (Hewlett-Packard)
BHO-x32: Adblock Plus for IE Browser Helper Object -> {FFCB3198-32F3-4E8B-9539-4324694ED664} -> C:\Program Files\Adblock Plus for IE\AdblockPlus32.dll [2015-02-25] (Eyeo GmbH)
StartMenuInternet: IEXPLORE.EXE - c:\program files\internet explorer\iexplore.exe hxxp://www.startpageing123.com/?type=sc&ts=148 ... 2_W3P2FY58

Edge:
======
Edge HomeButtonPage: HKU\S-1-5-21-2370912473-469425822-2799426420-1002 -> hxxp://www.amisites.com/?type=hp&ts=1486373569 ... 2_W3P2FY58

FireFox:
========
FF ProfilePath: C:\Users\Rita\AppData\Roaming\Mozilla\Firefox\naweriweentcofise\Profiles\y652r2ae.default\Profiles\y652r2ae.default [niet gevonden]
FF ProfilePath: C:\Users\Rita\AppData\Roaming\Firefox\Firefox\naweriweentcofise\Profiles\y652r2ae.default\Profiles\y652r2ae.default [niet gevonden]
FF ProfilePath: C:\Users\Rita\AppData\Roaming\Mozilla\Firefox\Profiles\y652r2ae.default [2017-02-22]
FF NewTab: Mozilla\Firefox\Profiles\y652r2ae.default -> hxxp://www.luckysearch123.com?type=hp&ts=14865 ... 7q8weg2w8t
FF DefaultSearchEngine: Mozilla\Firefox\Profiles\y652r2ae.default -> luck
FF SearchEngineOrder.1: Mozilla\Firefox\Profiles\y652r2ae.default -> luck
FF SelectedSearchEngine: Mozilla\Firefox\Profiles\y652r2ae.default -> luck
FF Homepage: Mozilla\Firefox\Profiles\y652r2ae.default -> hxxp://www.startpageing123.com/?type=hp&ts=148 ... 2_W3P2FY58
FF Extension: (Avira Browser Safety) - C:\Users\Rita\AppData\Roaming\Mozilla\Firefox\Profiles\y652r2ae.default\Extensions\abs@avira.com.xpi [2016-11-22]
FF Extension: (xRocket Toolbar) - C:\Users\Rita\AppData\Roaming\Mozilla\Firefox\Profiles\y652r2ae.default\Extensions\arthurj8283@gmail.com [2017-02-08] [ niet getekend]
FF Extension: (iCloud Bookmarks) - C:\Users\Rita\AppData\Roaming\Mozilla\Firefox\Profiles\y652r2ae.default\Extensions\firefoxdav@icloud.com [2017-01-13]
FF Extension: (AdBlocker Lite) - C:\Users\Rita\AppData\Roaming\Mozilla\Firefox\Profiles\y652r2ae.default\Extensions\jid1-dwtFBkQjb3SIQp@jetpack.xpi [2016-11-03]
FF Extension: (Avira SafeSearch Plus) - C:\Users\Rita\AppData\Roaming\Mozilla\Firefox\Profiles\y652r2ae.default\Extensions\safesearchplus2@avira.com.xpi [2016-12-15]
FF Extension: (Adblock Plus) - C:\Users\Rita\AppData\Roaming\Mozilla\Firefox\Profiles\y652r2ae.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-11-24]
FF SearchPlugin: C:\Users\Rita\AppData\Roaming\Mozilla\Firefox\Profiles\y652r2ae.default\searchplugins\amisites.xml [2017-02-06]
FF SearchPlugin: C:\Users\Rita\AppData\Roaming\Mozilla\Firefox\Profiles\y652r2ae.default\searchplugins\luck.xml [2017-02-08]
FF SearchPlugin: C:\Users\Rita\AppData\Roaming\Mozilla\Firefox\Profiles\y652r2ae.default\searchplugins\securesearch.xml [2015-06-28]
FF SearchPlugin: C:\Users\Rita\AppData\Roaming\Mozilla\Firefox\Profiles\y652r2ae.default\searchplugins\startpageing123.xml [2017-02-22]
FF ProfilePath: C:\Users\Rita\AppData\Roaming\Firefox\Firefox\Profiles\y652r2ae.default [2017-02-24]
FF Homepage: Firefox\Firefox\Profiles\y652r2ae.default -> hxxp://www.seniorennet.be/forum/viewforum.php? ... 70efc92afa
FF Extension: (Avira Browser Safety) - C:\Users\Rita\AppData\Roaming\Firefox\Firefox\Profiles\y652r2ae.default\Extensions\abs@avira.com.xpi [2017-02-09]
FF Extension: (Firefox Hotfix) - C:\Users\Rita\AppData\Roaming\Firefox\Firefox\Profiles\y652r2ae.default\Extensions\firefox-hotfix@mozilla.org.xpi [2016-08-31]
FF Extension: (AdBlocker Lite) - C:\Users\Rita\AppData\Roaming\Firefox\Firefox\Profiles\y652r2ae.default\Extensions\jid1-dwtFBkQjb3SIQp@jetpack.xpi [2016-11-03]
FF Extension: (English (US) Language Pack) - C:\Users\Rita\AppData\Roaming\Firefox\Firefox\Profiles\y652r2ae.default\Extensions\langpack-en-US@firefox.mozilla.org.xpi [2017-01-05] [ niet getekend]
FF Extension: (Woordenboek Nederlands) - C:\Users\Rita\AppData\Roaming\Firefox\Firefox\Profiles\y652r2ae.default\Extensions\nl-NL@dictionaries.addons.mozilla.org [2017-01-06] [ niet getekend]
FF Extension: (Avira SafeSearch Plus) - C:\Users\Rita\AppData\Roaming\Firefox\Firefox\Profiles\y652r2ae.default\Extensions\safesearchplus2@avira.com.xpi [2016-12-15]
FF Extension: (Adblock Plus) - C:\Users\Rita\AppData\Roaming\Firefox\Firefox\Profiles\y652r2ae.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-11-24]
FF SearchPlugin: C:\Users\Rita\AppData\Roaming\Firefox\Firefox\Profiles\y652r2ae.default\searchplugins\securesearch.xml [2015-06-28]
FF Extension: (Belgium eID) - C:\Program Files (x86)\Mozilla Firefox\extensions\belgiumeid@eid.belgium.be [2017-01-27] [ niet getekend]
FF HKLM-x32\...\Firefox\Extensions: [belgiumeid@eid.belgium.be] - C:\Program Files\Mozilla Firefox\extensions\belgiumeid@eid.belgium.be => niet gevonden
FF HKLM-x32\...\Firefox\Extensions: [arthurj8283@gmail.com] - C:\Users\Rita\AppData\Roaming\Mozilla\Firefox\Profiles\y652r2ae.default\extensions\arthurj8283@gmail.com
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_24_0_0_221.dll [2017-02-17] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50901.0\npctrl.dll [2016-08-31] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWoW64\Macromed\Flash\NPSWF32_24_0_0_221.dll [2017-02-17] ()
FF Plugin-x32: @avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin -> C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\40.3.1\\npsitesafety.dll [Geen bestand]
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2013-10-07] (Google)
FF Plugin-x32: @java.com/DTPlugin,version=11.121.2 -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\dtplugin\npDeployJava1.dll [2017-02-24] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.121.2 -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\plugin2\npjp2.dll [2017-02-24] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50901.0\npctrl.dll [2016-08-31] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3508.0205 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2013-02-05] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll [2014-05-07] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll [2014-05-07] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2016-12-23] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-2370912473-469425822-2799426420-1002: vasco.com/MDPCardReaderPlugin -> C:\Users\Rita\AppData\Roaming\VASCO\MDPCardReaderPlugin\3.2.3.6\npMDPCardReaderPlugin.dll [2015-03-13] (VASCO Data Security)
FF Plugin HKU\S-1-5-21-2370912473-469425822-2799426420-1002: vasco.com/MDPCardReaderPlugin64 -> C:\Users\Rita\AppData\Roaming\VASCO\MDPCardReaderPlugin\3.2.3.6\npMDPCardReaderPlugin64.dll [2015-03-13] (VASCO Data Security)
FF Plugin HKU\S-1-5-21-2370912473-469425822-2799426420-1002: vasco.com/VascoCardReaderPlugin -> C:\Users\Rita\AppData\Roaming\VASCO\VascoCardReaderPlugin\3.2.3.4\npVascoCardReaderPlugin.dll [2014-10-27] (VASCO Data Security)
FF Plugin HKU\S-1-5-21-2370912473-469425822-2799426420-1002: vasco.com/VascoCardReaderPlugin64 -> C:\Users\Rita\AppData\Roaming\VASCO\VascoCardReaderPlugin\3.2.3.4\npVascoCardReaderPlugin64.dll [2014-10-27] (VASCO Data Security)
StartMenuInternet: FIREFOX.EXE - c:\program files (x86)\mozilla firefox\firefox.exe hxxp://www.startpageing123.com/?type=sc&ts=148 ... 2_W3P2FY58

Chrome:
=======
CHR dev: Chrome dev build gedetecteerd! <======= AANDACHT
CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM\...\Chrome\Extension: [ipmkfpcnmccejididiaagpgchgjfajgp] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [ipmkfpcnmccejididiaagpgchgjfajgp] - hxxps://clients2.google.com/service/update2/crx

==================== Services (gefilterd) ====================

(Als een item is opgenomen in de fixlist, wordt uit het register verwijderd. Het bestand zal niet worden verplaatst tenzij apart vermeld.)

R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2016-09-22] (Apple Inc.)
R2 Archer; C:\Program Files (x86)\WinArcher\Archer.dll [760320 2017-02-10] () [Bestand niet getekend]
R2 bilibili; C:\Program Files (x86)\bilibili\bilibili.dll [122880 2017-02-14] () [Bestand niet getekend]
R2 Cachedrv server; C:\Program Files\Hewlett-Packard\SimplePass\cachesrvr.exe [109568 2013-08-23] () [Bestand niet getekend]
R2 CyberLink PowerDVD 12 Media Server Monitor Service; C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSMonitorServicePDVD12.exe [77576 2013-08-12] (CyberLink)
R2 CyberLink PowerDVD 12 Media Server Service; C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe [298760 2013-08-12] (CyberLink)
R2 FirefoxU; C:\Program Files (x86)\Firefox\bin\FirefoxUpdate.exe [160432 2017-02-03] ()
R2 GubedZL; C:\Program Files (x86)\Gubed\GubedZL.dll [118272 2017-02-04] () [Bestand niet getekend]
R2 GubZL; C:\Program Files (x86)\Gub\GubZL.dll [122880 2017-02-09] () [Bestand niet getekend]
R2 HP Support Assistant Service; C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [92160 2013-08-29] (Hewlett-Packard Company) [Bestand niet getekend]
R2 HPWMISVC; C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPWMISVC.exe [1039160 2013-07-23] (Hewlett-Packard Development Company, L.P.)
R3 iThemes5; C:\Program Files (x86)\Common Files\Services\iThemes.dll [459264 2017-02-13] () [Bestand niet getekend] <==== AANDACHT
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.11.474\McCHSvc.exe [329480 2016-12-14] (McAfee, Inc.)
R2 MDM; C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe [335872 2006-10-26] (Microsoft Corporation) [Bestand niet getekend]
R2 MSCFG_SVR; C:\ProgramData\Microsoft\Office\office_update.dll [486912 2017-02-04] () [Bestand niet getekend]
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [246488 2013-06-19] (Realtek Semiconductor)
R2 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [269400 2016-10-05] (Synaptics Incorporated)
R2 Themes; C:\WINDOWS\system32\themeservice.dll [70656 2016-07-16] (Microsoft Corporation) [DependOnService: iThemes5]<==== AANDACHT
R2 Update service; C:\Program Files (x86)\Popcorn Time\Updater.exe [339968 2015-07-17] (Popcorn Time) [Bestand niet getekend]
R2 vToolbarUpdater40.3.1; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\40.3.1\ToolbarUpdater.exe [1323080 2016-06-08] (AVG Secure Search)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347328 2016-07-16] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103720 2016-07-16] (Microsoft Corporation)
R2 WinSAPSvc; C:\Users\Rita\AppData\Roaming\WinSAPSvc\WinSAP.dll [184832 2017-02-24] (TODO: <Company name>) [Bestand niet getekend]
R2 WinSnare; C:\Users\Rita\AppData\Roaming\WinSnare\WinSnare.dll [778752 2017-02-24] (InterSect Alliance Pty Ltd) [Bestand niet getekend]
R2 WtuSystemSupport; C:\Program Files (x86)\AVG Web TuneUp\WtuSystemSupport.exe [972872 2016-06-18] ()
S2 ed2kidle; "C:\Program Files (x86)\amuleCe\ed2k.exe" -downloadwhenidle [X]

===================== Drivers (gefilterd) ======================

(Als een item is opgenomen in de fixlist, wordt uit het register verwijderd. Het bestand zal niet worden verplaatst tenzij apart vermeld.)

R3 AmdAS4; C:\WINDOWS\System32\drivers\AmdAS4.sys [17504 2013-02-07] (Advanced Micro Devices, INC.)
R3 amdkmdag; C:\WINDOWS\System32\DriverStore\FileRepository\c0309377.inf_amd64_7ab08912e1e1da0a\atikmdag.sys [26568848 2017-01-25] (Advanced Micro Devices, Inc.)
R3 amdkmdap; C:\WINDOWS\System32\DriverStore\FileRepository\c0309377.inf_amd64_7ab08912e1e1da0a\atikmpag.sys [536600 2017-01-25] (Advanced Micro Devices, Inc.)
R3 AtiHDAudioService; C:\WINDOWS\system32\drivers\AtihdWT6.sys [102912 2015-05-28] (Advanced Micro Devices)
R1 CLVirtualDrive; C:\WINDOWS\system32\DRIVERS\CLVirtualDrive.sys [91712 2013-03-05] (CyberLink)
R1 HWiNFO32; C:\WINDOWS\SysWoW64\drivers\HWiNFO64A.SYS [27552 2017-01-03] (REALiX(tm))
U5 iaStorA; C:\Windows\System32\Drivers\iaStorA.sys [644968 2013-08-17] (Intel Corporation)
S3 NetAdapterCx; C:\WINDOWS\System32\drivers\NetAdapterCx.sys [90624 2016-07-16] ()
R3 netr28x; C:\WINDOWS\system32\DRIVERS\netr28x.sys [2554528 2015-06-12] (MediaTek Inc.)
R3 RSP2STOR; C:\WINDOWS\system32\DRIVERS\RtsP2Stor.sys [310528 2015-06-05] (Realtek Semiconductor Corp.)
R3 rtbth; C:\WINDOWS\System32\drivers\rtbth.sys [1219200 2015-06-03] (Ralink Technology, Corp.)
S0 WdBoot; C:\WINDOWS\System32\drivers\WdBoot.sys [44056 2016-07-16] (Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\WdFilter.sys [290144 2016-07-16] (Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [123232 2016-07-16] (Microsoft Corporation)
R3 WirelessButtonDriver; C:\WINDOWS\System32\drivers\WirelessButtonDriver64.sys [20800 2013-07-22] (Hewlett-Packard Development Company, L.P.)
S3 avchv; \SystemRoot\system32\DRIVERS\avchv.sys [X]
S0 MBAMSwissArmy; system32\drivers\MBAMSwissArmy.sys [X]
S3 SmbDrv; \SystemRoot\System32\drivers\Smb_driver_AMDASF.sys [X]
S3 SmbDrvI; \SystemRoot\System32\drivers\Smb_driver_Intel.sys [X]
S1 tukxjbng; \??\C:\WINDOWS\system32\drivers\tukxjbng.sys [X]

==================== NetSvcs (gefilterd) ===================

(Als een item is opgenomen in de fixlist, wordt uit het register verwijderd. Het bestand zal niet worden verplaatst tenzij apart vermeld.)


==================== Een Maand Aangemaakt bestanden en mappen ========

(Als een item is opgenomen in de fixlist, het bestand/map wordt verplaatst.)

2017-02-24 12:31 - 2017-02-24 12:31 - 00000000 ____D C:\FRST
2017-02-24 09:05 - 2017-02-24 09:05 - 00000000 ____D C:\Users\Rita\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\amuleC
2017-02-24 09:05 - 2017-02-24 09:05 - 00000000 ____D C:\Users\Rita\AppData\Roaming\aMule
2017-02-24 09:05 - 2017-02-24 09:05 - 00000000 ____D C:\Program Files (x86)\WinSnare(4.1.6)
2017-02-24 09:05 - 2017-02-24 09:05 - 00000000 ____D C:\Program Files (x86)\amuleCexx
2017-02-24 08:47 - 2017-02-24 08:47 - 00000000 ____D C:\ProgramData\Synaptics
2017-02-22 14:44 - 2017-02-22 14:44 - 00000000 ____D C:\Program Files\Synaptics
2017-02-22 08:29 - 2017-02-22 12:56 - 00000040 _____ C:\Program Files (x86)\settings.dat
2017-02-22 08:29 - 2017-02-22 08:29 - 00000000 ____D C:\Program Files (x86)\reports
2017-02-22 08:29 - 2017-02-22 08:29 - 00000000 _____ C:\Program Files (x86)\metadata
2017-02-21 14:20 - 2017-02-21 14:20 - 00000214 _____ C:\Users\Rita\Desktop\Google.URL
2017-02-21 14:17 - 2017-02-21 14:17 - 00000207 _____ C:\Users\Rita\Desktop\httpwww.seniorennet.be.URL
2017-02-21 05:02 - 2017-02-21 07:02 - 00000000 ____D C:\Program Files\wwchromek3
2017-02-14 14:37 - 2017-02-24 09:26 - 00000000 ____D C:\Users\Rita\AppData\Roaming\WinSAPSvc
2017-02-14 14:37 - 2017-02-14 14:37 - 00000000 ____D C:\Program Files (x86)\bilibili
2017-02-12 19:14 - 2017-02-12 19:14 - 00000000 ____D C:\Users\Rita\Downloads\0-Movie
2017-02-11 11:14 - 2016-12-21 08:46 - 00624048 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2017-02-11 11:14 - 2016-12-21 08:43 - 04130440 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2017-02-11 11:14 - 2016-12-21 08:43 - 01454504 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfnetsrc.dll
2017-02-11 11:14 - 2016-12-21 08:43 - 01071736 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfnetcore.dll
2017-02-11 11:14 - 2016-12-21 08:42 - 22224480 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2017-02-11 11:14 - 2016-12-21 08:42 - 01988560 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll
2017-02-11 11:14 - 2016-12-21 08:42 - 01702392 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfasfsrcsnk.dll
2017-02-11 11:14 - 2016-12-21 08:42 - 01300600 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll
2017-02-11 11:14 - 2016-12-21 08:41 - 01600632 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll
2017-02-11 11:14 - 2016-12-21 08:08 - 00360448 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpencom.dll
2017-02-11 11:14 - 2016-12-21 08:06 - 06285312 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
2017-02-11 11:14 - 2016-12-21 07:59 - 00883712 _____ (Microsoft Corporation) C:\WINDOWS\system32\samsrv.dll
2017-02-11 11:14 - 2016-12-21 07:56 - 00936960 _____ (Microsoft Corporation) C:\WINDOWS\system32\MCRecvSrc.dll
2017-02-11 11:14 - 2016-12-21 07:53 - 04474368 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_47.dll
2017-02-11 11:14 - 2016-12-21 07:51 - 08075776 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll
2017-02-11 11:14 - 2016-12-21 07:51 - 05611008 _____ (Microsoft Corporation) C:\WINDOWS\system32\d2d1.dll
2017-02-11 11:14 - 2016-12-21 07:50 - 01490432 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2017-02-11 11:14 - 2016-12-21 07:47 - 01121280 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadtb.dll
2017-02-11 11:14 - 2016-12-21 06:59 - 00218976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\offlinesam.dll
2017-02-11 11:14 - 2016-12-21 06:09 - 00263472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Storage.ApplicationData.dll
2017-02-11 11:14 - 2016-12-21 06:01 - 20969928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2017-02-11 11:14 - 2016-12-21 05:43 - 00285184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.BlockedShutdown.dll
2017-02-11 11:14 - 2016-12-21 05:41 - 00253952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.BioFeedback.dll
2017-02-11 11:14 - 2016-12-21 05:40 - 00557568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StoreAgent.dll
2017-02-11 11:14 - 2016-12-21 05:40 - 00180224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgent.exe
2017-02-11 11:14 - 2016-12-21 05:39 - 00223232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgentUserBroker.exe
2017-02-11 11:14 - 2016-12-21 05:38 - 00866816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Cred.dll
2017-02-11 11:14 - 2016-12-21 05:35 - 00198656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\indexeddbserver.dll
2017-02-11 11:14 - 2016-12-21 05:32 - 19417600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2017-02-11 11:14 - 2016-12-21 05:30 - 05398016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aclui.dll
2017-02-11 11:14 - 2016-12-21 05:26 - 01155072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSVP9DEC.dll
2017-02-11 11:14 - 2016-12-21 05:22 - 01883648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Logon.dll
2017-02-11 11:14 - 2016-12-14 06:41 - 01235296 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2017-02-11 11:14 - 2016-12-14 06:23 - 00404832 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll
2017-02-11 11:14 - 2016-12-14 06:21 - 02206496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msmpeg2vdec.dll
2017-02-11 11:14 - 2016-12-14 06:17 - 00319288 _____ (Microsoft Corporation) C:\WINDOWS\system32\wow64.dll
2017-02-11 11:14 - 2016-12-14 06:01 - 00382784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AUDIOKSE.dll
2017-02-11 11:14 - 2016-12-14 05:48 - 01631232 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.dll
2017-02-11 11:14 - 2016-12-14 05:46 - 01631232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.Resources.dll
2017-02-11 11:14 - 2016-12-14 05:43 - 00201728 _____ (Microsoft Corporation) C:\WINDOWS\system32\ScDeviceEnum.dll
2017-02-11 11:14 - 2016-12-14 05:42 - 00236544 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinSCard.dll
2017-02-11 11:14 - 2016-12-14 05:42 - 00167424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WinSCard.dll
2017-02-11 11:14 - 2016-12-14 05:40 - 00193536 _____ (Microsoft Corporation) C:\WINDOWS\system32\certprop.dll
2017-02-11 11:14 - 2016-12-14 05:38 - 17188864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2017-02-11 11:14 - 2016-12-14 05:38 - 00213504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.CredDialogController.dll
2017-02-11 11:14 - 2016-12-14 05:37 - 00090112 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatepolicy.dll
2017-02-11 11:14 - 2016-12-14 05:36 - 00074752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\updatepolicy.dll
2017-02-11 11:14 - 2016-12-14 05:35 - 00755712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
2017-02-11 11:14 - 2016-12-14 05:35 - 00600576 _____ (Microsoft Corporation) C:\WINDOWS\system32\cryptui.dll
2017-02-11 11:14 - 2016-12-14 05:35 - 00553984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cryptui.dll
2017-02-11 11:14 - 2016-12-14 05:26 - 00932864 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
2017-02-11 11:14 - 2016-12-14 05:26 - 00869888 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
2017-02-11 11:14 - 2016-12-14 05:24 - 01005568 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3D12.dll
2017-02-11 11:14 - 2016-12-14 05:24 - 00673792 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe
2017-02-11 11:14 - 2016-12-14 05:23 - 03134976 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcore.dll
2017-02-11 11:14 - 2016-12-14 05:22 - 02317824 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2017-02-11 11:14 - 2016-12-14 05:22 - 00391168 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll
2017-02-11 11:14 - 2016-11-02 13:01 - 00484584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll
2017-02-11 11:14 - 2016-08-02 05:30 - 00822784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakradiag.dll
2017-02-11 11:13 - 2016-12-21 09:04 - 07816032 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2017-02-11 11:13 - 2016-12-21 08:49 - 00328008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Storage.ApplicationData.dll
2017-02-11 11:13 - 2016-12-21 08:43 - 00092512 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpudd.dll
2017-02-11 11:13 - 2016-12-21 08:37 - 00455520 _____ (Microsoft Corporation) C:\WINDOWS\system32\securekernel.exe
2017-02-11 11:13 - 2016-12-21 08:15 - 22563840 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2017-02-11 11:13 - 2016-12-21 08:14 - 00043008 _____ (Microsoft Corporation) C:\WINDOWS\system32\LaunchWinApp.exe
2017-02-11 11:13 - 2016-12-21 08:09 - 00368640 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneBackupHandler.dll
2017-02-11 11:13 - 2016-12-21 08:09 - 00363520 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.BioFeedback.dll
2017-02-11 11:13 - 2016-12-21 08:08 - 00418304 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.BlockedShutdown.dll
2017-02-11 11:13 - 2016-12-21 08:08 - 00289792 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeveloperOptionsSettingsHandlers.dll
2017-02-11 11:13 - 2016-12-21 08:08 - 00211968 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgent.exe
2017-02-11 11:13 - 2016-12-21 08:07 - 00748544 _____ (Microsoft Corporation) C:\WINDOWS\system32\StoreAgent.dll
2017-02-11 11:13 - 2016-12-21 08:06 - 00310784 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncSettings.dll
2017-02-11 11:13 - 2016-12-21 08:06 - 00260608 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgentUserBroker.exe
2017-02-11 11:13 - 2016-12-21 08:06 - 00147456 _____ (Microsoft Corporation) C:\WINDOWS\system32\winsrv.dll
2017-02-11 11:13 - 2016-12-21 08:05 - 00425984 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadcloudap.dll
2017-02-11 11:13 - 2016-12-21 08:05 - 00261632 _____ (Microsoft Corporation) C:\WINDOWS\system32\indexeddbserver.dll
2017-02-11 11:13 - 2016-12-21 08:05 - 00049152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Shell.dll
2017-02-11 11:13 - 2016-12-21 08:01 - 09131008 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2017-02-11 11:13 - 2016-12-21 08:00 - 00440320 _____ (Microsoft Corporation) C:\WINDOWS\system32\fhcfg.dll
2017-02-11 11:13 - 2016-12-21 07:59 - 01908224 _____ (Microsoft Corporation) C:\WINDOWS\system32\AzureSettingSyncProvider.dll
2017-02-11 11:13 - 2016-12-21 07:58 - 23678464 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2017-02-11 11:13 - 2016-12-21 07:57 - 00462336 _____ (Microsoft Corporation) C:\WINDOWS\system32\fhsettingsprovider.dll
2017-02-11 11:13 - 2016-12-21 07:56 - 00947712 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVP9DEC.dll
2017-02-11 11:13 - 2016-12-21 07:55 - 08129536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2017-02-11 11:13 - 2016-12-21 07:55 - 04749312 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll
2017-02-11 11:13 - 2016-12-21 07:54 - 05511680 _____ (Microsoft Corporation) C:\WINDOWS\system32\aclui.dll
2017-02-11 11:13 - 2016-12-21 07:53 - 06664192 _____ (Microsoft Corporation) C:\WINDOWS\system32\mspaint.exe
2017-02-11 11:13 - 2016-12-21 07:49 - 04149248 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcorets.dll
2017-02-11 11:13 - 2016-12-21 07:49 - 02691072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll
2017-02-11 11:13 - 2016-12-21 07:49 - 01062912 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncCore.dll
2017-02-11 11:13 - 2016-12-21 06:02 - 03892864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
2017-02-11 11:13 - 2016-12-21 06:02 - 01852720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll
2017-02-11 11:13 - 2016-12-21 06:02 - 01360464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfnetsrc.dll
2017-02-11 11:13 - 2016-12-21 06:02 - 01277344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfasfsrcsnk.dll
2017-02-11 11:13 - 2016-12-21 06:02 - 01201872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmpeg2srcsnk.dll
2017-02-11 11:13 - 2016-12-21 06:02 - 00980832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfnetcore.dll
2017-02-11 11:13 - 2016-12-21 05:46 - 00034304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LaunchWinApp.exe
2017-02-11 11:13 - 2016-12-21 05:41 - 00231936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.LockScreen.dll
2017-02-11 11:13 - 2016-12-21 05:40 - 00318976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpencom.dll
2017-02-11 11:13 - 2016-12-21 05:40 - 00237056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SyncSettings.dll
2017-02-11 11:13 - 2016-12-21 05:39 - 01300480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSVPXENC.dll
2017-02-11 11:13 - 2016-12-21 05:35 - 04612608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll
2017-02-11 11:13 - 2016-12-21 05:34 - 07626752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2017-02-11 11:13 - 2016-12-21 05:33 - 19413504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2017-02-11 11:13 - 2016-12-21 05:30 - 01255936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AzureSettingSyncProvider.dll
2017-02-11 11:13 - 2016-12-21 05:27 - 00640000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MCRecvSrc.dll
2017-02-11 11:13 - 2016-12-21 05:25 - 07469056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll
2017-02-11 11:13 - 2016-12-21 05:25 - 06474752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mspaint.exe
2017-02-11 11:13 - 2016-12-21 05:24 - 06044160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2017-02-11 11:13 - 2016-12-14 06:41 - 00590960 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
2017-02-11 11:13 - 2016-12-14 06:34 - 02482280 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2vdec.dll
2017-02-11 11:13 - 2016-12-14 06:33 - 01356864 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipUp.exe
2017-02-11 11:13 - 2016-12-14 06:19 - 00584544 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncHost.exe
2017-02-11 11:13 - 2016-12-14 06:18 - 00715104 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vhdmp.sys
2017-02-11 11:13 - 2016-12-14 06:18 - 00335712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pci.sys
2017-02-11 11:13 - 2016-12-14 06:14 - 01694712 _____ (Microsoft Corporation) C:\WINDOWS\system32\winmde.dll
2017-02-11 11:13 - 2016-12-14 06:14 - 00418952 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll
2017-02-11 11:13 - 2016-12-14 06:14 - 00089416 _____ (Microsoft Corporation) C:\WINDOWS\system32\remoteaudioendpoint.dll
2017-02-11 11:13 - 2016-12-14 06:01 - 01557808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winmde.dll
2017-02-11 11:13 - 2016-12-14 06:01 - 00076984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\remoteaudioendpoint.dll
2017-02-11 11:13 - 2016-12-14 05:46 - 00206848 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2017-02-11 11:13 - 2016-12-14 05:42 - 00352768 _____ (Microsoft Corporation) C:\WINDOWS\system32\cloudAP.dll
2017-02-11 11:13 - 2016-12-14 05:42 - 00208896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.UI.Logon.ProxyStub.dll
2017-02-11 11:13 - 2016-12-14 05:41 - 00223744 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2017-02-11 11:13 - 2016-12-14 05:40 - 00324096 _____ (Microsoft Corporation) C:\WINDOWS\system32\domgmt.dll
2017-02-11 11:13 - 2016-12-14 05:40 - 00231424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CloudBackupSettings.dll
2017-02-11 11:13 - 2016-12-14 05:39 - 00837632 _____ (Microsoft Corporation) C:\WINDOWS\system32\wbiosrvc.dll
2017-02-11 11:13 - 2016-12-14 05:39 - 00290816 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatehandlers.dll
2017-02-11 11:13 - 2016-12-14 05:39 - 00257024 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.CredDialogController.dll
2017-02-11 11:13 - 2016-12-14 05:38 - 13869056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2017-02-11 11:13 - 2016-12-14 05:38 - 00295424 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudBackupSettings.dll
2017-02-11 11:13 - 2016-12-14 05:36 - 01002496 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRH.dll
2017-02-11 11:13 - 2016-12-14 05:36 - 00539648 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocore.dll
2017-02-11 11:13 - 2016-12-14 05:35 - 00712192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll
2017-02-11 11:13 - 2016-12-14 05:32 - 00497152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LogonController.dll
2017-02-11 11:13 - 2016-12-14 05:25 - 02009600 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRHInproc.dll
2017-02-11 11:13 - 2016-12-14 05:23 - 01231872 _____ (Microsoft Corporation) C:\WINDOWS\system32\dosvc.dll
2017-02-11 11:13 - 2016-12-14 05:22 - 02748416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpcore.dll
2017-02-11 11:13 - 2016-12-14 05:22 - 01513472 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2017-02-11 11:13 - 2016-12-14 05:21 - 03616768 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2017-02-11 11:13 - 2016-11-02 12:00 - 00534096 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll
2017-02-11 11:13 - 2016-11-02 11:28 - 00324608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.LockScreen.dll
2017-02-11 11:13 - 2016-11-02 11:22 - 00337920 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
2017-02-11 11:13 - 2016-11-02 11:21 - 00942080 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2017-02-11 11:12 - 2016-12-21 08:42 - 00241504 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHost.dll
2017-02-11 11:12 - 2016-12-21 08:13 - 00119808 _____ (Microsoft Corporation) C:\WINDOWS\system32\KnobsCsp.dll
2017-02-11 11:12 - 2016-12-21 08:12 - 00083968 _____ (Microsoft Corporation) C:\WINDOWS\system32\ProvPluginEng.dll
2017-02-11 11:12 - 2016-12-21 08:10 - 00234496 _____ (Microsoft Corporation) C:\WINDOWS\system32\KnobsCore.dll
2017-02-11 11:12 - 2016-12-21 08:08 - 01292288 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVPXENC.dll
2017-02-11 11:12 - 2016-12-21 08:08 - 00349184 _____ (Microsoft Corporation) C:\WINDOWS\system32\provengine.dll
2017-02-11 11:12 - 2016-12-21 07:53 - 01692672 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll
2017-02-11 11:12 - 2016-12-21 07:51 - 02275840 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2017-02-11 11:12 - 2016-12-21 05:24 - 05061120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d2d1.dll
2017-02-11 11:12 - 2016-12-21 05:24 - 03733504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_47.dll
2017-02-11 11:12 - 2016-12-21 05:24 - 00886272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aadtb.dll
2017-02-11 11:12 - 2016-12-21 05:22 - 00860672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncCore.dll
2017-02-11 11:12 - 2016-12-14 06:08 - 00341344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll
2017-02-11 11:12 - 2016-12-14 06:06 - 00509792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncHost.exe
2017-02-11 11:12 - 2016-12-14 05:45 - 00147968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32k.sys
2017-02-11 11:12 - 2016-12-14 05:40 - 00266752 _____ (Microsoft Corporation) C:\WINDOWS\system32\ConsoleLogon.dll
2017-02-11 11:12 - 2016-12-14 05:40 - 00104448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.UI.Logon.ProxyStub.dll
2017-02-11 11:12 - 2016-12-14 05:32 - 00806400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3D12.dll
2017-02-11 11:12 - 2016-12-14 05:22 - 02998272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys
2017-02-11 11:12 - 2016-12-14 05:22 - 00707584 _____ (Microsoft Corporation) C:\WINDOWS\system32\LogonController.dll
2017-02-11 11:01 - 2016-12-21 09:08 - 00136032 _____ (Microsoft Corporation) C:\WINDOWS\system32\ImplatSetup.dll
2017-02-11 11:00 - 2016-12-21 09:08 - 00245600 _____ (Microsoft Corporation) C:\WINDOWS\system32\offlinesam.dll
2017-02-09 16:59 - 2017-02-09 16:59 - 02302976 _____ C:\Users\Rita\Downloads\E-Mailadressen 17-01-08 backup(1).pst
2017-02-09 16:58 - 2017-02-09 16:58 - 02302976 _____ C:\Users\Rita\Downloads\E-Mailadressen 17-01-08 backup.pst
2017-02-09 11:37 - 2017-02-20 11:11 - 00000000 ____D C:\Program Files (x86)\WinSnare(4.1.0)
2017-02-06 10:52 - 2017-02-06 10:52 - 03516080 _____ (Enigma Software Group USA, LLC.) C:\Users\Rita\Downloads\sh-remover.exe
2017-02-06 10:19 - 2017-02-24 12:32 - 00000000 ____D C:\Users\Rita\AppData\Roaming\WinSnare
2017-02-06 10:19 - 2017-02-08 11:20 - 00000000 ____D C:\Program Files (x86)\WinSnare(4.0.9)
2017-02-06 10:19 - 2017-02-06 10:19 - 00000000 ____D C:\Program Files (x86)\Gub
2017-02-05 09:02 - 2017-02-05 09:02 - 00000000 ____D C:\Users\Rita\AppData\Local\Mapbob
2017-02-05 08:34 - 2017-02-21 14:11 - 00002490 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-02-05 08:33 - 2017-02-05 08:33 - 00000000 ____D C:\Program Files (x86)\Mapbob
2017-02-05 08:33 - 2017-02-05 08:33 - 00000000 ____D C:\Program Files (x86)\Firefox
2017-02-03 15:05 - 2017-02-03 15:05 - 00000000 ____D C:\Program Files (x86)\Gubed
2017-01-30 09:01 - 2017-01-30 09:01 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iCloud
2017-01-27 09:57 - 2017-01-29 09:09 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2017-01-25 19:40 - 2016-12-21 08:08 - 00142848 _____ (Microsoft Corporation) C:\WINDOWS\system32\poqexec.exe
2017-01-25 19:40 - 2016-12-21 05:44 - 00120320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\poqexec.exe
2017-01-25 01:29 - 2017-01-25 01:29 - 09405464 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\amdvlk64.dll
2017-01-25 01:29 - 2017-01-25 01:29 - 07589400 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\amdvlk32.dll
2017-01-25 01:29 - 2017-01-25 01:29 - 02463256 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\amfrt64.dll
2017-01-25 01:29 - 2017-01-25 01:29 - 02150928 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\amfrt32.dll
2017-01-25 01:29 - 2017-01-25 01:29 - 01351192 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\atiadlxx.dll
2017-01-25 01:29 - 2017-01-25 01:29 - 01015832 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\atiadlxy.dll
2017-01-25 01:29 - 2017-01-25 01:29 - 01015832 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\atiadlxx.dll
2017-01-25 01:29 - 2017-01-25 01:29 - 00768024 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\amdlvr64.dll
2017-01-25 01:29 - 2017-01-25 01:29 - 00643096 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\amdlvr32.dll
2017-01-25 01:29 - 2017-01-25 01:29 - 00476696 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\atidemgy.dll
2017-01-25 01:29 - 2017-01-25 01:29 - 00420376 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\atiapfxx.exe
2017-01-25 01:29 - 2017-01-25 01:29 - 00310808 _____ C:\WINDOWS\system32\dgtrayicon.exe
2017-01-25 01:29 - 2017-01-25 01:29 - 00293400 _____ C:\WINDOWS\system32\GameManager64.dll
2017-01-25 01:29 - 2017-01-25 01:29 - 00287248 _____ C:\WINDOWS\system32\clinfo.exe
2017-01-25 01:29 - 2017-01-25 01:29 - 00285720 _____ C:\WINDOWS\system32\hsa-thunk64.dll
2017-01-25 01:29 - 2017-01-25 01:29 - 00266256 _____ C:\WINDOWS\system32\amdgfxinfo64.dll
2017-01-25 01:29 - 2017-01-25 01:29 - 00258072 _____ C:\WINDOWS\SysWOW64\GameManager32.dll
2017-01-25 01:29 - 2017-01-25 01:29 - 00251416 _____ C:\WINDOWS\SysWOW64\hsa-thunk.dll
2017-01-25 01:29 - 2017-01-25 01:29 - 00248344 _____ C:\WINDOWS\system32\atieah64.exe
2017-01-25 01:29 - 2017-01-25 01:29 - 00239128 _____ C:\WINDOWS\SysWOW64\amdgfxinfo32.dll
2017-01-25 01:29 - 2017-01-25 01:29 - 00226328 _____ C:\WINDOWS\SysWOW64\atieah32.exe
2017-01-25 01:29 - 2017-01-25 01:29 - 00219672 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\atig6txx.dll
2017-01-25 01:29 - 2017-01-25 01:29 - 00193560 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\atigktxx.dll
2017-01-25 01:29 - 2017-01-25 01:29 - 00178200 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\mantle64.dll
2017-01-25 01:29 - 2017-01-25 01:29 - 00158336 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\aticfx64.dll
2017-01-25 01:29 - 2017-01-25 01:29 - 00154648 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\atisamu64.dll
2017-01-25 01:29 - 2017-01-25 01:29 - 00153112 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\mantle32.dll
2017-01-25 01:29 - 2017-01-25 01:29 - 00147480 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\mantleaxl64.dll
2017-01-25 01:29 - 2017-01-25 01:29 - 00145952 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\aticfx32.dll
2017-01-25 01:29 - 2017-01-25 01:29 - 00135704 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\atisamu32.dll
2017-01-25 01:29 - 2017-01-25 01:29 - 00130584 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.dll
2017-01-25 01:29 - 2017-01-25 01:29 - 00128536 _____ (AMD) C:\WINDOWS\system32\atimuixx.dll
2017-01-25 01:29 - 2017-01-25 01:29 - 00126488 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\mantleaxl32.dll
2017-01-25 01:29 - 2017-01-25 01:29 - 00121368 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.dll
2017-01-25 01:29 - 2017-01-25 01:29 - 00118800 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\atidxx64.dll
2017-01-25 01:29 - 2017-01-25 01:29 - 00107544 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\atidxx32.dll
2017-01-25 01:29 - 2017-01-25 01:29 - 00100888 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\amdmcl64.dll
2017-01-25 01:29 - 2017-01-25 01:29 - 00084504 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\amdmcl32.dll
2017-01-25 01:29 - 2017-01-25 01:29 - 00077848 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\ati2erec.dll
2017-01-25 01:29 - 2017-01-25 01:29 - 00038424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\detoured.dll
2017-01-25 01:29 - 2017-01-25 01:29 - 00038416 _____ (Microsoft Corporation) C:\WINDOWS\system32\detoured.dll
2017-01-25 01:28 - 2017-01-25 01:28 - 00488496 _____ C:\WINDOWS\system32\amdmiracast.dll
2017-01-25 01:28 - 2017-01-25 01:28 - 00166408 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\amdave64.dll
2017-01-25 01:28 - 2017-01-25 01:28 - 00162216 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\amdhcp64.dll
2017-01-25 01:28 - 2017-01-25 01:28 - 00145872 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\amdhcp32.dll
2017-01-25 01:28 - 2017-01-25 01:28 - 00145360 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\amdave32.dll
2017-01-25 01:28 - 2017-01-25 01:28 - 00130224 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\amdpcom64.dll
2017-01-25 01:28 - 2017-01-25 01:28 - 00130216 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\atimpc64.dll
2017-01-25 01:28 - 2017-01-25 01:28 - 00112336 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\atimpc32.dll
2017-01-25 01:28 - 2017-01-25 01:28 - 00112328 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\amdpcom32.dll

==================== Een Maand Gewijzigd bestanden en mappen ========

(Als een item is opgenomen in de fixlist, het bestand/map wordt verplaatst.)

2017-02-24 12:32 - 2017-01-22 08:30 - 00003612 _____ C:\WINDOWS\System32\Tasks\Milimili
2017-02-24 12:31 - 2017-01-04 14:25 - 00034328 _____ (Sysinternals - www.sysinternals.com) C:\WINDOWS\system32\Drivers\PROCEXP152.SYS
2017-02-24 12:22 - 2016-09-25 09:34 - 00000000 ____D C:\WINDOWS\system32\SleepStudy
2017-02-24 11:31 - 2016-11-16 18:33 - 00000000 ____D C:\Users\Rita\AppData\LocalLow\Mozilla
2017-02-24 11:30 - 2014-03-12 17:02 - 00000000 ____D C:\Users\Rita\AppData\Local\VirtualStore
2017-02-24 11:03 - 2017-01-05 16:17 - 00000000 _____ C:\Users\Public\Documents\report.dat
2017-02-24 10:21 - 2014-03-14 15:44 - 00000000 ____D C:\Users\Rita\AppData\Roaming\uTorrent
2017-02-24 10:18 - 2016-07-04 17:17 - 00000000 ___RD C:\Users\Rita\iCloudDrive
2017-02-24 10:16 - 2017-01-05 16:17 - 00000000 _____ C:\Users\Public\Documents\temp.dat
2017-02-24 10:16 - 2016-09-25 10:34 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2017-02-24 10:16 - 2016-09-25 09:37 - 00065536 _____ C:\WINDOWS\system32\spu_storage.bin
2017-02-24 10:16 - 2016-07-16 07:04 - 01048576 _____ C:\WINDOWS\system32\config\BBI
2017-02-24 10:15 - 2016-09-25 09:45 - 00000000 ____D C:\Users\Rita
2017-02-24 09:59 - 2014-09-10 09:37 - 00000000 ____D C:\ProgramData\Oracle
2017-02-24 09:56 - 2015-09-23 15:19 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2017-02-24 09:56 - 2015-09-23 15:19 - 00000000 ____D C:\Program Files (x86)\Java
2017-02-24 09:55 - 2015-09-23 15:19 - 00097856 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\WindowsAccessBridge-32.dll
2017-02-24 08:58 - 2016-07-16 12:47 - 00000000 ___HD C:\Program Files\WindowsApps
2017-02-24 08:58 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\AppReadiness
2017-02-23 19:19 - 2015-11-27 08:27 - 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2017-02-23 10:52 - 2014-03-14 15:44 - 00000000 ____D C:\Users\Rita\AppData\Roaming\vlc
2017-02-22 14:44 - 2016-07-16 12:45 - 00000000 ____D C:\WINDOWS\INF
2017-02-22 13:02 - 2014-03-12 17:03 - 00000000 ____D C:\Users\Rita\AppData\Roaming\Synaptics
2017-02-22 09:47 - 2016-07-16 12:36 - 00000000 ____D C:\WINDOWS\CbsTemp
2017-02-21 23:01 - 2015-11-22 08:31 - 00000000 ___RD C:\Users\Rita\OneDrive
2017-02-20 14:57 - 2016-09-25 09:34 - 00353744 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2017-02-19 09:24 - 2014-03-27 13:53 - 00000000 ____D C:\Users\Rita\AppData\Roaming\dvdcss
2017-02-17 08:32 - 2014-03-16 10:30 - 00000940 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2017-02-17 01:05 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\SysWOW64\Macromed
2017-02-17 01:05 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\Macromed
2017-02-15 17:03 - 2017-01-18 20:24 - 00000000 ____D C:\ProgramData\WinSAPSvc
2017-02-13 15:05 - 2016-09-25 09:38 - 00000000 ____D C:\ProgramData\Package Cache
2017-02-13 15:02 - 2017-01-14 12:03 - 00000028 ___RH C:\Users\Rita\AppData\Roaming\be046e943fe726861c04b0318e13b2f274b1ec06.sys
2017-02-12 19:52 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\rescache
2017-02-11 11:46 - 2014-03-12 16:59 - 00000000 __RHD C:\Users\Public\AccountPictures
2017-02-11 11:45 - 2016-09-25 09:44 - 03370300 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2017-02-11 11:45 - 2016-07-16 23:15 - 01467736 _____ C:\WINDOWS\system32\perfh013.dat
2017-02-11 11:45 - 2016-07-16 23:15 - 00382028 _____ C:\WINDOWS\system32\perfc013.dat
2017-02-11 11:38 - 2016-07-16 12:47 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2017-02-11 11:38 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2017-02-11 11:38 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\oobe
2017-02-11 11:38 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\ShellExperiences
2017-02-11 11:38 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\Provisioning
2017-02-09 20:13 - 2017-01-22 08:30 - 00000000 ____D C:\Program Files (x86)\MIO
2017-02-08 15:54 - 2014-03-31 20:37 - 00000000 ____D C:\Users\Rita\AppData\Local\Google
2017-02-07 16:48 - 2014-03-14 15:27 - 00096960 _____ C:\Users\Rita\AppData\Local\GDIPFONTCACHEV1.DAT
2017-02-06 20:48 - 2016-11-10 02:26 - 00835576 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2017-02-06 20:48 - 2016-11-10 02:26 - 00177656 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2017-02-06 17:55 - 2017-01-03 19:53 - 00000000 ____D C:\Program Files (x86)\Ocecult
2017-02-06 10:32 - 2015-09-12 11:05 - 00002378 _____ C:\Users\Rita\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2017-02-06 10:32 - 2015-09-12 11:05 - 00002347 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2017-02-06 10:32 - 2015-09-12 11:05 - 00002277 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2017-02-06 10:32 - 2015-09-12 11:05 - 00002228 _____ C:\Users\Rita\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk
2017-02-06 10:17 - 2017-01-04 14:25 - 00000000 ____D C:\Program Files (x86)\7cveykf6
2017-02-03 22:29 - 2014-05-02 18:17 - 00000085 _____ C:\WINDOWS\wininit.ini
2017-02-03 22:29 - 2014-04-09 10:21 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy
2017-02-03 15:05 - 2017-01-10 22:11 - 00000000 ____D C:\Program Files (x86)\WinArcher
2017-02-02 23:41 - 2014-04-30 16:42 - 00000000 ____D C:\Users\Rita\Documents\Mijn Downloads
2017-01-30 13:20 - 2016-07-04 17:18 - 00000000 ____D C:\Users\Rita\AppData\Local\4B557FDC-16F9-4C32-BA63-A9BE30F65F83.aplzod
2017-01-30 10:09 - 2016-07-16 07:04 - 00032768 _____ C:\WINDOWS\system32\config\ELAM
2017-01-29 09:09 - 2014-06-17 08:17 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2017-01-26 16:39 - 2016-09-25 09:37 - 00000000 ____D C:\Program Files\AMD
2017-01-26 16:26 - 2015-10-18 09:34 - 00000000 ____D C:\Users\Rita\Documents\My PSP Files
2017-01-26 10:18 - 2015-11-22 03:22 - 00000000 ____D C:\AMD
2017-01-25 20:04 - 2014-05-30 06:33 - 00000000 ____D C:\ProgramData\Malwarebytes
2017-01-25 01:29 - 2016-10-26 00:04 - 00909336 _____ (AMD) C:\WINDOWS\system32\coinst_16.40.dll
2017-01-25 01:29 - 2016-09-13 21:08 - 00541208 _____ (AMD) C:\WINDOWS\system32\atieclxx.exe
2017-01-25 01:29 - 2016-09-13 21:08 - 00305176 _____ (AMD) C:\WINDOWS\system32\atiesrxx.exe

==================== Bestanden in de root van sommige mappen =======

2017-02-22 08:29 - 2017-02-22 08:29 - 0000000 _____ () C:\Program Files (x86)\metadata
2017-02-22 08:29 - 2017-02-22 12:56 - 0000040 _____ () C:\Program Files (x86)\settings.dat
2017-01-14 12:03 - 2017-02-13 15:02 - 0000028 ___RH () C:\Users\Rita\AppData\Roaming\be046e943fe726861c04b0318e13b2f274b1ec06.sys
2017-01-14 12:03 - 2017-01-14 12:03 - 0000028 _RSHO () C:\Users\Rita\AppData\Roaming\c54da0d4db72e7476d261013371d583ed5cee3ac.sys
2014-07-07 13:03 - 2016-01-22 15:51 - 0009342 _____ () C:\Users\Rita\AppData\Roaming\Microsoft Access 97-2003.EML
2015-09-10 06:34 - 2015-09-10 06:34 - 0000066 _____ () C:\Users\Rita\AppData\Roaming\sn.txt
2015-09-10 06:34 - 2015-09-10 06:34 - 3531374 _____ () C:\Users\Rita\AppData\Local\curl.zip
2015-02-05 22:30 - 2017-01-16 12:09 - 0003584 _____ () C:\Users\Rita\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-09-10 06:36 - 2015-09-10 06:36 - 0000520 _____ () C:\Users\Rita\AppData\Local\GGAvhX.vbs
2015-09-03 22:20 - 2015-09-03 22:20 - 0000398 _____ () C:\Users\Rita\AppData\Local\PMJwv.vbs
2014-06-01 10:27 - 2014-06-01 10:27 - 0000017 _____ () C:\Users\Rita\AppData\Local\resmon.resmoncfg
2014-05-02 18:39 - 2014-05-02 18:39 - 0000008 __RSH () C:\ProgramData\2C9DF356C2.sys
2014-05-02 18:39 - 2014-05-28 21:53 - 0003140 ___SH () C:\ProgramData\KGyGaAvL.sys
2015-09-03 21:21 - 2015-09-12 08:26 - 0000102 _____ () C:\ProgramData\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat

Bestanden om te verplaatsen of verwijderen:
====================
C:\ProgramData\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat


Sommige bestanden in TEMP:
====================
2017-01-03 19:53 - 2017-01-03 19:53 - 0089088 _____ () C:\Users\Rita\AppData\Local\Temp\DriverBoosterSetup.exe
2017-01-03 19:53 - 2017-01-03 19:53 - 17156848 _____ (IObit ) C:\Users\Rita\AppData\Local\Temp\E2.tmp.exe
2017-01-18 20:24 - 2017-01-18 20:24 - 26967248 _____ () C:\Users\Rita\AppData\Local\Temp\inst12.exe
2017-01-07 16:08 - 2017-01-07 16:08 - 0737856 _____ (Oracle Corporation) C:\Users\Rita\AppData\Local\T
Groetjes van meme-rietje,
het is gemakkelijker op te geven dan door te gaan

abbs
Lid geworden op: 16 dec 2016, 13:49
Locatie: Leidschendam
Contacteer:

24 feb 2017, 15:17

Hallo,

Schik niet van de fix die ik voor je heb gemaakt. Er staat genoeg malsware/adware op je pc, dat gaan we in stappen verwijderen. Als je iets niet snapt vraag het dan :)
Lees eerst alles rustig door voor je het gaat uitvoeren.

De tool FRST.exe staat in de dik gedrukte map: C:\Users\Rita\Documents\Mijn Downloads\Hijackthislog mapje <== Sleep de FRST.exe vanuit deze map naar je bureaublad.


Note: Dit script is speciaal bedoeld voor deze computer, gebruik dit dan ook niet op andere computers met een gelijkaardig probleem.
Open Kladblok. Klik op het vergrootglas naast Start > Type bij "Zoeken in Windows" Kladblok en klik op Enter.
Kopieer onderstaande dik gedrukte code en plak dat in "Kladblok"


start
CreateRestorePoint:
CloseProcesses:
ShellExecuteHooks: Geen Naam - {0914E00A-CAAF-11E6-B429-64006A5CFC23} - C:\Users\Rita\AppData\Roaming\Tlosparamerk\Kudidom.dll -> Geen bestand
HKU\S-1-5-21-2370912473-469425822-2799426420-1002\SOFTWARE\Policies\Microsoft\Internet Explorer: Restrictie <======= AANDACHT
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.amisites.com/?type=hp&ts=1486373569 ... 2_W3P2FY58
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.amisites.com/?type=hp&ts=1486373569 ... 2_W3P2FY58
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.amisites.com/search/?type=ds&ts=148 ... earchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.amisites.com/search/?type=ds&ts=148 ... earchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.amisites.com/?type=hp&ts=1486373569 ... 2_W3P2FY58
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.amisites.com/?type=hp&ts=1486373569 ... 2_W3P2FY58
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.amisites.com/search/?type=ds&ts=148 ... earchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.amisites.com/search/?type=ds&ts=148 ... earchTerms}
HKU\S-1-5-21-2370912473-469425822-2799426420-1002\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.amisites.com/?type=hp&ts=1486373569 ... 2_W3P2FY58
HKU\S-1-5-21-2370912473-469425822-2799426420-1002\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.amisites.com/?type=hp&ts=1486373569 ... 2_W3P2FY58
SearchScopes: HKLM -> {25C97E8F-8EAA-45AE-B37F-4AE0F315EC73} URL = hxxp://www.amazon.co.uk/s/ref=azs_osd_ieauk?ie ... earchTerms}
SearchScopes: HKLM -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/1553-29906-12136-18/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms}
SearchScopes: HKU\S-1-5-21-2370912473-469425822-2799426420-1002 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.amisites.com/search/?type=ds&ts=148 ... earchTerms}
SearchScopes: HKU\S-1-5-21-2370912473-469425822-2799426420-1002 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.amisites.com/search/?type=ds&ts=148 ... earchTerms}
SearchScopes: HKU\S-1-5-21-2370912473-469425822-2799426420-1002 -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL =
StartMenuInternet: IEXPLORE.EXE - c:\program files\internet explorer\iexplore.exe hxxp://www.startpageing123.com/?type=sc&ts=148 ... 2_W3P2FY58
Edge HomeButtonPage: HKU\S-1-5-21-2370912473-469425822-2799426420-1002 -> hxxp://www.amisites.com/?type=hp&ts=1486373569 ... 2_W3P2FY58
FF NewTab: Mozilla\Firefox\Profiles\y652r2ae.default -> hxxp://www.luckysearch123.com?type=hp&ts=14865 ... 7q8weg2w8t
FF Homepage: Mozilla\Firefox\Profiles\y652r2ae.default -> hxxp://www.startpageing123.com/?type=hp&ts=148 ... 2_W3P2FY58
StartMenuInternet: FIREFOX.EXE - c:\program files (x86)\mozilla firefox\firefox.exe hxxp://www.startpageing123.com/?type=sc&ts=148 ... 2_W3P2FY58
CHR dev: Chrome dev build gedetecteerd! <======= AANDACHT
R2 Archer; C:\Program Files (x86)\WinArcher\Archer.dll [760320 2017-02-10] () [Bestand niet getekend]
R2 bilibili; C:\Program Files (x86)\bilibili\bilibili.dll [122880 2017-02-14] () [Bestand niet getekend]
R2 GubedZL; C:\Program Files (x86)\Gubed\GubedZL.dll [118272 2017-02-04] () [Bestand niet getekend]
R2 GubZL; C:\Program Files (x86)\Gub\GubZL.dll [122880 2017-02-09] () [Bestand niet getekend]
R3 iThemes5; C:\Program Files (x86)\Common Files\Services\iThemes.dll [459264 2017-02-13] () [Bestand niet getekend] <==== AANDACHT
R2 Themes; C:\WINDOWS\system32\themeservice.dll [70656 2016-07-16] (Microsoft Corporation) [DependOnService: iThemes5]<==== AANDACHT
R2 WinSAPSvc; C:\Users\Rita\AppData\Roaming\WinSAPSvc\WinSAP.dll [184832 2017-02-24] (TODO: <Company name>) [Bestand niet getekend]
R2 WinSnare; C:\Users\Rita\AppData\Roaming\WinSnare\WinSnare.dll [778752 2017-02-24] (InterSect Alliance Pty Ltd) [Bestand niet getekend]
S2 ed2kidle; "C:\Program Files (x86)\amuleCe\ed2k.exe" -downloadwhenidle [X]
S3 avchv; \SystemRoot\system32\DRIVERS\avchv.sys [X]
S0 MBAMSwissArmy; system32\drivers\MBAMSwissArmy.sys [X]
S3 SmbDrv; \SystemRoot\System32\drivers\Smb_driver_AMDASF.sys [X]
S3 SmbDrvI; \SystemRoot\System32\drivers\Smb_driver_Intel.sys [X]
S1 tukxjbng; \??\C:\WINDOWS\system32\drivers\tukxjbng.sys [X]
2017-02-24 09:05 - 2017-02-24 09:05 - 00000000 ____D C:\Users\Rita\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\amuleC
2017-02-24 09:05 - 2017-02-24 09:05 - 00000000 ____D C:\Users\Rita\AppData\Roaming\aMule
2017-02-24 09:05 - 2017-02-24 09:05 - 00000000 ____D C:\Program Files (x86)\WinSnare(4.1.6)
2017-02-24 09:05 - 2017-02-24 09:05 - 00000000 ____D C:\Program Files (x86)\amuleCexx
2017-02-21 05:02 - 2017-02-21 07:02 - 00000000 ____D C:\Program Files\wwchromek3
2017-02-14 14:37 - 2017-02-24 09:26 - 00000000 ____D C:\Users\Rita\AppData\Roaming\WinSAPSvc
2017-02-14 14:37 - 2017-02-14 14:37 - 00000000 ____D C:\Program Files (x86)\bilibili
2017-02-09 11:37 - 2017-02-20 11:11 - 00000000 ____D C:\Program Files (x86)\WinSnare(4.1.0)
2017-02-06 10:52 - 2017-02-06 10:52 - 03516080 _____ (Enigma Software Group USA, LLC.) C:\Users\Rita\Downloads\sh-remover.exe
2017-02-06 10:19 - 2017-02-24 12:32 - 00000000 ____D C:\Users\Rita\AppData\Roaming\WinSnare
2017-02-06 10:19 - 2017-02-08 11:20 - 00000000 ____D C:\Program Files (x86)\WinSnare(4.0.9)
2017-02-06 10:19 - 2017-02-06 10:19 - 00000000 ____D C:\Program Files (x86)\Gub
2017-02-03 15:05 - 2017-02-03 15:05 - 00000000 ____D C:\Program Files (x86)\Gubed
2017-02-06 10:17 - 2017-01-04 14:25 - 00000000 ____D C:\Program Files (x86)\7cveykf6
2017-02-03 22:29 - 2014-05-02 18:17 - 00000085 _____ C:\WINDOWS\wininit.ini
2017-02-06 17:55 - 2017-01-03 19:53 - 00000000 ____D C:\Program Files (x86)\Ocecult
C:\ProgramData\wintools
c:\program files (x86)\winarcher
C:\Program Files (x86)\Common Files\Services\iThemes.dll
C:\ProgramData\Convertor
C:\WINDOWS\Tasks\CNPMUIBY.job
C:\Users\Rita\AppData\Roaming\CNPMUIBY.exe
C:\WINDOWS\Tasks\ZRHPV.job
C:\Users\Rita\AppData\Roaming\ZRHPV.exe
Task: {03526C99-3349-4342-B3DF-AEFFF442C319} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> Geen bestand <==== AANDACHT
Task: {1083B94B-A02A-46A5-970E-F99837D421E2} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> Geen bestand <==== AANDACHT
Task: {28096E47-B52C-42C5-8A61-F85C12913536} - \globalUpdateUpdateTaskMachineUA1cffdf5c420f8f5 -> Geen bestand <==== AANDACHT
Task: {3014E785-AC78-4C3E-A41B-7899280DCA83} - \Super Optimizer Schedule -> Geen bestand <==== AANDACHT
Task: {39276186-E80B-457B-AF92-864E28C87DAE} - System32\Tasks\WinTOOL => C:\ProgramData\wintools\WintoolUprI.exe [2017-01-18] ()
Task: {3F2FEEA1-7F02-4F0B-9D9D-D7939400EA5A} - System32\Tasks\{6FE9B310-0CE2-4C7A-8B77-B2A6498B0700} => pcalua.exe -a "C:\Program Files (x86)\Linkey\uninstall.exe"
Task: {41537B8D-4567-48C6-9936-5FE174FFE0BC} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> Geen bestand <==== AANDACHT
Task: {458DB6B1-33B3-4338-B1C7-672407A405C7} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> Geen bestand <==== AANDACHT
Task: {4A4A53D2-3BBD-4D1E-8E7C-A8444F89D393} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> Geen bestand <==== AANDACHT
Task: {4B1AACB4-6418-4760-8438-7882E2D068BE} - \globalUpdateUpdateTaskMachineCore1cffdf5c112f5ab -> Geen bestand <==== AANDACHT
Task: {4C0F23CB-E397-4CE9-AD31-5DB89D5D807E} - \Winsta Update -> Geen bestand <==== AANDACHT
Task: {7145D40F-2436-4E75-8C18-1E207FE177E2} - \CCleanerSkipUAC -> Geen bestand <==== AANDACHT
Task: {7369E587-F550-47EB-AB33-91C2306C5602} - System32\Tasks\ZRHPV => C:\Users\Rita\AppData\Roaming\ZRHPV.exe <==== AANDACHT
Task: {7BFC02F4-9B90-493B-AC56-71421B39F84E} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> Geen bestand <==== AANDACHT
Task: {877F2F0E-8972-4C7A-B9DD-AE24FF9C01E6} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> Geen bestand <==== AANDACHT
Task: {B6616827-4055-4908-99EC-B9848D7F2222} - \Tempo Runner osizdvoo -> Geen bestand <==== AANDACHT
Task: {BCA31B11-C400-472F-A138-D3BB036401C7} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> Geen bestand <==== AANDACHT
Task: {BD2C1E53-7248-4A59-AED7-94C4BB5AA297} - System32\Tasks\Ananoward Server => C:\Program Files (x86)\Ocecult\fafiied.exe
Task: {BFD50D19-B0C7-4254-863C-76DFEB8F50B6} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> Geen bestand <==== AANDACHT
Task: {C2ED3488-4F65-4EF8-AD68-8A5DD104044D} - System32\Tasks\zTt => C:\ProgramData\Convertor\Convertor.exe <==== AANDACHT
Task: {C7514129-5B16-42B2-BB83-D3AD0F7C6CF5} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> Geen bestand <==== AANDACHT
Task: {D316CF50-92B6-4722-9441-7188A0A1FBB7} - System32\Tasks\{7AD7F214-FA81-40D2-8A5A-6B3E3088D8FA} => pcalua.exe -a C:\Users\Rita\AppData\Roaming\mystartsearch\UninstallManager.exe -c -ptid=cmi
Task: {E049875B-58C3-44D5-848F-D0A5374017C5} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> Geen bestand <==== AANDACHT
Task: {EF6B3364-6C46-48E2-B66E-0E54C30EA344} - System32\Tasks\{5777954B-8B4F-45A4-83BB-2F7B590AE52C} => pcalua.exe -a C:\Users\Rita\AppData\Local\PriceMeter\uninst.exe -c /uninstall
Task: {F813AB52-E070-4C8D-A0A2-2A7824ED6A0D} - System32\Tasks\CNPMUIBY => C:\Users\Rita\AppData\Roaming\CNPMUIBY.exe <==== AANDACHT
Task: C:\WINDOWS\Tasks\CNPMUIBY.job => C:\Users\Rita\AppData\Roaming\CNPMUIBY.exe <==== AANDACHT
Task: C:\WINDOWS\Tasks\ZRHPV.job => C:\Users\Rita\AppData\Roaming\ZRHPV.exe <==== AANDACHT
ShortcutWithArgument: C:\Users\Rita\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk -> C:\Program Files (x86)\Firefox\Firefox.exe (Mozilla Corporation) -> hxxp://www.amisites.com/?type=sc&ts=1486373569 ... 2_W3P2FY58
ShortcutWithArgument: C:\Users\Rita\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://www.amisites.com/?type=sc&ts=1486373569 ... 2_W3P2FY58
ShortcutWithArgument: C:\Users\Rita\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.amisites.com/?type=sc&ts=1486373569 ... 2_W3P2FY58
ShortcutWithArgument: C:\Users\Rita\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.amisites.com/?type=sc&ts=1486373569 ... 2_W3P2FY58
ShortcutWithArgument: C:\Users\Rita\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Sparta.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://www.amisites.com/?type=sc&ts=1486373569 ... 2_W3P2FY58
ShortcutWithArgument: C:\Users\Rita\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk -> C:\Program Files (x86)\Firefox\Firefox.exe (Mozilla Corporation) -> hxxp://www.amisites.com/?type=sc&ts=1486373569 ... 2_W3P2FY58
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk -> C:\Program Files (x86)\Mapbob\Application\chrome.exe (Google Inc.) -> hxxp://www.amisites.com/?type=sc&ts=1486373569 ... 2_W3P2FY58
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk -> C:\Program Files (x86)\Firefox\Firefox.exe (Mozilla Corporation) -> hxxp://www.amisites.com/?type=sc&ts=1486373569 ... 2_W3P2FY58
ShortcutWithArgument: C:\Users\Public\Desktop\Mozilla Firefox.lnk -> C:\Program Files (x86)\Firefox\Firefox.exe (Mozilla Corporation) -> hxxp://www.amisites.com/?type=sc&ts=1486373569 ... 2_W3P2FY58
EmptyTemp:
end

Ga naar Bestand - Opslaan als.
Kies als locatie bureaublad.
Bij "Bestandsnaam" zet je:fixlist.txt.
Bij "Opslaan als type" selecteer je: Alle bestanden.

Als het goed is staat er nu een text bestand op je bureaublad?

Start de Farbar Recovery Scan Tool.
Als het programma is geopend klik Yes (Ja) bij de disclaimer. (indien nodig)
Druk op de Fix knop.
Er zal u een logbestand aangemaakt worden (fixlog.txt) op dezelfde plaats vanwaar de 'tool' is gestart.
Kopieer en plak de inhoud van de logbestanden in je het volgende bericht.(als de inhoud te groot is voor één bericht plaats het in meerdere berichten)
Groeten abbs
Afbeelding
Member of UNITE (Unified Network of Instructors and Trained Eliminators)

meme-rietje
Lid geworden op: 13 okt 2003, 19:51
Locatie: Zuid-West-Vl.

24 feb 2017, 17:36

Fix resultaat van Farbar Recovery Scan Tool (x64) Versie: 23-02-2017 01
Gestart door Rita (24-02-2017 16:52:09) Run:1
Gestart vanaf C:\Users\Rita\Desktop
Geladen Profielen: Rita (Beschikbare Profielen: Rita)
Boot Modus: Normal
==============================================

fixlist inhoud:
*****************

start
CreateRestorePoint:
CloseProcesses:
ShellExecuteHooks: Geen Naam - {0914E00A-CAAF-11E6-B429-64006A5CFC23} - C:\Users\Rita\AppData\Roaming\Tlosparamerk\Kudidom.dll -> Geen bestand
HKU\S-1-5-21-2370912473-469425822-2799426420-1002\SOFTWARE\Policies\Microsoft\Internet Explorer: Restrictie <======= AANDACHT
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.amisites.com/?type=hp&ts=1486373569 ... 2_W3P2FY58
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.amisites.com/?type=hp&ts=1486373569 ... 2_W3P2FY58
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.amisites.com/search/?type=ds&ts=148 ... earchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.amisites.com/search/?type=ds&ts=148 ... earchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.amisites.com/?type=hp&ts=1486373569 ... 2_W3P2FY58
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.amisites.com/?type=hp&ts=1486373569 ... 2_W3P2FY58
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.amisites.com/search/?type=ds&ts=148 ... earchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.amisites.com/search/?type=ds&ts=148 ... earchTerms}
HKU\S-1-5-21-2370912473-469425822-2799426420-1002\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.amisites.com/?type=hp&ts=1486373569 ... 2_W3P2FY58
HKU\S-1-5-21-2370912473-469425822-2799426420-1002\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.amisites.com/?type=hp&ts=1486373569 ... 2_W3P2FY58
SearchScopes: HKLM -> {25C97E8F-8EAA-45AE-B37F-4AE0F315EC73} URL = hxxp://www.amazon.co.uk/s/ref=azs_osd_ieauk?ie ... earchTerms}
SearchScopes: HKLM -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/1553-29906-12136-18/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms}
SearchScopes: HKU\S-1-5-21-2370912473-469425822-2799426420-1002 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.amisites.com/search/?type=ds&ts=148 ... earchTerms}
SearchScopes: HKU\S-1-5-21-2370912473-469425822-2799426420-1002 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.amisites.com/search/?type=ds&ts=148 ... earchTerms}
SearchScopes: HKU\S-1-5-21-2370912473-469425822-2799426420-1002 -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL =
StartMenuInternet: IEXPLORE.EXE - c:\program files\internet explorer\iexplore.exe hxxp://www.startpageing123.com/?type=sc&ts=148 ... 2_W3P2FY58
Edge HomeButtonPage: HKU\S-1-5-21-2370912473-469425822-2799426420-1002 -> hxxp://www.amisites.com/?type=hp&ts=1486373569 ... 2_W3P2FY58
FF NewTab: Mozilla\Firefox\Profiles\y652r2ae.default -> hxxp://www.luckysearch123.com?type=hp&ts=14865 ... 7q8weg2w8t
FF Homepage: Mozilla\Firefox\Profiles\y652r2ae.default -> hxxp://www.startpageing123.com/?type=hp&ts=148 ... 2_W3P2FY58
StartMenuInternet: FIREFOX.EXE - c:\program files (x86)\mozilla firefox\firefox.exe hxxp://www.startpageing123.com/?type=sc&ts=148 ... 2_W3P2FY58
CHR dev: Chrome dev build gedetecteerd! <======= AANDACHT
R2 Archer; C:\Program Files (x86)\WinArcher\Archer.dll [760320 2017-02-10] () [Bestand niet getekend]
R2 bilibili; C:\Program Files (x86)\bilibili\bilibili.dll [122880 2017-02-14] () [Bestand niet getekend]
R2 GubedZL; C:\Program Files (x86)\Gubed\GubedZL.dll [118272 2017-02-04] () [Bestand niet getekend]
R2 GubZL; C:\Program Files (x86)\Gub\GubZL.dll [122880 2017-02-09] () [Bestand niet getekend]
R3 iThemes5; C:\Program Files (x86)\Common Files\Services\iThemes.dll [459264 2017-02-13] () [Bestand niet getekend] <==== AANDACHT
R2 Themes; C:\WINDOWS\system32\themeservice.dll [70656 2016-07-16] (Microsoft Corporation) [DependOnService: iThemes5]<==== AANDACHT
R2 WinSAPSvc; C:\Users\Rita\AppData\Roaming\WinSAPSvc\WinSAP.dll [184832 2017-02-24] (TODO: <Company name>) [Bestand niet getekend]
R2 WinSnare; C:\Users\Rita\AppData\Roaming\WinSnare\WinSnare.dll [778752 2017-02-24] (InterSect Alliance Pty Ltd) [Bestand niet getekend]
S2 ed2kidle; "C:\Program Files (x86)\amuleCe\ed2k.exe" -downloadwhenidle [X]
S3 avchv; \SystemRoot\system32\DRIVERS\avchv.sys [X]
S0 MBAMSwissArmy; system32\drivers\MBAMSwissArmy.sys [X]
S3 SmbDrv; \SystemRoot\System32\drivers\Smb_driver_AMDASF.sys [X]
S3 SmbDrvI; \SystemRoot\System32\drivers\Smb_driver_Intel.sys [X]
S1 tukxjbng; \??\C:\WINDOWS\system32\drivers\tukxjbng.sys [X]
2017-02-24 09:05 - 2017-02-24 09:05 - 00000000 ____D C:\Users\Rita\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\amuleC
2017-02-24 09:05 - 2017-02-24 09:05 - 00000000 ____D C:\Users\Rita\AppData\Roaming\aMule
2017-02-24 09:05 - 2017-02-24 09:05 - 00000000 ____D C:\Program Files (x86)\WinSnare(4.1.6)
2017-02-24 09:05 - 2017-02-24 09:05 - 00000000 ____D C:\Program Files (x86)\amuleCexx
2017-02-21 05:02 - 2017-02-21 07:02 - 00000000 ____D C:\Program Files\wwchromek3
2017-02-14 14:37 - 2017-02-24 09:26 - 00000000 ____D C:\Users\Rita\AppData\Roaming\WinSAPSvc
2017-02-14 14:37 - 2017-02-14 14:37 - 00000000 ____D C:\Program Files (x86)\bilibili
2017-02-09 11:37 - 2017-02-20 11:11 - 00000000 ____D C:\Program Files (x86)\WinSnare(4.1.0)
2017-02-06 10:52 - 2017-02-06 10:52 - 03516080 _____ (Enigma Software Group USA, LLC.) C:\Users\Rita\Downloads\sh-remover.exe
2017-02-06 10:19 - 2017-02-24 12:32 - 00000000 ____D C:\Users\Rita\AppData\Roaming\WinSnare
2017-02-06 10:19 - 2017-02-08 11:20 - 00000000 ____D C:\Program Files (x86)\WinSnare(4.0.9)
2017-02-06 10:19 - 2017-02-06 10:19 - 00000000 ____D C:\Program Files (x86)\Gub
2017-02-03 15:05 - 2017-02-03 15:05 - 00000000 ____D C:\Program Files (x86)\Gubed
2017-02-06 10:17 - 2017-01-04 14:25 - 00000000 ____D C:\Program Files (x86)\7cveykf6
2017-02-03 22:29 - 2014-05-02 18:17 - 00000085 _____ C:\WINDOWS\wininit.ini
2017-02-06 17:55 - 2017-01-03 19:53 - 00000000 ____D C:\Program Files (x86)\Ocecult
C:\ProgramData\wintools
c:\program files (x86)\winarcher
C:\Program Files (x86)\Common Files\Services\iThemes.dll
C:\ProgramData\Convertor
C:\WINDOWS\Tasks\CNPMUIBY.job
C:\Users\Rita\AppData\Roaming\CNPMUIBY.exe
C:\WINDOWS\Tasks\ZRHPV.job
C:\Users\Rita\AppData\Roaming\ZRHPV.exe
Task: {03526C99-3349-4342-B3DF-AEFFF442C319} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> Geen bestand <==== AANDACHT
Task: {1083B94B-A02A-46A5-970E-F99837D421E2} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> Geen bestand <==== AANDACHT
Task: {28096E47-B52C-42C5-8A61-F85C12913536} - \globalUpdateUpdateTaskMachineUA1cffdf5c420f8f5 -> Geen bestand <==== AANDACHT
Task: {3014E785-AC78-4C3E-A41B-7899280DCA83} - \Super Optimizer Schedule -> Geen bestand <==== AANDACHT
Task: {39276186-E80B-457B-AF92-864E28C87DAE} - System32\Tasks\WinTOOL => C:\ProgramData\wintools\WintoolUprI.exe [2017-01-18] ()
Task: {3F2FEEA1-7F02-4F0B-9D9D-D7939400EA5A} - System32\Tasks\{6FE9B310-0CE2-4C7A-8B77-B2A6498B0700} => pcalua.exe -a "C:\Program Files (x86)\Linkey\uninstall.exe"
Task: {41537B8D-4567-48C6-9936-5FE174FFE0BC} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> Geen bestand <==== AANDACHT
Task: {458DB6B1-33B3-4338-B1C7-672407A405C7} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> Geen bestand <==== AANDACHT
Task: {4A4A53D2-3BBD-4D1E-8E7C-A8444F89D393} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> Geen bestand <==== AANDACHT
Task: {4B1AACB4-6418-4760-8438-7882E2D068BE} - \globalUpdateUpdateTaskMachineCore1cffdf5c112f5ab -> Geen bestand <==== AANDACHT
Task: {4C0F23CB-E397-4CE9-AD31-5DB89D5D807E} - \Winsta Update -> Geen bestand <==== AANDACHT
Task: {7145D40F-2436-4E75-8C18-1E207FE177E2} - \CCleanerSkipUAC -> Geen bestand <==== AANDACHT
Task: {7369E587-F550-47EB-AB33-91C2306C5602} - System32\Tasks\ZRHPV => C:\Users\Rita\AppData\Roaming\ZRHPV.exe <==== AANDACHT
Task: {7BFC02F4-9B90-493B-AC56-71421B39F84E} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> Geen bestand <==== AANDACHT
Task: {877F2F0E-8972-4C7A-B9DD-AE24FF9C01E6} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> Geen bestand <==== AANDACHT
Task: {B6616827-4055-4908-99EC-B9848D7F2222} - \Tempo Runner osizdvoo -> Geen bestand <==== AANDACHT
Task: {BCA31B11-C400-472F-A138-D3BB036401C7} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> Geen bestand <==== AANDACHT
Task: {BD2C1E53-7248-4A59-AED7-94C4BB5AA297} - System32\Tasks\Ananoward Server => C:\Program Files (x86)\Ocecult\fafiied.exe
Task: {BFD50D19-B0C7-4254-863C-76DFEB8F50B6} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> Geen bestand <==== AANDACHT
Task: {C2ED3488-4F65-4EF8-AD68-8A5DD104044D} - System32\Tasks\zTt => C:\ProgramData\Convertor\Convertor.exe <==== AANDACHT
Task: {C7514129-5B16-42B2-BB83-D3AD0F7C6CF5} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> Geen bestand <==== AANDACHT
Task: {D316CF50-92B6-4722-9441-7188A0A1FBB7} - System32\Tasks\{7AD7F214-FA81-40D2-8A5A-6B3E3088D8FA} => pcalua.exe -a C:\Users\Rita\AppData\Roaming\mystartsearch\UninstallManager.exe -c -ptid=cmi
Task: {E049875B-58C3-44D5-848F-D0A5374017C5} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> Geen bestand <==== AANDACHT
Task: {EF6B3364-6C46-48E2-B66E-0E54C30EA344} - System32\Tasks\{5777954B-8B4F-45A4-83BB-2F7B590AE52C} => pcalua.exe -a C:\Users\Rita\AppData\Local\PriceMeter\uninst.exe -c /uninstall
Task: {F813AB52-E070-4C8D-A0A2-2A7824ED6A0D} - System32\Tasks\CNPMUIBY => C:\Users\Rita\AppData\Roaming\CNPMUIBY.exe <==== AANDACHT
Task: C:\WINDOWS\Tasks\CNPMUIBY.job => C:\Users\Rita\AppData\Roaming\CNPMUIBY.exe <==== AANDACHT
Task: C:\WINDOWS\Tasks\ZRHPV.job => C:\Users\Rita\AppData\Roaming\ZRHPV.exe <==== AANDACHT
ShortcutWithArgument: C:\Users\Rita\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk -> C:\Program Files (x86)\Firefox\Firefox.exe (Mozilla Corporation) -> hxxp://www.amisites.com/?type=sc&ts=1486373569 ... 2_W3P2FY58
ShortcutWithArgument: C:\Users\Rita\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://www.amisites.com/?type=sc&ts=1486373569 ... 2_W3P2FY58
ShortcutWithArgument: C:\Users\Rita\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.amisites.com/?type=sc&ts=1486373569 ... 2_W3P2FY58
ShortcutWithArgument: C:\Users\Rita\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.amisites.com/?type=sc&ts=1486373569 ... 2_W3P2FY58
ShortcutWithArgument: C:\Users\Rita\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Sparta.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://www.amisites.com/?type=sc&ts=1486373569 ... 2_W3P2FY58
ShortcutWithArgument: C:\Users\Rita\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk -> C:\Program Files (x86)\Firefox\Firefox.exe (Mozilla Corporation) -> hxxp://www.amisites.com/?type=sc&ts=1486373569 ... 2_W3P2FY58
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk -> C:\Program Files (x86)\Mapbob\Application\chrome.exe (Google Inc.) -> hxxp://www.amisites.com/?type=sc&ts=1486373569 ... 2_W3P2FY58
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk -> C:\Program Files (x86)\Firefox\Firefox.exe (Mozilla Corporation) -> hxxp://www.amisites.com/?type=sc&ts=1486373569 ... 2_W3P2FY58
ShortcutWithArgument: C:\Users\Public\Desktop\Mozilla Firefox.lnk -> C:\Program Files (x86)\Firefox\Firefox.exe (Mozilla Corporation) -> hxxp://www.amisites.com/?type=sc&ts=1486373569 ... 2_W3P2FY58
EmptyTemp:
end

*****************

Herstelpunt is succesvol gemaakt.
Proces succesvol afgesloten.
HKLM\Software\Microsoft\Windows\CurrentVersion\explorer\ShellExecuteHooks\\{0914E00A-CAAF-11E6-B429-64006A5CFC23} => waarde is succesvol verwijderd.
HKCR\CLSID\{0914E00A-CAAF-11E6-B429-64006A5CFC23} => sleutel niet gevonden.
HKU\S-1-5-21-2370912473-469425822-2799426420-1002\SOFTWARE\Policies\Microsoft\Internet Explorer => sleutel is succesvol verwijderd.
HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => waarde met succes hersteld
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page => waarde met succes hersteld
HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => waarde met succes hersteld
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Search Page => waarde met succes hersteld
HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => waarde met succes hersteld
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL => waarde met succes hersteld
HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => waarde met succes hersteld
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Search_URL => waarde met succes hersteld
HKU\S-1-5-21-2370912473-469425822-2799426420-1002\Software\Microsoft\Internet Explorer\Main\\Start Page => waarde met succes hersteld
HKU\S-1-5-21-2370912473-469425822-2799426420-1002\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL => waarde met succes hersteld
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{25C97E8F-8EAA-45AE-B37F-4AE0F315EC73} => sleutel is succesvol verwijderd.
HKCR\CLSID\{25C97E8F-8EAA-45AE-B37F-4AE0F315EC73} => sleutel niet gevonden.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC} => sleutel is succesvol verwijderd.
HKCR\CLSID\{D944BB61-2E34-4DBF-A683-47E505C587DC} => sleutel niet gevonden.
HKU\S-1-5-21-2370912473-469425822-2799426420-1002\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => waarde is succesvol verwijderd.
HKU\S-1-5-21-2370912473-469425822-2799426420-1002\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => sleutel is succesvol verwijderd.
HKCR\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => sleutel niet gevonden.
HKU\S-1-5-21-2370912473-469425822-2799426420-1002\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC} => sleutel is succesvol verwijderd.
HKCR\CLSID\{D944BB61-2E34-4DBF-A683-47E505C587DC} => sleutel niet gevonden.
HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => waarde met succes hersteld
HKU\S-1-5-21-2370912473-469425822-2799426420-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\Main\\HomeButtonPage => waarde is succesvol verwijderd.
Firefox "newtab" is succesvol verwijderd.
Firefox "homepage" is succesvol verwijderd.
HKLM\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command\\Default => waarde met succes hersteld
CHR dev: Chrome dev build gedetecteerd! <======= AANDACHT => Fout: Geen automatische fix gevonden voor dit item.
HKLM\System\CurrentControlSet\Services\Archer => sleutel is succesvol verwijderd.
Archer => dienst is succesvol verwijderd.
HKLM\System\CurrentControlSet\Services\bilibili => sleutel is succesvol verwijderd.
bilibili => dienst is succesvol verwijderd.
HKLM\System\CurrentControlSet\Services\GubedZL => sleutel is succesvol verwijderd.
GubedZL => dienst is succesvol verwijderd.
HKLM\System\CurrentControlSet\Services\GubZL => sleutel is succesvol verwijderd.
GubZL => dienst is succesvol verwijderd.
HKLM\System\CurrentControlSet\Services\iThemes5 => sleutel is succesvol verwijderd.
iThemes5 => dienst is succesvol verwijderd.
HKLM\System\CurrentControlSet\Services\Themes\\DependOnService => waarde is succesvol verwijderd.
HKLM\System\CurrentControlSet\Services\Themes\\DependOnService => waarde niet gevonden.
WinSAPSvc => Kon service niet stoppen.
HKLM\System\CurrentControlSet\Services\WinSAPSvc => sleutel is succesvol verwijderd.
WinSAPSvc => dienst is succesvol verwijderd.
WinSnare => Kon service niet stoppen.
HKLM\System\CurrentControlSet\Services\WinSnare => sleutel is succesvol verwijderd.
WinSnare => dienst is succesvol verwijderd.
HKLM\System\CurrentControlSet\Services\ed2kidle => sleutel is succesvol verwijderd.
ed2kidle => dienst is succesvol verwijderd.
HKLM\System\CurrentControlSet\Services\avchv => sleutel is succesvol verwijderd.
avchv => dienst is succesvol verwijderd.
HKLM\System\CurrentControlSet\Services\MBAMSwissArmy => sleutel is succesvol verwijderd.
MBAMSwissArmy => dienst is succesvol verwijderd.
HKLM\System\CurrentControlSet\Services\SmbDrv => sleutel is succesvol verwijderd.
SmbDrv => dienst is succesvol verwijderd.
HKLM\System\CurrentControlSet\Services\SmbDrvI => sleutel is succesvol verwijderd.
SmbDrvI => dienst is succesvol verwijderd.
HKLM\System\CurrentControlSet\Services\tukxjbng => sleutel is succesvol verwijderd.
tukxjbng => dienst is succesvol verwijderd.
C:\Users\Rita\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\amuleC => is succesvol verplaatst.
C:\Users\Rita\AppData\Roaming\aMule => is succesvol verplaatst.
C:\Program Files (x86)\WinSnare(4.1.6) => is succesvol verplaatst.
C:\Program Files (x86)\amuleCexx => is succesvol verplaatst.
C:\Program Files\wwchromek3 => is succesvol verplaatst.

"C:\Users\Rita\AppData\Roaming\WinSAPSvc" map verplaatsing:

Kon niet verplaatsen "C:\Users\Rita\AppData\Roaming\WinSAPSvc" => Gepland te verplaatsen bij herstart.

C:\Program Files (x86)\bilibili => is succesvol verplaatst.
C:\Program Files (x86)\WinSnare(4.1.0) => is succesvol verplaatst.
C:\Users\Rita\Downloads\sh-remover.exe => is succesvol verplaatst.
C:\Users\Rita\AppData\Roaming\WinSnare => is succesvol verplaatst.
C:\Program Files (x86)\WinSnare(4.0.9) => is succesvol verplaatst.
C:\Program Files (x86)\Gub => is succesvol verplaatst.
C:\Program Files (x86)\Gubed => is succesvol verplaatst.
C:\Program Files (x86)\7cveykf6 => is succesvol verplaatst.
C:\WINDOWS\wininit.ini => is succesvol verplaatst.
C:\Program Files (x86)\Ocecult => is succesvol verplaatst.
C:\ProgramData\wintools => is succesvol verplaatst.
c:\program files (x86)\winarcher => is succesvol verplaatst.
C:\Program Files (x86)\Common Files\Services\iThemes.dll => is succesvol verplaatst.
"C:\ProgramData\Convertor" => niet gevonden.
C:\WINDOWS\Tasks\CNPMUIBY.job => is succesvol verplaatst.
"C:\Users\Rita\AppData\Roaming\CNPMUIBY.exe" => niet gevonden.
C:\WINDOWS\Tasks\ZRHPV.job => is succesvol verplaatst.
"C:\Users\Rita\AppData\Roaming\ZRHPV.exe" => niet gevonden.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{03526C99-3349-4342-B3DF-AEFFF442C319} => sleutel is succesvol verwijderd.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{03526C99-3349-4342-B3DF-AEFFF442C319} => sleutel is succesvol verwijderd.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxconfig => sleutel is succesvol verwijderd.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{1083B94B-A02A-46A5-970E-F99837D421E2} => sleutel is succesvol verwijderd.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1083B94B-A02A-46A5-970E-F99837D421E2} => sleutel is succesvol verwijderd.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Logon-5d => sleutel is succesvol verwijderd.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{28096E47-B52C-42C5-8A61-F85C12913536} => sleutel is succesvol verwijderd.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{28096E47-B52C-42C5-8A61-F85C12913536} => sleutel is succesvol verwijderd.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\globalUpdateUpdateTaskMachineUA1cffdf5c420f8f5 => sleutel niet gevonden.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{3014E785-AC78-4C3E-A41B-7899280DCA83} => sleutel is succesvol verwijderd.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3014E785-AC78-4C3E-A41B-7899280DCA83} => sleutel is succesvol verwijderd.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Super Optimizer Schedule => sleutel niet gevonden.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{39276186-E80B-457B-AF92-864E28C87DAE} => sleutel is succesvol verwijderd.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{39276186-E80B-457B-AF92-864E28C87DAE} => sleutel is succesvol verwijderd.
C:\WINDOWS\System32\Tasks\WinTOOL => is succesvol verplaatst.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WinTOOL => sleutel is succesvol verwijderd.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{3F2FEEA1-7F02-4F0B-9D9D-D7939400EA5A} => sleutel is succesvol verwijderd.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3F2FEEA1-7F02-4F0B-9D9D-D7939400EA5A} => sleutel is succesvol verwijderd.
C:\WINDOWS\System32\Tasks\{6FE9B310-0CE2-4C7A-8B77-B2A6498B0700} => is succesvol verplaatst.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{6FE9B310-0CE2-4C7A-8B77-B2A6498B0700} => sleutel is succesvol verwijderd.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{41537B8D-4567-48C6-9936-5FE174FFE0BC} => sleutel is succesvol verwijderd.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{41537B8D-4567-48C6-9936-5FE174FFE0BC} => sleutel is succesvol verwijderd.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\launchtrayprocess => sleutel is succesvol verwijderd.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{458DB6B1-33B3-4338-B1C7-672407A405C7} => sleutel is succesvol verwijderd.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{458DB6B1-33B3-4338-B1C7-672407A405C7} => sleutel is succesvol verwijderd.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent => sleutel is succesvol verwijderd.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{4A4A53D2-3BBD-4D1E-8E7C-A8444F89D393} => sleutel is succesvol verwijderd.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4A4A53D2-3BBD-4D1E-8E7C-A8444F89D393} => sleutel is succesvol verwijderd.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd => sleutel is succesvol verwijderd.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{4B1AACB4-6418-4760-8438-7882E2D068BE} => sleutel is succesvol verwijderd.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4B1AACB4-6418-4760-8438-7882E2D068BE} => sleutel is succesvol verwijderd.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\globalUpdateUpdateTaskMachineCore1cffdf5c112f5ab => sleutel niet gevonden.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{4C0F23CB-E397-4CE9-AD31-5DB89D5D807E} => sleutel is succesvol verwijderd.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4C0F23CB-E397-4CE9-AD31-5DB89D5D807E} => sleutel is succesvol verwijderd.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Winsta Update => sleutel niet gevonden.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{7145D40F-2436-4E75-8C18-1E207FE177E2} => sleutel is succesvol verwijderd.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7145D40F-2436-4E75-8C18-1E207FE177E2} => sleutel is succesvol verwijderd.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\CCleanerSkipUAC => sleutel niet gevonden.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{7369E587-F550-47EB-AB33-91C2306C5602} => sleutel is succesvol verwijderd.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7369E587-F550-47EB-AB33-91C2306C5602} => sleutel is succesvol verwijderd.
C:\WINDOWS\System32\Tasks\ZRHPV => is succesvol verplaatst.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ZRHPV => sleutel is succesvol verwijderd.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{7BFC02F4-9B90-493B-AC56-71421B39F84E} => sleutel is succesvol verwijderd.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7BFC02F4-9B90-493B-AC56-71421B39F84E} => sleutel is succesvol verwijderd.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d => sleutel is succesvol verwijderd.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{877F2F0E-8972-4C7A-B9DD-AE24FF9C01E6} => sleutel is succesvol verwijderd.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{877F2F0E-8972-4C7A-B9DD-AE24FF9C01E6} => sleutel is succesvol verwijderd.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d => sleutel is succesvol verwijderd.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{B6616827-4055-4908-99EC-B9848D7F2222} => sleutel is succesvol verwijderd.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B6616827-4055-4908-99EC-B9848D7F2222} => sleutel is succesvol verwijderd.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Tempo Runner osizdvoo => sleutel niet gevonden.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{BCA31B11-C400-472F-A138-D3BB036401C7} => sleutel is succesvol verwijderd.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BCA31B11-C400-472F-A138-D3BB036401C7} => sleutel is succesvol verwijderd.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Time-5d => sleutel is succesvol verwijderd.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{BD2C1E53-7248-4A59-AED7-94C4BB5AA297} => sleutel is succesvol verwijderd.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BD2C1E53-7248-4A59-AED7-94C4BB5AA297} => sleutel is succesvol verwijderd.
C:\WINDOWS\System32\Tasks\Ananoward Server => is succesvol verplaatst.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Ananoward Server => sleutel is succesvol verwijderd.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{BFD50D19-B0C7-4254-863C-76DFEB8F50B6} => sleutel is succesvol verwijderd.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BFD50D19-B0C7-4254-863C-76DFEB8F50B6} => sleutel is succesvol verwijderd.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d => sleutel is succesvol verwijderd.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{C2ED3488-4F65-4EF8-AD68-8A5DD104044D} => sleutel is succesvol verwijderd.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C2ED3488-4F65-4EF8-AD68-8A5DD104044D} => sleutel is succesvol verwijderd.
C:\WINDOWS\System32\Tasks\zTt => is succesvol verplaatst.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\zTt => sleutel is succesvol verwijderd.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{C7514129-5B16-42B2-BB83-D3AD0F7C6CF5} => sleutel is succesvol verwijderd.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C7514129-5B16-42B2-BB83-D3AD0F7C6CF5} => sleutel is succesvol verwijderd.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B => sleutel is succesvol verwijderd.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{D316CF50-92B6-4722-9441-7188A0A1FBB7} => sleutel is succesvol verwijderd.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D316CF50-92B6-4722-9441-7188A0A1FBB7} => sleutel is succesvol verwijderd.
C:\WINDOWS\System32\Tasks\{7AD7F214-FA81-40D2-8A5A-6B3E3088D8FA} => is succesvol verplaatst.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{7AD7F214-FA81-40D2-8A5A-6B3E3088D8FA} => sleutel is succesvol verwijderd.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{E049875B-58C3-44D5-848F-D0A5374017C5} => sleutel is succesvol verwijderd.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E049875B-58C3-44D5-848F-D0A5374017C5} => sleutel is succesvol verwijderd.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxcontent => sleutel is succesvol verwijderd.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{EF6B3364-6C46-48E2-B66E-0E54C30EA344} => sleutel is succesvol verwijderd.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{EF6B3364-6C46-48E2-B66E-0E54C30EA344} => sleutel is succesvol verwijderd.
C:\WINDOWS\System32\Tasks\{5777954B-8B4F-45A4-83BB-2F7B590AE52C} => is succesvol verplaatst.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{5777954B-8B4F-45A4-83BB-2F7B590AE52C} => sleutel is succesvol verwijderd.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{F813AB52-E070-4C8D-A0A2-2A7824ED6A0D} => sleutel is succesvol verwijderd.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F813AB52-E070-4C8D-A0A2-2A7824ED6A0D} => sleutel is succesvol verwijderd.
C:\WINDOWS\System32\Tasks\CNPMUIBY => is succesvol verplaatst.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\CNPMUIBY => sleutel is succesvol verwijderd.
C:\WINDOWS\Tasks\CNPMUIBY.job => niet gevonden.
C:\WINDOWS\Tasks\ZRHPV.job => niet gevonden.
C:\Users\Rita\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk => snelkoppeling argument is succesvol verwijderd..
C:\Users\Rita\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk => snelkoppeling argument is succesvol verwijderd..
C:\Users\Rita\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Internet Explorer.lnk => snelkoppeling argument is succesvol verwijderd..
C:\Users\Rita\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk => snelkoppeling argument is succesvol verwijderd..
C:\Users\Rita\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Sparta.lnk => snelkoppeling argument is succesvol verwijderd..
C:\Users\Rita\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk => snelkoppeling argument is succesvol verwijderd..
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk => snelkoppeling argument is succesvol verwijderd..
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk => snelkoppeling argument is succesvol verwijderd..
C:\Users\Public\Desktop\Mozilla Firefox.lnk => snelkoppeling argument is succesvol verwijderd..

=========== EmptyTemp: ==========

BITS transfer queue => 3613488 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 50910188 B
Java, Flash, Steam htmlcache => 11829 B
Windows/system/drivers => 162221293 B
Edge => 8292528 B
Chrome => 0 B
Firefox => 412847865 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Default => 7680 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 2658313 B
systemprofile32 => 172217764 B
LocalService => 293754 B
NetworkService => 378376 B
Rita => 1361361777 B

RecycleBin => 0 B
EmptyTemp: => 2 GB tijdelijke gegevens verwijderd.

================================

Resultaat van geplande bestanden te verplaatsen (Boot Modus: Normal) (Datum&Tijd: 24-02-2017 17:30:43)

C:\Users\Rita\AppData\Roaming\WinSAPSvc => is succesvol verplaatst.

==== Eind van Fixlog 17:30:50 ====
Groetjes van meme-rietje,
het is gemakkelijker op te geven dan door te gaan

abbs
Lid geworden op: 16 dec 2016, 13:49
Locatie: Leidschendam
Contacteer:

24 feb 2017, 18:16

Hallo,

Dat heb je netjes uitgevoerd, we gaan de volgende stap doen.
Voer nu AdwCleaner eens uit.
Canadees heeft een mooie handleiding gemaakt: http://www.seniorennet.be/forum/viewtopic.php?t=194247

Voer die uit en plaats de inhoud van het verkregen logje in je volgende bericht.
Groeten abbs
Afbeelding
Member of UNITE (Unified Network of Instructors and Trained Eliminators)

meme-rietje
Lid geworden op: 13 okt 2003, 19:51
Locatie: Zuid-West-Vl.

24 feb 2017, 22:49

# AdwCleaner v6.043 - Logbestand aangemaakt 24/02/2017 op 21:57:28
# Bijgewerkt op 27/01/2017 door Malwarebytes
# Database : 2017-02-24.1 [Lokaal]
# Besturingssysteem : Windows 10 Home (X64)
# Gebruikersnaam : Rita - RVO001
# Gestart vanuit : C:\Users\Rita\Documents\Mijn Downloads\17-02-24-app's spyware\adwcleaner\adwcleaner_6.043.exe
# Mode: Verwijderen
# Ondersteuning : https://www.malwarebytes.com/support



***** [ Services ] *****



***** [ Mappen ] *****



***** [ Bestanden ] *****

[-] Bestand verwijderd: C:\Users\Public\Documents\temp.dat


***** [ DLL ] *****



***** [ WMI ] *****



***** [ Snelkoppelingen ] *****



***** [ Geplande Taken ] *****



***** [ Register ] *****

[-] Sleutel verwijderd: HKLM\SOFTWARE\Classes\CLSID\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
[-] Sleutel verwijderd: HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
[-] Sleutel verwijderd: HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
[-] Sleutel verwijderd: HKLM\SOFTWARE\Classes\CLSID\{933B95E2-E7B7-4AD9-B952-7AC336682AE3}
[-] Sleutel verwijderd: HKLM\SOFTWARE\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}
[-] Sleutel verwijderd: HKLM\SOFTWARE\Classes\CLSID\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
[-] Sleutel verwijderd: HKLM\SOFTWARE\Classes\CLSID\{459DD0F7-0D55-D3DC-67BC-E6BE37E9D762}
[-] Sleutel verwijderd: HKLM\SOFTWARE\Classes\CLSID\{B2BC04DF-EFBD-409A-95CA-36874E5AB92A}
[-] Sleutel verwijderd: HKLM\SOFTWARE\Classes\CLSID\{CA3A5461-96B5-46DD-9341-5350D3C94615}
[-] Sleutel verwijderd: HKLM\SOFTWARE\Classes\CLSID\{BD6ECB00-7C4A-4F97-B425-44117F2A7AAE}
[-] Sleutel verwijderd: HKLM\SOFTWARE\Classes\CLSID\{E4ADC61E-D06A-4E0E-8582-78C809CC8450}
[-] Sleutel verwijderd: HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
[-] Sleutel verwijderd: HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94}
[-] Sleutel verwijderd: HKLM\SOFTWARE\Classes\TypeLib\{FA6468D2-FAA4-4951-A53B-2A5CF9CC0A36}
[-] Sleutel verwijderd: HKLM\SOFTWARE\Classes\TypeLib\{4BC8AD89-AC5F-4DBD-A38F-C355C7DD33D7}
[-] Sleutel verwijderd: HKLM\SOFTWARE\Classes\TypeLib\{EB2BEAEF-150C-4DE4-9D09-F16403C22769}
[-] Sleutel verwijderd: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}
[-] Sleutel verwijderd: HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{BD6ECB00-7C4A-4F97-B425-44117F2A7AAE}
[-] Sleutel verwijderd: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233}
[-] Sleutel verwijderd: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{BD6ECB00-7C4A-4F97-B425-44117F2A7AAE}
[-] Sleutel verwijderd: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{54739D49-AC03-4C57-9264-C5195596B3A1}
[-] Sleutel verwijderd: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{95B7759C-8C7F-4BF1-B163-73684A933233}
[-] Sleutel verwijderd: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{6C97A91E-4524-4019-86AF-2AA2D567BF5C}
[-] Sleutel verwijderd: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{B2BC04DF-EFBD-409A-95CA-36874E5AB92A}
[-] Waarde verwijderd: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID [{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}]
[-] Sleutel verwijderd: HKU\.DEFAULT\Software\jhdbca
[-] Sleutel verwijderd: HKU\.DEFAULT\Software\AppDataLow\{12DA0E6F-5543-440C-BAA2-28BF01070AFA}
[-] Sleutel verwijderd: HKU\S-1-5-21-2370912473-469425822-2799426420-1002\Software\genesis
[-] Sleutel verwijderd: HKU\S-1-5-21-2370912473-469425822-2799426420-1002\Software\GlobalUpdate
[-] Sleutel verwijderd: HKU\S-1-5-21-2370912473-469425822-2799426420-1002\Software\ilivid
[-] Sleutel verwijderd: HKU\S-1-5-21-2370912473-469425822-2799426420-1002\Software\InstalledBrowserExtensions
[-] Sleutel verwijderd: HKU\S-1-5-21-2370912473-469425822-2799426420-1002\Software\Linkey
[-] Sleutel verwijderd: HKU\S-1-5-21-2370912473-469425822-2799426420-1002\Software\torch
[-] Sleutel verwijderd: HKU\S-1-5-21-2370912473-469425822-2799426420-1002\Software\tstamptoken
[-] Sleutel verwijderd: HKU\S-1-5-21-2370912473-469425822-2799426420-1002\Software\Tune
[-] Sleutel verwijderd: HKU\S-1-5-21-2370912473-469425822-2799426420-1002\Software\Yahoo\Companion
[-] Sleutel verwijderd: HKU\S-1-5-21-2370912473-469425822-2799426420-1002\Software\Yahoo\YFriendsBar
[-] Sleutel verwijderd: HKU\S-1-5-21-2370912473-469425822-2799426420-1002\Software\WinSnare
[-] Sleutel verwijderd: HKU\S-1-5-21-2370912473-469425822-2799426420-1002\Software\AppDataLow\{12DA0E6F-5543-440C-BAA2-28BF01070AFA}
[-] Sleutel verwijderd: HKU\S-1-5-21-2370912473-469425822-2799426420-1002\Software\AppDataLow\Software\adawarebp
[-] Sleutel verwijderd: HKU\S-1-5-21-2370912473-469425822-2799426420-1002\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Software\MediaPlayerplus
[#] Sleutel verwijderd tijdens herstart: HKU\S-1-5-18\Software\jhdbca
[#] Sleutel verwijderd tijdens herstart: HKU\S-1-5-18\Software\AppDataLow\{12DA0E6F-5543-440C-BAA2-28BF01070AFA}
[#] Sleutel verwijderd tijdens herstart: HKCU\Software\genesis
[#] Sleutel verwijderd tijdens herstart: HKCU\Software\GlobalUpdate
[#] Sleutel verwijderd tijdens herstart: HKCU\Software\ilivid
[#] Sleutel verwijderd tijdens herstart: HKCU\Software\InstalledBrowserExtensions
[#] Sleutel verwijderd tijdens herstart: HKCU\Software\Linkey
[#] Sleutel verwijderd tijdens herstart: HKCU\Software\torch
[#] Sleutel verwijderd tijdens herstart: HKCU\Software\tstamptoken
[#] Sleutel verwijderd tijdens herstart: HKCU\Software\Tune
[#] Sleutel verwijderd tijdens herstart: HKCU\Software\Yahoo\Companion
[#] Sleutel verwijderd tijdens herstart: HKCU\Software\Yahoo\YFriendsBar
[#] Sleutel verwijderd tijdens herstart: HKCU\Software\WinSnare
[#] Sleutel verwijderd tijdens herstart: HKCU\Software\AppDataLow\{12DA0E6F-5543-440C-BAA2-28BF01070AFA}
[#] Sleutel verwijderd tijdens herstart: HKCU\Software\AppDataLow\Software\adawarebp
[-] Sleutel verwijderd: HKLM\SOFTWARE\{12A61307-94CD-4F8E-94BC-918E511FAA81}
[-] Sleutel verwijderd: HKLM\SOFTWARE\{12DA0E6F-5543-440C-BAA2-28BF01070AFA}
[-] Sleutel verwijderd: HKLM\SOFTWARE\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
[-] Sleutel verwijderd: HKLM\SOFTWARE\{77D46E27-0E41-4478-87A6-AABE6FBCF252}
[-] Sleutel verwijderd: HKLM\SOFTWARE\GlobalUpdate
[-] Sleutel verwijderd: HKLM\SOFTWARE\InstalledBrowserExtensions
[-] Sleutel verwijderd: HKLM\SOFTWARE\SiteSee
[-] Sleutel verwijderd: HKLM\SOFTWARE\torch
[-] Sleutel verwijderd: HKLM\SOFTWARE\Tune
[-] Sleutel verwijderd: HKLM\SOFTWARE\Yahoo\Companion
[-] Sleutel verwijderd: HKLM\SOFTWARE\AVG Tuneup
[-] Sleutel verwijderd: HKLM\SOFTWARE\Lavasoft\Web Companion
[-] Sleutel verwijderd: HKLM\SOFTWARE\MaxPower
[-] Sleutel verwijderd: HKLM\SOFTWARE\ScreenShot
[-] Sleutel verwijderd: HKLM\SOFTWARE\jhdbca
[-] Sleutel verwijderd: HKLM\SOFTWARE\WinArcher
[-] Sleutel verwijderd: HKLM\SOFTWARE\amule-custom
[-] Sleutel verwijderd: HKLM\SOFTWARE\amisitesSoftware
[-] Sleutel verwijderd: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SU
[-] Sleutel verwijderd: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Toolbar Cleaner
[-] Sleutel verwijderd: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{B2EFFD4E-D098-4845-9D56-DE75BEB35913}
[#] Sleutel verwijderd tijdens herstart: [x64] HKCU\Software\genesis
[#] Sleutel verwijderd tijdens herstart: [x64] HKCU\Software\GlobalUpdate
[#] Sleutel verwijderd tijdens herstart: [x64] HKCU\Software\ilivid
[#] Sleutel verwijderd tijdens herstart: [x64] HKCU\Software\InstalledBrowserExtensions
[#] Sleutel verwijderd tijdens herstart: [x64] HKCU\Software\Linkey
[#] Sleutel verwijderd tijdens herstart: [x64] HKCU\Software\torch
[#] Sleutel verwijderd tijdens herstart: [x64] HKCU\Software\tstamptoken
[#] Sleutel verwijderd tijdens herstart: [x64] HKCU\Software\Tune
[#] Sleutel verwijderd tijdens herstart: [x64] HKCU\Software\Yahoo\Companion
[#] Sleutel verwijderd tijdens herstart: [x64] HKCU\Software\Yahoo\YFriendsBar
[#] Sleutel verwijderd tijdens herstart: [x64] HKCU\Software\WinSnare
[#] Sleutel verwijderd tijdens herstart: [x64] HKCU\Software\AppDataLow\{12DA0E6F-5543-440C-BAA2-28BF01070AFA}
[#] Sleutel verwijderd tijdens herstart: [x64] HKCU\Software\AppDataLow\Software\adawarebp
[-] Sleutel verwijderd: [x64] HKLM\SOFTWARE\InstalledBrowserExtensions
[-] Sleutel verwijderd: [x64] HKLM\SOFTWARE\jhdbca
[-] Sleutel verwijderd: [x64] HKLM\SOFTWARE\InterSect Alliance
[-] Sleutel verwijderd: HKLM\SOFTWARE\Classes\Installer\Features\F39E5917C417B4041A46F88010121C6E
[-] Sleutel verwijderd: HKLM\SOFTWARE\Classes\Installer\Products\F39E5917C417B4041A46F88010121C6E
[-] Sleutel verwijderd: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\3DCCCD6BD02558446B24CF1C63EC213C
[-] Sleutel verwijderd: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\F39E5917C417B4041A46F88010121C6E
[-] Sleutel verwijderd: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\649A52D257CA5DB4EAAE8BA9EB23E467
[-] Sleutel verwijderd: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B68CE107A2DED706DC47D6BC4BF3C4C1
[-] Sleutel verwijderd: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9C767D9D7BB3F9C4B839FF09B6C80DCF
[-] Sleutel verwijderd: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4EE2F0310EBEC29A0C48C035C43786AA
[-] Sleutel verwijderd: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4B2A47D6F1D42DD81A292C027724D291
[-] Sleutel verwijderd: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\02C076B2283AB74D88D5E4D34BC497FF
[#] Sleutel verwijderd tijdens herstart: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\3DCCCD6BD02558446B24CF1C63EC213C
[#] Sleutel verwijderd tijdens herstart: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\F39E5917C417B4041A46F88010121C6E
[#] Sleutel verwijderd tijdens herstart: [x64] HKLM\SOFTWARE\Classes\Installer\Features\F39E5917C417B4041A46F88010121C6E
[#] Sleutel verwijderd tijdens herstart: [x64] HKLM\SOFTWARE\Classes\Installer\Products\F39E5917C417B4041A46F88010121C6E
[-] Sleutel verwijderd: HKU\S-1-5-21-2370912473-469425822-2799426420-1002\Software\Microsoft\Internet Explorer\SearchScopes\{BDF61FAE-9D19-40F0-8F34-688DEB334CA9}
[#] Sleutel verwijderd tijdens herstart: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{BDF61FAE-9D19-40F0-8F34-688DEB334CA9}
[#] Sleutel verwijderd tijdens herstart: [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{BDF61FAE-9D19-40F0-8F34-688DEB334CA9}
[-] Sleutel verwijderd: HKCU\Software\Microsoft\Internet Explorer\DOMStorage\linkeyproject.com
[-] Sleutel verwijderd: HKCU\Software\Microsoft\Internet Explorer\DOMStorage\www.superfish.com
[-] Sleutel verwijderd: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\amazonbrowserapp.com
[-] Sleutel verwijderd: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\analytics.app.amazonbrowserapp.com
[-] Sleutel verwijderd: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\ask.com
[-] Sleutel verwijderd: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\audiotoaudio.dl.tb.ask.com
[-] Sleutel verwijderd: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\foxi69.tlscdn.com
[-] Sleutel verwijderd: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\land.pckeeper.software
[-] Sleutel verwijderd: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\linkeyproject.com
[-] Sleutel verwijderd: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\pckeeper.software
[-] Sleutel verwijderd: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\superfish.com
[-] Sleutel verwijderd: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\tlscdn.com
[-] Sleutel verwijderd: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\www.superfish.com
[-] Sleutel verwijderd: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\land.pckeeper.software
[-] Sleutel verwijderd: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\pckeeper.software
[-] Sleutel verwijderd: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\land.pckeeper.software
[-] Sleutel verwijderd: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\pckeeper.software
[#] Sleutel verwijderd tijdens herstart: [x64] HKCU\Software\Microsoft\Internet Explorer\DOMStorage\linkeyproject.com
[#] Sleutel verwijderd tijdens herstart: [x64] HKCU\Software\Microsoft\Internet Explorer\DOMStorage\www.superfish.com
[#] Sleutel verwijderd tijdens herstart: [x64] HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\amazonbrowserapp.com
[#] Sleutel verwijderd tijdens herstart: [x64] HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\analytics.app.amazonbrowserapp.com
[#] Sleutel verwijderd tijdens herstart: [x64] HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\ask.com
[#] Sleutel verwijderd tijdens herstart: [x64] HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\audiotoaudio.dl.tb.ask.com
[#] Sleutel verwijderd tijdens herstart: [x64] HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\foxi69.tlscdn.com
[#] Sleutel verwijderd tijdens herstart: [x64] HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\land.pckeeper.software
[#] Sleutel verwijderd tijdens herstart: [x64] HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\linkeyproject.com
[#] Sleutel verwijderd tijdens herstart: [x64] HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\pckeeper.software
[#] Sleutel verwijderd tijdens herstart: [x64] HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\superfish.com
[#] Sleutel verwijderd tijdens herstart: [x64] HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\tlscdn.com
[#] Sleutel verwijderd tijdens herstart: [x64] HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\www.superfish.com
[#] Sleutel verwijderd tijdens herstart: [x64] HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\land.pckeeper.software
[#] Sleutel verwijderd tijdens herstart: [x64] HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\pckeeper.software
[#] Sleutel verwijderd tijdens herstart: [x64] HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\land.pckeeper.software
[#] Sleutel verwijderd tijdens herstart: [x64] HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\pckeeper.software
[-] Waarde verwijderd: HKU\S-1-5-21-2370912473-469425822-2799426420-1002\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run [PriceMeterW]
[-] Waarde verwijderd: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [vProt]
[-] Waarde verwijderd: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32 [vProt]
[-] Waarde verwijderd: HKU\S-1-5-21-2370912473-469425822-2799426420-1002\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run [Web Companion]
[-] Sleutel verwijderd: HKLM\SOFTWARE\Classes\AppID\escortApp.DLL
[-] Sleutel verwijderd: HKLM\SOFTWARE\Classes\AppID\escortEng.DLL
[-] Sleutel verwijderd: HKLM\SOFTWARE\Classes\AppID\escorTlbr.DLL
[-] Sleutel verwijderd: HKLM\SOFTWARE\Classes\Applications\Torch.exe
[-] Sleutel verwijderd: HKLM\SOFTWARE\Classes\Record\{425E7597-03A2-338D-B72A-0E51FFE77A7E}
[-] Sleutel verwijderd: HKLM\SOFTWARE\Classes\Record\{915BB7D5-082E-3B91-B1E0-45B5FDE01F24}
[-] Sleutel verwijderd: HKLM\SOFTWARE\Classes\Record\{2009AF2F-5786-3067-8799-B97F7832FDD6}
[-] Sleutel verwijderd: HKLM\SOFTWARE\Classes\Record\{FB2E65F4-5687-33EF-9BBF-4E3C9C98D3B9}
[-] Sleutel verwijderd: HKLM\SOFTWARE\Clients\StartMenuInternet\Torch
[-] Sleutel verwijderd: HKLM\SOFTWARE\Google\Chrome\NativeMessagingHosts\avgsh
[-] Sleutel verwijderd: HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin
[-] Sleutel verwijderd: HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\webcompanion.com
[-] Waarde verwijderd: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost [WinSAPSvc]
[-] Waarde verwijderd: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost [ArcherGroupEx]
[-] Waarde verwijderd: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost [GubedZLGroupEx]
[-] Waarde verwijderd: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost [GubZLGroEx]
[-] Waarde verwijderd: HKLM\SOFTWARE\Mozilla\Firefox\Extensions [arthurj8283@gmail.com]
[#] Waarde verwijderd tijdens herstart: HKLM\SOFTWARE\Mozilla\Firefox\Extensions [arthurj8283@gmail.com]
[#] Waarde verwijderd tijdens herstart: HKLM\SOFTWARE\Mozilla\Firefox\Extensions [arthurj8283@gmail.com]


***** [ Browsers ] *****

[-] Firefox voorkeuren opgeschoond: "browser.search.searchengine.iconURL" - "hxxp://www.luckysearch123.com/favicon.ico?t=1"
[-] Firefox voorkeuren opgeschoond: "browser.search.searchengine.url" - "hxxp://www.luckysearch123.com/search.php?type= ... earchTerms}"
[-] Firefox voorkeuren opgeschoond: "extensions.jid1-dwtFBkQjb3SIQp@jetpack.allowedURLs" - "[\"charity.org\",\"www.gnome.org\",\"www.cancer.org\",\"www.concern.net\",\"sourceforge.net\",\"www.redcross.org\",\"www.wikipedia.org\",\"chrome.google.com\",\"stackoverflow.com\",\"mybrowseraddon.com\",\"www.worldvision.org\",\"www.latex-project.org\",\"redribbonfoundation.org\",\"www.linuxfoundation.org\",\"www.libreoffice.org\",\"addons.mozilla.org\",\"www.openoffice.org\",\"addons.opera.com\",\"www.unicef.org\",\"www.kernel.org\",\"opensource.org\",\"github.com\",\"nodejs.org\",\"nrdc.org\"]"


*************************

:: "Tracing" sleutels verwijderd
:: Winsock instellingen gereset

*************************

C:\AdwCleaner\AdwCleaner[C0].txt - [19304 bytes] - [24/02/2017 21:57:28]
C:\AdwCleaner\AdwCleaner[S0].txt - [24927 bytes] - [24/02/2017 19:03:33]
C:\AdwCleaner\AdwCleaner[S1].txt - [25001 bytes] - [24/02/2017 19:10:32]
C:\AdwCleaner\AdwCleaner[S2].txt - [17913 bytes] - [24/02/2017 19:37:07]

########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt - [19600 bytes] ##########
Groetjes van meme-rietje,
het is gemakkelijker op te geven dan door te gaan

Danny.
Lid geworden op: 15 mei 2003, 21:42
Locatie: Vlaams Brabant

25 feb 2017, 09:30

@Abbs, sorry voor mijn tussenkomst :oops: , maar ik bewonder mensen die uit dat Chinees dat hier te lezen staat, iets kunnen verstaan, en zomaar eruit halen wat er mis is.

Ik kan voor dergelijke prestaties enkel maar mijn hoed afnemen (maar ik draag er geen :wink: ).

Groetjes

Danny
Windows 11 Home 64-bit, Ram 8GB, Medion Akoya E23403 All-In-One, Microsoft Defender

abbs
Lid geworden op: 16 dec 2016, 13:49
Locatie: Leidschendam
Contacteer:

25 feb 2017, 09:46

@Danny: Dank je wel :)

@meme-rietje:

Dat zijn mooie opruimingen, we gaan nu Malwarebytes gebruiken.
Weer een mooie handleiding van Canadees: http://www.seniorennet.be/forum/viewtopic.php?t=195914

Zorg tijdens de installatie dat je het vinkje weg haalt bij de melding dat je de premium versie 30 dagen gratis kan gebruiken.
Plaats na de scan het ver,kregen logje in je volgende antwoord.
Groeten abbs
Afbeelding
Member of UNITE (Unified Network of Instructors and Trained Eliminators)

meme-rietje
Lid geworden op: 13 okt 2003, 19:51
Locatie: Zuid-West-Vl.

25 feb 2017, 14:52

Malwarebytes
www.malwarebytes.com

-Logboekdetails-
Scandatum: 25-02-17
Scantijd: 12:22
Logboekbestand: 1.txt
Beheerder: Ja

-Software-informatie-
Versie: 3.0.6.1469
Versie componenten: 1.0.50
Update pakketversie: 1.0.1352
Licentie: Verlopen

-Systeeminformatie-
Besturingssysteem: Windows 10
Processor: x64
Bestandssysteem: NTFS
Gebruiker: RVO001\Rita

-Scansamenvatting-
Scantype: Bedreigingsscan
Resultaat: Voltooid
Objecten gescand: 450703
Verstreken tijd: 17 min, 50 sec

-Scanopties-
Geheugen: Ingeschakeld
Opstarten: Ingeschakeld
Bestandssysteem: Ingeschakeld
Archieven: Ingeschakeld
Rootkits: Uitgeschakeld
Heuristiek: Ingeschakeld
POP: Ingeschakeld
POA: Ingeschakeld

-Scandetails-
Proces: 0
(Geen kwaadaardige items gedetecteerd)

Module: 1
Adware.Elex, C:\PROGRAMDATA\MICROSOFT\OFFICE\OFFICE_UPDATE.DLL, In quarantaine, [305], [368112],1.0.1352

Registersleutel: 6
Adware.Ghokswa, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\CHROME.EXE, Verwijder-bij-herstart, [557], [373041],1.0.1352
Adware.Ghokswa, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\CHROME.EXE, Verwijder-bij-herstart, [557], [373041],1.0.1352
Adware.Ghokswa, HKU\S-1-5-21-2370912473-469425822-2799426420-1002_Classes\CHROMEHTML, Verwijder-bij-herstart, [557], [-1],0.0.0
Adware.Elex, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\MSCFG_SVR, Verwijder-bij-herstart, [305], [368111],1.0.1352
Adware.Elex, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\WinSnare, Verwijder-bij-herstart, [305], [360760],1.0.1352
PUP.Optional.StartPage.ShrtCln, HKLM\SOFTWARE\WOW6432NODE\startpageing123Software, Verwijder-bij-herstart, [2241], [373991],1.0.1352

Registerwaarde: 0
(Geen kwaadaardige items gedetecteerd)

Registerdata: 0
(Geen kwaadaardige items gedetecteerd)

Gegevensstroom: 0
(Geen kwaadaardige items gedetecteerd)

Map: 152
Adware.Ghokswa, C:\Program Files (x86)\Mapbob\Application\VisualElements, Verwijder-bij-herstart, [557], [373041],1.0.1352
Adware.Ghokswa, C:\Program Files (x86)\Mapbob\Application\locales, Verwijder-bij-herstart, [557], [373041],1.0.1352
Adware.Ghokswa, C:\Program Files (x86)\Mapbob\Application\bin, Verwijder-bij-herstart, [557], [373041],1.0.1352
Adware.Ghokswa, C:\Program Files (x86)\Mapbob\Application, Verwijder-bij-herstart, [557], [373041],1.0.1352
Adware.Ghokswa, C:\PROGRAM FILES (X86)\Mapbob, Verwijder-bij-herstart, [557], [373041],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5516.1005.0.3_0\cloud_route_details, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5516.1005.0.3_0\_locales\pt_PT, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5516.1005.0.3_0\_locales\pt_BR, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5516.1005.0.3_0\_locales\zh_TW, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5516.1005.0.3_0\_locales\fil, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5516.1005.0.3_0\_locales\ko, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5516.1005.0.3_0\_locales\nb, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5516.1005.0.3_0\_locales\ms, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5516.1005.0.3_0\_locales\mr, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5516.1005.0.3_0\_locales\vi, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5516.1005.0.3_0\_locales\lv, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5516.1005.0.3_0\_locales\lt, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5516.1005.0.3_0\_locales\hi, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5516.1005.0.3_0\_locales\kn, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5516.1005.0.3_0\_locales\ja, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5516.1005.0.3_0\_locales\it, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5516.1005.0.3_0\_locales\id, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5516.1005.0.3_0\_locales\hu, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5516.1005.0.3_0\_locales\hr, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5516.1005.0.3_0\_locales\zh, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5516.1005.0.3_0\_locales\gu, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5516.1005.0.3_0\_locales\fr, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5516.1005.0.3_0\_locales\ml, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5516.1005.0.3_0\_locales\iw, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5516.1005.0.3_0\_locales\am, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5516.1005.0.3_0\_locales\ar, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5516.1005.0.3_0\_locales\da, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5516.1005.0.3_0\_locales\bg, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5516.1005.0.3_0\_locales\bn, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5516.1005.0.3_0\_locales\ca, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5516.1005.0.3_0\_locales\cs, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5516.1005.0.3_0\_locales\fa, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5516.1005.0.3_0\_locales\de, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5516.1005.0.3_0\_locales\el, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5516.1005.0.3_0\_locales\en, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5516.1005.0.3_0\_locales\fi, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5516.1005.0.3_0\_locales\et, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5516.1005.0.3_0\_locales\es, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5516.1005.0.3_0\_locales\nl, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5516.1005.0.3_0\_locales\pl, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5516.1005.0.3_0\_locales\pt, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5516.1005.0.3_0\_locales\ro, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5516.1005.0.3_0\_locales\ru, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5516.1005.0.3_0\_locales\sk, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5516.1005.0.3_0\_locales\sl, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5516.1005.0.3_0\_locales\sr, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5516.1005.0.3_0\_locales\sv, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5516.1005.0.3_0\_locales\sw, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5516.1005.0.3_0\_locales\ta, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5516.1005.0.3_0\_locales\te, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5516.1005.0.3_0\_locales\th, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5516.1005.0.3_0\_locales\tr, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5516.1005.0.3_0\_locales\uk, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5516.1005.0.3_0\cast_setup, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.1_0\_locales\es_419, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5516.1005.0.3_0\_metadata, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.1_0\_locales\zh_CN, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.1_0\_locales\pt_PT, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.1_0\_locales\en_GB, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.1_0\_locales\zh_TW, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.1_0\_locales\pt_BR, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5516.1005.0.3_0\_locales, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.1_0\_locales\fil, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.1_0\_locales\ro, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.1_0\_locales\ru, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.1_0\_locales\sk, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.1_0\_locales\sl, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.1_0\_locales\sr, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.1_0\_locales\sv, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.1_0\_locales\th, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.1_0\_locales\tr, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.1_0\_locales\uk, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.1_0\_locales\vi, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.1_0\_locales\ja, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.1_0\_locales\ca, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.1_0\_locales\bg, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.1_0\_locales\cs, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.1_0\_locales\da, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.1_0\_locales\de, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.1_0\_locales\el, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.1_0\_locales\en, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.1_0\_locales\es, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.1_0\_locales\et, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.1_0\_locales\fi, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.1_0\_locales\fr, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.1_0\_locales\hi, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.1_0\_locales\hr, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.1_0\_locales\hu, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.1_0\_locales\id, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.1_0\_locales\it, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.1_0\_locales\ko, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.1_0\_locales\lt, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.1_0\_locales\lv, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.1_0\_locales\nb, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.1_0\_locales\nl, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.1_0\_locales\pl, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.1_0\_metadata, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.1_0\_locales, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\bpiopmneeadfapifejkfpahpljkicpik\1.1.6_0\background, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.1_0\images, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\bpiopmneeadfapifejkfpahpljkicpik\1.1.6_0\content, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5516.1005.0.3_0, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.1_0\html, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.1_0\css, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Sync Extension Settings\pkedcjkdefgpdelpbcmbmeomcjbeemfm, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.1_0, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\bpiopmneeadfapifejkfpahpljkicpik\1.1.6_0, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\CertificateTransparency\311\_platform_specific\all\sths, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\bpiopmneeadfapifejkfpahpljkicpik, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\CertificateTransparency\311\_platform_specific\all, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\CertificateTransparency\311\_platform_specific, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\data_reduction_proxy_leveldb, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\EVWhitelist\7\_platform_specific\all, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\EVWhitelist\7\_platform_specific, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Sync Extension Settings, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\CertificateTransparency\311, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\JumpListIconsOld, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extension State, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extension Rules, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\CertificateTransparency, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Session Storage, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\EVWhitelist\7\_metadata, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\PepperFlash\24.0.0.221, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\JumpListIcons, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Local Storage, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\ShaderCache\GPUCache, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Media Cache, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\FileTypePolicies\8, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\SwReporter\16.92.2, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\GPUCache, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\FileTypePolicies, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\EVWhitelist\7, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\OriginTrials, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\PepperFlash, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\EVWhitelist, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\ShaderCache, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\SwiftShader, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\SwReporter, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Crashpad, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\USERS\RITA\APPDATA\LOCAL\Mapbob, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Elex, C:\USERS\RITA\APPDATA\LOCAL\Sunoghtthwiph, Verwijder-bij-herstart, [305], [362262],1.0.1352

Bestand: 517
Adware.Ghokswa, C:\Program Files (x86)\Mapbob\Application\locales\gu.pak, Verwijder-bij-herstart, [557], [373041],1.0.1352
Adware.Ghokswa, C:\Program Files (x86)\Mapbob\Application\locales\am.pak, Verwijder-bij-herstart, [557], [373041],1.0.1352
Adware.Ghokswa, C:\Program Files (x86)\Mapbob\Application\locales\ar.pak, Verwijder-bij-herstart, [557], [373041],1.0.1352
Adware.Ghokswa, C:\Program Files (x86)\Mapbob\Application\locales\bg.pak, Verwijder-bij-herstart, [557], [373041],1.0.1352
Adware.Ghokswa, C:\Program Files (x86)\Mapbob\Application\locales\bn.pak, Verwijder-bij-herstart, [557], [373041],1.0.1352
Adware.Ghokswa, C:\Program Files (x86)\Mapbob\Application\locales\ca.pak, Verwijder-bij-herstart, [557], [373041],1.0.1352
Adware.Ghokswa, C:\Program Files (x86)\Mapbob\Application\locales\cs.pak, Verwijder-bij-herstart, [557], [373041],1.0.1352
Adware.Ghokswa, C:\Program Files (x86)\Mapbob\Application\locales\da.pak, Verwijder-bij-herstart, [557], [373041],1.0.1352
Adware.Ghokswa, C:\Program Files (x86)\Mapbob\Application\locales\de.pak, Verwijder-bij-herstart, [557], [373041],1.0.1352
Adware.Ghokswa, C:\Program Files (x86)\Mapbob\Application\locales\el.pak, Verwijder-bij-herstart, [557], [373041],1.0.1352
Adware.Ghokswa, C:\Program Files (x86)\Mapbob\Application\locales\en-GB.pak, Verwijder-bij-herstart, [557], [373041],1.0.1352
Adware.Ghokswa, C:\Program Files (x86)\Mapbob\Application\locales\en-US.pak, Verwijder-bij-herstart, [557], [373041],1.0.1352
Adware.Ghokswa, C:\Program Files (x86)\Mapbob\Application\locales\es-419.pak, Verwijder-bij-herstart, [557], [373041],1.0.1352
Adware.Ghokswa, C:\Program Files (x86)\Mapbob\Application\locales\es.pak, Verwijder-bij-herstart, [557], [373041],1.0.1352
Adware.Ghokswa, C:\Program Files (x86)\Mapbob\Application\locales\et.pak, Verwijder-bij-herstart, [557], [373041],1.0.1352
Adware.Ghokswa, C:\Program Files (x86)\Mapbob\Application\locales\fa.pak, Verwijder-bij-herstart, [557], [373041],1.0.1352
Adware.Ghokswa, C:\Program Files (x86)\Mapbob\Application\locales\fake-bidi.pak, Verwijder-bij-herstart, [557], [373041],1.0.1352
Adware.Ghokswa, C:\Program Files (x86)\Mapbob\Application\locales\fi.pak, Verwijder-bij-herstart, [557], [373041],1.0.1352
Adware.Ghokswa, C:\Program Files (x86)\Mapbob\Application\locales\fil.pak, Verwijder-bij-herstart, [557], [373041],1.0.1352
Adware.Ghokswa, C:\Program Files (x86)\Mapbob\Application\locales\fr.pak, Verwijder-bij-herstart, [557], [373041],1.0.1352
Adware.Ghokswa, C:\Program Files (x86)\Mapbob\Application\locales\he.pak, Verwijder-bij-herstart, [557], [373041],1.0.1352
Adware.Ghokswa, C:\Program Files (x86)\Mapbob\Application\locales\hi.pak, Verwijder-bij-herstart, [557], [373041],1.0.1352
Adware.Ghokswa, C:\Program Files (x86)\Mapbob\Application\locales\hr.pak, Verwijder-bij-herstart, [557], [373041],1.0.1352
Adware.Ghokswa, C:\Program Files (x86)\Mapbob\Application\locales\hu.pak, Verwijder-bij-herstart, [557], [373041],1.0.1352
Adware.Ghokswa, C:\Program Files (x86)\Mapbob\Application\locales\id.pak, Verwijder-bij-herstart, [557], [373041],1.0.1352
Adware.Ghokswa, C:\Program Files (x86)\Mapbob\Application\locales\it.pak, Verwijder-bij-herstart, [557], [373041],1.0.1352
Adware.Ghokswa, C:\Program Files (x86)\Mapbob\Application\locales\ja.pak, Verwijder-bij-herstart, [557], [373041],1.0.1352
Adware.Ghokswa, C:\Program Files (x86)\Mapbob\Application\locales\kn.pak, Verwijder-bij-herstart, [557], [373041],1.0.1352
Adware.Ghokswa, C:\Program Files (x86)\Mapbob\Application\locales\ko.pak, Verwijder-bij-herstart, [557], [373041],1.0.1352
Adware.Ghokswa, C:\Program Files (x86)\Mapbob\Application\locales\lt.pak, Verwijder-bij-herstart, [557], [373041],1.0.1352
Adware.Ghokswa, C:\Program Files (x86)\Mapbob\Application\locales\lv.pak, Verwijder-bij-herstart, [557], [373041],1.0.1352
Adware.Ghokswa, C:\Program Files (x86)\Mapbob\Application\locales\ml.pak, Verwijder-bij-herstart, [557], [373041],1.0.1352
Adware.Ghokswa, C:\Program Files (x86)\Mapbob\Application\locales\mr.pak, Verwijder-bij-herstart, [557], [373041],1.0.1352
Adware.Ghokswa, C:\Program Files (x86)\Mapbob\Application\locales\ms.pak, Verwijder-bij-herstart, [557], [373041],1.0.1352
Adware.Ghokswa, C:\Program Files (x86)\Mapbob\Application\locales\nb.pak, Verwijder-bij-herstart, [557], [373041],1.0.1352
Adware.Ghokswa, C:\Program Files (x86)\Mapbob\Application\locales\nl.pak, Verwijder-bij-herstart, [557], [373041],1.0.1352
Adware.Ghokswa, C:\Program Files (x86)\Mapbob\Application\locales\pl.pak, Verwijder-bij-herstart, [557], [373041],1.0.1352
Adware.Ghokswa, C:\Program Files (x86)\Mapbob\Application\locales\pt-BR.pak, Verwijder-bij-herstart, [557], [373041],1.0.1352
Adware.Ghokswa, C:\Program Files (x86)\Mapbob\Application\locales\pt-PT.pak, Verwijder-bij-herstart, [557], [373041],1.0.1352
Adware.Ghokswa, C:\Program Files (x86)\Mapbob\Application\locales\ro.pak, Verwijder-bij-herstart, [557], [373041],1.0.1352
Adware.Ghokswa, C:\Program Files (x86)\Mapbob\Application\locales\ru.pak, Verwijder-bij-herstart, [557], [373041],1.0.1352
Adware.Ghokswa, C:\Program Files (x86)\Mapbob\Application\locales\sk.pak, Verwijder-bij-herstart, [557], [373041],1.0.1352
Adware.Ghokswa, C:\Program Files (x86)\Mapbob\Application\locales\sl.pak, Verwijder-bij-herstart, [557], [373041],1.0.1352
Adware.Ghokswa, C:\Program Files (x86)\Mapbob\Application\locales\sr.pak, Verwijder-bij-herstart, [557], [373041],1.0.1352
Adware.Ghokswa, C:\Program Files (x86)\Mapbob\Application\locales\sv.pak, Verwijder-bij-herstart, [557], [373041],1.0.1352
Adware.Ghokswa, C:\Program Files (x86)\Mapbob\Application\locales\sw.pak, Verwijder-bij-herstart, [557], [373041],1.0.1352
Adware.Ghokswa, C:\Program Files (x86)\Mapbob\Application\locales\ta.pak, Verwijder-bij-herstart, [557], [373041],1.0.1352
Adware.Ghokswa, C:\Program Files (x86)\Mapbob\Application\locales\te.pak, Verwijder-bij-herstart, [557], [373041],1.0.1352
Adware.Ghokswa, C:\Program Files (x86)\Mapbob\Application\locales\th.pak, Verwijder-bij-herstart, [557], [373041],1.0.1352
Adware.Ghokswa, C:\Program Files (x86)\Mapbob\Application\locales\tr.pak, Verwijder-bij-herstart, [557], [373041],1.0.1352
Adware.Ghokswa, C:\Program Files (x86)\Mapbob\Application\locales\uk.pak, Verwijder-bij-herstart, [557], [373041],1.0.1352
Adware.Ghokswa, C:\Program Files (x86)\Mapbob\Application\locales\vi.pak, Verwijder-bij-herstart, [557], [373041],1.0.1352
Adware.Ghokswa, C:\Program Files (x86)\Mapbob\Application\locales\zh-CN.pak, Verwijder-bij-herstart, [557], [373041],1.0.1352
Adware.Ghokswa, C:\Program Files (x86)\Mapbob\Application\locales\zh-TW.pak, Verwijder-bij-herstart, [557], [373041],1.0.1352
Adware.Ghokswa, C:\Program Files (x86)\Mapbob\Application\VisualElements\logo.png, Verwijder-bij-herstart, [557], [373041],1.0.1352
Adware.Ghokswa, C:\Program Files (x86)\Mapbob\Application\VisualElements\smalllogo.png, Verwijder-bij-herstart, [557], [373041],1.0.1352
Adware.Ghokswa, C:\Program Files (x86)\Mapbob\Application\55.0.2883.75.manifest, Verwijder-bij-herstart, [557], [373041],1.0.1352
Adware.Ghokswa, C:\Program Files (x86)\Mapbob\Application\chrome.dll, Verwijder-bij-herstart, [557], [373041],1.0.1352
Adware.Ghokswa, C:\Program Files (x86)\Mapbob\Application\chrome.exe, Verwijder-bij-herstart, [557], [373041],1.0.1352
Adware.Ghokswa, C:\Program Files (x86)\Mapbob\Application\chrome_100_percent.pak, Verwijder-bij-herstart, [557], [373041],1.0.1352
Adware.Ghokswa, C:\Program Files (x86)\Mapbob\Application\chrome_200_percent.pak, Verwijder-bij-herstart, [557], [373041],1.0.1352
Adware.Ghokswa, C:\Program Files (x86)\Mapbob\Application\chrome_child.dll, Verwijder-bij-herstart, [557], [373041],1.0.1352
Adware.Ghokswa, C:\Program Files (x86)\Mapbob\Application\chrome_elf.dll, Verwijder-bij-herstart, [557], [373041],1.0.1352
Adware.Ghokswa, C:\Program Files (x86)\Mapbob\Application\chrome_watcher.dll, Verwijder-bij-herstart, [557], [373041],1.0.1352
Adware.Ghokswa, C:\Program Files (x86)\Mapbob\Application\d3dcompiler_47.dll, Verwijder-bij-herstart, [557], [373041],1.0.1352
Adware.Ghokswa, C:\Program Files (x86)\Mapbob\Application\icudtl.dat, Verwijder-bij-herstart, [557], [373041],1.0.1352
Adware.Ghokswa, C:\Program Files (x86)\Mapbob\Application\libegl.dll, Verwijder-bij-herstart, [557], [373041],1.0.1352
Adware.Ghokswa, C:\Program Files (x86)\Mapbob\Application\libglesv2.dll, Verwijder-bij-herstart, [557], [373041],1.0.1352
Adware.Ghokswa, C:\Program Files (x86)\Mapbob\Application\natives_blob.bin, Verwijder-bij-herstart, [557], [373041],1.0.1352
Adware.Ghokswa, C:\Program Files (x86)\Mapbob\Application\resources.pak, Verwijder-bij-herstart, [557], [373041],1.0.1352
Adware.Ghokswa, C:\Program Files (x86)\Mapbob\Application\snapshot_blob.bin, Verwijder-bij-herstart, [557], [373041],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\CertificateTransparency\311\_platform_specific\all\sths\293c519654c83965baaa50fc5807d4b76fbf587a2972dca4c30cf4e54547f478.sth, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\CertificateTransparency\311\_platform_specific\all\sths\34bb6ad6c3df9c03eea8a499ff7891486c9d5e5cac92d01f7bfd1bce19db48ef.sth, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\CertificateTransparency\311\_platform_specific\all\sths\41b2dc2e89e63ce4af1ba7bb29bf68c6dee6f9f1cc047e30dffae3b3ba259263.sth, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\CertificateTransparency\311\_platform_specific\all\sths\5614069a2fd7c2ecd3f5e1bd44b23ec74676b9bc99115cc0ef949855d689d0dd.sth, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\CertificateTransparency\311\_platform_specific\all\sths\68f698f81f6482be3a8ceeb9281d4cfc71515d6793d444d10a67acbb4f4ffbc4.sth, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\CertificateTransparency\311\_platform_specific\all\sths\7461b4a09cfb3d41d75159575b2e7649a445a8d27709b0cc564a6482b7eb41a3.sth, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\CertificateTransparency\311\_platform_specific\all\sths\a4b90990b418581487bb13a2cc67700a3c359804f91bdfb8e377cd0ec80ddc10.sth, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\CertificateTransparency\311\_platform_specific\all\sths\a577ac9ced7548dd8f025b67a241089df86e0f476ec203c2ecbedb185f282638.sth, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\CertificateTransparency\311\_platform_specific\all\sths\ac3b9aed7fa9674757159e6d7d575672f9d98100941e9bdeffeca1313b75782d.sth, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\CertificateTransparency\311\_platform_specific\all\sths\bbd9dfbc1f8a71b593942397aa927b473857950aab52e81a909664368e1ed185.sth, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\CertificateTransparency\311\_platform_specific\all\sths\bc78e1dfc5f63c684649334da10fa15f0979692009c081b4f3f6917f3ed9b8a5.sth, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\CertificateTransparency\311\_platform_specific\all\sths\cdb5179b7fc1c046feea31136a3f8f002e6182faf8896fecc8b2f5b5ab604900.sth, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\CertificateTransparency\311\_platform_specific\all\sths\ddeb1d2b7a0d4fa6208b81ad8168707e2e8e9d01d55c888d3d11c4cdb6ecbecc.sth, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\CertificateTransparency\311\_platform_specific\all\sths\ee4bbdb775ce60bae142691fabe19e66a30f7e5fb072d88300c47b897aa8fdcb.sth, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\CertificateTransparency\311\manifest.fingerprint, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\CertificateTransparency\311\manifest.json, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\data_0, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\data_1, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\data_2, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\data_3, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_000001, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_000002, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_000003, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_000004, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_000005, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_000006, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_000007, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_000009, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_00000a, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_00000b, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_00000c, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_00000d, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_00000e, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_00000f, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_000011, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_000012, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_000013, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_000014, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_000015, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_000016, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_000017, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_000018, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_000019, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_00001a, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_00001b, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_00001c, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_00001d, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_00001e, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_00001f, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_000020, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_000022, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_000023, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_000025, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_000026, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_000027, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_000028, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_000029, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_00002a, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_00002b, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_00002c, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_00002e, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_00002f, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_000031, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_000032, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_000033, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_000034, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_000035, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_000036, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_000039, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_00003a, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_00003b, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_00003d, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_00003f, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_000040, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_000046, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_000047, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_000048, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_000049, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_00004a, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_00004b, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_00004c, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_00004d, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_00004e, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_00004f, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_000055, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_000056, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_000057, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_000058, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_000059, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_00005a, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_00005b, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_00005c, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_00005d, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_00005e, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_00005f, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_000060, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_000061, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_000062, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_000063, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_000064, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_000065, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_000066, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_000067, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_000069, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_00006a, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_00006b, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_00006c, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_00006d, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_00006f, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_000071, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_000073, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_000074, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_000075, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_000076, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_000077, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_000078, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_000079, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_00007a, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_00007b, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_00007c, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_00007d, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_00007e, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_000010, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_000024, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_00003c, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_000052, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_000068, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_00007f, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_000080, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_000081, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_000082, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_000083, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_000084, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_000085, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_000086, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_000087, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_000088, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_000089, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_00008a, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_00008b, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_00008c, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_00008d, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_00008e, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_00008f, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_000090, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_000091, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_000092, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_000093, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_000094, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_000095, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_000096, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_000097, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_000098, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_000099, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\f_00009a, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Cache\index, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\data_reduction_proxy_leveldb\000003.log, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\data_reduction_proxy_leveldb\CURRENT, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\data_reduction_proxy_leveldb\LOCK, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\data_reduction_proxy_leveldb\LOG, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\data_reduction_proxy_leveldb\LOG.old, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\data_reduction_proxy_leveldb\MANIFEST-000001, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extension Rules\000003.log, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extension Rules\CURRENT, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extension Rules\LOCK, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extension Rules\LOG, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extension Rules\LOG.old, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extension Rules\MANIFEST-000001, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extension State\000003.log, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extension State\CURRENT, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extension State\LOCK, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extension State\LOG, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extension State\LOG.old, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extension State\MANIFEST-000001, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\bpiopmneeadfapifejkfpahpljkicpik\1.1.6_0\background\background.js, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\bpiopmneeadfapifejkfpahpljkicpik\1.1.6_0\background\funs.js, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\bpiopmneeadfapifejkfpahpljkicpik\1.1.6_0\background\g_gg_c.js, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\bpiopmneeadfapifejkfpahpljkicpik\1.1.6_0\background\ist_bg.js, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\bpiopmneeadfapifejkfpahpljkicpik\1.1.6_0\background\upalytics_ch.js, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\bpiopmneeadfapifejkfpahpljkicpik\1.1.6_0\content\content_scripts.js, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\bpiopmneeadfapifejkfpahpljkicpik\1.1.6_0\content\gli.js, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\bpiopmneeadfapifejkfpahpljkicpik\1.1.6_0\content\irc.js, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\bpiopmneeadfapifejkfpahpljkicpik\1.1.6_0\content\ist.js, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\bpiopmneeadfapifejkfpahpljkicpik\1.1.6_0\content\up.js, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\bpiopmneeadfapifejkfpahpljkicpik\1.1.6_0\manifest.json, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.1_0\css\craw_window.css, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.1_0\html\craw_window.html, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.1_0\images\flapper.gif, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.1_0\images\icon_128.png, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.1_0\images\icon_16.png, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.1_0\images\topbar_floating_button.png, Verwijder-bij-herstart, [557], [373039],1.0.1352
Adware.Ghokswa, C:\Users\Rita\AppData\Local\Mapbob\User Data\Default\E
Groetjes van meme-rietje,
het is gemakkelijker op te geven dan door te gaan

abbs
Lid geworden op: 16 dec 2016, 13:49
Locatie: Leidschendam
Contacteer:

25 feb 2017, 16:44

Hallo,

Heel goed, hoe staat het na deze schoonmaak beurt met je problemen?
Groeten abbs
Afbeelding
Member of UNITE (Unified Network of Instructors and Trained Eliminators)

meme-rietje
Lid geworden op: 13 okt 2003, 19:51
Locatie: Zuid-West-Vl.

25 feb 2017, 18:17

hey,
wel hij draait een beetje raper
hij draait nu volledig op window 10
ben wel al mijn icoontjes kwijt van bank mijn forums elektriek de bib
eigenlijk alles van window 8,maar dat vind ik wel terug
nu zijn het met tegels
maar alles is weer in het Nederlands
toen was alles versprongen naar Engels
moet ik nog iets doen?
of is alles in orde nu?
Groetjes van meme-rietje,
het is gemakkelijker op te geven dan door te gaan

abbs
Lid geworden op: 16 dec 2016, 13:49
Locatie: Leidschendam
Contacteer:

25 feb 2017, 18:37

Hallo,

Waarschijnlijk ben je veel iconen kwijt van malware programma's dus kijk uit met wat je weer download.

Je had/heb zoveel infecties op je pc dat het raar is dat je er nog mee kon werken.

Download ZHPCleaner via onderstaande link:
- ZHPCleaner (klik op de blauwe knop 'TÉLÉCHARGER !')
Bewaar het op je bureaublad.

Sluit alle programma's en internet browsers. Internet browsers zullen automatisch afgesloten worden.

ZHPCleaner uitvoeren
  • Rechtsklik op ZHPCleaner.exe en klik op "Als administrator uitvoeren".
  • Klik op de knop "Akkoord" als je dit programma voor de eerste keer gebruikt.
  • Klik op "Scanner" en wacht geduldig tot dit klaar is.
  • Let op: Laat het programma nog niets repareren!
  • Na afloop staat er een tekstbestand met de naam ZHPCleaner.txt op je bureaublad, post deze in je volgend bericht.
    (Het logbestand kan je ook terugvinden in de map %AppData%\ZHP.)
Groeten abbs
Afbeelding
Member of UNITE (Unified Network of Instructors and Trained Eliminators)

meme-rietje
Lid geworden op: 13 okt 2003, 19:51
Locatie: Zuid-West-Vl.

25 feb 2017, 19:06

~ ZHPCleaner v2017.2.24.35 by Nicolas Coolman (2017/02/24)
~ Run by Rita (Administrator) (25/02/2017 18:48:30)
~ Web: https://www.nicolascoolman.com
~ Blog: https://nicolascoolman.eu/
~ Facebook : https://www.facebook.com/nicolascoolman1
~ State version : Versie OK
~ Type : Scan
~ Report : C:\Users\Rita\Desktop\ZHPCleaner.txt
~ Quarantine : C:\Users\Rita\AppData\Roaming\ZHP\ZHPCleaner_Quarantine.txt
~ UAC : Activate
~ Boot Mode : Normal (Normal boot)
Windows 10 Home, 64-bit (Build 14393)


---\\ Services (0)
~ Geen schadelijk of onnodig element gevonden.


---\\ Browser internet (3)
GEVONDEN bestand: C:\Users\Rita\AppData\Roaming\Mozilla\Firefox\Profiles\y652r2ae.default\storage\default\http+++nl.reimageplus.com\.metadata =>.Superfluous.ReimageRepair
GEVONDEN bestand: C:\Users\Rita\AppData\Roaming\Mozilla\Firefox\Profiles\y652r2ae.default\storage\default\http+++nl.reimageplus.com\.metadata-v2 =>.Superfluous.ReimageRepair
GEVONDEN bestand: C:\Users\Rita\AppData\Roaming\Mozilla\Firefox\Profiles\y652r2ae.default\storage\default\http+++nl.reimageplus.com\idb\1320802654iedibk_oeovcer.sqlite =>.Superfluous.ReimageRepair


---\\ Hosts file (2)
GEVONDEN: 0.0.0.1 mssplus.mcafee.com
Aantal gevonden redirections 1/27


---\\ Scheduled automatic tasks. (0)
~ Geen schadelijk of onnodig element gevonden.


---\\ Explorer ( Bestand, Map) (78)
GEVONDEN bestand: C:\Windows\Prefetch\AMZNSEARCHPROTECT.EXE-A0190CB3.pf =>PUP.Optional.SearchProtect
GEVONDEN bestand: C:\Windows\Installer\wix{3D310F56-A7CA-441F-993E-35BF9CE0B021}.SchedServiceConfig.rmi =>.Superfluous.Empty
GEVONDEN bestand: C:\Windows\Installer\wix{55BB2110-FB43-49B3-93F4-945A0CFB0A6C}.SchedServiceConfig.rmi =>.Superfluous.Empty
GEVONDEN bestand: C:\Windows\Installer\wix{B6DCCCD3-520D-4485-B642-FCC136CE12C3}.SchedServiceConfig.rmi =>.Superfluous.Empty
GEVONDEN bestand: C:\Windows\Installer\wix{D4D86CB2-2370-4691-8272-3869EDED6C64}.SchedServiceConfig.rmi =>.Superfluous.Empty
GEVONDEN bestand: C:\Windows\Installer\wix{FA378CD1-F32D-4610-9884-3902DF8AF826}.SchedServiceConfig.rmi =>.Superfluous.Empty
GEVONDEN bestand: C:\Users\Rita\Downloads\Popcorn-Time-0.3.9-Setup.exe [Popcorn Time - Popcorn-Time 0.3.9 Installer] =>.Superfluous.PopcornTime
GEVONDEN bestand: C:\Program Files (x86)\Popcorn Time\init.txt =>.Superfluous.PopcornTime
GEVONDEN bestand: C:\Program Files (x86)\Popcorn Time\Updater.exe [Popcorn Time - Updater] =>.Superfluous.PopcornTime
GEVONDEN bestand: C:\Program Files (x86)\Save to 4shared\Save to 4shared.dat =>PUP.Optional.SaveShare
GEVONDEN bestand: C:\Program Files (x86)\SaveeNewAAppz\SaveeNewAAppz.dat =>PUP.Optional.SaveNewAppz
GEVONDEN bestand: C:\Program Files (x86)\SaVeLoets\SaVeLoets.dat =>PUP.Optional.SaveLots
GEVONDEN bestand: C:\Program Files (x86)\SaveNEwaAPpzz\SaveNEwaAPpzz.dat =>PUP.Optional.SaveNewAppz
GEVONDEN bestand: C:\Program Files (x86)\Weather Europe Extension\Weather Europe Extension.dat =>PUP.Optional.Multiplug
GEVONDEN map: C:\Program Files (x86)\Popcorn Time =>.Superfluous.PopcornTime
GEVONDEN map: C:\Program Files (x86)\Save to 4shared =>PUP.Optional.SaveShare
GEVONDEN map: C:\Program Files (x86)\SaveeNewAAppz =>PUP.Optional.SaveNewAppz
GEVONDEN map: C:\Program Files (x86)\SaVeLoets =>PUP.Optional.SaveLots
GEVONDEN map: C:\Program Files (x86)\SaveNEwaAPpzz =>PUP.Optional.SaveNewAppz
GEVONDEN map: C:\Program Files (x86)\Stardock =>.Superfluous.Empty
GEVONDEN map: C:\Program Files (x86)\Weather Europe Extension =>PUP.Optional.Multiplug
GEVONDEN bestand: C:\ProgramData\FlexuibaleeSohooppEra\uYjlSHb0I.dat =>PUP.Optional.FlexibleShoper
GEVONDEN bestand: C:\ProgramData\FlexuibaleeSohooppEra\uYjlSHb0I.tlb =>PUP.Optional.FlexibleShoper
GEVONDEN map: C:\ProgramData\FlexuibaleeSohooppEra =>PUP.Optional.FlexibleShoper
GEVONDEN bestand: C:\Users\Rita\AppData\Local\Popcorn-Time-CE\cookies =>.Superfluous.PopcornTime
GEVONDEN bestand: C:\Users\Rita\AppData\Local\Popcorn-Time-CE\cookies-journal =>.Superfluous.PopcornTime
GEVONDEN bestand: C:\Users\Rita\AppData\Local\Popcorn-Time-CE\QuotaManager =>.Superfluous.PopcornTime
GEVONDEN bestand: C:\Users\Rita\AppData\Local\Popcorn-Time-CE\QuotaManager-journal =>.Superfluous.PopcornTime
GEVONDEN bestand: C:\Users\Rita\AppData\Local\Popcorn-Time-CE\Web Data =>.Superfluous.PopcornTime
GEVONDEN bestand: C:\Users\Rita\AppData\Local\Popcorn-Time-CE\Web Data-journal =>.Superfluous.PopcornTime
GEVONDEN map: C:\Users\Rita\AppData\Local\Popcorn-Time-CE\Cache =>.Superfluous.PopcornTime
GEVONDEN map: C:\Users\Rita\AppData\Local\Popcorn-Time-CE\data =>.Superfluous.PopcornTime
GEVONDEN map: C:\Users\Rita\AppData\Local\Popcorn-Time-CE\databases =>.Superfluous.PopcornTime
GEVONDEN map: C:\Users\Rita\AppData\Local\Popcorn-Time-CE\GPUCache =>.Superfluous.PopcornTime
GEVONDEN map: C:\Users\Rita\AppData\Local\Popcorn-Time-CE\IndexedDB =>.Superfluous.PopcornTime
GEVONDEN map: C:\Users\Rita\AppData\Local\Popcorn-Time-CE\Local Storage =>.Superfluous.PopcornTime
GEVONDEN map: C:\Users\Rita\AppData\Local\Popcorn-Time-CE\TorrentCollection =>.Superfluous.PopcornTime
GEVONDEN map: C:\Users\Rita\AppData\Local\PopcornTimeDesktop\.cache =>.Superfluous.PopcornTime
GEVONDEN map: C:\Users\Rita\AppData\Local\Popcorn-Time-CE =>.Superfluous.PopcornTime
GEVONDEN map: C:\Users\Rita\AppData\Local\PopcornTimeDesktop =>.Superfluous.PopcornTime
GEVONDEN map: C:\Program Files (x86)\QuickTime =>Riskware.QuickTime
GEVONDEN map: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime =>Riskware.QuickTime
GEVONDEN map: C:\WINDOWS\Installer\MSI112F.tmp- =>.Superfluous.Empty
GEVONDEN map: C:\WINDOWS\Installer\MSI149E.tmp- =>.Superfluous.Empty
GEVONDEN map: C:\WINDOWS\Installer\MSI193B.tmp- =>.Superfluous.Empty
GEVONDEN map: C:\WINDOWS\Installer\MSI296C.tmp- =>.Superfluous.Empty
GEVONDEN map: C:\WINDOWS\Installer\MSI3837.tmp- =>.Superfluous.Empty
GEVONDEN map: C:\WINDOWS\Installer\MSI3AD7.tmp- =>.Superfluous.Empty
GEVONDEN map: C:\WINDOWS\Installer\MSI3C9E.tmp- =>.Superfluous.Empty
GEVONDEN map: C:\WINDOWS\Installer\MSI3F10.tmp- =>.Superfluous.Empty
GEVONDEN map: C:\WINDOWS\Installer\MSI40B6.tmp- =>.Superfluous.Empty
GEVONDEN map: C:\WINDOWS\Installer\MSI4CCE.tmp- =>.Superfluous.Empty
GEVONDEN map: C:\WINDOWS\Installer\MSI5AB9.tmp- =>.Superfluous.Empty
GEVONDEN map: C:\WINDOWS\Installer\MSI66EF.tmp- =>.Superfluous.Empty
GEVONDEN map: C:\WINDOWS\Installer\MSI7085.tmp- =>.Superfluous.Empty
GEVONDEN map: C:\WINDOWS\Installer\MSI83E2.tmp- =>.Superfluous.Empty
GEVONDEN map: C:\WINDOWS\Installer\MSI93FE.tmp- =>.Superfluous.Empty
GEVONDEN map: C:\WINDOWS\Installer\MSI94C7.tmp- =>.Superfluous.Empty
GEVONDEN map: C:\WINDOWS\Installer\MSI9AF8.tmp- =>.Superfluous.Empty
GEVONDEN map: C:\WINDOWS\Installer\MSIAEB7.tmp- =>.Superfluous.Empty
GEVONDEN map: C:\WINDOWS\Installer\MSIB50F.tmp- =>.Superfluous.Empty
GEVONDEN map: C:\WINDOWS\Installer\MSIBAC0.tmp- =>.Superfluous.Empty
GEVONDEN map: C:\WINDOWS\Installer\MSIBE01.tmp- =>.Superfluous.Empty
GEVONDEN map: C:\WINDOWS\Installer\MSIC025.tmp- =>.Superfluous.Empty
GEVONDEN map: C:\WINDOWS\Installer\MSIC1CC.tmp- =>.Superfluous.Empty
GEVONDEN map: C:\WINDOWS\Installer\MSIC7F7.tmp- =>.Superfluous.Empty
GEVONDEN map: C:\WINDOWS\Installer\MSICB9A.tmp- =>.Superfluous.Empty
GEVONDEN map: C:\WINDOWS\Installer\MSICF13.tmp- =>.Superfluous.Empty
GEVONDEN map: C:\WINDOWS\Installer\MSID52F.tmp- =>.Superfluous.Empty
GEVONDEN map: C:\WINDOWS\Installer\MSIDA09.tmp- =>.Superfluous.Empty
GEVONDEN map: C:\WINDOWS\Installer\MSIEA2C.tmp- =>.Superfluous.Empty
GEVONDEN map: C:\WINDOWS\Installer\MSIF0D5.tmp- =>.Superfluous.Empty
GEVONDEN map: C:\WINDOWS\Installer\MSIF3E6.tmp- =>.Superfluous.Empty
GEVONDEN map: C:\WINDOWS\Installer\MSIF5A8.tmp- =>.Superfluous.Empty
GEVONDEN map: C:\WINDOWS\Installer\MSIF972.tmp- =>.Superfluous.Empty
GEVONDEN map: C:\WINDOWS\Installer\MSIFB57.tmp- =>.Superfluous.Empty
GEVONDEN map: C:\WINDOWS\Installer\MSIFF61.tmp- =>.Superfluous.Empty
GEVONDEN bestand: C:\Windows\Installer\{C881D603-277F-4056-918D-654844EF2B37}\_853F67D554F05449430E7E.exe =>.Superfluous.WinSnare


---\\ Register ( Sleutel, Waarde, Data) (43)
GEVONDEN sleutel: HKEY_USERS\S-1-5-21-2370912473-469425822-2799426420-1002\SOFTWARE\Popcorn Time [] =>.Superfluous.PopcornTime
GEVONDEN sleutel: HKEY_USERS\S-1-5-21-2370912473-469425822-2799426420-1002\SOFTWARE\PopcornTime [] =>.Superfluous.PopcornTime
GEVONDEN sleutel: HKCU\Software\Popcorn Time [] =>.Superfluous.PopcornTime
GEVONDEN sleutel: HKCU\Software\PopcornTime [] =>.Superfluous.PopcornTime
GEVONDEN sleutel: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\nl.softonic.com [] =>.Superfluous.Softonic
GEVONDEN sleutel: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\softonic.com [] =>.Superfluous.Softonic
GEVONDEN sleutel: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\solitaire-windows-10.nl.softonic.com [] =>.Superfluous.Softonic
GEVONDEN sleutel: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\nl.softonic.com [] =>.Superfluous.Softonic
GEVONDEN sleutel: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\softonic.com [] =>.Superfluous.Softonic
GEVONDEN sleutel: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\solitaire-windows-10.nl.softonic.com [314] =>.Superfluous.Softonic
GEVONDEN sleutel: HKCU\Software\Microsoft\Internet Explorer\DOMStorage\sharelive.net [] =>PUP.Optional.SaveNet
GEVONDEN sleutel: HKCU\Software\WEBAPP [] =>.Superfluous.Downloader
GEVONDEN sleutel: HKLM\SOFTWARE\Wow6432Node\Firefox [] =>Adware.GhokswaBrowser
GEVONDEN sleutel: HKLM\SOFTWARE\Firefox [] =>Adware.GhokswaBrowser
GEVONDEN sleutel: [X64] HKLM\SOFTWARE\Classes\S [] =>Toolbar.Agent
GEVONDEN sleutel: [X64] HKLM\Software\Classes\Installer\Products\306D188CF772650419D8568444FEB273 [WinSnare] =>.Superfluous.WinSnare
GEVONDEN sleutel: [X64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bitguard.exe [] =>.Superfluous.MediaTechSoft
GEVONDEN sleutel: [X64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bprotect.exe [] =>PUP.Optional.BProtector
GEVONDEN sleutel: [X64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bpsvc.exe [] =>PUP.Optional.BProtector
GEVONDEN sleutel: [X64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dprotectsvc.exe [] =>PUP.Optional.Staser
GEVONDEN sleutel: [X64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\protectedsearch.exe [] =>PUP.Optional.ProtectedSearch
GEVONDEN sleutel: [X64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotection.exe [] =>PUP.Optional.SearchProtect
GEVONDEN sleutel: [X64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotector.exe [] =>PUP.Optional.SearchProtect
GEVONDEN sleutel: [X64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchsettings.exe [] =>PUP.Optional.SearchSettings
GEVONDEN sleutel: [X64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchsettings64.exe [] =>PUP.Optional.SearchSettings
GEVONDEN sleutel: [X64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\snapdo.exe [] =>PUP.Optional.SmartBar
GEVONDEN sleutel: [X64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst32.exe [] =>.Superfluous.SimplyTech
GEVONDEN sleutel: [X64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst64.exe [] =>.Superfluous.SimplyTech
GEVONDEN sleutel: [X64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\utiljumpflip.exe [] =>PUP.Optional.JumpFlip
GEVONDEN sleutel: [X64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\websteroids.exe [] =>PUP.Optional.InternetUpdater
GEVONDEN sleutel: [X64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\websteroidsservice.exe [] =>PUP.Optional.InternetUpdater
GEVONDEN sleutel: [X64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2370912473-469425822-2799426420-1002\Products\E4DFFE2B890D5484D965ED57EB3B9531 [amuleC] =>.Superfluous.aMULEcustom
GEVONDEN sleutel: [X64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0785F5BAB0464947A123C88A3DA58014 [C:\Program Files (x86)\WinSnare(4.1.6)\openweb.bat (Not File)] =>.Superfluous.WinSnare
GEVONDEN sleutel: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{C881D603-277F-4056-918D-654844EF2B37} [WinSnare] =>.Superfluous.WinSnare
GEVONDEN waarde: HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\StartupFolder\\MyPC Backup.lnk [0x020000000000000000000000] =>PUP.Optional.MyPCBackup
GEVONDEN waarde: HKEY_USERS\S-1-5-21-2370912473-469425822-2799426420-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\StartupFolder\\MyPC Backup.lnk [0x020000000000000000000000] =>PUP.Optional.MyPCBackup
GEVONDEN sleutel: [X64] HKLM\Software\Classes\Installer\Features\306D188CF772650419D8568444FEB273 [WinSnare] =>.Superfluous.WinSnare
GEVONDEN sleutel: HKCU\SOFTWARE\D0579E3B78ECAC2B3B8C52A63342F575 [] =>Hijacker.Browser
GEVONDEN sleutel: [X64] HKLM\SOFTWARE\D0579E3B78ECAC2B3B8C52A63342F575 [] =>Hijacker.Browser
GEVONDEN waarde: HKLM\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\firewallRules\\UDP Query User{42B1FFFB-356F-4694-82B2-B36DD4B0BE4B}C:\users\rita\appdata\local\popcorn time ce yify\nw.exe [C:\users\rita\appdata\local\popcorn time ce yify\nw.exe] =>.Superfluous.PopcornTime
GEVONDEN waarde: HKLM\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\firewallRules\\TCP Query User{BD84E35D-05B7-42D8-AA83-FA373593CD0E}C:\users\rita\appdata\local\popcorn time ce yify\nw.exe [C:\users\rita\appdata\local\popcorn time ce yify\nw.exe] =>.Superfluous.PopcornTime
GEVONDEN waarde: HKLM\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\firewallRules\\{331E6220-E5D5-4F46-A9C3-3B65763A4688} [C:\Program Files (x86)\Popcorn Time\Updater.exe] =>.Superfluous.PopcornTime
GEVONDEN waarde: HKLM\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\firewallRules\\{286222D5-FD2D-459D-843F-7A9135954934} [C:\Program Files (x86)\Popcorn Time\Updater.exe] =>.Superfluous.PopcornTime


---\\ Samenvatting van elementen gevonden op uw werkstation (28)
https://nicolascoolman.eu/2017/01/27/su ... agerepair/ =>.Superfluous.ReimageRepair
https://nicolascoolman.eu/2017/02/07/pu ... chprotect/ =>PUP.Optional.SearchProtect
https://nicolascoolman.eu/2017/01/20/lo ... superflus/ =>.Superfluous.Empty
https://www.anti-malware.top/2016/09/28 ... pcorntime/ =>.Superfluous.PopcornTime
https://nicolascoolman.eu/2017/01/27/re ... infection/ =>PUP.Optional.SaveShare
https://nicolascoolman.eu/2017/01/27/re ... infection/ =>PUP.Optional.SaveNewAppz
https://nicolascoolman.eu/2017/01/27/re ... infection/ =>PUP.Optional.SaveLots
https://www.anti-malware.top/2016/04/28 ... multiplug/ =>PUP.Optional.Multiplug
https://nicolascoolman.eu/2017/01/27/re ... infection/ =>PUP.Optional.FlexibleShoper
https://nicolascoolman.eu/2017/01/15/ri ... quicktime/ =>Riskware.QuickTime
https://nicolascoolman.eu/2017/01/12/su ... -winsnare/ =>.Superfluous.WinSnare
https://nicolascoolman.eu/2017/01/20/lo ... superflus/ =>.Superfluous.Softonic
https://nicolascoolman.eu/2017/01/27/re ... infection/ =>PUP.Optional.SaveNet
https://nicolascoolman.eu/2017/01/20/lo ... superflus/ =>.Superfluous.Downloader
https://nicolascoolman.eu/2017/02/19/ad ... wabrowser/ =>Adware.GhokswaBrowser
https://www.nicolascoolman.com/fr/?p=5143 =>Toolbar.Agent
https://nicolascoolman.eu/2017/01/20/lo ... superflus/ =>.Superfluous.MediaTechSoft
https://www.anti-malware.top/2016/04/30 ... protector/ =>PUP.Optional.BProtector
https://www.nicolascoolman.com/fr/trojan-staser/ =>PUP.Optional.Staser
https://www.nicolascoolman.com/fr/spywa ... tedsearch/ =>PUP.Optional.ProtectedSearch
https://www.nicolascoolman.com/fr/adwar ... hsettings/ =>PUP.Optional.SearchSettings
https://www.nicolascoolman.com/fr/hijacker-smartbar/ =>PUP.Optional.SmartBar
https://nicolascoolman.eu/2017/01/20/lo ... superflus/ =>.Superfluous.SimplyTech
https://www.nicolascoolman.com/fr/pup-jumpflip/ =>PUP.Optional.JumpFlip
https://www.nicolascoolman.com/fr/pup-internetupdater/ =>PUP.Optional.InternetUpdater
https://www.anti-malware.top/2016/10/11 ... ulecustom/ =>.Superfluous.aMULEcustom
https://www.nicolascoolman.com/fr/pup-mypcbackup/ =>PUP.Optional.MyPCBackup
https://nicolascoolman.eu/2017/02/02/hi ... browser-2/ =>Hijacker.Browser


---\\Resultaat van reparaties
~ Gerepareerd
~ Browser niet gevonden (Google Chrome)
~ Browser niet gevonden (Opera Software)


---\\Statistics
~ Items gescand : 93447
~ Items gevonden : 135
~ Items gecancelled : 0
~ Items gerepareerd : 0


~ End of search in 00h15mn34s
~====================
ZHPCleaner-[S]-25022017-19_04_04.txt
Groetjes van meme-rietje,
het is gemakkelijker op te geven dan door te gaan