startpage changed, commercials on screen

haramo

Well-known member
Joined
Dec 18, 2014
Posts
147
Please help with this.

logs:

Scanresultaten van Farbar Recovery Scan Tool (FRST) (x64) Versie:01-12-2015
Gestart door bryan77 (Beheerder) op BRYAN77-PC (01-12-2015 21:47:25)
Gestart vanaf C:\Users\bryan77\Desktop
Geladen Profielen: bryan77 (Beschikbare Profielen: bryan77 & Bryan & Barbara)
Platform: Windows 7 Home Premium Service Pack 1 (X64) Taal: Nederlands (Nederland)
Internet Explorer Versie 11 (Standaardbrowser: Chrome)
Boot Modus: Normal
Handleiding voor Farbar Recovery Scan Tool: FRST Tutorial - How to use Farbar Recovery Scan Tool - Malware Removal Guides and Tutorials


==================== Processen (gefilterd) =================


(Als een item is opgenomen in de fixlist, het proces zal worden gesloten. Het bestand zal niet worden verplaatst.)


(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
(ASUS) C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnSrv.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
() C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Microsoft Corporation) C:\Windows\System32\wisptis.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Desktop.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
(ASUS) C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnWMI.exe
(Microsoft Corporation) C:\Windows\System32\wisptis.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
(ASUS) C:\Program Files\ASUS\P4G\BatteryLife.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\FaceLogon\sensorsrv.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ATKOSD.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\WDC.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Virtual Touch\QuickGesture\x64\QuickGesture64.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Virtual Touch\QuickGesture\x86\QuickGesture.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_w32.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_x64.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(Alcor Micro Corp.) C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe
(ASUS) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
(Nico Mak Computing) C:\Program Files\File Association Helper\FAHWindow.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(VIA) C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
(ASUSTeK) C:\Windows\SysWOW64\ACEngSvr.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgui.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDGesture.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\ink\InputPersonalization.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe




==================== Register (gefilterd) ===========================


(Als een item is opgenomen in de fixlist, het registry item zal worden teruggezet naar de standaardwaarden of verwijderd. Het bestand zal niet worden verplaatst.)


HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2661672 2012-05-14] (ELAN Microelectronics Corp.)
HKLM\...\Run: [AmIcoSinglun64] => C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe [361984 2011-03-21] (Alcor Micro Corp.)
HKLM\...\Run: [ACMON] => C:\Program Files (x86)\ASUS\Splendid\ACMON.exe [90792 2012-05-08] (ASUS)
HKLM\...\Run: [FAHConsole] => C:\Program Files\File Association Helper\FAHConsole.exe [729272 2014-01-28] (Nico Mak Computing)
HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291608 2012-02-07] (Intel Corporation)
HKLM-x32\...\Run: [HDAudDeck] => C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [5142128 2012-04-19] (VIA)
HKLM-x32\...\Run: [ATKOSD2] => C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [318080 2011-12-23] (ASUSTek Computer Inc.)
HKLM-x32\...\Run: [ATKMEDIA] => C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [174720 2011-10-25] (ASUS)
HKLM-x32\...\Run: [HControlUser] => C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [105016 2009-06-19] (ASUS)
HKLM-x32\...\Run: [ASUSWebStorage] => C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.108.222\AsusWSPanel.exe [737104 2011-07-29] (ecareme)
HKLM-x32\...\Run: [CLMLServer] => C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe [107816 2010-08-20] (CyberLink)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-10-28] (Hewlett-Packard)
HKLM-x32\...\Run: [AVG_UI] => C:\Program Files (x86)\AVG\AVG2014\avgui.exe [5212584 2015-10-20] (AVG Technologies CZ, s.r.o.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [597040 2015-10-06] (Oracle Corporation)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-3732487481-855672253-929003311-1001\...\Run: [PCSpeedUp] => C:\Program Files (x86)\PC Speed Up\PCSUNotifier.exe
ShellIconOverlayIdentifiers: [###MegaShellExtPending] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => C:\Users\Bryan\AppData\Local\MEGAsync\ShellExtX64.dll Geen bestand
ShellIconOverlayIdentifiers: [###MegaShellExtSynced] -> {05B38830-F4E9-4329-978B-1DD28605D202} => C:\Users\Bryan\AppData\Local\MEGAsync\ShellExtX64.dll Geen bestand
ShellIconOverlayIdentifiers: [###MegaShellExtSyncing] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => C:\Users\Bryan\AppData\Local\MEGAsync\ShellExtX64.dll Geen bestand
ShellIconOverlayIdentifiers: [AsusWSShellExt_B] -> {6D4133E5-0742-4ADC-8A8C-9303440F7190} => C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.108.222\ASUSWSShellExt64.dll [2011-05-25] (eCareme Technologies, Inc.)
ShellIconOverlayIdentifiers: [AsusWSShellExt_O] -> {64174815-8D98-4CE6-8646-4C039977D808} => C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.108.222\ASUSWSShellExt64.dll [2011-05-25] (eCareme Technologies, Inc.)
ShellIconOverlayIdentifiers-x32: [###MegaShellExtPending] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => C:\Users\Bryan\AppData\Local\MEGAsync\ShellExtX32.dll Geen bestand
ShellIconOverlayIdentifiers-x32: [###MegaShellExtSynced] -> {05B38830-F4E9-4329-978B-1DD28605D202} => C:\Users\Bryan\AppData\Local\MEGAsync\ShellExtX32.dll Geen bestand
ShellIconOverlayIdentifiers-x32: [###MegaShellExtSyncing] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => C:\Users\Bryan\AppData\Local\MEGAsync\ShellExtX32.dll Geen bestand
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AsusVibeLauncher.lnk [2012-02-24]
ShortcutTarget: AsusVibeLauncher.lnk -> C:\Program Files (x86)\ASUS\AsusVibe\AsusVibeLauncher.exe (ASUSTeK Computer Inc.)


==================== Internet (gefilterd) ====================


(Als een item is opgenomen in de fixlist, als het een registry item is wordt verwijderd of hersteld naar de standaard.)


Tcpip\Parameters: [DhcpNameServer] 195.130.131.4 195.130.130.132
Tcpip\..\Interfaces\{954017FF-42DA-42FD-84E1-ECB55673A792}: [DhcpNameServer] 195.130.131.4 195.130.130.132
Tcpip\..\Interfaces\{B7BD57C6-76C0-4AB4-AC64-4D8C834D3915}: [DhcpNameServer] 195.130.131.4 195.130.130.132


Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617912&ResetID=130892591560222338&GUID=D4782CC4-99AC-4097-BD5E-2E9FF6B401FD
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617912&ResetID=130892591560242339&GUID=D4782CC4-99AC-4097-BD5E-2E9FF6B401FD
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Google
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = Google
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = Google
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = Google
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Google
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = Google
HKU\S-1-5-21-3732487481-855672253-929003311-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617912&ResetID=130892591573953123&GUID=D4782CC4-99AC-4097-BD5E-2E9FF6B401FD
URLSearchHook: HKU\S-1-5-21-3732487481-855672253-929003311-1001 - (Geen Naam) - {7a55cbb2-2b2e-4a41-9de1-6ac5d2c2be0a} - C:\Program Files (x86)\UtilityChest_49\bar\1.bin\49SrcAs.dll Geen bestand
SearchScopes: HKLM -> DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSERBM&pc=MSERT1
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=ASUTDF&pc=NP06&src=IE-SearchBox
SearchScopes: HKLM -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSERBM&pc=MSERT1
SearchScopes: HKLM-x32 -> DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSERBM&pc=MSERT1
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=ASUTDF&pc=NP06&src=IE-SearchBox
SearchScopes: HKLM-x32 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSERBM&pc=MSERT1
SearchScopes: HKU\S-1-5-21-3732487481-855672253-929003311-1001 -> DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSERBM&pc=MSERT1
SearchScopes: HKU\S-1-5-21-3732487481-855672253-929003311-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-3732487481-855672253-929003311-1001 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSERBM&pc=MSERT1
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_65\bin\ssv.dll [2015-10-24] (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_65\bin\jp2ssv.dll [2015-10-24] (Oracle Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_65\bin\ssv.dll [2015-10-24] (Oracle Corporation)
BHO-x32: Aanmeldhulp voor Microsoft-account -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_65\bin\jp2ssv.dll [2015-10-24] (Oracle Corporation)
Toolbar: HKU\S-1-5-21-3732487481-855672253-929003311-1001 -> Geen Naam - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - Geen bestand
DPF: HKLM-x32 {4B54A9DE-EF1C-4EBE-A328-7C28EA3B433A} hxxp://quickscan.bitdefender.com/qsax/qsax.cab
DPF: HKLM-x32 {7530BFB8-7293-4D34-9923-61A11451AFC5} hxxp://download.eset.com/special/eos/OnlineScanner.cab
StartMenuInternet: IEXPLORE.EXE - iexplore.exe


FireFox:
========
FF Plugin: @java.com/DTPlugin,version=11.65.2 -> C:\Program Files\Java\jre1.8.0_65\bin\dtplugin\npDeployJava1.dll [2015-10-24] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.65.2 -> C:\Program Files\Java\jre1.8.0_65\bin\plugin2\npjp2.dll [2015-10-24] (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE -> disabled [Geen bestand]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-01-06] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-01-06] (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.65.2 -> C:\Program Files (x86)\Java\jre1.8.0_65\bin\dtplugin\npDeployJava1.dll [2015-10-24] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.65.2 -> C:\Program Files (x86)\Java\jre1.8.0_65\bin\plugin2\npjp2.dll [2015-10-24] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [Geen bestand]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2013-02-05] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3508.0205 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2013-02-05] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-17] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-17] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-09-27] (Adobe Systems Inc.)


Chrome:
=======
CHR Profile: C:\Users\bryan77\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Betalingen via Chrome Web Store) - C:\Users\bryan77\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-07-30]


==================== Services (gefilterd) ========================


(Als een item is opgenomen in de fixlist, wordt uit het register verwijderd. Het bestand zal niet worden verplaatst tenzij apart vermeld.)


R2 ASUS InstantOn; C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnSrv.exe [277120 2012-04-13] (ASUS)
S2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe [3259304 2015-10-20] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe [301896 2015-10-20] (AVG Technologies CZ, s.r.o.)
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [128280 2012-02-21] ()
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [161560 2012-02-21] (Intel Corporation)
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [5702416 2015-09-11] (TeamViewer GmbH)
S2 VIAKaraokeService; C:\Windows\system32\viakaraokesrv.exe [27760 2012-03-23] (VIA Technologies, Inc.)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
S4 0169601385920986mcinstcleanup; C:\Windows\TEMP\016960~1.EXE -cleanup -nolog [X]


===================== Drivers (gefilterd) ==========================


(Als een item is opgenomen in de fixlist, wordt uit het register verwijderd. Het bestand zal niet worden verplaatst tenzij apart vermeld.)


R3 AsusVBus; C:\Windows\System32\DRIVERS\AsusVBus.sys [35968 2012-04-12] (Windows (R) Win 7 DDK provider)
R3 AsusVTouch; C:\Windows\System32\DRIVERS\AsusVTouch.sys [16512 2012-04-12] (Windows (R) Win 7 DDK provider)
R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [152344 2014-06-30] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [244504 2014-07-21] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [237536 2015-05-26] (AVG Technologies CZ, s.r.o.)
R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [237848 2014-10-24] (AVG Technologies CZ, s.r.o.)
R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [369120 2015-05-26] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [211936 2015-05-26] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [31512 2014-06-17] (AVG Technologies CZ, s.r.o.)
R1 Avgtdia; C:\Windows\System32\DRIVERS\avgtdia.sys [276960 2015-05-18] (AVG Technologies CZ, s.r.o.)
S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [15416 2009-07-20] ( )
R3 L1C; C:\Windows\System32\DRIVERS\L1C62x64.sys [104560 2012-04-25] (Qualcomm Atheros Co., Ltd.)


==================== NetSvcs (gefilterd) ===================


(Als een item is opgenomen in de fixlist, wordt uit het register verwijderd. Het bestand zal niet worden verplaatst tenzij apart vermeld.)




==================== Een Maand Aangemaakt bestanden en mappen ========


(Als een item is opgenomen in de fixlist, het bestand/map wordt verplaatst.)


2015-12-01 21:48 - 2015-12-01 21:48 - 00852771 _____ C:\Users\bryan77\Downloads\SecurityCheck.exe
2015-12-01 21:47 - 2015-12-01 21:47 - 00019588 _____ C:\Users\bryan77\Desktop\FRST.txt
2015-12-01 21:46 - 2015-12-01 21:47 - 00000000 ____D C:\FRST
2015-12-01 21:45 - 2015-12-01 21:45 - 00000000 ____D C:\Users\bryan77\Desktop\uitgevoerde stappen
2015-12-01 21:45 - 2015-12-01 21:44 - 02350080 _____ (Farbar) C:\Users\bryan77\Desktop\FRST64.exe
2015-12-01 21:44 - 2015-12-01 21:44 - 02350080 _____ (Farbar) C:\Users\bryan77\Downloads\FRST64.exe
2015-11-22 14:44 - 2015-11-22 14:44 - 00000000 ____D C:\Users\Bryan\AppData\Roaming\Sun
2015-11-22 14:29 - 2015-11-22 14:29 - 00000000 ____D C:\Users\Barbara.bryan77-PC\AppData\Local\AvgSetupLog
2015-11-21 16:10 - 2015-11-21 16:10 - 00679936 _____ C:\Users\Bryan\Downloads\Detection (10).msi
2015-11-15 20:44 - 2015-11-15 11:44 - 00159444 ____N C:\Users\Barbara.bryan77-PC\Desktop\Kasverkoop nr 128 - 06-11-2015- Barbara Verbist.pdf
2015-11-15 20:36 - 2015-11-15 20:36 - 00001376 _____ C:\Users\bryan77\Desktop\Photo Gallery.lnk
2015-11-15 20:34 - 2015-11-15 20:34 - 00001116 _____ C:\Users\bryan77\Desktop\Afbeeldingen - Snelkoppeling.lnk
2015-11-15 19:43 - 2015-11-15 19:43 - 00000000 ____D C:\Users\bryan77\Desktop\AdminPc
2015-11-15 19:36 - 2015-11-03 18:55 - 03211264 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-11-15 19:35 - 2015-10-20 19:42 - 03168768 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2015-11-15 19:35 - 2015-10-20 19:42 - 02608128 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2015-11-15 19:35 - 2015-10-20 19:42 - 00696320 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2015-11-15 19:35 - 2015-10-20 19:42 - 00192512 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2015-11-15 19:35 - 2015-10-20 19:42 - 00098816 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2015-11-15 19:35 - 2015-10-20 19:42 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2015-11-15 19:35 - 2015-10-20 19:42 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2015-11-15 19:35 - 2015-10-20 19:41 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2015-11-15 19:35 - 2015-10-20 19:41 - 00091136 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
2015-11-15 19:35 - 2015-10-20 19:41 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2015-11-15 19:35 - 2015-10-20 19:41 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll
2015-11-15 19:35 - 2015-10-20 18:46 - 00566784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2015-11-15 19:35 - 2015-10-20 18:46 - 00174080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2015-11-15 19:35 - 2015-10-20 18:46 - 00093696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2015-11-15 19:35 - 2015-10-20 18:46 - 00030208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2015-11-15 19:35 - 2015-10-20 18:45 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2015-11-15 19:34 - 2015-11-03 23:10 - 00390344 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-11-15 19:34 - 2015-11-03 22:51 - 00342728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2015-11-15 19:34 - 2015-10-31 00:46 - 25818624 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-11-15 19:34 - 2015-10-31 00:40 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-11-15 19:34 - 2015-10-31 00:40 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2015-11-15 19:34 - 2015-10-31 00:25 - 02886656 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-11-15 19:34 - 2015-10-31 00:25 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-11-15 19:34 - 2015-10-31 00:25 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2015-11-15 19:34 - 2015-10-31 00:25 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2015-11-15 19:34 - 2015-10-31 00:24 - 00585728 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-11-15 19:34 - 2015-10-31 00:24 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2015-11-15 19:34 - 2015-10-31 00:17 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-11-15 19:34 - 2015-10-31 00:16 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2015-11-15 19:34 - 2015-10-31 00:13 - 00616960 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-11-15 19:34 - 2015-10-31 00:12 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-11-15 19:34 - 2015-10-31 00:12 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2015-11-15 19:34 - 2015-10-31 00:11 - 05990912 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-11-15 19:34 - 2015-10-31 00:11 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-11-15 19:34 - 2015-10-31 00:11 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2015-11-15 19:34 - 2015-10-31 00:04 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2015-11-15 19:34 - 2015-10-31 00:01 - 00489984 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-11-15 19:34 - 2015-10-30 23:58 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2015-11-15 19:34 - 2015-10-30 23:53 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-11-15 19:34 - 2015-10-30 23:52 - 20331520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2015-11-15 19:34 - 2015-10-30 23:49 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2015-11-15 19:34 - 2015-10-30 23:49 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-11-15 19:34 - 2015-10-30 23:47 - 00504832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2015-11-15 19:34 - 2015-10-30 23:46 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-11-15 19:34 - 2015-10-30 23:46 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2015-11-15 19:34 - 2015-10-30 23:45 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2015-11-15 19:34 - 2015-10-30 23:45 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2015-11-15 19:34 - 2015-10-30 23:44 - 00152064 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2015-11-15 19:34 - 2015-10-30 23:44 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2015-11-15 19:34 - 2015-10-30 23:42 - 02279936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2015-11-15 19:34 - 2015-10-30 23:39 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2015-11-15 19:34 - 2015-10-30 23:39 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2015-11-15 19:34 - 2015-10-30 23:37 - 00480256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2015-11-15 19:34 - 2015-10-30 23:36 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2015-11-15 19:34 - 2015-10-30 23:36 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2015-11-15 19:34 - 2015-10-30 23:36 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2015-11-15 19:34 - 2015-10-30 23:34 - 00262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2015-11-15 19:34 - 2015-10-30 23:32 - 00720896 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-11-15 19:34 - 2015-10-30 23:31 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-11-15 19:34 - 2015-10-30 23:29 - 02126336 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-11-15 19:34 - 2015-10-30 23:29 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2015-11-15 19:34 - 2015-10-30 23:28 - 00416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2015-11-15 19:34 - 2015-10-30 23:23 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2015-11-15 19:34 - 2015-10-30 23:22 - 14457856 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-11-15 19:34 - 2015-10-30 23:21 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2015-11-15 19:34 - 2015-10-30 23:19 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2015-11-15 19:34 - 2015-10-30 23:18 - 00279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2015-11-15 19:34 - 2015-10-30 23:17 - 02487808 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-11-15 19:34 - 2015-10-30 23:17 - 00130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2015-11-15 19:34 - 2015-10-30 23:16 - 04527616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2015-11-15 19:34 - 2015-10-30 23:11 - 00230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2015-11-15 19:34 - 2015-10-30 23:10 - 00689152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2015-11-15 19:34 - 2015-10-30 23:09 - 12854272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2015-11-15 19:34 - 2015-10-30 23:09 - 02052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2015-11-15 19:34 - 2015-10-30 23:09 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2015-11-15 19:34 - 2015-10-30 23:04 - 01547264 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-11-15 19:34 - 2015-10-30 22:53 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-11-15 19:34 - 2015-10-30 22:51 - 02011136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2015-11-15 19:34 - 2015-10-30 22:48 - 01311744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2015-11-15 19:34 - 2015-10-30 22:46 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2015-11-15 19:33 - 2015-10-29 18:50 - 00342016 _____ (Microsoft Corporation) C:\Windows\system32\apphelp.dll
2015-11-15 19:33 - 2015-10-29 18:50 - 00072192 _____ (Microsoft Corporation) C:\Windows\system32\aelupsvc.dll
2015-11-15 19:33 - 2015-10-29 18:50 - 00023552 _____ (Microsoft Corporation) C:\Windows\system32\sdbinst.exe
2015-11-15 19:33 - 2015-10-29 18:50 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\shimeng.dll
2015-11-15 19:33 - 2015-10-29 18:50 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shimeng.dll
2015-11-15 19:33 - 2015-10-29 18:49 - 00295936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apphelp.dll
2015-11-15 19:33 - 2015-10-29 18:49 - 00020992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sdbinst.exe
2015-11-15 19:33 - 2015-10-20 02:12 - 05570496 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-11-15 19:33 - 2015-10-20 02:12 - 00154560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2015-11-15 19:33 - 2015-10-20 02:12 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2015-11-15 19:33 - 2015-10-20 02:09 - 01730496 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2015-11-15 19:33 - 2015-10-20 02:06 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2015-11-15 19:33 - 2015-10-20 02:06 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2015-11-15 19:33 - 2015-10-20 02:06 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2015-11-15 19:33 - 2015-10-20 02:06 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2015-11-15 19:33 - 2015-10-20 02:05 - 01461760 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2015-11-15 19:33 - 2015-10-20 02:05 - 01216512 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2015-11-15 19:33 - 2015-10-20 02:05 - 01164800 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2015-11-15 19:33 - 2015-10-20 02:05 - 00729600 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2015-11-15 19:33 - 2015-10-20 02:05 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-11-15 19:33 - 2015-10-20 02:05 - 00424960 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2015-11-15 19:33 - 2015-10-20 02:05 - 00344064 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-11-15 19:33 - 2015-10-20 02:05 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2015-11-15 19:33 - 2015-10-20 02:05 - 00312320 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2015-11-15 19:33 - 2015-10-20 02:05 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-11-15 19:33 - 2015-10-20 02:05 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2015-11-15 19:33 - 2015-10-20 02:05 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2015-11-15 19:33 - 2015-10-20 02:05 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2015-11-15 19:33 - 2015-10-20 02:05 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2015-11-15 19:33 - 2015-10-20 02:05 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-11-15 19:33 - 2015-10-20 02:05 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2015-11-15 19:33 - 2015-10-20 02:05 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2015-11-15 19:33 - 2015-10-20 02:05 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2015-11-15 19:33 - 2015-10-20 02:05 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2015-11-15 19:33 - 2015-10-20 02:05 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2015-11-15 19:33 - 2015-10-20 02:05 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2015-11-15 19:33 - 2015-10-20 02:04 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2015-11-15 19:33 - 2015-10-20 02:04 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2015-11-15 19:33 - 2015-10-20 02:04 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2015-11-15 19:33 - 2015-10-20 02:00 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2015-11-15 19:33 - 2015-10-20 01:59 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2015-11-15 19:33 - 2015-10-20 01:53 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2015-11-15 19:33 - 2015-10-20 01:53 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2015-11-15 19:33 - 2015-10-20 01:53 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:53 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:53 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:53 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:53 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:53 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:53 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:53 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:53 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:53 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:53 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:53 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:53 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:53 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:53 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:52 - 03991488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2015-11-15 19:33 - 2015-10-20 01:52 - 03935680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2015-11-15 19:33 - 2015-10-20 01:48 - 01311768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2015-11-15 19:33 - 2015-10-20 01:45 - 00552960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2015-11-15 19:33 - 2015-10-20 01:45 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2015-11-15 19:33 - 2015-10-20 01:45 - 00251392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2015-11-15 19:33 - 2015-10-20 01:45 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2015-11-15 19:33 - 2015-10-20 01:45 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2015-11-15 19:33 - 2015-10-20 01:45 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2015-11-15 19:33 - 2015-10-20 01:45 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2015-11-15 19:33 - 2015-10-20 01:45 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll
2015-11-15 19:33 - 2015-10-20 01:45 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2015-11-15 19:33 - 2015-10-20 01:45 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2015-11-15 19:33 - 2015-10-20 01:45 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2015-11-15 19:33 - 2015-10-20 01:45 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2015-11-15 19:33 - 2015-10-20 01:44 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2015-11-15 19:33 - 2015-10-20 01:44 - 00665088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2015-11-15 19:33 - 2015-10-20 01:44 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2015-11-15 19:33 - 2015-10-20 01:44 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2015-11-15 19:33 - 2015-10-20 01:44 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2015-11-15 19:33 - 2015-10-20 01:44 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2015-11-15 19:33 - 2015-10-20 01:39 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2015-11-15 19:33 - 2015-10-20 01:39 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2015-11-15 19:33 - 2015-10-20 01:35 - 00686080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2015-11-15 19:33 - 2015-10-20 01:35 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2015-11-15 19:33 - 2015-10-20 01:35 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:35 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:35 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:35 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:35 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:35 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:35 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:35 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:35 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:35 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:35 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:35 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:35 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 00:41 - 00159232 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2015-11-15 19:33 - 2015-10-20 00:40 - 00290816 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2015-11-15 19:33 - 2015-10-20 00:40 - 00129024 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2015-11-15 19:33 - 2015-10-20 00:29 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2015-11-15 19:33 - 2015-10-20 00:29 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2015-11-15 19:33 - 2015-10-20 00:27 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 00:27 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 00:27 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 00:27 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2015-11-15 19:33 - 2015-10-13 17:41 - 00497664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2015-11-15 19:33 - 2015-10-13 17:40 - 00118272 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdx.sys
2015-11-15 19:33 - 2015-09-23 14:15 - 00460776 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2015-11-15 19:33 - 2015-09-23 14:15 - 00299632 _____ (Microsoft Corporation) C:\Windows\system32\bcryptprimitives.dll
2015-11-15 19:33 - 2015-09-23 14:09 - 00251000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcryptprimitives.dll
2015-11-15 19:27 - 2015-11-15 19:27 - 00000000 ____D C:\Users\bryan77\AppData\Local\Mega Limited
2015-11-15 19:24 - 2015-10-13 05:57 - 00950720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys
2015-11-15 19:24 - 2015-10-01 19:00 - 00275456 _____ (Microsoft Corporation) C:\Windows\system32\InkEd.dll
2015-11-15 19:24 - 2015-10-01 19:00 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\jnwmon.dll
2015-11-15 19:24 - 2015-10-01 18:50 - 00216064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InkEd.dll
2015-11-09 08:55 - 2015-11-09 08:55 - 00120507 _____ C:\Users\Barbara.bryan77-PC\Downloads\105521 (1).pdf
2015-11-09 08:51 - 2015-11-09 08:51 - 00120507 _____ C:\Users\Barbara.bryan77-PC\Downloads\105521.pdf


==================== Een Maand Gewijzigd bestanden en mappen ========


(Als een item is opgenomen in de fixlist, het bestand/map wordt verplaatst.)


2015-12-01 21:46 - 2009-07-14 05:45 - 00009920 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-12-01 21:46 - 2009-07-14 05:45 - 00009920 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-12-01 21:46 - 2009-07-14 04:20 - 00000000 ____D C:\Windows
2015-12-01 21:44 - 2013-12-08 21:48 - 00000940 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-12-01 21:40 - 2013-12-01 22:44 - 00000828 _____ C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job
2015-12-01 21:40 - 2013-12-01 14:21 - 00000380 _____ C:\Users\bryan77\AppData\Roaming\sp_data.sys
2015-12-01 21:40 - 2012-02-24 03:29 - 00001052 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-12-01 21:40 - 2009-07-14 06:09 - 00000000 ____D C:\Windows\System32\Tasks\WPD
2015-12-01 20:59 - 2012-02-24 03:29 - 00001056 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-12-01 20:54 - 2013-12-01 20:24 - 00000380 _____ C:\Users\Barbara.bryan77-PC\AppData\Roaming\sp_data.sys
2015-12-01 18:06 - 2011-02-19 05:40 - 00746450 _____ C:\Windows\system32\perfh013.dat
2015-12-01 18:06 - 2011-02-19 05:40 - 00154112 _____ C:\Windows\system32\perfc013.dat
2015-12-01 18:06 - 2009-07-14 06:13 - 01672504 _____ C:\Windows\system32\PerfStringBackup.INI
2015-12-01 18:06 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\inf
2015-12-01 17:22 - 2013-12-01 20:07 - 00000000 ____D C:\ProgramData\MFAData
2015-12-01 12:12 - 2013-12-01 22:44 - 00000830 _____ C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job
2015-11-26 16:56 - 2014-09-15 18:06 - 00000000 ____D C:\Users\Bryan\AppData\Roaming\Software Informer
2015-11-26 16:54 - 2015-06-03 11:41 - 00000000 ____D C:\Users\Bryan\AppData\Local\Spotify
2015-11-26 16:06 - 2015-06-03 11:40 - 00000000 ____D C:\Users\Bryan\AppData\Roaming\Spotify
2015-11-26 16:06 - 2013-12-01 21:06 - 00000380 _____ C:\Users\Bryan\AppData\Roaming\sp_data.sys
2015-11-22 20:59 - 2014-11-06 21:55 - 00000000 ____D C:\Program Files (x86)\TeamViewer
2015-11-22 14:44 - 2015-10-27 19:41 - 00000000 ____D C:\Users\Bryan\.oracle_jre_usage
2015-11-22 14:29 - 2014-11-26 08:12 - 00000000 ____D C:\Users\Barbara.bryan77-PC\AppData\Local\Avg
2015-11-16 04:06 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache
2015-11-16 03:29 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-11-16 03:29 - 2009-07-14 05:45 - 00270888 _____ C:\Windows\system32\FNTCACHE.DAT
2015-11-16 03:24 - 2015-06-03 21:56 - 00000000 ____D C:\Windows\system32\MRT
2015-11-16 03:11 - 2015-06-03 21:55 - 145617392 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-11-16 03:03 - 2012-02-24 03:28 - 01647172 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2015-11-16 03:02 - 2009-07-14 08:45 - 00000000 ____D C:\Program Files\Windows Journal
2015-11-15 20:36 - 2013-12-01 19:25 - 00000000 ____D C:\Users\bryan77\AppData\Local\Windows Live
2015-11-15 19:44 - 2013-12-08 21:48 - 00780488 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-11-15 19:44 - 2013-12-08 21:48 - 00142536 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-11-15 19:44 - 2013-12-08 21:48 - 00003878 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-11-15 19:43 - 2014-11-21 21:01 - 00000000 ____D C:\Users\AdminPc
2015-11-15 19:32 - 2009-07-14 04:20 - 00000000 __RHD C:\Users\Public\Libraries
2015-11-15 19:27 - 2014-10-01 09:20 - 00000000 ____D C:\Users\Bryan\AppData\Local\MEGAsync
2015-11-15 19:15 - 2014-07-29 10:51 - 00000000 ____D C:\Users\bryan77\AppData\Roaming\.minecraft
2015-11-15 19:02 - 2013-12-01 21:05 - 00000000 ____D C:\Users\Bryan
2015-11-15 19:02 - 2013-12-01 14:18 - 00000000 ____D C:\Users\bryan77
2015-11-13 00:29 - 2015-04-05 02:00 - 00000000 ___SD C:\Windows\system32\GWX
2015-11-13 00:29 - 2014-12-02 23:36 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2015-11-13 00:29 - 2014-08-28 07:09 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
2015-11-13 00:29 - 2013-12-08 21:48 - 00000000 ____D C:\Windows\system32\Macromed
2015-11-13 00:29 - 2013-12-01 20:24 - 00000000 ____D C:\Users\Barbara.bryan77-PC
2015-11-13 00:29 - 2012-02-24 03:29 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-11-13 00:29 - 2009-07-14 08:44 - 00000000 ___RD C:\Users\Public\Recorded TV
2015-11-13 00:29 - 2009-07-14 04:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared
2015-11-13 00:28 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\registration
2015-11-07 11:11 - 2014-08-11 12:27 - 00000184 _____ C:\Users\Bryan\Downloads\eula.txt
2015-11-01 10:43 - 2014-12-25 22:00 - 00003886 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task


==================== Bestanden in de root van sommige mappen =======


2013-12-01 14:21 - 2015-12-01 21:40 - 0000380 _____ () C:\Users\bryan77\AppData\Roaming\sp_data.sys
2014-04-16 18:15 - 2014-04-16 18:15 - 0000057 _____ () C:\ProgramData\Ament.ini
2012-02-24 03:42 - 2010-10-06 18:45 - 0131984 _____ () C:\ProgramData\FullRemove.exe
2013-12-01 14:06 - 2013-12-01 14:06 - 0000109 _____ () C:\ProgramData\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}.log
2013-12-01 14:05 - 2013-12-01 14:06 - 0000105 _____ () C:\ProgramData\{40BF1E83-20EB-11D8-97C5-0009C5020658}.log
2013-12-01 14:04 - 2013-12-01 14:05 - 0000107 _____ () C:\ProgramData\{C59C179C-668D-49A9-B6EA-0121CCFC1243}.log


Sommige bestanden in TEMP:
====================
C:\Users\Bryan\AppData\Local\Temp\i4jdel0.exe
C:\Users\Bryan\AppData\Local\Temp\ICReinstall_Malavida_Download_Manager.exe
C:\Users\Bryan\AppData\Local\Temp\jre-8u31-windows-au.exe
C:\Users\Bryan\AppData\Local\Temp\jre-8u40-windows-au.exe
C:\Users\Bryan\AppData\Local\Temp\tmp17FF.tmp.exe
C:\Users\bryan77\AppData\Local\Temp\i4jdel0.exe
C:\Users\bryan77\AppData\Local\Temp\jre-8u45-windows-au.exe
C:\Users\bryan77\AppData\Local\Temp\jre-8u65-windows-au.exe
C:\Users\bryan77\AppData\Local\Temp\Uninstall.exe




==================== Bamital & volsnap =================


(Er is geen automatische fix voor bestanden die de verificatie niet doorkomen.)


C:\Windows\system32\winlogon.exe => Bestand is getekend
C:\Windows\system32\wininit.exe => Bestand is getekend
C:\Windows\SysWOW64\wininit.exe => Bestand is getekend
C:\Windows\explorer.exe => Bestand is getekend
C:\Windows\SysWOW64\explorer.exe => Bestand is getekend
C:\Windows\system32\svchost.exe => Bestand is getekend
C:\Windows\SysWOW64\svchost.exe => Bestand is getekend
C:\Windows\system32\services.exe => Bestand is getekend
C:\Windows\system32\User32.dll => Bestand is getekend
C:\Windows\SysWOW64\User32.dll => Bestand is getekend
C:\Windows\system32\userinit.exe => Bestand is getekend
C:\Windows\SysWOW64\userinit.exe => Bestand is getekend
C:\Windows\system32\rpcss.dll => Bestand is getekend
C:\Windows\system32\dnsapi.dll => Bestand is getekend
C:\Windows\SysWOW64\dnsapi.dll => Bestand is getekend
C:\Windows\system32\Drivers\volsnap.sys => Bestand is getekend




LastRegBack: 2015-11-30 00:25


==================== Eind van FRST.txt ============================

Extra scanresultaten van Farbar Recovery Scan Tool (x64) Versie:01-12-2015
Gestart door bryan77 (2015-12-01 21:48:47)
Gestart vanaf C:\Users\bryan77\Desktop
Windows 7 Home Premium Service Pack 1 (X64) (2013-12-01 13:17:59)
Boot Modus: Normal
==========================================================




==================== Accounts: =============================


Administrator (S-1-5-21-3732487481-855672253-929003311-500 - Administrator - Disabled)
Barbara (S-1-5-21-3732487481-855672253-929003311-1006 - Limited - Enabled) => C:\Users\Barbara.bryan77-PC
Bryan (S-1-5-21-3732487481-855672253-929003311-1005 - Limited - Enabled) => C:\Users\Bryan
bryan77 (S-1-5-21-3732487481-855672253-929003311-1001 - Administrator - Enabled) => C:\Users\bryan77
Gast (S-1-5-21-3732487481-855672253-929003311-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-3732487481-855672253-929003311-1002 - Limited - Enabled)


==================== Security Center ========================


(Als een item is opgenomen in de fixlist, zal het worden verwijderd.)


AV: AVG AntiVirus Free Edition 2014 (Disabled - Up to date) {4D41356F-32AD-7C42-C820-63775EE4F413}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: AVG AntiVirus Free Edition 2014 (Disabled - Up to date) {F620D48B-1497-73CC-F290-58052563BEAE}


==================== Geïnstalleerde programma's ======================


(Alleen de adware-programma's met 'verborgen' vlag zou kunnen worden toegevoegd aan de fixlist om ze zichtbaar te maken. De adware-programma's moeten handmatig gedeinstallerd worden.)


Adobe Flash Player 10 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 10.0.32.18 - Adobe Systems Incorporated)
Adobe Flash Player 19 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 19.0.0.245 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.13) - Nederlands (HKLM-x32\...\{AC76BA86-7AD7-1043-7B44-AB0000000001}) (Version: 11.0.13 - Adobe Systems Incorporated)
Alcor Micro USB Card Reader (HKLM-x32\...\AmUStor) (Version: 1.2.0117.08443 - Alcor Micro Corp.)
Alcor Micro USB Card Reader (x32 Version: 1.2.0117.08443 - Alcor Micro Corp.) Hidden
ASUS AI Recovery (HKLM-x32\...\{D39F0676-163E-4595-A917-E28F99BBD4D2}) (Version: 1.0.24 - ASUS)
ASUS FaceLogon (HKLM-x32\...\{64452561-169F-4A36-A2FF-B5E118EC65F5}) (Version: 1.0.0014 - ASUS)
ASUS Instant Connect (HKLM-x32\...\{89ECB85A-D933-4CEA-9116-5CBC9C2ED95B}) (Version: 1.2.2 - ASUS)
ASUS LifeFrame3 (HKLM-x32\...\{1DBD1F12-ED93-49C0-A7CC-56CBDE488158}) (Version: 3.1.1 - ASUS)
ASUS Live Update (HKLM-x32\...\{FA540E67-095C-4A1B-97BA-4D547DEC9AF4}) (Version: 3.1.5 - ASUS)
ASUS Power4Gear Hybrid (HKLM\...\{9B6239BF-4E85-4590-8D72-51E30DB1A9AA}) (Version: 1.2.1 - ASUS)
ASUS Splendid Video Enhancement Technology (HKLM-x32\...\{0969AF05-4FF6-4C00-9406-43599238DE0D}) (Version: 1.03.0001 - ASUS)
ASUS USB Charger Plus (HKLM-x32\...\{A859E3E5-C62F-4BFA-AF1D-2B95E03166AF}) (Version: 2.1.1 - ASUS)
ASUS Virtual Camera (HKLM-x32\...\{EC8BD21F-0CA0-4BBF-97D9-4A52B30041A1}) (Version: 1.0.25 - ASUS)
ASUS Virtual Touch (HKLM-x32\...\{938CFBD4-0652-49E5-BB8B-153948865941}) (Version: 1.0.11 - ASUS)
ASUS WebStorage (HKLM-x32\...\ASUS WebStorage) (Version: 3.0.108.222 - eCareme Technologies, Inc.)
AsusVibe2.0 (HKLM-x32\...\Asus Vibe2.0) (Version: 2.0.9.157 - ASUSTEK)
Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver (HKLM-x32\...\{3108C217-BE83-42E4-AE9E-A56A2A92E549}) (Version: 2.0.15.16 - Atheros Communications Inc.)
ATK Package (HKLM-x32\...\{AB5C933E-5C7D-4D30-B314-9C83A49B94BE}) (Version: 1.0.0015 - ASUS)
AVG 2014 (HKLM\...\AVG) (Version: 2014.0.4842 - AVG Technologies)
AVG 2014 (Version: 14.0.4447 - AVG Technologies) Hidden
AVG 2014 (Version: 14.0.4842 - AVG Technologies) Hidden
Bubbletown (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-115065740}) (Version: - Oberon Media)
Contenta Converter PREMIUM (HKLM-x32\...\ContentaConverter-PREMIUM) (Version: - Contenta Software)
CyberLink LabelPrint (HKLM-x32\...\InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}) (Version: 2.5.3624 - CyberLink Corp.)
CyberLink Media Suite (HKLM-x32\...\InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}) (Version: 8.0.2926 - CyberLink Corp.)
CyberLink Power2Go (HKLM-x32\...\InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 7.0.0.1126 - CyberLink Corp.)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Deadtime Stories (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-118716773}) (Version: - Oberon Media)
Dream Day First Home (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-113832110}) (Version: - Oberon Media)
Dream Vacation Solitaire (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111249233}) (Version: - Oberon Media)
ESET Online Scanner v3 (HKLM-x32\...\ESET Online Scanner) (Version: - )
ETDWare PS/2-X64 10.5.10.0 (HKLM\...\Elantech) (Version: 10.5.10.0 - ELAN Microelectronic Corp.)
Farm Frenzy 3 - Madagascar (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-119205603}) (Version: - Oberon Media)
File Association Helper (HKLM\...\{C168639F-5810-4EC8-B1E8-0251AA8A771C}) (Version: 1.2.225.65451 - WinZip Computing International, LLC)
Fotogalerie (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Galapago (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111307457}) (Version: - Oberon Media)
Galeria de Fotografias (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Galería de fotos (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Galerie de photos (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Game Park Console (HKLM-x32\...\Game Park Console) (Version: 1.2.4.431 - Oberon Media Inc.)
Go Go Gourmet Chef of the Year (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-115290153}) (Version: - Oberon Media)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 46.0.2490.86 - Google Inc.)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.28.15 - Google Inc.) Hidden
HP Deskjet 1050 J410 series Basissoftware van het apparaat (HKLM\...\{FA37D2E8-0A8B-46D2-A74A-310F935DE920}) (Version: 28.0.1313.0 - Hewlett-Packard Co.)
HP Deskjet 1050 J410 series Haelp (HKLM-x32\...\{5C90D8CF-F12A-41C6-9007-3B651A1F0D78}) (Version: 140.0.66.66 - Hewlett Packard)
HP Deskjet 1050 J410 series Productverbeteringsonderzoek (HKLM\...\{44C6BB22-7E25-4A6D-8851-6FB26407D9C1}) (Version: 28.0.1313.0 - Hewlett-Packard Co.)
HP Photo Creations (HKLM-x32\...\HP Photo Creations) (Version: 1.0.0.7702 - HP)
HP Update (HKLM-x32\...\{6F1C00D2-25C2-4CBA-8126-AE9A6E2E9CD5}) (Version: 5.003.003.001 - Hewlett-Packard)
InstantOn for NB (HKLM-x32\...\{749F674B-2674-47E8-879C-5626A06B2A91}) (Version: 2.3.3 - ASUS)
Intel(R) Manageability Engine Firmware Recovery Agent (HKLM-x32\...\{A6C48A9F-694A-4234-B3AA-62590B668927}) (Version: 1.0.0.35342 - Intel Corporation)
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.0.3.1427 - Intel Corporation)
Intel(R) OpenCL CPU Runtime (HKLM-x32\...\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2653 - Intel Corporation)
Intel(R) USB 3.0 eXtensible Host Controller Driver (HKLM-x32\...\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 1.0.3.214 - Intel Corporation)
Intel® Trusted Connect Service Client (HKLM\...\{09536BA1-E498-4CC3-B834-D884A67D7E34}) (Version: 1.23.605.1 - Intel Corporation)
Java 8 Update 65 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86418065F0}) (Version: 8.0.650.17 - Oracle Corporation)
Java 8 Update 65 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218065F0}) (Version: 8.0.650.17 - Oracle Corporation)
Junk Mail filter update (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Mahjong Memoirs (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-117948443}) (Version: - Oberon Media)
MediaFire Desktop (HKLM-x32\...\MediaFire Desktop 1.3.9.10486) (Version: 1.3.9.10486 - MediaFire)
Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft Office 2010 (HKLM-x32\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office Klik-en-Klaar 2010 (HKLM-x32\...\Office14.Click2Run) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office Starter 2010 - Nederlands (HKLM-x32\...\{90140011-0066-0413-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft PowerPoint Viewer (HKLM-x32\...\{95140000-00AF-0413-0000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40728.0 - Microsoft Corporation)
Microsoft SkyDrive (HKU\S-1-5-21-3732487481-855672253-929003311-1001\...\SkyDriveSetup.exe) (Version: 16.4.6013.0910 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Movie Maker (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
myBitCast 1.0.0.3 (HKLM\...\myBitCast) (Version: 1.0.0.3 - ASUS Cloud Corporation)
Plants vs Zombies (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-117080787}) (Version: - Oberon Media)
Platform (x32 Version: 1.39 - VIA Technologies, Inc.) Hidden
Qualcomm Atheros WiFi Driver Installation (HKLM-x32\...\{7D916FA5-DAE9-4A25-B089-655C70EAF607}) (Version: 3.0 - Qualcomm Atheros)
Raccolta foto (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
SceneSwitch (HKLM-x32\...\{5172E572-C175-4F80-A6D5-5CB45826AD61}) (Version: 1.0.12 - ASUS)
TeamViewer 10 (HKLM-x32\...\TeamViewer) (Version: 10.0.47484 - TeamViewer)
The Simpsons Tapped Out Packages (HKU\S-1-5-21-3732487481-855672253-929003311-1001\...\The Simpsons Tapped Out Packages) (Version: - ) <==== AANDACHT
Turbo Fiesta (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-115320460}) (Version: - Oberon Media)
VIA Platform Device Manager (HKLM-x32\...\InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}) (Version: 1.39 - VIA Technologies, Inc.)
Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
Visual Studio 2012 x86 Redistributables (HKLM-x32\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3508.0205 - Microsoft Corporation)
Windows Phone app for desktop (HKLM-x32\...\{54EC61F0-6D02-450E-9F1B-9506EAE9F23C}) (Version: 1.1.2726.0 - Microsoft Corporation)
WinFlash (HKLM-x32\...\{8F21291E-0444-4B1D-B9F9-4370A73E346D}) (Version: 2.41.0 - ASUS)
WinRAR 5.01 (32-bit) (HKLM-x32\...\WinRAR archiver) (Version: 5.01.0 - win.rar GmbH)
WinZip 18.5 (HKLM\...\{CD95F661-A5C4-44F5-A6AA-ECDD91C240E3}) (Version: 18.5.11111 - WinZip Computing, S.L. )
Wireless Console 3 (HKLM-x32\...\{19EA33FB-B34E-40EA-8B8A-61743AEB795A}) (Version: 3.0.30 - ASUS)
World of Goo (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-116672750}) (Version: - Oberon Media)
Συλλογή φωτογραφιών (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Основные компоненты Windows Live (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Почта Windows Live (x32 Version: 16.4.3508.0205 - Корпорация Майкрософт) Hidden
Фотоальбом (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Фотографии (общедоступная версия) (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
גלריית התמונות (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
بريد Windows Live (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
معرض الصور (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
影像中心 (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden


==================== Aangepaste CLSID (gefilterd): ==========================


(Als een item is opgenomen in de fixlist, wordt uit het register verwijderd. Het bestand zal niet worden verplaatst tenzij apart vermeld.)




==================== Herstelpunten =========================


21-11-2015 16:11:01 Installed System Requirements Lab Detection
29-11-2015 00:00:02 Gepland controlepunt


==================== Hosts inhoud: ===============================


(Als nodig Hosts: opdracht kan worden opgenomen in de fixlist om Hosts te resetten.)


2009-07-14 03:34 - 2014-11-27 22:36 - 00000098 ____A C:\Windows\system32\Drivers\etc\hosts


127.0.0.1 localhost
::1 localhost


==================== Geplande Taken (gefilterd) =============


(Als een item is opgenomen in de fixlist, wordt uit het register verwijderd. Het bestand zal niet worden verplaatst tenzij apart vermeld.)


Task: {016EB10C-9FA8-4770-8EBC-FB988737FFAC} - System32\Tasks\ASUS USB Charger Plus => C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe [2012-05-08] (ASUSTek Computer Inc.)
Task: {03E6DA50-A095-4B57-902E-4DF77C5BF8F7} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2011-11-25] (Intel Corporation)
Task: {0B3022E3-1822-42D2-853B-060D9B16FE85} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
Task: {10101098-8567-43F5-9791-02068557C5E4} - System32\Tasks\ASUS SmartLogon Console Sensor => C:\Program Files (x86)\ASUS\FaceLogon\sensorsrv.exe [2012-02-17] (ASUSTek Computer Inc.)
Task: {202E950A-44F4-4239-B80C-69E0FA7FE0E1} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-11-15] (Adobe Systems Incorporated)
Task: {646DF190-524D-4096-A992-877B333AC272} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2011-11-25] (Intel Corporation)
Task: {665B67F0-541F-45A7-89B7-F2ACC49878F2} - System32\Tasks\HPCustParticipation HP Deskjet 1050 J410 series => C:\Program Files\HP\HP Deskjet 1050 J410 series\Bin\HPCustPartic.exe [2012-10-02] (Hewlett-Packard Co.)
Task: {67604CC6-E4A2-471C-8838-4D78A2D5DEF4} - System32\Tasks\ATKOSD2 => C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [2011-12-23] (ASUSTek Computer Inc.)
Task: {73A21D4C-2845-4D8B-9C8E-73FDEA7C9874} - System32\Tasks\ASUS Quick Gesture (x64) => C:\Program Files (x86)\ASUS\ASUS Virtual Touch\QuickGesture\x64\QuickGesture64.exe [2012-04-12] (ASUSTeK Computer Inc.)
Task: {75D32B76-8DCE-43E7-A42C-9D9F74B667CF} - System32\Tasks\ASUS Wireless Console 3 => C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [2012-05-17] (ASUSTeK Computer Inc.)
Task: {797BE614-709C-4392-8414-E7339AA5FED9} - System32\Tasks\ASUS P4G => C:\Program Files\ASUS\P4G\BatteryLife.exe [2012-02-16] (ASUS)
Task: {8BDDB50A-894A-44C8-8F18-AC996B599520} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
Task: {D243337D-A7BA-4BDC-94F5-D685FC8BC71D} - System32\Tasks\ASUS Quick Gesture => C:\Program Files (x86)\ASUS\ASUS Virtual Touch\QuickGesture\x86\QuickGesture.exe [2012-04-12] (ASUSTeK Computer Inc.)
Task: {DB88D52C-111F-4457-B2ED-6C6055D80BA8} - System32\Tasks\ASUS Live Update => C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe [2012-05-22] (ASUSTeK Computer Inc.)
Task: {EC10FEA5-971D-4A52-8BA5-075DE9A65021} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-10-28] (Adobe Systems Incorporated)
Task: {F518AA26-3DD4-48B6-AF10-875985913339} - System32\Tasks\0615tbUpdateInfo => C:\ProgramData\Avg_Update_0615tb\0615tb_{7065CFD9-63B9-47E1-A239-3232D511C3F6}.exe [2015-06-20] ()


(Als een item is opgenomen in de fixlist, de taak (job) bestand wordt verplaatst. Het bestand dat wordt uitgevoerd door de taak zal niet worden verplaatst.)


Task: C:\Windows\Tasks\0615tbUpdateInfo.job => C:\ProgramData\Avg_Update_0615tb\0615tb_{7065CFD9-63B9-47E1-A239-3232D511C3F6}.exe
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe
Task: C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe


==================== Snelkoppelingen =============================


(De items kunnen worden opgenomen in de fixlist.txt om hersteld of verwijderd te worden.)


ShortcutWithArgument: C:\Users\bryan77\Desktop\Internet Explorer.lnk -> C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.sweet-page.com/?type=sc&ts=1410798019&from=cor&uid=ST320LT020-9YG142_W0Q4K52MXXXXW0Q4K52M <==== AANDACHT
ShortcutWithArgument: C:\Users\bryan77\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.sweet-page.com/?type=sc&ts=1410798019&from=cor&uid=ST320LT020-9YG142_W0Q4K52MXXXXW0Q4K52M <==== AANDACHT
ShortcutWithArgument: C:\Users\bryan77\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.sweet-page.com/?type=sc&ts=1410798019&from=cor&uid=ST320LT020-9YG142_W0Q4K52MXXXXW0Q4K52M <==== AANDACHT
ShortcutWithArgument: C:\Users\bryan77\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.sweet-page.com/?type=sc&ts=1410798019&from=cor&uid=ST320LT020-9YG142_W0Q4K52MXXXXW0Q4K52M <==== AANDACHT
ShortcutWithArgument: C:\Users\bryan77\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk -> C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.sweet-page.com/?type=sc&ts=1410798019&from=cor&uid=ST320LT020-9YG142_W0Q4K52MXXXXW0Q4K52M <==== AANDACHT
ShortcutWithArgument: C:\Users\bryan77\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.sweet-page.com/?type=sc&ts=1410798019&from=cor&uid=ST320LT020-9YG142_W0Q4K52MXXXXW0Q4K52M <==== AANDACHT
ShortcutWithArgument: C:\Users\bryan77\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.sweet-page.com/?type=sc&ts=1410798019&from=cor&uid=ST320LT020-9YG142_W0Q4K52MXXXXW0Q4K52M <==== AANDACHT


==================== Geladen Modules (gefilterd) ==============


2013-12-01 22:44 - 2012-02-21 21:29 - 00128280 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
2010-07-15 01:11 - 2010-07-15 01:11 - 00031360 _____ () C:\Program Files\ASUS\P4G\DevMng.dll
2012-06-27 04:04 - 2012-02-22 08:18 - 00094208 _____ () C:\Windows\system32\IccLibDll_x64.dll
2013-12-01 22:45 - 2012-04-19 03:24 - 00078448 _____ () C:\Program Files (x86)\VIA\VIAudioi\VDeck\QsApoApi64.dll
2013-12-01 22:45 - 2012-04-19 03:24 - 00386160 _____ () C:\Program Files (x86)\VIA\VIAudioi\VDeck\Dts2ApoApi64.dll
2013-12-01 22:44 - 2012-02-21 21:09 - 01198872 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll
2012-01-31 18:25 - 2012-01-31 18:25 - 01163264 _____ () C:\Program Files (x86)\ASUS\Wireless Console 3\acAuth.dll
2012-05-08 01:48 - 2012-05-08 01:48 - 00009216 _____ () C:\Program Files (x86)\ASUS\Splendid\GLCDdll.dll
2010-08-20 18:57 - 2010-08-20 18:57 - 00619816 _____ () C:\Program Files (x86)\CyberLink\Power2Go\CLMediaLibrary.dll
2010-08-20 18:57 - 2010-08-20 18:57 - 00013096 _____ () C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvcPS.dll
2015-11-16 01:00 - 2015-11-07 05:36 - 01532744 _____ () C:\Program Files (x86)\Google\Chrome\Application\46.0.2490.86\libglesv2.dll
2015-11-16 01:00 - 2015-11-07 05:36 - 00081224 _____ () C:\Program Files (x86)\Google\Chrome\Application\46.0.2490.86\libegl.dll


==================== Alternate Data Streams (gefilterd) =========


(Als een item is opgenomen in de fixlist, alleen de ADS wordt verwijderd.)




==================== Veilige Modus (gefilterd) ===================


(Als een item is opgenomen in de fixlist, wordt uit het register verwijderd. De "AlternateShell" waarde wordt hersteld.)




==================== EXE Bestandskoppeling (gefilterd) ===============


(Als een item is opgenomen in de fixlist, het registry item zal worden teruggezet naar de standaardwaarden of verwijderd.)




==================== Internet Explorer vertrouwde/beperkte toegang ===============


(Als een item is opgenomen in de fixlist, wordt uit het register verwijderd.)




==================== Andere gebieden ============================


(Momenteel is er geen automatische fix voor dit onderdeel.)


HKU\S-1-5-21-3732487481-855672253-929003311-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\bryan77\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 195.130.131.4 - 195.130.130.132
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is ingeschakeld.


==================== MSCONFIG/TASK MANAGER Uitgeschakelde items ==


(Momenteel is er geen automatische fix voor dit onderdeel.)


MSCONFIG\Services: 0169601385920986mcinstcleanup => 2
MSCONFIG\Services: MBAMScheduler => 2
MSCONFIG\Services: MBAMService => 2
MSCONFIG\Services: McAfee SiteAdvisor Service => 2
MSCONFIG\Services: McAWFwk => 3
MSCONFIG\Services: mcmscsvc => 2
MSCONFIG\Services: McNaiAnn => 2
MSCONFIG\Services: McNASvc => 2
MSCONFIG\Services: McODS => 3
MSCONFIG\Services: McOobeSv => 2
MSCONFIG\Services: McProxy => 2
MSCONFIG\Services: MSK80Service => 2
MSCONFIG\startupreg: AVG_UI => "C:\Program Files (x86)\AVG\AVG2014\avgui.exe" /TRAYONLY
MSCONFIG\startupreg: mcui_exe => "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey


==================== Firewall regels (gefilterd) ===============


(Als een item is opgenomen in de fixlist, wordt uit het register verwijderd. Het bestand zal niet worden verplaatst tenzij apart vermeld.)


FirewallRules: [TCP Query User{EBA49DCD-5C2F-4F0E-BF4F-A983FD370081}C:\program files (x86)\java\jre1.8.0_25\bin\javaw.exe] => (Block) C:\program files (x86)\java\jre1.8.0_25\bin\javaw.exe
FirewallRules: [UDP Query User{04EF1A3B-E8E1-408D-A433-3D778365BB2A}C:\program files (x86)\java\jre1.8.0_25\bin\javaw.exe] => (Block) C:\program files (x86)\java\jre1.8.0_25\bin\javaw.exe
FirewallRules: [TCP Query User{49B33151-1BF6-4A16-9671-A38AC8E1DA7F}D:\gta5.exe] => (Allow) D:\gta5.exe
FirewallRules: [UDP Query User{5F17BCE1-5BAB-4AF9-BC8C-2031EEA73D41}D:\gta5.exe] => (Allow) D:\gta5.exe
FirewallRules: [TCP Query User{21411C96-5716-44DB-97AE-6AAFEBC0D31B}C:\users\bryan\appdata\roaming\spotify\spotify.exe] => (Block) C:\users\bryan\appdata\roaming\spotify\spotify.exe
FirewallRules: [UDP Query User{921FF2AA-205F-4238-912D-AC80D00B83E6}C:\users\bryan\appdata\roaming\spotify\spotify.exe] => (Block) C:\users\bryan\appdata\roaming\spotify\spotify.exe
FirewallRules: [TCP Query User{B9BE8C40-DEBE-49C5-AE3A-E1498EAB80DA}C:\program files (x86)\java\jre1.8.0_45\bin\java.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_45\bin\java.exe
FirewallRules: [UDP Query User{5D64D027-EE91-41AD-A490-E62C7653EB88}C:\program files (x86)\java\jre1.8.0_45\bin\java.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_45\bin\java.exe
FirewallRules: [{7129689C-CE17-4737-BACC-4DDF25C9B34C}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{96E25971-D876-4129-9C15-D8EA0429C079}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{4660A62B-8C06-4943-B5FB-280CA615DFE6}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [{B035D7DF-7034-477E-9AE9-5129C494ECBD}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [{4A8DF4BB-2F8C-43C7-A9E4-CE99882730D1}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{CDE4D536-EAC6-4FB2-85A0-4E4F871B922D}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{8FE3476B-6184-441D-8C96-2CA1DD32DBE9}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [{9531F97E-338F-4533-B4BB-9A32D6B4764D}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [TCP Query User{D3C51161-AB03-4053-B366-DBB01F6DA1A0}C:\program files\java\jre1.8.0_65\bin\javaw.exe] => (Block) C:\program files\java\jre1.8.0_65\bin\javaw.exe
FirewallRules: [UDP Query User{6E6E1AC3-B769-4DB0-92AE-80A9159BD7AE}C:\program files\java\jre1.8.0_65\bin\javaw.exe] => (Block) C:\program files\java\jre1.8.0_65\bin\javaw.exe
FirewallRules: [TCP Query User{074F5DDC-5183-44DA-9FF2-431BE3FFFC2F}C:\program files\java\jre1.8.0_65\bin\java.exe] => (Allow) C:\program files\java\jre1.8.0_65\bin\java.exe
FirewallRules: [UDP Query User{E9A707DB-5A5F-4F63-8681-AC8E2BE7CD33}C:\program files\java\jre1.8.0_65\bin\java.exe] => (Allow) C:\program files\java\jre1.8.0_65\bin\java.exe
FirewallRules: [{6D7622EE-6E74-470D-A067-1D34D8747E98}] => (Allow) C:\Program Files (x86)\AVG\AVG2014\avgnsa.exe
FirewallRules: [{F70545F6-489D-4862-877D-A8770F3D67AC}] => (Allow) C:\Program Files (x86)\AVG\AVG2014\avgnsa.exe
FirewallRules: [{E2EBE6BC-6C48-4AC8-A2F3-8291386F4E9E}] => (Allow) C:\Program Files (x86)\AVG\AVG2014\avgdiagex.exe
FirewallRules: [{75951CA5-A51D-4E8D-AEA7-05089C1D711E}] => (Allow) C:\Program Files (x86)\AVG\AVG2014\avgdiagex.exe
FirewallRules: [{385FA559-3B1C-4007-ABC7-A2D9EFC11C02}] => (Allow) C:\Program Files (x86)\AVG\AVG2014\avgemca.exe
FirewallRules: [{B9235D54-F6A8-4C88-B11A-98C262A144C6}] => (Allow) C:\Program Files (x86)\AVG\AVG2014\avgemca.exe
FirewallRules: [{AC569F6C-DE67-48AF-9066-CDD57D42B4D5}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe


==================== Defecte Apparaatbeheer Apparaten =============




==================== Eventlog fouten: =========================


Applicatiefouten:
==================
Error: (11/21/2015 04:10:21 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Naam van toepassing met fout: Explorer.EXE, versie: 6.1.7601.17567, tijdstempel: 0x4d672ee4
Naam van module met fout: unknown, versie: 0.0.0.0, tijdstempel: 0x00000000
Uitzonderingscode: 0xc0000005
Foutoffset: 0x0000000000000000
Id van proces met fout: 0x163c
Starttijd van toepassing met fout: 0xExplorer.EXE0
Pad naar toepassing met fout: Explorer.EXE1
Pad naar module met fout: Explorer.EXE2
Rapport-id: Explorer.EXE3


Error: (11/15/2015 09:53:04 PM) (Source: CVHSVC) (EventID: 100) (User: )
Description: Alleen informatie.
(Patch task for {90140011-0066-0413-0000-0000000FF1CE}): DownloadLatest Failed:


Error: (11/15/2015 08:30:52 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Naam van toepassing met fout: DllHost.exe, versie: 6.1.7600.16385, tijdstempel: 0x4a5bca54
Naam van module met fout: igdumd64.dll, versie: 8.15.10.2653, tijdstempel: 0x4f3aac44
Uitzonderingscode: 0xc0000005
Foutoffset: 0x000000000030eb06
Id van proces met fout: 0x148c
Starttijd van toepassing met fout: 0xDllHost.exe0
Pad naar toepassing met fout: DllHost.exe1
Pad naar module met fout: DllHost.exe2
Rapport-id: DllHost.exe3


Error: (11/15/2015 08:29:19 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Naam van toepassing met fout: DllHost.exe, versie: 6.1.7600.16385, tijdstempel: 0x4a5bca54
Naam van module met fout: igdumd64.dll, versie: 8.15.10.2653, tijdstempel: 0x4f3aac44
Uitzonderingscode: 0xc000041d
Foutoffset: 0x000000000030eb06
Id van proces met fout: 0x12d0
Starttijd van toepassing met fout: 0xDllHost.exe0
Pad naar toepassing met fout: DllHost.exe1
Pad naar module met fout: DllHost.exe2
Rapport-id: DllHost.exe3


Error: (11/15/2015 08:29:12 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Naam van toepassing met fout: DllHost.exe, versie: 6.1.7600.16385, tijdstempel: 0x4a5bca54
Naam van module met fout: igdumd64.dll, versie: 8.15.10.2653, tijdstempel: 0x4f3aac44
Uitzonderingscode: 0xc0000005
Foutoffset: 0x000000000030eb06
Id van proces met fout: 0x12d0
Starttijd van toepassing met fout: 0xDllHost.exe0
Pad naar toepassing met fout: DllHost.exe1
Pad naar module met fout: DllHost.exe2
Rapport-id: DllHost.exe3


Error: (11/15/2015 08:17:07 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Naam van toepassing met fout: DllHost.exe, versie: 6.1.7600.16385, tijdstempel: 0x4a5bca54
Naam van module met fout: igdumd64.dll, versie: 8.15.10.2653, tijdstempel: 0x4f3aac44
Uitzonderingscode: 0xc0000005
Foutoffset: 0x000000000030eb06
Id van proces met fout: 0x11e4
Starttijd van toepassing met fout: 0xDllHost.exe0
Pad naar toepassing met fout: DllHost.exe1
Pad naar module met fout: DllHost.exe2
Rapport-id: DllHost.exe3


Error: (11/15/2015 08:01:22 PM) (Source: CVHSVC) (EventID: 100) (User: )
Description: Alleen informatie.
(Patch task for {90140011-0066-0413-0000-0000000FF1CE}): DownloadLatest Failed:


Error: (11/15/2015 07:43:53 PM) (Source: Microsoft-Windows-User Profiles Service) (EventID: 1533) (User: bryan77-PC)
Description: Kan de profielmap C:\Users\AdminPc niet verwijderen. Deze fout wordt mogelijk veroorzaakt door bestanden in deze map, die door een ander programma worden gebruikt.


DETAIL - De map is niet leeg.


Error: (11/15/2015 07:12:26 PM) (Source: CVHSVC) (EventID: 100) (User: )
Description: Alleen informatie.
(Patch task for {90140011-0066-0413-0000-0000000FF1CE}): DownloadLatest Failed:


Error: (11/15/2015 07:02:08 PM) (Source: BstHdAndroidSvc) (EventID: 0) (User: )
Description: Service kan niet worden gestart. System.ApplicationException: Cannot start service. Service did not stop gracefully the last time it was run.
bij BlueStacks.hyperDroid.Service.Service.OnStart(String[] args)
bij System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)




Systeemfouten:
=============
Error: (12/01/2015 10:14:39 AM) (Source: DCOM) (EventID: 10010) (User: )
Description: {078AEF33-C48A-49F7-AFF3-A0EE810BFE7C}


Error: (11/26/2015 01:42:58 AM) (Source: DCOM) (EventID: 10010) (User: )
Description: {995C996E-D918-4A8C-A302-45719A6F4EA7}


Error: (11/21/2015 00:05:11 AM) (Source: DCOM) (EventID: 10010) (User: )
Description: {995C996E-D918-4A8C-A302-45719A6F4EA7}


Error: (11/16/2015 08:28:12 AM) (Source: DCOM) (EventID: 10010) (User: )
Description: {995C996E-D918-4A8C-A302-45719A6F4EA7}


Error: (11/16/2015 03:32:03 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: De Client Virtualization Handler-service is afhankelijk van de Application Virtualization Client-service, die vanwege de volgende fout niet kan worden gestart:
%%1053


Error: (11/16/2015 03:30:53 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: De Application Virtualization Client-service kan vanwege de volgende fout niet worden gestart:
%%1053


Error: (11/16/2015 03:30:53 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Time-out (30000 seconden) tijdens het wachten op het verbinden van deze service: Application Virtualization Client.


Error: (11/16/2015 03:30:23 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: De Windows Live ID Sign-in Assistant-service kan vanwege de volgende fout niet worden gestart:
%%1053


Error: (11/16/2015 03:30:23 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Time-out (30000 seconden) tijdens het wachten op het verbinden van deze service: Windows Live ID Sign-in Assistant.


Error: (11/16/2015 03:29:52 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: De VIA Karaoke digital mixer Service-service kan vanwege de volgende fout niet worden gestart:
%%1053




==================== Geheugen info ===========================


Processor: Intel(R) Pentium(R) CPU B970 @ 2.30GHz
Percentage geheugen in gebruik: 51%
Totaal fysiek RAM-geheugen: 3979.96 MB
Beschikbaar fysiek RAM-geheugen: 1947.18 MB
Totaal Virtueel geheugen: 8258.13 MB
Beschikbaar Virtual geheugen: 5826.17 MB


==================== Schijven ================================


Drive c: (OS) (Fixed) (Total:119.24 GB) (Free:37.24 GB) NTFS ==>[systeem met boot componenten (verkregen van schijf)]
Drive d: (DATA) (Fixed) (Total:153.53 GB) (Free:153.42 GB) NTFS


==================== MBR & Partitietabel ==================


========================================================
Disk: 0 (Size: 298.1 GB) (Disk ID: 30EC77D9)


Partition: GPT.


==================== Eind van Addition.txt ============================


Results of screen317's Security Check version 1.013 --- 11/28/15
Windows 7 Service Pack 1 x64 (UAC is enabled)
Internet Explorer 11
``````````````Antivirus/Firewall Check:``````````````
AVG AntiVirus Free Edition 2014
Antivirus out of date!
`````````Anti-malware/Other Utilities Check:`````````
Java 8 Update 65
Java version 32-bit out of Date!
Adobe Flash Player 10 Flash Player out of Date!
Adobe Reader XI
Google Chrome (46.0.2490.80)
Google Chrome (46.0.2490.86)
````````Process Check: objlist.exe by Laurent````````
AVG avgwdsvc.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C: 0%
````````````````````End of Log``````````````````````
 
Hi, Haramo. Welcome to Sysnative Forums!

Let's see what we can do to get your computer back to normal.

1. Please note that your antivirus software is out of date. You are advised to update AVG to the latest version. Note: It is strongly recommended that you do a custom install and watch each screen since AVG bundles AVG Zen and will also nage you into downloading potentially unwanted programs such as AVG PC TuneUp and AVG Web TuneUp.

2. I note that you have both the 32- and 64-bit versions of Java installed on the computer. You do not need both (and in fact most people do not need Java at all.) Please uninstall one or both of the following:

Java 8 Update 65 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86418065F0}) (Version: 8.0.650.17 - Oracle Corporation)
Java 8 Update 65 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218065F0}) (Version: 8.0.650.17 - Oracle Corporation)

3. Please do the following to run FRST:

Note: If the tool warns you about the version you're using being an outdated version please download and run the updated version.

NOTICE: This script was written specifically for this user. Running it on another machine may cause damage to your operating system
  • Open Notepad (Start =>All Programs => Accessories => Notepad).
  • Copy/Paste the entire contents of the code box below into Notepad.
Code:
start
CreateRestorePoint:
CloseProcesses:
ShortcutWithArgument: C:\Users\bryan77\Desktop\Internet Explorer.lnk -> C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.sweet-page.com/?type=sc&ts=1410798019&from=cor&uid=ST320LT020-9YG142_W0Q4K52MXXXXW0Q4K52M <==== AANDACHT
ShortcutWithArgument: C:\Users\bryan77\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.sweet-page.com/?type=sc&ts=1410798019&from=cor&uid=ST320LT020-9YG142_W0Q4K52MXXXXW0Q4K52M <==== AANDACHT
ShortcutWithArgument: C:\Users\bryan77\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.sweet-page.com/?type=sc&ts=1410798019&from=cor&uid=ST320LT020-9YG142_W0Q4K52MXXXXW0Q4K52M <==== AANDACHT
ShortcutWithArgument: C:\Users\bryan77\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.sweet-page.com/?type=sc&ts=1410798019&from=cor&uid=ST320LT020-9YG142_W0Q4K52MXXXXW0Q4K52M <==== AANDACHT
ShortcutWithArgument: C:\Users\bryan77\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk -> C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.sweet-page.com/?type=sc&ts=1410798019&from=cor&uid=ST320LT020-9YG142_W0Q4K52MXXXXW0Q4K52M <==== AANDACHT
ShortcutWithArgument: C:\Users\bryan77\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.sweet-page.com/?type=sc&ts=1410798019&from=cor&uid=ST320LT020-9YG142_W0Q4K52MXXXXW0Q4K52M <==== AANDACHT
ShortcutWithArgument: C:\Users\bryan77\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.sweet-page.com/?type=sc&ts=1410798019&from=cor&uid=ST320LT020-9YG142_W0Q4K52MXXXXW0Q4K52M <==== AANDACHT
EmptyTemp:
end
  • Click Format and ensure Wordwrap is unchecked.
  • Important: Save the code to the same folder/directory that FRST.exe is located in, naming it as fixlist.txt
  • Start FRST in a similar manner to when you ran a scan earlier, but this time when it opens ....
    • Press the Fix button once and wait.
    • FRST will process fixlist.txt
    • When finished, it will produce a log fixlog.txt in the same folder/directory as FRST64.exe
    • Please post the log in your next reply.

4. Please download AdwCleaner by Xplode and save to your Desktop.
  • Right-click on AdwCleaner.exe and select Run As Administrator
  • The tool will start to update the database, please wait a bit.
  • Click on the Scan button.
  • AdwCleaner will begin. Please be patient as the scan may take some time to complete.
  • After the scan has finished, click on the Clean button.
  • Press OK when asked to close all programs and follow the onscreen prompts.
  • Press OK again to allow AdwCleaner to restart the computer and complete the removal process.
  • After rebooting, a logfile report (AdwCleaner[S#].txt) will open automatically (where the largest value of # represents the most recent report).
  • Copy and paste the contents of that logfile in your next reply.
  • A copy of that logfile will also be saved in the C:\AdwCleaner folder.

5. Please download Junkware Removal Tool to your desktop.
  • Disable your protection software now to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select "Run as Administrator".
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.
 
Fix resultaat van Farbar Recovery Scan Tool (x64) Versie:01-12-2015
Gestart door bryan77 (2015-12-02 13:39:14) Run:1
Gestart vanaf C:\Users\bryan77\Desktop
Geladen Profielen: bryan77 (Beschikbare Profielen: bryan77 & Bryan & Barbara)
Boot Modus: Normal
==============================================


fixlist inhoud:
*****************
start
CreateRestorePoint:
CloseProcesses:
ShortcutWithArgument: C:\Users\bryan77\Desktop\Internet Explorer.lnk -> C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.sweet-page.com/?type=sc&ts=1410798019&from=cor&uid=ST320LT020-9YG142_W0Q4K52MXXXXW0Q4K52M <==== AANDACHT
ShortcutWithArgument: C:\Users\bryan77\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.sweet-page.com/?type=sc&ts=1410798019&from=cor&uid=ST320LT020-9YG142_W0Q4K52MXXXXW0Q4K52M <==== AANDACHT
ShortcutWithArgument: C:\Users\bryan77\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.sweet-page.com/?type=sc&ts=1410798019&from=cor&uid=ST320LT020-9YG142_W0Q4K52MXXXXW0Q4K52M <==== AANDACHT
ShortcutWithArgument: C:\Users\bryan77\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.sweet-page.com/?type=sc&ts=1410798019&from=cor&uid=ST320LT020-9YG142_W0Q4K52MXXXXW0Q4K52M <==== AANDACHT
ShortcutWithArgument: C:\Users\bryan77\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk -> C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.sweet-page.com/?type=sc&ts=1410798019&from=cor&uid=ST320LT020-9YG142_W0Q4K52MXXXXW0Q4K52M <==== AANDACHT
ShortcutWithArgument: C:\Users\bryan77\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.sweet-page.com/?type=sc&ts=1410798019&from=cor&uid=ST320LT020-9YG142_W0Q4K52MXXXXW0Q4K52M <==== AANDACHT
ShortcutWithArgument: C:\Users\bryan77\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.sweet-page.com/?type=sc&ts=1410798019&from=cor&uid=ST320LT020-9YG142_W0Q4K52MXXXXW0Q4K52M <==== AANDACHT
EmptyTemp:
end
*****************


Herstelpunt is succesfol gemaakt.
Proces succesvol afgesloten.
C:\Users\bryan77\Desktop\Internet Explorer.lnk => snelkoppeling argument is succesvol verwijderd..
C:\Users\bryan77\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk => snelkoppeling argument is succesvol verwijderd..
C:\Users\bryan77\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk => snelkoppeling argument met succes hersteld
C:\Users\bryan77\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk => snelkoppeling argument is succesvol verwijderd..
C:\Users\bryan77\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk => snelkoppeling argument is succesvol verwijderd..
C:\Users\bryan77\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk => snelkoppeling argument is succesvol verwijderd..
C:\Users\bryan77\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk => snelkoppeling argument is succesvol verwijderd..
EmptyTemp: => 6.3 GB tijdelijke gegevens verwijderd.




Het systeem moest herstart worden.


==== Eind van Fixlog 13:47:00 ====


# AdwCleaner v5.023 - Logbestand aangemaakt 02/12/2015 op 15:25:38
# Laatste update 30/11/2015 door Xplode
# Database : 2015-11-30.1 [Server]
# Besturingssysteem : Windows 7 Home Premium Service Pack 1 (x64)
# Gebruikersnaam : bryan77 - BRYAN77-PC
# Gestart vanuit : C:\Users\bryan77\Desktop\adwcleaner_5.023.exe
# Optie : Verwijderen
# Ondersteuning : Forum - ToolsLib


***** [ Services ] *****




***** [ Mappen ] *****


[-] Map Verwijderd : C:\ProgramData\AVG Security Toolbar
[-] Map Verwijderd : C:\ProgramData\Avg_Update_0215tb
[-] Map Verwijderd : C:\ProgramData\Avg_Update_0615tb
[-] Map Verwijderd : C:\ProgramData\{d56f2512-cc9e-1e06-d56f-f2512cc9944b}
[-] Map Verwijderd : C:\ProgramData\ddjiaoeajkbgjpckeijaapfbkmpifcpf
[-] Map Verwijderd : C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nafaimnnclfjfedmmabolbppcngeolgf
[-] Map Verwijderd : C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\gafhhbahpojnjfhpepjjfjojbphnogmn
[-] Map Verwijderd : C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\blgkblimeaijgefaoiedchmmemmikpdg
[-] Map Verwijderd : C:\Users\Bryan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Gameo


***** [ Bestanden ] *****


[-] Bestand Verwijderd : C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_nafaimnnclfjfedmmabolbppcngeolgf_0.localstorage
[-] Bestand Verwijderd : C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_nafaimnnclfjfedmmabolbppcngeolgf_0.localstorage-journal
[-] Bestand Verwijderd : C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_gafhhbahpojnjfhpepjjfjojbphnogmn_0.localstorage
[-] Bestand Verwijderd : C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_gafhhbahpojnjfhpepjjfjojbphnogmn_0.localstorage-journal
[-] Bestand Verwijderd : C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_minecraft-server.nl.softonic.com_0.localstorage
[-] Bestand Verwijderd : C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_minecraft-server.nl.softonic.com_0.localstorage-journal
[-] Bestand Verwijderd : C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_minecraft.nl.softonic.com_0.localstorage
[-] Bestand Verwijderd : C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_minecraft.nl.softonic.com_0.localstorage-journal
[-] Bestand Verwijderd : C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_nl.softonic.com_0.localstorage
[-] Bestand Verwijderd : C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_nl.softonic.com_0.localstorage-journal
[-] Bestand Verwijderd : C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_pconverter.dl.myway.com_0.localstorage
[-] Bestand Verwijderd : C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_pconverter.dl.myway.com_0.localstorage-journal
[-] Bestand Verwijderd : C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_pconverter.dl.tb.ask.com_0.localstorage
[-] Bestand Verwijderd : C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_pconverter.dl.tb.ask.com_0.localstorage-journal
[-] Bestand Verwijderd : C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_search.tb.ask.com_0.localstorage
[-] Bestand Verwijderd : C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_search.tb.ask.com_0.localstorage-journal
[-] Bestand Verwijderd : C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www2.inbox.com_0.localstorage
[-] Bestand Verwijderd : C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www2.inbox.com_0.localstorage-journal
[-] Bestand Verwijderd : C:\Users\Bryan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\gameo.lnk
[-] Bestand Verwijderd : C:\Users\Bryan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Play Games Online.url


***** [ DLLs ] *****




***** [ Snelkoppelingen ] *****




***** [ geplande taken ] *****




***** [ Register ] *****


[-] Waarde Verwijderd : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [pcspeedup]
[-] Sleutel Verwijderd : HKLM\SOFTWARE\Classes\PCSU.Registry
[-] Sleutel Verwijderd : HKLM\SOFTWARE\Classes\PCSU.SysUtils
[-] Sleutel Verwijderd : HKLM\SOFTWARE\Classes\PCSU.SysUtils.1
[-] Sleutel Verwijderd : HKLM\SOFTWARE\Classes\PCSU.Registry.1
[-] Sleutel Verwijderd : HKCU\Software\Classes\CLSID\{7A55CBB2-2B2E-4A41-9DE1-6AC5D2C2BE0A}
[-] Sleutel Verwijderd : HKCU\Software\Classes\CLSID\{F28C2F70-47DE-4EA5-8F6D-7D1476CD1EF5}
[-] Sleutel Verwijderd : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
[-] Sleutel Verwijderd : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
[-] Sleutel Verwijderd : HKLM\SOFTWARE\Classes\Interface\{64C4BD7C-A0A5-4753-A507-6ED10DB57A44}
[-] Sleutel Verwijderd : HKLM\SOFTWARE\Classes\Interface\{67866A4D-618A-4E57-BE3E-44E98042F87C}
[-] Sleutel Verwijderd : HKLM\SOFTWARE\Classes\Interface\{7F7B3D8C-F4CE-4A1F-8BB4-B7E191D7D3AF}
[-] Sleutel Verwijderd : HKLM\SOFTWARE\Classes\Interface\{BE6FA26E-397F-4462-8B44-35DA526A3F2F}
[-] Sleutel Verwijderd : HKLM\SOFTWARE\Classes\Interface\{D2E0014A-4C61-4DEF-B7A4-CD16677961C7
}
[-] Sleutel Verwijderd : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
[-] Sleutel Verwijderd : HKLM\SOFTWARE\Classes\TypeLib\{3157E247-2784-4028-BF0F-52D6DDC70E1B}
[-] Sleutel Verwijderd : HKLM\SOFTWARE\Classes\TypeLib\{0B6C9E5C-4E2D-4874-BC84-4A6178E8E179}
[-] Sleutel Verwijderd : HKLM\SOFTWARE\Classes\TypeLib\{6F9AD55C-1BCE-4A69-939D-1A94CD5E1DB8}
[-] Sleutel Verwijderd : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{B2BC04DF-EFBD-409A-95CA-36874E5AB92A}
[-] Waarde Verwijderd : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID [{54E67346-EE5A-45B6-82AA-4F0BB28C79C2}]
[-] Sleutel Verwijderd : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B2BC04DF-EFBD-409A-95CA-36874E5AB92A}
[-] Waarde Verwijderd : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{7A55CBB2-2B2E-4A41-9DE1-6AC5D2C2BE0A}]
[-] Sleutel Verwijderd : [x64] HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
[-] Sleutel Verwijderd : [x64] HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
[-] Sleutel Verwijderd : [x64] HKLM\SOFTWARE\Classes\Interface\{64C4BD7C-A0A5-4753-A507-6ED10DB57A44}
[-] Sleutel Verwijderd : [x64] HKLM\SOFTWARE\Classes\Interface\{67866A4D-618A-4E57-BE3E-44E98042F87C}
[-] Sleutel Verwijderd : [x64] HKLM\SOFTWARE\Classes\Interface\{7F7B3D8C-F4CE-4A1F-8BB4-B7E191D7D3AF}
[-] Sleutel Verwijderd : [x64] HKLM\SOFTWARE\Classes\Interface\{BE6FA26E-397F-4462-8B44-35DA526A3F2F}
[-] Sleutel Verwijderd : [x64] HKLM\SOFTWARE\Classes\Interface\{D2E0014A-4C61-4DEF-B7A4-CD16677961C7}
[-] Sleutel Verwijderd : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B2BC04DF-EFBD-409A-95CA-36874E5AB92A}
[-] Sleutel Verwijderd : HKCU\Software\Softonic
[-] Sleutel Verwijderd : HKCU\Software\Speedchecker Limited
[-] Sleutel Verwijderd : HKCU\Software\Vittalia
[-] Sleutel Verwijderd : HKCU\Software\Avg Secure Update
[-] Sleutel Verwijderd : HKCU\Software\WEBAPP
[-] Sleutel Verwijderd : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{C168639F-5810-4EC8-B1E8-0251AA8A771C}
[-] Sleutel Verwijderd : HKU\.DEFAULT\Software\Avg Secure Update
[-] Sleutel Verwijderd : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\sweet-page.com
[-] Sleutel Verwijderd : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\sweet-page


***** [ Internetbrowsers ] *****


[-] [C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Verwijderd : five-nights-at-freddys-2-demo.en.softonic.com
[-] [C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Verwijderd : minecraft-server.nl.softonic.com
[-] [C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Verwijderd : aaaaahlfahldnilidgnlikdckbfehhca
[-] [C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Verwijderd : aaaaaiabcopkplhgaedhbloeejhhankf
[-] [C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Verwijderd : blgkblimeaijgefaoiedchmmemmikpdg
[-] [C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Verwijderd : ddjiaoeajkbgjpckeijaapfbkmpifcpf
[-] [C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Verwijderd : gafhhbahpojnjfhpepjjfjojbphnogmn
[-] [C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Verwijderd : nafaimnnclfjfedmmabolbppcngeolgf


*************************


:: "Tracing" sleutels verwijderd
:: Winsock instellingen gereset


########## EOF - C:\AdwCleaner\AdwCleaner
Danger

.txt - [9265 bytes] ##########






~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.0.1 (11.24.2015)
Operating System: Windows 7 Home Premium x64
Ran by bryan77 (Administrator) on wo 02-12-2015 at 15:33:01,94
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~








File System: 6


Successfully deleted: C:\Users\bryan77\AppData\Local\{34E5F845-55B9-4A6F-B40D-E30ACC8CD12E} (Empty Folder)
Successfully deleted: C:\Users\bryan77\AppData\Roaming\sp_data.sys (File)
Successfully deleted: C:\Windows\SysWOW64\REN7B4.tmp (File)
Successfully deleted: C:\Windows\SysWOW64\sho3786.tmp (File)
Successfully deleted: C:\Windows\SysWOW64\sho4C77.tmp (File)
Successfully deleted: C:\Windows\SysWOW64\shoF869.tmp (File)






Registry: 3


Successfully deleted: HKLM\SYSTEM\CurrentControlSet\services\0169601385920986mcinstcleanup (Registry Key)
Successfully deleted: HKLM\SYSTEM\CurrentControlSet\services\PCSUUCDRV (Registry Key)
Successfully deleted: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} (Registry Key)








~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on wo 02-12-2015 at 15:36:21,77
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

 
Please download Malwarebytes Anti-Malware and save it to your desktop.
  • Double-click on the setup file (mbam-setup.exe), then click on Run to install. (Note: At the end, Uncheck enable free trial of Malwarebytes' Anti-Malware. You can activate this when we've finished, if you wish)
  • Malwarebytes will automatically open to it's Dashboard. If you have never run this version, you should see a red note at the top indicating "A scan has never been run on your system"
  • Click on Update Now to download the current database definitions, then click the Scan Now >> button.
  • If you have run this version before, you should see a green note at the top indicating "Your system is fully protected".
  • You will be prompted to update Malwarebytes...click on the Update Now button.
  • The THREAT SCAN will automatically begin.
  • When the scan has completed, the results will be displayed. Click on Quarantine All, then click on Apply Actions.
  • To complete any actions taken you will be prompted to restart your computer...click on Yes. Failure to reboot normally will prevent Malwarebytes from removing all the malware.
  • After rebooting the computer, copy and paste the mbam.log in your next reply.
To retrieve the Malwarebytes Anti-Malware scan log information (Method 1)
  • Open Malwarebytes Anti-Malware.
  • Click the History Tab at the top and select Application Logs.
  • Select (check) the box next to Scan Log. Choose the most current scan.
  • Click the View button.
  • Click Copy to Clipboard at the bottom...come back to this thread, click Add Reply, then right-click and choose Paste.
  • Alternatively, you can click Export and save the log as a .txt file on your Desktop or another location.
  • Be sure to post the complete log to include the top portion which shows MBAM's database version and your operating system.
To retrieve the Malwarebytes Anti-Malware 2.0 scan log information (Method 2)
  • Open Malwarebytes Anti-Malware.
  • Click the Scan Tab at the top.
  • Click the View detailed log link on the right.
  • Click Copy to Clipboard at the bottom...come back to this thread, click Add Reply, then right-click and choose Paste.
  • Alternatively, you can click Export and save the log as a .txt file on your Desktop or another location.
  • Be sure to post the complete log to include the top portion which shows MBAM's database version and your operating system.
Logs are named by the date of scan in the following format: mbam-log-yyyy-mm-dd and automatically saved to the following locations:
-- XP: C:\Documents and Settings\<Username>\Application Data\Malwarebytes\Malwarebytes Anti-Malware\Logs\mbam-log-yyyy-mm-dd
-- Vista, Windows 7/8: C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Logs\mbam-log-yyyy-mm-dd

What do you mean about "watch4"?
 
testing posting on this thread, as I could not post the log (results finally in an error, after a window appear if I want to leave to page or not)

Ok posting works, maybe the log is to big? hmm, will divide it and post it

log mbam 1st part

here is the log, laptop still slow


Malwarebytes Anti-Malware
Malwarebytes | Free Anti-Malware & Internet Security Software


Scandatum: 4-12-2015
Scantijd: 14:06
Logboekbestand:
Beheerder: Ja


Versie: 2.2.0.1024
Malware-database: v2015.12.04.02
Rootkit-database: v2015.11.26.01
Licentie: Gratis
Malware-bescherming: Uitgeschakeld
Bescherming tegen kwaadaardige websites: Uitgeschakeld
Zelfbescherming: Uitgeschakeld


Besturingssysteem: Windows 7 Service Pack 1
Processor: x64
Bestandssysteem: NTFS
Gebruiker: bryan77


Scantype: Bedreigingsscan
Resultaat: Voltooid
Objecten gescand: 466639
Verstreken tijd: 40 min, 17 sec


Geheugen: Ingeschakeld
Opstarten: Ingeschakeld
Bestandssysteem: Ingeschakeld
Archieven: Ingeschakeld
Rootkits: Ingeschakeld
Heuristiek: Ingeschakeld
POP: Ingeschakeld
POA: Ingeschakeld


Processen: 0
(Geen kwaadaardige items gedetecteerd)


Modules: 0
(Geen kwaadaardige items gedetecteerd)


Registersleutels: 3
PUP.Optional.MultiPlug, HKU\S-1-5-21-3732487481-855672253-929003311-1001_Classes\TYPELIB\{157B1AA6-3E5C-404A-9118-C1D91F537040}, In quarantaine, [50c28a17ef9c0f27dc0a01c05ca7ba46],
PUP.Optional.MultiPlug, HKU\S-1-5-21-3732487481-855672253-929003311-1001_Classes\INTERFACE\{3B3F3AAD-FB97-49FF-BFEE-D22869AC4326}, In quarantaine, [50c28a17ef9c0f27dc0a01c05ca7ba46],
PUP.Optional.ProductSetup, HKU\S-1-5-21-3732487481-855672253-929003311-1005\SOFTWARE\PRODUCTSETUP, In quarantaine, [14fe0998fc8fdf572167158c62a1f907],


Registerwaarden: 1
PUP.Optional.ProductSetup, HKU\S-1-5-21-3732487481-855672253-929003311-1005\SOFTWARE\PRODUCTSETUP|tb, 0H1N1M, In quarantaine, [14fe0998fc8fdf572167158c62a1f907]


Registerdata: 0
(Geen kwaadaardige items gedetecteerd)


Mappen: 291
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\ar, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\bg, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\ca, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\cs, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\da, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\de, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\el, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\en_GB, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\en_US, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\es, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\es_419, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\et, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\fi, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\fil, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\fr, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\he, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\hi, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\hu, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\id, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\it, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\ja, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\ko, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\lt, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\lv, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\ms, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\nl, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\no, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\pl, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\pt_BR, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\pt_PT, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\ro, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\ru, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\sk, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\sl, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\sr, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\sv, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\th, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\tr, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\uk, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\vi, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\zh_CN, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\zh_TW, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_metadata, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\ar, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\bg, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\ca, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
 
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\cs, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\da, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\de, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\el, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\en_GB, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\en_US, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\es, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\es_419, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\et, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\eu, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\fi, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\fil, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\fr, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\he, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\hi, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\hr, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\hu, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\id, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\it, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\ja, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\ko, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\lt, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\lv, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\ms, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\nl, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\no, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\pl, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\pt_BR, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\pt_PT, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\ro, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\ru, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\sk, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\sl, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\sr, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\sv, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\th, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\tr, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\uk, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\vi, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\zh_CN, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\zh_TW, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_metadata, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0, In quarantaine, [7a98673a048771c58d339b02c242f40c],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\css, In quarantaine, [7a98673a048771c58d339b02c242f40c],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\html, In quarantaine, [7a98673a048771c58d339b02c242f40c],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\images, In quarantaine, [7a98673a048771c58d339b02c242f40c],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales, In quarantaine, [7a98673a048771c58d339b02c242f40c],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\bg, In quarantaine, [7a98673a048771c58d339b02c242f40c],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\ca, In quarantaine, [7a98673a048771c58d339b02c242f40c],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\cs, In quarantaine, [7a98673a048771c58d339b02c242f40c],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\da, In quarantaine, [7a98673a048771c58d339b02c242f40c],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\de, In quarantaine, [7a98673a048771c58d339b02c242f40c],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\el, In quarantaine, [7a98673a048771c58d339b02c242f40c],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\en, In quarantaine, [7a98673a048771c58d339b02c242f40c],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\en_GB, In quarantaine, [7a98673a048771c58d339b02c242f40c],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\es, In quarantaine, [7a98673a048771c58d339b02c242f40c],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\es_419, In quarantaine, [7a98673a048771c58d339b02c242f40c],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\et, In quarantaine, [7a98673a048771c58d339b02c242f40c],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\fi, In quarantaine, [7a98673a048771c58d339b02c242f40c],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\fil, In quarantaine, [7a98673a048771c58d339b02c242f40c],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\fr, In quarantaine, [7a98673a048771c58d339b02c242f40c],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\hi, In quarantaine, [7a98673a048771c58d339b02c242f40c],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\hr, In quarantaine, [7a98673a048771c58d339b02c242f40c],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\hu, In quarantaine, [7a98673a048771c58d339b02c242f40c],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\id, In quarantaine, [7a98673a048771c58d339b02c242f40c],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\it, In quarantaine, [7a98673a048771c58d339b02c242f40c],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\ja, In quarantaine, [7a98673a048771c58d339b02c242f40c],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\ko, In quarantaine, [7a98673a048771c58d339b02c242f40c],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\lt, In quarantaine, [7a98673a048771c58d339b02c242f40c],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\lv, In quarantaine, [7a98673a048771c58d339b02c242f40c],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\nb, In quarantaine, [7a98673a048771c58d339b02c242f40c],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\nl, In quarantaine, [7a98673a048771c58d339b02c242f40c],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\pl, In quarantaine, [7a98673a048771c58d339b02c242f40c],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\pt_BR, In quarantaine, [7a98673a048771c58d339b02c242f40c],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\pt_PT, In quarantaine, [7a98673a048771c58d339b02c242f40c],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\ro, In quarantaine, [7a98673a048771c58d339b02c242f40c],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\ru, In quarantaine, [7a98673a048771c58d339b02c242f40c],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\sk, In quarantaine, [7a98673a048771c58d339b02c242f40c],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\sl, In quarantaine, [7a98673a048771c58d339b02c242f40c],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\sr, In quarantaine, [7a98673a048771c58d339b02c242f40c],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\sv, In quarantaine, [7a98673a048771c58d339b02c242f40c],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\th, In quarantaine, [7a98673a048771c58d339b02c242f40c],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\tr, In quarantaine, [7a98673a048771c58d339b02c242f40c],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\uk, In quarantaine, [7a98673a048771c58d339b02c242f40c],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\vi, In quarantaine, [7a98673a048771c58d339b02c242f40c],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\zh_CN, In quarantaine, [7a98673a048771c58d339b02c242f40c],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\zh_TW, In quarantaine, [7a98673a048771c58d339b02c242f40c],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_metadata, In quarantaine, [7a98673a048771c58d339b02c242f40c],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda, In quarantaine, [7a98673a048771c58d339b02c242f40c],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\ar, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\bg, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\ca, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\cs, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\da, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\de, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\el, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\en, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\en-GB, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\es, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\es-419, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\et, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\fi, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\fil, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\fr, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\hr, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\hu, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\id, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\it, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\iw, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\ja, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\ko, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\lt, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\lv, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\nl, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\no, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\pl, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\pt-BR, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\pt-PT, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\ro, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\ru, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\sk, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\sl, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\sr, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\sv, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\th, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\tr, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\uk, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\vi, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\zh-CN, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\zh-TW, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_metadata, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\hr, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\am, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\ar, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\bg, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\bn, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\ca, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\cs, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\da, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\de, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\el, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\en, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\en_GB, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\en_US, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\es, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\es_419, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\et, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\fa, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\fi, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\fil, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\fr, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\gu, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\he, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\hi, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\hu, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\id, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\it, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\ja, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\kn, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\ko, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\lt, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\lv, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\ml, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\mr, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\ms, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\nl, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\no, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\pl, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\pt_BR, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\pt_PT, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\ro, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\ru, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\sk, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\sl, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\sr, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\sv, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\sw, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\ta, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\te, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\th, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\tr, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\uk, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\vi, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\zh_CN, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\zh_TW, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_metadata, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\css, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\html, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\images, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\bg, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\ca, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\cs, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\da, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\de, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\el, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\en, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\en_GB, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\es, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\es_419, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\et, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\fi, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\fil, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\fr, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\hi, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\hr, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\hu, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\id, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\it, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\ja, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\ko, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\lt, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\lv, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\nb, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\nl, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\pl, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\pt_BR, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\pt_PT, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\ro, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\ru, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\sk, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\sl, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\sr, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\sv, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\th, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\tr, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\uk, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\vi, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\zh_CN, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\zh_TW, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_metadata, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
 
Bestanden: 306
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\manifest.json, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\icon_128.png, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\icon_16.png, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\main.html, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\main.js, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\ar\messages.json, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\bg\messages.json, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\ca\messages.json, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\cs\messages.json, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\da\messages.json, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\de\messages.json, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\el\messages.json, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\en_GB\messages.json, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\en_US\messages.json, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\es\messages.json, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\es_419\messages.json, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\et\messages.json, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\fi\messages.json, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\fil\messages.json, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\fr\messages.json, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\he\messages.json, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\hi\messages.json, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\hu\messages.json, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\id\messages.json, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\it\messages.json, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\ja\messages.json, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\ko\messages.json, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\lt\messages.json, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\lv\messages.json, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\ms\messages.json, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\nl\messages.json, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\no\messages.json, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\pl\messages.json, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\pt_BR\messages.json, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\pt_PT\messages.json, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\ro\messages.json, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\ru\messages.json, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\sk\messages.json, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\sl\messages.json, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\sr\messages.json, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\sv\messages.json, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\th\messages.json, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\tr\messages.json, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\uk\messages.json, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\vi\messages.json, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\zh_CN\messages.json, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\zh_TW\messages.json, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_metadata\computed_hashes.json, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_metadata\verified_contents.json, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\manifest.json, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\128.png, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
 
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\ar\messages.json, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\bg\messages.json, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\ca\messages.json, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\cs\messages.json, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\da\messages.json, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\de\messages.json, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\el\messages.json, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\en_GB\messages.json, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\en_US\messages.json, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\es\messages.json, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\es_419\messages.json, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\et\messages.json, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\eu\messages.json, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\fi\messages.json, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\fil\messages.json, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\fr\messages.json, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\he\messages.json, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\hi\messages.json, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\hr\messages.json, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\hu\messages.json, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\id\messages.json, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\it\messages.json, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\ja\messages.json, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\ko\messages.json, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\lt\messages.json, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\lv\messages.json, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\ms\messages.json, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\nl\messages.json, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\no\messages.json, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\pl\messages.json, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\pt_BR\messages.json, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\pt_PT\messages.json, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\ro\messages.json, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\ru\messages.json, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\sk\messages.json, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\sl\messages.json, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\sr\messages.json, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\sv\messages.json, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\th\messages.json, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\tr\messages.json, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\uk\messages.json, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\vi\messages.json, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\zh_CN\messages.json, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\zh_TW\messages.json, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_metadata\verified_contents.json, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\manifest.json, In quarantaine, [7a98673a048771c58d339b02c242f40c],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\craw_background.js, In quarantaine, [7a98673a048771c58d339b02c242f40c],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\craw_window.js, In quarantaine, [7a98673a048771c58d339b02c242f40c],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\css\craw_window.css, In quarantaine, [7a98673a048771c58d339b02c242f40c],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\html\craw_window.html, In quarantaine, [7a98673a048771c58d339b02c242f40c],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\images\flapper.gif, In quarantaine, [7a98673a048771c58d339b02c242f40c],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\images\icon_128.png, In quarantaine, [7a98673a048771c58d339b02c242f40c],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\images\icon_16.png, In quarantaine, [7a98673a048771c58d339b02c242f40c],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\images\topbar_floating_button.png, In quarantaine, [7a98673a048771c58d339b02c242f40c],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\images\topbar_floating_button_close.png, In quarantaine, [7a98673a048771c58d339b02c242f40c],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\images\topbar_floating_button_hover.png, In quarantaine, [7a98673a048771c58d339b02c242f40c],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\images\topbar_floating_button_maximize.png, In quarantaine, [7a98673a048771c58d339b02c242f40c],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\images\topbar_floating_button_pressed.png, In quarantaine, [7a98673a048771c58d339b02c242f40c],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\bg\messages.json, In quarantaine, [7a98673a048771c58d339b02c242f40c],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\ca\messages.json, In quarantaine, [7a98673a048771c58d339b02c242f40c],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\cs\messages.json, In quarantaine, [7a98673a048771c58d339b02c242f40c],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\da\messages.json, In quarantaine, [7a98673a048771c58d339b02c242f40c],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\de\messages.json, In quarantaine, [7a98673a048771c58d339b02c242f40c],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\el\messages.json, In quarantaine, [7a98673a048771c58d339b02c242f40c],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\en\messages.json, In quarantaine, [7a98673a048771c58d339b02c242f40c],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\en_GB\messages.json, In quarantaine, [7a98673a048771c58d339b02c242f40c],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\es\messages.json, In quarantaine, [7a98673a048771c58d339b02c242f40c],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\es_419\messages.json, In quarantaine, [7a98673a048771c58d339b02c242f40c],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\et\messages.json, In quarantaine, [7a98673a048771c58d339b02c242f40c],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\fi\messages.json, In quarantaine, [7a98673a048771c58d339b02c242f40c],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\fil\messages.json, In quarantaine, [7a98673a048771c58d339b02c242f40c],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\fr\messages.json, In quarantaine, [7a98673a048771c58d339b02c242f40c],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\hi\messages.json, In quarantaine, [7a98673a048771c58d339b02c242f40c],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\hr\messages.json, In quarantaine, [7a98673a048771c58d339b02c242f40c],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\hu\messages.json, In quarantaine, [7a98673a048771c58d339b02c242f40c],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\id\messages.json, In quarantaine, [7a98673a048771c58d339b02c242f40c],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\it\messages.json, In quarantaine, [7a98673a048771c58d339b02c242f40c],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\ja\messages.json, In quarantaine, [7a98673a048771c58d339b02c242f40c],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\ko\messages.json, In quarantaine, [7a98673a048771c58d339b02c242f40c],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\lt\messages.json, In quarantaine, [7a98673a048771c58d339b02c242f40c],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\lv\messages.json, In quarantaine, [7a98673a048771c58d339b02c242f40c],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\nb\messages.json, In quarantaine, [7a98673a048771c58d339b02c242f40c],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\nl\messages.json, In quarantaine, [7a98673a048771c58d339b02c242f40c],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\pl\messages.json, In quarantaine, [7a98673a048771c58d339b02c242f40c],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\pt_BR\messages.json, In quarantaine, [7a98673a048771c58d339b02c242f40c],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\pt_PT\messages.json, In quarantaine, [7a98673a048771c58d339b02c242f40c],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\ro\messages.json, In quarantaine, [7a98673a048771c58d339b02c242f40c],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\ru\messages.json, In quarantaine, [7a98673a048771c58d339b02c242f40c],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\sk\messages.json, In quarantaine, [7a98673a048771c58d339b02c242f40c],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\sl\messages.json, In quarantaine, [7a98673a048771c58d339b02c242f40c],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\sr\messages.json, In quarantaine, [7a98673a048771c58d339b02c242f40c],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\sv\messages.json, In quarantaine, [7a98673a048771c58d339b02c242f40c],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\th\messages.json, In quarantaine, [7a98673a048771c58d339b02c242f40c],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\tr\messages.json, In quarantaine, [7a98673a048771c58d339b02c242f40c],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\uk\messages.json, In quarantaine, [7a98673a048771c58d339b02c242f40c],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\vi\messages.json, In quarantaine, [7a98673a048771c58d339b02c242f40c],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\zh_CN\messages.json, In quarantaine, [7a98673a048771c58d339b02c242f40c],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\zh_TW\messages.json, In quarantaine, [7a98673a048771c58d339b02c242f40c],
PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_metadata\verified_contents.json, In quarantaine, [7a98673a048771c58d339b02c242f40c],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\manifest.json, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\128.png, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\16.png, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\ar\messages.json, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\bg\messages.json, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\ca\messages.json, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\cs\messages.json, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\da\messages.json, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\de\messages.json, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\el\messages.json, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\en\messages.json, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\en-GB\messages.json, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\es\messages.json, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\es-419\messages.json, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\et\messages.json, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\fi\messages.json, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\fil\messages.json, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\fr\messages.json, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\hr\messages.json, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\hu\messages.json, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\id\messages.json, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\it\messages.json, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\iw\messages.json, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\ja\messages.json, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\ko\messages.json, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\lt\messages.json, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\lv\messages.json, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\nl\messages.json, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\no\messages.json, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\pl\messages.json, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\pt-BR\messages.json, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\pt-PT\messages.json, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\ro\messages.json, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\ru\messages.json, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\sk\messages.json, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\sl\messages.json, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\sr\messages.json, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\sv\messages.json, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\th\messages.json, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\tr\messages.json, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\uk\messages.json, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\vi\messages.json, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\zh-CN\messages.json, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\zh-TW\messages.json, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_metadata\verified_contents.json, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\manifest.json, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\icon_128.png, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\hr\messages.json, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\am\messages.json, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\ar\messages.json, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\bg\messages.json, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\bn\messages.json, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\ca\messages.json, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\cs\messages.json, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\da\messages.json, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\de\messages.json, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\el\messages.json, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\en\messages.json, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\en_GB\messages.json, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\en_US\messages.json, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\es\messages.json, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\es_419\messages.json, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\et\messages.json, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\fa\messages.json, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\fi\messages.json, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\fil\messages.json, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\fr\messages.json, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\gu\messages.json, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\he\messages.json, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\hi\messages.json, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\hu\messages.json, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\id\messages.json, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\it\messages.json, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\ja\messages.json, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\kn\messages.json, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\ko\messages.json, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\lt\messages.json, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\lv\messages.json, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\ml\messages.json, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\mr\messages.json, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\ms\messages.json, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\nl\messages.json, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\no\messages.json, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\pl\messages.json, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\pt_BR\messages.json, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\pt_PT\messages.json, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\ro\messages.json, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\ru\messages.json, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\sk\messages.json, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\sl\messages.json, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\sr\messages.json, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\sv\messages.json, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\sw\messages.json, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\ta\messages.json, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\te\messages.json, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\th\messages.json, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\tr\messages.json, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\uk\messages.json, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\vi\messages.json, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\zh_CN\messages.json, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\zh_TW\messages.json, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_metadata\verified_contents.json, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\manifest.json, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\craw_background.js, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\craw_window.js, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\css\craw_window.css, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\html\craw_window.html, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\images\flapper.gif, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\images\icon_128.png, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\images\icon_16.png, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\images\topbar_floating_button.png, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\images\topbar_floating_button_close.png, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\images\topbar_floating_button_hover.png, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\images\topbar_floating_button_maximize.png, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\images\topbar_floating_button_pressed.png, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\bg\messages.json, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\ca\messages.json, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\cs\messages.json, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\da\messages.json, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\de\messages.json, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\el\messages.json, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\en\messages.json, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\en_GB\messages.json, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\es\messages.json, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\es_419\messages.json, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\et\messages.json, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\fi\messages.json, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\fil\messages.json, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\fr\messages.json, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\hi\messages.json, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\hr\messages.json, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\hu\messages.json, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\id\messages.json, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\it\messages.json, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\ja\messages.json, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\ko\messages.json, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\lt\messages.json, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\lv\messages.json, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\nb\messages.json, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\nl\messages.json, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\pl\messages.json, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\pt_BR\messages.json, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\pt_PT\messages.json, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\ro\messages.json, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\ru\messages.json, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\sk\messages.json, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\sl\messages.json, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\sr\messages.json, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\sv\messages.json, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\th\messages.json, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\tr\messages.json, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\uk\messages.json, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\vi\messages.json, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\zh_CN\messages.json, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\zh_TW\messages.json, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_metadata\verified_contents.json, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],


Fysieke Sectoren: 0
(Geen kwaadaardige items gedetecteerd)




(end)
 
Malwarebytes didn't detect any malicious items, rather PUPs (Potentially Unwaned Programs). What I don't normally see are installed files in multiple languages as shown in your log. Dutch fits but have you intentionally installed Hebrew, Arabic, Russian and Chinese versions on your computer?

Συλλογή φωτογραφιών (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Основные компоненты Windows Live (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Почта Windows Live (x32 Version: 16.4.3508.0205 - Корпорация Майкрософт) Hidden
Фотоальбом (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Фотографии (общедоступная версия) (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
גלריית התמונות (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
بريد Windows Live (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
معرض الصور (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
影像中心 (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden

What can you tell me about "The Simpsons Tapped Out Packages (HKU\S-1-5-21-3732487481-855672253-929003311-1001\...\The Simpsons Tapped Out Packages) (Version: - )"? As it appears there is some question regarding the program and it is suggested that you uninstall it.

Let's see what an online scan shows. Please follow the instructions below to run an on-line scan from ESET.
  • Note: It is easiest if you use Internet explorer for this scan. (If you use an alternate browser, it will be necessary to download the ESET Smart Installer)
    • Hold down Control and click on this link to open ESET OnlineScan in a new window so you can refer to these instructions.
    • Click the green ESET Online Scanner box.
    • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
      • Click on esetsmartinstaller_enu.exe to download the ESET Smart Installer. Save it to your desktop.
      • Double click on the Eset Smart Installer icon on your desktop.
    • Check "YES, I accept the Terms of Use."
    • Click the Start button.
    • Accept any security warnings from your browser.
    • Under scan settings, check "Scan Archives" and "Remove found threats"
    • Click Advanced settings and select the following:
      • Scan potentially unwanted applications
      • Scan for potentially unsafe applications
      • Enable Anti-Stealth technology
    • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
    • When the scan completes, click List Threats
    • Click Export, and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
    • Click the Back button.
    • Click the Finish button.
 
No no other languases installed intentionally.

he Simpsons Tapped Out Packages: I tried to uninstall in control panal, remove programs, when I click to uninstall, a window appears that are is an error with this app and it's possible it is already uninstalled, so I had the choise to delete it from the list. Hope that's enough?

Probably the children installed, it, laptop normally only used for school tasks or facebook, hotmail, social media.

eset online is scanning now, will post log if finished.
 
eset log only one line:

C:\Users\bryan77\AppData\LocalLow\Sun\Java\jre1.7.0_67\java_sp.dll a variant of Win32/Bundled.Toolbar.Ask.M potentially unsafe application cleaned by deleting - quarantined
 
Thank you.

Let's have FRST create a restore point and remove the various language versions of Photo Gallery, etc. I'll also include Simpsons, just in case it is still there and hidden. I'll provide instructions following that for fresh FRST logs. Although, please let me know if there is any improvement.

1. Please do the following to run FRST:

Note: If the tool warns you about the version you're using being an outdated version please download and run the updated version.

NOTICE: This script was written specifically for this user. Running it on another machine may cause damage to your operating system
  • Open Notepad (Start =>All Programs => Accessories => Notepad).
  • Copy/Paste the entire contents of the code box below into Notepad.
Code:
start
CreateRestorePoint:
CloseProcesses:
The Simpsons Tapped Out Packages (HKU\S-1-5-21-3732487481-855672253-929003311-1001\...\The Simpsons Tapped Out Packages) (Version: - ) <==== AANDACHT
Συλλογή φωτογραφιών (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Основные компоненты Windows Live (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Почта Windows Live (x32 Version: 16.4.3508.0205 - Корпорация Майкрософт) Hidden
Фотоальбом (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Фотографии (общедоступная версия) (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
גלריית התמונות (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
بريد Windows Live (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
معرض الصور (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
影像中心 (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
EmptyTemp:
end
  • Click Format and ensure Wordwrap is unchecked.
  • Important: Save the code to the same folder/directory that FRST.exe is located in, naming it as fixlist.txt
  • Start FRST in a similar manner to when you ran a scan earlier, but this time when it opens ....
    • Press the Fix button once and wait.
    • FRST will process fixlist.txt
    • When finished, it will produce a log fixlog.txt in the same folder/directory as FRST64.exe
    • Please post the log in your next reply.

2. Please note the instructions below and provide a fresh FRST scan.
  • Right click to run as administrator. When the tool opens click Yes to disclaimer.
  • Note: After FRST completes updating and the tool appears, check the box next to Addition.txt under the "Optional Scan" section
  • Press Scan button.
  • Please copy/paste both logs in your reply.
 
when I want to save the fixlist txt file, after copy to it the code, it says that the file contains characters in unicode that will be lost if I save this file as a ANSI textfile.

If I select cancel, I can save the document myself and change the code ANSI to Unicode.
Do I need to change code that text is saved to from ANSI to Unicode?
 
I saved text file as unicode in place of ANSI code, thaught to give it a try, FRST fix seemed to work so it's ok.

fixlist log reports that for the simpsons it found no automatc fix.

Fix resultaat van Farbar Recovery Scan Tool (x64) Versie:05-12-2015
Gestart door bryan77 (2015-12-05 22:50:30) Run:2
Gestart vanaf C:\Users\bryan77\Desktop
Geladen Profielen: bryan77 (Beschikbare Profielen: bryan77 & Bryan & Barbara)
Boot Modus: Normal
==============================================


fixlist inhoud:
*****************
start
CreateRestorePoint:
CloseProcesses:
The Simpsons Tapped Out Packages (HKU\S-1-5-21-3732487481-855672253-929003311-1001\...\The Simpsons Tapped Out Packages) (Version: - ) <==== AANDACHT
Συλλογή φωτογραφιών (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Основные компоненты Windows Live (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Почта Windows Live (x32 Version: 16.4.3508.0205 - Корпорация Майкрософт) Hidden
Фотоальбом (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Фотографии (общедоступная версия) (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
גלריית התמונות (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
بريد Windows Live (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
معرض الصور (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
影像中心 (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
EmptyTemp:
end
*****************


Herstelpunt is succesfol gemaakt.
Proces succesvol afgesloten.
The Simpsons Tapped Out Packages (HKU\S-1-5-21-3732487481-855672253-929003311-1001\...\The Simpsons Tapped Out Packages) (Version: - ) <==== AANDACHT => Fout: Geen automatische fix gevonden voor dit item.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{032CB0D7-FDBF-4CA9-901B-A4C1B01B1777}\\SystemComponent => waarde is succesvol verwijderd.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{7A9122B2-CF90-4ACB-8E10-AA83F725916B}\\SystemComponent => waarde is succesvol verwijderd.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{44B4333A-60A6-4FFC-BCC5-B0ECA23D2AAB}\\SystemComponent => waarde is succesvol verwijderd.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{CE4EEFE0-85E0-436E-95C5-BCB2EE30C976}\\SystemComponent => waarde is succesvol verwijderd.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{234BD64C-99F4-42B5-837F-82F00E37A7E1}\\SystemComponent => waarde is succesvol verwijderd.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{B1AC8AF0-2979-4DF8-AE26-B1D543F3543F}\\SystemComponent => waarde is succesvol verwijderd.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{7A546E5C-0906-42CC-92DF-B2E787FFA7D2}\\SystemComponent => waarde is succesvol verwijderd.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{6F77C156-7660-4CEC-8793-97D80D5BFEC0}\\SystemComponent => waarde is succesvol verwijderd.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{7DB15F28-5E38-476A-A773-EA07EAEAB1B3}\\SystemComponent => waarde is succesvol verwijderd.
EmptyTemp: => 1.3 GB tijdelijke gegevens verwijderd.




Het systeem moest herstart worden.


==== Eind van Fixlog 22:51:24 ====
 
Scanresultaten van Farbar Recovery Scan Tool (FRST) (x64) Versie:05-12-2015
Gestart door bryan77 (Beheerder) op BRYAN77-PC (05-12-2015 23:03:20)
Gestart vanaf C:\Users\bryan77\Desktop
Geladen Profielen: bryan77 (Beschikbare Profielen: bryan77 & Bryan & Barbara)
Platform: Windows 7 Home Premium Service Pack 1 (X64) Taal: Nederlands (Nederland)
Internet Explorer Versie 11 (Standaardbrowser: Chrome)
Boot Modus: Normal
Handleiding voor Farbar Recovery Scan Tool: FRST Tutorial - How to use Farbar Recovery Scan Tool - Malware Removal Guides and Tutorials


==================== Processen (gefilterd) =================


(Als een item is opgenomen in de fixlist, het proces zal worden gesloten. Het bestand zal niet worden verplaatst.)


(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgrsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgcsrva.exe
(Microsoft Corporation) C:\Windows\System32\wisptis.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
(ASUS) C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnSrv.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgidsagent.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgwdsvcx.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
() C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(VIA Technologies, Inc.) C:\Windows\System32\ViakaraokeSrv.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgnsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgemca.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Desktop.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
(ASUS) C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnWMI.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ATKOSD.exe
(Microsoft Corporation) C:\Windows\System32\wisptis.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\WDC.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe
(ASUS) C:\Program Files\ASUS\P4G\BatteryLife.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\FaceLogon\sensorsrv.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Virtual Touch\QuickGesture\x64\QuickGesture64.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Virtual Touch\QuickGesture\x86\QuickGesture.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
(Alcor Micro Corp.) C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe
(ASUS) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Nico Mak Computing) C:\Program Files\File Association Helper\FAHWindow.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(VIA) C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgui.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Framework\Common\avguix.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(ASUSTeK) C:\Windows\SysWOW64\ACEngSvr.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_w32.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_x64.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDGesture.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\ink\InputPersonalization.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe




==================== Register (gefilterd) ===========================


(Als een item is opgenomen in de fixlist, het registry item zal worden teruggezet naar de standaardwaarden of verwijderd. Het bestand zal niet worden verplaatst.)


HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2661672 2012-05-14] (ELAN Microelectronics Corp.)
HKLM\...\Run: [AmIcoSinglun64] => C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe [361984 2011-03-21] (Alcor Micro Corp.)
HKLM\...\Run: [ACMON] => C:\Program Files (x86)\ASUS\Splendid\ACMON.exe [90792 2012-05-08] (ASUS)
HKLM\...\Run: [FAHConsole] => C:\Program Files\File Association Helper\FAHConsole.exe [729272 2014-01-28] (Nico Mak Computing)
HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291608 2012-02-07] (Intel Corporation)
HKLM-x32\...\Run: [HDAudDeck] => C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [5142128 2012-04-19] (VIA)
HKLM-x32\...\Run: [ATKOSD2] => C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [318080 2011-12-23] (ASUSTek Computer Inc.)
HKLM-x32\...\Run: [ATKMEDIA] => C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [174720 2011-10-25] (ASUS)
HKLM-x32\...\Run: [HControlUser] => C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [105016 2009-06-19] (ASUS)
HKLM-x32\...\Run: [ASUSWebStorage] => C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.108.222\AsusWSPanel.exe [737104 2011-07-29] (ecareme)
HKLM-x32\...\Run: [CLMLServer] => C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe [107816 2010-08-20] (CyberLink)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-10-28] (Hewlett-Packard)
HKLM-x32\...\Run: [AVG_UI] => C:\Program Files (x86)\AVG\Av\avgui.exe [3855272 2015-11-20] (AVG Technologies CZ, s.r.o.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [597040 2015-10-06] (Oracle Corporation)
HKLM-x32\...\Run: [AvgUi] => C:\Program Files (x86)\AVG\Framework\Common\avguix.exe [1136552 2015-11-12] (AVG Technologies CZ, s.r.o.)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
ShellIconOverlayIdentifiers: [###MegaShellExtPending] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => C:\Users\Bryan\AppData\Local\MEGAsync\ShellExtX64.dll Geen bestand
ShellIconOverlayIdentifiers: [###MegaShellExtSynced] -> {05B38830-F4E9-4329-978B-1DD28605D202} => C:\Users\Bryan\AppData\Local\MEGAsync\ShellExtX64.dll Geen bestand
ShellIconOverlayIdentifiers: [###MegaShellExtSyncing] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => C:\Users\Bryan\AppData\Local\MEGAsync\ShellExtX64.dll Geen bestand
ShellIconOverlayIdentifiers: [AsusWSShellExt_B] -> {6D4133E5-0742-4ADC-8A8C-9303440F7190} => C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.108.222\ASUSWSShellExt64.dll [2011-05-25] (eCareme Technologies, Inc.)
ShellIconOverlayIdentifiers: [AsusWSShellExt_O] -> {64174815-8D98-4CE6-8646-4C039977D808} => C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.108.222\ASUSWSShellExt64.dll [2011-05-25] (eCareme Technologies, Inc.)
ShellIconOverlayIdentifiers-x32: [###MegaShellExtPending] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => C:\Users\Bryan\AppData\Local\MEGAsync\ShellExtX32.dll Geen bestand
ShellIconOverlayIdentifiers-x32: [###MegaShellExtSynced] -> {05B38830-F4E9-4329-978B-1DD28605D202} => C:\Users\Bryan\AppData\Local\MEGAsync\ShellExtX32.dll Geen bestand
ShellIconOverlayIdentifiers-x32: [###MegaShellExtSyncing] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => C:\Users\Bryan\AppData\Local\MEGAsync\ShellExtX32.dll Geen bestand
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AsusVibeLauncher.lnk [2012-02-24]
ShortcutTarget: AsusVibeLauncher.lnk -> C:\Program Files (x86)\ASUS\AsusVibe\AsusVibeLauncher.exe (ASUSTeK Computer Inc.)


==================== Internet (gefilterd) ====================


(Als een item is opgenomen in de fixlist, als het een registry item is wordt verwijderd of hersteld naar de standaard.)


Tcpip\Parameters: [DhcpNameServer] 195.130.131.4 195.130.130.132
Tcpip\..\Interfaces\{954017FF-42DA-42FD-84E1-ECB55673A792}: [DhcpNameServer] 195.130.131.4 195.130.130.132
Tcpip\..\Interfaces\{B7BD57C6-76C0-4AB4-AC64-4D8C834D3915}: [DhcpNameServer] 195.130.131.4 195.130.130.132


Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617912&ResetID=130892591560222338&GUID=D4782CC4-99AC-4097-BD5E-2E9FF6B401FD
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617912&ResetID=130892591560242339&GUID=D4782CC4-99AC-4097-BD5E-2E9FF6B401FD
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Google
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = Google
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = Google
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = Google
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Google
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = Google
HKU\S-1-5-21-3732487481-855672253-929003311-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617912&ResetID=130892591573953123&GUID=D4782CC4-99AC-4097-BD5E-2E9FF6B401FD
SearchScopes: HKLM -> DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSERBM&pc=MSERT1
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=ASUTDF&pc=NP06&src=IE-SearchBox
SearchScopes: HKLM -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSERBM&pc=MSERT1
SearchScopes: HKLM-x32 -> DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSERBM&pc=MSERT1
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=ASUTDF&pc=NP06&src=IE-SearchBox
SearchScopes: HKLM-x32 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSERBM&pc=MSERT1
SearchScopes: HKU\S-1-5-21-3732487481-855672253-929003311-1001 -> DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSERBM&pc=MSERT1
SearchScopes: HKU\S-1-5-21-3732487481-855672253-929003311-1001 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSERBM&pc=MSERT1
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_65\bin\ssv.dll [2015-10-24] (Oracle Corporation)
BHO-x32: Aanmeldhulp voor Microsoft-account -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_65\bin\jp2ssv.dll [2015-10-24] (Oracle Corporation)
Toolbar: HKU\S-1-5-21-3732487481-855672253-929003311-1001 -> Geen Naam - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - Geen bestand
DPF: HKLM-x32 {4B54A9DE-EF1C-4EBE-A328-7C28EA3B433A} hxxp://quickscan.bitdefender.com/qsax/qsax.cab
DPF: HKLM-x32 {7530BFB8-7293-4D34-9923-61A11451AFC5} hxxp://download.eset.com/special/eos/OnlineScanner.cab
StartMenuInternet: IEXPLORE.EXE - iexplore.exe


FireFox:
========
FF Plugin: @microsoft.com/GENUINE -> disabled [Geen bestand]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-01-06] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-01-06] (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.65.2 -> C:\Program Files (x86)\Java\jre1.8.0_65\bin\dtplugin\npDeployJava1.dll [2015-10-24] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.65.2 -> C:\Program Files (x86)\Java\jre1.8.0_65\bin\plugin2\npjp2.dll [2015-10-24] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [Geen bestand]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2013-02-05] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3508.0205 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2013-02-05] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-02] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-02] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-09-27] (Adobe Systems Inc.)


Chrome:
=======
CHR Profile: C:\Users\bryan77\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Betalingen via Chrome Web Store) - C:\Users\bryan77\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-07-30]


==================== Services (gefilterd) ========================


(Als een item is opgenomen in de fixlist, wordt uit het register verwijderd. Het bestand zal niet worden verplaatst tenzij apart vermeld.)


R2 ASUS InstantOn; C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnSrv.exe [277120 2012-04-13] (ASUS)
S3 AvgAMPS; C:\Program Files (x86)\AVG\Av\avgamps.exe [615584 2015-11-20] (AVG Technologies CZ, s.r.o.)
R2 AVGIDSAgent; C:\Program Files (x86)\AVG\Av\avgidsagent.exe [3857272 2015-11-20] (AVG Technologies CZ, s.r.o.)
R2 avgsvc; C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe [1046952 2015-11-12] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files (x86)\AVG\Av\avgwdsvcx.exe [579776 2015-11-20] (AVG Technologies CZ, s.r.o.)
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [128280 2012-02-21] ()
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [161560 2012-02-21] (Intel Corporation)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1135416 2015-10-05] (Malwarebytes)
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [5702416 2015-09-11] (TeamViewer GmbH)
R2 VIAKaraokeService; C:\Windows\system32\viakaraokesrv.exe [27760 2012-03-23] (VIA Technologies, Inc.)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)


===================== Drivers (gefilterd) ==========================


(Als een item is opgenomen in de fixlist, wordt uit het register verwijderd. Het bestand zal niet worden verplaatst tenzij apart vermeld.)


R3 AsusVBus; C:\Windows\System32\DRIVERS\AsusVBus.sys [35968 2012-04-12] (Windows (R) Win 7 DDK provider)
R3 AsusVTouch; C:\Windows\System32\DRIVERS\AsusVTouch.sys [16512 2012-04-12] (Windows (R) Win 7 DDK provider)
R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [184240 2015-11-06] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [313776 2015-11-06] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [298416 2015-08-20] (AVG Technologies CZ, s.r.o.)
R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [284080 2015-10-21] (AVG Technologies CZ, s.r.o.)
R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [398256 2015-08-14] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [256432 2015-11-06] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [42416 2015-08-10] (AVG Technologies CZ, s.r.o.)
R1 Avgtdia; C:\Windows\System32\DRIVERS\avgtdia.sys [302000 2015-10-08] (AVG Technologies CZ, s.r.o.)
S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [15416 2009-07-20] ( )
R3 L1C; C:\Windows\System32\DRIVERS\L1C62x64.sys [104560 2012-04-25] (Qualcomm Atheros Co., Ltd.)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-10-05] (Malwarebytes)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-10-05] (Malwarebytes Corporation)


==================== NetSvcs (gefilterd) ===================


(Als een item is opgenomen in de fixlist, wordt uit het register verwijderd. Het bestand zal niet worden verplaatst tenzij apart vermeld.)




==================== Een Maand Aangemaakt bestanden en mappen ========


(Als een item is opgenomen in de fixlist, het bestand/map wordt verplaatst.)


2015-12-05 22:50 - 2015-12-05 22:50 - 00000000 ____D C:\Users\bryan77\Desktop\FRST-OlderVersion
2015-12-05 08:53 - 2015-12-05 08:53 - 00000000 ___HD C:\Windows\AxInstSV
2015-12-04 20:25 - 2015-12-04 20:25 - 00000000 ____D C:\Users\Bryan\AppData\Roaming\AVG
2015-12-04 14:05 - 2015-12-04 15:23 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-12-04 14:04 - 2015-12-04 14:04 - 00001104 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-12-04 14:04 - 2015-12-04 14:04 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-12-04 14:04 - 2015-12-04 14:04 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-12-04 14:04 - 2015-10-05 09:50 - 00109272 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-12-04 14:04 - 2015-10-05 09:50 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-12-04 14:04 - 2015-10-05 09:50 - 00025816 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
2015-12-04 14:02 - 2015-12-05 23:03 - 00000380 _____ C:\Users\bryan77\AppData\Roaming\sp_data.sys
2015-12-03 12:30 - 2015-12-03 12:30 - 00000000 ____D C:\Users\Barbara.bryan77-PC\AppData\Roaming\AVG
2015-12-02 15:36 - 2015-12-02 15:36 - 00001325 _____ C:\Users\bryan77\Desktop\JRT.txt
2015-12-02 15:30 - 2015-12-02 15:30 - 01599336 _____ (Malwarebytes) C:\Users\bryan77\Desktop\JRT.exe
2015-12-02 14:44 - 2015-12-02 14:44 - 01736704 _____ C:\Users\bryan77\Downloads\adwcleaner_5.023 (1).exe
2015-12-02 14:44 - 2015-12-02 14:44 - 01736704 _____ C:\Users\bryan77\Desktop\adwcleaner_5.023.exe
2015-12-02 14:26 - 2015-12-02 14:26 - 00000000 ____D C:\Users\bryan77\AppData\Roaming\AVG
2015-12-02 14:21 - 2015-12-02 14:21 - 00000936 _____ C:\Users\Public\Desktop\AVG.lnk
2015-12-02 14:21 - 2015-12-02 14:21 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG Zen
2015-12-02 14:20 - 2015-12-02 14:24 - 00000000 ____D C:\ProgramData\Avg
2015-12-02 14:19 - 2015-12-02 14:19 - 02970984 _____ (AVG Technologies CZ, s.r.o.) C:\Users\bryan77\Desktop\AVG_Protection_Free_698.exe
2015-12-02 13:41 - 2015-12-02 14:21 - 00000000 ____D C:\Users\bryan77\AppData\Local\AvgSetupLog
2015-12-02 13:39 - 2015-12-05 22:51 - 00003289 _____ C:\Users\bryan77\Desktop\Fixlog.txt
2015-12-02 13:36 - 2015-10-24 10:20 - 00097888 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2015-12-01 21:48 - 2015-12-01 21:49 - 00035072 _____ C:\Users\bryan77\Desktop\Addition.txt
2015-12-01 21:48 - 2015-12-01 21:48 - 00852771 _____ C:\Users\bryan77\Desktop\SecurityCheck.exe
2015-12-01 21:47 - 2015-12-05 23:05 - 00019628 _____ C:\Users\bryan77\Desktop\FRST.txt
2015-12-01 21:46 - 2015-12-05 23:03 - 00000000 ____D C:\FRST
2015-12-01 21:45 - 2015-12-05 22:50 - 02369024 _____ (Farbar) C:\Users\bryan77\Desktop\FRST64.exe
2015-12-01 21:45 - 2015-12-05 11:22 - 00000000 ____D C:\Users\bryan77\Desktop\uitgevoerde stappen
2015-12-01 21:44 - 2015-12-01 21:44 - 02350080 _____ (Farbar) C:\Users\bryan77\Downloads\FRST64.exe
2015-11-22 14:44 - 2015-11-22 14:44 - 00000000 ____D C:\Users\Bryan\AppData\Roaming\Sun
2015-11-22 14:29 - 2015-11-22 14:29 - 00000000 ____D C:\Users\Barbara.bryan77-PC\AppData\Local\AvgSetupLog
2015-11-21 16:10 - 2015-11-21 16:10 - 00679936 _____ C:\Users\Bryan\Downloads\Detection (10).msi
2015-11-15 20:44 - 2015-11-15 11:44 - 00159444 ____N C:\Users\Barbara.bryan77-PC\Desktop\Kasverkoop nr 128 - 06-11-2015- Barbara Verbist.pdf
2015-11-15 20:36 - 2015-11-15 20:36 - 00001376 _____ C:\Users\bryan77\Desktop\Photo Gallery.lnk
2015-11-15 20:34 - 2015-11-15 20:34 - 00001116 _____ C:\Users\bryan77\Desktop\Afbeeldingen - Snelkoppeling.lnk
2015-11-15 19:43 - 2015-11-15 19:43 - 00000000 ____D C:\Users\bryan77\Desktop\AdminPc
2015-11-15 19:36 - 2015-11-03 18:55 - 03211264 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-11-15 19:35 - 2015-10-20 19:42 - 03168768 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2015-11-15 19:35 - 2015-10-20 19:42 - 02608128 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2015-11-15 19:35 - 2015-10-20 19:42 - 00696320 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2015-11-15 19:35 - 2015-10-20 19:42 - 00192512 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2015-11-15 19:35 - 2015-10-20 19:42 - 00098816 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2015-11-15 19:35 - 2015-10-20 19:42 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2015-11-15 19:35 - 2015-10-20 19:42 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2015-11-15 19:35 - 2015-10-20 19:41 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2015-11-15 19:35 - 2015-10-20 19:41 - 00091136 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
2015-11-15 19:35 - 2015-10-20 19:41 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2015-11-15 19:35 - 2015-10-20 19:41 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll
2015-11-15 19:35 - 2015-10-20 18:46 - 00566784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2015-11-15 19:35 - 2015-10-20 18:46 - 00174080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2015-11-15 19:35 - 2015-10-20 18:46 - 00093696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2015-11-15 19:35 - 2015-10-20 18:46 - 00030208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2015-11-15 19:35 - 2015-10-20 18:45 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2015-11-15 19:34 - 2015-11-03 23:10 - 00390344 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-11-15 19:34 - 2015-11-03 22:51 - 00342728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2015-11-15 19:34 - 2015-10-31 00:46 - 25818624 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-11-15 19:34 - 2015-10-31 00:40 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-11-15 19:34 - 2015-10-31 00:40 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2015-11-15 19:34 - 2015-10-31 00:25 - 02886656 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-11-15 19:34 - 2015-10-31 00:25 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-11-15 19:34 - 2015-10-31 00:25 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2015-11-15 19:34 - 2015-10-31 00:25 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2015-11-15 19:34 - 2015-10-31 00:24 - 00585728 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-11-15 19:34 - 2015-10-31 00:24 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2015-11-15 19:34 - 2015-10-31 00:17 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-11-15 19:34 - 2015-10-31 00:16 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2015-11-15 19:34 - 2015-10-31 00:13 - 00616960 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-11-15 19:34 - 2015-10-31 00:12 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-11-15 19:34 - 2015-10-31 00:12 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2015-11-15 19:34 - 2015-10-31 00:11 - 05990912 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-11-15 19:34 - 2015-10-31 00:11 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-11-15 19:34 - 2015-10-31 00:11 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2015-11-15 19:34 - 2015-10-31 00:04 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2015-11-15 19:34 - 2015-10-31 00:01 - 00489984 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-11-15 19:34 - 2015-10-30 23:58 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2015-11-15 19:34 - 2015-10-30 23:53 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-11-15 19:34 - 2015-10-30 23:52 - 20331520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2015-11-15 19:34 - 2015-10-30 23:49 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2015-11-15 19:34 - 2015-10-30 23:49 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-11-15 19:34 - 2015-10-30 23:47 - 00504832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2015-11-15 19:34 - 2015-10-30 23:46 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-11-15 19:34 - 2015-10-30 23:46 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2015-11-15 19:34 - 2015-10-30 23:45 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2015-11-15 19:34 - 2015-10-30 23:45 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2015-11-15 19:34 - 2015-10-30 23:44 - 00152064 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2015-11-15 19:34 - 2015-10-30 23:44 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2015-11-15 19:34 - 2015-10-30 23:42 - 02279936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2015-11-15 19:34 - 2015-10-30 23:39 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2015-11-15 19:34 - 2015-10-30 23:39 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2015-11-15 19:34 - 2015-10-30 23:37 - 00480256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2015-11-15 19:34 - 2015-10-30 23:36 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2015-11-15 19:34 - 2015-10-30 23:36 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2015-11-15 19:34 - 2015-10-30 23:36 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2015-11-15 19:34 - 2015-10-30 23:34 - 00262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2015-11-15 19:34 - 2015-10-30 23:32 - 00720896 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-11-15 19:34 - 2015-10-30 23:31 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-11-15 19:34 - 2015-10-30 23:29 - 02126336 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-11-15 19:34 - 2015-10-30 23:29 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2015-11-15 19:34 - 2015-10-30 23:28 - 00416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2015-11-15 19:34 - 2015-10-30 23:23 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2015-11-15 19:34 - 2015-10-30 23:22 - 14457856 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-11-15 19:34 - 2015-10-30 23:21 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2015-11-15 19:34 - 2015-10-30 23:19 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2015-11-15 19:34 - 2015-10-30 23:18 - 00279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2015-11-15 19:34 - 2015-10-30 23:17 - 02487808 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-11-15 19:34 - 2015-10-30 23:17 - 00130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2015-11-15 19:34 - 2015-10-30 23:16 - 04527616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2015-11-15 19:34 - 2015-10-30 23:11 - 00230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2015-11-15 19:34 - 2015-10-30 23:10 - 00689152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2015-11-15 19:34 - 2015-10-30 23:09 - 12854272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2015-11-15 19:34 - 2015-10-30 23:09 - 02052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2015-11-15 19:34 - 2015-10-30 23:09 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2015-11-15 19:34 - 2015-10-30 23:04 - 01547264 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-11-15 19:34 - 2015-10-30 22:53 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-11-15 19:34 - 2015-10-30 22:51 - 02011136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2015-11-15 19:34 - 2015-10-30 22:48 - 01311744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2015-11-15 19:34 - 2015-10-30 22:46 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2015-11-15 19:33 - 2015-10-29 18:50 - 00342016 _____ (Microsoft Corporation) C:\Windows\system32\apphelp.dll
2015-11-15 19:33 - 2015-10-29 18:50 - 00072192 _____ (Microsoft Corporation) C:\Windows\system32\aelupsvc.dll
2015-11-15 19:33 - 2015-10-29 18:50 - 00023552 _____ (Microsoft Corporation) C:\Windows\system32\sdbinst.exe
2015-11-15 19:33 - 2015-10-29 18:50 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\shimeng.dll
2015-11-15 19:33 - 2015-10-29 18:50 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shimeng.dll
2015-11-15 19:33 - 2015-10-29 18:49 - 00295936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apphelp.dll
2015-11-15 19:33 - 2015-10-29 18:49 - 00020992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sdbinst.exe
2015-11-15 19:33 - 2015-10-20 02:12 - 05570496 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-11-15 19:33 - 2015-10-20 02:12 - 00154560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2015-11-15 19:33 - 2015-10-20 02:12 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2015-11-15 19:33 - 2015-10-20 02:09 - 01730496 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2015-11-15 19:33 - 2015-10-20 02:06 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2015-11-15 19:33 - 2015-10-20 02:06 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2015-11-15 19:33 - 2015-10-20 02:06 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2015-11-15 19:33 - 2015-10-20 02:06 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2015-11-15 19:33 - 2015-10-20 02:05 - 01461760 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2015-11-15 19:33 - 2015-10-20 02:05 - 01216512 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2015-11-15 19:33 - 2015-10-20 02:05 - 01164800 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2015-11-15 19:33 - 2015-10-20 02:05 - 00729600 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2015-11-15 19:33 - 2015-10-20 02:05 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-11-15 19:33 - 2015-10-20 02:05 - 00424960 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2015-11-15 19:33 - 2015-10-20 02:05 - 00344064 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-11-15 19:33 - 2015-10-20 02:05 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2015-11-15 19:33 - 2015-10-20 02:05 - 00312320 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2015-11-15 19:33 - 2015-10-20 02:05 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-11-15 19:33 - 2015-10-20 02:05 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2015-11-15 19:33 - 2015-10-20 02:05 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2015-11-15 19:33 - 2015-10-20 02:05 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2015-11-15 19:33 - 2015-10-20 02:05 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2015-11-15 19:33 - 2015-10-20 02:05 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-11-15 19:33 - 2015-10-20 02:05 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2015-11-15 19:33 - 2015-10-20 02:05 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2015-11-15 19:33 - 2015-10-20 02:05 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2015-11-15 19:33 - 2015-10-20 02:05 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2015-11-15 19:33 - 2015-10-20 02:05 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2015-11-15 19:33 - 2015-10-20 02:05 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2015-11-15 19:33 - 2015-10-20 02:04 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2015-11-15 19:33 - 2015-10-20 02:04 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2015-11-15 19:33 - 2015-10-20 02:04 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2015-11-15 19:33 - 2015-10-20 02:00 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2015-11-15 19:33 - 2015-10-20 01:59 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2015-11-15 19:33 - 2015-10-20 01:53 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2015-11-15 19:33 - 2015-10-20 01:53 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2015-11-15 19:33 - 2015-10-20 01:53 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:53 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:53 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:53 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:53 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:53 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:53 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:53 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:53 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:53 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:53 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:53 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:53 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:53 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:53 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:52 - 03991488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2015-11-15 19:33 - 2015-10-20 01:52 - 03935680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2015-11-15 19:33 - 2015-10-20 01:48 - 01311768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2015-11-15 19:33 - 2015-10-20 01:45 - 00552960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2015-11-15 19:33 - 2015-10-20 01:45 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2015-11-15 19:33 - 2015-10-20 01:45 - 00251392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2015-11-15 19:33 - 2015-10-20 01:45 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2015-11-15 19:33 - 2015-10-20 01:45 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2015-11-15 19:33 - 2015-10-20 01:45 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2015-11-15 19:33 - 2015-10-20 01:45 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2015-11-15 19:33 - 2015-10-20 01:45 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll
2015-11-15 19:33 - 2015-10-20 01:45 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2015-11-15 19:33 - 2015-10-20 01:45 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2015-11-15 19:33 - 2015-10-20 01:45 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2015-11-15 19:33 - 2015-10-20 01:45 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2015-11-15 19:33 - 2015-10-20 01:44 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2015-11-15 19:33 - 2015-10-20 01:44 - 00665088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2015-11-15 19:33 - 2015-10-20 01:44 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2015-11-15 19:33 - 2015-10-20 01:44 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2015-11-15 19:33 - 2015-10-20 01:44 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2015-11-15 19:33 - 2015-10-20 01:44 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2015-11-15 19:33 - 2015-10-20 01:39 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2015-11-15 19:33 - 2015-10-20 01:39 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2015-11-15 19:33 - 2015-10-20 01:35 - 00686080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2015-11-15 19:33 - 2015-10-20 01:35 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2015-11-15 19:33 - 2015-10-20 01:35 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:35 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:35 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:35 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:35 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:35 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:35 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:35 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:35 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:35 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:35 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:35 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:35 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 00:41 - 00159232 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2015-11-15 19:33 - 2015-10-20 00:40 - 00290816 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2015-11-15 19:33 - 2015-10-20 00:40 - 00129024 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2015-11-15 19:33 - 2015-10-20 00:29 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2015-11-15 19:33 - 2015-10-20 00:29 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2015-11-15 19:33 - 2015-10-20 00:27 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 00:27 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 00:27 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 00:27 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2015-11-15 19:33 - 2015-10-13 17:41 - 00497664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2015-11-15 19:33 - 2015-10-13 17:40 - 00118272 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdx.sys
2015-11-15 19:33 - 2015-09-23 14:15 - 00460776 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2015-11-15 19:33 - 2015-09-23 14:15 - 00299632 _____ (Microsoft Corporation) C:\Windows\system32\bcryptprimitives.dll
2015-11-15 19:33 - 2015-09-23 14:09 - 00251000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcryptprimitives.dll
2015-11-15 19:27 - 2015-11-15 19:27 - 00000000 ____D C:\Users\bryan77\AppData\Local\Mega Limited
2015-11-15 19:24 - 2015-10-13 05:57 - 00950720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys
2015-11-15 19:24 - 2015-10-01 19:00 - 00275456 _____ (Microsoft Corporation) C:\Windows\system32\InkEd.dll
2015-11-15 19:24 - 2015-10-01 19:00 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\jnwmon.dll
2015-11-15 19:24 - 2015-10-01 18:50 - 00216064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InkEd.dll
2015-11-09 08:55 - 2015-11-09 08:55 - 00120507 _____ C:\Users\Barbara.bryan77-PC\Downloads\105521 (1).pdf
2015-11-09 08:51 - 2015-11-09 08:51 - 00120507 _____ C:\Users\Barbara.bryan77-PC\Downloads\105521.pdf
2015-11-06 15:50 - 2015-11-06 15:50 - 00184240 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgdiska.sys
2015-11-06 15:49 - 2015-11-06 15:49 - 00313776 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgidsdrivera.sys
2015-11-06 15:49 - 2015-11-06 15:49 - 00256432 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgmfx64.sys


==================== Een Maand Gewijzigd bestanden en mappen ========


(Als een item is opgenomen in de fixlist, het bestand/map wordt verplaatst.)


2015-12-05 23:04 - 2012-02-24 03:29 - 00001056 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-12-05 22:57 - 2013-12-01 22:44 - 00000828 _____ C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job
2015-12-05 22:57 - 2012-02-24 03:29 - 00001052 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-12-05 22:55 - 2013-12-01 20:07 - 00000000 ____D C:\ProgramData\MFAData
2015-12-05 22:55 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-12-05 22:46 - 2009-07-14 05:45 - 00009920 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-12-05 22:46 - 2009-07-14 05:45 - 00009920 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-12-05 22:44 - 2013-12-08 21:48 - 00000940 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-12-05 22:22 - 2014-09-15 18:06 - 00000000 ____D C:\Users\Bryan\AppData\Roaming\Software Informer
2015-12-05 20:29 - 2015-06-03 11:41 - 00000000 ____D C:\Users\Bryan\AppData\Local\Spotify
2015-12-05 20:29 - 2015-06-03 11:40 - 00000000 ____D C:\Users\Bryan\AppData\Roaming\Spotify
2015-12-05 20:29 - 2013-12-01 21:06 - 00000380 _____ C:\Users\Bryan\AppData\Roaming\sp_data.sys
2015-12-05 12:12 - 2013-12-01 22:44 - 00000830 _____ C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job
2015-12-05 11:43 - 2013-12-01 20:24 - 00000380 _____ C:\Users\Barbara.bryan77-PC\AppData\Roaming\sp_data.sys
2015-12-05 08:53 - 2009-07-14 06:32 - 00000000 ____D C:\Windows\Downloaded Program Files
2015-12-05 08:53 - 2009-07-14 04:20 - 00000000 ____D C:\Windows
2015-12-05 08:52 - 2015-05-21 19:40 - 00000000 __SHD C:\Users\bryan77\AppData\Local\EmieUserList
2015-12-05 08:52 - 2015-05-21 19:40 - 00000000 __SHD C:\Users\bryan77\AppData\Local\EmieSiteList
2015-12-05 08:52 - 2015-05-21 19:40 - 00000000 __SHD C:\Users\bryan77\AppData\Local\EmieBrowserModeList
2015-12-04 20:25 - 2014-11-26 08:12 - 00000000 ____D C:\Users\Bryan\AppData\Local\Avg
2015-12-04 15:02 - 2009-07-14 06:32 - 00000000 ____D C:\Windows\Performance
2015-12-04 14:02 - 2014-11-06 21:55 - 00000000 ____D C:\Program Files (x86)\TeamViewer
2015-12-02 17:59 - 2012-02-24 03:29 - 00004052 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2015-12-02 17:59 - 2012-02-24 03:29 - 00003800 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2015-12-02 15:34 - 2011-02-19 05:40 - 00746450 _____ C:\Windows\system32\perfh013.dat
2015-12-02 15:34 - 2011-02-19 05:40 - 00154112 _____ C:\Windows\system32\perfc013.dat
2015-12-02 15:34 - 2009-07-14 06:13 - 01672504 _____ C:\Windows\system32\PerfStringBackup.INI
2015-12-02 15:34 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\inf
2015-12-02 15:25 - 2014-11-27 23:08 - 00000000 ____D C:\AdwCleaner
2015-12-02 14:34 - 2013-12-01 20:15 - 00000000 ____D C:\ProgramData\AVG2014
2015-12-02 14:26 - 2014-11-26 08:12 - 00000000 ____D C:\Users\bryan77\AppData\Local\Avg
2015-12-02 14:26 - 2014-08-28 07:09 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
2015-12-02 14:26 - 2013-12-01 20:15 - 00000000 ___HD C:\$AVG
2015-12-02 14:26 - 2013-12-01 20:13 - 00000000 ____D C:\Program Files (x86)\AVG
2015-12-02 14:25 - 2015-06-26 08:09 - 00000000 ____D C:\Program Files\Common Files\AV
2015-12-02 13:39 - 2013-12-01 17:57 - 00001144 _____ C:\Users\bryan77\Desktop\Internet Explorer.lnk
2015-12-02 13:39 - 2013-12-01 14:19 - 00001144 _____ C:\Users\bryan77\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-12-02 13:36 - 2014-12-02 23:36 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2015-12-01 21:40 - 2009-07-14 06:09 - 00000000 ____D C:\Windows\System32\Tasks\WPD
2015-11-22 14:44 - 2015-10-27 19:41 - 00000000 ____D C:\Users\Bryan\.oracle_jre_usage
2015-11-22 14:29 - 2014-11-26 08:12 - 00000000 ____D C:\Users\Barbara.bryan77-PC\AppData\Local\Avg
2015-11-16 04:06 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache
2015-11-16 03:29 - 2009-07-14 05:45 - 00270888 _____ C:\Windows\system32\FNTCACHE.DAT
2015-11-16 03:24 - 2015-06-03 21:56 - 00000000 ____D C:\Windows\system32\MRT
2015-11-16 03:11 - 2015-06-03 21:55 - 145617392 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-11-16 03:03 - 2012-02-24 03:28 - 01647172 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2015-11-16 03:02 - 2009-07-14 08:45 - 00000000 ____D C:\Program Files\Windows Journal
2015-11-15 20:36 - 2013-12-01 19:25 - 00000000 ____D C:\Users\bryan77\AppData\Local\Windows Live
2015-11-15 19:44 - 2013-12-08 21:48 - 00780488 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-11-15 19:44 - 2013-12-08 21:48 - 00142536 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-11-15 19:44 - 2013-12-08 21:48 - 00003878 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-11-15 19:43 - 2014-11-21 21:01 - 00000000 ____D C:\Users\AdminPc
2015-11-15 19:32 - 2009-07-14 04:20 - 00000000 __RHD C:\Users\Public\Libraries
2015-11-15 19:27 - 2014-10-01 09:20 - 00000000 ____D C:\Users\Bryan\AppData\Local\MEGAsync
2015-11-15 19:15 - 2014-07-29 10:51 - 00000000 ____D C:\Users\bryan77\AppData\Roaming\.minecraft
2015-11-15 19:02 - 2013-12-01 21:05 - 00000000 ____D C:\Users\Bryan
2015-11-15 19:02 - 2013-12-01 14:18 - 00000000 ____D C:\Users\bryan77
2015-11-13 00:29 - 2015-04-05 02:00 - 00000000 ___SD C:\Windows\system32\GWX
2015-11-13 00:29 - 2013-12-08 21:48 - 00000000 ____D C:\Windows\system32\Macromed
2015-11-13 00:29 - 2013-12-01 20:24 - 00000000 ____D C:\Users\Barbara.bryan77-PC
2015-11-13 00:29 - 2012-02-24 03:29 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-11-13 00:29 - 2009-07-14 08:44 - 00000000 ___RD C:\Users\Public\Recorded TV
2015-11-13 00:29 - 2009-07-14 04:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared
2015-11-13 00:28 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\registration
2015-11-07 11:11 - 2014-08-11 12:27 - 00000184 _____ C:\Users\Bryan\Downloads\eula.txt


==================== Bestanden in de root van sommige mappen =======


2015-12-04 14:02 - 2015-12-05 23:03 - 0000380 _____ () C:\Users\bryan77\AppData\Roaming\sp_data.sys
2014-04-16 18:15 - 2014-04-16 18:15 - 0000057 _____ () C:\ProgramData\Ament.ini
2012-02-24 03:42 - 2010-10-06 18:45 - 0131984 _____ () C:\ProgramData\FullRemove.exe
2013-12-01 14:06 - 2013-12-01 14:06 - 0000109 _____ () C:\ProgramData\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}.log
2013-12-01 14:05 - 2013-12-01 14:06 - 0000105 _____ () C:\ProgramData\{40BF1E83-20EB-11D8-97C5-0009C5020658}.log
2013-12-01 14:04 - 2013-12-01 14:05 - 0000107 _____ () C:\ProgramData\{C59C179C-668D-49A9-B6EA-0121CCFC1243}.log


==================== Bamital & volsnap =================


(Er is geen automatische fix voor bestanden die de verificatie niet doorkomen.)


C:\Windows\system32\winlogon.exe => Bestand is getekend
C:\Windows\system32\wininit.exe => Bestand is getekend
C:\Windows\SysWOW64\wininit.exe => Bestand is getekend
C:\Windows\explorer.exe => Bestand is getekend
C:\Windows\SysWOW64\explorer.exe => Bestand is getekend
C:\Windows\system32\svchost.exe => Bestand is getekend
C:\Windows\SysWOW64\svchost.exe => Bestand is getekend
C:\Windows\system32\services.exe => Bestand is getekend
C:\Windows\system32\User32.dll => Bestand is getekend
C:\Windows\SysWOW64\User32.dll => Bestand is getekend
C:\Windows\system32\userinit.exe => Bestand is getekend
C:\Windows\SysWOW64\userinit.exe => Bestand is getekend
C:\Windows\system32\rpcss.dll => Bestand is getekend
C:\Windows\system32\dnsapi.dll => Bestand is getekend
C:\Windows\SysWOW64\dnsapi.dll => Bestand is getekend
C:\Windows\system32\Drivers\volsnap.sys => Bestand is getekend




LastRegBack: 2015-11-30 00:25


==================== Eind van FRST.txt ============================


Extra scanresultaten van Farbar Recovery Scan Tool (x64) Versie:05-12-2015
Gestart door bryan77 (2015-12-05 23:06:18)
Gestart vanaf C:\Users\bryan77\Desktop
Windows 7 Home Premium Service Pack 1 (X64) (2013-12-01 13:17:59)
Boot Modus: Normal
==========================================================




==================== Accounts: =============================


Administrator (S-1-5-21-3732487481-855672253-929003311-500 - Administrator - Disabled)
Barbara (S-1-5-21-3732487481-855672253-929003311-1006 - Limited - Enabled) => C:\Users\Barbara.bryan77-PC
Bryan (S-1-5-21-3732487481-855672253-929003311-1005 - Limited - Enabled) => C:\Users\Bryan
bryan77 (S-1-5-21-3732487481-855672253-929003311-1001 - Administrator - Enabled) => C:\Users\bryan77
Gast (S-1-5-21-3732487481-855672253-929003311-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-3732487481-855672253-929003311-1002 - Limited - Enabled)


==================== Security Center ========================


(Als een item is opgenomen in de fixlist, zal het worden verwijderd.)


AV: AVG AntiVirus Free Edition (Enabled - Up to date) {4D41356F-32AD-7C42-C820-63775EE4F413}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: AVG AntiVirus Free Edition (Enabled - Up to date) {F620D48B-1497-73CC-F290-58052563BEAE}


==================== Geïnstalleerde programma's ======================


(Alleen de adware-programma's met 'verborgen' vlag zou kunnen worden toegevoegd aan de fixlist om ze zichtbaar te maken. De adware-programma's moeten handmatig gedeinstallerd worden.)


Adobe Flash Player 10 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 10.0.32.18 - Adobe Systems Incorporated)
Adobe Flash Player 19 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 19.0.0.245 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.13) - Nederlands (HKLM-x32\...\{AC76BA86-7AD7-1043-7B44-AB0000000001}) (Version: 11.0.13 - Adobe Systems Incorporated)
Alcor Micro USB Card Reader (HKLM-x32\...\AmUStor) (Version: 1.2.0117.08443 - Alcor Micro Corp.)
Alcor Micro USB Card Reader (x32 Version: 1.2.0117.08443 - Alcor Micro Corp.) Hidden
ASUS AI Recovery (HKLM-x32\...\{D39F0676-163E-4595-A917-E28F99BBD4D2}) (Version: 1.0.24 - ASUS)
ASUS FaceLogon (HKLM-x32\...\{64452561-169F-4A36-A2FF-B5E118EC65F5}) (Version: 1.0.0014 - ASUS)
ASUS Instant Connect (HKLM-x32\...\{89ECB85A-D933-4CEA-9116-5CBC9C2ED95B}) (Version: 1.2.2 - ASUS)
ASUS LifeFrame3 (HKLM-x32\...\{1DBD1F12-ED93-49C0-A7CC-56CBDE488158}) (Version: 3.1.1 - ASUS)
ASUS Live Update (HKLM-x32\...\{FA540E67-095C-4A1B-97BA-4D547DEC9AF4}) (Version: 3.1.5 - ASUS)
ASUS Power4Gear Hybrid (HKLM\...\{9B6239BF-4E85-4590-8D72-51E30DB1A9AA}) (Version: 1.2.1 - ASUS)
ASUS Splendid Video Enhancement Technology (HKLM-x32\...\{0969AF05-4FF6-4C00-9406-43599238DE0D}) (Version: 1.03.0001 - ASUS)
ASUS USB Charger Plus (HKLM-x32\...\{A859E3E5-C62F-4BFA-AF1D-2B95E03166AF}) (Version: 2.1.1 - ASUS)
ASUS Virtual Camera (HKLM-x32\...\{EC8BD21F-0CA0-4BBF-97D9-4A52B30041A1}) (Version: 1.0.25 - ASUS)
ASUS Virtual Touch (HKLM-x32\...\{938CFBD4-0652-49E5-BB8B-153948865941}) (Version: 1.0.11 - ASUS)
ASUS WebStorage (HKLM-x32\...\ASUS WebStorage) (Version: 3.0.108.222 - eCareme Technologies, Inc.)
AsusVibe2.0 (HKLM-x32\...\Asus Vibe2.0) (Version: 2.0.9.157 - ASUSTEK)
Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver (HKLM-x32\...\{3108C217-BE83-42E4-AE9E-A56A2A92E549}) (Version: 2.0.15.16 - Atheros Communications Inc.)
ATK Package (HKLM-x32\...\{AB5C933E-5C7D-4D30-B314-9C83A49B94BE}) (Version: 1.0.0015 - ASUS)
AVG (HKLM\...\AvgZen) (Version: 1.22.1.40089 - AVG Technologies)
AVG (Version: 16.12.7294 - AVG Technologies) Hidden
AVG 2016 (Version: 16.0.4483 - AVG Technologies) Hidden
AVG Protection (HKLM\...\AVG) (Version: 2016.12.7294 - AVG Technologies)
AVG Zen (Version: 1.22.1 - AVG Technologies) Hidden
Bubbletown (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-115065740}) (Version: - Oberon Media)
Contenta Converter PREMIUM (HKLM-x32\...\ContentaConverter-PREMIUM) (Version: - Contenta Software)
CyberLink LabelPrint (HKLM-x32\...\InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}) (Version: 2.5.3624 - CyberLink Corp.)
CyberLink Media Suite (HKLM-x32\...\InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}) (Version: 8.0.2926 - CyberLink Corp.)
CyberLink Power2Go (HKLM-x32\...\InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 7.0.0.1126 - CyberLink Corp.)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Deadtime Stories (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-118716773}) (Version: - Oberon Media)
Dream Day First Home (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-113832110}) (Version: - Oberon Media)
Dream Vacation Solitaire (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111249233}) (Version: - Oberon Media)
ESET Online Scanner v3 (HKLM-x32\...\ESET Online Scanner) (Version: - )
ETDWare PS/2-X64 10.5.10.0 (HKLM\...\Elantech) (Version: 10.5.10.0 - ELAN Microelectronic Corp.)
Farm Frenzy 3 - Madagascar (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-119205603}) (Version: - Oberon Media)
FMW 1 (Version: 1.32.2 - AVG Technologies) Hidden
Fotogalerie (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Galapago (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111307457}) (Version: - Oberon Media)
Galeria de Fotografias (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Galería de fotos (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Galerie de photos (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Game Park Console (HKLM-x32\...\Game Park Console) (Version: 1.2.4.431 - Oberon Media Inc.)
Go Go Gourmet Chef of the Year (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-115290153}) (Version: - Oberon Media)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 47.0.2526.73 - Google Inc.)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.29.1 - Google Inc.) Hidden
HP Deskjet 1050 J410 series Basissoftware van het apparaat (HKLM\...\{FA37D2E8-0A8B-46D2-A74A-310F935DE920}) (Version: 28.0.1313.0 - Hewlett-Packard Co.)
HP Deskjet 1050 J410 series Haelp (HKLM-x32\...\{5C90D8CF-F12A-41C6-9007-3B651A1F0D78}) (Version: 140.0.66.66 - Hewlett Packard)
HP Deskjet 1050 J410 series Productverbeteringsonderzoek (HKLM\...\{44C6BB22-7E25-4A6D-8851-6FB26407D9C1}) (Version: 28.0.1313.0 - Hewlett-Packard Co.)
HP Photo Creations (HKLM-x32\...\HP Photo Creations) (Version: 1.0.0.7702 - HP)
HP Update (HKLM-x32\...\{6F1C00D2-25C2-4CBA-8126-AE9A6E2E9CD5}) (Version: 5.003.003.001 - Hewlett-Packard)
InstantOn for NB (HKLM-x32\...\{749F674B-2674-47E8-879C-5626A06B2A91}) (Version: 2.3.3 - ASUS)
Intel(R) Manageability Engine Firmware Recovery Agent (HKLM-x32\...\{A6C48A9F-694A-4234-B3AA-62590B668927}) (Version: 1.0.0.35342 - Intel Corporation)
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.0.3.1427 - Intel Corporation)
Intel(R) OpenCL CPU Runtime (HKLM-x32\...\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2653 - Intel Corporation)
Intel(R) USB 3.0 eXtensible Host Controller Driver (HKLM-x32\...\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 1.0.3.214 - Intel Corporation)
Intel® Trusted Connect Service Client (HKLM\...\{09536BA1-E498-4CC3-B834-D884A67D7E34}) (Version: 1.23.605.1 - Intel Corporation)
Java 8 Update 65 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218065F0}) (Version: 8.0.650.17 - Oracle Corporation)
Junk Mail filter update (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Mahjong Memoirs (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-117948443}) (Version: - Oberon Media)
Malwarebytes Anti-Malware versie 2.2.0.1024 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.0.1024 - Malwarebytes)
MediaFire Desktop (HKLM-x32\...\MediaFire Desktop 1.3.9.10486) (Version: 1.3.9.10486 - MediaFire)
Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft Office 2010 (HKLM-x32\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office Klik-en-Klaar 2010 (HKLM-x32\...\Office14.Click2Run) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office Starter 2010 - Nederlands (HKLM-x32\...\{90140011-0066-0413-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft PowerPoint Viewer (HKLM-x32\...\{95140000-00AF-0413-0000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40728.0 - Microsoft Corporation)
Microsoft SkyDrive (HKU\S-1-5-21-3732487481-855672253-929003311-1001\...\SkyDriveSetup.exe) (Version: 16.4.6013.0910 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Movie Maker (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
myBitCast 1.0.0.3 (HKLM\...\myBitCast) (Version: 1.0.0.3 - ASUS Cloud Corporation)
Plants vs Zombies (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-117080787}) (Version: - Oberon Media)
Platform (x32 Version: 1.39 - VIA Technologies, Inc.) Hidden
Qualcomm Atheros WiFi Driver Installation (HKLM-x32\...\{7D916FA5-DAE9-4A25-B089-655C70EAF607}) (Version: 3.0 - Qualcomm Atheros)
Raccolta foto (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
SceneSwitch (HKLM-x32\...\{5172E572-C175-4F80-A6D5-5CB45826AD61}) (Version: 1.0.12 - ASUS)
TeamViewer 10 (HKLM-x32\...\TeamViewer) (Version: 10.0.47484 - TeamViewer)
Turbo Fiesta (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-115320460}) (Version: - Oberon Media)
VIA Platform Device Manager (HKLM-x32\...\InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}) (Version: 1.39 - VIA Technologies, Inc.)
Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
Visual Studio 2012 x86 Redistributables (HKLM-x32\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3508.0205 - Microsoft Corporation)
Windows Phone app for desktop (HKLM-x32\...\{54EC61F0-6D02-450E-9F1B-9506EAE9F23C}) (Version: 1.1.2726.0 - Microsoft Corporation)
WinFlash (HKLM-x32\...\{8F21291E-0444-4B1D-B9F9-4370A73E346D}) (Version: 2.41.0 - ASUS)
WinRAR 5.01 (32-bit) (HKLM-x32\...\WinRAR archiver) (Version: 5.01.0 - win.rar GmbH)
WinZip 18.5 (HKLM\...\{CD95F661-A5C4-44F5-A6AA-ECDD91C240E3}) (Version: 18.5.11111 - WinZip Computing, S.L. )
Wireless Console 3 (HKLM-x32\...\{19EA33FB-B34E-40EA-8B8A-61743AEB795A}) (Version: 3.0.30 - ASUS)
World of Goo (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-116672750}) (Version: - Oberon Media)
Συλλογή φωτογραφιών (HKLM-x32\...\{032CB0D7-FDBF-4CA9-901B-A4C1B01B1777}) (Version: 16.4.3508.0205 - Microsoft Corporation)
Основные компоненты Windows Live (HKLM-x32\...\{7A9122B2-CF90-4ACB-8E10-AA83F725916B}) (Version: 16.4.3508.0205 - Microsoft Corporation)
Почта Windows Live (HKLM-x32\...\{44B4333A-60A6-4FFC-BCC5-B0ECA23D2AAB}) (Version: 16.4.3508.0205 - Корпорация Майкрософт)
Фотоальбом (HKLM-x32\...\{CE4EEFE0-85E0-436E-95C5-BCB2EE30C976}) (Version: 16.4.3508.0205 - Microsoft Corporation)
Фотографии (общедоступная версия) (HKLM-x32\...\{234BD64C-99F4-42B5-837F-82F00E37A7E1}) (Version: 16.4.3508.0205 - Microsoft Corporation)
גלריית התמונות (HKLM-x32\...\{B1AC8AF0-2979-4DF8-AE26-B1D543F3543F}) (Version: 16.4.3508.0205 - Microsoft Corporation)
بريد Windows Live (HKLM-x32\...\{7A546E5C-0906-42CC-92DF-B2E787FFA7D2}) (Version: 16.4.3508.0205 - Microsoft Corporation)
معرض الصور (HKLM-x32\...\{6F77C156-7660-4CEC-8793-97D80D5BFEC0}) (Version: 16.4.3508.0205 - Microsoft Corporation)
影像中心 (HKLM-x32\...\{7DB15F28-5E38-476A-A773-EA07EAEAB1B3}) (Version: 16.4.3508.0205 - Microsoft Corporation)


==================== Aangepaste CLSID (gefilterd): ==========================


(Als een item is opgenomen in de fixlist, wordt uit het register verwijderd. Het bestand zal niet worden verplaatst tenzij apart vermeld.)




==================== Herstelpunten =========================


05-12-2015 22:50:35 Restore Point Created by FRST


==================== Hosts inhoud: ===============================


(Als nodig Hosts: opdracht kan worden opgenomen in de fixlist om Hosts te resetten.)


2009-07-14 03:34 - 2014-11-27 22:36 - 00000098 ____A C:\Windows\system32\Drivers\etc\hosts


127.0.0.1 localhost
::1 localhost


==================== Geplande Taken (gefilterd) =============


(Als een item is opgenomen in de fixlist, wordt uit het register verwijderd. Het bestand zal niet worden verplaatst tenzij apart vermeld.)


Task: {016EB10C-9FA8-4770-8EBC-FB988737FFAC} - System32\Tasks\ASUS USB Charger Plus => C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe [2012-05-08] (ASUSTek Computer Inc.)
Task: {03E6DA50-A095-4B57-902E-4DF77C5BF8F7} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2011-11-25] (Intel Corporation)
Task: {0B3022E3-1822-42D2-853B-060D9B16FE85} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
Task: {10101098-8567-43F5-9791-02068557C5E4} - System32\Tasks\ASUS SmartLogon Console Sensor => C:\Program Files (x86)\ASUS\FaceLogon\sensorsrv.exe [2012-02-17] (ASUSTek Computer Inc.)
Task: {202E950A-44F4-4239-B80C-69E0FA7FE0E1} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-11-15] (Adobe Systems Incorporated)
Task: {646DF190-524D-4096-A992-877B333AC272} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2011-11-25] (Intel Corporation)
Task: {665B67F0-541F-45A7-89B7-F2ACC49878F2} - System32\Tasks\HPCustParticipation HP Deskjet 1050 J410 series => C:\Program Files\HP\HP Deskjet 1050 J410 series\Bin\HPCustPartic.exe [2012-10-02] (Hewlett-Packard Co.)
Task: {67604CC6-E4A2-471C-8838-4D78A2D5DEF4} - System32\Tasks\ATKOSD2 => C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [2011-12-23] (ASUSTek Computer Inc.)
Task: {73A21D4C-2845-4D8B-9C8E-73FDEA7C9874} - System32\Tasks\ASUS Quick Gesture (x64) => C:\Program Files (x86)\ASUS\ASUS Virtual Touch\QuickGesture\x64\QuickGesture64.exe [2012-04-12] (ASUSTeK Computer Inc.)
Task: {75D32B76-8DCE-43E7-A42C-9D9F74B667CF} - System32\Tasks\ASUS Wireless Console 3 => C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [2012-05-17] (ASUSTeK Computer Inc.)
Task: {797BE614-709C-4392-8414-E7339AA5FED9} - System32\Tasks\ASUS P4G => C:\Program Files\ASUS\P4G\BatteryLife.exe [2012-02-16] (ASUS)
Task: {8BDDB50A-894A-44C8-8F18-AC996B599520} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
Task: {D243337D-A7BA-4BDC-94F5-D685FC8BC71D} - System32\Tasks\ASUS Quick Gesture => C:\Program Files (x86)\ASUS\ASUS Virtual Touch\QuickGesture\x86\QuickGesture.exe [2012-04-12] (ASUSTeK Computer Inc.)
Task: {DB88D52C-111F-4457-B2ED-6C6055D80BA8} - System32\Tasks\ASUS Live Update => C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe [2012-05-22] (ASUSTeK Computer Inc.)
Task: {EC10FEA5-971D-4A52-8BA5-075DE9A65021} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-10-28] (Adobe Systems Incorporated)
Task: {F518AA26-3DD4-48B6-AF10-875985913339} - System32\Tasks\0615tbUpdateInfo => C:\ProgramData\Avg_Update_0615tb\0615tb_{7065CFD9-63B9-47E1-A239-3232D511C3F6}.exe


(Als een item is opgenomen in de fixlist, de taak (job) bestand wordt verplaatst. Het bestand dat wordt uitgevoerd door de taak zal niet worden verplaatst.)


Task: C:\Windows\Tasks\0615tbUpdateInfo.job => C:\ProgramData\Avg_Update_0615tb\0615tb_{7065CFD9-63B9-47E1-A239-3232D511C3F6}.exe
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe
Task: C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe


==================== Snelkoppelingen =============================


(De items kunnen worden opgenomen in de fixlist.txt om hersteld of verwijderd te worden.)


==================== Geladen Modules (gefilterd) ==============


2013-12-01 22:44 - 2012-02-21 21:29 - 00128280 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
2010-07-15 01:11 - 2010-07-15 01:11 - 00031360 _____ () C:\Program Files\ASUS\P4G\DevMng.dll
2013-12-01 22:45 - 2012-04-19 03:24 - 00078448 _____ () C:\Program Files (x86)\VIA\VIAudioi\VDeck\QsApoApi64.dll
2013-12-01 22:45 - 2012-04-19 03:24 - 00386160 _____ () C:\Program Files (x86)\VIA\VIAudioi\VDeck\Dts2ApoApi64.dll
2012-06-27 04:04 - 2012-02-22 08:18 - 00094208 _____ () C:\Windows\system32\IccLibDll_x64.dll
2012-01-31 18:25 - 2012-01-31 18:25 - 01163264 _____ () C:\Program Files (x86)\ASUS\Wireless Console 3\acAuth.dll
2012-05-08 01:48 - 2012-05-08 01:48 - 00009216 _____ () C:\Program Files (x86)\ASUS\Splendid\GLCDdll.dll
2010-08-20 18:57 - 2010-08-20 18:57 - 00619816 _____ () C:\Program Files (x86)\CyberLink\Power2Go\CLMediaLibrary.dll
2010-08-20 18:57 - 2010-08-20 18:57 - 00013096 _____ () C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvcPS.dll
2015-12-02 14:20 - 2015-12-02 14:20 - 40500224 _____ () C:\Program Files (x86)\AVG\UiDll\2171\libcef.dll
2013-12-01 22:44 - 2012-02-21 21:09 - 01198872 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll


==================== Alternate Data Streams (gefilterd) =========


(Als een item is opgenomen in de fixlist, alleen de ADS wordt verwijderd.)




==================== Veilige Modus (gefilterd) ===================


(Als een item is opgenomen in de fixlist, wordt uit het register verwijderd. De "AlternateShell" waarde wordt hersteld.)




==================== EXE Bestandskoppeling (gefilterd) ===============


(Als een item is opgenomen in de fixlist, het registry item zal worden teruggezet naar de standaardwaarden of verwijderd.)




==================== Internet Explorer vertrouwde/beperkte toegang ===============


(Als een item is opgenomen in de fixlist, wordt uit het register verwijderd.)




==================== Andere gebieden ============================


(Momenteel is er geen automatische fix voor dit onderdeel.)


HKU\S-1-5-21-3732487481-855672253-929003311-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\bryan77\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 195.130.131.4 - 195.130.130.132
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is ingeschakeld.


==================== MSCONFIG/TASK MANAGER Uitgeschakelde items ==


(Momenteel is er geen automatische fix voor dit onderdeel.)


MSCONFIG\Services: 0169601385920986mcinstcleanup => 2
MSCONFIG\Services: MBAMScheduler => 2
MSCONFIG\Services: MBAMService => 2
MSCONFIG\Services: McAfee SiteAdvisor Service => 2
MSCONFIG\Services: McAWFwk => 3
MSCONFIG\Services: mcmscsvc => 2
MSCONFIG\Services: McNaiAnn => 2
MSCONFIG\Services: McNASvc => 2
MSCONFIG\Services: McODS => 3
MSCONFIG\Services: McOobeSv => 2
MSCONFIG\Services: McProxy => 2
MSCONFIG\Services: MSK80Service => 2
MSCONFIG\startupreg: AVG_UI => "C:\Program Files (x86)\AVG\AVG2014\avgui.exe" /TRAYONLY
MSCONFIG\startupreg: mcui_exe => "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey


==================== Firewall regels (gefilterd) ===============


(Als een item is opgenomen in de fixlist, wordt uit het register verwijderd. Het bestand zal niet worden verplaatst tenzij apart vermeld.)


FirewallRules: [TCP Query User{EBA49DCD-5C2F-4F0E-BF4F-A983FD370081}C:\program files (x86)\java\jre1.8.0_25\bin\javaw.exe] => (Block) C:\program files (x86)\java\jre1.8.0_25\bin\javaw.exe
FirewallRules: [UDP Query User{04EF1A3B-E8E1-408D-A433-3D778365BB2A}C:\program files (x86)\java\jre1.8.0_25\bin\javaw.exe] => (Block) C:\program files (x86)\java\jre1.8.0_25\bin\javaw.exe
FirewallRules: [TCP Query User{49B33151-1BF6-4A16-9671-A38AC8E1DA7F}D:\gta5.exe] => (Allow) D:\gta5.exe
FirewallRules: [UDP Query User{5F17BCE1-5BAB-4AF9-BC8C-2031EEA73D41}D:\gta5.exe] => (Allow) D:\gta5.exe
FirewallRules: [TCP Query User{21411C96-5716-44DB-97AE-6AAFEBC0D31B}C:\users\bryan\appdata\roaming\spotify\spotify.exe] => (Block) C:\users\bryan\appdata\roaming\spotify\spotify.exe
FirewallRules: [UDP Query User{921FF2AA-205F-4238-912D-AC80D00B83E6}C:\users\bryan\appdata\roaming\spotify\spotify.exe] => (Block) C:\users\bryan\appdata\roaming\spotify\spotify.exe
FirewallRules: [TCP Query User{B9BE8C40-DEBE-49C5-AE3A-E1498EAB80DA}C:\program files (x86)\java\jre1.8.0_45\bin\java.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_45\bin\java.exe
FirewallRules: [UDP Query User{5D64D027-EE91-41AD-A490-E62C7653EB88}C:\program files (x86)\java\jre1.8.0_45\bin\java.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_45\bin\java.exe
FirewallRules: [{7129689C-CE17-4737-BACC-4DDF25C9B34C}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{96E25971-D876-4129-9C15-D8EA0429C079}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{4660A62B-8C06-4943-B5FB-280CA615DFE6}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [{B035D7DF-7034-477E-9AE9-5129C494ECBD}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [{4A8DF4BB-2F8C-43C7-A9E4-CE99882730D1}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{CDE4D536-EAC6-4FB2-85A0-4E4F871B922D}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{8FE3476B-6184-441D-8C96-2CA1DD32DBE9}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [{9531F97E-338F-4533-B4BB-9A32D6B4764D}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [TCP Query User{D3C51161-AB03-4053-B366-DBB01F6DA1A0}C:\program files\java\jre1.8.0_65\bin\javaw.exe] => (Block) C:\program files\java\jre1.8.0_65\bin\javaw.exe
FirewallRules: [UDP Query User{6E6E1AC3-B769-4DB0-92AE-80A9159BD7AE}C:\program files\java\jre1.8.0_65\bin\javaw.exe] => (Block) C:\program files\java\jre1.8.0_65\bin\javaw.exe
FirewallRules: [TCP Query User{074F5DDC-5183-44DA-9FF2-431BE3FFFC2F}C:\program files\java\jre1.8.0_65\bin\java.exe] => (Allow) C:\program files\java\jre1.8.0_65\bin\java.exe
FirewallRules: [UDP Query User{E9A707DB-5A5F-4F63-8681-AC8E2BE7CD33}C:\program files\java\jre1.8.0_65\bin\java.exe] => (Allow) C:\program files\java\jre1.8.0_65\bin\java.exe
FirewallRules: [{2DE804F1-AC29-4FB5-94DF-36F6A75EACED}] => (Allow) C:\Program Files (x86)\AVG\Av\avgnsa.exe
FirewallRules: [{77499CE2-A253-4185-9452-710444A30D0B}] => (Allow) C:\Program Files (x86)\AVG\Av\avgnsa.exe
FirewallRules: [{066B187D-8C61-4F4E-B9F8-DFC85CDBC716}] => (Allow) C:\Program Files (x86)\AVG\Av\avgdiagex.exe
FirewallRules: [{EFCE7FCC-F7CB-488A-A1C0-D7DEC8997440}] => (Allow) C:\Program Files (x86)\AVG\Av\avgdiagex.exe
FirewallRules: [{905DB3C3-6451-4918-B8F7-9C981A9D58C8}] => (Allow) C:\Program Files (x86)\AVG\Av\avgmfapx.exe
FirewallRules: [{6AF2248B-6DD9-45C1-BBA6-813BE5C012A0}] => (Allow) C:\Program Files (x86)\AVG\Av\avgmfapx.exe
FirewallRules: [{DA86E969-765A-4B2D-8FAA-9CFB8BA80912}] => (Allow) C:\Program Files (x86)\AVG\Av\avgemca.exe
FirewallRules: [{FBD3498B-8E7B-499C-9BA1-43501E3FBDE1}] => (Allow) C:\Program Files (x86)\AVG\Av\avgemca.exe
FirewallRules: [{AF1F6EDE-83D3-402B-B0B2-36DC8459BE07}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe


==================== Defecte Apparaatbeheer Apparaten =============




==================== Eventlog fouten: =========================


Applicatiefouten:
==================
Error: (12/05/2015 11:05:48 PM) (Source: CVHSVC) (EventID: 100) (User: )
Description: Alleen informatie.
(Patch task for {90140011-0066-0413-0000-0000000FF1CE}): DownloadLatest Failed:


Error: (12/05/2015 10:50:31 PM) (Source: VSS) (EventID: 8194) (User: )
Description: Fout in de Volume Shadow Copy-service: onverwachte fout bij het uitvoeren van een query voor de IVssWriterCallback-interface. hr = 0x80070005, Toegang geweigerd.
.
Dit wordt vaak veroorzaakt door onjuiste beveiligingsinstellingen in het writer- of requestorproces.




Bewerking:
Schrijvergegevens verzamelen


Context:
Klasse-id van schrijver: {e8132975-6f93-4464-a53e-1050253ae220}
Naam van schrijver: System Writer
Instantie-id van schrijver: {a793fd06-b9d4-4afe-b542-7038794c4eea}


Error: (12/05/2015 10:41:42 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Naam van toepassing met fout: Explorer.EXE, versie: 6.1.7601.17567, tijdstempel: 0x4d672ee4
Naam van module met fout: unknown, versie: 0.0.0.0, tijdstempel: 0x00000000
Uitzonderingscode: 0xc0000005
Foutoffset: 0x0000000000000000
Id van proces met fout: 0x10dc
Starttijd van toepassing met fout: 0xExplorer.EXE0
Pad naar toepassing met fout: Explorer.EXE1
Pad naar module met fout: Explorer.EXE2
Rapport-id: Explorer.EXE3


Error: (12/05/2015 11:35:11 AM) (Source: CVHSVC) (EventID: 100) (User: )
Description: Alleen informatie.
(Patch task for {90140011-0066-0413-0000-0000000FF1CE}): DownloadLatest Failed:


Error: (12/05/2015 08:50:49 AM) (Source: CVHSVC) (EventID: 100) (User: )
Description: Alleen informatie.
(Patch task for {90140011-0066-0413-0000-0000000FF1CE}): DownloadLatest Failed:


Error: (12/04/2015 03:13:19 PM) (Source: CVHSVC) (EventID: 100) (User: )
Description: Alleen informatie.
(Patch task for {90140011-0066-0413-0000-0000000FF1CE}): DownloadLatest Failed:


Error: (12/04/2015 01:29:51 PM) (Source: CVHSVC) (EventID: 100) (User: )
Description: Alleen informatie.
(Patch task for {90140011-0066-0413-0000-0000000FF1CE}): DownloadLatest Failed:


Error: (12/04/2015 01:07:57 PM) (Source: CVHSVC) (EventID: 100) (User: )
Description: Alleen informatie.
(Patch task for {90140011-0066-0413-0000-0000000FF1CE}): DownloadLatest Failed:


Error: (12/02/2015 04:04:04 PM) (Source: CVHSVC) (EventID: 100) (User: )
Description: Alleen informatie.
(Patch task for {90140011-0066-0413-0000-0000000FF1CE}): DownloadLatest Failed:


Error: (12/02/2015 03:38:01 PM) (Source: CVHSVC) (EventID: 100) (User: )
Description: Alleen informatie.
(Patch task for {90140011-0066-0413-0000-0000000FF1CE}): DownloadLatest Failed:




Systeemfouten:
=============
Error: (12/05/2015 10:53:49 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT AUTHORITY)
Description: WLAN-uitbreidingsmodule is onverwacht gestopt.


Pad naar module: C:\Program Files (x86)\Qualcomm Atheros WiFi Driver Installation\AthIhvWlanExt.dll


Error: (12/05/2015 10:53:49 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT AUTHORITY)
Description: WLAN-uitbreidingsmodule is onverwacht gestopt.


Pad naar module: C:\Program Files (x86)\Qualcomm Atheros WiFi Driver Installation\AthIhvWlanExt.dll


Error: (12/05/2015 10:53:38 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT AUTHORITY)
Description: WLAN-uitbreidingsmodule is onverwacht gestopt.


Pad naar module: C:\Program Files (x86)\Qualcomm Atheros WiFi Driver Installation\AthIhvWlanExt.dll


Error: (12/05/2015 10:51:34 PM) (Source: Service Control Manager) (EventID: 7032) (User: )
Description: Servicebesturingsbeheer heeft na het onverwachte afsluiten van de Windows Search-service geprobeerd een herstelactie (Service opnieuw starten) uit te voeren, maar deze actie is met de volgende fout mislukt:
%%1056


Error: (12/05/2015 10:51:09 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: De Application Virtualization Client-service is onverwacht beëindigd. Dit is nu 1 keer gebeurd.


Error: (12/05/2015 10:51:05 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: De Windows Presentation Foundation Font Cache 3.0.0.0-service is onverwacht gestopt. Dit is 1 keer gebeurd. De volgende herstelbewerking zal over 0 milliseconden worden uitgevoerd: Service opnieuw starten.


Error: (12/05/2015 10:51:04 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: De VIA Karaoke digital mixer Service-service is onverwacht beëindigd. Dit is nu 1 keer gebeurd.


Error: (12/05/2015 10:51:04 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: De Windows Live ID Sign-in Assistant-service is onverwacht gestopt. Dit is 1 keer gebeurd. De volgende herstelbewerking zal over 10000 milliseconden worden uitgevoerd: Service opnieuw starten.


Error: (12/05/2015 10:51:04 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: De Client Virtualization Handler-service is onverwacht beëindigd. Dit is nu 1 keer gebeurd.


Error: (12/05/2015 10:51:04 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: De Windows Media Player Network Sharing Service-service is onverwacht gestopt. Dit is 1 keer gebeurd. De volgende herstelbewerking zal over 30000 milliseconden worden uitgevoerd: Service opnieuw starten.




==================== Geheugen info ===========================


Processor: Intel(R) Pentium(R) CPU B970 @ 2.30GHz
Percentage geheugen in gebruik: 58%
Totaal fysiek RAM-geheugen: 3979.96 MB
Beschikbaar fysiek RAM-geheugen: 1667.87 MB
Totaal Virtueel geheugen: 8258.13 MB
Beschikbaar Virtual geheugen: 5910.52 MB


==================== Schijven ================================


Drive c: (OS) (Fixed) (Total:119.24 GB) (Free:45.1 GB) NTFS ==>[systeem met boot componenten (verkregen van schijf)]
Drive d: (DATA) (Fixed) (Total:153.53 GB) (Free:153.42 GB) NTFS


==================== MBR & Partitietabel ==================


========================================================
Disk: 0 (Size: 298.1 GB) (Disk ID: 30EC77D9)


Partition: GPT.


==================== Eind van Addition.txt ============================
 
Scanresultaten van Farbar Recovery Scan Tool (FRST) (x64) Versie:05-12-2015
Gestart door bryan77 (Beheerder) op BRYAN77-PC (05-12-2015 23:03:20)
Gestart vanaf C:\Users\bryan77\Desktop
Geladen Profielen: bryan77 (Beschikbare Profielen: bryan77 & Bryan & Barbara)
Platform: Windows 7 Home Premium Service Pack 1 (X64) Taal: Nederlands (Nederland)
Internet Explorer Versie 11 (Standaardbrowser: Chrome)
Boot Modus: Normal
Handleiding voor Farbar Recovery Scan Tool: FRST Tutorial - How to use Farbar Recovery Scan Tool - Malware Removal Guides and Tutorials


==================== Processen (gefilterd) =================


(Als een item is opgenomen in de fixlist, het proces zal worden gesloten. Het bestand zal niet worden verplaatst.)


(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgrsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgcsrva.exe
(Microsoft Corporation) C:\Windows\System32\wisptis.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
(ASUS) C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnSrv.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgidsagent.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgwdsvcx.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
() C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(VIA Technologies, Inc.) C:\Windows\System32\ViakaraokeSrv.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgnsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgemca.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Desktop.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
(ASUS) C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnWMI.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ATKOSD.exe
(Microsoft Corporation) C:\Windows\System32\wisptis.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\WDC.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe
(ASUS) C:\Program Files\ASUS\P4G\BatteryLife.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\FaceLogon\sensorsrv.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Virtual Touch\QuickGesture\x64\QuickGesture64.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Virtual Touch\QuickGesture\x86\QuickGesture.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
(Alcor Micro Corp.) C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe
(ASUS) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Nico Mak Computing) C:\Program Files\File Association Helper\FAHWindow.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(VIA) C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgui.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Framework\Common\avguix.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(ASUSTeK) C:\Windows\SysWOW64\ACEngSvr.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_w32.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_x64.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDGesture.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\ink\InputPersonalization.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe




==================== Register (gefilterd) ===========================


(Als een item is opgenomen in de fixlist, het registry item zal worden teruggezet naar de standaardwaarden of verwijderd. Het bestand zal niet worden verplaatst.)


HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2661672 2012-05-14] (ELAN Microelectronics Corp.)
HKLM\...\Run: [AmIcoSinglun64] => C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe [361984 2011-03-21] (Alcor Micro Corp.)
HKLM\...\Run: [ACMON] => C:\Program Files (x86)\ASUS\Splendid\ACMON.exe [90792 2012-05-08] (ASUS)
HKLM\...\Run: [FAHConsole] => C:\Program Files\File Association Helper\FAHConsole.exe [729272 2014-01-28] (Nico Mak Computing)
HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291608 2012-02-07] (Intel Corporation)
HKLM-x32\...\Run: [HDAudDeck] => C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [5142128 2012-04-19] (VIA)
HKLM-x32\...\Run: [ATKOSD2] => C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [318080 2011-12-23] (ASUSTek Computer Inc.)
HKLM-x32\...\Run: [ATKMEDIA] => C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [174720 2011-10-25] (ASUS)
HKLM-x32\...\Run: [HControlUser] => C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [105016 2009-06-19] (ASUS)
HKLM-x32\...\Run: [ASUSWebStorage] => C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.108.222\AsusWSPanel.exe [737104 2011-07-29] (ecareme)
HKLM-x32\...\Run: [CLMLServer] => C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe [107816 2010-08-20] (CyberLink)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-10-28] (Hewlett-Packard)
HKLM-x32\...\Run: [AVG_UI] => C:\Program Files (x86)\AVG\Av\avgui.exe [3855272 2015-11-20] (AVG Technologies CZ, s.r.o.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [597040 2015-10-06] (Oracle Corporation)
HKLM-x32\...\Run: [AvgUi] => C:\Program Files (x86)\AVG\Framework\Common\avguix.exe [1136552 2015-11-12] (AVG Technologies CZ, s.r.o.)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
ShellIconOverlayIdentifiers: [###MegaShellExtPending] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => C:\Users\Bryan\AppData\Local\MEGAsync\ShellExtX64.dll Geen bestand
ShellIconOverlayIdentifiers: [###MegaShellExtSynced] -> {05B38830-F4E9-4329-978B-1DD28605D202} => C:\Users\Bryan\AppData\Local\MEGAsync\ShellExtX64.dll Geen bestand
ShellIconOverlayIdentifiers: [###MegaShellExtSyncing] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => C:\Users\Bryan\AppData\Local\MEGAsync\ShellExtX64.dll Geen bestand
ShellIconOverlayIdentifiers: [AsusWSShellExt_B] -> {6D4133E5-0742-4ADC-8A8C-9303440F7190} => C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.108.222\ASUSWSShellExt64.dll [2011-05-25] (eCareme Technologies, Inc.)
ShellIconOverlayIdentifiers: [AsusWSShellExt_O] -> {64174815-8D98-4CE6-8646-4C039977D808} => C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.108.222\ASUSWSShellExt64.dll [2011-05-25] (eCareme Technologies, Inc.)
ShellIconOverlayIdentifiers-x32: [###MegaShellExtPending] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => C:\Users\Bryan\AppData\Local\MEGAsync\ShellExtX32.dll Geen bestand
ShellIconOverlayIdentifiers-x32: [###MegaShellExtSynced] -> {05B38830-F4E9-4329-978B-1DD28605D202} => C:\Users\Bryan\AppData\Local\MEGAsync\ShellExtX32.dll Geen bestand
ShellIconOverlayIdentifiers-x32: [###MegaShellExtSyncing] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => C:\Users\Bryan\AppData\Local\MEGAsync\ShellExtX32.dll Geen bestand
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AsusVibeLauncher.lnk [2012-02-24]
ShortcutTarget: AsusVibeLauncher.lnk -> C:\Program Files (x86)\ASUS\AsusVibe\AsusVibeLauncher.exe (ASUSTeK Computer Inc.)


==================== Internet (gefilterd) ====================


(Als een item is opgenomen in de fixlist, als het een registry item is wordt verwijderd of hersteld naar de standaard.)


Tcpip\Parameters: [DhcpNameServer] 195.130.131.4 195.130.130.132
Tcpip\..\Interfaces\{954017FF-42DA-42FD-84E1-ECB55673A792}: [DhcpNameServer] 195.130.131.4 195.130.130.132
Tcpip\..\Interfaces\{B7BD57C6-76C0-4AB4-AC64-4D8C834D3915}: [DhcpNameServer] 195.130.131.4 195.130.130.132


Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617912&ResetID=130892591560222338&GUID=D4782CC4-99AC-4097-BD5E-2E9FF6B401FD
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617912&ResetID=130892591560242339&GUID=D4782CC4-99AC-4097-BD5E-2E9FF6B401FD
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Google
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = Google
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = Google
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = Google
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Google
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = Google
HKU\S-1-5-21-3732487481-855672253-929003311-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617912&ResetID=130892591573953123&GUID=D4782CC4-99AC-4097-BD5E-2E9FF6B401FD
SearchScopes: HKLM -> DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSERBM&pc=MSERT1
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=ASUTDF&pc=NP06&src=IE-SearchBox
SearchScopes: HKLM -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSERBM&pc=MSERT1
SearchScopes: HKLM-x32 -> DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSERBM&pc=MSERT1
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=ASUTDF&pc=NP06&src=IE-SearchBox
SearchScopes: HKLM-x32 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSERBM&pc=MSERT1
SearchScopes: HKU\S-1-5-21-3732487481-855672253-929003311-1001 -> DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSERBM&pc=MSERT1
SearchScopes: HKU\S-1-5-21-3732487481-855672253-929003311-1001 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSERBM&pc=MSERT1
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_65\bin\ssv.dll [2015-10-24] (Oracle Corporation)
BHO-x32: Aanmeldhulp voor Microsoft-account -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_65\bin\jp2ssv.dll [2015-10-24] (Oracle Corporation)
Toolbar: HKU\S-1-5-21-3732487481-855672253-929003311-1001 -> Geen Naam - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - Geen bestand
DPF: HKLM-x32 {4B54A9DE-EF1C-4EBE-A328-7C28EA3B433A} hxxp://quickscan.bitdefender.com/qsax/qsax.cab
DPF: HKLM-x32 {7530BFB8-7293-4D34-9923-61A11451AFC5} hxxp://download.eset.com/special/eos/OnlineScanner.cab
StartMenuInternet: IEXPLORE.EXE - iexplore.exe


FireFox:
========
FF Plugin: @microsoft.com/GENUINE -> disabled [Geen bestand]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-01-06] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-01-06] (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.65.2 -> C:\Program Files (x86)\Java\jre1.8.0_65\bin\dtplugin\npDeployJava1.dll [2015-10-24] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.65.2 -> C:\Program Files (x86)\Java\jre1.8.0_65\bin\plugin2\npjp2.dll [2015-10-24] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [Geen bestand]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2013-02-05] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3508.0205 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2013-02-05] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-02] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-02] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-09-27] (Adobe Systems Inc.)


Chrome:
=======
CHR Profile: C:\Users\bryan77\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Betalingen via Chrome Web Store) - C:\Users\bryan77\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-07-30]


==================== Services (gefilterd) ========================


(Als een item is opgenomen in de fixlist, wordt uit het register verwijderd. Het bestand zal niet worden verplaatst tenzij apart vermeld.)


R2 ASUS InstantOn; C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnSrv.exe [277120 2012-04-13] (ASUS)
S3 AvgAMPS; C:\Program Files (x86)\AVG\Av\avgamps.exe [615584 2015-11-20] (AVG Technologies CZ, s.r.o.)
R2 AVGIDSAgent; C:\Program Files (x86)\AVG\Av\avgidsagent.exe [3857272 2015-11-20] (AVG Technologies CZ, s.r.o.)
R2 avgsvc; C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe [1046952 2015-11-12] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files (x86)\AVG\Av\avgwdsvcx.exe [579776 2015-11-20] (AVG Technologies CZ, s.r.o.)
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [128280 2012-02-21] ()
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [161560 2012-02-21] (Intel Corporation)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1135416 2015-10-05] (Malwarebytes)
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [5702416 2015-09-11] (TeamViewer GmbH)
R2 VIAKaraokeService; C:\Windows\system32\viakaraokesrv.exe [27760 2012-03-23] (VIA Technologies, Inc.)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)


===================== Drivers (gefilterd) ==========================


(Als een item is opgenomen in de fixlist, wordt uit het register verwijderd. Het bestand zal niet worden verplaatst tenzij apart vermeld.)


R3 AsusVBus; C:\Windows\System32\DRIVERS\AsusVBus.sys [35968 2012-04-12] (Windows (R) Win 7 DDK provider)
R3 AsusVTouch; C:\Windows\System32\DRIVERS\AsusVTouch.sys [16512 2012-04-12] (Windows (R) Win 7 DDK provider)
R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [184240 2015-11-06] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [313776 2015-11-06] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [298416 2015-08-20] (AVG Technologies CZ, s.r.o.)
R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [284080 2015-10-21] (AVG Technologies CZ, s.r.o.)
R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [398256 2015-08-14] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [256432 2015-11-06] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [42416 2015-08-10] (AVG Technologies CZ, s.r.o.)
R1 Avgtdia; C:\Windows\System32\DRIVERS\avgtdia.sys [302000 2015-10-08] (AVG Technologies CZ, s.r.o.)
S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [15416 2009-07-20] ( )
R3 L1C; C:\Windows\System32\DRIVERS\L1C62x64.sys [104560 2012-04-25] (Qualcomm Atheros Co., Ltd.)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-10-05] (Malwarebytes)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-10-05] (Malwarebytes Corporation)


==================== NetSvcs (gefilterd) ===================


(Als een item is opgenomen in de fixlist, wordt uit het register verwijderd. Het bestand zal niet worden verplaatst tenzij apart vermeld.)




==================== Een Maand Aangemaakt bestanden en mappen ========


(Als een item is opgenomen in de fixlist, het bestand/map wordt verplaatst.)


2015-12-05 22:50 - 2015-12-05 22:50 - 00000000 ____D C:\Users\bryan77\Desktop\FRST-OlderVersion
2015-12-05 08:53 - 2015-12-05 08:53 - 00000000 ___HD C:\Windows\AxInstSV
2015-12-04 20:25 - 2015-12-04 20:25 - 00000000 ____D C:\Users\Bryan\AppData\Roaming\AVG
2015-12-04 14:05 - 2015-12-04 15:23 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-12-04 14:04 - 2015-12-04 14:04 - 00001104 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-12-04 14:04 - 2015-12-04 14:04 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-12-04 14:04 - 2015-12-04 14:04 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-12-04 14:04 - 2015-10-05 09:50 - 00109272 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-12-04 14:04 - 2015-10-05 09:50 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-12-04 14:04 - 2015-10-05 09:50 - 00025816 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
2015-12-04 14:02 - 2015-12-05 23:03 - 00000380 _____ C:\Users\bryan77\AppData\Roaming\sp_data.sys
2015-12-03 12:30 - 2015-12-03 12:30 - 00000000 ____D C:\Users\Barbara.bryan77-PC\AppData\Roaming\AVG
2015-12-02 15:36 - 2015-12-02 15:36 - 00001325 _____ C:\Users\bryan77\Desktop\JRT.txt
2015-12-02 15:30 - 2015-12-02 15:30 - 01599336 _____ (Malwarebytes) C:\Users\bryan77\Desktop\JRT.exe
2015-12-02 14:44 - 2015-12-02 14:44 - 01736704 _____ C:\Users\bryan77\Downloads\adwcleaner_5.023 (1).exe
2015-12-02 14:44 - 2015-12-02 14:44 - 01736704 _____ C:\Users\bryan77\Desktop\adwcleaner_5.023.exe
2015-12-02 14:26 - 2015-12-02 14:26 - 00000000 ____D C:\Users\bryan77\AppData\Roaming\AVG
2015-12-02 14:21 - 2015-12-02 14:21 - 00000936 _____ C:\Users\Public\Desktop\AVG.lnk
2015-12-02 14:21 - 2015-12-02 14:21 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG Zen
2015-12-02 14:20 - 2015-12-02 14:24 - 00000000 ____D C:\ProgramData\Avg
2015-12-02 14:19 - 2015-12-02 14:19 - 02970984 _____ (AVG Technologies CZ, s.r.o.) C:\Users\bryan77\Desktop\AVG_Protection_Free_698.exe
2015-12-02 13:41 - 2015-12-02 14:21 - 00000000 ____D C:\Users\bryan77\AppData\Local\AvgSetupLog
2015-12-02 13:39 - 2015-12-05 22:51 - 00003289 _____ C:\Users\bryan77\Desktop\Fixlog.txt
2015-12-02 13:36 - 2015-10-24 10:20 - 00097888 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2015-12-01 21:48 - 2015-12-01 21:49 - 00035072 _____ C:\Users\bryan77\Desktop\Addition.txt
2015-12-01 21:48 - 2015-12-01 21:48 - 00852771 _____ C:\Users\bryan77\Desktop\SecurityCheck.exe
2015-12-01 21:47 - 2015-12-05 23:05 - 00019628 _____ C:\Users\bryan77\Desktop\FRST.txt
2015-12-01 21:46 - 2015-12-05 23:03 - 00000000 ____D C:\FRST
2015-12-01 21:45 - 2015-12-05 22:50 - 02369024 _____ (Farbar) C:\Users\bryan77\Desktop\FRST64.exe
2015-12-01 21:45 - 2015-12-05 11:22 - 00000000 ____D C:\Users\bryan77\Desktop\uitgevoerde stappen
2015-12-01 21:44 - 2015-12-01 21:44 - 02350080 _____ (Farbar) C:\Users\bryan77\Downloads\FRST64.exe
2015-11-22 14:44 - 2015-11-22 14:44 - 00000000 ____D C:\Users\Bryan\AppData\Roaming\Sun
2015-11-22 14:29 - 2015-11-22 14:29 - 00000000 ____D C:\Users\Barbara.bryan77-PC\AppData\Local\AvgSetupLog
2015-11-21 16:10 - 2015-11-21 16:10 - 00679936 _____ C:\Users\Bryan\Downloads\Detection (10).msi
2015-11-15 20:44 - 2015-11-15 11:44 - 00159444 ____N C:\Users\Barbara.bryan77-PC\Desktop\Kasverkoop nr 128 - 06-11-2015- Barbara Verbist.pdf
2015-11-15 20:36 - 2015-11-15 20:36 - 00001376 _____ C:\Users\bryan77\Desktop\Photo Gallery.lnk
2015-11-15 20:34 - 2015-11-15 20:34 - 00001116 _____ C:\Users\bryan77\Desktop\Afbeeldingen - Snelkoppeling.lnk
2015-11-15 19:43 - 2015-11-15 19:43 - 00000000 ____D C:\Users\bryan77\Desktop\AdminPc
2015-11-15 19:36 - 2015-11-03 18:55 - 03211264 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-11-15 19:35 - 2015-10-20 19:42 - 03168768 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2015-11-15 19:35 - 2015-10-20 19:42 - 02608128 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2015-11-15 19:35 - 2015-10-20 19:42 - 00696320 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2015-11-15 19:35 - 2015-10-20 19:42 - 00192512 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2015-11-15 19:35 - 2015-10-20 19:42 - 00098816 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2015-11-15 19:35 - 2015-10-20 19:42 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2015-11-15 19:35 - 2015-10-20 19:42 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2015-11-15 19:35 - 2015-10-20 19:41 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2015-11-15 19:35 - 2015-10-20 19:41 - 00091136 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
2015-11-15 19:35 - 2015-10-20 19:41 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2015-11-15 19:35 - 2015-10-20 19:41 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll
2015-11-15 19:35 - 2015-10-20 18:46 - 00566784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2015-11-15 19:35 - 2015-10-20 18:46 - 00174080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2015-11-15 19:35 - 2015-10-20 18:46 - 00093696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2015-11-15 19:35 - 2015-10-20 18:46 - 00030208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2015-11-15 19:35 - 2015-10-20 18:45 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2015-11-15 19:34 - 2015-11-03 23:10 - 00390344 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-11-15 19:34 - 2015-11-03 22:51 - 00342728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2015-11-15 19:34 - 2015-10-31 00:46 - 25818624 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-11-15 19:34 - 2015-10-31 00:40 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-11-15 19:34 - 2015-10-31 00:40 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2015-11-15 19:34 - 2015-10-31 00:25 - 02886656 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-11-15 19:34 - 2015-10-31 00:25 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-11-15 19:34 - 2015-10-31 00:25 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2015-11-15 19:34 - 2015-10-31 00:25 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2015-11-15 19:34 - 2015-10-31 00:24 - 00585728 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-11-15 19:34 - 2015-10-31 00:24 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2015-11-15 19:34 - 2015-10-31 00:17 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-11-15 19:34 - 2015-10-31 00:16 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2015-11-15 19:34 - 2015-10-31 00:13 - 00616960 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-11-15 19:34 - 2015-10-31 00:12 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-11-15 19:34 - 2015-10-31 00:12 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2015-11-15 19:34 - 2015-10-31 00:11 - 05990912 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-11-15 19:34 - 2015-10-31 00:11 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-11-15 19:34 - 2015-10-31 00:11 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2015-11-15 19:34 - 2015-10-31 00:04 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2015-11-15 19:34 - 2015-10-31 00:01 - 00489984 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-11-15 19:34 - 2015-10-30 23:58 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2015-11-15 19:34 - 2015-10-30 23:53 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-11-15 19:34 - 2015-10-30 23:52 - 20331520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2015-11-15 19:34 - 2015-10-30 23:49 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2015-11-15 19:34 - 2015-10-30 23:49 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-11-15 19:34 - 2015-10-30 23:47 - 00504832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2015-11-15 19:34 - 2015-10-30 23:46 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-11-15 19:34 - 2015-10-30 23:46 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2015-11-15 19:34 - 2015-10-30 23:45 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2015-11-15 19:34 - 2015-10-30 23:45 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2015-11-15 19:34 - 2015-10-30 23:44 - 00152064 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2015-11-15 19:34 - 2015-10-30 23:44 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2015-11-15 19:34 - 2015-10-30 23:42 - 02279936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2015-11-15 19:34 - 2015-10-30 23:39 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2015-11-15 19:34 - 2015-10-30 23:39 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2015-11-15 19:34 - 2015-10-30 23:37 - 00480256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2015-11-15 19:34 - 2015-10-30 23:36 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2015-11-15 19:34 - 2015-10-30 23:36 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2015-11-15 19:34 - 2015-10-30 23:36 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2015-11-15 19:34 - 2015-10-30 23:34 - 00262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2015-11-15 19:34 - 2015-10-30 23:32 - 00720896 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-11-15 19:34 - 2015-10-30 23:31 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-11-15 19:34 - 2015-10-30 23:29 - 02126336 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-11-15 19:34 - 2015-10-30 23:29 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2015-11-15 19:34 - 2015-10-30 23:28 - 00416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2015-11-15 19:34 - 2015-10-30 23:23 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2015-11-15 19:34 - 2015-10-30 23:22 - 14457856 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-11-15 19:34 - 2015-10-30 23:21 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2015-11-15 19:34 - 2015-10-30 23:19 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2015-11-15 19:34 - 2015-10-30 23:18 - 00279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2015-11-15 19:34 - 2015-10-30 23:17 - 02487808 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-11-15 19:34 - 2015-10-30 23:17 - 00130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2015-11-15 19:34 - 2015-10-30 23:16 - 04527616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2015-11-15 19:34 - 2015-10-30 23:11 - 00230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2015-11-15 19:34 - 2015-10-30 23:10 - 00689152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2015-11-15 19:34 - 2015-10-30 23:09 - 12854272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2015-11-15 19:34 - 2015-10-30 23:09 - 02052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2015-11-15 19:34 - 2015-10-30 23:09 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2015-11-15 19:34 - 2015-10-30 23:04 - 01547264 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-11-15 19:34 - 2015-10-30 22:53 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-11-15 19:34 - 2015-10-30 22:51 - 02011136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2015-11-15 19:34 - 2015-10-30 22:48 - 01311744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2015-11-15 19:34 - 2015-10-30 22:46 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2015-11-15 19:33 - 2015-10-29 18:50 - 00342016 _____ (Microsoft Corporation) C:\Windows\system32\apphelp.dll
2015-11-15 19:33 - 2015-10-29 18:50 - 00072192 _____ (Microsoft Corporation) C:\Windows\system32\aelupsvc.dll
2015-11-15 19:33 - 2015-10-29 18:50 - 00023552 _____ (Microsoft Corporation) C:\Windows\system32\sdbinst.exe
2015-11-15 19:33 - 2015-10-29 18:50 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\shimeng.dll
2015-11-15 19:33 - 2015-10-29 18:50 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shimeng.dll
2015-11-15 19:33 - 2015-10-29 18:49 - 00295936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apphelp.dll
2015-11-15 19:33 - 2015-10-29 18:49 - 00020992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sdbinst.exe
2015-11-15 19:33 - 2015-10-20 02:12 - 05570496 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-11-15 19:33 - 2015-10-20 02:12 - 00154560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2015-11-15 19:33 - 2015-10-20 02:12 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2015-11-15 19:33 - 2015-10-20 02:09 - 01730496 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2015-11-15 19:33 - 2015-10-20 02:06 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2015-11-15 19:33 - 2015-10-20 02:06 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2015-11-15 19:33 - 2015-10-20 02:06 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2015-11-15 19:33 - 2015-10-20 02:06 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2015-11-15 19:33 - 2015-10-20 02:05 - 01461760 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2015-11-15 19:33 - 2015-10-20 02:05 - 01216512 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2015-11-15 19:33 - 2015-10-20 02:05 - 01164800 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2015-11-15 19:33 - 2015-10-20 02:05 - 00729600 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2015-11-15 19:33 - 2015-10-20 02:05 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-11-15 19:33 - 2015-10-20 02:05 - 00424960 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2015-11-15 19:33 - 2015-10-20 02:05 - 00344064 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-11-15 19:33 - 2015-10-20 02:05 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2015-11-15 19:33 - 2015-10-20 02:05 - 00312320 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2015-11-15 19:33 - 2015-10-20 02:05 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-11-15 19:33 - 2015-10-20 02:05 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2015-11-15 19:33 - 2015-10-20 02:05 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2015-11-15 19:33 - 2015-10-20 02:05 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2015-11-15 19:33 - 2015-10-20 02:05 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2015-11-15 19:33 - 2015-10-20 02:05 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-11-15 19:33 - 2015-10-20 02:05 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2015-11-15 19:33 - 2015-10-20 02:05 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2015-11-15 19:33 - 2015-10-20 02:05 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2015-11-15 19:33 - 2015-10-20 02:05 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2015-11-15 19:33 - 2015-10-20 02:05 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2015-11-15 19:33 - 2015-10-20 02:05 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2015-11-15 19:33 - 2015-10-20 02:04 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2015-11-15 19:33 - 2015-10-20 02:04 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2015-11-15 19:33 - 2015-10-20 02:04 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2015-11-15 19:33 - 2015-10-20 02:00 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2015-11-15 19:33 - 2015-10-20 01:59 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2015-11-15 19:33 - 2015-10-20 01:53 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2015-11-15 19:33 - 2015-10-20 01:53 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2015-11-15 19:33 - 2015-10-20 01:53 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:53 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:53 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:53 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:53 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:53 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:53 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:53 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:53 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:53 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:53 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:53 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:53 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:53 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:53 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:52 - 03991488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2015-11-15 19:33 - 2015-10-20 01:52 - 03935680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2015-11-15 19:33 - 2015-10-20 01:48 - 01311768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2015-11-15 19:33 - 2015-10-20 01:45 - 00552960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2015-11-15 19:33 - 2015-10-20 01:45 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2015-11-15 19:33 - 2015-10-20 01:45 - 00251392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2015-11-15 19:33 - 2015-10-20 01:45 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2015-11-15 19:33 - 2015-10-20 01:45 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2015-11-15 19:33 - 2015-10-20 01:45 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2015-11-15 19:33 - 2015-10-20 01:45 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2015-11-15 19:33 - 2015-10-20 01:45 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll
2015-11-15 19:33 - 2015-10-20 01:45 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2015-11-15 19:33 - 2015-10-20 01:45 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2015-11-15 19:33 - 2015-10-20 01:45 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2015-11-15 19:33 - 2015-10-20 01:45 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2015-11-15 19:33 - 2015-10-20 01:44 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2015-11-15 19:33 - 2015-10-20 01:44 - 00665088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2015-11-15 19:33 - 2015-10-20 01:44 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2015-11-15 19:33 - 2015-10-20 01:44 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2015-11-15 19:33 - 2015-10-20 01:44 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2015-11-15 19:33 - 2015-10-20 01:44 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2015-11-15 19:33 - 2015-10-20 01:39 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2015-11-15 19:33 - 2015-10-20 01:39 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2015-11-15 19:33 - 2015-10-20 01:35 - 00686080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2015-11-15 19:33 - 2015-10-20 01:35 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2015-11-15 19:33 - 2015-10-20 01:35 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:35 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:35 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:35 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:35 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:35 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:35 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:35 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:35 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:35 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:35 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:35 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:35 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 00:41 - 00159232 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2015-11-15 19:33 - 2015-10-20 00:40 - 00290816 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2015-11-15 19:33 - 2015-10-20 00:40 - 00129024 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2015-11-15 19:33 - 2015-10-20 00:29 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2015-11-15 19:33 - 2015-10-20 00:29 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2015-11-15 19:33 - 2015-10-20 00:27 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 00:27 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 00:27 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2015-11-15 19:33 - 2015-10-20 00:27 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2015-11-15 19:33 - 2015-10-13 17:41 - 00497664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2015-11-15 19:33 - 2015-10-13 17:40 - 00118272 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdx.sys
2015-11-15 19:33 - 2015-09-23 14:15 - 00460776 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2015-11-15 19:33 - 2015-09-23 14:15 - 00299632 _____ (Microsoft Corporation) C:\Windows\system32\bcryptprimitives.dll
2015-11-15 19:33 - 2015-09-23 14:09 - 00251000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcryptprimitives.dll
2015-11-15 19:27 - 2015-11-15 19:27 - 00000000 ____D C:\Users\bryan77\AppData\Local\Mega Limited
2015-11-15 19:24 - 2015-10-13 05:57 - 00950720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys
2015-11-15 19:24 - 2015-10-01 19:00 - 00275456 _____ (Microsoft Corporation) C:\Windows\system32\InkEd.dll
2015-11-15 19:24 - 2015-10-01 19:00 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\jnwmon.dll
2015-11-15 19:24 - 2015-10-01 18:50 - 00216064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InkEd.dll
2015-11-09 08:55 - 2015-11-09 08:55 - 00120507 _____ C:\Users\Barbara.bryan77-PC\Downloads\105521 (1).pdf
2015-11-09 08:51 - 2015-11-09 08:51 - 00120507 _____ C:\Users\Barbara.bryan77-PC\Downloads\105521.pdf
2015-11-06 15:50 - 2015-11-06 15:50 - 00184240 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgdiska.sys
2015-11-06 15:49 - 2015-11-06 15:49 - 00313776 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgidsdrivera.sys
2015-11-06 15:49 - 2015-11-06 15:49 - 00256432 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgmfx64.sys


==================== Een Maand Gewijzigd bestanden en mappen ========


(Als een item is opgenomen in de fixlist, het bestand/map wordt verplaatst.)


2015-12-05 23:04 - 2012-02-24 03:29 - 00001056 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-12-05 22:57 - 2013-12-01 22:44 - 00000828 _____ C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job
2015-12-05 22:57 - 2012-02-24 03:29 - 00001052 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-12-05 22:55 - 2013-12-01 20:07 - 00000000 ____D C:\ProgramData\MFAData
2015-12-05 22:55 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-12-05 22:46 - 2009-07-14 05:45 - 00009920 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-12-05 22:46 - 2009-07-14 05:45 - 00009920 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-12-05 22:44 - 2013-12-08 21:48 - 00000940 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-12-05 22:22 - 2014-09-15 18:06 - 00000000 ____D C:\Users\Bryan\AppData\Roaming\Software Informer
2015-12-05 20:29 - 2015-06-03 11:41 - 00000000 ____D C:\Users\Bryan\AppData\Local\Spotify
2015-12-05 20:29 - 2015-06-03 11:40 - 00000000 ____D C:\Users\Bryan\AppData\Roaming\Spotify
2015-12-05 20:29 - 2013-12-01 21:06 - 00000380 _____ C:\Users\Bryan\AppData\Roaming\sp_data.sys
2015-12-05 12:12 - 2013-12-01 22:44 - 00000830 _____ C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job
2015-12-05 11:43 - 2013-12-01 20:24 - 00000380 _____ C:\Users\Barbara.bryan77-PC\AppData\Roaming\sp_data.sys
2015-12-05 08:53 - 2009-07-14 06:32 - 00000000 ____D C:\Windows\Downloaded Program Files
2015-12-05 08:53 - 2009-07-14 04:20 - 00000000 ____D C:\Windows
2015-12-05 08:52 - 2015-05-21 19:40 - 00000000 __SHD C:\Users\bryan77\AppData\Local\EmieUserList
2015-12-05 08:52 - 2015-05-21 19:40 - 00000000 __SHD C:\Users\bryan77\AppData\Local\EmieSiteList
2015-12-05 08:52 - 2015-05-21 19:40 - 00000000 __SHD C:\Users\bryan77\AppData\Local\EmieBrowserModeList
2015-12-04 20:25 - 2014-11-26 08:12 - 00000000 ____D C:\Users\Bryan\AppData\Local\Avg
2015-12-04 15:02 - 2009-07-14 06:32 - 00000000 ____D C:\Windows\Performance
2015-12-04 14:02 - 2014-11-06 21:55 - 00000000 ____D C:\Program Files (x86)\TeamViewer
2015-12-02 17:59 - 2012-02-24 03:29 - 00004052 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2015-12-02 17:59 - 2012-02-24 03:29 - 00003800 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2015-12-02 15:34 - 2011-02-19 05:40 - 00746450 _____ C:\Windows\system32\perfh013.dat
2015-12-02 15:34 - 2011-02-19 05:40 - 00154112 _____ C:\Windows\system32\perfc013.dat
2015-12-02 15:34 - 2009-07-14 06:13 - 01672504 _____ C:\Windows\system32\PerfStringBackup.INI
2015-12-02 15:34 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\inf
2015-12-02 15:25 - 2014-11-27 23:08 - 00000000 ____D C:\AdwCleaner
2015-12-02 14:34 - 2013-12-01 20:15 - 00000000 ____D C:\ProgramData\AVG2014
2015-12-02 14:26 - 2014-11-26 08:12 - 00000000 ____D C:\Users\bryan77\AppData\Local\Avg
2015-12-02 14:26 - 2014-08-28 07:09 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
2015-12-02 14:26 - 2013-12-01 20:15 - 00000000 ___HD C:\$AVG
2015-12-02 14:26 - 2013-12-01 20:13 - 00000000 ____D C:\Program Files (x86)\AVG
2015-12-02 14:25 - 2015-06-26 08:09 - 00000000 ____D C:\Program Files\Common Files\AV
2015-12-02 13:39 - 2013-12-01 17:57 - 00001144 _____ C:\Users\bryan77\Desktop\Internet Explorer.lnk
2015-12-02 13:39 - 2013-12-01 14:19 - 00001144 _____ C:\Users\bryan77\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-12-02 13:36 - 2014-12-02 23:36 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2015-12-01 21:40 - 2009-07-14 06:09 - 00000000 ____D C:\Windows\System32\Tasks\WPD
2015-11-22 14:44 - 2015-10-27 19:41 - 00000000 ____D C:\Users\Bryan\.oracle_jre_usage
2015-11-22 14:29 - 2014-11-26 08:12 - 00000000 ____D C:\Users\Barbara.bryan77-PC\AppData\Local\Avg
2015-11-16 04:06 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache
2015-11-16 03:29 - 2009-07-14 05:45 - 00270888 _____ C:\Windows\system32\FNTCACHE.DAT
2015-11-16 03:24 - 2015-06-03 21:56 - 00000000 ____D C:\Windows\system32\MRT
2015-11-16 03:11 - 2015-06-03 21:55 - 145617392 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-11-16 03:03 - 2012-02-24 03:28 - 01647172 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2015-11-16 03:02 - 2009-07-14 08:45 - 00000000 ____D C:\Program Files\Windows Journal
2015-11-15 20:36 - 2013-12-01 19:25 - 00000000 ____D C:\Users\bryan77\AppData\Local\Windows Live
2015-11-15 19:44 - 2013-12-08 21:48 - 00780488 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-11-15 19:44 - 2013-12-08 21:48 - 00142536 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-11-15 19:44 - 2013-12-08 21:48 - 00003878 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-11-15 19:43 - 2014-11-21 21:01 - 00000000 ____D C:\Users\AdminPc
2015-11-15 19:32 - 2009-07-14 04:20 - 00000000 __RHD C:\Users\Public\Libraries
2015-11-15 19:27 - 2014-10-01 09:20 - 00000000 ____D C:\Users\Bryan\AppData\Local\MEGAsync
2015-11-15 19:15 - 2014-07-29 10:51 - 00000000 ____D C:\Users\bryan77\AppData\Roaming\.minecraft
2015-11-15 19:02 - 2013-12-01 21:05 - 00000000 ____D C:\Users\Bryan
2015-11-15 19:02 - 2013-12-01 14:18 - 00000000 ____D C:\Users\bryan77
2015-11-13 00:29 - 2015-04-05 02:00 - 00000000 ___SD C:\Windows\system32\GWX
2015-11-13 00:29 - 2013-12-08 21:48 - 00000000 ____D C:\Windows\system32\Macromed
2015-11-13 00:29 - 2013-12-01 20:24 - 00000000 ____D C:\Users\Barbara.bryan77-PC
2015-11-13 00:29 - 2012-02-24 03:29 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-11-13 00:29 - 2009-07-14 08:44 - 00000000 ___RD C:\Users\Public\Recorded TV
2015-11-13 00:29 - 2009-07-14 04:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared
2015-11-13 00:28 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\registration
2015-11-07 11:11 - 2014-08-11 12:27 - 00000184 _____ C:\Users\Bryan\Downloads\eula.txt


==================== Bestanden in de root van sommige mappen =======


2015-12-04 14:02 - 2015-12-05 23:03 - 0000380 _____ () C:\Users\bryan77\AppData\Roaming\sp_data.sys
2014-04-16 18:15 - 2014-04-16 18:15 - 0000057 _____ () C:\ProgramData\Ament.ini
2012-02-24 03:42 - 2010-10-06 18:45 - 0131984 _____ () C:\ProgramData\FullRemove.exe
2013-12-01 14:06 - 2013-12-01 14:06 - 0000109 _____ () C:\ProgramData\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}.log
2013-12-01 14:05 - 2013-12-01 14:06 - 0000105 _____ () C:\ProgramData\{40BF1E83-20EB-11D8-97C5-0009C5020658}.log
2013-12-01 14:04 - 2013-12-01 14:05 - 0000107 _____ () C:\ProgramData\{C59C179C-668D-49A9-B6EA-0121CCFC1243}.log


==================== Bamital & volsnap =================


(Er is geen automatische fix voor bestanden die de verificatie niet doorkomen.)


C:\Windows\system32\winlogon.exe => Bestand is getekend
C:\Windows\system32\wininit.exe => Bestand is getekend
C:\Windows\SysWOW64\wininit.exe => Bestand is getekend
C:\Windows\explorer.exe => Bestand is getekend
C:\Windows\SysWOW64\explorer.exe => Bestand is getekend
C:\Windows\system32\svchost.exe => Bestand is getekend
C:\Windows\SysWOW64\svchost.exe => Bestand is getekend
C:\Windows\system32\services.exe => Bestand is getekend
C:\Windows\system32\User32.dll => Bestand is getekend
C:\Windows\SysWOW64\User32.dll => Bestand is getekend
C:\Windows\system32\userinit.exe => Bestand is getekend
C:\Windows\SysWOW64\userinit.exe => Bestand is getekend
C:\Windows\system32\rpcss.dll => Bestand is getekend
C:\Windows\system32\dnsapi.dll => Bestand is getekend
C:\Windows\SysWOW64\dnsapi.dll => Bestand is getekend
C:\Windows\system32\Drivers\volsnap.sys => Bestand is getekend




LastRegBack: 2015-11-30 00:25


==================== Eind van FRST.txt ============================


Extra scanresultaten van Farbar Recovery Scan Tool (x64) Versie:05-12-2015
Gestart door bryan77 (2015-12-05 23:06:18)
Gestart vanaf C:\Users\bryan77\Desktop
Windows 7 Home Premium Service Pack 1 (X64) (2013-12-01 13:17:59)
Boot Modus: Normal
==========================================================




==================== Accounts: =============================


Administrator (S-1-5-21-3732487481-855672253-929003311-500 - Administrator - Disabled)
Barbara (S-1-5-21-3732487481-855672253-929003311-1006 - Limited - Enabled) => C:\Users\Barbara.bryan77-PC
Bryan (S-1-5-21-3732487481-855672253-929003311-1005 - Limited - Enabled) => C:\Users\Bryan
bryan77 (S-1-5-21-3732487481-855672253-929003311-1001 - Administrator - Enabled) => C:\Users\bryan77
Gast (S-1-5-21-3732487481-855672253-929003311-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-3732487481-855672253-929003311-1002 - Limited - Enabled)


==================== Security Center ========================


(Als een item is opgenomen in de fixlist, zal het worden verwijderd.)


AV: AVG AntiVirus Free Edition (Enabled - Up to date) {4D41356F-32AD-7C42-C820-63775EE4F413}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: AVG AntiVirus Free Edition (Enabled - Up to date) {F620D48B-1497-73CC-F290-58052563BEAE}


==================== Geïnstalleerde programma's ======================


(Alleen de adware-programma's met 'verborgen' vlag zou kunnen worden toegevoegd aan de fixlist om ze zichtbaar te maken. De adware-programma's moeten handmatig gedeinstallerd worden.)


Adobe Flash Player 10 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 10.0.32.18 - Adobe Systems Incorporated)
Adobe Flash Player 19 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 19.0.0.245 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.13) - Nederlands (HKLM-x32\...\{AC76BA86-7AD7-1043-7B44-AB0000000001}) (Version: 11.0.13 - Adobe Systems Incorporated)
Alcor Micro USB Card Reader (HKLM-x32\...\AmUStor) (Version: 1.2.0117.08443 - Alcor Micro Corp.)
Alcor Micro USB Card Reader (x32 Version: 1.2.0117.08443 - Alcor Micro Corp.) Hidden
ASUS AI Recovery (HKLM-x32\...\{D39F0676-163E-4595-A917-E28F99BBD4D2}) (Version: 1.0.24 - ASUS)
ASUS FaceLogon (HKLM-x32\...\{64452561-169F-4A36-A2FF-B5E118EC65F5}) (Version: 1.0.0014 - ASUS)
ASUS Instant Connect (HKLM-x32\...\{89ECB85A-D933-4CEA-9116-5CBC9C2ED95B}) (Version: 1.2.2 - ASUS)
ASUS LifeFrame3 (HKLM-x32\...\{1DBD1F12-ED93-49C0-A7CC-56CBDE488158}) (Version: 3.1.1 - ASUS)
ASUS Live Update (HKLM-x32\...\{FA540E67-095C-4A1B-97BA-4D547DEC9AF4}) (Version: 3.1.5 - ASUS)
ASUS Power4Gear Hybrid (HKLM\...\{9B6239BF-4E85-4590-8D72-51E30DB1A9AA}) (Version: 1.2.1 - ASUS)
ASUS Splendid Video Enhancement Technology (HKLM-x32\...\{0969AF05-4FF6-4C00-9406-43599238DE0D}) (Version: 1.03.0001 - ASUS)
ASUS USB Charger Plus (HKLM-x32\...\{A859E3E5-C62F-4BFA-AF1D-2B95E03166AF}) (Version: 2.1.1 - ASUS)
ASUS Virtual Camera (HKLM-x32\...\{EC8BD21F-0CA0-4BBF-97D9-4A52B30041A1}) (Version: 1.0.25 - ASUS)
ASUS Virtual Touch (HKLM-x32\...\{938CFBD4-0652-49E5-BB8B-153948865941}) (Version: 1.0.11 - ASUS)
ASUS WebStorage (HKLM-x32\...\ASUS WebStorage) (Version: 3.0.108.222 - eCareme Technologies, Inc.)
AsusVibe2.0 (HKLM-x32\...\Asus Vibe2.0) (Version: 2.0.9.157 - ASUSTEK)
Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver (HKLM-x32\...\{3108C217-BE83-42E4-AE9E-A56A2A92E549}) (Version: 2.0.15.16 - Atheros Communications Inc.)
ATK Package (HKLM-x32\...\{AB5C933E-5C7D-4D30-B314-9C83A49B94BE}) (Version: 1.0.0015 - ASUS)
AVG (HKLM\...\AvgZen) (Version: 1.22.1.40089 - AVG Technologies)
AVG (Version: 16.12.7294 - AVG Technologies) Hidden
AVG 2016 (Version: 16.0.4483 - AVG Technologies) Hidden
AVG Protection (HKLM\...\AVG) (Version: 2016.12.7294 - AVG Technologies)
AVG Zen (Version: 1.22.1 - AVG Technologies) Hidden
Bubbletown (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-115065740}) (Version: - Oberon Media)
Contenta Converter PREMIUM (HKLM-x32\...\ContentaConverter-PREMIUM) (Version: - Contenta Software)
CyberLink LabelPrint (HKLM-x32\...\InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}) (Version: 2.5.3624 - CyberLink Corp.)
CyberLink Media Suite (HKLM-x32\...\InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}) (Version: 8.0.2926 - CyberLink Corp.)
CyberLink Power2Go (HKLM-x32\...\InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 7.0.0.1126 - CyberLink Corp.)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Deadtime Stories (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-118716773}) (Version: - Oberon Media)
Dream Day First Home (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-113832110}) (Version: - Oberon Media)
Dream Vacation Solitaire (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111249233}) (Version: - Oberon Media)
ESET Online Scanner v3 (HKLM-x32\...\ESET Online Scanner) (Version: - )
ETDWare PS/2-X64 10.5.10.0 (HKLM\...\Elantech) (Version: 10.5.10.0 - ELAN Microelectronic Corp.)
Farm Frenzy 3 - Madagascar (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-119205603}) (Version: - Oberon Media)
FMW 1 (Version: 1.32.2 - AVG Technologies) Hidden
Fotogalerie (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Galapago (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111307457}) (Version: - Oberon Media)
Galeria de Fotografias (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Galería de fotos (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Galerie de photos (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Game Park Console (HKLM-x32\...\Game Park Console) (Version: 1.2.4.431 - Oberon Media Inc.)
Go Go Gourmet Chef of the Year (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-115290153}) (Version: - Oberon Media)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 47.0.2526.73 - Google Inc.)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.29.1 - Google Inc.) Hidden
HP Deskjet 1050 J410 series Basissoftware van het apparaat (HKLM\...\{FA37D2E8-0A8B-46D2-A74A-310F935DE920}) (Version: 28.0.1313.0 - Hewlett-Packard Co.)
HP Deskjet 1050 J410 series Haelp (HKLM-x32\...\{5C90D8CF-F12A-41C6-9007-3B651A1F0D78}) (Version: 140.0.66.66 - Hewlett Packard)
HP Deskjet 1050 J410 series Productverbeteringsonderzoek (HKLM\...\{44C6BB22-7E25-4A6D-8851-6FB26407D9C1}) (Version: 28.0.1313.0 - Hewlett-Packard Co.)
HP Photo Creations (HKLM-x32\...\HP Photo Creations) (Version: 1.0.0.7702 - HP)
HP Update (HKLM-x32\...\{6F1C00D2-25C2-4CBA-8126-AE9A6E2E9CD5}) (Version: 5.003.003.001 - Hewlett-Packard)
InstantOn for NB (HKLM-x32\...\{749F674B-2674-47E8-879C-5626A06B2A91}) (Version: 2.3.3 - ASUS)
Intel(R) Manageability Engine Firmware Recovery Agent (HKLM-x32\...\{A6C48A9F-694A-4234-B3AA-62590B668927}) (Version: 1.0.0.35342 - Intel Corporation)
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.0.3.1427 - Intel Corporation)
Intel(R) OpenCL CPU Runtime (HKLM-x32\...\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2653 - Intel Corporation)
Intel(R) USB 3.0 eXtensible Host Controller Driver (HKLM-x32\...\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 1.0.3.214 - Intel Corporation)
Intel® Trusted Connect Service Client (HKLM\...\{09536BA1-E498-4CC3-B834-D884A67D7E34}) (Version: 1.23.605.1 - Intel Corporation)
Java 8 Update 65 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218065F0}) (Version: 8.0.650.17 - Oracle Corporation)
Junk Mail filter update (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Mahjong Memoirs (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-117948443}) (Version: - Oberon Media)
Malwarebytes Anti-Malware versie 2.2.0.1024 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.0.1024 - Malwarebytes)
MediaFire Desktop (HKLM-x32\...\MediaFire Desktop 1.3.9.10486) (Version: 1.3.9.10486 - MediaFire)
Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft Office 2010 (HKLM-x32\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office Klik-en-Klaar 2010 (HKLM-x32\...\Office14.Click2Run) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office Starter 2010 - Nederlands (HKLM-x32\...\{90140011-0066-0413-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft PowerPoint Viewer (HKLM-x32\...\{95140000-00AF-0413-0000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40728.0 - Microsoft Corporation)
Microsoft SkyDrive (HKU\S-1-5-21-3732487481-855672253-929003311-1001\...\SkyDriveSetup.exe) (Version: 16.4.6013.0910 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Movie Maker (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
myBitCast 1.0.0.3 (HKLM\...\myBitCast) (Version: 1.0.0.3 - ASUS Cloud Corporation)
Plants vs Zombies (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-117080787}) (Version: - Oberon Media)
Platform (x32 Version: 1.39 - VIA Technologies, Inc.) Hidden
Qualcomm Atheros WiFi Driver Installation (HKLM-x32\...\{7D916FA5-DAE9-4A25-B089-655C70EAF607}) (Version: 3.0 - Qualcomm Atheros)
Raccolta foto (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
SceneSwitch (HKLM-x32\...\{5172E572-C175-4F80-A6D5-5CB45826AD61}) (Version: 1.0.12 - ASUS)
TeamViewer 10 (HKLM-x32\...\TeamViewer) (Version: 10.0.47484 - TeamViewer)
Turbo Fiesta (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-115320460}) (Version: - Oberon Media)
VIA Platform Device Manager (HKLM-x32\...\InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}) (Version: 1.39 - VIA Technologies, Inc.)
Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
Visual Studio 2012 x86 Redistributables (HKLM-x32\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3508.0205 - Microsoft Corporation)
Windows Phone app for desktop (HKLM-x32\...\{54EC61F0-6D02-450E-9F1B-9506EAE9F23C}) (Version: 1.1.2726.0 - Microsoft Corporation)
WinFlash (HKLM-x32\...\{8F21291E-0444-4B1D-B9F9-4370A73E346D}) (Version: 2.41.0 - ASUS)
WinRAR 5.01 (32-bit) (HKLM-x32\...\WinRAR archiver) (Version: 5.01.0 - win.rar GmbH)
WinZip 18.5 (HKLM\...\{CD95F661-A5C4-44F5-A6AA-ECDD91C240E3}) (Version: 18.5.11111 - WinZip Computing, S.L. )
Wireless Console 3 (HKLM-x32\...\{19EA33FB-B34E-40EA-8B8A-61743AEB795A}) (Version: 3.0.30 - ASUS)
World of Goo (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-116672750}) (Version: - Oberon Media)
Συλλογή φωτογραφιών (HKLM-x32\...\{032CB0D7-FDBF-4CA9-901B-A4C1B01B1777}) (Version: 16.4.3508.0205 - Microsoft Corporation)
Основные компоненты Windows Live (HKLM-x32\...\{7A9122B2-CF90-4ACB-8E10-AA83F725916B}) (Version: 16.4.3508.0205 - Microsoft Corporation)
Почта Windows Live (HKLM-x32\...\{44B4333A-60A6-4FFC-BCC5-B0ECA23D2AAB}) (Version: 16.4.3508.0205 - Корпорация Майкрософт)
Фотоальбом (HKLM-x32\...\{CE4EEFE0-85E0-436E-95C5-BCB2EE30C976}) (Version: 16.4.3508.0205 - Microsoft Corporation)
Фотографии (общедоступная версия) (HKLM-x32\...\{234BD64C-99F4-42B5-837F-82F00E37A7E1}) (Version: 16.4.3508.0205 - Microsoft Corporation)
גלריית התמונות (HKLM-x32\...\{B1AC8AF0-2979-4DF8-AE26-B1D543F3543F}) (Version: 16.4.3508.0205 - Microsoft Corporation)
بريد Windows Live (HKLM-x32\...\{7A546E5C-0906-42CC-92DF-B2E787FFA7D2}) (Version: 16.4.3508.0205 - Microsoft Corporation)
معرض الصور (HKLM-x32\...\{6F77C156-7660-4CEC-8793-97D80D5BFEC0}) (Version: 16.4.3508.0205 - Microsoft Corporation)
影像中心 (HKLM-x32\...\{7DB15F28-5E38-476A-A773-EA07EAEAB1B3}) (Version: 16.4.3508.0205 - Microsoft Corporation)


==================== Aangepaste CLSID (gefilterd): ==========================


(Als een item is opgenomen in de fixlist, wordt uit het register verwijderd. Het bestand zal niet worden verplaatst tenzij apart vermeld.)




==================== Herstelpunten =========================


05-12-2015 22:50:35 Restore Point Created by FRST


==================== Hosts inhoud: ===============================


(Als nodig Hosts: opdracht kan worden opgenomen in de fixlist om Hosts te resetten.)


2009-07-14 03:34 - 2014-11-27 22:36 - 00000098 ____A C:\Windows\system32\Drivers\etc\hosts


127.0.0.1 localhost
::1 localhost


==================== Geplande Taken (gefilterd) =============


(Als een item is opgenomen in de fixlist, wordt uit het register verwijderd. Het bestand zal niet worden verplaatst tenzij apart vermeld.)


Task: {016EB10C-9FA8-4770-8EBC-FB988737FFAC} - System32\Tasks\ASUS USB Charger Plus => C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe [2012-05-08] (ASUSTek Computer Inc.)
Task: {03E6DA50-A095-4B57-902E-4DF77C5BF8F7} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2011-11-25] (Intel Corporation)
Task: {0B3022E3-1822-42D2-853B-060D9B16FE85} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
Task: {10101098-8567-43F5-9791-02068557C5E4} - System32\Tasks\ASUS SmartLogon Console Sensor => C:\Program Files (x86)\ASUS\FaceLogon\sensorsrv.exe [2012-02-17] (ASUSTek Computer Inc.)
Task: {202E950A-44F4-4239-B80C-69E0FA7FE0E1} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-11-15] (Adobe Systems Incorporated)
Task: {646DF190-524D-4096-A992-877B333AC272} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2011-11-25] (Intel Corporation)
Task: {665B67F0-541F-45A7-89B7-F2ACC49878F2} - System32\Tasks\HPCustParticipation HP Deskjet 1050 J410 series => C:\Program Files\HP\HP Deskjet 1050 J410 series\Bin\HPCustPartic.exe [2012-10-02] (Hewlett-Packard Co.)
Task: {67604CC6-E4A2-471C-8838-4D78A2D5DEF4} - System32\Tasks\ATKOSD2 => C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [2011-12-23] (ASUSTek Computer Inc.)
Task: {73A21D4C-2845-4D8B-9C8E-73FDEA7C9874} - System32\Tasks\ASUS Quick Gesture (x64) => C:\Program Files (x86)\ASUS\ASUS Virtual Touch\QuickGesture\x64\QuickGesture64.exe [2012-04-12] (ASUSTeK Computer Inc.)
Task: {75D32B76-8DCE-43E7-A42C-9D9F74B667CF} - System32\Tasks\ASUS Wireless Console 3 => C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [2012-05-17] (ASUSTeK Computer Inc.)
Task: {797BE614-709C-4392-8414-E7339AA5FED9} - System32\Tasks\ASUS P4G => C:\Program Files\ASUS\P4G\BatteryLife.exe [2012-02-16] (ASUS)
Task: {8BDDB50A-894A-44C8-8F18-AC996B599520} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
Task: {D243337D-A7BA-4BDC-94F5-D685FC8BC71D} - System32\Tasks\ASUS Quick Gesture => C:\Program Files (x86)\ASUS\ASUS Virtual Touch\QuickGesture\x86\QuickGesture.exe [2012-04-12] (ASUSTeK Computer Inc.)
Task: {DB88D52C-111F-4457-B2ED-6C6055D80BA8} - System32\Tasks\ASUS Live Update => C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe [2012-05-22] (ASUSTeK Computer Inc.)
Task: {EC10FEA5-971D-4A52-8BA5-075DE9A65021} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-10-28] (Adobe Systems Incorporated)
Task: {F518AA26-3DD4-48B6-AF10-875985913339} - System32\Tasks\0615tbUpdateInfo => C:\ProgramData\Avg_Update_0615tb\0615tb_{7065CFD9-63B9-47E1-A239-3232D511C3F6}.exe


(Als een item is opgenomen in de fixlist, de taak (job) bestand wordt verplaatst. Het bestand dat wordt uitgevoerd door de taak zal niet worden verplaatst.)


Task: C:\Windows\Tasks\0615tbUpdateInfo.job => C:\ProgramData\Avg_Update_0615tb\0615tb_{7065CFD9-63B9-47E1-A239-3232D511C3F6}.exe
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe
Task: C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe


==================== Snelkoppelingen =============================


(De items kunnen worden opgenomen in de fixlist.txt om hersteld of verwijderd te worden.)


==================== Geladen Modules (gefilterd) ==============


2013-12-01 22:44 - 2012-02-21 21:29 - 00128280 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
2010-07-15 01:11 - 2010-07-15 01:11 - 00031360 _____ () C:\Program Files\ASUS\P4G\DevMng.dll
2013-12-01 22:45 - 2012-04-19 03:24 - 00078448 _____ () C:\Program Files (x86)\VIA\VIAudioi\VDeck\QsApoApi64.dll
2013-12-01 22:45 - 2012-04-19 03:24 - 00386160 _____ () C:\Program Files (x86)\VIA\VIAudioi\VDeck\Dts2ApoApi64.dll
2012-06-27 04:04 - 2012-02-22 08:18 - 00094208 _____ () C:\Windows\system32\IccLibDll_x64.dll
2012-01-31 18:25 - 2012-01-31 18:25 - 01163264 _____ () C:\Program Files (x86)\ASUS\Wireless Console 3\acAuth.dll
2012-05-08 01:48 - 2012-05-08 01:48 - 00009216 _____ () C:\Program Files (x86)\ASUS\Splendid\GLCDdll.dll
2010-08-20 18:57 - 2010-08-20 18:57 - 00619816 _____ () C:\Program Files (x86)\CyberLink\Power2Go\CLMediaLibrary.dll
2010-08-20 18:57 - 2010-08-20 18:57 - 00013096 _____ () C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvcPS.dll
2015-12-02 14:20 - 2015-12-02 14:20 - 40500224 _____ () C:\Program Files (x86)\AVG\UiDll\2171\libcef.dll
2013-12-01 22:44 - 2012-02-21 21:09 - 01198872 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll


==================== Alternate Data Streams (gefilterd) =========


(Als een item is opgenomen in de fixlist, alleen de ADS wordt verwijderd.)




==================== Veilige Modus (gefilterd) ===================


(Als een item is opgenomen in de fixlist, wordt uit het register verwijderd. De "AlternateShell" waarde wordt hersteld.)




==================== EXE Bestandskoppeling (gefilterd) ===============


(Als een item is opgenomen in de fixlist, het registry item zal worden teruggezet naar de standaardwaarden of verwijderd.)




==================== Internet Explorer vertrouwde/beperkte toegang ===============


(Als een item is opgenomen in de fixlist, wordt uit het register verwijderd.)




==================== Andere gebieden ============================


(Momenteel is er geen automatische fix voor dit onderdeel.)


HKU\S-1-5-21-3732487481-855672253-929003311-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\bryan77\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 195.130.131.4 - 195.130.130.132
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is ingeschakeld.


==================== MSCONFIG/TASK MANAGER Uitgeschakelde items ==


(Momenteel is er geen automatische fix voor dit onderdeel.)


MSCONFIG\Services: 0169601385920986mcinstcleanup => 2
MSCONFIG\Services: MBAMScheduler => 2
MSCONFIG\Services: MBAMService => 2
MSCONFIG\Services: McAfee SiteAdvisor Service => 2
MSCONFIG\Services: McAWFwk => 3
MSCONFIG\Services: mcmscsvc => 2
MSCONFIG\Services: McNaiAnn => 2
MSCONFIG\Services: McNASvc => 2
MSCONFIG\Services: McODS => 3
MSCONFIG\Services: McOobeSv => 2
MSCONFIG\Services: McProxy => 2
MSCONFIG\Services: MSK80Service => 2
MSCONFIG\startupreg: AVG_UI => "C:\Program Files (x86)\AVG\AVG2014\avgui.exe" /TRAYONLY
MSCONFIG\startupreg: mcui_exe => "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey


==================== Firewall regels (gefilterd) ===============


(Als een item is opgenomen in de fixlist, wordt uit het register verwijderd. Het bestand zal niet worden verplaatst tenzij apart vermeld.)


FirewallRules: [TCP Query User{EBA49DCD-5C2F-4F0E-BF4F-A983FD370081}C:\program files (x86)\java\jre1.8.0_25\bin\javaw.exe] => (Block) C:\program files (x86)\java\jre1.8.0_25\bin\javaw.exe
FirewallRules: [UDP Query User{04EF1A3B-E8E1-408D-A433-3D778365BB2A}C:\program files (x86)\java\jre1.8.0_25\bin\javaw.exe] => (Block) C:\program files (x86)\java\jre1.8.0_25\bin\javaw.exe
FirewallRules: [TCP Query User{49B33151-1BF6-4A16-9671-A38AC8E1DA7F}D:\gta5.exe] => (Allow) D:\gta5.exe
FirewallRules: [UDP Query User{5F17BCE1-5BAB-4AF9-BC8C-2031EEA73D41}D:\gta5.exe] => (Allow) D:\gta5.exe
FirewallRules: [TCP Query User{21411C96-5716-44DB-97AE-6AAFEBC0D31B}C:\users\bryan\appdata\roaming\spotify\spotify.exe] => (Block) C:\users\bryan\appdata\roaming\spotify\spotify.exe
FirewallRules: [UDP Query User{921FF2AA-205F-4238-912D-AC80D00B83E6}C:\users\bryan\appdata\roaming\spotify\spotify.exe] => (Block) C:\users\bryan\appdata\roaming\spotify\spotify.exe
FirewallRules: [TCP Query User{B9BE8C40-DEBE-49C5-AE3A-E1498EAB80DA}C:\program files (x86)\java\jre1.8.0_45\bin\java.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_45\bin\java.exe
FirewallRules: [UDP Query User{5D64D027-EE91-41AD-A490-E62C7653EB88}C:\program files (x86)\java\jre1.8.0_45\bin\java.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_45\bin\java.exe
FirewallRules: [{7129689C-CE17-4737-BACC-4DDF25C9B34C}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{96E25971-D876-4129-9C15-D8EA0429C079}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{4660A62B-8C06-4943-B5FB-280CA615DFE6}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [{B035D7DF-7034-477E-9AE9-5129C494ECBD}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [{4A8DF4BB-2F8C-43C7-A9E4-CE99882730D1}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{CDE4D536-EAC6-4FB2-85A0-4E4F871B922D}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{8FE3476B-6184-441D-8C96-2CA1DD32DBE9}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [{9531F97E-338F-4533-B4BB-9A32D6B4764D}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [TCP Query User{D3C51161-AB03-4053-B366-DBB01F6DA1A0}C:\program files\java\jre1.8.0_65\bin\javaw.exe] => (Block) C:\program files\java\jre1.8.0_65\bin\javaw.exe
FirewallRules: [UDP Query User{6E6E1AC3-B769-4DB0-92AE-80A9159BD7AE}C:\program files\java\jre1.8.0_65\bin\javaw.exe] => (Block) C:\program files\java\jre1.8.0_65\bin\javaw.exe
FirewallRules: [TCP Query User{074F5DDC-5183-44DA-9FF2-431BE3FFFC2F}C:\program files\java\jre1.8.0_65\bin\java.exe] => (Allow) C:\program files\java\jre1.8.0_65\bin\java.exe
FirewallRules: [UDP Query User{E9A707DB-5A5F-4F63-8681-AC8E2BE7CD33}C:\program files\java\jre1.8.0_65\bin\java.exe] => (Allow) C:\program files\java\jre1.8.0_65\bin\java.exe
FirewallRules: [{2DE804F1-AC29-4FB5-94DF-36F6A75EACED}] => (Allow) C:\Program Files (x86)\AVG\Av\avgnsa.exe
FirewallRules: [{77499CE2-A253-4185-9452-710444A30D0B}] => (Allow) C:\Program Files (x86)\AVG\Av\avgnsa.exe
FirewallRules: [{066B187D-8C61-4F4E-B9F8-DFC85CDBC716}] => (Allow) C:\Program Files (x86)\AVG\Av\avgdiagex.exe
FirewallRules: [{EFCE7FCC-F7CB-488A-A1C0-D7DEC8997440}] => (Allow) C:\Program Files (x86)\AVG\Av\avgdiagex.exe
FirewallRules: [{905DB3C3-6451-4918-B8F7-9C981A9D58C8}] => (Allow) C:\Program Files (x86)\AVG\Av\avgmfapx.exe
FirewallRules: [{6AF2248B-6DD9-45C1-BBA6-813BE5C012A0}] => (Allow) C:\Program Files (x86)\AVG\Av\avgmfapx.exe
FirewallRules: [{DA86E969-765A-4B2D-8FAA-9CFB8BA80912}] => (Allow) C:\Program Files (x86)\AVG\Av\avgemca.exe
FirewallRules: [{FBD3498B-8E7B-499C-9BA1-43501E3FBDE1}] => (Allow) C:\Program Files (x86)\AVG\Av\avgemca.exe
FirewallRules: [{AF1F6EDE-83D3-402B-B0B2-36DC8459BE07}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe


==================== Defecte Apparaatbeheer Apparaten =============




==================== Eventlog fouten: =========================


Applicatiefouten:
==================
Error: (12/05/2015 11:05:48 PM) (Source: CVHSVC) (EventID: 100) (User: )
Description: Alleen informatie.
(Patch task for {90140011-0066-0413-0000-0000000FF1CE}): DownloadLatest Failed:


Error: (12/05/2015 10:50:31 PM) (Source: VSS) (EventID: 8194) (User: )
Description: Fout in de Volume Shadow Copy-service: onverwachte fout bij het uitvoeren van een query voor de IVssWriterCallback-interface. hr = 0x80070005, Toegang geweigerd.
.
Dit wordt vaak veroorzaakt door onjuiste beveiligingsinstellingen in het writer- of requestorproces.




Bewerking:
Schrijvergegevens verzamelen


Context:
Klasse-id van schrijver: {e8132975-6f93-4464-a53e-1050253ae220}
Naam van schrijver: System Writer
Instantie-id van schrijver: {a793fd06-b9d4-4afe-b542-7038794c4eea}


Error: (12/05/2015 10:41:42 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Naam van toepassing met fout: Explorer.EXE, versie: 6.1.7601.17567, tijdstempel: 0x4d672ee4
Naam van module met fout: unknown, versie: 0.0.0.0, tijdstempel: 0x00000000
Uitzonderingscode: 0xc0000005
Foutoffset: 0x0000000000000000
Id van proces met fout: 0x10dc
Starttijd van toepassing met fout: 0xExplorer.EXE0
Pad naar toepassing met fout: Explorer.EXE1
Pad naar module met fout: Explorer.EXE2
Rapport-id: Explorer.EXE3


Error: (12/05/2015 11:35:11 AM) (Source: CVHSVC) (EventID: 100) (User: )
Description: Alleen informatie.
(Patch task for {90140011-0066-0413-0000-0000000FF1CE}): DownloadLatest Failed:


Error: (12/05/2015 08:50:49 AM) (Source: CVHSVC) (EventID: 100) (User: )
Description: Alleen informatie.
(Patch task for {90140011-0066-0413-0000-0000000FF1CE}): DownloadLatest Failed:


Error: (12/04/2015 03:13:19 PM) (Source: CVHSVC) (EventID: 100) (User: )
Description: Alleen informatie.
(Patch task for {90140011-0066-0413-0000-0000000FF1CE}): DownloadLatest Failed:


Error: (12/04/2015 01:29:51 PM) (Source: CVHSVC) (EventID: 100) (User: )
Description: Alleen informatie.
(Patch task for {90140011-0066-0413-0000-0000000FF1CE}): DownloadLatest Failed:


Error: (12/04/2015 01:07:57 PM) (Source: CVHSVC) (EventID: 100) (User: )
Description: Alleen informatie.
(Patch task for {90140011-0066-0413-0000-0000000FF1CE}): DownloadLatest Failed:


Error: (12/02/2015 04:04:04 PM) (Source: CVHSVC) (EventID: 100) (User: )
Description: Alleen informatie.
(Patch task for {90140011-0066-0413-0000-0000000FF1CE}): DownloadLatest Failed:


Error: (12/02/2015 03:38:01 PM) (Source: CVHSVC) (EventID: 100) (User: )
Description: Alleen informatie.
(Patch task for {90140011-0066-0413-0000-0000000FF1CE}): DownloadLatest Failed:




Systeemfouten:
=============
Error: (12/05/2015 10:53:49 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT AUTHORITY)
Description: WLAN-uitbreidingsmodule is onverwacht gestopt.


Pad naar module: C:\Program Files (x86)\Qualcomm Atheros WiFi Driver Installation\AthIhvWlanExt.dll


Error: (12/05/2015 10:53:49 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT AUTHORITY)
Description: WLAN-uitbreidingsmodule is onverwacht gestopt.


Pad naar module: C:\Program Files (x86)\Qualcomm Atheros WiFi Driver Installation\AthIhvWlanExt.dll


Error: (12/05/2015 10:53:38 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT AUTHORITY)
Description: WLAN-uitbreidingsmodule is onverwacht gestopt.


Pad naar module: C:\Program Files (x86)\Qualcomm Atheros WiFi Driver Installation\AthIhvWlanExt.dll


Error: (12/05/2015 10:51:34 PM) (Source: Service Control Manager) (EventID: 7032) (User: )
Description: Servicebesturingsbeheer heeft na het onverwachte afsluiten van de Windows Search-service geprobeerd een herstelactie (Service opnieuw starten) uit te voeren, maar deze actie is met de volgende fout mislukt:
%%1056


Error: (12/05/2015 10:51:09 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: De Application Virtualization Client-service is onverwacht beëindigd. Dit is nu 1 keer gebeurd.


Error: (12/05/2015 10:51:05 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: De Windows Presentation Foundation Font Cache 3.0.0.0-service is onverwacht gestopt. Dit is 1 keer gebeurd. De volgende herstelbewerking zal over 0 milliseconden worden uitgevoerd: Service opnieuw starten.


Error: (12/05/2015 10:51:04 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: De VIA Karaoke digital mixer Service-service is onverwacht beëindigd. Dit is nu 1 keer gebeurd.


Error: (12/05/2015 10:51:04 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: De Windows Live ID Sign-in Assistant-service is onverwacht gestopt. Dit is 1 keer gebeurd. De volgende herstelbewerking zal over 10000 milliseconden worden uitgevoerd: Service opnieuw starten.


Error: (12/05/2015 10:51:04 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: De Client Virtualization Handler-service is onverwacht beëindigd. Dit is nu 1 keer gebeurd.


Error: (12/05/2015 10:51:04 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: De Windows Media Player Network Sharing Service-service is onverwacht gestopt. Dit is 1 keer gebeurd. De volgende herstelbewerking zal over 30000 milliseconden worden uitgevoerd: Service opnieuw starten.




==================== Geheugen info ===========================


Processor: Intel(R) Pentium(R) CPU B970 @ 2.30GHz
Percentage geheugen in gebruik: 58%
Totaal fysiek RAM-geheugen: 3979.96 MB
Beschikbaar fysiek RAM-geheugen: 1667.87 MB
Totaal Virtueel geheugen: 8258.13 MB
Beschikbaar Virtual geheugen: 5910.52 MB


==================== Schijven ================================


Drive c: (OS) (Fixed) (Total:119.24 GB) (Free:45.1 GB) NTFS ==>[systeem met boot componenten (verkregen van schijf)]
Drive d: (DATA) (Fixed) (Total:153.53 GB) (Free:153.42 GB) NTFS


==================== MBR & Partitietabel ==================


========================================================
Disk: 0 (Size: 298.1 GB) (Disk ID: 30EC77D9)


Partition: GPT.


==================== Eind van Addition.txt ============================
 
Wow! The first time FRST ran, it removed 6.3 GB temp data. This last time it was another 1.3 GB temp data was removed.

Good catch, haramo! I forgot to include saving the script as Unicode in the instructions. That said, what FRST did was remove the "unhidie" the entries so that you should now be able to uninstall any of the following that you do not want on the computer:

Συλλογή φωτογραφιών (HKLM-x32\...\{032CB0D7-FDBF-4CA9-901B-A4C1B01B1777}) (Version: 16.4.3508.0205 - Microsoft Corporation)
Основные компоненты Windows Live (HKLM-x32\...\{7A9122B2-CF90-4ACB-8E10-AA83F725916B}) (Version: 16.4.3508.0205 - Microsoft Corporation)
Почта Windows Live (HKLM-x32\...\{44B4333A-60A6-4FFC-BCC5-B0ECA23D2AAB}) (Version: 16.4.3508.0205 - Корпорация Майкрософт)
Фотоальбом (HKLM-x32\...\{CE4EEFE0-85E0-436E-95C5-BCB2EE30C976}) (Version: 16.4.3508.0205 - Microsoft Corporation)
Фотографии (общедоступная версия) (HKLM-x32\...\{234BD64C-99F4-42B5-837F-82F00E37A7E1}) (Version: 16.4.3508.0205 - Microsoft Corporation)
גלריית התמונות (HKLM-x32\...\{B1AC8AF0-2979-4DF8-AE26-B1D543F3543F}) (Version: 16.4.3508.0205 - Microsoft Corporation)
بريد Windows Live (HKLM-x32\...\{7A546E5C-0906-42CC-92DF-B2E787FFA7D2}) (Version: 16.4.3508.0205 - Microsoft Corporation)
معرض الصور (HKLM-x32\...\{6F77C156-7660-4CEC-8793-97D80D5BFEC0}) (Version: 16.4.3508.0205 - Microsoft Corporation)
影像中心 (HKLM-x32\...\{7DB15F28-5E38-476A-A773-EA07EAEAB1B3}) (Version: 16.4.3508.0205 - Microsoft Corporation)

Please let me know how the computer is running now.
 
no commercials anymore, but still very slow.

also last days laptop turns itself off, strange.

will try to uninstall the list with foreing languages.
 
Back
Top