Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

computer slow [Solved]


  • This topic is locked This topic is locked

#1
HaraMo

HaraMo

    Member

  • Member
  • PipPipPip
  • 456 posts

Hi

 

This computer is not that fast anymore.

 

Lastly problems with commercial windows that appear. and internet explorer hangs witout a reason (processor and memoryuse is low).

 

kaspersky helped to stop this.

 

But system still slow.

 

Please help

 

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 18-04-2015 01
Ran by transit (administrator) on TRANSIT-PC on 18-04-2015 23:56:26
Running from C:\Users\transit\Desktop
Loaded Profiles: transit & UpdatusUser (Available profiles: transit & UpdatusUser & DefaultAppPool)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Nederlands (Nederland)
Internet Explorer Version 9 (Default browser: Opera)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo...very-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Windows\System32\CISVC.EXE
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(Microsoft Corporation) C:\Windows\System32\TCPSVCS.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_w32.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_x64.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Desktop.exe
 
 
==================== Registry (Whitelisted) ==================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [1794704 2015-03-11] (NVIDIA Corporation)
HKLM\...\RunOnce: [MedionReminder] => C:\Program Files (x86)\CyberLink\PowerRecover\Reminder.exe [443688 2011-05-26] (CyberLink)
HKU\S-1-5-19\...\Run: [Sidebar] => %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
HKU\S-1-5-19\Control Panel\Desktop\\SCRNSAVE.EXE -> 
HKU\S-1-5-20\...\Run: [Sidebar] => %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
HKU\S-1-5-20\Control Panel\Desktop\\SCRNSAVE.EXE -> 
HKU\S-1-5-21-3839137701-2974941544-2065132041-1002\...\RunOnce: [Uninstall C:\Users\transit\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\transit\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64"
HKU\S-1-5-21-3839137701-2974941544-2065132041-1002\...\Policies\system: [LogonHoursAction] 2
HKU\S-1-5-21-3839137701-2974941544-2065132041-1002\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
HKU\S-1-5-21-3839137701-2974941544-2065132041-1002\...\Policies\Explorer: [NoInstrumentation] 0
HKU\S-1-5-21-3839137701-2974941544-2065132041-1002\...\MountPoints2: {1767b950-20e8-11e1-ab1a-8c89a57d6dd6} - I:\iStudio.exe
HKU\S-1-5-21-3839137701-2974941544-2065132041-1002\Control Panel\Desktop\\SCRNSAVE.EXE -> 
HKU\S-1-5-21-3839137701-2974941544-2065132041-1007\...\Run: [Sidebar] => %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
HKU\S-1-5-21-3839137701-2974941544-2065132041-1007\...\Run: [Driver Whiz] => C:\Program Files (x86)\Driver Whiz\Driver Whiz\DriverWhiz.exe /applicationMode:systemTray /showWelcome:false
HKU\S-1-5-21-3839137701-2974941544-2065132041-1007\...\RunOnce: [HKCU] => C:\Windows\System32\oobe\info\HKCU.vbs [126 2009-11-12] ()
HKU\S-1-5-21-3839137701-2974941544-2065132041-1007\...\RunOnce: [Screensaver] => C:\Windows\Web\Wallpaper\MEDION\start.vbs
HKU\S-1-5-21-3839137701-2974941544-2065132041-1007\...\MountPoints2: {1767b950-20e8-11e1-ab1a-8c89a57d6dd6} - I:\iStudio.exe
HKU\S-1-5-21-3839137701-2974941544-2065132041-1007\Control Panel\Desktop\\SCRNSAVE.EXE -> 
HKU\S-1-5-18\Control Panel\Desktop\\SCRNSAVE.EXE -> 
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  No File
ShellIconOverlayIdentifiers: [KAVOverlayIcon] -> {014F27E2-6D75-4E42-A0E9-2A2C68498AFA} => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 15.0.1\x64\shellex.dll (Kaspersky Lab ZAO)
ShellIconOverlayIdentifiers-x32: [KAVOverlayIcon] -> {014F27E2-6D75-4E42-A0E9-2A2C68498AFA} => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 15.0.1\shellex.dll (Kaspersky Lab ZAO)
GroupPolicyUsers\S-1-5-21-3839137701-2974941544-2065132041-1007\User: Group Policy restriction detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
HKU\S-1-5-21-3839137701-2974941544-2065132041-1002\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.delta-...q={searchTerms}
HKU\S-1-5-21-3839137701-2974941544-2065132041-1002\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.be/
HKU\S-1-5-21-3839137701-2974941544-2065132041-1002\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.mystartse...AWHXXXX6YD18AWH
HKU\S-1-5-21-3839137701-2974941544-2065132041-1007\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.delta-...q={searchTerms}
SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.mystartse...q={searchTerms}
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.mystartse...q={searchTerms}
SearchScopes: HKLM -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = http://dts.search.as...q={searchTerms}
SearchScopes: HKLM -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2498} URL = 
SearchScopes: HKLM-x32 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.mystartse...q={searchTerms}
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKLM-x32 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.mystartse...q={searchTerms}
SearchScopes: HKLM-x32 -> {425ED333-6083-428a-92C9-0CFC28B9D1BF} URL = http://www.v9.com/we...q={searchTerms}
SearchScopes: HKLM-x32 -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = http://dts.search.as...q={searchTerms}
SearchScopes: HKLM-x32 -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2498} URL = 
SearchScopes: HKU\S-1-5-21-3839137701-2974941544-2065132041-1002 -> DefaultScope {2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} URL = http://www.mystartse...q={searchTerms}
SearchScopes: HKU\S-1-5-21-3839137701-2974941544-2065132041-1002 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.mystartse...q={searchTerms}
SearchScopes: HKU\S-1-5-21-3839137701-2974941544-2065132041-1002 -> {2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} URL = http://www.mystartse...q={searchTerms}
SearchScopes: HKU\S-1-5-21-3839137701-2974941544-2065132041-1002 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.mystartse...q={searchTerms}
SearchScopes: HKU\S-1-5-21-3839137701-2974941544-2065132041-1002 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = http://www.mystartse...q={searchTerms}
SearchScopes: HKU\S-1-5-21-3839137701-2974941544-2065132041-1002 -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = http://www.mystartse...q={searchTerms}
SearchScopes: HKU\S-1-5-21-3839137701-2974941544-2065132041-1002 -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2498} URL = http://www.mystartse...q={searchTerms}
SearchScopes: HKU\S-1-5-21-3839137701-2974941544-2065132041-1002 -> {E733165D-CBCF-4FDA-883E-ADEF965B476C} URL = http://www.mystartse...q={searchTerms}
SearchScopes: HKU\S-1-5-21-3839137701-2974941544-2065132041-1007 -> DefaultScope {425ED333-6083-428a-92C9-0CFC28B9D1BF} URL = http://www.v9.com/we...q={searchTerms}
SearchScopes: HKU\S-1-5-21-3839137701-2974941544-2065132041-1007 -> 528CB8441A254254BF9CDE1F824F96E2 URL = http://dts.search.as...q={searchTerms}
SearchScopes: HKU\S-1-5-21-3839137701-2974941544-2065132041-1007 -> {2077B4E2-3ADF-4315-BC05-B46E93073FAA} URL = 
SearchScopes: HKU\S-1-5-21-3839137701-2974941544-2065132041-1007 -> {425ED333-6083-428a-92C9-0CFC28B9D1BF} URL = http://www.v9.com/we...q={searchTerms}
SearchScopes: HKU\S-1-5-21-3839137701-2974941544-2065132041-1007 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = 
SearchScopes: HKU\S-1-5-21-3839137701-2974941544-2065132041-1007 -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = 
SearchScopes: HKU\S-1-5-21-3839137701-2974941544-2065132041-1007 -> {E88E0043-C9D4-4e33-8555-FEE4F5B63060} URL = 
SearchScopes: HKU\S-1-5-21-3839137701-2974941544-2065132041-1007 -> {F47F85FE-AF0F-4C1F-8EB8-EFFDEAA53904} URL = 
BHO: Content Blocker Plugin -> {03C04F0A-E2A3-4F7F-BA30-BFA06FFD1358} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 15.0.1\x64\IEExt\ie_plugin.dll [2015-03-20] (Kaspersky Lab ZAO)
BHO: cheAp4alL -> {6157f868-f12f-4ba9-804a-09533fccf080} -> C:\Program Files (x86)\cheAp4alL\V7eWClGiRZNClM.x64.dll [2015-04-15] ()
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO: Louwpriocees -> {a1c8fa6f-f886-4e2c-a175-0e59314e7bd1} -> C:\Program Files (x86)\Louwpriocees\q5bxY2zF9OCIQL.x64.dll [2015-04-15] ()
BHO: Virtual Keyboard Plugin -> {B5D5BB14-C8E2-478D-9C97-574AC10AF9E8} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 15.0.1\x64\IEExt\ie_plugin.dll [2015-03-20] (Kaspersky Lab ZAO)
BHO: Safe Money Plugin -> {E3D96E85-529D-4269-AC6A-97CF9E2221E3} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 15.0.1\x64\IEExt\ie_plugin.dll [2015-03-20] (Kaspersky Lab ZAO)
BHO-x32: Content Blocker Plugin -> {03C04F0A-E2A3-4F7F-BA30-BFA06FFD1358} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 15.0.1\IEExt\ie_plugin.dll [2015-03-20] (Kaspersky Lab ZAO)
BHO-x32: IETabPage Class -> {3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} -> C:\Program Files (x86)\XTab\SupTab.dll [2015-01-16] (Thinknice Co. Limited)
BHO-x32: cheAp4alL -> {6157f868-f12f-4ba9-804a-09533fccf080} -> C:\Program Files (x86)\cheAp4alL\V7eWClGiRZNClM.dll [2015-04-15] ()
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\ssv.dll [2015-03-18] (Oracle Corporation)
BHO-x32: Aanmeldhulp voor Microsoft-account -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO-x32: Louwpriocees -> {a1c8fa6f-f886-4e2c-a175-0e59314e7bd1} -> C:\Program Files (x86)\Louwpriocees\q5bxY2zF9OCIQL.dll [2015-04-15] ()
BHO-x32: Virtual Keyboard Plugin -> {B5D5BB14-C8E2-478D-9C97-574AC10AF9E8} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 15.0.1\IEExt\ie_plugin.dll [2015-03-20] (Kaspersky Lab ZAO)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\jp2ssv.dll [2015-03-18] (Oracle Corporation)
BHO-x32: Safe Money Plugin -> {E3D96E85-529D-4269-AC6A-97CF9E2221E3} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 15.0.1\IEExt\ie_plugin.dll [2015-03-20] (Kaspersky Lab ZAO)
DPF: HKLM-x32 {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.micros...n/ieawsdc32.cab
Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} -  No File
Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} -  No File
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
 
FireFox:
========
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_17_0_0_169.dll [2015-04-17] ()
FF Plugin: @microsoft.com/GENUINE -> C:\Windows\system32\Wat\npWatWeb.dll [2011-08-12] (Microsoft Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_169.dll [2015-04-17] ()
FF Plugin-x32: @java.com/DTPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll [2015-03-18] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\plugin2\npjp2.dll [2015-03-18] (Oracle Corporation)
FF Plugin-x32: @kaspersky.com/content_blocker_6418E0D362104DADA084DC312DFA8ABC -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 15.0.1\FFExt\[email protected] [2015-03-20] ()
FF Plugin-x32: @kaspersky.com/online_banking_69A4E213815F42BD863D889007201D82 -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 15.0.1\FFExt\[email protected] [2015-03-20] ()
FF Plugin-x32: @kaspersky.com/virtual_keyboard_294FF26A1D5B455495946778FDE7CEDB -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 15.0.1\FFExt\[email protected] [2015-03-20] ()
FF Plugin-x32: @microsoft.com/GENUINE -> C:\Windows\system32\Wat\npWatWeb.dll [2011-08-12] (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-09-12] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-09-12] (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2015-02-05] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2015-02-05] (NVIDIA Corporation)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-12-03] (Adobe Systems Inc.)
FF Extension: Belgium eID - C:\Program Files (x86)\Mozilla Firefox\extensions\[email protected] [2013-05-31]
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files (x86)\Babylon\Babylon-Pro\Utils\[email protected]
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 15.0.1\FFExt\[email protected]
FF Extension: Dangerous Websites Blocker - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 15.0.1\FFExt\[email protected] [2015-03-20]
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 15.0.1\FFExt\[email protected]
FF Extension: Virtual Keyboard - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 15.0.1\FFExt\[email protected] [2015-03-20]
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 15.0.1\FFExt\[email protected]
FF Extension: Safe Money - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 15.0.1\FFExt\[email protected] [2015-03-20]
 
Chrome: 
=======
CHR dev: Chrome dev build detected! <======= ATTENTION
CHR StartupUrls: Default -> "hxxp://www.mystartsearch.com/?type=hppp&ts=1424876756&from=cmi&uid=ST2000DL003-9VT166_6YD18AWHXXXX6YD18AWH"
CHR DefaultSearchKeyword: Default -> mystartsearch
CHR DefaultSuggestURL: Default -> 
CHR Profile: C:\Users\transit\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\transit\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2014-10-14]
CHR Extension: (Google Docs) - C:\Users\transit\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-10-14]
CHR Extension: (Google Drive) - C:\Users\transit\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-10-14]
CHR Extension: (YouTube) - C:\Users\transit\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-10-14]
CHR Extension: (Adblock Plus) - C:\Users\transit\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2015-02-27]
CHR Extension: (Google Search) - C:\Users\transit\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-10-14]
CHR Extension: (Select Search) - C:\Users\transit\AppData\Local\Google\Chrome\User Data\Default\Extensions\fcjoilhmjjhfpeflkmlhejiaadbgfkgn [2015-04-15]
CHR Extension: (Google Sheets) - C:\Users\transit\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2014-10-14]
CHR Extension: (Allin1Convert) - C:\Users\transit\AppData\Local\Google\Chrome\User Data\Default\Extensions\gcncagkkhfoombgbihckkccmkjemhohl [2015-02-04]
CHR Extension: (Clickable Links) - C:\Users\transit\AppData\Local\Google\Chrome\User Data\Default\Extensions\mgamelhnfokapndfdodnmfiningckjia [2015-03-17]
CHR Extension: (Google Wallet) - C:\Users\transit\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-10-14]
CHR Extension: (20-20 3D Viewer for IKEA) - C:\Users\transit\AppData\Local\Google\Chrome\User Data\Default\Extensions\pfhldcakmgpmglboaclpfdedehjblalp [2014-12-03]
CHR Extension: (Gmail) - C:\Users\transit\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-10-14]
CHR HKLM\...\Chrome\Extension: [dbhjdbfgekjfcfkkfjjmlmojhbllhbho] - https://chrome.googl...jjmlmojhbllhbho
CHR HKLM-x32\...\Chrome\Extension: [dbhjdbfgekjfcfkkfjjmlmojhbllhbho] - https://chrome.googl...jjmlmojhbllhbho
CHR HKLM-x32\...\Chrome\Extension: [iomphmdalfmaifjccmagmllnicjoghhk] - https://clients2.goo...ice/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [ogfjmhfnldnajmfaofeiaepghjenbgjo] - No Path Or update_url value
 
==================== Services (Whitelisted) =================
 
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
 
S3 AVP15.0.1; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 15.0.1\avp.exe [234520 2014-08-30] (Kaspersky Lab ZAO)
S4 BotkindSyncService; C:\Program Files (x86)\Allway Sync\Bin\SyncService.exe [182784 2012-12-26] () [File not signed]
R2 HPSLPSVC; C:\Users\transit\AppData\Local\Temp\7zS36B0\hpslpsvc64.dll [1039360 2013-07-19] (Hewlett-Packard Co.) [File not signed]
R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [71680 2010-08-06] (Hewlett-Packard) [File not signed]
R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [89600 2010-08-06] (Hewlett-Packard) [File not signed]
S4 ReimageRealTimeProtector; C:\Program Files\Reimage\Reimage Protector\ReiGuard.exe [7410024 2015-01-14] (Reimage®)
R2 simptcp; C:\Windows\SysWOW64\tcpsvcs.exe [9216 2009-07-14] (Microsoft Corporation)
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [5448464 2015-03-30] (TeamViewer GmbH)
S4 TlntSvr; C:\Windows\System32\tlntsvr.exe [81920 2009-07-14] (Microsoft Corporation)
R2 W3SVC; C:\Windows\system32\inetsrv\iisw3adm.dll [453120 2010-11-21] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
 
==================== Drivers (Whitelisted) ====================
 
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
 
S3 AVFSFilter; No ImagePath
R0 cm_km_w; C:\Windows\System32\DRIVERS\cm_km_w.sys [238288 2013-01-14] (Kaspersky Lab UK Ltd)
S3 IntcAzAudAddService; No ImagePath
R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [468576 2014-03-31] (Kaspersky Lab ZAO)
R2 kldisk; C:\Windows\System32\DRIVERS\kldisk.sys [46144 2014-07-02] (Kaspersky Lab ZAO)
R3 klflt; C:\Windows\System32\DRIVERS\klflt.sys [150536 2015-03-20] (Kaspersky Lab ZAO)
R1 klhk; C:\Windows\System32\DRIVERS\klhk.sys [246456 2014-08-12] (Kaspersky Lab ZAO)
R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [819896 2015-03-20] (Kaspersky Lab ZAO)
R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [30304 2014-02-25] (Kaspersky Lab ZAO)
R3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [28768 2014-03-28] (Kaspersky Lab ZAO)
R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [29280 2013-08-08] (Kaspersky Lab ZAO)
R1 klpd; C:\Windows\System32\DRIVERS\klpd.sys [15456 2013-04-12] (Kaspersky Lab ZAO)
R1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [55872 2014-06-05] (Kaspersky Lab ZAO)
R1 Klwtp; C:\Windows\System32\DRIVERS\klwtp.sys [77512 2015-03-20] (Kaspersky Lab ZAO)
R1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [179776 2014-07-09] (Kaspersky Lab ZAO)
S0 nvpciflt; No ImagePath
S3 cpuz134; \??\C:\Users\transit\AppData\Local\Temp\cpuz134\cpuz134_x64.sys [X]
S1 iSafeKrnlMon; \??\C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlMon.sys [X]
U4 klkbdflt2; system32\DRIVERS\klkbdflt2.sys [X]
S1 qrnfd_1_10_0_9; system32\drivers\qrnfd_1_10_0_9.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
 
 
==================== One Month Created Files and Folders ========
 
(If an entry is included in the fixlist, the file\folder will be moved.)
 
2015-04-18 23:56 - 2015-04-18 23:56 - 00025206 _____ () C:\Users\transit\Desktop\FRST.txt
2015-04-18 23:56 - 2015-04-18 23:56 - 00000000 ____D () C:\FRST
2015-04-18 23:53 - 2015-04-18 23:53 - 02098176 _____ (Farbar) C:\Users\transit\Desktop\FRST64.exe
2015-04-18 23:53 - 2015-04-18 23:53 - 00000000 ____D () C:\Users\transit\Desktop\hidara solutions
2015-04-18 23:31 - 2015-04-18 23:31 - 00000000 ____D () C:\Users\transit\AppData\Local\TeamViewer
2015-04-18 23:30 - 2015-04-18 23:30 - 00000975 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 10.lnk
2015-04-18 15:04 - 2015-04-18 15:04 - 00000000 ____D () C:\Windows\pss
2015-04-18 11:42 - 2015-04-18 11:42 - 00001405 _____ () C:\Users\transit\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
2015-04-17 17:13 - 2015-04-17 17:13 - 00000636 __RSH () C:\Users\transit\ntuser.pol
2015-04-17 15:18 - 2015-04-17 15:18 - 00003030 _____ () C:\Windows\System32\Tasks\{50C37B14-2259-4BCD-B52E-783030EF8F71}
2015-04-17 15:16 - 2015-04-17 15:16 - 00003030 _____ () C:\Windows\System32\Tasks\{9514EDF2-1A91-4E9F-A395-CB65BC391C6E}
2015-04-17 15:11 - 2015-04-17 15:12 - 00009988 _____ () C:\Windows\iis7.log
2015-04-17 14:54 - 2015-04-17 14:54 - 18178736 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2015-04-16 22:30 - 2015-04-16 22:30 - 00000169 _____ () C:\Users\transit\Desktop\Google.url
2015-04-15 16:50 - 2015-04-15 16:50 - 00000000 ____D () C:\Program Files (x86)\daialypriiZe
2015-04-15 16:49 - 2015-04-15 17:22 - 00000000 ____D () C:\Program Files (x86)\Louwpriocees
2015-04-15 16:49 - 2015-04-15 16:50 - 00000000 ____D () C:\Program Files (x86)\Select Search
2015-04-15 16:49 - 2015-04-15 16:50 - 00000000 ____D () C:\Program Files (x86)\cheAp4alL
2015-04-15 16:24 - 2015-03-25 05:24 - 03298816 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2015-04-15 16:24 - 2015-03-25 05:24 - 02553856 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2015-04-15 16:24 - 2015-03-25 05:24 - 00696320 _____ (Microsoft Corporation) C:\Windows\system32\wuapi(72).dll
2015-04-15 16:24 - 2015-03-25 05:24 - 00191488 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2015-04-15 16:24 - 2015-03-25 05:24 - 00098304 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2015-04-15 16:24 - 2015-03-25 05:24 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
2015-04-15 16:24 - 2015-03-25 05:24 - 00037376 _____ (Microsoft Corporation) C:\Windows\system32\wups2(73).dll
2015-04-15 16:24 - 2015-03-25 05:24 - 00035328 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2015-04-15 16:24 - 2015-03-25 05:23 - 00135168 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2015-04-15 16:24 - 2015-03-25 05:23 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2015-04-15 16:24 - 2015-03-25 05:23 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll
2015-04-15 16:24 - 2015-03-25 05:00 - 00566784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2015-04-15 16:24 - 2015-03-25 05:00 - 00173056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2015-04-15 16:24 - 2015-03-25 05:00 - 00092672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2015-04-15 16:24 - 2015-03-25 05:00 - 00033792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2015-04-15 16:24 - 2015-03-25 05:00 - 00029696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2015-04-15 16:24 - 2015-03-23 05:25 - 00769536 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2015-04-15 16:24 - 2015-03-23 05:25 - 00726528 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2015-04-15 16:24 - 2015-03-23 05:24 - 00957952 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2015-04-15 16:24 - 2015-03-23 05:24 - 00419840 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2015-04-15 16:24 - 2015-03-23 05:24 - 00227328 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2015-04-15 16:24 - 2015-03-23 05:24 - 00192000 _____ (Microsoft Corporation) C:\Windows\system32\aepic(41).dll
2015-04-15 16:24 - 2015-03-23 05:24 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2015-04-15 16:24 - 2015-03-23 05:17 - 01111552 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2015-04-15 16:24 - 2015-03-17 07:22 - 05557696 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-04-15 16:24 - 2015-03-17 07:22 - 00155576 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2015-04-15 16:24 - 2015-03-17 07:22 - 00095672 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2015-04-15 16:24 - 2015-03-17 07:19 - 01727904 _____ (Microsoft Corporation) C:\Windows\system32\ntdll(56).dll
2015-04-15 16:24 - 2015-03-17 07:17 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win(71).dll
2015-04-15 16:24 - 2015-03-17 07:17 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64(69).dll
2015-04-15 16:24 - 2015-03-17 07:17 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu(70).dll
2015-04-15 16:24 - 2015-03-17 07:16 - 01461760 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv(50).dll
2015-04-15 16:24 - 2015-03-17 07:16 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32(48).dll
2015-04-15 16:24 - 2015-03-17 07:16 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos(47).dll
2015-04-15 16:24 - 2015-03-17 07:16 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore(60).dll
2015-04-15 16:24 - 2015-03-17 07:16 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase(49).dll
2015-04-15 16:24 - 2015-03-17 07:16 - 00341504 _____ (Microsoft Corporation) C:\Windows\system32\schannel(57).dll
2015-04-15 16:24 - 2015-03-17 07:16 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0(52).dll
2015-04-15 16:24 - 2015-03-17 07:16 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt(55).dll
2015-04-15 16:24 - 2015-03-17 07:16 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-04-15 16:24 - 2015-03-17 07:16 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv(68).dll
2015-04-15 16:24 - 2015-03-17 07:16 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest(65).dll
2015-04-15 16:24 - 2015-03-17 07:16 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli(61).dll
2015-04-15 16:24 - 2015-03-17 07:16 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss(59).exe
2015-04-15 16:24 - 2015-03-17 07:16 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg(63).dll
2015-04-15 16:24 - 2015-03-17 07:16 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-04-15 16:24 - 2015-03-17 07:16 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv(44).dll
2015-04-15 16:24 - 2015-03-17 07:16 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv(62).dll
2015-04-15 16:24 - 2015-03-17 07:16 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32(58).dll
2015-04-15 16:24 - 2015-03-17 07:16 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp(43).dll
2015-04-15 16:24 - 2015-03-17 07:16 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2015-04-15 16:24 - 2015-03-17 07:15 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2015-04-15 16:24 - 2015-03-17 07:15 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2015-04-15 16:24 - 2015-03-17 07:15 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass(51).exe
2015-04-15 16:24 - 2015-03-17 07:13 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2015-04-15 16:24 - 2015-03-17 07:13 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2015-04-15 16:24 - 2015-03-17 07:11 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2015-04-15 16:24 - 2015-03-17 07:11 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema(42).dll
2015-04-15 16:24 - 2015-03-17 07:11 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2015-04-15 16:24 - 2015-03-17 07:11 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2015-04-15 16:24 - 2015-03-17 07:11 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2015-04-15 16:24 - 2015-03-17 07:11 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2015-04-15 16:24 - 2015-03-17 07:11 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2015-04-15 16:24 - 2015-03-17 07:11 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2015-04-15 16:24 - 2015-03-17 07:11 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2015-04-15 16:24 - 2015-03-17 07:11 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2015-04-15 16:24 - 2015-03-17 07:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-04-15 16:24 - 2015-03-17 07:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2015-04-15 16:24 - 2015-03-17 07:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2015-04-15 16:24 - 2015-03-17 07:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2015-04-15 16:24 - 2015-03-17 07:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2015-04-15 16:24 - 2015-03-17 07:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2015-04-15 16:24 - 2015-03-17 07:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2015-04-15 16:24 - 2015-03-17 07:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2015-04-15 16:24 - 2015-03-17 07:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2015-04-15 16:24 - 2015-03-17 07:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2015-04-15 16:24 - 2015-03-17 07:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2015-04-15 16:24 - 2015-03-17 07:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2015-04-15 16:24 - 2015-03-17 07:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2015-04-15 16:24 - 2015-03-17 07:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2015-04-15 16:24 - 2015-03-17 07:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2015-04-15 16:24 - 2015-03-17 07:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2015-04-15 16:24 - 2015-03-17 07:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2015-04-15 16:24 - 2015-03-17 07:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2015-04-15 16:24 - 2015-03-17 07:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2015-04-15 16:24 - 2015-03-17 07:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2015-04-15 16:24 - 2015-03-17 07:01 - 03976632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2015-04-15 16:24 - 2015-03-17 07:01 - 03920824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2015-04-15 16:24 - 2015-03-17 06:59 - 01309696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll(79).dll
2015-04-15 16:24 - 2015-03-17 06:57 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2015-04-15 16:24 - 2015-03-17 06:57 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2015-04-15 16:24 - 2015-03-17 06:57 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2015-04-15 16:24 - 2015-03-17 06:57 - 00221184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2015-04-15 16:24 - 2015-03-17 06:57 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2015-04-15 16:24 - 2015-03-17 06:57 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2015-04-15 16:24 - 2015-03-17 06:57 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2015-04-15 16:24 - 2015-03-17 06:57 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32(80).dll
2015-04-15 16:24 - 2015-03-17 06:57 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2015-04-15 16:24 - 2015-03-17 06:56 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32(77).dll
2015-04-15 16:24 - 2015-03-17 06:56 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase(78).dll
2015-04-15 16:24 - 2015-03-17 06:56 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli(81).dll
2015-04-15 16:24 - 2015-03-17 06:56 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2015-04-15 16:24 - 2015-03-17 06:56 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2015-04-15 16:24 - 2015-03-17 06:56 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp(74).dll
2015-04-15 16:24 - 2015-03-17 06:56 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2015-04-15 16:24 - 2015-03-17 06:53 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2015-04-15 16:24 - 2015-03-17 06:53 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2015-04-15 16:24 - 2015-03-17 06:50 - 00686080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2015-04-15 16:24 - 2015-03-17 06:50 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2015-04-15 16:24 - 2015-03-17 06:50 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2015-04-15 16:24 - 2015-03-17 06:50 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2015-04-15 16:24 - 2015-03-17 06:50 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2015-04-15 16:24 - 2015-03-17 06:50 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2015-04-15 16:24 - 2015-03-17 06:50 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2015-04-15 16:24 - 2015-03-17 06:50 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2015-04-15 16:24 - 2015-03-17 06:50 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2015-04-15 16:24 - 2015-03-17 06:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2015-04-15 16:24 - 2015-03-17 06:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2015-04-15 16:24 - 2015-03-17 06:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2015-04-15 16:24 - 2015-03-17 06:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2015-04-15 16:24 - 2015-03-17 06:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2015-04-15 16:24 - 2015-03-17 06:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2015-04-15 16:24 - 2015-03-17 06:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2015-04-15 16:24 - 2015-03-17 06:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-04-15 16:24 - 2015-03-17 06:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2015-04-15 16:24 - 2015-03-17 06:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2015-04-15 16:24 - 2015-03-17 06:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2015-04-15 16:24 - 2015-03-17 06:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2015-04-15 16:24 - 2015-03-17 06:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2015-04-15 16:24 - 2015-03-17 06:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2015-04-15 16:24 - 2015-03-17 06:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2015-04-15 16:24 - 2015-03-17 06:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2015-04-15 16:24 - 2015-03-17 06:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2015-04-15 16:24 - 2015-03-17 05:45 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2015-04-15 16:24 - 2015-03-17 05:45 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2015-04-15 16:24 - 2015-03-17 05:43 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2015-04-15 16:24 - 2015-03-17 05:43 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2015-04-15 16:24 - 2015-03-17 05:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2015-04-15 16:24 - 2015-03-17 05:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2015-04-15 16:24 - 2015-03-13 06:07 - 02886144 _____ (Microsoft Corporation) C:\Windows\system32\iertutil(46).dll
2015-04-15 16:24 - 2015-03-13 05:22 - 02278400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil(76).dll
2015-04-15 16:24 - 2015-03-13 04:45 - 02358784 _____ (Microsoft Corporation) C:\Windows\system32\wininet(67).dll
2015-04-15 16:24 - 2015-03-13 04:33 - 01548288 _____ (Microsoft Corporation) C:\Windows\system32\urlmon(64).dll
2015-04-15 16:24 - 2015-03-13 04:20 - 01888256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet(83).dll
2015-04-15 16:24 - 2015-03-13 04:16 - 01311232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon(82).dll
2015-04-15 16:24 - 2015-03-10 05:25 - 01882624 _____ (Microsoft Corporation) C:\Windows\system32\msxml3(53).dll
2015-04-15 16:24 - 2015-03-10 05:21 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r(54).dll
2015-04-15 16:24 - 2015-03-10 05:08 - 01237504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2015-04-15 16:24 - 2015-03-10 05:05 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2015-04-15 16:24 - 2015-03-05 07:12 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32(45).dll
2015-04-15 16:24 - 2015-03-05 06:05 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32(75).dll
2015-04-15 16:24 - 2015-02-25 05:18 - 00754688 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\http.sys
2015-04-15 16:23 - 2015-03-04 06:55 - 00367552 _____ (Microsoft Corporation) C:\Windows\system32\clfs.sys
2015-04-15 16:23 - 2015-03-04 06:41 - 00079360 _____ (Microsoft Corporation) C:\Windows\system32\clfsw32.dll
2015-04-15 16:23 - 2015-03-04 06:10 - 00058880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\clfsw32.dll
2015-03-28 10:17 - 2015-03-28 10:17 - 00000000 ____D () C:\Users\transit\AppData\Local\NVIDIA
2015-03-28 10:10 - 2015-04-16 18:05 - 00000000 ___SD () C:\Windows\system32\GWX
2015-03-28 10:10 - 2015-03-28 10:10 - 00000000 ___SD () C:\Windows\SysWOW64\GWX
2015-03-28 10:09 - 2015-03-28 10:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2015-03-28 10:09 - 2015-02-05 19:57 - 00621384 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe
2015-03-28 09:49 - 2015-03-28 09:49 - 00000998 _____ () C:\Users\transit\Desktop\Apple iPhone - Snelkoppeling.lnk
2015-03-28 09:09 - 2015-03-28 09:10 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live
2015-03-28 09:05 - 2015-03-28 09:05 - 00000382 _____ () C:\Windows\DirectX.log
2015-03-28 09:04 - 2015-03-28 09:04 - 00002210 _____ () C:\Users\transit\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft OneDrive.lnk
2015-03-25 11:15 - 2015-03-11 06:05 - 00192000 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2015-03-24 16:22 - 2015-03-25 14:51 - 00002012 _____ () C:\Users\Public\Desktop\HP Print and Scan Doctor.lnk
2015-03-23 19:57 - 2015-04-18 10:09 - 00001829 _____ () C:\Windows\system32\ScanResults.xml
2015-03-23 19:55 - 2015-04-18 10:04 - 00000464 _____ () C:\Windows\system32\ScannerSettings
2015-03-20 19:57 - 2015-03-20 19:57 - 00262144 _____ () C:\Windows\system32\config\elam
2015-03-20 19:34 - 2015-03-20 19:34 - 00002311 _____ () C:\Users\transit\Desktop\Veilig Bankieren.lnk
2015-03-20 19:33 - 2015-03-20 19:33 - 00002057 _____ () C:\Users\Public\Desktop\Kaspersky Total Security.lnk
2015-03-20 19:33 - 2015-03-20 19:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Total Security
2015-03-20 19:32 - 2015-04-18 10:35 - 00000000 ____D () C:\ProgramData\Kaspersky Lab
2015-03-20 19:32 - 2015-03-20 19:32 - 00000000 ____D () C:\Windows\ELAMBKUP
2015-03-20 19:32 - 2015-03-20 19:32 - 00000000 ____D () C:\Program Files (x86)\Kaspersky Lab
2015-03-20 19:32 - 2014-08-12 19:33 - 00246456 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klhk.sys
2015-03-20 19:32 - 2013-05-06 10:13 - 00110176 _____ (Kaspersky Lab ZAO) C:\Windows\system32\klfphc.dll
2015-03-20 19:18 - 2015-03-20 19:18 - 00000000 ____D () C:\Users\Default\AppData\Roaming\Adobe
2015-03-20 19:18 - 2015-03-20 19:18 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\Adobe
2015-03-20 19:12 - 2015-03-20 19:12 - 00000546 _____ () C:\Users\transit\Desktop\Facturatie (2).lnk
2015-03-20 15:32 - 2015-03-20 15:32 - 00004282 _____ () C:\Windows\System32\Tasks\ReimageUpdater
2015-03-20 15:32 - 2015-03-20 15:32 - 00000000 ____D () C:\ProgramData\Reimage Protector
2015-03-20 15:32 - 2015-03-20 15:32 - 00000000 ____D () C:\ProgramData\Reimage Express
2015-03-20 15:32 - 2015-03-20 15:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Reimage Express
2015-03-20 15:32 - 2015-03-20 15:32 - 00000000 ____D () C:\Program Files\Reimage
2015-03-20 15:15 - 2015-04-18 23:17 - 00006991 _____ () C:\Windows\setupact.log
2015-03-20 15:15 - 2015-03-20 15:15 - 00000000 _____ () C:\Windows\setuperr.log
2015-03-20 15:14 - 2015-04-18 15:05 - 00007274 _____ () C:\Windows\PFRO.log
2015-03-19 10:46 - 2015-03-19 10:46 - 00000322 _____ () C:\Users\transit\Desktop\Firmware-update voor de Deskjet 2540 All-in-One printerserie.url
 
==================== One Month Modified Files and Folders =======
 
(If an entry is included in the fixlist, the file\folder will be moved.)
 
2015-04-18 23:54 - 2012-05-17 09:39 - 00000940 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-04-18 23:34 - 2011-12-07 17:34 - 00088536 _____ () C:\Users\transit\AppData\Local\GDIPFONTCACHEV1.DAT
2015-04-18 23:31 - 2012-05-17 11:43 - 00000000 ____D () C:\Program Files (x86)\TeamViewer
2015-04-18 23:31 - 2012-05-15 20:12 - 00000000 ____D () C:\Users\transit\AppData\Roaming\TeamViewer
2015-04-18 23:26 - 2009-07-14 06:45 - 00024800 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-04-18 23:26 - 2009-07-14 06:45 - 00024800 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-04-18 23:21 - 2011-12-07 17:27 - 01251931 _____ () C:\Windows\WindowsUpdate.log
2015-04-18 23:17 - 2011-09-06 00:24 - 00000000 ____D () C:\ProgramData\NVIDIA
2015-04-18 23:17 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-04-18 23:15 - 2014-01-26 21:36 - 00003974 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{401E2AD1-3D61-4E10-AEA2-12D09233DAF5}
2015-04-18 15:18 - 2011-05-16 16:47 - 00854064 _____ () C:\Windows\system32\perfh013.dat
2015-04-18 15:18 - 2011-05-16 16:47 - 00192888 _____ () C:\Windows\system32\perfc013.dat
2015-04-18 15:18 - 2009-07-14 07:13 - 01943218 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-04-18 15:01 - 2014-10-04 13:34 - 00000000 ____D () C:\Users\transit\AppData\Local\Unity
2015-04-18 15:00 - 2013-04-24 12:47 - 00000000 ____D () C:\Users\transit\AppData\Roaming\Fighters
2015-04-18 15:00 - 2013-04-24 12:47 - 00000000 ____D () C:\Program Files (x86)\Fighters
2015-04-18 15:00 - 2013-04-24 12:46 - 00000000 ____D () C:\ProgramData\Fighters
2015-04-18 13:45 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache
2015-04-18 12:38 - 2012-01-25 15:36 - 01916950 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI
2015-04-18 11:34 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\tr-TR
2015-04-18 11:34 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\sl-SI
2015-04-18 11:34 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\tr-TR
2015-04-18 11:34 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\sl-SI
2015-04-18 11:34 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2015-04-17 17:13 - 2011-12-07 17:33 - 00000000 ____D () C:\Users\transit
2015-04-17 17:13 - 2009-07-14 05:20 - 00000000 ___HD () C:\Windows\system32\GroupPolicy
2015-04-17 15:57 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\NDF
2015-04-17 15:08 - 2009-07-14 07:32 - 00000000 ____D () C:\Program Files\Windows Sidebar
2015-04-17 15:08 - 2009-07-14 07:32 - 00000000 ____D () C:\Program Files\DVD Maker
2015-04-17 15:07 - 2011-04-12 10:28 - 00000000 ___RD () C:\Users\Public\Recorded TV
2015-04-17 15:07 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\inetsrv
2015-04-17 15:07 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\inetsrv
2015-04-17 14:54 - 2012-05-17 09:39 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-04-17 14:54 - 2012-05-17 09:39 - 00003878 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-04-17 14:54 - 2011-08-10 21:09 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-04-17 14:18 - 2015-03-02 15:33 - 00000000 ____D () C:\Users\DefaultAppPool
2015-04-17 14:18 - 2015-02-25 16:22 - 00000000 ____D () C:\ProgramData\{73ae9642-a57e-1a36-73ae-e9642a57590a}
2015-04-17 14:18 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\registration
2015-04-16 19:44 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\AppCompat
2015-04-16 18:06 - 2014-12-11 04:23 - 00000000 ____D () C:\Windows\system32\appraiser
2015-04-16 18:06 - 2014-04-30 15:07 - 00000000 ___SD () C:\Windows\system32\CompatTel
2015-04-16 18:05 - 2014-03-25 15:02 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2015-04-16 18:05 - 2011-12-07 17:28 - 00000000 ____D () C:\Program Files (x86)\Google
2015-04-16 18:05 - 2009-07-14 05:20 - 00000000 ____D () C:\Program Files\Common Files\Microsoft Shared
2015-04-16 18:02 - 2011-12-07 17:47 - 00000000 ____D () C:\Users\transit\AppData\Local\Google
2015-04-16 17:29 - 2015-02-25 16:23 - 00000000 ____D () C:\Program Files (x86)\Super Optimizer
2015-04-16 15:37 - 2015-02-26 17:28 - 00000000 ____D () C:\Users\transit\Documents\Optimizer Pro
2015-04-16 10:50 - 2015-03-17 06:34 - 00000000 ____D () C:\Program Files (x86)\offeRdeal
2015-04-16 10:15 - 2015-03-17 06:34 - 00000000 ____D () C:\Program Files (x86)\loWpriiceS
2015-04-16 03:13 - 2013-08-15 08:48 - 00000000 ____D () C:\Windows\system32\MRT
2015-04-16 03:05 - 2011-07-18 22:31 - 128913832 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-04-15 17:05 - 2015-02-25 16:27 - 00000000 ____D () C:\Users\transit\AppData\Local\SmartWeb
2015-04-15 16:50 - 2015-03-10 14:26 - 00000000 ____D () C:\ProgramData\5786049068603124795
2015-03-28 10:09 - 2014-05-02 17:27 - 00000000 ____D () C:\temp
2015-03-28 10:09 - 2011-08-11 23:24 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation
2015-03-28 10:09 - 2011-08-11 23:22 - 00000000 ____D () C:\Program Files\NVIDIA Corporation
2015-03-28 09:10 - 2011-07-18 22:51 - 00000000 ____D () C:\Program Files (x86)\Windows Live
2015-03-26 11:35 - 2014-05-05 19:20 - 00000000 ____D () C:\Users\transit\AppData\Roaming\HpUpdate
2015-03-24 16:15 - 2009-07-14 07:09 - 00000000 ____D () C:\Windows\System32\Tasks\WPD
2015-03-21 15:44 - 2015-02-25 17:06 - 00000000 ____D () C:\Program Files (x86)\XTab
2015-03-20 20:11 - 2009-07-14 07:08 - 00032622 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2015-03-20 20:11 - 2009-07-14 07:08 - 00032622 _____ () C:\Windows\Tasks\SCHEDLGU(84).TXT
2015-03-20 20:08 - 2015-02-26 17:28 - 00000000 ____D () C:\ProgramData\{01409120-2ea8-636d-0140-091202ea4480}
2015-03-20 19:38 - 2014-08-20 19:04 - 00819896 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klif.sys
2015-03-20 19:38 - 2014-08-18 15:43 - 00150536 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klflt.sys
2015-03-20 19:38 - 2014-08-13 20:34 - 00077512 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klwtp.sys
2015-03-20 19:34 - 2012-03-12 11:01 - 00000000 ____D () C:\ProgramData\Kaspersky Lab Setup Files
2015-03-20 19:17 - 2015-02-04 12:00 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TweakBit
2015-03-20 19:17 - 2015-02-04 12:00 - 00000000 ____D () C:\Program Files (x86)\TweakBit
2015-03-20 18:59 - 2014-04-17 14:00 - 00000923 _____ () C:\Users\transit\Desktop\Garantie.lnk
2015-03-20 18:48 - 2009-07-14 04:34 - 00000466 _____ () C:\Windows\win.ini
2015-03-20 18:39 - 2014-05-02 21:33 - 00001912 _____ () C:\Windows\epplauncher.mif
2015-03-20 15:32 - 2015-02-25 16:53 - 00000158 _____ () C:\Windows\Reimage.ini
2015-03-20 15:25 - 2013-04-25 13:32 - 00000000 ____D () C:\Users\transit\AppData\Roaming\Systweak
2015-03-20 15:18 - 2015-02-28 19:35 - 00003970 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{5D07E2B6-FF41-4FA0-877B-89FFADBE5835}
2015-03-20 12:17 - 2015-02-25 16:53 - 00000120 _____ () C:\Windows\efix.ini
 
==================== Files in the root of some directories =======
 
2012-05-15 16:33 - 2012-05-15 16:33 - 0002116 _____ () C:\Program Files (x86)\INSTALL.LOG
2011-12-07 20:25 - 2011-12-07 20:25 - 0020816 _____ () C:\Users\transit\AppData\Roaming\UserTile.png
2013-12-19 14:17 - 2014-10-09 13:17 - 0000167 _____ () C:\Users\transit\AppData\Roaming\WB.CFG
2014-05-05 19:19 - 2014-05-05 19:19 - 0000057 _____ () C:\ProgramData\Ament.ini
2012-01-08 23:52 - 2012-01-08 23:52 - 0000000 _____ () C:\ProgramData\cmn_upld.log
2012-01-09 00:09 - 2012-01-09 00:09 - 0000252 _____ () C:\ProgramData\FastPics.log
2014-05-04 19:58 - 2014-05-05 19:15 - 0015205 _____ () C:\ProgramData\hpzinstall.log
2014-05-02 19:33 - 2014-05-02 19:33 - 0000256 _____ () C:\ProgramData\lxee.log
2012-01-09 00:13 - 2012-02-14 10:43 - 0046798 _____ () C:\ProgramData\lxeeJSW.log
2012-01-08 23:57 - 2014-05-02 19:33 - 0109051 _____ () C:\ProgramData\lxeescan.log
2012-01-08 23:52 - 2012-01-08 23:52 - 0000000 _____ () C:\ProgramData\LxWbGwLog.log
2012-01-08 23:52 - 2012-01-08 23:52 - 0000000 _____ () C:\ProgramData\UpdaterLog.txt
 
Some content of TEMP:
====================
C:\Users\transit\AppData\Local\Temp\HPPSdr.exe
C:\Users\transit\AppData\Local\Temp\pc-support-bar-setup.exe
C:\Users\transit\AppData\Local\Temp\pc-support-bar-setup_0.exe
C:\Users\transit\AppData\Local\Temp\pc-support-bar-setup_1.exe
 
 
==================== Bamital & volsnap Check =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2015-04-16 19:21
 
==================== End Of Log ============================

 

 

 

 

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 18-04-2015 01
Ran by transit at 2015-04-18 23:57:00
Running from C:\Users\transit\Desktop
Boot Mode: Normal
==========================================================
 
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Kaspersky Total Security (Disabled - Up to date) {179979E8-273D-D14E-0543-2861940E4886}
AS: Kaspersky Total Security (Disabled - Up to date) {ACF8980C-0107-DEC0-3FF3-1313EF89023B}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: Kaspersky Total Security (Disabled) {2FA2F8CD-6D52-D016-2E1C-81546ADD0FFD}
 
==================== Installed Programs ======================
 
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
64 Bit HP CIO Components Installer (Version: 7.2.8 - Hewlett-Packard) Hidden
ABBYY FineReader 6.0 Sprint (HKLM-x32\...\{ACF60000-22B9-4CE9-98D6-2CCF359BAC07}) (Version: 6.00.2146.41621 - ABBYY Software House)
Adobe Flash Player 17 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 17.0.0.169 - Adobe Systems Incorporated)
Adobe Flash Player 17 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 17.0.0.169 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.10) - Nederlands (HKLM-x32\...\{AC76BA86-7AD7-1043-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated)
Asmedia ASM104x USB 3.0 Host Controller Driver (HKLM-x32\...\{E4FB0B39-C991-4EE7-95DD-1A1A7857D33D}) (Version: 1.12.5.0 - Asmedia Technology)
Belgium e-ID middleware 4.0.5 (build 7363) (HKLM\...\{824563DE-75AD-4166-9DC0-B6482F207363}) (Version: 4.0.7363 - Belgian Government)
bpd_scan (x32 Version: 3.00.0000 - Hewlett-Packard) Hidden
CorelDRAW Essentials X5 - Common (x32 Version: 15.3 - Corel Corporation) Hidden
CorelDRAW Essentials X5 - Connect (x32 Version: 15.3 - Corel Corporation) Hidden
CorelDRAW Essentials X5 - Custom Data (x32 Version: 15.3 - Corel Corporation) Hidden
CorelDRAW Essentials X5 - DE (x32 Version: 15.3 - Corel Corporation) Hidden
CorelDRAW Essentials X5 - Draw (x32 Version: 15.3 - Corel Corporation) Hidden
CorelDRAW Essentials X5 - EN (x32 Version: 15.3 - Corel Corporation) Hidden
CorelDRAW Essentials X5 - ES (x32 Version: 15.3 - Corel Corporation) Hidden
CorelDRAW Essentials X5 - Extra Content (x32 Version: 15.0 - Corel Corporation) Hidden
CorelDRAW Essentials X5 - Filters (x32 Version: 15.3 - Corel Corporation) Hidden
CorelDRAW Essentials X5 - FR (x32 Version: 15.3 - Corel Corporation) Hidden
CorelDRAW Essentials X5 - IPM (x32 Version: 15.3 - Corel Corporation) Hidden
CorelDRAW Essentials X5 - IT (x32 Version: 15.3 - Corel Corporation) Hidden
CorelDRAW Essentials X5 - PHOTO-PAINT (x32 Version: 15.3 - Corel Corporation) Hidden
CorelDRAW Essentials X5 - Redist (x32 Version: 15.0 - Corel Corporation) Hidden
CorelDRAW Essentials X5 - Setup Files (x32 Version: 15.3 - Corel Corporation) Hidden
CorelDRAW Essentials X5 - WT (x32 Version: 15.3 -  Corel Corporation) Hidden
CorelDRAW Essentials X5 (HKLM-x32\...\_{EDBEBF07-F880-48FB-9AA5-0E8E71E02D83}) (Version: 15.2.0.686 - Corel Corporation)
CorelDRAW Essentials X5 (x32 Version: 15.3 - Corel Corporation) Hidden
CyberLink PowerRecover (HKLM-x32\...\InstallShield_{44B2A0AB-412E-4F8C-B058-D1E8AECCDFF5}) (Version: 5.5.4125 - CyberLink Corp.)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
DealPly (HKU\.DEFAULT\...\DealPly) (Version:  - ) <==== ATTENTION
DealPly (remove only) (HKLM-x32\...\DealPly) (Version: 4.8.6.3 - DealPly Technologies Ltd.) <==== ATTENTION
DJ2540FWUpdateAlert (x32 Version: 1.00.0000 - HP) Hidden
EZ Software Updater version 1.2.0.4 (HKLM-x32\...\EZ Software Updater_is1) (Version: 1.2.0.4 - www.ezupdater.com)
Fotogalerie (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Fotogalerija (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Fotoğraf Galerisi (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Fotótár (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
FoxTab PDF Creator (HKU\S-1-5-21-3839137701-2974941544-2065132041-1002\...\FoxTab PDF Creator) (Version:  - ) <==== ATTENTION
FoxTab PDF Creator (HKU\S-1-5-21-3839137701-2974941544-2065132041-1007\...\FoxTab PDF Creator) (Version:  - ) <==== ATTENTION
Galeria de Fotografias do Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galería de fotos (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Galeria fotografii (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Galerie de photos (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Google Chrome (HKU\S-1-5-21-3839137701-2974941544-2065132041-1007\...\Google Chrome) (Version: 40.0.2214.115 - Google Inc.)
HP Deskjet 2540 series Basissoftware van het apparaat (HKLM\...\{A7F14256-6DC6-458A-A92D-B5EEF79429AB}) (Version: 32.2.188.47710 - Hewlett-Packard Co.)
HP Deskjet 2540 series Help (HKLM-x32\...\{50467ECF-F6A9-40EC-A649-67EB6FAD9894}) (Version: 30.0.0 - Hewlett Packard)
HP FWUpdateEDO2 (HKLM-x32\...\{415FA9AD-DA10-4ABE-97B6-5051D4795C90}) (Version: 1.2.0.0 - Hewlett-Packard)
HP Photo Creations (HKLM-x32\...\HP Photo Creations) (Version: 1.0.0.7702 - HP)
HP Update (HKLM-x32\...\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard)
HPDiagnosticAlert (x32 Version: 1.00.0001 - Microsoft) Hidden
HPDiagnosticCoreDll (HKLM-x32\...\{9262B08F-E183-4FED-A2BD-23FF1A84EB79}) (Version: 1.0.15.0 - Hewlett Packard)
Intel® Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1144 - Intel Corporation)
Java 8 Update 25 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218025F0}) (Version: 8.0.250 - Oracle Corporation)
Junk Mail filter update (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Kaspersky Total Security (HKLM-x32\...\InstallWIX_{8ED07EBD-22AD-415A-B71E-C1AD86862C2E}) (Version: 15.0.1.415 - Kaspersky Lab)
Kaspersky Total Security (x32 Version: 15.0.1.415 - Kaspersky Lab) Hidden
Malwarebytes Anti-Malware versie 2.0.4.1028 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.4.1028 - Malwarebytes Corporation)
Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft .NET Framework 4.5.2 (Nederlands) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1043) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft Office 2010 (HKLM-x32\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office Klik-en-Klaar 2010 (HKLM-x32\...\Office14.Click2Run) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office Starter 2010 - Nederlands (HKLM-x32\...\{90140011-0066-0413-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-3839137701-2974941544-2065132041-1002\...\OneDriveSetup.exe) (Version: 17.0.4035.0328 - Microsoft Corporation)
Microsoft PowerPoint Viewer (HKLM-x32\...\{95140000-00AF-0413-0000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft ReportViewer 2010 Redistributable (HKLM-x32\...\{C19B3EB6-B54C-3204-A4DF-88432E0C79F7}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft SkyDrive (HKU\S-1-5-21-3839137701-2974941544-2065132041-1007\...\SkyDriveSetup.exe) (Version: 16.4.6013.0910 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Windows Debugging Symbols (HKLM-x32\...\{C6DB958A-50CC-481B-9ED8-3BAD236F7B49}) (Version: 7601 - Microsoft)
Movie Maker (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MyDriveConnect 3.3.0.1812 (HKLM-x32\...\MyDriveConnect) (Version: 3.3.0.1812 - TomTom)
NVIDIA 3D Vision stuurprogramma 347.52 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 347.52 - NVIDIA Corporation)
NVIDIA Grafisch stuurprogramma 347.52 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 347.52 - NVIDIA Corporation)
NVIDIA HD Audio-stuurprogramma 1.3.33.0 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.33.0 - NVIDIA Corporation)
NVIDIA PhysX System Software 9.11.0621 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.11.0621 - NVIDIA Corporation)
NVIDIA Update 10.4.0 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 10.4.0 - NVIDIA Corporation)
PlayReady PC Runtime amd64 (HKLM\...\{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}) (Version: 1.3.0 - Microsoft Corporation)
Poczta usługi Windows Live (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Podstawowe programy Windows Live (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Pošta Windows Live (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Productverbeteringsonderzoek voor HP Deskjet 2540 series (HKLM\...\{08FB88A2-3FB6-4E82-AD55-393EBAD0E967}) (Version: 32.2.188.47710 - Hewlett-Packard Co.)
Raccolta foto (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 6.3.273.37 - Realtek Semiconductor Corp.)
Reimage Express (HKLM\...\Reimage Express) (Version: 1.0.3.3 - Reimage)
salesale (HKLM-x32\...\{37476589-E48E-439E-A706-56189E2ED4C4}_is1) (Version:  - salesale) <==== ATTENTION
SAMSUNG Intelli-studio (HKLM-x32\...\Intelli-studio) (Version:  - )
Spelling Dictionaries Support For Adobe Reader X (HKLM-x32\...\{AC76BA86-7AD7-5464-3428-A00000000004}) (Version: 10.0.0 - Adobe Systems Incorporated)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
Stuurprogrammapakket voor Windows - Fedict SmartCard  (10/04/2011 4.0.0.5) (HKLM\...\3FE3642036A0F4AEC17772437CE14BB1E67006AA) (Version: 10/04/2011 4.0.0.5 - Fedict)
swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
TeamViewer 10 (HKLM-x32\...\TeamViewer) (Version: 10.0.40798 - TeamViewer)
Visual Studio C++ 10.0 Runtime (HKLM-x32\...\{4412F224-3849-4461-A3E9-DEEF8D252790}) (Version: 10.0.0 - TomTom International B.V.)
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3505.0912 - Microsoft Corporation)
Yontoo 2.052 (HKLM\...\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}) (Version: 2.052 - Yontoo LLC) <==== ATTENTION
Συλλογή φωτογραφιών (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
 
==================== Custom CLSID (selected items): ==========================
 
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
 
CustomCLSID: HKU\S-1-5-21-3839137701-2974941544-2065132041-1002_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\transit\AppData\Roaming\Dropbox\bin\Dropbox.exe /autoplay No File
CustomCLSID: HKU\S-1-5-21-3839137701-2974941544-2065132041-1002_Classes\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}\InprocServer32 -> C:\Users\transit\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3839137701-2974941544-2065132041-1002_Classes\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}\InprocServer32 -> C:\Users\transit\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3839137701-2974941544-2065132041-1002_Classes\CLSID\{CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B}\InprocServer32 -> C:\Users\transit\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3839137701-2974941544-2065132041-1002_Classes\CLSID\{D0336C0B-7919-4C04-8CCE-2EBAE2ECE8C9}\InprocServer32 -> C:\Users\transit\AppData\Local\Google\Update\1.3.25.11\psuser_64.dll No File
CustomCLSID: HKU\S-1-5-21-3839137701-2974941544-2065132041-1002_Classes\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}\InprocServer32 -> C:\Users\transit\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3839137701-2974941544-2065132041-1002_Classes\CLSID\{F8071786-1FD0-4A66-81A1-3CBE29274458}\InprocServer32 -> C:\Users\transit\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\FileSyncApi64.dll (Microsoft Corporation)
 
==================== Restore Points  =========================
 
17-04-2015 14:59:26 Removed Adobe Reader XI (11.0.10) - Nederlands.
17-04-2015 15:01:06 Removed Adobe Reader XI (11.0.10) - Nederlands.
17-04-2015 15:30:35 Installatieprogramma voor Windows-modules
17-04-2015 16:27:26 Installed SLOW-PCfighter.
17-04-2015 16:30:32 Fighters Backup
17-04-2015 17:18:39 exploter
18-04-2015 10:25:51 Installatieprogramma voor Windows-modules
18-04-2015 11:02:50 Herstelbewerking
18-04-2015 11:22:43 Installatieprogramma voor Windows-modules
18-04-2015 12:33:46 Removed Java 7 Update 76 (64-bit)
18-04-2015 12:36:53 Windows Update
 
==================== Hosts content: ==========================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____N C:\Windows\system32\Drivers\etc\hosts
 
==================== Scheduled Tasks (whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
 
Task: {004A59DD-0CD0-48FE-AD8E-50037D0B5211} - System32\Tasks\{81C5B759-FF0B-46CE-84A8-89D669780F07} => C:\POLAX\Polax.exe [2001-12-27] ()
Task: {07511566-5EFA-44D8-B54A-96A839FB4940} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-04-17] (Adobe Systems Incorporated)
Task: {08AD675C-78E2-4C28-A195-03D5E3092C32} - System32\Tasks\{ED19E1C3-8C8E-4068-ABBB-3F14C0916900} => C:\digosoft\digo.exe [2012-05-21] ()
Task: {0EF33F4E-247B-4A59-8ECC-AF1CD752B9A3} - System32\Tasks\Microsoft\Windows\Media Center\StartRecording => C:\Windows\ehome\ehrec.exe
Task: {1151529D-38AE-46EC-A02B-1363A1A8D351} - System32\Tasks\{97043C5F-54E3-4B29-90E1-55167C3C6216} => C:\POLAX\Polax.exe [2001-12-27] ()
Task: {126D4E91-3891-4847-BAC8-47720DEE87F7} - System32\Tasks\{A80688EE-9AEB-414D-AC41-9BCEF6B0A689} => C:\Users\transit\Desktop\POLAX\polax\Polax.exe
Task: {1CCC9F0E-4523-4FF0-8190-DCABF2C96743} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxcontent => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-25] (Microsoft Corporation)
Task: {1E8A395B-EA24-4F17-A9B9-5DCBC117B411} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfig => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-25] (Microsoft Corporation)
Task: {1FDB7AF3-6786-4302-8BCD-5E78A5EB1322} - System32\Tasks\{87DCE43B-5D3C-4981-81B8-CEB1BB2F98AE} => pcalua.exe -a C:\Users\transit\Desktop\windows-live-messenger.exe -d C:\Users\transit\Desktop
Task: {2915B59A-96C8-413C-A63A-7B77B25EEE95} - System32\Tasks\{E6B6C12B-5E62-46A2-8B7B-01F892CD7BA3} => C:\POLAX\Polax.exe [2001-12-27] ()
Task: {2A21520C-26AF-4116-830A-5CF06BBFDF92} - System32\Tasks\{0B90DE2A-AFE4-4574-963D-5387DCAACE9E} => C:\Users\transit\AppData\Local\iLivid\iLivid.exe
Task: {2D5904E5-E1C4-4A0F-AACA-053FA1F77000} - System32\Tasks\{BECA6EBB-F09F-40F9-999B-6BEACA975A2F} => C:\Users\transit\Desktop\POLAX\polax\Polax.exe
Task: {2F30E610-459D-4D12-BD13-0ABB00195095} - System32\Tasks\{476E3058-9339-41F6-8093-F6DAEF21E489} => C:\POLAX\Polax.exe [2001-12-27] ()
Task: {3F6AF2EE-DC50-42CD-B263-93F949D28BA8} - System32\Tasks\{27219742-9C26-4399-988F-BEC36EBA342D} => C:\POLAX\Polax.exe [2001-12-27] ()
Task: {451ED1C6-E3C9-493D-9153-E7A4C10FBB45} - System32\Tasks\{A524AE01-64F6-4CF1-B185-84C161D68BE2} => C:\digosoft\digo.exe [2012-05-21] ()
Task: {507FA522-84FB-4C7E-91DE-2C4CB7CBF79E} - System32\Tasks\SmartWeb Upgrade Trigger Task => C:\Users\transit\AppData\Local\SmartWeb\SmartWebHelper.exe <==== ATTENTION
Task: {5C676637-9DF8-4509-90A0-6E757725816D} - System32\Tasks\{50C37B14-2259-4BCD-B52E-783030EF8F71} => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 15.0.1\avpui.exe [2014-08-30] (Kaspersky Lab ZAO)
Task: {6BAF0B69-9610-4F68-9B26-CEB692D234C0} - System32\Tasks\{D24854C4-754C-4629-BD4B-4E64A4182239} => Chrome.exe 
Task: {6CF08229-C3E1-464D-9312-FF1BF08D0168} - System32\Tasks\{D01BDC77-7FD7-4F19-906D-BEBBA2C8913B} => C:\POLAX\Polax.exe [2001-12-27] ()
Task: {6EE7B04C-350B-4608-BC4E-A60B80BC1693} - System32\Tasks\{6D87EEA5-1509-4B98-A666-FA989574B84C} => C:\Users\transit\AppData\Local\iLivid\iLivid.exe
Task: {7226CC10-B3A4-459C-92A5-8C0B954CF9AC} - System32\Tasks\{1E44404E-8B72-452D-8498-10DBE60EBF0C} => C:\digosoft\digo.exe [2012-05-21] ()
Task: {76D3377E-7B04-4FC4-8EAD-045851B5482F} - System32\Tasks\{C7ADE54A-98C4-4561-B488-F4AECB96FC7D} => C:\Users\transit\AppData\Local\iLivid\iLivid.exe
Task: {790CA437-1925-47B9-BBF9-AF4335C11EB7} - System32\Tasks\{A02B6ABC-C50D-4680-8DE7-FE0BDDBE7928} => C:\POLAX\Polax.exe [2001-12-27] ()
Task: {7A4E990B-41D0-4B85-ACC0-A704048BF869} - System32\Tasks\{3A580740-5F12-4B2B-8145-B4F2CE15A9E3} => pcalua.exe -a "C:\Users\transit\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TYUPHMOW\pure9.1.0.124nl.exe" -d C:\Users\transit\Desktop
Task: {808A239B-CB70-4D90-AB08-AB860F7264F8} - System32\Tasks\{F00A7E00-4D5B-4D15-BFF3-9B4AAB175A3D} => C:\POLAX\Polax.exe [2001-12-27] ()
Task: {86F8AE53-DF9F-4C53-96D3-179E0C50B287} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated)
Task: {9AA0B14C-9084-43A4-895E-D660B85AE351} - System32\Tasks\ReimageUpdater => C:\Program Files\Reimage\Reimage Protector\ReiGuard.exe [2015-01-14] (Reimage®) <==== ATTENTION
Task: {9F41D46B-DAA2-4CDC-A46D-623B99643A20} - System32\Tasks\HPCustParticipation HP Deskjet 2540 series => C:\Program Files\HP\HP Deskjet 2540 series\Bin\HPCustPartic.exe [2014-03-06] (Hewlett-Packard Co.)
Task: {A6CC5361-E4B6-4588-9DFF-9052C8B45294} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc
Task: {A939B57B-4C43-48E4-8DAE-6DEFE4B00EAD} - System32\Tasks\{2B42464D-0E58-47A4-BDC6-382E841EBACE} => C:\digosoft\digo.exe [2012-05-21] ()
Task: {AA04715B-CD3D-4F3C-B269-FEE890575CDB} - System32\Tasks\Microsoft\Windows\Setup\gwx\runappraiser => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-25] (Microsoft Corporation)
Task: {AB9B3EB5-4971-4F7A-9C0E-19135FFA8618} - System32\Tasks\{BBE38C98-3012-450E-8C92-66E8326EBD74} => C:\Users\transit\AppData\Local\iLivid\iLivid.exe
Task: {AF2A9AB9-97D3-4EA9-B3AE-DA5FD740A58B} - System32\Tasks\{E3B9F4CA-63AA-40C4-812A-881CB1B4DF80} => Chrome.exe 
Task: {B322BBB8-3653-4A4E-985A-4D968C505D33} - System32\Tasks\{9514EDF2-1A91-4E9F-A395-CB65BC391C6E} => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 15.0.1\avpui.exe [2014-08-30] (Kaspersky Lab ZAO)
Task: {B4B832A9-9CF0-4976-AE45-B9914FBF119F} - System32\Tasks\{49A2827B-1E9E-4142-91E3-550C21B01A4D} => C:\POLAX\Polax.exe [2001-12-27] ()
Task: {C2F93822-6370-4737-9FED-70C4EDDC985B} - System32\Tasks\{0E904838-A6D6-49E6-94C9-9148A50BB3EE} => C:\POLAX\Polax.exe [2001-12-27] ()
Task: {C536211A-2615-4B22-95BC-9D101DC8BE33} - System32\Tasks\{F6EA5C37-FEF5-467C-ABDE-771B8D998DCB} => C:\POLAX\Polax.exe [2001-12-27] ()
Task: {CA1E189F-5F29-4FC4-8EEA-DEF423E7D23B} - System32\Tasks\{17EFE308-059E-46D6-8B1C-70226613F8D6} => C:\POLAX\Polax.exe [2001-12-27] ()
Task: {D2093C2A-9D5E-43AF-9CEE-8CB05D511518} - System32\Tasks\{B6273C86-F98D-47D9-90F5-220E9D9E406A} => Chrome.exe 
Task: {DCF6A5C4-1955-415D-9FCB-28D6E13E67E7} - System32\Tasks\{7D4AD985-F398-41DA-A952-F9C1266F2381} => C:\POLAX\Polax.exe [2001-12-27] ()
Task: {DDF08966-2A52-4923-8C81-EF4A0BEAE5FA} - System32\Tasks\{A1E12A37-0C30-495B-8528-02D0F981C87C} => C:\POLAX\Polax.exe [2001-12-27] ()
Task: {E030BAE9-671C-4B06-B532-01D38F6263C8} - System32\Tasks\{687B5129-7122-4341-80E4-56FEE542F839} => C:\POLAX\Polax.exe [2001-12-27] ()
Task: {E212C79A-5141-40D2-AEB5-18D833D0336C} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\Windows\ehome\mcupdate.exe
Task: {F6EB4723-55C9-44DE-9544-7C020D42DA2F} - System32\Tasks\{C1C9685A-AA10-481D-A3F6-DD2993E52B97} => pcalua.exe -a "C:\Program Files (x86)\WinZipper\eUninstall.exe" <==== ATTENTION
Task: {FAEAA3EA-2394-4704-9FA8-E0E353FA964C} - System32\Tasks\Microsoft\Windows\Setup\gwx\launchtrayprocess => C:\Windows\system32\GWX\GWX.exe [2015-03-25] (Microsoft Corporation)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
 
==================== Loaded Modules (whitelisted) ==============
 
2012-01-09 00:18 - 2009-05-18 09:40 - 00053760 _____ () C:\Windows\System32\LXEEPMON.DLL
2012-01-09 00:18 - 2009-01-13 15:15 - 04485120 _____ () C:\Windows\System32\LXEEOEM.DLL
2012-01-08 23:58 - 2009-11-04 15:17 - 00189440 _____ () C:\Windows\system32\spool\PRTPROCS\x64\lxeedrpp.dll
 
==================== Alternate Data Streams (whitelisted) =========
 
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
 
 
==================== Safe Mode (whitelisted) ===================
 
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
 
==================== EXE Association (whitelisted) ===============
 
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
 
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-3839137701-2974941544-2065132041-1002\Control Panel\Desktop\\Wallpaper -> C:\Users\transit\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
HKU\S-1-5-21-3839137701-2974941544-2065132041-1007\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\MEDION\Wallpaper.jpg
DNS Servers: 192.168.1.1
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
(Currently there is no automatic fix for this section.)
 
MSCONFIG\Services: AdobeARMservice => 2
MSCONFIG\Services: AdobeFlashPlayerUpdateSvc => 3
MSCONFIG\Services: ASO3DiskOptimizer => 2
MSCONFIG\Services: BotkindSyncService => 2
MSCONFIG\Services: DatamngrCoordinator => 2
MSCONFIG\Services: IePluginService => 2
MSCONFIG\Services: PSI_SVC_2 => 2
MSCONFIG\Services: ReimageRealTimeProtector => 2
MSCONFIG\Services: Steam Client Service => 3
MSCONFIG\Services: Wpm => 2
MSCONFIG\startupfolder: C:^Users^transit^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^SuperOptimizer.lnk => C:\Windows\pss\SuperOptimizer.lnk.Startup
MSCONFIG\startupreg: Babylon Client => C:\Program Files (x86)\Babylon\Babylon-Pro\Babylon.exe -AutoStart
MSCONFIG\startupreg: CommonToolkitTray => C:\Program Files (x86)\Fighters\Tray\FightersTray.exe
MSCONFIG\startupreg: Driver Whiz => C:\Program Files (x86)\Driver Whiz\Driver Whiz\DriverWhiz.exe /applicationMode:systemTray /showWelcome:false
MSCONFIG\startupreg: HP Software Update => C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
MSCONFIG\startupreg: iLivid => "C:\Users\transit\AppData\Local\iLivid\iLivid.exe" -autorun
MSCONFIG\startupreg: MedionReminder => C:\Program Files (x86)\CyberLink\PowerRecover\Reminder.exe
MSCONFIG\startupreg: MyDriveConnect.exe => "C:\Program Files (x86)\MyDrive Connect\MyDriveConnect.exe"
MSCONFIG\startupreg: Yontoo Desktop => "C:\Users\transit\AppData\Roaming\Yontoo\YontooDesktop.exe"
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-3839137701-2974941544-2065132041-500 - Administrator - Disabled)
Gast (S-1-5-21-3839137701-2974941544-2065132041-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-3839137701-2974941544-2065132041-1010 - Limited - Enabled)
transit (S-1-5-21-3839137701-2974941544-2065132041-1002 - Administrator - Enabled) => C:\Users\transit
UpdatusUser (S-1-5-21-3839137701-2974941544-2065132041-1007 - Limited - Enabled) => C:\Users\UpdatusUser
 
==================== Faulty Device Manager Devices =============
 
Name: Realtek RTL8191SU Wireless LAN 802.11n USB 2.0 Network Adapter
Description: Realtek RTL8191SU Wireless LAN 802.11n USB 2.0 Network Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Realtek Semiconductor Corp.
Service: RTL8192su
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
 
Name: qrnfd_1_10_0_9
Description: qrnfd_1_10_0_9
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Manufacturer: 
Service: qrnfd_1_10_0_9
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (04/18/2015 03:18:18 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Naam van toepassing met fout: digo.exe, versie: 0.0.0.0, tijdstempel: 0x41bdebae
Naam van module met fout: VFP9r.dll, versie: 9.0.0.7423, tijdstempel: 0x49a31c32
Uitzonderingscode: 0xc0000005
Foutoffset: 0x00029842
Id van proces met fout: 0xea8
Starttijd van toepassing met fout: 0xdigo.exe0
Pad naar toepassing met fout: digo.exe1
Pad naar module met fout: digo.exe2
Rapport-id: digo.exe3
 
Error: (04/18/2015 03:01:19 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Het programma iexplore.exe, versie 9.0.8112.16476 reageert niet meer op Windows en is afgesloten. Als u wilt zien of er meer informatie over het probleem beschikbaar is, raadpleegt u de probleemgeschiedenis in het onderdeel Onderhoudscentrum in het Configuratiescherm.
 
Proces-id: 1354
 
Starttijd: 01d079d7ae2e5431
 
Eindtijd: 16
 
Toepassingspad: C:\Program Files (x86)\Internet Explorer\iexplore.exe
 
Rapport-id:
 
Error: (04/18/2015 00:27:37 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Het programma iexplore.exe, versie 9.0.8112.16476 reageert niet meer op Windows en is afgesloten. Als u wilt zien of er meer informatie over het probleem beschikbaar is, raadpleegt u de probleemgeschiedenis in het onderdeel Onderhoudscentrum in het Configuratiescherm.
 
Proces-id: 11bc
 
Starttijd: 01d079c238ad024e
 
Eindtijd: 31
 
Toepassingspad: C:\Program Files (x86)\Internet Explorer\iexplore.exe
 
Rapport-id:
 
Error: (04/18/2015 00:27:07 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Het programma iexplore.exe, versie 9.0.8112.16476 reageert niet meer op Windows en is afgesloten. Als u wilt zien of er meer informatie over het probleem beschikbaar is, raadpleegt u de probleemgeschiedenis in het onderdeel Onderhoudscentrum in het Configuratiescherm.
 
Proces-id: de8
 
Starttijd: 01d079c22561baf6
 
Eindtijd: 15
 
Toepassingspad: C:\Program Files (x86)\Internet Explorer\iexplore.exe
 
Rapport-id:
 
Error: (04/18/2015 00:21:46 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Het programma iexplore.exe, versie 9.0.8112.16476 reageert niet meer op Windows en is afgesloten. Als u wilt zien of er meer informatie over het probleem beschikbaar is, raadpleegt u de probleemgeschiedenis in het onderdeel Onderhoudscentrum in het Configuratiescherm.
 
Proces-id: 1394
 
Starttijd: 01d079beac96024f
 
Eindtijd: 50
 
Toepassingspad: C:\Program Files (x86)\Internet Explorer\iexplore.exe
 
Rapport-id:
 
Error: (04/18/2015 11:33:27 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Het programma IEXPLORE.EXE, versie 10.0.9200.16736 reageert niet meer op Windows en is afgesloten. Als u wilt zien of er meer informatie over het probleem beschikbaar is, raadpleegt u de probleemgeschiedenis in het onderdeel Onderhoudscentrum in het Configuratiescherm.
 
Proces-id: a30
 
Starttijd: 01d079ba24c91fc4
 
Eindtijd: 38
 
Toepassingspad: C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
 
Rapport-id:
 
Error: (04/18/2015 11:21:37 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Het programma IEXPLORE.EXE, versie 10.0.9200.16736 reageert niet meer op Windows en is afgesloten. Als u wilt zien of er meer informatie over het probleem beschikbaar is, raadpleegt u de probleemgeschiedenis in het onderdeel Onderhoudscentrum in het Configuratiescherm.
 
Proces-id: 13cc
 
Starttijd: 01d079b8dfb0a80f
 
Eindtijd: 22
 
Toepassingspad: C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
 
Rapport-id:
 
Error: (04/18/2015 11:13:11 AM) (Source: System Restore) (EventID: 8210) (User: )
Description: Er is tijdens Systeemherstel een onbekende fout opgetreden: (Installatieprogramma voor Windows-modules). Aanvullende gegevens: 0x8000ffff.
 
Error: (04/18/2015 11:01:58 AM) (Source: System Restore) (EventID: 8210) (User: )
Description: Er is tijdens Systeemherstel een onbekende fout opgetreden: (exploter). Aanvullende gegevens: 0x8000ffff.
 
Error: (04/18/2015 10:08:36 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Het programma IEXPLORE.EXE, versie 11.0.9600.17728 reageert niet meer op Windows en is afgesloten. Als u wilt zien of er meer informatie over het probleem beschikbaar is, raadpleegt u de probleemgeschiedenis in het onderdeel Onderhoudscentrum in het Configuratiescherm.
 
Proces-id: 1070
 
Starttijd: 01d079ae9e648290
 
Eindtijd: 20
 
Toepassingspad: C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
 
Rapport-id:
 
 
System errors:
=============
Error: (04/18/2015 11:18:22 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: De volgende opstartstuurprogramma's zijn niet geladen: 
iSafeKrnlMon
qrnfd_1_10_0_9
 
Error: (04/18/2015 11:16:01 PM) (Source: Service Control Manager) (EventID: 7006) (User: )
Description: ScRegSetValueExW-oproep voor Start is niet geslaagd vanwege deze fout: 
%%5.
 
Error: (04/18/2015 11:12:26 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: De volgende opstartstuurprogramma's zijn niet geladen: 
iSafeKrnlMon
qrnfd_1_10_0_9
 
Error: (04/18/2015 03:06:25 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: De volgende opstartstuurprogramma's zijn niet geladen: 
iSafeKrnlMon
qrnfd_1_10_0_9
 
Error: (04/18/2015 02:57:41 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: De volgende opstartstuurprogramma's zijn niet geladen: 
iSafeKrnlMon
qrnfd_1_10_0_9
 
Error: (04/18/2015 01:20:11 PM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
Description: De volgende melding van een onherstelbare fout is ontvangen: 20.
 
Error: (04/18/2015 00:54:07 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: De volgende opstartstuurprogramma's zijn niet geladen: 
iSafeKrnlMon
qrnfd_1_10_0_9
 
Error: (04/18/2015 11:39:10 AM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: De volgende opstartstuurprogramma's zijn niet geladen: 
iSafeKrnlMon
qrnfd_1_10_0_9
 
Error: (04/18/2015 11:10:33 AM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: De volgende opstartstuurprogramma's zijn niet geladen: 
iSafeKrnlMon
qrnfd_1_10_0_9
 
Error: (04/18/2015 11:10:16 AM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: De Function Discovery Resource Publication-service is gestopt met de volgende foutcode: 
%%-2147014847.
 
 
Microsoft Office Sessions:
=========================
Error: (04/18/2015 03:18:18 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: digo.exe0.0.0.041bdebaeVFP9r.dll9.0.0.742349a31c32c000000500029842ea801d079d93c1adf63C:\digosoft\digo.exeC:\Program Files (x86)\Common Files\microsoft shared\VFP\VFP9r.dll6076139b-e5cd-11e4-a197-8c89a57d6dd6
 
Error: (04/18/2015 03:01:19 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: iexplore.exe9.0.8112.16476135401d079d7ae2e543116C:\Program Files (x86)\Internet Explorer\iexplore.exe
 
Error: (04/18/2015 00:27:37 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: iexplore.exe9.0.8112.1647611bc01d079c238ad024e31C:\Program Files (x86)\Internet Explorer\iexplore.exe
 
Error: (04/18/2015 00:27:07 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: iexplore.exe9.0.8112.16476de801d079c22561baf615C:\Program Files (x86)\Internet Explorer\iexplore.exe
 
Error: (04/18/2015 00:21:46 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: iexplore.exe9.0.8112.16476139401d079beac96024f50C:\Program Files (x86)\Internet Explorer\iexplore.exe
 
Error: (04/18/2015 11:33:27 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: IEXPLORE.EXE10.0.9200.16736a3001d079ba24c91fc438C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
 
Error: (04/18/2015 11:21:37 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: IEXPLORE.EXE10.0.9200.1673613cc01d079b8dfb0a80f22C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
 
Error: (04/18/2015 11:13:11 AM) (Source: System Restore) (EventID: 8210) (User: )
Description: Installatieprogramma voor Windows-modules0x8000ffff
 
Error: (04/18/2015 11:01:58 AM) (Source: System Restore) (EventID: 8210) (User: )
Description: exploter0x8000ffff
 
Error: (04/18/2015 10:08:36 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: IEXPLORE.EXE11.0.9600.17728107001d079ae9e64829020C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
 
 
CodeIntegrity Errors:
===================================
  Date: 2012-04-26 10:59:24.325
  Description: De integriteit van de kopie van het bestand \Device\HarddiskVolume2\Users\transit\AppData\Local\Temp\OnlineScanner\Anti-Virus\fsgk.sys kan niet worden geverifieerd omdat de bestands-hash niet is gevonden op het systeem. Tijdens een recente hardware- of softwarewijziging is mogelijk een bestand geïnstalleerd dat onjuist ondertekend of beschadigd is, of dat mogelijk kwaadwillende software van een onbekende bron is.
 
  Date: 2012-04-26 10:59:24.315
  Description: De integriteit van de kopie van het bestand \Device\HarddiskVolume2\Users\transit\AppData\Local\Temp\OnlineScanner\Anti-Virus\fsgk.sys kan niet worden geverifieerd omdat de bestands-hash niet is gevonden op het systeem. Tijdens een recente hardware- of softwarewijziging is mogelijk een bestand geïnstalleerd dat onjuist ondertekend of beschadigd is, of dat mogelijk kwaadwillende software van een onbekende bron is.
 
 
==================== Memory info =========================== 
 
Processor: Intel® Core™ i5-2320 CPU @ 3.00GHz
Percentage of memory in use: 30%
Total physical RAM: 4077.64 MB
Available physical RAM: 2846.92 MB
Total Pagefile: 8153.47 MB
Available Pagefile: 6842.23 MB
Total Virtual: 8192 MB
Available Virtual: 8191.82 MB
 
==================== Drives ================================
 
Drive c: (Boot) (Fixed) (Total:1811.92 GB) (Free:1726.15 GB) NTFS
Drive d: (Recover) (Fixed) (Total:50 GB) (Free:45.44 GB) NTFS
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (Size: 1863 GB) (Disk ID: 2BD2C32A)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=1811.9 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=50 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=1 GB) - (Type=12)
 
==================== End Of Log ============================

  • 0

Advertisements


#2
BrianDrab

BrianDrab

    Trusted Helper

  • Malware Removal
  • 3,591 posts

Hi. My name is Brian, and I would be happy to look into your issue.
 


- General Instructions -

  • Please read all instructions and fixes thoroughly. Read the ENTIRE post BEFORE performing any steps so you understand all that needs to be done.
  • I would advise printing any instructions for easy reference as some of the fixes may require you to boot in Safe mode. Access to these instructions may not be available in Safe Mode.
  • Any fixes provided by myself are for this log file only and should not be used on any other systems.
  • Do not run any other removal software or perform updates other than the ones I provide, as it will complicate the cleaning process.
  • It's very likely that part of our cleanup will include emptying your recycle bin. If you use your recycle bin as an archive and do not wish this to be emptied, please let me know.
  • You have 4 days to reply to each post or the topic will be closed. You will be able to request that the topic be re-opened by sending me a PM (Personal Message) or PM a moderator.
  • Please feel free to ask any questions, especially if you are having problems with my instructions.


- Save ALL Tools to your Desktop-

 

All tools that I have you download should be placed on the desktop unless otherwise stated. If you are familiar with how to save files to the desktop then you can skip this step.
 
Since you are continuing with this step then I assume you are unfamiliar with saving files to your desktop. As a result it's easiest if you configure your browser(s) to download any tools to the desktop by default. Please use the appropriate instructions below depending on the browser you are using.
Chrome.JPGGoogle Chrome - Click the "Customize and control Google Chrome" button in the upper right-corner of the browser.Settings.JPG Choose Settings. at the bottom of the screen click the
"Show advanced settings..." link. Scroll down to find the Downloads section and click the Change... button. Select your desktop and click OK.
Firefox.JPGMozilla Firefox - Click the "Open Menu" button in the upper right-corner of the browser. Settings.JPG Choose Options. In the downloads section, click the Browse button, click on the Desktop folder
and the click the "Select Folder" button. Click OK to get out of the Options menu.
IE.jpgInternet Explorer - Click the Tools menu in the upper right-corner of the browser. Tools.JPG Select View downloads. Select the Options link in the lower left of the window. Click Browse and
select the Desktop and then choose the Select Folder button. Click OK to get out of the download options screen and then click Close to get out of the View Downloads screen.
NOTE: IE8 Does not support changing download locations in this manner. You will need to download the tool(s) to the default folder, usually Downloads, then copy them to the desktop.
 

- Finally Before We Start-

 
Removing malware is a complicated multiple step process, Please stay with me until I have declared your system clean. I strongly recommend you backup your personal files and folders. Although rare, attempting to remove malware can render your machine unbootable or cause data loss. Having backups of your data is your responsibility. Your security programs may give warnings for some of the tools I will ask you to use. Be assured, any links I give are safe.

 

 

 

Please do the following.

 

Step#1 - JRT
1. Download Junkware Removal Tool to your desktop.
1. Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
2. The tool will open and start scanning your system.
3. Please be patient as this can take a while to complete depending on your system's specifications.
4. On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
5. Close the text file and reboot your machine.
6. Post the contents of JRT.txt into your next message.

 

Step#2 - AdWCleaner
1. Please download AdwCleaner by Xplode onto your desktop.
2. Close all open programs and internet browsers.
3. Right-click on AdwCleaner.exe and select Run as administrator to run the tool.
4. Click on Scan.
5. After the scan is complete click on "Clean"
6. Confirm each time with Ok.
7. Your computer will be rebooted automatically. A text file will open after the restart.
8. Please post the content of that logfile with your next answer.
9. If need be, you can also find the logfile at C:\AdwCleaner\AdwCleaner[S0].txt as well.

 

Step#3 - Re-install Chrome
Unless you did this yourself, malware has changed your Chrome version into the Development Build. Among other things this allows malware to install any extension it wants. We need to resolve this.
1. If you have bookmarks, let's save them by exporting them - Export Bookmarks
2. Then I need you to go Google Sync and sign into your account
3. Scroll down until you see the "Stop and Clear" button and click on the button. At the prompt click on "Ok"
4. Now we need to uninstall chrome. Note: When asked about user data or settings you must remove this also so please check the box.
5. Restart the computer and reinstall chrome, You can download The latest version from here - Google Chrome
6. Import your bookmarks back into Chrome
7. Sign back in to your Chrome browser so that your bookmarks sync with your online account.
 

Step#4 - Fresh Set of Logs
 
1. Right click on FRST64.exe and select Run as administrator. When the tool opens click Yes to disclaimer.
2. Please ensure you place a check mark in the Addition.txt check box at the bottom of the form before running.
3. Press Scan button.
4. It will produce a log called FRST.txt in the same directory the tool is run from (which should now be the desktop)
5. Please copy and paste log back here.
6. Because you selected the Addition.txt check box this log will be created as well. Please copy and paste this log as well.
 
 
 
Items for your next post

1. Junkware Log

2. AdwCleaner log
3. FRST and Addition logs

 


  • 0

#3
HaraMo

HaraMo

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 456 posts
  • Do not run any other removal software or perform updates other than the ones I provide, as it will complicate the cleaning process.

windows update did install new updates.

 

and I'm intalling a backup software to first make a backup

 

Do I have to rerun the analyse with FRST?


  • 0

#4
HaraMo

HaraMo

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 456 posts
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.6.0 (04.20.2015:1)
OS: Windows 7 Home Premium x64
Ran by transit on wo 22/04/2015 at 14:07:58,77
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
 
 
 
~~~ Services
 
Successfully stopped: [Service] isafekrnlmon
Successfully deleted: [Service] isafekrnlmon
Successfully stopped: [Service] reimagerealtimeprotector
Successfully deleted: [Service] reimagerealtimeprotector
 
 
 
~~~ Tasks
 
Successfully deleted: [Task] C:\Windows\system32\tasks\ReimageUpdater
 
 
 
~~~ Registry Values
 
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bitguard.exe
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bprotect.exe
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bpsvc.exe
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserdefender.exe
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserprotect.exe
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browsersafeguard.exe
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dprotectsvc.exe
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\protectedsearch.exe
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchinstaller.exe
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotection.exe
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotector.exe
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchsettings.exe
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchsettings64.exe
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\snapdo.exe
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\umbrella.exe
Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL
Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\\Search Page
Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search\\SearchAssistant
Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\\DisplayName
Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\\URL
Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}\\DisplayName
Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}\\URL
 
 
 
~~~ Registry Keys
 
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{6157f868-f12f-4ba9-804a-09533fccf080}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{a1c8fa6f-f886-4e2c-a175-0e59314e7bd1}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\MapsGalaxy_39.ToolbarProtector
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\MapsGalaxy_39.ToolbarProtector.1
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2498}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{E733165D-CBCF-4FDA-883E-ADEF965B476C}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{425ED333-6083-428a-92C9-0CFC28B9D1BF}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2498}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6157f868-f12f-4ba9-804a-09533fccf080}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{a1c8fa6f-f886-4e2c-a175-0e59314e7bd1}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{6157f868-f12f-4ba9-804a-09533fccf080}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{a1c8fa6f-f886-4e2c-a175-0e59314e7bd1}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Eventlog\Application\NVIDIA Update Service
 
 
 
~~~ Files
 
Successfully deleted: [File] C:\Users\transit\appdata\local\google\chrome\user data\default\local storage\http_static.boostsaves.com_0.localstorage-journal
Successfully deleted: [File] C:\Users\transit\appdata\local\google\chrome\user data\default\local storage\http_static.boostsaves.com_0.localstorage
Successfully deleted: [File] C:\Users\transit\appdata\local\google\chrome\user data\default\local storage\https_static.boostsaves.com_0.localstorage-journal
Successfully deleted: [File] C:\Users\transit\appdata\local\google\chrome\user data\default\local storage\https_static.boostsaves.com_0.localstorage
Successfully deleted: [File] C:\Windows\patsearch.bin
Successfully deleted: [File] C:\Windows\reimage.ini
 
 
 
~~~ Folders
 
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{0090C502-530E-471A-9AD2-60AAFB947233}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{00BBA366-FA5E-470A-AF2D-A2FDF04B6119}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{00CFA0E9-6252-4942-8645-71D9B498D782}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{012B7ECC-D0FC-44E4-A5AD-2EA8046A3971}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{01A4E2C8-0EAF-424D-AC9B-909C820B7927}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{02066675-EDCD-4DE1-A2CD-81809001D657}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{02095586-00E9-4877-92D6-CBBD324C5970}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{040DB3FF-DE95-4921-9EDB-34F98133982F}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{05C40C60-152E-4199-8E1C-E064F08159A0}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{05CD1053-B4AD-4793-910A-A1C34C321F81}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{0657B061-D660-4E71-BCB4-C9603F52EC01}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{07A63C40-0129-418F-85ED-AD5B07367634}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{07D03144-58F6-43F5-8E18-56C9858A3E3C}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{0866863A-9AA9-413B-A2D9-91FAC39D6D10}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{08EDD6D0-FCE6-4AE4-BC07-43D2D02A448A}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{0C7FBD47-5A38-4A25-A8D1-4F1048DE34D0}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{0D930D03-76E1-44C1-8F01-A6093D2CCCDB}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{0DDF9C53-AD88-4BAF-AD92-E9DC17776598}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{0DE13FEC-FB04-445E-9330-AEC8A6DD2ABF}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{0EF03565-BDE1-4048-943B-B6789341B609}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{0F4F1C4F-DD97-4F30-BB08-917B6AF8E86C}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{0F9C173D-A47E-4572-9EAB-9D432DBE22FD}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{0FC55C29-77BE-4BCC-96B5-9D544B83F4E3}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{0FC7EA6B-5D7B-49A5-9370-939802465688}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{1005867A-C45A-430F-B133-15D34DA4D905}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{10832FF5-4F2D-4B29-975E-C109BD271D24}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{10F87655-CF77-4EE8-B58E-0DE6AF27B54F}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{123ED420-AB90-4095-B6C7-18D9C913188C}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{12AEDC8C-88E1-4C8A-9D5A-0D26C4BE08CF}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{131263E9-1D1D-4C49-8538-E15B4ECAB1FA}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{142550EF-92F4-42C1-8A07-375D31319CAB}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{14B60C2E-D066-4F7D-B75B-396274DCE333}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{156B7E42-08C0-41AC-B35C-4C587639C41A}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{160CF53B-59A6-44A1-B7FE-977CB4DBDC27}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{16AC4374-44FA-4222-B880-E53DFE821072}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{17E48891-A740-4995-A990-C41D97C06E52}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{18F87E5D-DB09-43C7-97C0-240F90301B14}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{193E8E5C-5C1B-458E-B71A-CFBE1F081E7B}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{1AD91A06-3045-44BA-8746-CDA9B0D8BEA2}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{1AECA8D9-5929-4AE2-B9E4-F1575F768329}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{1AF77DF5-542C-41E3-AAAE-14CC0D4BA72F}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{1BC86C74-780B-4BED-B103-C2CCF8F75411}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{1D25924B-4366-46DF-9E41-3DC195D3F65E}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{1D3634D8-6016-445E-92DC-5566F4E6886B}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{1D42192F-B57A-403E-84A7-0CC810E545FD}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{1E677AD0-11B7-433A-91F1-D7B8B2FA1213}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{20354D31-90C1-4064-A6D1-B7D67F3F6F88}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{20DE26B4-DA73-44C7-98D5-28DB8CC8DB43}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{2142FCBB-84F6-427A-BC3A-0B61EACA7EE4}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{21A17FFD-1C08-49CE-BFAA-A60F193D7157}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{21FA9311-E5F3-47D4-8446-C58BB625972A}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{2297EF16-FAED-45B9-95A6-256A19B254D4}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{22A99C16-ECB6-4235-B83D-E55804FB5B61}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{22C08553-B3BC-45A1-AA7A-5AA590A48119}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{231A41E7-E03F-4DDE-BD2D-53234FFF07DC}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{23256762-E4EB-45F4-BBC3-47AA6FFEBB3B}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{233B7EBD-3C52-49C6-A21D-8C9A4DF4291A}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{239F8ECA-73DB-4512-993E-07F102F5C631}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{250F4554-B127-4FD7-BA78-C8E19302348A}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{2510AF38-A9EB-42D2-8860-C32A4B96992C}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{25402B42-31FE-4A1C-94ED-4A5457F5DD51}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{267A4F72-A0C7-4EC3-95FC-D0440202B5B2}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{2745FAEB-B345-4D23-AB53-AA2836A98CAF}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{2754F3E3-E320-414A-8958-2423173541C7}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{287F080F-7FAD-44B0-8AD9-9027FE12DC29}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{28A745B8-9165-4A53-9869-FB1902A0F6BC}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{28E0547F-9FD3-42B5-849F-BAB7DC992A72}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{28E33B25-02B6-4043-8431-FD4AF30E8384}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{2990C3C9-0350-4BE3-A2A4-AE12F3BFF0FF}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{29FE2938-C0E5-428D-9D31-6AE884FAFB46}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{2A1EABA4-DF4C-4AD6-963F-8D15A0A7659E}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{2C0789E2-9A62-4DA1-8532-2B750668BAEF}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{2CB2BF2D-202E-4D38-888E-AA347B7BAA76}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{2CD19204-2F81-46E6-B8A7-6F1317BCFDBF}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{2D76919B-F30A-4C6F-A4DA-A41C92D0D558}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{2DC9533A-6C0F-4D4E-9003-B6496DEA5D3E}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{2DD59C40-A58F-4783-BCC6-3D229C57995F}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{302E9489-452B-4079-871E-3783DE6F9753}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{306B52EA-6BDF-4AAF-B1E9-D67F0C637BA2}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{30AFF87A-B3E0-4B89-A2BF-2A845E4378D2}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{311B590E-D4E6-40E0-9279-FF182641CABF}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{3213DD1B-E294-447C-8BF4-844F0D0B1674}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{33B0B0FD-30C3-4457-8FAD-C6A274294C7A}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{347885CC-9B06-4562-A800-EC7E757BC8CD}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{34C07ACF-7559-431B-96C7-D0DF8277EA3E}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{34D30F90-A33A-4A67-8639-1468DF0D2C54}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{366EECC4-E9BA-4640-B0E8-370A31F5DA0B}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{36AC719D-265D-4D02-AB27-1DB0198134F0}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{36E9D92F-2852-4099-9A07-BAC897BB09CA}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{37BC0B91-7839-425C-868A-36785641B8AE}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{37D46C63-E186-4DF1-9228-BD3D93F0592A}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{37F89889-4B7F-438B-AE46-F5287C5EEAEB}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{38166DA0-EAE5-4CB2-95A5-C3619E6D550C}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{3833E113-5E6F-4AB3-996F-85CD26E3E8B5}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{38B59BB7-6F65-4C9F-A077-09A7EF7F5F69}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{3A193F5B-8E38-4E20-861E-05BEE0E7437B}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{3A89F138-493D-45A6-8ADC-0E9FC9A84CE6}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{3AB0C545-8DD6-4C18-A568-A66F94474E06}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{3AE82335-4AE5-4A5A-A0AE-E5F6CB78343C}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{3AFD5624-3E9E-4309-BDC0-AC4036A04C30}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{3B21D74E-CF73-4A3E-BAD5-DD3AD9AAFEAD}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{3B6B4513-045D-4A96-9ADA-761C39418261}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{3B761762-31A6-405A-9B3B-2688176A7419}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{3BD5BDBA-88FF-4B92-BFEB-6B75F34463AA}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{3C382821-C40E-4A49-A2B8-E2643376B4B6}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{3C3C3F3D-27D1-4D4B-8EA2-7AAC8604F3CE}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{3C41E849-6A37-4180-91CD-AD4F0A043C80}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{3C7662B2-F207-49DD-A6F4-B04E39AD368F}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{3D20EA16-D3FB-4C4C-BB9D-4BAD25A512EB}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{3DF378BD-9635-4A5F-A739-B97D40C83EEF}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{3E6016C6-B6E1-4F73-92C3-3C9A6E8A092D}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{3EADAC2F-2A6B-4A93-AD4C-D73A39921EFA}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{3FC0F764-CBB2-4719-A61D-1593EA1C25E1}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{3FEF6ABF-B620-4F0B-ACA3-9979D86A9962}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{40344423-CBF5-498B-BE38-A43D43A2706E}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{40374A04-6DF7-41CF-96F1-E9170CC9FC41}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{406698F7-6530-4118-82D3-6EF357139EE0}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{406ED295-6208-41EA-A64F-01B3E5ACABAA}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{40749D51-D687-4AAC-AF10-F40FE8E848E9}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{414B01AA-A790-4439-9905-7FB336EA4F7B}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{415526F6-BB63-4133-BE9E-3F9868386837}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{4233CFF2-B6B2-43C4-AE7F-E9ABE2C99CB6}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{42C22824-1E77-4511-83FE-5ABA12B82D23}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{42DBFBF2-EBEE-4FF9-8538-A7AA4367106E}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{42F682A2-F46F-447A-88DA-0F202521E4C3}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{4376B332-0487-4873-BC00-BEF3B52AB16A}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{44475D39-3368-4845-A6EC-CFEC942B7875}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{44861222-A84E-4902-BAB6-194574C55FDA}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{45833FE4-C055-4284-8560-35BA5E305F4A}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{4644FCE2-6720-41B0-BCF2-9D35789EA3D5}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{46AFDB55-F095-4498-A7DE-8A3EF5543FDC}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{47AD7199-7A28-42B9-8432-129D2D6FA7C1}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{481C8A26-C5B4-4ED4-A3C2-E294BF70DF9D}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{48B15ABF-A962-4C7C-98D9-E48CA38E871F}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{4905F4B9-F7A8-4724-BB4D-B08E51146C3B}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{491209CF-52B3-4895-8967-E44CA00B46CA}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{4942ED9D-3726-4FD6-B2E2-B97E4524619C}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{49C1F7AB-8F32-4ABB-9BA2-D2E3C9AEDEF1}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{4A8D20EA-D67A-4872-A476-CC3278FBC291}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{4A90B291-164C-48D1-9867-74083B14887F}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{4AA39267-9CBE-4155-9E30-B3FA4808B0C3}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{4B40C8F8-EE1C-49F4-ABA3-B6C51B002864}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{4BE20AB7-0580-4CA2-B2CA-CD15539FDA1C}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{4C79E98B-0BB3-4A41-84EC-417CD46947C0}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{4CA18212-08CD-43BC-B7A2-8E69FB1F9C42}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{4DB1D1EF-8E83-413F-BBC7-F8B4AE887913}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{4DE0EDB1-18D1-4B50-B192-CDF61B8B758C}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{4EAE0C47-4492-4FBC-8E80-9D5DA8B70EEC}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{4F2AA944-2D6C-47EA-8150-83670B3AE689}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{506783BE-D33B-483A-9849-42B275387D50}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{50B0CC55-0C83-4E6E-9C3A-88E50C539A82}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{50F2002B-CC23-4386-AFFE-C7EEE26DAE1F}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{51332D32-B34F-4FC1-9703-8CEA7E01461D}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{514A70F6-4437-4773-BE9B-655BB26E53D0}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{51A031F1-4ABC-41E9-9E0A-B7CC91691B54}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{51F304C5-E0B4-4203-B6D5-62B5395E1AE3}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{52725F96-5625-4A22-9945-8CD010A8FFE0}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{538F1960-51BA-4708-8338-4EDA731EFCF9}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{5444BC5F-A224-4864-9608-1F8135551D9D}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{54B186CC-1A1C-4D77-9054-57505C532A24}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{55BA07D0-9835-4314-BFE7-EC283C7F3AA6}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{560961B4-9FFA-4755-A466-96C1F6319146}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{58528CEF-6FE1-42CE-8C3B-16137EE23C4A}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{58AA4DAA-3C2A-45ED-8A61-2997035FE234}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{59820F80-740F-453C-890F-43D717F994FD}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{59F21ED3-5612-4ACC-A197-C1081ADAF76A}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{5A426D20-48DF-48EE-BC22-7F60A9920309}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{5A4AA72E-6911-4B6C-AF9A-93273CFAD1E9}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{5BC0112B-45BB-48B9-8D21-CA845E5EEA68}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{5C1895CD-2E1A-4522-A307-21E64F4BFA38}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{5C24FC8D-8D98-418B-87AC-0696A835566B}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{5C2B8AB4-C0D1-49D7-AE07-14A5D033E813}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{5CBA21E9-DECD-408C-8819-4C2A83E24DF5}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{5CCB97DB-9FEC-48F4-8556-093CB32B8124}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{5DB6550E-9572-4CF7-959C-71D6F6A584E9}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{5E4F1753-757C-4275-9925-58E1CA3DCFDC}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{5E879CFB-57D9-4C8A-A70B-2C9A30AF2ED4}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{5F32A569-D3A4-4553-9538-AD16818A6154}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{5F832C5E-99D1-4A6F-A50E-B293C9F11BBA}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{5F8E9CDD-8527-4167-9606-84C04D19AA17}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{5FC779B7-DD0B-45BA-8BCF-DA5CA5E17287}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{60C0A912-9899-4ACC-866D-4C81A7D97531}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{61160692-606C-4AAF-A7BB-BA8E899EAEBD}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{6159918F-AD48-414B-9131-107A668C0092}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{6185AFAD-206D-4CAF-B0F4-2B6E9E32C762}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{61C4D24C-A956-4A47-A248-71643F8FADCB}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{61DBE5F6-354B-47D4-953D-1CEA74881ED3}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{624D9E95-D850-4E92-ABF9-6DF6CE04A0E0}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{628BD465-21D3-4903-BAA2-ABF7EBBDCFE2}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{62B69B2A-9F8D-4FF8-86F4-02BBAE271D59}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{6346716D-A35E-4B2F-A217-DD30A3D3EC83}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{63A9196A-F49E-4D72-97B2-F1057C954B9A}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{63B2DD11-7503-42F5-8DB2-FA5919F2BF69}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{63EED96A-B2D9-43A1-8B16-E1178A09C627}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{646E130B-AFC8-4803-9238-DF8466BCE9FA}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{64F8F7AA-FB53-424D-8903-2EDF04B6F83B}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{663250A5-FFB1-4D57-8983-CDABBCD3ADB4}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{67B733C8-5093-4A69-AEAD-1F8E795D3059}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{67DC7291-A7A9-413B-85FC-F4D2AEB94622}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{689BD82A-8016-43DB-B6A2-01792C65F92F}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{6906FEE2-D3BB-4324-AFFB-615AB78F5BBD}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{6AF74180-CB19-4540-A384-3DCF193D1F8D}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{6B69F71C-FB30-4454-8534-AA65CB43909C}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{6BBBCFCD-4158-44A4-BC1B-CA6E6D20F68A}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{6BDD84D1-D772-4043-9CA3-0153A63E7E53}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{6C19E0DC-4963-4626-BB1C-EBFA9510042F}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{6C7C095E-8FC7-453C-94E7-799003836618}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{6C8F1EAA-A8A0-41D4-88BF-FB68767077DF}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{6D379AEE-2467-4F93-95A7-9D7F7E486A30}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{6DA75590-0932-47FE-A4E8-2008204D466D}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{6DC11B61-E99D-4E4E-BF75-1BC2635AAE41}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{6DF999D2-5CBA-4FEE-BF68-2D991C9D31C2}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{6DFFFB0C-AD53-46A0-833B-72ED7037110B}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{6F4057E9-B076-4497-B575-18A5A1434C56}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{6F4863E0-AC14-45CC-9E79-3307E591045F}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{6F73CAE1-3735-4AF3-AEF4-5B97792B8426}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{6F7A9E1E-09EE-4DA2-A726-5B0222D84F01}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{6F8C7A4F-446E-441E-B6AB-0B6F3507E944}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{6FBB48EB-112D-4EB5-A867-8E855DF1219C}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{7045236C-6FCA-4FB2-A83B-21DDF5588933}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{70753670-8BA5-4E45-8AFF-EB70257CFFCD}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{70CDB936-88DB-430D-8E1C-174C6A9F36E5}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{717C5A85-3E62-4303-BB5F-7DD44238B7A9}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{718ACC2B-DE83-4A08-98D3-F10FDE9BA85D}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{71FF620B-77EF-4546-AE78-B6E8B8D6536E}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{721A8F92-CFF7-4989-A660-41490861EFEA}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{7257607D-3352-4A4C-B5FA-894747B02EE8}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{734D82C1-461A-4EC5-B427-F938BFE9C387}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{73F649B0-A141-4A0A-89E8-298DB7202D5B}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{7485FF4C-A908-4974-95AA-BBA5F408DA44}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{756644FD-CE1E-4900-B3DC-2C3D461C350D}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{75B87FA6-D3BB-4AF2-9257-0EDFE6C19C5B}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{75E51B5C-3F7C-4E1C-81E9-FEC034E12AC3}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{76A163C9-2660-404C-B0FE-EBD08F4DFAA8}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{76B9C38A-9173-45C7-B0BD-4942F638C881}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{76BB654F-6881-47BE-BB9A-0A33B367A6C8}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{77C3DD44-7176-4696-A948-D909475C16E3}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{793A95FC-FF06-46D5-95F3-65E794E30376}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{795C5467-1E91-40E4-8750-626E8A8F3E04}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{797091A5-B308-4FAC-8F00-34EEB428B76B}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{7B3E225B-F518-4F74-80A7-654D2C33D9FB}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{7B525124-07DD-4DCA-AC5E-0216636E9638}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{7C6F594F-2C35-4FFB-B109-19506FC18C37}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{7D27CF22-A61F-4C27-B295-9203359C7BBC}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{7D85E690-593B-45C1-B622-C38997B978CB}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{7DC15C1F-C6CB-4F0A-933D-6FAFB725901E}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{7F13A20D-10DD-4957-813A-85BE46FD6F0B}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{7F13EE8F-13E1-4A7A-A04D-0EEA054BFA77}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{7F5A5252-C6C8-489F-84E4-044E0DC420CA}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{7F7A867F-3295-455C-B481-DDE3B524F001}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{7FB57146-2398-4FD2-A333-E820548DE62C}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{805565E7-A693-4484-80AE-1475DBA4E411}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{806105EB-6BDE-4202-A3B0-1A76290F997A}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{8075DBDA-9199-4E2A-A27F-47867B824BE0}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{808C31C4-C0F3-455C-82FD-8BF9C62F2F45}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{80D6F433-6703-4833-B49A-223C701EDBAF}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{80DC1007-05EE-47D5-9A6B-B113F0F9787B}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{811378E9-8039-45E5-84E1-FA14E05E21D0}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{81850217-2D65-408B-9DA9-846B63865DF0}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{82173ADE-EEAD-4972-80BE-8DBA6B7C5EB9}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{8330ABAA-11BB-4F7D-93BA-C52986952E52}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{8339B31E-4D1F-4D85-83C5-AD3DE45808D0}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{8347C8EA-1C29-484C-845E-07F4769EACD0}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{843E999A-A7C1-4E16-BFB8-A8F8B76C3DA7}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{8449851C-5E55-457E-BF3C-4A07833E7214}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{85492071-FC15-4164-8E50-BEB33C7B1396}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{882B5479-C12B-4D95-B10A-BDCC596EF828}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{8935668D-4A1F-42E4-A446-67085029C843}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{89AC8683-5CD9-4351-BC64-EF52B1D51F54}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{8A342BF2-513C-4890-9C0C-C6EF98959ECF}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{8B3CF3AC-2689-4DE0-B502-E9B5259A5D20}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{8C40388A-9718-4A10-A8EB-F224F490BFC1}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{8CC8C05F-2C90-42C6-947D-A0DF7A4EDFE7}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{8CF7245D-8495-4F72-BDBA-564F0CFBE594}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{8DC74D5E-315B-48EC-8E34-FC9BFA47E981}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{8FC379EC-2AA3-497E-8610-FB66A3403C49}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{8FC459F7-1557-409D-A151-532C3C2028CE}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{9070FDF0-41DA-421C-97CE-1243430CAE62}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{90DD812E-E1A6-4895-A4C8-F03CE76D4B31}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{91687AD5-ABB3-4FAB-9E42-3E845A65B167}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{91A81AC5-52E5-46E0-AC85-AA293645F8C2}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{92175679-627F-434A-BB42-7F4EA7808117}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{929F353F-E2EA-4F55-882A-9CC98DE21817}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{93204DD1-DE7E-4696-AD75-658790C6E725}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{947BB8EA-76FE-4BFA-80E9-ED38E819DD33}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{94ACA155-AE2E-49F2-9238-1C858CB1F99E}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{94CCDDB4-00FF-48A9-82CC-93E1C424DD86}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{963B972F-8E5B-472E-A6B4-71DDC8A9A5B9}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{9648E3BB-3220-4DB1-892D-E6CB355E1219}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{9649B651-0D83-4D86-9B6E-F9C359728C2E}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{969DE9DD-B464-4141-99C0-60B5041D9E3F}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{975A3081-53C2-46BE-AC5B-702D24B63915}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{9762765B-BD02-47AB-BB5C-0368909E5773}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{98265A3F-66E5-468A-829E-5C41B8DB5340}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{983AB551-BD7A-4BC3-85EE-9FBEE71AB454}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{988E4C87-6B7E-4DCB-BFAD-AFA44DDD9488}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{98A10AE5-72CD-4073-A32B-879E43AB13B8}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{99D92DF7-9A78-4478-8E02-F869D81BFA23}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{99F05135-C9EE-414A-8B64-2DFA62994D78}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{9A56B4EF-96EF-405B-9BCA-95CD32A905CA}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{9AB3C055-704A-4476-BE5C-CAF9CE0C5EA5}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{9ADD2A74-B111-4ED0-A519-088351FBC2B9}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{9B580EF3-B028-4A0E-82E2-61868738A1D8}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{9B98FE9F-437D-4698-AB2C-1524BA0207D8}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{9C0E2510-4EDF-4DE7-8203-99D1599DCC58}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{9CE5475D-21BE-4DAB-AF1A-BC70CC5BDBD7}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{9E170BC3-631B-4F5D-8374-67F96B0671C7}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{9E437BDF-2577-4D75-ACCE-326AB76476F2}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{9E5E71DC-1AF6-4255-B4A4-CB65B4DCC27C}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{9F7145F6-76F5-4020-838C-D5C647A47C04}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{9FA88E63-D2CB-4282-B40D-4B681E80F496}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{9FC09C81-215B-4855-8037-3C939BCB8306}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{A06CEBC8-A7C5-4689-83D4-1909FAC5B5D0}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{A0873BC8-FAF9-46B3-A7B6-0424721A5FE8}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{A135BD60-328D-4387-9947-299D16DD7F95}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{A14A262F-DFE6-45E0-81C8-21E440DFAAFD}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{A1BEBCC7-746A-427B-BF38-C6E4F7CF754E}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{A1F3DCFC-D149-4B2F-A365-E1AEE8DE7A07}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{A31D7060-EEE2-482C-94A7-7AB8ECEAB9D4}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{A3C67386-753E-4B21-8EFE-040E60047CD0}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{A3C9C995-6149-4C5D-B400-E72CEFE40C52}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{A3F90133-8A7B-4212-8FA7-4B7217704C0B}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{A4E3138D-8076-4A0E-A94C-633E1C89B4FE}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{A5513957-3209-4EC7-9D53-D194DA16044E}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{A59180C9-EC72-4F65-8F7A-ABBDA52A425D}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{A637A98A-386E-437F-8E74-C28C392592AA}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{A660F7F5-C0C6-470C-9F05-735327943D8A}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{A7902842-A8EA-426B-9EE3-B91AC8EF7EF5}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{A7E81E78-7B8B-4C77-B22C-42D81DEB0A9F}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{A80AF406-261D-4A07-8501-F6CED420A627}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{A82839BB-CDF8-4772-B683-13461BB580E2}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{A887A501-1071-4741-A64F-8FFF11F296A7}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{A88971B5-0DB2-473A-BD3D-C30A6A39294F}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{A93D2711-0FED-4E32-B016-3F53A1D9ACB4}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{A9577409-180E-43E3-A9C2-46E4DB704C3B}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{AB2C01E0-7274-475D-97C0-1279855CE6A6}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{ABD8D877-C4E9-4A5C-A7EB-C283EC2E4799}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{ABE82DBE-8995-4071-984D-52EEA925722B}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{AC1DDBD3-020A-4461-AB78-D060D5A9A1E5}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{AC9274DA-7500-4887-B272-7E1C24C072FA}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{AE654AFA-9F01-4170-A9A5-5F968B298DCB}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{AEC1FE1A-818A-44D9-B970-F072A415489C}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{B122713D-7603-4520-8A33-4EB4E0CDE591}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{B26B0557-B906-4AC1-BC67-D35639E64267}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{B350FC41-345A-4773-BEC3-F8F1DE2086D3}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{B46D0456-4308-40BE-8362-60B1D568D15B}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{B4B69DA7-E490-40B3-AE79-D2641E657BBE}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{B6C88CAE-2E41-4723-AB9D-30E3877E0590}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{B724DE11-6CD7-4670-8924-760A62AE0DF7}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{B781D656-0334-4089-A380-F1DF20477143}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{B85C5C7D-2ECD-4027-B563-4E7BDCB88E38}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{B8DD80B1-1671-4481-B35A-AA16D2FDE66D}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{B8F1BFCC-8EA2-49A9-A7A9-E316C86DC880}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{B95325DD-55CA-416D-B5F5-6AC14A6330C9}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{B99BCE42-C136-48D2-9FC5-4F20FE2AF326}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{B9D0E541-694E-41EA-B0D5-062422ECD224}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{BA754AF6-00A0-47EB-B05B-8E6B6B1E346A}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{BA8D12BD-4366-41BD-B71D-0B79CD04DD1F}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{BA9FBF9A-6AD8-41B2-922C-C82BD64906DD}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{BAB9CC3F-E0A3-4686-837D-A4AE3F7C70B3}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{BBDCAD87-E8FB-4B1E-A820-E821ABDA5BA1}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{BBF565D6-F65A-4AA7-BD30-FAFF0FCCCBCB}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{BC5A1DAE-A825-4064-9294-8F6C6B3F1206}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{BC80961A-F45E-4D73-B8B6-C20257F72E4E}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{BD4B5646-919E-4D4E-AA3D-64C5359782D5}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{BD9655D0-B938-4AA7-B3CA-74A5A379D312}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{BDA8720F-0D5C-464D-A1EC-57207FB26617}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{BE6ECD74-5424-43C9-94FF-A14073852654}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{BE7A5342-8E0B-4506-A88B-401A68F73A02}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{BE87BFD4-7F67-4CFB-B333-49BD3DC151EC}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{BEA246E4-F3FD-45CB-A047-F4A12CB1AEE5}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{C19C9D36-CBED-435A-BE05-9155A5F68F5A}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{C2864589-DEF9-4487-B12C-0EE54C467AAA}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{C291DD2A-134E-4D58-B743-4A114EB549B0}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{C2930339-8A34-43EB-9E33-E484306D0B32}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{C2E5D763-7191-4E43-A4F9-ADA6DE6C9E70}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{C350AF70-2352-43F6-9A60-975B404C7A9E}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{C356A8D5-A70C-4D78-A4D2-B2A2E20E2C59}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{C362E875-4E64-42B0-A772-0FE6C3F442A9}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{C3B84C15-5A7B-46DB-A952-2FBEB159C44C}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{C4E77700-A29B-41F9-A0BE-FA7EE561892A}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{C4F70845-D012-4408-A27A-F2D668A8EE03}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{C59B2425-25CC-4A64-9FDE-C1B0F9AF1093}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{C60C2B47-0B52-4940-96D9-F6A750DC4BBF}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{C61983E9-559A-4A2C-8372-F394F830B8B1}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{C6B80B87-B1A9-48A7-8AC6-8676D311A1B9}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{C6D6DFAE-5E5C-487D-B07C-89996F6EB516}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{C6F4C474-7580-4D4C-B992-2E2EE168376D}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{C8072A5F-A5F1-4D2E-AE20-E6B23C047FC9}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{C8E97065-24C5-46D5-8EBC-5A733F99FF41}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{C9301974-6AC9-4EE6-91BD-A64C3E461E82}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{C962BCBF-845E-4CB1-85A5-99D0E8D349A7}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{CB2E4E79-901D-4108-AB3E-44F02A4AD60E}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{CB8DFC3F-BDA8-4EFE-844C-EFEF8D83F037}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{CBCDA322-2E06-4A89-9C86-2E424B647729}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{CC883BBF-91D7-4365-A966-E04FB0F892F4}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{CCEA4D92-AE21-49D0-898E-59E5999742E1}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{CD5B98ED-019A-47E6-8DDC-2D7250286A00}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{CD9E1D43-EC91-4754-961B-92F5E77F5C94}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{CF6EF677-9B61-4CFC-92BD-3971E743D56D}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{CF7B5889-195D-4A61-9FFB-955FDB2A68F9}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{CF9172CE-6579-4B36-84D8-2ABDA888F3F9}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{D14E69FE-E8DE-41A8-9CC0-33DB20AD9E0C}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{D14F5326-A366-4F2B-BE8E-A95D85CF74FA}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{D1E639F5-16C9-462D-8319-8F149D9BAAC3}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{D2B482C0-48B5-4A26-BD17-F1A783B193E1}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{D3F92CEC-E975-4691-A5A1-6DBE566A90D8}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{D653D2F3-592D-4E34-9567-3E788B9726EB}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{D67358A4-93AD-4CA5-8EF7-D5BB337F30F4}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{D7A82486-A5F1-4E43-9526-0FD439155012}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{D7DC561F-DA08-4D94-B065-2C58C3395F80}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{D863711A-8908-4724-BAF5-78CF950276FD}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{D874C8A3-8F64-419F-B36B-640977ADA2AE}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{D91BCF1E-E824-466A-BB45-5BC9674C18C8}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{D93BD139-E5D8-4746-871C-DE2BAF6B2028}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{D9E67C9D-B0BB-4469-B235-DA205FC2F1F3}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{DA366312-EC29-4E05-9D0D-A308215487DB}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{DA588C82-3C07-46CA-BE48-1831100AD087}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{DAED0602-4CC2-4333-9EB9-FA15504D8F60}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{DB0DD43E-E52F-4D46-97C1-D237D9B5C5FE}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{DB5503CC-3426-4618-AC6B-1D442439F42C}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{DB7AC1A4-8FEB-42F6-9BCE-BEB08B426F21}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{DBA8F06A-B1BC-4E08-9A71-DFA98A28C97D}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{DC68CCA7-7AB2-4293-AF25-EE5286EF117C}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{DCE6B38A-3350-44AB-9441-2EA197A695F9}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{DD31E44E-66B2-42C9-BF62-98D3249ED8AC}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{DD384D63-B92D-4504-8ACA-3DEA3F982D0B}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{DD9541B6-2E9C-4B8D-A343-900961567303}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{DE666C69-49DD-40B3-8B97-AD9A3F622483}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{DE7D7B2F-783B-42ED-93B4-09AEE3CAB170}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{DF248AA5-1643-489E-A9AD-7E76CF6E03EC}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{DF77E2B2-2C99-4F2F-BF62-BA2F736780A5}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{DFBEBA69-B41A-4471-8A71-9AB3853A1F23}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{DFF1BD8A-E84D-49FF-B68C-C0FD96EEE148}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{E0332D77-4311-4040-B0C5-FE17B052F6C5}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{E09989BD-33EF-400E-B920-44E44E27BB38}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{E0D9D81B-D834-4F12-ACCE-2D0C566A1503}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{E0DB689C-34B5-4B6F-ACE5-3B558B14213E}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{E1385092-227C-45ED-9D32-76181471DB3B}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{E13C7132-31A4-407A-BE1E-A647FC153217}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{E2E5E737-F768-4B58-BA5B-9C6EC85E9BEC}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{E364E83C-B94D-40ED-A814-A658D84EB7EA}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{E3E7E795-9E21-4E26-A521-E963D5D08C19}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{E4067D91-051D-4833-89A8-4EDB72530393}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{E41580FF-1A3E-4281-8179-32F14642561D}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{E47060FD-2182-46D1-8836-E277347D40CE}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{E724D12D-DBB1-485E-B3FA-E228BF288606}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{E8B9F988-8CC4-40B0-8820-ECB838EAE43B}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{E9314645-EEC6-4177-A148-3A7311086EDC}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{E9ACFDF5-2B76-4B66-8FF2-B74599866DCA}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{EAA4DD7D-771C-4C1F-89FB-14B788600C86}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{EB5A7A74-3271-4139-BA23-CEEAB15FF1D6}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{EBABBCD1-5A5A-4C37-A670-0FB2168683EE}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{ECB7F766-B1C4-48F5-9415-CD84C943FEA5}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{EE12B392-4C86-4D23-968F-87A8CBAAF661}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{EE7C650A-F55E-4680-81F7-A74EBBE58DAB}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{EF194106-0385-4AA6-A1F7-A49C83B3E989}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{EF249C30-4ECD-44FB-A73D-01586C28E7C1}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{EF8274A4-2ED0-48A7-BEEA-CB31E59A1300}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{EF930FA9-6EBC-456C-B018-A3F60EBC6E55}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{EFC72344-81EA-4E0E-AE3F-5AF341A36C19}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{F0BA43B7-2DEB-4F0B-88F6-F69416A2B5EB}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{F0DDE8F4-9AFA-47AA-AF06-14FF95A736E1}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{F26412E9-D115-40EF-8126-201DEBB72843}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{F276455A-3886-4258-85B5-796D56C61184}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{F36C0A73-4DD3-428C-887D-417EA8DF919B}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{F3C0AC6D-954D-4CF2-BB9E-A04EEF1E1F1C}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{F3E67204-109A-4742-BE78-0A9934FBC21C}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{F54F4544-C733-4985-8213-C6386399821C}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{F73BBBD5-008D-4FEC-920D-FCB7A34507D0}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{F770AB32-D53C-4068-BD1C-0A14AD9E4A0F}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{F834F529-C1FD-415B-A7B7-B9B0ADC66979}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{F8BD7EB9-9621-4F28-B79A-8D9147AC53B9}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{FA6B6860-F40A-4732-B038-18227CD9B549}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{FAB5D3B9-1179-47B7-91C0-277F8DBF1ACD}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{FAD31631-0FA3-4ADF-82A6-BA00B303E120}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{FBF04647-13E1-4728-92A6-6A17CBFF5D55}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{FC070535-D5D2-4994-B840-54B87BEBD5E4}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{FC4979C4-1C69-4C15-B452-D0602087A970}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{FC561D9C-7104-4895-A5E7-2A933FB5D061}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{FCA8356D-E5AB-4825-9696-7329C1000AB9}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{FDFB10CE-4D1C-4DE4-B1CC-F897043C5A82}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{FE6E7B2A-BE03-454E-8049-DED069D0790F}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{FE76A6C1-7CD7-43BA-89B9-5B91514195B4}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{FED90DFE-5205-4B77-8A02-F3BF7BA7C65E}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{FF0AEF0A-D904-4D93-BA61-DAA10228E18E}
Successfully deleted: [Empty Folder] C:\Users\transit\appdata\local\{FF6AF72C-F7EA-4F5A-B4A5-E0117F550553}
Successfully deleted: [Folder] C:\Program Files (x86)\babylon
Successfully deleted: [Folder] C:\Program Files (x86)\fighters
Successfully deleted: [Folder] C:\Program Files (x86)\Optimizer Pro 3.46
Successfully deleted: [Folder] C:\Program Files (x86)\regclean pro
Successfully deleted: [Folder] C:\Program Files (x86)\super optimizer
Successfully deleted: [Folder] C:\Program Files (x86)\systweak
Successfully deleted: [Folder] C:\Program Files (x86)\xtab
Successfully deleted: [Folder] C:\ProgramData\fighters
Successfully deleted: [Folder] C:\ProgramData\ihprotectupdate
Successfully deleted: [Folder] C:\ProgramData\reimage protector
Successfully deleted: [Folder] C:\ProgramData\windowsmangerprotect
Successfully deleted: [Folder] C:\Users\transit\appdata\local\babylon
Successfully deleted: [Folder] C:\Users\transit\appdata\locallow\delta
Successfully deleted: [Folder] C:\Users\transit\AppData\Roaming\babylon
Successfully deleted: [Folder] C:\Users\transit\AppData\Roaming\fighters
Successfully deleted: [Folder] C:\Users\transit\AppData\Roaming\systweak
Successfully deleted: [Folder] C:\Users\transit\documents\optimizer pro
 
 
 
 
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on wo 22/04/2015 at 14:09:32,37
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

  • 0

#5
HaraMo

HaraMo

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 456 posts

 # AdwCleaner v4.201 - Logbestand aangemaakt 22/04/2015 op 14:18:10

# Laatste update 08/04/2015 door Xplode
# Database : 2015-04-21.3 [Server]
# Besturingssysteem : Windows 7 Home Premium Service Pack 1 (x64)
# Gebruikersnaam : transit - TRANSIT-PC
# Gestart vanuit : C:\Users\transit\Desktop\adwcleaner_4.201.exe
# Optie : Verwijderen
 
***** [ Services ] *****
 
[#] Service Verwijderd : qrnfd_1_10_0_9
 
***** [ Bestanden / Mappen ] *****
 
Map Verwijderd : C:\ProgramData\Reimage Express
Map Verwijderd : C:\ProgramData\cba236c900006553
Map Verwijderd : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Super Optimizer
Map Verwijderd : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Reimage Express
Map Verwijderd : C:\Program Files (x86)\EZ Software Updater
Map Verwijderd : C:\Program Files (x86)\driver whiz
Map Verwijderd : C:\Program Files (x86)\daialypriiZe
Map Verwijderd : C:\Program Files (x86)\frEE2uyou
Map Verwijderd : C:\Program Files (x86)\Louwpriocees
Map Verwijderd : C:\Program Files (x86)\loWpriiceS
Map Verwijderd : C:\Program Files (x86)\offeRdeal
Map Verwijderd : C:\Program Files (x86)\Common Files\337
Map Verwijderd : C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\DealPly
Map Verwijderd : C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\Fighters
Map Verwijderd : C:\Windows\SysWOW64\config\systemprofile\AppData\Local\torch
Map Verwijderd : C:\Program Files\Babylon
Map Verwijderd : C:\Program Files\Reimage
Map Verwijderd : C:\Users\DefaultAppPool\AppData\Roaming\Systweak
Map Verwijderd : C:\Users\transit\AppData\Local\SmartWeb
Map Verwijderd : C:\Users\transit\AppData\LocalLow\HPAppData
Map Verwijderd : C:\Users\transit\AppData\LocalLow\Mail.Ru
Map Verwijderd : C:\Users\transit\AppData\Local\Google\Chrome\User Data\Default\Extensions\gcncagkkhfoombgbihckkccmkjemhohl
Bestand Verwijderd : C:\Users\transit\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_gcncagkkhfoombgbihckkccmkjemhohl_0.localstorage
Bestand Verwijderd : C:\Users\transit\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_gcncagkkhfoombgbihckkccmkjemhohl_0.localstorage-journal
Bestand Verwijderd : C:\Windows\efix.ini
Bestand Verwijderd : C:\Windows\System32\log\iSafeKrnlCall.log
Bestand Verwijderd : C:\Windows\System32\roboot64.exe
Bestand Verwijderd : C:\Users\transit\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Babylon.lnk
Bestand Verwijderd : C:\Users\transit\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\iLivid.lnk
Bestand Verwijderd : C:\Users\transit\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_allin1convert.dl.tb.ask.com_0.localstorage
Bestand Verwijderd : C:\Users\transit\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_allin1convert.dl.tb.ask.com_0.localstorage-journal
Bestand Verwijderd : C:\Users\transit\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_nl.reimageplus.com_0.localstorage
Bestand Verwijderd : C:\Users\transit\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_nl.reimageplus.com_0.localstorage-journal
Bestand Verwijderd : C:\Users\transit\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_plarium.com_0.localstorage
Bestand Verwijderd : C:\Users\transit\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_plarium.com_0.localstorage-journal
Bestand Verwijderd : C:\Users\transit\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_voiture.trovit.fr_0.localstorage
Bestand Verwijderd : C:\Users\transit\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_voiture.trovit.fr_0.localstorage-journal
Bestand Verwijderd : C:\Users\transit\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.mystartsearch.com_0.localstorage
Bestand Verwijderd : C:\Users\transit\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.mystartsearch.com_0.localstorage-journal
 
***** [ Geplande taken ] *****
 
Taak Verwijderd : ReimageUpdater
Taak Verwijderd : SmartWeb Upgrade Trigger Task
 
***** [ Snelkoppelingen ] *****
 
 
***** [ Register ] *****
 
Sleutel Verwijderd : HKLM\SOFTWARE\Google\Chrome\Extensions\ogfjmhfnldnajmfaofeiaepghjenbgjo
Sleutel Verwijderd : HKLM\SOFTWARE\Google\Chrome\Extensions\iomphmdalfmaifjccmagmllnicjoghhk
Sleutel Verwijderd : HKCU\Software\Classes\iLivid.torrent
Sleutel Verwijderd : HKCU\Software\Classes\VirtualStore\MACHINE\SOFTWARE\Wow6432Node\BabylonToolbar
Sleutel Verwijderd : HKCU\Software\Microsoft\Internet Explorer\MenuExt\Translate this web page with Babylon
Sleutel Verwijderd : HKCU\Software\Microsoft\Internet Explorer\MenuExt\Translate with Babylon
Sleutel Verwijderd : HKCU\Software\Microsoft\Office\Powerpoint\Addins\babylonofficeaddin.officeaddin
Sleutel Verwijderd : HKCU\Software\Microsoft\Office\Word\Addins\babylonofficeaddin.officeaddin
Sleutel Verwijderd : HKLM\SOFTWARE\Classes\.bdc
Sleutel Verwijderd : HKLM\SOFTWARE\Classes\.bgl
Sleutel Verwijderd : HKLM\SOFTWARE\Classes\.bof
Sleutel Verwijderd : HKLM\SOFTWARE\Classes\AppID\BabylonHelper.EXE
Sleutel Verwijderd : HKLM\SOFTWARE\Classes\AppID\BabylonIEPI.DLL
Sleutel Verwijderd : HKLM\SOFTWARE\Classes\BabyDict
Sleutel Verwijderd : HKLM\SOFTWARE\Classes\BabyGloss
Sleutel Verwijderd : HKLM\SOFTWARE\Classes\BabylonOfficeAddin.OfficeAddin
Sleutel Verwijderd : HKLM\SOFTWARE\Classes\BabylonOfficeAddin.OfficeAddin.1
Sleutel Verwijderd : HKLM\SOFTWARE\Classes\BabyOptFile
Sleutel Verwijderd : HKLM\SOFTWARE\Classes\bbylnApp.appCore
Sleutel Verwijderd : HKLM\SOFTWARE\Classes\bbylnApp.appCore.1
Sleutel Verwijderd : HKLM\SOFTWARE\Classes\escort.escrtBtn.1
Sleutel Verwijderd : HKLM\SOFTWARE\Classes\iLivid.torrent
Sleutel Verwijderd : HKLM\SOFTWARE\Classes\Prod.cap
Sleutel Verwijderd : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\Babylon.exe
Sleutel Verwijderd : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\DeskSvc
Sleutel Verwijderd : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WindowsMangerProtect
Sleutel Verwijderd : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WsysSvc
Sleutel Verwijderd : HKCU\Software\Classes\keepmysearch
Sleutel Verwijderd : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\IePluginService
Sleutel Verwijderd : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Wpm
Sleutel Verwijderd : HKLM\SOFTWARE\Classes\AppID\REI_AxControl.DLL
Sleutel Verwijderd : HKLM\SOFTWARE\Classes\REI_AxControl.ReiEngine.1
Sleutel Verwijderd : HKLM\SOFTWARE\Classes\REI_AxControl.ReiEngine
Sleutel Verwijderd : HKLM\SOFTWARE\408f163d-e8f8-ed28-77ff-b0b17203a7b2
Sleutel Verwijderd : HKLM\SOFTWARE\596da8ab76fbf41
Sleutel Verwijderd : HKLM\SOFTWARE\Classes\AppID\{15F6BCB7-BB0F-4A66-8762-4765B05597EB}
Sleutel Verwijderd : HKLM\SOFTWARE\Classes\AppID\{1973277F-87B0-4EA3-9ED2-470A91D284CF}
Sleutel Verwijderd : HKLM\SOFTWARE\Classes\AppID\{6536801B-F50C-449B-9476-093DFD3789E3}
Sleutel Verwijderd : HKLM\SOFTWARE\Classes\AppID\{B16632F1-24E0-4D99-A68D-70BFB6447C48}
Sleutel Verwijderd : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}
Sleutel Verwijderd : HKLM\SOFTWARE\Classes\AppID\{CFDAFE39-20CE-451D-BD45-A37452F39CF0}
Sleutel Verwijderd : HKLM\SOFTWARE\Classes\AppID\{28FF42B8-A0DA-4BE5-9B81-E26DD59B350A}
Sleutel Verwijderd : HKLM\SOFTWARE\Classes\CLSID\{6801410E-CC88-42D6-A93B-909E95645407}
Sleutel Verwijderd : HKLM\SOFTWARE\Classes\CLSID\{6AC0BB10-C922-45E2-857D-2A368FE749E5}
Sleutel Verwijderd : HKLM\SOFTWARE\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D}
Sleutel Verwijderd : HKLM\SOFTWARE\Classes\CLSID\{947217BD-E967-400A-B14A-BA851A8EDCBB}
Sleutel Verwijderd : HKLM\SOFTWARE\Classes\CLSID\{97F2FF5B-260C-4CCF-834A-2DDA4E29E39E}
Sleutel Verwijderd : HKLM\SOFTWARE\Classes\CLSID\{99066096-8989-4612-841F-621A01D54AD7}
Sleutel Verwijderd : HKLM\SOFTWARE\Classes\CLSID\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
Sleutel Verwijderd : HKLM\SOFTWARE\Classes\CLSID\{E46C8196-B634-44A1-AF6E-957C64278AB1}
Sleutel Verwijderd : HKLM\SOFTWARE\Classes\CLSID\{FE9271F2-6EFD-44B0-A826-84C829536E93}
Sleutel Verwijderd : HKLM\SOFTWARE\Classes\CLSID\{FFB9ADCB-8C79-4C29-81D3-74D46A93D370}
Sleutel Verwijderd : HKLM\SOFTWARE\Classes\CLSID\{459DD0F7-0D55-D3DC-67BC-E6BE37E9D762}
Sleutel Verwijderd : HKLM\SOFTWARE\Classes\Interface\{2E9A2DCB-F5DB-40D0-8E62-3B47DD476A77}
Sleutel Verwijderd : HKLM\SOFTWARE\Classes\Interface\{59B23951-2232-4AFB-81D4-64A8A16D457A}
Sleutel Verwijderd : HKLM\SOFTWARE\Classes\Interface\{5F339F0B-716F-408F-A627-DEEB5DEB4020}
Sleutel Verwijderd : HKLM\SOFTWARE\Classes\Interface\{81E522F1-9E90-47DD-A2CE-39B0C00274A0}
Sleutel Verwijderd : HKLM\SOFTWARE\Classes\Interface\{8E096DFB-6AB7-45C7-BF64-B313C7096529}
Sleutel Verwijderd : HKLM\SOFTWARE\Classes\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}
Sleutel Verwijderd : HKLM\SOFTWARE\Classes\Interface\{928FE5E7-D557-46B7-8AF6-17ACCE1FB4ED}
Sleutel Verwijderd : HKLM\SOFTWARE\Classes\Interface\{996A9940-2F2C-4486-A479-439C4A15F278}
Sleutel Verwijderd : HKLM\SOFTWARE\Classes\Interface\{9B7D44BA-376C-456F-B289-5034270322FD}
Sleutel Verwijderd : HKLM\SOFTWARE\Classes\Interface\{9BD8FF26-2C71-4D35-9FE2-AD8D25AECC36}
Sleutel Verwijderd : HKLM\SOFTWARE\Classes\Interface\{BCE6E914-AEF0-4FEE-8FC8-06F9B42BF890}
Sleutel Verwijderd : HKLM\SOFTWARE\Classes\Interface\{BD8D5FFA-4F92-48AD-BFBE-7896916656F5}
Sleutel Verwijderd : HKLM\SOFTWARE\Classes\Interface\{C92E6D80-EC54-45CC-AC4B-A7CF42F11B52}
Sleutel Verwijderd : HKLM\SOFTWARE\Classes\Interface\{D1CB564E-F38A-4F2A-8257-60E3F8BE9F34}
Sleutel Verwijderd : HKLM\SOFTWARE\Classes\Interface\{F293BBC0-DA7E-4CF1-9EEA-CE90CFE0DF86}
Sleutel Verwijderd : HKLM\SOFTWARE\Classes\Interface\{FEFBC559-C3C7-4287-B05B-49D489B80749}
Sleutel Verwijderd : HKLM\SOFTWARE\Classes\Interface\{9BB31AD8-5DB2-459E-A901-DEA536F23BA4}
Sleutel Verwijderd : HKLM\SOFTWARE\Classes\Interface\{BD51A48E-EB5F-4454-8774-EF962DF64546}
Sleutel Verwijderd : HKLM\SOFTWARE\Classes\TypeLib\{69332529-EEC8-4D0D-9FD3-202C4AE8E589}
Sleutel Verwijderd : HKLM\SOFTWARE\Classes\TypeLib\{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}
Sleutel Verwijderd : HKLM\SOFTWARE\Classes\TypeLib\{A1489C85-4F6F-48C4-AC9E-18B63AF4703E}
Sleutel Verwijderd : HKLM\SOFTWARE\Classes\TypeLib\{F310F027-15CB-4A7F-B10D-3A4AFB5013A5}
Sleutel Verwijderd : HKLM\SOFTWARE\Classes\TypeLib\{FA6468D2-FAA4-4951-A53B-2A5CF9CC0A36}
Sleutel Verwijderd : HKLM\SOFTWARE\Classes\TypeLib\{41F978F3-431A-4464-A789-5C0692D562FB}
Sleutel Verwijderd : HKLM\SOFTWARE\Classes\TypeLib\{C1EC170E-C5ED-4100-9078-559C31AFDBF5}
Sleutel Verwijderd : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
Sleutel Verwijderd : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8F0B76E1-4E46-427B-B55B-B90593468AC6}
Sleutel Verwijderd : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{97F2FF5B-260C-4CCF-834A-2DDA4E29E39E}
Sleutel Verwijderd : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
Sleutel Verwijderd : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F72841F0-4EF1-4DF5-BCE5-B3AC8ACF5478}
Sleutel Verwijderd : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
Sleutel Verwijderd : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{10ECCE17-29B5-4880-A8F5-EAD298611484}
Sleutel Verwijderd : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{8F0B76E1-4E46-427B-B55B-B90593468AC6}
Sleutel Verwijderd : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
Sleutel Verwijderd : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{F72841F0-4EF1-4DF5-BCE5-B3AC8ACF5478}
Sleutel Verwijderd : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{819DC4CA-4FFF-4C2E-800D-F346471D99BC}
Sleutel Verwijderd : [x64] HKLM\SOFTWARE\Classes\CLSID\{64B00DAC-870D-4E6A-8D34-3A6E3E427A30}
Sleutel Verwijderd : [x64] HKLM\SOFTWARE\Classes\CLSID\{947217BD-E967-400A-B14A-BA851A8EDCBB}
Sleutel Verwijderd : [x64] HKLM\SOFTWARE\Classes\CLSID\{10ECCE17-29B5-4880-A8F5-EAD298611484}
Sleutel Verwijderd : [x64] HKLM\SOFTWARE\Classes\CLSID\{801B440B-1EE3-49B0-B05D-2AB076D4E8CB}
Sleutel Verwijderd : [x64] HKLM\SOFTWARE\Classes\Interface\{0BF91075-F457-4A8B-99EF-140B52D2F22A}
Sleutel Verwijderd : [x64] HKLM\SOFTWARE\Classes\Interface\{2E9A2DCB-F5DB-40D0-8E62-3B47DD476A77}
Sleutel Verwijderd : [x64] HKLM\SOFTWARE\Classes\Interface\{37425600-CB21-49A0-8659-476FBAB0F8E8}
Sleutel Verwijderd : [x64] HKLM\SOFTWARE\Classes\Interface\{431FB0E5-2CBB-4602-9FE6-F1D64488ADD7}
Sleutel Verwijderd : [x64] HKLM\SOFTWARE\Classes\Interface\{59B23951-2232-4AFB-81D4-64A8A16D457A}
Sleutel Verwijderd : [x64] HKLM\SOFTWARE\Classes\Interface\{5C9A230D-70A5-11D5-AFB0-0050DAC67890}
Sleutel Verwijderd : [x64] HKLM\SOFTWARE\Classes\Interface\{5F339F0B-716F-408F-A627-DEEB5DEB4020}
Sleutel Verwijderd : [x64] HKLM\SOFTWARE\Classes\Interface\{81E522F1-9E90-47DD-A2CE-39B0C00274A0}
Sleutel Verwijderd : [x64] HKLM\SOFTWARE\Classes\Interface\{8911483C-C00A-4183-9FBC-6C9C00946C15}
Sleutel Verwijderd : [x64] HKLM\SOFTWARE\Classes\Interface\{8E096DFB-6AB7-45C7-BF64-B313C7096529}
Sleutel Verwijderd : [x64] HKLM\SOFTWARE\Classes\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}
Sleutel Verwijderd : [x64] HKLM\SOFTWARE\Classes\Interface\{928FE5E7-D557-46B7-8AF6-17ACCE1FB4ED}
Sleutel Verwijderd : [x64] HKLM\SOFTWARE\Classes\Interface\{996A9940-2F2C-4486-A479-439C4A15F278}
Sleutel Verwijderd : [x64] HKLM\SOFTWARE\Classes\Interface\{9B7D44BA-376C-456F-B289-5034270322FD}
Sleutel Verwijderd : [x64] HKLM\SOFTWARE\Classes\Interface\{9BD8FF26-2C71-4D35-9FE2-AD8D25AECC36}
Sleutel Verwijderd : [x64] HKLM\SOFTWARE\Classes\Interface\{BCE6E914-AEF0-4FEE-8FC8-06F9B42BF890}
Sleutel Verwijderd : [x64] HKLM\SOFTWARE\Classes\Interface\{BD8D5FFA-4F92-48AD-BFBE-7896916656F5}
Sleutel Verwijderd : [x64] HKLM\SOFTWARE\Classes\Interface\{C3F058A9-407D-4CD1-8F66-B75605B54B69}
Sleutel Verwijderd : [x64] HKLM\SOFTWARE\Classes\Interface\{C92E6D80-EC54-45CC-AC4B-A7CF42F11B52}
Sleutel Verwijderd : [x64] HKLM\SOFTWARE\Classes\Interface\{D1CB564E-F38A-4F2A-8257-60E3F8BE9F34}
Sleutel Verwijderd : [x64] HKLM\SOFTWARE\Classes\Interface\{EFDCAF05-D29C-4D4D-9836-8CDCD606A6B2}
Sleutel Verwijderd : [x64] HKLM\SOFTWARE\Classes\Interface\{F293BBC0-DA7E-4CF1-9EEA-CE90CFE0DF86}
Sleutel Verwijderd : [x64] HKLM\SOFTWARE\Classes\Interface\{FEFBC559-C3C7-4287-B05B-49D489B80749}
Sleutel Verwijderd : [x64] HKLM\SOFTWARE\Classes\Interface\{9BB31AD8-5DB2-459E-A901-DEA536F23BA4}
Sleutel Verwijderd : [x64] HKLM\SOFTWARE\Classes\Interface\{BD51A48E-EB5F-4454-8774-EF962DF64546}
Sleutel Verwijderd : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
Sleutel Verwijderd : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2498}
Sleutel Verwijderd : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Sleutel Verwijderd : HKCU\Software\AnyProtect
Sleutel Verwijderd : HKCU\Software\APNDTX
Sleutel Verwijderd : HKCU\Software\Babylon
Sleutel Verwijderd : HKCU\Software\Driver Pro
Sleutel Verwijderd : HKCU\Software\GlobalUpdate
Sleutel Verwijderd : HKCU\Software\ilivid
Sleutel Verwijderd : HKCU\Software\Ironsource
Sleutel Verwijderd : HKCU\Software\Optimizer Pro
Sleutel Verwijderd : HKCU\Software\Softonic
Sleutel Verwijderd : HKCU\Software\systweak
Sleutel Verwijderd : HKCU\Software\torch
Sleutel Verwijderd : HKCU\Software\TutoTag
Sleutel Verwijderd : HKCU\Software\V9
Sleutel Verwijderd : HKCU\Software\Reimage
Sleutel Verwijderd : HKCU\Software\GAMESDESKTOP
Sleutel Verwijderd : HKCU\Software\Super Optimizer
Sleutel Verwijderd : HKCU\Software\eFix
Sleutel Verwijderd : HKCU\Software\Local AppWizard-Generated Applications
Sleutel Verwijderd : HKCU\Software\Linkey
Sleutel Verwijderd : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
Sleutel Verwijderd : HKCU\Software\AppDataLow\Software\BlockAndSurf
Sleutel Verwijderd : HKCU\Software\AppDataLow\Software\Crossrider
Sleutel Verwijderd : HKLM\SOFTWARE\{1146AC44-2F03-4431-B4FD-889BC837521F}
Sleutel Verwijderd : HKLM\SOFTWARE\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Sleutel Verwijderd : HKLM\SOFTWARE\{6791A2F3-FC80-475C-A002-C014AF797E9C}
Sleutel Verwijderd : HKLM\SOFTWARE\Babylon
Sleutel Verwijderd : HKLM\SOFTWARE\Desksvc
Sleutel Verwijderd : HKLM\SOFTWARE\EZ Software Updater
Sleutel Verwijderd : HKLM\SOFTWARE\GlobalUpdate
Sleutel Verwijderd : HKLM\SOFTWARE\hdcode
Sleutel Verwijderd : HKLM\SOFTWARE\IePlugin
Sleutel Verwijderd : HKLM\SOFTWARE\Ironsource
Sleutel Verwijderd : HKLM\SOFTWARE\portaldositesSoftware
Sleutel Verwijderd : HKLM\SOFTWARE\SmdmF
Sleutel Verwijderd : HKLM\SOFTWARE\Solvusoft
Sleutel Verwijderd : HKLM\SOFTWARE\SupDp
Sleutel Verwijderd : HKLM\SOFTWARE\SupTab
Sleutel Verwijderd : HKLM\SOFTWARE\supWindowsMangerProtect
Sleutel Verwijderd : HKLM\SOFTWARE\systweak
Sleutel Verwijderd : HKLM\SOFTWARE\torch
Sleutel Verwijderd : HKLM\SOFTWARE\Tutorials
Sleutel Verwijderd : HKLM\SOFTWARE\V9
Sleutel Verwijderd : HKLM\SOFTWARE\V9Software
Sleutel Verwijderd : HKLM\SOFTWARE\winzipersvc
Sleutel Verwijderd : HKLM\SOFTWARE\Wpm
Sleutel Verwijderd : HKLM\SOFTWARE\mystartsearchSoftware
Sleutel Verwijderd : HKLM\SOFTWARE\GAMESDESKTOP
Sleutel Verwijderd : HKLM\SOFTWARE\IHProtect
Sleutel Verwijderd : HKLM\SOFTWARE\Fighters
Sleutel Verwijderd : HKLM\SOFTWARE\QuickRef_1.10.0.9
Sleutel Verwijderd : HKU\.DEFAULT\Software\systweak
Sleutel Verwijderd : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DealPly
Sleutel Verwijderd : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\EZ Software Updater_is1
Sleutel Verwijderd : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\VOPackage
Sleutel Verwijderd : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{37476589-E48E-439E-A706-56189E2ED4C4}_is1
Sleutel Verwijderd : [x64] HKLM\SOFTWARE\Tarma Installer
Sleutel Verwijderd : [x64] HKLM\SOFTWARE\Reimage
Sleutel Verwijderd : [x64] HKLM\SOFTWARE\eFix
Sleutel Verwijderd : [x64] HKLM\SOFTWARE\Linkey
Sleutel Verwijderd : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}
Sleutel Verwijderd : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Reimage Express
Sleutel Verwijderd : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst32.exe
Sleutel Verwijderd : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst64.exe
Sleutel Verwijderd : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\utiljumpflip.exe
Sleutel Verwijderd : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\websteroids.exe
Sleutel Verwijderd : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\websteroidsservice.exe
 
***** [ Webbrowsers ] *****
 
-\\ Internet Explorer v9.0.8112.16636
 
Setting Hersteld : HKCU\Software\Microsoft\Internet Explorer\Search [CustomizeSearch]
 
-\\ Google Chrome v
 
[C:\Users\transit\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Verwijderd [Search Provider] : hxxp://nl.softonic.com/s/{searchTerms}
[C:\Users\transit\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Verwijderd [Search Provider] : hxxp://www.v9.com/web?type=ds&ts=1422519313&from=zbd1&uid=st2000dl003-9vt166_6yd18awhxxxx6yd18awh&q={searchTerms}&ref=d3d3Lm15c3RhcnRzZWFyY2guY29t
[C:\Users\transit\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Verwijderd [Search Provider] : hxxp://www.v9.com/web?type=ds&ts=1422519313&from=zbd1&uid=st2000dl003-9vt166_6yd18awhxxxx6yd18awh&q={searchTerms}&ref=d3d3Lm15c3RhcnRzZWFyY2guY29t
[C:\Users\transit\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Verwijderd [Search Provider] : hxxp://www.mystartsearch.com/web/?type=dspp&ts=1424876756&from=cmi&uid=ST2000DL003-9VT166_6YD18AWHXXXX6YD18AWH&q={searchTerms}
[C:\Users\transit\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Verwijderd [Search Provider] : hxxp://www.mystartsearch.com/web/?type=dspp&ts=1424876756&from=cmi&uid=ST2000DL003-9VT166_6YD18AWHXXXX6YD18AWH&q={searchTerms}
[C:\Users\transit\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] - Verwijderd [Extension] : booedmolknjekdopkepjjeckmjkdpfgl
[C:\Users\transit\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] - Verwijderd [Extension] : flpcjncodpafbgdpnkljologafpionhb
[C:\Users\transit\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] - Verwijderd [Extension] : fpmeembnagmagppkgghhfjfdfajdfcah
[C:\Users\transit\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] - Verwijderd [Extension] : gcncagkkhfoombgbihckkccmkjemhohl
[C:\Users\transit\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] - Verwijderd [Extension] : iomphmdalfmaifjccmagmllnicjoghhk
[C:\Users\transit\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] - Verwijderd [Homepage] : hxxp://www.mystartsearch.com/?type=hppp&ts=1424876756&from=cmi&uid=ST2000DL003-9VT166_6YD18AWHXXXX6YD18AWH
[C:\Users\transit\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] - Verwijderd [Default_Search_Provider_Data] : hxxp://www.mystartsearch.com/web/?type=dspp&ts=1424876756&from=cmi&uid=ST2000DL003-9VT166_6YD18AWHXXXX6YD18AWH&q={searchTerms}
 
-\\ Opera v0.0.0.0
 
 
*************************
 
AdwCleaner[R0].txt - [22783 bytes] - [22/04/2015 14:16:09]
AdwCleaner[S0].txt - [21699 bytes] - [22/04/2015 14:18:10]
 
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [21759  bytes] ##########

  • 0

#6
HaraMo

HaraMo

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 456 posts

About google chrome, I don't see it on the system, only internet explorer.


  • 0

#7
HaraMo

HaraMo

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 456 posts
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 20-04-2015
Ran by transit (administrator) on TRANSIT-PC on 22-04-2015 14:29:06
Running from C:\Users\transit\Desktop
Loaded Profiles: transit & UpdatusUser (Available profiles: transit & UpdatusUser & DefaultAppPool)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Nederlands (Nederland)
Internet Explorer Version 9 (Default browser: Opera)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo...very-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Windows\System32\CISVC.EXE
(Paramount Software UK Ltd) C:\Program Files\Macrium\Reflect\ReflectService.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(Microsoft Corporation) C:\Windows\System32\TCPSVCS.EXE
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_w32.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_x64.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Desktop.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
 
 
==================== Registry (Whitelisted) ==================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [1794704 2015-03-11] (NVIDIA Corporation)
HKLM\...\RunOnce: [MedionReminder] => C:\Program Files (x86)\CyberLink\PowerRecover\Reminder.exe [443688 2011-05-26] (CyberLink)
HKU\S-1-5-19\...\Run: [Sidebar] => %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
HKU\S-1-5-19\Control Panel\Desktop\\SCRNSAVE.EXE -> 
HKU\S-1-5-20\...\Run: [Sidebar] => %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
HKU\S-1-5-20\Control Panel\Desktop\\SCRNSAVE.EXE -> 
HKU\S-1-5-21-3839137701-2974941544-2065132041-1002\...\RunOnce: [Uninstall C:\Users\transit\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\transit\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64"
HKU\S-1-5-21-3839137701-2974941544-2065132041-1002\...\Policies\system: [LogonHoursAction] 2
HKU\S-1-5-21-3839137701-2974941544-2065132041-1002\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
HKU\S-1-5-21-3839137701-2974941544-2065132041-1002\...\Policies\Explorer: [NoInstrumentation] 0
HKU\S-1-5-21-3839137701-2974941544-2065132041-1002\...\MountPoints2: {1767b950-20e8-11e1-ab1a-8c89a57d6dd6} - I:\iStudio.exe
HKU\S-1-5-21-3839137701-2974941544-2065132041-1002\Control Panel\Desktop\\SCRNSAVE.EXE -> 
HKU\S-1-5-21-3839137701-2974941544-2065132041-1007\...\Run: [Sidebar] => %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
HKU\S-1-5-21-3839137701-2974941544-2065132041-1007\...\Run: [Driver Whiz] => C:\Program Files (x86)\Driver Whiz\Driver Whiz\DriverWhiz.exe /applicationMode:systemTray /showWelcome:false
HKU\S-1-5-21-3839137701-2974941544-2065132041-1007\...\RunOnce: [HKCU] => C:\Windows\System32\oobe\info\HKCU.vbs [126 2009-11-12] ()
HKU\S-1-5-21-3839137701-2974941544-2065132041-1007\...\RunOnce: [Screensaver] => C:\Windows\Web\Wallpaper\MEDION\start.vbs
HKU\S-1-5-21-3839137701-2974941544-2065132041-1007\...\MountPoints2: {1767b950-20e8-11e1-ab1a-8c89a57d6dd6} - I:\iStudio.exe
HKU\S-1-5-21-3839137701-2974941544-2065132041-1007\Control Panel\Desktop\\SCRNSAVE.EXE -> 
HKU\S-1-5-18\Control Panel\Desktop\\SCRNSAVE.EXE -> 
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  No File
ShellIconOverlayIdentifiers: [KAVOverlayIcon] -> {014F27E2-6D75-4E42-A0E9-2A2C68498AFA} => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 15.0.1\x64\shellex.dll [2015-03-20] (Kaspersky Lab ZAO)
ShellIconOverlayIdentifiers-x32: [KAVOverlayIcon] -> {014F27E2-6D75-4E42-A0E9-2A2C68498AFA} => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 15.0.1\shellex.dll [2015-03-20] (Kaspersky Lab ZAO)
GroupPolicyUsers\S-1-5-21-3839137701-2974941544-2065132041-1007\User: Group Policy restriction detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
HKU\S-1-5-21-3839137701-2974941544-2065132041-1002\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.be/
HKU\S-1-5-21-3839137701-2974941544-2065132041-1007\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.delta-...q={searchTerms}
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-21-3839137701-2974941544-2065132041-1002 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = http://www.google.com/search
SearchScopes: HKU\S-1-5-21-3839137701-2974941544-2065132041-1007 -> DefaultScope {425ED333-6083-428a-92C9-0CFC28B9D1BF} URL = http://www.v9.com/we...q={searchTerms}
SearchScopes: HKU\S-1-5-21-3839137701-2974941544-2065132041-1007 -> 528CB8441A254254BF9CDE1F824F96E2 URL = http://dts.search.as...q={searchTerms}
SearchScopes: HKU\S-1-5-21-3839137701-2974941544-2065132041-1007 -> {2077B4E2-3ADF-4315-BC05-B46E93073FAA} URL = 
SearchScopes: HKU\S-1-5-21-3839137701-2974941544-2065132041-1007 -> {425ED333-6083-428a-92C9-0CFC28B9D1BF} URL = http://www.v9.com/we...q={searchTerms}
SearchScopes: HKU\S-1-5-21-3839137701-2974941544-2065132041-1007 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = 
SearchScopes: HKU\S-1-5-21-3839137701-2974941544-2065132041-1007 -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = 
SearchScopes: HKU\S-1-5-21-3839137701-2974941544-2065132041-1007 -> {E88E0043-C9D4-4e33-8555-FEE4F5B63060} URL = 
SearchScopes: HKU\S-1-5-21-3839137701-2974941544-2065132041-1007 -> {F47F85FE-AF0F-4C1F-8EB8-EFFDEAA53904} URL = 
BHO: Content Blocker Plugin -> {03C04F0A-E2A3-4F7F-BA30-BFA06FFD1358} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 15.0.1\x64\IEExt\ie_plugin.dll [2015-03-20] (Kaspersky Lab ZAO)
BHO: cheAp4alL -> {6157f868-f12f-4ba9-804a-09533fccf080} -> C:\Program Files (x86)\cheAp4alL\V7eWClGiRZNClM.x64.dll [2015-04-15] ()
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO: Louwpriocees -> {a1c8fa6f-f886-4e2c-a175-0e59314e7bd1} -> C:\Program Files (x86)\Louwpriocees\q5bxY2zF9OCIQL.x64.dll No File
BHO: Virtual Keyboard Plugin -> {B5D5BB14-C8E2-478D-9C97-574AC10AF9E8} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 15.0.1\x64\IEExt\ie_plugin.dll [2015-03-20] (Kaspersky Lab ZAO)
BHO: Safe Money Plugin -> {E3D96E85-529D-4269-AC6A-97CF9E2221E3} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 15.0.1\x64\IEExt\ie_plugin.dll [2015-03-20] (Kaspersky Lab ZAO)
BHO-x32: Content Blocker Plugin -> {03C04F0A-E2A3-4F7F-BA30-BFA06FFD1358} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 15.0.1\IEExt\ie_plugin.dll [2015-03-20] (Kaspersky Lab ZAO)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\ssv.dll [2015-03-18] (Oracle Corporation)
BHO-x32: Aanmeldhulp voor Microsoft-account -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO-x32: Virtual Keyboard Plugin -> {B5D5BB14-C8E2-478D-9C97-574AC10AF9E8} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 15.0.1\IEExt\ie_plugin.dll [2015-03-20] (Kaspersky Lab ZAO)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\jp2ssv.dll [2015-03-18] (Oracle Corporation)
BHO-x32: Safe Money Plugin -> {E3D96E85-529D-4269-AC6A-97CF9E2221E3} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 15.0.1\IEExt\ie_plugin.dll [2015-03-20] (Kaspersky Lab ZAO)
DPF: HKLM-x32 {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.micros...n/ieawsdc32.cab
Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} -  No File
Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} -  No File
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
 
FireFox:
========
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_17_0_0_169.dll [2015-04-17] ()
FF Plugin: @microsoft.com/GENUINE -> C:\Windows\system32\Wat\npWatWeb.dll [2011-08-12] (Microsoft Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_169.dll [2015-04-17] ()
FF Plugin-x32: @java.com/DTPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll [2015-03-18] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\plugin2\npjp2.dll [2015-03-18] (Oracle Corporation)
FF Plugin-x32: @kaspersky.com/content_blocker_6418E0D362104DADA084DC312DFA8ABC -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 15.0.1\FFExt\[email protected] [2015-03-20] ()
FF Plugin-x32: @kaspersky.com/online_banking_69A4E213815F42BD863D889007201D82 -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 15.0.1\FFExt\[email protected] [2015-03-20] ()
FF Plugin-x32: @kaspersky.com/virtual_keyboard_294FF26A1D5B455495946778FDE7CEDB -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 15.0.1\FFExt\[email protected] [2015-03-20] ()
FF Plugin-x32: @microsoft.com/GENUINE -> C:\Windows\system32\Wat\npWatWeb.dll [2011-08-12] (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-09-12] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-09-12] (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2015-02-05] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2015-02-05] (NVIDIA Corporation)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-12-03] (Adobe Systems Inc.)
FF Extension: Belgium eID - C:\Program Files (x86)\Mozilla Firefox\extensions\[email protected] [2013-05-31]
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files (x86)\Babylon\Babylon-Pro\Utils\[email protected]
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 15.0.1\FFExt\[email protected]
FF Extension: Dangerous Websites Blocker - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 15.0.1\FFExt\[email protected] [2015-03-20]
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 15.0.1\FFExt\[email protected]
FF Extension: Virtual Keyboard - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 15.0.1\FFExt\[email protected] [2015-03-20]
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 15.0.1\FFExt\[email protected]
FF Extension: Safe Money - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 15.0.1\FFExt\[email protected] [2015-03-20]
 
Chrome: 
=======
CHR dev: Chrome dev build detected! <======= ATTENTION
CHR StartupUrls: Default -> "hxxp://www.mystartsearch.com/?type=hppp&ts=1424876756&from=cmi&uid=ST2000DL003-9VT166_6YD18AWHXXXX6YD18AWH"
CHR Profile: C:\Users\transit\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\transit\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2014-10-14]
CHR Extension: (Google Docs) - C:\Users\transit\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-10-14]
CHR Extension: (Google Drive) - C:\Users\transit\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-10-14]
CHR Extension: (YouTube) - C:\Users\transit\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-10-14]
CHR Extension: (Adblock Plus) - C:\Users\transit\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2015-02-27]
CHR Extension: (Google Search) - C:\Users\transit\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-10-14]
CHR Extension: (Select Search) - C:\Users\transit\AppData\Local\Google\Chrome\User Data\Default\Extensions\fcjoilhmjjhfpeflkmlhejiaadbgfkgn [2015-04-15]
CHR Extension: (Google Sheets) - C:\Users\transit\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2014-10-14]
CHR Extension: (Clickable Links) - C:\Users\transit\AppData\Local\Google\Chrome\User Data\Default\Extensions\mgamelhnfokapndfdodnmfiningckjia [2015-03-17]
CHR Extension: (Google Wallet) - C:\Users\transit\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-10-14]
CHR Extension: (20-20 3D Viewer for IKEA) - C:\Users\transit\AppData\Local\Google\Chrome\User Data\Default\Extensions\pfhldcakmgpmglboaclpfdedehjblalp [2014-12-03]
CHR Extension: (Gmail) - C:\Users\transit\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-10-14]
CHR HKLM\...\Chrome\Extension: [dbhjdbfgekjfcfkkfjjmlmojhbllhbho] - https://chrome.googl...jjmlmojhbllhbho
CHR HKLM-x32\...\Chrome\Extension: [dbhjdbfgekjfcfkkfjjmlmojhbllhbho] - https://chrome.googl...jjmlmojhbllhbho
 
==================== Services (Whitelisted) =================
 
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
 
S3 AVP15.0.1; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 15.0.1\avp.exe [234520 2014-08-30] (Kaspersky Lab ZAO)
S4 BotkindSyncService; C:\Program Files (x86)\Allway Sync\Bin\SyncService.exe [182784 2012-12-26] () [File not signed]
R2 HPSLPSVC; C:\Users\transit\AppData\Local\Temp\7zS36B0\hpslpsvc64.dll [1039360 2013-07-19] (Hewlett-Packard Co.) [File not signed]
R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [71680 2010-08-06] (Hewlett-Packard) [File not signed]
R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [89600 2010-08-06] (Hewlett-Packard) [File not signed]
R2 ReflectService.exe; C:\Program Files\Macrium\Reflect\ReflectService.exe [3272656 2014-07-21] (Paramount Software UK Ltd)
R2 simptcp; C:\Windows\SysWOW64\tcpsvcs.exe [9216 2009-07-14] (Microsoft Corporation)
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [5448464 2015-03-30] (TeamViewer GmbH)
S4 TlntSvr; C:\Windows\System32\tlntsvr.exe [81920 2009-07-14] (Microsoft Corporation)
R2 W3SVC; C:\Windows\system32\inetsrv\iisw3adm.dll [453120 2010-11-21] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
 
==================== Drivers (Whitelisted) ====================
 
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
 
S3 AVFSFilter; No ImagePath
R0 cm_km_w; C:\Windows\System32\DRIVERS\cm_km_w.sys [238288 2013-01-14] (Kaspersky Lab UK Ltd)
S3 IntcAzAudAddService; No ImagePath
R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [468576 2014-03-31] (Kaspersky Lab ZAO)
R2 kldisk; C:\Windows\System32\DRIVERS\kldisk.sys [46144 2014-07-02] (Kaspersky Lab ZAO)
R3 klflt; C:\Windows\System32\DRIVERS\klflt.sys [150536 2015-03-20] (Kaspersky Lab ZAO)
R1 klhk; C:\Windows\System32\DRIVERS\klhk.sys [246456 2014-08-12] (Kaspersky Lab ZAO)
R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [819896 2015-03-20] (Kaspersky Lab ZAO)
R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [30304 2014-02-25] (Kaspersky Lab ZAO)
R3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [28768 2014-03-28] (Kaspersky Lab ZAO)
R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [29280 2013-08-08] (Kaspersky Lab ZAO)
R1 klpd; C:\Windows\System32\DRIVERS\klpd.sys [15456 2013-04-12] (Kaspersky Lab ZAO)
R1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [55872 2014-06-05] (Kaspersky Lab ZAO)
R1 Klwtp; C:\Windows\System32\DRIVERS\klwtp.sys [77512 2015-03-20] (Kaspersky Lab ZAO)
R1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [179776 2014-07-09] (Kaspersky Lab ZAO)
S0 nvpciflt; No ImagePath
S3 PSMounterEx; C:\Windows\system32\drivers\psmounterex.sys [169992 2015-04-02] (Windows ® Win 7 DDK provider)
S3 PSVolAcc; C:\Windows\System32\Drivers\PSVolAcc.sys [12760 2014-07-21] (Paramount Software UK Ltd)
S3 cpuz134; \??\C:\Users\transit\AppData\Local\Temp\cpuz134\cpuz134_x64.sys [X]
U4 klkbdflt2; system32\DRIVERS\klkbdflt2.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
 
 
==================== One Month Created Files and Folders ========
 
(If an entry is included in the fixlist, the file\folder will be moved.)
 
2015-04-22 14:28 - 2015-04-22 14:28 - 00000000 ____D () C:\Users\transit\Desktop\FRST-OlderVersion
2015-04-22 14:15 - 2015-04-22 14:18 - 00000000 ____D () C:\AdwCleaner
2015-04-22 14:15 - 2015-04-22 12:24 - 02217984 _____ () C:\Users\transit\Desktop\adwcleaner_4.201.exe
2015-04-22 14:09 - 2015-04-22 14:09 - 00061551 _____ () C:\Users\transit\Desktop\JRT.txt
2015-04-22 14:08 - 2015-04-22 14:08 - 00000207 _____ () C:\Windows\tweaking.com-regbackup-TRANSIT-PC-Windows-7-Home-Premium-(64-bit).dat
2015-04-22 14:08 - 2015-04-22 14:08 - 00000000 ____D () C:\RegBackup
2015-04-22 14:07 - 2015-04-22 12:22 - 02685507 _____ (Thisisu) C:\Users\transit\Desktop\JRT.exe
2015-04-22 12:11 - 2015-04-22 12:11 - 00000000 ____D () C:\Users\transit\Documents\Reflect
2015-04-22 12:06 - 2015-04-22 12:06 - 00002483 _____ () C:\Users\Public\Desktop\Reflect.lnk
2015-04-22 12:06 - 2015-04-22 12:06 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Macrium
2015-04-22 12:06 - 2015-04-22 12:06 - 00000000 ____D () C:\Program Files\Macrium
2015-04-22 12:05 - 2015-04-22 12:06 - 00377892 _____ () C:\Reflect_Install.log
2015-04-22 12:03 - 2015-04-22 12:04 - 00000000 ____D () C:\Users\transit\Downloads\Macrium
2015-04-22 12:03 - 2015-04-22 12:04 - 00000000 ____D () C:\ProgramData\Macrium
2015-04-22 12:02 - 2015-04-22 12:00 - 03545552 _____ (Paramount Software UK Ltd) C:\Users\transit\Desktop\ReflectDL.exe
2015-04-20 00:16 - 2015-03-10 02:31 - 17882112 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-04-20 00:16 - 2015-03-10 02:19 - 02339840 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-04-20 00:16 - 2015-03-10 02:19 - 00448512 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-04-20 00:16 - 2015-03-10 02:18 - 10931200 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-04-20 00:16 - 2015-03-10 02:14 - 01392128 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-04-20 00:16 - 2015-03-10 02:14 - 01388032 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-04-20 00:16 - 2015-03-10 02:13 - 02157568 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-04-20 00:16 - 2015-03-10 02:13 - 01494016 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-04-20 00:16 - 2015-03-10 02:13 - 00816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-04-20 00:16 - 2015-03-10 02:13 - 00729088 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-04-20 00:16 - 2015-03-10 02:13 - 00598528 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-04-20 00:16 - 2015-03-10 02:13 - 00237056 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2015-04-20 00:16 - 2015-03-10 02:13 - 00173056 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-04-20 00:16 - 2015-03-10 02:13 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-04-20 00:16 - 2015-03-10 02:12 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-04-20 00:16 - 2015-03-10 02:12 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-04-20 00:16 - 2015-03-10 02:12 - 00282112 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-04-20 00:16 - 2015-03-10 02:12 - 00248320 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-04-20 00:16 - 2015-03-10 02:12 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-04-20 00:16 - 2015-03-10 02:12 - 00055296 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2015-04-20 00:16 - 2015-03-10 02:12 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2015-04-20 00:16 - 2015-03-10 02:12 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2015-04-20 00:16 - 2015-03-10 01:06 - 12377600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2015-04-20 00:16 - 2015-03-10 01:03 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2015-04-20 00:16 - 2015-03-10 01:02 - 01810944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2015-04-20 00:16 - 2015-03-10 01:00 - 09747968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2015-04-20 00:16 - 2015-03-10 00:57 - 01139200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2015-04-20 00:16 - 2015-03-10 00:57 - 01129472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2015-04-20 00:16 - 2015-03-10 00:56 - 01803264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2015-04-20 00:16 - 2015-03-10 00:56 - 01427968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2015-04-20 00:16 - 2015-03-10 00:56 - 00717824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2015-04-20 00:16 - 2015-03-10 00:56 - 00421376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2015-04-20 00:16 - 2015-03-10 00:56 - 00231936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2015-04-20 00:16 - 2015-03-10 00:56 - 00065024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2015-04-20 00:16 - 2015-03-10 00:55 - 02382848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2015-04-20 00:16 - 2015-03-10 00:55 - 00607744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2015-04-20 00:16 - 2015-03-10 00:55 - 00353792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2015-04-20 00:16 - 2015-03-10 00:55 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2015-04-20 00:16 - 2015-03-10 00:55 - 00176640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2015-04-20 00:16 - 2015-03-10 00:55 - 00142848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2015-04-20 00:16 - 2015-03-10 00:55 - 00073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2015-04-20 00:16 - 2015-03-10 00:55 - 00041472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2015-04-20 00:16 - 2015-03-10 00:55 - 00011776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
2015-04-20 00:16 - 2015-03-10 00:55 - 00010752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2015-04-18 23:57 - 2015-04-18 23:57 - 00037834 _____ () C:\Users\transit\Desktop\Addition.txt
2015-04-18 23:56 - 2015-04-22 14:29 - 00020294 _____ () C:\Users\transit\Desktop\FRST.txt
2015-04-18 23:56 - 2015-04-22 14:29 - 00000000 ____D () C:\FRST
2015-04-18 23:53 - 2015-04-22 14:28 - 02099712 _____ (Farbar) C:\Users\transit\Desktop\FRST64.exe
2015-04-18 23:53 - 2015-04-22 12:24 - 00000000 ____D () C:\Users\transit\Desktop\stappen
2015-04-18 23:31 - 2015-04-18 23:31 - 00000000 ____D () C:\Users\transit\AppData\Local\TeamViewer
2015-04-18 23:30 - 2015-04-18 23:30 - 00000975 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 10.lnk
2015-04-18 15:04 - 2015-04-18 15:04 - 00000000 ____D () C:\Windows\pss
2015-04-18 11:42 - 2015-04-18 11:42 - 00001405 _____ () C:\Users\transit\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
2015-04-17 17:13 - 2015-04-17 17:13 - 00000636 __RSH () C:\Users\transit\ntuser.pol
2015-04-17 15:18 - 2015-04-17 15:18 - 00003030 _____ () C:\Windows\System32\Tasks\{50C37B14-2259-4BCD-B52E-783030EF8F71}
2015-04-17 15:16 - 2015-04-17 15:16 - 00003030 _____ () C:\Windows\System32\Tasks\{9514EDF2-1A91-4E9F-A395-CB65BC391C6E}
2015-04-17 15:11 - 2015-04-17 15:12 - 00009988 _____ () C:\Windows\iis7.log
2015-04-17 14:54 - 2015-04-17 14:54 - 18178736 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2015-04-16 22:30 - 2015-04-16 22:30 - 00000169 _____ () C:\Users\transit\Desktop\Google.url
2015-04-15 16:49 - 2015-04-15 16:50 - 00000000 ____D () C:\Program Files (x86)\Select Search
2015-04-15 16:49 - 2015-04-15 16:50 - 00000000 ____D () C:\Program Files (x86)\cheAp4alL
2015-04-15 16:24 - 2015-03-25 05:24 - 03298816 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2015-04-15 16:24 - 2015-03-25 05:24 - 02553856 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2015-04-15 16:24 - 2015-03-25 05:24 - 00696320 _____ (Microsoft Corporation) C:\Windows\system32\wuapi(72).dll
2015-04-15 16:24 - 2015-03-25 05:24 - 00191488 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2015-04-15 16:24 - 2015-03-25 05:24 - 00098304 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2015-04-15 16:24 - 2015-03-25 05:24 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
2015-04-15 16:24 - 2015-03-25 05:24 - 00037376 _____ (Microsoft Corporation) C:\Windows\system32\wups2(73).dll
2015-04-15 16:24 - 2015-03-25 05:24 - 00035328 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2015-04-15 16:24 - 2015-03-25 05:23 - 00135168 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2015-04-15 16:24 - 2015-03-25 05:23 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2015-04-15 16:24 - 2015-03-25 05:23 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll
2015-04-15 16:24 - 2015-03-25 05:00 - 00566784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2015-04-15 16:24 - 2015-03-25 05:00 - 00173056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2015-04-15 16:24 - 2015-03-25 05:00 - 00092672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2015-04-15 16:24 - 2015-03-25 05:00 - 00033792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2015-04-15 16:24 - 2015-03-25 05:00 - 00029696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2015-04-15 16:24 - 2015-03-23 05:25 - 00769536 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2015-04-15 16:24 - 2015-03-23 05:25 - 00726528 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2015-04-15 16:24 - 2015-03-23 05:24 - 00957952 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2015-04-15 16:24 - 2015-03-23 05:24 - 00419840 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2015-04-15 16:24 - 2015-03-23 05:24 - 00227328 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2015-04-15 16:24 - 2015-03-23 05:24 - 00192000 _____ (Microsoft Corporation) C:\Windows\system32\aepic(41).dll
2015-04-15 16:24 - 2015-03-23 05:24 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2015-04-15 16:24 - 2015-03-23 05:17 - 01111552 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2015-04-15 16:24 - 2015-03-17 07:22 - 05557696 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-04-15 16:24 - 2015-03-17 07:22 - 00155576 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2015-04-15 16:24 - 2015-03-17 07:22 - 00095672 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2015-04-15 16:24 - 2015-03-17 07:19 - 01727904 _____ (Microsoft Corporation) C:\Windows\system32\ntdll(56).dll
2015-04-15 16:24 - 2015-03-17 07:17 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win(71).dll
2015-04-15 16:24 - 2015-03-17 07:17 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64(69).dll
2015-04-15 16:24 - 2015-03-17 07:17 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu(70).dll
2015-04-15 16:24 - 2015-03-17 07:16 - 01461760 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv(50).dll
2015-04-15 16:24 - 2015-03-17 07:16 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32(48).dll
2015-04-15 16:24 - 2015-03-17 07:16 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos(47).dll
2015-04-15 16:24 - 2015-03-17 07:16 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore(60).dll
2015-04-15 16:24 - 2015-03-17 07:16 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase(49).dll
2015-04-15 16:24 - 2015-03-17 07:16 - 00341504 _____ (Microsoft Corporation) C:\Windows\system32\schannel(57).dll
2015-04-15 16:24 - 2015-03-17 07:16 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0(52).dll
2015-04-15 16:24 - 2015-03-17 07:16 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt(55).dll
2015-04-15 16:24 - 2015-03-17 07:16 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-04-15 16:24 - 2015-03-17 07:16 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv(68).dll
2015-04-15 16:24 - 2015-03-17 07:16 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest(65).dll
2015-04-15 16:24 - 2015-03-17 07:16 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli(61).dll
2015-04-15 16:24 - 2015-03-17 07:16 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss(59).exe
2015-04-15 16:24 - 2015-03-17 07:16 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg(63).dll
2015-04-15 16:24 - 2015-03-17 07:16 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-04-15 16:24 - 2015-03-17 07:16 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv(44).dll
2015-04-15 16:24 - 2015-03-17 07:16 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv(62).dll
2015-04-15 16:24 - 2015-03-17 07:16 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32(58).dll
2015-04-15 16:24 - 2015-03-17 07:16 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp(43).dll
2015-04-15 16:24 - 2015-03-17 07:16 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2015-04-15 16:24 - 2015-03-17 07:15 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2015-04-15 16:24 - 2015-03-17 07:15 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2015-04-15 16:24 - 2015-03-17 07:15 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass(51).exe
2015-04-15 16:24 - 2015-03-17 07:13 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2015-04-15 16:24 - 2015-03-17 07:13 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2015-04-15 16:24 - 2015-03-17 07:11 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2015-04-15 16:24 - 2015-03-17 07:11 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema(42).dll
2015-04-15 16:24 - 2015-03-17 07:11 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2015-04-15 16:24 - 2015-03-17 07:11 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2015-04-15 16:24 - 2015-03-17 07:11 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2015-04-15 16:24 - 2015-03-17 07:11 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2015-04-15 16:24 - 2015-03-17 07:11 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2015-04-15 16:24 - 2015-03-17 07:11 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2015-04-15 16:24 - 2015-03-17 07:11 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2015-04-15 16:24 - 2015-03-17 07:11 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2015-04-15 16:24 - 2015-03-17 07:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-04-15 16:24 - 2015-03-17 07:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2015-04-15 16:24 - 2015-03-17 07:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2015-04-15 16:24 - 2015-03-17 07:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2015-04-15 16:24 - 2015-03-17 07:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2015-04-15 16:24 - 2015-03-17 07:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2015-04-15 16:24 - 2015-03-17 07:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2015-04-15 16:24 - 2015-03-17 07:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2015-04-15 16:24 - 2015-03-17 07:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2015-04-15 16:24 - 2015-03-17 07:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2015-04-15 16:24 - 2015-03-17 07:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2015-04-15 16:24 - 2015-03-17 07:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2015-04-15 16:24 - 2015-03-17 07:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2015-04-15 16:24 - 2015-03-17 07:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2015-04-15 16:24 - 2015-03-17 07:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2015-04-15 16:24 - 2015-03-17 07:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2015-04-15 16:24 - 2015-03-17 07:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2015-04-15 16:24 - 2015-03-17 07:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2015-04-15 16:24 - 2015-03-17 07:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2015-04-15 16:24 - 2015-03-17 07:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2015-04-15 16:24 - 2015-03-17 07:01 - 03976632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2015-04-15 16:24 - 2015-03-17 07:01 - 03920824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2015-04-15 16:24 - 2015-03-17 06:59 - 01309696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll(79).dll
2015-04-15 16:24 - 2015-03-17 06:57 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2015-04-15 16:24 - 2015-03-17 06:57 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2015-04-15 16:24 - 2015-03-17 06:57 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2015-04-15 16:24 - 2015-03-17 06:57 - 00221184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2015-04-15 16:24 - 2015-03-17 06:57 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2015-04-15 16:24 - 2015-03-17 06:57 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2015-04-15 16:24 - 2015-03-17 06:57 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2015-04-15 16:24 - 2015-03-17 06:57 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32(80).dll
2015-04-15 16:24 - 2015-03-17 06:57 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2015-04-15 16:24 - 2015-03-17 06:56 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32(77).dll
2015-04-15 16:24 - 2015-03-17 06:56 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase(78).dll
2015-04-15 16:24 - 2015-03-17 06:56 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli(81).dll
2015-04-15 16:24 - 2015-03-17 06:56 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2015-04-15 16:24 - 2015-03-17 06:56 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2015-04-15 16:24 - 2015-03-17 06:56 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp(74).dll
2015-04-15 16:24 - 2015-03-17 06:56 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2015-04-15 16:24 - 2015-03-17 06:53 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2015-04-15 16:24 - 2015-03-17 06:53 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2015-04-15 16:24 - 2015-03-17 06:50 - 00686080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2015-04-15 16:24 - 2015-03-17 06:50 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2015-04-15 16:24 - 2015-03-17 06:50 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2015-04-15 16:24 - 2015-03-17 06:50 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2015-04-15 16:24 - 2015-03-17 06:50 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2015-04-15 16:24 - 2015-03-17 06:50 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2015-04-15 16:24 - 2015-03-17 06:50 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2015-04-15 16:24 - 2015-03-17 06:50 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2015-04-15 16:24 - 2015-03-17 06:50 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2015-04-15 16:24 - 2015-03-17 06:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2015-04-15 16:24 - 2015-03-17 06:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2015-04-15 16:24 - 2015-03-17 06:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2015-04-15 16:24 - 2015-03-17 06:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2015-04-15 16:24 - 2015-03-17 06:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2015-04-15 16:24 - 2015-03-17 06:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2015-04-15 16:24 - 2015-03-17 06:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2015-04-15 16:24 - 2015-03-17 06:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-04-15 16:24 - 2015-03-17 06:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2015-04-15 16:24 - 2015-03-17 06:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2015-04-15 16:24 - 2015-03-17 06:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2015-04-15 16:24 - 2015-03-17 06:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2015-04-15 16:24 - 2015-03-17 06:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2015-04-15 16:24 - 2015-03-17 06:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2015-04-15 16:24 - 2015-03-17 06:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2015-04-15 16:24 - 2015-03-17 06:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2015-04-15 16:24 - 2015-03-17 06:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2015-04-15 16:24 - 2015-03-17 05:45 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2015-04-15 16:24 - 2015-03-17 05:45 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2015-04-15 16:24 - 2015-03-17 05:43 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2015-04-15 16:24 - 2015-03-17 05:43 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2015-04-15 16:24 - 2015-03-17 05:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2015-04-15 16:24 - 2015-03-17 05:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2015-04-15 16:24 - 2015-03-13 06:07 - 02886144 _____ (Microsoft Corporation) C:\Windows\system32\iertutil(46).dll
2015-04-15 16:24 - 2015-03-13 05:22 - 02278400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil(76).dll
2015-04-15 16:24 - 2015-03-13 04:45 - 02358784 _____ (Microsoft Corporation) C:\Windows\system32\wininet(67).dll
2015-04-15 16:24 - 2015-03-13 04:33 - 01548288 _____ (Microsoft Corporation) C:\Windows\system32\urlmon(64).dll
2015-04-15 16:24 - 2015-03-13 04:20 - 01888256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet(83).dll
2015-04-15 16:24 - 2015-03-13 04:16 - 01311232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon(82).dll
2015-04-15 16:24 - 2015-03-10 05:25 - 01882624 _____ (Microsoft Corporation) C:\Windows\system32\msxml3(53).dll
2015-04-15 16:24 - 2015-03-10 05:21 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r(54).dll
2015-04-15 16:24 - 2015-03-10 05:08 - 01237504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2015-04-15 16:24 - 2015-03-10 05:05 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2015-04-15 16:24 - 2015-03-05 07:12 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32(45).dll
2015-04-15 16:24 - 2015-03-05 06:05 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32(75).dll
2015-04-15 16:24 - 2015-02-25 05:18 - 00754688 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\http.sys
2015-04-15 16:23 - 2015-03-04 06:55 - 00367552 _____ (Microsoft Corporation) C:\Windows\system32\clfs.sys
2015-04-15 16:23 - 2015-03-04 06:41 - 00079360 _____ (Microsoft Corporation) C:\Windows\system32\clfsw32.dll
2015-04-15 16:23 - 2015-03-04 06:10 - 00058880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\clfsw32.dll
2015-04-02 02:26 - 2015-04-02 02:26 - 00169992 _____ (Windows ® Win 7 DDK provider) C:\Windows\system32\Drivers\psmounterex.sys
2015-03-28 10:17 - 2015-03-28 10:17 - 00000000 ____D () C:\Users\transit\AppData\Local\NVIDIA
2015-03-28 10:10 - 2015-04-16 18:05 - 00000000 ___SD () C:\Windows\system32\GWX
2015-03-28 10:10 - 2015-03-28 10:10 - 00000000 ___SD () C:\Windows\SysWOW64\GWX
2015-03-28 10:09 - 2015-03-28 10:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2015-03-28 10:09 - 2015-02-05 19:57 - 00621384 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe
2015-03-28 09:49 - 2015-03-28 09:49 - 00000998 _____ () C:\Users\transit\Desktop\Apple iPhone - Snelkoppeling.lnk
2015-03-28 09:09 - 2015-03-28 09:10 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live
2015-03-28 09:05 - 2015-03-28 09:05 - 00000382 _____ () C:\Windows\DirectX.log
2015-03-28 09:04 - 2015-03-28 09:04 - 00002210 _____ () C:\Users\transit\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft OneDrive.lnk
2015-03-25 11:15 - 2015-03-11 06:05 - 00192000 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2015-03-24 16:22 - 2015-03-25 14:51 - 00002012 _____ () C:\Users\Public\Desktop\HP Print and Scan Doctor.lnk
2015-03-23 19:57 - 2015-04-18 10:09 - 00001829 _____ () C:\Windows\system32\ScanResults.xml
2015-03-23 19:55 - 2015-04-18 10:04 - 00000464 _____ () C:\Windows\system32\ScannerSettings
 
==================== One Month Modified Files and Folders =======
 
(If an entry is included in the fixlist, the file\folder will be moved.)
 
2015-04-22 14:28 - 2009-07-14 06:45 - 00024800 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-04-22 14:28 - 2009-07-14 06:45 - 00024800 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-04-22 14:23 - 2011-12-07 17:27 - 01374674 _____ () C:\Windows\WindowsUpdate.log
2015-04-22 14:19 - 2015-03-20 15:15 - 00007215 _____ () C:\Windows\setupact.log
2015-04-22 14:19 - 2011-09-06 00:24 - 00000000 ____D () C:\ProgramData\NVIDIA
2015-04-22 14:19 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-04-22 14:18 - 2015-01-09 15:33 - 00000000 ____D () C:\Windows\system32\log
2015-04-22 13:54 - 2012-05-17 09:39 - 00000940 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-04-22 12:12 - 2015-03-20 19:32 - 00000000 ____D () C:\ProgramData\Kaspersky Lab
2015-04-22 12:10 - 2011-05-16 16:47 - 00854064 _____ () C:\Windows\system32\perfh013.dat
2015-04-22 12:10 - 2011-05-16 16:47 - 00192888 _____ () C:\Windows\system32\perfc013.dat
2015-04-22 12:10 - 2009-07-14 07:13 - 01943218 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-04-22 11:49 - 2014-01-26 21:36 - 00003974 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{401E2AD1-3D61-4E10-AEA2-12D09233DAF5}
2015-04-19 13:02 - 2009-07-14 06:45 - 00358224 _____ () C:\Windows\system32\FNTCACHE.DAT
2015-04-19 00:04 - 2012-05-17 11:43 - 00000000 ____D () C:\Program Files (x86)\TeamViewer
2015-04-18 23:34 - 2011-12-07 17:34 - 00088536 _____ () C:\Users\transit\AppData\Local\GDIPFONTCACHEV1.DAT
2015-04-18 23:31 - 2012-05-15 20:12 - 00000000 ____D () C:\Users\transit\AppData\Roaming\TeamViewer
2015-04-18 15:05 - 2015-03-20 15:14 - 00007274 _____ () C:\Windows\PFRO.log
2015-04-18 15:01 - 2014-10-04 13:34 - 00000000 ____D () C:\Users\transit\AppData\Local\Unity
2015-04-18 13:45 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache
2015-04-18 12:38 - 2012-01-25 15:36 - 01916950 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI
2015-04-18 11:34 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\tr-TR
2015-04-18 11:34 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\sl-SI
2015-04-18 11:34 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\tr-TR
2015-04-18 11:34 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\sl-SI
2015-04-18 11:34 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2015-04-17 17:13 - 2011-12-07 17:33 - 00000000 ____D () C:\Users\transit
2015-04-17 17:13 - 2009-07-14 05:20 - 00000000 ___HD () C:\Windows\system32\GroupPolicy
2015-04-17 15:57 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\NDF
2015-04-17 15:08 - 2009-07-14 07:32 - 00000000 ____D () C:\Program Files\Windows Sidebar
2015-04-17 15:08 - 2009-07-14 07:32 - 00000000 ____D () C:\Program Files\DVD Maker
2015-04-17 15:07 - 2011-04-12 10:28 - 00000000 ___RD () C:\Users\Public\Recorded TV
2015-04-17 15:07 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\inetsrv
2015-04-17 15:07 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\inetsrv
2015-04-17 14:54 - 2012-05-17 09:39 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-04-17 14:54 - 2012-05-17 09:39 - 00003878 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-04-17 14:54 - 2011-08-10 21:09 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-04-17 14:18 - 2015-03-02 15:33 - 00000000 ____D () C:\Users\DefaultAppPool
2015-04-17 14:18 - 2015-02-25 16:22 - 00000000 ____D () C:\ProgramData\{73ae9642-a57e-1a36-73ae-e9642a57590a}
2015-04-17 14:18 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\registration
2015-04-16 19:44 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\AppCompat
2015-04-16 18:06 - 2014-12-11 04:23 - 00000000 ____D () C:\Windows\system32\appraiser
2015-04-16 18:06 - 2014-04-30 15:07 - 00000000 ___SD () C:\Windows\system32\CompatTel
2015-04-16 18:05 - 2014-03-25 15:02 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2015-04-16 18:05 - 2011-12-07 17:28 - 00000000 ____D () C:\Program Files (x86)\Google
2015-04-16 18:05 - 2009-07-14 05:20 - 00000000 ____D () C:\Program Files\Common Files\Microsoft Shared
2015-04-16 18:02 - 2011-12-07 17:47 - 00000000 ____D () C:\Users\transit\AppData\Local\Google
2015-04-16 03:13 - 2013-08-15 08:48 - 00000000 ____D () C:\Windows\system32\MRT
2015-04-16 03:05 - 2011-07-18 22:31 - 128913832 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-04-15 16:50 - 2015-03-10 14:26 - 00000000 ____D () C:\ProgramData\5786049068603124795
2015-03-28 10:09 - 2014-05-02 17:27 - 00000000 ____D () C:\temp
2015-03-28 10:09 - 2011-08-11 23:24 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation
2015-03-28 10:09 - 2011-08-11 23:22 - 00000000 ____D () C:\Program Files\NVIDIA Corporation
2015-03-28 09:10 - 2011-07-18 22:51 - 00000000 ____D () C:\Program Files (x86)\Windows Live
2015-03-26 11:35 - 2014-05-05 19:20 - 00000000 ____D () C:\Users\transit\AppData\Roaming\HpUpdate
2015-03-24 16:15 - 2009-07-14 07:09 - 00000000 ____D () C:\Windows\System32\Tasks\WPD
 
==================== Files in the root of some directories =======
 
2012-05-15 16:33 - 2012-05-15 16:33 - 0002116 _____ () C:\Program Files (x86)\INSTALL.LOG
2011-12-07 20:25 - 2011-12-07 20:25 - 0020816 _____ () C:\Users\transit\AppData\Roaming\UserTile.png
2013-12-19 14:17 - 2014-10-09 13:17 - 0000167 _____ () C:\Users\transit\AppData\Roaming\WB.CFG
2014-05-05 19:19 - 2014-05-05 19:19 - 0000057 _____ () C:\ProgramData\Ament.ini
2012-01-08 23:52 - 2012-01-08 23:52 - 0000000 _____ () C:\ProgramData\cmn_upld.log
2012-01-09 00:09 - 2012-01-09 00:09 - 0000252 _____ () C:\ProgramData\FastPics.log
2014-05-04 19:58 - 2014-05-05 19:15 - 0015205 _____ () C:\ProgramData\hpzinstall.log
2014-05-02 19:33 - 2014-05-02 19:33 - 0000256 _____ () C:\ProgramData\lxee.log
2012-01-09 00:13 - 2012-02-14 10:43 - 0046798 _____ () C:\ProgramData\lxeeJSW.log
2012-01-08 23:57 - 2014-05-02 19:33 - 0109051 _____ () C:\ProgramData\lxeescan.log
2012-01-08 23:52 - 2012-01-08 23:52 - 0000000 _____ () C:\ProgramData\LxWbGwLog.log
2012-01-08 23:52 - 2012-01-08 23:52 - 0000000 _____ () C:\ProgramData\UpdaterLog.txt
 
Some content of TEMP:
====================
C:\Users\transit\AppData\Local\Temp\HPPSdr.exe
C:\Users\transit\AppData\Local\Temp\pc-support-bar-setup.exe
C:\Users\transit\AppData\Local\Temp\pc-support-bar-setup_0.exe
C:\Users\transit\AppData\Local\Temp\pc-support-bar-setup_1.exe
C:\Users\transit\AppData\Local\Temp\Quarantine.exe
C:\Users\transit\AppData\Local\Temp\sqlite3.dll
 
 
==================== Bamital & volsnap Check =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2015-04-16 19:21
 
==================== End Of Log ============================
 
 
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 20-04-2015
Ran by transit at 2015-04-22 14:29:34
Running from C:\Users\transit\Desktop
Boot Mode: Normal
==========================================================
 
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Kaspersky Total Security (Disabled - Up to date) {179979E8-273D-D14E-0543-2861940E4886}
AS: Kaspersky Total Security (Disabled - Up to date) {ACF8980C-0107-DEC0-3FF3-1313EF89023B}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: Kaspersky Total Security (Disabled) {2FA2F8CD-6D52-D016-2E1C-81546ADD0FFD}
 
==================== Installed Programs ======================
 
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
64 Bit HP CIO Components Installer (Version: 7.2.8 - Hewlett-Packard) Hidden
ABBYY FineReader 6.0 Sprint (HKLM-x32\...\{ACF60000-22B9-4CE9-98D6-2CCF359BAC07}) (Version: 6.00.2146.41621 - ABBYY Software House)
Adobe Flash Player 17 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 17.0.0.169 - Adobe Systems Incorporated)
Adobe Flash Player 17 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 17.0.0.169 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.10) - Nederlands (HKLM-x32\...\{AC76BA86-7AD7-1043-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated)
Asmedia ASM104x USB 3.0 Host Controller Driver (HKLM-x32\...\{E4FB0B39-C991-4EE7-95DD-1A1A7857D33D}) (Version: 1.12.5.0 - Asmedia Technology)
Belgium e-ID middleware 4.0.5 (build 7363) (HKLM\...\{824563DE-75AD-4166-9DC0-B6482F207363}) (Version: 4.0.7363 - Belgian Government)
bpd_scan (x32 Version: 3.00.0000 - Hewlett-Packard) Hidden
CorelDRAW Essentials X5 - Common (x32 Version: 15.3 - Corel Corporation) Hidden
CorelDRAW Essentials X5 - Connect (x32 Version: 15.3 - Corel Corporation) Hidden
CorelDRAW Essentials X5 - Custom Data (x32 Version: 15.3 - Corel Corporation) Hidden
CorelDRAW Essentials X5 - DE (x32 Version: 15.3 - Corel Corporation) Hidden
CorelDRAW Essentials X5 - Draw (x32 Version: 15.3 - Corel Corporation) Hidden
CorelDRAW Essentials X5 - EN (x32 Version: 15.3 - Corel Corporation) Hidden
CorelDRAW Essentials X5 - ES (x32 Version: 15.3 - Corel Corporation) Hidden
CorelDRAW Essentials X5 - Extra Content (x32 Version: 15.0 - Corel Corporation) Hidden
CorelDRAW Essentials X5 - Filters (x32 Version: 15.3 - Corel Corporation) Hidden
CorelDRAW Essentials X5 - FR (x32 Version: 15.3 - Corel Corporation) Hidden
CorelDRAW Essentials X5 - IPM (x32 Version: 15.3 - Corel Corporation) Hidden
CorelDRAW Essentials X5 - IT (x32 Version: 15.3 - Corel Corporation) Hidden
CorelDRAW Essentials X5 - PHOTO-PAINT (x32 Version: 15.3 - Corel Corporation) Hidden
CorelDRAW Essentials X5 - Redist (x32 Version: 15.0 - Corel Corporation) Hidden
CorelDRAW Essentials X5 - Setup Files (x32 Version: 15.3 - Corel Corporation) Hidden
CorelDRAW Essentials X5 - WT (x32 Version: 15.3 -  Corel Corporation) Hidden
CorelDRAW Essentials X5 (HKLM-x32\...\_{EDBEBF07-F880-48FB-9AA5-0E8E71E02D83}) (Version: 15.2.0.686 - Corel Corporation)
CorelDRAW Essentials X5 (x32 Version: 15.3 - Corel Corporation) Hidden
CyberLink PowerRecover (HKLM-x32\...\InstallShield_{44B2A0AB-412E-4F8C-B058-D1E8AECCDFF5}) (Version: 5.5.4125 - CyberLink Corp.)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
DealPly (HKU\.DEFAULT\...\DealPly) (Version:  - ) <==== ATTENTION
DJ2540FWUpdateAlert (x32 Version: 1.00.0000 - HP) Hidden
Fotogalerie (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Fotogalerija (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Fotoğraf Galerisi (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Fotótár (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
FoxTab PDF Creator (HKU\S-1-5-21-3839137701-2974941544-2065132041-1002\...\FoxTab PDF Creator) (Version:  - ) <==== ATTENTION
FoxTab PDF Creator (HKU\S-1-5-21-3839137701-2974941544-2065132041-1007\...\FoxTab PDF Creator) (Version:  - ) <==== ATTENTION
Galeria de Fotografias do Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galería de fotos (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Galeria fotografii (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Galerie de photos (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Google Chrome (HKU\S-1-5-21-3839137701-2974941544-2065132041-1007\...\Google Chrome) (Version: 40.0.2214.115 - Google Inc.)
HP Deskjet 2540 series Basissoftware van het apparaat (HKLM\...\{A7F14256-6DC6-458A-A92D-B5EEF79429AB}) (Version: 32.2.188.47710 - Hewlett-Packard Co.)
HP Deskjet 2540 series Help (HKLM-x32\...\{50467ECF-F6A9-40EC-A649-67EB6FAD9894}) (Version: 30.0.0 - Hewlett Packard)
HP FWUpdateEDO2 (HKLM-x32\...\{415FA9AD-DA10-4ABE-97B6-5051D4795C90}) (Version: 1.2.0.0 - Hewlett-Packard)
HP Photo Creations (HKLM-x32\...\HP Photo Creations) (Version: 1.0.0.7702 - HP)
HP Update (HKLM-x32\...\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard)
HPDiagnosticAlert (x32 Version: 1.00.0001 - Microsoft) Hidden
HPDiagnosticCoreDll (HKLM-x32\...\{9262B08F-E183-4FED-A2BD-23FF1A84EB79}) (Version: 1.0.15.0 - Hewlett Packard)
Intel® Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1144 - Intel Corporation)
Java 8 Update 25 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218025F0}) (Version: 8.0.250 - Oracle Corporation)
Junk Mail filter update (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Kaspersky Total Security (HKLM-x32\...\InstallWIX_{8ED07EBD-22AD-415A-B71E-C1AD86862C2E}) (Version: 15.0.1.415 - Kaspersky Lab)
Kaspersky Total Security (x32 Version: 15.0.1.415 - Kaspersky Lab) Hidden
Macrium Reflect Free Edition (HKLM\...\MacriumReflect) (Version: 5.3 - Paramount Software (UK) Ltd.)
Macrium Reflect Free Edition (Version: 5.3.7299 - Paramount Software (UK) Ltd.) Hidden
Malwarebytes Anti-Malware versie 2.0.4.1028 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.4.1028 - Malwarebytes Corporation)
Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft .NET Framework 4.5.2 (Nederlands) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1043) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft Office 2010 (HKLM-x32\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office Klik-en-Klaar 2010 (HKLM-x32\...\Office14.Click2Run) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office Starter 2010 - Nederlands (HKLM-x32\...\{90140011-0066-0413-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-3839137701-2974941544-2065132041-1002\...\OneDriveSetup.exe) (Version: 17.0.4035.0328 - Microsoft Corporation)
Microsoft PowerPoint Viewer (HKLM-x32\...\{95140000-00AF-0413-0000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft ReportViewer 2010 Redistributable (HKLM-x32\...\{C19B3EB6-B54C-3204-A4DF-88432E0C79F7}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft SkyDrive (HKU\S-1-5-21-3839137701-2974941544-2065132041-1007\...\SkyDriveSetup.exe) (Version: 16.4.6013.0910 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Windows Debugging Symbols (HKLM-x32\...\{C6DB958A-50CC-481B-9ED8-3BAD236F7B49}) (Version: 7601 - Microsoft)
Movie Maker (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MyDriveConnect 3.3.0.1812 (HKLM-x32\...\MyDriveConnect) (Version: 3.3.0.1812 - TomTom)
NVIDIA 3D Vision stuurprogramma 347.52 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 347.52 - NVIDIA Corporation)
NVIDIA Grafisch stuurprogramma 347.52 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 347.52 - NVIDIA Corporation)
NVIDIA HD Audio-stuurprogramma 1.3.33.0 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.33.0 - NVIDIA Corporation)
NVIDIA PhysX System Software 9.11.0621 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.11.0621 - NVIDIA Corporation)
NVIDIA Update 10.4.0 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 10.4.0 - NVIDIA Corporation)
PlayReady PC Runtime amd64 (HKLM\...\{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}) (Version: 1.3.0 - Microsoft Corporation)
Poczta usługi Windows Live (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Podstawowe programy Windows Live (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Pošta Windows Live (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Productverbeteringsonderzoek voor HP Deskjet 2540 series (HKLM\...\{08FB88A2-3FB6-4E82-AD55-393EBAD0E967}) (Version: 32.2.188.47710 - Hewlett-Packard Co.)
Raccolta foto (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 6.3.273.37 - Realtek Semiconductor Corp.)
SAMSUNG Intelli-studio (HKLM-x32\...\Intelli-studio) (Version:  - )
Spelling Dictionaries Support For Adobe Reader X (HKLM-x32\...\{AC76BA86-7AD7-5464-3428-A00000000004}) (Version: 10.0.0 - Adobe Systems Incorporated)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
Stuurprogrammapakket voor Windows - Fedict SmartCard  (10/04/2011 4.0.0.5) (HKLM\...\3FE3642036A0F4AEC17772437CE14BB1E67006AA) (Version: 10/04/2011 4.0.0.5 - Fedict)
swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
TeamViewer 10 (HKLM-x32\...\TeamViewer) (Version: 10.0.40798 - TeamViewer)
Visual Studio C++ 10.0 Runtime (HKLM-x32\...\{4412F224-3849-4461-A3E9-DEEF8D252790}) (Version: 10.0.0 - TomTom International B.V.)
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3505.0912 - Microsoft Corporation)
Συλλογή φωτογραφιών (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
 
==================== Custom CLSID (selected items): ==========================
 
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
 
CustomCLSID: HKU\S-1-5-21-3839137701-2974941544-2065132041-1002_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\transit\AppData\Roaming\Dropbox\bin\Dropbox.exe /autoplay No File
CustomCLSID: HKU\S-1-5-21-3839137701-2974941544-2065132041-1002_Classes\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}\InprocServer32 -> C:\Users\transit\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3839137701-2974941544-2065132041-1002_Classes\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}\InprocServer32 -> C:\Users\transit\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3839137701-2974941544-2065132041-1002_Classes\CLSID\{CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B}\InprocServer32 -> C:\Users\transit\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3839137701-2974941544-2065132041-1002_Classes\CLSID\{D0336C0B-7919-4C04-8CCE-2EBAE2ECE8C9}\InprocServer32 -> C:\Users\transit\AppData\Local\Google\Update\1.3.25.11\psuser_64.dll No File
CustomCLSID: HKU\S-1-5-21-3839137701-2974941544-2065132041-1002_Classes\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}\InprocServer32 -> C:\Users\transit\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3839137701-2974941544-2065132041-1002_Classes\CLSID\{F8071786-1FD0-4A66-81A1-3CBE29274458}\InprocServer32 -> C:\Users\transit\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\FileSyncApi64.dll (Microsoft Corporation)
 
==================== Restore Points  =========================
 
17-04-2015 14:59:26 Removed Adobe Reader XI (11.0.10) - Nederlands.
17-04-2015 15:01:06 Removed Adobe Reader XI (11.0.10) - Nederlands.
17-04-2015 15:30:35 Installatieprogramma voor Windows-modules
17-04-2015 16:27:26 Installed SLOW-PCfighter.
17-04-2015 16:30:32 Fighters Backup
17-04-2015 17:18:39 exploter
18-04-2015 10:25:51 Installatieprogramma voor Windows-modules
18-04-2015 11:02:50 Herstelbewerking
18-04-2015 11:22:43 Installatieprogramma voor Windows-modules
18-04-2015 12:33:46 Removed Java 7 Update 76 (64-bit)
18-04-2015 12:36:53 Windows Update
20-04-2015 00:17:31 Windows Update
22-04-2015 12:05:39 Installed Macrium Reflect Free Edition
 
==================== Hosts content: ==========================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____N C:\Windows\system32\Drivers\etc\hosts
 
==================== Scheduled Tasks (whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
 
Task: {004A59DD-0CD0-48FE-AD8E-50037D0B5211} - System32\Tasks\{81C5B759-FF0B-46CE-84A8-89D669780F07} => C:\POLAX\Polax.exe [2001-12-27] ()
Task: {07511566-5EFA-44D8-B54A-96A839FB4940} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-04-17] (Adobe Systems Incorporated)
Task: {08AD675C-78E2-4C28-A195-03D5E3092C32} - System32\Tasks\{ED19E1C3-8C8E-4068-ABBB-3F14C0916900} => C:\digosoft\digo.exe [2012-05-21] ()
Task: {0EF33F4E-247B-4A59-8ECC-AF1CD752B9A3} - System32\Tasks\Microsoft\Windows\Media Center\StartRecording => C:\Windows\ehome\ehrec.exe
Task: {1151529D-38AE-46EC-A02B-1363A1A8D351} - System32\Tasks\{97043C5F-54E3-4B29-90E1-55167C3C6216} => C:\POLAX\Polax.exe [2001-12-27] ()
Task: {126D4E91-3891-4847-BAC8-47720DEE87F7} - System32\Tasks\{A80688EE-9AEB-414D-AC41-9BCEF6B0A689} => C:\Users\transit\Desktop\POLAX\polax\Polax.exe
Task: {1CCC9F0E-4523-4FF0-8190-DCABF2C96743} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxcontent => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-25] (Microsoft Corporation)
Task: {1E8A395B-EA24-4F17-A9B9-5DCBC117B411} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfig => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-25] (Microsoft Corporation)
Task: {1FDB7AF3-6786-4302-8BCD-5E78A5EB1322} - System32\Tasks\{87DCE43B-5D3C-4981-81B8-CEB1BB2F98AE} => pcalua.exe -a C:\Users\transit\Desktop\windows-live-messenger.exe -d C:\Users\transit\Desktop
Task: {2915B59A-96C8-413C-A63A-7B77B25EEE95} - System32\Tasks\{E6B6C12B-5E62-46A2-8B7B-01F892CD7BA3} => C:\POLAX\Polax.exe [2001-12-27] ()
Task: {2A21520C-26AF-4116-830A-5CF06BBFDF92} - System32\Tasks\{0B90DE2A-AFE4-4574-963D-5387DCAACE9E} => C:\Users\transit\AppData\Local\iLivid\iLivid.exe
Task: {2D5904E5-E1C4-4A0F-AACA-053FA1F77000} - System32\Tasks\{BECA6EBB-F09F-40F9-999B-6BEACA975A2F} => C:\Users\transit\Desktop\POLAX\polax\Polax.exe
Task: {2F30E610-459D-4D12-BD13-0ABB00195095} - System32\Tasks\{476E3058-9339-41F6-8093-F6DAEF21E489} => C:\POLAX\Polax.exe [2001-12-27] ()
Task: {3F6AF2EE-DC50-42CD-B263-93F949D28BA8} - System32\Tasks\{27219742-9C26-4399-988F-BEC36EBA342D} => C:\POLAX\Polax.exe [2001-12-27] ()
Task: {451ED1C6-E3C9-493D-9153-E7A4C10FBB45} - System32\Tasks\{A524AE01-64F6-4CF1-B185-84C161D68BE2} => C:\digosoft\digo.exe [2012-05-21] ()
Task: {5C676637-9DF8-4509-90A0-6E757725816D} - System32\Tasks\{50C37B14-2259-4BCD-B52E-783030EF8F71} => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 15.0.1\avpui.exe [2014-08-30] (Kaspersky Lab ZAO)
Task: {6BAF0B69-9610-4F68-9B26-CEB692D234C0} - System32\Tasks\{D24854C4-754C-4629-BD4B-4E64A4182239} => Chrome.exe 
Task: {6CF08229-C3E1-464D-9312-FF1BF08D0168} - System32\Tasks\{D01BDC77-7FD7-4F19-906D-BEBBA2C8913B} => C:\POLAX\Polax.exe [2001-12-27] ()
Task: {6EE7B04C-350B-4608-BC4E-A60B80BC1693} - System32\Tasks\{6D87EEA5-1509-4B98-A666-FA989574B84C} => C:\Users\transit\AppData\Local\iLivid\iLivid.exe
Task: {7226CC10-B3A4-459C-92A5-8C0B954CF9AC} - System32\Tasks\{1E44404E-8B72-452D-8498-10DBE60EBF0C} => C:\digosoft\digo.exe [2012-05-21] ()
Task: {76D3377E-7B04-4FC4-8EAD-045851B5482F} - System32\Tasks\{C7ADE54A-98C4-4561-B488-F4AECB96FC7D} => C:\Users\transit\AppData\Local\iLivid\iLivid.exe
Task: {790CA437-1925-47B9-BBF9-AF4335C11EB7} - System32\Tasks\{A02B6ABC-C50D-4680-8DE7-FE0BDDBE7928} => C:\POLAX\Polax.exe [2001-12-27] ()
Task: {7A4E990B-41D0-4B85-ACC0-A704048BF869} - System32\Tasks\{3A580740-5F12-4B2B-8145-B4F2CE15A9E3} => pcalua.exe -a "C:\Users\transit\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TYUPHMOW\pure9.1.0.124nl.exe" -d C:\Users\transit\Desktop
Task: {808A239B-CB70-4D90-AB08-AB860F7264F8} - System32\Tasks\{F00A7E00-4D5B-4D15-BFF3-9B4AAB175A3D} => C:\POLAX\Polax.exe [2001-12-27] ()
Task: {86F8AE53-DF9F-4C53-96D3-179E0C50B287} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated)
Task: {9F41D46B-DAA2-4CDC-A46D-623B99643A20} - System32\Tasks\HPCustParticipation HP Deskjet 2540 series => C:\Program Files\HP\HP Deskjet 2540 series\Bin\HPCustPartic.exe [2014-03-06] (Hewlett-Packard Co.)
Task: {A6CC5361-E4B6-4588-9DFF-9052C8B45294} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc
Task: {A939B57B-4C43-48E4-8DAE-6DEFE4B00EAD} - System32\Tasks\{2B42464D-0E58-47A4-BDC6-382E841EBACE} => C:\digosoft\digo.exe [2012-05-21] ()
Task: {AA04715B-CD3D-4F3C-B269-FEE890575CDB} - System32\Tasks\Microsoft\Windows\Setup\gwx\runappraiser => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-25] (Microsoft Corporation)
Task: {AB9B3EB5-4971-4F7A-9C0E-19135FFA8618} - System32\Tasks\{BBE38C98-3012-450E-8C92-66E8326EBD74} => C:\Users\transit\AppData\Local\iLivid\iLivid.exe
Task: {AF2A9AB9-97D3-4EA9-B3AE-DA5FD740A58B} - System32\Tasks\{E3B9F4CA-63AA-40C4-812A-881CB1B4DF80} => Chrome.exe 
Task: {B322BBB8-3653-4A4E-985A-4D968C505D33} - System32\Tasks\{9514EDF2-1A91-4E9F-A395-CB65BC391C6E} => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 15.0.1\avpui.exe [2014-08-30] (Kaspersky Lab ZAO)
Task: {B4B832A9-9CF0-4976-AE45-B9914FBF119F} - System32\Tasks\{49A2827B-1E9E-4142-91E3-550C21B01A4D} => C:\POLAX\Polax.exe [2001-12-27] ()
Task: {C2F93822-6370-4737-9FED-70C4EDDC985B} - System32\Tasks\{0E904838-A6D6-49E6-94C9-9148A50BB3EE} => C:\POLAX\Polax.exe [2001-12-27] ()
Task: {C536211A-2615-4B22-95BC-9D101DC8BE33} - System32\Tasks\{F6EA5C37-FEF5-467C-ABDE-771B8D998DCB} => C:\POLAX\Polax.exe [2001-12-27] ()
Task: {CA1E189F-5F29-4FC4-8EEA-DEF423E7D23B} - System32\Tasks\{17EFE308-059E-46D6-8B1C-70226613F8D6} => C:\POLAX\Polax.exe [2001-12-27] ()
Task: {D2093C2A-9D5E-43AF-9CEE-8CB05D511518} - System32\Tasks\{B6273C86-F98D-47D9-90F5-220E9D9E406A} => Chrome.exe 
Task: {DCF6A5C4-1955-415D-9FCB-28D6E13E67E7} - System32\Tasks\{7D4AD985-F398-41DA-A952-F9C1266F2381} => C:\POLAX\Polax.exe [2001-12-27] ()
Task: {DDF08966-2A52-4923-8C81-EF4A0BEAE5FA} - System32\Tasks\{A1E12A37-0C30-495B-8528-02D0F981C87C} => C:\POLAX\Polax.exe [2001-12-27] ()
Task: {E030BAE9-671C-4B06-B532-01D38F6263C8} - System32\Tasks\{687B5129-7122-4341-80E4-56FEE542F839} => C:\POLAX\Polax.exe [2001-12-27] ()
Task: {E212C79A-5141-40D2-AEB5-18D833D0336C} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\Windows\ehome\mcupdate.exe
Task: {F6EB4723-55C9-44DE-9544-7C020D42DA2F} - System32\Tasks\{C1C9685A-AA10-481D-A3F6-DD2993E52B97} => pcalua.exe -a "C:\Program Files (x86)\WinZipper\eUninstall.exe" <==== ATTENTION
Task: {FAEAA3EA-2394-4704-9FA8-E0E353FA964C} - System32\Tasks\Microsoft\Windows\Setup\gwx\launchtrayprocess => C:\Windows\system32\GWX\GWX.exe [2015-03-25] (Microsoft Corporation)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
 
==================== Loaded Modules (whitelisted) ==============
 
2014-05-05 20:56 - 2015-02-05 21:07 - 00117576 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2012-01-09 00:18 - 2009-05-18 09:40 - 00053760 _____ () C:\Windows\System32\LXEEPMON.DLL
2012-01-09 00:18 - 2009-01-13 15:15 - 04485120 _____ () C:\Windows\System32\LXEEOEM.DLL
2012-01-08 23:58 - 2009-11-04 15:17 - 00189440 _____ () C:\Windows\system32\spool\PRTPROCS\x64\lxeedrpp.dll
 
==================== Alternate Data Streams (whitelisted) =========
 
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
 
 
==================== Safe Mode (whitelisted) ===================
 
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
 
==================== EXE Association (whitelisted) ===============
 
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, the associated entry will be removed from the registry.)
 
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-3839137701-2974941544-2065132041-1002\Control Panel\Desktop\\Wallpaper -> C:\Users\transit\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
HKU\S-1-5-21-3839137701-2974941544-2065132041-1007\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\MEDION\Wallpaper.jpg
DNS Servers: 192.168.1.1
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
(Currently there is no automatic fix for this section.)
 
MSCONFIG\Services: AdobeARMservice => 2
MSCONFIG\Services: AdobeFlashPlayerUpdateSvc => 3
MSCONFIG\Services: ASO3DiskOptimizer => 2
MSCONFIG\Services: BotkindSyncService => 2
MSCONFIG\Services: DatamngrCoordinator => 2
MSCONFIG\Services: IePluginService => 2
MSCONFIG\Services: PSI_SVC_2 => 2
MSCONFIG\Services: ReimageRealTimeProtector => 2
MSCONFIG\Services: Steam Client Service => 3
MSCONFIG\Services: Wpm => 2
MSCONFIG\startupfolder: C:^Users^transit^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^SuperOptimizer.lnk => C:\Windows\pss\SuperOptimizer.lnk.Startup
MSCONFIG\startupreg: Babylon Client => C:\Program Files (x86)\Babylon\Babylon-Pro\Babylon.exe -AutoStart
MSCONFIG\startupreg: CommonToolkitTray => C:\Program Files (x86)\Fighters\Tray\FightersTray.exe
MSCONFIG\startupreg: Driver Whiz => C:\Program Files (x86)\Driver Whiz\Driver Whiz\DriverWhiz.exe /applicationMode:systemTray /showWelcome:false
MSCONFIG\startupreg: HP Software Update => C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
MSCONFIG\startupreg: iLivid => "C:\Users\transit\AppData\Local\iLivid\iLivid.exe" -autorun
MSCONFIG\startupreg: MedionReminder => C:\Program Files (x86)\CyberLink\PowerRecover\Reminder.exe
MSCONFIG\startupreg: MyDriveConnect.exe => "C:\Program Files (x86)\MyDrive Connect\MyDriveConnect.exe"
MSCONFIG\startupreg: Yontoo Desktop => "C:\Users\transit\AppData\Roaming\Yontoo\YontooDesktop.exe"
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-3839137701-2974941544-2065132041-500 - Administrator - Disabled)
Gast (S-1-5-21-3839137701-2974941544-2065132041-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-3839137701-2974941544-2065132041-1010 - Limited - Enabled)
transit (S-1-5-21-3839137701-2974941544-2065132041-1002 - Administrator - Enabled) => C:\Users\transit
UpdatusUser (S-1-5-21-3839137701-2974941544-2065132041-1007 - Limited - Enabled) => C:\Users\UpdatusUser
 
==================== Faulty Device Manager Devices =============
 
Name: Realtek RTL8191SU Wireless LAN 802.11n USB 2.0 Network Adapter
Description: Realtek RTL8191SU Wireless LAN 802.11n USB 2.0 Network Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Realtek Semiconductor Corp.
Service: RTL8192su
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (04/22/2015 11:54:14 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Het programma iexplore.exe, versie 9.0.8112.16636 reageert niet meer op Windows en is afgesloten. Als u wilt zien of er meer informatie over het probleem beschikbaar is, raadpleegt u de probleemgeschiedenis in het onderdeel Onderhoudscentrum in het Configuratiescherm.
 
Proces-id: 904
 
Starttijd: 01d07ce225b17383
 
Eindtijd: 16
 
Toepassingspad: C:\Program Files\Internet Explorer\iexplore.exe
 
Rapport-id:
 
Error: (04/19/2015 01:12:54 PM) (Source: CVHSVC) (EventID: 100) (User: )
Description: Alleen informatie.
(Patch task for {90140011-0066-0413-0000-0000000FF1CE}): DownloadLatest Failed:
 
Error: (04/18/2015 03:18:18 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Naam van toepassing met fout: digo.exe, versie: 0.0.0.0, tijdstempel: 0x41bdebae
Naam van module met fout: VFP9r.dll, versie: 9.0.0.7423, tijdstempel: 0x49a31c32
Uitzonderingscode: 0xc0000005
Foutoffset: 0x00029842
Id van proces met fout: 0xea8
Starttijd van toepassing met fout: 0xdigo.exe0
Pad naar toepassing met fout: digo.exe1
Pad naar module met fout: digo.exe2
Rapport-id: digo.exe3
 
Error: (04/18/2015 03:01:19 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Het programma iexplore.exe, versie 9.0.8112.16476 reageert niet meer op Windows en is afgesloten. Als u wilt zien of er meer informatie over het probleem beschikbaar is, raadpleegt u de probleemgeschiedenis in het onderdeel Onderhoudscentrum in het Configuratiescherm.
 
Proces-id: 1354
 
Starttijd: 01d079d7ae2e5431
 
Eindtijd: 16
 
Toepassingspad: C:\Program Files (x86)\Internet Explorer\iexplore.exe
 
Rapport-id:
 
Error: (04/18/2015 00:27:37 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Het programma iexplore.exe, versie 9.0.8112.16476 reageert niet meer op Windows en is afgesloten. Als u wilt zien of er meer informatie over het probleem beschikbaar is, raadpleegt u de probleemgeschiedenis in het onderdeel Onderhoudscentrum in het Configuratiescherm.
 
Proces-id: 11bc
 
Starttijd: 01d079c238ad024e
 
Eindtijd: 31
 
Toepassingspad: C:\Program Files (x86)\Internet Explorer\iexplore.exe
 
Rapport-id:
 
Error: (04/18/2015 00:27:07 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Het programma iexplore.exe, versie 9.0.8112.16476 reageert niet meer op Windows en is afgesloten. Als u wilt zien of er meer informatie over het probleem beschikbaar is, raadpleegt u de probleemgeschiedenis in het onderdeel Onderhoudscentrum in het Configuratiescherm.
 
Proces-id: de8
 
Starttijd: 01d079c22561baf6
 
Eindtijd: 15
 
Toepassingspad: C:\Program Files (x86)\Internet Explorer\iexplore.exe
 
Rapport-id:
 
Error: (04/18/2015 00:21:46 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Het programma iexplore.exe, versie 9.0.8112.16476 reageert niet meer op Windows en is afgesloten. Als u wilt zien of er meer informatie over het probleem beschikbaar is, raadpleegt u de probleemgeschiedenis in het onderdeel Onderhoudscentrum in het Configuratiescherm.
 
Proces-id: 1394
 
Starttijd: 01d079beac96024f
 
Eindtijd: 50
 
Toepassingspad: C:\Program Files (x86)\Internet Explorer\iexplore.exe
 
Rapport-id:
 
Error: (04/18/2015 11:33:27 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Het programma IEXPLORE.EXE, versie 10.0.9200.16736 reageert niet meer op Windows en is afgesloten. Als u wilt zien of er meer informatie over het probleem beschikbaar is, raadpleegt u de probleemgeschiedenis in het onderdeel Onderhoudscentrum in het Configuratiescherm.
 
Proces-id: a30
 
Starttijd: 01d079ba24c91fc4
 
Eindtijd: 38
 
Toepassingspad: C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
 
Rapport-id:
 
Error: (04/18/2015 11:21:37 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Het programma IEXPLORE.EXE, versie 10.0.9200.16736 reageert niet meer op Windows en is afgesloten. Als u wilt zien of er meer informatie over het probleem beschikbaar is, raadpleegt u de probleemgeschiedenis in het onderdeel Onderhoudscentrum in het Configuratiescherm.
 
Proces-id: 13cc
 
Starttijd: 01d079b8dfb0a80f
 
Eindtijd: 22
 
Toepassingspad: C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
 
Rapport-id:
 
Error: (04/18/2015 11:13:11 AM) (Source: System Restore) (EventID: 8210) (User: )
Description: Er is tijdens Systeemherstel een onbekende fout opgetreden: (Installatieprogramma voor Windows-modules). Aanvullende gegevens: 0x8000ffff.
 
 
System errors:
=============
Error: (04/22/2015 02:18:40 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: De Windows Search-service kan vanwege de volgende fout niet worden gestart: 
%%1069
 
Error: (04/22/2015 02:18:40 PM) (Source: Service Control Manager) (EventID: 7038) (User: )
Description: De WSearch-service kan niet als NT AUTHORITY\SYSTEM met het huidig ingestelde wachtwoord worden aangemeld vanwege de volgende fout: 
%%50
 
Gebruik de module Services in de Microsoft Management Console (MMC) om te controleren of de service juist is geconfigureerd.
 
Error: (04/22/2015 02:18:16 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: De Windows Search-service is onverwacht gestopt. Dit is 2 keer gebeurd. De volgende herstelbewerking zal over 30000 milliseconden worden uitgevoerd: Service opnieuw starten.
 
Error: (04/22/2015 02:18:12 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: De Application Virtualization Client-service is onverwacht beëindigd. Dit is nu 1 keer gebeurd.
 
Error: (04/22/2015 02:18:10 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: De Software Protection-service is onverwacht gestopt. Dit is 1 keer gebeurd. De volgende herstelbewerking zal over 120000 milliseconden worden uitgevoerd: Service opnieuw starten.
 
Error: (04/22/2015 02:18:10 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: De Intel® Management and Security Application User Notification Service-service is onverwacht beëindigd. Dit is nu 1 keer gebeurd.
 
Error: (04/22/2015 02:18:10 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: De NVIDIA Update Service Daemon-service is onverwacht beëindigd. Dit is nu 1 keer gebeurd.
 
Error: (04/22/2015 02:18:10 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: De Windows Search-service is onverwacht gestopt. Dit is 1 keer gebeurd. De volgende herstelbewerking zal over 30000 milliseconden worden uitgevoerd: Service opnieuw starten.
 
Error: (04/22/2015 02:18:10 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: De Client Virtualization Handler-service is onverwacht beëindigd. Dit is nu 1 keer gebeurd.
 
Error: (04/22/2015 02:18:10 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: De Windows Live ID Sign-in Assistant-service is onverwacht gestopt. Dit is 1 keer gebeurd. De volgende herstelbewerking zal over 10000 milliseconden worden uitgevoerd: Service opnieuw starten.
 
 
Microsoft Office Sessions:
=========================
Error: (04/22/2015 11:54:14 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: iexplore.exe9.0.8112.1663690401d07ce225b1738316C:\Program Files\Internet Explorer\iexplore.exe
 
Error: (04/19/2015 01:12:54 PM) (Source: CVHSVC) (EventID: 100) (User: )
Description: (Patch task for {90140011-0066-0413-0000-0000000FF1CE}): DownloadLatest Failed:
 
Error: (04/18/2015 03:18:18 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: digo.exe0.0.0.041bdebaeVFP9r.dll9.0.0.742349a31c32c000000500029842ea801d079d93c1adf63C:\digosoft\digo.exeC:\Program Files (x86)\Common Files\microsoft shared\VFP\VFP9r.dll6076139b-e5cd-11e4-a197-8c89a57d6dd6
 
Error: (04/18/2015 03:01:19 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: iexplore.exe9.0.8112.16476135401d079d7ae2e543116C:\Program Files (x86)\Internet Explorer\iexplore.exe
 
Error: (04/18/2015 00:27:37 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: iexplore.exe9.0.8112.1647611bc01d079c238ad024e31C:\Program Files (x86)\Internet Explorer\iexplore.exe
 
Error: (04/18/2015 00:27:07 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: iexplore.exe9.0.8112.16476de801d079c22561baf615C:\Program Files (x86)\Internet Explorer\iexplore.exe
 
Error: (04/18/2015 00:21:46 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: iexplore.exe9.0.8112.16476139401d079beac96024f50C:\Program Files (x86)\Internet Explorer\iexplore.exe
 
Error: (04/18/2015 11:33:27 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: IEXPLORE.EXE10.0.9200.16736a3001d079ba24c91fc438C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
 
Error: (04/18/2015 11:21:37 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: IEXPLORE.EXE10.0.9200.1673613cc01d079b8dfb0a80f22C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
 
Error: (04/18/2015 11:13:11 AM) (Source: System Restore) (EventID: 8210) (User: )
Description: Installatieprogramma voor Windows-modules0x8000ffff
 
 
CodeIntegrity Errors:
===================================
  Date: 2012-04-26 10:59:24.325
  Description: De integriteit van de kopie van het bestand \Device\HarddiskVolume2\Users\transit\AppData\Local\Temp\OnlineScanner\Anti-Virus\fsgk.sys kan niet worden geverifieerd omdat de bestands-hash niet is gevonden op het systeem. Tijdens een recente hardware- of softwarewijziging is mogelijk een bestand geïnstalleerd dat onjuist ondertekend of beschadigd is, of dat mogelijk kwaadwillende software van een onbekende bron is.
 
  Date: 2012-04-26 10:59:24.315
  Description: De integriteit van de kopie van het bestand \Device\HarddiskVolume2\Users\transit\AppData\Local\Temp\OnlineScanner\Anti-Virus\fsgk.sys kan niet worden geverifieerd omdat de bestands-hash niet is gevonden op het systeem. Tijdens een recente hardware- of softwarewijziging is mogelijk een bestand geïnstalleerd dat onjuist ondertekend of beschadigd is, of dat mogelijk kwaadwillende software van een onbekende bron is.
 
 
==================== Memory info =========================== 
 
Processor: Intel® Core™ i5-2320 CPU @ 3.00GHz
Percentage of memory in use: 28%
Total physical RAM: 4077.64 MB
Available physical RAM: 2934.38 MB
Total Pagefile: 8153.47 MB
Available Pagefile: 7046.21 MB
Total Virtual: 8192 MB
Available Virtual: 8191.84 MB
 
==================== Drives ================================
 
Drive c: (Boot) (Fixed) (Total:1811.92 GB) (Free:1725.8 GB) NTFS
Drive d: (Recover) (Fixed) (Total:50 GB) (Free:45.42 GB) NTFS
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (Size: 1863 GB) (Disk ID: 2BD2C32A)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=1811.9 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=50 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=1 GB) - (Type=12)
 
==================== End Of Log ============================

  • 0

#8
BrianDrab

BrianDrab

    Trusted Helper

  • Malware Removal
  • 3,591 posts

About google chrome, I don't see it on the system, only internet explorer.

 

You will see it in Add/Remove programs.

Click your Start button...Control Panel and then Add/Remove programs. If you don't use it then just uninstall it. Instructions for uninstalling are here.


  • 0

#9
BrianDrab

BrianDrab

    Trusted Helper

  • Malware Removal
  • 3,591 posts

After removing Chrome, please do the following.

 

Step#1 - Uninstalls
Please uninstall the following programs one at a time. Instructions for doing so are here.
If any of the programs give you an error during the uninstall, notate it and move on to the next one. Just let me know which ones had issues. If you are asked to reboot, answer No until all the programs have been uninstalled and then you can reboot. All of these programs are either outdated, malware/adware, have a bad reputation or are not recommended. If you absolutely must have one of them I suggest that you wait until you are declared clean before reinstalling.
 

DealPly
FoxTab PDF Creator
Malwarebytes Anti-Malware versie 2.0.4.1028

 

Step#2 - VirusTotal Scan

Do you know what the following two programs are?

C:\POLAX\Polax.exe
C:\digosoft\digo.exe

 

If you do, simply let me know. If you don't please follow the instructions below for each file.

VirusTotal, a subsidiary of Google, provides a service that allows us to scan this file using many antiviurs engines to see if any are currently detecting this as a threat. Please follow the instructions below.
1. To use VirusTotal, please go here.
VirusTotal.JPG
2. Copy the following line to your clipboard. To do so, select the text with your mouse and then right-click your mouse and select Copy.
C:\POLAX\Polax.exe
3. Click the Choose File button and paste in the contents of the clipboard into the "File name:" field.
4. Click the Scan It! button. VirusTotal will check this file against 50 different antivirus softwares to see if any detect this as a threat.
Note: If you receive a message stating that the File was already analysed, please click Reanalyse.
5. Once the scan finishes, please copy and paste the VirusTotal URL in your next reply. To do this, click your mouse at the very top of your browser window in the URL that starts with https:// and the entire line will turn blue. Right click your mouse and select copy. Paste this in your next reply.

 

Repeat the steps for C:\digosoft\digo.exe

 

 

Step#3 - Windows Sidebar
I see that you use the Windows Sidebar with Gadgets. Microsoft deems these as a security vulnerability and recommends that they are disabled. Unless you have good reason not to, please download and install the Microsoft Fix-It from here. Note: Please ensure you reboot when prompted. If you don't and continue this could leave your machine in an unstable state.

 

 

Step#4 - FRST Fix
NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system
1. Download attached file and save it to the Desktop. Attached File  fixlist.txt   3.32KB   266 downloads
Note. It's important that both files, FRST64 and fixlist.txt are in the same location or the fix will not work (in this case...the desktop).
2. Run FRST64 by Right-Clicking on the file and choosing Run as administrator.
3. Press the Fix button just once and wait. If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
4. When finished FRST64 will generate a log on the Desktop (Fixlog.txt). Please post the contents of it in your reply.

 

Step#5 - Rootkit Scan
1. Download aswMBR to your desktop.
2. Right-click on aswMBR.exe and select Run as administrator to run it.
3. If you get a question about Virtualization Technology, answer Yes.
4. If you see this question: Would you like to download latest Avast! virus definitions?" say "Yes".
5. Click the "Scan" button to start scan.
6. On completion of the scan click "Save log", save it to your desktop and post in your next reply.
NOTE. aswMBR will create MBR.dat file on your desktop. This is a copy of your MBR. Do NOT delete it.

 

 

Items for your next post

1. VirusTotal results

2. FRST Fix log

3. Rootkit Scan log

 


  • 0

#10
HaraMo

HaraMo

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 456 posts

 


About google chrome, I don't see it on the system, only internet explorer.

 

You will see it in Add/Remove programs.

Click your Start button...Control Panel and then Add/Remove programs. If you don't use it then just uninstall it. Instructions for uninstalling are here.

 

 

 


About google chrome, I don't see it on the system, only internet explorer.

 

You will see it in Add/Remove programs.

Click your Start button...Control Panel and then Add/Remove programs. If you don't use it then just uninstall it. Instructions for uninstalling are here.

 

No, already checked add/remove programs, checked it again, no google chrome or any google software


Edited by HaraMo, 22 April 2015 - 09:05 AM.

  • 0

Advertisements


#11
BrianDrab

BrianDrab

    Trusted Helper

  • Malware Removal
  • 3,591 posts

OK, we'll handle the removal manually later. Go ahead and do the rest of the instructions. Thanks.


  • 0

#12
HaraMo

HaraMo

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 456 posts

digosoft and plax are custom made program used for car business.


  • 0

#13
BrianDrab

BrianDrab

    Trusted Helper

  • Malware Removal
  • 3,591 posts

digosoft and plax are custom made program used for car business.

 

Understood. Thanks. Skip the VirustTotal step.


  • 0

#14
HaraMo

HaraMo

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 456 posts

FoxTab PDF Creator: an error occured while removing foxtab pdf creator. it is possible it was removed earler.

I clicked yes so the programm will be removed from the program list.

 

malwarebytes anti-malwarae:

 

file c:\ program files(x86)\malwarebytes .... \unins000.dat doesn't exist, cannot remove the program.

 

 

 

dealply not in the program list.

 

windows side bar not active on dekstop but I will run the fix it


Edited by HaraMo, 22 April 2015 - 10:09 AM.

  • 0

#15
BrianDrab

BrianDrab

    Trusted Helper

  • Malware Removal
  • 3,591 posts

FoxTab PDF Creator: an error occured while removing foxtab pdf creator. it is possible it was removed earler.

I clicked yes so the programm will be removed from the program list.

 

:thumbsup:


  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP