Page 1 of 2 12 Last
  1. #1

    startpage changed, commercials on screen

    Please help with this.

    logs:

    Scanresultaten van Farbar Recovery Scan Tool (FRST) (x64) Versie:01-12-2015
    Gestart door bryan77 (Beheerder) op BRYAN77-PC (01-12-2015 21:47:25)
    Gestart vanaf C:\Users\bryan77\Desktop
    Geladen Profielen: bryan77 (Beschikbare Profielen: bryan77 & Bryan & Barbara)
    Platform: Windows 7 Home Premium Service Pack 1 (X64) Taal: Nederlands (Nederland)
    Internet Explorer Versie 11 (Standaardbrowser: Chrome)
    Boot Modus: Normal
    Handleiding voor Farbar Recovery Scan Tool: FRST Tutorial - How to use Farbar Recovery Scan Tool - Malware Removal Guides and Tutorials


    ==================== Processen (gefilterd) =================


    (Als een item is opgenomen in de fixlist, het proces zal worden gesloten. Het bestand zal niet worden verplaatst.)


    (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe
    (Microsoft Corporation) C:\Windows\System32\wlanext.exe
    (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
    (ASUS) C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnSrv.exe
    (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe
    (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
    () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
    (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
    (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
    (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
    (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
    (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
    (Microsoft Corporation) C:\Windows\System32\dllhost.exe
    (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
    (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
    (Microsoft Corporation) C:\Windows\System32\wisptis.exe
    (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Desktop.exe
    (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
    (ASUS) C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnWMI.exe
    (Microsoft Corporation) C:\Windows\System32\wisptis.exe
    (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
    (ASUS) C:\Program Files\ASUS\P4G\BatteryLife.exe
    (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe
    (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\FaceLogon\sensorsrv.exe
    (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
    (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ATKOSD.exe
    (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe
    (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\WDC.exe
    (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Virtual Touch\QuickGesture\x64\QuickGesture64.exe
    (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe
    (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
    (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Virtual Touch\QuickGesture\x86\QuickGesture.exe
    (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_w32.exe
    (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_x64.exe
    (Intel Corporation) C:\Windows\System32\igfxtray.exe
    (Intel Corporation) C:\Windows\System32\hkcmd.exe
    (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
    (Alcor Micro Corp.) C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe
    (ASUS) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
    (Nico Mak Computing) C:\Program Files\File Association Helper\FAHWindow.exe
    (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
    (Intel Corporation) C:\Windows\System32\igfxpers.exe
    (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
    (VIA) C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe
    (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
    (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
    (CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
    (ASUSTeK) C:\Windows\SysWOW64\ACEngSvr.exe
    (Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
    (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgui.exe
    (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
    (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
    (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDGesture.exe
    (Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
    (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
    (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\ink\InputPersonalization.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe




    ==================== Register (gefilterd) ===========================


    (Als een item is opgenomen in de fixlist, het registry item zal worden teruggezet naar de standaardwaarden of verwijderd. Het bestand zal niet worden verplaatst.)


    HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2661672 2012-05-14] (ELAN Microelectronics Corp.)
    HKLM\...\Run: [AmIcoSinglun64] => C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe [361984 2011-03-21] (Alcor Micro Corp.)
    HKLM\...\Run: [ACMON] => C:\Program Files (x86)\ASUS\Splendid\ACMON.exe [90792 2012-05-08] (ASUS)
    HKLM\...\Run: [FAHConsole] => C:\Program Files\File Association Helper\FAHConsole.exe [729272 2014-01-28] (Nico Mak Computing)
    HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291608 2012-02-07] (Intel Corporation)
    HKLM-x32\...\Run: [HDAudDeck] => C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [5142128 2012-04-19] (VIA)
    HKLM-x32\...\Run: [ATKOSD2] => C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [318080 2011-12-23] (ASUSTek Computer Inc.)
    HKLM-x32\...\Run: [ATKMEDIA] => C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [174720 2011-10-25] (ASUS)
    HKLM-x32\...\Run: [HControlUser] => C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [105016 2009-06-19] (ASUS)
    HKLM-x32\...\Run: [ASUSWebStorage] => C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.108.222\AsusWSPanel.exe [737104 2011-07-29] (ecareme)
    HKLM-x32\...\Run: [CLMLServer] => C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe [107816 2010-08-20] (CyberLink)
    HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-10-28] (Hewlett-Packard)
    HKLM-x32\...\Run: [AVG_UI] => C:\Program Files (x86)\AVG\AVG2014\avgui.exe [5212584 2015-10-20] (AVG Technologies CZ, s.r.o.)
    HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [597040 2015-10-06] (Oracle Corporation)
    Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
    HKU\S-1-5-21-3732487481-855672253-929003311-1001\...\Run: [PCSpeedUp] => C:\Program Files (x86)\PC Speed Up\PCSUNotifier.exe
    ShellIconOverlayIdentifiers: [###MegaShellExtPending] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => C:\Users\Bryan\AppData\Local\MEGAsync\ShellExtX64.dll Geen bestand
    ShellIconOverlayIdentifiers: [###MegaShellExtSynced] -> {05B38830-F4E9-4329-978B-1DD28605D202} => C:\Users\Bryan\AppData\Local\MEGAsync\ShellExtX64.dll Geen bestand
    ShellIconOverlayIdentifiers: [###MegaShellExtSyncing] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => C:\Users\Bryan\AppData\Local\MEGAsync\ShellExtX64.dll Geen bestand
    ShellIconOverlayIdentifiers: [AsusWSShellExt_B] -> {6D4133E5-0742-4ADC-8A8C-9303440F7190} => C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.108.222\ASUSWSShellExt64.dll [2011-05-25] (eCareme Technologies, Inc.)
    ShellIconOverlayIdentifiers: [AsusWSShellExt_O] -> {64174815-8D98-4CE6-8646-4C039977D808} => C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.108.222\ASUSWSShellExt64.dll [2011-05-25] (eCareme Technologies, Inc.)
    ShellIconOverlayIdentifiers-x32: [###MegaShellExtPending] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => C:\Users\Bryan\AppData\Local\MEGAsync\ShellExtX32.dll Geen bestand
    ShellIconOverlayIdentifiers-x32: [###MegaShellExtSynced] -> {05B38830-F4E9-4329-978B-1DD28605D202} => C:\Users\Bryan\AppData\Local\MEGAsync\ShellExtX32.dll Geen bestand
    ShellIconOverlayIdentifiers-x32: [###MegaShellExtSyncing] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => C:\Users\Bryan\AppData\Local\MEGAsync\ShellExtX32.dll Geen bestand
    Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AsusVibeLauncher.lnk [2012-02-24]
    ShortcutTarget: AsusVibeLauncher.lnk -> C:\Program Files (x86)\ASUS\AsusVibe\AsusVibeLauncher.exe (ASUSTeK Computer Inc.)


    ==================== Internet (gefilterd) ====================


    (Als een item is opgenomen in de fixlist, als het een registry item is wordt verwijderd of hersteld naar de standaard.)


    Tcpip\Parameters: [DhcpNameServer] 195.130.131.4 195.130.130.132
    Tcpip\..\Interfaces\{954017FF-42DA-42FD-84E1-ECB55673A792}: [DhcpNameServer] 195.130.131.4 195.130.130.132
    Tcpip\..\Interfaces\{B7BD57C6-76C0-4AB4-AC64-4D8C834D3915}: [DhcpNameServer] 195.130.131.4 195.130.130.132


    Internet Explorer:
    ==================
    HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617912&ResetID=130892591560222338&GUID=D4782CC4-99AC-4097-BD5E-2E9FF6B401FD
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617912&ResetID=130892591560242339&GUID=D4782CC4-99AC-4097-BD5E-2E9FF6B401FD
    HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Google
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = Google
    HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = Google
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = Google
    HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Google
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = Google
    HKU\S-1-5-21-3732487481-855672253-929003311-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617912&ResetID=130892591573953123&GUID=D4782CC4-99AC-4097-BD5E-2E9FF6B401FD
    URLSearchHook: HKU\S-1-5-21-3732487481-855672253-929003311-1001 - (Geen Naam) - {7a55cbb2-2b2e-4a41-9de1-6ac5d2c2be0a} - C:\Program Files (x86)\UtilityChest_49\bar\1.bin\49SrcAs.dll Geen bestand
    SearchScopes: HKLM -> DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSERBM&pc=MSERT1
    SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=ASUTDF&pc=NP06&src=IE-SearchBox
    SearchScopes: HKLM -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSERBM&pc=MSERT1
    SearchScopes: HKLM-x32 -> DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSERBM&pc=MSERT1
    SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=ASUTDF&pc=NP06&src=IE-SearchBox
    SearchScopes: HKLM-x32 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSERBM&pc=MSERT1
    SearchScopes: HKU\S-1-5-21-3732487481-855672253-929003311-1001 -> DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSERBM&pc=MSERT1
    SearchScopes: HKU\S-1-5-21-3732487481-855672253-929003311-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    SearchScopes: HKU\S-1-5-21-3732487481-855672253-929003311-1001 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSERBM&pc=MSERT1
    BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_65\bin\ssv.dll [2015-10-24] (Oracle Corporation)
    BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
    BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_65\bin\jp2ssv.dll [2015-10-24] (Oracle Corporation)
    BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_65\bin\ssv.dll [2015-10-24] (Oracle Corporation)
    BHO-x32: Aanmeldhulp voor Microsoft-account -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
    BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_65\bin\jp2ssv.dll [2015-10-24] (Oracle Corporation)
    Toolbar: HKU\S-1-5-21-3732487481-855672253-929003311-1001 -> Geen Naam - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - Geen bestand
    DPF: HKLM-x32 {4B54A9DE-EF1C-4EBE-A328-7C28EA3B433A} hxxp://quickscan.bitdefender.com/qsax/qsax.cab
    DPF: HKLM-x32 {7530BFB8-7293-4D34-9923-61A11451AFC5} hxxp://download.eset.com/special/eos/OnlineScanner.cab
    StartMenuInternet: IEXPLORE.EXE - iexplore.exe


    FireFox:
    ========
    FF Plugin: @java.com/DTPlugin,version=11.65.2 -> C:\Program Files\Java\jre1.8.0_65\bin\dtplugin\npDeployJava1.dll [2015-10-24] (Oracle Corporation)
    FF Plugin: @java.com/JavaPlugin,version=11.65.2 -> C:\Program Files\Java\jre1.8.0_65\bin\plugin2\npjp2.dll [2015-10-24] (Oracle Corporation)
    FF Plugin: @microsoft.com/GENUINE -> disabled [Geen bestand]
    FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
    FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-01-06] (Intel Corporation)
    FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-01-06] (Intel Corporation)
    FF Plugin-x32: @java.com/DTPlugin,version=11.65.2 -> C:\Program Files (x86)\Java\jre1.8.0_65\bin\dtplugin\npDeployJava1.dll [2015-10-24] (Oracle Corporation)
    FF Plugin-x32: @java.com/JavaPlugin,version=11.65.2 -> C:\Program Files (x86)\Java\jre1.8.0_65\bin\plugin2\npjp2.dll [2015-10-24] (Oracle Corporation)
    FF Plugin-x32: @microsoft.com/GENUINE -> disabled [Geen bestand]
    FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
    FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
    FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2013-02-05] (Microsoft Corporation)
    FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3508.0205 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2013-02-05] (Microsoft Corporation)
    FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-17] (Google Inc.)
    FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-17] (Google Inc.)
    FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-09-27] (Adobe Systems Inc.)


    Chrome:
    =======
    CHR Profile: C:\Users\bryan77\AppData\Local\Google\Chrome\User Data\Default
    CHR Extension: (Betalingen via Chrome Web Store) - C:\Users\bryan77\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-07-30]


    ==================== Services (gefilterd) ========================


    (Als een item is opgenomen in de fixlist, wordt uit het register verwijderd. Het bestand zal niet worden verplaatst tenzij apart vermeld.)


    R2 ASUS InstantOn; C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnSrv.exe [277120 2012-04-13] (ASUS)
    S2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe [3259304 2015-10-20] (AVG Technologies CZ, s.r.o.)
    R2 avgwd; C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe [301896 2015-10-20] (AVG Technologies CZ, s.r.o.)
    R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [128280 2012-02-21] ()
    R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [161560 2012-02-21] (Intel Corporation)
    R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [5702416 2015-09-11] (TeamViewer GmbH)
    S2 VIAKaraokeService; C:\Windows\system32\viakaraokesrv.exe [27760 2012-03-23] (VIA Technologies, Inc.)
    S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
    S4 0169601385920986mcinstcleanup; C:\Windows\TEMP\016960~1.EXE -cleanup -nolog [X]


    ===================== Drivers (gefilterd) ==========================


    (Als een item is opgenomen in de fixlist, wordt uit het register verwijderd. Het bestand zal niet worden verplaatst tenzij apart vermeld.)


    R3 AsusVBus; C:\Windows\System32\DRIVERS\AsusVBus.sys [35968 2012-04-12] (Windows (R) Win 7 DDK provider)
    R3 AsusVTouch; C:\Windows\System32\DRIVERS\AsusVTouch.sys [16512 2012-04-12] (Windows (R) Win 7 DDK provider)
    R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [152344 2014-06-30] (AVG Technologies CZ, s.r.o.)
    R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [244504 2014-07-21] (AVG Technologies CZ, s.r.o.)
    R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [237536 2015-05-26] (AVG Technologies CZ, s.r.o.)
    R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [237848 2014-10-24] (AVG Technologies CZ, s.r.o.)
    R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [369120 2015-05-26] (AVG Technologies CZ, s.r.o.)
    R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [211936 2015-05-26] (AVG Technologies CZ, s.r.o.)
    R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [31512 2014-06-17] (AVG Technologies CZ, s.r.o.)
    R1 Avgtdia; C:\Windows\System32\DRIVERS\avgtdia.sys [276960 2015-05-18] (AVG Technologies CZ, s.r.o.)
    S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
    R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [15416 2009-07-20] ( )
    R3 L1C; C:\Windows\System32\DRIVERS\L1C62x64.sys [104560 2012-04-25] (Qualcomm Atheros Co., Ltd.)


    ==================== NetSvcs (gefilterd) ===================


    (Als een item is opgenomen in de fixlist, wordt uit het register verwijderd. Het bestand zal niet worden verplaatst tenzij apart vermeld.)




    ==================== Een Maand Aangemaakt bestanden en mappen ========


    (Als een item is opgenomen in de fixlist, het bestand/map wordt verplaatst.)


    2015-12-01 21:48 - 2015-12-01 21:48 - 00852771 _____ C:\Users\bryan77\Downloads\SecurityCheck.exe
    2015-12-01 21:47 - 2015-12-01 21:47 - 00019588 _____ C:\Users\bryan77\Desktop\FRST.txt
    2015-12-01 21:46 - 2015-12-01 21:47 - 00000000 ____D C:\FRST
    2015-12-01 21:45 - 2015-12-01 21:45 - 00000000 ____D C:\Users\bryan77\Desktop\uitgevoerde stappen
    2015-12-01 21:45 - 2015-12-01 21:44 - 02350080 _____ (Farbar) C:\Users\bryan77\Desktop\FRST64.exe
    2015-12-01 21:44 - 2015-12-01 21:44 - 02350080 _____ (Farbar) C:\Users\bryan77\Downloads\FRST64.exe
    2015-11-22 14:44 - 2015-11-22 14:44 - 00000000 ____D C:\Users\Bryan\AppData\Roaming\Sun
    2015-11-22 14:29 - 2015-11-22 14:29 - 00000000 ____D C:\Users\Barbara.bryan77-PC\AppData\Local\AvgSetupLog
    2015-11-21 16:10 - 2015-11-21 16:10 - 00679936 _____ C:\Users\Bryan\Downloads\Detection (10).msi
    2015-11-15 20:44 - 2015-11-15 11:44 - 00159444 ____N C:\Users\Barbara.bryan77-PC\Desktop\Kasverkoop nr 128 - 06-11-2015- Barbara Verbist.pdf
    2015-11-15 20:36 - 2015-11-15 20:36 - 00001376 _____ C:\Users\bryan77\Desktop\Photo Gallery.lnk
    2015-11-15 20:34 - 2015-11-15 20:34 - 00001116 _____ C:\Users\bryan77\Desktop\Afbeeldingen - Snelkoppeling.lnk
    2015-11-15 19:43 - 2015-11-15 19:43 - 00000000 ____D C:\Users\bryan77\Desktop\AdminPc
    2015-11-15 19:36 - 2015-11-03 18:55 - 03211264 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
    2015-11-15 19:35 - 2015-10-20 19:42 - 03168768 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
    2015-11-15 19:35 - 2015-10-20 19:42 - 02608128 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
    2015-11-15 19:35 - 2015-10-20 19:42 - 00696320 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
    2015-11-15 19:35 - 2015-10-20 19:42 - 00192512 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
    2015-11-15 19:35 - 2015-10-20 19:42 - 00098816 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
    2015-11-15 19:35 - 2015-10-20 19:42 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
    2015-11-15 19:35 - 2015-10-20 19:42 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
    2015-11-15 19:35 - 2015-10-20 19:41 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
    2015-11-15 19:35 - 2015-10-20 19:41 - 00091136 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
    2015-11-15 19:35 - 2015-10-20 19:41 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
    2015-11-15 19:35 - 2015-10-20 19:41 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll
    2015-11-15 19:35 - 2015-10-20 18:46 - 00566784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
    2015-11-15 19:35 - 2015-10-20 18:46 - 00174080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
    2015-11-15 19:35 - 2015-10-20 18:46 - 00093696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
    2015-11-15 19:35 - 2015-10-20 18:46 - 00030208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
    2015-11-15 19:35 - 2015-10-20 18:45 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
    2015-11-15 19:34 - 2015-11-03 23:10 - 00390344 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
    2015-11-15 19:34 - 2015-11-03 22:51 - 00342728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
    2015-11-15 19:34 - 2015-10-31 00:46 - 25818624 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
    2015-11-15 19:34 - 2015-10-31 00:40 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
    2015-11-15 19:34 - 2015-10-31 00:40 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
    2015-11-15 19:34 - 2015-10-31 00:25 - 02886656 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
    2015-11-15 19:34 - 2015-10-31 00:25 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
    2015-11-15 19:34 - 2015-10-31 00:25 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
    2015-11-15 19:34 - 2015-10-31 00:25 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
    2015-11-15 19:34 - 2015-10-31 00:24 - 00585728 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
    2015-11-15 19:34 - 2015-10-31 00:24 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
    2015-11-15 19:34 - 2015-10-31 00:17 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
    2015-11-15 19:34 - 2015-10-31 00:16 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
    2015-11-15 19:34 - 2015-10-31 00:13 - 00616960 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
    2015-11-15 19:34 - 2015-10-31 00:12 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
    2015-11-15 19:34 - 2015-10-31 00:12 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
    2015-11-15 19:34 - 2015-10-31 00:11 - 05990912 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
    2015-11-15 19:34 - 2015-10-31 00:11 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
    2015-11-15 19:34 - 2015-10-31 00:11 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
    2015-11-15 19:34 - 2015-10-31 00:04 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
    2015-11-15 19:34 - 2015-10-31 00:01 - 00489984 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
    2015-11-15 19:34 - 2015-10-30 23:58 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
    2015-11-15 19:34 - 2015-10-30 23:53 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
    2015-11-15 19:34 - 2015-10-30 23:52 - 20331520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
    2015-11-15 19:34 - 2015-10-30 23:49 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
    2015-11-15 19:34 - 2015-10-30 23:49 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
    2015-11-15 19:34 - 2015-10-30 23:47 - 00504832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
    2015-11-15 19:34 - 2015-10-30 23:46 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
    2015-11-15 19:34 - 2015-10-30 23:46 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
    2015-11-15 19:34 - 2015-10-30 23:45 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
    2015-11-15 19:34 - 2015-10-30 23:45 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
    2015-11-15 19:34 - 2015-10-30 23:44 - 00152064 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
    2015-11-15 19:34 - 2015-10-30 23:44 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
    2015-11-15 19:34 - 2015-10-30 23:42 - 02279936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
    2015-11-15 19:34 - 2015-10-30 23:39 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
    2015-11-15 19:34 - 2015-10-30 23:39 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
    2015-11-15 19:34 - 2015-10-30 23:37 - 00480256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
    2015-11-15 19:34 - 2015-10-30 23:36 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
    2015-11-15 19:34 - 2015-10-30 23:36 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
    2015-11-15 19:34 - 2015-10-30 23:36 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
    2015-11-15 19:34 - 2015-10-30 23:34 - 00262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
    2015-11-15 19:34 - 2015-10-30 23:32 - 00720896 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
    2015-11-15 19:34 - 2015-10-30 23:31 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
    2015-11-15 19:34 - 2015-10-30 23:29 - 02126336 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
    2015-11-15 19:34 - 2015-10-30 23:29 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
    2015-11-15 19:34 - 2015-10-30 23:28 - 00416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
    2015-11-15 19:34 - 2015-10-30 23:23 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
    2015-11-15 19:34 - 2015-10-30 23:22 - 14457856 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
    2015-11-15 19:34 - 2015-10-30 23:21 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
    2015-11-15 19:34 - 2015-10-30 23:19 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
    2015-11-15 19:34 - 2015-10-30 23:18 - 00279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
    2015-11-15 19:34 - 2015-10-30 23:17 - 02487808 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
    2015-11-15 19:34 - 2015-10-30 23:17 - 00130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
    2015-11-15 19:34 - 2015-10-30 23:16 - 04527616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
    2015-11-15 19:34 - 2015-10-30 23:11 - 00230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
    2015-11-15 19:34 - 2015-10-30 23:10 - 00689152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
    2015-11-15 19:34 - 2015-10-30 23:09 - 12854272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
    2015-11-15 19:34 - 2015-10-30 23:09 - 02052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
    2015-11-15 19:34 - 2015-10-30 23:09 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
    2015-11-15 19:34 - 2015-10-30 23:04 - 01547264 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
    2015-11-15 19:34 - 2015-10-30 22:53 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
    2015-11-15 19:34 - 2015-10-30 22:51 - 02011136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
    2015-11-15 19:34 - 2015-10-30 22:48 - 01311744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
    2015-11-15 19:34 - 2015-10-30 22:46 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
    2015-11-15 19:33 - 2015-10-29 18:50 - 00342016 _____ (Microsoft Corporation) C:\Windows\system32\apphelp.dll
    2015-11-15 19:33 - 2015-10-29 18:50 - 00072192 _____ (Microsoft Corporation) C:\Windows\system32\aelupsvc.dll
    2015-11-15 19:33 - 2015-10-29 18:50 - 00023552 _____ (Microsoft Corporation) C:\Windows\system32\sdbinst.exe
    2015-11-15 19:33 - 2015-10-29 18:50 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\shimeng.dll
    2015-11-15 19:33 - 2015-10-29 18:50 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shimeng.dll
    2015-11-15 19:33 - 2015-10-29 18:49 - 00295936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apphelp.dll
    2015-11-15 19:33 - 2015-10-29 18:49 - 00020992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sdbinst.exe
    2015-11-15 19:33 - 2015-10-20 02:12 - 05570496 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
    2015-11-15 19:33 - 2015-10-20 02:12 - 00154560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
    2015-11-15 19:33 - 2015-10-20 02:12 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
    2015-11-15 19:33 - 2015-10-20 02:09 - 01730496 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
    2015-11-15 19:33 - 2015-10-20 02:06 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
    2015-11-15 19:33 - 2015-10-20 02:06 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
    2015-11-15 19:33 - 2015-10-20 02:06 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
    2015-11-15 19:33 - 2015-10-20 02:06 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
    2015-11-15 19:33 - 2015-10-20 02:05 - 01461760 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
    2015-11-15 19:33 - 2015-10-20 02:05 - 01216512 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
    2015-11-15 19:33 - 2015-10-20 02:05 - 01164800 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
    2015-11-15 19:33 - 2015-10-20 02:05 - 00729600 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
    2015-11-15 19:33 - 2015-10-20 02:05 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
    2015-11-15 19:33 - 2015-10-20 02:05 - 00424960 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
    2015-11-15 19:33 - 2015-10-20 02:05 - 00344064 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
    2015-11-15 19:33 - 2015-10-20 02:05 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
    2015-11-15 19:33 - 2015-10-20 02:05 - 00312320 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
    2015-11-15 19:33 - 2015-10-20 02:05 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
    2015-11-15 19:33 - 2015-10-20 02:05 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
    2015-11-15 19:33 - 2015-10-20 02:05 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
    2015-11-15 19:33 - 2015-10-20 02:05 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
    2015-11-15 19:33 - 2015-10-20 02:05 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
    2015-11-15 19:33 - 2015-10-20 02:05 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
    2015-11-15 19:33 - 2015-10-20 02:05 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
    2015-11-15 19:33 - 2015-10-20 02:05 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
    2015-11-15 19:33 - 2015-10-20 02:05 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
    2015-11-15 19:33 - 2015-10-20 02:05 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
    2015-11-15 19:33 - 2015-10-20 02:05 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
    2015-11-15 19:33 - 2015-10-20 02:05 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
    2015-11-15 19:33 - 2015-10-20 02:04 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
    2015-11-15 19:33 - 2015-10-20 02:04 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
    2015-11-15 19:33 - 2015-10-20 02:04 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
    2015-11-15 19:33 - 2015-10-20 02:00 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
    2015-11-15 19:33 - 2015-10-20 01:59 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
    2015-11-15 19:33 - 2015-10-20 01:53 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
    2015-11-15 19:33 - 2015-10-20 01:53 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
    2015-11-15 19:33 - 2015-10-20 01:53 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:53 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:53 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:53 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:53 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:53 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:53 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:53 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:53 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:53 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:53 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:53 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:53 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:53 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:53 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:52 - 03991488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
    2015-11-15 19:33 - 2015-10-20 01:52 - 03935680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
    2015-11-15 19:33 - 2015-10-20 01:48 - 01311768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
    2015-11-15 19:33 - 2015-10-20 01:45 - 00552960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
    2015-11-15 19:33 - 2015-10-20 01:45 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
    2015-11-15 19:33 - 2015-10-20 01:45 - 00251392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
    2015-11-15 19:33 - 2015-10-20 01:45 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
    2015-11-15 19:33 - 2015-10-20 01:45 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
    2015-11-15 19:33 - 2015-10-20 01:45 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
    2015-11-15 19:33 - 2015-10-20 01:45 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
    2015-11-15 19:33 - 2015-10-20 01:45 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll
    2015-11-15 19:33 - 2015-10-20 01:45 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
    2015-11-15 19:33 - 2015-10-20 01:45 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
    2015-11-15 19:33 - 2015-10-20 01:45 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
    2015-11-15 19:33 - 2015-10-20 01:45 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
    2015-11-15 19:33 - 2015-10-20 01:44 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
    2015-11-15 19:33 - 2015-10-20 01:44 - 00665088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
    2015-11-15 19:33 - 2015-10-20 01:44 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
    2015-11-15 19:33 - 2015-10-20 01:44 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
    2015-11-15 19:33 - 2015-10-20 01:44 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
    2015-11-15 19:33 - 2015-10-20 01:44 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
    2015-11-15 19:33 - 2015-10-20 01:39 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
    2015-11-15 19:33 - 2015-10-20 01:39 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
    2015-11-15 19:33 - 2015-10-20 01:35 - 00686080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
    2015-11-15 19:33 - 2015-10-20 01:35 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
    2015-11-15 19:33 - 2015-10-20 01:35 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:35 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:35 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:35 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:35 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:35 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:35 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:35 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:35 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:35 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:35 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:35 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:35 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 00:41 - 00159232 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
    2015-11-15 19:33 - 2015-10-20 00:40 - 00290816 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
    2015-11-15 19:33 - 2015-10-20 00:40 - 00129024 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
    2015-11-15 19:33 - 2015-10-20 00:29 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
    2015-11-15 19:33 - 2015-10-20 00:29 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
    2015-11-15 19:33 - 2015-10-20 00:27 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 00:27 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 00:27 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 00:27 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-13 17:41 - 00497664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
    2015-11-15 19:33 - 2015-10-13 17:40 - 00118272 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdx.sys
    2015-11-15 19:33 - 2015-09-23 14:15 - 00460776 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
    2015-11-15 19:33 - 2015-09-23 14:15 - 00299632 _____ (Microsoft Corporation) C:\Windows\system32\bcryptprimitives.dll
    2015-11-15 19:33 - 2015-09-23 14:09 - 00251000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcryptprimitives.dll
    2015-11-15 19:27 - 2015-11-15 19:27 - 00000000 ____D C:\Users\bryan77\AppData\Local\Mega Limited
    2015-11-15 19:24 - 2015-10-13 05:57 - 00950720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys
    2015-11-15 19:24 - 2015-10-01 19:00 - 00275456 _____ (Microsoft Corporation) C:\Windows\system32\InkEd.dll
    2015-11-15 19:24 - 2015-10-01 19:00 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\jnwmon.dll
    2015-11-15 19:24 - 2015-10-01 18:50 - 00216064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InkEd.dll
    2015-11-09 08:55 - 2015-11-09 08:55 - 00120507 _____ C:\Users\Barbara.bryan77-PC\Downloads\105521 (1).pdf
    2015-11-09 08:51 - 2015-11-09 08:51 - 00120507 _____ C:\Users\Barbara.bryan77-PC\Downloads\105521.pdf


    ==================== Een Maand Gewijzigd bestanden en mappen ========


    (Als een item is opgenomen in de fixlist, het bestand/map wordt verplaatst.)


    2015-12-01 21:46 - 2009-07-14 05:45 - 00009920 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
    2015-12-01 21:46 - 2009-07-14 05:45 - 00009920 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
    2015-12-01 21:46 - 2009-07-14 04:20 - 00000000 ____D C:\Windows
    2015-12-01 21:44 - 2013-12-08 21:48 - 00000940 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
    2015-12-01 21:40 - 2013-12-01 22:44 - 00000828 _____ C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job
    2015-12-01 21:40 - 2013-12-01 14:21 - 00000380 _____ C:\Users\bryan77\AppData\Roaming\sp_data.sys
    2015-12-01 21:40 - 2012-02-24 03:29 - 00001052 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
    2015-12-01 21:40 - 2009-07-14 06:09 - 00000000 ____D C:\Windows\System32\Tasks\WPD
    2015-12-01 20:59 - 2012-02-24 03:29 - 00001056 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
    2015-12-01 20:54 - 2013-12-01 20:24 - 00000380 _____ C:\Users\Barbara.bryan77-PC\AppData\Roaming\sp_data.sys
    2015-12-01 18:06 - 2011-02-19 05:40 - 00746450 _____ C:\Windows\system32\perfh013.dat
    2015-12-01 18:06 - 2011-02-19 05:40 - 00154112 _____ C:\Windows\system32\perfc013.dat
    2015-12-01 18:06 - 2009-07-14 06:13 - 01672504 _____ C:\Windows\system32\PerfStringBackup.INI
    2015-12-01 18:06 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\inf
    2015-12-01 17:22 - 2013-12-01 20:07 - 00000000 ____D C:\ProgramData\MFAData
    2015-12-01 12:12 - 2013-12-01 22:44 - 00000830 _____ C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job
    2015-11-26 16:56 - 2014-09-15 18:06 - 00000000 ____D C:\Users\Bryan\AppData\Roaming\Software Informer
    2015-11-26 16:54 - 2015-06-03 11:41 - 00000000 ____D C:\Users\Bryan\AppData\Local\Spotify
    2015-11-26 16:06 - 2015-06-03 11:40 - 00000000 ____D C:\Users\Bryan\AppData\Roaming\Spotify
    2015-11-26 16:06 - 2013-12-01 21:06 - 00000380 _____ C:\Users\Bryan\AppData\Roaming\sp_data.sys
    2015-11-22 20:59 - 2014-11-06 21:55 - 00000000 ____D C:\Program Files (x86)\TeamViewer
    2015-11-22 14:44 - 2015-10-27 19:41 - 00000000 ____D C:\Users\Bryan\.oracle_jre_usage
    2015-11-22 14:29 - 2014-11-26 08:12 - 00000000 ____D C:\Users\Barbara.bryan77-PC\AppData\Local\Avg
    2015-11-16 04:06 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache
    2015-11-16 03:29 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
    2015-11-16 03:29 - 2009-07-14 05:45 - 00270888 _____ C:\Windows\system32\FNTCACHE.DAT
    2015-11-16 03:24 - 2015-06-03 21:56 - 00000000 ____D C:\Windows\system32\MRT
    2015-11-16 03:11 - 2015-06-03 21:55 - 145617392 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
    2015-11-16 03:03 - 2012-02-24 03:28 - 01647172 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
    2015-11-16 03:02 - 2009-07-14 08:45 - 00000000 ____D C:\Program Files\Windows Journal
    2015-11-15 20:36 - 2013-12-01 19:25 - 00000000 ____D C:\Users\bryan77\AppData\Local\Windows Live
    2015-11-15 19:44 - 2013-12-08 21:48 - 00780488 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
    2015-11-15 19:44 - 2013-12-08 21:48 - 00142536 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
    2015-11-15 19:44 - 2013-12-08 21:48 - 00003878 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
    2015-11-15 19:43 - 2014-11-21 21:01 - 00000000 ____D C:\Users\AdminPc
    2015-11-15 19:32 - 2009-07-14 04:20 - 00000000 __RHD C:\Users\Public\Libraries
    2015-11-15 19:27 - 2014-10-01 09:20 - 00000000 ____D C:\Users\Bryan\AppData\Local\MEGAsync
    2015-11-15 19:15 - 2014-07-29 10:51 - 00000000 ____D C:\Users\bryan77\AppData\Roaming\.minecraft
    2015-11-15 19:02 - 2013-12-01 21:05 - 00000000 ____D C:\Users\Bryan
    2015-11-15 19:02 - 2013-12-01 14:18 - 00000000 ____D C:\Users\bryan77
    2015-11-13 00:29 - 2015-04-05 02:00 - 00000000 ___SD C:\Windows\system32\GWX
    2015-11-13 00:29 - 2014-12-02 23:36 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
    2015-11-13 00:29 - 2014-08-28 07:09 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
    2015-11-13 00:29 - 2013-12-08 21:48 - 00000000 ____D C:\Windows\system32\Macromed
    2015-11-13 00:29 - 2013-12-01 20:24 - 00000000 ____D C:\Users\Barbara.bryan77-PC
    2015-11-13 00:29 - 2012-02-24 03:29 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
    2015-11-13 00:29 - 2009-07-14 08:44 - 00000000 ___RD C:\Users\Public\Recorded TV
    2015-11-13 00:29 - 2009-07-14 04:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared
    2015-11-13 00:28 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\registration
    2015-11-07 11:11 - 2014-08-11 12:27 - 00000184 _____ C:\Users\Bryan\Downloads\eula.txt
    2015-11-01 10:43 - 2014-12-25 22:00 - 00003886 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task


    ==================== Bestanden in de root van sommige mappen =======


    2013-12-01 14:21 - 2015-12-01 21:40 - 0000380 _____ () C:\Users\bryan77\AppData\Roaming\sp_data.sys
    2014-04-16 18:15 - 2014-04-16 18:15 - 0000057 _____ () C:\ProgramData\Ament.ini
    2012-02-24 03:42 - 2010-10-06 18:45 - 0131984 _____ () C:\ProgramData\FullRemove.exe
    2013-12-01 14:06 - 2013-12-01 14:06 - 0000109 _____ () C:\ProgramData\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}.log
    2013-12-01 14:05 - 2013-12-01 14:06 - 0000105 _____ () C:\ProgramData\{40BF1E83-20EB-11D8-97C5-0009C5020658}.log
    2013-12-01 14:04 - 2013-12-01 14:05 - 0000107 _____ () C:\ProgramData\{C59C179C-668D-49A9-B6EA-0121CCFC1243}.log


    Sommige bestanden in TEMP:
    ====================
    C:\Users\Bryan\AppData\Local\Temp\i4jdel0.exe
    C:\Users\Bryan\AppData\Local\Temp\ICReinstall_Malavida_Download_Manager.exe
    C:\Users\Bryan\AppData\Local\Temp\jre-8u31-windows-au.exe
    C:\Users\Bryan\AppData\Local\Temp\jre-8u40-windows-au.exe
    C:\Users\Bryan\AppData\Local\Temp\tmp17FF.tmp.exe
    C:\Users\bryan77\AppData\Local\Temp\i4jdel0.exe
    C:\Users\bryan77\AppData\Local\Temp\jre-8u45-windows-au.exe
    C:\Users\bryan77\AppData\Local\Temp\jre-8u65-windows-au.exe
    C:\Users\bryan77\AppData\Local\Temp\Uninstall.exe




    ==================== Bamital & volsnap =================


    (Er is geen automatische fix voor bestanden die de verificatie niet doorkomen.)


    C:\Windows\system32\winlogon.exe => Bestand is getekend
    C:\Windows\system32\wininit.exe => Bestand is getekend
    C:\Windows\SysWOW64\wininit.exe => Bestand is getekend
    C:\Windows\explorer.exe => Bestand is getekend
    C:\Windows\SysWOW64\explorer.exe => Bestand is getekend
    C:\Windows\system32\svchost.exe => Bestand is getekend
    C:\Windows\SysWOW64\svchost.exe => Bestand is getekend
    C:\Windows\system32\services.exe => Bestand is getekend
    C:\Windows\system32\User32.dll => Bestand is getekend
    C:\Windows\SysWOW64\User32.dll => Bestand is getekend
    C:\Windows\system32\userinit.exe => Bestand is getekend
    C:\Windows\SysWOW64\userinit.exe => Bestand is getekend
    C:\Windows\system32\rpcss.dll => Bestand is getekend
    C:\Windows\system32\dnsapi.dll => Bestand is getekend
    C:\Windows\SysWOW64\dnsapi.dll => Bestand is getekend
    C:\Windows\system32\Drivers\volsnap.sys => Bestand is getekend




    LastRegBack: 2015-11-30 00:25


    ==================== Eind van FRST.txt ============================

    Extra scanresultaten van Farbar Recovery Scan Tool (x64) Versie:01-12-2015
    Gestart door bryan77 (2015-12-01 21:48:47)
    Gestart vanaf C:\Users\bryan77\Desktop
    Windows 7 Home Premium Service Pack 1 (X64) (2013-12-01 13:17:59)
    Boot Modus: Normal
    ==========================================================




    ==================== Accounts: =============================


    Administrator (S-1-5-21-3732487481-855672253-929003311-500 - Administrator - Disabled)
    Barbara (S-1-5-21-3732487481-855672253-929003311-1006 - Limited - Enabled) => C:\Users\Barbara.bryan77-PC
    Bryan (S-1-5-21-3732487481-855672253-929003311-1005 - Limited - Enabled) => C:\Users\Bryan
    bryan77 (S-1-5-21-3732487481-855672253-929003311-1001 - Administrator - Enabled) => C:\Users\bryan77
    Gast (S-1-5-21-3732487481-855672253-929003311-501 - Limited - Disabled)
    HomeGroupUser$ (S-1-5-21-3732487481-855672253-929003311-1002 - Limited - Enabled)


    ==================== Security Center ========================


    (Als een item is opgenomen in de fixlist, zal het worden verwijderd.)


    AV: AVG AntiVirus Free Edition 2014 (Disabled - Up to date) {4D41356F-32AD-7C42-C820-63775EE4F413}
    AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    AS: AVG AntiVirus Free Edition 2014 (Disabled - Up to date) {F620D48B-1497-73CC-F290-58052563BEAE}


    ==================== GeÔnstalleerde programma's ======================


    (Alleen de adware-programma's met 'verborgen' vlag zou kunnen worden toegevoegd aan de fixlist om ze zichtbaar te maken. De adware-programma's moeten handmatig gedeinstallerd worden.)


    Adobe Flash Player 10 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 10.0.32.18 - Adobe Systems Incorporated)
    Adobe Flash Player 19 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 19.0.0.245 - Adobe Systems Incorporated)
    Adobe Reader XI (11.0.13) - Nederlands (HKLM-x32\...\{AC76BA86-7AD7-1043-7B44-AB0000000001}) (Version: 11.0.13 - Adobe Systems Incorporated)
    Alcor Micro USB Card Reader (HKLM-x32\...\AmUStor) (Version: 1.2.0117.08443 - Alcor Micro Corp.)
    Alcor Micro USB Card Reader (x32 Version: 1.2.0117.08443 - Alcor Micro Corp.) Hidden
    ASUS AI Recovery (HKLM-x32\...\{D39F0676-163E-4595-A917-E28F99BBD4D2}) (Version: 1.0.24 - ASUS)
    ASUS FaceLogon (HKLM-x32\...\{64452561-169F-4A36-A2FF-B5E118EC65F5}) (Version: 1.0.0014 - ASUS)
    ASUS Instant Connect (HKLM-x32\...\{89ECB85A-D933-4CEA-9116-5CBC9C2ED95B}) (Version: 1.2.2 - ASUS)
    ASUS LifeFrame3 (HKLM-x32\...\{1DBD1F12-ED93-49C0-A7CC-56CBDE488158}) (Version: 3.1.1 - ASUS)
    ASUS Live Update (HKLM-x32\...\{FA540E67-095C-4A1B-97BA-4D547DEC9AF4}) (Version: 3.1.5 - ASUS)
    ASUS Power4Gear Hybrid (HKLM\...\{9B6239BF-4E85-4590-8D72-51E30DB1A9AA}) (Version: 1.2.1 - ASUS)
    ASUS Splendid Video Enhancement Technology (HKLM-x32\...\{0969AF05-4FF6-4C00-9406-43599238DE0D}) (Version: 1.03.0001 - ASUS)
    ASUS USB Charger Plus (HKLM-x32\...\{A859E3E5-C62F-4BFA-AF1D-2B95E03166AF}) (Version: 2.1.1 - ASUS)
    ASUS Virtual Camera (HKLM-x32\...\{EC8BD21F-0CA0-4BBF-97D9-4A52B30041A1}) (Version: 1.0.25 - ASUS)
    ASUS Virtual Touch (HKLM-x32\...\{938CFBD4-0652-49E5-BB8B-153948865941}) (Version: 1.0.11 - ASUS)
    ASUS WebStorage (HKLM-x32\...\ASUS WebStorage) (Version: 3.0.108.222 - eCareme Technologies, Inc.)
    AsusVibe2.0 (HKLM-x32\...\Asus Vibe2.0) (Version: 2.0.9.157 - ASUSTEK)
    Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver (HKLM-x32\...\{3108C217-BE83-42E4-AE9E-A56A2A92E549}) (Version: 2.0.15.16 - Atheros Communications Inc.)
    ATK Package (HKLM-x32\...\{AB5C933E-5C7D-4D30-B314-9C83A49B94BE}) (Version: 1.0.0015 - ASUS)
    AVG 2014 (HKLM\...\AVG) (Version: 2014.0.4842 - AVG Technologies)
    AVG 2014 (Version: 14.0.4447 - AVG Technologies) Hidden
    AVG 2014 (Version: 14.0.4842 - AVG Technologies) Hidden
    Bubbletown (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-115065740}) (Version: - Oberon Media)
    Contenta Converter PREMIUM (HKLM-x32\...\ContentaConverter-PREMIUM) (Version: - Contenta Software)
    CyberLink LabelPrint (HKLM-x32\...\InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}) (Version: 2.5.3624 - CyberLink Corp.)
    CyberLink Media Suite (HKLM-x32\...\InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}) (Version: 8.0.2926 - CyberLink Corp.)
    CyberLink Power2Go (HKLM-x32\...\InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 7.0.0.1126 - CyberLink Corp.)
    D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
    Deadtime Stories (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-118716773}) (Version: - Oberon Media)
    Dream Day First Home (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-113832110}) (Version: - Oberon Media)
    Dream Vacation Solitaire (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111249233}) (Version: - Oberon Media)
    ESET Online Scanner v3 (HKLM-x32\...\ESET Online Scanner) (Version: - )
    ETDWare PS/2-X64 10.5.10.0 (HKLM\...\Elantech) (Version: 10.5.10.0 - ELAN Microelectronic Corp.)
    Farm Frenzy 3 - Madagascar (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-119205603}) (Version: - Oberon Media)
    File Association Helper (HKLM\...\{C168639F-5810-4EC8-B1E8-0251AA8A771C}) (Version: 1.2.225.65451 - WinZip Computing International, LLC)
    Fotogalerie (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
    Galapago (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111307457}) (Version: - Oberon Media)
    Galeria de Fotografias (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
    GalerŪa de fotos (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
    Galerie de photos (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
    Game Park Console (HKLM-x32\...\Game Park Console) (Version: 1.2.4.431 - Oberon Media Inc.)
    Go Go Gourmet Chef of the Year (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-115290153}) (Version: - Oberon Media)
    Google Chrome (HKLM-x32\...\Google Chrome) (Version: 46.0.2490.86 - Google Inc.)
    Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
    Google Update Helper (x32 Version: 1.3.28.15 - Google Inc.) Hidden
    HP Deskjet 1050 J410 series Basissoftware van het apparaat (HKLM\...\{FA37D2E8-0A8B-46D2-A74A-310F935DE920}) (Version: 28.0.1313.0 - Hewlett-Packard Co.)
    HP Deskjet 1050 J410 series Haelp (HKLM-x32\...\{5C90D8CF-F12A-41C6-9007-3B651A1F0D78}) (Version: 140.0.66.66 - Hewlett Packard)
    HP Deskjet 1050 J410 series Productverbeteringsonderzoek (HKLM\...\{44C6BB22-7E25-4A6D-8851-6FB26407D9C1}) (Version: 28.0.1313.0 - Hewlett-Packard Co.)
    HP Photo Creations (HKLM-x32\...\HP Photo Creations) (Version: 1.0.0.7702 - HP)
    HP Update (HKLM-x32\...\{6F1C00D2-25C2-4CBA-8126-AE9A6E2E9CD5}) (Version: 5.003.003.001 - Hewlett-Packard)
    InstantOn for NB (HKLM-x32\...\{749F674B-2674-47E8-879C-5626A06B2A91}) (Version: 2.3.3 - ASUS)
    Intel(R) Manageability Engine Firmware Recovery Agent (HKLM-x32\...\{A6C48A9F-694A-4234-B3AA-62590B668927}) (Version: 1.0.0.35342 - Intel Corporation)
    Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.0.3.1427 - Intel Corporation)
    Intel(R) OpenCL CPU Runtime (HKLM-x32\...\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: - Intel Corporation)
    Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2653 - Intel Corporation)
    Intel(R) USB 3.0 eXtensible Host Controller Driver (HKLM-x32\...\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 1.0.3.214 - Intel Corporation)
    Intelģ Trusted Connect Service Client (HKLM\...\{09536BA1-E498-4CC3-B834-D884A67D7E34}) (Version: 1.23.605.1 - Intel Corporation)
    Java 8 Update 65 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86418065F0}) (Version: 8.0.650.17 - Oracle Corporation)
    Java 8 Update 65 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218065F0}) (Version: 8.0.650.17 - Oracle Corporation)
    Junk Mail filter update (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
    Mahjong Memoirs (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-117948443}) (Version: - Oberon Media)
    MediaFire Desktop (HKLM-x32\...\MediaFire Desktop 1.3.9.10486) (Version: 1.3.9.10486 - MediaFire)
    Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
    Microsoft Office 2010 (HKLM-x32\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
    Microsoft Office Klik-en-Klaar 2010 (HKLM-x32\...\Office14.Click2Run) (Version: 14.0.4763.1000 - Microsoft Corporation)
    Microsoft Office Starter 2010 - Nederlands (HKLM-x32\...\{90140011-0066-0413-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
    Microsoft PowerPoint Viewer (HKLM-x32\...\{95140000-00AF-0413-0000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation)
    Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40728.0 - Microsoft Corporation)
    Microsoft SkyDrive (HKU\S-1-5-21-3732487481-855672253-929003311-1001\...\SkyDriveSetup.exe) (Version: 16.4.6013.0910 - Microsoft Corporation)
    Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
    Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
    Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
    Movie Maker (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
    myBitCast 1.0.0.3 (HKLM\...\myBitCast) (Version: 1.0.0.3 - ASUS Cloud Corporation)
    Plants vs Zombies (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-117080787}) (Version: - Oberon Media)
    Platform (x32 Version: 1.39 - VIA Technologies, Inc.) Hidden
    Qualcomm Atheros WiFi Driver Installation (HKLM-x32\...\{7D916FA5-DAE9-4A25-B089-655C70EAF607}) (Version: 3.0 - Qualcomm Atheros)
    Raccolta foto (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
    SceneSwitch (HKLM-x32\...\{5172E572-C175-4F80-A6D5-5CB45826AD61}) (Version: 1.0.12 - ASUS)
    TeamViewer 10 (HKLM-x32\...\TeamViewer) (Version: 10.0.47484 - TeamViewer)
    The Simpsons Tapped Out Packages (HKU\S-1-5-21-3732487481-855672253-929003311-1001\...\The Simpsons Tapped Out Packages) (Version: - ) <==== AANDACHT
    Turbo Fiesta (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-115320460}) (Version: - Oberon Media)
    VIA Platform Device Manager (HKLM-x32\...\InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}) (Version: 1.39 - VIA Technologies, Inc.)
    Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
    Visual Studio 2012 x86 Redistributables (HKLM-x32\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
    Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3508.0205 - Microsoft Corporation)
    Windows Phone app for desktop (HKLM-x32\...\{54EC61F0-6D02-450E-9F1B-9506EAE9F23C}) (Version: 1.1.2726.0 - Microsoft Corporation)
    WinFlash (HKLM-x32\...\{8F21291E-0444-4B1D-B9F9-4370A73E346D}) (Version: 2.41.0 - ASUS)
    WinRAR 5.01 (32-bit) (HKLM-x32\...\WinRAR archiver) (Version: 5.01.0 - win.rar GmbH)
    WinZip 18.5 (HKLM\...\{CD95F661-A5C4-44F5-A6AA-ECDD91C240E3}) (Version: 18.5.11111 - WinZip Computing, S.L. )
    Wireless Console 3 (HKLM-x32\...\{19EA33FB-B34E-40EA-8B8A-61743AEB795A}) (Version: 3.0.30 - ASUS)
    World of Goo (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-116672750}) (Version: - Oberon Media)
    Συλλογή φωτογραφιών (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
    Основные компоненты Windows Live (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
    Почта Windows Live (x32 Version: 16.4.3508.0205 - Корпорация Майкрософт) Hidden
    Фотоальбом (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
    Фотографии (общедоступная версия) (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
    גלריית התמונות (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
    بريد Windows Live (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
    معرض الصور (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
    影像中心 (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden


    ==================== Aangepaste CLSID (gefilterd): ==========================


    (Als een item is opgenomen in de fixlist, wordt uit het register verwijderd. Het bestand zal niet worden verplaatst tenzij apart vermeld.)




    ==================== Herstelpunten =========================


    21-11-2015 16:11:01 Installed System Requirements Lab Detection
    29-11-2015 00:00:02 Gepland controlepunt


    ==================== Hosts inhoud: ===============================


    (Als nodig Hosts: opdracht kan worden opgenomen in de fixlist om Hosts te resetten.)


    2009-07-14 03:34 - 2014-11-27 22:36 - 00000098 ____A C:\Windows\system32\Drivers\etc\hosts


    127.0.0.1 localhost
    ::1 localhost


    ==================== Geplande Taken (gefilterd) =============


    (Als een item is opgenomen in de fixlist, wordt uit het register verwijderd. Het bestand zal niet worden verplaatst tenzij apart vermeld.)


    Task: {016EB10C-9FA8-4770-8EBC-FB988737FFAC} - System32\Tasks\ASUS USB Charger Plus => C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe [2012-05-08] (ASUSTek Computer Inc.)
    Task: {03E6DA50-A095-4B57-902E-4DF77C5BF8F7} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2011-11-25] (Intel Corporation)
    Task: {0B3022E3-1822-42D2-853B-060D9B16FE85} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
    Task: {10101098-8567-43F5-9791-02068557C5E4} - System32\Tasks\ASUS SmartLogon Console Sensor => C:\Program Files (x86)\ASUS\FaceLogon\sensorsrv.exe [2012-02-17] (ASUSTek Computer Inc.)
    Task: {202E950A-44F4-4239-B80C-69E0FA7FE0E1} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-11-15] (Adobe Systems Incorporated)
    Task: {646DF190-524D-4096-A992-877B333AC272} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2011-11-25] (Intel Corporation)
    Task: {665B67F0-541F-45A7-89B7-F2ACC49878F2} - System32\Tasks\HPCustParticipation HP Deskjet 1050 J410 series => C:\Program Files\HP\HP Deskjet 1050 J410 series\Bin\HPCustPartic.exe [2012-10-02] (Hewlett-Packard Co.)
    Task: {67604CC6-E4A2-471C-8838-4D78A2D5DEF4} - System32\Tasks\ATKOSD2 => C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [2011-12-23] (ASUSTek Computer Inc.)
    Task: {73A21D4C-2845-4D8B-9C8E-73FDEA7C9874} - System32\Tasks\ASUS Quick Gesture (x64) => C:\Program Files (x86)\ASUS\ASUS Virtual Touch\QuickGesture\x64\QuickGesture64.exe [2012-04-12] (ASUSTeK Computer Inc.)
    Task: {75D32B76-8DCE-43E7-A42C-9D9F74B667CF} - System32\Tasks\ASUS Wireless Console 3 => C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [2012-05-17] (ASUSTeK Computer Inc.)
    Task: {797BE614-709C-4392-8414-E7339AA5FED9} - System32\Tasks\ASUS P4G => C:\Program Files\ASUS\P4G\BatteryLife.exe [2012-02-16] (ASUS)
    Task: {8BDDB50A-894A-44C8-8F18-AC996B599520} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
    Task: {D243337D-A7BA-4BDC-94F5-D685FC8BC71D} - System32\Tasks\ASUS Quick Gesture => C:\Program Files (x86)\ASUS\ASUS Virtual Touch\QuickGesture\x86\QuickGesture.exe [2012-04-12] (ASUSTeK Computer Inc.)
    Task: {DB88D52C-111F-4457-B2ED-6C6055D80BA8} - System32\Tasks\ASUS Live Update => C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe [2012-05-22] (ASUSTeK Computer Inc.)
    Task: {EC10FEA5-971D-4A52-8BA5-075DE9A65021} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-10-28] (Adobe Systems Incorporated)
    Task: {F518AA26-3DD4-48B6-AF10-875985913339} - System32\Tasks\0615tbUpdateInfo => C:\ProgramData\Avg_Update_0615tb\0615tb_{7065CFD9-63B9-47E1-A239-3232D511C3F6}.exe [2015-06-20] ()


    (Als een item is opgenomen in de fixlist, de taak (job) bestand wordt verplaatst. Het bestand dat wordt uitgevoerd door de taak zal niet worden verplaatst.)


    Task: C:\Windows\Tasks\0615tbUpdateInfo.job => C:\ProgramData\Avg_Update_0615tb\0615tb_{7065CFD9-63B9-47E1-A239-3232D511C3F6}.exe
    Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
    Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    Task: C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe
    Task: C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe


    ==================== Snelkoppelingen =============================


    (De items kunnen worden opgenomen in de fixlist.txt om hersteld of verwijderd te worden.)


    ShortcutWithArgument: C:\Users\bryan77\Desktop\Internet Explorer.lnk -> C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.sweet-page.com/?type=sc&ts=1410798019&from=cor&uid=ST320LT020-9YG142_W0Q4K52MXXXXW0Q4K52M <==== AANDACHT
    ShortcutWithArgument: C:\Users\bryan77\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.sweet-page.com/?type=sc&ts=1410798019&from=cor&uid=ST320LT020-9YG142_W0Q4K52MXXXXW0Q4K52M <==== AANDACHT
    ShortcutWithArgument: C:\Users\bryan77\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.sweet-page.com/?type=sc&ts=1410798019&from=cor&uid=ST320LT020-9YG142_W0Q4K52MXXXXW0Q4K52M <==== AANDACHT
    ShortcutWithArgument: C:\Users\bryan77\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.sweet-page.com/?type=sc&ts=1410798019&from=cor&uid=ST320LT020-9YG142_W0Q4K52MXXXXW0Q4K52M <==== AANDACHT
    ShortcutWithArgument: C:\Users\bryan77\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk -> C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.sweet-page.com/?type=sc&ts=1410798019&from=cor&uid=ST320LT020-9YG142_W0Q4K52MXXXXW0Q4K52M <==== AANDACHT
    ShortcutWithArgument: C:\Users\bryan77\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.sweet-page.com/?type=sc&ts=1410798019&from=cor&uid=ST320LT020-9YG142_W0Q4K52MXXXXW0Q4K52M <==== AANDACHT
    ShortcutWithArgument: C:\Users\bryan77\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.sweet-page.com/?type=sc&ts=1410798019&from=cor&uid=ST320LT020-9YG142_W0Q4K52MXXXXW0Q4K52M <==== AANDACHT


    ==================== Geladen Modules (gefilterd) ==============


    2013-12-01 22:44 - 2012-02-21 21:29 - 00128280 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
    2010-07-15 01:11 - 2010-07-15 01:11 - 00031360 _____ () C:\Program Files\ASUS\P4G\DevMng.dll
    2012-06-27 04:04 - 2012-02-22 08:18 - 00094208 _____ () C:\Windows\system32\IccLibDll_x64.dll
    2013-12-01 22:45 - 2012-04-19 03:24 - 00078448 _____ () C:\Program Files (x86)\VIA\VIAudioi\VDeck\QsApoApi64.dll
    2013-12-01 22:45 - 2012-04-19 03:24 - 00386160 _____ () C:\Program Files (x86)\VIA\VIAudioi\VDeck\Dts2ApoApi64.dll
    2013-12-01 22:44 - 2012-02-21 21:09 - 01198872 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll
    2012-01-31 18:25 - 2012-01-31 18:25 - 01163264 _____ () C:\Program Files (x86)\ASUS\Wireless Console 3\acAuth.dll
    2012-05-08 01:48 - 2012-05-08 01:48 - 00009216 _____ () C:\Program Files (x86)\ASUS\Splendid\GLCDdll.dll
    2010-08-20 18:57 - 2010-08-20 18:57 - 00619816 _____ () C:\Program Files (x86)\CyberLink\Power2Go\CLMediaLibrary.dll
    2010-08-20 18:57 - 2010-08-20 18:57 - 00013096 _____ () C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvcPS.dll
    2015-11-16 01:00 - 2015-11-07 05:36 - 01532744 _____ () C:\Program Files (x86)\Google\Chrome\Application\46.0.2490.86\libglesv2.dll
    2015-11-16 01:00 - 2015-11-07 05:36 - 00081224 _____ () C:\Program Files (x86)\Google\Chrome\Application\46.0.2490.86\libegl.dll


    ==================== Alternate Data Streams (gefilterd) =========


    (Als een item is opgenomen in de fixlist, alleen de ADS wordt verwijderd.)




    ==================== Veilige Modus (gefilterd) ===================


    (Als een item is opgenomen in de fixlist, wordt uit het register verwijderd. De "AlternateShell" waarde wordt hersteld.)




    ==================== EXE Bestandskoppeling (gefilterd) ===============


    (Als een item is opgenomen in de fixlist, het registry item zal worden teruggezet naar de standaardwaarden of verwijderd.)




    ==================== Internet Explorer vertrouwde/beperkte toegang ===============


    (Als een item is opgenomen in de fixlist, wordt uit het register verwijderd.)




    ==================== Andere gebieden ============================


    (Momenteel is er geen automatische fix voor dit onderdeel.)


    HKU\S-1-5-21-3732487481-855672253-929003311-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\bryan77\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
    DNS Servers: 195.130.131.4 - 195.130.130.132
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
    Windows Firewall is ingeschakeld.


    ==================== MSCONFIG/TASK MANAGER Uitgeschakelde items ==


    (Momenteel is er geen automatische fix voor dit onderdeel.)


    MSCONFIG\Services: 0169601385920986mcinstcleanup => 2
    MSCONFIG\Services: MBAMScheduler => 2
    MSCONFIG\Services: MBAMService => 2
    MSCONFIG\Services: McAfee SiteAdvisor Service => 2
    MSCONFIG\Services: McAWFwk => 3
    MSCONFIG\Services: mcmscsvc => 2
    MSCONFIG\Services: McNaiAnn => 2
    MSCONFIG\Services: McNASvc => 2
    MSCONFIG\Services: McODS => 3
    MSCONFIG\Services: McOobeSv => 2
    MSCONFIG\Services: McProxy => 2
    MSCONFIG\Services: MSK80Service => 2
    MSCONFIG\startupreg: AVG_UI => "C:\Program Files (x86)\AVG\AVG2014\avgui.exe" /TRAYONLY
    MSCONFIG\startupreg: mcui_exe => "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey


    ==================== Firewall regels (gefilterd) ===============


    (Als een item is opgenomen in de fixlist, wordt uit het register verwijderd. Het bestand zal niet worden verplaatst tenzij apart vermeld.)


    FirewallRules: [TCP Query User{EBA49DCD-5C2F-4F0E-BF4F-A983FD370081}C:\program files (x86)\java\jre1.8.0_25\bin\javaw.exe] => (Block) C:\program files (x86)\java\jre1.8.0_25\bin\javaw.exe
    FirewallRules: [UDP Query User{04EF1A3B-E8E1-408D-A433-3D778365BB2A}C:\program files (x86)\java\jre1.8.0_25\bin\javaw.exe] => (Block) C:\program files (x86)\java\jre1.8.0_25\bin\javaw.exe
    FirewallRules: [TCP Query User{49B33151-1BF6-4A16-9671-A38AC8E1DA7F}D:\gta5.exe] => (Allow) D:\gta5.exe
    FirewallRules: [UDP Query User{5F17BCE1-5BAB-4AF9-BC8C-2031EEA73D41}D:\gta5.exe] => (Allow) D:\gta5.exe
    FirewallRules: [TCP Query User{21411C96-5716-44DB-97AE-6AAFEBC0D31B}C:\users\bryan\appdata\roaming\spotify\spotify.exe] => (Block) C:\users\bryan\appdata\roaming\spotify\spotify.exe
    FirewallRules: [UDP Query User{921FF2AA-205F-4238-912D-AC80D00B83E6}C:\users\bryan\appdata\roaming\spotify\spotify.exe] => (Block) C:\users\bryan\appdata\roaming\spotify\spotify.exe
    FirewallRules: [TCP Query User{B9BE8C40-DEBE-49C5-AE3A-E1498EAB80DA}C:\program files (x86)\java\jre1.8.0_45\bin\java.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_45\bin\java.exe
    FirewallRules: [UDP Query User{5D64D027-EE91-41AD-A490-E62C7653EB88}C:\program files (x86)\java\jre1.8.0_45\bin\java.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_45\bin\java.exe
    FirewallRules: [{7129689C-CE17-4737-BACC-4DDF25C9B34C}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
    FirewallRules: [{96E25971-D876-4129-9C15-D8EA0429C079}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
    FirewallRules: [{4660A62B-8C06-4943-B5FB-280CA615DFE6}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
    FirewallRules: [{B035D7DF-7034-477E-9AE9-5129C494ECBD}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
    FirewallRules: [{4A8DF4BB-2F8C-43C7-A9E4-CE99882730D1}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
    FirewallRules: [{CDE4D536-EAC6-4FB2-85A0-4E4F871B922D}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
    FirewallRules: [{8FE3476B-6184-441D-8C96-2CA1DD32DBE9}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
    FirewallRules: [{9531F97E-338F-4533-B4BB-9A32D6B4764D}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
    FirewallRules: [TCP Query User{D3C51161-AB03-4053-B366-DBB01F6DA1A0}C:\program files\java\jre1.8.0_65\bin\javaw.exe] => (Block) C:\program files\java\jre1.8.0_65\bin\javaw.exe
    FirewallRules: [UDP Query User{6E6E1AC3-B769-4DB0-92AE-80A9159BD7AE}C:\program files\java\jre1.8.0_65\bin\javaw.exe] => (Block) C:\program files\java\jre1.8.0_65\bin\javaw.exe
    FirewallRules: [TCP Query User{074F5DDC-5183-44DA-9FF2-431BE3FFFC2F}C:\program files\java\jre1.8.0_65\bin\java.exe] => (Allow) C:\program files\java\jre1.8.0_65\bin\java.exe
    FirewallRules: [UDP Query User{E9A707DB-5A5F-4F63-8681-AC8E2BE7CD33}C:\program files\java\jre1.8.0_65\bin\java.exe] => (Allow) C:\program files\java\jre1.8.0_65\bin\java.exe
    FirewallRules: [{6D7622EE-6E74-470D-A067-1D34D8747E98}] => (Allow) C:\Program Files (x86)\AVG\AVG2014\avgnsa.exe
    FirewallRules: [{F70545F6-489D-4862-877D-A8770F3D67AC}] => (Allow) C:\Program Files (x86)\AVG\AVG2014\avgnsa.exe
    FirewallRules: [{E2EBE6BC-6C48-4AC8-A2F3-8291386F4E9E}] => (Allow) C:\Program Files (x86)\AVG\AVG2014\avgdiagex.exe
    FirewallRules: [{75951CA5-A51D-4E8D-AEA7-05089C1D711E}] => (Allow) C:\Program Files (x86)\AVG\AVG2014\avgdiagex.exe
    FirewallRules: [{385FA559-3B1C-4007-ABC7-A2D9EFC11C02}] => (Allow) C:\Program Files (x86)\AVG\AVG2014\avgemca.exe
    FirewallRules: [{B9235D54-F6A8-4C88-B11A-98C262A144C6}] => (Allow) C:\Program Files (x86)\AVG\AVG2014\avgemca.exe
    FirewallRules: [{AC569F6C-DE67-48AF-9066-CDD57D42B4D5}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe


    ==================== Defecte Apparaatbeheer Apparaten =============




    ==================== Eventlog fouten: =========================


    Applicatiefouten:
    ==================
    Error: (11/21/2015 04:10:21 PM) (Source: Application Error) (EventID: 1000) (User: )
    Description: Naam van toepassing met fout: Explorer.EXE, versie: 6.1.7601.17567, tijdstempel: 0x4d672ee4
    Naam van module met fout: unknown, versie: 0.0.0.0, tijdstempel: 0x00000000
    Uitzonderingscode: 0xc0000005
    Foutoffset: 0x0000000000000000
    Id van proces met fout: 0x163c
    Starttijd van toepassing met fout: 0xExplorer.EXE0
    Pad naar toepassing met fout: Explorer.EXE1
    Pad naar module met fout: Explorer.EXE2
    Rapport-id: Explorer.EXE3


    Error: (11/15/2015 09:53:04 PM) (Source: CVHSVC) (EventID: 100) (User: )
    Description: Alleen informatie.
    (Patch task for {90140011-0066-0413-0000-0000000FF1CE}): DownloadLatest Failed:


    Error: (11/15/2015 08:30:52 PM) (Source: Application Error) (EventID: 1000) (User: )
    Description: Naam van toepassing met fout: DllHost.exe, versie: 6.1.7600.16385, tijdstempel: 0x4a5bca54
    Naam van module met fout: igdumd64.dll, versie: 8.15.10.2653, tijdstempel: 0x4f3aac44
    Uitzonderingscode: 0xc0000005
    Foutoffset: 0x000000000030eb06
    Id van proces met fout: 0x148c
    Starttijd van toepassing met fout: 0xDllHost.exe0
    Pad naar toepassing met fout: DllHost.exe1
    Pad naar module met fout: DllHost.exe2
    Rapport-id: DllHost.exe3


    Error: (11/15/2015 08:29:19 PM) (Source: Application Error) (EventID: 1000) (User: )
    Description: Naam van toepassing met fout: DllHost.exe, versie: 6.1.7600.16385, tijdstempel: 0x4a5bca54
    Naam van module met fout: igdumd64.dll, versie: 8.15.10.2653, tijdstempel: 0x4f3aac44
    Uitzonderingscode: 0xc000041d
    Foutoffset: 0x000000000030eb06
    Id van proces met fout: 0x12d0
    Starttijd van toepassing met fout: 0xDllHost.exe0
    Pad naar toepassing met fout: DllHost.exe1
    Pad naar module met fout: DllHost.exe2
    Rapport-id: DllHost.exe3


    Error: (11/15/2015 08:29:12 PM) (Source: Application Error) (EventID: 1000) (User: )
    Description: Naam van toepassing met fout: DllHost.exe, versie: 6.1.7600.16385, tijdstempel: 0x4a5bca54
    Naam van module met fout: igdumd64.dll, versie: 8.15.10.2653, tijdstempel: 0x4f3aac44
    Uitzonderingscode: 0xc0000005
    Foutoffset: 0x000000000030eb06
    Id van proces met fout: 0x12d0
    Starttijd van toepassing met fout: 0xDllHost.exe0
    Pad naar toepassing met fout: DllHost.exe1
    Pad naar module met fout: DllHost.exe2
    Rapport-id: DllHost.exe3


    Error: (11/15/2015 08:17:07 PM) (Source: Application Error) (EventID: 1000) (User: )
    Description: Naam van toepassing met fout: DllHost.exe, versie: 6.1.7600.16385, tijdstempel: 0x4a5bca54
    Naam van module met fout: igdumd64.dll, versie: 8.15.10.2653, tijdstempel: 0x4f3aac44
    Uitzonderingscode: 0xc0000005
    Foutoffset: 0x000000000030eb06
    Id van proces met fout: 0x11e4
    Starttijd van toepassing met fout: 0xDllHost.exe0
    Pad naar toepassing met fout: DllHost.exe1
    Pad naar module met fout: DllHost.exe2
    Rapport-id: DllHost.exe3


    Error: (11/15/2015 08:01:22 PM) (Source: CVHSVC) (EventID: 100) (User: )
    Description: Alleen informatie.
    (Patch task for {90140011-0066-0413-0000-0000000FF1CE}): DownloadLatest Failed:


    Error: (11/15/2015 07:43:53 PM) (Source: Microsoft-Windows-User Profiles Service) (EventID: 1533) (User: bryan77-PC)
    Description: Kan de profielmap C:\Users\AdminPc niet verwijderen. Deze fout wordt mogelijk veroorzaakt door bestanden in deze map, die door een ander programma worden gebruikt.


    DETAIL - De map is niet leeg.


    Error: (11/15/2015 07:12:26 PM) (Source: CVHSVC) (EventID: 100) (User: )
    Description: Alleen informatie.
    (Patch task for {90140011-0066-0413-0000-0000000FF1CE}): DownloadLatest Failed:


    Error: (11/15/2015 07:02:08 PM) (Source: BstHdAndroidSvc) (EventID: 0) (User: )
    Description: Service kan niet worden gestart. System.ApplicationException: Cannot start service. Service did not stop gracefully the last time it was run.
    bij BlueStacks.hyperDroid.Service.Service.OnStart(String[] args)
    bij System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)




    Systeemfouten:
    =============
    Error: (12/01/2015 10:14:39 AM) (Source: DCOM) (EventID: 10010) (User: )
    Description: {078AEF33-C48A-49F7-AFF3-A0EE810BFE7C}


    Error: (11/26/2015 01:42:58 AM) (Source: DCOM) (EventID: 10010) (User: )
    Description: {995C996E-D918-4A8C-A302-45719A6F4EA7}


    Error: (11/21/2015 00:05:11 AM) (Source: DCOM) (EventID: 10010) (User: )
    Description: {995C996E-D918-4A8C-A302-45719A6F4EA7}


    Error: (11/16/2015 08:28:12 AM) (Source: DCOM) (EventID: 10010) (User: )
    Description: {995C996E-D918-4A8C-A302-45719A6F4EA7}


    Error: (11/16/2015 03:32:03 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
    Description: De Client Virtualization Handler-service is afhankelijk van de Application Virtualization Client-service, die vanwege de volgende fout niet kan worden gestart:
    %%1053


    Error: (11/16/2015 03:30:53 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
    Description: De Application Virtualization Client-service kan vanwege de volgende fout niet worden gestart:
    %%1053


    Error: (11/16/2015 03:30:53 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
    Description: Time-out (30000 seconden) tijdens het wachten op het verbinden van deze service: Application Virtualization Client.


    Error: (11/16/2015 03:30:23 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
    Description: De Windows Live ID Sign-in Assistant-service kan vanwege de volgende fout niet worden gestart:
    %%1053


    Error: (11/16/2015 03:30:23 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
    Description: Time-out (30000 seconden) tijdens het wachten op het verbinden van deze service: Windows Live ID Sign-in Assistant.


    Error: (11/16/2015 03:29:52 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
    Description: De VIA Karaoke digital mixer Service-service kan vanwege de volgende fout niet worden gestart:
    %%1053




    ==================== Geheugen info ===========================


    Processor: Intel(R) Pentium(R) CPU B970 @ 2.30GHz
    Percentage geheugen in gebruik: 51%
    Totaal fysiek RAM-geheugen: 3979.96 MB
    Beschikbaar fysiek RAM-geheugen: 1947.18 MB
    Totaal Virtueel geheugen: 8258.13 MB
    Beschikbaar Virtual geheugen: 5826.17 MB


    ==================== Schijven ================================


    Drive c: (OS) (Fixed) (Total:119.24 GB) (Free:37.24 GB) NTFS ==>[systeem met boot componenten (verkregen van schijf)]
    Drive d: (DATA) (Fixed) (Total:153.53 GB) (Free:153.42 GB) NTFS


    ==================== MBR & Partitietabel ==================


    ========================================================
    Disk: 0 (Size: 298.1 GB) (Disk ID: 30EC77D9)


    Partition: GPT.


    ==================== Eind van Addition.txt ============================


    Results of screen317's Security Check version 1.013 --- 11/28/15
    Windows 7 Service Pack 1 x64 (UAC is enabled)
    Internet Explorer 11
    ``````````````Antivirus/Firewall Check:``````````````
    AVG AntiVirus Free Edition 2014
    Antivirus out of date!
    `````````Anti-malware/Other Utilities Check:`````````
    Java 8 Update 65
    Java version 32-bit out of Date!
    Adobe Flash Player 10 Flash Player out of Date!
    Adobe Reader XI
    Google Chrome (46.0.2490.80)
    Google Chrome (46.0.2490.86)
    ````````Process Check: objlist.exe by Laurent````````
    AVG avgwdsvc.exe
    `````````````````System Health check`````````````````
    Total Fragmentation on Drive C: 0%
    ````````````````````End of Log``````````````````````


    • Ad Bot

      advertising
      Beep.

        
       

  2. #2
    Corrine's Avatar
    Join Date
    Feb 2012
    Location
    Upstate, NY
    Posts
    9,056

    Re: startpage changed, commercials on screen

    Hi, Haramo. Welcome to Sysnative Forums!

    Let's see what we can do to get your computer back to normal.

    1. Please note that your antivirus software is out of date. You are advised to update AVG to the latest version. Note: It is strongly recommended that you do a custom install and watch each screen since AVG bundles AVG Zen and will also nage you into downloading potentially unwanted programs such as AVG PC TuneUp and AVG Web TuneUp.

    2. I note that you have both the 32- and 64-bit versions of Java installed on the computer. You do not need both (and in fact most people do not need Java at all.) Please uninstall one or both of the following:

    Java 8 Update 65 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86418065F0}) (Version: 8.0.650.17 - Oracle Corporation)
    Java 8 Update 65 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218065F0}) (Version: 8.0.650.17 - Oracle Corporation)

    3. Please do the following to run FRST:

    Note: If the tool warns you about the version you're using being an outdated version please download and run the updated version.

    NOTICE: This script was written specifically for this user. Running it on another machine may cause damage to your operating system
    • Open Notepad (Start =>All Programs => Accessories => Notepad).
    • Copy/Paste the entire contents of the code box below into Notepad.
    Code:
    start
    CreateRestorePoint:
    CloseProcesses:
    ShortcutWithArgument: C:\Users\bryan77\Desktop\Internet Explorer.lnk -> C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.sweet-page.com/?type=sc&ts=1410798019&from=cor&uid=ST320LT020-9YG142_W0Q4K52MXXXXW0Q4K52M <==== AANDACHT
    ShortcutWithArgument: C:\Users\bryan77\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.sweet-page.com/?type=sc&ts=1410798019&from=cor&uid=ST320LT020-9YG142_W0Q4K52MXXXXW0Q4K52M <==== AANDACHT
    ShortcutWithArgument: C:\Users\bryan77\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.sweet-page.com/?type=sc&ts=1410798019&from=cor&uid=ST320LT020-9YG142_W0Q4K52MXXXXW0Q4K52M <==== AANDACHT
    ShortcutWithArgument: C:\Users\bryan77\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.sweet-page.com/?type=sc&ts=1410798019&from=cor&uid=ST320LT020-9YG142_W0Q4K52MXXXXW0Q4K52M <==== AANDACHT
    ShortcutWithArgument: C:\Users\bryan77\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk -> C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.sweet-page.com/?type=sc&ts=1410798019&from=cor&uid=ST320LT020-9YG142_W0Q4K52MXXXXW0Q4K52M <==== AANDACHT
    ShortcutWithArgument: C:\Users\bryan77\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.sweet-page.com/?type=sc&ts=1410798019&from=cor&uid=ST320LT020-9YG142_W0Q4K52MXXXXW0Q4K52M <==== AANDACHT
    ShortcutWithArgument: C:\Users\bryan77\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.sweet-page.com/?type=sc&ts=1410798019&from=cor&uid=ST320LT020-9YG142_W0Q4K52MXXXXW0Q4K52M <==== AANDACHT
    EmptyTemp:
    end
    • Click Format and ensure Wordwrap is unchecked.
    • Important: Save the code to the same folder/directory that FRST.exe is located in, naming it as fixlist.txt
    • Start FRST in a similar manner to when you ran a scan earlier, but this time when it opens ....
      • Press the Fix button once and wait.
      • FRST will process fixlist.txt
      • When finished, it will produce a log fixlog.txt in the same folder/directory as FRST64.exe
      • Please post the log in your next reply.


    4. Please download AdwCleaner by Xplode and save to your Desktop.
    • Right-click on AdwCleaner.exe and select Run As Administrator
    • The tool will start to update the database, please wait a bit.
    • Click on the Scan button.
    • AdwCleaner will begin. Please be patient as the scan may take some time to complete.
    • After the scan has finished, click on the Clean button.
    • Press OK when asked to close all programs and follow the onscreen prompts.
    • Press OK again to allow AdwCleaner to restart the computer and complete the removal process.
    • After rebooting, a logfile report (AdwCleaner[S#].txt) will open automatically (where the largest value of # represents the most recent report).
    • Copy and paste the contents of that logfile in your next reply.
    • A copy of that logfile will also be saved in the C:\AdwCleaner folder.


    5. Please download Junkware Removal Tool to your desktop.
    • Disable your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select "Run as Administrator".
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Post the contents of JRT.txt into your next message.


    Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

    Remember - A day without laughter is a day wasted.
    May the wind sing to you and the sun rise in your heart.

  3. #3

    Re: startpage changed, commercials on screen

    Fix resultaat van Farbar Recovery Scan Tool (x64) Versie:01-12-2015
    Gestart door bryan77 (2015-12-02 13:39:14) Run:1
    Gestart vanaf C:\Users\bryan77\Desktop
    Geladen Profielen: bryan77 (Beschikbare Profielen: bryan77 & Bryan & Barbara)
    Boot Modus: Normal
    ==============================================


    fixlist inhoud:
    *****************
    start
    CreateRestorePoint:
    CloseProcesses:
    ShortcutWithArgument: C:\Users\bryan77\Desktop\Internet Explorer.lnk -> C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.sweet-page.com/?type=sc&ts=1410798019&from=cor&uid=ST320LT020-9YG142_W0Q4K52MXXXXW0Q4K52M <==== AANDACHT
    ShortcutWithArgument: C:\Users\bryan77\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.sweet-page.com/?type=sc&ts=1410798019&from=cor&uid=ST320LT020-9YG142_W0Q4K52MXXXXW0Q4K52M <==== AANDACHT
    ShortcutWithArgument: C:\Users\bryan77\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.sweet-page.com/?type=sc&ts=1410798019&from=cor&uid=ST320LT020-9YG142_W0Q4K52MXXXXW0Q4K52M <==== AANDACHT
    ShortcutWithArgument: C:\Users\bryan77\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.sweet-page.com/?type=sc&ts=1410798019&from=cor&uid=ST320LT020-9YG142_W0Q4K52MXXXXW0Q4K52M <==== AANDACHT
    ShortcutWithArgument: C:\Users\bryan77\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk -> C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.sweet-page.com/?type=sc&ts=1410798019&from=cor&uid=ST320LT020-9YG142_W0Q4K52MXXXXW0Q4K52M <==== AANDACHT
    ShortcutWithArgument: C:\Users\bryan77\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.sweet-page.com/?type=sc&ts=1410798019&from=cor&uid=ST320LT020-9YG142_W0Q4K52MXXXXW0Q4K52M <==== AANDACHT
    ShortcutWithArgument: C:\Users\bryan77\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.sweet-page.com/?type=sc&ts=1410798019&from=cor&uid=ST320LT020-9YG142_W0Q4K52MXXXXW0Q4K52M <==== AANDACHT
    EmptyTemp:
    end
    *****************


    Herstelpunt is succesfol gemaakt.
    Proces succesvol afgesloten.
    C:\Users\bryan77\Desktop\Internet Explorer.lnk => snelkoppeling argument is succesvol verwijderd..
    C:\Users\bryan77\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk => snelkoppeling argument is succesvol verwijderd..
    C:\Users\bryan77\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk => snelkoppeling argument met succes hersteld
    C:\Users\bryan77\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk => snelkoppeling argument is succesvol verwijderd..
    C:\Users\bryan77\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk => snelkoppeling argument is succesvol verwijderd..
    C:\Users\bryan77\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk => snelkoppeling argument is succesvol verwijderd..
    C:\Users\bryan77\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk => snelkoppeling argument is succesvol verwijderd..
    EmptyTemp: => 6.3 GB tijdelijke gegevens verwijderd.




    Het systeem moest herstart worden.


    ==== Eind van Fixlog 13:47:00 ====


    # AdwCleaner v5.023 - Logbestand aangemaakt 02/12/2015 op 15:25:38
    # Laatste update 30/11/2015 door Xplode
    # Database : 2015-11-30.1 [Server]
    # Besturingssysteem : Windows 7 Home Premium Service Pack 1 (x64)
    # Gebruikersnaam : bryan77 - BRYAN77-PC
    # Gestart vanuit : C:\Users\bryan77\Desktop\adwcleaner_5.023.exe
    # Optie : Verwijderen
    # Ondersteuning : Forum - ToolsLib


    ***** [ Services ] *****




    ***** [ Mappen ] *****


    [-] Map Verwijderd : C:\ProgramData\AVG Security Toolbar
    [-] Map Verwijderd : C:\ProgramData\Avg_Update_0215tb
    [-] Map Verwijderd : C:\ProgramData\Avg_Update_0615tb
    [-] Map Verwijderd : C:\ProgramData\{d56f2512-cc9e-1e06-d56f-f2512cc9944b}
    [-] Map Verwijderd : C:\ProgramData\ddjiaoeajkbgjpckeijaapfbkmpifcpf
    [-] Map Verwijderd : C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nafaimnnclfjfedmmabolbppcngeolgf
    [-] Map Verwijderd : C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\gafhhbahpojnjfhpepjjfjojbphnogmn
    [-] Map Verwijderd : C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\blgkblimeaijgefaoiedchmmemmikpdg
    [-] Map Verwijderd : C:\Users\Bryan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Gameo


    ***** [ Bestanden ] *****


    [-] Bestand Verwijderd : C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_nafaimnnclfjfedmmabolbppcngeolgf_0.localstorage
    [-] Bestand Verwijderd : C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_nafaimnnclfjfedmmabolbppcngeolgf_0.localstorage-journal
    [-] Bestand Verwijderd : C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_gafhhbahpojnjfhpepjjfjojbphnogmn_0.localstorage
    [-] Bestand Verwijderd : C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_gafhhbahpojnjfhpepjjfjojbphnogmn_0.localstorage-journal
    [-] Bestand Verwijderd : C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_minecraft-server.nl.softonic.com_0.localstorage
    [-] Bestand Verwijderd : C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_minecraft-server.nl.softonic.com_0.localstorage-journal
    [-] Bestand Verwijderd : C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_minecraft.nl.softonic.com_0.localstorage
    [-] Bestand Verwijderd : C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_minecraft.nl.softonic.com_0.localstorage-journal
    [-] Bestand Verwijderd : C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_nl.softonic.com_0.localstorage
    [-] Bestand Verwijderd : C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_nl.softonic.com_0.localstorage-journal
    [-] Bestand Verwijderd : C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_pconverter.dl.myway.com_0.localstorage
    [-] Bestand Verwijderd : C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_pconverter.dl.myway.com_0.localstorage-journal
    [-] Bestand Verwijderd : C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_pconverter.dl.tb.ask.com_0.localstorage
    [-] Bestand Verwijderd : C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_pconverter.dl.tb.ask.com_0.localstorage-journal
    [-] Bestand Verwijderd : C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_search.tb.ask.com_0.localstorage
    [-] Bestand Verwijderd : C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_search.tb.ask.com_0.localstorage-journal
    [-] Bestand Verwijderd : C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www2.inbox.com_0.localstorage
    [-] Bestand Verwijderd : C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www2.inbox.com_0.localstorage-journal
    [-] Bestand Verwijderd : C:\Users\Bryan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\gameo.lnk
    [-] Bestand Verwijderd : C:\Users\Bryan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Play Games Online.url


    ***** [ DLLs ] *****




    ***** [ Snelkoppelingen ] *****




    ***** [ geplande taken ] *****




    ***** [ Register ] *****


    [-] Waarde Verwijderd : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [pcspeedup]
    [-] Sleutel Verwijderd : HKLM\SOFTWARE\Classes\PCSU.Registry
    [-] Sleutel Verwijderd : HKLM\SOFTWARE\Classes\PCSU.SysUtils
    [-] Sleutel Verwijderd : HKLM\SOFTWARE\Classes\PCSU.SysUtils.1
    [-] Sleutel Verwijderd : HKLM\SOFTWARE\Classes\PCSU.Registry.1
    [-] Sleutel Verwijderd : HKCU\Software\Classes\CLSID\{7A55CBB2-2B2E-4A41-9DE1-6AC5D2C2BE0A}
    [-] Sleutel Verwijderd : HKCU\Software\Classes\CLSID\{F28C2F70-47DE-4EA5-8F6D-7D1476CD1EF5}
    [-] Sleutel Verwijderd : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
    [-] Sleutel Verwijderd : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
    [-] Sleutel Verwijderd : HKLM\SOFTWARE\Classes\Interface\{64C4BD7C-A0A5-4753-A507-6ED10DB57A44}
    [-] Sleutel Verwijderd : HKLM\SOFTWARE\Classes\Interface\{67866A4D-618A-4E57-BE3E-44E98042F87C}
    [-] Sleutel Verwijderd : HKLM\SOFTWARE\Classes\Interface\{7F7B3D8C-F4CE-4A1F-8BB4-B7E191D7D3AF}
    [-] Sleutel Verwijderd : HKLM\SOFTWARE\Classes\Interface\{BE6FA26E-397F-4462-8B44-35DA526A3F2F}
    [-] Sleutel Verwijderd : HKLM\SOFTWARE\Classes\Interface\{D2E0014A-4C61-4DEF-B7A4-CD16677961C7
    }
    [-] Sleutel Verwijderd : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
    [-] Sleutel Verwijderd : HKLM\SOFTWARE\Classes\TypeLib\{3157E247-2784-4028-BF0F-52D6DDC70E1B}
    [-] Sleutel Verwijderd : HKLM\SOFTWARE\Classes\TypeLib\{0B6C9E5C-4E2D-4874-BC84-4A6178E8E179}
    [-] Sleutel Verwijderd : HKLM\SOFTWARE\Classes\TypeLib\{6F9AD55C-1BCE-4A69-939D-1A94CD5E1DB8}
    [-] Sleutel Verwijderd : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{B2BC04DF-EFBD-409A-95CA-36874E5AB92A}
    [-] Waarde Verwijderd : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID [{54E67346-EE5A-45B6-82AA-4F0BB28C79C2}]
    [-] Sleutel Verwijderd : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B2BC04DF-EFBD-409A-95CA-36874E5AB92A}
    [-] Waarde Verwijderd : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{7A55CBB2-2B2E-4A41-9DE1-6AC5D2C2BE0A}]
    [-] Sleutel Verwijderd : [x64] HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
    [-] Sleutel Verwijderd : [x64] HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
    [-] Sleutel Verwijderd : [x64] HKLM\SOFTWARE\Classes\Interface\{64C4BD7C-A0A5-4753-A507-6ED10DB57A44}
    [-] Sleutel Verwijderd : [x64] HKLM\SOFTWARE\Classes\Interface\{67866A4D-618A-4E57-BE3E-44E98042F87C}
    [-] Sleutel Verwijderd : [x64] HKLM\SOFTWARE\Classes\Interface\{7F7B3D8C-F4CE-4A1F-8BB4-B7E191D7D3AF}
    [-] Sleutel Verwijderd : [x64] HKLM\SOFTWARE\Classes\Interface\{BE6FA26E-397F-4462-8B44-35DA526A3F2F}
    [-] Sleutel Verwijderd : [x64] HKLM\SOFTWARE\Classes\Interface\{D2E0014A-4C61-4DEF-B7A4-CD16677961C7}
    [-] Sleutel Verwijderd : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B2BC04DF-EFBD-409A-95CA-36874E5AB92A}
    [-] Sleutel Verwijderd : HKCU\Software\Softonic
    [-] Sleutel Verwijderd : HKCU\Software\Speedchecker Limited
    [-] Sleutel Verwijderd : HKCU\Software\Vittalia
    [-] Sleutel Verwijderd : HKCU\Software\Avg Secure Update
    [-] Sleutel Verwijderd : HKCU\Software\WEBAPP
    [-] Sleutel Verwijderd : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{C168639F-5810-4EC8-B1E8-0251AA8A771C}
    [-] Sleutel Verwijderd : HKU\.DEFAULT\Software\Avg Secure Update
    [-] Sleutel Verwijderd : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\sweet-page.com
    [-] Sleutel Verwijderd : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\sweet-page


    ***** [ Internetbrowsers ] *****


    [-] [C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Verwijderd : five-nights-at-freddys-2-demo.en.softonic.com
    [-] [C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Verwijderd : minecraft-server.nl.softonic.com
    [-] [C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Verwijderd : aaaaahlfahldnilidgnlikdckbfehhca
    [-] [C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Verwijderd : aaaaaiabcopkplhgaedhbloeejhhankf
    [-] [C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Verwijderd : blgkblimeaijgefaoiedchmmemmikpdg
    [-] [C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Verwijderd : ddjiaoeajkbgjpckeijaapfbkmpifcpf
    [-] [C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Verwijderd : gafhhbahpojnjfhpepjjfjojbphnogmn
    [-] [C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Verwijderd : nafaimnnclfjfedmmabolbppcngeolgf


    *************************


    :: "Tracing" sleutels verwijderd
    :: Winsock instellingen gereset


    ########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [9265 bytes] ##########






    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    Junkware Removal Tool (JRT) by Malwarebytes
    Version: 8.0.1 (11.24.2015)
    Operating System: Windows 7 Home Premium x64
    Ran by bryan77 (Administrator) on wo 02-12-2015 at 15:33:01,94
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~








    File System: 6


    Successfully deleted: C:\Users\bryan77\AppData\Local\{34E5F845-55B9-4A6F-B40D-E30ACC8CD12E} (Empty Folder)
    Successfully deleted: C:\Users\bryan77\AppData\Roaming\sp_data.sys (File)
    Successfully deleted: C:\Windows\SysWOW64\REN7B4.tmp (File)
    Successfully deleted: C:\Windows\SysWOW64\sho3786.tmp (File)
    Successfully deleted: C:\Windows\SysWOW64\sho4C77.tmp (File)
    Successfully deleted: C:\Windows\SysWOW64\shoF869.tmp (File)






    Registry: 3


    Successfully deleted: HKLM\SYSTEM\CurrentControlSet\services\0169601385920986mcinstcleanup (Registry Key)
    Successfully deleted: HKLM\SYSTEM\CurrentControlSet\services\PCSUUCDRV (Registry Key)
    Successfully deleted: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} (Registry Key)








    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    Scan was completed on wo 02-12-2015 at 15:36:21,77
    End of JRT log
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

  4. #4
    Corrine's Avatar
    Join Date
    Feb 2012
    Location
    Upstate, NY
    Posts
    9,056

    Re: startpage changed, commercials on screen

    How is your computer now?


    Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

    Remember - A day without laughter is a day wasted.
    May the wind sing to you and the sun rise in your heart.

  5. #5

    Re: startpage changed, commercials on screen

    Quote Originally Posted by Corrine View Post
    How is your computer now?

    Laptop slow, advertisements, after updating avg, it gives a message that laptop is slow.

    Windows 10 free install pops up

    watch4, don't know what this is

  6. #6
    Corrine's Avatar
    Join Date
    Feb 2012
    Location
    Upstate, NY
    Posts
    9,056

    Re: startpage changed, commercials on screen

    Please download Malwarebytes Anti-Malware and save it to your desktop.
    • Double-click on the setup file (mbam-setup.exe), then click on Run to install. (Note: At the end, Uncheck enable free trial of Malwarebytes' Anti-Malware. You can activate this when we've finished, if you wish)
    • Malwarebytes will automatically open to it's Dashboard. If you have never run this version, you should see a red note at the top indicating "A scan has never been run on your system"
    • Click on Update Now to download the current database definitions, then click the Scan Now >> button.
    • If you have run this version before, you should see a green note at the top indicating "Your system is fully protected".
    • You will be prompted to update Malwarebytes...click on the Update Now button.
    • The THREAT SCAN will automatically begin.
    • When the scan has completed, the results will be displayed. Click on Quarantine All, then click on Apply Actions.
    • To complete any actions taken you will be prompted to restart your computer...click on Yes. Failure to reboot normally will prevent Malwarebytes from removing all the malware.
    • After rebooting the computer, copy and paste the mbam.log in your next reply.

    To retrieve the Malwarebytes Anti-Malware scan log information (Method 1)
    • Open Malwarebytes Anti-Malware.
    • Click the History Tab at the top and select Application Logs.
    • Select (check) the box next to Scan Log. Choose the most current scan.
    • Click the View button.
    • Click Copy to Clipboard at the bottom...come back to this thread, click Add Reply, then right-click and choose Paste.
    • Alternatively, you can click Export and save the log as a .txt file on your Desktop or another location.
    • Be sure to post the complete log to include the top portion which shows MBAM's database version and your operating system.

    To retrieve the Malwarebytes Anti-Malware 2.0 scan log information (Method 2)
    • Open Malwarebytes Anti-Malware.
    • Click the Scan Tab at the top.
    • Click the View detailed log link on the right.
    • Click Copy to Clipboard at the bottom...come back to this thread, click Add Reply, then right-click and choose Paste.
    • Alternatively, you can click Export and save the log as a .txt file on your Desktop or another location.
    • Be sure to post the complete log to include the top portion which shows MBAM's database version and your operating system.

    Logs are named by the date of scan in the following format: mbam-log-yyyy-mm-dd and automatically saved to the following locations:
    -- XP: C:\Documents and Settings\<Username>\Application Data\Malwarebytes\Malwarebytes Anti-Malware\Logs\mbam-log-yyyy-mm-dd
    -- Vista, Windows 7/8: C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Logs\mbam-log-yyyy-mm-dd

    What do you mean about "watch4"?


    Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

    Remember - A day without laughter is a day wasted.
    May the wind sing to you and the sun rise in your heart.

  7. #7

    Re: startpage changed, commercials on screen

    testing posting on this thread, as I could not post the log (results finally in an error, after a window appear if I want to leave to page or not)

    Ok posting works, maybe the log is to big? hmm, will divide it and post it

    log mbam 1st part

    here is the log, laptop still slow


    Malwarebytes Anti-Malware
    Malwarebytes | Free Anti-Malware & Internet Security Software


    Scandatum: 4-12-2015
    Scantijd: 14:06
    Logboekbestand:
    Beheerder: Ja


    Versie: 2.2.0.1024
    Malware-database: v2015.12.04.02
    Rootkit-database: v2015.11.26.01
    Licentie: Gratis
    Malware-bescherming: Uitgeschakeld
    Bescherming tegen kwaadaardige websites: Uitgeschakeld
    Zelfbescherming: Uitgeschakeld


    Besturingssysteem: Windows 7 Service Pack 1
    Processor: x64
    Bestandssysteem: NTFS
    Gebruiker: bryan77


    Scantype: Bedreigingsscan
    Resultaat: Voltooid
    Objecten gescand: 466639
    Verstreken tijd: 40 min, 17 sec


    Geheugen: Ingeschakeld
    Opstarten: Ingeschakeld
    Bestandssysteem: Ingeschakeld
    Archieven: Ingeschakeld
    Rootkits: Ingeschakeld
    Heuristiek: Ingeschakeld
    POP: Ingeschakeld
    POA: Ingeschakeld


    Processen: 0
    (Geen kwaadaardige items gedetecteerd)


    Modules: 0
    (Geen kwaadaardige items gedetecteerd)


    Registersleutels: 3
    PUP.Optional.MultiPlug, HKU\S-1-5-21-3732487481-855672253-929003311-1001_Classes\TYPELIB\{157B1AA6-3E5C-404A-9118-C1D91F537040}, In quarantaine, [50c28a17ef9c0f27dc0a01c05ca7ba46],
    PUP.Optional.MultiPlug, HKU\S-1-5-21-3732487481-855672253-929003311-1001_Classes\INTERFACE\{3B3F3AAD-FB97-49FF-BFEE-D22869AC4326}, In quarantaine, [50c28a17ef9c0f27dc0a01c05ca7ba46],
    PUP.Optional.ProductSetup, HKU\S-1-5-21-3732487481-855672253-929003311-1005\SOFTWARE\PRODUCTSETUP, In quarantaine, [14fe0998fc8fdf572167158c62a1f907],


    Registerwaarden: 1
    PUP.Optional.ProductSetup, HKU\S-1-5-21-3732487481-855672253-929003311-1005\SOFTWARE\PRODUCTSETUP|tb, 0H1N1M, In quarantaine, [14fe0998fc8fdf572167158c62a1f907]


    Registerdata: 0
    (Geen kwaadaardige items gedetecteerd)


    Mappen: 291
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\ar, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\bg, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\ca, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\cs, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\da, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\de, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\el, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\en_GB, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\en_US, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\es, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\es_419, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\et, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\fi, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\fil, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\fr, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\he, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\hi, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\hu, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\id, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\it, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\ja, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\ko, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\lt, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\lv, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\ms, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\nl, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\no, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\pl, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\pt_BR, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\pt_PT, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\ro, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\ru, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\sk, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\sl, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\sr, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\sv, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\th, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\tr, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\uk, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\vi, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\zh_CN, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\zh_TW, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_metadata, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\ar, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\bg, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\ca, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],

  8. #8

    Re: startpage changed, commercials on screen

    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\cs, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\da, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\de, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\el, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\en_GB, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\en_US, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\es, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\es_419, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\et, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\eu, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\fi, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\fil, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\fr, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\he, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\hi, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\hr, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\hu, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\id, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\it, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\ja, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\ko, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\lt, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\lv, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\ms, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\nl, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\no, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\pl, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\pt_BR, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\pt_PT, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\ro, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\ru, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\sk, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\sl, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\sr, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\sv, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\th, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\tr, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\uk, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\vi, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\zh_CN, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\zh_TW, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_metadata, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0, In quarantaine, [7a98673a048771c58d339b02c242f40c],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\css, In quarantaine, [7a98673a048771c58d339b02c242f40c],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\html, In quarantaine, [7a98673a048771c58d339b02c242f40c],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\images, In quarantaine, [7a98673a048771c58d339b02c242f40c],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales, In quarantaine, [7a98673a048771c58d339b02c242f40c],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\bg, In quarantaine, [7a98673a048771c58d339b02c242f40c],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\ca, In quarantaine, [7a98673a048771c58d339b02c242f40c],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\cs, In quarantaine, [7a98673a048771c58d339b02c242f40c],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\da, In quarantaine, [7a98673a048771c58d339b02c242f40c],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\de, In quarantaine, [7a98673a048771c58d339b02c242f40c],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\el, In quarantaine, [7a98673a048771c58d339b02c242f40c],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\en, In quarantaine, [7a98673a048771c58d339b02c242f40c],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\en_GB, In quarantaine, [7a98673a048771c58d339b02c242f40c],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\es, In quarantaine, [7a98673a048771c58d339b02c242f40c],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\es_419, In quarantaine, [7a98673a048771c58d339b02c242f40c],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\et, In quarantaine, [7a98673a048771c58d339b02c242f40c],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\fi, In quarantaine, [7a98673a048771c58d339b02c242f40c],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\fil, In quarantaine, [7a98673a048771c58d339b02c242f40c],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\fr, In quarantaine, [7a98673a048771c58d339b02c242f40c],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\hi, In quarantaine, [7a98673a048771c58d339b02c242f40c],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\hr, In quarantaine, [7a98673a048771c58d339b02c242f40c],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\hu, In quarantaine, [7a98673a048771c58d339b02c242f40c],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\id, In quarantaine, [7a98673a048771c58d339b02c242f40c],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\it, In quarantaine, [7a98673a048771c58d339b02c242f40c],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\ja, In quarantaine, [7a98673a048771c58d339b02c242f40c],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\ko, In quarantaine, [7a98673a048771c58d339b02c242f40c],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\lt, In quarantaine, [7a98673a048771c58d339b02c242f40c],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\lv, In quarantaine, [7a98673a048771c58d339b02c242f40c],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\nb, In quarantaine, [7a98673a048771c58d339b02c242f40c],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\nl, In quarantaine, [7a98673a048771c58d339b02c242f40c],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\pl, In quarantaine, [7a98673a048771c58d339b02c242f40c],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\pt_BR, In quarantaine, [7a98673a048771c58d339b02c242f40c],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\pt_PT, In quarantaine, [7a98673a048771c58d339b02c242f40c],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\ro, In quarantaine, [7a98673a048771c58d339b02c242f40c],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\ru, In quarantaine, [7a98673a048771c58d339b02c242f40c],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\sk, In quarantaine, [7a98673a048771c58d339b02c242f40c],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\sl, In quarantaine, [7a98673a048771c58d339b02c242f40c],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\sr, In quarantaine, [7a98673a048771c58d339b02c242f40c],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\sv, In quarantaine, [7a98673a048771c58d339b02c242f40c],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\th, In quarantaine, [7a98673a048771c58d339b02c242f40c],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\tr, In quarantaine, [7a98673a048771c58d339b02c242f40c],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\uk, In quarantaine, [7a98673a048771c58d339b02c242f40c],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\vi, In quarantaine, [7a98673a048771c58d339b02c242f40c],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\zh_CN, In quarantaine, [7a98673a048771c58d339b02c242f40c],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\zh_TW, In quarantaine, [7a98673a048771c58d339b02c242f40c],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_metadata, In quarantaine, [7a98673a048771c58d339b02c242f40c],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda, In quarantaine, [7a98673a048771c58d339b02c242f40c],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\ar, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\bg, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\ca, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\cs, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\da, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\de, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\el, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\en, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\en-GB, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\es, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\es-419, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\et, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\fi, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\fil, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\fr, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\hr, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\hu, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\id, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\it, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\iw, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\ja, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\ko, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\lt, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\lv, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\nl, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\no, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\pl, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\pt-BR, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\pt-PT, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\ro, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\ru, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\sk, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\sl, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\sr, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\sv, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\th, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\tr, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\uk, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\vi, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\zh-CN, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\zh-TW, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_metadata, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\hr, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\am, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\ar, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\bg, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\bn, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\ca, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\cs, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\da, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\de, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\el, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\en, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\en_GB, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\en_US, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\es, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\es_419, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\et, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\fa, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\fi, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\fil, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\fr, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\gu, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\he, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\hi, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\hu, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\id, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\it, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\ja, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\kn, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\ko, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\lt, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\lv, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\ml, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\mr, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\ms, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\nl, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\no, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\pl, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\pt_BR, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\pt_PT, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\ro, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\ru, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\sk, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\sl, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\sr, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\sv, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\sw, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\ta, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\te, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\th, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\tr, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\uk, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\vi, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\zh_CN, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\zh_TW, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_metadata, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\css, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\html, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\images, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\bg, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\ca, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\cs, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\da, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\de, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\el, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\en, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\en_GB, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\es, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\es_419, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\et, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\fi, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\fil, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\fr, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\hi, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\hr, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\hu, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\id, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\it, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\ja, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\ko, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\lt, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\lv, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\nb, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\nl, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\pl, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\pt_BR, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\pt_PT, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\ro, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\ru, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\sk, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\sl, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\sr, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\sv, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\th, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\tr, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\uk, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\vi, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\zh_CN, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\zh_TW, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_metadata, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],

  9. #9

    Re: startpage changed, commercials on screen

    Bestanden: 306
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\manifest.json, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\icon_128.png, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\icon_16.png, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\main.html, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\main.js, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\ar\messages.json, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\bg\messages.json, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\ca\messages.json, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\cs\messages.json, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\da\messages.json, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\de\messages.json, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\el\messages.json, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\en_GB\messages.json, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\en_US\messages.json, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\es\messages.json, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\es_419\messages.json, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\et\messages.json, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\fi\messages.json, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\fil\messages.json, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\fr\messages.json, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\he\messages.json, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\hi\messages.json, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\hu\messages.json, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\id\messages.json, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\it\messages.json, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\ja\messages.json, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\ko\messages.json, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\lt\messages.json, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\lv\messages.json, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\ms\messages.json, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\nl\messages.json, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\no\messages.json, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\pl\messages.json, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\pt_BR\messages.json, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\pt_PT\messages.json, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\ro\messages.json, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\ru\messages.json, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\sk\messages.json, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\sl\messages.json, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\sr\messages.json, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\sv\messages.json, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\th\messages.json, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\tr\messages.json, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\uk\messages.json, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\vi\messages.json, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\zh_CN\messages.json, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_locales\zh_TW\messages.json, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_metadata\computed_hashes.json, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\_metadata\verified_contents.json, In quarantaine, [4ac8e9b843482e084d73afee43c128d8],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\manifest.json, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\128.png, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],

  10. #10

    Re: startpage changed, commercials on screen

    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\ar\messages.json, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\bg\messages.json, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\ca\messages.json, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\cs\messages.json, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\da\messages.json, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\de\messages.json, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\el\messages.json, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\en_GB\messages.json, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\en_US\messages.json, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\es\messages.json, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\es_419\messages.json, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\et\messages.json, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\eu\messages.json, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\fi\messages.json, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\fil\messages.json, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\fr\messages.json, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\he\messages.json, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\hi\messages.json, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\hr\messages.json, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\hu\messages.json, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\id\messages.json, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\it\messages.json, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\ja\messages.json, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\ko\messages.json, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\lt\messages.json, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\lv\messages.json, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\ms\messages.json, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\nl\messages.json, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\no\messages.json, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\pl\messages.json, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\pt_BR\messages.json, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\pt_PT\messages.json, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\ro\messages.json, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\ru\messages.json, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\sk\messages.json, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\sl\messages.json, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\sr\messages.json, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\sv\messages.json, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\th\messages.json, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\tr\messages.json, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\uk\messages.json, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\vi\messages.json, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\zh_CN\messages.json, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_locales\zh_TW\messages.json, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\_metadata\verified_contents.json, In quarantaine, [48cab4ed5e2df04659670895e51f2cd4],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\manifest.json, In quarantaine, [7a98673a048771c58d339b02c242f40c],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\craw_background.js, In quarantaine, [7a98673a048771c58d339b02c242f40c],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\craw_window.js, In quarantaine, [7a98673a048771c58d339b02c242f40c],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\css\craw_window.css, In quarantaine, [7a98673a048771c58d339b02c242f40c],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\html\craw_window.html, In quarantaine, [7a98673a048771c58d339b02c242f40c],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\images\flapper.gif, In quarantaine, [7a98673a048771c58d339b02c242f40c],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\images\icon_128.png, In quarantaine, [7a98673a048771c58d339b02c242f40c],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\images\icon_16.png, In quarantaine, [7a98673a048771c58d339b02c242f40c],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\images\topbar_floating_button.png, In quarantaine, [7a98673a048771c58d339b02c242f40c],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\images\topbar_floating_button_close.png, In quarantaine, [7a98673a048771c58d339b02c242f40c],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\images\topbar_floating_button_hover.png, In quarantaine, [7a98673a048771c58d339b02c242f40c],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\images\topbar_floating_button_maximize.png, In quarantaine, [7a98673a048771c58d339b02c242f40c],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\images\topbar_floating_button_pressed.png, In quarantaine, [7a98673a048771c58d339b02c242f40c],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\bg\messages.json, In quarantaine, [7a98673a048771c58d339b02c242f40c],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\ca\messages.json, In quarantaine, [7a98673a048771c58d339b02c242f40c],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\cs\messages.json, In quarantaine, [7a98673a048771c58d339b02c242f40c],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\da\messages.json, In quarantaine, [7a98673a048771c58d339b02c242f40c],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\de\messages.json, In quarantaine, [7a98673a048771c58d339b02c242f40c],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\el\messages.json, In quarantaine, [7a98673a048771c58d339b02c242f40c],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\en\messages.json, In quarantaine, [7a98673a048771c58d339b02c242f40c],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\en_GB\messages.json, In quarantaine, [7a98673a048771c58d339b02c242f40c],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\es\messages.json, In quarantaine, [7a98673a048771c58d339b02c242f40c],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\es_419\messages.json, In quarantaine, [7a98673a048771c58d339b02c242f40c],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\et\messages.json, In quarantaine, [7a98673a048771c58d339b02c242f40c],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\fi\messages.json, In quarantaine, [7a98673a048771c58d339b02c242f40c],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\fil\messages.json, In quarantaine, [7a98673a048771c58d339b02c242f40c],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\fr\messages.json, In quarantaine, [7a98673a048771c58d339b02c242f40c],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\hi\messages.json, In quarantaine, [7a98673a048771c58d339b02c242f40c],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\hr\messages.json, In quarantaine, [7a98673a048771c58d339b02c242f40c],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\hu\messages.json, In quarantaine, [7a98673a048771c58d339b02c242f40c],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\id\messages.json, In quarantaine, [7a98673a048771c58d339b02c242f40c],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\it\messages.json, In quarantaine, [7a98673a048771c58d339b02c242f40c],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\ja\messages.json, In quarantaine, [7a98673a048771c58d339b02c242f40c],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\ko\messages.json, In quarantaine, [7a98673a048771c58d339b02c242f40c],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\lt\messages.json, In quarantaine, [7a98673a048771c58d339b02c242f40c],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\lv\messages.json, In quarantaine, [7a98673a048771c58d339b02c242f40c],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\nb\messages.json, In quarantaine, [7a98673a048771c58d339b02c242f40c],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\nl\messages.json, In quarantaine, [7a98673a048771c58d339b02c242f40c],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\pl\messages.json, In quarantaine, [7a98673a048771c58d339b02c242f40c],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\pt_BR\messages.json, In quarantaine, [7a98673a048771c58d339b02c242f40c],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\pt_PT\messages.json, In quarantaine, [7a98673a048771c58d339b02c242f40c],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\ro\messages.json, In quarantaine, [7a98673a048771c58d339b02c242f40c],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\ru\messages.json, In quarantaine, [7a98673a048771c58d339b02c242f40c],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\sk\messages.json, In quarantaine, [7a98673a048771c58d339b02c242f40c],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\sl\messages.json, In quarantaine, [7a98673a048771c58d339b02c242f40c],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\sr\messages.json, In quarantaine, [7a98673a048771c58d339b02c242f40c],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\sv\messages.json, In quarantaine, [7a98673a048771c58d339b02c242f40c],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\th\messages.json, In quarantaine, [7a98673a048771c58d339b02c242f40c],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\tr\messages.json, In quarantaine, [7a98673a048771c58d339b02c242f40c],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\uk\messages.json, In quarantaine, [7a98673a048771c58d339b02c242f40c],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\vi\messages.json, In quarantaine, [7a98673a048771c58d339b02c242f40c],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\zh_CN\messages.json, In quarantaine, [7a98673a048771c58d339b02c242f40c],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\zh_TW\messages.json, In quarantaine, [7a98673a048771c58d339b02c242f40c],
    PUP.Optional.HijackModifiedExtension, C:\Users\Barbara.bryan77-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_metadata\verified_contents.json, In quarantaine, [7a98673a048771c58d339b02c242f40c],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\manifest.json, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\128.png, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\16.png, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\ar\messages.json, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\bg\messages.json, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\ca\messages.json, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\cs\messages.json, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\da\messages.json, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\de\messages.json, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\el\messages.json, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\en\messages.json, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\en-GB\messages.json, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\es\messages.json, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\es-419\messages.json, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\et\messages.json, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\fi\messages.json, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\fil\messages.json, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\fr\messages.json, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\hr\messages.json, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\hu\messages.json, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\id\messages.json, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\it\messages.json, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\iw\messages.json, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\ja\messages.json, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\ko\messages.json, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\lt\messages.json, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\lv\messages.json, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\nl\messages.json, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\no\messages.json, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\pl\messages.json, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\pt-BR\messages.json, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\pt-PT\messages.json, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\ro\messages.json, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\ru\messages.json, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\sk\messages.json, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\sl\messages.json, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\sr\messages.json, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\sv\messages.json, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\th\messages.json, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\tr\messages.json, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\uk\messages.json, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\vi\messages.json, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\zh-CN\messages.json, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_locales\zh-TW\messages.json, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.8_0\_metadata\verified_contents.json, In quarantaine, [e52d7f222e5d58de12ae881553b17e82],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\manifest.json, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\icon_128.png, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\hr\messages.json, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\am\messages.json, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\ar\messages.json, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\bg\messages.json, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\bn\messages.json, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\ca\messages.json, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\cs\messages.json, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\da\messages.json, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\de\messages.json, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\el\messages.json, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\en\messages.json, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\en_GB\messages.json, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\en_US\messages.json, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\es\messages.json, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\es_419\messages.json, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\et\messages.json, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\fa\messages.json, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\fi\messages.json, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\fil\messages.json, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\fr\messages.json, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\gu\messages.json, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\he\messages.json, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\hi\messages.json, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\hu\messages.json, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\id\messages.json, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\it\messages.json, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\ja\messages.json, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\kn\messages.json, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\ko\messages.json, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\lt\messages.json, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\lv\messages.json, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\ml\messages.json, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\mr\messages.json, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\ms\messages.json, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\nl\messages.json, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\no\messages.json, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\pl\messages.json, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\pt_BR\messages.json, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\pt_PT\messages.json, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\ro\messages.json, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\ru\messages.json, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\sk\messages.json, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\sl\messages.json, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\sr\messages.json, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\sv\messages.json, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\sw\messages.json, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\ta\messages.json, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\te\messages.json, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\th\messages.json, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\tr\messages.json, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\uk\messages.json, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\vi\messages.json, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\zh_CN\messages.json, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_locales\zh_TW\messages.json, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldmooljopkgnladppbhlfggdioddjhhb\1.0_0\_metadata\verified_contents.json, In quarantaine, [bf53366b07842610fdc3cecfa262bc44],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\manifest.json, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\craw_background.js, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\craw_window.js, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\css\craw_window.css, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\html\craw_window.html, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\images\flapper.gif, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\images\icon_128.png, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\images\icon_16.png, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\images\topbar_floating_button.png, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\images\topbar_floating_button_close.png, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\images\topbar_floating_button_hover.png, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\images\topbar_floating_button_maximize.png, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\images\topbar_floating_button_pressed.png, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\bg\messages.json, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\ca\messages.json, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\cs\messages.json, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\da\messages.json, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\de\messages.json, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\el\messages.json, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\en\messages.json, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\en_GB\messages.json, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\es\messages.json, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\es_419\messages.json, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\et\messages.json, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\fi\messages.json, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\fil\messages.json, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\fr\messages.json, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\hi\messages.json, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\hr\messages.json, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\hu\messages.json, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\id\messages.json, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\it\messages.json, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\ja\messages.json, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\ko\messages.json, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\lt\messages.json, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\lv\messages.json, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\nb\messages.json, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\nl\messages.json, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\pl\messages.json, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\pt_BR\messages.json, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\pt_PT\messages.json, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\ro\messages.json, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\ru\messages.json, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\sk\messages.json, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\sl\messages.json, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\sr\messages.json, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\sv\messages.json, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\th\messages.json, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\tr\messages.json, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\uk\messages.json, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\vi\messages.json, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\zh_CN\messages.json, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_locales\zh_TW\messages.json, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],
    PUP.Optional.HijackModifiedExtension, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\_metadata\verified_contents.json, In quarantaine, [bf53b8e9e0ab9c9ae8d8f3aad62eaa56],


    Fysieke Sectoren: 0
    (Geen kwaadaardige items gedetecteerd)




    (end)

  11. #11
    Corrine's Avatar
    Join Date
    Feb 2012
    Location
    Upstate, NY
    Posts
    9,056

    Re: startpage changed, commercials on screen

    Malwarebytes didn't detect any malicious items, rather PUPs (Potentially Unwaned Programs). What I don't normally see are installed files in multiple languages as shown in your log. Dutch fits but have you intentionally installed Hebrew, Arabic, Russian and Chinese versions on your computer?

    Συλλογή φωτογραφιών (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
    Основные компоненты Windows Live (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
    Почта Windows Live (x32 Version: 16.4.3508.0205 - Корпорация Майкрософт) Hidden
    Фотоальбом (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
    Фотографии (общедоступная версия) (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
    גלריית התמונות (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
    بريد Windows Live (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
    معرض الصور (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
    影像中心 (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
    What can you tell me about "The Simpsons Tapped Out Packages (HKU\S-1-5-21-3732487481-855672253-929003311-1001\...\The Simpsons Tapped Out Packages) (Version: - )"? As it appears there is some question regarding the program and it is suggested that you uninstall it.

    Let's see what an online scan shows. Please follow the instructions below to run an on-line scan from ESET.
    • Note: It is easiest if you use Internet explorer for this scan. (If you use an alternate browser, it will be necessary to download the ESET Smart Installer)
      • Hold down Control and click on this link to open ESET OnlineScan in a new window so you can refer to these instructions.
      • Click the green ESET Online Scanner box.
      • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
        • Click on esetsmartinstaller_enu.exe to download the ESET Smart Installer. Save it to your desktop.
        • Double click on the Eset Smart Installer icon on your desktop.
      • Check "YES, I accept the Terms of Use."
      • Click the Start button.
      • Accept any security warnings from your browser.
      • Under scan settings, check "Scan Archives" and "Remove found threats"
      • Click Advanced settings and select the following:
        • Scan potentially unwanted applications
        • Scan for potentially unsafe applications
        • Enable Anti-Stealth technology
      • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
      • When the scan completes, click List Threats
      • Click Export, and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
      • Click the Back button.
      • Click the Finish button.


    Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

    Remember - A day without laughter is a day wasted.
    May the wind sing to you and the sun rise in your heart.

  12. #12

    Re: startpage changed, commercials on screen

    No no other languases installed intentionally.

    he Simpsons Tapped Out Packages: I tried to uninstall in control panal, remove programs, when I click to uninstall, a window appears that are is an error with this app and it's possible it is already uninstalled, so I had the choise to delete it from the list. Hope that's enough?

    Probably the children installed, it, laptop normally only used for school tasks or facebook, hotmail, social media.

    eset online is scanning now, will post log if finished.

  13. #13

    Re: startpage changed, commercials on screen

    eset log only one line:

    C:\Users\bryan77\AppData\LocalLow\Sun\Java\jre1.7.0_67\java_sp.dll a variant of Win32/Bundled.Toolbar.Ask.M potentially unsafe application cleaned by deleting - quarantined

  14. #14
    Corrine's Avatar
    Join Date
    Feb 2012
    Location
    Upstate, NY
    Posts
    9,056

    Re: startpage changed, commercials on screen

    Thank you.

    Let's have FRST create a restore point and remove the various language versions of Photo Gallery, etc. I'll also include Simpsons, just in case it is still there and hidden. I'll provide instructions following that for fresh FRST logs. Although, please let me know if there is any improvement.

    1. Please do the following to run FRST:

    Note: If the tool warns you about the version you're using being an outdated version please download and run the updated version.

    NOTICE: This script was written specifically for this user. Running it on another machine may cause damage to your operating system
    • Open Notepad (Start =>All Programs => Accessories => Notepad).
    • Copy/Paste the entire contents of the code box below into Notepad.
    Code:
    start
    CreateRestorePoint:
    CloseProcesses:
    The Simpsons Tapped Out Packages (HKU\S-1-5-21-3732487481-855672253-929003311-1001\...\The Simpsons Tapped Out Packages) (Version: - ) <==== AANDACHT
    Συλλογή φωτογραφιών (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
    Основные компоненты Windows Live (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
    Почта Windows Live (x32 Version: 16.4.3508.0205 - Корпорация Майкрософт) Hidden
    Фотоальбом (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
    Фотографии (общедоступная версия) (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
    גלריית התמונות (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
    بريد Windows Live (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
    معرض الصور (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
    影像中心 (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
    EmptyTemp:
    end
    • Click Format and ensure Wordwrap is unchecked.
    • Important: Save the code to the same folder/directory that FRST.exe is located in, naming it as fixlist.txt
    • Start FRST in a similar manner to when you ran a scan earlier, but this time when it opens ....
      • Press the Fix button once and wait.
      • FRST will process fixlist.txt
      • When finished, it will produce a log fixlog.txt in the same folder/directory as FRST64.exe
      • Please post the log in your next reply.


    2. Please note the instructions below and provide a fresh FRST scan.
    • Right click to run as administrator. When the tool opens click Yes to disclaimer.
    • Note: After FRST completes updating and the tool appears, check the box next to Addition.txt under the "Optional Scan" section
    • Press Scan button.
    • Please copy/paste both logs in your reply.


    Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

    Remember - A day without laughter is a day wasted.
    May the wind sing to you and the sun rise in your heart.

  15. #15

    Re: startpage changed, commercials on screen

    when I want to save the fixlist txt file, after copy to it the code, it says that the file contains characters in unicode that will be lost if I save this file as a ANSI textfile.

    If I select cancel, I can save the document myself and change the code ANSI to Unicode.
    Do I need to change code that text is saved to from ANSI to Unicode?

  16. #16

    Re: startpage changed, commercials on screen

    I saved text file as unicode in place of ANSI code, thaught to give it a try, FRST fix seemed to work so it's ok.

    fixlist log reports that for the simpsons it found no automatc fix.

    Fix resultaat van Farbar Recovery Scan Tool (x64) Versie:05-12-2015
    Gestart door bryan77 (2015-12-05 22:50:30) Run:2
    Gestart vanaf C:\Users\bryan77\Desktop
    Geladen Profielen: bryan77 (Beschikbare Profielen: bryan77 & Bryan & Barbara)
    Boot Modus: Normal
    ==============================================


    fixlist inhoud:
    *****************
    start
    CreateRestorePoint:
    CloseProcesses:
    The Simpsons Tapped Out Packages (HKU\S-1-5-21-3732487481-855672253-929003311-1001\...\The Simpsons Tapped Out Packages) (Version: - ) <==== AANDACHT
    Συλλογή φωτογραφιών (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
    Основные компоненты Windows Live (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
    Почта Windows Live (x32 Version: 16.4.3508.0205 - Корпорация Майкрософт) Hidden
    Фотоальбом (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
    Фотографии (общедоступная версия) (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
    גלריית התמונות (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
    بريد Windows Live (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
    معرض الصور (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
    影像中心 (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
    EmptyTemp:
    end
    *****************


    Herstelpunt is succesfol gemaakt.
    Proces succesvol afgesloten.
    The Simpsons Tapped Out Packages (HKU\S-1-5-21-3732487481-855672253-929003311-1001\...\The Simpsons Tapped Out Packages) (Version: - ) <==== AANDACHT => Fout: Geen automatische fix gevonden voor dit item.
    HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{032CB0D7-FDBF-4CA9-901B-A4C1B01B1777}\\SystemComponent => waarde is succesvol verwijderd.
    HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{7A9122B2-CF90-4ACB-8E10-AA83F725916B}\\SystemComponent => waarde is succesvol verwijderd.
    HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{44B4333A-60A6-4FFC-BCC5-B0ECA23D2AAB}\\SystemComponent => waarde is succesvol verwijderd.
    HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{CE4EEFE0-85E0-436E-95C5-BCB2EE30C976}\\SystemComponent => waarde is succesvol verwijderd.
    HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{234BD64C-99F4-42B5-837F-82F00E37A7E1}\\SystemComponent => waarde is succesvol verwijderd.
    HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{B1AC8AF0-2979-4DF8-AE26-B1D543F3543F}\\SystemComponent => waarde is succesvol verwijderd.
    HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{7A546E5C-0906-42CC-92DF-B2E787FFA7D2}\\SystemComponent => waarde is succesvol verwijderd.
    HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{6F77C156-7660-4CEC-8793-97D80D5BFEC0}\\SystemComponent => waarde is succesvol verwijderd.
    HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{7DB15F28-5E38-476A-A773-EA07EAEAB1B3}\\SystemComponent => waarde is succesvol verwijderd.
    EmptyTemp: => 1.3 GB tijdelijke gegevens verwijderd.




    Het systeem moest herstart worden.


    ==== Eind van Fixlog 22:51:24 ====

  17. #17

    Re: startpage changed, commercials on screen

    Scanresultaten van Farbar Recovery Scan Tool (FRST) (x64) Versie:05-12-2015
    Gestart door bryan77 (Beheerder) op BRYAN77-PC (05-12-2015 23:03:20)
    Gestart vanaf C:\Users\bryan77\Desktop
    Geladen Profielen: bryan77 (Beschikbare Profielen: bryan77 & Bryan & Barbara)
    Platform: Windows 7 Home Premium Service Pack 1 (X64) Taal: Nederlands (Nederland)
    Internet Explorer Versie 11 (Standaardbrowser: Chrome)
    Boot Modus: Normal
    Handleiding voor Farbar Recovery Scan Tool: FRST Tutorial - How to use Farbar Recovery Scan Tool - Malware Removal Guides and Tutorials


    ==================== Processen (gefilterd) =================


    (Als een item is opgenomen in de fixlist, het proces zal worden gesloten. Het bestand zal niet worden verplaatst.)


    (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgrsa.exe
    (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgcsrva.exe
    (Microsoft Corporation) C:\Windows\System32\wisptis.exe
    (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe
    (Microsoft Corporation) C:\Windows\System32\wlanext.exe
    (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
    (ASUS) C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnSrv.exe
    (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgidsagent.exe
    (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe
    (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgwdsvcx.exe
    (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
    () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
    (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
    (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
    (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
    (VIA Technologies, Inc.) C:\Windows\System32\ViakaraokeSrv.exe
    (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
    (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgnsa.exe
    (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgemca.exe
    (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
    (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
    (Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE
    (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Desktop.exe
    (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
    (ASUS) C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnWMI.exe
    (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ATKOSD.exe
    (Microsoft Corporation) C:\Windows\System32\wisptis.exe
    (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe
    (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\WDC.exe
    (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe
    (ASUS) C:\Program Files\ASUS\P4G\BatteryLife.exe
    (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\FaceLogon\sensorsrv.exe
    (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Virtual Touch\QuickGesture\x64\QuickGesture64.exe
    (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Virtual Touch\QuickGesture\x86\QuickGesture.exe
    (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe
    (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
    (Intel Corporation) C:\Windows\System32\igfxtray.exe
    (Intel Corporation) C:\Windows\System32\hkcmd.exe
    (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
    (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
    (Alcor Micro Corp.) C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe
    (ASUS) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
    (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
    (Nico Mak Computing) C:\Program Files\File Association Helper\FAHWindow.exe
    (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
    (VIA) C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe
    (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
    (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
    (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
    (CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
    (Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
    (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgui.exe
    (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
    (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Framework\Common\avguix.exe
    (Intel Corporation) C:\Windows\System32\igfxpers.exe
    (ASUSTeK) C:\Windows\SysWOW64\ACEngSvr.exe
    (Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
    (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_w32.exe
    (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_x64.exe
    (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
    (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDGesture.exe
    (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
    (Microsoft Corporation) C:\Windows\System32\dllhost.exe
    (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\ink\InputPersonalization.exe
    (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
    (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
    (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe




    ==================== Register (gefilterd) ===========================


    (Als een item is opgenomen in de fixlist, het registry item zal worden teruggezet naar de standaardwaarden of verwijderd. Het bestand zal niet worden verplaatst.)


    HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2661672 2012-05-14] (ELAN Microelectronics Corp.)
    HKLM\...\Run: [AmIcoSinglun64] => C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe [361984 2011-03-21] (Alcor Micro Corp.)
    HKLM\...\Run: [ACMON] => C:\Program Files (x86)\ASUS\Splendid\ACMON.exe [90792 2012-05-08] (ASUS)
    HKLM\...\Run: [FAHConsole] => C:\Program Files\File Association Helper\FAHConsole.exe [729272 2014-01-28] (Nico Mak Computing)
    HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291608 2012-02-07] (Intel Corporation)
    HKLM-x32\...\Run: [HDAudDeck] => C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [5142128 2012-04-19] (VIA)
    HKLM-x32\...\Run: [ATKOSD2] => C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [318080 2011-12-23] (ASUSTek Computer Inc.)
    HKLM-x32\...\Run: [ATKMEDIA] => C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [174720 2011-10-25] (ASUS)
    HKLM-x32\...\Run: [HControlUser] => C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [105016 2009-06-19] (ASUS)
    HKLM-x32\...\Run: [ASUSWebStorage] => C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.108.222\AsusWSPanel.exe [737104 2011-07-29] (ecareme)
    HKLM-x32\...\Run: [CLMLServer] => C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe [107816 2010-08-20] (CyberLink)
    HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-10-28] (Hewlett-Packard)
    HKLM-x32\...\Run: [AVG_UI] => C:\Program Files (x86)\AVG\Av\avgui.exe [3855272 2015-11-20] (AVG Technologies CZ, s.r.o.)
    HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [597040 2015-10-06] (Oracle Corporation)
    HKLM-x32\...\Run: [AvgUi] => C:\Program Files (x86)\AVG\Framework\Common\avguix.exe [1136552 2015-11-12] (AVG Technologies CZ, s.r.o.)
    Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
    ShellIconOverlayIdentifiers: [###MegaShellExtPending] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => C:\Users\Bryan\AppData\Local\MEGAsync\ShellExtX64.dll Geen bestand
    ShellIconOverlayIdentifiers: [###MegaShellExtSynced] -> {05B38830-F4E9-4329-978B-1DD28605D202} => C:\Users\Bryan\AppData\Local\MEGAsync\ShellExtX64.dll Geen bestand
    ShellIconOverlayIdentifiers: [###MegaShellExtSyncing] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => C:\Users\Bryan\AppData\Local\MEGAsync\ShellExtX64.dll Geen bestand
    ShellIconOverlayIdentifiers: [AsusWSShellExt_B] -> {6D4133E5-0742-4ADC-8A8C-9303440F7190} => C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.108.222\ASUSWSShellExt64.dll [2011-05-25] (eCareme Technologies, Inc.)
    ShellIconOverlayIdentifiers: [AsusWSShellExt_O] -> {64174815-8D98-4CE6-8646-4C039977D808} => C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.108.222\ASUSWSShellExt64.dll [2011-05-25] (eCareme Technologies, Inc.)
    ShellIconOverlayIdentifiers-x32: [###MegaShellExtPending] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => C:\Users\Bryan\AppData\Local\MEGAsync\ShellExtX32.dll Geen bestand
    ShellIconOverlayIdentifiers-x32: [###MegaShellExtSynced] -> {05B38830-F4E9-4329-978B-1DD28605D202} => C:\Users\Bryan\AppData\Local\MEGAsync\ShellExtX32.dll Geen bestand
    ShellIconOverlayIdentifiers-x32: [###MegaShellExtSyncing] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => C:\Users\Bryan\AppData\Local\MEGAsync\ShellExtX32.dll Geen bestand
    Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AsusVibeLauncher.lnk [2012-02-24]
    ShortcutTarget: AsusVibeLauncher.lnk -> C:\Program Files (x86)\ASUS\AsusVibe\AsusVibeLauncher.exe (ASUSTeK Computer Inc.)


    ==================== Internet (gefilterd) ====================


    (Als een item is opgenomen in de fixlist, als het een registry item is wordt verwijderd of hersteld naar de standaard.)


    Tcpip\Parameters: [DhcpNameServer] 195.130.131.4 195.130.130.132
    Tcpip\..\Interfaces\{954017FF-42DA-42FD-84E1-ECB55673A792}: [DhcpNameServer] 195.130.131.4 195.130.130.132
    Tcpip\..\Interfaces\{B7BD57C6-76C0-4AB4-AC64-4D8C834D3915}: [DhcpNameServer] 195.130.131.4 195.130.130.132


    Internet Explorer:
    ==================
    HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617912&ResetID=130892591560222338&GUID=D4782CC4-99AC-4097-BD5E-2E9FF6B401FD
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617912&ResetID=130892591560242339&GUID=D4782CC4-99AC-4097-BD5E-2E9FF6B401FD
    HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Google
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = Google
    HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = Google
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = Google
    HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Google
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = Google
    HKU\S-1-5-21-3732487481-855672253-929003311-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617912&ResetID=130892591573953123&GUID=D4782CC4-99AC-4097-BD5E-2E9FF6B401FD
    SearchScopes: HKLM -> DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSERBM&pc=MSERT1
    SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=ASUTDF&pc=NP06&src=IE-SearchBox
    SearchScopes: HKLM -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSERBM&pc=MSERT1
    SearchScopes: HKLM-x32 -> DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSERBM&pc=MSERT1
    SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=ASUTDF&pc=NP06&src=IE-SearchBox
    SearchScopes: HKLM-x32 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSERBM&pc=MSERT1
    SearchScopes: HKU\S-1-5-21-3732487481-855672253-929003311-1001 -> DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSERBM&pc=MSERT1
    SearchScopes: HKU\S-1-5-21-3732487481-855672253-929003311-1001 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSERBM&pc=MSERT1
    BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
    BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_65\bin\ssv.dll [2015-10-24] (Oracle Corporation)
    BHO-x32: Aanmeldhulp voor Microsoft-account -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
    BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_65\bin\jp2ssv.dll [2015-10-24] (Oracle Corporation)
    Toolbar: HKU\S-1-5-21-3732487481-855672253-929003311-1001 -> Geen Naam - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - Geen bestand
    DPF: HKLM-x32 {4B54A9DE-EF1C-4EBE-A328-7C28EA3B433A} hxxp://quickscan.bitdefender.com/qsax/qsax.cab
    DPF: HKLM-x32 {7530BFB8-7293-4D34-9923-61A11451AFC5} hxxp://download.eset.com/special/eos/OnlineScanner.cab
    StartMenuInternet: IEXPLORE.EXE - iexplore.exe


    FireFox:
    ========
    FF Plugin: @microsoft.com/GENUINE -> disabled [Geen bestand]
    FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
    FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-01-06] (Intel Corporation)
    FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-01-06] (Intel Corporation)
    FF Plugin-x32: @java.com/DTPlugin,version=11.65.2 -> C:\Program Files (x86)\Java\jre1.8.0_65\bin\dtplugin\npDeployJava1.dll [2015-10-24] (Oracle Corporation)
    FF Plugin-x32: @java.com/JavaPlugin,version=11.65.2 -> C:\Program Files (x86)\Java\jre1.8.0_65\bin\plugin2\npjp2.dll [2015-10-24] (Oracle Corporation)
    FF Plugin-x32: @microsoft.com/GENUINE -> disabled [Geen bestand]
    FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
    FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
    FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2013-02-05] (Microsoft Corporation)
    FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3508.0205 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2013-02-05] (Microsoft Corporation)
    FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-02] (Google Inc.)
    FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-02] (Google Inc.)
    FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-09-27] (Adobe Systems Inc.)


    Chrome:
    =======
    CHR Profile: C:\Users\bryan77\AppData\Local\Google\Chrome\User Data\Default
    CHR Extension: (Betalingen via Chrome Web Store) - C:\Users\bryan77\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-07-30]


    ==================== Services (gefilterd) ========================


    (Als een item is opgenomen in de fixlist, wordt uit het register verwijderd. Het bestand zal niet worden verplaatst tenzij apart vermeld.)


    R2 ASUS InstantOn; C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnSrv.exe [277120 2012-04-13] (ASUS)
    S3 AvgAMPS; C:\Program Files (x86)\AVG\Av\avgamps.exe [615584 2015-11-20] (AVG Technologies CZ, s.r.o.)
    R2 AVGIDSAgent; C:\Program Files (x86)\AVG\Av\avgidsagent.exe [3857272 2015-11-20] (AVG Technologies CZ, s.r.o.)
    R2 avgsvc; C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe [1046952 2015-11-12] (AVG Technologies CZ, s.r.o.)
    R2 avgwd; C:\Program Files (x86)\AVG\Av\avgwdsvcx.exe [579776 2015-11-20] (AVG Technologies CZ, s.r.o.)
    R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [128280 2012-02-21] ()
    R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [161560 2012-02-21] (Intel Corporation)
    S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1135416 2015-10-05] (Malwarebytes)
    R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [5702416 2015-09-11] (TeamViewer GmbH)
    R2 VIAKaraokeService; C:\Windows\system32\viakaraokesrv.exe [27760 2012-03-23] (VIA Technologies, Inc.)
    S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)


    ===================== Drivers (gefilterd) ==========================


    (Als een item is opgenomen in de fixlist, wordt uit het register verwijderd. Het bestand zal niet worden verplaatst tenzij apart vermeld.)


    R3 AsusVBus; C:\Windows\System32\DRIVERS\AsusVBus.sys [35968 2012-04-12] (Windows (R) Win 7 DDK provider)
    R3 AsusVTouch; C:\Windows\System32\DRIVERS\AsusVTouch.sys [16512 2012-04-12] (Windows (R) Win 7 DDK provider)
    R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [184240 2015-11-06] (AVG Technologies CZ, s.r.o.)
    R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [313776 2015-11-06] (AVG Technologies CZ, s.r.o.)
    R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [298416 2015-08-20] (AVG Technologies CZ, s.r.o.)
    R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [284080 2015-10-21] (AVG Technologies CZ, s.r.o.)
    R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [398256 2015-08-14] (AVG Technologies CZ, s.r.o.)
    R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [256432 2015-11-06] (AVG Technologies CZ, s.r.o.)
    R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [42416 2015-08-10] (AVG Technologies CZ, s.r.o.)
    R1 Avgtdia; C:\Windows\System32\DRIVERS\avgtdia.sys [302000 2015-10-08] (AVG Technologies CZ, s.r.o.)
    S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
    R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [15416 2009-07-20] ( )
    R3 L1C; C:\Windows\System32\DRIVERS\L1C62x64.sys [104560 2012-04-25] (Qualcomm Atheros Co., Ltd.)
    R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-10-05] (Malwarebytes)
    S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-10-05] (Malwarebytes Corporation)


    ==================== NetSvcs (gefilterd) ===================


    (Als een item is opgenomen in de fixlist, wordt uit het register verwijderd. Het bestand zal niet worden verplaatst tenzij apart vermeld.)




    ==================== Een Maand Aangemaakt bestanden en mappen ========


    (Als een item is opgenomen in de fixlist, het bestand/map wordt verplaatst.)


    2015-12-05 22:50 - 2015-12-05 22:50 - 00000000 ____D C:\Users\bryan77\Desktop\FRST-OlderVersion
    2015-12-05 08:53 - 2015-12-05 08:53 - 00000000 ___HD C:\Windows\AxInstSV
    2015-12-04 20:25 - 2015-12-04 20:25 - 00000000 ____D C:\Users\Bryan\AppData\Roaming\AVG
    2015-12-04 14:05 - 2015-12-04 15:23 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
    2015-12-04 14:04 - 2015-12-04 14:04 - 00001104 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
    2015-12-04 14:04 - 2015-12-04 14:04 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
    2015-12-04 14:04 - 2015-12-04 14:04 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
    2015-12-04 14:04 - 2015-10-05 09:50 - 00109272 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamchameleon.sys
    2015-12-04 14:04 - 2015-10-05 09:50 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
    2015-12-04 14:04 - 2015-10-05 09:50 - 00025816 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
    2015-12-04 14:02 - 2015-12-05 23:03 - 00000380 _____ C:\Users\bryan77\AppData\Roaming\sp_data.sys
    2015-12-03 12:30 - 2015-12-03 12:30 - 00000000 ____D C:\Users\Barbara.bryan77-PC\AppData\Roaming\AVG
    2015-12-02 15:36 - 2015-12-02 15:36 - 00001325 _____ C:\Users\bryan77\Desktop\JRT.txt
    2015-12-02 15:30 - 2015-12-02 15:30 - 01599336 _____ (Malwarebytes) C:\Users\bryan77\Desktop\JRT.exe
    2015-12-02 14:44 - 2015-12-02 14:44 - 01736704 _____ C:\Users\bryan77\Downloads\adwcleaner_5.023 (1).exe
    2015-12-02 14:44 - 2015-12-02 14:44 - 01736704 _____ C:\Users\bryan77\Desktop\adwcleaner_5.023.exe
    2015-12-02 14:26 - 2015-12-02 14:26 - 00000000 ____D C:\Users\bryan77\AppData\Roaming\AVG
    2015-12-02 14:21 - 2015-12-02 14:21 - 00000936 _____ C:\Users\Public\Desktop\AVG.lnk
    2015-12-02 14:21 - 2015-12-02 14:21 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG Zen
    2015-12-02 14:20 - 2015-12-02 14:24 - 00000000 ____D C:\ProgramData\Avg
    2015-12-02 14:19 - 2015-12-02 14:19 - 02970984 _____ (AVG Technologies CZ, s.r.o.) C:\Users\bryan77\Desktop\AVG_Protection_Free_698.exe
    2015-12-02 13:41 - 2015-12-02 14:21 - 00000000 ____D C:\Users\bryan77\AppData\Local\AvgSetupLog
    2015-12-02 13:39 - 2015-12-05 22:51 - 00003289 _____ C:\Users\bryan77\Desktop\Fixlog.txt
    2015-12-02 13:36 - 2015-10-24 10:20 - 00097888 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
    2015-12-01 21:48 - 2015-12-01 21:49 - 00035072 _____ C:\Users\bryan77\Desktop\Addition.txt
    2015-12-01 21:48 - 2015-12-01 21:48 - 00852771 _____ C:\Users\bryan77\Desktop\SecurityCheck.exe
    2015-12-01 21:47 - 2015-12-05 23:05 - 00019628 _____ C:\Users\bryan77\Desktop\FRST.txt
    2015-12-01 21:46 - 2015-12-05 23:03 - 00000000 ____D C:\FRST
    2015-12-01 21:45 - 2015-12-05 22:50 - 02369024 _____ (Farbar) C:\Users\bryan77\Desktop\FRST64.exe
    2015-12-01 21:45 - 2015-12-05 11:22 - 00000000 ____D C:\Users\bryan77\Desktop\uitgevoerde stappen
    2015-12-01 21:44 - 2015-12-01 21:44 - 02350080 _____ (Farbar) C:\Users\bryan77\Downloads\FRST64.exe
    2015-11-22 14:44 - 2015-11-22 14:44 - 00000000 ____D C:\Users\Bryan\AppData\Roaming\Sun
    2015-11-22 14:29 - 2015-11-22 14:29 - 00000000 ____D C:\Users\Barbara.bryan77-PC\AppData\Local\AvgSetupLog
    2015-11-21 16:10 - 2015-11-21 16:10 - 00679936 _____ C:\Users\Bryan\Downloads\Detection (10).msi
    2015-11-15 20:44 - 2015-11-15 11:44 - 00159444 ____N C:\Users\Barbara.bryan77-PC\Desktop\Kasverkoop nr 128 - 06-11-2015- Barbara Verbist.pdf
    2015-11-15 20:36 - 2015-11-15 20:36 - 00001376 _____ C:\Users\bryan77\Desktop\Photo Gallery.lnk
    2015-11-15 20:34 - 2015-11-15 20:34 - 00001116 _____ C:\Users\bryan77\Desktop\Afbeeldingen - Snelkoppeling.lnk
    2015-11-15 19:43 - 2015-11-15 19:43 - 00000000 ____D C:\Users\bryan77\Desktop\AdminPc
    2015-11-15 19:36 - 2015-11-03 18:55 - 03211264 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
    2015-11-15 19:35 - 2015-10-20 19:42 - 03168768 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
    2015-11-15 19:35 - 2015-10-20 19:42 - 02608128 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
    2015-11-15 19:35 - 2015-10-20 19:42 - 00696320 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
    2015-11-15 19:35 - 2015-10-20 19:42 - 00192512 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
    2015-11-15 19:35 - 2015-10-20 19:42 - 00098816 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
    2015-11-15 19:35 - 2015-10-20 19:42 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
    2015-11-15 19:35 - 2015-10-20 19:42 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
    2015-11-15 19:35 - 2015-10-20 19:41 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
    2015-11-15 19:35 - 2015-10-20 19:41 - 00091136 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
    2015-11-15 19:35 - 2015-10-20 19:41 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
    2015-11-15 19:35 - 2015-10-20 19:41 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll
    2015-11-15 19:35 - 2015-10-20 18:46 - 00566784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
    2015-11-15 19:35 - 2015-10-20 18:46 - 00174080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
    2015-11-15 19:35 - 2015-10-20 18:46 - 00093696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
    2015-11-15 19:35 - 2015-10-20 18:46 - 00030208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
    2015-11-15 19:35 - 2015-10-20 18:45 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
    2015-11-15 19:34 - 2015-11-03 23:10 - 00390344 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
    2015-11-15 19:34 - 2015-11-03 22:51 - 00342728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
    2015-11-15 19:34 - 2015-10-31 00:46 - 25818624 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
    2015-11-15 19:34 - 2015-10-31 00:40 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
    2015-11-15 19:34 - 2015-10-31 00:40 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
    2015-11-15 19:34 - 2015-10-31 00:25 - 02886656 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
    2015-11-15 19:34 - 2015-10-31 00:25 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
    2015-11-15 19:34 - 2015-10-31 00:25 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
    2015-11-15 19:34 - 2015-10-31 00:25 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
    2015-11-15 19:34 - 2015-10-31 00:24 - 00585728 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
    2015-11-15 19:34 - 2015-10-31 00:24 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
    2015-11-15 19:34 - 2015-10-31 00:17 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
    2015-11-15 19:34 - 2015-10-31 00:16 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
    2015-11-15 19:34 - 2015-10-31 00:13 - 00616960 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
    2015-11-15 19:34 - 2015-10-31 00:12 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
    2015-11-15 19:34 - 2015-10-31 00:12 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
    2015-11-15 19:34 - 2015-10-31 00:11 - 05990912 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
    2015-11-15 19:34 - 2015-10-31 00:11 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
    2015-11-15 19:34 - 2015-10-31 00:11 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
    2015-11-15 19:34 - 2015-10-31 00:04 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
    2015-11-15 19:34 - 2015-10-31 00:01 - 00489984 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
    2015-11-15 19:34 - 2015-10-30 23:58 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
    2015-11-15 19:34 - 2015-10-30 23:53 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
    2015-11-15 19:34 - 2015-10-30 23:52 - 20331520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
    2015-11-15 19:34 - 2015-10-30 23:49 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
    2015-11-15 19:34 - 2015-10-30 23:49 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
    2015-11-15 19:34 - 2015-10-30 23:47 - 00504832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
    2015-11-15 19:34 - 2015-10-30 23:46 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
    2015-11-15 19:34 - 2015-10-30 23:46 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
    2015-11-15 19:34 - 2015-10-30 23:45 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
    2015-11-15 19:34 - 2015-10-30 23:45 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
    2015-11-15 19:34 - 2015-10-30 23:44 - 00152064 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
    2015-11-15 19:34 - 2015-10-30 23:44 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
    2015-11-15 19:34 - 2015-10-30 23:42 - 02279936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
    2015-11-15 19:34 - 2015-10-30 23:39 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
    2015-11-15 19:34 - 2015-10-30 23:39 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
    2015-11-15 19:34 - 2015-10-30 23:37 - 00480256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
    2015-11-15 19:34 - 2015-10-30 23:36 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
    2015-11-15 19:34 - 2015-10-30 23:36 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
    2015-11-15 19:34 - 2015-10-30 23:36 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
    2015-11-15 19:34 - 2015-10-30 23:34 - 00262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
    2015-11-15 19:34 - 2015-10-30 23:32 - 00720896 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
    2015-11-15 19:34 - 2015-10-30 23:31 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
    2015-11-15 19:34 - 2015-10-30 23:29 - 02126336 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
    2015-11-15 19:34 - 2015-10-30 23:29 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
    2015-11-15 19:34 - 2015-10-30 23:28 - 00416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
    2015-11-15 19:34 - 2015-10-30 23:23 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
    2015-11-15 19:34 - 2015-10-30 23:22 - 14457856 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
    2015-11-15 19:34 - 2015-10-30 23:21 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
    2015-11-15 19:34 - 2015-10-30 23:19 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
    2015-11-15 19:34 - 2015-10-30 23:18 - 00279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
    2015-11-15 19:34 - 2015-10-30 23:17 - 02487808 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
    2015-11-15 19:34 - 2015-10-30 23:17 - 00130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
    2015-11-15 19:34 - 2015-10-30 23:16 - 04527616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
    2015-11-15 19:34 - 2015-10-30 23:11 - 00230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
    2015-11-15 19:34 - 2015-10-30 23:10 - 00689152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
    2015-11-15 19:34 - 2015-10-30 23:09 - 12854272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
    2015-11-15 19:34 - 2015-10-30 23:09 - 02052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
    2015-11-15 19:34 - 2015-10-30 23:09 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
    2015-11-15 19:34 - 2015-10-30 23:04 - 01547264 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
    2015-11-15 19:34 - 2015-10-30 22:53 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
    2015-11-15 19:34 - 2015-10-30 22:51 - 02011136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
    2015-11-15 19:34 - 2015-10-30 22:48 - 01311744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
    2015-11-15 19:34 - 2015-10-30 22:46 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
    2015-11-15 19:33 - 2015-10-29 18:50 - 00342016 _____ (Microsoft Corporation) C:\Windows\system32\apphelp.dll
    2015-11-15 19:33 - 2015-10-29 18:50 - 00072192 _____ (Microsoft Corporation) C:\Windows\system32\aelupsvc.dll
    2015-11-15 19:33 - 2015-10-29 18:50 - 00023552 _____ (Microsoft Corporation) C:\Windows\system32\sdbinst.exe
    2015-11-15 19:33 - 2015-10-29 18:50 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\shimeng.dll
    2015-11-15 19:33 - 2015-10-29 18:50 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shimeng.dll
    2015-11-15 19:33 - 2015-10-29 18:49 - 00295936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apphelp.dll
    2015-11-15 19:33 - 2015-10-29 18:49 - 00020992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sdbinst.exe
    2015-11-15 19:33 - 2015-10-20 02:12 - 05570496 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
    2015-11-15 19:33 - 2015-10-20 02:12 - 00154560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
    2015-11-15 19:33 - 2015-10-20 02:12 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
    2015-11-15 19:33 - 2015-10-20 02:09 - 01730496 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
    2015-11-15 19:33 - 2015-10-20 02:06 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
    2015-11-15 19:33 - 2015-10-20 02:06 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
    2015-11-15 19:33 - 2015-10-20 02:06 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
    2015-11-15 19:33 - 2015-10-20 02:06 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
    2015-11-15 19:33 - 2015-10-20 02:05 - 01461760 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
    2015-11-15 19:33 - 2015-10-20 02:05 - 01216512 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
    2015-11-15 19:33 - 2015-10-20 02:05 - 01164800 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
    2015-11-15 19:33 - 2015-10-20 02:05 - 00729600 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
    2015-11-15 19:33 - 2015-10-20 02:05 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
    2015-11-15 19:33 - 2015-10-20 02:05 - 00424960 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
    2015-11-15 19:33 - 2015-10-20 02:05 - 00344064 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
    2015-11-15 19:33 - 2015-10-20 02:05 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
    2015-11-15 19:33 - 2015-10-20 02:05 - 00312320 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
    2015-11-15 19:33 - 2015-10-20 02:05 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
    2015-11-15 19:33 - 2015-10-20 02:05 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
    2015-11-15 19:33 - 2015-10-20 02:05 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
    2015-11-15 19:33 - 2015-10-20 02:05 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
    2015-11-15 19:33 - 2015-10-20 02:05 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
    2015-11-15 19:33 - 2015-10-20 02:05 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
    2015-11-15 19:33 - 2015-10-20 02:05 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
    2015-11-15 19:33 - 2015-10-20 02:05 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
    2015-11-15 19:33 - 2015-10-20 02:05 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
    2015-11-15 19:33 - 2015-10-20 02:05 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
    2015-11-15 19:33 - 2015-10-20 02:05 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
    2015-11-15 19:33 - 2015-10-20 02:05 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
    2015-11-15 19:33 - 2015-10-20 02:04 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
    2015-11-15 19:33 - 2015-10-20 02:04 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
    2015-11-15 19:33 - 2015-10-20 02:04 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
    2015-11-15 19:33 - 2015-10-20 02:00 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
    2015-11-15 19:33 - 2015-10-20 01:59 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
    2015-11-15 19:33 - 2015-10-20 01:53 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
    2015-11-15 19:33 - 2015-10-20 01:53 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
    2015-11-15 19:33 - 2015-10-20 01:53 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:53 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:53 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:53 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:53 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:53 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:53 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:53 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:53 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:53 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:53 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:53 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:53 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:53 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:53 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:52 - 03991488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
    2015-11-15 19:33 - 2015-10-20 01:52 - 03935680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
    2015-11-15 19:33 - 2015-10-20 01:48 - 01311768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
    2015-11-15 19:33 - 2015-10-20 01:45 - 00552960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
    2015-11-15 19:33 - 2015-10-20 01:45 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
    2015-11-15 19:33 - 2015-10-20 01:45 - 00251392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
    2015-11-15 19:33 - 2015-10-20 01:45 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
    2015-11-15 19:33 - 2015-10-20 01:45 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
    2015-11-15 19:33 - 2015-10-20 01:45 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
    2015-11-15 19:33 - 2015-10-20 01:45 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
    2015-11-15 19:33 - 2015-10-20 01:45 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll
    2015-11-15 19:33 - 2015-10-20 01:45 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
    2015-11-15 19:33 - 2015-10-20 01:45 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
    2015-11-15 19:33 - 2015-10-20 01:45 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
    2015-11-15 19:33 - 2015-10-20 01:45 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
    2015-11-15 19:33 - 2015-10-20 01:44 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
    2015-11-15 19:33 - 2015-10-20 01:44 - 00665088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
    2015-11-15 19:33 - 2015-10-20 01:44 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
    2015-11-15 19:33 - 2015-10-20 01:44 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
    2015-11-15 19:33 - 2015-10-20 01:44 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
    2015-11-15 19:33 - 2015-10-20 01:44 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
    2015-11-15 19:33 - 2015-10-20 01:39 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
    2015-11-15 19:33 - 2015-10-20 01:39 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
    2015-11-15 19:33 - 2015-10-20 01:35 - 00686080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
    2015-11-15 19:33 - 2015-10-20 01:35 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
    2015-11-15 19:33 - 2015-10-20 01:35 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:35 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:35 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:35 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:35 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:35 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:35 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:35 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:35 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:35 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:35 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:35 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:35 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 00:41 - 00159232 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
    2015-11-15 19:33 - 2015-10-20 00:40 - 00290816 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
    2015-11-15 19:33 - 2015-10-20 00:40 - 00129024 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
    2015-11-15 19:33 - 2015-10-20 00:29 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
    2015-11-15 19:33 - 2015-10-20 00:29 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
    2015-11-15 19:33 - 2015-10-20 00:27 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 00:27 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 00:27 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 00:27 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-13 17:41 - 00497664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
    2015-11-15 19:33 - 2015-10-13 17:40 - 00118272 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdx.sys
    2015-11-15 19:33 - 2015-09-23 14:15 - 00460776 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
    2015-11-15 19:33 - 2015-09-23 14:15 - 00299632 _____ (Microsoft Corporation) C:\Windows\system32\bcryptprimitives.dll
    2015-11-15 19:33 - 2015-09-23 14:09 - 00251000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcryptprimitives.dll
    2015-11-15 19:27 - 2015-11-15 19:27 - 00000000 ____D C:\Users\bryan77\AppData\Local\Mega Limited
    2015-11-15 19:24 - 2015-10-13 05:57 - 00950720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys
    2015-11-15 19:24 - 2015-10-01 19:00 - 00275456 _____ (Microsoft Corporation) C:\Windows\system32\InkEd.dll
    2015-11-15 19:24 - 2015-10-01 19:00 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\jnwmon.dll
    2015-11-15 19:24 - 2015-10-01 18:50 - 00216064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InkEd.dll
    2015-11-09 08:55 - 2015-11-09 08:55 - 00120507 _____ C:\Users\Barbara.bryan77-PC\Downloads\105521 (1).pdf
    2015-11-09 08:51 - 2015-11-09 08:51 - 00120507 _____ C:\Users\Barbara.bryan77-PC\Downloads\105521.pdf
    2015-11-06 15:50 - 2015-11-06 15:50 - 00184240 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgdiska.sys
    2015-11-06 15:49 - 2015-11-06 15:49 - 00313776 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgidsdrivera.sys
    2015-11-06 15:49 - 2015-11-06 15:49 - 00256432 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgmfx64.sys


    ==================== Een Maand Gewijzigd bestanden en mappen ========


    (Als een item is opgenomen in de fixlist, het bestand/map wordt verplaatst.)


    2015-12-05 23:04 - 2012-02-24 03:29 - 00001056 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
    2015-12-05 22:57 - 2013-12-01 22:44 - 00000828 _____ C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job
    2015-12-05 22:57 - 2012-02-24 03:29 - 00001052 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
    2015-12-05 22:55 - 2013-12-01 20:07 - 00000000 ____D C:\ProgramData\MFAData
    2015-12-05 22:55 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
    2015-12-05 22:46 - 2009-07-14 05:45 - 00009920 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
    2015-12-05 22:46 - 2009-07-14 05:45 - 00009920 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
    2015-12-05 22:44 - 2013-12-08 21:48 - 00000940 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
    2015-12-05 22:22 - 2014-09-15 18:06 - 00000000 ____D C:\Users\Bryan\AppData\Roaming\Software Informer
    2015-12-05 20:29 - 2015-06-03 11:41 - 00000000 ____D C:\Users\Bryan\AppData\Local\Spotify
    2015-12-05 20:29 - 2015-06-03 11:40 - 00000000 ____D C:\Users\Bryan\AppData\Roaming\Spotify
    2015-12-05 20:29 - 2013-12-01 21:06 - 00000380 _____ C:\Users\Bryan\AppData\Roaming\sp_data.sys
    2015-12-05 12:12 - 2013-12-01 22:44 - 00000830 _____ C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job
    2015-12-05 11:43 - 2013-12-01 20:24 - 00000380 _____ C:\Users\Barbara.bryan77-PC\AppData\Roaming\sp_data.sys
    2015-12-05 08:53 - 2009-07-14 06:32 - 00000000 ____D C:\Windows\Downloaded Program Files
    2015-12-05 08:53 - 2009-07-14 04:20 - 00000000 ____D C:\Windows
    2015-12-05 08:52 - 2015-05-21 19:40 - 00000000 __SHD C:\Users\bryan77\AppData\Local\EmieUserList
    2015-12-05 08:52 - 2015-05-21 19:40 - 00000000 __SHD C:\Users\bryan77\AppData\Local\EmieSiteList
    2015-12-05 08:52 - 2015-05-21 19:40 - 00000000 __SHD C:\Users\bryan77\AppData\Local\EmieBrowserModeList
    2015-12-04 20:25 - 2014-11-26 08:12 - 00000000 ____D C:\Users\Bryan\AppData\Local\Avg
    2015-12-04 15:02 - 2009-07-14 06:32 - 00000000 ____D C:\Windows\Performance
    2015-12-04 14:02 - 2014-11-06 21:55 - 00000000 ____D C:\Program Files (x86)\TeamViewer
    2015-12-02 17:59 - 2012-02-24 03:29 - 00004052 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
    2015-12-02 17:59 - 2012-02-24 03:29 - 00003800 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
    2015-12-02 15:34 - 2011-02-19 05:40 - 00746450 _____ C:\Windows\system32\perfh013.dat
    2015-12-02 15:34 - 2011-02-19 05:40 - 00154112 _____ C:\Windows\system32\perfc013.dat
    2015-12-02 15:34 - 2009-07-14 06:13 - 01672504 _____ C:\Windows\system32\PerfStringBackup.INI
    2015-12-02 15:34 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\inf
    2015-12-02 15:25 - 2014-11-27 23:08 - 00000000 ____D C:\AdwCleaner
    2015-12-02 14:34 - 2013-12-01 20:15 - 00000000 ____D C:\ProgramData\AVG2014
    2015-12-02 14:26 - 2014-11-26 08:12 - 00000000 ____D C:\Users\bryan77\AppData\Local\Avg
    2015-12-02 14:26 - 2014-08-28 07:09 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
    2015-12-02 14:26 - 2013-12-01 20:15 - 00000000 ___HD C:\$AVG
    2015-12-02 14:26 - 2013-12-01 20:13 - 00000000 ____D C:\Program Files (x86)\AVG
    2015-12-02 14:25 - 2015-06-26 08:09 - 00000000 ____D C:\Program Files\Common Files\AV
    2015-12-02 13:39 - 2013-12-01 17:57 - 00001144 _____ C:\Users\bryan77\Desktop\Internet Explorer.lnk
    2015-12-02 13:39 - 2013-12-01 14:19 - 00001144 _____ C:\Users\bryan77\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
    2015-12-02 13:36 - 2014-12-02 23:36 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
    2015-12-01 21:40 - 2009-07-14 06:09 - 00000000 ____D C:\Windows\System32\Tasks\WPD
    2015-11-22 14:44 - 2015-10-27 19:41 - 00000000 ____D C:\Users\Bryan\.oracle_jre_usage
    2015-11-22 14:29 - 2014-11-26 08:12 - 00000000 ____D C:\Users\Barbara.bryan77-PC\AppData\Local\Avg
    2015-11-16 04:06 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache
    2015-11-16 03:29 - 2009-07-14 05:45 - 00270888 _____ C:\Windows\system32\FNTCACHE.DAT
    2015-11-16 03:24 - 2015-06-03 21:56 - 00000000 ____D C:\Windows\system32\MRT
    2015-11-16 03:11 - 2015-06-03 21:55 - 145617392 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
    2015-11-16 03:03 - 2012-02-24 03:28 - 01647172 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
    2015-11-16 03:02 - 2009-07-14 08:45 - 00000000 ____D C:\Program Files\Windows Journal
    2015-11-15 20:36 - 2013-12-01 19:25 - 00000000 ____D C:\Users\bryan77\AppData\Local\Windows Live
    2015-11-15 19:44 - 2013-12-08 21:48 - 00780488 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
    2015-11-15 19:44 - 2013-12-08 21:48 - 00142536 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
    2015-11-15 19:44 - 2013-12-08 21:48 - 00003878 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
    2015-11-15 19:43 - 2014-11-21 21:01 - 00000000 ____D C:\Users\AdminPc
    2015-11-15 19:32 - 2009-07-14 04:20 - 00000000 __RHD C:\Users\Public\Libraries
    2015-11-15 19:27 - 2014-10-01 09:20 - 00000000 ____D C:\Users\Bryan\AppData\Local\MEGAsync
    2015-11-15 19:15 - 2014-07-29 10:51 - 00000000 ____D C:\Users\bryan77\AppData\Roaming\.minecraft
    2015-11-15 19:02 - 2013-12-01 21:05 - 00000000 ____D C:\Users\Bryan
    2015-11-15 19:02 - 2013-12-01 14:18 - 00000000 ____D C:\Users\bryan77
    2015-11-13 00:29 - 2015-04-05 02:00 - 00000000 ___SD C:\Windows\system32\GWX
    2015-11-13 00:29 - 2013-12-08 21:48 - 00000000 ____D C:\Windows\system32\Macromed
    2015-11-13 00:29 - 2013-12-01 20:24 - 00000000 ____D C:\Users\Barbara.bryan77-PC
    2015-11-13 00:29 - 2012-02-24 03:29 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
    2015-11-13 00:29 - 2009-07-14 08:44 - 00000000 ___RD C:\Users\Public\Recorded TV
    2015-11-13 00:29 - 2009-07-14 04:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared
    2015-11-13 00:28 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\registration
    2015-11-07 11:11 - 2014-08-11 12:27 - 00000184 _____ C:\Users\Bryan\Downloads\eula.txt


    ==================== Bestanden in de root van sommige mappen =======


    2015-12-04 14:02 - 2015-12-05 23:03 - 0000380 _____ () C:\Users\bryan77\AppData\Roaming\sp_data.sys
    2014-04-16 18:15 - 2014-04-16 18:15 - 0000057 _____ () C:\ProgramData\Ament.ini
    2012-02-24 03:42 - 2010-10-06 18:45 - 0131984 _____ () C:\ProgramData\FullRemove.exe
    2013-12-01 14:06 - 2013-12-01 14:06 - 0000109 _____ () C:\ProgramData\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}.log
    2013-12-01 14:05 - 2013-12-01 14:06 - 0000105 _____ () C:\ProgramData\{40BF1E83-20EB-11D8-97C5-0009C5020658}.log
    2013-12-01 14:04 - 2013-12-01 14:05 - 0000107 _____ () C:\ProgramData\{C59C179C-668D-49A9-B6EA-0121CCFC1243}.log


    ==================== Bamital & volsnap =================


    (Er is geen automatische fix voor bestanden die de verificatie niet doorkomen.)


    C:\Windows\system32\winlogon.exe => Bestand is getekend
    C:\Windows\system32\wininit.exe => Bestand is getekend
    C:\Windows\SysWOW64\wininit.exe => Bestand is getekend
    C:\Windows\explorer.exe => Bestand is getekend
    C:\Windows\SysWOW64\explorer.exe => Bestand is getekend
    C:\Windows\system32\svchost.exe => Bestand is getekend
    C:\Windows\SysWOW64\svchost.exe => Bestand is getekend
    C:\Windows\system32\services.exe => Bestand is getekend
    C:\Windows\system32\User32.dll => Bestand is getekend
    C:\Windows\SysWOW64\User32.dll => Bestand is getekend
    C:\Windows\system32\userinit.exe => Bestand is getekend
    C:\Windows\SysWOW64\userinit.exe => Bestand is getekend
    C:\Windows\system32\rpcss.dll => Bestand is getekend
    C:\Windows\system32\dnsapi.dll => Bestand is getekend
    C:\Windows\SysWOW64\dnsapi.dll => Bestand is getekend
    C:\Windows\system32\Drivers\volsnap.sys => Bestand is getekend




    LastRegBack: 2015-11-30 00:25


    ==================== Eind van FRST.txt ============================


    Extra scanresultaten van Farbar Recovery Scan Tool (x64) Versie:05-12-2015
    Gestart door bryan77 (2015-12-05 23:06:18)
    Gestart vanaf C:\Users\bryan77\Desktop
    Windows 7 Home Premium Service Pack 1 (X64) (2013-12-01 13:17:59)
    Boot Modus: Normal
    ==========================================================




    ==================== Accounts: =============================


    Administrator (S-1-5-21-3732487481-855672253-929003311-500 - Administrator - Disabled)
    Barbara (S-1-5-21-3732487481-855672253-929003311-1006 - Limited - Enabled) => C:\Users\Barbara.bryan77-PC
    Bryan (S-1-5-21-3732487481-855672253-929003311-1005 - Limited - Enabled) => C:\Users\Bryan
    bryan77 (S-1-5-21-3732487481-855672253-929003311-1001 - Administrator - Enabled) => C:\Users\bryan77
    Gast (S-1-5-21-3732487481-855672253-929003311-501 - Limited - Disabled)
    HomeGroupUser$ (S-1-5-21-3732487481-855672253-929003311-1002 - Limited - Enabled)


    ==================== Security Center ========================


    (Als een item is opgenomen in de fixlist, zal het worden verwijderd.)


    AV: AVG AntiVirus Free Edition (Enabled - Up to date) {4D41356F-32AD-7C42-C820-63775EE4F413}
    AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    AS: AVG AntiVirus Free Edition (Enabled - Up to date) {F620D48B-1497-73CC-F290-58052563BEAE}


    ==================== GeÔnstalleerde programma's ======================


    (Alleen de adware-programma's met 'verborgen' vlag zou kunnen worden toegevoegd aan de fixlist om ze zichtbaar te maken. De adware-programma's moeten handmatig gedeinstallerd worden.)


    Adobe Flash Player 10 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 10.0.32.18 - Adobe Systems Incorporated)
    Adobe Flash Player 19 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 19.0.0.245 - Adobe Systems Incorporated)
    Adobe Reader XI (11.0.13) - Nederlands (HKLM-x32\...\{AC76BA86-7AD7-1043-7B44-AB0000000001}) (Version: 11.0.13 - Adobe Systems Incorporated)
    Alcor Micro USB Card Reader (HKLM-x32\...\AmUStor) (Version: 1.2.0117.08443 - Alcor Micro Corp.)
    Alcor Micro USB Card Reader (x32 Version: 1.2.0117.08443 - Alcor Micro Corp.) Hidden
    ASUS AI Recovery (HKLM-x32\...\{D39F0676-163E-4595-A917-E28F99BBD4D2}) (Version: 1.0.24 - ASUS)
    ASUS FaceLogon (HKLM-x32\...\{64452561-169F-4A36-A2FF-B5E118EC65F5}) (Version: 1.0.0014 - ASUS)
    ASUS Instant Connect (HKLM-x32\...\{89ECB85A-D933-4CEA-9116-5CBC9C2ED95B}) (Version: 1.2.2 - ASUS)
    ASUS LifeFrame3 (HKLM-x32\...\{1DBD1F12-ED93-49C0-A7CC-56CBDE488158}) (Version: 3.1.1 - ASUS)
    ASUS Live Update (HKLM-x32\...\{FA540E67-095C-4A1B-97BA-4D547DEC9AF4}) (Version: 3.1.5 - ASUS)
    ASUS Power4Gear Hybrid (HKLM\...\{9B6239BF-4E85-4590-8D72-51E30DB1A9AA}) (Version: 1.2.1 - ASUS)
    ASUS Splendid Video Enhancement Technology (HKLM-x32\...\{0969AF05-4FF6-4C00-9406-43599238DE0D}) (Version: 1.03.0001 - ASUS)
    ASUS USB Charger Plus (HKLM-x32\...\{A859E3E5-C62F-4BFA-AF1D-2B95E03166AF}) (Version: 2.1.1 - ASUS)
    ASUS Virtual Camera (HKLM-x32\...\{EC8BD21F-0CA0-4BBF-97D9-4A52B30041A1}) (Version: 1.0.25 - ASUS)
    ASUS Virtual Touch (HKLM-x32\...\{938CFBD4-0652-49E5-BB8B-153948865941}) (Version: 1.0.11 - ASUS)
    ASUS WebStorage (HKLM-x32\...\ASUS WebStorage) (Version: 3.0.108.222 - eCareme Technologies, Inc.)
    AsusVibe2.0 (HKLM-x32\...\Asus Vibe2.0) (Version: 2.0.9.157 - ASUSTEK)
    Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver (HKLM-x32\...\{3108C217-BE83-42E4-AE9E-A56A2A92E549}) (Version: 2.0.15.16 - Atheros Communications Inc.)
    ATK Package (HKLM-x32\...\{AB5C933E-5C7D-4D30-B314-9C83A49B94BE}) (Version: 1.0.0015 - ASUS)
    AVG (HKLM\...\AvgZen) (Version: 1.22.1.40089 - AVG Technologies)
    AVG (Version: 16.12.7294 - AVG Technologies) Hidden
    AVG 2016 (Version: 16.0.4483 - AVG Technologies) Hidden
    AVG Protection (HKLM\...\AVG) (Version: 2016.12.7294 - AVG Technologies)
    AVG Zen (Version: 1.22.1 - AVG Technologies) Hidden
    Bubbletown (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-115065740}) (Version: - Oberon Media)
    Contenta Converter PREMIUM (HKLM-x32\...\ContentaConverter-PREMIUM) (Version: - Contenta Software)
    CyberLink LabelPrint (HKLM-x32\...\InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}) (Version: 2.5.3624 - CyberLink Corp.)
    CyberLink Media Suite (HKLM-x32\...\InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}) (Version: 8.0.2926 - CyberLink Corp.)
    CyberLink Power2Go (HKLM-x32\...\InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 7.0.0.1126 - CyberLink Corp.)
    D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
    Deadtime Stories (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-118716773}) (Version: - Oberon Media)
    Dream Day First Home (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-113832110}) (Version: - Oberon Media)
    Dream Vacation Solitaire (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111249233}) (Version: - Oberon Media)
    ESET Online Scanner v3 (HKLM-x32\...\ESET Online Scanner) (Version: - )
    ETDWare PS/2-X64 10.5.10.0 (HKLM\...\Elantech) (Version: 10.5.10.0 - ELAN Microelectronic Corp.)
    Farm Frenzy 3 - Madagascar (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-119205603}) (Version: - Oberon Media)
    FMW 1 (Version: 1.32.2 - AVG Technologies) Hidden
    Fotogalerie (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
    Galapago (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111307457}) (Version: - Oberon Media)
    Galeria de Fotografias (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
    GalerŪa de fotos (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
    Galerie de photos (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
    Game Park Console (HKLM-x32\...\Game Park Console) (Version: 1.2.4.431 - Oberon Media Inc.)
    Go Go Gourmet Chef of the Year (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-115290153}) (Version: - Oberon Media)
    Google Chrome (HKLM-x32\...\Google Chrome) (Version: 47.0.2526.73 - Google Inc.)
    Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
    Google Update Helper (x32 Version: 1.3.29.1 - Google Inc.) Hidden
    HP Deskjet 1050 J410 series Basissoftware van het apparaat (HKLM\...\{FA37D2E8-0A8B-46D2-A74A-310F935DE920}) (Version: 28.0.1313.0 - Hewlett-Packard Co.)
    HP Deskjet 1050 J410 series Haelp (HKLM-x32\...\{5C90D8CF-F12A-41C6-9007-3B651A1F0D78}) (Version: 140.0.66.66 - Hewlett Packard)
    HP Deskjet 1050 J410 series Productverbeteringsonderzoek (HKLM\...\{44C6BB22-7E25-4A6D-8851-6FB26407D9C1}) (Version: 28.0.1313.0 - Hewlett-Packard Co.)
    HP Photo Creations (HKLM-x32\...\HP Photo Creations) (Version: 1.0.0.7702 - HP)
    HP Update (HKLM-x32\...\{6F1C00D2-25C2-4CBA-8126-AE9A6E2E9CD5}) (Version: 5.003.003.001 - Hewlett-Packard)
    InstantOn for NB (HKLM-x32\...\{749F674B-2674-47E8-879C-5626A06B2A91}) (Version: 2.3.3 - ASUS)
    Intel(R) Manageability Engine Firmware Recovery Agent (HKLM-x32\...\{A6C48A9F-694A-4234-B3AA-62590B668927}) (Version: 1.0.0.35342 - Intel Corporation)
    Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.0.3.1427 - Intel Corporation)
    Intel(R) OpenCL CPU Runtime (HKLM-x32\...\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: - Intel Corporation)
    Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2653 - Intel Corporation)
    Intel(R) USB 3.0 eXtensible Host Controller Driver (HKLM-x32\...\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 1.0.3.214 - Intel Corporation)
    Intelģ Trusted Connect Service Client (HKLM\...\{09536BA1-E498-4CC3-B834-D884A67D7E34}) (Version: 1.23.605.1 - Intel Corporation)
    Java 8 Update 65 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218065F0}) (Version: 8.0.650.17 - Oracle Corporation)
    Junk Mail filter update (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
    Mahjong Memoirs (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-117948443}) (Version: - Oberon Media)
    Malwarebytes Anti-Malware versie 2.2.0.1024 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.0.1024 - Malwarebytes)
    MediaFire Desktop (HKLM-x32\...\MediaFire Desktop 1.3.9.10486) (Version: 1.3.9.10486 - MediaFire)
    Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
    Microsoft Office 2010 (HKLM-x32\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
    Microsoft Office Klik-en-Klaar 2010 (HKLM-x32\...\Office14.Click2Run) (Version: 14.0.4763.1000 - Microsoft Corporation)
    Microsoft Office Starter 2010 - Nederlands (HKLM-x32\...\{90140011-0066-0413-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
    Microsoft PowerPoint Viewer (HKLM-x32\...\{95140000-00AF-0413-0000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation)
    Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40728.0 - Microsoft Corporation)
    Microsoft SkyDrive (HKU\S-1-5-21-3732487481-855672253-929003311-1001\...\SkyDriveSetup.exe) (Version: 16.4.6013.0910 - Microsoft Corporation)
    Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
    Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
    Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
    Movie Maker (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
    myBitCast 1.0.0.3 (HKLM\...\myBitCast) (Version: 1.0.0.3 - ASUS Cloud Corporation)
    Plants vs Zombies (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-117080787}) (Version: - Oberon Media)
    Platform (x32 Version: 1.39 - VIA Technologies, Inc.) Hidden
    Qualcomm Atheros WiFi Driver Installation (HKLM-x32\...\{7D916FA5-DAE9-4A25-B089-655C70EAF607}) (Version: 3.0 - Qualcomm Atheros)
    Raccolta foto (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
    SceneSwitch (HKLM-x32\...\{5172E572-C175-4F80-A6D5-5CB45826AD61}) (Version: 1.0.12 - ASUS)
    TeamViewer 10 (HKLM-x32\...\TeamViewer) (Version: 10.0.47484 - TeamViewer)
    Turbo Fiesta (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-115320460}) (Version: - Oberon Media)
    VIA Platform Device Manager (HKLM-x32\...\InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}) (Version: 1.39 - VIA Technologies, Inc.)
    Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
    Visual Studio 2012 x86 Redistributables (HKLM-x32\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
    Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3508.0205 - Microsoft Corporation)
    Windows Phone app for desktop (HKLM-x32\...\{54EC61F0-6D02-450E-9F1B-9506EAE9F23C}) (Version: 1.1.2726.0 - Microsoft Corporation)
    WinFlash (HKLM-x32\...\{8F21291E-0444-4B1D-B9F9-4370A73E346D}) (Version: 2.41.0 - ASUS)
    WinRAR 5.01 (32-bit) (HKLM-x32\...\WinRAR archiver) (Version: 5.01.0 - win.rar GmbH)
    WinZip 18.5 (HKLM\...\{CD95F661-A5C4-44F5-A6AA-ECDD91C240E3}) (Version: 18.5.11111 - WinZip Computing, S.L. )
    Wireless Console 3 (HKLM-x32\...\{19EA33FB-B34E-40EA-8B8A-61743AEB795A}) (Version: 3.0.30 - ASUS)
    World of Goo (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-116672750}) (Version: - Oberon Media)
    Συλλογή φωτογραφιών (HKLM-x32\...\{032CB0D7-FDBF-4CA9-901B-A4C1B01B1777}) (Version: 16.4.3508.0205 - Microsoft Corporation)
    Основные компоненты Windows Live (HKLM-x32\...\{7A9122B2-CF90-4ACB-8E10-AA83F725916B}) (Version: 16.4.3508.0205 - Microsoft Corporation)
    Почта Windows Live (HKLM-x32\...\{44B4333A-60A6-4FFC-BCC5-B0ECA23D2AAB}) (Version: 16.4.3508.0205 - Корпорация Майкрософт)
    Фотоальбом (HKLM-x32\...\{CE4EEFE0-85E0-436E-95C5-BCB2EE30C976}) (Version: 16.4.3508.0205 - Microsoft Corporation)
    Фотографии (общедоступная версия) (HKLM-x32\...\{234BD64C-99F4-42B5-837F-82F00E37A7E1}) (Version: 16.4.3508.0205 - Microsoft Corporation)
    גלריית התמונות (HKLM-x32\...\{B1AC8AF0-2979-4DF8-AE26-B1D543F3543F}) (Version: 16.4.3508.0205 - Microsoft Corporation)
    بريد Windows Live (HKLM-x32\...\{7A546E5C-0906-42CC-92DF-B2E787FFA7D2}) (Version: 16.4.3508.0205 - Microsoft Corporation)
    معرض الصور (HKLM-x32\...\{6F77C156-7660-4CEC-8793-97D80D5BFEC0}) (Version: 16.4.3508.0205 - Microsoft Corporation)
    影像中心 (HKLM-x32\...\{7DB15F28-5E38-476A-A773-EA07EAEAB1B3}) (Version: 16.4.3508.0205 - Microsoft Corporation)


    ==================== Aangepaste CLSID (gefilterd): ==========================


    (Als een item is opgenomen in de fixlist, wordt uit het register verwijderd. Het bestand zal niet worden verplaatst tenzij apart vermeld.)




    ==================== Herstelpunten =========================


    05-12-2015 22:50:35 Restore Point Created by FRST


    ==================== Hosts inhoud: ===============================


    (Als nodig Hosts: opdracht kan worden opgenomen in de fixlist om Hosts te resetten.)


    2009-07-14 03:34 - 2014-11-27 22:36 - 00000098 ____A C:\Windows\system32\Drivers\etc\hosts


    127.0.0.1 localhost
    ::1 localhost


    ==================== Geplande Taken (gefilterd) =============


    (Als een item is opgenomen in de fixlist, wordt uit het register verwijderd. Het bestand zal niet worden verplaatst tenzij apart vermeld.)


    Task: {016EB10C-9FA8-4770-8EBC-FB988737FFAC} - System32\Tasks\ASUS USB Charger Plus => C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe [2012-05-08] (ASUSTek Computer Inc.)
    Task: {03E6DA50-A095-4B57-902E-4DF77C5BF8F7} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2011-11-25] (Intel Corporation)
    Task: {0B3022E3-1822-42D2-853B-060D9B16FE85} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
    Task: {10101098-8567-43F5-9791-02068557C5E4} - System32\Tasks\ASUS SmartLogon Console Sensor => C:\Program Files (x86)\ASUS\FaceLogon\sensorsrv.exe [2012-02-17] (ASUSTek Computer Inc.)
    Task: {202E950A-44F4-4239-B80C-69E0FA7FE0E1} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-11-15] (Adobe Systems Incorporated)
    Task: {646DF190-524D-4096-A992-877B333AC272} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2011-11-25] (Intel Corporation)
    Task: {665B67F0-541F-45A7-89B7-F2ACC49878F2} - System32\Tasks\HPCustParticipation HP Deskjet 1050 J410 series => C:\Program Files\HP\HP Deskjet 1050 J410 series\Bin\HPCustPartic.exe [2012-10-02] (Hewlett-Packard Co.)
    Task: {67604CC6-E4A2-471C-8838-4D78A2D5DEF4} - System32\Tasks\ATKOSD2 => C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [2011-12-23] (ASUSTek Computer Inc.)
    Task: {73A21D4C-2845-4D8B-9C8E-73FDEA7C9874} - System32\Tasks\ASUS Quick Gesture (x64) => C:\Program Files (x86)\ASUS\ASUS Virtual Touch\QuickGesture\x64\QuickGesture64.exe [2012-04-12] (ASUSTeK Computer Inc.)
    Task: {75D32B76-8DCE-43E7-A42C-9D9F74B667CF} - System32\Tasks\ASUS Wireless Console 3 => C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [2012-05-17] (ASUSTeK Computer Inc.)
    Task: {797BE614-709C-4392-8414-E7339AA5FED9} - System32\Tasks\ASUS P4G => C:\Program Files\ASUS\P4G\BatteryLife.exe [2012-02-16] (ASUS)
    Task: {8BDDB50A-894A-44C8-8F18-AC996B599520} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
    Task: {D243337D-A7BA-4BDC-94F5-D685FC8BC71D} - System32\Tasks\ASUS Quick Gesture => C:\Program Files (x86)\ASUS\ASUS Virtual Touch\QuickGesture\x86\QuickGesture.exe [2012-04-12] (ASUSTeK Computer Inc.)
    Task: {DB88D52C-111F-4457-B2ED-6C6055D80BA8} - System32\Tasks\ASUS Live Update => C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe [2012-05-22] (ASUSTeK Computer Inc.)
    Task: {EC10FEA5-971D-4A52-8BA5-075DE9A65021} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-10-28] (Adobe Systems Incorporated)
    Task: {F518AA26-3DD4-48B6-AF10-875985913339} - System32\Tasks\0615tbUpdateInfo => C:\ProgramData\Avg_Update_0615tb\0615tb_{7065CFD9-63B9-47E1-A239-3232D511C3F6}.exe


    (Als een item is opgenomen in de fixlist, de taak (job) bestand wordt verplaatst. Het bestand dat wordt uitgevoerd door de taak zal niet worden verplaatst.)


    Task: C:\Windows\Tasks\0615tbUpdateInfo.job => C:\ProgramData\Avg_Update_0615tb\0615tb_{7065CFD9-63B9-47E1-A239-3232D511C3F6}.exe
    Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
    Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    Task: C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe
    Task: C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe


    ==================== Snelkoppelingen =============================


    (De items kunnen worden opgenomen in de fixlist.txt om hersteld of verwijderd te worden.)


    ==================== Geladen Modules (gefilterd) ==============


    2013-12-01 22:44 - 2012-02-21 21:29 - 00128280 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
    2010-07-15 01:11 - 2010-07-15 01:11 - 00031360 _____ () C:\Program Files\ASUS\P4G\DevMng.dll
    2013-12-01 22:45 - 2012-04-19 03:24 - 00078448 _____ () C:\Program Files (x86)\VIA\VIAudioi\VDeck\QsApoApi64.dll
    2013-12-01 22:45 - 2012-04-19 03:24 - 00386160 _____ () C:\Program Files (x86)\VIA\VIAudioi\VDeck\Dts2ApoApi64.dll
    2012-06-27 04:04 - 2012-02-22 08:18 - 00094208 _____ () C:\Windows\system32\IccLibDll_x64.dll
    2012-01-31 18:25 - 2012-01-31 18:25 - 01163264 _____ () C:\Program Files (x86)\ASUS\Wireless Console 3\acAuth.dll
    2012-05-08 01:48 - 2012-05-08 01:48 - 00009216 _____ () C:\Program Files (x86)\ASUS\Splendid\GLCDdll.dll
    2010-08-20 18:57 - 2010-08-20 18:57 - 00619816 _____ () C:\Program Files (x86)\CyberLink\Power2Go\CLMediaLibrary.dll
    2010-08-20 18:57 - 2010-08-20 18:57 - 00013096 _____ () C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvcPS.dll
    2015-12-02 14:20 - 2015-12-02 14:20 - 40500224 _____ () C:\Program Files (x86)\AVG\UiDll\2171\libcef.dll
    2013-12-01 22:44 - 2012-02-21 21:09 - 01198872 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll


    ==================== Alternate Data Streams (gefilterd) =========


    (Als een item is opgenomen in de fixlist, alleen de ADS wordt verwijderd.)




    ==================== Veilige Modus (gefilterd) ===================


    (Als een item is opgenomen in de fixlist, wordt uit het register verwijderd. De "AlternateShell" waarde wordt hersteld.)




    ==================== EXE Bestandskoppeling (gefilterd) ===============


    (Als een item is opgenomen in de fixlist, het registry item zal worden teruggezet naar de standaardwaarden of verwijderd.)




    ==================== Internet Explorer vertrouwde/beperkte toegang ===============


    (Als een item is opgenomen in de fixlist, wordt uit het register verwijderd.)




    ==================== Andere gebieden ============================


    (Momenteel is er geen automatische fix voor dit onderdeel.)


    HKU\S-1-5-21-3732487481-855672253-929003311-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\bryan77\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
    DNS Servers: 195.130.131.4 - 195.130.130.132
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
    Windows Firewall is ingeschakeld.


    ==================== MSCONFIG/TASK MANAGER Uitgeschakelde items ==


    (Momenteel is er geen automatische fix voor dit onderdeel.)


    MSCONFIG\Services: 0169601385920986mcinstcleanup => 2
    MSCONFIG\Services: MBAMScheduler => 2
    MSCONFIG\Services: MBAMService => 2
    MSCONFIG\Services: McAfee SiteAdvisor Service => 2
    MSCONFIG\Services: McAWFwk => 3
    MSCONFIG\Services: mcmscsvc => 2
    MSCONFIG\Services: McNaiAnn => 2
    MSCONFIG\Services: McNASvc => 2
    MSCONFIG\Services: McODS => 3
    MSCONFIG\Services: McOobeSv => 2
    MSCONFIG\Services: McProxy => 2
    MSCONFIG\Services: MSK80Service => 2
    MSCONFIG\startupreg: AVG_UI => "C:\Program Files (x86)\AVG\AVG2014\avgui.exe" /TRAYONLY
    MSCONFIG\startupreg: mcui_exe => "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey


    ==================== Firewall regels (gefilterd) ===============


    (Als een item is opgenomen in de fixlist, wordt uit het register verwijderd. Het bestand zal niet worden verplaatst tenzij apart vermeld.)


    FirewallRules: [TCP Query User{EBA49DCD-5C2F-4F0E-BF4F-A983FD370081}C:\program files (x86)\java\jre1.8.0_25\bin\javaw.exe] => (Block) C:\program files (x86)\java\jre1.8.0_25\bin\javaw.exe
    FirewallRules: [UDP Query User{04EF1A3B-E8E1-408D-A433-3D778365BB2A}C:\program files (x86)\java\jre1.8.0_25\bin\javaw.exe] => (Block) C:\program files (x86)\java\jre1.8.0_25\bin\javaw.exe
    FirewallRules: [TCP Query User{49B33151-1BF6-4A16-9671-A38AC8E1DA7F}D:\gta5.exe] => (Allow) D:\gta5.exe
    FirewallRules: [UDP Query User{5F17BCE1-5BAB-4AF9-BC8C-2031EEA73D41}D:\gta5.exe] => (Allow) D:\gta5.exe
    FirewallRules: [TCP Query User{21411C96-5716-44DB-97AE-6AAFEBC0D31B}C:\users\bryan\appdata\roaming\spotify\spotify.exe] => (Block) C:\users\bryan\appdata\roaming\spotify\spotify.exe
    FirewallRules: [UDP Query User{921FF2AA-205F-4238-912D-AC80D00B83E6}C:\users\bryan\appdata\roaming\spotify\spotify.exe] => (Block) C:\users\bryan\appdata\roaming\spotify\spotify.exe
    FirewallRules: [TCP Query User{B9BE8C40-DEBE-49C5-AE3A-E1498EAB80DA}C:\program files (x86)\java\jre1.8.0_45\bin\java.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_45\bin\java.exe
    FirewallRules: [UDP Query User{5D64D027-EE91-41AD-A490-E62C7653EB88}C:\program files (x86)\java\jre1.8.0_45\bin\java.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_45\bin\java.exe
    FirewallRules: [{7129689C-CE17-4737-BACC-4DDF25C9B34C}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
    FirewallRules: [{96E25971-D876-4129-9C15-D8EA0429C079}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
    FirewallRules: [{4660A62B-8C06-4943-B5FB-280CA615DFE6}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
    FirewallRules: [{B035D7DF-7034-477E-9AE9-5129C494ECBD}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
    FirewallRules: [{4A8DF4BB-2F8C-43C7-A9E4-CE99882730D1}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
    FirewallRules: [{CDE4D536-EAC6-4FB2-85A0-4E4F871B922D}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
    FirewallRules: [{8FE3476B-6184-441D-8C96-2CA1DD32DBE9}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
    FirewallRules: [{9531F97E-338F-4533-B4BB-9A32D6B4764D}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
    FirewallRules: [TCP Query User{D3C51161-AB03-4053-B366-DBB01F6DA1A0}C:\program files\java\jre1.8.0_65\bin\javaw.exe] => (Block) C:\program files\java\jre1.8.0_65\bin\javaw.exe
    FirewallRules: [UDP Query User{6E6E1AC3-B769-4DB0-92AE-80A9159BD7AE}C:\program files\java\jre1.8.0_65\bin\javaw.exe] => (Block) C:\program files\java\jre1.8.0_65\bin\javaw.exe
    FirewallRules: [TCP Query User{074F5DDC-5183-44DA-9FF2-431BE3FFFC2F}C:\program files\java\jre1.8.0_65\bin\java.exe] => (Allow) C:\program files\java\jre1.8.0_65\bin\java.exe
    FirewallRules: [UDP Query User{E9A707DB-5A5F-4F63-8681-AC8E2BE7CD33}C:\program files\java\jre1.8.0_65\bin\java.exe] => (Allow) C:\program files\java\jre1.8.0_65\bin\java.exe
    FirewallRules: [{2DE804F1-AC29-4FB5-94DF-36F6A75EACED}] => (Allow) C:\Program Files (x86)\AVG\Av\avgnsa.exe
    FirewallRules: [{77499CE2-A253-4185-9452-710444A30D0B}] => (Allow) C:\Program Files (x86)\AVG\Av\avgnsa.exe
    FirewallRules: [{066B187D-8C61-4F4E-B9F8-DFC85CDBC716}] => (Allow) C:\Program Files (x86)\AVG\Av\avgdiagex.exe
    FirewallRules: [{EFCE7FCC-F7CB-488A-A1C0-D7DEC8997440}] => (Allow) C:\Program Files (x86)\AVG\Av\avgdiagex.exe
    FirewallRules: [{905DB3C3-6451-4918-B8F7-9C981A9D58C8}] => (Allow) C:\Program Files (x86)\AVG\Av\avgmfapx.exe
    FirewallRules: [{6AF2248B-6DD9-45C1-BBA6-813BE5C012A0}] => (Allow) C:\Program Files (x86)\AVG\Av\avgmfapx.exe
    FirewallRules: [{DA86E969-765A-4B2D-8FAA-9CFB8BA80912}] => (Allow) C:\Program Files (x86)\AVG\Av\avgemca.exe
    FirewallRules: [{FBD3498B-8E7B-499C-9BA1-43501E3FBDE1}] => (Allow) C:\Program Files (x86)\AVG\Av\avgemca.exe
    FirewallRules: [{AF1F6EDE-83D3-402B-B0B2-36DC8459BE07}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe


    ==================== Defecte Apparaatbeheer Apparaten =============




    ==================== Eventlog fouten: =========================


    Applicatiefouten:
    ==================
    Error: (12/05/2015 11:05:48 PM) (Source: CVHSVC) (EventID: 100) (User: )
    Description: Alleen informatie.
    (Patch task for {90140011-0066-0413-0000-0000000FF1CE}): DownloadLatest Failed:


    Error: (12/05/2015 10:50:31 PM) (Source: VSS) (EventID: 8194) (User: )
    Description: Fout in de Volume Shadow Copy-service: onverwachte fout bij het uitvoeren van een query voor de IVssWriterCallback-interface. hr = 0x80070005, Toegang geweigerd.
    .
    Dit wordt vaak veroorzaakt door onjuiste beveiligingsinstellingen in het writer- of requestorproces.




    Bewerking:
    Schrijvergegevens verzamelen


    Context:
    Klasse-id van schrijver: {e8132975-6f93-4464-a53e-1050253ae220}
    Naam van schrijver: System Writer
    Instantie-id van schrijver: {a793fd06-b9d4-4afe-b542-7038794c4eea}


    Error: (12/05/2015 10:41:42 PM) (Source: Application Error) (EventID: 1000) (User: )
    Description: Naam van toepassing met fout: Explorer.EXE, versie: 6.1.7601.17567, tijdstempel: 0x4d672ee4
    Naam van module met fout: unknown, versie: 0.0.0.0, tijdstempel: 0x00000000
    Uitzonderingscode: 0xc0000005
    Foutoffset: 0x0000000000000000
    Id van proces met fout: 0x10dc
    Starttijd van toepassing met fout: 0xExplorer.EXE0
    Pad naar toepassing met fout: Explorer.EXE1
    Pad naar module met fout: Explorer.EXE2
    Rapport-id: Explorer.EXE3


    Error: (12/05/2015 11:35:11 AM) (Source: CVHSVC) (EventID: 100) (User: )
    Description: Alleen informatie.
    (Patch task for {90140011-0066-0413-0000-0000000FF1CE}): DownloadLatest Failed:


    Error: (12/05/2015 08:50:49 AM) (Source: CVHSVC) (EventID: 100) (User: )
    Description: Alleen informatie.
    (Patch task for {90140011-0066-0413-0000-0000000FF1CE}): DownloadLatest Failed:


    Error: (12/04/2015 03:13:19 PM) (Source: CVHSVC) (EventID: 100) (User: )
    Description: Alleen informatie.
    (Patch task for {90140011-0066-0413-0000-0000000FF1CE}): DownloadLatest Failed:


    Error: (12/04/2015 01:29:51 PM) (Source: CVHSVC) (EventID: 100) (User: )
    Description: Alleen informatie.
    (Patch task for {90140011-0066-0413-0000-0000000FF1CE}): DownloadLatest Failed:


    Error: (12/04/2015 01:07:57 PM) (Source: CVHSVC) (EventID: 100) (User: )
    Description: Alleen informatie.
    (Patch task for {90140011-0066-0413-0000-0000000FF1CE}): DownloadLatest Failed:


    Error: (12/02/2015 04:04:04 PM) (Source: CVHSVC) (EventID: 100) (User: )
    Description: Alleen informatie.
    (Patch task for {90140011-0066-0413-0000-0000000FF1CE}): DownloadLatest Failed:


    Error: (12/02/2015 03:38:01 PM) (Source: CVHSVC) (EventID: 100) (User: )
    Description: Alleen informatie.
    (Patch task for {90140011-0066-0413-0000-0000000FF1CE}): DownloadLatest Failed:




    Systeemfouten:
    =============
    Error: (12/05/2015 10:53:49 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT AUTHORITY)
    Description: WLAN-uitbreidingsmodule is onverwacht gestopt.


    Pad naar module: C:\Program Files (x86)\Qualcomm Atheros WiFi Driver Installation\AthIhvWlanExt.dll


    Error: (12/05/2015 10:53:49 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT AUTHORITY)
    Description: WLAN-uitbreidingsmodule is onverwacht gestopt.


    Pad naar module: C:\Program Files (x86)\Qualcomm Atheros WiFi Driver Installation\AthIhvWlanExt.dll


    Error: (12/05/2015 10:53:38 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT AUTHORITY)
    Description: WLAN-uitbreidingsmodule is onverwacht gestopt.


    Pad naar module: C:\Program Files (x86)\Qualcomm Atheros WiFi Driver Installation\AthIhvWlanExt.dll


    Error: (12/05/2015 10:51:34 PM) (Source: Service Control Manager) (EventID: 7032) (User: )
    Description: Servicebesturingsbeheer heeft na het onverwachte afsluiten van de Windows Search-service geprobeerd een herstelactie (Service opnieuw starten) uit te voeren, maar deze actie is met de volgende fout mislukt:
    %%1056


    Error: (12/05/2015 10:51:09 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
    Description: De Application Virtualization Client-service is onverwacht beŽindigd. Dit is nu 1 keer gebeurd.


    Error: (12/05/2015 10:51:05 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
    Description: De Windows Presentation Foundation Font Cache 3.0.0.0-service is onverwacht gestopt. Dit is 1 keer gebeurd. De volgende herstelbewerking zal over 0 milliseconden worden uitgevoerd: Service opnieuw starten.


    Error: (12/05/2015 10:51:04 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
    Description: De VIA Karaoke digital mixer Service-service is onverwacht beŽindigd. Dit is nu 1 keer gebeurd.


    Error: (12/05/2015 10:51:04 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
    Description: De Windows Live ID Sign-in Assistant-service is onverwacht gestopt. Dit is 1 keer gebeurd. De volgende herstelbewerking zal over 10000 milliseconden worden uitgevoerd: Service opnieuw starten.


    Error: (12/05/2015 10:51:04 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
    Description: De Client Virtualization Handler-service is onverwacht beŽindigd. Dit is nu 1 keer gebeurd.


    Error: (12/05/2015 10:51:04 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
    Description: De Windows Media Player Network Sharing Service-service is onverwacht gestopt. Dit is 1 keer gebeurd. De volgende herstelbewerking zal over 30000 milliseconden worden uitgevoerd: Service opnieuw starten.




    ==================== Geheugen info ===========================


    Processor: Intel(R) Pentium(R) CPU B970 @ 2.30GHz
    Percentage geheugen in gebruik: 58%
    Totaal fysiek RAM-geheugen: 3979.96 MB
    Beschikbaar fysiek RAM-geheugen: 1667.87 MB
    Totaal Virtueel geheugen: 8258.13 MB
    Beschikbaar Virtual geheugen: 5910.52 MB


    ==================== Schijven ================================


    Drive c: (OS) (Fixed) (Total:119.24 GB) (Free:45.1 GB) NTFS ==>[systeem met boot componenten (verkregen van schijf)]
    Drive d: (DATA) (Fixed) (Total:153.53 GB) (Free:153.42 GB) NTFS


    ==================== MBR & Partitietabel ==================


    ========================================================
    Disk: 0 (Size: 298.1 GB) (Disk ID: 30EC77D9)


    Partition: GPT.


    ==================== Eind van Addition.txt ============================

  18. #18

    Re: startpage changed, commercials on screen

    Scanresultaten van Farbar Recovery Scan Tool (FRST) (x64) Versie:05-12-2015
    Gestart door bryan77 (Beheerder) op BRYAN77-PC (05-12-2015 23:03:20)
    Gestart vanaf C:\Users\bryan77\Desktop
    Geladen Profielen: bryan77 (Beschikbare Profielen: bryan77 & Bryan & Barbara)
    Platform: Windows 7 Home Premium Service Pack 1 (X64) Taal: Nederlands (Nederland)
    Internet Explorer Versie 11 (Standaardbrowser: Chrome)
    Boot Modus: Normal
    Handleiding voor Farbar Recovery Scan Tool: FRST Tutorial - How to use Farbar Recovery Scan Tool - Malware Removal Guides and Tutorials


    ==================== Processen (gefilterd) =================


    (Als een item is opgenomen in de fixlist, het proces zal worden gesloten. Het bestand zal niet worden verplaatst.)


    (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgrsa.exe
    (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgcsrva.exe
    (Microsoft Corporation) C:\Windows\System32\wisptis.exe
    (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe
    (Microsoft Corporation) C:\Windows\System32\wlanext.exe
    (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
    (ASUS) C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnSrv.exe
    (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgidsagent.exe
    (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe
    (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgwdsvcx.exe
    (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
    () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
    (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
    (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
    (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
    (VIA Technologies, Inc.) C:\Windows\System32\ViakaraokeSrv.exe
    (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
    (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgnsa.exe
    (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgemca.exe
    (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
    (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
    (Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE
    (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Desktop.exe
    (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
    (ASUS) C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnWMI.exe
    (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ATKOSD.exe
    (Microsoft Corporation) C:\Windows\System32\wisptis.exe
    (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe
    (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\WDC.exe
    (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe
    (ASUS) C:\Program Files\ASUS\P4G\BatteryLife.exe
    (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\FaceLogon\sensorsrv.exe
    (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Virtual Touch\QuickGesture\x64\QuickGesture64.exe
    (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Virtual Touch\QuickGesture\x86\QuickGesture.exe
    (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe
    (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
    (Intel Corporation) C:\Windows\System32\igfxtray.exe
    (Intel Corporation) C:\Windows\System32\hkcmd.exe
    (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
    (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
    (Alcor Micro Corp.) C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe
    (ASUS) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
    (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
    (Nico Mak Computing) C:\Program Files\File Association Helper\FAHWindow.exe
    (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
    (VIA) C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe
    (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
    (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
    (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
    (CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
    (Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
    (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgui.exe
    (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
    (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Framework\Common\avguix.exe
    (Intel Corporation) C:\Windows\System32\igfxpers.exe
    (ASUSTeK) C:\Windows\SysWOW64\ACEngSvr.exe
    (Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
    (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_w32.exe
    (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_x64.exe
    (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
    (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDGesture.exe
    (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
    (Microsoft Corporation) C:\Windows\System32\dllhost.exe
    (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\ink\InputPersonalization.exe
    (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
    (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
    (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe




    ==================== Register (gefilterd) ===========================


    (Als een item is opgenomen in de fixlist, het registry item zal worden teruggezet naar de standaardwaarden of verwijderd. Het bestand zal niet worden verplaatst.)


    HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2661672 2012-05-14] (ELAN Microelectronics Corp.)
    HKLM\...\Run: [AmIcoSinglun64] => C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe [361984 2011-03-21] (Alcor Micro Corp.)
    HKLM\...\Run: [ACMON] => C:\Program Files (x86)\ASUS\Splendid\ACMON.exe [90792 2012-05-08] (ASUS)
    HKLM\...\Run: [FAHConsole] => C:\Program Files\File Association Helper\FAHConsole.exe [729272 2014-01-28] (Nico Mak Computing)
    HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291608 2012-02-07] (Intel Corporation)
    HKLM-x32\...\Run: [HDAudDeck] => C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [5142128 2012-04-19] (VIA)
    HKLM-x32\...\Run: [ATKOSD2] => C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [318080 2011-12-23] (ASUSTek Computer Inc.)
    HKLM-x32\...\Run: [ATKMEDIA] => C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [174720 2011-10-25] (ASUS)
    HKLM-x32\...\Run: [HControlUser] => C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [105016 2009-06-19] (ASUS)
    HKLM-x32\...\Run: [ASUSWebStorage] => C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.108.222\AsusWSPanel.exe [737104 2011-07-29] (ecareme)
    HKLM-x32\...\Run: [CLMLServer] => C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe [107816 2010-08-20] (CyberLink)
    HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-10-28] (Hewlett-Packard)
    HKLM-x32\...\Run: [AVG_UI] => C:\Program Files (x86)\AVG\Av\avgui.exe [3855272 2015-11-20] (AVG Technologies CZ, s.r.o.)
    HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [597040 2015-10-06] (Oracle Corporation)
    HKLM-x32\...\Run: [AvgUi] => C:\Program Files (x86)\AVG\Framework\Common\avguix.exe [1136552 2015-11-12] (AVG Technologies CZ, s.r.o.)
    Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
    ShellIconOverlayIdentifiers: [###MegaShellExtPending] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => C:\Users\Bryan\AppData\Local\MEGAsync\ShellExtX64.dll Geen bestand
    ShellIconOverlayIdentifiers: [###MegaShellExtSynced] -> {05B38830-F4E9-4329-978B-1DD28605D202} => C:\Users\Bryan\AppData\Local\MEGAsync\ShellExtX64.dll Geen bestand
    ShellIconOverlayIdentifiers: [###MegaShellExtSyncing] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => C:\Users\Bryan\AppData\Local\MEGAsync\ShellExtX64.dll Geen bestand
    ShellIconOverlayIdentifiers: [AsusWSShellExt_B] -> {6D4133E5-0742-4ADC-8A8C-9303440F7190} => C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.108.222\ASUSWSShellExt64.dll [2011-05-25] (eCareme Technologies, Inc.)
    ShellIconOverlayIdentifiers: [AsusWSShellExt_O] -> {64174815-8D98-4CE6-8646-4C039977D808} => C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.108.222\ASUSWSShellExt64.dll [2011-05-25] (eCareme Technologies, Inc.)
    ShellIconOverlayIdentifiers-x32: [###MegaShellExtPending] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => C:\Users\Bryan\AppData\Local\MEGAsync\ShellExtX32.dll Geen bestand
    ShellIconOverlayIdentifiers-x32: [###MegaShellExtSynced] -> {05B38830-F4E9-4329-978B-1DD28605D202} => C:\Users\Bryan\AppData\Local\MEGAsync\ShellExtX32.dll Geen bestand
    ShellIconOverlayIdentifiers-x32: [###MegaShellExtSyncing] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => C:\Users\Bryan\AppData\Local\MEGAsync\ShellExtX32.dll Geen bestand
    Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AsusVibeLauncher.lnk [2012-02-24]
    ShortcutTarget: AsusVibeLauncher.lnk -> C:\Program Files (x86)\ASUS\AsusVibe\AsusVibeLauncher.exe (ASUSTeK Computer Inc.)


    ==================== Internet (gefilterd) ====================


    (Als een item is opgenomen in de fixlist, als het een registry item is wordt verwijderd of hersteld naar de standaard.)


    Tcpip\Parameters: [DhcpNameServer] 195.130.131.4 195.130.130.132
    Tcpip\..\Interfaces\{954017FF-42DA-42FD-84E1-ECB55673A792}: [DhcpNameServer] 195.130.131.4 195.130.130.132
    Tcpip\..\Interfaces\{B7BD57C6-76C0-4AB4-AC64-4D8C834D3915}: [DhcpNameServer] 195.130.131.4 195.130.130.132


    Internet Explorer:
    ==================
    HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617912&ResetID=130892591560222338&GUID=D4782CC4-99AC-4097-BD5E-2E9FF6B401FD
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617912&ResetID=130892591560242339&GUID=D4782CC4-99AC-4097-BD5E-2E9FF6B401FD
    HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Google
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = Google
    HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = Google
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = Google
    HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Google
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = Google
    HKU\S-1-5-21-3732487481-855672253-929003311-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617912&ResetID=130892591573953123&GUID=D4782CC4-99AC-4097-BD5E-2E9FF6B401FD
    SearchScopes: HKLM -> DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSERBM&pc=MSERT1
    SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=ASUTDF&pc=NP06&src=IE-SearchBox
    SearchScopes: HKLM -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSERBM&pc=MSERT1
    SearchScopes: HKLM-x32 -> DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSERBM&pc=MSERT1
    SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=ASUTDF&pc=NP06&src=IE-SearchBox
    SearchScopes: HKLM-x32 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSERBM&pc=MSERT1
    SearchScopes: HKU\S-1-5-21-3732487481-855672253-929003311-1001 -> DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSERBM&pc=MSERT1
    SearchScopes: HKU\S-1-5-21-3732487481-855672253-929003311-1001 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSERBM&pc=MSERT1
    BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
    BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_65\bin\ssv.dll [2015-10-24] (Oracle Corporation)
    BHO-x32: Aanmeldhulp voor Microsoft-account -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
    BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_65\bin\jp2ssv.dll [2015-10-24] (Oracle Corporation)
    Toolbar: HKU\S-1-5-21-3732487481-855672253-929003311-1001 -> Geen Naam - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - Geen bestand
    DPF: HKLM-x32 {4B54A9DE-EF1C-4EBE-A328-7C28EA3B433A} hxxp://quickscan.bitdefender.com/qsax/qsax.cab
    DPF: HKLM-x32 {7530BFB8-7293-4D34-9923-61A11451AFC5} hxxp://download.eset.com/special/eos/OnlineScanner.cab
    StartMenuInternet: IEXPLORE.EXE - iexplore.exe


    FireFox:
    ========
    FF Plugin: @microsoft.com/GENUINE -> disabled [Geen bestand]
    FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
    FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-01-06] (Intel Corporation)
    FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-01-06] (Intel Corporation)
    FF Plugin-x32: @java.com/DTPlugin,version=11.65.2 -> C:\Program Files (x86)\Java\jre1.8.0_65\bin\dtplugin\npDeployJava1.dll [2015-10-24] (Oracle Corporation)
    FF Plugin-x32: @java.com/JavaPlugin,version=11.65.2 -> C:\Program Files (x86)\Java\jre1.8.0_65\bin\plugin2\npjp2.dll [2015-10-24] (Oracle Corporation)
    FF Plugin-x32: @microsoft.com/GENUINE -> disabled [Geen bestand]
    FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
    FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
    FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2013-02-05] (Microsoft Corporation)
    FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3508.0205 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2013-02-05] (Microsoft Corporation)
    FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-02] (Google Inc.)
    FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-02] (Google Inc.)
    FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-09-27] (Adobe Systems Inc.)


    Chrome:
    =======
    CHR Profile: C:\Users\bryan77\AppData\Local\Google\Chrome\User Data\Default
    CHR Extension: (Betalingen via Chrome Web Store) - C:\Users\bryan77\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-07-30]


    ==================== Services (gefilterd) ========================


    (Als een item is opgenomen in de fixlist, wordt uit het register verwijderd. Het bestand zal niet worden verplaatst tenzij apart vermeld.)


    R2 ASUS InstantOn; C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnSrv.exe [277120 2012-04-13] (ASUS)
    S3 AvgAMPS; C:\Program Files (x86)\AVG\Av\avgamps.exe [615584 2015-11-20] (AVG Technologies CZ, s.r.o.)
    R2 AVGIDSAgent; C:\Program Files (x86)\AVG\Av\avgidsagent.exe [3857272 2015-11-20] (AVG Technologies CZ, s.r.o.)
    R2 avgsvc; C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe [1046952 2015-11-12] (AVG Technologies CZ, s.r.o.)
    R2 avgwd; C:\Program Files (x86)\AVG\Av\avgwdsvcx.exe [579776 2015-11-20] (AVG Technologies CZ, s.r.o.)
    R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [128280 2012-02-21] ()
    R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [161560 2012-02-21] (Intel Corporation)
    S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1135416 2015-10-05] (Malwarebytes)
    R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [5702416 2015-09-11] (TeamViewer GmbH)
    R2 VIAKaraokeService; C:\Windows\system32\viakaraokesrv.exe [27760 2012-03-23] (VIA Technologies, Inc.)
    S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)


    ===================== Drivers (gefilterd) ==========================


    (Als een item is opgenomen in de fixlist, wordt uit het register verwijderd. Het bestand zal niet worden verplaatst tenzij apart vermeld.)


    R3 AsusVBus; C:\Windows\System32\DRIVERS\AsusVBus.sys [35968 2012-04-12] (Windows (R) Win 7 DDK provider)
    R3 AsusVTouch; C:\Windows\System32\DRIVERS\AsusVTouch.sys [16512 2012-04-12] (Windows (R) Win 7 DDK provider)
    R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [184240 2015-11-06] (AVG Technologies CZ, s.r.o.)
    R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [313776 2015-11-06] (AVG Technologies CZ, s.r.o.)
    R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [298416 2015-08-20] (AVG Technologies CZ, s.r.o.)
    R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [284080 2015-10-21] (AVG Technologies CZ, s.r.o.)
    R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [398256 2015-08-14] (AVG Technologies CZ, s.r.o.)
    R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [256432 2015-11-06] (AVG Technologies CZ, s.r.o.)
    R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [42416 2015-08-10] (AVG Technologies CZ, s.r.o.)
    R1 Avgtdia; C:\Windows\System32\DRIVERS\avgtdia.sys [302000 2015-10-08] (AVG Technologies CZ, s.r.o.)
    S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
    R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [15416 2009-07-20] ( )
    R3 L1C; C:\Windows\System32\DRIVERS\L1C62x64.sys [104560 2012-04-25] (Qualcomm Atheros Co., Ltd.)
    R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-10-05] (Malwarebytes)
    S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-10-05] (Malwarebytes Corporation)


    ==================== NetSvcs (gefilterd) ===================


    (Als een item is opgenomen in de fixlist, wordt uit het register verwijderd. Het bestand zal niet worden verplaatst tenzij apart vermeld.)




    ==================== Een Maand Aangemaakt bestanden en mappen ========


    (Als een item is opgenomen in de fixlist, het bestand/map wordt verplaatst.)


    2015-12-05 22:50 - 2015-12-05 22:50 - 00000000 ____D C:\Users\bryan77\Desktop\FRST-OlderVersion
    2015-12-05 08:53 - 2015-12-05 08:53 - 00000000 ___HD C:\Windows\AxInstSV
    2015-12-04 20:25 - 2015-12-04 20:25 - 00000000 ____D C:\Users\Bryan\AppData\Roaming\AVG
    2015-12-04 14:05 - 2015-12-04 15:23 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
    2015-12-04 14:04 - 2015-12-04 14:04 - 00001104 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
    2015-12-04 14:04 - 2015-12-04 14:04 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
    2015-12-04 14:04 - 2015-12-04 14:04 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
    2015-12-04 14:04 - 2015-10-05 09:50 - 00109272 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamchameleon.sys
    2015-12-04 14:04 - 2015-10-05 09:50 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
    2015-12-04 14:04 - 2015-10-05 09:50 - 00025816 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
    2015-12-04 14:02 - 2015-12-05 23:03 - 00000380 _____ C:\Users\bryan77\AppData\Roaming\sp_data.sys
    2015-12-03 12:30 - 2015-12-03 12:30 - 00000000 ____D C:\Users\Barbara.bryan77-PC\AppData\Roaming\AVG
    2015-12-02 15:36 - 2015-12-02 15:36 - 00001325 _____ C:\Users\bryan77\Desktop\JRT.txt
    2015-12-02 15:30 - 2015-12-02 15:30 - 01599336 _____ (Malwarebytes) C:\Users\bryan77\Desktop\JRT.exe
    2015-12-02 14:44 - 2015-12-02 14:44 - 01736704 _____ C:\Users\bryan77\Downloads\adwcleaner_5.023 (1).exe
    2015-12-02 14:44 - 2015-12-02 14:44 - 01736704 _____ C:\Users\bryan77\Desktop\adwcleaner_5.023.exe
    2015-12-02 14:26 - 2015-12-02 14:26 - 00000000 ____D C:\Users\bryan77\AppData\Roaming\AVG
    2015-12-02 14:21 - 2015-12-02 14:21 - 00000936 _____ C:\Users\Public\Desktop\AVG.lnk
    2015-12-02 14:21 - 2015-12-02 14:21 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG Zen
    2015-12-02 14:20 - 2015-12-02 14:24 - 00000000 ____D C:\ProgramData\Avg
    2015-12-02 14:19 - 2015-12-02 14:19 - 02970984 _____ (AVG Technologies CZ, s.r.o.) C:\Users\bryan77\Desktop\AVG_Protection_Free_698.exe
    2015-12-02 13:41 - 2015-12-02 14:21 - 00000000 ____D C:\Users\bryan77\AppData\Local\AvgSetupLog
    2015-12-02 13:39 - 2015-12-05 22:51 - 00003289 _____ C:\Users\bryan77\Desktop\Fixlog.txt
    2015-12-02 13:36 - 2015-10-24 10:20 - 00097888 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
    2015-12-01 21:48 - 2015-12-01 21:49 - 00035072 _____ C:\Users\bryan77\Desktop\Addition.txt
    2015-12-01 21:48 - 2015-12-01 21:48 - 00852771 _____ C:\Users\bryan77\Desktop\SecurityCheck.exe
    2015-12-01 21:47 - 2015-12-05 23:05 - 00019628 _____ C:\Users\bryan77\Desktop\FRST.txt
    2015-12-01 21:46 - 2015-12-05 23:03 - 00000000 ____D C:\FRST
    2015-12-01 21:45 - 2015-12-05 22:50 - 02369024 _____ (Farbar) C:\Users\bryan77\Desktop\FRST64.exe
    2015-12-01 21:45 - 2015-12-05 11:22 - 00000000 ____D C:\Users\bryan77\Desktop\uitgevoerde stappen
    2015-12-01 21:44 - 2015-12-01 21:44 - 02350080 _____ (Farbar) C:\Users\bryan77\Downloads\FRST64.exe
    2015-11-22 14:44 - 2015-11-22 14:44 - 00000000 ____D C:\Users\Bryan\AppData\Roaming\Sun
    2015-11-22 14:29 - 2015-11-22 14:29 - 00000000 ____D C:\Users\Barbara.bryan77-PC\AppData\Local\AvgSetupLog
    2015-11-21 16:10 - 2015-11-21 16:10 - 00679936 _____ C:\Users\Bryan\Downloads\Detection (10).msi
    2015-11-15 20:44 - 2015-11-15 11:44 - 00159444 ____N C:\Users\Barbara.bryan77-PC\Desktop\Kasverkoop nr 128 - 06-11-2015- Barbara Verbist.pdf
    2015-11-15 20:36 - 2015-11-15 20:36 - 00001376 _____ C:\Users\bryan77\Desktop\Photo Gallery.lnk
    2015-11-15 20:34 - 2015-11-15 20:34 - 00001116 _____ C:\Users\bryan77\Desktop\Afbeeldingen - Snelkoppeling.lnk
    2015-11-15 19:43 - 2015-11-15 19:43 - 00000000 ____D C:\Users\bryan77\Desktop\AdminPc
    2015-11-15 19:36 - 2015-11-03 18:55 - 03211264 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
    2015-11-15 19:35 - 2015-10-20 19:42 - 03168768 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
    2015-11-15 19:35 - 2015-10-20 19:42 - 02608128 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
    2015-11-15 19:35 - 2015-10-20 19:42 - 00696320 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
    2015-11-15 19:35 - 2015-10-20 19:42 - 00192512 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
    2015-11-15 19:35 - 2015-10-20 19:42 - 00098816 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
    2015-11-15 19:35 - 2015-10-20 19:42 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
    2015-11-15 19:35 - 2015-10-20 19:42 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
    2015-11-15 19:35 - 2015-10-20 19:41 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
    2015-11-15 19:35 - 2015-10-20 19:41 - 00091136 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
    2015-11-15 19:35 - 2015-10-20 19:41 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
    2015-11-15 19:35 - 2015-10-20 19:41 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll
    2015-11-15 19:35 - 2015-10-20 18:46 - 00566784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
    2015-11-15 19:35 - 2015-10-20 18:46 - 00174080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
    2015-11-15 19:35 - 2015-10-20 18:46 - 00093696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
    2015-11-15 19:35 - 2015-10-20 18:46 - 00030208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
    2015-11-15 19:35 - 2015-10-20 18:45 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
    2015-11-15 19:34 - 2015-11-03 23:10 - 00390344 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
    2015-11-15 19:34 - 2015-11-03 22:51 - 00342728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
    2015-11-15 19:34 - 2015-10-31 00:46 - 25818624 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
    2015-11-15 19:34 - 2015-10-31 00:40 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
    2015-11-15 19:34 - 2015-10-31 00:40 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
    2015-11-15 19:34 - 2015-10-31 00:25 - 02886656 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
    2015-11-15 19:34 - 2015-10-31 00:25 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
    2015-11-15 19:34 - 2015-10-31 00:25 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
    2015-11-15 19:34 - 2015-10-31 00:25 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
    2015-11-15 19:34 - 2015-10-31 00:24 - 00585728 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
    2015-11-15 19:34 - 2015-10-31 00:24 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
    2015-11-15 19:34 - 2015-10-31 00:17 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
    2015-11-15 19:34 - 2015-10-31 00:16 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
    2015-11-15 19:34 - 2015-10-31 00:13 - 00616960 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
    2015-11-15 19:34 - 2015-10-31 00:12 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
    2015-11-15 19:34 - 2015-10-31 00:12 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
    2015-11-15 19:34 - 2015-10-31 00:11 - 05990912 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
    2015-11-15 19:34 - 2015-10-31 00:11 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
    2015-11-15 19:34 - 2015-10-31 00:11 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
    2015-11-15 19:34 - 2015-10-31 00:04 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
    2015-11-15 19:34 - 2015-10-31 00:01 - 00489984 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
    2015-11-15 19:34 - 2015-10-30 23:58 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
    2015-11-15 19:34 - 2015-10-30 23:53 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
    2015-11-15 19:34 - 2015-10-30 23:52 - 20331520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
    2015-11-15 19:34 - 2015-10-30 23:49 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
    2015-11-15 19:34 - 2015-10-30 23:49 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
    2015-11-15 19:34 - 2015-10-30 23:47 - 00504832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
    2015-11-15 19:34 - 2015-10-30 23:46 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
    2015-11-15 19:34 - 2015-10-30 23:46 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
    2015-11-15 19:34 - 2015-10-30 23:45 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
    2015-11-15 19:34 - 2015-10-30 23:45 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
    2015-11-15 19:34 - 2015-10-30 23:44 - 00152064 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
    2015-11-15 19:34 - 2015-10-30 23:44 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
    2015-11-15 19:34 - 2015-10-30 23:42 - 02279936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
    2015-11-15 19:34 - 2015-10-30 23:39 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
    2015-11-15 19:34 - 2015-10-30 23:39 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
    2015-11-15 19:34 - 2015-10-30 23:37 - 00480256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
    2015-11-15 19:34 - 2015-10-30 23:36 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
    2015-11-15 19:34 - 2015-10-30 23:36 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
    2015-11-15 19:34 - 2015-10-30 23:36 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
    2015-11-15 19:34 - 2015-10-30 23:34 - 00262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
    2015-11-15 19:34 - 2015-10-30 23:32 - 00720896 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
    2015-11-15 19:34 - 2015-10-30 23:31 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
    2015-11-15 19:34 - 2015-10-30 23:29 - 02126336 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
    2015-11-15 19:34 - 2015-10-30 23:29 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
    2015-11-15 19:34 - 2015-10-30 23:28 - 00416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
    2015-11-15 19:34 - 2015-10-30 23:23 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
    2015-11-15 19:34 - 2015-10-30 23:22 - 14457856 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
    2015-11-15 19:34 - 2015-10-30 23:21 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
    2015-11-15 19:34 - 2015-10-30 23:19 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
    2015-11-15 19:34 - 2015-10-30 23:18 - 00279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
    2015-11-15 19:34 - 2015-10-30 23:17 - 02487808 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
    2015-11-15 19:34 - 2015-10-30 23:17 - 00130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
    2015-11-15 19:34 - 2015-10-30 23:16 - 04527616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
    2015-11-15 19:34 - 2015-10-30 23:11 - 00230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
    2015-11-15 19:34 - 2015-10-30 23:10 - 00689152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
    2015-11-15 19:34 - 2015-10-30 23:09 - 12854272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
    2015-11-15 19:34 - 2015-10-30 23:09 - 02052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
    2015-11-15 19:34 - 2015-10-30 23:09 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
    2015-11-15 19:34 - 2015-10-30 23:04 - 01547264 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
    2015-11-15 19:34 - 2015-10-30 22:53 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
    2015-11-15 19:34 - 2015-10-30 22:51 - 02011136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
    2015-11-15 19:34 - 2015-10-30 22:48 - 01311744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
    2015-11-15 19:34 - 2015-10-30 22:46 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
    2015-11-15 19:33 - 2015-10-29 18:50 - 00342016 _____ (Microsoft Corporation) C:\Windows\system32\apphelp.dll
    2015-11-15 19:33 - 2015-10-29 18:50 - 00072192 _____ (Microsoft Corporation) C:\Windows\system32\aelupsvc.dll
    2015-11-15 19:33 - 2015-10-29 18:50 - 00023552 _____ (Microsoft Corporation) C:\Windows\system32\sdbinst.exe
    2015-11-15 19:33 - 2015-10-29 18:50 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\shimeng.dll
    2015-11-15 19:33 - 2015-10-29 18:50 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shimeng.dll
    2015-11-15 19:33 - 2015-10-29 18:49 - 00295936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apphelp.dll
    2015-11-15 19:33 - 2015-10-29 18:49 - 00020992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sdbinst.exe
    2015-11-15 19:33 - 2015-10-20 02:12 - 05570496 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
    2015-11-15 19:33 - 2015-10-20 02:12 - 00154560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
    2015-11-15 19:33 - 2015-10-20 02:12 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
    2015-11-15 19:33 - 2015-10-20 02:09 - 01730496 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
    2015-11-15 19:33 - 2015-10-20 02:06 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
    2015-11-15 19:33 - 2015-10-20 02:06 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
    2015-11-15 19:33 - 2015-10-20 02:06 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
    2015-11-15 19:33 - 2015-10-20 02:06 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
    2015-11-15 19:33 - 2015-10-20 02:05 - 01461760 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
    2015-11-15 19:33 - 2015-10-20 02:05 - 01216512 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
    2015-11-15 19:33 - 2015-10-20 02:05 - 01164800 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
    2015-11-15 19:33 - 2015-10-20 02:05 - 00729600 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
    2015-11-15 19:33 - 2015-10-20 02:05 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
    2015-11-15 19:33 - 2015-10-20 02:05 - 00424960 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
    2015-11-15 19:33 - 2015-10-20 02:05 - 00344064 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
    2015-11-15 19:33 - 2015-10-20 02:05 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
    2015-11-15 19:33 - 2015-10-20 02:05 - 00312320 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
    2015-11-15 19:33 - 2015-10-20 02:05 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
    2015-11-15 19:33 - 2015-10-20 02:05 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
    2015-11-15 19:33 - 2015-10-20 02:05 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
    2015-11-15 19:33 - 2015-10-20 02:05 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
    2015-11-15 19:33 - 2015-10-20 02:05 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
    2015-11-15 19:33 - 2015-10-20 02:05 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
    2015-11-15 19:33 - 2015-10-20 02:05 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
    2015-11-15 19:33 - 2015-10-20 02:05 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
    2015-11-15 19:33 - 2015-10-20 02:05 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
    2015-11-15 19:33 - 2015-10-20 02:05 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
    2015-11-15 19:33 - 2015-10-20 02:05 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
    2015-11-15 19:33 - 2015-10-20 02:05 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
    2015-11-15 19:33 - 2015-10-20 02:04 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
    2015-11-15 19:33 - 2015-10-20 02:04 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
    2015-11-15 19:33 - 2015-10-20 02:04 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
    2015-11-15 19:33 - 2015-10-20 02:00 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
    2015-11-15 19:33 - 2015-10-20 01:59 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
    2015-11-15 19:33 - 2015-10-20 01:53 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
    2015-11-15 19:33 - 2015-10-20 01:53 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
    2015-11-15 19:33 - 2015-10-20 01:53 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:53 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:53 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:53 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:53 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:53 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:53 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:53 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:53 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:53 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:53 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:53 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:53 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:53 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:53 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:52 - 03991488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
    2015-11-15 19:33 - 2015-10-20 01:52 - 03935680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
    2015-11-15 19:33 - 2015-10-20 01:48 - 01311768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
    2015-11-15 19:33 - 2015-10-20 01:45 - 00552960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
    2015-11-15 19:33 - 2015-10-20 01:45 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
    2015-11-15 19:33 - 2015-10-20 01:45 - 00251392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
    2015-11-15 19:33 - 2015-10-20 01:45 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
    2015-11-15 19:33 - 2015-10-20 01:45 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
    2015-11-15 19:33 - 2015-10-20 01:45 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
    2015-11-15 19:33 - 2015-10-20 01:45 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
    2015-11-15 19:33 - 2015-10-20 01:45 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll
    2015-11-15 19:33 - 2015-10-20 01:45 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
    2015-11-15 19:33 - 2015-10-20 01:45 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
    2015-11-15 19:33 - 2015-10-20 01:45 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
    2015-11-15 19:33 - 2015-10-20 01:45 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
    2015-11-15 19:33 - 2015-10-20 01:44 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
    2015-11-15 19:33 - 2015-10-20 01:44 - 00665088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
    2015-11-15 19:33 - 2015-10-20 01:44 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
    2015-11-15 19:33 - 2015-10-20 01:44 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
    2015-11-15 19:33 - 2015-10-20 01:44 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
    2015-11-15 19:33 - 2015-10-20 01:44 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
    2015-11-15 19:33 - 2015-10-20 01:39 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
    2015-11-15 19:33 - 2015-10-20 01:39 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
    2015-11-15 19:33 - 2015-10-20 01:35 - 00686080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
    2015-11-15 19:33 - 2015-10-20 01:35 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
    2015-11-15 19:33 - 2015-10-20 01:35 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:35 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:35 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:35 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:35 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:35 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:35 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:35 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:35 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:35 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:35 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:35 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:35 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 01:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 00:41 - 00159232 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
    2015-11-15 19:33 - 2015-10-20 00:40 - 00290816 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
    2015-11-15 19:33 - 2015-10-20 00:40 - 00129024 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
    2015-11-15 19:33 - 2015-10-20 00:29 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
    2015-11-15 19:33 - 2015-10-20 00:29 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
    2015-11-15 19:33 - 2015-10-20 00:27 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 00:27 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 00:27 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-20 00:27 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
    2015-11-15 19:33 - 2015-10-13 17:41 - 00497664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
    2015-11-15 19:33 - 2015-10-13 17:40 - 00118272 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdx.sys
    2015-11-15 19:33 - 2015-09-23 14:15 - 00460776 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
    2015-11-15 19:33 - 2015-09-23 14:15 - 00299632 _____ (Microsoft Corporation) C:\Windows\system32\bcryptprimitives.dll
    2015-11-15 19:33 - 2015-09-23 14:09 - 00251000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcryptprimitives.dll
    2015-11-15 19:27 - 2015-11-15 19:27 - 00000000 ____D C:\Users\bryan77\AppData\Local\Mega Limited
    2015-11-15 19:24 - 2015-10-13 05:57 - 00950720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys
    2015-11-15 19:24 - 2015-10-01 19:00 - 00275456 _____ (Microsoft Corporation) C:\Windows\system32\InkEd.dll
    2015-11-15 19:24 - 2015-10-01 19:00 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\jnwmon.dll
    2015-11-15 19:24 - 2015-10-01 18:50 - 00216064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InkEd.dll
    2015-11-09 08:55 - 2015-11-09 08:55 - 00120507 _____ C:\Users\Barbara.bryan77-PC\Downloads\105521 (1).pdf
    2015-11-09 08:51 - 2015-11-09 08:51 - 00120507 _____ C:\Users\Barbara.bryan77-PC\Downloads\105521.pdf
    2015-11-06 15:50 - 2015-11-06 15:50 - 00184240 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgdiska.sys
    2015-11-06 15:49 - 2015-11-06 15:49 - 00313776 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgidsdrivera.sys
    2015-11-06 15:49 - 2015-11-06 15:49 - 00256432 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgmfx64.sys


    ==================== Een Maand Gewijzigd bestanden en mappen ========


    (Als een item is opgenomen in de fixlist, het bestand/map wordt verplaatst.)


    2015-12-05 23:04 - 2012-02-24 03:29 - 00001056 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
    2015-12-05 22:57 - 2013-12-01 22:44 - 00000828 _____ C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job
    2015-12-05 22:57 - 2012-02-24 03:29 - 00001052 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
    2015-12-05 22:55 - 2013-12-01 20:07 - 00000000 ____D C:\ProgramData\MFAData
    2015-12-05 22:55 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
    2015-12-05 22:46 - 2009-07-14 05:45 - 00009920 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
    2015-12-05 22:46 - 2009-07-14 05:45 - 00009920 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
    2015-12-05 22:44 - 2013-12-08 21:48 - 00000940 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
    2015-12-05 22:22 - 2014-09-15 18:06 - 00000000 ____D C:\Users\Bryan\AppData\Roaming\Software Informer
    2015-12-05 20:29 - 2015-06-03 11:41 - 00000000 ____D C:\Users\Bryan\AppData\Local\Spotify
    2015-12-05 20:29 - 2015-06-03 11:40 - 00000000 ____D C:\Users\Bryan\AppData\Roaming\Spotify
    2015-12-05 20:29 - 2013-12-01 21:06 - 00000380 _____ C:\Users\Bryan\AppData\Roaming\sp_data.sys
    2015-12-05 12:12 - 2013-12-01 22:44 - 00000830 _____ C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job
    2015-12-05 11:43 - 2013-12-01 20:24 - 00000380 _____ C:\Users\Barbara.bryan77-PC\AppData\Roaming\sp_data.sys
    2015-12-05 08:53 - 2009-07-14 06:32 - 00000000 ____D C:\Windows\Downloaded Program Files
    2015-12-05 08:53 - 2009-07-14 04:20 - 00000000 ____D C:\Windows
    2015-12-05 08:52 - 2015-05-21 19:40 - 00000000 __SHD C:\Users\bryan77\AppData\Local\EmieUserList
    2015-12-05 08:52 - 2015-05-21 19:40 - 00000000 __SHD C:\Users\bryan77\AppData\Local\EmieSiteList
    2015-12-05 08:52 - 2015-05-21 19:40 - 00000000 __SHD C:\Users\bryan77\AppData\Local\EmieBrowserModeList
    2015-12-04 20:25 - 2014-11-26 08:12 - 00000000 ____D C:\Users\Bryan\AppData\Local\Avg
    2015-12-04 15:02 - 2009-07-14 06:32 - 00000000 ____D C:\Windows\Performance
    2015-12-04 14:02 - 2014-11-06 21:55 - 00000000 ____D C:\Program Files (x86)\TeamViewer
    2015-12-02 17:59 - 2012-02-24 03:29 - 00004052 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
    2015-12-02 17:59 - 2012-02-24 03:29 - 00003800 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
    2015-12-02 15:34 - 2011-02-19 05:40 - 00746450 _____ C:\Windows\system32\perfh013.dat
    2015-12-02 15:34 - 2011-02-19 05:40 - 00154112 _____ C:\Windows\system32\perfc013.dat
    2015-12-02 15:34 - 2009-07-14 06:13 - 01672504 _____ C:\Windows\system32\PerfStringBackup.INI
    2015-12-02 15:34 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\inf
    2015-12-02 15:25 - 2014-11-27 23:08 - 00000000 ____D C:\AdwCleaner
    2015-12-02 14:34 - 2013-12-01 20:15 - 00000000 ____D C:\ProgramData\AVG2014
    2015-12-02 14:26 - 2014-11-26 08:12 - 00000000 ____D C:\Users\bryan77\AppData\Local\Avg
    2015-12-02 14:26 - 2014-08-28 07:09 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
    2015-12-02 14:26 - 2013-12-01 20:15 - 00000000 ___HD C:\$AVG
    2015-12-02 14:26 - 2013-12-01 20:13 - 00000000 ____D C:\Program Files (x86)\AVG
    2015-12-02 14:25 - 2015-06-26 08:09 - 00000000 ____D C:\Program Files\Common Files\AV
    2015-12-02 13:39 - 2013-12-01 17:57 - 00001144 _____ C:\Users\bryan77\Desktop\Internet Explorer.lnk
    2015-12-02 13:39 - 2013-12-01 14:19 - 00001144 _____ C:\Users\bryan77\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
    2015-12-02 13:36 - 2014-12-02 23:36 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
    2015-12-01 21:40 - 2009-07-14 06:09 - 00000000 ____D C:\Windows\System32\Tasks\WPD
    2015-11-22 14:44 - 2015-10-27 19:41 - 00000000 ____D C:\Users\Bryan\.oracle_jre_usage
    2015-11-22 14:29 - 2014-11-26 08:12 - 00000000 ____D C:\Users\Barbara.bryan77-PC\AppData\Local\Avg
    2015-11-16 04:06 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache
    2015-11-16 03:29 - 2009-07-14 05:45 - 00270888 _____ C:\Windows\system32\FNTCACHE.DAT
    2015-11-16 03:24 - 2015-06-03 21:56 - 00000000 ____D C:\Windows\system32\MRT
    2015-11-16 03:11 - 2015-06-03 21:55 - 145617392 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
    2015-11-16 03:03 - 2012-02-24 03:28 - 01647172 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
    2015-11-16 03:02 - 2009-07-14 08:45 - 00000000 ____D C:\Program Files\Windows Journal
    2015-11-15 20:36 - 2013-12-01 19:25 - 00000000 ____D C:\Users\bryan77\AppData\Local\Windows Live
    2015-11-15 19:44 - 2013-12-08 21:48 - 00780488 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
    2015-11-15 19:44 - 2013-12-08 21:48 - 00142536 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
    2015-11-15 19:44 - 2013-12-08 21:48 - 00003878 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
    2015-11-15 19:43 - 2014-11-21 21:01 - 00000000 ____D C:\Users\AdminPc
    2015-11-15 19:32 - 2009-07-14 04:20 - 00000000 __RHD C:\Users\Public\Libraries
    2015-11-15 19:27 - 2014-10-01 09:20 - 00000000 ____D C:\Users\Bryan\AppData\Local\MEGAsync
    2015-11-15 19:15 - 2014-07-29 10:51 - 00000000 ____D C:\Users\bryan77\AppData\Roaming\.minecraft
    2015-11-15 19:02 - 2013-12-01 21:05 - 00000000 ____D C:\Users\Bryan
    2015-11-15 19:02 - 2013-12-01 14:18 - 00000000 ____D C:\Users\bryan77
    2015-11-13 00:29 - 2015-04-05 02:00 - 00000000 ___SD C:\Windows\system32\GWX
    2015-11-13 00:29 - 2013-12-08 21:48 - 00000000 ____D C:\Windows\system32\Macromed
    2015-11-13 00:29 - 2013-12-01 20:24 - 00000000 ____D C:\Users\Barbara.bryan77-PC
    2015-11-13 00:29 - 2012-02-24 03:29 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
    2015-11-13 00:29 - 2009-07-14 08:44 - 00000000 ___RD C:\Users\Public\Recorded TV
    2015-11-13 00:29 - 2009-07-14 04:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared
    2015-11-13 00:28 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\registration
    2015-11-07 11:11 - 2014-08-11 12:27 - 00000184 _____ C:\Users\Bryan\Downloads\eula.txt


    ==================== Bestanden in de root van sommige mappen =======


    2015-12-04 14:02 - 2015-12-05 23:03 - 0000380 _____ () C:\Users\bryan77\AppData\Roaming\sp_data.sys
    2014-04-16 18:15 - 2014-04-16 18:15 - 0000057 _____ () C:\ProgramData\Ament.ini
    2012-02-24 03:42 - 2010-10-06 18:45 - 0131984 _____ () C:\ProgramData\FullRemove.exe
    2013-12-01 14:06 - 2013-12-01 14:06 - 0000109 _____ () C:\ProgramData\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}.log
    2013-12-01 14:05 - 2013-12-01 14:06 - 0000105 _____ () C:\ProgramData\{40BF1E83-20EB-11D8-97C5-0009C5020658}.log
    2013-12-01 14:04 - 2013-12-01 14:05 - 0000107 _____ () C:\ProgramData\{C59C179C-668D-49A9-B6EA-0121CCFC1243}.log


    ==================== Bamital & volsnap =================


    (Er is geen automatische fix voor bestanden die de verificatie niet doorkomen.)


    C:\Windows\system32\winlogon.exe => Bestand is getekend
    C:\Windows\system32\wininit.exe => Bestand is getekend
    C:\Windows\SysWOW64\wininit.exe => Bestand is getekend
    C:\Windows\explorer.exe => Bestand is getekend
    C:\Windows\SysWOW64\explorer.exe => Bestand is getekend
    C:\Windows\system32\svchost.exe => Bestand is getekend
    C:\Windows\SysWOW64\svchost.exe => Bestand is getekend
    C:\Windows\system32\services.exe => Bestand is getekend
    C:\Windows\system32\User32.dll => Bestand is getekend
    C:\Windows\SysWOW64\User32.dll => Bestand is getekend
    C:\Windows\system32\userinit.exe => Bestand is getekend
    C:\Windows\SysWOW64\userinit.exe => Bestand is getekend
    C:\Windows\system32\rpcss.dll => Bestand is getekend
    C:\Windows\system32\dnsapi.dll => Bestand is getekend
    C:\Windows\SysWOW64\dnsapi.dll => Bestand is getekend
    C:\Windows\system32\Drivers\volsnap.sys => Bestand is getekend




    LastRegBack: 2015-11-30 00:25


    ==================== Eind van FRST.txt ============================


    Extra scanresultaten van Farbar Recovery Scan Tool (x64) Versie:05-12-2015
    Gestart door bryan77 (2015-12-05 23:06:18)
    Gestart vanaf C:\Users\bryan77\Desktop
    Windows 7 Home Premium Service Pack 1 (X64) (2013-12-01 13:17:59)
    Boot Modus: Normal
    ==========================================================




    ==================== Accounts: =============================


    Administrator (S-1-5-21-3732487481-855672253-929003311-500 - Administrator - Disabled)
    Barbara (S-1-5-21-3732487481-855672253-929003311-1006 - Limited - Enabled) => C:\Users\Barbara.bryan77-PC
    Bryan (S-1-5-21-3732487481-855672253-929003311-1005 - Limited - Enabled) => C:\Users\Bryan
    bryan77 (S-1-5-21-3732487481-855672253-929003311-1001 - Administrator - Enabled) => C:\Users\bryan77
    Gast (S-1-5-21-3732487481-855672253-929003311-501 - Limited - Disabled)
    HomeGroupUser$ (S-1-5-21-3732487481-855672253-929003311-1002 - Limited - Enabled)


    ==================== Security Center ========================


    (Als een item is opgenomen in de fixlist, zal het worden verwijderd.)


    AV: AVG AntiVirus Free Edition (Enabled - Up to date) {4D41356F-32AD-7C42-C820-63775EE4F413}
    AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    AS: AVG AntiVirus Free Edition (Enabled - Up to date) {F620D48B-1497-73CC-F290-58052563BEAE}


    ==================== GeÔnstalleerde programma's ======================


    (Alleen de adware-programma's met 'verborgen' vlag zou kunnen worden toegevoegd aan de fixlist om ze zichtbaar te maken. De adware-programma's moeten handmatig gedeinstallerd worden.)


    Adobe Flash Player 10 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 10.0.32.18 - Adobe Systems Incorporated)
    Adobe Flash Player 19 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 19.0.0.245 - Adobe Systems Incorporated)
    Adobe Reader XI (11.0.13) - Nederlands (HKLM-x32\...\{AC76BA86-7AD7-1043-7B44-AB0000000001}) (Version: 11.0.13 - Adobe Systems Incorporated)
    Alcor Micro USB Card Reader (HKLM-x32\...\AmUStor) (Version: 1.2.0117.08443 - Alcor Micro Corp.)
    Alcor Micro USB Card Reader (x32 Version: 1.2.0117.08443 - Alcor Micro Corp.) Hidden
    ASUS AI Recovery (HKLM-x32\...\{D39F0676-163E-4595-A917-E28F99BBD4D2}) (Version: 1.0.24 - ASUS)
    ASUS FaceLogon (HKLM-x32\...\{64452561-169F-4A36-A2FF-B5E118EC65F5}) (Version: 1.0.0014 - ASUS)
    ASUS Instant Connect (HKLM-x32\...\{89ECB85A-D933-4CEA-9116-5CBC9C2ED95B}) (Version: 1.2.2 - ASUS)
    ASUS LifeFrame3 (HKLM-x32\...\{1DBD1F12-ED93-49C0-A7CC-56CBDE488158}) (Version: 3.1.1 - ASUS)
    ASUS Live Update (HKLM-x32\...\{FA540E67-095C-4A1B-97BA-4D547DEC9AF4}) (Version: 3.1.5 - ASUS)
    ASUS Power4Gear Hybrid (HKLM\...\{9B6239BF-4E85-4590-8D72-51E30DB1A9AA}) (Version: 1.2.1 - ASUS)
    ASUS Splendid Video Enhancement Technology (HKLM-x32\...\{0969AF05-4FF6-4C00-9406-43599238DE0D}) (Version: 1.03.0001 - ASUS)
    ASUS USB Charger Plus (HKLM-x32\...\{A859E3E5-C62F-4BFA-AF1D-2B95E03166AF}) (Version: 2.1.1 - ASUS)
    ASUS Virtual Camera (HKLM-x32\...\{EC8BD21F-0CA0-4BBF-97D9-4A52B30041A1}) (Version: 1.0.25 - ASUS)
    ASUS Virtual Touch (HKLM-x32\...\{938CFBD4-0652-49E5-BB8B-153948865941}) (Version: 1.0.11 - ASUS)
    ASUS WebStorage (HKLM-x32\...\ASUS WebStorage) (Version: 3.0.108.222 - eCareme Technologies, Inc.)
    AsusVibe2.0 (HKLM-x32\...\Asus Vibe2.0) (Version: 2.0.9.157 - ASUSTEK)
    Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver (HKLM-x32\...\{3108C217-BE83-42E4-AE9E-A56A2A92E549}) (Version: 2.0.15.16 - Atheros Communications Inc.)
    ATK Package (HKLM-x32\...\{AB5C933E-5C7D-4D30-B314-9C83A49B94BE}) (Version: 1.0.0015 - ASUS)
    AVG (HKLM\...\AvgZen) (Version: 1.22.1.40089 - AVG Technologies)
    AVG (Version: 16.12.7294 - AVG Technologies) Hidden
    AVG 2016 (Version: 16.0.4483 - AVG Technologies) Hidden
    AVG Protection (HKLM\...\AVG) (Version: 2016.12.7294 - AVG Technologies)
    AVG Zen (Version: 1.22.1 - AVG Technologies) Hidden
    Bubbletown (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-115065740}) (Version: - Oberon Media)
    Contenta Converter PREMIUM (HKLM-x32\...\ContentaConverter-PREMIUM) (Version: - Contenta Software)
    CyberLink LabelPrint (HKLM-x32\...\InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}) (Version: 2.5.3624 - CyberLink Corp.)
    CyberLink Media Suite (HKLM-x32\...\InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}) (Version: 8.0.2926 - CyberLink Corp.)
    CyberLink Power2Go (HKLM-x32\...\InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 7.0.0.1126 - CyberLink Corp.)
    D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
    Deadtime Stories (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-118716773}) (Version: - Oberon Media)
    Dream Day First Home (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-113832110}) (Version: - Oberon Media)
    Dream Vacation Solitaire (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111249233}) (Version: - Oberon Media)
    ESET Online Scanner v3 (HKLM-x32\...\ESET Online Scanner) (Version: - )
    ETDWare PS/2-X64 10.5.10.0 (HKLM\...\Elantech) (Version: 10.5.10.0 - ELAN Microelectronic Corp.)
    Farm Frenzy 3 - Madagascar (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-119205603}) (Version: - Oberon Media)
    FMW 1 (Version: 1.32.2 - AVG Technologies) Hidden
    Fotogalerie (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
    Galapago (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111307457}) (Version: - Oberon Media)
    Galeria de Fotografias (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
    GalerŪa de fotos (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
    Galerie de photos (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
    Game Park Console (HKLM-x32\...\Game Park Console) (Version: 1.2.4.431 - Oberon Media Inc.)
    Go Go Gourmet Chef of the Year (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-115290153}) (Version: - Oberon Media)
    Google Chrome (HKLM-x32\...\Google Chrome) (Version: 47.0.2526.73 - Google Inc.)
    Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
    Google Update Helper (x32 Version: 1.3.29.1 - Google Inc.) Hidden
    HP Deskjet 1050 J410 series Basissoftware van het apparaat (HKLM\...\{FA37D2E8-0A8B-46D2-A74A-310F935DE920}) (Version: 28.0.1313.0 - Hewlett-Packard Co.)
    HP Deskjet 1050 J410 series Haelp (HKLM-x32\...\{5C90D8CF-F12A-41C6-9007-3B651A1F0D78}) (Version: 140.0.66.66 - Hewlett Packard)
    HP Deskjet 1050 J410 series Productverbeteringsonderzoek (HKLM\...\{44C6BB22-7E25-4A6D-8851-6FB26407D9C1}) (Version: 28.0.1313.0 - Hewlett-Packard Co.)
    HP Photo Creations (HKLM-x32\...\HP Photo Creations) (Version: 1.0.0.7702 - HP)
    HP Update (HKLM-x32\...\{6F1C00D2-25C2-4CBA-8126-AE9A6E2E9CD5}) (Version: 5.003.003.001 - Hewlett-Packard)
    InstantOn for NB (HKLM-x32\...\{749F674B-2674-47E8-879C-5626A06B2A91}) (Version: 2.3.3 - ASUS)
    Intel(R) Manageability Engine Firmware Recovery Agent (HKLM-x32\...\{A6C48A9F-694A-4234-B3AA-62590B668927}) (Version: 1.0.0.35342 - Intel Corporation)
    Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.0.3.1427 - Intel Corporation)
    Intel(R) OpenCL CPU Runtime (HKLM-x32\...\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: - Intel Corporation)
    Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2653 - Intel Corporation)
    Intel(R) USB 3.0 eXtensible Host Controller Driver (HKLM-x32\...\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 1.0.3.214 - Intel Corporation)
    Intelģ Trusted Connect Service Client (HKLM\...\{09536BA1-E498-4CC3-B834-D884A67D7E34}) (Version: 1.23.605.1 - Intel Corporation)
    Java 8 Update 65 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218065F0}) (Version: 8.0.650.17 - Oracle Corporation)
    Junk Mail filter update (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
    Mahjong Memoirs (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-117948443}) (Version: - Oberon Media)
    Malwarebytes Anti-Malware versie 2.2.0.1024 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.0.1024 - Malwarebytes)
    MediaFire Desktop (HKLM-x32\...\MediaFire Desktop 1.3.9.10486) (Version: 1.3.9.10486 - MediaFire)
    Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
    Microsoft Office 2010 (HKLM-x32\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
    Microsoft Office Klik-en-Klaar 2010 (HKLM-x32\...\Office14.Click2Run) (Version: 14.0.4763.1000 - Microsoft Corporation)
    Microsoft Office Starter 2010 - Nederlands (HKLM-x32\...\{90140011-0066-0413-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
    Microsoft PowerPoint Viewer (HKLM-x32\...\{95140000-00AF-0413-0000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation)
    Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40728.0 - Microsoft Corporation)
    Microsoft SkyDrive (HKU\S-1-5-21-3732487481-855672253-929003311-1001\...\SkyDriveSetup.exe) (Version: 16.4.6013.0910 - Microsoft Corporation)
    Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
    Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
    Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
    Movie Maker (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
    myBitCast 1.0.0.3 (HKLM\...\myBitCast) (Version: 1.0.0.3 - ASUS Cloud Corporation)
    Plants vs Zombies (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-117080787}) (Version: - Oberon Media)
    Platform (x32 Version: 1.39 - VIA Technologies, Inc.) Hidden
    Qualcomm Atheros WiFi Driver Installation (HKLM-x32\...\{7D916FA5-DAE9-4A25-B089-655C70EAF607}) (Version: 3.0 - Qualcomm Atheros)
    Raccolta foto (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
    SceneSwitch (HKLM-x32\...\{5172E572-C175-4F80-A6D5-5CB45826AD61}) (Version: 1.0.12 - ASUS)
    TeamViewer 10 (HKLM-x32\...\TeamViewer) (Version: 10.0.47484 - TeamViewer)
    Turbo Fiesta (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-115320460}) (Version: - Oberon Media)
    VIA Platform Device Manager (HKLM-x32\...\InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}) (Version: 1.39 - VIA Technologies, Inc.)
    Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
    Visual Studio 2012 x86 Redistributables (HKLM-x32\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
    Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3508.0205 - Microsoft Corporation)
    Windows Phone app for desktop (HKLM-x32\...\{54EC61F0-6D02-450E-9F1B-9506EAE9F23C}) (Version: 1.1.2726.0 - Microsoft Corporation)
    WinFlash (HKLM-x32\...\{8F21291E-0444-4B1D-B9F9-4370A73E346D}) (Version: 2.41.0 - ASUS)
    WinRAR 5.01 (32-bit) (HKLM-x32\...\WinRAR archiver) (Version: 5.01.0 - win.rar GmbH)
    WinZip 18.5 (HKLM\...\{CD95F661-A5C4-44F5-A6AA-ECDD91C240E3}) (Version: 18.5.11111 - WinZip Computing, S.L. )
    Wireless Console 3 (HKLM-x32\...\{19EA33FB-B34E-40EA-8B8A-61743AEB795A}) (Version: 3.0.30 - ASUS)
    World of Goo (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-116672750}) (Version: - Oberon Media)
    Συλλογή φωτογραφιών (HKLM-x32\...\{032CB0D7-FDBF-4CA9-901B-A4C1B01B1777}) (Version: 16.4.3508.0205 - Microsoft Corporation)
    Основные компоненты Windows Live (HKLM-x32\...\{7A9122B2-CF90-4ACB-8E10-AA83F725916B}) (Version: 16.4.3508.0205 - Microsoft Corporation)
    Почта Windows Live (HKLM-x32\...\{44B4333A-60A6-4FFC-BCC5-B0ECA23D2AAB}) (Version: 16.4.3508.0205 - Корпорация Майкрософт)
    Фотоальбом (HKLM-x32\...\{CE4EEFE0-85E0-436E-95C5-BCB2EE30C976}) (Version: 16.4.3508.0205 - Microsoft Corporation)
    Фотографии (общедоступная версия) (HKLM-x32\...\{234BD64C-99F4-42B5-837F-82F00E37A7E1}) (Version: 16.4.3508.0205 - Microsoft Corporation)
    גלריית התמונות (HKLM-x32\...\{B1AC8AF0-2979-4DF8-AE26-B1D543F3543F}) (Version: 16.4.3508.0205 - Microsoft Corporation)
    بريد Windows Live (HKLM-x32\...\{7A546E5C-0906-42CC-92DF-B2E787FFA7D2}) (Version: 16.4.3508.0205 - Microsoft Corporation)
    معرض الصور (HKLM-x32\...\{6F77C156-7660-4CEC-8793-97D80D5BFEC0}) (Version: 16.4.3508.0205 - Microsoft Corporation)
    影像中心 (HKLM-x32\...\{7DB15F28-5E38-476A-A773-EA07EAEAB1B3}) (Version: 16.4.3508.0205 - Microsoft Corporation)


    ==================== Aangepaste CLSID (gefilterd): ==========================


    (Als een item is opgenomen in de fixlist, wordt uit het register verwijderd. Het bestand zal niet worden verplaatst tenzij apart vermeld.)




    ==================== Herstelpunten =========================


    05-12-2015 22:50:35 Restore Point Created by FRST


    ==================== Hosts inhoud: ===============================


    (Als nodig Hosts: opdracht kan worden opgenomen in de fixlist om Hosts te resetten.)


    2009-07-14 03:34 - 2014-11-27 22:36 - 00000098 ____A C:\Windows\system32\Drivers\etc\hosts


    127.0.0.1 localhost
    ::1 localhost


    ==================== Geplande Taken (gefilterd) =============


    (Als een item is opgenomen in de fixlist, wordt uit het register verwijderd. Het bestand zal niet worden verplaatst tenzij apart vermeld.)


    Task: {016EB10C-9FA8-4770-8EBC-FB988737FFAC} - System32\Tasks\ASUS USB Charger Plus => C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe [2012-05-08] (ASUSTek Computer Inc.)
    Task: {03E6DA50-A095-4B57-902E-4DF77C5BF8F7} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2011-11-25] (Intel Corporation)
    Task: {0B3022E3-1822-42D2-853B-060D9B16FE85} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
    Task: {10101098-8567-43F5-9791-02068557C5E4} - System32\Tasks\ASUS SmartLogon Console Sensor => C:\Program Files (x86)\ASUS\FaceLogon\sensorsrv.exe [2012-02-17] (ASUSTek Computer Inc.)
    Task: {202E950A-44F4-4239-B80C-69E0FA7FE0E1} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-11-15] (Adobe Systems Incorporated)
    Task: {646DF190-524D-4096-A992-877B333AC272} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2011-11-25] (Intel Corporation)
    Task: {665B67F0-541F-45A7-89B7-F2ACC49878F2} - System32\Tasks\HPCustParticipation HP Deskjet 1050 J410 series => C:\Program Files\HP\HP Deskjet 1050 J410 series\Bin\HPCustPartic.exe [2012-10-02] (Hewlett-Packard Co.)
    Task: {67604CC6-E4A2-471C-8838-4D78A2D5DEF4} - System32\Tasks\ATKOSD2 => C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [2011-12-23] (ASUSTek Computer Inc.)
    Task: {73A21D4C-2845-4D8B-9C8E-73FDEA7C9874} - System32\Tasks\ASUS Quick Gesture (x64) => C:\Program Files (x86)\ASUS\ASUS Virtual Touch\QuickGesture\x64\QuickGesture64.exe [2012-04-12] (ASUSTeK Computer Inc.)
    Task: {75D32B76-8DCE-43E7-A42C-9D9F74B667CF} - System32\Tasks\ASUS Wireless Console 3 => C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [2012-05-17] (ASUSTeK Computer Inc.)
    Task: {797BE614-709C-4392-8414-E7339AA5FED9} - System32\Tasks\ASUS P4G => C:\Program Files\ASUS\P4G\BatteryLife.exe [2012-02-16] (ASUS)
    Task: {8BDDB50A-894A-44C8-8F18-AC996B599520} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
    Task: {D243337D-A7BA-4BDC-94F5-D685FC8BC71D} - System32\Tasks\ASUS Quick Gesture => C:\Program Files (x86)\ASUS\ASUS Virtual Touch\QuickGesture\x86\QuickGesture.exe [2012-04-12] (ASUSTeK Computer Inc.)
    Task: {DB88D52C-111F-4457-B2ED-6C6055D80BA8} - System32\Tasks\ASUS Live Update => C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe [2012-05-22] (ASUSTeK Computer Inc.)
    Task: {EC10FEA5-971D-4A52-8BA5-075DE9A65021} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-10-28] (Adobe Systems Incorporated)
    Task: {F518AA26-3DD4-48B6-AF10-875985913339} - System32\Tasks\0615tbUpdateInfo => C:\ProgramData\Avg_Update_0615tb\0615tb_{7065CFD9-63B9-47E1-A239-3232D511C3F6}.exe


    (Als een item is opgenomen in de fixlist, de taak (job) bestand wordt verplaatst. Het bestand dat wordt uitgevoerd door de taak zal niet worden verplaatst.)


    Task: C:\Windows\Tasks\0615tbUpdateInfo.job => C:\ProgramData\Avg_Update_0615tb\0615tb_{7065CFD9-63B9-47E1-A239-3232D511C3F6}.exe
    Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
    Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    Task: C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe
    Task: C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe


    ==================== Snelkoppelingen =============================


    (De items kunnen worden opgenomen in de fixlist.txt om hersteld of verwijderd te worden.)


    ==================== Geladen Modules (gefilterd) ==============


    2013-12-01 22:44 - 2012-02-21 21:29 - 00128280 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
    2010-07-15 01:11 - 2010-07-15 01:11 - 00031360 _____ () C:\Program Files\ASUS\P4G\DevMng.dll
    2013-12-01 22:45 - 2012-04-19 03:24 - 00078448 _____ () C:\Program Files (x86)\VIA\VIAudioi\VDeck\QsApoApi64.dll
    2013-12-01 22:45 - 2012-04-19 03:24 - 00386160 _____ () C:\Program Files (x86)\VIA\VIAudioi\VDeck\Dts2ApoApi64.dll
    2012-06-27 04:04 - 2012-02-22 08:18 - 00094208 _____ () C:\Windows\system32\IccLibDll_x64.dll
    2012-01-31 18:25 - 2012-01-31 18:25 - 01163264 _____ () C:\Program Files (x86)\ASUS\Wireless Console 3\acAuth.dll
    2012-05-08 01:48 - 2012-05-08 01:48 - 00009216 _____ () C:\Program Files (x86)\ASUS\Splendid\GLCDdll.dll
    2010-08-20 18:57 - 2010-08-20 18:57 - 00619816 _____ () C:\Program Files (x86)\CyberLink\Power2Go\CLMediaLibrary.dll
    2010-08-20 18:57 - 2010-08-20 18:57 - 00013096 _____ () C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvcPS.dll
    2015-12-02 14:20 - 2015-12-02 14:20 - 40500224 _____ () C:\Program Files (x86)\AVG\UiDll\2171\libcef.dll
    2013-12-01 22:44 - 2012-02-21 21:09 - 01198872 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll


    ==================== Alternate Data Streams (gefilterd) =========


    (Als een item is opgenomen in de fixlist, alleen de ADS wordt verwijderd.)




    ==================== Veilige Modus (gefilterd) ===================


    (Als een item is opgenomen in de fixlist, wordt uit het register verwijderd. De "AlternateShell" waarde wordt hersteld.)




    ==================== EXE Bestandskoppeling (gefilterd) ===============


    (Als een item is opgenomen in de fixlist, het registry item zal worden teruggezet naar de standaardwaarden of verwijderd.)




    ==================== Internet Explorer vertrouwde/beperkte toegang ===============


    (Als een item is opgenomen in de fixlist, wordt uit het register verwijderd.)




    ==================== Andere gebieden ============================


    (Momenteel is er geen automatische fix voor dit onderdeel.)


    HKU\S-1-5-21-3732487481-855672253-929003311-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\bryan77\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
    DNS Servers: 195.130.131.4 - 195.130.130.132
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
    Windows Firewall is ingeschakeld.


    ==================== MSCONFIG/TASK MANAGER Uitgeschakelde items ==


    (Momenteel is er geen automatische fix voor dit onderdeel.)


    MSCONFIG\Services: 0169601385920986mcinstcleanup => 2
    MSCONFIG\Services: MBAMScheduler => 2
    MSCONFIG\Services: MBAMService => 2
    MSCONFIG\Services: McAfee SiteAdvisor Service => 2
    MSCONFIG\Services: McAWFwk => 3
    MSCONFIG\Services: mcmscsvc => 2
    MSCONFIG\Services: McNaiAnn => 2
    MSCONFIG\Services: McNASvc => 2
    MSCONFIG\Services: McODS => 3
    MSCONFIG\Services: McOobeSv => 2
    MSCONFIG\Services: McProxy => 2
    MSCONFIG\Services: MSK80Service => 2
    MSCONFIG\startupreg: AVG_UI => "C:\Program Files (x86)\AVG\AVG2014\avgui.exe" /TRAYONLY
    MSCONFIG\startupreg: mcui_exe => "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey


    ==================== Firewall regels (gefilterd) ===============


    (Als een item is opgenomen in de fixlist, wordt uit het register verwijderd. Het bestand zal niet worden verplaatst tenzij apart vermeld.)


    FirewallRules: [TCP Query User{EBA49DCD-5C2F-4F0E-BF4F-A983FD370081}C:\program files (x86)\java\jre1.8.0_25\bin\javaw.exe] => (Block) C:\program files (x86)\java\jre1.8.0_25\bin\javaw.exe
    FirewallRules: [UDP Query User{04EF1A3B-E8E1-408D-A433-3D778365BB2A}C:\program files (x86)\java\jre1.8.0_25\bin\javaw.exe] => (Block) C:\program files (x86)\java\jre1.8.0_25\bin\javaw.exe
    FirewallRules: [TCP Query User{49B33151-1BF6-4A16-9671-A38AC8E1DA7F}D:\gta5.exe] => (Allow) D:\gta5.exe
    FirewallRules: [UDP Query User{5F17BCE1-5BAB-4AF9-BC8C-2031EEA73D41}D:\gta5.exe] => (Allow) D:\gta5.exe
    FirewallRules: [TCP Query User{21411C96-5716-44DB-97AE-6AAFEBC0D31B}C:\users\bryan\appdata\roaming\spotify\spotify.exe] => (Block) C:\users\bryan\appdata\roaming\spotify\spotify.exe
    FirewallRules: [UDP Query User{921FF2AA-205F-4238-912D-AC80D00B83E6}C:\users\bryan\appdata\roaming\spotify\spotify.exe] => (Block) C:\users\bryan\appdata\roaming\spotify\spotify.exe
    FirewallRules: [TCP Query User{B9BE8C40-DEBE-49C5-AE3A-E1498EAB80DA}C:\program files (x86)\java\jre1.8.0_45\bin\java.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_45\bin\java.exe
    FirewallRules: [UDP Query User{5D64D027-EE91-41AD-A490-E62C7653EB88}C:\program files (x86)\java\jre1.8.0_45\bin\java.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_45\bin\java.exe
    FirewallRules: [{7129689C-CE17-4737-BACC-4DDF25C9B34C}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
    FirewallRules: [{96E25971-D876-4129-9C15-D8EA0429C079}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
    FirewallRules: [{4660A62B-8C06-4943-B5FB-280CA615DFE6}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
    FirewallRules: [{B035D7DF-7034-477E-9AE9-5129C494ECBD}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
    FirewallRules: [{4A8DF4BB-2F8C-43C7-A9E4-CE99882730D1}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
    FirewallRules: [{CDE4D536-EAC6-4FB2-85A0-4E4F871B922D}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
    FirewallRules: [{8FE3476B-6184-441D-8C96-2CA1DD32DBE9}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
    FirewallRules: [{9531F97E-338F-4533-B4BB-9A32D6B4764D}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
    FirewallRules: [TCP Query User{D3C51161-AB03-4053-B366-DBB01F6DA1A0}C:\program files\java\jre1.8.0_65\bin\javaw.exe] => (Block) C:\program files\java\jre1.8.0_65\bin\javaw.exe
    FirewallRules: [UDP Query User{6E6E1AC3-B769-4DB0-92AE-80A9159BD7AE}C:\program files\java\jre1.8.0_65\bin\javaw.exe] => (Block) C:\program files\java\jre1.8.0_65\bin\javaw.exe
    FirewallRules: [TCP Query User{074F5DDC-5183-44DA-9FF2-431BE3FFFC2F}C:\program files\java\jre1.8.0_65\bin\java.exe] => (Allow) C:\program files\java\jre1.8.0_65\bin\java.exe
    FirewallRules: [UDP Query User{E9A707DB-5A5F-4F63-8681-AC8E2BE7CD33}C:\program files\java\jre1.8.0_65\bin\java.exe] => (Allow) C:\program files\java\jre1.8.0_65\bin\java.exe
    FirewallRules: [{2DE804F1-AC29-4FB5-94DF-36F6A75EACED}] => (Allow) C:\Program Files (x86)\AVG\Av\avgnsa.exe
    FirewallRules: [{77499CE2-A253-4185-9452-710444A30D0B}] => (Allow) C:\Program Files (x86)\AVG\Av\avgnsa.exe
    FirewallRules: [{066B187D-8C61-4F4E-B9F8-DFC85CDBC716}] => (Allow) C:\Program Files (x86)\AVG\Av\avgdiagex.exe
    FirewallRules: [{EFCE7FCC-F7CB-488A-A1C0-D7DEC8997440}] => (Allow) C:\Program Files (x86)\AVG\Av\avgdiagex.exe
    FirewallRules: [{905DB3C3-6451-4918-B8F7-9C981A9D58C8}] => (Allow) C:\Program Files (x86)\AVG\Av\avgmfapx.exe
    FirewallRules: [{6AF2248B-6DD9-45C1-BBA6-813BE5C012A0}] => (Allow) C:\Program Files (x86)\AVG\Av\avgmfapx.exe
    FirewallRules: [{DA86E969-765A-4B2D-8FAA-9CFB8BA80912}] => (Allow) C:\Program Files (x86)\AVG\Av\avgemca.exe
    FirewallRules: [{FBD3498B-8E7B-499C-9BA1-43501E3FBDE1}] => (Allow) C:\Program Files (x86)\AVG\Av\avgemca.exe
    FirewallRules: [{AF1F6EDE-83D3-402B-B0B2-36DC8459BE07}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe


    ==================== Defecte Apparaatbeheer Apparaten =============




    ==================== Eventlog fouten: =========================


    Applicatiefouten:
    ==================
    Error: (12/05/2015 11:05:48 PM) (Source: CVHSVC) (EventID: 100) (User: )
    Description: Alleen informatie.
    (Patch task for {90140011-0066-0413-0000-0000000FF1CE}): DownloadLatest Failed:


    Error: (12/05/2015 10:50:31 PM) (Source: VSS) (EventID: 8194) (User: )
    Description: Fout in de Volume Shadow Copy-service: onverwachte fout bij het uitvoeren van een query voor de IVssWriterCallback-interface. hr = 0x80070005, Toegang geweigerd.
    .
    Dit wordt vaak veroorzaakt door onjuiste beveiligingsinstellingen in het writer- of requestorproces.




    Bewerking:
    Schrijvergegevens verzamelen


    Context:
    Klasse-id van schrijver: {e8132975-6f93-4464-a53e-1050253ae220}
    Naam van schrijver: System Writer
    Instantie-id van schrijver: {a793fd06-b9d4-4afe-b542-7038794c4eea}


    Error: (12/05/2015 10:41:42 PM) (Source: Application Error) (EventID: 1000) (User: )
    Description: Naam van toepassing met fout: Explorer.EXE, versie: 6.1.7601.17567, tijdstempel: 0x4d672ee4
    Naam van module met fout: unknown, versie: 0.0.0.0, tijdstempel: 0x00000000
    Uitzonderingscode: 0xc0000005
    Foutoffset: 0x0000000000000000
    Id van proces met fout: 0x10dc
    Starttijd van toepassing met fout: 0xExplorer.EXE0
    Pad naar toepassing met fout: Explorer.EXE1
    Pad naar module met fout: Explorer.EXE2
    Rapport-id: Explorer.EXE3


    Error: (12/05/2015 11:35:11 AM) (Source: CVHSVC) (EventID: 100) (User: )
    Description: Alleen informatie.
    (Patch task for {90140011-0066-0413-0000-0000000FF1CE}): DownloadLatest Failed:


    Error: (12/05/2015 08:50:49 AM) (Source: CVHSVC) (EventID: 100) (User: )
    Description: Alleen informatie.
    (Patch task for {90140011-0066-0413-0000-0000000FF1CE}): DownloadLatest Failed:


    Error: (12/04/2015 03:13:19 PM) (Source: CVHSVC) (EventID: 100) (User: )
    Description: Alleen informatie.
    (Patch task for {90140011-0066-0413-0000-0000000FF1CE}): DownloadLatest Failed:


    Error: (12/04/2015 01:29:51 PM) (Source: CVHSVC) (EventID: 100) (User: )
    Description: Alleen informatie.
    (Patch task for {90140011-0066-0413-0000-0000000FF1CE}): DownloadLatest Failed:


    Error: (12/04/2015 01:07:57 PM) (Source: CVHSVC) (EventID: 100) (User: )
    Description: Alleen informatie.
    (Patch task for {90140011-0066-0413-0000-0000000FF1CE}): DownloadLatest Failed:


    Error: (12/02/2015 04:04:04 PM) (Source: CVHSVC) (EventID: 100) (User: )
    Description: Alleen informatie.
    (Patch task for {90140011-0066-0413-0000-0000000FF1CE}): DownloadLatest Failed:


    Error: (12/02/2015 03:38:01 PM) (Source: CVHSVC) (EventID: 100) (User: )
    Description: Alleen informatie.
    (Patch task for {90140011-0066-0413-0000-0000000FF1CE}): DownloadLatest Failed:




    Systeemfouten:
    =============
    Error: (12/05/2015 10:53:49 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT AUTHORITY)
    Description: WLAN-uitbreidingsmodule is onverwacht gestopt.


    Pad naar module: C:\Program Files (x86)\Qualcomm Atheros WiFi Driver Installation\AthIhvWlanExt.dll


    Error: (12/05/2015 10:53:49 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT AUTHORITY)
    Description: WLAN-uitbreidingsmodule is onverwacht gestopt.


    Pad naar module: C:\Program Files (x86)\Qualcomm Atheros WiFi Driver Installation\AthIhvWlanExt.dll


    Error: (12/05/2015 10:53:38 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT AUTHORITY)
    Description: WLAN-uitbreidingsmodule is onverwacht gestopt.


    Pad naar module: C:\Program Files (x86)\Qualcomm Atheros WiFi Driver Installation\AthIhvWlanExt.dll


    Error: (12/05/2015 10:51:34 PM) (Source: Service Control Manager) (EventID: 7032) (User: )
    Description: Servicebesturingsbeheer heeft na het onverwachte afsluiten van de Windows Search-service geprobeerd een herstelactie (Service opnieuw starten) uit te voeren, maar deze actie is met de volgende fout mislukt:
    %%1056


    Error: (12/05/2015 10:51:09 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
    Description: De Application Virtualization Client-service is onverwacht beŽindigd. Dit is nu 1 keer gebeurd.


    Error: (12/05/2015 10:51:05 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
    Description: De Windows Presentation Foundation Font Cache 3.0.0.0-service is onverwacht gestopt. Dit is 1 keer gebeurd. De volgende herstelbewerking zal over 0 milliseconden worden uitgevoerd: Service opnieuw starten.


    Error: (12/05/2015 10:51:04 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
    Description: De VIA Karaoke digital mixer Service-service is onverwacht beŽindigd. Dit is nu 1 keer gebeurd.


    Error: (12/05/2015 10:51:04 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
    Description: De Windows Live ID Sign-in Assistant-service is onverwacht gestopt. Dit is 1 keer gebeurd. De volgende herstelbewerking zal over 10000 milliseconden worden uitgevoerd: Service opnieuw starten.


    Error: (12/05/2015 10:51:04 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
    Description: De Client Virtualization Handler-service is onverwacht beŽindigd. Dit is nu 1 keer gebeurd.


    Error: (12/05/2015 10:51:04 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
    Description: De Windows Media Player Network Sharing Service-service is onverwacht gestopt. Dit is 1 keer gebeurd. De volgende herstelbewerking zal over 30000 milliseconden worden uitgevoerd: Service opnieuw starten.




    ==================== Geheugen info ===========================


    Processor: Intel(R) Pentium(R) CPU B970 @ 2.30GHz
    Percentage geheugen in gebruik: 58%
    Totaal fysiek RAM-geheugen: 3979.96 MB
    Beschikbaar fysiek RAM-geheugen: 1667.87 MB
    Totaal Virtueel geheugen: 8258.13 MB
    Beschikbaar Virtual geheugen: 5910.52 MB


    ==================== Schijven ================================


    Drive c: (OS) (Fixed) (Total:119.24 GB) (Free:45.1 GB) NTFS ==>[systeem met boot componenten (verkregen van schijf)]
    Drive d: (DATA) (Fixed) (Total:153.53 GB) (Free:153.42 GB) NTFS


    ==================== MBR & Partitietabel ==================


    ========================================================
    Disk: 0 (Size: 298.1 GB) (Disk ID: 30EC77D9)


    Partition: GPT.


    ==================== Eind van Addition.txt ============================

  19. #19
    Corrine's Avatar
    Join Date
    Feb 2012
    Location
    Upstate, NY
    Posts
    9,056

    Re: startpage changed, commercials on screen

    Wow! The first time FRST ran, it removed 6.3 GB temp data. This last time it was another 1.3 GB temp data was removed.

    Good catch, haramo! I forgot to include saving the script as Unicode in the instructions. That said, what FRST did was remove the "unhidie" the entries so that you should now be able to uninstall any of the following that you do not want on the computer:

    Συλλογή φωτογραφιών (HKLM-x32\...\{032CB0D7-FDBF-4CA9-901B-A4C1B01B1777}) (Version: 16.4.3508.0205 - Microsoft Corporation)
    Основные компоненты Windows Live (HKLM-x32\...\{7A9122B2-CF90-4ACB-8E10-AA83F725916B}) (Version: 16.4.3508.0205 - Microsoft Corporation)
    Почта Windows Live (HKLM-x32\...\{44B4333A-60A6-4FFC-BCC5-B0ECA23D2AAB}) (Version: 16.4.3508.0205 - Корпорация Майкрософт)
    Фотоальбом (HKLM-x32\...\{CE4EEFE0-85E0-436E-95C5-BCB2EE30C976}) (Version: 16.4.3508.0205 - Microsoft Corporation)
    Фотографии (общедоступная версия) (HKLM-x32\...\{234BD64C-99F4-42B5-837F-82F00E37A7E1}) (Version: 16.4.3508.0205 - Microsoft Corporation)
    גלריית התמונות (HKLM-x32\...\{B1AC8AF0-2979-4DF8-AE26-B1D543F3543F}) (Version: 16.4.3508.0205 - Microsoft Corporation)
    بريد Windows Live (HKLM-x32\...\{7A546E5C-0906-42CC-92DF-B2E787FFA7D2}) (Version: 16.4.3508.0205 - Microsoft Corporation)
    معرض الصور (HKLM-x32\...\{6F77C156-7660-4CEC-8793-97D80D5BFEC0}) (Version: 16.4.3508.0205 - Microsoft Corporation)
    影像中心 (HKLM-x32\...\{7DB15F28-5E38-476A-A773-EA07EAEAB1B3}) (Version: 16.4.3508.0205 - Microsoft Corporation)

    Please let me know how the computer is running now.
    Evyatar says thanks for this.


    Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

    Remember - A day without laughter is a day wasted.
    May the wind sing to you and the sun rise in your heart.

  20. #20

    Re: startpage changed, commercials on screen

    no commercials anymore, but still very slow.

    also last days laptop turns itself off, strange.

    will try to uninstall the list with foreing languages.

Page 1 of 2 12 Last

Similar Threads

  1. Four ways to bypass the Windows 8 startpage
    By zigzag3143 in forum Microsoft News
    Replies: 0
    Last Post: 08-29-2012, 03:20 AM
  2. [SOLVED] video / desktop has changed, cant see start bar or left side of screen
    By one_unique_guy in forum Windows 7 | Windows Vista
    Replies: 7
    Last Post: 05-16-2012, 10:17 AM

Log in

Log in