• Hulpvragenden in dit forumonderdeel worden enkel geholpen door daartoe bevoegde teamleden.
    Dit is belangrijk, zodat de hulpvragende goed geholpen kan worden zonder (goedbedoelde) aanvullende berichten van andere leden.
    Reageren op andermans discussie is daarom uitgeschakeld.
  • De afgelopen dagen zijn er meerdere fora waarop bestaande accounts worden overgenomen door spammers. De gebruikersnamen en wachtwoorden zijn via een hack of een lek via andere sites buitgemaakt. Via have i been pwned? kan je controleren of jouw gegeven ook zijn buitgemaakt. Wijzig bij twijfel jouw wachtwoord of schakel de twee-staps-verificatie in.

[Opgelost] Nation Zoom opent in IE en in Chrome Niet te verwijderen.

Status
Niet open voor verdere reacties.

schults2005

Vaak hier
Lid geworden
11 nov 2005
Berichten
559
Waarderingsscore
7
Bij openen IE en Chrome komt steeds NationZoom als startpagina. Zag dat er nog niets op dit forum erover stond en eerst maar eens mbam gedraaid. Tot 2 keer toe vond die bedreigingen. Pas bij de 3de keer geen problemen gevonden, maar nog steeds dat nationzoom, die start NB ook yahoo als zoekmachine op.

Zag verder op internet tip om adwcleaner - dds en mbam te draaien. Meen op google chrome forum ivm nation zoom
Dat dus maar gedaan en nu hier posten.
Maar de browsers starten nog steeds met nation zoom op. Heb ook alle laatste geinstalleerde progs verwijderd, want er zaten een paar "rare" tussen 1tje met iets van 365 in de naam. Zeker met iets anders meegekomen helaas, want o.a. dit progje heeft te maken met nationzoom probleem zag ik ergens.

Adwcleaner log
# AdwCleaner v3.014 - Report created 10/12/2013 at 04:16:53
# Updated 01/12/2013 by Xplode
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : Chris - CHRIS-HP
# Running from : C:\Users\Chris\Desktop\adwcleaner.exe
# Option : Clean

***** [ Services ] *****


***** [ Files / Folders ] *****

Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\jZip
Folder Deleted : C:\Program Files (x86)\jZip
Folder Deleted : C:\Program Files (x86)\WinZipper
Folder Deleted : C:\Program Files (x86)\Common Files\337
Folder Deleted : C:\Users\Chris\AppData\Local\jZip
Folder Deleted : C:\Users\Chris\AppData\Local\Temp\jZip
Folder Deleted : C:\Users\Chris\AppData\Roaming\WinZipper
Folder Deleted : C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Default\Extensions\cekcjpgehmohobmdiikfnopibipmgnml
File Deleted : C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_ifohbjbgfchkkfhphahclmkpgejiplfo_0.localstorage
File Deleted : C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtab.crx
File Deleted : C:\Windows\System32\Tasks\Dealply
File Deleted : C:\Windows\System32\Tasks\Desk 365 RunAsStdUser
File Deleted : C:\Windows\System32\Tasks\YourFile Update

***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\hbcennhacfaagdopikcegfcobcadeocj
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\icdlfehblmklkikfigmjhbmmpmkmpooj
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\mhkaekfpcppmmioggniknbnbdbcigpkk
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\pfndaklgolladniicklehhancnlgocpp
Key Deleted : HKLM\SOFTWARE\Classes\jZip.file
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\jZip_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\jZip_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\YourFile_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\YourFile_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\YourFileUpdater_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\YourFileUpdater_RASMANCS
Key Deleted : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\DeskSvc
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Virtual Plastic Surgery Software - VPSS_is1
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{0A18A436-2A7A-49F3-A488-30538A2F6323}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{7ABBFE1C-E485-44AA-8F36-353751B4124D}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{007EFBDF-8A5D-4930-97CC-A4B437CBA777}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{25A3A431-30BB-47C8-AD6A-E1063801134F}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{25A3A431-30BB-47C8-AD6A-E1063801134F}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{25A3A431-30BB-47C8-AD6A-E1063801134F}
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{25A3A431-30BB-47C8-AD6A-E1063801134F}]
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Key Deleted : HKCU\Software\OCS
Key Deleted : HKLM\Software\hdcode
Key Deleted : HKLM\Software\jZip
Key Deleted : HKLM\Software\V9
Key Deleted : HKLM\Software\winzipersvc
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\jZip

***** [ Browsers ] *****

-\\ Internet Explorer v10.0.9200.16736


-\\ Mozilla Firefox v

-\\ Google Chrome v31.0.1650.63

[ File : C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Default\preferences ]


*************************

AdwCleaner[R0].txt - [4095 octets] - [10/12/2013 00:31:27]
AdwCleaner[R1].txt - [3758 octets] - [10/12/2013 04:15:11]
AdwCleaner[S0].txt - [3732 octets] - [10/12/2013 04:16:53]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [3792 octets] ##########


dds kleur log

[hjt]
dds (ver_2012-11-20.01) - ntfs_amd64
internet explorer: 10.0.9200.16736 browserjavaversion: 10.45.2
run by chris at 4:27:17 on 2013-12-10
microsoft windows 7 home premium 6.1.7601.1.1252.31.1043.18.6143.4345 [gmt 1:00]
.
av: avast! antivirus *enabled/updated* {17ad7d40-ba12-9c46-7131-94903a54ad8b}
sp: windows defender *enabled/updated* {d68ddc3a-831f-4fae-9e44-da132c1acf46}
sp: avast! antivirus *enabled/updated* {accc9ca4-9c28-93c8-4b81-afe241d3e736}
.
============== running processes ===============
.
c:\windows\system32\lsm.exe
c:\windows\system32\svchost.exe -k dcomlaunch
c:\windows\system32\svchost.exe -k rpcss
c:\windows\system32\atiesrxx.exe
c:\windows\system32\svchost.exe -k localservicenetworkrestricted
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted
c:\windows\system32\svchost.exe -k netsvcs
c:\windows\system32\svchost.exe -k gpsvcgroup
c:\program files\tablet\pen\pen_touchservice.exe
c:\windows\system32\svchost.exe -k localservice
c:\windows\system32\svchost.exe -k networkservice
c:\windows\system32\atieclxx.exe
c:\program files\avast software\avast\avastsvc.exe
c:\program files\tablet\pen\pen_touchuser.exe
c:\windows\explorer.exe
c:\windows\system32\taskeng.exe
c:\windows\system32\spoolsv.exe
c:\windows\system32\taskhost.exe
c:\windows\system32\svchost.exe -k localservicenonetwork
c:\program files (x86)\common files\arcsoft\connection service\bin\acservice.exe
c:\program files (x86)\common files\adobe\arm\1.0\armsvc.exe
c:\windows\syswow64\ezsharedsvchost.exe
c:\program files (x86)\garmin\core update service\garmin.cartography.mapupdate.coreservice.exe
c:\windows\system32\taskeng.exe
c:\program files (x86)\common files\lightscribe\lssrvc.exe
c:\program files (x86)\malwarebytes' anti-malware\mbamscheduler.exe
c:\program files (x86)\malwarebytes' anti-malware\mbamservice.exe
c:\program files (x86)\malwarebytes' anti-malware\mbamgui.exe
c:\program files (x86)\sony\pmb\pmbdeviceinfoprovider.exe
c:\program files (x86)\common files\protexis\license service\psiservice_2.exe
c:\program files\tablet\pen\pen_tablet.exe
c:\program files\tablet\pen\pen_tabletuser.exe
c:\program files (x86)\tuneup utilities 2013\tuneuputilitiesservice64.exe
c:\windows\system32\svchost.exe -k secsvcs
c:\program files\common files\microsoft shared\windows live\wlidsvc.exe
c:\program files\tablet\pen\pen_tablet.exe
c:\program files\common files\microsoft shared\windows live\wlidsvcm.exe
c:\windows\system32\taskeng.exe
c:\windows\system32\svchost.exe -k networkservicenetworkrestricted
c:\program files (x86)\tuneup utilities 2013\tuneuputilitiesapp64.exe
c:\windows\servicing\trustedinstaller.exe
c:\program files (x86)\hewlett-packard\hp odometer\hpsysdrv.exe
c:\program files (x86)\nokia\nokia suite\nokiasuite.exe
c:\program files (x86)\common files\lightscribe\lightscribecontrolpanel.exe
c:\program files (x86)\garmin\express tray\expresstray.exe
c:\program files\windows sidebar\sidebar.exe
c:\program files (x86)\sony\pmb\pmbvolumewatcher.exe
c:\program files\avast software\avast\avastui.exe
c:\windows\system32\svchost.exe -k localserviceandnoimpersonation
c:\windows\system32\wisptis.exe
c:\program files (x86)\ati technologies\ati.ace\core-static\mom.exe
c:\program files (x86)\ati technologies\ati.ace\core-static\ccc.exe
c:\program files (x86)\google\update\googleupdate.exe
c:\program files (x86)\hewlett-packard\hp support framework\hpsa_service.exe
c:\program files (x86)\google\update\1.3.22.3\googlecrashhandler.exe
c:\program files (x86)\google\update\1.3.22.3\googlecrashhandler64.exe
c:\windows\system32\sppsvc.exe
c:\windows\system32\svchost.exe -k wersvcgroup
c:\windows\microsoft.net\framework64\v3.0\wpf\presentationfontcache.exe
c:\windows\system32\wbem\wmiprvse.exe
c:\windows\system32\cscript.exe
.
============== pseudo hjt report ===============
.
ustart page = hxxp://www.zeelandnet.nl/index.php/
udefault_page_url = hxxp://www.google.com
mstart page = hxxp://www.google.com
msearch page = hxxp://www.google.com
mdefault_page_url = hxxp://www.google.com
mdefault_search_url = hxxp://www.google.com
msearchassistant = hxxp://www.google.com/
mcustomizesearch = hxxp://www.google.com/
bho: pdf architect helper: {3a2d5eba-f86d-4bd3-a177-019765996711} - c:\program files (x86)\pdf architect\pdfiehelper.dll
bho: java(tm) plug-in ssv helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files (x86)\java\jre7\bin\ssv.dll
bho: avast! online security: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - c:\program files\avast software\avast\aswwebrepie.dll
bho: aanmeldhulp voor windows live id: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files (x86)\common files\microsoft shared\windows live\windowslivelogin.dll
bho: java(tm) plug-in 2 ssv helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files (x86)\java\jre7\bin\jp2ssv.dll
bho: hp network check helper: {e76fd755-c1ba-4dcb-9f13-99bd91223ade} - c:\program files (x86)\hewlett-packard\hp support framework\resources\hpnetworkcheck\hpnetworkcheckplugin.dll
tb: avast! online security: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - c:\program files\avast software\avast\aswwebrepie.dll
urun: [nokiasuite.exe] c:\program files (x86)\nokia\nokia suite\nokiasuite.exe -tray
urun: [lightscribe control panel] c:\program files (x86)\common files\lightscribe\lightscribecontrolpanel.exe -hidden
urun: [garminexpresstrayapp] c:\program files (x86)\garmin\express tray\expresstray.exe
urun: [sidebar] c:\program files\windows sidebar\sidebar.exe /autorun
mrun: [mypoi monitor] c:\program files (x86)\common files\mypoiworld shared\mypoimonitor\mypoimonitor.exe
mrun: [pmbvolumewatcher] c:\program files (x86)\sony\pmb\pmbvolumewatcher.exe
mrun: [smkrun] c:\program files (x86)\justwrite office\screenmark.exe -i
mrun: [apsdaemon] c:\program files (x86)\common files\apple\apple application support\apsdaemon.exe
mrun: [startccc] c:\program files (x86)\ati technologies\ati.ace\core-static\clistart.exe msrun
mrun: [adobe arm] c:\program files (x86)\common files\adobe\arm\1.0\adobearm.exe
mrun: [avastui.exe] c:\program files\avast software\avast\avastui.exe /nogui
mrun: [20131121] c:\program files\avast software\avast\setup\emupdate\991770ab-afc8-4779-a147-d7f72b2803a9.exe /check
mrun: [mobilegeni daemon] c:\program files (x86)\mobogenie\daemonprocess.exe
startupfolder: c:\users\chris\appdata\roaming\micros~1\windows\startm~1\programs\startup\adobeg~1.lnk - c:\program files (x86)\common files\adobe\calibration\adobe gamma loader.exe
upolicies-explorer: nodrivetypeautorun = dword:145
mpolicies-explorer: enableshellexecutehooks = dword:1
mpolicies-explorer: noresolvetrack = dword:1
mpolicies-system: consentpromptbehavioradmin = dword:5
mpolicies-system: consentpromptbehavioruser = dword:3
mpolicies-system: enableuiadesktoptoggle = dword:0
mpolicies-system: hidefastuserswitching = dword:0
ie: {25510184-5a38-4a99-b273-dca8eef6cd08} - c:\program files (x86)\hewlett-packard\hp support framework\resources\hpnetworkcheck\nclauncherfromie.exe
ie: {36ecaf82-3300-8f84-092e-aff36d6c7040} - {86529161-034e-4f8a-88d2-3c625e612e04} - c:\program files (x86)\winhttrack\winhttrackiebar.dll
dpf: garmin communicator plug-in - hxxps://static.garmincdn.com/gcp/ie/4.0.1.0/garminaxcontrol_32.cab
dpf: {cb50428b-657f-47df-9b32-671f82aa73f7} - hxxp://www.photodex.com/pxplay.cab
dpf: {d27cdb6e-ae6d-11cf-96b8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
dpf: {f27237d7-93c8-44c2-ac6e-d6057b9a918f} - hxxps://webaccess.minvenw.nl/dana-cached/sc/junipersetupclient.cab
tcp: nameserver = 62.238.255.69 212.115.192.100
tcp: interfaces\{f2a0558d-b9c8-4c73-8a0e-4076cc58faf6} : dhcpnameserver = 62.238.255.69 212.115.192.100
handler: wlpg - {e43ef6cd-a37a-4a9b-9e6f-83f89b8e6324} - c:\program files (x86)\windows live\photo gallery\albumdownloadprotocolhandler.dll
masetup: {10880d85-aad9-4558-abdc-2ab1552d831f} - c:\program files (x86)\common files\lightscribe\lsrunonce.exe
masetup: {8a69d345-d564-463c-aff1-a69d9e530f96} - c:\program files (x86)\google\chrome\application\31.0.1650.63\installer\chrmstp.exe --configure-user-settings --verbose-logging --system-level --multi-install --chrome
x64-mstart page = hxxp://www.nationzoom.com/?type=hp&ts=1386550966&from=adks&uid=hitachixhds721010cla332_jp2940hd0s1ymc0s1ymcx
x64-msearch page = hxxp://www.nationzoom.com/web/?type=ds&ts=1386550966&from=adks&uid=hitachixhds721010cla332_jp2940hd0s1ymc0s1ymcx&q={searchterms}
x64-mdefault_page_url = hxxp://www.nationzoom.com/?type=hp&ts=1386550966&from=adks&uid=hitachixhds721010cla332_jp2940hd0s1ymc0s1ymcx
x64-mdefault_search_url = hxxp://www.nationzoom.com/web/?type=ds&ts=1386550966&from=adks&uid=hitachixhds721010cla332_jp2940hd0s1ymc0s1ymcx&q={searchterms}
x64-msearchassistant = hxxp://www.nationzoom.com/web/?type=ds&ts=1386550966&from=adks&uid=hitachixhds721010cla332_jp2940hd0s1ymc0s1ymcx&q={searchterms}
x64-mcustomizesearch = hxxp://www.nationzoom.com/web/?type=ds&ts=1386550966&from=adks&uid=hitachixhds721010cla332_jp2940hd0s1ymc0s1ymcx&q={searchterms}
x64-bho: explorerwnd helper: {10921475-03ce-4e04-90ce-e2e7ef20c814} -
x64-bho: avast! online security: {318a227b-5e9f-45bd-8999-7f8f10ca4cf5} - c:\program files\avast software\avast\aswwebrepie64.dll
x64-bho: windows live id sign-in helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\windowslivelogin.dll
x64-bho: hp network check helper: {e76fd755-c1ba-4dcb-9f13-99bd91223ade} - c:\program files (x86)\hewlett-packard\hp support framework\resources\hpnetworkcheck\hpnetworkcheckpluginx64.dll
x64-tb: avast! online security: {318a227b-5e9f-45bd-8999-7f8f10ca4cf5} - c:\program files\avast software\avast\aswwebrepie64.dll
x64-run: [hpsysdrv] c:\program files (x86)\hewlett-packard\hp odometer\hpsysdrv.exe
x64-runonce: [ncpluginupdater] c:\program files (x86)\hewlett-packard\hp health check\activecheck\product_line\ncpluginupdater.exe update
x64-ie: {25510184-5a38-4a99-b273-dca8eef6cd08} - c:\program files (x86)\hewlett-packard\hp support framework\resources\hpnetworkcheck\nclauncherfromie.exe
x64-dpf: {73ecb3aa-4717-450c-a2ab-d00dad9ee203} - hxxp://h20614.www2.hp.com/ediags/gmd/install/cab/hpdetect121.cab
x64-dpf: {aa570693-00e2-4907-b6f1-60a1199b030c} - hxxps://juniper.net/dana-cached/sc/junipersetupclient64.cab
x64-dpf: {d27cdb6e-ae6d-11cf-96b8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
x64-handler: wlpg - {e43ef6cd-a37a-4a9b-9e6f-83f89b8e6324} - <orphaned>
.
============= services / drivers ===============
.
r0 aswrvrt;avast! revert;c:\windows\system32\drivers\aswrvrt.sys [2013-3-15 65776]
r0 aswvmm;avast! vm monitor;c:\windows\system32\drivers\aswvmm.sys [2013-3-15 205320]
r0 bthidbus;bluetooth hid bus service;c:\windows\system32\drivers\bthidbus.sys [2011-12-21 25056]
r1 aswsnx;aswsnx;c:\windows\system32\drivers\aswsnx.sys [2011-11-27 1032416]
r1 aswsp;aswsp;c:\windows\system32\drivers\aswsp.sys [2011-11-27 409832]
r1 csn5pdts82x64;csn5pdts82x64 ndis protocol driver;c:\windows\system32\drivers\csn5pdts82x64.sys [2013-10-24 34840]
r2 amd external events utility;amd external events utility;c:\windows\system32\atiesrxx.exe [2013-5-14 204288]
r2 aswfsblk;aswfsblk;c:\windows\system32\drivers\aswfsblk.sys [2011-11-27 38984]
r2 aswmonflt;aswmonflt;c:\windows\system32\drivers\aswmonflt.sys [2011-11-27 84328]
r2 avast! antivirus;avast! antivirus;c:\program files\avast software\avast\avastsvc.exe [2013-11-19 50344]
r2 ezsharedsvc;easybits services for windows;c:\windows\system32\ezsharedsvchost.exe --> c:\windows\system32\ezsharedsvchost.exe [?]
r2 garmin core update service;garmin core update service;c:\program files (x86)\garmin\core update service\garmin.cartography.mapupdate.coreservice.exe [2013-8-22 220504]
r2 hp support assistant service;hp support assistant service;c:\program files (x86)\hewlett-packard\hp support framework\hpsa_service.exe [2012-9-27 86528]
r2 mbamscheduler;mbamscheduler;c:\program files (x86)\malwarebytes' anti-malware\mbamscheduler.exe [2013-12-9 418376]
r2 mbamservice;mbamservice;c:\program files (x86)\malwarebytes' anti-malware\mbamservice.exe [2013-12-9 701512]
r2 pmbdeviceinfoprovider;pmbdeviceinfoprovider;c:\program files (x86)\sony\pmb\pmbdeviceinfoprovider.exe [2009-10-24 360224]
r2 tabletservicepen;tabletservicepen;c:\program files\tablet\pen\pen_tablet.exe [2012-11-25 6583160]
r2 touchservicepen;wacom consumer touch service;c:\program files\tablet\pen\pen_touchservice.exe [2012-11-25 528760]
r2 tuneup.utilitiessvc;tuneup utilities service;c:\program files (x86)\tuneup utilities 2013\tuneuputilitiesservice64.exe [2013-10-11 2409272]
r3 atihdaudioservice;amd function driver for hd audio service;c:\windows\system32\drivers\atihdw76.sys [2013-5-14 231440]
r3 mbamprotector;mbamprotector;c:\windows\system32\drivers\mbam.sys [2013-12-9 25928]
r3 netr28x;ralink 802.11n extensible wireless driver;c:\windows\system32\drivers\netr28x.sys [2010-8-3 2431792]
r3 rtl8167;realtek 8167 nt driver;c:\windows\system32\drivers\rt64win7.sys [2010-8-3 346144]
r3 tuneuputilitiesdrv;tuneuputilitiesdrv;c:\program files (x86)\tuneup utilities 2013\tuneuputilitiesdriver64.sys [2012-9-19 11880]
r3 usbfilter;amd usb filter driver;c:\windows\system32\drivers\usbfilter.sys [2010-8-3 39480]
r3 wacmoumonitor;wacom mode helper;c:\windows\system32\drivers\wacmoumonitor.sys [2012-11-25 13312]
s2 clr_optimization_v4.0.30319_32;microsoft .net framework ngen v4.0.30319_x86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
s2 clr_optimization_v4.0.30319_64;microsoft .net framework ngen v4.0.30319_x64;c:\windows\microsoft.net\framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
s2 liveupdatesvc;liveupdate;c:\program files (x86)\iobit\liveupdate\liveupdate.exe --> c:\program files (x86)\iobit\liveupdate\liveupdate.exe [?]
s3 btcom;bluetooth serial port driver;c:\windows\system32\drivers\btcomport.sys [2011-7-27 29576]
s3 btcombus;bluetooth serial port bus service;c:\windows\system32\drivers\btcombus.sys [2011-7-27 25352]
s3 btnetbus;bluetooth pan bus service;c:\windows\system32\drivers\btnetbus.sys [2011-12-21 31968]
s3 ivtbtbus;ivt bluetooth bus service;c:\windows\system32\drivers\ivtbtbus.sys [2010-4-6 27016]
s3 ov550i;ovt scanner;c:\windows\system32\drivers\ov550ivx.sys [2008-2-21 196992]
s3 pcdsrvc{56782d80-7eacdb16-06000000}_0;pcdsrvc{56782d80-7eacdb16-06000000}_0 - pcdr kernel mode service helper driver;c:\progra~1\pc-doc~1\pcdsrvc_x64.pkms [2010-1-19 23536]
s3 tsusbflt;tsusbflt;c:\windows\system32\drivers\tsusbflt.sys [2011-11-28 59392]
s3 watadminsvc;windows activation technologies-service;c:\windows\system32\wat\watadminsvc.exe [2011-11-28 1255736]
s4 fabs;fabs - helping agent for magix media database;c:\program files (x86)\common files\magix services\database\bin\fabs.exe [2011-5-24 1840128]
s4 gamesappservice;gamesappservice;c:\program files (x86)\wildtangent games\app\gamesappservice.exe [2010-10-12 206072]
s4 pdf architect helper service;pdf architect helper service;c:\program files (x86)\pdf architect\helperservice.exe [2012-11-22 1522312]
s4 pdf architect service;pdf architect service;c:\program files (x86)\pdf architect\conversionservice.exe [2012-11-22 905864]
.
=============== file associations ===============
.
shellexec: ff30.exe: open=c:\program files (x86)\reallusion\facefilter3\ffapp.exe "%1"
.
=============== created last 30 ================
.
2013-12-10 00:28:48 -------- d-----w- c:\program files\enigma software group
2013-12-10 00:28:33 -------- d-----w- c:\windows\72aaf4551e54475bb0ab5413c78d0e63.tmp
2013-12-09 23:31:23 -------- d-----w- c:\adwcleaner
2013-12-09 06:20:05 25928 ----a-w- c:\windows\system32\drivers\mbam.sys
2013-12-09 06:20:05 -------- d-----w- c:\program files (x86)\malwarebytes' anti-malware
2013-12-09 05:58:01 -------- d-----w- c:\users\chris\grabit downloads
2013-12-09 01:05:17 -------- d-----w- c:\windows\system32\log
2013-12-09 01:04:17 -------- d-----w- c:\users\chris\.android
2013-12-09 01:04:15 -------- d-----w- c:\users\chris\appdata\local\cache
2013-12-09 01:04:14 -------- d-----w- c:\users\chris\appdata\local\mobogenie
2013-12-09 01:03:36 -------- d-----w- c:\program files (x86)\mobogenie
2013-12-09 01:03:19 -------- d-----w- c:\programdata\wpm
2013-12-07 00:31:55 10285968 ----a-w- c:\programdata\microsoft\windows defender\definition updates\{f4bf6e58-afa9-4171-873f-9617e012be11}\mpengine.dll
2013-12-03 19:30:20 10285968 ----a-w- c:\programdata\microsoft\windows defender\definition updates\backup\mpengine.dll
2013-12-03 08:26:56 -------- d-----w- c:\program files (x86)\citrix
2013-11-28 13:36:55 -------- d-----w- c:\users\chris\appdata\local\juniper networks
2013-11-19 19:35:34 -------- d-----w- c:\users\chris\appdata\roaming\avast software
2013-11-13 19:36:57 1474048 ----a-w- c:\windows\system32\crypt32.dll
.
==================== find3m ====================
.
2013-12-09 06:35:25 73216 ----a-w- c:\windows\st6unst.exe
2013-12-09 06:35:25 249856 ------w- c:\windows\setup1.exe
2013-12-04 06:56:40 71048 ----a-w- c:\windows\syswow64\flashplayercplapp.cpl
2013-12-04 06:56:40 692616 ----a-w- c:\windows\syswow64\flashplayerapp.exe
2013-11-19 19:33:16 92544 ----a-w- c:\windows\system32\drivers\aswrdr2.sys
2013-11-19 19:33:16 84328 ----a-w- c:\windows\system32\drivers\aswmonflt.sys
2013-11-19 19:33:16 65776 ----a-w- c:\windows\system32\drivers\aswrvrt.sys
2013-11-19 19:33:16 43152 ----a-w- c:\windows\avastss.scr
2013-11-19 19:33:16 205320 ----a-w- c:\windows\system32\drivers\aswvmm.sys
2013-11-19 19:33:16 1032416 ----a-w- c:\windows\system32\drivers\aswsnx.sys
2013-11-11 04:50:16 267936 ------w- c:\windows\system32\mpsigstub.exe
2013-10-12 08:45:20 2241536 ----a-w- c:\windows\system32\wininet.dll
2013-10-12 08:43:37 3959808 ----a-w- c:\windows\system32\jscript9.dll
2013-10-12 08:43:32 67072 ----a-w- c:\windows\system32\iesetup.dll
2013-10-12 08:43:32 136704 ----a-w- c:\windows\system32\iesysprep.dll
2013-10-12 07:03:50 1767936 ----a-w- c:\windows\syswow64\wininet.dll
2013-10-12 07:02:33 2877952 ----a-w- c:\windows\syswow64\jscript9.dll
2013-10-12 07:02:29 61440 ----a-w- c:\windows\syswow64\iesetup.dll
2013-10-12 07:02:29 109056 ----a-w- c:\windows\syswow64\iesysprep.dll
2013-10-12 06:35:26 2706432 ----a-w- c:\windows\system32\mshtml.tlb
2013-10-12 06:08:58 2706432 ----a-w- c:\windows\syswow64\mshtml.tlb
2013-10-12 05:44:38 89600 ----a-w- c:\windows\system32\registeriepkeys.exe
2013-10-12 05:15:39 71680 ----a-w- c:\windows\syswow64\registeriepkeys.exe
2013-10-12 02:30:42 830464 ----a-w- c:\windows\system32\nshwfp.dll
2013-10-12 02:29:21 859648 ----a-w- c:\windows\system32\ikeext.dll
2013-10-12 02:29:08 324096 ----a-w- c:\windows\system32\fwpuclnt.dll
2013-10-12 02:03:08 656896 ----a-w- c:\windows\syswow64\nshwfp.dll
2013-10-12 02:01:25 216576 ----a-w- c:\windows\syswow64\fwpuclnt.dll
2013-10-11 14:38:12 35640 ----a-w- c:\windows\system32\turegopt.exe
2013-10-11 14:38:08 38200 ----a-w- c:\windows\system32\uxtuneup.dll
2013-10-11 14:38:08 30520 ----a-w- c:\windows\syswow64\uxtuneup.dll
2013-10-11 14:38:08 26936 ----a-w- c:\windows\system32\authuitu.dll
2013-10-11 14:38:08 22328 ----a-w- c:\windows\syswow64\authuitu.dll
2013-10-08 06:50:37 96168 ----a-w- c:\windows\syswow64\windowsaccessbridge-32.dll
2013-10-05 19:57:25 1168384 ----a-w- c:\windows\syswow64\crypt32.dll
2013-10-04 02:28:31 190464 ----a-w- c:\windows\system32\smartcardcredentialprovider.dll
2013-10-04 02:25:17 197120 ----a-w- c:\windows\system32\credui.dll
2013-10-04 02:24:49 1930752 ----a-w- c:\windows\system32\authui.dll
2013-10-04 01:58:50 152576 ----a-w- c:\windows\syswow64\smartcardcredentialprovider.dll
2013-10-04 01:56:25 168960 ----a-w- c:\windows\syswow64\credui.dll
2013-10-04 01:56:00 1796096 ----a-w- c:\windows\syswow64\authui.dll
2013-10-03 02:23:48 404480 ----a-w- c:\windows\system32\gdi32.dll
2013-10-03 02:00:44 311808 ----a-w- c:\windows\syswow64\gdi32.dll
2013-09-28 01:09:10 497152 ----a-w- c:\windows\system32\drivers\afd.sys
2013-09-25 02:26:40 95680 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2013-09-25 02:26:40 154560 ----a-w- c:\windows\system32\drivers\ksecpkg.sys
2013-09-25 02:23:33 28672 ----a-w- c:\windows\system32\sspisrv.dll
2013-09-25 02:23:33 135680 ----a-w- c:\windows\system32\sspicli.dll
2013-09-25 02:23:01 28160 ----a-w- c:\windows\system32\secur32.dll
2013-09-25 02:22:59 340992 ----a-w- c:\windows\system32\schannel.dll
2013-09-25 02:21:50 307200 ----a-w- c:\windows\system32\ncrypt.dll
2013-09-25 02:21:07 1447936 ----a-w- c:\windows\system32\lsasrv.dll
2013-09-25 01:58:17 96768 ----a-w- c:\windows\syswow64\sspicli.dll
2013-09-25 01:57:26 22016 ----a-w- c:\windows\syswow64\secur32.dll
2013-09-25 01:57:24 247808 ----a-w- c:\windows\syswow64\schannel.dll
2013-09-25 01:56:42 220160 ----a-w- c:\windows\syswow64\ncrypt.dll
2013-09-25 01:03:24 30720 ----a-w- c:\windows\system32\lsass.exe
.
============= finish: 4:27:58,46 ===============

[/hjt]


mbam log

Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org

Databaseversie: v2013.12.10.01

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 10.0.9200.16736
Chris :: CHRIS-HP [administrator]

10-12-2013 4:44:07
mbam-log-2013-12-10 (04-44-07).txt

Scan type: Snelle scan
Ingeschakelde scan opties: Geheugen | Opstartitems | Register | Bestanden en mappen | Heuristiek/Extra | Heuristiek/Shuriken | PUP | PUM
Uitgeschakelde scan opties: P2P
Objecten gescand: 216540
Verstreken tijd: 4 minuut/minuten, 44 seconde(n)

Geheugenprocessen gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)

Geheugenmodulen gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)

Registersleutels gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)

Registerwaarden gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)

Registerdata gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)

Mappen gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)

Bestanden gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)

(einde)
 
Re: Nation Zoom opent in IE en in Chrome Niet te verwijderen.

We kijken verder:

Download
51f51523a23a0-OTL_Canned_Nieuw.png
OTL.exe

Downloadlokatie: Dit programma absoluut naar het bureaublad downloaden of anders naar het bureaublad verplaatsen!
Sluit voordat OTL.exe gaat scannen, eerst alle andere openstaande vensters!

OTL.exe gebruiken:
    • Windows 2000 en Windows XP: dubbelklik op OTL.exe.
    • Windows Vista, Windows 7 en Windows 8: via rechtsklik op OTL.exe en kies voor "Als Administrator uitvoeren".

  • Zet een vinkje bij Scan All Users, LOP Check en bij PURITY Check.
  • Kopieer onderstaande in de Code-kader staande tekst en plak deze in het kader onder
    4f9111a6d2a6c-OTL-2.png


    Code:
    services.*
    explorer.exe
    winlogon.exe
    Userinit.exe
    svchost.exe
    netsvcs
    BASESERVICES
    DRIVES
    msconfig
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\system32\drivers\*.sys /lockedfiles
    %systemroot%\system32\*.exe /lockedfiles
    %PROGRAMFILES%\*
  • Klik vervolgens op de knop
    50cd93c69be5b-OTL_-_Run_Scan_knop.jpg
    .
  • Verander verder geen andere instellingen in OTL, alleen tenzij ik hiervoor specifiek instructies geef.
  • De scan zal niet heel erg lang duren.
    • Er zullen twee Kladblok-vensters geopend worden wanneer de scan klaar is: OTL.Txt en Extras.txt.
    • Kopieer vervolgens de inhoud van zowel OTL.txt alsmede Extras.txt en plak die gegevens in je volgende bericht.


Notabene: indien het log niet in ??n bericht past, spreidt het dan over twee of meer berichten.
 
Re: Nation Zoom opent in IE en in Chrome Niet te verwijderen.

Abraham
Ik had vanochtend ook mbam maar dan alles scna nog eens opgestrta bijna 6 uur! Maar dan pakt die ook partitie Z en externe HD K mee, waardoor er nogal wat verwijderd kon worden. Ook nog 2 op de C-schijf intussen weer.
Hierbij log van deze mbam en dan zet ik de andere in volgend bericht(en)

Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org

Databaseversie: v2013.12.10.01

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 10.0.9200.16736
Chris :: CHRIS-HP [administrator]

10-12-2013 5:27:43
mbam-log-2013-12-10 (05-27-43).txt

Scan type: Volledige scan (C:\|D:\|K:\|Z:\|)
Ingeschakelde scan opties: Geheugen | Opstartitems | Register | Bestanden en mappen | Heuristiek/Extra | Heuristiek/Shuriken | PUP | PUM
Uitgeschakelde scan opties: P2P
Objecten gescand: 1780205
Verstreken tijd: 5 uur/uren, 26 minuut/minuten, 39 seconde(n)

Geheugenprocessen gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)

Geheugenmodulen gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)

Registersleutels gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)

Registerwaarden gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)

Registerdata gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)

Mappen gedetecteerd: 0
(Geen kwaadaardige objecten gedetecteerd)

Bestanden gedetecteerd: 24
C:\Users\Chris\Downloads\progs\installer_ulead_photo_express.exe (PUP.BundleInstaller.BT) -> Succesvol in quarantaine geplaatst en verwijderd.
C:\Users\Chris\Downloads\progs\pictomio.exe (PUP.Optional.OpenCandy) -> Succesvol in quarantaine geplaatst en verwijderd.
K:\all chris user\DownLoads\pictomio.exe (PUP.Optional.OpenCandy) -> Succesvol in quarantaine geplaatst en verwijderd.
K:\all chris user\DownLoads\progs\installer_ulead_photo_express.exe (PUP.BundleInstaller.BT) -> Succesvol in quarantaine geplaatst en verwijderd.
K:\Downloads\pictomio.exe (PUP.Optional.OpenCandy) -> Succesvol in quarantaine geplaatst en verwijderd.
K:\Downloads\Beer.Box.Art.rar__3865_i171947115_il6695672.exe (PUP.Optional.InstallMonetizer) -> Succesvol in quarantaine geplaatst en verwijderd.
K:\Downloads\Beer.Box.Art.rar__3865_i171948141_il6695672.exe (PUP.Optional.InstallMonetizer) -> Succesvol in quarantaine geplaatst en verwijderd.
K:\Downloads\SetupImgBurn_2.5.8.0.exe (PUP.Optional.OpenCandy) -> Succesvol in quarantaine geplaatst en verwijderd.
K:\Downloads\Zylom-Installer_LUXORGreatAdventures_NL.exe (PUP.Optional.OpenCandy) -> Succesvol in quarantaine geplaatst en verwijderd.
K:\Downloads\progs\installer_ulead_photo_express.exe (PUP.BundleInstaller.BT) -> Succesvol in quarantaine geplaatst en verwijderd.
K:\Downloads\progs\pictomio.exe (PUP.Optional.OpenCandy) -> Succesvol in quarantaine geplaatst en verwijderd.
K:\All USBsticks\4shared_desktop_3.3.5.exe (PUP.Optional.4Shared) -> Succesvol in quarantaine geplaatst en verwijderd.
K:\Else4-2010\TRAW\pdfcracker.exe (Hacktool.Agent) -> Succesvol in quarantaine geplaatst en verwijderd.
K:\Navigatie\HC2Setup64.exe (PUP.Optional.Somoto) -> Succesvol in quarantaine geplaatst en verwijderd.
K:\Steampunk art and brushes\7ZipSetup.exe (PUP.Optional.Somoto) -> Succesvol in quarantaine geplaatst en verwijderd.
K:\Chris\Downloads\pictomio.exe (PUP.Optional.OpenCandy) -> Succesvol in quarantaine geplaatst en verwijderd.
K:\Chris\Downloads\WinUtilitiesPro.zip (PUP.Riskware.GameCheat) -> Succesvol in quarantaine geplaatst en verwijderd.
K:\Chris\Downloads\progs\installer_ulead_photo_express.exe (PUP.BundleInstaller.BT) -> Succesvol in quarantaine geplaatst en verwijderd.
K:\Chris\Downloads\Perfect Effects onone software\installer_adobe_camera_raw.exe (PUP.BundleInstaller.BEN) -> Succesvol in quarantaine geplaatst en verwijderd.
K:\ELSE4\TRAW\pdfcracker.exe (Hacktool.Agent) -> Succesvol in quarantaine geplaatst en verwijderd.
Z:\All USBsticks\4shared_desktop_3.3.5.exe (PUP.Optional.4Shared) -> Succesvol in quarantaine geplaatst en verwijderd.
Z:\Navigatie\HC2Setup64.exe (PUP.Optional.Somoto) -> Succesvol in quarantaine geplaatst en verwijderd.
Z:\verzameld\iLividSetupV1.exe (PUP.Optional.Bandoo) -> Succesvol in quarantaine geplaatst en verwijderd.
Z:\verzameld\Zylom-Installer_LUXORGreatAdventures_NL.exe (PUP.Optional.OpenCandy) -> Succesvol in quarantaine geplaatst en verwijderd.

(einde)
 
Re: Nation Zoom opent in IE en in Chrome Niet te verwijderen.

hierbij OTL txt

OTL logfile created on: 12/10/2013 11:59:05 AM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Chris\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16736)
Locale: 00000409 | Country: Nederland | Language: NLD | Date Format: d-M-yyyy

6.00 Gb Total Physical Memory | 4.34 Gb Available Physical Memory | 72.40% Memory free
7.07 Gb Paging File | 5.00 Gb Available in Paging File | 70.65% Paging File free
Paging file location(s): c:\pagefile.sys 100 100z:\pagefil [Binary data over 200 bytes]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 465.85 Gb Total Space | 283.37 Gb Free Space | 60.83% Space Free | Partition Type: NTFS
Drive D: | 11.69 Gb Total Space | 1.41 Gb Free Space | 12.09% Space Free | Partition Type: NTFS
Drive K: | 1396.92 Gb Total Space | 705.66 Gb Free Space | 50.52% Space Free | Partition Type: FAT32
Drive Z: | 453.87 Gb Total Space | 204.11 Gb Free Space | 44.97% Space Free | Partition Type: NTFS

Computer Name: CHRIS-HP | User Name: Chris | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2013/12/10 11:53:39 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Chris\Desktop\OTL.exe
PRC - [2013/12/06 04:14:45 | 000,223,112 | ---- | M] (Google Inc.) -- C:\Program Files (x86)\Google\Update\1.3.22.3\GoogleCrashHandler.exe
PRC - [2013/11/19 20:33:15 | 003,568,312 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe
PRC - [2013/11/19 20:33:15 | 000,050,344 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe
PRC - [2013/08/22 13:00:04 | 000,220,504 | ---- | M] (Garmin Ltd or its subsidiaries) -- C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe
PRC - [2013/05/10 08:57:22 | 000,065,640 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2013/04/04 14:50:32 | 000,701,512 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2013/04/04 14:50:32 | 000,532,040 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2013/04/04 14:50:32 | 000,418,376 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
PRC - [2012/10/13 01:54:40 | 001,088,424 | ---- | M] (Nokia) -- C:\Program Files (x86)\Nokia\Nokia Suite\NokiaSuite.exe
PRC - [2010/03/24 14:42:10 | 000,599,328 | ---- | M] (Sony Corporation) -- C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe
PRC - [2010/03/18 10:19:26 | 000,113,152 | ---- | M] (ArcSoft Inc.) -- C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
PRC - [2010/03/10 13:26:48 | 000,189,728 | ---- | M] (Protexis Inc.) -- C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
PRC - [2010/01/25 20:00:00 | 000,514,232 | ---- | M] (EasyBits Software AS) -- C:\Windows\SysWOW64\ezSharedSvcHost.exe
PRC - [2009/10/24 02:18:54 | 000,360,224 | ---- | M] (Sony Corporation) -- C:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe
PRC - [2008/11/20 18:47:28 | 000,062,768 | ---- | M] (Hewlett-Packard) -- C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe


========== Modules (No Company Name) ==========

MOD - [2013-11-19 20:33:15 | 019,336,120 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\libcef.dll
MOD - [2012/10/13 01:55:38 | 000,276,392 | ---- | M] () -- C:\Program Files (x86)\Nokia\Nokia Suite\phonon4.dll
MOD - [2012/10/13 01:55:38 | 000,092,584 | ---- | M] () -- C:\Program Files (x86)\Nokia\Nokia Suite\qjson.dll
MOD - [2012/10/13 01:55:22 | 002,652,584 | ---- | M] () -- C:\Program Files (x86)\Nokia\Nokia Suite\QtXmlPatterns4.dll
MOD - [2012/10/13 01:55:22 | 000,363,944 | ---- | M] () -- C:\Program Files (x86)\Nokia\Nokia Suite\QtXml4.dll
MOD - [2012/10/13 01:55:20 | 011,166,120 | ---- | M] () -- C:\Program Files (x86)\Nokia\Nokia Suite\QtWebKit4.dll
MOD - [2012/10/13 01:55:18 | 001,346,472 | ---- | M] () -- C:\Program Files (x86)\Nokia\Nokia Suite\QtScript4.dll
MOD - [2012/10/13 01:55:18 | 000,205,736 | ---- | M] () -- C:\Program Files (x86)\Nokia\Nokia Suite\QtSql4.dll
MOD - [2012/10/13 01:55:16 | 001,013,672 | ---- | M] () -- C:\Program Files (x86)\Nokia\Nokia Suite\QtNetwork4.dll
MOD - [2012/10/13 01:55:16 | 000,720,296 | ---- | M] () -- C:\Program Files (x86)\Nokia\Nokia Suite\QtOpenGL4.dll
MOD - [2012/10/13 01:55:14 | 008,506,792 | ---- | M] () -- C:\Program Files (x86)\Nokia\Nokia Suite\QtGui4.dll
MOD - [2012/10/13 01:55:14 | 000,520,104 | ---- | M] () -- C:\Program Files (x86)\Nokia\Nokia Suite\QtMultimediaKit1.dll
MOD - [2012/10/13 01:55:12 | 002,480,552 | ---- | M] () -- C:\Program Files (x86)\Nokia\Nokia Suite\QtDeclarative4.dll
MOD - [2012/10/13 01:55:12 | 002,353,576 | ---- | M] () -- C:\Program Files (x86)\Nokia\Nokia Suite\QtCore4.dll
MOD - [2012/10/13 01:55:08 | 000,445,864 | ---- | M] () -- C:\Program Files (x86)\Nokia\Nokia Suite\sqldrivers\qsqlite4.dll
MOD - [2012/10/13 01:55:04 | 000,206,760 | ---- | M] () -- C:\Program Files (x86)\Nokia\Nokia Suite\Imageformats\qjpeg4.dll
MOD - [2012/10/13 01:55:04 | 000,035,240 | ---- | M] () -- C:\Program Files (x86)\Nokia\Nokia Suite\Imageformats\qico4.dll
MOD - [2012/10/13 01:55:02 | 000,032,680 | ---- | M] () -- C:\Program Files (x86)\Nokia\Nokia Suite\Imageformats\qgif4.dll
MOD - [2012/10/13 01:54:34 | 000,437,672 | ---- | M] () -- C:\Program Files (x86)\Nokia\Nokia Suite\NService.dll
MOD - [2012/10/13 01:53:56 | 000,605,608 | ---- | M] () -- C:\Program Files (x86)\Nokia\Nokia Suite\CommonUpdateChecker.dll
MOD - [2012/10/13 01:31:20 | 000,391,600 | ---- | M] () -- C:\Program Files (x86)\Nokia\Nokia Suite\ssoengine.dll
MOD - [2012/10/13 01:31:20 | 000,059,280 | ---- | M] () -- C:\Program Files (x86)\Nokia\Nokia Suite\securestorage.dll
MOD - [2012/10/13 01:30:34 | 000,110,080 | ---- | M] () -- C:\Program Files (x86)\Nokia\Nokia Suite\mediaservice\dsengine.dll
MOD - [2012/05/23 16:00:02 | 008,626,176 | ---- | M] () -- C:\Program Files (x86)\Common Files\LightScribe\QtGui4.dll
MOD - [2012/05/23 16:00:00 | 002,408,448 | ---- | M] () -- C:\Program Files (x86)\Common Files\LightScribe\QtCore4.dll
MOD - [2012/05/23 16:00:00 | 000,212,992 | ---- | M] () -- C:\Program Files (x86)\Common Files\LightScribe\plugins\imageformats\qjpeg4.dll


========== Services (SafeList) ==========

SRV:64bit: - [2013-11-19 20:33:15 | 000,050,344 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)
SRV:64bit: - [2013-10-11 15:38:08 | 000,038,200 | ---- | M] (TuneUp Software) [Auto | Running] -- C:\Windows\SysNative\uxtuneup.dll -- (UxTuneUp)
SRV:64bit: - [2013-05-27 06:50:47 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:64bit: - [2011-10-24 12:16:40 | 000,204,288 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:64bit: - [2011-09-08 17:48:36 | 006,583,160 | ---- | M] (Wacom Technology, Corp.) [Auto | Running] -- C:\Program Files\Tablet\Pen\Pen_Tablet.exe -- (TabletServicePen)
SRV:64bit: - [2011-09-08 17:48:36 | 000,528,760 | ---- | M] (Wacom Technology, Corp.) [Auto | Running] -- C:\Program Files\Tablet\Pen\Pen_TouchService.exe -- (TouchServicePen)
SRV - [2013-12-04 07:56:40 | 000,257,416 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2013-10-11 15:38:10 | 002,409,272 | ---- | M] (TuneUp Software) [Auto | Running] -- C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesService64.exe -- (TuneUp.UtilitiesSvc)
SRV - [2013-10-11 15:38:08 | 000,030,520 | ---- | M] (TuneUp Software) [Auto | Running] -- C:\Windows\SysWOW64\uxtuneup.dll -- (UxTuneUp)
SRV - [2013-08-22 13:00:04 | 000,220,504 | ---- | M] (Garmin Ltd or its subsidiaries) [Auto | Running] -- C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe -- (Garmin Core Update Service)
SRV - [2013-05-10 08:57:22 | 000,065,640 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2013-04-04 14:50:32 | 000,701,512 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2013-04-04 14:50:32 | 000,418,376 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe -- (MBAMScheduler)
SRV - [2012-11-22 16:58:14 | 001,522,312 | ---- | M] (pdfforge GbR) [Disabled | Stopped] -- C:\Program Files (x86)\PDF Architect\HelperService.exe -- (PDF Architect Helper Service)
SRV - [2012-11-22 16:56:10 | 000,905,864 | ---- | M] (pdfforge GbR) [Disabled | Stopped] -- C:\Program Files (x86)\PDF Architect\ConversionService.exe -- (PDF Architect Service)
SRV - [2012-10-03 15:51:04 | 000,725,400 | ---- | M] (Nokia) [Disabled | Stopped] -- C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
SRV - [2012-09-27 11:55:16 | 000,086,528 | ---- | M] (Hewlett-Packard Company) [Auto | Running] -- C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe -- (HP Support Assistant Service)
SRV - [2011-05-24 10:33:30 | 001,840,128 | ---- | M] (MAGIX AG) [Disabled | Stopped] -- C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe -- (Fabs)
SRV - [2010-10-12 18:59:12 | 000,206,072 | ---- | M] (WildTangent, Inc.) [Disabled | Stopped] -- C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe -- (GamesAppService)
SRV - [2010-03-18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2010-03-18 10:19:26 | 000,113,152 | ---- | M] (ArcSoft Inc.) [Auto | Running] -- C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe -- (ACDaemon)
SRV - [2010-03-10 13:26:48 | 000,189,728 | ---- | M] (Protexis Inc.) [Auto | Running] -- C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe -- (PSI_SVC_2)
SRV - [2010-01-04 19:03:42 | 000,238,328 | ---- | M] (WildTangent, Inc.) [Disabled | Stopped] -- C:\Program Files (x86)\HP Games\HP Game Console\GameConsoleService.exe -- (GameConsoleService)
SRV - [2009-10-24 02:18:54 | 000,360,224 | ---- | M] (Sony Corporation) [Auto | Running] -- C:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe -- (PMBDeviceInfoProvider)
SRV - [2009-06-10 22:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)


========== Driver Services (SafeList) ==========

DRV:64bit: - File not found [Kernel | On_Demand | Stopped] -- C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys -- (esgiguard)
DRV:64bit: - [2013-11-19 20:33:16 | 001,032,416 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\SysNative\drivers\aswSnx.sys -- (aswSnx)
DRV:64bit: - [2013-11-19 20:33:16 | 000,409,832 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswSP.sys -- (aswSP)
DRV:64bit: - [2013-11-19 20:33:16 | 000,205,320 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\aswVmm.sys -- (aswVmm)
DRV:64bit: - [2013-11-19 20:33:16 | 000,092,544 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswRdr2.sys -- (aswRdr)
DRV:64bit: - [2013-11-19 20:33:16 | 000,084,328 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\aswMonFlt.sys -- (aswMonFlt)
DRV:64bit: - [2013-11-19 20:33:16 | 000,065,776 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\aswRvrt.sys -- (aswRvrt)
DRV:64bit: - [2013-11-19 20:33:16 | 000,065,264 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswTdi.sys -- (aswTdi)
DRV:64bit: - [2013-11-19 20:33:16 | 000,038,984 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV:64bit: - [2013-04-12 18:19:24 | 002,431,792 | ---- | M] (Ralink Technology, Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\netr28x.sys -- (netr28x)
DRV:64bit: - [2013-04-04 14:50:32 | 000,025,928 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\mbam.sys -- (MBAMProtector)
DRV:64bit: - [2012-10-24 13:49:46 | 000,034,840 | ---- | M] (Colasoft Co., Ltd.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\CSN5PDTS82x64.sys -- (CSN5PDTS82x64)
DRV:64bit: - [2012-06-27 15:18:52 | 000,026,112 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\pccsmcfdx64.sys -- (pccsmcfd)
DRV:64bit: - [2012-04-13 11:05:16 | 000,075,016 | ---- | M] (FTDI Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ftdibus.sys -- (FTDIBUS)
DRV:64bit: - [2012-04-13 11:05:02 | 000,085,384 | ---- | M] (FTDI Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ftser2k.sys -- (FTSER2K)
DRV:64bit: - [2012-03-01 07:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2011-12-27 10:18:48 | 000,043,616 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btcusb.sys -- (Btcsrusb)
DRV:64bit: - [2011-12-21 14:47:52 | 000,031,968 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btnetBus.sys -- (btnetBUs)
DRV:64bit: - [2011-12-21 14:47:08 | 000,025,056 | ---- | M] (IVT Corporation.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\BtHidBus.sys -- (BtHidBus)
DRV:64bit: - [2011-10-24 12:56:52 | 010,203,648 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)
DRV:64bit: - [2011-10-24 11:40:06 | 000,310,784 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
DRV:64bit: - [2011-09-08 17:49:36 | 000,013,312 | ---- | M] (Wacom Technology) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\wacmoumonitor.sys -- (wacmoumonitor)
DRV:64bit: - [2011-09-08 17:49:24 | 000,016,168 | ---- | M] (Wacom Technology) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\wacomvhid.sys -- (wacomvhid)
DRV:64bit: - [2011-07-27 10:29:08 | 000,025,352 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btcombus.sys -- (BTCOMBUS)
DRV:64bit: - [2011-07-27 10:28:58 | 000,029,576 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btcomport.sys -- (BTCOM)
DRV:64bit: - [2011-06-07 05:07:00 | 000,231,440 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtihdW76.sys -- (AtiHDAudioService)
DRV:64bit: - [2010-11-20 14:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010-11-20 12:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2010-04-06 18:32:48 | 000,027,016 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\IvtBtBus.sys -- (IvtBtBUs)
DRV:64bit: - [2010-03-10 17:33:52 | 000,016,440 | ---- | M] (Advanced Micro Devices Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\AtiPcie64.sys -- (AtiPcie)
DRV:64bit: - [2010-03-04 15:43:00 | 000,346,144 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2010-01-19 20:44:32 | 000,023,536 | ---- | M] (PC-Doctor, Inc.) [Kernel | On_Demand | Stopped] -- c:\Program Files\PC-Doctor for Windows\pcdsrvc_x64.pkms -- (PCDSRVC{56782D80-7EACDB16-06000000}_0)
DRV:64bit: - [2009-11-18 13:30:56 | 000,123,408 | ---- | M] (ATI Technologies, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\AtiHdmi.sys -- (AtiHdmiService)
DRV:64bit: - [2009-10-19 22:45:54 | 000,039,480 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\usbfilter.sys -- (usbfilter)
DRV:64bit: - [2009-10-08 01:13:34 | 000,070,200 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2009-10-08 01:13:34 | 000,028,728 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2009-07-14 02:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009-07-14 02:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009-07-14 02:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009-07-14 01:10:47 | 000,011,264 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\rootmdm.sys -- (ROOTMODEM)
DRV:64bit: - [2009-06-10 21:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009-06-10 21:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009-06-10 21:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009-06-10 21:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2008-02-21 09:10:36 | 000,196,992 | ---- | M] (Omnivision Technologies, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ov550ivx.sys -- (OV550I)
DRV:64bit: - [2007-05-23 04:25:18 | 000,019,728 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\BtNetDrv.sys -- (BT)
DRV:64bit: - [2007-05-11 03:12:06 | 000,038,160 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\blueletaudio.sys -- (BlueletAudio)
DRV:64bit: - [2007-03-05 05:48:12 | 000,037,648 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\BlueletSCOAudio.sys -- (BlueletSCOAudio)
DRV:64bit: - [2007-03-05 05:42:54 | 000,049,680 | ---- | M] (IVT Corporation.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\BTHidMgr.sys -- (BTHidMgr)
DRV:64bit: - [2007-03-05 05:41:34 | 000,024,976 | ---- | M] (IVT Corporation.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\VBTEnum.sys -- (BTHidEnum)
DRV:64bit: - [2007-03-05 05:39:28 | 000,063,248 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\VcommMgr.sys -- (VcommMgr)
DRV:64bit: - [2007-03-05 05:38:20 | 000,047,120 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\VComm.sys -- (VComm)
DRV:64bit: - [2007-02-16 11:12:00 | 000,012,848 | ---- | M] (Wacom Technology) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\wacommousefilter.sys -- (wacommousefilter)
DRV - [2012-09-19 10:50:50 | 000,011,880 | ---- | M] (TuneUp Software) [Kernel | On_Demand | Running] -- C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesDriver64.sys -- (TuneUpUtilitiesDrv)
DRV - [2009-07-14 02:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
DRV - [2007-05-23 04:25:18 | 000,019,728 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysWOW64\drivers\btnetdrv.sys -- (BT)
DRV - [2007-05-23 04:25:12 | 000,044,688 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\btcusb.sys -- (Btcsrusb)
DRV - [2007-05-11 03:12:06 | 000,038,160 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysWOW64\drivers\blueletaudio.sys -- (BlueletAudio)
DRV - [2007-03-05 05:48:12 | 000,037,648 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysWOW64\drivers\BlueletSCOAudio.sys -- (BlueletSCOAudio)
DRV - [2007-03-05 05:42:54 | 000,049,680 | ---- | M] (IVT Corporation.) [Kernel | Boot | Running] -- C:\Windows\SysWOW64\drivers\BtHidMgr.sys -- (BTHidMgr)
DRV - [2007-03-05 05:41:34 | 000,024,976 | ---- | M] (IVT Corporation.) [Kernel | Boot | Running] -- C:\Windows\SysWOW64\drivers\VBTEnum.sys -- (BTHidEnum)
DRV - [2007-03-05 05:39:28 | 000,063,248 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysWOW64\drivers\VCommMgr.sys -- (VcommMgr)
DRV - [2007-03-05 05:38:20 | 000,047,120 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysWOW64\drivers\VComm.sys -- (VComm)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.nationzoom.com/?type=hp&...HitachiXHDS721010CLA332_JP2940HD0S1YMC0S1YMCX
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.nationzoom.com/web/?type=ds&ts=1386550966&from=adks&uid=HitachiXHDS721010CLA332_JP2940HD0S1YMC0S1YMCX&q={searchTerms}
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.nationzoom.com/web/?type=ds&ts=1386550966&from=adks&uid=HitachiXHDS721010CLA332_JP2940HD0S1YMC0S1YMCX&q={searchTerms}
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.nationzoom.com/?type=hp&...HitachiXHDS721010CLA332_JP2940HD0S1YMC0S1YMCX
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.nationzoom.com/web/?type=ds&ts=1386550966&from=adks&uid=HitachiXHDS721010CLA332_JP2940HD0S1YMC0S1YMCX&q={searchTerms}
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.nationzoom.com/web/?type=ds&ts=1386550966&from=adks&uid=HitachiXHDS721010CLA332_JP2940HD0S1YMC0S1YMCX&q={searchTerms}
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {33BB0A4E-99AF-4226-BDF6-49120163DE86}
IE:64bit: - HKLM\..\SearchScopes\{3A7E8335-43F8-4822-815F-8992CC4F0B69}: "URL" = http://www.bing.com/search?q={searchTerms}&form=HPDTDF&pc=HPDTDF&src=IE-SearchBox
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.google.com/
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{3A7E8335-43F8-4822-815F-8992CC4F0B69}: "URL" = http://www.bing.com/search?q={searchTerms}&form=HPDTDF&pc=HPDTDF&src=IE-SearchBox

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.zeelandnet.nl/index.php/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = nl-NL
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = BD B5 13 FE 6D 07 CE 01 [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


========== FireFox ==========

FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_43: C:\Windows\system32\npdeployJava1.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.45.2: C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.45.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nokia.com/EnablerPlugin: C:\Program Files (x86)\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll ( )
FF - HKLM\Software\MozillaPlugins\@spoon.net/Spoon Plugin 3.32: C:\Program Files (x86)\Spoon\3.32.2.12\npMozillaSpoonPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@wacom.com/wtPlugin,version=2.0.0.1: C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll (Wacom)
FF - HKLM\Software\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\wacom.com/WacomTabletPlugin: C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll (Wacom)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\FFPDFArchitectConverter@pdfarchitect.com: C:\Program Files (x86)\PDF Architect\FFPDFArchitectExt [2012-12-13 20:45:31 | 000,000,000 | ---D | M]

[2012-11-11 11:55:43 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Chris\AppData\Roaming\mozilla\Firefox\extensions
[2012-11-11 11:55:43 | 000,000,000 | ---D | M] (uTorrentBar_NL) -- C:\Users\Chris\AppData\Roaming\mozilla\Firefox\extensions\{87775fdb-6972-41f9-ae51-8326e38cb206}
[2013-11-03 11:08:37 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Chris\AppData\Roaming\mozilla\Firefox\Profiles\extensions
[2013-11-03 12:41:50 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Chris\AppData\Roaming\mozilla\Firefox\Profiles\extensions\extensions
[2012-08-16 21:08:11 | 000,000,000 | ---D | M] (OneClickDownloader) -- C:\Users\Chris\AppData\Roaming\mozilla\Firefox\Profiles\extensions\OneClickDownload@OneClickDownload.com
[2013-02-05 15:08:18 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:eek:riginalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:bookmarkBarPinned}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}{google:eek:mniboxStartMarginParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}{google:pageClassification}sugkey={google:suggestAPIKeyParameter},
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\pdf.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Garmin Communicator Plug-In (Enabled) = C:\Program Files (x86)\Garmin GPS Plugin\npGarmin.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll
CHR - plugin: Java(TM) Platform SE 7 U21 (Enabled) = C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll
CHR - plugin: Nokia Suite Enabler Plugin (Enabled) = C:\Program Files (x86)\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll
CHR - plugin: WacomTabletPlugin (Enabled) = C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll
CHR - plugin: WildTangent Games App V2 Presence Detector (Enabled) = C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll
CHR - plugin: Windows Live Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - Extension: YouTube = C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: Google Zoeken = C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: avast! Online Security = C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki\8.0.8_0\
CHR - Extension: Google Maps = C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Default\Extensions\lneaknkopdijkpnocmklfnjbeapigfbh\5.2.7_0\
CHR - Extension: Google Wallet = C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.5.0_0\
CHR - Extension: Gmail = C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
CHR - Extension: YouTube = C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: Google Zoeken = C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: avast! Online Security = C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki\8.0.8_0\
CHR - Extension: Google Maps = C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Default\Extensions\lneaknkopdijkpnocmklfnjbeapigfbh\5.2.7_0\
CHR - Extension: Google Wallet = C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.5.0_0\
CHR - Extension: Gmail = C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2013-04-07 20:17:19 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2:64bit: - BHO: (ExplorerWnd Helper) - {10921475-03CE-4E04-90CE-E2E7EF20C814} - C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer64.dll File not found
O2:64bit: - BHO: (avast! Online Security) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O2:64bit: - BHO: (HP Network Check Helper) - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll (Hewlett-Packard)
O2 - BHO: (PDF Architect Helper) - {3A2D5EBA-F86D-4BD3-A177-019765996711} - C:\Program Files (x86)\PDF Architect\PDFIEHelper.dll (pdfforge GbR)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (HP Network Check Helper) - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll (Hewlett-Packard)
O3:64bit: - HKLM\..\Toolbar: (avast! Online Security) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O4:64bit: - HKLM..\Run: [hpsysdrv] c:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe (Hewlett-Packard)
O4 - HKLM..\Run: [20131121] C:\Program Files\AVAST Software\Avast\setup\emupdate\991770ab-afc8-4779-a147-d7f72b2803a9.exe (AVAST Software)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [AvastUI.exe] C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software)
O4 - HKLM..\Run: [mobilegeni daemon] C:\Program Files (x86)\Mobogenie\DaemonProcess.exe File not found
O4 - HKLM..\Run: [MyPoi Monitor] C:\Program Files (x86)\Common Files\MyPoiWorld Shared\MyPoiMonitor\MyPoiMonitor.exe (ANWB)
O4 - HKLM..\Run: [PMBVolumeWatcher] C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe (Sony Corporation)
O4 - HKLM..\Run: [SMKRun] C:\Program Files (x86)\JustWrite Office\ScreenMark.exe (Wacom Co., Ltd)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKCU..\Run: [GarminExpressTrayApp] C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe (Garmin Ltd or its subsidiaries)
O4 - HKCU..\Run: [NokiaSuite.exe] C:\Program Files (x86)\Nokia\Nokia Suite\NokiaSuite.exe (Nokia)
O4:64bit: - HKLM..\RunOnce: [NCPluginUpdater] C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\NCPluginUpdater.exe (Hewlett-Packard)
O4 - Startup: C:\Users\Chris\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma.lnk = C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: EnableShellExecuteHooks = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideFastUserSwitching = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableLockWorkstation = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableChangePassword = 0
O9:64bit: - Extra Button: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll,-103 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe (Hewlett-Packard)
O9:64bit: - Extra 'Tools' menuitem : @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll,-102 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe (Hewlett-Packard)
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - Reg Error: Key error. File not found
O9 - Extra Button: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-103 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe (Hewlett-Packard)
O9 - Extra 'Tools' menuitem : @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-102 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe (Hewlett-Packard)
O9 - Extra Button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files (x86)\WinHTTrack\WinHTTrackIEBar.dll ()
O9 - Extra 'Tools' menuitem : Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files (x86)\WinHTTrack\WinHTTrackIEBar.dll ()
O16:64bit: - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} http://h20614.www2.hp.com/ediags/gmd/Install/Cab/hpdetect121.cab (Reg Error: Key error.)
O16:64bit: - DPF: {AA570693-00E2-4907-B6F1-60A1199B030C} https://juniper.net/dana-cached/sc/JuniperSetupClient64.cab (JuniperSetupClientControl64 Class)
O16:64bit: - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {CB50428B-657F-47DF-9B32-671F82AA73F7} http://www.photodex.com/pxplay.cab (Reg Error: Key error.)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {F27237D7-93C8-44C2-AC6E-D6057B9A918F} https://webaccess.minvenw.nl/dana-cached/sc/JuniperSetupClient.cab (JuniperSetupClientControl Class)
O16 - DPF: Garmin Communicator Plug-In https://static.garmincdn.com/gcp/ie/4.0.1.0/GarminAxControl_32.CAB (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 62.238.255.69 212.115.192.100
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{F2A0558D-B9C8-4C73-8A0E-4076CC58FAF6}: DhcpNameServer = 62.238.255.69 212.115.192.100
O18:64bit: - Protocol\Handler\ipp - No CLSID value found
O18:64bit: - Protocol\Handler\ipp\0x00000001 - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\0x00000001 - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\oledb - No CLSID value found
O18:64bit: - Protocol\Handler\ms-itss - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2013-12-10 01:29:23 | 000,000,000 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2010-07-28 19:27:36 | 009,164,956 | ---- | M] () - K:\Auto.TIF -- [ FAT32 ]
O32 - AutoRun File - [2001-09-28 19:58:52 | 000,001,078 | ---- | M] () - K:\autorun.ico -- [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk /r \??\K:)
O34 - HKLM BootExecute: (autocheck autochk /p \??\K:)
O34 - HKLM BootExecute: (autocheck autochk /r \??\K:)
O34 - HKLM BootExecute: (autocheck autochk /r \??\J:)
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = ComFile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

NetSvcs:64bit: UxTuneUp - C:\Windows\SysNative\uxtuneup.dll (TuneUp Software)


========== Files/Folders - Created Within 30 Days ==========

[2013-12-10 11:53:38 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Chris\Desktop\OTL.exe
[2013-12-10 07:57:01 | 000,000,000 | ---D | C] -- C:\Users\Chris\AppData\Local\{DF6A7D33-1D24-4F76-8E87-30AEEC2DDAEA}
[2013-12-10 04:12:28 | 000,688,992 | R--- | C] (Swearware) -- C:\Users\Chris\Desktop\dds.com
[2013-12-10 00:31:23 | 000,000,000 | ---D | C] -- C:\AdwCleaner
[2013-12-09 07:20:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2013-12-09 07:20:05 | 000,025,928 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2013-12-09 07:20:05 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2013-12-09 06:58:01 | 000,000,000 | ---D | C] -- C:\Users\Chris\GrabIt Downloads
[2013-12-09 02:05:17 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\log
[2013-12-09 02:04:17 | 000,000,000 | ---D | C] -- C:\Users\Chris\.android
[2013-12-09 02:04:15 | 000,000,000 | ---D | C] -- C:\Users\Chris\AppData\Local\cache
[2013-12-09 02:04:14 | 000,000,000 | ---D | C] -- C:\Users\Chris\Documents\Mobogenie
[2013-12-09 02:04:14 | 000,000,000 | ---D | C] -- C:\Users\Chris\AppData\Local\Mobogenie
[2013-12-09 02:03:36 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mobogenie
[2013-12-09 02:03:19 | 000,000,000 | ---D | C] -- C:\ProgramData\WPM
[2013-12-03 09:26:56 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Citrix
[2013-11-28 14:36:55 | 000,000,000 | ---D | C] -- C:\Users\Chris\AppData\Local\Juniper Networks
[2013-11-19 20:35:34 | 000,000,000 | ---D | C] -- C:\Users\Chris\AppData\Roaming\AVAST Software
[2013-11-19 20:33:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast
[2013-11-17 15:32:29 | 000,526,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll
[2013-11-17 15:32:29 | 000,391,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
[2013-11-17 15:32:28 | 000,109,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iesysprep.dll
[2013-11-17 15:32:28 | 000,071,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\RegisterIEPKEYs.exe
[2013-11-17 15:32:28 | 000,067,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iesetup.dll
[2013-11-17 15:32:28 | 000,061,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iesetup.dll
[2013-11-17 15:32:28 | 000,039,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iernonce.dll
[2013-11-17 15:32:28 | 000,033,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iernonce.dll
[2013-11-17 15:32:27 | 000,136,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iesysprep.dll
[2013-11-17 15:32:27 | 000,089,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\RegisterIEPKEYs.exe
[2013-11-17 15:32:27 | 000,051,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ie4uinit.exe
[2013-11-17 15:32:25 | 000,855,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll
[2013-11-17 15:32:25 | 000,690,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll
[2013-11-17 15:32:25 | 000,603,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll
[2013-11-17 15:32:24 | 003,959,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll
[2013-11-13 20:36:57 | 001,474,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\crypt32.dll
[2013-11-13 20:36:52 | 001,930,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\authui.dll
[2013-11-13 20:36:52 | 001,796,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\authui.dll
[2013-11-13 20:36:52 | 000,197,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\credui.dll
[2013-11-13 20:36:52 | 000,190,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SmartcardCredentialProvider.dll
[2013-11-13 20:36:52 | 000,152,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\SmartcardCredentialProvider.dll
[2013-11-13 20:36:48 | 001,447,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\lsasrv.dll
[2013-11-13 20:36:48 | 000,307,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ncrypt.dll
[2013-11-13 20:36:48 | 000,135,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sspicli.dll
[2013-11-13 20:36:48 | 000,028,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sspisrv.dll
[2013-11-13 20:36:48 | 000,028,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\secur32.dll
[2013-11-13 20:36:46 | 000,404,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\gdi32.dll
[2013-11-13 20:36:44 | 000,830,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\nshwfp.dll
[2013-11-13 20:36:44 | 000,656,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\nshwfp.dll
[2013-11-13 20:36:44 | 000,324,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\FWPUCLNT.DLL
[2013-11-13 20:36:44 | 000,216,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\FWPUCLNT.DLL
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2013-12-10 11:56:31 | 000,015,792 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013-12-10 11:56:31 | 000,015,792 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013-12-10 11:53:39 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Chris\Desktop\OTL.exe
[2013-12-10 11:49:02 | 000,391,832 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2013-12-10 11:48:58 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013-12-10 11:38:00 | 000,000,940 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2013-12-10 07:49:17 | 000,000,194 | ---- | M] () -- C:\Windows\SysWow64\_WKERNEL.SYL
[2013-12-10 04:29:16 | 000,003,635 | ---- | M] () -- C:\Users\Chris\Desktop\attach.rar
[2013-12-10 04:29:01 | 001,549,498 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2013-12-10 04:29:01 | 000,701,548 | ---- | M] () -- C:\Windows\SysNative\perfh013.dat
[2013-12-10 04:29:01 | 000,616,032 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2013-12-10 04:29:01 | 000,133,580 | ---- | M] () -- C:\Windows\SysNative\perfc013.dat
[2013-12-10 04:29:01 | 000,106,412 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2013-12-10 04:12:28 | 000,688,992 | R--- | M] (Swearware) -- C:\Users\Chris\Desktop\dds.com
[2013-12-10 04:11:04 | 001,110,034 | ---- | M] () -- C:\Users\Chris\Desktop\adwcleaner.exe
[2013-12-10 01:29:23 | 000,000,000 | ---- | M] () -- C:\autoexec.bat
[2013-12-09 07:35:25 | 000,249,856 | ---- | M] (Microsoft Corporation) -- C:\Windows\Setup1.exe
[2013-12-09 07:35:25 | 000,073,216 | ---- | M] (Microsoft Corporation) -- C:\Windows\ST6UNST.EXE
[2013-12-09 07:20:07 | 000,001,129 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013-12-09 02:02:46 | 000,001,645 | ---- | M] () -- C:\Users\Chris\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2013-12-09 01:50:41 | 000,067,187 | ---- | M] () -- C:\Users\Chris\Documents\autofx dream suite moasaic serial number.pdf
[2013-12-09 01:49:57 | 000,049,846 | ---- | M] () -- C:\Users\Chris\Documents\auto fx software download and trial license number.pdf
[2013-12-07 08:50:07 | 000,000,332 | ---- | M] () -- C:\Windows\tasks\HPCeeScheduleForChris.job
[2013-12-07 05:38:35 | 000,001,054 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013-12-07 05:38:35 | 000,001,050 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013-12-04 08:28:49 | 000,031,232 | ---- | M] () -- C:\Users\Chris\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2013-12-04 08:21:57 | 000,002,232 | ---- | M] () -- C:\Users\Chris\.xmlcopyeditor
[2013-12-04 07:56:40 | 000,692,616 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe
[2013-12-04 07:56:40 | 000,071,048 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2013-12-03 14:32:03 | 000,000,342 | ---- | M] () -- C:\Windows\tasks\HPCeeScheduleForCHRIS-HP$.job
[2013-11-30 12:56:13 | 000,000,544 | ---- | M] () -- C:\Windows\tasks\PCDRScheduledMaintenance.job
[2013-11-19 20:33:16 | 001,032,416 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswSnx.sys
[2013-11-19 20:33:16 | 000,409,832 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswSP.sys
[2013-11-19 20:33:16 | 000,334,648 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\aswBoot.exe
[2013-11-19 20:33:16 | 000,205,320 | ---- | M] () -- C:\Windows\SysNative\drivers\aswVmm.sys
[2013-11-19 20:33:16 | 000,092,544 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswRdr2.sys
[2013-11-19 20:33:16 | 000,084,328 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswMonFlt.sys
[2013-11-19 20:33:16 | 000,065,776 | ---- | M] () -- C:\Windows\SysNative\drivers\aswRvrt.sys
[2013-11-19 20:33:16 | 000,065,264 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswTdi.sys
[2013-11-19 20:33:16 | 000,043,152 | ---- | M] (AVAST Software) -- C:\Windows\avastSS.scr
[2013-11-19 20:33:16 | 000,038,984 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswFsBlk.sys
[2013-11-19 20:32:32 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\config.nt
[2013-11-10 14:23:49 | 000,001,271 | ---- | M] () -- C:\Users\Public\Desktop\Corel PaintShop Pro X6 (64-bit).lnk
[2013-11-10 13:41:40 | 000,009,216 | ---- | M] () -- C:\Users\Chris\Documents\Prettigekerst2.wps
[2013-11-10 13:41:40 | 000,002,148 | ---- | M] () -- C:\Users\Chris\AppData\Roaming\wklnhst.dat
[2013-11-10 13:27:05 | 000,010,240 | ---- | M] () -- C:\Users\Chris\Documents\prettige kerst testletters.wps
[2013-11-10 13:08:45 | 000,009,216 | ---- | M] () -- C:\Users\Chris\Documents\Prettigekerst.wps
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]

========== Files Created - No Company Name ==========

[2013-12-10 04:29:16 | 000,003,635 | ---- | C] () -- C:\Users\Chris\Desktop\attach.rar
[2013-12-10 04:11:03 | 001,110,034 | ---- | C] () -- C:\Users\Chris\Desktop\adwcleaner.exe
[2013-12-10 01:29:23 | 000,000,000 | ---- | C] () -- C:\autoexec.bat
[2013-12-10 00:42:27 | 000,391,832 | ---- | C] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2013-12-09 07:20:07 | 000,001,129 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013-12-09 01:50:41 | 000,067,187 | ---- | C] () -- C:\Users\Chris\Documents\autofx dream suite moasaic serial number.pdf
[2013-12-09 01:49:56 | 000,049,846 | ---- | C] () -- C:\Users\Chris\Documents\auto fx software download and trial license number.pdf
[2013-11-10 13:41:40 | 000,009,216 | ---- | C] () -- C:\Users\Chris\Documents\Prettigekerst2.wps
[2013-11-10 13:27:05 | 000,010,240 | ---- | C] () -- C:\Users\Chris\Documents\prettige kerst testletters.wps
[2013-11-10 13:02:48 | 000,009,216 | ---- | C] () -- C:\Users\Chris\Documents\Prettigekerst.wps
[2013-09-01 11:50:17 | 000,000,186 | RHS- | C] () -- C:\Windows\FF3STET.BIN
[2013-09-01 09:34:49 | 000,000,041 | -HS- | C] () -- C:\ProgramData\.zreglib
[2013-06-02 16:04:08 | 000,470,636 | ---- | C] () -- C:\Users\Chris\MALORIGplus3blac+.2013_06_02_17_04_08.1.svg
[2013-06-02 16:04:08 | 000,029,073 | ---- | C] () -- C:\Users\Chris\MALORIGplus3blac+.2013_06_02_17_04_08.0.svg
[2013-05-14 20:13:47 | 000,003,929 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat
[2013-04-28 10:02:35 | 000,000,240 | ---- | C] () -- C:\Users\Chris\AppData\Roaming\.ptbt0
[2013-04-28 08:50:29 | 000,000,012 | ---- | C] () -- C:\ProgramData\7060
[2013-04-28 08:50:29 | 000,000,012 | ---- | C] () -- C:\Users\Chris\AppData\Local\5050
[2013-04-28 08:50:29 | 000,000,012 | ---- | C] () -- C:\Users\Chris\AppData\Roaming\4629
[2013-04-28 08:50:29 | 000,000,012 | ---- | C] () -- C:\ProgramData\3036
[2013-04-28 08:50:29 | 000,000,012 | ---- | C] () -- C:\ProgramData\0843
[2013-02-27 15:37:21 | 000,068,078 | ---- | C] () -- C:\Users\Chris\geo_sans_light.zip
[2013-02-05 16:45:58 | 000,210,944 | ---- | C] () -- C:\Windows\SysWow64\MSVCRT10.DLL
[2013-01-18 15:53:13 | 000,003,146 | ---- | C] () -- C:\Windows\SysWow64\vsort.com
[2013-01-05 12:59:11 | 000,615,254 | ---- | C] () -- C:\Users\Chris\test digi design.ddp
[2012-12-25 13:54:33 | 000,007,630 | ---- | C] () -- C:\Users\Chris\AppData\Local\Resmon.ResmonCfg
[2012-12-23 15:52:17 | 000,002,048 | ---- | C] () -- C:\Users\Chris\AppData\Roaming\Bergboek Prefs
[2012-12-23 15:06:47 | 001,901,251 | ---- | C] () -- C:\Users\Chris\SL383586abewerkt met engel 01 en tekstlaag.jpg
[2012-12-19 20:52:22 | 000,204,952 | ---- | C] () -- C:\Windows\SysWow64\ativvsvl.dat
[2012-12-19 20:52:22 | 000,157,144 | ---- | C] () -- C:\Windows\SysWow64\ativvsva.dat
[2012-12-01 10:29:31 | 000,002,232 | ---- | C] () -- C:\Users\Chris\.xmlcopyeditor
[2012-09-24 11:18:57 | 000,086,016 | ---- | C] () -- C:\Windows\SysWow64\qtXLS.dll
[2012-09-23 13:33:14 | 000,001,866 | ---- | C] () -- C:\ProgramData\gpicsync.conf
[2012-09-09 21:02:31 | 000,000,000 | ---- | C] () -- C:\Windows\CleaningLab.INI
[2012-09-09 18:24:02 | 000,010,240 | ---- | C] () -- C:\Windows\SysWow64\vidx16.dll
[2012-09-09 18:23:53 | 000,019,968 | ---- | C] () -- C:\Windows\SysWow64\cpuinf32.dll
[2012-09-09 18:19:05 | 000,006,176 | ---- | C] () -- C:\Windows\mgxoschk.ini
[2012-07-15 13:33:18 | 000,000,000 | ---- | C] () -- C:\Windows\DATAINST.INI
[2012-07-01 12:32:43 | 000,000,056 | ---- | C] () -- C:\Windows\SysWow64\ezsidmv.dat
[2012-06-15 09:05:44 | 000,000,284 | ---- | C] () -- C:\Windows\{8EF7A04E-C5A6-459E-8106-362AEE79A5F6}_WiseFW.ini
[2012-04-08 12:51:30 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2012-04-08 12:51:30 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2012-04-08 12:51:30 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2012-04-08 12:51:30 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2012-04-08 12:51:30 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2012-03-31 16:25:10 | 000,014,848 | ---- | C] () -- C:\Windows\SysWow64\BASSMOD.dll
[2012-02-23 20:44:35 | 000,000,278 | ---- | C] () -- C:\Windows\{0C6DB6B9-2D17-4AA5-A207-42D28BF9F434}_WiseFW.ini
[2012-02-01 21:13:56 | 000,581,257 | ---- | C] () -- C:\Users\Chris\B19ELEMENTS022test.jpg
[2012-02-01 21:12:27 | 000,222,766 | ---- | C] () -- C:\Users\Chris\1024X768test.jpg
[2012-01-29 11:01:19 | 000,026,039 | ---- | C] () -- C:\Users\Chris\bridge.jpg
[2012-01-29 10:39:06 | 000,461,315 | ---- | C] () -- C:\Users\Chris\SL380347atranaspar.jpg
[2011-12-04 22:44:42 | 000,002,148 | ---- | C] () -- C:\Users\Chris\AppData\Roaming\wklnhst.dat
[2011-12-02 20:20:49 | 000,031,232 | ---- | C] () -- C:\Users\Chris\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011-12-02 20:20:21 | 000,000,952 | -HS- | C] () -- C:\ProgramData\KGyGaAvL.sys

========== ZeroAccess Check ==========

[2009-07-14 05:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2013-07-26 03:24:57 | 014,172,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2013-07-26 02:55:59 | 012,872,704 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009-07-14 02:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010-11-20 13:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009-07-14 02:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== LOP Check ==========

[2012-12-13 20:45:44 | 000,000,000 | ---D | M] -- C:\Users\Chris\AppData\Roaming\APP_NAME_NON_STRING
[2012-09-06 18:37:26 | 000,000,000 | ---D | M] -- C:\Users\Chris\AppData\Roaming\Apygna
[2013-09-01 12:39:08 | 000,000,000 | ---D | M] -- C:\Users\Chris\AppData\Roaming\Athentech
[2013-11-19 20:35:34 | 000,000,000 | ---D | M] -- C:\Users\Chris\AppData\Roaming\AVAST Software
[2013-03-27 20:35:21 | 000,000,000 | ---D | M] -- C:\Users\Chris\AppData\Roaming\Belastingdienst
[2012-12-23 15:51:40 | 000,000,000 | ---D | M] -- C:\Users\Chris\AppData\Roaming\Bergboek
[2012-12-26 16:52:55 | 000,000,000 | ---D | M] -- C:\Users\Chris\AppData\Roaming\Canon
[2013-10-24 18:57:49 | 000,000,000 | ---D | M] -- C:\Users\Chris\AppData\Roaming\Colasoft Capsa 7 - Free Edition
[2013-10-25 19:26:14 | 000,000,000 | ---D | M] -- C:\Users\Chris\AppData\Roaming\Colasoft MAC Scanner
[2013-01-05 09:02:16 | 000,000,000 | ---D | M] -- C:\Users\Chris\AppData\Roaming\com.docrafts.digital
[2013-02-09 12:01:38 | 000,000,000 | ---D | M] -- C:\Users\Chris\AppData\Roaming\DAEMON Tools Lite
[2012-12-28 10:39:27 | 000,000,000 | ---D | M] -- C:\Users\Chris\AppData\Roaming\DAZ 3D
[2013-04-28 08:39:17 | 000,000,000 | ---D | M] -- C:\Users\Chris\AppData\Roaming\Easypano Panoweaver
[2012-09-01 09:08:53 | 000,000,000 | ---D | M] -- C:\Users\Chris\AppData\Roaming\ePaperPress
[2011-12-17 15:13:02 | 000,000,000 | ---D | M] -- C:\Users\Chris\AppData\Roaming\FaceOffMax
[2013-03-27 20:05:48 | 000,000,000 | ---D | M] -- C:\Users\Chris\AppData\Roaming\Garmin
[2012-07-31 03:02:10 | 000,000,000 | ---D | M] -- C:\Users\Chris\AppData\Roaming\Genealogica Grafica
[2013-11-05 20:53:42 | 000,000,000 | ---D | M] -- C:\Users\Chris\AppData\Roaming\GeoSetter
[2012-09-01 12:28:03 | 000,000,000 | ---D | M] -- C:\Users\Chris\AppData\Roaming\Golden Ratio
[2013-01-27 11:29:56 | 000,000,000 | ---D | M] -- C:\Users\Chris\AppData\Roaming\GrabIt
[2012-05-29 14:38:36 | 000,000,000 | ---D | M] -- C:\Users\Chris\AppData\Roaming\ICAClient
[2011-12-02 20:16:47 | 000,000,000 | ---D | M] -- C:\Users\Chris\AppData\Roaming\IGC
[2013-09-01 09:50:35 | 000,000,000 | ---D | M] -- C:\Users\Chris\AppData\Roaming\ImgBurn
[2013-11-03 11:28:03 | 000,000,000 | ---D | M] -- C:\Users\Chris\AppData\Roaming\inkscape
[2013-11-03 11:08:38 | 000,000,000 | ---D | M] -- C:\Users\Chris\AppData\Roaming\IObit
[2012-10-26 19:52:05 | 000,000,000 | ---D | M] -- C:\Users\Chris\AppData\Roaming\jAlbum
[2013-11-28 14:37:07 | 000,000,000 | ---D | M] -- C:\Users\Chris\AppData\Roaming\Juniper Networks
[2013-11-05 21:08:00 | 000,000,000 | ---D | M] -- C:\Users\Chris\AppData\Roaming\JustWrite Office
[2012-09-05 21:33:13 | 000,000,000 | ---D | M] -- C:\Users\Chris\AppData\Roaming\Lumaur
[2013-02-05 15:24:14 | 000,000,000 | ---D | M] -- C:\Users\Chris\AppData\Roaming\MAGIX
[2012-01-30 21:28:06 | 000,000,000 | ---D | M] -- C:\Users\Chris\AppData\Roaming\Netscape
[2012-04-25 20:26:47 | 000,000,000 | ---D | M] -- C:\Users\Chris\AppData\Roaming\Nik Software
[2012-05-18 12:40:17 | 000,000,000 | ---D | M] -- C:\Users\Chris\AppData\Roaming\Nokia
[2013-02-23 10:31:14 | 000,000,000 | ---D | M] -- C:\Users\Chris\AppData\Roaming\Obsidium
[2012-05-18 12:38:37 | 000,000,000 | ---D | M] -- C:\Users\Chris\AppData\Roaming\PC Suite
[2012-12-13 20:47:11 | 000,000,000 | ---D | M] -- C:\Users\Chris\AppData\Roaming\PDF Architect
[2013-05-12 08:04:52 | 000,000,000 | ---D | M] -- C:\Users\Chris\AppData\Roaming\Serif
[2013-05-08 20:59:53 | 000,000,000 | ---D | M] -- C:\Users\Chris\AppData\Roaming\SignCut
[2012-05-28 19:35:25 | 000,000,000 | ---D | M] -- C:\Users\Chris\AppData\Roaming\Softinterface, Inc
[2013-04-28 08:50:29 | 000,000,000 | ---D | M] -- C:\Users\Chris\AppData\Roaming\STOIKPMLOGS
[2012-12-27 10:58:58 | 000,000,000 | ---D | M] -- C:\Users\Chris\AppData\Roaming\SuperEasy Software
[2011-12-23 13:33:06 | 000,000,000 | ---D | M] -- C:\Users\Chris\AppData\Roaming\Template
[2012-12-26 13:06:03 | 000,000,000 | ---D | M] -- C:\Users\Chris\AppData\Roaming\TuneUp Software
[2012-03-27 04:59:31 | 000,000,000 | ---D | M] -- C:\Users\Chris\AppData\Roaming\Two Pilots
[2012-10-02 08:27:26 | 000,000,000 | ---D | M] -- C:\Users\Chris\AppData\Roaming\Tyre
[2013-02-05 15:35:27 | 000,000,000 | ---D | M] -- C:\Users\Chris\AppData\Roaming\Ulead Systems
[2013-02-09 12:01:37 | 000,000,000 | ---D | M] -- C:\Users\Chris\AppData\Roaming\uTorrent
[2013-10-20 15:18:39 | 000,000,000 | ---D | M] -- C:\Users\Chris\AppData\Roaming\VOS
[2013-02-05 15:30:38 | 000,000,000 | ---D | M] -- C:\Users\Chris\AppData\Roaming\WildTangent
[2011-12-11 19:24:41 | 000,000,000 | ---D | M] -- C:\Users\Chris\AppData\Roaming\WinBatch
[2011-12-04 23:01:59 | 000,000,000 | ---D | M] -- C:\Users\Chris\AppData\Roaming\Windows Live Writer
[2013-08-04 10:24:52 | 000,000,000 | ---D | M] -- C:\Users\Chris\AppData\Roaming\WirePilot
[2013-11-05 20:50:45 | 000,000,000 | ---D | M] -- C:\Users\Chris\AppData\Roaming\XnView
[2013-03-06 22:00:01 | 000,000,000 | ---D | M] -- C:\Users\Chris\AppData\Roaming\YCanPDF
[2012-10-01 09:32:55 | 000,000,000 | ---D | M] -- C:\Users\Chris\AppData\Roaming\Zoner
[2012-07-01 12:32:39 | 000,000,000 | ---D | M] -- C:\Users\Chris\AppData\Roaming\_MDLogs

========== Purity Check ==========



========== Custom Scans ==========

< services.* >
[2009-07-14 06:08:49 | 000,000,006 | -H-- | C] () -- C:\Windows\Tasks\SA.DAT
[2009-07-14 06:08:49 | 000,032,618 | ---- | C] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2011-11-27 08:13:15 | 000,000,544 | ---- | C] () -- C:\Windows\Tasks\PCDRScheduledMaintenance.job
[2011-11-27 08:19:36 | 000,000,332 | ---- | C] () -- C:\Windows\Tasks\HPCeeScheduleForChris.job
[2011-11-27 08:44:00 | 000,001,050 | ---- | C] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
[2011-11-27 08:44:06 | 000,001,054 | ---- | C] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
[2012-03-27 07:37:07 | 000,000,342 | ---- | C] () -- C:\Windows\Tasks\HPCeeScheduleForCHRIS-HP$.job
[2012-11-20 19:07:39 | 000,000,940 | ---- | C] () -- C:\Windows\Tasks\Adobe Flash Player Updater.job

< explorer.exe >

< winlogon.exe >

< Userinit.exe >

< svchost.exe >

========== Base Services ==========
SRV:64bit: - [2009-07-14 02:40:01 | 000,072,192 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\aelupsvc.dll -- (AeLookupSvc)
SRV:64bit: - [2013-02-27 06:47:10 | 000,070,144 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\appinfo.dll -- (Appinfo)
SRV:64bit: - [2009-07-14 02:38:55 | 000,079,360 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\alg.exe -- (ALG)
SRV:64bit: - [2010-11-20 14:27:23 | 000,849,920 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\qmgr.dll -- (BITS)
SRV:64bit: - [2010-11-20 14:25:45 | 000,705,024 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\BFE.DLL -- (BFE)
SRV:64bit: - [2013-09-25 02:03:24 | 000,030,720 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\lsass.exe -- (KeyIso)
SRV:64bit: - [2009-07-14 02:40:50 | 000,402,944 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\es.dll -- (EventSystem)
SRV - [2009-07-14 02:15:19 | 000,271,360 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysWOW64\es.dll -- (EventSystem)
SRV:64bit: - [2012-07-04 23:13:27 | 000,136,704 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\browser.dll -- (Browser)
SRV:64bit: - [2013-07-09 06:46:20 | 000,184,320 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\cryptsvc.dll -- (CryptSvc)
SRV - [2013-07-09 05:46:31 | 000,140,288 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysWOW64\cryptsvc.dll -- (CryptSvc)
SRV:64bit: - [2010-11-20 14:27:24 | 000,512,000 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\rpcss.dll -- (DcomLaunch)
SRV:64bit: - [2010-11-20 14:26:04 | 000,317,952 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\dhcpcore.dll -- (Dhcp)
SRV - [2010-11-20 13:18:30 | 000,254,464 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysWOW64\dhcpcore.dll -- (Dhcp)
SRV:64bit: - [2011-03-03 07:24:16 | 000,183,296 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\dnsrslvr.dll -- (Dnscache)
SRV:64bit: - [2009-07-14 02:40:35 | 000,111,104 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\eapsvc.dll -- (EapHost)
SRV:64bit: - [2009-07-14 02:41:00 | 000,038,912 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\hidserv.dll -- (hidserv)
SRV - [2009-07-14 02:15:24 | 000,049,152 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysWOW64\hidserv.dll -- (hidserv)
SRV:64bit: - [2009-07-14 02:41:10 | 000,359,424 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\ipnathlp.dll -- (SharedAccess)
SRV:64bit: - [2010-11-20 14:26:39 | 000,501,248 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\IPSECSVC.DLL -- (PolicyAgent)
No service found with a name of MsMpSvc
No service found with a name of NisSrv
SRV:64bit: - [2009-07-14 02:41:54 | 000,524,288 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\SysNative\swprv.dll -- (swprv)
SRV:64bit: - [2009-07-14 02:41:26 | 000,067,584 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\SysNative\mmcss.dll -- (MMCSS)
SRV:64bit: - [2009-07-14 02:41:52 | 000,360,448 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\netman.dll -- (Netman)
SRV:64bit: - [2009-07-14 02:41:52 | 000,459,776 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\netprofm.dll -- (netprofm)
SRV - [2009-07-14 02:16:03 | 000,360,448 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysWOW64\netprofm.dll -- (netprofm)
SRV:64bit: - [2012-10-03 18:44:21 | 000,303,104 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\nlasvc.dll -- (NlaSvc)
SRV:64bit: - [2009-07-14 02:41:53 | 000,025,600 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\nsisvc.dll -- (nsi)
SRV:64bit: - [2011-05-24 12:42:55 | 000,404,480 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\umpnpmgr.dll -- (PlugPlay)
SRV:64bit: - [2012-02-11 07:36:02 | 000,559,104 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\spoolsv.exe -- (Spooler)
SRV:64bit: - [2013-09-25 02:03:24 | 000,030,720 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\lsass.exe -- (ProtectedStorage)
No service found with a name of EMDMgmt
SRV:64bit: - [2009-07-14 02:41:53 | 000,099,328 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\rasauto.dll -- (RasAuto)
SRV:64bit: - [2010-11-20 14:27:24 | 000,344,064 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\rasmans.dll -- (RasMan)
SRV:64bit: - [2010-11-20 14:27:24 | 000,512,000 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\rpcss.dll -- (RpcSs)
SRV:64bit: - [2010-11-20 14:27:25 | 000,030,720 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\seclogon.dll -- (seclogon)
SRV:64bit: - [2013-09-25 02:03:24 | 000,030,720 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\lsass.exe -- (SamSs)
SRV:64bit: - [2009-07-14 02:41:58 | 000,097,280 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wscsvc.dll -- (wscsvc)
SRV:64bit: - [2010-11-20 14:27:26 | 000,236,032 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\srvsvc.dll -- (LanmanServer)
SRV:64bit: - [2010-11-20 14:27:25 | 000,370,688 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\SysNative\shsvcs.dll -- (ShellHWDetection)
SRV - [2010-11-20 13:21:19 | 000,328,192 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\SysWOW64\shsvcs.dll -- (ShellHWDetection)
No service found with a name of slsvc
SRV:64bit: - [2010-11-20 14:27:25 | 001,110,016 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\schedsvc.dll -- (Schedule)
SRV:64bit: - [2010-11-20 14:27:26 | 000,316,928 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\tapisrv.dll -- (TapiSrv)
SRV - [2010-11-20 13:21:28 | 000,242,176 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\tapisrv.dll -- (TapiSrv)
SRV:64bit: - [2009-07-14 02:41:55 | 000,044,544 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\themeservice.dll -- (Themes)
SRV:64bit: - [2012-05-01 06:40:20 | 000,209,920 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\profsvc.dll -- (ProfSvc)
SRV:64bit: - [2010-11-20 14:25:27 | 001,600,512 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\VSSVC.exe -- (VSS)
SRV:64bit: - [2010-11-20 14:25:42 | 000,679,424 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\audiosrv.dll -- (AudioSrv)
SRV:64bit: - [2010-11-20 14:25:42 | 000,679,424 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\audiosrv.dll -- (AudioEndpointBuilder)
SRV:64bit: - [2010-11-20 14:27:25 | 000,170,496 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\sdrsvc.dll -- (SDRSVC)
SRV:64bit: - [2013-05-27 06:50:47 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:64bit: - [2010-11-20 14:27:28 | 001,646,080 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wevtsvc.dll -- (eventlog)
SRV:64bit: - [2010-11-20 14:26:59 | 000,828,416 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\MPSSVC.dll -- (MpsSvc)
SRV:64bit: - [2010-11-20 14:27:28 | 000,580,096 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\SysNative\wiaservc.dll -- (stisvc)
SRV:64bit: - [2010-11-20 14:24:58 | 000,128,000 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\msiexec.exe -- (msiserver)
SRV - [2010-11-20 13:17:22 | 000,073,216 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWow64\msiexec.exe -- (msiserver)
SRV:64bit: - [2009-07-14 02:41:56 | 000,242,688 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wbem\WMIsvc.dll -- (Winmgmt)
SRV:64bit: - [2012-06-02 23:19:43 | 002,428,952 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wuaueng.dll -- (wuauserv)
SRV:64bit: - [2010-11-20 14:26:07 | 000,252,416 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\dot3svc.dll -- (dot3svc)
SRV:64bit: - [2009-07-14 02:41:56 | 000,886,784 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wlansvc.dll -- (Wlansvc)
SRV:64bit: - [2010-11-20 14:27:28 | 000,118,784 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wkssvc.dll -- (LanmanWorkstation)

========== Drive Information ==========

Physical Drives
---------------

Drive: \\\\.\\PHYSICALDRIVE0 - Fixed hard disk media
Interface type: IDE
Media Type: Fixed hard disk media
Model: Hitachi HDS721010CLA332 SATA Disk Device
Partitions: 4
Status: OK
Status Info: 0

Drive: \\\\.\\PHYSICALDRIVE1 -
Interface type: USB
Media Type:
Model: Generic- Compact Flash USB Device
Partitions: 0
Status: OK
Status Info: 0

Drive: \\\\.\\PHYSICALDRIVE2 -
Interface type: USB
Media Type:
Model: Generic- SM/xD-Picture USB Device
Partitions: 0
Status: OK
Status Info: 0

Drive: \\\\.\\PHYSICALDRIVE3 -
Interface type: USB
Media Type:
Model: Generic- SD/MMC USB Device
Partitions: 0
Status: OK
Status Info: 0

Drive: \\\\.\\PHYSICALDRIVE4 -
Interface type: USB
Media Type:
Model: Generic- MS/MS-Pro USB Device
Partitions: 0
Status: OK
Status Info: 0

Drive: \\\\.\\PHYSICALDRIVE5 - External hard disk media
Interface type: USB
Media Type: External hard disk media
Model: SAMSUNG HD154UI USB Device
Partitions: 1
Status: OK
Status Info: 0

Partitions
---------------

DeviceID: Disk #0, Partition #0
PartitionType: Installable File System
Bootable: True
BootPartition: True
PrimaryPartition: True
Size: 100,00MB
Starting Offset: 1048576
Hidden sectors: 0


DeviceID: Disk #0, Partition #1
PartitionType: Installable File System
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 466,00GB
Starting Offset: 105906176
Hidden sectors: 0


DeviceID: Disk #0, Partition #2
PartitionType: Extended w/Extended Int 13
Bootable: False
BootPartition: False
PrimaryPartition: False
Size: 454,00GB
Starting Offset: 500304969728
Hidden sectors: 0


DeviceID: Disk #0, Partition #3
PartitionType: Installable File System
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 12,00GB
Starting Offset: 987646394368
Hidden sectors: 0


DeviceID: Disk #5, Partition #0
PartitionType: Unknown
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 1.397,00GB
Starting Offset: 32256
Hidden sectors: 0


< %systemroot%\system32\*.dll /lockedfiles >

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /lockedfiles >

< %systemroot%\system32\*.exe /lockedfiles >

< %PROGRAMFILES%\* >
[2009-07-14 05:54:24 | 000,000,174 | -HS- | M] () -- C:\Program Files (x86)\desktop.ini

========== Alternate Data Streams ==========

@Alternate Data Stream - 24 bytes -> C:\Windows:FF733822351C799B
@Alternate Data Stream - 173 bytes -> C:\ProgramData\Temp:F8B88761

< End of report >
 
Re: Nation Zoom opent in IE en in Chrome Niet te verwijderen.

kreeg steeds vraag deze pagina verlaten/op deze pagina blijven. doordat ik koos voor blijven is otl wellicht 2x geplaatst.
wilde het op gaan knippen, maar dat werkte ook niet hierbij dan extras
OTL Extras logfile created on: 12/10/2013 11:59:05 AM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Chris\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16736)
Locale: 00000409 | Country: Nederland | Language: NLD | Date Format: d-M-yyyy

6.00 Gb Total Physical Memory | 4.34 Gb Available Physical Memory | 72.40% Memory free
7.07 Gb Paging File | 5.00 Gb Available in Paging File | 70.65% Paging File free
Paging file location(s): c:\pagefile.sys 100 100z:\pagefil [Binary data over 200 bytes]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 465.85 Gb Total Space | 283.37 Gb Free Space | 60.83% Space Free | Partition Type: NTFS
Drive D: | 11.69 Gb Total Space | 1.41 Gb Free Space | 12.09% Space Free | Partition Type: NTFS
Drive K: | 1396.92 Gb Total Space | 705.66 Gb Free Space | 50.52% Space Free | Partition Type: FAT32
Drive Z: | 453.87 Gb Total Space | 204.11 Gb Free Space | 44.97% Space Free | Partition Type: NTFS

Computer Name: CHRIS-HP | User Name: Chris | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html[@ = ChromeHTML] -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = ChromeHTML] -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)

[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = ChromeHTML] -- Reg Error: Key error. File not found

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htafile [open] -- "%1" %*
htmlfile [edit] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1"
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [ALDI Print Software] -- "C:\Program Files (x86)\ALDI\ALDI Print Software\ALDI Print Software.exe" "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [Doorbladeren met Corel PaintShop Pro X5] -- "c:\Program Files (x86)\Corel\Corel PaintShop Pro X5\Corel PaintShop Pro.exe" "%L" (Corel, Inc.)
Directory [Doorbladeren met Corel PaintShop Pro X6] -- "c:\Program Files (x86)\Corel\Corel PaintShop Pro X6 (64-bit)\Corel PaintShop Pro.exe" "%L" (Corel, Inc.)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [tralih] -- "C:\Program Files (x86)\Trader's Little Helper\tralih.exe" /0 "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htafile [open] -- "%1" %*
htmlfile [edit] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1"
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [ALDI Print Software] -- "C:\Program Files (x86)\ALDI\ALDI Print Software\ALDI Print Software.exe" "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [Doorbladeren met Corel PaintShop Pro X5] -- "c:\Program Files (x86)\Corel\Corel PaintShop Pro X5\Corel PaintShop Pro.exe" "%L" (Corel, Inc.)
Directory [Doorbladeren met Corel PaintShop Pro X6] -- "c:\Program Files (x86)\Corel\Corel PaintShop Pro X6 (64-bit)\Corel PaintShop Pro.exe" "%L" (Corel, Inc.)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [tralih] -- "C:\Program Files (x86)\Trader's Little Helper\tralih.exe" /0 "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error.

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

========== Firewall Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0B7BC77A-F995-4F17-8CF7-2949B57F9A44}" = lport=445 | protocol=6 | dir=in | app=system |
"{14206650-2724-4D87-9C1F-212FAA262E3B}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{190257D4-6CE5-4D40-8B94-5A25A6F8D38C}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{44645350-61D6-4D92-A550-D38C1CFAD06F}" = rport=445 | protocol=6 | dir=out | app=system |
"{623A01A5-A774-4D68-BC3E-59E49EF46B9E}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{6D79163F-80E6-495D-A4E4-0086ED7361CB}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
"{7046FD8A-2A5C-4851-8A05-4C2FE2D434E1}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{7156B8B0-5CB6-4A06-958B-7CDD72A90168}" = lport=138 | protocol=17 | dir=in | app=system |
"{80097693-E3E9-4CEC-B4ED-A8386646B428}" = rport=138 | protocol=17 | dir=out | app=system |
"{8E2D791F-867F-4065-A417-D1B8D085A237}" = rport=137 | protocol=17 | dir=out | app=system |
"{A8A9D1D8-17DD-402A-BF89-067AD7E19AFC}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{B460CD34-D1E5-412A-A5A1-F04833B2891E}" = lport=137 | protocol=17 | dir=in | app=system |
"{BE3599C2-61D1-476A-9C11-2BC6F39D3F97}" = rport=139 | protocol=6 | dir=out | app=system |
"{E0210346-64CD-4256-99D7-ED0DECECFB02}" = lport=139 | protocol=6 | dir=in | app=system |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0B3C118C-1EDF-47D9-93D2-C2D4F13AC64B}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\dvd\hpdvdsmart.exe |
"{22C12025-192D-4A46-A60D-414B3F221EC2}" = protocol=6 | dir=in | app=c:\program files (x86)\anwb-reiswijzer\anwbreiswijzer.exe |
"{3227DF37-FCEE-4305-ABD3-97D21F9ABF7F}" = protocol=17 | dir=in | app=c:\program files (x86)\mypoi manager\mypoimanager.exe |
"{45499F0C-084D-48CC-BAB3-DDD738616E39}" = protocol=17 | dir=in | app=c:\program files (x86)\ivt corporation\bluesoleil\bluesoleil.exe |
"{4E0FDA0A-F30B-407C-AA5E-DC0E4916D423}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{4E5AA99C-9139-467D-B2F5-7DA82AD5899B}" = protocol=6 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe |
"{63B86D5D-2457-4594-9AE6-7C4CACACA244}" = protocol=6 | dir=in | app=c:\program files (x86)\mypoi manager\mypoimanager.exe |
"{6979B5E7-E481-4912-B71F-6F4D4F3BF2C7}" = protocol=17 | dir=in | app=c:\program files (x86)\namo\webeditor 8\bin\webeditor.exe |
"{6F3B03E1-F4D6-4B79-9953-59EC56CC57C4}" = protocol=6 | dir=in | app=c:\program files (x86)\ivt corporation\bluesoleil\bluesoleil.exe |
"{78C0C749-0FB9-4458-9C53-7DF684720C52}" = protocol=17 | dir=in | app=c:\windows\syswow64\msiexec.exe |
"{84A6BE33-753D-41EE-8AF3-C957AEFE74B0}" = dir=in | app=c:\program files (x86)\hewlett-packard\hp support framework\resources\hpwarrantycheck\hpdevicedetection3.exe |
"{890905CA-28C2-4E41-B9D3-7C32C0471FDC}" = protocol=17 | dir=in | app=c:\program files (x86)\anwb-reiswijzer\anwbreiswijzer.exe |
"{8A64134D-9883-4714-BE78-FAD54B628574}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{91790A59-5720-4790-B5D8-6691097D1F13}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{9C9C9C8F-E899-422A-9CA8-9E1E389355A5}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe |
"{A49C858A-B319-4E26-926B-FFD6F0698033}" = protocol=17 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe |
"{B0A34A2B-A15A-4E2F-ADC4-DB859CA7D3C3}" = dir=in | app=c:\program files (x86)\nokia\nokia suite\nokiasuite.exe |
"{BEE0AA5B-CA19-436A-8991-07199B507C34}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe |
"{CB921DD2-C656-4726-95AD-B63AFEAE1813}" = dir=in | app=c:\program files (x86)\nokia\nokia suite\nokiasuite.exe |
"{D10117E0-40C5-4729-BF08-4D1BDF34C51C}" = protocol=6 | dir=in | app=c:\windows\syswow64\msiexec.exe |
"{D71B044A-F20D-42F5-BC99-42A60803B876}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{F060EFCB-F0EA-4A6D-9442-B8183B61B7D1}" = protocol=6 | dir=in | app=c:\program files (x86)\namo\webeditor 8\bin\webeditor.exe |
"TCP Query User{ED943E9C-2E22-457F-8615-9690D26B079D}C:\program files (x86)\namo\webeditor 8\bin\webeditor.exe" = protocol=6 | dir=in | app=c:\program files (x86)\namo\webeditor 8\bin\webeditor.exe |
"UDP Query User{70A7F870-7B17-4FE7-BC9D-D874B996C325}C:\program files (x86)\namo\webeditor 8\bin\webeditor.exe" = protocol=17 | dir=in | app=c:\program files (x86)\namo\webeditor 8\bin\webeditor.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{027E5FAB-1476-4C59-AAB4-32EF28520399}" = Windows Live Language Selector
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_cnq4809" = CanoScan LiDE 210 Scanner Driver
"{1551A29F-B1B0-43CA-90B5-E6E5186F683E}" = PSPPro64
"{16582334-495C-4F1C-A66B-3BFD8866B674}" = PSPPro64
"{1678F86C-889D-4198-8249-F4625058256B}" = IPM_PSP_COM64
"{1ACC8FFB-9D84-4C05-A4DE-D28A9BC91698}" = Windows Live ID Sign-in Assistant
"{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
"{237D687E-9E50-4A30-B810-262764CC491B}" = Garmin Communicator Plugin x64
"{350AA351-21FA-3270-8B7A-835434E766AD}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{4D668D4F-FAA2-4726-834C-31F4614F312E}" = MSVC80_x64_v2
"{503F672D-6C84-448A-8F8F-4BC35AC83441}" = AMD APP SDK Runtime
"{53A19094-2C04-A9B9-7309-3E92152D4845}" = AMD Catalyst Install Manager
"{5B08AF35-B699-4A44-BB89-3E51E70611E8}" = HP MediaSmart SmartMenu
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{680EDA59-9266-44B4-949E-0C24F65DFF82}" = Microsoft_VC100_CRT_SP1_x64
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{AB071C8B-873C-459F-ACA9-9EBE03C3E89B}" = MSVC90_x64
"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{B6E3757B-5E77-3915-866A-CCFC4B8D194C}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053
"{B821CDAA-34DE-46FD-87C9-E6EE7158DB5D}" = Microsoft Image Composite Editor
"{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}" = PlayReady PC Runtime amd64
"{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter
"{EA78A5C4-E494-4232-85BE-A1F2CDDD1A54}" = Athentech Perfectly Clear
"{ED246336-2A22-E930-6602-9B942BE7A7C4}" = ccc-utility64
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"{F7CF9A5B-35DD-4C5D-8138-C94A1E324F7A}" = Microsoft Camera Codec Pack
"{FB237A35-F491-4AC1-95E0-85118D6751D9}" = Topaz Adjust 4 (64-bit)
"3134FEF0E1D959EC0CC2E458C94B7057B2AC0CC9" = Windows-stuurprogrammapakket - FTDI CDM Driver Package (10/22/2009 2.06.00)
"62BBD193ADFDBB228C7E1ADB56463F5732FF7F6F" = Windows-stuurprogrammapakket - Nokia pccsmcfd LegacyDriver (05/31/2012 7.1.2.0)
"72A50F48CC5601190B9C4E74D81161693133E7F7" = Windows-stuurprogrammapakket - Nokia Modem (02/25/2011 7.01.0.9)
"88EB56038379B8B7DCFB4D2448A60F52E064B265" = Windows-stuurprogrammapakket - FTDI CDM Driver Package (10/22/2009 2.06.00)
"98157A226B40B173301B0F53C8E98C47805D5152" = Windows Driver Package - Garmin (grmnusb) GARMIN Devices (04/19/2012 2.3.1.0)
"Artensoft Photo Collage Maker_is1" = Artensoft Photo Collage Maker
"E0AC723A3DE3A04256288CADBBB011B112AED454" = Windows-stuurprogrammapakket - Nokia Modem (02/25/2011 4.7)
"Juniper_Setup_Client Activex Control" = Juniper Networks, Inc. Setup Client 64-bit Activex Control
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"PC-Doctor for Windows" = Hardware Diagnostic Tools
"Pen Tablet Driver" = Bamboo
"Recuva" = Recuva
"WinRAR archiver" = WinRAR 4.00 (64-bit)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"_{050AE842-C0D4-4322-ABAF-4202459E003F}" = Corel PaintShop Pro Picture Tube Content
"_{12097B7C-04C4-4049-AEBF-0ECE0D6FCEE3}" = Athentech Perfectly Clear
"_{12229E88-1510-474C-88B9-E635830F9C82}" = Corel PaintShop Pro Picture Frame Content
"_{1563C6F2-E9B5-42DE-9EA6-207C9A8C2DFB}" = Corel PaintShop Pro X5
"_{166D1CB6-DD8A-40DD-9E25-4D31D2D6DE4D}" = Corel PaintShop Pro X6
"_{21C5C3F6-C670-4A09-86E5-B88A67A9F406}" = Corel PaintShop Pro Misc Content
"_{4A263708-ED65-4E60-B7C8-CE5B0EED5FC6}" = Corel PaintShop Pro Misc Content
"_{6036ED4A-954A-4DED-8565-C91D439024BE}" = Corel PaintShop Pro Misc Content
"_{7BEBFF10-797B-4883-9959-06E66D6254DE}" = Corel KPT Collection
"_{A5BD6F26-D9D5-4ABD-A82E-9F5ABD5504CB}" = Creative Content
"_{AE4364BD-ED09-4D94-8DA2-315C10A57CD1}" = Ultimate Creative Collection (X5)
"_{B20C88E8-CD0D-4354-8A78-32CCF73F6240}" = Corel PaintShop Pro Misc Content
"_{BA7B3A61-EB8C-4C70-8179-93DDA248AA49}" = Nik Color Efex Pro 3.0
"_{BEDD3AB4-28DA-45CF-AFE3-55EF4B4C7608}" = Corel PaintShop Pro Misc Content
"_{BFF48D77-3D57-4005-AE39-76D389153042}" = Corel PaintShop Pro Misc Content
"_{C42299E7-8CB0-48F1-93ED-245A42C85D9F}" = Corel PaintShop Pro Brush Content
"_{C59A783C-FF5C-40BE-843A-5458513D655B}" = Corel KPT Collection
"_{D5346965-CB0A-41B8-8B5F-8B41ABF848BF}" = Corel PaintShop Pro Misc Content
"_{D839B02E-8C50-4F8F-BA53-84FF75487A1A}" = Ultimate Creative Collection (X6)
"{00000413-78E1-11D2-B60F-006097C998E7}" = Microsoft Office 2000 Premium
"{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}" = PDFCreator
"{0138F525-6C8A-333F-A105-14AE030B9A54}" = Visual C++ 9.0 CRT (x86) WinSXS MSM
"{022E2D1B-439D-4AA6-B74E-F644A425CF48}" = iPictDB Windows Live Gallery Plugin
"{031338C0-4C21-4DAC-875B-26ACD7ADDF23}" = Corel KPT Collection
"{050AE842-C0D4-4322-ABAF-4202459E003F}" = Corel PaintShop Pro Picture Tube Content
"{06F25DC8-71E2-44E2-805A-F15E15B51C74}_is1" = Remove Empty Directories version 2.2
"{07FA4960-B038-49EB-891B-9F95930AA544}" = HP Customer Experience Enhancements
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0C6DB6B9-2D17-4AA5-A207-42D28BF9F434}" = MyPoi Manager
"{116A9A5B-D5B5-C0AE-52ED-F50013BA1185}" = CCC Help Norwegian
"{12097B7C-04C4-4049-AEBF-0ECE0D6FCEE3}" = Athentech Perfectly Clear
"{12229E88-1510-474C-88B9-E635830F9C82}" = Corel PaintShop Pro Picture Frame Content
"{14B441B7-774D-4170-98EA-A13667AE6218}" = Windows Live Writer Resources
"{15002A1B-C1E7-4E91-A3EC-5502BF924A32}" = Setup
"{15180A90-1FC0-47E4-A150-3AECEF07B3B6}" = Corel PaintShop Pro X5
"{1522E36C-3739-41E4-8CD3-A4AFEA70086A}" = PSPPContent
"{153DD765-C8C6-4893-8CEF-D965351D82EC}" = PSPPHelp
"{154B0B16-ABCD-4A06-B0B7-8146B7A89B25}" = IPM_PSP_COM
"{1563C6F2-E9B5-42DE-9EA6-207C9A8C2DFB}" = ICA
"{16006EE1-DDB7-4E5F-8696-9FEF32C0151A}" = Setup
"{161AB62E-65D6-46E5-B3D8-2AC15D3B920B}" = Corel PaintShop Pro X6
"{162BD2D6-6C63-41A7-8151-93188450D36A}" = PSPPContent
"{16346B2A-87BC-407C-9D6B-72A4D21ABF03}" = PSPPHelp
"{164D34E1-0271-4960-8A26-E8990A302DB1}" = IPM_PSP_COM
"{166D1CB6-DD8A-40DD-9E25-4D31D2D6DE4D}" = ICA
"{196467F1-C11F-4F76-858B-5812ADC83B94}" = MSXML 4.0 SP3 Parser
"{1987D283-9A22-2FCF-859C-41D362C170C3}" = CCC Help Russian
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{1F976B1D-7CFD-44F6-B016-1D3B0FFA937A}" = TuneUp Utilities Language Pack (nl-NL)
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{21C5C3F6-C670-4A09-86E5-B88A67A9F406}" = Corel PaintShop Pro Misc Content
"{236BB7C4-4419-42FD-0409-1E257A25E34D}" = Adobe Photoshop CS2
"{25AC788F-0563-260D-32E0-022D92716227}" = CCC Help Spanish
"{2624B680-02BC-4CBC-839C-DA20DF6EF6EC}" = Citrix Presentation Server Client
"{26A24AE4-039D-4CA4-87B4-2F83217025FF}" = Java 7 Update 45
"{290B6C2A-19BB-BE0A-C091-43B5D0A32427}" = CCC Help Chinese Traditional
"{2A07C35B-8384-4DA4-9A95-442B6C89A073}" = Windows Live Essentials
"{2EFA4E4C-7B5F-48F7-A1C0-1AA882B7A9C3}" = HP Update
"{2FA94A64-C84E-49d1-97DD-7BF06C7BBFB2}.WildTangent Games App" = Update Installer for WildTangent Games App
"{30B41B7A-3C9D-44DE-A7A1-949011F33CC3}" = PDF Architect
"{31a12940-e5c8-4d27-a6ac-005212152f1f}" = Garmin Express
"{31C40A62-78E5-4662-3DA3-6AC9C3425F72}" = Catalyst Control Center Graphics Previews Common
"{33032DAA-32D3-C954-8CC3-468522F4F745}" = CCC Help French
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{33EBF075-8593-4698-BDAF-CF8DED80BB5B}" = Nokia Suite
"{359FCAA7-B544-4147-AE3B-8C8A526E2427}" = Sony Image Data Suite
"{369FA236-890F-4490-B607-092BC17E10CD}" = Elevated Installer
"{36DA2332-923F-8262-190A-020087A6643D}" = CCC Help English
"{3D5D6CFC-3097-425A-8D8F-7EAF5D57641D}" = Garmin USB Drivers
"{40FB8D7C-6FF8-4AF2-BC8B-0B1DB32AF04B}" = HP Advisor
"{417F3E7E-C754-4707-BF5B-94750B83D58A}" = Garmin Express Tray
"{4209F371-393F-E3AF-1440-2EAD843B93B4}_is1" = Ashampoo WinOptimizer Free v.1.0.0
"{42B9D779-CF1F-478D-A393-950CE0E48177}" = Garmin Update Service
"{42D10994-A566-495D-A5E7-D0C6B5C6B35C}" = HP Product Detection
"{44B2A0AB-412E-4F8C-B058-D1E8AECCDFF5}" = Recovery Manager
"{477213DD-8FFC-CDFE-3E12-145F71ADAA7D}" = Catalyst Control Center Localization All
"{47E0C66C-6696-D28F-5E3A-76CD761C5E57}" = CCC Help Swedish
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4A263708-ED65-4E60-B7C8-CE5B0EED5FC6}" = Corel PaintShop Pro Misc Content
"{4D933B36-4A8A-C2C1-6A88-2FC20EFD2772}" = AMD VISION Engine Control Center
"{5158F1F5-FA1B-4D49-B546-55A5004B89BD}" = Microsoft Works
"{52B99BCA-6251-498F-88CA-420D31CBC8C7}" = Wacom JustWrite Office
"{5A12B00F-080C-A75E-E127-1F8D884EBFAF}" = CCC Help Czech
"{5BDA2F58-1F21-4D10-9910-92B01EBCC958}" = AMD USB Filter Driver
"{5CA74EDC-CFC3-4FA0-AED7-1415CA19F250}" = Garmin POI Loader
"{5E87E7CE-9E68-FF00-71E0-2BF35D90DAA3}" = CCC Help Italian
"{6020758E-57A9-41E3-AF20-8EE311EA6156}" = FaceFilter v3.02 Standard
"{6036ED4A-954A-4DED-8565-C91D439024BE}" = Corel PaintShop Pro Misc Content
"{658AB1BF-9A07-4AAD-B6BB-7CADD2307C75}" = Garmin Express
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{6845255F-15CC-4DD1-94D5-D38F370118B3}_is1" = Auslogics Duplicate File Finder
"{6AFCA4E1-9B78-3640-8F72-A7BF33448200}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
"{6C5F8503-55D2-4398-858C-362B7A7AF51C}" = Firebird SQL Server - MAGIX Edition
"{6D3245B1-8DB8-4A23-9CD2-2C90F40ABAF6}" = MSVC80_x86_v2
"{6DAF8CDC-9B04-413B-A0F2-BCC13CF8A5BF}" = HP MediaSmart Photo
"{6F340107-F9AA-47C6-B54C-C3A19F11553F}" = Hewlett-Packard ACLM.NET v1.2.1.1
"{70B446D1-E03B-4ab0-9B3C-0832142C9AA8}.WildTangent Games App-hp" = WildTangent Games App (HP Games)
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{729A3000-BC8A-3B74-BA5D-5068FE12D70C}" = Microsoft Visual F# 2.0 Runtime
"{752D319E-E2D1-2C60-5FD8-311DF92C62A3}" = CCC Help Hungarian
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{772DF2FC-DB4B-3DF4-C65D-CBF0A094DDC9}" = CCC Help Portuguese
"{786C5747-1033-0000-B58E-000000000001}" = Adobe Stock Photos 1.0
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{7A99276D-3D92-50A5-8EF0-3ADDD1507D43}" = CCC Help Danish
"{7BEBFF10-797B-4883-9959-06E66D6254DE}" = Corel KPT Collection
"{7FB71EA0-843D-23C1-8926-E2CDC347296F}" = CCC Help Chinese Standard
"{80E0CBFB-6895-2C0B-39DE-7F42F42FDC9A}" = CCC Help Greek
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{846AC73B-9394-48B9-B941-8F7F472F0047}" = Bluesoleil2.6.0.9 Release 070606
"{866C4563-ED53-43F3-A29D-8BEE2BD1BA3C}" = Nokia PC Suite
"{8D0B7E15-AAA8-BE2B-B010-95D5A76EC397}" = CCC Help Dutch
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{8EDBA74D-0686-4C99-BFDD-F894678E5B39}" = Adobe Common File Installer
"{8EF7A04E-C5A6-459E-8106-362AEE79A5F6}" = ANWB-reiswijzer
"{8FC4F1DD-F7FD-4766-804D-3C8FF1D309AF}" = Ralink 802.11n Wireless LAN Card
"{90120000-0020-0413-0000-0000000FF1CE}" = Compatibiliteitspakket voor het 2007 Microsoft Office system
"{90538B62-F392-4DE1-B886-7B48123866E9}" = LightScribe System Software
"{91A34181-9FAD-43AB-A35F-E7A8945B7E1C}" = HP MediaSmart Music
"{91F7C67B-C1A2-F1DB-C286-7F56A07C6B49}" = HydraVision
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{96AD3B61-EAE2-11E2-9E72-B8AC6F98CCE3}" = Google Earth
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BD262D0-B788-4546-A0A5-F4F56EC3834B}" = Windows Live Photo Common
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{9FCBD98D-F8B3-6ECC-5293-9C28817E3269}" = Catalyst Control Center InstallProxy
"{9FDC7042-CB9F-4336-A14C-DF10F53762E2}" = Topaz Adjust 4
"{A2090170-70B6-40D6-8B43-04ECDC641EA6}" = TuneUp Utilities Language Pack (nl-NL)
"{A57025CC-5F2E-4D01-B387-06DB10500D43}" = Nokia Connectivity Cable Driver
"{A5BD6F26-D9D5-4ABD-A82E-9F5ABD5504CB}" = Creative Content
"{A60B3BF0-954B-42AF-B8D8-2C1D34B613AA}" = Windows Live Photo Gallery
"{A7D1EC13-4B5F-43AA-A048-B1AF591450A6}" = Garmin BaseCamp
"{A85E0098-F8BA-40A2-B9E1-E3C04574C53A}" = jAlbum
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AAFC6C24-11A1-7AA8-75C1-63037733F06D}" = CCC Help Japanese
"{AC6B513F-311B-910C-FC02-59CE31D47648}" = Catalyst Control Center Profiles Desktop
"{AC76BA86-7AD7-1043-7B44-AA1000000001}" = Adobe Reader X (10.1.8) - Nederlands
"{ACDE3E85-CB61-48D8-B19B-F6D6AA0AA62A}" = Catalyst Control Center - Branding
"{AE09704D-9051-4C25-B940-77F889F0C93F}" = OVTScanner_X64
"{AE4364BD-ED09-4D94-8DA2-315C10A57CD1}" = Ultimate Creative Collection (X5)
"{AF111648-99A1-453E-81DD-80DBBF6DAD0D}" = MSVC90_x86
"{AFBAB9A0-DDE8-49AE-8C17-A01B61BEE64B}" = Garmin MapSource
"{B20C88E8-CD0D-4354-8A78-32CCF73F6240}" = Corel PaintShop Pro Misc Content
"{B67BAFBA-4C9F-48FA-9496-933E3B255044}" = QuickTime
"{B6A98E5F-D6A7-46FB-9E9D-1F7BF443491C}" = PMB
"{B74D4E10-1033-0000-0000-000000000001}" = Adobe Bridge 1.0
"{B8AC1A89-FFD1-4F97-8051-E505A160F562}" = HP Odometer
"{B9A03B7B-E0FF-4FB3-BA83-762E58A1B0AA}" = HP Support Information
"{BA77F9D2-CD35-41EB-9BC9-769879DFF8A6}" = PC Connectivity Solution
"{BA7B3A61-EB8C-4C70-8179-93DDA248AA49}" = Nik Color Efex Pro 3.0
"{BEDD3AB4-28DA-45CF-AFE3-55EF4B4C7608}" = Corel PaintShop Pro Misc Content
"{BFF48D77-3D57-4005-AE39-76D389153042}" = Corel PaintShop Pro Misc Content
"{C34AB2ED-D990-645C-77A3-9B916C23B3C0}" = CCC Help Finnish
"{C42299E7-8CB0-48F1-93ED-245A42C85D9F}" = Corel PaintShop Pro Brush Content
"{C4ABDBC8-1C81-42C9-BFFC-4A68511E9E4F}" = TuneUp Utilities 2013
"{C59A783C-FF5C-40BE-843A-5458513D655B}" = Corel KPT Collection
"{C7340571-7773-4A8C-9EBC-4E4243B38C76}" = Microsoft XML Parser
"{CB7224D9-6DCA-43F1-8F83-6B1E39A00F92}" = Windows Live Movie Maker
"{CBD8081C-0FE6-4EB3-A7F8-FFC13A603BBF}" = CCC Help Thai
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{CEC8F2E3-AC9A-357C-BFCB-BFAC37C4AC50}" = Visual C++ 9.0 ATL (x86) WinSXS MSM
"{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64
"{D3507473-2CE3-4073-A6BA-A0846B5CC687}" = Namo WebEditor 8
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{D5346965-CB0A-41B8-8B5F-8B41ABF848BF}" = Corel PaintShop Pro Misc Content
"{D588365A-AE39-4F27-BDAE-B4E72C8E900C}" = Windows Live Mail
"{D6F25CF9-4E87-43EB-B324-C12BE9CDD668}" = Windows Live UX Platform Language Pack
"{D839B02E-8C50-4F8F-BA53-84FF75487A1A}" = Ultimate Creative Collection (X6)
"{D8603E3A-F40F-E3B4-6AAA-9C3E69ADC8B9}" = CCC Help Korean
"{DCCAD079-F92C-44DA-B258-624FC6517A5A}" = HP MediaSmart DVD
"{DDA44FB3-1CE1-02B2-5610-444C24EC55BB}" = CCC Help Turkish
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}" = Windows Media Encoder 9 Series
"{E3B64CC5-C011-40C0-92BC-7316CD5E5688}" = Microsoft_VC100_CRT_SP1_x86
"{E9787678-1033-0000-8E67-000000000001}" = Adobe Help Center 1.0
"{ED09A2DF-9342-8F82-B6FD-FA5311050F77}" = CCC Help German
"{EE202411-2C26-49E8-9784-1BC1DBF7DE96}" = HP Support Assistant
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F177CDAF-0A53-9B0D-A0F1-E83E237CA2A6}" = Catalyst Control Center InstallProxy
"{F5266D28-E0B2-4130-BFC5-EE155AD514DC}" = Apple Application Support
"{F5C7FD70-2C0A-401E-95E9-916363567DDA}" = HP Setup
"{F6CE5596-9C67-2E12-DC9B-F81859F2BB26}" = CCC Help Polish
"{FC274982-5AAD-4C20-848D-4424A5043009}_is1" = WinUtilities 10.55 Professional Edition
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Photoshop CS2 - {236BB7C4-4419-42FD-0409-1E257A25E34D}" = Adobe Photoshop CS2
"ALDI Print Software" = ALDI Print Software
"avast" = avast! Free Antivirus
"CanonSolutionMenuEX" = Canon Solution Menu EX
"Colasoft Capsa 7 Free_is1" = Colasoft Capsa 7 Free
"DreamSuite Bonus" = Uninstall DreamSuite Bonus
"Exif Pilot_is1" = Exif Pilot 4.7
"FaceOffMax" = Face Off Max
"GeoSetter_is1" = GeoSetter 3.4.16
"Google Chrome" = Google Chrome
"GPicSync_is1" = GPicSync 1.30
"GrabIt_is1" = GrabIt 1.7.2 Beta 4 (build 997)
"ImgBurn" = ImgBurn
"Inkscape" = Inkscape 0.47
"InstallShield_{6DAF8CDC-9B04-413B-A0F2-BCC13CF8A5BF}" = HP MediaSmart Photo
"InstallShield_{91A34181-9FAD-43AB-A35F-E7A8945B7E1C}" = HP MediaSmart Music
"InstallShield_{DCCAD079-F92C-44DA-B258-624FC6517A5A}" = HP MediaSmart DVD
"Karen's Directory Printer" = Karen's Directory Printer
"MAGIX Music Cleaning Lab 2007 deluxe NL" = MAGIX Music Cleaning Lab 2007 deluxe (NL)
"MAGIX Music Manager 2006 NL" = MAGIX Music Manager 2006 (NL)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware versie 1.75.0.1300
"MP Navigator 3.1" = Canon MP Navigator 3.1
"MP Navigator EX 4.0" = Canon MP Navigator EX 4.0
"MusicStationNetstaller" = MusicStation
"My HP Game Console" = HP Game Console
"Nokia PC Suite" = Nokia PC Suite
"Nokia Suite" = Nokia Suite
"PoiEdit" = PoiEdit
"SignCut" = SignCut (remove only)
"TradersLittleHelper_is1" = Trader's Little Helper 2.7.0
"TuneUp Utilities 2013" = TuneUp Utilities 2013
"Tyre_is1" = Tyre
"uTorrent" = ?Torrent
"Wacom WebTabletPlugin for IE" = WebTablet IE Plugin
"Wacom WebTabletPlugin for Internet Explorer and Netscape" = WebTablet FB Plugin
"WildTangent hp Master Uninstall" = HP Games
"Windows Media Encoder 9" = Windows Media Encoder 9 Series
"WinHTTrack Website Copier_is1" = WinHTTrack Website Copier 3.46-1
"WinLiveSuite" = Windows Live Essentials
"Wire Pilot Lite_is1" = Wire Pilot Lite 3.0.4
"WT082122" = Blackhawk Striker 2
"WT082124" = Blasterball 3
"WT082133" = Dora's Carnival Adventure
"WT082141" = FATE
"WT082168" = Penguins!
"WT082170" = Plants vs. Zombies
"WT082171" = Poker Superstars III
"WT082172" = Polar Bowler
"WT082173" = Polar Golfer
"WT082188" = Virtual Families
"WT082192" = Bejeweled 2 Deluxe
"WT082200" = Chuzzle Deluxe
"WT082241" = Virtual Villagers - The Secret City
"WT082439" = Bus Driver
"WT082442" = Faerie Solitaire
"WT082443" = Jewel Quest 3
"WT082463" = Zuma's Revenge
"WT083484" = Escape Rosecliff Island
"WT083492" = Agatha Christie - Death on the Nile
"XML Copy Editor_is1" = XML Copy Editor version 1.2.0.9

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Aldfaer" = Aldfaer
"Juniper_Networks_Cache_Cleaner 6.5.0" = Juniper Networks Cache Cleaner 6.5.0
"Juniper_Setup_Client" = Juniper Networks, Inc. Setup Client
"Neoteris_Host_Checker" = Juniper Networks Host Checker
"TwistedBrush Pro Studio" = TwistedBrush Pro Studio

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 9-12-2013 22:43:47 | Computer Name = Chris-HP | Source = VSS | ID = 12292
Description =

Error - 9-12-2013 22:43:47 | Computer Name = Chris-HP | Source = VSS | ID = 8193
Description =

Error - 9-12-2013 22:43:47 | Computer Name = Chris-HP | Source = System Restore | ID = 8193
Description =

Error - 9-12-2013 23:27:00 | Computer Name = Chris-HP | Source = Application Error | ID = 1000
Description = Naam van toepassing met fout: dds.com, versie: 2012.11.20.1, tijdstempel:
0x4b1ae3c6 Naam van module met fout: System.dll, versie: 0.0.0.0, tijdstempel: 0x4b1ae3ad
Uitzonderingscode:
0xc0000005 Foutoffset: 0x0000186d Id van proces met fout: 0x122c Starttijd van toepassing
met fout: 0x01cef5578ed856a1 Pad naar toepassing met fout: C:\Users\Chris\Desktop\dds.com
Pad
naar module met fout: C:\Users\Chris\AppData\Local\Temp\nsg2F8A.tmp\System.dll Rapport-id:
ed8eea32-614a-11e3-8292-00116778ad73

Error - 9-12-2013 23:28:01 | Computer Name = Chris-HP | Source = VSS | ID = 13
Description =

Error - 9-12-2013 23:28:01 | Computer Name = Chris-HP | Source = VSS | ID = 12292
Description =

Error - 10-12-2013 2:09:41 | Computer Name = Chris-HP | Source = VSS | ID = 13
Description =

Error - 10-12-2013 2:09:41 | Computer Name = Chris-HP | Source = VSS | ID = 12292
Description =

Error - 10-12-2013 2:09:41 | Computer Name = Chris-HP | Source = VSS | ID = 8193
Description =

Error - 10-12-2013 2:09:41 | Computer Name = Chris-HP | Source = System Restore | ID = 8193
Description =

[ Hewlett-Packard Events ]
Error - 22-9-2012 23:49:17 | Computer Name = Chris-HP | Source = hpsa_service.exe | ID = 2000
Description = HP Error ID: -2146233088 bij HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetect()

bij HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan,
Boolean localScan) Message: One HP Active Check Local Mode job already running. StackTrace:
bij HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetect()

bij HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan,
Boolean localScan) Source: HP.ActiveCheckLocalMode.SessionManager Name: hpsa_service.exe
Version:
06.00.01.01 Path: C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
Format:
nl-NL RAM: 6143 Ram Utilization: 30 TargetSite: Void UpdateAndDetect()

Error - 25-9-2012 2:12:31 | Computer Name = Chris-HP | Source = hpsa_service.exe | ID = 2000
Description = HP Error ID: -2146233088 bij HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetect()

bij HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan,
Boolean localScan) Message: One HP Active Check Local Mode job already running. StackTrace:
bij HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetect()

bij HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan,
Boolean localScan) Source: HP.ActiveCheckLocalMode.SessionManager Name: hpsa_service.exe
Version:
06.00.01.01 Path: C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
Format:
nl-NL RAM: 6143 Ram Utilization: 50 TargetSite: Void UpdateAndDetect()

Error - 9-10-2012 2:31:52 | Computer Name = Chris-HP | Source = hpsa_service.exe | ID = 2000
Description = HP Error ID: -2146233088 bij HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetect()

bij HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan,
Boolean localScan) Message: One HP Active Check Local Mode job already running. StackTrace:
bij HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetect()

bij HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan,
Boolean localScan) Source: HP.ActiveCheckLocalMode.SessionManager Name: hpsa_service.exe
Version:
06.00.01.01 Path: C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
Format:
nl-NL RAM: 6143 Ram Utilization: 20 TargetSite: Void UpdateAndDetect()

Error - 16-10-2012 2:48:19 | Computer Name = Chris-HP | Source = hpsa_service.exe | ID = 2000
Description = HP Error ID: -2146233088 bij HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetect()

bij HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan,
Boolean localScan) Message: One HP Active Check Local Mode job already running. StackTrace:
bij HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetect()

bij HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan,
Boolean localScan) Source: HP.ActiveCheckLocalMode.SessionManager Name: hpsa_service.exe
Version:
06.00.01.01 Path: C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
Format:
nl-NL RAM: 6143 Ram Utilization: 80 TargetSite: Void UpdateAndDetect()

Error - 23-10-2012 13:12:05 | Computer Name = Chris-HP | Source = hpsa_service.exe | ID = 2000
Description = HP Error ID: -2146233088 bij HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetect()

bij HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan,
Boolean localScan) Message: One HP Active Check Local Mode job already running. StackTrace:
bij HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetect()

bij HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan,
Boolean localScan) Source: HP.ActiveCheckLocalMode.SessionManager Name: hpsa_service.exe
Version:
06.00.01.01 Path: C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
Format:
nl-NL RAM: 6143 Ram Utilization: 20 TargetSite: Void UpdateAndDetect()

Error - 30-10-2012 3:10:39 | Computer Name = Chris-HP | Source = hpsa_service.exe | ID = 2000
Description = HP Error ID: -2146233088 bij HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetect()

bij HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan,
Boolean localScan) Message: One HP Active Check Local Mode job already running. StackTrace:
bij HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetect()

bij HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan,
Boolean localScan) Source: HP.ActiveCheckLocalMode.SessionManager Name: hpsa_service.exe
Version:
06.00.01.01 Path: C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
Format:
nl-NL RAM: 6143 Ram Utilization: 80 TargetSite: Void UpdateAndDetect()

Error - 6-11-2012 3:10:53 | Computer Name = Chris-HP | Source = hpsa_service.exe | ID = 2000
Description = HP Error ID: -2146233088 bij HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetect()

bij HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan,
Boolean localScan) Message: One HP Active Check Local Mode job already running. StackTrace:
bij HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetect()

bij HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan,
Boolean localScan) Source: HP.ActiveCheckLocalMode.SessionManager Name: hpsa_service.exe
Version:
06.00.01.01 Path: C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
Format:
nl-NL RAM: 6143 Ram Utilization: 30 TargetSite: Void UpdateAndDetect()

Error - 13-11-2012 3:23:04 | Computer Name = Chris-HP | Source = hpsa_service.exe | ID = 2000
Description = HP Error ID: -2146233088 bij HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetect()

bij HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan,
Boolean localScan) Message: One HP Active Check Local Mode job already running. StackTrace:
bij HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetect()

bij HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan,
Boolean localScan) Source: HP.ActiveCheckLocalMode.SessionManager Name: hpsa_service.exe
Version:
06.00.01.01 Path: C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
Format:
nl-NL RAM: 6143 Ram Utilization: 80 TargetSite: Void UpdateAndDetect()

Error - 20-11-2012 14:13:04 | Computer Name = Chris-HP | Source = hpsa_service.exe | ID = 2000
Description = HP Error ID: -2146233088 bij HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetect()

bij HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan,
Boolean localScan) Message: One HP Active Check Local Mode job already running. StackTrace:
bij HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetect()

bij HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan,
Boolean localScan) Source: HP.ActiveCheckLocalMode.SessionManager Name: hpsa_service.exe
Version:
06.00.01.01 Path: C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
Format:
nl-NL RAM: 6143 Ram Utilization: TargetSite: Void UpdateAndDetect()

Error - 22-11-2012 12:02:17 | Computer Name = Chris-HP | Source = HPSF.exe | ID = 2000
Description = HP Error ID: -2147467261 bij HP.SupportFramework.Utilities.CustomerExperience.HPSASession.AddNavigationProperties()
Message:
De objectverwijzing is niet op een exemplaar van een object ingesteld. StackTrace:
bij HP.SupportFramework.Utilities.CustomerExperience.HPSASession.AddNavigationProperties()
Source:
HP.SupportFramework.Utilities Name: HPSF.exe Version: 07.00.01.01 Path: C:\Program
Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe Format: nl-NL RAM: 6143
Ram
Utilization: 30 TargetSite: HP.SupportFramework.HPSFReporting._Property[] AddNavigationProperties()


[ System Events ]
Error - 9-12-2013 23:24:48 | Computer Name = Chris-HP | Source = Service Control Manager | ID = 7001
Description = De Windows Image Acquisition (WIA)-service is afhankelijk van de Shell
Hardware Detection-service, die vanwege de volgende fout niet kan worden gestart:
%%1058

Error - 9-12-2013 23:24:56 | Computer Name = Chris-HP | Source = Service Control Manager | ID = 7026
Description = De volgende opstartstuurprogramma's zijn niet geladen: CSN5PDTS82

Error - 9-12-2013 23:25:25 | Computer Name = Chris-HP | Source = Service Control Manager | ID = 7001
Description = De HomeGroup Provider-service is afhankelijk van de Function Discovery
Provider Host-service, die vanwege de volgende fout niet kan worden gestart: %%1058

Error - 9-12-2013 23:25:52 | Computer Name = Chris-HP | Source = WMPNetworkSvc | ID = 866300
Description =

Error - 10-12-2013 6:49:17 | Computer Name = Chris-HP | Source = Service Control Manager | ID = 7000
Description = De LiveUpdate-service kan vanwege de volgende fout niet worden gestart:
%%2

Error - 10-12-2013 6:49:21 | Computer Name = Chris-HP | Source = Service Control Manager | ID = 7001
Description = De Windows Image Acquisition (WIA)-service is afhankelijk van de Shell
Hardware Detection-service, die vanwege de volgende fout niet kan worden gestart:
%%1058

Error - 10-12-2013 6:49:25 | Computer Name = Chris-HP | Source = Service Control Manager | ID = 7026
Description = De volgende opstartstuurprogramma's zijn niet geladen: CSN5PDTS82

Error - 10-12-2013 6:49:55 | Computer Name = Chris-HP | Source = WMPNetworkSvc | ID = 866300
Description =

Error - 10-12-2013 6:50:22 | Computer Name = Chris-HP | Source = WMPNetworkSvc | ID = 866300
Description =

Error - 10-12-2013 6:50:22 | Computer Name = Chris-HP | Source = Service Control Manager | ID = 7001
Description = De HomeGroup Provider-service is afhankelijk van de Function Discovery
Provider Host-service, die vanwege de volgende fout niet kan worden gestart: %%1058


< End of report >

---------- Bericht toegevoegd op 12:33 ---------- Vorige bericht was op 12:33 ----------

kreeg steeds vraag deze pagina verlaten/op deze pagina blijven. doordat ik koos voor blijven is otl wellicht 2x geplaatst.
wilde het op gaan knippen, maar dat werkte ook niet hierbij dan extras
OTL Extras logfile created on: 12/10/2013 11:59:05 AM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Chris\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16736)
Locale: 00000409 | Country: Nederland | Language: NLD | Date Format: d-M-yyyy

6.00 Gb Total Physical Memory | 4.34 Gb Available Physical Memory | 72.40% Memory free
7.07 Gb Paging File | 5.00 Gb Available in Paging File | 70.65% Paging File free
Paging file location(s): c:\pagefile.sys 100 100z:\pagefil [Binary data over 200 bytes]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 465.85 Gb Total Space | 283.37 Gb Free Space | 60.83% Space Free | Partition Type: NTFS
Drive D: | 11.69 Gb Total Space | 1.41 Gb Free Space | 12.09% Space Free | Partition Type: NTFS
Drive K: | 1396.92 Gb Total Space | 705.66 Gb Free Space | 50.52% Space Free | Partition Type: FAT32
Drive Z: | 453.87 Gb Total Space | 204.11 Gb Free Space | 44.97% Space Free | Partition Type: NTFS

Computer Name: CHRIS-HP | User Name: Chris | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html[@ = ChromeHTML] -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = ChromeHTML] -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)

[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = ChromeHTML] -- Reg Error: Key error. File not found

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htafile [open] -- "%1" %*
htmlfile [edit] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1"
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [ALDI Print Software] -- "C:\Program Files (x86)\ALDI\ALDI Print Software\ALDI Print Software.exe" "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [Doorbladeren met Corel PaintShop Pro X5] -- "c:\Program Files (x86)\Corel\Corel PaintShop Pro X5\Corel PaintShop Pro.exe" "%L" (Corel, Inc.)
Directory [Doorbladeren met Corel PaintShop Pro X6] -- "c:\Program Files (x86)\Corel\Corel PaintShop Pro X6 (64-bit)\Corel PaintShop Pro.exe" "%L" (Corel, Inc.)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [tralih] -- "C:\Program Files (x86)\Trader's Little Helper\tralih.exe" /0 "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htafile [open] -- "%1" %*
htmlfile [edit] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1"
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [ALDI Print Software] -- "C:\Program Files (x86)\ALDI\ALDI Print Software\ALDI Print Software.exe" "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [Doorbladeren met Corel PaintShop Pro X5] -- "c:\Program Files (x86)\Corel\Corel PaintShop Pro X5\Corel PaintShop Pro.exe" "%L" (Corel, Inc.)
Directory [Doorbladeren met Corel PaintShop Pro X6] -- "c:\Program Files (x86)\Corel\Corel PaintShop Pro X6 (64-bit)\Corel PaintShop Pro.exe" "%L" (Corel, Inc.)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [tralih] -- "C:\Program Files (x86)\Trader's Little Helper\tralih.exe" /0 "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error.

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

========== Firewall Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0B7BC77A-F995-4F17-8CF7-2949B57F9A44}" = lport=445 | protocol=6 | dir=in | app=system |
"{14206650-2724-4D87-9C1F-212FAA262E3B}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{190257D4-6CE5-4D40-8B94-5A25A6F8D38C}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{44645350-61D6-4D92-A550-D38C1CFAD06F}" = rport=445 | protocol=6 | dir=out | app=system |
"{623A01A5-A774-4D68-BC3E-59E49EF46B9E}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{6D79163F-80E6-495D-A4E4-0086ED7361CB}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
"{7046FD8A-2A5C-4851-8A05-4C2FE2D434E1}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{7156B8B0-5CB6-4A06-958B-7CDD72A90168}" = lport=138 | protocol=17 | dir=in | app=system |
"{80097693-E3E9-4CEC-B4ED-A8386646B428}" = rport=138 | protocol=17 | dir=out | app=system |
"{8E2D791F-867F-4065-A417-D1B8D085A237}" = rport=137 | protocol=17 | dir=out | app=system |
"{A8A9D1D8-17DD-402A-BF89-067AD7E19AFC}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{B460CD34-D1E5-412A-A5A1-F04833B2891E}" = lport=137 | protocol=17 | dir=in | app=system |
"{BE3599C2-61D1-476A-9C11-2BC6F39D3F97}" = rport=139 | protocol=6 | dir=out | app=system |
"{E0210346-64CD-4256-99D7-ED0DECECFB02}" = lport=139 | protocol=6 | dir=in | app=system |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0B3C118C-1EDF-47D9-93D2-C2D4F13AC64B}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\dvd\hpdvdsmart.exe |
"{22C12025-192D-4A46-A60D-414B3F221EC2}" = protocol=6 | dir=in | app=c:\program files (x86)\anwb-reiswijzer\anwbreiswijzer.exe |
"{3227DF37-FCEE-4305-ABD3-97D21F9ABF7F}" = protocol=17 | dir=in | app=c:\program files (x86)\mypoi manager\mypoimanager.exe |
"{45499F0C-084D-48CC-BAB3-DDD738616E39}" = protocol=17 | dir=in | app=c:\program files (x86)\ivt corporation\bluesoleil\bluesoleil.exe |
"{4E0FDA0A-F30B-407C-AA5E-DC0E4916D423}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{4E5AA99C-9139-467D-B2F5-7DA82AD5899B}" = protocol=6 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe |
"{63B86D5D-2457-4594-9AE6-7C4CACACA244}" = protocol=6 | dir=in | app=c:\program files (x86)\mypoi manager\mypoimanager.exe |
"{6979B5E7-E481-4912-B71F-6F4D4F3BF2C7}" = protocol=17 | dir=in | app=c:\program files (x86)\namo\webeditor 8\bin\webeditor.exe |
"{6F3B03E1-F4D6-4B79-9953-59EC56CC57C4}" = protocol=6 | dir=in | app=c:\program files (x86)\ivt corporation\bluesoleil\bluesoleil.exe |
"{78C0C749-0FB9-4458-9C53-7DF684720C52}" = protocol=17 | dir=in | app=c:\windows\syswow64\msiexec.exe |
"{84A6BE33-753D-41EE-8AF3-C957AEFE74B0}" = dir=in | app=c:\program files (x86)\hewlett-packard\hp support framework\resources\hpwarrantycheck\hpdevicedetection3.exe |
"{890905CA-28C2-4E41-B9D3-7C32C0471FDC}" = protocol=17 | dir=in | app=c:\program files (x86)\anwb-reiswijzer\anwbreiswijzer.exe |
"{8A64134D-9883-4714-BE78-FAD54B628574}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{91790A59-5720-4790-B5D8-6691097D1F13}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{9C9C9C8F-E899-422A-9CA8-9E1E389355A5}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe |
"{A49C858A-B319-4E26-926B-FFD6F0698033}" = protocol=17 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe |
"{B0A34A2B-A15A-4E2F-ADC4-DB859CA7D3C3}" = dir=in | app=c:\program files (x86)\nokia\nokia suite\nokiasuite.exe |
"{BEE0AA5B-CA19-436A-8991-07199B507C34}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe |
"{CB921DD2-C656-4726-95AD-B63AFEAE1813}" = dir=in | app=c:\program files (x86)\nokia\nokia suite\nokiasuite.exe |
"{D10117E0-40C5-4729-BF08-4D1BDF34C51C}" = protocol=6 | dir=in | app=c:\windows\syswow64\msiexec.exe |
"{D71B044A-F20D-42F5-BC99-42A60803B876}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{F060EFCB-F0EA-4A6D-9442-B8183B61B7D1}" = protocol=6 | dir=in | app=c:\program files (x86)\namo\webeditor 8\bin\webeditor.exe |
"TCP Query User{ED943E9C-2E22-457F-8615-9690D26B079D}C:\program files (x86)\namo\webeditor 8\bin\webeditor.exe" = protocol=6 | dir=in | app=c:\program files (x86)\namo\webeditor 8\bin\webeditor.exe |
"UDP Query User{70A7F870-7B17-4FE7-BC9D-D874B996C325}C:\program files (x86)\namo\webeditor 8\bin\webeditor.exe" = protocol=17 | dir=in | app=c:\program files (x86)\namo\webeditor 8\bin\webeditor.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{027E5FAB-1476-4C59-AAB4-32EF28520399}" = Windows Live Language Selector
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_cnq4809" = CanoScan LiDE 210 Scanner Driver
"{1551A29F-B1B0-43CA-90B5-E6E5186F683E}" = PSPPro64
"{16582334-495C-4F1C-A66B-3BFD8866B674}" = PSPPro64
"{1678F86C-889D-4198-8249-F4625058256B}" = IPM_PSP_COM64
"{1ACC8FFB-9D84-4C05-A4DE-D28A9BC91698}" = Windows Live ID Sign-in Assistant
"{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
"{237D687E-9E50-4A30-B810-262764CC491B}" = Garmin Communicator Plugin x64
"{350AA351-21FA-3270-8B7A-835434E766AD}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{4D668D4F-FAA2-4726-834C-31F4614F312E}" = MSVC80_x64_v2
"{503F672D-6C84-448A-8F8F-4BC35AC83441}" = AMD APP SDK Runtime
"{53A19094-2C04-A9B9-7309-3E92152D4845}" = AMD Catalyst Install Manager
"{5B08AF35-B699-4A44-BB89-3E51E70611E8}" = HP MediaSmart SmartMenu
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{680EDA59-9266-44B4-949E-0C24F65DFF82}" = Microsoft_VC100_CRT_SP1_x64
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{AB071C8B-873C-459F-ACA9-9EBE03C3E89B}" = MSVC90_x64
"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{B6E3757B-5E77-3915-866A-CCFC4B8D194C}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053
"{B821CDAA-34DE-46FD-87C9-E6EE7158DB5D}" = Microsoft Image Composite Editor
"{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}" = PlayReady PC Runtime amd64
"{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter
"{EA78A5C4-E494-4232-85BE-A1F2CDDD1A54}" = Athentech Perfectly Clear
"{ED246336-2A22-E930-6602-9B942BE7A7C4}" = ccc-utility64
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"{F7CF9A5B-35DD-4C5D-8138-C94A1E324F7A}" = Microsoft Camera Codec Pack
"{FB237A35-F491-4AC1-95E0-85118D6751D9}" = Topaz Adjust 4 (64-bit)
"3134FEF0E1D959EC0CC2E458C94B7057B2AC0CC9" = Windows-stuurprogrammapakket - FTDI CDM Driver Package (10/22/2009 2.06.00)
"62BBD193ADFDBB228C7E1ADB56463F5732FF7F6F" = Windows-stuurprogrammapakket - Nokia pccsmcfd LegacyDriver (05/31/2012 7.1.2.0)
"72A50F48CC5601190B9C4E74D81161693133E7F7" = Windows-stuurprogrammapakket - Nokia Modem (02/25/2011 7.01.0.9)
"88EB56038379B8B7DCFB4D2448A60F52E064B265" = Windows-stuurprogrammapakket - FTDI CDM Driver Package (10/22/2009 2.06.00)
"98157A226B40B173301B0F53C8E98C47805D5152" = Windows Driver Package - Garmin (grmnusb) GARMIN Devices (04/19/2012 2.3.1.0)
"Artensoft Photo Collage Maker_is1" = Artensoft Photo Collage Maker
"E0AC723A3DE3A04256288CADBBB011B112AED454" = Windows-stuurprogrammapakket - Nokia Modem (02/25/2011 4.7)
"Juniper_Setup_Client Activex Control" = Juniper Networks, Inc. Setup Client 64-bit Activex Control
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"PC-Doctor for Windows" = Hardware Diagnostic Tools
"Pen Tablet Driver" = Bamboo
"Recuva" = Recuva
"WinRAR archiver" = WinRAR 4.00 (64-bit)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"_{050AE842-C0D4-4322-ABAF-4202459E003F}" = Corel PaintShop Pro Picture Tube Content
"_{12097B7C-04C4-4049-AEBF-0ECE0D6FCEE3}" = Athentech Perfectly Clear
"_{12229E88-1510-474C-88B9-E635830F9C82}" = Corel PaintShop Pro Picture Frame Content
"_{1563C6F2-E9B5-42DE-9EA6-207C9A8C2DFB}" = Corel PaintShop Pro X5
"_{166D1CB6-DD8A-40DD-9E25-4D31D2D6DE4D}" = Corel PaintShop Pro X6
"_{21C5C3F6-C670-4A09-86E5-B88A67A9F406}" = Corel PaintShop Pro Misc Content
"_{4A263708-ED65-4E60-B7C8-CE5B0EED5FC6}" = Corel PaintShop Pro Misc Content
"_{6036ED4A-954A-4DED-8565-C91D439024BE}" = Corel PaintShop Pro Misc Content
"_{7BEBFF10-797B-4883-9959-06E66D6254DE}" = Corel KPT Collection
"_{A5BD6F26-D9D5-4ABD-A82E-9F5ABD5504CB}" = Creative Content
"_{AE4364BD-ED09-4D94-8DA2-315C10A57CD1}" = Ultimate Creative Collection (X5)
"_{B20C88E8-CD0D-4354-8A78-32CCF73F6240}" = Corel PaintShop Pro Misc Content
"_{BA7B3A61-EB8C-4C70-8179-93DDA248AA49}" = Nik Color Efex Pro 3.0
"_{BEDD3AB4-28DA-45CF-AFE3-55EF4B4C7608}" = Corel PaintShop Pro Misc Content
"_{BFF48D77-3D57-4005-AE39-76D389153042}" = Corel PaintShop Pro Misc Content
"_{C42299E7-8CB0-48F1-93ED-245A42C85D9F}" = Corel PaintShop Pro Brush Content
"_{C59A783C-FF5C-40BE-843A-5458513D655B}" = Corel KPT Collection
"_{D5346965-CB0A-41B8-8B5F-8B41ABF848BF}" = Corel PaintShop Pro Misc Content
"_{D839B02E-8C50-4F8F-BA53-84FF75487A1A}" = Ultimate Creative Collection (X6)
"{00000413-78E1-11D2-B60F-006097C998E7}" = Microsoft Office 2000 Premium
"{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}" = PDFCreator
"{0138F525-6C8A-333F-A105-14AE030B9A54}" = Visual C++ 9.0 CRT (x86) WinSXS MSM
"{022E2D1B-439D-4AA6-B74E-F644A425CF48}" = iPictDB Windows Live Gallery Plugin
"{031338C0-4C21-4DAC-875B-26ACD7ADDF23}" = Corel KPT Collection
"{050AE842-C0D4-4322-ABAF-4202459E003F}" = Corel PaintShop Pro Picture Tube Content
"{06F25DC8-71E2-44E2-805A-F15E15B51C74}_is1" = Remove Empty Directories version 2.2
"{07FA4960-B038-49EB-891B-9F95930AA544}" = HP Customer Experience Enhancements
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0C6DB6B9-2D17-4AA5-A207-42D28BF9F434}" = MyPoi Manager
"{116A9A5B-D5B5-C0AE-52ED-F50013BA1185}" = CCC Help Norwegian
"{12097B7C-04C4-4049-AEBF-0ECE0D6FCEE3}" = Athentech Perfectly Clear
"{12229E88-1510-474C-88B9-E635830F9C82}" = Corel PaintShop Pro Picture Frame Content
"{14B441B7-774D-4170-98EA-A13667AE6218}" = Windows Live Writer Resources
"{15002A1B-C1E7-4E91-A3EC-5502BF924A32}" = Setup
"{15180A90-1FC0-47E4-A150-3AECEF07B3B6}" = Corel PaintShop Pro X5
"{1522E36C-3739-41E4-8CD3-A4AFEA70086A}" = PSPPContent
"{153DD765-C8C6-4893-8CEF-D965351D82EC}" = PSPPHelp
"{154B0B16-ABCD-4A06-B0B7-8146B7A89B25}" = IPM_PSP_COM
"{1563C6F2-E9B5-42DE-9EA6-207C9A8C2DFB}" = ICA
"{16006EE1-DDB7-4E5F-8696-9FEF32C0151A}" = Setup
"{161AB62E-65D6-46E5-B3D8-2AC15D3B920B}" = Corel PaintShop Pro X6
"{162BD2D6-6C63-41A7-8151-93188450D36A}" = PSPPContent
"{16346B2A-87BC-407C-9D6B-72A4D21ABF03}" = PSPPHelp
"{164D34E1-0271-4960-8A26-E8990A302DB1}" = IPM_PSP_COM
"{166D1CB6-DD8A-40DD-9E25-4D31D2D6DE4D}" = ICA
"{196467F1-C11F-4F76-858B-5812ADC83B94}" = MSXML 4.0 SP3 Parser
"{1987D283-9A22-2FCF-859C-41D362C170C3}" = CCC Help Russian
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{1F976B1D-7CFD-44F6-B016-1D3B0FFA937A}" = TuneUp Utilities Language Pack (nl-NL)
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{21C5C3F6-C670-4A09-86E5-B88A67A9F406}" = Corel PaintShop Pro Misc Content
"{236BB7C4-4419-42FD-0409-1E257A25E34D}" = Adobe Photoshop CS2
"{25AC788F-0563-260D-32E0-022D92716227}" = CCC Help Spanish
"{2624B680-02BC-4CBC-839C-DA20DF6EF6EC}" = Citrix Presentation Server Client
"{26A24AE4-039D-4CA4-87B4-2F83217025FF}" = Java 7 Update 45
"{290B6C2A-19BB-BE0A-C091-43B5D0A32427}" = CCC Help Chinese Traditional
"{2A07C35B-8384-4DA4-9A95-442B6C89A073}" = Windows Live Essentials
"{2EFA4E4C-7B5F-48F7-A1C0-1AA882B7A9C3}" = HP Update
"{2FA94A64-C84E-49d1-97DD-7BF06C7BBFB2}.WildTangent Games App" = Update Installer for WildTangent Games App
"{30B41B7A-3C9D-44DE-A7A1-949011F33CC3}" = PDF Architect
"{31a12940-e5c8-4d27-a6ac-005212152f1f}" = Garmin Express
"{31C40A62-78E5-4662-3DA3-6AC9C3425F72}" = Catalyst Control Center Graphics Previews Common
"{33032DAA-32D3-C954-8CC3-468522F4F745}" = CCC Help French
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{33EBF075-8593-4698-BDAF-CF8DED80BB5B}" = Nokia Suite
"{359FCAA7-B544-4147-AE3B-8C8A526E2427}" = Sony Image Data Suite
"{369FA236-890F-4490-B607-092BC17E10CD}" = Elevated Installer
"{36DA2332-923F-8262-190A-020087A6643D}" = CCC Help English
"{3D5D6CFC-3097-425A-8D8F-7EAF5D57641D}" = Garmin USB Drivers
"{40FB8D7C-6FF8-4AF2-BC8B-0B1DB32AF04B}" = HP Advisor
"{417F3E7E-C754-4707-BF5B-94750B83D58A}" = Garmin Express Tray
"{4209F371-393F-E3AF-1440-2EAD843B93B4}_is1" = Ashampoo WinOptimizer Free v.1.0.0
"{42B9D779-CF1F-478D-A393-950CE0E48177}" = Garmin Update Service
"{42D10994-A566-495D-A5E7-D0C6B5C6B35C}" = HP Product Detection
"{44B2A0AB-412E-4F8C-B058-D1E8AECCDFF5}" = Recovery Manager
"{477213DD-8FFC-CDFE-3E12-145F71ADAA7D}" = Catalyst Control Center Localization All
"{47E0C66C-6696-D28F-5E3A-76CD761C5E57}" = CCC Help Swedish
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4A263708-ED65-4E60-B7C8-CE5B0EED5FC6}" = Corel PaintShop Pro Misc Content
"{4D933B36-4A8A-C2C1-6A88-2FC20EFD2772}" = AMD VISION Engine Control Center
"{5158F1F5-FA1B-4D49-B546-55A5004B89BD}" = Microsoft Works
"{52B99BCA-6251-498F-88CA-420D31CBC8C7}" = Wacom JustWrite Office
"{5A12B00F-080C-A75E-E127-1F8D884EBFAF}" = CCC Help Czech
"{5BDA2F58-1F21-4D10-9910-92B01EBCC958}" = AMD USB Filter Driver
"{5CA74EDC-CFC3-4FA0-AED7-1415CA19F250}" = Garmin POI Loader
"{5E87E7CE-9E68-FF00-71E0-2BF35D90DAA3}" = CCC Help Italian
"{6020758E-57A9-41E3-AF20-8EE311EA6156}" = FaceFilter v3.02 Standard
"{6036ED4A-954A-4DED-8565-C91D439024BE}" = Corel PaintShop Pro Misc Content
"{658AB1BF-9A07-4AAD-B6BB-7CADD2307C75}" = Garmin Express
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{6845255F-15CC-4DD1-94D5-D38F370118B3}_is1" = Auslogics Duplicate File Finder
"{6AFCA4E1-9B78-3640-8F72-A7BF33448200}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
"{6C5F8503-55D2-4398-858C-362B7A7AF51C}" = Firebird SQL Server - MAGIX Edition
"{6D3245B1-8DB8-4A23-9CD2-2C90F40ABAF6}" = MSVC80_x86_v2
"{6DAF8CDC-9B04-413B-A0F2-BCC13CF8A5BF}" = HP MediaSmart Photo
"{6F340107-F9AA-47C6-B54C-C3A19F11553F}" = Hewlett-Packard ACLM.NET v1.2.1.1
"{70B446D1-E03B-4ab0-9B3C-0832142C9AA8}.WildTangent Games App-hp" = WildTangent Games App (HP Games)
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{729A3000-BC8A-3B74-BA5D-5068FE12D70C}" = Microsoft Visual F# 2.0 Runtime
"{752D319E-E2D1-2C60-5FD8-311DF92C62A3}" = CCC Help Hungarian
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{772DF2FC-DB4B-3DF4-C65D-CBF0A094DDC9}" = CCC Help Portuguese
"{786C5747-1033-0000-B58E-000000000001}" = Adobe Stock Photos 1.0
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{7A99276D-3D92-50A5-8EF0-3ADDD1507D43}" = CCC Help Danish
"{7BEBFF10-797B-4883-9959-06E66D6254DE}" = Corel KPT Collection
"{7FB71EA0-843D-23C1-8926-E2CDC347296F}" = CCC Help Chinese Standard
"{80E0CBFB-6895-2C0B-39DE-7F42F42FDC9A}" = CCC Help Greek
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{846AC73B-9394-48B9-B941-8F7F472F0047}" = Bluesoleil2.6.0.9 Release 070606
"{866C4563-ED53-43F3-A29D-8BEE2BD1BA3C}" = Nokia PC Suite
"{8D0B7E15-AAA8-BE2B-B010-95D5A76EC397}" = CCC Help Dutch
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{8EDBA74D-0686-4C99-BFDD-F894678E5B39}" = Adobe Common File Installer
"{8EF7A04E-C5A6-459E-8106-362AEE79A5F6}" = ANWB-reiswijzer
"{8FC4F1DD-F7FD-4766-804D-3C8FF1D309AF}" = Ralink 802.11n Wireless LAN Card
"{90120000-0020-0413-0000-0000000FF1CE}" = Compatibiliteitspakket voor het 2007 Microsoft Office system
"{90538B62-F392-4DE1-B886-7B48123866E9}" = LightScribe System Software
"{91A34181-9FAD-43AB-A35F-E7A8945B7E1C}" = HP MediaSmart Music
"{91F7C67B-C1A2-F1DB-C286-7F56A07C6B49}" = HydraVision
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{96AD3B61-EAE2-11E2-9E72-B8AC6F98CCE3}" = Google Earth
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BD262D0-B788-4546-A0A5-F4F56EC3834B}" = Windows Live Photo Common
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{9FCBD98D-F8B3-6ECC-5293-9C28817E3269}" = Catalyst Control Center InstallProxy
"{9FDC7042-CB9F-4336-A14C-DF10F53762E2}" = Topaz Adjust 4
"{A2090170-70B6-40D6-8B43-04ECDC641EA6}" = TuneUp Utilities Language Pack (nl-NL)
"{A57025CC-5F2E-4D01-B387-06DB10500D43}" = Nokia Connectivity Cable Driver
"{A5BD6F26-D9D5-4ABD-A82E-9F5ABD5504CB}" = Creative Content
"{A60B3BF0-954B-42AF-B8D8-2C1D34B613AA}" = Windows Live Photo Gallery
"{A7D1EC13-4B5F-43AA-A048-B1AF591450A6}" = Garmin BaseCamp
"{A85E0098-F8BA-40A2-B9E1-E3C04574C53A}" = jAlbum
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AAFC6C24-11A1-7AA8-75C1-63037733F06D}" = CCC Help Japanese
"{AC6B513F-311B-910C-FC02-59CE31D47648}" = Catalyst Control Center Profiles Desktop
"{AC76BA86-7AD7-1043-7B44-AA1000000001}" = Adobe Reader X (10.1.8) - Nederlands
"{ACDE3E85-CB61-48D8-B19B-F6D6AA0AA62A}" = Catalyst Control Center - Branding
"{AE09704D-9051-4C25-B940-77F889F0C93F}" = OVTScanner_X64
"{AE4364BD-ED09-4D94-8DA2-315C10A57CD1}" = Ultimate Creative Collection (X5)
"{AF111648-99A1-453E-81DD-80DBBF6DAD0D}" = MSVC90_x86
"{AFBAB9A0-DDE8-49AE-8C17-A01B61BEE64B}" = Garmin MapSource
"{B20C88E8-CD0D-4354-8A78-32CCF73F6240}" = Corel PaintShop Pro Misc Content
"{B67BAFBA-4C9F-48FA-9496-933E3B255044}" = QuickTime
"{B6A98E5F-D6A7-46FB-9E9D-1F7BF443491C}" = PMB
"{B74D4E10-1033-0000-0000-000000000001}" = Adobe Bridge 1.0
"{B8AC1A89-FFD1-4F97-8051-E505A160F562}" = HP Odometer
"{B9A03B7B-E0FF-4FB3-BA83-762E58A1B0AA}" = HP Support Information
"{BA77F9D2-CD35-41EB-9BC9-769879DFF8A6}" = PC Connectivity Solution
"{BA7B3A61-EB8C-4C70-8179-93DDA248AA49}" = Nik Color Efex Pro 3.0
"{BEDD3AB4-28DA-45CF-AFE3-55EF4B4C7608}" = Corel PaintShop Pro Misc Content
"{BFF48D77-3D57-4005-AE39-76D389153042}" = Corel PaintShop Pro Misc Content
"{C34AB2ED-D990-645C-77A3-9B916C23B3C0}" = CCC Help Finnish
"{C42299E7-8CB0-48F1-93ED-245A42C85D9F}" = Corel PaintShop Pro Brush Content
"{C4ABDBC8-1C81-42C9-BFFC-4A68511E9E4F}" = TuneUp Utilities 2013
"{C59A783C-FF5C-40BE-843A-5458513D655B}" = Corel KPT Collection
"{C7340571-7773-4A8C-9EBC-4E4243B38C76}" = Microsoft XML Parser
"{CB7224D9-6DCA-43F1-8F83-6B1E39A00F92}" = Windows Live Movie Maker
"{CBD8081C-0FE6-4EB3-A7F8-FFC13A603BBF}" = CCC Help Thai
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{CEC8F2E3-AC9A-357C-BFCB-BFAC37C4AC50}" = Visual C++ 9.0 ATL (x86) WinSXS MSM
"{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64
"{D3507473-2CE3-4073-A6BA-A0846B5CC687}" = Namo WebEditor 8
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{D5346965-CB0A-41B8-8B5F-8B41ABF848BF}" = Corel PaintShop Pro Misc Content
"{D588365A-AE39-4F27-BDAE-B4E72C8E900C}" = Windows Live Mail
"{D6F25CF9-4E87-43EB-B324-C12BE9CDD668}" = Windows Live UX Platform Language Pack
"{D839B02E-8C50-4F8F-BA53-84FF75487A1A}" = Ultimate Creative Collection (X6)
"{D8603E3A-F40F-E3B4-6AAA-9C3E69ADC8B9}" = CCC Help Korean
"{DCCAD079-F92C-44DA-B258-624FC6517A5A}" = HP MediaSmart DVD
"{DDA44FB3-1CE1-02B2-5610-444C24EC55BB}" = CCC Help Turkish
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}" = Windows Media Encoder 9 Series
"{E3B64CC5-C011-40C0-92BC-7316CD5E5688}" = Microsoft_VC100_CRT_SP1_x86
"{E9787678-1033-0000-8E67-000000000001}" = Adobe Help Center 1.0
"{ED09A2DF-9342-8F82-B6FD-FA5311050F77}" = CCC Help German
"{EE202411-2C26-49E8-9784-1BC1DBF7DE96}" = HP Support Assistant
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F177CDAF-0A53-9B0D-A0F1-E83E237CA2A6}" = Catalyst Control Center InstallProxy
"{F5266D28-E0B2-4130-BFC5-EE155AD514DC}" = Apple Application Support
"{F5C7FD70-2C0A-401E-95E9-916363567DDA}" = HP Setup
"{F6CE5596-9C67-2E12-DC9B-F81859F2BB26}" = CCC Help Polish
"{FC274982-5AAD-4C20-848D-4424A5043009}_is1" = WinUtilities 10.55 Professional Edition
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Photoshop CS2 - {236BB7C4-4419-42FD-0409-1E257A25E34D}" = Adobe Photoshop CS2
"ALDI Print Software" = ALDI Print Software
"avast" = avast! Free Antivirus
"CanonSolutionMenuEX" = Canon Solution Menu EX
"Colasoft Capsa 7 Free_is1" = Colasoft Capsa 7 Free
"DreamSuite Bonus" = Uninstall DreamSuite Bonus
"Exif Pilot_is1" = Exif Pilot 4.7
"FaceOffMax" = Face Off Max
"GeoSetter_is1" = GeoSetter 3.4.16
"Google Chrome" = Google Chrome
"GPicSync_is1" = GPicSync 1.30
"GrabIt_is1" = GrabIt 1.7.2 Beta 4 (build 997)
"ImgBurn" = ImgBurn
"Inkscape" = Inkscape 0.47
"InstallShield_{6DAF8CDC-9B04-413B-A0F2-BCC13CF8A5BF}" = HP MediaSmart Photo
"InstallShield_{91A34181-9FAD-43AB-A35F-E7A8945B7E1C}" = HP MediaSmart Music
"InstallShield_{DCCAD079-F92C-44DA-B258-624FC6517A5A}" = HP MediaSmart DVD
"Karen's Directory Printer" = Karen's Directory Printer
"MAGIX Music Cleaning Lab 2007 deluxe NL" = MAGIX Music Cleaning Lab 2007 deluxe (NL)
"MAGIX Music Manager 2006 NL" = MAGIX Music Manager 2006 (NL)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware versie 1.75.0.1300
"MP Navigator 3.1" = Canon MP Navigator 3.1
"MP Navigator EX 4.0" = Canon MP Navigator EX 4.0
"MusicStationNetstaller" = MusicStation
"My HP Game Console" = HP Game Console
"Nokia PC Suite" = Nokia PC Suite
"Nokia Suite" = Nokia Suite
"PoiEdit" = PoiEdit
"SignCut" = SignCut (remove only)
"TradersLittleHelper_is1" = Trader's Little Helper 2.7.0
"TuneUp Utilities 2013" = TuneUp Utilities 2013
"Tyre_is1" = Tyre
"uTorrent" = ?Torrent
"Wacom WebTabletPlugin for IE" = WebTablet IE Plugin
"Wacom WebTabletPlugin for Internet Explorer and Netscape" = WebTablet FB Plugin
"WildTangent hp Master Uninstall" = HP Games
"Windows Media Encoder 9" = Windows Media Encoder 9 Series
"WinHTTrack Website Copier_is1" = WinHTTrack Website Copier 3.46-1
"WinLiveSuite" = Windows Live Essentials
"Wire Pilot Lite_is1" = Wire Pilot Lite 3.0.4
"WT082122" = Blackhawk Striker 2
"WT082124" = Blasterball 3
"WT082133" = Dora's Carnival Adventure
"WT082141" = FATE
"WT082168" = Penguins!
"WT082170" = Plants vs. Zombies
"WT082171" = Poker Superstars III
"WT082172" = Polar Bowler
"WT082173" = Polar Golfer
"WT082188" = Virtual Families
"WT082192" = Bejeweled 2 Deluxe
"WT082200" = Chuzzle Deluxe
"WT082241" = Virtual Villagers - The Secret City
"WT082439" = Bus Driver
"WT082442" = Faerie Solitaire
"WT082443" = Jewel Quest 3
"WT082463" = Zuma's Revenge
"WT083484" = Escape Rosecliff Island
"WT083492" = Agatha Christie - Death on the Nile
"XML Copy Editor_is1" = XML Copy Editor version 1.2.0.9

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Aldfaer" = Aldfaer
"Juniper_Networks_Cache_Cleaner 6.5.0" = Juniper Networks Cache Cleaner 6.5.0
"Juniper_Setup_Client" = Juniper Networks, Inc. Setup Client
"Neoteris_Host_Checker" = Juniper Networks Host Checker
"TwistedBrush Pro Studio" = TwistedBrush Pro Studio

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 9-12-2013 22:43:47 | Computer Name = Chris-HP | Source = VSS | ID = 12292
Description =

Error - 9-12-2013 22:43:47 | Computer Name = Chris-HP | Source = VSS | ID = 8193
Description =

Error - 9-12-2013 22:43:47 | Computer Name = Chris-HP | Source = System Restore | ID = 8193
Description =

Error - 9-12-2013 23:27:00 | Computer Name = Chris-HP | Source = Application Error | ID = 1000
Description = Naam van toepassing met fout: dds.com, versie: 2012.11.20.1, tijdstempel:
0x4b1ae3c6 Naam van module met fout: System.dll, versie: 0.0.0.0, tijdstempel: 0x4b1ae3ad
Uitzonderingscode:
0xc0000005 Foutoffset: 0x0000186d Id van proces met fout: 0x122c Starttijd van toepassing
met fout: 0x01cef5578ed856a1 Pad naar toepassing met fout: C:\Users\Chris\Desktop\dds.com
Pad
naar module met fout: C:\Users\Chris\AppData\Local\Temp\nsg2F8A.tmp\System.dll Rapport-id:
ed8eea32-614a-11e3-8292-00116778ad73

Error - 9-12-2013 23:28:01 | Computer Name = Chris-HP | Source = VSS | ID = 13
Description =

Error - 9-12-2013 23:28:01 | Computer Name = Chris-HP | Source = VSS | ID = 12292
Description =

Error - 10-12-2013 2:09:41 | Computer Name = Chris-HP | Source = VSS | ID = 13
Description =

Error - 10-12-2013 2:09:41 | Computer Name = Chris-HP | Source = VSS | ID = 12292
Description =

Error - 10-12-2013 2:09:41 | Computer Name = Chris-HP | Source = VSS | ID = 8193
Description =

Error - 10-12-2013 2:09:41 | Computer Name = Chris-HP | Source = System Restore | ID = 8193
Description =

[ Hewlett-Packard Events ]
Error - 22-9-2012 23:49:17 | Computer Name = Chris-HP | Source = hpsa_service.exe | ID = 2000
Description = HP Error ID: -2146233088 bij HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetect()

bij HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan,
Boolean localScan) Message: One HP Active Check Local Mode job already running. StackTrace:
bij HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetect()

bij HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan,
Boolean localScan) Source: HP.ActiveCheckLocalMode.SessionManager Name: hpsa_service.exe
Version:
06.00.01.01 Path: C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
Format:
nl-NL RAM: 6143 Ram Utilization: 30 TargetSite: Void UpdateAndDetect()

Error - 25-9-2012 2:12:31 | Computer Name = Chris-HP | Source = hpsa_service.exe | ID = 2000
Description = HP Error ID: -2146233088 bij HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetect()

bij HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan,
Boolean localScan) Message: One HP Active Check Local Mode job already running. StackTrace:
bij HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetect()

bij HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan,
Boolean localScan) Source: HP.ActiveCheckLocalMode.SessionManager Name: hpsa_service.exe
Version:
06.00.01.01 Path: C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
Format:
nl-NL RAM: 6143 Ram Utilization: 50 TargetSite: Void UpdateAndDetect()

Error - 9-10-2012 2:31:52 | Computer Name = Chris-HP | Source = hpsa_service.exe | ID = 2000
Description = HP Error ID: -2146233088 bij HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetect()

bij HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan,
Boolean localScan) Message: One HP Active Check Local Mode job already running. StackTrace:
bij HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetect()

bij HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan,
Boolean localScan) Source: HP.ActiveCheckLocalMode.SessionManager Name: hpsa_service.exe
Version:
06.00.01.01 Path: C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
Format:
nl-NL RAM: 6143 Ram Utilization: 20 TargetSite: Void UpdateAndDetect()

Error - 16-10-2012 2:48:19 | Computer Name = Chris-HP | Source = hpsa_service.exe | ID = 2000
Description = HP Error ID: -2146233088 bij HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetect()

bij HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan,
Boolean localScan) Message: One HP Active Check Local Mode job already running. StackTrace:
bij HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetect()

bij HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan,
Boolean localScan) Source: HP.ActiveCheckLocalMode.SessionManager Name: hpsa_service.exe
Version:
06.00.01.01 Path: C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
Format:
nl-NL RAM: 6143 Ram Utilization: 80 TargetSite: Void UpdateAndDetect()

Error - 23-10-2012 13:12:05 | Computer Name = Chris-HP | Source = hpsa_service.exe | ID = 2000
Description = HP Error ID: -2146233088 bij HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetect()

bij HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan,
Boolean localScan) Message: One HP Active Check Local Mode job already running. StackTrace:
bij HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetect()

bij HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan,
Boolean localScan) Source: HP.ActiveCheckLocalMode.SessionManager Name: hpsa_service.exe
Version:
06.00.01.01 Path: C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
Format:
nl-NL RAM: 6143 Ram Utilization: 20 TargetSite: Void UpdateAndDetect()

Error - 30-10-2012 3:10:39 | Computer Name = Chris-HP | Source = hpsa_service.exe | ID = 2000
Description = HP Error ID: -2146233088 bij HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetect()

bij HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan,
Boolean localScan) Message: One HP Active Check Local Mode job already running. StackTrace:
bij HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetect()

bij HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan,
Boolean localScan) Source: HP.ActiveCheckLocalMode.SessionManager Name: hpsa_service.exe
Version:
06.00.01.01 Path: C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
Format:
nl-NL RAM: 6143 Ram Utilization: 80 TargetSite: Void UpdateAndDetect()

Error - 6-11-2012 3:10:53 | Computer Name = Chris-HP | Source = hpsa_service.exe | ID = 2000
Description = HP Error ID: -2146233088 bij HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetect()

bij HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan,
Boolean localScan) Message: One HP Active Check Local Mode job already running. StackTrace:
bij HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetect()

bij HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan,
Boolean localScan) Source: HP.ActiveCheckLocalMode.SessionManager Name: hpsa_service.exe
Version:
06.00.01.01 Path: C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
Format:
nl-NL RAM: 6143 Ram Utilization: 30 TargetSite: Void UpdateAndDetect()

Error - 13-11-2012 3:23:04 | Computer Name = Chris-HP | Source = hpsa_service.exe | ID = 2000
Description = HP Error ID: -2146233088 bij HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetect()

bij HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan,
Boolean localScan) Message: One HP Active Check Local Mode job already running. StackTrace:
bij HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetect()

bij HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan,
Boolean localScan) Source: HP.ActiveCheckLocalMode.SessionManager Name: hpsa_service.exe
Version:
06.00.01.01 Path: C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
Format:
nl-NL RAM: 6143 Ram Utilization: 80 TargetSite: Void UpdateAndDetect()

Error - 20-11-2012 14:13:04 | Computer Name = Chris-HP | Source = hpsa_service.exe | ID = 2000
Description = HP Error ID: -2146233088 bij HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetect()

bij HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan,
Boolean localScan) Message: One HP Active Check Local Mode job already running. StackTrace:
bij HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetect()

bij HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan,
Boolean localScan) Source: HP.ActiveCheckLocalMode.SessionManager Name: hpsa_service.exe
Version:
06.00.01.01 Path: C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
Format:
nl-NL RAM: 6143 Ram Utilization: TargetSite: Void UpdateAndDetect()

Error - 22-11-2012 12:02:17 | Computer Name = Chris-HP | Source = HPSF.exe | ID = 2000
Description = HP Error ID: -2147467261 bij HP.SupportFramework.Utilities.CustomerExperience.HPSASession.AddNavigationProperties()
Message:
De objectverwijzing is niet op een exemplaar van een object ingesteld. StackTrace:
bij HP.SupportFramework.Utilities.CustomerExperience.HPSASession.AddNavigationProperties()
Source:
HP.SupportFramework.Utilities Name: HPSF.exe Version: 07.00.01.01 Path: C:\Program
Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe Format: nl-NL RAM: 6143
Ram
Utilization: 30 TargetSite: HP.SupportFramework.HPSFReporting._Property[] AddNavigationProperties()


[ System Events ]
Error - 9-12-2013 23:24:48 | Computer Name = Chris-HP | Source = Service Control Manager | ID = 7001
Description = De Windows Image Acquisition (WIA)-service is afhankelijk van de Shell
Hardware Detection-service, die vanwege de volgende fout niet kan worden gestart:
%%1058

Error - 9-12-2013 23:24:56 | Computer Name = Chris-HP | Source = Service Control Manager | ID = 7026
Description = De volgende opstartstuurprogramma's zijn niet geladen: CSN5PDTS82

Error - 9-12-2013 23:25:25 | Computer Name = Chris-HP | Source = Service Control Manager | ID = 7001
Description = De HomeGroup Provider-service is afhankelijk van de Function Discovery
Provider Host-service, die vanwege de volgende fout niet kan worden gestart: %%1058

Error - 9-12-2013 23:25:52 | Computer Name = Chris-HP | Source = WMPNetworkSvc | ID = 866300
Description =

Error - 10-12-2013 6:49:17 | Computer Name = Chris-HP | Source = Service Control Manager | ID = 7000
Description = De LiveUpdate-service kan vanwege de volgende fout niet worden gestart:
%%2

Error - 10-12-2013 6:49:21 | Computer Name = Chris-HP | Source = Service Control Manager | ID = 7001
Description = De Windows Image Acquisition (WIA)-service is afhankelijk van de Shell
Hardware Detection-service, die vanwege de volgende fout niet kan worden gestart:
%%1058

Error - 10-12-2013 6:49:25 | Computer Name = Chris-HP | Source = Service Control Manager | ID = 7026
Description = De volgende opstartstuurprogramma's zijn niet geladen: CSN5PDTS82

Error - 10-12-2013 6:49:55 | Computer Name = Chris-HP | Source = WMPNetworkSvc | ID = 866300
Description =

Error - 10-12-2013 6:50:22 | Computer Name = Chris-HP | Source = WMPNetworkSvc | ID = 866300
Description =

Error - 10-12-2013 6:50:22 | Computer Name = Chris-HP | Source = Service Control Manager | ID = 7001
Description = De HomeGroup Provider-service is afhankelijk van de Function Discovery
Provider Host-service, die vanwege de volgende fout niet kan worden gestart: %%1058


< End of report >

---------- Bericht toegevoegd op 12:35 ---------- Vorige bericht was op 12:33 ----------

POEH

kreeg bij extras ook weer die vraag.
pas na kiezen pagina verlaten op F5 drukken, weer pagina verlaten lukte het om bericht te plaatsen.
 
Re: Nation Zoom opent in IE en in Chrome Niet te verwijderen.

Je hebt die browser hijack vermoedelijk met de installatie van Mobogenie binnengehaald!

Sluit voordat
51f51523a23a0-OTL_Canned_Nieuw.png
OTL de fix gaat doen, eerst alle andere openstaande vensters!

  • Windows 2000 en Windows XP: dubbelklik op OTL.exe.
  • Windows Vista, Windows 7 en Windows 8: via rechtsklik op OTL.exe en kies voor "Als Administrator uitvoeren".
    [*]Kopieer onderstaande in de Code-kader staande tekst en plak deze in het venster onder
    4f9111a6d2a6c-OTL-2.png

Code:
:OTL 
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.nationzoom.com/?type=hp&t...D0S1YMC0S1YMCX
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.nationzoom.com/web/?type=ds&ts=1386550966&from=adks&uid=HitachiXHDS72 1010CLA332_JP2940HD0S1YMC0S1YMCX&q={searchTerms}
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.nationzoom.com/web/?type=ds&ts=1386550966&from=adks&uid=HitachiXHDS72 1010CLA332_JP2940HD0S1YMC0S1YMCX&q={searchTerms}
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.nationzoom.com/?type=hp&t...D0S1YMC0S1YMCX
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.nationzoom.com/web/?type=ds&ts=1386550966&from=adks&uid=HitachiXHDS72 1010CLA332_JP2940HD0S1YMC0S1YMCX&q={searchTerms}
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.nationzoom.com/web/?type=ds&ts=1386550966&from=adks&uid=HitachiXHDS72 1010CLA332_JP2940HD0S1YMC0S1YMCX&q={searchTerms}
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - Reg Error: Key error. File not found
@Alternate Data Stream - 24 bytes -> C:\Windows:FF733822351C799B
@Alternate Data Stream - 173 bytes -> C:\ProgramData\Temp:F8B88761


:Services


:Reg


:Files
ipconfig /flushdns /c

:Commands
[purity]
[emptytemp]
[resethosts]
[emptyjava]
[emptyflash]
[createrestorepoint]
[reboot]


  • Klik daarna bovenaan op
    4f911cee9da59-OTL-4.png
  • Laat het programma ongestoord zijn werk doen.
  • OTL zal na de scan melden dat de PC opnieuw opgestart gaat worden. Sta dat dus toe.
  • Klik op OK
  • Na het opnieuw opstarten wordt enkel een nieuw log geopend.
  • Post via kopi?ren en plakken de inhoud van dat OTL-scanlog.
 
Re: Nation Zoom opent in IE en in Chrome Niet te verwijderen.

hierbij logje van otl --- N.B. browser start nog steeds op met NationZoom

All processes killed
========== OTL ==========
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Default_Page_URL| /E : value set successfully!
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Default_Search_URL| /E : value set successfully!
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Search Page| /E : value set successfully!
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
HKLM\SOFTWARE\Microsoft\Internet Explorer\Search\\CustomizeSearch| /E : value set successfully!
HKLM\SOFTWARE\Microsoft\Internet Explorer\Search\\SearchAssistant| /E : value set successfully!
64bit-Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@microsoft.com/GENUINE\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@microsoft.com/GENUINE\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{08B0E5C0-4FCB-11CF-AAA5-00401C608501}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{08B0E5C0-4FCB-11CF-AAA5-00401C608501}\ deleted successfully.
ADS C:\Windows:FF733822351C799B deleted successfully.
ADS C:\ProgramData\Temp:F8B88761 deleted successfully.
========== SERVICES/DRIVERS ==========
========== REGISTRY ==========
========== FILES ==========
< ipconfig /flushdns /c >
Windows IP-configuratie
De DNS-omzettingscache is leeggemaakt.
C:\Users\Chris\Desktop\cmd.bat deleted successfully.
C:\Users\Chris\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Chris
->Temp folder emptied: 2002 bytes
->Temporary Internet Files folder emptied: 3715390 bytes
->Java cache emptied: 3101209 bytes
->Google Chrome cache emptied: 14501611 bytes
->Flash cache emptied: 511 bytes

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes

User: Default User

User: Public
->Temp folder emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 1524900 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 20192 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 36640 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 67680 bytes
%systemroot%\sysnative\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment folder emptied: 666 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 22.00 mb

C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYJAVA]

User: All Users

User: Chris
->Java cache emptied: 0 bytes

User: Default

User: Default User

User: Public

Total Java Files Cleaned = 0.00 mb


[EMPTYFLASH]

User: All Users

User: Chris
->Flash cache emptied: 0 bytes

User: Default

User: Default User

User: Public

Total Flash Files Cleaned = 0.00 mb

System Restore Service not available.

OTL by OldTimer - Version 3.2.69.0 log created on 12102013_142150

Files\Folders moved on Reboot...
C:\Users\Chris\AppData\Local\Microsoft\Windows\Temporary Internet Files\counters.dat moved successfully.
File move failed. C:\Windows\temp\_avast_\Webshlock.txt scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\counters.dat scheduled to be moved on reboot.

PendingFileRenameOperations files...

Registry entries deleted on Reboot...
 
Re: Nation Zoom opent in IE en in Chrome Niet te verwijderen.

Welke browser betreft het?
 
Re: Nation Zoom opent in IE en in Chrome Niet te verwijderen.

Deze vraag doe ik in IE, na reboot startte ik dus IE weer op. Omdat ik dat van Nation zag ook even Chrome geprobeerd en hetzelfde.
Dus beiden.
 
Re: Nation Zoom opent in IE en in Chrome Niet te verwijderen.

Download zhpdiag.exe vanaf deze website: http://en.kioskea.net/download/download-23176-zhpdiag

iV2VCbEW-capture2-s-.png


ZHPDiag opstarten:
  • Windows 2000 en Windows XP: dubbelklik op zhpdiag.exe.
  • Windows Vista, Windows 7 en Windows 8: via rechtsklik op zhpdiag.exe en kies voor "Als Administrator uitvoeren".
ZHPDiag is opgestart:.
  • Klik meerdere keren op "Suivant" om het installatieproces te doorlopen.
  • Klik op "Installer" wanneer daar om gevraagd wordt en op "Terminer" wanneer de installatie voltooid is.
  • Er zijn nu 2 pictogrammen op je bureaublad verschenen: ZHPDiag en ZHPFix.
  • Dubbelklik nu op de snelkoppeling met de naam ZHPDiag
  • Het startvenster verschijnt, klik nu op "Configurer".
  • Klik rechts onderaan op het icoontje met het huisje "S?lectionner une langue" en kies "Anglais"(Engels).
  • Klik daarna links onderaan op het middelste icoontje(een vergrootglas en een + symbool) "Diagnostic options".
  • Er wordt nu een scan van je systeem gemaakt wacht geduldig tot deze voltooid is.
  • Na afloop staat er een tekstbestand met de naam ZHPDiag.txt op het bureaublad.
  • Post vervolgens de inhoud van dit log in je volgende bericht.
 
Re: Nation Zoom opent in IE en in Chrome Niet te verwijderen.

is nu ook in het NL - ging standaard zo opstarten

~ Verslag van ZHPDiag v2013.12.7.16 - Nicolas Coolman (7-12-2013)
~ Gelanceerd door Chris (10-12-2013 16:30:56)
~ Het adres van de website : http://nicolascoolman.webs.com
~ Gratis supportforum voor desinfectie : http://nicolascoolman.webs.com/apps/links/
~ Vertaald door de gebruiker
~ Staat van de versie :
~ Lijst wit : Ingeschakeld door het programma
~ Tot misbruik van bevoegdheden : OK
~ Gebruikersaccountbeheer (UAC) : Activate by user


---\\ Internet-browsers
MSIE: Internet Explorer v10.0.9200.16736 (Defaut)
GCIE: Google Chrome v31.0.1650.63
OBIE: Wacom WebTabletPlugin for Internet Explorer and Netscape v2.0.0.1

---\\ Windows productinformatie
~ Langage: N?erlandais
Windows 7 Home Premium Edition, 64-bit Service Pack 1 (Build 7601)
Windows Server License Manager Script : OK
Software Protection Service (Protection logicielle) : OK
Windows Automatic Updates : OK
Windows Activation Technologies : OK

---\\ Software om het systeem te beveiligen
avast! Free Antivirus v9.0.2008
Malwarebytes Anti-Malware versie 1.75.0.1300
Windows Defender W7

---\\ Systeem optimalisatie software

---\\ Delen van software PeerToPeer
?Torrent v3.2.2.28500 =>P2P.?Torrent

---\\ Software die extra aandacht behoeft
Adobe Flash Player 11 ActiveX
Adobe Reader X
Java 7 Update 45

---\\ Informatie over het systeem
~ Processor: AMD64 Family 16 Model 10 Stepping 0, AuthenticAMD
~ Operating System: 64 Bits
Boot mode: Normal (Normal boot)
Total RAM: 6143 MB (61% free)
System Restore: Activ? (Enable)
System drive C: has 283 GB (60%) free of 466 GB

---\\ Verbinding met het systeem-modus
~ Computer Name: CHRIS-HP
~ User Name: Chris
~ All Users Names: Gast, Chris, Administrator,
~ Unselected Option: None
Logged in as Administrator

---\\ Omgevingsvariabelen
~ System Unit : C:\
~ %AppZHP% : C:\Users\Chris\AppData\Roaming\ZHP\
~ %AppData% : C:\Users\Chris\AppData\Roaming\
~ %Desktop% : C:\Users\Chris\Desktop\
~ %Favorites% : C:\Users\Chris\Favorites\
~ %LocalAppData% : C:\Users\Chris\AppData\Local\
~ %StartMenu% : C:\Users\Chris\AppData\Roaming\Microsoft\Windows\Start Menu\
~ %Windir% : C:\Windows\
~ %System% : C:\Windows\System32\

---\\ Overzicht vaste en verwisselbare stations
C: Hard drive, Flash drive, Thumb drive (Free 283 Go of 466 Go)
D: Hard drive, Flash drive, Thumb drive (Free 1 Go of 12 Go)
E: CD-ROM drive (Not Inserted)
G: Floppy drive, Flash card reader, USB Key (Not Inserted)
H: Floppy drive, Flash card reader, USB Key (Not Inserted)
I: Floppy drive, Flash card reader, USB Key (Not Inserted)
J: Floppy drive, Flash card reader, USB Key (Not Inserted)
K: Hard drive, Flash drive, Thumb drive (Free 706 Go of 1397 Go)
Z: Hard drive, Flash drive, Thumb drive (Free 204 Go of 454 Go)



---\\ Staat van het Windows Beveiligingscentrum
~ Security Center: 49 Legitimates Filtered in 00mn 00s



---\\ Zoeken naar bepaalde algemene bestanden
[MD5.332FEAB1435662FC6C672E25BEB37BE3] - (.Microsoft Corporation - Windows Verkenner.) (.25-2-2011 - 7:19:30.) -- C:\Windows\Explorer.exe [2871808]
[MD5.94355C28C1970635A31B3FE52EB7CEBA] - (.Microsoft Corporation - Windows Toepassing Opstarten.) (.14-7-2009 - 2:39:52.) -- C:\Windows\System32\Wininit.exe [129024]
[MD5.9706C99DAEBE3FEAC811B239617E98C4] - (.Microsoft Corporation - Internetuitbreidingen voor Win32.) (.12-10-2013 - 9:45:20.) -- C:\Windows\System32\wininet.dll [2241536]
[MD5.1151B1BAA6F350B1DB6598E0FEA7C457] - (.Microsoft Corporation - Toepassing Windows-aanmelden.) (.20-11-2010 - 14:25:30.) -- C:\Windows\System32\Winlogon.exe [390656]
[MD5.067FA52BFB59A56110A12312EF9AF243] - (.Microsoft Corporation - Software Licensing-bibliotheek.) (.20-11-2010 - 14:27:26.) -- C:\Windows\System32\sppcomapi.dll [232448]
[MD5.79059559E89D06E8B80CE2944BE20228] - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) (.28-9-2013 - 2:09:10.) -- C:\Windows\system32\Drivers\AFD.sys [497152]
[MD5.02062C0B390B7729EDC9E69C680A6F3C] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) (.14-7-2009 - 2:52:21.) -- C:\Windows\system32\Drivers\atapi.sys [24128]
[MD5.B8BD2BB284668C84865658C77574381A] - (.Microsoft Corporation - CD-ROM File System Driver.) (.14-7-2009 - 0:19:47.) -- C:\Windows\system32\Drivers\Cdfs.sys [92160]
[MD5.F036CE71586E93D94DAB220D7BDF4416] - (.Microsoft Corporation - SCSI CD-ROM Driver.) (.20-11-2010 - 10:19:21.) -- C:\Windows\system32\Drivers\Cdrom.sys [147456]
[MD5.9BB2EF44EAA163B29C4A4587887A0FE4] - (.Microsoft Corporation - DFS Namespace Client Driver.) (.20-11-2010 - 10:26:32.) -- C:\Windows\system32\Drivers\DfsC.sys [102400]
[MD5.97BFED39B6B79EB12CDDBFEED51F56BB] - (.Microsoft Corporation - High Definition Audio Bus Driver.) (.20-11-2010 - 11:43:43.) -- C:\Windows\system32\Drivers\HDAudBus.sys [122368]
[MD5.FA55C73D4AFFA7EE23AC4BE53B4592D3] - (.Microsoft Corporation - i8042-poortstuurprogramma.) (.14-7-2009 - 0:19:57.) -- C:\Windows\system32\Drivers\i8042prt.sys [105472]
[MD5.AF9B39A7E7B6CAA203B3862582E9F2D0] - (.Microsoft Corporation - IP Network Address Translator.) (.14-7-2009 - 1:10:03.) -- C:\Windows\system32\Drivers\IpNat.sys [116224]
[MD5.A5D9106A73DC88564C825D317CAC68AC] - (.Microsoft Corporation - Windows NT SMB Minirdr.) (.27-4-2011 - 3:40:40.) -- C:\Windows\system32\Drivers\MRxSmb.sys [158208]
[MD5.09594D1089C523423B32A4229263F068] - (.Microsoft Corporation - MBT Transport driver.) (.20-11-2010 - 10:23:20.) -- C:\Windows\system32\Drivers\netBT.sys [261632]
[MD5.B98F8C6E31CD07B2E6F71F7F648E38C0] - (.Microsoft Corporation - NT-bestandssysteemstuurprogramma.) (.12-4-2013 - 15:45:08.) -- C:\Windows\system32\Drivers\ntfs.sys [1656680]
[MD5.0086431C29C35BE1DBC43F52CC273887] - (.Microsoft Corporation - Stuurprogramma voor parallelle poort.) (.14-7-2009 - 1:00:41.) -- C:\Windows\system32\Drivers\Parport.sys [97280]
[MD5.471815800AE33E6F1C32FB1B97C490CA] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) (.20-11-2010 - 11:52:35.) -- C:\Windows\system32\Drivers\Rasl2tp.sys [129536]
[MD5.548260A7B8654E024DC30BF8A7C5BAA4] - (.Microsoft Corporation - SMB Transport driver.) (.14-7-2009 - 1:09:09.) -- C:\Windows\system32\Drivers\smb.sys [93184]
[MD5.DDAD5A7AB24D8B65F8D724F5C20FD806] - (.Microsoft Corporation - TDI Translation Driver.) (.20-11-2010 - 10:21:56.) -- C:\Windows\system32\Drivers\tdx.sys [119296]
[MD5.0D08D2F3B3FF84E433346669B5E0F639] - (.Microsoft Corporation - Volume Shadow Copy-stuurprogramma.) (.20-11-2010 - 14:34:02.) -- C:\Windows\system32\Drivers\volsnap.sys [295808]
~ Generic Processes: Scanned in 00mn 00s



---\\ Status van de verborgen bestanden (verborgen/totaal)
~ Mes images (My Pictures) : 1/6177
~ Mes musiques (My Musics) : 1/2
~ Mes Videos (My Videos) : 1/41
~ Mes Favoris (My Favorites) : 1/226
~ Mes Documents (My Documents) : 2/22228
~ Mon Bureau (My Desktop) : 1/1617
~ Menu demarrer (Programs) : 1/40
~ Hidden Files: Scanned in 00mn 03s



---\\ Gestarte processen
[MD5.D1D5DAB39DCB4BE0359943738D87409B] - (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe [532040] [PID.2636]
[MD5.554A50B5310E702029D3A675459108FF] - (.Hewlett-Packard - hpsysdrv.) -- C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe [62768] [PID.3936]
[MD5.1725061D691D00BA94EF1D7896F6D950] - (.Nokia - Nokia Suite.) -- C:\Program Files (x86)\Nokia\Nokia Suite\NokiaSuite.exe [1088424] [PID.3952]
[MD5.A42806221ACF327C48784B93EADA3E12] - (.Hewlett-Packard Company - No Comment.) -- C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe [2736128] [PID.3964]
[MD5.766E24A20116AFA41F380B57FFE7AF02] - (.Sony Corporation - Media Check Tool.) -- C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe [599328] [PID.3260]
[MD5.1F0A97900FC718CE617A722BEF8580CD] - (.AVAST Software - avast! Antivirus.) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe [3568312] [PID.3252]
[MD5.D7D5768B8A697FCBAEE2CFE137070F02] - (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\IEXPLORE.exe [770736] [PID.3280]
[MD5.C0F5728CCD08AB01D66646FA320A03F2] - (.Nicolas Coolman - ZHPDiag.) -- C:\Program Files (x86)\ZHPDiag\ZHPDiag.exe [8286208] [PID.5528]
[MD5.4D41D30E2FAB3307967C7A0B045DC874] - (.AVAST Software - avast! Service.) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344] [PID.1332]
[MD5.ADC420616C501B45D26C0FD3EF1E54E4] - (.ArcSoft Inc. - ArcSoft Connect Service.) -- C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152] [PID.2004]
[MD5.ADDA5E1951B90D3D23C56D3CF0622ADC] - (.Adobe Systems Incorporated - Adobe Acrobat Update Service.) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [65640] [PID.2024]
[MD5.CA793DCC1D5F619021EF1D37CC7A831E] - (.EasyBits Software AS - Shared EasyBits services for Windows.) -- C:\Windows\SysWOW64\ezSharedSvcHost.exe [514232] [PID.1168]
[MD5.CFD54D70F76E84E1E737AE1140FBC5C0] - (.Garmin Ltd or its subsidiaries - Garmin Core Update Service.) -- C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe [220504] [PID.1108]
[MD5.EE963D96BFD97E54BA6CE6D2AC58DE35] - (.Hewlett-Packard Company - LightScribe Service.) -- C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe [73728] [PID.2432]
[MD5.65085456FD9A74D7F1A999520C299ECB] - (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376] [PID.2572]
[MD5.E0D7732F2D2E24B2DB3F67B6750295B8] - (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512] [PID.2596]
[MD5.627FA58ADC043704F9D14CA44340956F] - (.Sony Corporation - Device Information Provider.) -- C:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe [360224] [PID.2648]
[MD5.543A4EF0923BF70D126625B034EF25AF] - (.Protexis Inc. - PsiService PsiService.) -- C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe [189728] [PID.2704]
[MD5.F02A533F517EB38333CB12A9E8963773] - (.Google Inc. - Google Installer.) -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [136176] [PID.3752]
[MD5.465680BDE344CE4FF6646626AA3A9125] - (.Google Inc. - Google Crash Handler.) -- C:\Program Files (x86)\Google\Update\1.3.22.3\GoogleCrashHandler.exe [223112] [PID.124]
~ Processes Running: Scanned in 00mn 00s



---\\ Google Chrome, start, zoeken, extensies (G0, G1, G2)
C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Default\Preferences
G0 - GCSP: Preference [User Data\Default] http://www.zeelandnet.nl
~ Google Browser: 13 Legitimates Filtered in 00mn 01s



---\\ Mozilla Firefox, Plugins, start, zoeken, extensies (P2, M0, M1, M2, M3)
C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\prefs.js (.not file.)
~ Firefox Browser: 3 Legitimates Filtered in 00mn 00s



---\\ Internet Explorer, start, zoeken, URLSearchHook, Phishing (R0, R1, R3, R4)
R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.zeelandnet.nl
~ IE Browser: 17 Legitimates Filtered in 00mn 00s



---\\ Internet Explorer, proxybeheer (R5)
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = no key
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyHttp1.1 = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll
~ Proxy management: Scanned in 00mn 00s



---\\ Analyse van lijnen F0, F1, F2, F3 - IniFiles, Autoloading programma's
F2 - REG:system.ini: USERINIT=C:\Windows\system32\userinit.exe,
F2 - REG:system.ini: Shell=C:\Windows\explorer.exe
F2 - REG:system.ini: VMApplet=C:\Windows\System32\SystemPropertiesPerformance.exe
~ Keys: Scanned in 00mn 00s



---\\ Hosts-bestand omleiding (O1)
~ Le fichier hosts est sain (The hosts file is clean).
~ Hosts File: Scanned in 00mn 00s
~ Nombre de lignes (Lines number): 2



---\\ Internet Explorer werkbalken (O3)
O3 - Toolbar: (no name) [64Bits] - [HKLM]{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} Orphan sleutel
~ Toolbar: Scanned in 00mn 00s



---\\ Andere Verwijzigingen gebruikers (O4)
O4 - GS\Desktop [Public]: 1-Click-Optimizer.lnk . (.Ashampoo GmbH & Co. KG - Ashampoo WinOptimizer Free.) -- C:\Program Files (x86)\Ashampoo\Ashampoo WinOptimizer Free\WOFree.exe
O4 - GS\Desktop [Public]: Ashampoo WinOptimizer Free.lnk . (.Ashampoo GmbH & Co. KG - Ashampoo WinOptimizer Free.) -- C:\Program Files (x86)\Ashampoo\Ashampoo WinOptimizer Free\WOFree.exe
O4 - GS\Desktop [Public]: FaceFilter v3.02 Standard.lnk . (.Reallusion Inc. - FaceFilter3 AP.) -- C:\Program Files (x86)\Reallusion\FaceFilter3\FFApp.exe
O4 - GS\Desktop [Public]: Namo WebEditor 8.lnk . (.Namo Interactive, Inc. - Namo WebEditor 8.) -- C:\Program Files (x86)\Namo\WebEditor 8\bin\WebEditor.exe
O4 - GS\Program [Public]: eBay.nl.lnk . (...) -- C:\Program Files (x86)\Hewlett-Packard\Shared\WizLink.exe =>Toolbar.eBay
O4 - GS\Program [Public]: Inkscape.lnk . (.inkscape.org - Inkscape.) -- C:\Program Files (x86)\Inkscape\inkscape.exe
O4 - GS\Program [Public]: Shortcut to IPictDB Plugin.lnk . (...) -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IPictDB Plugin
O4 - GS\QuickLaunch [Chris]: Artensoft Photo Collage Maker.lnk . (.Artensoft Company - Artensoft Photo Collage Maker 1.2.) -- C:\Program Files\Artensoft Photo Collage Maker\Artensoft Photo Collage Maker.exe
O4 - GS\QuickLaunch [Chris]: Colasoft Capsa 7 Free.lnk . (.Colasoft - Colasoft Capsa 7.) -- C:\Program Files (x86)\Colasoft Capsa 7 Free Edition\capsa.exe
O4 - GS\QuickLaunch [Chris]: GrabIt.lnk . (...) -- C:\Program Files (x86)\GrabIt\GrabIt.exe
O4 - GS\QuickLaunch [Chris]: Inkscape.lnk . (.inkscape.org - Inkscape.) -- C:\Program Files (x86)\Inkscape\inkscape.exe
O4 - GS\QuickLaunch [Chris]: jZip.lnk . (...) -- C:\Program Files (x86)\jZip\jZip.exe (.not file.)
O4 - GS\QuickLaunch [Chris]: Launch Internet Explorer Browser.lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe http://www.nationzoom.com =>Hijacker.NationZoom
O4 - GS\QuickLaunch [Chris]: SignCut.lnk . (...) -- C:\Program Files (x86)\SignCut\SignCut.exe
O4 - GS\QuickLaunch [Chris]: ?Torrent.lnk . (.BitTorrent, Inc. - ?Torrent.) -- C:\Program Files (x86)\uTorrent\uTorrent.exe =>P2P.BitTorrent
O4 - GS\TaskBar [Chris]: DATA (Z).lnk . (.Microsoft Corporation - Windows Verkenner.) -- C:\Windows\explorer.exe
O4 - GS\TaskBar [Chris]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe http://www.nationzoom.com =>Hijacker.NationZoom
O4 - GS\TaskBar [Chris]: WinHTTrack Website Copier.lnk . (.HTTrack - WinHTTrack Website Copier, Copy Websites to.) -- C:\Program Files (x86)\WinHTTrack\WinHTTrack.exe
O4 - GS\Program [Chris]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe http://www.nationzoom.com =>Hijacker.NationZoom
O4 - GS\SystemTools [Chris]: Internet Explorer (No Add-ons).lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe http://www.nationzoom.com =>Hijacker.NationZoom
O4 - GS\SendTo [Chris]: Bestandsoverdracht via Bluetooth.LNK . (.Microsoft Corporation - No Comment.) -- C:\Windows\System32\fsquirt.exe
O4 - GS\SendTo [Chris]: SignCut.lnk . (...) -- C:\Program Files (x86)\SignCut\SignCut.exe
~ Global Startup: 87 Legitimates Filtered in 00mn 01s



---\\ Toepassingen gestart door register &amp; bestand (O4)
O4 - GS\Startup [Chris]: Adobe Gamma.lnk . (.Adobe Systems, Inc. - Adobe Gamma Loader.) -- C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - HKLM\..\Run: [hpsysdrv] . (.Hewlett-Packard - hpsysdrv.) -- c:\program files (x86)\hewlett-packard\HP odometer\hpsysdrv.exe =>.Hewlett-Packard Co
O4 - HKLM\..\RunOnce: [NCPluginUpdater] . (.Hewlett-Packard - NCPluginUpdater.) -- C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\NCPluginUpdater.exe
O4 - HKCU\..\Run: [NokiaSuite.exe] . (.Nokia - Nokia Suite.) -- C:\Program Files (x86)\Nokia\Nokia Suite\NokiaSuite.exe
O4 - HKCU\..\Run: [LightScribe Control Panel] . (.Hewlett-Packard Company - No Comment.) -- C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe
O4 - HKCU\..\Run: [GarminExpressTrayApp] . (.Garmin Ltd or its subsidiaries - Express Tray.) -- C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe
O4 - HKCU\..\Run: [Sidebar] . (.Microsoft Corporation - Windows-bureaubladgadgets.) -- C:\Program Files\Windows Sidebar\sidebar.exe
O4 - HKLM\..\Wow6432Node\Run: [MyPoi Monitor] . (.ANWB - ANWB Monitor.) -- C:\Program Files (x86)\Common Files\MyPoiWorld Shared\MyPoiMonitor\MyPoiMonitor.exe
O4 - HKLM\..\Wow6432Node\Run: [PMBVolumeWatcher] . (.Sony Corporation - Media Check Tool.) -- C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe
O4 - HKLM\..\Wow6432Node\Run: [SMKRun] . (.Wacom Co., Ltd - ScreenMark MFC Application.) -- C:\Program Files (x86)\JustWrite Office\ScreenMark.exe
O4 - HKLM\..\Wow6432Node\Run: [APSDaemon] . (.Apple Inc. - Apple Push.) -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe
O4 - HKLM\..\Wow6432Node\Run: [StartCCC] . (.Advanced Micro Devices, Inc. - Catalyst? Control Center Launcher.) -- C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe =>.Advanced Micro Devices, Inc
O4 - HKLM\..\Wow6432Node\Run: [Adobe ARM] . (.Adobe Systems Incorporated - Adobe Reader and Acrobat Manager.) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe =>.Adobe Systems Incorporated
O4 - HKLM\..\Wow6432Node\Run: [AvastUI.exe] . (.AVAST Software - avast! Antivirus.) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe
O4 - HKLM\..\Wow6432Node\Run: [20131121] . (.AVAST Software - avast! Emergency Update.) -- C:\Program Files\AVAST Software\Avast\setup\emupdate\991770ab-afc8-4779-a147-d7f72b2803a9.exe
O4 - HKLM\..\Wow6432Node\Run: [mobilegeni daemon] C:\Program Files (x86)\Mobogenie\DaemonProcess.exe (.not file.)
O4 - HKUS\S-1-5-21-54043301-2395897540-3358933016-1000\..\Run: [NokiaSuite.exe] . (.Nokia - Nokia Suite.) -- C:\Program Files (x86)\Nokia\Nokia Suite\NokiaSuite.exe
O4 - HKUS\S-1-5-21-54043301-2395897540-3358933016-1000\..\Run: [LightScribe Control Panel] . (.Hewlett-Packard Company - No Comment.) -- C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe
O4 - HKUS\S-1-5-21-54043301-2395897540-3358933016-1000\..\Run: [GarminExpressTrayApp] . (.Garmin Ltd or its subsidiaries - Express Tray.) -- C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe
O4 - HKUS\S-1-5-21-54043301-2395897540-3358933016-1000\..\Run: [Sidebar] . (.Microsoft Corporation - Windows-bureaubladgadgets.) -- C:\Program Files\Windows Sidebar\sidebar.exe
~ Application: Scanned in 00mn 00s



---\\ Knoppen op de werkbalk "belangrijkste instrumenten" Internet Explorer (O9)
O9 - Extra button: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll,-102 [64Bits] - {25510184-5A38-4A99-B273-DCA8EEF6CD08} . (...) -- C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\Resources\Icons\HP.ico
~ IE Extra Buttons: Scanned in 00mn 00s



---\\ ActiveX-objecten (Downloaded Program Files) (O16)
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} ((no name)) - http://h20614.www2.hp.com/ediags/gmd/Install/Cab/hpdetect121.cab
O16 - DPF: {AA570693-00E2-4907-B6F1-60A1199B030C} ((no name)) - https://juniper.net/dana-cached/sc/JuniperSetupClient64.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} ((no name)) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
~ Objets ActiveX: Scanned in 00mn 00s



---\\ Domeinadres van de DNS (O17) wijzigen
O17 - HKLM\System\CCS\Services\Tcpip\..\{F2A0558D-B9C8-4C73-8A0E-4076CC58FAF6}: DhcpNameServer = 62.238.255.69 212.115.192.100
O17 - HKLM\System\CS1\Services\Tcpip\..\{F2A0558D-B9C8-4C73-8A0E-4076CC58FAF6}: DhcpNameServer = 62.238.255.69 212.115.192.100
O17 - HKLM\System\CS2\Services\Tcpip\..\{F2A0558D-B9C8-4C73-8A0E-4076CC58FAF6}: DhcpNameServer = 62.238.255.69 212.115.192.100
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 62.238.255.69 212.115.192.100
~ Domain: Scanned in 00mn 00s



---\\ Aanvullend Protocol (O18)
O18 - Handler: wlpg [64Bits] - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} . (...) --
O18 - Filter: application/x-msdownload [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll =>.Microsoft Corporation
~ Protocole Additionnel: Scanned in 00mn 00s



---\\ Lijst van niet-Microsoft NT services die niet uitgeschakeld zijn (O23)
O23 - Service: LiveUpdate (LiveUpdateSvc) . (...) - C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe (.not file.)
O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) . (.TuneUp Software - TuneUp Utilities Service.) - C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesService64.exe
~ Services: 15 Legitimates Filtered in 00mn 04s



---\\ Geeft een opsomming van de BootExecute (BEX) gegevens (O34)
O34 - HKLM BootExecute: (autocheck autochk /r \??\K:) - File not found
O34 - HKLM BootExecute: (autocheck autochk /p \??\K:) - File not found
O34 - HKLM BootExecute: (autocheck autochk /r \??\K:) - File not found
O34 - HKLM BootExecute: (autocheck autochk /r \??\J:) - File not found
~ BEX: 5 Legitimates Filtered in 00mn 00s



---\\ Taken die zijn gepland in de automatische modus (O39)
[MD5.00000000000000000000000000000000] [APT] [SuperEasyDriverUpdaterRunAtStartup] (...) -- C:\Program Files (x86)\SuperEasy Software\Driver Updater\supereasydu.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{031D31DF-D4E5-4704-A021-FB1CD7E01B5D}] (...) -- C:\Users\Chris\Downloads\GENKWA\GENKWA.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{0584FB7E-CAEA-4EC4-9159-406AC82E2DC2}] (...) -- K:\AllNewDriversMei2010\Corel PaintShopPro\PlaatjesPenselen\06_04_Tubes.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{07A2BA85-8125-4391-82FC-0DA75453C914}] (...) -- C:\Users\Chris\Downloads\SmartST.Navman.iCN.530\Expand.exe (.not file.) [0]
[MD5.7514F93A09ADF6A0AE0198360EA2528A] [APT] [{0FEFEE64-8E8B-4609-89F1-30F155CB36DF}] (...) -- C:\Program Files (x86)\SignCut\SignCut.exe [3766272]
[MD5.B23AB77A960F56232DDAFFED743058C7] [APT] [{142B3A70-8B6A-4C78-86CF-5921EFDA2D3E}] (.Stichting Aldfaer, Kollum.) -- C:\Aldfaer\Aldfaer.exe [7425024]
[MD5.00000000000000000000000000000000] [APT] [{1F1E8BCD-E82C-4684-BDF6-B998C821FF77}] (...) -- K:\Navman Connection pack\Install.exe (.not file.) [0]
[MD5.2417CECFD619A7007A638DC665FCC4FE] [APT] [{2161351E-6AE3-4970-ADA6-053C2941F358}] (.Acro Software Inc..) -- Z:\COUGAR\BlackCat PDF Writer Folder\BlackCat PDF Writer Folder\Setup.exe [53248]
[MD5.00000000000000000000000000000000] [APT] [{29DA36CE-FDE7-433E-B091-FC61333B92FA}] (...) -- K:\AllNewDriversMei2010\Corel PaintShopPro\Fotolijsten\12_04_frames.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{46FB4E1A-1BC4-4F3C-8ED5-7EC1D6963E42}] (...) -- E:\Kluwer\SETUP.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{49888ECB-B10F-466B-8909-E092867451AB}] (...) -- K:\Justwrite Office 4.4\install.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{86A37646-0036-4F72-B971-C5517EA2F7EB}] (...) -- K:\Navman Connection pack\Install.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{86EDB9E4-0CF8-40C8-9D62-593FAEA56B57}] (...) -- K:\AllNewDriversMei2010\Corel PaintShopPro\Fotolijsten\05_21_framesPSPA.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{96598113-3B4A-472F-85D7-1D09E531475B}] (...) -- K:\AllNewDriversMei2010\Corel PaintShopPro\PlaatjesPenselen\10_04_tubes.exe (.not file.) [0]
[MD5.7514F93A09ADF6A0AE0198360EA2528A] [APT] [{96B82CC2-35B0-4EAE-B27D-330570729984}] (...) -- C:\Program Files (x86)\SignCut\SignCut.exe [3766272]
[MD5.00000000000000000000000000000000] [APT] [{96DDDF67-B255-4271-BCF8-5CBE1A8BAF17}] (...) -- K:\AllNewDriversMei2010\Corel PaintShopPro\Fotolijsten\08_04_Frames.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{9A3EB825-B8DC-45BA-A199-D7687ED3279A}] (...) -- E:\Kluwer\SETUP.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{9F585B07-9F34-4DFD-9790-C5C9848FCD2E}] (...) -- E:\Kluwer\SETUP.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{9FA40B7F-CE87-4754-81F6-98EA68F16813}] (...) -- K:\AllNewDriversMei2010\Corel PaintShopPro\Fotolijsten\2004_holiday_frames.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{A0904247-8A85-43D5-A92A-2E80692EC60A}] (...) -- E:\Kluwer\SETUP.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{A7E57CEE-CC38-411E-8040-A326153E1A87}] (...) -- K:\Navman Connection pack\Install.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{A9DBBE24-3967-4AD6-99AC-C1675251E606}] (...) -- K:\AllNewDriversMei2010\Corel PaintShopPro\Fotolijsten\1_04_frames.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{ADE04678-3988-4CEF-AE31-8A5D6D05FF9D}] (...) -- K:\AllNewDriversMei2010\Corel PaintShopPro\Fotolijsten\12_03_frames.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{B0236764-C746-4B19-A111-94556756739E}] (...) -- C:\Program Files (x86)\Navman\F Series Connection Pack\POIEditor.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{C0D2A2C2-1194-45EB-BE08-F3E8806CE09D}] (...) -- E:\Kluwer\SETUP.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{C12AB581-F257-4D00-A101-CA114CB754E3}] (...) -- K:\AllNewDriversMei2010\Corel PaintShopPro\PlaatjesPenselen\11_04_Tubes.exe (.not file.) [0]
[MD5.380E1329E9E6DFC161DC2ADA5EC7F11E] [APT] [{C1403E9A-8E89-4DC3-B0C0-385B111D5352}] (.inkscape.org.) -- C:\Program Files (x86)\Inkscape\inkscape.exe [14647296]
[MD5.00000000000000000000000000000000] [APT] [{C342ABF1-5FDD-4F7F-84AD-31E3A8343651}] (...) -- E:\Kluwer\SETUP.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{C48F7A7D-CC0F-4D7F-972F-1CB317D01415}] (...) -- C:\Users\Chris\Downloads\GENKWA\GENKWA.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{C6EA55BC-E06B-4E47-B32B-C1210BA9C0AD}] (...) -- K:\AllNewDriversMei2010\Corel PaintShopPro\Fotolijsten\09_04_Frames.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{C7BA3C3F-D5CE-42A9-9D6A-FDF9CBA50F6C}] (...) -- K:\AllNewDriversMei2010\Corel PaintShopPro\Fotolijsten\10_04_frames.exe (.not file.) [0]
[MD5.380E1329E9E6DFC161DC2ADA5EC7F11E] [APT] [{E8B0E806-1687-4888-B6FF-81187F42B17C}] (.inkscape.org.) -- C:\Program Files (x86)\Inkscape\inkscape.exe [14647296]
[MD5.00000000000000000000000000000000] [APT] [{F5412E89-AF46-42D3-8FBC-F1428847BDC8}] (...) -- K:\Navman Connection pack\Expand.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{F5888516-FE7A-4B5F-9968-1E86567DF290}] (...) -- E:\Kluwer\SETUP.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{FDCCCC37-8624-48A1-82A5-CB86463F4ACA}] (...) -- C:\Program Files (x86)\Navman\F Series Connection Pack\POIEditor.exe (.not file.) [0]
[MD5.1B3943485328C35F6F186E13CA373FB1] [APT] [{FF815ADB-AC6C-4A7A-9CF0-C1C461BF24E0}] (...) -- C:\Program Files (x86)\COMMON~1\MICROS~1\Datamap\DATAINST.exe [292864]
~ Scheduled Task: 73 Legitimates Filtered in 00mn 04s



---\\ Piloot aan het begin van het systeem (O41)
O41 - Driver: (CSN5PDTS82) . (. - .) - C:\Windows\System32\Drivers\CSN5PDTS82.sys (.not file.)
O41 - Driver: (CSN5PDTS82x64) . (.Colasoft Co., Ltd. - Colasoft NDIS 5.0 Protocol Driver (x64).) - C:\Windows\System32\Drivers\CSN5PDTS82x64.sys
~ Drivers: 81 Legitimates Filtered in 00mn 00s



---\\ Ge?nstalleerde software (O42)
O42 - Logiciel: ANWB-reiswijzer - (.ANWB B.V./MyPoi World B.V..) [HKLM][64Bits] -- {8EF7A04E-C5A6-459E-8106-362AEE79A5F6}
O42 - Logiciel: Aldfaer - (...) [HKCU][64Bits] -- Aldfaer
O42 - Logiciel: Face Off Max - (...) [HKLM][64Bits] -- FaceOffMax
O42 - Logiciel: GPicSync 1.30 - (.GPicSync.) [HKLM][64Bits] -- GPicSync_is1
O42 - Logiciel: MyPoi Manager - (.MyPoi World.) [HKLM][64Bits] -- {0C6DB6B9-2D17-4AA5-A207-42D28BF9F434}
O42 - Logiciel: SignCut (remove only) - (...) [HKLM][64Bits] -- SignCut
O42 - Logiciel: XML Copy Editor version 1.2.0.9 - (.Zane U. Ji.) [HKLM][64Bits] -- XML Copy Editor_is1
~ Logic: 41 Legitimates Filtered in 00mn 01s



---\\ HKCU & HKLM Software Keys
[HKCU\Software\AllMyBooks]
[HKCU\Software\CraftEdge]
[HKCU\Software\Google Map Buddy]
[HKCU\Software\Pretek]
[HKCU\Software\SignCutPreview]
[HKCU\Software\SignCut]
[HKCU\Software\SoftGold]
[HKCU\Software\Stichting Aldfaer]
[HKCU\Software\TurboCCC]
[HKCU\Software\Whisqu Graphic AB]
[HKCU\Software\artensoft]
[HKCU\Software\iPictDB]
[HKCU\Software\wCEdge]
[HKCU\Software\xaCE2]
[HKLM\Software\Wow6432Node\Whisqu Graphic AB]
[HKLM\Software\Wow6432Node\supWPM] =>PUP.WpManager
~ Key Software: 543 Legitimates Filtered in 00mn 01s



---\\ 'Inhoud van mappen programma's, ProgramFiles, ProgramData, AppData (O43)
O43 - CFD: 15-6-2012 - 9:05:49 - [7,186] ----D C:\Program Files (x86)\ANWB-reiswijzer
O43 - CFD: 3-11-2013 - 12:43:19 - [8,117] ----D C:\Program Files (x86)\Belastingdienst
O43 - CFD: 4-8-2013 - 10:23:56 - [5,666] ----D C:\Program Files (x86)\Exif Pilot
O43 - CFD: 23-9-2012 - 13:33:14 - [30,713] ----D C:\Program Files (x86)\GPicSync
O43 - CFD: 13-10-2012 - 9:34:36 - [0,388] ----D C:\Program Files (x86)\iPictDB
O43 - CFD: 5-11-2013 - 21:08:00 - [8,888] ----D C:\Program Files (x86)\JustWrite Office
O43 - CFD: 23-2-2012 - 20:44:39 - [9,706] ----D C:\Program Files (x86)\MyPoi Manager
O43 - CFD: 1-6-2013 - 19:18:10 - [78,170] ----D C:\Program Files (x86)\SignCut
O43 - CFD: 23-2-2012 - 21:23:06 - [1,875] ----D C:\Program Files (x86)\TurboCCC
O43 - CFD: 1-10-2012 - 10:09:35 - [0] ----D C:\Program Files (x86)\TWSteampunk
O43 - CFD: 4-8-2013 - 10:24:39 - [5,466] ----D C:\Program Files (x86)\Wire Pilot
O43 - CFD: 1-12-2012 - 10:24:53 - [37,879] ----D C:\Program Files (x86)\XML Copy Editor
O43 - CFD: 23-2-2013 - 10:33:54 - [0] ----D C:\ProgramData\AllMyBooks
O43 - CFD: 12-5-2013 - 12:19:52 - [0] ----D C:\ProgramData\CraftEdge
O43 - CFD: 4-12-2013 - 8:42:02 - [0] ----D C:\ProgramData\ProductData
O43 - CFD: 9-12-2013 - 2:06:53 - [0] ----D C:\ProgramData\WPM =>PUP.WpManager
O43 - CFD: 3-11-2013 - 11:08:28 - [0] ----D C:\ProgramData\{3C5CBD7B-3D1D-411E-96C2-513FFCA84D2D}
O43 - CFD: 18-1-2013 - 17:02:54 - [0] --H-D C:\ProgramData\{8265C354-3D13-4FE5-95C7-65F277FF3041}
O43 - CFD: 18-1-2013 - 17:02:54 - [0] --H-D C:\ProgramData\{9DE75BC9-6CF5-4972-8A4E-86BAAD477DC6}
O43 - CFD: 26-12-2012 - 13:55:13 - [0] -SH-D C:\ProgramData\{C4ABDBC8-1C81-42C9-BFFC-4A68511E9E4F}
O43 - CFD: 6-9-2012 - 18:37:26 - [0] ----D C:\Users\Chris\AppData\Roaming\Apygna
O43 - CFD: 27-3-2013 - 20:35:21 - [0] ----D C:\Users\Chris\AppData\Roaming\Belastingdienst
O43 - CFD: 23-12-2012 - 15:51:40 - [171,823] ----D C:\Users\Chris\AppData\Roaming\Bergboek
O43 - CFD: 5-1-2013 - 9:02:16 - [0] ----D C:\Users\Chris\AppData\Roaming\com.docrafts.digital
O43 - CFD: 28-4-2013 - 8:39:17 - [0,023] ----D C:\Users\Chris\AppData\Roaming\Easypano Panoweaver
O43 - CFD: 31-7-2012 - 3:02:10 - [0,002] ----D C:\Users\Chris\AppData\Roaming\Genealogica Grafica
O43 - CFD: 5-11-2013 - 21:08:00 - [0,001] ----D C:\Users\Chris\AppData\Roaming\JustWrite Office
O43 - CFD: 5-9-2012 - 21:33:13 - [0] ----D C:\Users\Chris\AppData\Roaming\Lumaur
O43 - CFD: 8-5-2013 - 20:59:53 - [4,839] ----D C:\Users\Chris\AppData\Roaming\SignCut
O43 - CFD: 4-8-2013 - 10:24:52 - [0] ----D C:\Users\Chris\AppData\Roaming\WirePilot
O43 - CFD: 24-9-2012 - 11:19:17 - [0] ----D C:\Users\Chris\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\POI format conversion
~ 1 Dossiers CLSID vides (CLSID Empty Folders)
~ Program Folder: 348 Legitimates Filtered in 00mn 05s



---\\ Meest recente bestanden gewijzigd of gemaakt op Windows en System32 (O44)
O44 - LFC:[MD5.D41D8CD98F00B204E9800998ECF8427E] - 10-12-2013 - 1:29:23 ---A- . (...) -- C:\autoexec.bat [0]
~ Files: 16 Legitimates Filtered in 00mn 06s



---\\ Laatste bestanden die zijn gemaakt in Windows Prefetcher (O45)
O45 - LFCP:[MD5.6F183F01168EF5694243FCBD3EE7D4EF] - 10-12-2013 - 8:24:48 ---A- - C:\Windows\Prefetch\INSTUP.EXE-7E543EAF.pf
~ Prefetcher: 101 Legitimates Filtered in 00mn 00s



---\\ Opsomming van het register sleutels PoliciesSystem (MWPS) (O55)
O55 - MWPS:[HKLM\...\Policies\System] - "EnableUIADesktopToggle"=0
O55 - MWPS:[HKLM\...\Policies\System] - "FilterAdministratorToken"=0
~ MWPS: 21 Legitimates Filtered in 00mn 00s



---\\ Opsomming van de registersleutel PoliciesExplorer (C?KVI) (O56)
O56 - MWPE:[HKLM\...\policies\Explorer] - "NoResolveTrack"=1
~ MWPE Keys: 3 Legitimates Filtered in 00mn 00s



---\\ Overzicht van de drivers (SDL) (O58)
O58 - SDL:[MD5.C04F7B373881009D7994D9BF55D24AB4] - 19-11-2013 - 20:33:16 ---A- . (...) -- C:\Windows\System32\Drivers\aswRvrt.sys [65776]
O58 - SDL:[MD5.59787B95DD9CA44CB139D96863438587] - 19-11-2013 - 20:33:16 ---A- . (...) -- C:\Windows\System32\Drivers\aswVmm.sys [205320]
O58 - SDL:[MD5.0262A199D98C2405C90F3188C5A54C6A] - 9-10-2006 - 0:29:22 ---A- . (...) -- C:\Windows\System32\Drivers\BTNetFilter.sys [32832]
O58 - SDL:[MD5.B6F4A83911336E84BEAD8F8905285FAB] - 11-6-2007 - 23:00:00 ---A- . (.www.winchiphead.com - Win98 WDM for CH341 serial, by W.ch.) -- C:\Windows\System32\Drivers\CH341S98.SYS [19680]
O58 - SDL:[MD5.4798C1AD22BAF6FF25451E2194E034D1] - 4-11-2011 - 23:00:00 ---A- . (.www.winchiphead.com - WDM for CH341 serial, by W.ch.) -- C:\Windows\System32\Drivers\CH341SER.SYS [39696]
O58 - SDL:[MD5.2285B31039611D509F6120D691CA661F] - 29-5-2012 - 15:53:30 ---A- . (.Windows (R) Codename Longhorn DDK provider - hpvhd 64bit support driver.) -- C:\Windows\System32\Drivers\cpqdfw.sys [27456]
O58 - SDL:[MD5.E7956DB62954ECA3FFD2AC88F6B83BB4] - 24-10-2012 - 13:49:46 ---A- . (.Colasoft Co., Ltd. - Colasoft NDIS 5.0 Protocol Driver (x64).) -- C:\Windows\System32\Drivers\CSN5PDTS82x64.sys [34840]
O58 - SDL:[MD5.0E5DA5369A0FCAEA12456DD852545184] - 14-7-2009 - 2:47:48 ---A- . (.Emulex - Storport Miniport Driver for LightPulse HBAs.) -- C:\Windows\System32\Drivers\elxstor.sys [530496]
O58 - SDL:[MD5.F2523EF6460FC42405B12248338AB2F0] - 10-6-2009 - 21:31:59 ---A- . (.Hauppauge Computer Works, Inc. - Hauppauge WinTV 885 Consumer IR Driver for eHome.) -- C:\Windows\System32\Drivers\hcw85cir.sys [31232]
O58 - SDL:[MD5.5F79934084DF6DC0635578864376CE54] - 21-2-2008 - 9:10:36 ---A- . (.Omnivision Technologies, Inc. - Stream Class Mini Driver.) -- C:\Windows\System32\Drivers\ov550ivx.sys [196992]
O58 - SDL:[MD5.F3817967ED533D08327DC73BC4D5542A] - 14-7-2009 - 2:45:55 ---A- . (.Promise Technology - Promise SuperTrak EX Series Driver for Windows.) -- C:\Windows\System32\Drivers\stexstor.sys [24656]
O58 - SDL:[MD5.0262A199D98C2405C90F3188C5A54C6A] - 9-10-2006 - 0:29:22 ---A- . (...) -- C:\Windows\SysWOW64\drivers\BTNetFilter.sys [32832]
O58 - SDL:[MD5.8DB0DBDEC7880E81B73B8E7E8E9A666A] - 28-4-2003 - 10:31:18 ---A- . (.OEM - OX16C95x Serial Device Driver.) -- C:\Windows\SysWOW64\drivers\OXSER.SYS [51169]
~ Drivers: 21 Legitimates Filtered in 00mn 05s



---\\ Meest recente bestanden gewijzigd of gemaakt (gebruiker) (O61)
O61 - LFC: 10-12-2013 - 16:33:18 ---A- . (...) -- C:\Users\Chris\AppData\Local\GDIPFONTCACHEV1.DAT [143128]
O61 - LFC: 10-12-2013 - 16:33:18 ---A- . (...) -- C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Certificate Revocation Lists [265801]
O61 - LFC: 10-12-2013 - 16:33:18 ---A- . (...) -- C:\Users\Chris\AppData\Local\Google\Chrome\User Data\chrome_shutdown_ms.txt [5]
O61 - LFC: 10-12-2013 - 16:33:21 ---A- . (...) -- C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Local State [49016]
O61 - LFC: 10-12-2013 - 16:34:21 ---A- . (...) -- C:\Users\Chris\AppData\Roaming\ZHP\HOSTS.txt [98] =>.Nicolas Coolman
O61 - LFC: 10-12-2013 - 16:34:21 ---A- . (...) -- C:\Users\Chris\AppData\Roaming\ZHP\Log.txt [18009] =>.Nicolas Coolman
O61 - LFC: 10-12-2013 - 16:34:21 ---A- . (...) -- C:\Users\Chris\AppData\Roaming\ZHP\TestsZHPDiag.txt [2859] =>.Nicolas Coolman
O61 - LFC: 7-12-2013 - 16:33:59 ---A- . (...) -- C:\Users\Chris\AppData\Roaming\ICAClient\APPSRV.INI [2027]
O61 - LFC: 7-12-2013 - 16:33:59 ---A- . (...) -- C:\Users\Chris\AppData\Roaming\ICAClient\UISTATE.INI [911]
O61 - LFC: 7-12-2013 - 16:36:14 ---A- . (...) -- C:\Users\Chris\Downloads\,DanaInfo=.asceCmszyiwo4L4-7P43+launch (5).ica [1417]
O61 - LFC: 7-12-2013 - 16:36:15 ---A- . (...) -- C:\Users\Chris\Downloads\carbon_SHDR.zip [1271788]
O61 - LFC: 7-12-2013 - 16:36:16 ---A- . (...) -- C:\Users\Chris\Downloads\Dome_01_set_01.hdr.zip [4616734]
O61 - LFC: 7-12-2013 - 16:36:16 ---A- . (...) -- C:\Users\Chris\Downloads\Dome_02_set_02_ret.hdr.zip [4046174]
O61 - LFC: 7-12-2013 - 16:36:16 ---A- . (...) -- C:\Users\Chris\Downloads\Dome_04_set_03.hdr.zip [4737279]
O61 - LFC: 7-12-2013 - 16:36:20 ---A- . (...) -- C:\Users\Chris\Downloads\sim.zip [1228666]
O61 - LFC: 7-12-2013 - 16:36:22 ---A- . (...) -- C:\Users\Chris\Downloads\xdraw.exe [285175]
O61 - LFC: 8-12-2013 - 16:34:09 --HA- . (...) -- C:\Users\Chris\AppData\Roaming\Microsoft\Sjablonen\~$Normal.dot [162]
O61 - LFC: 8-12-2013 - 16:36:17 ---A- . (...) -- C:\Users\Chris\Downloads\mps-letter-graphic-pack-snick-008.zip [1316514]
O61 - LFC: 9-12-2013 - 16:34:21 ---A- . (...) -- C:\Users\Chris\daemonprocess.txt [0]
O61 - LFC: 9-12-2013 - 16:34:22 ---A- . (...) -- C:\Users\Chris\Documents\auto fx software download and trial license number.pdf [49846]
O61 - LFC: 9-12-2013 - 16:34:22 ---A- . (...) -- C:\Users\Chris\Documents\autofx dream suite moasaic serial number.pdf [67187]
O61 - LFC: 9-12-2013 - 16:36:16 ---A- . (...) -- C:\Users\Chris\Downloads\DreamSuite_Series_Guide.pdf [14343225]
O61 - LFC: 9-12-2013 - 16:36:16 ---A- . (...) -- C:\Users\Chris\Downloads\DreamSuite_Series_Manual.pdf [14494121]
O61 - LFC: 9-12-2013 - 16:36:17 ---A- . (...) -- C:\Users\Chris\Downloads\Mosaic_Manual.pdf [722117]
~ 31 Fichiers temporaires (Temporary files)
~ Files: 1127 Legitimates Filtered in 04mn 57s



---\\ Lijst van cleaning tools (CLAB) (O63)
O63 - Logiciel: ZHPDiag 2013 - (.Nicolas Coolman.) [HKLM] -- ZHPDiag_is1 =>.Nicolas Coolman
O63 - Logiciel: OTL - (.OldTimer.)
O63 - Logiciel: RSIT - (.random/random.)
~ ADS: Scanned in 00mn 00s



---\\ Bestandsassociaties mogelijk aangepast (O67)
O67 - Shell Spawning: <.html> <ChromeHTML>[HKCU\..\open\Command] (.Not Key.)
~ FASS Keys: 11 Legitimates Filtered in 00mn 00s



---\\ Startmenu Internet (SMI) (O68)
O68 - StartMenuInternet: <Google Chrome> <Google Chrome>[HKLM\..\Shell\open\Command] (.Google Inc. - Google Chrome.) -- c:\program files (x86)\google\chrome\application\chrome.exe
O68 - StartMenuInternet: <IEXPLORE.EXE> <Internet Explorer>[HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- c:\program files\internet explorer\iexplore.exe
~ Keys: Scanned in 00mn 00s



---\\ Geeft een opsomming van bestanden Crack &amp; Keygen (KKF) (O82)
K:\all chris user\DownLoads\AutoFX.DreamSuite.Series.Bundle.v1.36\AutoFX.DreamSuite.Series.Bundle.v1.36\AutoFX.DreamSuite.Series.Bundle.v1.36\Keygen\keygen.exe
K:\ABR Installeren\cracked_brushes_178255.zip
~ Files: Scanned in 04mn 36s



---\\ Bepaalde zoekopdracht in de hoofdmap van het systeem (SPRF) (O84)
[MD5.248E7DA5F002B1AA5066AD4B398F9673] [SPRF][14-10-2012] (...) -- C:\ProgramData\KGyGaAvL.sys [952]
[MD5.BCB0728F4B117855765CE8FE883B5E9B] [SPRF][10-12-2013] (...) -- C:\Users\Chris\AppData\Local\Temp\NOSEventMessages.dll [1536]
[MD5.28FC891FBC5BBBB31667417AB87D8D17] [SPRF][1-12-2013] (...) -- C:\Users\Chris\AppData\Local\Temp\Quarantine.exe [355227]
[MD5.C8F3AD4CA2B268C6F939739E7547AD48] [SPRF][10-12-2013] (...) -- C:\Users\Chris\AppData\Local\Temp\SHSetup.exe [46777424] =>Crapware.SpyHunter
[MD5.1218DDC1C56276BA4913766502563704] [SPRF][10-11-2013] (...) -- C:\Users\Chris\AppData\Roaming\wklnhst.dat [2148]
[MD5.5CE10688C6671AE9AFC20B09376E8AB2] [SPRF][10-12-2013] (...) -- C:\Users\Chris\Desktop\adwcleaner.exe [1110034]
[MD5.B130FB9B7F2C5D7F0E353A3393617380] [SPRF][19-9-2012] (...) -- C:\Windows\Downloaded Program Files\JuniperExt.exe [416880]
[MD5.C24B1EC4470E8460D35A018199EAC8E7] [SPRF][19-9-2012] (...) -- C:\Windows\Downloaded Program Files\JuniperExt64.exe [326768]
~ Files: 12 Legitimates Filtered in 00mn 03s



---\\ Lijst van uitzonderingen in de firewall (FirewallRules) (O87)
O87 - FAEL: "{63B86D5D-2457-4594-9AE6-7C4CACACA244}" | In - Public - P6 - TRUE | .(.MyPoi World - MyPoi Manager.) -- C:\Program Files (x86)\MyPoi Manager\MyPoiManager.exe
O87 - FAEL: "{3227DF37-FCEE-4305-ABD3-97D21F9ABF7F}" | In - Public - P17 - TRUE | .(.MyPoi World - MyPoi Manager.) -- C:\Program Files (x86)\MyPoi Manager\MyPoiManager.exe
O87 - FAEL: "{22C12025-192D-4A46-A60D-414B3F221EC2}" | In - Public - P6 - TRUE | .(.ANWB - ANWB-reiswijzer.) -- C:\Program Files (x86)\ANWB-reiswijzer\ANWBReiswijzer.exe
O87 - FAEL: "{890905CA-28C2-4E41-B9D3-7C32C0471FDC}" | In - Public - P17 - TRUE | .(.ANWB - ANWB-reiswijzer.) -- C:\Program Files (x86)\ANWB-reiswijzer\ANWBReiswijzer.exe
~ Firewall: 184 Legitimates Filtered in 00mn 00s



---\\ Overzicht van de productcodes van software (PUC) (O90)
O90 - PUC: "16A3B7ABC8BE07C4189739DD2A84AA94" . (.Nik Color Efex Pro 3.0.) -- c:\Windows\Installer\{BA7B3A61-EB8C-4C70-8179-93DDA248AA49}\ARPPRODUCTICON.exe
O90 - PUC: "4C5A87AE494E232458EB1A2FDCDDA145" . (.Athentech Perfectly Clear.) -- c:\Windows\Installer\{EA78A5C4-E494-4232-85BE-A1F2CDDD1A54}\ARPPRODUCTICON.exe
O90 - PUC: "C7B790214C409404EAFBE0ECD0F6EC3E" . (.Athentech Perfectly Clear.) -- c:\Windows\Installer\{12097B7C-04C4-4049-AEBF-0ECE0D6FCEE3}\ARPPRODUCTICON.exe
O90 - PUC: "D40790EA150952C49B04778F980F9CF3" . (.OVTScanner_X64.) -- C:\Windows\Installer\{AE09704D-9051-4C25-B940-77F889F0C93F}\ARPPRODUCTICON.exe
~ Update Products: 186 Legitimates Filtered in 00mn 00s



---\\ Microsoft Installer-bestanden (WIS) (NTFS) (O93)
[MD5.937BCE2F63DAE5AB7F3F2C5D642E5D34] [WIS][24-4-2012] (.TuneUp Software - TuneUp Utilities Language Pack (nl-NL).) -- C:\Windows\Installer\55467ac.msi [2629632]
[MD5.A59FD57E9E4C586F2540EC8258D53AF8] [WIS][3-12-2013] (.Citrix Systems, Inc. - Software used to connect to Citrix application servers.) -- C:\Windows\Installer\6b44407.msi [11810304]
[MD5.7B09592A44073ACB96533B400EF1970D] [WIS][18-5-2012] (.Nokia - MSVC80_x64_v2.) -- C:\Windows\Installer\8e8a39e.msi [12307968]
~ WIS: 191 Legitimates Filtered in 00mn 58s



---\\ Algemene toestand van niet-Microsoft services (GSR) (SR = Running, SS = gestopt)
SS - | Demand 28-7-2013 72704 | (Adobe LM Service) . (.Adobe Systems.) - C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
SS - | Demand 4-12-2013 257416 | (AdobeFlashPlayerUpdateSvc) . (.Adobe Systems Incorporated.) - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
SS - | Disabled 4-1-2010 238328 | (GameConsoleService) . (.WildTangent, Inc..) - C:\Program Files (x86)\HP Games\HP Game Console\GameConsoleService.exe
SS - | Disabled 12-10-2010 206072 | (GamesAppService) . (.WildTangent, Inc..) - C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe
SS - | Auto 27-11-2011 136176 | (gupdate) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
SS - | Demand 27-11-2011 136176 | (gupdatem) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
SS - | Demand 10-8-2012 1001376 | (hpqwmiex) . (.Hewlett-Packard Company.) - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
SS - | Auto 10-7-1658 0 | (LiveUpdateSvc) . (...) - C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe
SS - | Demand 10-7-1658 0 | (PCDSRVC{56782D80-7EACDB16-06000000}_0) . (...) - C:\Program Files (x86)\pc-doc~1\pcdsrvc_x64.pkms
SS - | Disabled 22-11-2012 1522312 | (PDF Architect Helper Service) . (.pdfforge GbR.) - C:\Program Files (x86)\PDF Architect\HelperService.exe
SS - | Disabled 22-11-2012 905864 | (PDF Architect Service) . (.pdfforge GbR.) - C:\Program Files (x86)\PDF Architect\ConversionService.exe
SS - | Disabled 3-10-2012 725400 | (ServiceLayer) . (.Nokia.) - C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
SS - | Demand 10-7-1658 0 | (WMPNetworkSvc) . (...) - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe =>.Microsoft Corporation

SR - | Auto 18-3-2010 113152 | (ACDaemon) . (.ArcSoft Inc..) - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
SR - | Auto 10-5-2013 65640 | (AdobeARMservice) . (.Adobe Systems Incorporated.) - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
SR - | Auto 24-10-2011 204288 | (AMD External Events Utility) . (.AMD.) - C:\Windows\System32\atiesrxx.exe
SR - | Auto 19-11-2013 50344 | (avast! Antivirus) . (.AVAST Software.) - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
SR - | Auto 10-7-1658 0 | (ezSharedSvc) . (.EasyBits Software AS.) - C:\Windows\System32\ezSharedSvcHost.exe =>.EasyBits Software AS
SR - | Disabled 24-5-2011 1840128 | (Fabs) . (.MAGIX AG.) - C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe
SR - | Auto 22-8-2013 220504 | (Garmin Core Update Service) . (.Garmin Ltd or its subsidiaries.) - C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe
SR - | Auto 27-9-2012 86528 | (HP Support Assistant Service) . (.Hewlett-Packard Company.) - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe =>.Hewlett-Packard Co
SR - | Auto 27-6-2012 73728 | (LightScribeService) . (.Hewlett-Packard Company.) - C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
SR - | Auto 4-4-2013 418376 | (MBAMScheduler) . (.Malwarebytes Corporation.) - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
SR - | Auto 4-4-2013 701512 | (MBAMService) . (.Malwarebytes Corporation.) - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
SR - | Auto 24-10-2009 360224 | (PMBDeviceInfoProvider) . (.Sony Corporation.) - C:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe
SR - | Auto 10-3-2010 189728 | (PSI_SVC_2) . (.Protexis Inc..) - C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
SR - | Auto 8-9-2011 6583160 | (TabletServicePen) . (.Wacom Technology, Corp..) - C:\Program Files\Tablet\Pen\Pen_Tablet.exe
SR - | Auto 8-9-2011 528760 | (TouchServicePen) . (.Wacom Technology, Corp..) - C:\Program Files\Tablet\Pen\Pen_TouchService.exe
SR - | Auto 11-10-2013 2409272 | (TuneUp.UtilitiesSvc) . (.TuneUp Software.) - C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesService64.exe
SR - | Auto 14-7-2009 27136 | C:\Windows\System32\uxtuneup.dll (UxTuneUp) . (.TuneUp Software.) - C:\Windows\System32\svchost.exe
SR - | Auto 14-7-2009 27136 | C:\Program Files (x86)\Windows Defender\mpsvc.dll (WinDefend) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe
SR - | Auto 14-7-2009 27136 | C:\Windows\System32\wuaueng.dll (wuauserv) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe

~ Services: Scanned in 00mn 59s



---\\ Onderzoek gelijktijdige op de Master Boot Record (MBR) (O80)
Run by Chris at 10-12-2013 16:42:25
~ OS 64 not supported by MBR tool

~ MBR: 0 Legitimates Filtered in 00mn 00s



---\\ Onderzoek de Master Boot Record op Infecties (MBRCheck) (O80)
Written by ad13, http://ad13.geekstog
Run by Chris at 10-12-2013 16:42:27

********* Dump file Name *********
C:\PhysicalDisk0_MBR.bin

~ MBR: Scanned in 00mn 02s



---\\ Extra scan (O88)
Database Version : 13011 - (7-12-2013)
Cl?s trouv?es (Keys found) : 3
Valeurs trouv?es (Values found) : 6
Dossiers trouv?s (Folders found) : 1
Fichiers trouv?s (Files found) : 2

[HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{C4ABDBC8-1C81-42C9-BFFC-4A68511E9E4F}] =>Toolbar.TuneUp
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Dealply] =>PUP.DealPly
[HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{21111111-1111-1111-1111-110011341191}] =>PUP.CrossRider
C:\ProgramData\WPM =>PUP.WpManager^
[HKLM\Software\Wow6432Node\supWPM] =>PUP.WpManager^
C:\Users\Chris\AppData\Local\Temp\SHSetup.exe =>Crapware.SpyHunter^
~ Additionnel Scan: 374332 Items scanned in 00mn 24s



---\\ Samenvatting van detecties gevonden op uw werkstation
~ http://nicolascoolman.webs.com/apps/blog/show/38126906-hijacker-nationzoom =>Hijacker.NationZoom
~ http://nicolascoolman.webs.com/apps/blog/show/38737316-pup-wpmanager =>PUP.WpManager
~ http://nicolascoolman.webs.com/apps/blog/show/26609241-crapware-spyhunter =>Crapware.SpyHunter
~ http://nicolascoolman.webs.com/apps/blog/show/28060597-pup-dealply =>PUP.DealPly
~ http://nicolascoolman.webs.com/apps/blog/show/27583526-pup-crossrider =>PUP.CrossRider
~ MSI: 5 link(s) detected in 00mn 24s



~ 2748 Legitimates filtered by white list
End of the scan (639 lines in 11mn 55s)(2)
 
Re: Nation Zoom opent in IE en in Chrome Niet te verwijderen.

is nu ook in het NL - ging standaard zo opstarten

~ Verslag van ZHPDiag v2013.12.7.16 - Nicolas Coolman (7-12-2013)
~ Gelanceerd door Chris (10-12-2013 16:30:56)
~ Het adres van de website : http://nicolascoolman.webs.com
~ Gratis supportforum voor desinfectie : http://nicolascoolman.webs.com/apps/links/
~ Vertaald door de gebruiker
~ Staat van de versie :
~ Lijst wit : Ingeschakeld door het programma
~ Tot misbruik van bevoegdheden : OK
~ Gebruikersaccountbeheer (UAC) : Activate by user


---\\ Internet-browsers
MSIE: Internet Explorer v10.0.9200.16736 (Defaut)
GCIE: Google Chrome v31.0.1650.63
OBIE: Wacom WebTabletPlugin for Internet Explorer and Netscape v2.0.0.1

---\\ Windows productinformatie
~ Langage: N?erlandais
Windows 7 Home Premium Edition, 64-bit Service Pack 1 (Build 7601)
Windows Server License Manager Script : OK
Software Protection Service (Protection logicielle) : OK
Windows Automatic Updates : OK
Windows Activation Technologies : OK

---\\ Software om het systeem te beveiligen
avast! Free Antivirus v9.0.2008
Malwarebytes Anti-Malware versie 1.75.0.1300
Windows Defender W7

---\\ Systeem optimalisatie software

---\\ Delen van software PeerToPeer
?Torrent v3.2.2.28500 =>P2P.?Torrent

---\\ Software die extra aandacht behoeft
Adobe Flash Player 11 ActiveX
Adobe Reader X
Java 7 Update 45

---\\ Informatie over het systeem
~ Processor: AMD64 Family 16 Model 10 Stepping 0, AuthenticAMD
~ Operating System: 64 Bits
Boot mode: Normal (Normal boot)
Total RAM: 6143 MB (61% free)
System Restore: Activ? (Enable)
System drive C: has 283 GB (60%) free of 466 GB

---\\ Verbinding met het systeem-modus
~ Computer Name: CHRIS-HP
~ User Name: Chris
~ All Users Names: Gast, Chris, Administrator,
~ Unselected Option: None
Logged in as Administrator

---\\ Omgevingsvariabelen
~ System Unit : C:\
~ %AppZHP% : C:\Users\Chris\AppData\Roaming\ZHP\
~ %AppData% : C:\Users\Chris\AppData\Roaming\
~ %Desktop% : C:\Users\Chris\Desktop\
~ %Favorites% : C:\Users\Chris\Favorites\
~ %LocalAppData% : C:\Users\Chris\AppData\Local\
~ %StartMenu% : C:\Users\Chris\AppData\Roaming\Microsoft\Windows\Start Menu\
~ %Windir% : C:\Windows\
~ %System% : C:\Windows\System32\

---\\ Overzicht vaste en verwisselbare stations
C: Hard drive, Flash drive, Thumb drive (Free 283 Go of 466 Go)
D: Hard drive, Flash drive, Thumb drive (Free 1 Go of 12 Go)
E: CD-ROM drive (Not Inserted)
G: Floppy drive, Flash card reader, USB Key (Not Inserted)
H: Floppy drive, Flash card reader, USB Key (Not Inserted)
I: Floppy drive, Flash card reader, USB Key (Not Inserted)
J: Floppy drive, Flash card reader, USB Key (Not Inserted)
K: Hard drive, Flash drive, Thumb drive (Free 706 Go of 1397 Go)
Z: Hard drive, Flash drive, Thumb drive (Free 204 Go of 454 Go)



---\\ Staat van het Windows Beveiligingscentrum
~ Security Center: 49 Legitimates Filtered in 00mn 00s



---\\ Zoeken naar bepaalde algemene bestanden
[MD5.332FEAB1435662FC6C672E25BEB37BE3] - (.Microsoft Corporation - Windows Verkenner.) (.25-2-2011 - 7:19:30.) -- C:\Windows\Explorer.exe [2871808]
[MD5.94355C28C1970635A31B3FE52EB7CEBA] - (.Microsoft Corporation - Windows Toepassing Opstarten.) (.14-7-2009 - 2:39:52.) -- C:\Windows\System32\Wininit.exe [129024]
[MD5.9706C99DAEBE3FEAC811B239617E98C4] - (.Microsoft Corporation - Internetuitbreidingen voor Win32.) (.12-10-2013 - 9:45:20.) -- C:\Windows\System32\wininet.dll [2241536]
[MD5.1151B1BAA6F350B1DB6598E0FEA7C457] - (.Microsoft Corporation - Toepassing Windows-aanmelden.) (.20-11-2010 - 14:25:30.) -- C:\Windows\System32\Winlogon.exe [390656]
[MD5.067FA52BFB59A56110A12312EF9AF243] - (.Microsoft Corporation - Software Licensing-bibliotheek.) (.20-11-2010 - 14:27:26.) -- C:\Windows\System32\sppcomapi.dll [232448]
[MD5.79059559E89D06E8B80CE2944BE20228] - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) (.28-9-2013 - 2:09:10.) -- C:\Windows\system32\Drivers\AFD.sys [497152]
[MD5.02062C0B390B7729EDC9E69C680A6F3C] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) (.14-7-2009 - 2:52:21.) -- C:\Windows\system32\Drivers\atapi.sys [24128]
[MD5.B8BD2BB284668C84865658C77574381A] - (.Microsoft Corporation - CD-ROM File System Driver.) (.14-7-2009 - 0:19:47.) -- C:\Windows\system32\Drivers\Cdfs.sys [92160]
[MD5.F036CE71586E93D94DAB220D7BDF4416] - (.Microsoft Corporation - SCSI CD-ROM Driver.) (.20-11-2010 - 10:19:21.) -- C:\Windows\system32\Drivers\Cdrom.sys [147456]
[MD5.9BB2EF44EAA163B29C4A4587887A0FE4] - (.Microsoft Corporation - DFS Namespace Client Driver.) (.20-11-2010 - 10:26:32.) -- C:\Windows\system32\Drivers\DfsC.sys [102400]
[MD5.97BFED39B6B79EB12CDDBFEED51F56BB] - (.Microsoft Corporation - High Definition Audio Bus Driver.) (.20-11-2010 - 11:43:43.) -- C:\Windows\system32\Drivers\HDAudBus.sys [122368]
[MD5.FA55C73D4AFFA7EE23AC4BE53B4592D3] - (.Microsoft Corporation - i8042-poortstuurprogramma.) (.14-7-2009 - 0:19:57.) -- C:\Windows\system32\Drivers\i8042prt.sys [105472]
[MD5.AF9B39A7E7B6CAA203B3862582E9F2D0] - (.Microsoft Corporation - IP Network Address Translator.) (.14-7-2009 - 1:10:03.) -- C:\Windows\system32\Drivers\IpNat.sys [116224]
[MD5.A5D9106A73DC88564C825D317CAC68AC] - (.Microsoft Corporation - Windows NT SMB Minirdr.) (.27-4-2011 - 3:40:40.) -- C:\Windows\system32\Drivers\MRxSmb.sys [158208]
[MD5.09594D1089C523423B32A4229263F068] - (.Microsoft Corporation - MBT Transport driver.) (.20-11-2010 - 10:23:20.) -- C:\Windows\system32\Drivers\netBT.sys [261632]
[MD5.B98F8C6E31CD07B2E6F71F7F648E38C0] - (.Microsoft Corporation - NT-bestandssysteemstuurprogramma.) (.12-4-2013 - 15:45:08.) -- C:\Windows\system32\Drivers\ntfs.sys [1656680]
[MD5.0086431C29C35BE1DBC43F52CC273887] - (.Microsoft Corporation - Stuurprogramma voor parallelle poort.) (.14-7-2009 - 1:00:41.) -- C:\Windows\system32\Drivers\Parport.sys [97280]
[MD5.471815800AE33E6F1C32FB1B97C490CA] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) (.20-11-2010 - 11:52:35.) -- C:\Windows\system32\Drivers\Rasl2tp.sys [129536]
[MD5.548260A7B8654E024DC30BF8A7C5BAA4] - (.Microsoft Corporation - SMB Transport driver.) (.14-7-2009 - 1:09:09.) -- C:\Windows\system32\Drivers\smb.sys [93184]
[MD5.DDAD5A7AB24D8B65F8D724F5C20FD806] - (.Microsoft Corporation - TDI Translation Driver.) (.20-11-2010 - 10:21:56.) -- C:\Windows\system32\Drivers\tdx.sys [119296]
[MD5.0D08D2F3B3FF84E433346669B5E0F639] - (.Microsoft Corporation - Volume Shadow Copy-stuurprogramma.) (.20-11-2010 - 14:34:02.) -- C:\Windows\system32\Drivers\volsnap.sys [295808]
~ Generic Processes: Scanned in 00mn 00s



---\\ Status van de verborgen bestanden (verborgen/totaal)
~ Mes images (My Pictures) : 1/6177
~ Mes musiques (My Musics) : 1/2
~ Mes Videos (My Videos) : 1/41
~ Mes Favoris (My Favorites) : 1/226
~ Mes Documents (My Documents) : 2/22228
~ Mon Bureau (My Desktop) : 1/1617
~ Menu demarrer (Programs) : 1/40
~ Hidden Files: Scanned in 00mn 03s



---\\ Gestarte processen
[MD5.D1D5DAB39DCB4BE0359943738D87409B] - (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe [532040] [PID.2636]
[MD5.554A50B5310E702029D3A675459108FF] - (.Hewlett-Packard - hpsysdrv.) -- C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe [62768] [PID.3936]
[MD5.1725061D691D00BA94EF1D7896F6D950] - (.Nokia - Nokia Suite.) -- C:\Program Files (x86)\Nokia\Nokia Suite\NokiaSuite.exe [1088424] [PID.3952]
[MD5.A42806221ACF327C48784B93EADA3E12] - (.Hewlett-Packard Company - No Comment.) -- C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe [2736128] [PID.3964]
[MD5.766E24A20116AFA41F380B57FFE7AF02] - (.Sony Corporation - Media Check Tool.) -- C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe [599328] [PID.3260]
[MD5.1F0A97900FC718CE617A722BEF8580CD] - (.AVAST Software - avast! Antivirus.) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe [3568312] [PID.3252]
[MD5.D7D5768B8A697FCBAEE2CFE137070F02] - (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\IEXPLORE.exe [770736] [PID.3280]
[MD5.C0F5728CCD08AB01D66646FA320A03F2] - (.Nicolas Coolman - ZHPDiag.) -- C:\Program Files (x86)\ZHPDiag\ZHPDiag.exe [8286208] [PID.5528]
[MD5.4D41D30E2FAB3307967C7A0B045DC874] - (.AVAST Software - avast! Service.) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344] [PID.1332]
[MD5.ADC420616C501B45D26C0FD3EF1E54E4] - (.ArcSoft Inc. - ArcSoft Connect Service.) -- C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152] [PID.2004]
[MD5.ADDA5E1951B90D3D23C56D3CF0622ADC] - (.Adobe Systems Incorporated - Adobe Acrobat Update Service.) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [65640] [PID.2024]
[MD5.CA793DCC1D5F619021EF1D37CC7A831E] - (.EasyBits Software AS - Shared EasyBits services for Windows.) -- C:\Windows\SysWOW64\ezSharedSvcHost.exe [514232] [PID.1168]
[MD5.CFD54D70F76E84E1E737AE1140FBC5C0] - (.Garmin Ltd or its subsidiaries - Garmin Core Update Service.) -- C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe [220504] [PID.1108]
[MD5.EE963D96BFD97E54BA6CE6D2AC58DE35] - (.Hewlett-Packard Company - LightScribe Service.) -- C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe [73728] [PID.2432]
[MD5.65085456FD9A74D7F1A999520C299ECB] - (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376] [PID.2572]
[MD5.E0D7732F2D2E24B2DB3F67B6750295B8] - (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512] [PID.2596]
[MD5.627FA58ADC043704F9D14CA44340956F] - (.Sony Corporation - Device Information Provider.) -- C:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe [360224] [PID.2648]
[MD5.543A4EF0923BF70D126625B034EF25AF] - (.Protexis Inc. - PsiService PsiService.) -- C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe [189728] [PID.2704]
[MD5.F02A533F517EB38333CB12A9E8963773] - (.Google Inc. - Google Installer.) -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [136176] [PID.3752]
[MD5.465680BDE344CE4FF6646626AA3A9125] - (.Google Inc. - Google Crash Handler.) -- C:\Program Files (x86)\Google\Update\1.3.22.3\GoogleCrashHandler.exe [223112] [PID.124]
~ Processes Running: Scanned in 00mn 00s



---\\ Google Chrome, start, zoeken, extensies (G0, G1, G2)
C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Default\Preferences
G0 - GCSP: Preference [User Data\Default] http://www.zeelandnet.nl
~ Google Browser: 13 Legitimates Filtered in 00mn 01s



---\\ Mozilla Firefox, Plugins, start, zoeken, extensies (P2, M0, M1, M2, M3)
C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\prefs.js (.not file.)
~ Firefox Browser: 3 Legitimates Filtered in 00mn 00s



---\\ Internet Explorer, start, zoeken, URLSearchHook, Phishing (R0, R1, R3, R4)
R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.zeelandnet.nl
~ IE Browser: 17 Legitimates Filtered in 00mn 00s



---\\ Internet Explorer, proxybeheer (R5)
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = no key
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyHttp1.1 = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll
~ Proxy management: Scanned in 00mn 00s



---\\ Analyse van lijnen F0, F1, F2, F3 - IniFiles, Autoloading programma's
F2 - REG:system.ini: USERINIT=C:\Windows\system32\userinit.exe,
F2 - REG:system.ini: Shell=C:\Windows\explorer.exe
F2 - REG:system.ini: VMApplet=C:\Windows\System32\SystemPropertiesPerformance.exe
~ Keys: Scanned in 00mn 00s



---\\ Hosts-bestand omleiding (O1)
~ Le fichier hosts est sain (The hosts file is clean).
~ Hosts File: Scanned in 00mn 00s
~ Nombre de lignes (Lines number): 2



---\\ Internet Explorer werkbalken (O3)
O3 - Toolbar: (no name) [64Bits] - [HKLM]{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} Orphan sleutel
~ Toolbar: Scanned in 00mn 00s



---\\ Andere Verwijzigingen gebruikers (O4)
O4 - GS\Desktop [Public]: 1-Click-Optimizer.lnk . (.Ashampoo GmbH & Co. KG - Ashampoo WinOptimizer Free.) -- C:\Program Files (x86)\Ashampoo\Ashampoo WinOptimizer Free\WOFree.exe
O4 - GS\Desktop [Public]: Ashampoo WinOptimizer Free.lnk . (.Ashampoo GmbH & Co. KG - Ashampoo WinOptimizer Free.) -- C:\Program Files (x86)\Ashampoo\Ashampoo WinOptimizer Free\WOFree.exe
O4 - GS\Desktop [Public]: FaceFilter v3.02 Standard.lnk . (.Reallusion Inc. - FaceFilter3 AP.) -- C:\Program Files (x86)\Reallusion\FaceFilter3\FFApp.exe
O4 - GS\Desktop [Public]: Namo WebEditor 8.lnk . (.Namo Interactive, Inc. - Namo WebEditor 8.) -- C:\Program Files (x86)\Namo\WebEditor 8\bin\WebEditor.exe
O4 - GS\Program [Public]: eBay.nl.lnk . (...) -- C:\Program Files (x86)\Hewlett-Packard\Shared\WizLink.exe =>Toolbar.eBay
O4 - GS\Program [Public]: Inkscape.lnk . (.inkscape.org - Inkscape.) -- C:\Program Files (x86)\Inkscape\inkscape.exe
O4 - GS\Program [Public]: Shortcut to IPictDB Plugin.lnk . (...) -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IPictDB Plugin
O4 - GS\QuickLaunch [Chris]: Artensoft Photo Collage Maker.lnk . (.Artensoft Company - Artensoft Photo Collage Maker 1.2.) -- C:\Program Files\Artensoft Photo Collage Maker\Artensoft Photo Collage Maker.exe
O4 - GS\QuickLaunch [Chris]: Colasoft Capsa 7 Free.lnk . (.Colasoft - Colasoft Capsa 7.) -- C:\Program Files (x86)\Colasoft Capsa 7 Free Edition\capsa.exe
O4 - GS\QuickLaunch [Chris]: GrabIt.lnk . (...) -- C:\Program Files (x86)\GrabIt\GrabIt.exe
O4 - GS\QuickLaunch [Chris]: Inkscape.lnk . (.inkscape.org - Inkscape.) -- C:\Program Files (x86)\Inkscape\inkscape.exe
O4 - GS\QuickLaunch [Chris]: jZip.lnk . (...) -- C:\Program Files (x86)\jZip\jZip.exe (.not file.)
O4 - GS\QuickLaunch [Chris]: Launch Internet Explorer Browser.lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe http://www.nationzoom.com =>Hijacker.NationZoom
O4 - GS\QuickLaunch [Chris]: SignCut.lnk . (...) -- C:\Program Files (x86)\SignCut\SignCut.exe
O4 - GS\QuickLaunch [Chris]: ?Torrent.lnk . (.BitTorrent, Inc. - ?Torrent.) -- C:\Program Files (x86)\uTorrent\uTorrent.exe =>P2P.BitTorrent
O4 - GS\TaskBar [Chris]: DATA (Z).lnk . (.Microsoft Corporation - Windows Verkenner.) -- C:\Windows\explorer.exe
O4 - GS\TaskBar [Chris]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe http://www.nationzoom.com =>Hijacker.NationZoom
O4 - GS\TaskBar [Chris]: WinHTTrack Website Copier.lnk . (.HTTrack - WinHTTrack Website Copier, Copy Websites to.) -- C:\Program Files (x86)\WinHTTrack\WinHTTrack.exe
O4 - GS\Program [Chris]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe http://www.nationzoom.com =>Hijacker.NationZoom
O4 - GS\SystemTools [Chris]: Internet Explorer (No Add-ons).lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe http://www.nationzoom.com =>Hijacker.NationZoom
O4 - GS\SendTo [Chris]: Bestandsoverdracht via Bluetooth.LNK . (.Microsoft Corporation - No Comment.) -- C:\Windows\System32\fsquirt.exe
O4 - GS\SendTo [Chris]: SignCut.lnk . (...) -- C:\Program Files (x86)\SignCut\SignCut.exe
~ Global Startup: 87 Legitimates Filtered in 00mn 01s



---\\ Toepassingen gestart door register &amp; bestand (O4)
O4 - GS\Startup [Chris]: Adobe Gamma.lnk . (.Adobe Systems, Inc. - Adobe Gamma Loader.) -- C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - HKLM\..\Run: [hpsysdrv] . (.Hewlett-Packard - hpsysdrv.) -- c:\program files (x86)\hewlett-packard\HP odometer\hpsysdrv.exe =>.Hewlett-Packard Co
O4 - HKLM\..\RunOnce: [NCPluginUpdater] . (.Hewlett-Packard - NCPluginUpdater.) -- C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\NCPluginUpdater.exe
O4 - HKCU\..\Run: [NokiaSuite.exe] . (.Nokia - Nokia Suite.) -- C:\Program Files (x86)\Nokia\Nokia Suite\NokiaSuite.exe
O4 - HKCU\..\Run: [LightScribe Control Panel] . (.Hewlett-Packard Company - No Comment.) -- C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe
O4 - HKCU\..\Run: [GarminExpressTrayApp] . (.Garmin Ltd or its subsidiaries - Express Tray.) -- C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe
O4 - HKCU\..\Run: [Sidebar] . (.Microsoft Corporation - Windows-bureaubladgadgets.) -- C:\Program Files\Windows Sidebar\sidebar.exe
O4 - HKLM\..\Wow6432Node\Run: [MyPoi Monitor] . (.ANWB - ANWB Monitor.) -- C:\Program Files (x86)\Common Files\MyPoiWorld Shared\MyPoiMonitor\MyPoiMonitor.exe
O4 - HKLM\..\Wow6432Node\Run: [PMBVolumeWatcher] . (.Sony Corporation - Media Check Tool.) -- C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe
O4 - HKLM\..\Wow6432Node\Run: [SMKRun] . (.Wacom Co., Ltd - ScreenMark MFC Application.) -- C:\Program Files (x86)\JustWrite Office\ScreenMark.exe
O4 - HKLM\..\Wow6432Node\Run: [APSDaemon] . (.Apple Inc. - Apple Push.) -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe
O4 - HKLM\..\Wow6432Node\Run: [StartCCC] . (.Advanced Micro Devices, Inc. - Catalyst? Control Center Launcher.) -- C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe =>.Advanced Micro Devices, Inc
O4 - HKLM\..\Wow6432Node\Run: [Adobe ARM] . (.Adobe Systems Incorporated - Adobe Reader and Acrobat Manager.) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe =>.Adobe Systems Incorporated
O4 - HKLM\..\Wow6432Node\Run: [AvastUI.exe] . (.AVAST Software - avast! Antivirus.) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe
O4 - HKLM\..\Wow6432Node\Run: [20131121] . (.AVAST Software - avast! Emergency Update.) -- C:\Program Files\AVAST Software\Avast\setup\emupdate\991770ab-afc8-4779-a147-d7f72b2803a9.exe
O4 - HKLM\..\Wow6432Node\Run: [mobilegeni daemon] C:\Program Files (x86)\Mobogenie\DaemonProcess.exe (.not file.)
O4 - HKUS\S-1-5-21-54043301-2395897540-3358933016-1000\..\Run: [NokiaSuite.exe] . (.Nokia - Nokia Suite.) -- C:\Program Files (x86)\Nokia\Nokia Suite\NokiaSuite.exe
O4 - HKUS\S-1-5-21-54043301-2395897540-3358933016-1000\..\Run: [LightScribe Control Panel] . (.Hewlett-Packard Company - No Comment.) -- C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe
O4 - HKUS\S-1-5-21-54043301-2395897540-3358933016-1000\..\Run: [GarminExpressTrayApp] . (.Garmin Ltd or its subsidiaries - Express Tray.) -- C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe
O4 - HKUS\S-1-5-21-54043301-2395897540-3358933016-1000\..\Run: [Sidebar] . (.Microsoft Corporation - Windows-bureaubladgadgets.) -- C:\Program Files\Windows Sidebar\sidebar.exe
~ Application: Scanned in 00mn 00s



---\\ Knoppen op de werkbalk "belangrijkste instrumenten" Internet Explorer (O9)
O9 - Extra button: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll,-102 [64Bits] - {25510184-5A38-4A99-B273-DCA8EEF6CD08} . (...) -- C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\Resources\Icons\HP.ico
~ IE Extra Buttons: Scanned in 00mn 00s



---\\ ActiveX-objecten (Downloaded Program Files) (O16)
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} ((no name)) - http://h20614.www2.hp.com/ediags/gmd/Install/Cab/hpdetect121.cab
O16 - DPF: {AA570693-00E2-4907-B6F1-60A1199B030C} ((no name)) - https://juniper.net/dana-cached/sc/JuniperSetupClient64.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} ((no name)) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
~ Objets ActiveX: Scanned in 00mn 00s



---\\ Domeinadres van de DNS (O17) wijzigen
O17 - HKLM\System\CCS\Services\Tcpip\..\{F2A0558D-B9C8-4C73-8A0E-4076CC58FAF6}: DhcpNameServer = 62.238.255.69 212.115.192.100
O17 - HKLM\System\CS1\Services\Tcpip\..\{F2A0558D-B9C8-4C73-8A0E-4076CC58FAF6}: DhcpNameServer = 62.238.255.69 212.115.192.100
O17 - HKLM\System\CS2\Services\Tcpip\..\{F2A0558D-B9C8-4C73-8A0E-4076CC58FAF6}: DhcpNameServer = 62.238.255.69 212.115.192.100
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 62.238.255.69 212.115.192.100
~ Domain: Scanned in 00mn 00s



---\\ Aanvullend Protocol (O18)
O18 - Handler: wlpg [64Bits] - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} . (...) --
O18 - Filter: application/x-msdownload [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll =>.Microsoft Corporation
~ Protocole Additionnel: Scanned in 00mn 00s



---\\ Lijst van niet-Microsoft NT services die niet uitgeschakeld zijn (O23)
O23 - Service: LiveUpdate (LiveUpdateSvc) . (...) - C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe (.not file.)
O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) . (.TuneUp Software - TuneUp Utilities Service.) - C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesService64.exe
~ Services: 15 Legitimates Filtered in 00mn 04s



---\\ Geeft een opsomming van de BootExecute (BEX) gegevens (O34)
O34 - HKLM BootExecute: (autocheck autochk /r \??\K:) - File not found
O34 - HKLM BootExecute: (autocheck autochk /p \??\K:) - File not found
O34 - HKLM BootExecute: (autocheck autochk /r \??\K:) - File not found
O34 - HKLM BootExecute: (autocheck autochk /r \??\J:) - File not found
~ BEX: 5 Legitimates Filtered in 00mn 00s



---\\ Taken die zijn gepland in de automatische modus (O39)
[MD5.00000000000000000000000000000000] [APT] [SuperEasyDriverUpdaterRunAtStartup] (...) -- C:\Program Files (x86)\SuperEasy Software\Driver Updater\supereasydu.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{031D31DF-D4E5-4704-A021-FB1CD7E01B5D}] (...) -- C:\Users\Chris\Downloads\GENKWA\GENKWA.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{0584FB7E-CAEA-4EC4-9159-406AC82E2DC2}] (...) -- K:\AllNewDriversMei2010\Corel PaintShopPro\PlaatjesPenselen\06_04_Tubes.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{07A2BA85-8125-4391-82FC-0DA75453C914}] (...) -- C:\Users\Chris\Downloads\SmartST.Navman.iCN.530\Expand.exe (.not file.) [0]
[MD5.7514F93A09ADF6A0AE0198360EA2528A] [APT] [{0FEFEE64-8E8B-4609-89F1-30F155CB36DF}] (...) -- C:\Program Files (x86)\SignCut\SignCut.exe [3766272]
[MD5.B23AB77A960F56232DDAFFED743058C7] [APT] [{142B3A70-8B6A-4C78-86CF-5921EFDA2D3E}] (.Stichting Aldfaer, Kollum.) -- C:\Aldfaer\Aldfaer.exe [7425024]
[MD5.00000000000000000000000000000000] [APT] [{1F1E8BCD-E82C-4684-BDF6-B998C821FF77}] (...) -- K:\Navman Connection pack\Install.exe (.not file.) [0]
[MD5.2417CECFD619A7007A638DC665FCC4FE] [APT] [{2161351E-6AE3-4970-ADA6-053C2941F358}] (.Acro Software Inc..) -- Z:\COUGAR\BlackCat PDF Writer Folder\BlackCat PDF Writer Folder\Setup.exe [53248]
[MD5.00000000000000000000000000000000] [APT] [{29DA36CE-FDE7-433E-B091-FC61333B92FA}] (...) -- K:\AllNewDriversMei2010\Corel PaintShopPro\Fotolijsten\12_04_frames.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{46FB4E1A-1BC4-4F3C-8ED5-7EC1D6963E42}] (...) -- E:\Kluwer\SETUP.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{49888ECB-B10F-466B-8909-E092867451AB}] (...) -- K:\Justwrite Office 4.4\install.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{86A37646-0036-4F72-B971-C5517EA2F7EB}] (...) -- K:\Navman Connection pack\Install.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{86EDB9E4-0CF8-40C8-9D62-593FAEA56B57}] (...) -- K:\AllNewDriversMei2010\Corel PaintShopPro\Fotolijsten\05_21_framesPSPA.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{96598113-3B4A-472F-85D7-1D09E531475B}] (...) -- K:\AllNewDriversMei2010\Corel PaintShopPro\PlaatjesPenselen\10_04_tubes.exe (.not file.) [0]
[MD5.7514F93A09ADF6A0AE0198360EA2528A] [APT] [{96B82CC2-35B0-4EAE-B27D-330570729984}] (...) -- C:\Program Files (x86)\SignCut\SignCut.exe [3766272]
[MD5.00000000000000000000000000000000] [APT] [{96DDDF67-B255-4271-BCF8-5CBE1A8BAF17}] (...) -- K:\AllNewDriversMei2010\Corel PaintShopPro\Fotolijsten\08_04_Frames.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{9A3EB825-B8DC-45BA-A199-D7687ED3279A}] (...) -- E:\Kluwer\SETUP.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{9F585B07-9F34-4DFD-9790-C5C9848FCD2E}] (...) -- E:\Kluwer\SETUP.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{9FA40B7F-CE87-4754-81F6-98EA68F16813}] (...) -- K:\AllNewDriversMei2010\Corel PaintShopPro\Fotolijsten\2004_holiday_frames.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{A0904247-8A85-43D5-A92A-2E80692EC60A}] (...) -- E:\Kluwer\SETUP.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{A7E57CEE-CC38-411E-8040-A326153E1A87}] (...) -- K:\Navman Connection pack\Install.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{A9DBBE24-3967-4AD6-99AC-C1675251E606}] (...) -- K:\AllNewDriversMei2010\Corel PaintShopPro\Fotolijsten\1_04_frames.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{ADE04678-3988-4CEF-AE31-8A5D6D05FF9D}] (...) -- K:\AllNewDriversMei2010\Corel PaintShopPro\Fotolijsten\12_03_frames.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{B0236764-C746-4B19-A111-94556756739E}] (...) -- C:\Program Files (x86)\Navman\F Series Connection Pack\POIEditor.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{C0D2A2C2-1194-45EB-BE08-F3E8806CE09D}] (...) -- E:\Kluwer\SETUP.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{C12AB581-F257-4D00-A101-CA114CB754E3}] (...) -- K:\AllNewDriversMei2010\Corel PaintShopPro\PlaatjesPenselen\11_04_Tubes.exe (.not file.) [0]
[MD5.380E1329E9E6DFC161DC2ADA5EC7F11E] [APT] [{C1403E9A-8E89-4DC3-B0C0-385B111D5352}] (.inkscape.org.) -- C:\Program Files (x86)\Inkscape\inkscape.exe [14647296]
[MD5.00000000000000000000000000000000] [APT] [{C342ABF1-5FDD-4F7F-84AD-31E3A8343651}] (...) -- E:\Kluwer\SETUP.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{C48F7A7D-CC0F-4D7F-972F-1CB317D01415}] (...) -- C:\Users\Chris\Downloads\GENKWA\GENKWA.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{C6EA55BC-E06B-4E47-B32B-C1210BA9C0AD}] (...) -- K:\AllNewDriversMei2010\Corel PaintShopPro\Fotolijsten\09_04_Frames.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{C7BA3C3F-D5CE-42A9-9D6A-FDF9CBA50F6C}] (...) -- K:\AllNewDriversMei2010\Corel PaintShopPro\Fotolijsten\10_04_frames.exe (.not file.) [0]
[MD5.380E1329E9E6DFC161DC2ADA5EC7F11E] [APT] [{E8B0E806-1687-4888-B6FF-81187F42B17C}] (.inkscape.org.) -- C:\Program Files (x86)\Inkscape\inkscape.exe [14647296]
[MD5.00000000000000000000000000000000] [APT] [{F5412E89-AF46-42D3-8FBC-F1428847BDC8}] (...) -- K:\Navman Connection pack\Expand.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{F5888516-FE7A-4B5F-9968-1E86567DF290}] (...) -- E:\Kluwer\SETUP.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{FDCCCC37-8624-48A1-82A5-CB86463F4ACA}] (...) -- C:\Program Files (x86)\Navman\F Series Connection Pack\POIEditor.exe (.not file.) [0]
[MD5.1B3943485328C35F6F186E13CA373FB1] [APT] [{FF815ADB-AC6C-4A7A-9CF0-C1C461BF24E0}] (...) -- C:\Program Files (x86)\COMMON~1\MICROS~1\Datamap\DATAINST.exe [292864]
~ Scheduled Task: 73 Legitimates Filtered in 00mn 04s



---\\ Piloot aan het begin van het systeem (O41)
O41 - Driver: (CSN5PDTS82) . (. - .) - C:\Windows\System32\Drivers\CSN5PDTS82.sys (.not file.)
O41 - Driver: (CSN5PDTS82x64) . (.Colasoft Co., Ltd. - Colasoft NDIS 5.0 Protocol Driver (x64).) - C:\Windows\System32\Drivers\CSN5PDTS82x64.sys
~ Drivers: 81 Legitimates Filtered in 00mn 00s



---\\ Ge?nstalleerde software (O42)
O42 - Logiciel: ANWB-reiswijzer - (.ANWB B.V./MyPoi World B.V..) [HKLM][64Bits] -- {8EF7A04E-C5A6-459E-8106-362AEE79A5F6}
O42 - Logiciel: Aldfaer - (...) [HKCU][64Bits] -- Aldfaer
O42 - Logiciel: Face Off Max - (...) [HKLM][64Bits] -- FaceOffMax
O42 - Logiciel: GPicSync 1.30 - (.GPicSync.) [HKLM][64Bits] -- GPicSync_is1
O42 - Logiciel: MyPoi Manager - (.MyPoi World.) [HKLM][64Bits] -- {0C6DB6B9-2D17-4AA5-A207-42D28BF9F434}
O42 - Logiciel: SignCut (remove only) - (...) [HKLM][64Bits] -- SignCut
O42 - Logiciel: XML Copy Editor version 1.2.0.9 - (.Zane U. Ji.) [HKLM][64Bits] -- XML Copy Editor_is1
~ Logic: 41 Legitimates Filtered in 00mn 01s



---\\ HKCU & HKLM Software Keys
[HKCU\Software\AllMyBooks]
[HKCU\Software\CraftEdge]
[HKCU\Software\Google Map Buddy]
[HKCU\Software\Pretek]
[HKCU\Software\SignCutPreview]
[HKCU\Software\SignCut]
[HKCU\Software\SoftGold]
[HKCU\Software\Stichting Aldfaer]
[HKCU\Software\TurboCCC]
[HKCU\Software\Whisqu Graphic AB]
[HKCU\Software\artensoft]
[HKCU\Software\iPictDB]
[HKCU\Software\wCEdge]
[HKCU\Software\xaCE2]
[HKLM\Software\Wow6432Node\Whisqu Graphic AB]
[HKLM\Software\Wow6432Node\supWPM] =>PUP.WpManager
~ Key Software: 543 Legitimates Filtered in 00mn 01s



---\\ 'Inhoud van mappen programma's, ProgramFiles, ProgramData, AppData (O43)
O43 - CFD: 15-6-2012 - 9:05:49 - [7,186] ----D C:\Program Files (x86)\ANWB-reiswijzer
O43 - CFD: 3-11-2013 - 12:43:19 - [8,117] ----D C:\Program Files (x86)\Belastingdienst
O43 - CFD: 4-8-2013 - 10:23:56 - [5,666] ----D C:\Program Files (x86)\Exif Pilot
O43 - CFD: 23-9-2012 - 13:33:14 - [30,713] ----D C:\Program Files (x86)\GPicSync
O43 - CFD: 13-10-2012 - 9:34:36 - [0,388] ----D C:\Program Files (x86)\iPictDB
O43 - CFD: 5-11-2013 - 21:08:00 - [8,888] ----D C:\Program Files (x86)\JustWrite Office
O43 - CFD: 23-2-2012 - 20:44:39 - [9,706] ----D C:\Program Files (x86)\MyPoi Manager
O43 - CFD: 1-6-2013 - 19:18:10 - [78,170] ----D C:\Program Files (x86)\SignCut
O43 - CFD: 23-2-2012 - 21:23:06 - [1,875] ----D C:\Program Files (x86)\TurboCCC
O43 - CFD: 1-10-2012 - 10:09:35 - [0] ----D C:\Program Files (x86)\TWSteampunk
O43 - CFD: 4-8-2013 - 10:24:39 - [5,466] ----D C:\Program Files (x86)\Wire Pilot
O43 - CFD: 1-12-2012 - 10:24:53 - [37,879] ----D C:\Program Files (x86)\XML Copy Editor
O43 - CFD: 23-2-2013 - 10:33:54 - [0] ----D C:\ProgramData\AllMyBooks
O43 - CFD: 12-5-2013 - 12:19:52 - [0] ----D C:\ProgramData\CraftEdge
O43 - CFD: 4-12-2013 - 8:42:02 - [0] ----D C:\ProgramData\ProductData
O43 - CFD: 9-12-2013 - 2:06:53 - [0] ----D C:\ProgramData\WPM =>PUP.WpManager
O43 - CFD: 3-11-2013 - 11:08:28 - [0] ----D C:\ProgramData\{3C5CBD7B-3D1D-411E-96C2-513FFCA84D2D}
O43 - CFD: 18-1-2013 - 17:02:54 - [0] --H-D C:\ProgramData\{8265C354-3D13-4FE5-95C7-65F277FF3041}
O43 - CFD: 18-1-2013 - 17:02:54 - [0] --H-D C:\ProgramData\{9DE75BC9-6CF5-4972-8A4E-86BAAD477DC6}
O43 - CFD: 26-12-2012 - 13:55:13 - [0] -SH-D C:\ProgramData\{C4ABDBC8-1C81-42C9-BFFC-4A68511E9E4F}
O43 - CFD: 6-9-2012 - 18:37:26 - [0] ----D C:\Users\Chris\AppData\Roaming\Apygna
O43 - CFD: 27-3-2013 - 20:35:21 - [0] ----D C:\Users\Chris\AppData\Roaming\Belastingdienst
O43 - CFD: 23-12-2012 - 15:51:40 - [171,823] ----D C:\Users\Chris\AppData\Roaming\Bergboek
O43 - CFD: 5-1-2013 - 9:02:16 - [0] ----D C:\Users\Chris\AppData\Roaming\com.docrafts.digital
O43 - CFD: 28-4-2013 - 8:39:17 - [0,023] ----D C:\Users\Chris\AppData\Roaming\Easypano Panoweaver
O43 - CFD: 31-7-2012 - 3:02:10 - [0,002] ----D C:\Users\Chris\AppData\Roaming\Genealogica Grafica
O43 - CFD: 5-11-2013 - 21:08:00 - [0,001] ----D C:\Users\Chris\AppData\Roaming\JustWrite Office
O43 - CFD: 5-9-2012 - 21:33:13 - [0] ----D C:\Users\Chris\AppData\Roaming\Lumaur
O43 - CFD: 8-5-2013 - 20:59:53 - [4,839] ----D C:\Users\Chris\AppData\Roaming\SignCut
O43 - CFD: 4-8-2013 - 10:24:52 - [0] ----D C:\Users\Chris\AppData\Roaming\WirePilot
O43 - CFD: 24-9-2012 - 11:19:17 - [0] ----D C:\Users\Chris\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\POI format conversion
~ 1 Dossiers CLSID vides (CLSID Empty Folders)
~ Program Folder: 348 Legitimates Filtered in 00mn 05s



---\\ Meest recente bestanden gewijzigd of gemaakt op Windows en System32 (O44)
O44 - LFC:[MD5.D41D8CD98F00B204E9800998ECF8427E] - 10-12-2013 - 1:29:23 ---A- . (...) -- C:\autoexec.bat [0]
~ Files: 16 Legitimates Filtered in 00mn 06s



---\\ Laatste bestanden die zijn gemaakt in Windows Prefetcher (O45)
O45 - LFCP:[MD5.6F183F01168EF5694243FCBD3EE7D4EF] - 10-12-2013 - 8:24:48 ---A- - C:\Windows\Prefetch\INSTUP.EXE-7E543EAF.pf
~ Prefetcher: 101 Legitimates Filtered in 00mn 00s



---\\ Opsomming van het register sleutels PoliciesSystem (MWPS) (O55)
O55 - MWPS:[HKLM\...\Policies\System] - "EnableUIADesktopToggle"=0
O55 - MWPS:[HKLM\...\Policies\System] - "FilterAdministratorToken"=0
~ MWPS: 21 Legitimates Filtered in 00mn 00s



---\\ Opsomming van de registersleutel PoliciesExplorer (C?KVI) (O56)
O56 - MWPE:[HKLM\...\policies\Explorer] - "NoResolveTrack"=1
~ MWPE Keys: 3 Legitimates Filtered in 00mn 00s



---\\ Overzicht van de drivers (SDL) (O58)
O58 - SDL:[MD5.C04F7B373881009D7994D9BF55D24AB4] - 19-11-2013 - 20:33:16 ---A- . (...) -- C:\Windows\System32\Drivers\aswRvrt.sys [65776]
O58 - SDL:[MD5.59787B95DD9CA44CB139D96863438587] - 19-11-2013 - 20:33:16 ---A- . (...) -- C:\Windows\System32\Drivers\aswVmm.sys [205320]
O58 - SDL:[MD5.0262A199D98C2405C90F3188C5A54C6A] - 9-10-2006 - 0:29:22 ---A- . (...) -- C:\Windows\System32\Drivers\BTNetFilter.sys [32832]
O58 - SDL:[MD5.B6F4A83911336E84BEAD8F8905285FAB] - 11-6-2007 - 23:00:00 ---A- . (.www.winchiphead.com - Win98 WDM for CH341 serial, by W.ch.) -- C:\Windows\System32\Drivers\CH341S98.SYS [19680]
O58 - SDL:[MD5.4798C1AD22BAF6FF25451E2194E034D1] - 4-11-2011 - 23:00:00 ---A- . (.www.winchiphead.com - WDM for CH341 serial, by W.ch.) -- C:\Windows\System32\Drivers\CH341SER.SYS [39696]
O58 - SDL:[MD5.2285B31039611D509F6120D691CA661F] - 29-5-2012 - 15:53:30 ---A- . (.Windows (R) Codename Longhorn DDK provider - hpvhd 64bit support driver.) -- C:\Windows\System32\Drivers\cpqdfw.sys [27456]
O58 - SDL:[MD5.E7956DB62954ECA3FFD2AC88F6B83BB4] - 24-10-2012 - 13:49:46 ---A- . (.Colasoft Co., Ltd. - Colasoft NDIS 5.0 Protocol Driver (x64).) -- C:\Windows\System32\Drivers\CSN5PDTS82x64.sys [34840]
O58 - SDL:[MD5.0E5DA5369A0FCAEA12456DD852545184] - 14-7-2009 - 2:47:48 ---A- . (.Emulex - Storport Miniport Driver for LightPulse HBAs.) -- C:\Windows\System32\Drivers\elxstor.sys [530496]
O58 - SDL:[MD5.F2523EF6460FC42405B12248338AB2F0] - 10-6-2009 - 21:31:59 ---A- . (.Hauppauge Computer Works, Inc. - Hauppauge WinTV 885 Consumer IR Driver for eHome.) -- C:\Windows\System32\Drivers\hcw85cir.sys [31232]
O58 - SDL:[MD5.5F79934084DF6DC0635578864376CE54] - 21-2-2008 - 9:10:36 ---A- . (.Omnivision Technologies, Inc. - Stream Class Mini Driver.) -- C:\Windows\System32\Drivers\ov550ivx.sys [196992]
O58 - SDL:[MD5.F3817967ED533D08327DC73BC4D5542A] - 14-7-2009 - 2:45:55 ---A- . (.Promise Technology - Promise SuperTrak EX Series Driver for Windows.) -- C:\Windows\System32\Drivers\stexstor.sys [24656]
O58 - SDL:[MD5.0262A199D98C2405C90F3188C5A54C6A] - 9-10-2006 - 0:29:22 ---A- . (...) -- C:\Windows\SysWOW64\drivers\BTNetFilter.sys [32832]
O58 - SDL:[MD5.8DB0DBDEC7880E81B73B8E7E8E9A666A] - 28-4-2003 - 10:31:18 ---A- . (.OEM - OX16C95x Serial Device Driver.) -- C:\Windows\SysWOW64\drivers\OXSER.SYS [51169]
~ Drivers: 21 Legitimates Filtered in 00mn 05s



---\\ Meest recente bestanden gewijzigd of gemaakt (gebruiker) (O61)
O61 - LFC: 10-12-2013 - 16:33:18 ---A- . (...) -- C:\Users\Chris\AppData\Local\GDIPFONTCACHEV1.DAT [143128]
O61 - LFC: 10-12-2013 - 16:33:18 ---A- . (...) -- C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Certificate Revocation Lists [265801]
O61 - LFC: 10-12-2013 - 16:33:18 ---A- . (...) -- C:\Users\Chris\AppData\Local\Google\Chrome\User Data\chrome_shutdown_ms.txt [5]
O61 - LFC: 10-12-2013 - 16:33:21 ---A- . (...) -- C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Local State [49016]
O61 - LFC: 10-12-2013 - 16:34:21 ---A- . (...) -- C:\Users\Chris\AppData\Roaming\ZHP\HOSTS.txt [98] =>.Nicolas Coolman
O61 - LFC: 10-12-2013 - 16:34:21 ---A- . (...) -- C:\Users\Chris\AppData\Roaming\ZHP\Log.txt [18009] =>.Nicolas Coolman
O61 - LFC: 10-12-2013 - 16:34:21 ---A- . (...) -- C:\Users\Chris\AppData\Roaming\ZHP\TestsZHPDiag.txt [2859] =>.Nicolas Coolman
O61 - LFC: 7-12-2013 - 16:33:59 ---A- . (...) -- C:\Users\Chris\AppData\Roaming\ICAClient\APPSRV.INI [2027]
O61 - LFC: 7-12-2013 - 16:33:59 ---A- . (...) -- C:\Users\Chris\AppData\Roaming\ICAClient\UISTATE.INI [911]
O61 - LFC: 7-12-2013 - 16:36:14 ---A- . (...) -- C:\Users\Chris\Downloads\,DanaInfo=.asceCmszyiwo4L4-7P43+launch (5).ica [1417]
O61 - LFC: 7-12-2013 - 16:36:15 ---A- . (...) -- C:\Users\Chris\Downloads\carbon_SHDR.zip [1271788]
O61 - LFC: 7-12-2013 - 16:36:16 ---A- . (...) -- C:\Users\Chris\Downloads\Dome_01_set_01.hdr.zip [4616734]
O61 - LFC: 7-12-2013 - 16:36:16 ---A- . (...) -- C:\Users\Chris\Downloads\Dome_02_set_02_ret.hdr.zip [4046174]
O61 - LFC: 7-12-2013 - 16:36:16 ---A- . (...) -- C:\Users\Chris\Downloads\Dome_04_set_03.hdr.zip [4737279]
O61 - LFC: 7-12-2013 - 16:36:20 ---A- . (...) -- C:\Users\Chris\Downloads\sim.zip [1228666]
O61 - LFC: 7-12-2013 - 16:36:22 ---A- . (...) -- C:\Users\Chris\Downloads\xdraw.exe [285175]
O61 - LFC: 8-12-2013 - 16:34:09 --HA- . (...) -- C:\Users\Chris\AppData\Roaming\Microsoft\Sjablonen\~$Normal.dot [162]
O61 - LFC: 8-12-2013 - 16:36:17 ---A- . (...) -- C:\Users\Chris\Downloads\mps-letter-graphic-pack-snick-008.zip [1316514]
O61 - LFC: 9-12-2013 - 16:34:21 ---A- . (...) -- C:\Users\Chris\daemonprocess.txt [0]
O61 - LFC: 9-12-2013 - 16:34:22 ---A- . (...) -- C:\Users\Chris\Documents\auto fx software download and trial license number.pdf [49846]
O61 - LFC: 9-12-2013 - 16:34:22 ---A- . (...) -- C:\Users\Chris\Documents\autofx dream suite moasaic serial number.pdf [67187]
O61 - LFC: 9-12-2013 - 16:36:16 ---A- . (...) -- C:\Users\Chris\Downloads\DreamSuite_Series_Guide.pdf [14343225]
O61 - LFC: 9-12-2013 - 16:36:16 ---A- . (...) -- C:\Users\Chris\Downloads\DreamSuite_Series_Manual.pdf [14494121]
O61 - LFC: 9-12-2013 - 16:36:17 ---A- . (...) -- C:\Users\Chris\Downloads\Mosaic_Manual.pdf [722117]
~ 31 Fichiers temporaires (Temporary files)
~ Files: 1127 Legitimates Filtered in 04mn 57s



---\\ Lijst van cleaning tools (CLAB) (O63)
O63 - Logiciel: ZHPDiag 2013 - (.Nicolas Coolman.) [HKLM] -- ZHPDiag_is1 =>.Nicolas Coolman
O63 - Logiciel: OTL - (.OldTimer.)
O63 - Logiciel: RSIT - (.random/random.)
~ ADS: Scanned in 00mn 00s



---\\ Bestandsassociaties mogelijk aangepast (O67)
O67 - Shell Spawning: <.html> <ChromeHTML>[HKCU\..\open\Command] (.Not Key.)
~ FASS Keys: 11 Legitimates Filtered in 00mn 00s



---\\ Startmenu Internet (SMI) (O68)
O68 - StartMenuInternet: <Google Chrome> <Google Chrome>[HKLM\..\Shell\open\Command] (.Google Inc. - Google Chrome.) -- c:\program files (x86)\google\chrome\application\chrome.exe
O68 - StartMenuInternet: <IEXPLORE.EXE> <Internet Explorer>[HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- c:\program files\internet explorer\iexplore.exe
~ Keys: Scanned in 00mn 00s



---\\ Geeft een opsomming van bestanden Crack &amp; Keygen (KKF) (O82)
K:\all chris user\DownLoads\AutoFX.DreamSuite.Series.Bundle.v1.36\AutoFX.DreamSuite.Series.Bundle.v1.36\AutoFX.DreamSuite.Series.Bundle.v1.36\Keygen\keygen.exe
K:\ABR Installeren\cracked_brushes_178255.zip
~ Files: Scanned in 04mn 36s



---\\ Bepaalde zoekopdracht in de hoofdmap van het systeem (SPRF) (O84)
[MD5.248E7DA5F002B1AA5066AD4B398F9673] [SPRF][14-10-2012] (...) -- C:\ProgramData\KGyGaAvL.sys [952]
[MD5.BCB0728F4B117855765CE8FE883B5E9B] [SPRF][10-12-2013] (...) -- C:\Users\Chris\AppData\Local\Temp\NOSEventMessages.dll [1536]
[MD5.28FC891FBC5BBBB31667417AB87D8D17] [SPRF][1-12-2013] (...) -- C:\Users\Chris\AppData\Local\Temp\Quarantine.exe [355227]
[MD5.C8F3AD4CA2B268C6F939739E7547AD48] [SPRF][10-12-2013] (...) -- C:\Users\Chris\AppData\Local\Temp\SHSetup.exe [46777424] =>Crapware.SpyHunter
[MD5.1218DDC1C56276BA4913766502563704] [SPRF][10-11-2013] (...) -- C:\Users\Chris\AppData\Roaming\wklnhst.dat [2148]
[MD5.5CE10688C6671AE9AFC20B09376E8AB2] [SPRF][10-12-2013] (...) -- C:\Users\Chris\Desktop\adwcleaner.exe [1110034]
[MD5.B130FB9B7F2C5D7F0E353A3393617380] [SPRF][19-9-2012] (...) -- C:\Windows\Downloaded Program Files\JuniperExt.exe [416880]
[MD5.C24B1EC4470E8460D35A018199EAC8E7] [SPRF][19-9-2012] (...) -- C:\Windows\Downloaded Program Files\JuniperExt64.exe [326768]
~ Files: 12 Legitimates Filtered in 00mn 03s



---\\ Lijst van uitzonderingen in de firewall (FirewallRules) (O87)
O87 - FAEL: "{63B86D5D-2457-4594-9AE6-7C4CACACA244}" | In - Public - P6 - TRUE | .(.MyPoi World - MyPoi Manager.) -- C:\Program Files (x86)\MyPoi Manager\MyPoiManager.exe
O87 - FAEL: "{3227DF37-FCEE-4305-ABD3-97D21F9ABF7F}" | In - Public - P17 - TRUE | .(.MyPoi World - MyPoi Manager.) -- C:\Program Files (x86)\MyPoi Manager\MyPoiManager.exe
O87 - FAEL: "{22C12025-192D-4A46-A60D-414B3F221EC2}" | In - Public - P6 - TRUE | .(.ANWB - ANWB-reiswijzer.) -- C:\Program Files (x86)\ANWB-reiswijzer\ANWBReiswijzer.exe
O87 - FAEL: "{890905CA-28C2-4E41-B9D3-7C32C0471FDC}" | In - Public - P17 - TRUE | .(.ANWB - ANWB-reiswijzer.) -- C:\Program Files (x86)\ANWB-reiswijzer\ANWBReiswijzer.exe
~ Firewall: 184 Legitimates Filtered in 00mn 00s



---\\ Overzicht van de productcodes van software (PUC) (O90)
O90 - PUC: "16A3B7ABC8BE07C4189739DD2A84AA94" . (.Nik Color Efex Pro 3.0.) -- c:\Windows\Installer\{BA7B3A61-EB8C-4C70-8179-93DDA248AA49}\ARPPRODUCTICON.exe
O90 - PUC: "4C5A87AE494E232458EB1A2FDCDDA145" . (.Athentech Perfectly Clear.) -- c:\Windows\Installer\{EA78A5C4-E494-4232-85BE-A1F2CDDD1A54}\ARPPRODUCTICON.exe
O90 - PUC: "C7B790214C409404EAFBE0ECD0F6EC3E" . (.Athentech Perfectly Clear.) -- c:\Windows\Installer\{12097B7C-04C4-4049-AEBF-0ECE0D6FCEE3}\ARPPRODUCTICON.exe
O90 - PUC: "D40790EA150952C49B04778F980F9CF3" . (.OVTScanner_X64.) -- C:\Windows\Installer\{AE09704D-9051-4C25-B940-77F889F0C93F}\ARPPRODUCTICON.exe
~ Update Products: 186 Legitimates Filtered in 00mn 00s



---\\ Microsoft Installer-bestanden (WIS) (NTFS) (O93)
[MD5.937BCE2F63DAE5AB7F3F2C5D642E5D34] [WIS][24-4-2012] (.TuneUp Software - TuneUp Utilities Language Pack (nl-NL).) -- C:\Windows\Installer\55467ac.msi [2629632]
[MD5.A59FD57E9E4C586F2540EC8258D53AF8] [WIS][3-12-2013] (.Citrix Systems, Inc. - Software used to connect to Citrix application servers.) -- C:\Windows\Installer\6b44407.msi [11810304]
[MD5.7B09592A44073ACB96533B400EF1970D] [WIS][18-5-2012] (.Nokia - MSVC80_x64_v2.) -- C:\Windows\Installer\8e8a39e.msi [12307968]
~ WIS: 191 Legitimates Filtered in 00mn 58s



---\\ Algemene toestand van niet-Microsoft services (GSR) (SR = Running, SS = gestopt)
SS - | Demand 28-7-2013 72704 | (Adobe LM Service) . (.Adobe Systems.) - C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
SS - | Demand 4-12-2013 257416 | (AdobeFlashPlayerUpdateSvc) . (.Adobe Systems Incorporated.) - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
SS - | Disabled 4-1-2010 238328 | (GameConsoleService) . (.WildTangent, Inc..) - C:\Program Files (x86)\HP Games\HP Game Console\GameConsoleService.exe
SS - | Disabled 12-10-2010 206072 | (GamesAppService) . (.WildTangent, Inc..) - C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe
SS - | Auto 27-11-2011 136176 | (gupdate) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
SS - | Demand 27-11-2011 136176 | (gupdatem) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
SS - | Demand 10-8-2012 1001376 | (hpqwmiex) . (.Hewlett-Packard Company.) - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
SS - | Auto 10-7-1658 0 | (LiveUpdateSvc) . (...) - C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe
SS - | Demand 10-7-1658 0 | (PCDSRVC{56782D80-7EACDB16-06000000}_0) . (...) - C:\Program Files (x86)\pc-doc~1\pcdsrvc_x64.pkms
SS - | Disabled 22-11-2012 1522312 | (PDF Architect Helper Service) . (.pdfforge GbR.) - C:\Program Files (x86)\PDF Architect\HelperService.exe
SS - | Disabled 22-11-2012 905864 | (PDF Architect Service) . (.pdfforge GbR.) - C:\Program Files (x86)\PDF Architect\ConversionService.exe
SS - | Disabled 3-10-2012 725400 | (ServiceLayer) . (.Nokia.) - C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
SS - | Demand 10-7-1658 0 | (WMPNetworkSvc) . (...) - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe =>.Microsoft Corporation

SR - | Auto 18-3-2010 113152 | (ACDaemon) . (.ArcSoft Inc..) - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
SR - | Auto 10-5-2013 65640 | (AdobeARMservice) . (.Adobe Systems Incorporated.) - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
SR - | Auto 24-10-2011 204288 | (AMD External Events Utility) . (.AMD.) - C:\Windows\System32\atiesrxx.exe
SR - | Auto 19-11-2013 50344 | (avast! Antivirus) . (.AVAST Software.) - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
SR - | Auto 10-7-1658 0 | (ezSharedSvc) . (.EasyBits Software AS.) - C:\Windows\System32\ezSharedSvcHost.exe =>.EasyBits Software AS
SR - | Disabled 24-5-2011 1840128 | (Fabs) . (.MAGIX AG.) - C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe
SR - | Auto 22-8-2013 220504 | (Garmin Core Update Service) . (.Garmin Ltd or its subsidiaries.) - C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe
SR - | Auto 27-9-2012 86528 | (HP Support Assistant Service) . (.Hewlett-Packard Company.) - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe =>.Hewlett-Packard Co
SR - | Auto 27-6-2012 73728 | (LightScribeService) . (.Hewlett-Packard Company.) - C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
SR - | Auto 4-4-2013 418376 | (MBAMScheduler) . (.Malwarebytes Corporation.) - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
SR - | Auto 4-4-2013 701512 | (MBAMService) . (.Malwarebytes Corporation.) - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
SR - | Auto 24-10-2009 360224 | (PMBDeviceInfoProvider) . (.Sony Corporation.) - C:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe
SR - | Auto 10-3-2010 189728 | (PSI_SVC_2) . (.Protexis Inc..) - C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
SR - | Auto 8-9-2011 6583160 | (TabletServicePen) . (.Wacom Technology, Corp..) - C:\Program Files\Tablet\Pen\Pen_Tablet.exe
SR - | Auto 8-9-2011 528760 | (TouchServicePen) . (.Wacom Technology, Corp..) - C:\Program Files\Tablet\Pen\Pen_TouchService.exe
SR - | Auto 11-10-2013 2409272 | (TuneUp.UtilitiesSvc) . (.TuneUp Software.) - C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesService64.exe
SR - | Auto 14-7-2009 27136 | C:\Windows\System32\uxtuneup.dll (UxTuneUp) . (.TuneUp Software.) - C:\Windows\System32\svchost.exe
SR - | Auto 14-7-2009 27136 | C:\Program Files (x86)\Windows Defender\mpsvc.dll (WinDefend) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe
SR - | Auto 14-7-2009 27136 | C:\Windows\System32\wuaueng.dll (wuauserv) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe

~ Services: Scanned in 00mn 59s



---\\ Onderzoek gelijktijdige op de Master Boot Record (MBR) (O80)
Run by Chris at 10-12-2013 16:42:25
~ OS 64 not supported by MBR tool

~ MBR: 0 Legitimates Filtered in 00mn 00s



---\\ Onderzoek de Master Boot Record op Infecties (MBRCheck) (O80)
Written by ad13, http://ad13.geekstog
Run by Chris at 10-12-2013 16:42:27

********* Dump file Name *********
C:\PhysicalDisk0_MBR.bin

~ MBR: Scanned in 00mn 02s



---\\ Extra scan (O88)
Database Version : 13011 - (7-12-2013)
Cl?s trouv?es (Keys found) : 3
Valeurs trouv?es (Values found) : 6
Dossiers trouv?s (Folders found) : 1
Fichiers trouv?s (Files found) : 2

[HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{C4ABDBC8-1C81-42C9-BFFC-4A68511E9E4F}] =>Toolbar.TuneUp
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Dealply] =>PUP.DealPly
[HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{21111111-1111-1111-1111-110011341191}] =>PUP.CrossRider
C:\ProgramData\WPM =>PUP.WpManager^
[HKLM\Software\Wow6432Node\supWPM] =>PUP.WpManager^
C:\Users\Chris\AppData\Local\Temp\SHSetup.exe =>Crapware.SpyHunter^
~ Additionnel Scan: 374332 Items scanned in 00mn 24s



---\\ Samenvatting van detecties gevonden op uw werkstation
~ http://nicolascoolman.webs.com/apps/blog/show/38126906-hijacker-nationzoom =>Hijacker.NationZoom
~ http://nicolascoolman.webs.com/apps/blog/show/38737316-pup-wpmanager =>PUP.WpManager
~ http://nicolascoolman.webs.com/apps/blog/show/26609241-crapware-spyhunter =>Crapware.SpyHunter
~ http://nicolascoolman.webs.com/apps/blog/show/28060597-pup-dealply =>PUP.DealPly
~ http://nicolascoolman.webs.com/apps/blog/show/27583526-pup-crossrider =>PUP.CrossRider
~ MSI: 5 link(s) detected in 00mn 24s



~ 2748 Legitimates filtered by white list
End of the scan (639 lines in 11mn 55s)(2)

---------- Bericht toegevoegd op 21:07 ---------- Vorige bericht was op 17:04 ----------

ik gebruik steeds meteen venster snelle reactie, maar na copy van een log en klik op snel reageren krijg ik steeds vraag wilt u pagina blijven/verlaten.
klik op verlaten, geberud er niets. druk dan opf5 en weer die vraag
klik dan op verlaten dan lukt het wel, maar staat mijn reactie 2x op het forum.
Kanik (vermoed ik) beter onder vorig bericht klikken op Reageren ??
Of maakt dat niets uit ?

voor zekerheid maak ik nu gebruik van uitgebreide edtor, kan dat helpen ?
 
Re: Nation Zoom opent in IE en in Chrome Niet te verwijderen.

Ga nu eerst Start>Configuratiescherm>Programma's en onderdelen
en verwijder daar:

a) WpManager
b) SpyHunter
c) DealPly
d) CrossRider
 
Re: Nation Zoom opent in IE en in Chrome Niet te verwijderen.

Hallo Abraham
Spyhunter had ik al verwijderd, ging niet zo vlotjes, maar na reboot lukte het.
De andere drie zijn niet te vinden in de lijst.
 
Re: Nation Zoom opent in IE en in Chrome Niet te verwijderen.

Download SystemLook.exe voor 32-bit- dan wel 64-bit Windows
  • Download het bestand naar het Bureaublad.

SystemLook.exe opstarten:
  • Windows 2000 en Windows XP: start SystemLook.exe middels dubbelklik op de snelkoppeling.
  • Windows Vista, Windows 7 en Windows 8: start SystemLook.exe middels rechtsklik op de snelkoppeling en dan kiezen voor "Als Administrator uitvoeren".
In het venster dat opent kopieer je onderstaande code:
Code:
[color=#0000FF][b][SIZE="4"]
:folderfind
WPM
SpyHunter
DealPly
CrossRider
nationzoom
:filefind
nationzoom[/SIZE][/b][/color]
  • Klik op de knop "Look" om de scan te activeren.
  • Als de scan klaar is opent een tekstbestand (SystemLook.txt).
  • Post de inhoud van dit logbestand.
 
Re: Nation Zoom opent in IE en in Chrome Niet te verwijderen.

resultaat is helaas niet echt bemoedigend lijkt me:

SystemLook 30.07.11 by jpshortstuff
Log created at 12:28 on 11/12/2013 by Chris
Administrator - Elevation successful

========== folderfind ==========

Searching for "WPM"
C:\ProgramData\WPM d------ [01:03 09/12/2013]

Searching for "SpyHunter"
No folders found.

Searching for "DealPly"
No folders found.

Searching for "CrossRider"
No folders found.

Searching for "nationzoom"
No folders found.

========== filefind ==========

Searching for "nationzoom"
No files found.

-= EOF =-

---------- Bericht toegevoegd op 15:15 ---------- Vorige bericht was op 14:15 ----------

heb nog even gekeken wat er in zhpdiag stond over wpmanager
moest staan in program data wpm
maar daarin staat alleen folder update en die is leeg.
 
Laatst bewerkt door een moderator:
Re: Nation Zoom opent in IE en in Chrome Niet te verwijderen.

Download
51e7051a0eb2f-HitmanPro_iconCanned.jpg
32 of 64 bit versie van HitmanPro
Downloadlokatie: Dit programma absoluut naar het bureaublad downloaden of anders naar het bureaublad verplaatsen!
Klik hier voor een uitgebreide handleiding van HitmanPro.

  • Houd de linker CTRL toets ingedrukt en dubbelklik op "HitmanPro36.exe" om de "Force Breach" te starten en klik op "volgende" als HitmanPro de processen heeft geblokkeerd.
  • Vink de optie "Ik accepteer de voorwaarden van de gebruikersovereenkomst aan" en klik op "Volgende"
  • Klik in het setup scherm nu nogmaals op "Volgende", nu zal automatisch de scan starten, doe verder niets op de computer totdat de scan gereed is.
  • Als de scan klaar is klik je op "volgende"
  • Activeer nu de gratis licentie, hiermee kunt u 30 dagen gratis HitmanPro gebruiken en de gevonden infecties verwijderen.
  • Note: indien u reeds eerder gebruik hebt gemaakt van de 30 dagen trial-versie van HitmanPro is het niet meer mogelijk om gratis de gevonden infecties te verwijderen.
  • Als het verwijderen gereed is klik je onderin het scherm op "Save log" of "Logbestand opslaan" en sla deze op bijvoorbeeld het bureaublad op.
    Post dit logje.
  • Klik nu op de knop "Herstarten".
 
Re: Nation Zoom opent in IE en in Chrome Niet te verwijderen.

duurde even, zit ziek thuis, iets aan mijn heup, waardoor ik slecht slaap. Zal verwijzing naar orthopeed worden, vandaar dat ik maar zo af en toe bij mijn pc zit.maar hierbij het log bestand, is wel vergeven van rocketfuel - mobogenie.
moet in 2x vanwege melding
De ingevoerde tekst is te lang (152157). Verkort de tekst tot maximaal 140000 tekens.

Code:
HitmanPro 3.7.8.208
www.hitmanpro.com

   Computer name . . . . : CHRIS-HP
   Windows . . . . . . . : 6.1.1.7601.X64/6
   User name . . . . . . : Chris-HP\Chris
   UAC . . . . . . . . . : Enabled
   License . . . . . . . : Trial (30 days left)

   Scan date . . . . . . : 2013-12-12 04:39:14
   Scan mode . . . . . . : Normal
   Scan duration . . . . : 6m 16s
   Disk access mode  . . : Direct disk access (SRB)
   Cloud . . . . . . . . : Internet
   Reboot  . . . . . . . : No

   Threats . . . . . . . : 0
   Traces  . . . . . . . : 1082

   Objects scanned . . . : 3.072.348
   Files scanned . . . . : 294.787
   Remnants scanned  . . : 1.488.342 files / 1.289.219 keys

Potential Unwanted Programs _________________________________________________

   C:\Program Files (x86)\Mobogenie\ (Rocketfuel)
   C:\Program Files (x86)\Mobogenie\mgusb.exe (Rocketfuel)
      Size . . . . . . . : 88.256 bytes
      Age  . . . . . . . : 3.1 days (2013-12-09 02:03:41)
      Entropy  . . . . . : 6.3
      SHA-256  . . . . . : AD59BA08A3C4828E5B1129903FDCCD5E28F5D430A960A9CC417BBB678ED90076
      RSA Key Size . . . : 2048
      Authenticode . . . : Valid
      Fuzzy  . . . . . . : -7.0
      Forensic Cluster
         -6.5s C:\AdwCleaner\Quarantine\C\Windows\System32\Tasks\Desk 365 RunAsStdUser.vir
         -4.8s C:\Program Files (x86)\Mobogenie\
         -4.5s C:\Program Files (x86)\Mobogenie\templates\
         -4.5s C:\Program Files (x86)\Mobogenie\templates\web\
         -4.5s C:\Program Files (x86)\Mobogenie\templates\web\dialog\
         -2.3s C:\Program Files (x86)\Mobogenie\templates\web\js_\
         -2.3s C:\Program Files (x86)\Mobogenie\templates\web\js_\
         -2.0s C:\Program Files (x86)\Mobogenie\templates\web\js_\i18n\
         -2.0s C:\Program Files (x86)\Mobogenie\templates\web\dialog\js_\
         -2.0s C:\Program Files (x86)\Mobogenie\templates\web\dialog\js_\i18n\
         -0.6s C:\Program Files (x86)\Mobogenie\templates\web\js_\i18n\语言名称.txt
         -0.6s C:\Program Files (x86)\Mobogenie\templates\web\dialog\js_\i18n\语言名称.txt
          0.0s C:\Program Files (x86)\Mobogenie\mgusb.exe

   C:\Program Files (x86)\Mobogenie\New_UpdateMoboGenie.exe (Rocketfuel)
      Size . . . . . . . : 651.456 bytes
      Age  . . . . . . . : 3.1 days (2013-12-09 02:05:00)
      Entropy  . . . . . : 6.6
      SHA-256  . . . . . : 9041E3A08A068DBAE6999320A9D909EF78478CC2C4D9E4B7F702A3C7D2007049
      RSA Key Size . . . : 2048
      Authenticode . . . : Valid
      Fuzzy  . . . . . . : -7.0

   C:\Program Files (x86)\Mobogenie\ok.htm (Rocketfuel)
   C:\Program Files (x86)\Mobogenie\release-update.xml (Rocketfuel)
   C:\Program Files (x86)\Mobogenie\templates\web\dialog\js_\i18n\ (Rocketfuel)
   C:\Program Files (x86)\Mobogenie\templates\web\dialog\js_\i18n\语言名称.txt (Rocketfuel)
   C:\Program Files (x86)\Mobogenie\templates\web\js_\i18n\ (Rocketfuel)
   C:\Program Files (x86)\Mobogenie\templates\web\js_\i18n\语言名称.txt (Rocketfuel)
   C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Default\Extensions\cekcjpgehmohobmdiikfnopibipmgnml\ (iPumper)
   C:\Users\Chris\AppData\Local\Mobogenie\ (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\client.time (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Data\ (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Data\mobogenie_u_user_dl.mg (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\driverresult.log (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\mobo.uuid (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Source.mu (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\ (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie2.1.32.zip (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\ (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\aapt.exe (Rocketfuel)
      Size . . . . . . . : 852.160 bytes
      Age  . . . . . . . : 3.1 days (2013-12-09 02:05:00)
      Entropy  . . . . . : 6.6
      SHA-256  . . . . . : DF39103525D353F7AA5834543CC0F87190FABB8FE6BE238CEC7C1DBB626C5D1D
      RSA Key Size . . . : 2048
      Authenticode . . . : Valid
      Fuzzy  . . . . . . : 1.0

   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\AutoItX3.dll (Rocketfuel)
      Size . . . . . . . : 325.376 bytes
      Age  . . . . . . . : 3.1 days (2013-12-09 02:05:00)
      Entropy  . . . . . : 6.6
      SHA-256  . . . . . : B53A2FC2E9DB2C061E271554B7DC5008BCE2E375B9D20EECC25826AE169F2927
      Product  . . . . . : AutoIt v3 ActiveX Control
      Publisher  . . . . : AutoIt Team
      Description  . . . : AutoIt v3 ActiveX Control
      Version  . . . . . : 3.3.8.1
      Copyright  . . . . : ?1999-2012 Jonathan Bennett & AutoIt Team
      RSA Key Size . . . : 2048
      Authenticode . . . : Valid
      Fuzzy  . . . . . . : -5.0

   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\AutoItX3_x64.dll (Rocketfuel)
      Size . . . . . . . : 382.208 bytes
      Age  . . . . . . . : 3.1 days (2013-12-09 02:05:00)
      Entropy  . . . . . : 6.3
      SHA-256  . . . . . : 64B60C192709CE3F0F96673146997D616B407E982F96A1F10350D9D22D5F7102
      Product  . . . . . : AutoIt v3 ActiveX Control
      Publisher  . . . . : AutoIt Team
      Description  . . . : AutoIt v3 ActiveX Control
      Version  . . . . . : 3.3.8.1
      Copyright  . . . . : ?1999-2012 Jonathan Bennett & AutoIt Team
      RSA Key Size . . . : 2048
      Authenticode . . . : Valid
      Fuzzy  . . . . . . : -5.0

   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\configure.mu (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\CrashReport.exe (Rocketfuel)
      Size . . . . . . . : 460.480 bytes
      Age  . . . . . . . : 3.1 days (2013-12-09 02:05:00)
      Entropy  . . . . . : 6.7
      SHA-256  . . . . . : F7EC39471DEFB4BE93B7B8B465F556FF914CEBFBD040386EEC2B940163C1A257
      Product  . . . . . :  CrashReport
      Publisher  . . . . : Changyou.com limited
      Description  . . . : CrashRepoprt
      Version  . . . . . : 0.0.1.8
      Copyright  . . . . : (C) 2008-2012 Changyou.com Limited.All Rights Reserved
      RSA Key Size . . . : 2048
      Authenticode . . . : Valid
      Fuzzy  . . . . . . : -5.0

   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\CrashRpt.dll (Rocketfuel)
      Size . . . . . . . : 111.296 bytes
      Age  . . . . . . . : 3.1 days (2013-12-09 02:05:00)
      Entropy  . . . . . : 6.5
      SHA-256  . . . . . : E3BF0A444BEE9D2BB1522F9AA6233CE8819D3742DA9CC2223A179F15700CA103
      Product  . . . . . : TODO: <Product name>
      Publisher  . . . . : changyou
      Description  . . . : CrashReport动态版本
      Version  . . . . . : 0.0.1.8
      Copyright  . . . . : Copyright (C) 2012
      RSA Key Size . . . : 2048
      Authenticode . . . : Valid
      Fuzzy  . . . . . . : -5.0

   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\DaemonProcess.exe (Rocketfuel)
      Size . . . . . . . : 747.712 bytes
      Age  . . . . . . . : 3.1 days (2013-12-09 02:05:00)
      Entropy  . . . . . : 6.6
      SHA-256  . . . . . : A498208852B1E0B2A67CA66E481BC20AAF6736665FCD91F46A7BB4D06142A422
      RSA Key Size . . . : 2048
      Authenticode . . . : Valid
      Fuzzy  . . . . . . : 1.0

   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\devcon_x64.exe (Rocketfuel)
      Size . . . . . . . : 85.696 bytes
      Age  . . . . . . . : 3.1 days (2013-12-09 02:05:00)
      Entropy  . . . . . : 5.1
      SHA-256  . . . . . : 6326091F6EED13FD809A4F76386B91B06BDF4527F7F817E1EFF225D9AABE791A
      Product  . . . . . : Microsoft? Windows? Operating System
      Publisher  . . . . : Microsoft Corporation
      Description  . . . : Windows Setup API
      Version  . . . . . : 6.1.7600.16385
      Copyright  . . . . : ? Microsoft Corporation. All rights reserved.
      RSA Key Size . . . : 2048
      Authenticode . . . : Valid
      Fuzzy  . . . . . . : -5.0

   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\devcon_x86.exe (Rocketfuel)
      Size . . . . . . . : 81.600 bytes
      Age  . . . . . . . : 3.1 days (2013-12-09 02:05:00)
      Entropy  . . . . . : 5.2
      SHA-256  . . . . . : F813ED582075E16349472570F25999ED9F5B43FC7B91A2138003FCFA0B886F07
      Product  . . . . . : Microsoft? Windows? Operating System
      Publisher  . . . . : Microsoft Corporation
      Description  . . . : Windows Setup API
      Version  . . . . . : 6.1.7600.16385
      Copyright  . . . . : ? Microsoft Corporation. All rights reserved.
      RSA Key Size . . . : 2048
      Authenticode . . . : Valid
      Fuzzy  . . . . . . : -5.0

   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\DriverInstall_x64.exe (Rocketfuel)
      Size . . . . . . . : 322.752 bytes
      Age  . . . . . . . : 3.1 days (2013-12-09 02:05:00)
      Entropy  . . . . . : 6.3
      SHA-256  . . . . . : 2E741E1172D7A389B4419EB4DD5234C8614E78A9B3D638CC3E11C59F01431510
      RSA Key Size . . . : 2048
      Authenticode . . . : Valid
      Fuzzy  . . . . . . : 1.0

   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\DriverInstall_x86.exe (Rocketfuel)
      Size . . . . . . . : 271.040 bytes
      Age  . . . . . . . : 3.1 days (2013-12-09 02:05:00)
      Entropy  . . . . . : 6.6
      SHA-256  . . . . . : 9EEFD0D19D57226A90A7EFB23A8A46FE19B8962CB6761D35AC992EA76F6A2A96
      RSA Key Size . . . : 2048
      Authenticode . . . : Valid
      Fuzzy  . . . . . . : 1.0

   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\imageformats\ (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\imageformats\qgif4.dll (Rocketfuel)
      Size . . . . . . . : 26.624 bytes
      Age  . . . . . . . : 3.1 days (2013-12-09 02:05:00)
      Entropy  . . . . . : 6.0
      SHA-256  . . . . . : 8DB40AF7DB8905F8A8D09B47F4DDD92DA98D43339E0ED1A8DED16F5DCB4435A7
      Product  . . . . . : Qt4
      Publisher  . . . . : Nokia Corporation and/or its subsidiary(-ies)
      Description  . . . : C++ application development framework.
      Version  . . . . . : 4.8.3.0
      Copyright  . . . . : Copyright (C) 2012 Nokia Corporation and/or its subsidiary(-ies).
      Fuzzy  . . . . . . : 2.0

   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\imageformats\qico4.dll (Rocketfuel)
      Size . . . . . . . : 28.672 bytes
      Age  . . . . . . . : 3.1 days (2013-12-09 02:05:00)
      Entropy  . . . . . : 6.1
      SHA-256  . . . . . : 012BA162D24775627826794A8AACD0DC42BCFE15A4A134D42E268F1A6601FB09
      Product  . . . . . : Qt4
      Publisher  . . . . : Nokia Corporation and/or its subsidiary(-ies)
      Description  . . . : C++ application development framework.
      Version  . . . . . : 4.8.3.0
      Copyright  . . . . : Copyright (C) 2012 Nokia Corporation and/or its subsidiary(-ies).
      Fuzzy  . . . . . . : 2.0

   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\imageformats\qjpeg4.dll (Rocketfuel)
      Size . . . . . . . : 201.216 bytes
      Age  . . . . . . . : 3.1 days (2013-12-09 02:05:00)
      Entropy  . . . . . : 6.5
      SHA-256  . . . . . : 3F51A82CE27FEBC2B411925A449B9D3B8EF91D081D61559A580389306AF22D77
      Product  . . . . . : Qt4
      Publisher  . . . . : Nokia Corporation and/or its subsidiary(-ies)
      Description  . . . : C++ application development framework.
      Version  . . . . . : 4.8.3.0
      Copyright  . . . . : Copyright (C) 2012 Nokia Corporation and/or its subsidiary(-ies).
      Fuzzy  . . . . . . : 2.0

   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\imageformats\qmng4.dll (Rocketfuel)
      Size . . . . . . . : 222.208 bytes
      Age  . . . . . . . : 3.1 days (2013-12-09 02:05:00)
      Entropy  . . . . . : 6.6
      SHA-256  . . . . . : 76E6DB525229610BD7D7660E9B9BAC3B2756C92132152E5078F7D7E2E78C0640
      Product  . . . . . : Qt4
      Publisher  . . . . : Nokia Corporation and/or its subsidiary(-ies)
      Description  . . . : C++ application development framework.
      Version  . . . . . : 4.8.3.0
      Copyright  . . . . : Copyright (C) 2012 Nokia Corporation and/or its subsidiary(-ies).
      Fuzzy  . . . . . . : 2.0

   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\imageformats\qsvg4.dll (Rocketfuel)
      Size . . . . . . . : 21.504 bytes
      Age  . . . . . . . : 3.1 days (2013-12-09 02:05:00)
      Entropy  . . . . . : 5.9
      SHA-256  . . . . . : 3611EF453FF5F99B738B22C92C90C1EE2F5C98D6E2B1B5F2828C080A7B469894
      Product  . . . . . : Qt4
      Publisher  . . . . : Nokia Corporation and/or its subsidiary(-ies)
      Description  . . . : C++ application development framework.
      Version  . . . . . : 4.8.3.0
      Copyright  . . . . : Copyright (C) 2012 Nokia Corporation and/or its subsidiary(-ies).
      Fuzzy  . . . . . . : 2.0

   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\imageformats\qtga4.dll (Rocketfuel)
      Size . . . . . . . : 19.968 bytes
      Age  . . . . . . . : 3.1 days (2013-12-09 02:05:00)
      Entropy  . . . . . : 5.9
      SHA-256  . . . . . : DF6C56AA679B05CD0F2C9BD58574B1AE9D3E9A304FDA8591999216FF9C357356
      Product  . . . . . : Qt4
      Publisher  . . . . : Nokia Corporation and/or its subsidiary(-ies)
      Description  . . . : C++ application development framework.
      Version  . . . . . : 4.8.3.0
      Copyright  . . . . : Copyright (C) 2012 Nokia Corporation and/or its subsidiary(-ies).
      Fuzzy  . . . . . . : 2.0

   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\imageformats\qtiff4.dll (Rocketfuel)
      Size . . . . . . . : 287.232 bytes
      Age  . . . . . . . : 3.1 days (2013-12-09 02:05:00)
      Entropy  . . . . . : 5.6
      SHA-256  . . . . . : 617F7E64A0AEFDD162A8E4747344F7ABD7D05A631FC3B14A7647B5C7B678285A
      Product  . . . . . : Qt4
      Publisher  . . . . : Nokia Corporation and/or its subsidiary(-ies)
      Description  . . . : C++ application development framework.
      Version  . . . . . : 4.8.3.0
      Copyright  . . . . : Copyright (C) 2012 Nokia Corporation and/or its subsidiary(-ies).
      Fuzzy  . . . . . . : 2.0

   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\lang.mu (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\libeay32.dll (Rocketfuel)
      Size . . . . . . . : 1.178.624 bytes
      Age  . . . . . . . : 3.1 days (2013-12-09 02:05:00)
      Entropy  . . . . . : 6.8
      SHA-256  . . . . . : B2F7887AE0BD418724EB32D3449197551A0895F2C764A933A7BD984F187EAB78
      Product  . . . . . : The OpenSSL Toolkit
      Publisher  . . . . : The OpenSSL Project, http://www.openssl.org/
      Description  . . . : OpenSSL Shared Library
      Version  . . . . . : 1.0.1e
      Copyright  . . . . : Copyright ? 1998-2005 The OpenSSL Project. Copyright ? 1995-1998 Eric A. Young, Tim J. Hudson. All rights reserved.
      Fuzzy  . . . . . . : 2.0

   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\log\ (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\log\2013-11-22.log (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\log\action.log (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\lsusb.exe (Rocketfuel)
      Size . . . . . . . : 36.544 bytes
      Age  . . . . . . . : 3.1 days (2013-12-09 02:05:00)
      Entropy  . . . . . : 6.6
      SHA-256  . . . . . : 12FED85F536958102DC22C103FD5E3C4CE35653DB22A3C0137FAF28086D35CAE
      RSA Key Size . . . : 2048
      Authenticode . . . : Valid
      Fuzzy  . . . . . . : 1.0

   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\mgadb.exe (Rocketfuel)
      Size . . . . . . . : 4.356.616 bytes
      Age  . . . . . . . : 3.1 days (2013-12-09 02:05:00)
      Entropy  . . . . . : 5.9
      SHA-256  . . . . . : EE20DFA59A8AD5F2DACAF2A6C13EC23B97A38E65F675E62803711DC0F6560B5B
      RSA Key Size . . . : 2048
      Authenticode . . . : Valid
      Fuzzy  . . . . . . : 1.0

   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\mgusb.exe (Rocketfuel)
      Size . . . . . . . : 88.256 bytes
      Age  . . . . . . . : 3.1 days (2013-12-09 02:05:00)
      Entropy  . . . . . : 6.3
      SHA-256  . . . . . : AD59BA08A3C4828E5B1129903FDCCD5E28F5D430A960A9CC417BBB678ED90076
      RSA Key Size . . . : 2048
      Authenticode . . . : Valid
      Fuzzy  . . . . . . : 1.0

   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\mobileu_chinese.qm (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\mobileu_traditional.qm (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\mobileu_vietnamese.qm (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\mobogenie.apk (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\Mobogenie.exe (Rocketfuel)
      Size . . . . . . . : 7.093.440 bytes
      Age  . . . . . . . : 3.1 days (2013-12-09 02:05:00)
      Entropy  . . . . . : 5.9
      SHA-256  . . . . . : B9B3C4C8B68BF6BADF9BF348A0C0F6B906262B85B824D62B3818AC46E6473068
      RSA Key Size . . . : 2048
      Authenticode . . . : Valid
      Fuzzy  . . . . . . : 1.0

   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\Mobogenie.url (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\MUServer.apk (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\New_UpdateMoboGenie.exe (Rocketfuel)
      Size . . . . . . . : 651.456 bytes
      Age  . . . . . . . : 3.1 days (2013-12-09 02:05:02)
      Entropy  . . . . . : 6.6
      SHA-256  . . . . . : 9041E3A08A068DBAE6999320A9D909EF78478CC2C4D9E4B7F702A3C7D2007049
      RSA Key Size . . . : 2048
      Authenticode . . . : Valid
      Fuzzy  . . . . . . : 1.0

   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\OutlookOperatorC.exe (Rocketfuel)
      Size . . . . . . . : 579.776 bytes
      Age  . . . . . . . : 3.1 days (2013-12-09 02:05:00)
      Entropy  . . . . . : 5.6
      SHA-256  . . . . . : 872D989A96810CD1516748D503296347BE6C82751E4F3249A9D1DD15DAA1B114
      RSA Key Size . . . : 2048
      Authenticode . . . : Valid
      Fuzzy  . . . . . . : 1.0

   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\phonon4.dll (Rocketfuel)
      Size . . . . . . . : 270.848 bytes
      Age  . . . . . . . : 3.1 days (2013-12-09 02:05:00)
      Entropy  . . . . . : 6.5
      SHA-256  . . . . . : 9D356212E9FA05A72B377C169E9AB5DAF4F6D300F744F164343970666D66DA80
      Product  . . . . . : Qt4
      Publisher  . . . . : Nokia Corporation and/or its subsidiary(-ies)
      Description  . . . : C++ application development framework.
      Version  . . . . . : 4.4.0.0
      Copyright  . . . . : Copyright (C) 2012 Nokia Corporation and/or its subsidiary(-ies).
      Fuzzy  . . . . . . : 2.0

   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\phonon_backend\ (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\phonon_backend\phonon_ds94.dll (Rocketfuel)
      Size . . . . . . . : 197.120 bytes
      Age  . . . . . . . : 3.1 days (2013-12-09 02:05:00)
      Entropy  . . . . . : 6.4
      SHA-256  . . . . . : C7F8DD0B0CBA135EEE6C145C10D041C4463A81E11FB965F2DA6D931CF28A257D
      Product  . . . . . : Qt4
      Publisher  . . . . : Nokia Corporation and/or its subsidiary(-ies)
      Description  . . . : C++ application development framework.
      Version  . . . . . : 4.8.3.0
      Copyright  . . . . : Copyright (C) 2012 Nokia Corporation and/or its subsidiary(-ies).
      Fuzzy  . . . . . . : 2.0

   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\QtCore4.dll (Rocketfuel)
      Size . . . . . . . : 2.576.384 bytes
      Age  . . . . . . . : 3.1 days (2013-12-09 02:05:00)
      Entropy  . . . . . : 6.6
      SHA-256  . . . . . : 182C0AB9EA5948E2F71A04CFAFCC352213F82B9FCE6A4FE373AF61108C196177
      Product  . . . . . : Qt4
      Publisher  . . . . : Nokia Corporation and/or its subsidiary(-ies)
      Description  . . . : C++ application development framework.
      Version  . . . . . : 4.8.3.0
      Copyright  . . . . : Copyright (C) 2012 Nokia Corporation and/or its subsidiary(-ies).
      Fuzzy  . . . . . . : 2.0

   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\QtGui4.dll (Rocketfuel)
      Size . . . . . . . : 8.571.392 bytes
      Age  . . . . . . . : 3.1 days (2013-12-09 02:05:00)
      Entropy  . . . . . : 6.7
      SHA-256  . . . . . : 9E4B5D153FD6B1FFAD6F8585D74E4EBFFD38BA45454E5BBE169ACC5E5929F8BD
      Product  . . . . . : Qt4
      Publisher  . . . . : Nokia Corporation and/or its subsidiary(-ies)
      Description  . . . : C++ application development framework.
      Version  . . . . . : 4.8.3.0
      Copyright  . . . . : Copyright (C) 2012 Nokia Corporation and/or its subsidiary(-ies).
      Fuzzy  . . . . . . : 2.0

   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\QtNetwork4.dll (Rocketfuel)
      Size . . . . . . . : 1.052.160 bytes
      Age  . . . . . . . : 3.1 days (2013-12-09 02:05:01)
      Entropy  . . . . . : 6.5
      SHA-256  . . . . . : D5723C58E349E855E6EB6235FFB298F6357AA01C4A825E686891F6B5BF24A53B
      Product  . . . . . : Qt4
      Publisher  . . . . : Nokia Corporation and/or its subsidiary(-ies)
      Description  . . . : C++ application development framework.
      Version  . . . . . : 4.8.3.0
      Copyright  . . . . : Copyright (C) 2012 Nokia Corporation and/or its subsidiary(-ies).
      Fuzzy  . . . . . . : 2.0

   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\QtSql4.dll (Rocketfuel)
      Size . . . . . . . : 201.728 bytes
      Age  . . . . . . . : 3.1 days (2013-12-09 02:05:01)
      Entropy  . . . . . : 6.5
      SHA-256  . . . . . : A6B038FEFB6A48B76DF34F8628D08DE5CEB1E9E105993CB2570CEA7A1C243B25
      Product  . . . . . : Qt4
      Publisher  . . . . : Nokia Corporation and/or its subsidiary(-ies)
      Description  . . . : C++ application development framework.
      Version  . . . . . : 4.8.3.0
      Copyright  . . . . : Copyright (C) 2012 Nokia Corporation and/or its subsidiary(-ies).
      Fuzzy  . . . . . . : 2.0

   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\QtWebKit4.dll (Rocketfuel)
      Size . . . . . . . : 13.109.248 bytes
      Age  . . . . . . . : 3.1 days (2013-12-09 02:05:01)
      Entropy  . . . . . : 6.7
      SHA-256  . . . . . : 1C70723E7D34DEA0BDCB53F15EC7E0C34643EE6C293773465E2934C9BE2EF86D
      Product  . . . . . : Qt4
      Publisher  . . . . : Nokia Corporation and/or its subsidiary(-ies)
      Description  . . . : C++ application development framework.
      Version  . . . . . : 4.9.3.0
      Copyright  . . . . : Copyright (C) 2012 Nokia Corporation and/or its subsidiary(-ies).
      Fuzzy  . . . . . . : 2.0

   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\shortcut.ico (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\Source.mu (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\sqldrivers\ (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\sqldrivers\qsqlite4.dll (Rocketfuel)
      Size . . . . . . . : 470.528 bytes
      Age  . . . . . . . : 3.1 days (2013-12-09 02:05:01)
      Entropy  . . . . . : 6.7
      SHA-256  . . . . . : 007FD69560CDDBC60F264EBC3DF7E8D9E3BFB4F66E227DE114E48B6685E0EF15
      Product  . . . . . : Qt4
      Publisher  . . . . : Nokia Corporation and/or its subsidiary(-ies)
      Description  . . . : C++ application development framework.
      Version  . . . . . : 4.8.3.0
      Copyright  . . . . : Copyright (C) 2012 Nokia Corporation and/or its subsidiary(-ies).
      Fuzzy  . . . . . . : 2.0

   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\ssleay32.dll (Rocketfuel)
      Size . . . . . . . : 269.824 bytes
      Age  . . . . . . . : 3.1 days (2013-12-09 02:05:01)
      Entropy  . . . . . : 6.4
      SHA-256  . . . . . : 1E6FB714037D30A6809AC7D1A46F63A8BB858BF33C97AFAA3DDA0D42C337DDEC
      Product  . . . . . : The OpenSSL Toolkit
      Publisher  . . . . : The OpenSSL Project, http://www.openssl.org/
      Description  . . . : OpenSSL Shared Library
      Version  . . . . . : 1.0.1e
      Copyright  . . . . : Copyright ? 1998-2005 The OpenSSL Project. Copyright ? 1995-1998 Eric A. Young, Tim J. Hudson. All rights reserved.
      Fuzzy  . . . . . . : 2.0

   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\StaConfig.mu (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\css\ (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\css\main.css (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\javascript\doT-master\ (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\javascript\doT-master\benchmarks\ (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\javascript\doT-master\benchmarks\compileBench.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\javascript\doT-master\benchmarks\genspeed.html (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\javascript\doT-master\benchmarks\index.html (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\javascript\doT-master\benchmarks\jslitmus.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\javascript\doT-master\benchmarks\templatesBench.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\javascript\doT-master\benchmarks\templating\ (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\javascript\doT-master\benchmarks\templating\doT.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\javascript\doT-master\benchmarks\templating\doU.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\javascript\doT-master\bin\ (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\javascript\doT-master\bin\dot-packer (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\javascript\doT-master\doT.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\javascript\doT-master\doT.min.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\javascript\doT-master\doU.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\javascript\doT-master\examples\ (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\javascript\doT-master\examples\advancedsnippet.txt (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\javascript\doT-master\examples\browsersample.html (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\javascript\doT-master\examples\customdoT.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\javascript\doT-master\examples\snippet.txt (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\javascript\doT-master\examples\views\ (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\javascript\doT-master\examples\views\multidef.def.jst (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\javascript\doT-master\examples\views\one.def (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\javascript\doT-master\examples\views\two.dot.jst (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\javascript\doT-master\examples\withdoT.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\javascript\doT-master\index.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\javascript\doT-master\LICENSE-DOT.txt (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\javascript\doT-master\package.json (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\javascript\doT-master\README.md (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\javascript\doT-master\test\ (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\javascript\doT-master\test\testdoT.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\javascript\libraries\ (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\javascript\libraries\bootstrap-typeahead.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\javascript\libraries\doT.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\javascript\libraries\ejs.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\javascript\libraries\ejs_production.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\javascript\libraries\jquery-1.8.3.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\javascript\libraries\jquery.prettyPhoto.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\javascript\libraries\undercore.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\ (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\app.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\app_hover.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\app_on.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\bigger.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\bigger_hover.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\bigger_on.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\border_top.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\bottom_bar.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\bottom_slider.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\bottomBar.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\bottomBar_46.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\close.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\close_hover.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\close_on.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\delete.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\download.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\downloading.gif (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\facebook.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\facebook_hover.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\facebook_on.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\feed.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\feed_hover.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\feed_on.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\feedback.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\feedback_hover.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\feedback_on.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\game.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\game_hover.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\game_on.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\geni.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\geni_hover.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\geni_on.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\google.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\google_hover.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\google_on.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\gphone.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\gphone_hover.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\gphone_on.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\header.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\home.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\home_hover.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\home_on.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\leftBar_20.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\leftBottom.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\leftBottom_44.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\leftTop.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\leftTop_03.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\logo.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\mode.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\more.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\more_hover.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\more_on.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\music.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\music_bg.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\music_hover.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\music_on.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\next.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\next_hover.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\next_on.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\normal.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\normal_hover.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\normal_on.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\pause.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\pause_hover.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\pause_on.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\phone.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\phone_hover.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\phone_on.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\picture.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\picture_hover.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\picture_on.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\play.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\play_hover.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\play_on.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\prev.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\prev_hover.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\prev_on.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\rightBar.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\rightBottom.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\rightBottom_48.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\rightTop.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\rightTop_07.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\sd_background.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\sd_background2.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\sd_btnDelete_disabled.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\sd_btnDelete_hover.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\sd_btnDelete_normal.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\sd_btnDelete_pressed.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\sd_btnExport_disabled.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\sd_btnExport_hover.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\sd_btnExport_normal.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\sd_btnExport_pressed.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\sd_btnImport_disabled.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\sd_btnImport_hover.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\sd_btnImport_normal.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\sd_btnImport_pressed.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\sd_btnLeft_disabled.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\sd_btnLeft_hover.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\sd_btnLeft_normal.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\sd_btnLeft_pressed.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\sd_btnNewDir_disabled.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\sd_btnNewDir_hover.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\sd_btnNewDir_normal.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\sd_btnNewDir_pressed.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\sd_btnRefresh_disabled.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\sd_btnRefresh_hover.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\sd_btnRefresh_normal.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\sd_btnRefresh_pressed.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\sd_btnRight_disabled.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\sd_btnRight_hover.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\sd_btnRight_normal.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\sd_btnRight_pressed.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\sd_close_hover.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\sd_close_normal.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\sd_close_pressed.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\sd_min_hover.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\sd_min_normal.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\sd_min_pressed.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\sd_title.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\search_bg.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\segment.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\small.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\small_hover.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\small_on.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\sound.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\sound_hover.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\sound_on.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\sound_slider_bg.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\sound_slider_bttn.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\split.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\Thumbs.db (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\top_bg.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\top_left_border.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\top_right_border.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\topBar_05.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\twitter.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\twitter_hover.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\twitter_on.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\video.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\video_hover.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\skin\default\video_on.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\ (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\css\ (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\css\app.css (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\css\bootstrap-typeahead.css (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\css\common.css (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\css\grid.css (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\css\image.css (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\css\jquery.autocomplete.css (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\css\main.css (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\css\message.css (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\css\prettyPhoto.css (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\css\style.css (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\css\vedio.css (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\ (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\add_web.html (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\backup_all.html (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\backup_status.html (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\backupAll.html (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\backupAll2.html (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\binding.html (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\close.html (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\collect_data.html (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\dialog.html (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\dm_backup.html (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\dm_installapp.html (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\download.html (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\download_center.html (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\driver_loading.html (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\exporting.html (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\images\ (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\images\an.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\images\animation_cicle.gif (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\images\animation_flower.gif (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\images\bd_phone.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\images\hx.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\images\images_156X167_1.jpg (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\images\images_156X167_151.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\images\images_156X167_2.jpg (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\images\images_156X167_3.jpg (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\images\pop1_11.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\images\pop2_03.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\images\pop3_07.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\images\Thumbs.db (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\images\ui-left-images.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\images\ui-right-images.png (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\import_from_file.html (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\import_from_file_v2.html (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\importing.html (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\install.html (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\install_failed.html (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\install_help.html (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\installing.html (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\ (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\arabic\ (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\arabic\app.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\arabic\barball.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\arabic\contact.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\arabic\download.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\arabic\iframe.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\arabic\message.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\arabic\music.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\arabic\picture.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\arabic\video.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\arabic\welcome.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\arabic\window.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\chinese\ (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\chinese\app.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\chinese\barball.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\chinese\contact.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\chinese\download.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\chinese\iframe.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\chinese\message.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\chinese\music.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\chinese\picture.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\chinese\video.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\chinese\welcome.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\chinese\window.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\english\ (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\english\app.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\english\barball.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\english\contact.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\english\download.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\english\iframe.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\english\message.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\english\music.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\english\picture.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\english\video.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\english\welcome.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\english\window.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\indonesian\ (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\indonesian\app.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\indonesian\barball.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\indonesian\contact.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\indonesian\download.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\indonesian\iframe.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\indonesian\message.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\indonesian\music.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\indonesian\picture.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\indonesian\video.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\indonesian\welcome.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\indonesian\window.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\italian\ (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\italian\app.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\italian\barball.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\italian\contact.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\italian\download.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\italian\iframe.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\italian\message.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\italian\music.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\italian\picture.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\italian\strings.xml (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\italian\video.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\italian\welcome.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\italian\window.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\language.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\poland\ (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\poland\app.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\poland\barball.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\poland\contact.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\poland\download.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\poland\iframe.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\poland\message.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\poland\music.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\poland\picture.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\poland\video.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\poland\welcome.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\poland\window.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\portuguese\ (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\portuguese\app.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\portuguese\barball.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\portuguese\contact.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\portuguese\download.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\portuguese\iframe.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\portuguese\message.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\portuguese\music.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\portuguese\picture.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\portuguese\video.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\portuguese\welcome.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\portuguese\window.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\russian\ (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\russian\app.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\russian\barball.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\russian\contact.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\russian\download.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\russian\iframe.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\russian\message.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\russian\music.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\russian\picture.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\russian\video.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\russian\welcome.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\russian\window.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\spanish\ (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\spanish\app.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\spanish\barball.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\spanish\contact.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\spanish\download.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\spanish\iframe.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\spanish\message.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\spanish\music.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\spanish\picture.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\spanish\video.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\spanish\welcome.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\spanish\window.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\thai\ (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\thai\app.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\thai\barball.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\thai\contact.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\thai\download.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\thai\iframe.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\thai\message.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\thai\music.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\thai\picture.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\thai\video.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\thai\welcome.js (Rocketfuel)
   C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\thai\window.js (Rocketfuel)
 
Re: Nation Zoom opent in IE en in Chrome Niet te verwijderen.

C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\vietna\ (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\vietna\app.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\vietna\barball.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\vietna\contact.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\vietna\download.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\vietna\iframe.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\vietna\message.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\vietna\music.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\vietna\picture.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\vietna\video.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\vietna\welcome.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\vietna\window.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\js_\i18n\????????.txt (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\loading.html (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\manual-update.html (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\newsms.html (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\nomem.html (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\promote_active.html (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\recommend.html (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\recommend2.html (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\restore_all.html (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\restore_status.html (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\restoreAll.html (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\settings.html (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\speed.html (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\update_app.html (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\upgrade.html (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\usb.html (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\usb2.html (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\dialog\video_select.html (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\footer.html (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\htmlTemp\ (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\htmlTemp\app.html (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\htmlTemp\barball.html (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\htmlTemp\contact.html (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\htmlTemp\download.html (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\htmlTemp\download_center.html (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\htmlTemp\driver.html (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\htmlTemp\footer.html (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\htmlTemp\good.html (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\htmlTemp\message.html (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\htmlTemp\music.html (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\htmlTemp\picture.html (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\htmlTemp\pop.html (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\htmlTemp\vedio.html (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\htmlTemp\welcome.html (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\htmlTemp\welcome_ok.html (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\iframe\ (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\iframe\appIframe.html (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\iframe\barballframe.html (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\iframe\gameIframe.html (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\iframe\homeIframe.html (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\iframe\imagesIframe.html (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\iframe\musicIframe.html (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\iframe\tempframe.html (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\iframe\topIframe.html (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\iframe\videoIframe.html (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\ (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\an.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\AngryBirdsStarWarsIIFree.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\app-default-small.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\backup_complete.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\backup_default_app.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\backup_default_content.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\backup_default_image.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\backup_default_msg.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\backup_default_music.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\backup_default_video.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\backup_li_bg.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\backup_loading.gif (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\BarbaraPalvinVictorias.jpg (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\battery-bg.gif (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\BBM.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\bd_phone.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\bd_right.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\bizhi.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\Camera360.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\CarAbstract.jpg (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\cate-icon.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\category-bg.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\caution.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\charge_finish.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\check_usb_debug.jpg (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\CleanMasterFREE.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\complete.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\connceting.gif (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\connect-error.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\connect_gif.gif (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\connected.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\connecting.gif (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\connecting.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\connecting_default.gif (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\connection-error.gif (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\connection-guide-bg-300X300.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\connection-no.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\contact-default-large.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\contact-default-small.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\contact_icon.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\content_mask_1X35.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\dc_icon_03.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\dc_icon_06.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\dc_icon_07.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\dc_icon_09.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\dc_icon_11.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\dc_weak.gif (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\deamon_process_close.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\default_image.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\default_small_app.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\default_small_images.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\default_small_music.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\default_small_vedio.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\default_video.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\diwali-special.jpg (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\down-anima-bg-16X32.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\download_icon.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\download_progress.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\download_progress_inner.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\drive-arrows.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\driver-no-link.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\driver_bottom_hx.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\driver_download.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\driver_exclam.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\driver_failure.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\driver_install.gif (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\driver_installing_04.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\driver_installing_07.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\driver_leftbar_bg.jpg (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\driver_loading2.gif (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\driver_no_link.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\driver_phone_sd.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\driver_right_bg.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\driver_success.gif (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\driver_tabs_03.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\driver_tabs_05.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\driver_tabs_07.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\driver_tabs_09.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\driver_tabs_11.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\driver_tabs_13.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\driver_tabs_15.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\driver_tabs_17.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\driver_tabs_20.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\driver_tabs_23.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\error.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\expression.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\Facebook.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\facebook_bg.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\facebook_button.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\facebook_sidebar_button.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\fastcharge.gif (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\footer-download-default-icon_03.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\footer-note-center-loading.gif (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\footer_download_icon.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\free.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\getall.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\gl.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\head-replacement_img.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\HillClimbRacing.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\home_03.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\home_05.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\huise.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\hx.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\icon-box.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\icon-contact.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\icon-sdb.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\icon.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\icon_default_app_36X36.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\icon_default_ebook_36X36.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\icon_default_file_36X36.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\icon_default_music_36X36.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\icon_default_pic_36X36.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\icon_default_video_36X36.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\icon_indentation.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\icon_left_triangle.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\icon_open.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\icon_right_triangle.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\imageNavLeft-disabled.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\imageNavLeft.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\imageNavRight-disabled.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\imageNavRight.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\info_panel_bg_8X8.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\Instagram.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\install_phone.gif (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\issue.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\jindu.gif (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\jindushu.gif (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\left_box.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\light.gif (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\load-bg.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\load.gif (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\loading-logo.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\loading.gif (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\loading.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\loading_16.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\loading_16X16.gif (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\logo.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\LoveLips.jpg (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\lucky_bg.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\lvse.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\m-ui-deamon-process-button.jpg (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\m-ui-toolbar.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\manual-update-bg.jpg (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\menu_li_bottom_bg.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\message-contact.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\Minecraft.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\minus.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\mobogenie_load.gif (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\mobogenie_load_img.gif (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\more-web.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\no-connect.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\no_link_icon.jpg (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\no_link_icon.jpg.bak (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\note_default_icon.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\phone_version_icon.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\photo\ (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\photo\mp_botbut.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\photo\mp_button.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\photo\mp_close.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\photo\mp_del.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\photo\mp_look.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\photo\mp_notsel.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\photo\mp_rotatel.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\photo\mp_rotater.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\photo\mp_selected.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\photo\mp_set.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\photo\Thumbs.db (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\PlantsVsZombies2.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\playing_11X11.gif (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\plus.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\point.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\PouMyPet.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\prettyPhoto\dark_rounded\ (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\prettyPhoto\dark_rounded\btnNext.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\prettyPhoto\dark_rounded\btnPrevious.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\prettyPhoto\dark_rounded\contentPattern.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\prettyPhoto\dark_rounded\default_thumbnail.gif (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\prettyPhoto\dark_rounded\loader.gif (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\prettyPhoto\dark_rounded\sprite.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\prettyPhoto\dark_rounded\Thumbs.db (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\prettyPhoto\dark_square\ (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\prettyPhoto\dark_square\btnNext.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\prettyPhoto\dark_square\btnPrevious.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\prettyPhoto\dark_square\contentPattern.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\prettyPhoto\dark_square\default_thumbnail.gif (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\prettyPhoto\dark_square\loader.gif (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\prettyPhoto\dark_square\sprite.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\prettyPhoto\dark_square\Thumbs.db (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\prettyPhoto\default\ (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\prettyPhoto\default\default_thumb.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\prettyPhoto\default\loader.gif (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\prettyPhoto\default\sprite.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\prettyPhoto\default\sprite_next.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\prettyPhoto\default\sprite_prev.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\prettyPhoto\default\sprite_x.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\prettyPhoto\default\sprite_y.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\prettyPhoto\default\Thumbs.db (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\prettyPhoto\facebook\ (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\prettyPhoto\facebook\btnNext.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\prettyPhoto\facebook\btnPrevious.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\prettyPhoto\facebook\contentPatternBottom.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\prettyPhoto\facebook\contentPatternLeft.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\prettyPhoto\facebook\contentPatternRight.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\prettyPhoto\facebook\contentPatternTop.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\prettyPhoto\facebook\default_thumbnail.gif (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\prettyPhoto\facebook\loader.gif (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\prettyPhoto\facebook\setWallpaperHover.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\prettyPhoto\facebook\sprite.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\prettyPhoto\facebook\Thumbs.db (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\prettyPhoto\light_rounded\ (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\prettyPhoto\light_rounded\btnNext.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\prettyPhoto\light_rounded\btnPrevious.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\prettyPhoto\light_rounded\default_thumbnail.gif (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\prettyPhoto\light_rounded\loader.gif (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\prettyPhoto\light_rounded\sprite.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\prettyPhoto\light_rounded\Thumbs.db (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\prettyPhoto\light_square\ (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\prettyPhoto\light_square\btnNext.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\prettyPhoto\light_square\btnPrevious.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\prettyPhoto\light_square\default_thumbnail.gif (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\prettyPhoto\light_square\loader.gif (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\prettyPhoto\light_square\sprite.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\prettyPhoto\light_square\Thumbs.db (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\process.gif (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\process.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\progress_bg_10X4.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\progress_bg_18X6.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\right_bg_346X484.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\sanjiao.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\search-btn1.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\search-btn2.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\search_btn_message.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\shuaxin.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\SpeedMoto.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\spit.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\split.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\sprite3.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\sprite_icon.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\sprite_lucky.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\sprite_nav_icon.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\step_bg.jpg (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\step_bg2.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\step_image1_09.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\step_image2_03.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\SubwaySurfers.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\tabs_default.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\tabs_light.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\tag-icon.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\TalkingTomCat2Free.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\TempleRun2.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\Thumbs.db (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\tip-new-app.jpg (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\tip-new-ringtone-wallpaper.jpg (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\tips-restore.jpg (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\to_link_icon.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\TreePathWallpaper.jpg (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\tuijian.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\ui-left-images.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\ui-right-images.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\ui_header_bg.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\ui_header_bg2.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\ui_update_icon.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\usb-dbug.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\usb-link.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\versition_03.jpg (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\versition_05.jpg (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\versition_07.jpg (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\versition_09.jpg (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\versition_15.jpg (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\versition_17.jpg (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\versition_19.jpg (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\versition_24.jpg (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\versition_26.jpg (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\versition_28.jpg (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\versition_30.jpg (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\video-box2.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\video-icon.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\video-share.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\video_11.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\video_13.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\video_15.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\video_17.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\video_icon.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\website-logo.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\website.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\welcome_bg.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\welcome_bg_100X100.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\welcome_connect_phone_animate.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\welcome_icon.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\WhatsAppMessenger.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\youtube_b.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\images\ytb-button.png (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\index.html (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\ (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\ (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\arabic\ (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\arabic\app.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\arabic\barball.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\arabic\contact.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\arabic\download.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\arabic\iframe.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\arabic\message.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\arabic\music.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\arabic\picture.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\arabic\video.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\arabic\welcome.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\arabic\window.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\chinese\ (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\chinese\app.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\chinese\barball.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\chinese\contact.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\chinese\download.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\chinese\iframe.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\chinese\message.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\chinese\music.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\chinese\picture.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\chinese\video.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\chinese\welcome.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\chinese\window.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\english\ (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\english\app.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\english\barball.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\english\contact.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\english\download.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\english\iframe.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\english\message.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\english\music.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\english\picture.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\english\video.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\english\welcome.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\english\window.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\indonesian\ (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\indonesian\app.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\indonesian\barball.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\indonesian\contact.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\indonesian\download.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\indonesian\iframe.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\indonesian\message.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\indonesian\music.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\indonesian\picture.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\indonesian\video.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\indonesian\welcome.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\indonesian\window.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\italian\ (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\italian\app.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\italian\barball.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\italian\contact.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\italian\download.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\italian\iframe.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\italian\message.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\italian\music.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\italian\picture.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\italian\video.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\italian\welcome.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\italian\window.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\language.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\poland\ (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\poland\app.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\poland\barball.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\poland\contact.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\poland\download.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\poland\iframe.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\poland\message.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\poland\music.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\poland\picture.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\poland\video.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\poland\welcome.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\poland\window.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\portuguese\ (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\portuguese\app.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\portuguese\barball.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\portuguese\contact.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\portuguese\download.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\portuguese\iframe.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\portuguese\message.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\portuguese\music.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\portuguese\picture.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\portuguese\video.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\portuguese\welcome.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\portuguese\window.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\russian\ (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\russian\app.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\russian\barball.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\russian\contact.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\russian\download.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\russian\iframe.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\russian\message.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\russian\music.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\russian\picture.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\russian\video.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\russian\welcome.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\russian\window.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\spanish\ (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\spanish\app.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\spanish\barball.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\spanish\contact.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\spanish\download.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\spanish\iframe.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\spanish\message.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\spanish\music.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\spanish\picture.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\spanish\video.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\spanish\welcome.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\spanish\window.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\thai\ (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\thai\app.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\thai\barball.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\thai\contact.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\thai\download.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\thai\iframe.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\thai\message.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\thai\music.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\thai\picture.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\thai\video.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\thai\welcome.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\thai\window.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\vietna\ (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\vietna\app.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\vietna\barball.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\vietna\contact.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\vietna\download.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\vietna\iframe.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\vietna\message.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\vietna\music.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\vietna\picture.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\vietna\video.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\vietna\welcome.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\vietna\window.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\i18n\????????.txt (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\interface\ (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\interface\interface_app.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\interface\interface_contact.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\interface\interface_download.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\interface\interface_downloadCenter.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\interface\interface_image.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\interface\interface_message.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\interface\interface_vedio.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\interface\moduleInteface.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\lib\ (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\lib\backbone.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\lib\bootstrap-typeahead.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\lib\doT.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\lib\ejs.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\lib\eventProxy.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\lib\jcarousellite.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\lib\jquery-1.8.3.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\lib\jquery.jtips.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\lib\jquery.prettyPhoto.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\lib\require.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\lib\undercore.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\main.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\module\ (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\module\app\ (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\module\app\app_common.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\module\app\app_main.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\module\app\app_nav.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\module\app\app_right.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\module\app\app_temp.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\module\app\local_main.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\module\app\system_main.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\module\app\update_main.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\module\app\update_model.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\module\contact\ (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\module\contact\contact.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\module\contact\contact_letter.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\module\contact\contact_temp.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\module\download\ (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\module\download\download_common.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\module\download\download_dialog_common.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\module\download\download_dialog_main.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\module\download\download_dialog_nav.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\module\download\download_main.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\module\download\download_nav.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\module\download\download_temp.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\module\driver\ (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\module\driver\driver.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\module\image\ (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\module\image\image_common.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\module\image\image_main.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\module\image\image_nav.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\module\image\image_temp.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\module\message\ (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\module\message\message_common.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\module\message\message_main.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\module\message\message_main_weinan.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\module\message\message_nav.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\module\message\message_right.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\module\message\message_temp.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\module\message\messageDialog.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\module\music.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\module\subject\ (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\module\subject\subject.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\module\subject\subject_temp.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\module\ui\ (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\module\ui\super_grid.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\module\ui\test.html (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\module\vedio\ (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\module\vedio\vedio_common.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\module\vedio\vedio_main.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\module\vedio\vedio_nav.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\module\vedio\vedio_temp.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\module\vedio\video_temp.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\moduletemp\ (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\moduletemp\appTemp.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\moduletemp\contactTemp.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\moduletemp\downloadTemp.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\moduletemp\imageTemp.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\moduletemp\messageTemp.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\moduletemp\musicTemp.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\moduletemp\vedioTemp.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\moduletemp\videoTemp.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\pb\ (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\pb\config.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\TEMPHTML.html (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\tpls\ (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\tpls\addweb.ejs (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\tpls\app.html (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\tpls\app_local.ejs (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\tpls\app_system.ejs (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\tpls\app_update.ejs (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\tpls\Disclaimer.ejs (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\tpls\download_animate.ejs (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\tpls\download_center.ejs (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\tpls\download_center_installed.ejs (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\tpls\PrivacyPolicy.ejs (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\tpls\recommend.ejs (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\tpls\recommendNewUser.ejs (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\util\ (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\util\DB.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\util\DeviceUtil.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\util\dialog.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\util\dialog_pop.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\util\EventProxyCenter.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\util\I18nUtil.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\util\log.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\util\module.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\util\navigation.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\util\prograss.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\util\PropertyUtil.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\util\search.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\util\util.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\welcome\ (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\welcome\sysCallback.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_\welcome\welcome_ok.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_static\dialog\ (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_static\dialog\backup_all.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_static\dialog\restore_all.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_static\iframe\ (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_static\iframe\category_switch.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_static\iframe\download_animate.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_static\iframe\iframe_download.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_static\iframe\loading.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_static\iframe\lottery.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_static\iframe\recommed.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_static\iframe\recommend2.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_static\iframe\recommend3.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_static\iframe\recommendForNew.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_static\iframe\tab_switch\ (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_static\iframe\tab_switch\appTab.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_static\iframe\tab_switch\gameTab.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_static\iframe\tab_switch\genieTab.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_static\iframe\tab_switch\homeTab.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_static\iframe\tab_switch\imageTab.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_static\iframe\tab_switch\musicTab.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_static\iframe\tab_switch\phoneTab.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_static\iframe\tab_switch\vedioTab.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_static\info\ (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_static\info\connect\ (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_static\info\connect\connect.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_static\info\download\ (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_static\info\download\download.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_static\info\download\download_collection.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_static\info\download\download_model.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_static\info\download\download_view.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_static\info\notice\ (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_static\info\notice\notice.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\templates\web\js_static\info\webnotify.js (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\uninst.exe (Rocketfuel)
Size . . . . . . . : 130.923 bytes
Age . . . . . . . : 3.1 days (2013-12-09 02:05:02)
Entropy . . . . . : 7.5
SHA-256 . . . . . : B4C83FE9C2C4D3D6C687B51176690B394436A0CEF57F0F12626F86E904231AA9
Fuzzy . . . . . . : 12.0

C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\updateConfigure.mu (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\UpdateLogFile.dat (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\websites.mu (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\websites_cn.mu (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\websites_traditional.mu (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\websites_vie.mu (Rocketfuel)
C:\Users\Chris\AppData\Local\Mobogenie\Version\OldVersion\release-update.xml (Rocketfuel)
HKLM\SOFTWARE\Classes\Record\{2009AF2F-5786-3067-8799-B97F7832FDD6}\ (FLV Player)
HKLM\SOFTWARE\Classes\Record\{425E7597-03A2-338D-B72A-0E51FFE77A7E}\ (FLV Player)
HKLM\SOFTWARE\Classes\Record\{915BB7D5-082E-3B91-B1E0-45B5FDE01F24}\ (FLV Player)
HKLM\SOFTWARE\Classes\Record\{FB2E65F4-5687-33EF-9BBF-4E3C9C98D3B9}\ (FLV Player)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\MobogenieAdd\ (Rocketfuel)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3152E1F19977892449DC968802CE8964\ (FLV Player)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\649A52D257CA5DB4EAAE8BA9EB23E467\ (FLV Player)
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{21111111-1111-1111-1111-110011341191}\ (VidSaver)
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\App Paths\MobogenieAdd\ (Rocketfuel)
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\mobilegeni daemon (Rocketfuel)
HKU\S-1-5-21-54043301-2395897540-3358933016-1000\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration\{AE07101B-46D4-4A98-AF68-0333EA26E113} (FLV Player)


[/code]

---------- Bericht toegevoegd op 05:13 ---------- Vorige bericht was op 05:05 ----------

Ik ga intussen mobogenie maar verwijderen. Hoewel hitman aangaf dat er geen schadelijke software was aangetroffen.
Want ik dacht dat ik zo apps voor mijn galaxy tablet kon downloaden en via usb/bluetooth erop kon zetten.
Maar ik ben niet zo'n app-fan geworden voor dat tablet, dus zal ik dit progje ook niet gaan gebruiken.
en voorzie ook problemen om dat via de pc op mijn tablet te zetten.
gebruik dat ding alleen om te surfen en voor facebook, maar ja kreeg hem gratis bij abbo van zeelandnet.
 
Re: Nation Zoom opent in IE en in Chrome Niet te verwijderen.

Ik heb ook dat tool in een vorige Windows gehad en brand mijn vingers er niet meer aan!
Maar je hoofdprobleem is dus nog niet opgelost vermoed ik.

Graag de drie logs in ??n keer posten.

Stap •1•
Download
52186926180a1-adwcleaner_nieuw.png
AdwCleaner by Xplode.
Downloadlokatie: Dit programma absoluut naar het bureaublad downloaden of anders naar het bureaublad verplaatsen!
Opmerkingen:
  • Alle openstaande programma's en webpagina's dienen afgesloten te zijn.
AdwCleaner opstarten:
  • Windows 2000 en Windows XP: dubbelklik op adwcleaner.exe.
  • Windows Vista, Windows 7 en Windows 8: via rechtsklik op adwcleaner.exe en kies voor "Als Administrator uitvoeren".
AdwCleaner is opgestart:
  • Klik op de knop Scan
  • Is de scan gereed, klik dan op de knop Clean
  • Klik bij AdwCleaner – Afsluiting van de programma's op OK
  • Klik bij AdwCleaner – Herstarten noodzakelijk op OK
AdwCleaner logbestand:
  • Nadat de PC opnieuw is opgestart, opent een logfile.
  • Ingeval het log niet opent, is dit alsnog terug te vinden in C:\AdwCleaner\AdwCleaner[R0, of 1, of 2].txt
  • Post vervolgens de inhoud van dit log in je volgende bericht.

Stap •2•
Download
51e281a62c183-Junkware_Removal_Tool_icon_Canned_1351185104.png.jpg
Junkware Removal Tool by Thisisu.
Downloadlokatie: Dit programma absoluut naar het bureaublad downloaden of anders naar het bureaublad verplaatsen!
Opmerkingen:
  • Alle openstaande programma's en webpagina's dienen afgesloten te zijn.
  • Het is raadzaam de actieve beveiligingssoftware te de-activeren, zodat mogelijke conflicten met JRT.exe uitgsloten worden.:
  • Hier en hier vindt je gegevens hoe antivirusprogramma's en spywarescanners te deaktiveren.
  • Dat tijdens de scan van JRT.exe tijdelijk de snelkoppelingen verdwijnen van het bureaublad, is normaal.
Junkware Removal Tool by Thisisu opstarten:
  • Windows 2000 en Windows XP: dubbelklik op JRT.exe.
  • Windows Vista, Windows 7 en Windows 8: via rechtsklik op JRT.exe en kies voor "Als Administrator uitvoeren".
  • JRT.exe zal daarna Windows gaan scannen.
  • Deze scan kan afhankelijk van de systeemspecificaties soms vrij lang duren, wees dus geduldig.
  • Indien de scan voltooid is, zal een logje (JRT.txt) op het bureaublad opgeslagen worden en automatisch openen.
  • Post de inhoud van dit log in je volgende bericht.

Stap •3•
Download
51c58e5dea07b-Mbam_resized.png
Malwarebytes MBAM
http://www.malwarebytes.org/mbam/program/mbam-setup.exe

Allereerst:
  • Al meteen na de installatie wil 'MBAM' zijn database opwaarderen – toestaan dus.
  • Ook bij herhaald gebruik: eerst Malwarebytes MBAM updaten via de tab 'Update'!
Malwarebytes MBAM opstarten:
  • Sluit nu eerst alle nog openstaande programmavensters!
  • Windows 2000 en Windows XP: dubbelklik op de MBAM -snelkoppeling.
  • Windows Vista, Windows 7 en Windows 8: rechtsklik op de MBAM-snelkoppeling en dan kiezen voor Als Administrator uitvoeren.
Let op:
  • Malwarebytes MBAM verstrekt nu de volledige versie van MBAM.
  • Zodra het afsluitende installatievenster opstart, kijg je de mogelijkheid de gratis probeerversie van Malwarebytes AntiMalware tijdelijk te gebruiken.
  • Onafhankelijk van welke antivirusprogramma in jouw Windows adviseer ik dan voor de gratis versie te gaan en dus het bovenste vinkje bij de probeerversie te verwijderen.
  • Zodoende zal Malwarebytes MBAM als gratis versie verder te gebruiken zijn
Doe ook nog het volgende:
  • Zodra het programma gestart is, ga dan naar het tabblad "Instellingen".
  • Vink hier aan: "Sluit Internet Explorer tijdens verwijdering van malware".
Scannen:
  • Bij het starten Malwarebytes MBAM kies je voor 'Snelle Scan'.
  • Het scannen kan een tijdje duren, dus wees geduldig. Indien de scan voltooid is, klik dan op de knop 'OK'.
  • Klik daarna op de knop 'Bekijk Resultaten' om de resultaten te zien.
Infecties gevonden:
  • Klik nu eerst op OK om de melding weg te klikken
  • Klik vervolgens rechtsonder op de knop Bekijk resultaten.
  • Zorg er nu voor dat alle gevonden infecties aangevinkt zijn, en klik linksonder op Verwijder geselecteerde.
  • Na het verwijderen zal een log openen en zal er gevraagd worden om de computer opnieuw op te starten.
  • Indien 'MBAM' moeilijkheden heeft met het verwijderen van bepaalde bestanden zal het enkele meldingen geven – dan telkens op 'OK' klikken!
  • Daarna zal Malwarebytes MBAM vragen om de Computer opnieuw op te starten - dus sta toe dat de computer opnieuw opgestart wordt.
MBAM-Log:
  • Het log wordt automatisch bewaard door Malwarebytes MBAM en dat kan je terugvinden door in het hoofdmenu van Malwarebytes MBAM op de tab 'Logbestanden' te klikken.
Post aansluitend in je volgende bericht de inhoud van het MBAM-log.
 
Status
Niet open voor verdere reacties.
Steun Ons

Nieuwste berichten

Terug
Bovenaan