Computer Forum voor al uw vragen en problemen.

Register een gratis account om van alle functies op het forum gebruik te kunnen maken.

Problemen met uw computer, of heeft u advies nodig? PC Web Plus helpt u graag verder.

Welkom op PC Web Plus, op dit computerforum kunt u terecht voor gratis hulp bij computerproblemen en allerhande vragen over software, hardware en computerbeveiliging.

Als gast kunt u alleen het forum bekijken en meelezen met de verschillende discussies. U kunt echter geen reacties of commentaar geven op bestaande discussies, of nieuwe onderwerpen op het forum starten met uw vraag of probleem.

Klik op de onderstaande link om geheel gratis een gebruikersaccount op ons forum te registreren. Vanaf dat moment kunt u deelnemen aan de diverse discussies op het forum.

Klik hier om een gratis account te registreren! - of lees onze Welkomstgids door voor meer informatie over het gebruik van het forum.

 
nuuub
PC Web Plus - Member
PC Web Plus - Member
Onderwerp Auteur
Berichten: 20
Lid geworden op: zo 25 okt, 2015 19:40:44
Kennisniveau: (3) Expert
OS: windows
AV: avg
AM: superantispyware
FW: avg

continue live installation shit

zo 25 okt, 2015 19:49:10

Heb sinds vanmiddag na het downloaden van divx voor windows media player last van malware, adware en andere ongewenste software. het installeert automatisch nieuwe software ongevraagd, pop-ups etc...

heb malwarebytes anti-malware en rsit uitgevoerd. Zie log-files onderstaand (in de log-files is mijn naam vervangen door streepjes "-------").

Logfile of random's system information tool 1.10 (written by random/random)
Run by --------- at 2015-10-25 19:26:35
Microsoft Windows 8.1
System drive C: has 13 GB (11%) free of 122 GB
Total RAM: 3982 MB (58% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 19:26:52, on 25-10-2015
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.17840)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
C:\Windows\SysWOW64\ACEngSvr.exe
C:\PROGRA~2\AVG\AVG8\avgtray.exe
C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x86\QuickGesture.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: Skype for Business Click to Call BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O2 - BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\PROGRA~2\MICROS~1\Office15\GROOVEEX.DLL
O4 - HKCU\..\Run: [AVG-Secure-Search-Update_1213b] C:\Users\-------\AppData\Roaming\AVG 1213b Campaign\AVG-Secure-Search-Update-1213b.exe /PROMPT /mid=0ad2ebd4570847d3a1ead929287094b5-73440893cb96ed969db31e71e22350bc29e1ac33 /CMPID=1213b
O4 - HKCU\..\Run: [OneDrive] "C:\Users\-------------\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
O4 - HKCU\..\Run: [GoogleChromeAutoLaunch_BC5241188ADF05F5293078119CA0F67C] "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --no-startup-window
O4 - HKUS\S-1-5-18\..\Run: [Autodesk Sync] C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Autodesk Sync] C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe (User 'Default user')
O8 - Extra context menu item: &Verzenden naar OneNote - res://C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office15\EXCEL.EXE/3000
O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~1\MICROS~1\Office15\ONBttnIE.dll/105
O9 - Extra button: Verzenden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Verzenden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra button: Lync - klikken om te bellen - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O9 - Extra 'Tools' menuitem: Lync - klikken om te bellen - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O9 - Extra button: &Gekoppelde notities van OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: &Gekoppelde notities van OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {8A5BE387-D09A-4DFA-A56B-DCB89BD11468} (20-20 3D Viewer for WEB) - http://tulp.keukencreator.nl/generic/Co ... _Win32.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG8\avgpp.dll
O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files (x86)\Microsoft Office\Office15\MSOSB.DLL
O18 - Filter hijack: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\MSOXMLMF.DLL
O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
O23 - Service: AFBAgent - Unknown owner - C:\Windows\system32\FBAgent.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: ASLDR Service (ASLDRService) - ASUSTek Computer Inc. - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
O23 - Service: ASUS InstantOn Service (ASUS InstantOn) - ASUS - C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe
O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - ASUS - C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
O23 - Service: Autodesk Content Service - Autodesk, Inc. - C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~2\AVG\AVG8\avgwdsvc.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: EPSON V3 Service4(01) (EPSON_PM_RPCV4_01) - SEIKO EPSON CORPORATION - C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RPB.EXE
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: FlexNet Licensing Service 64 - Flexera Software LLC - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe
O23 - Service: Google Update-service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update-service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: IconMan_R - Realsil Microelectronics Inc. - C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\WINDOWS\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) ME Service - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: MBAMService - Malwarebytes - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 10916 bytes

======Listing Processes======

 
nuuub
PC Web Plus - Member
PC Web Plus - Member
Onderwerp Auteur
Berichten: 20
Lid geworden op: zo 25 okt, 2015 19:40:44
Kennisniveau: (3) Expert
OS: windows
AV: avg
AM: superantispyware
FW: avg

Re: continue live installation shit

zo 25 okt, 2015 19:52:00

Hierbij nog een log-file (paste niet in het vorige bericht vanwege max. aantal leestekens per bericht) :

wininit.exe

winlogon.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k RPCSS
"dwm.exe"
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k NetworkService
"C:\Windows\system32\FBAgent.exe"
C:\WINDOWS\System32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
C:\WINDOWS\System32\svchost.exe -k utcsvc
dashost.exe {ebaa0a58-feb5-4ee9-99ca4f33cfac913b}
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\WINDOWS\System32\svchost.exe -k LocalServicePeerNet
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\DllHost.exe /Processid:{30D49246-D217-465F-B00B-AC9DDD652EB7}
taskhostex.exe
C:\WINDOWS\Explorer.EXE
"C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE"
"C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe"
KBFiltr.exe
"C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe"
"C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe"
"C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnWMI.exe"
"C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe"
"C:\Program Files (x86)\ASUS\Splendid\ACMON.exe"
"C:\Windows\SysWOW64\ACEngSvr.exe" -Embedding
"C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe"
"C:\PROGRA~2\AVG\AVG8\avgtray.exe"
C:\PROGRA~2\AVG\AVG8\avgwdsvc.exe
"C:\WINDOWS\system32\hkcmd.exe"
"C:\WINDOWS\system32\igfxsrvc.exe" -Embedding
avgam.exe
avgrsa.exe
avgnsa.exe
"C:\WINDOWS\system32\igfxtray.exe"
"C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RPB.EXE"
"C:\WINDOWS\system32\igfxpers.exe"
"C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
C:\WINDOWS\system32\SearchIndexer.exe /Embedding
"C:\Program Files\ASUS\P4G\BatteryLife.exe"
"C:\Program Files\Intel\iCLS Client\HeciServer.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe"
C:\Windows\System32\skydrive.exe -Embedding
"C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLoader.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x64\QuickGesture64.exe"
"C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x86\QuickGesture.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"
"C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPCenter.exe"
"C:\Program Files (x86)\Google\Update\1.3.28.15\GoogleCrashHandler.exe"
"C:\Program Files (x86)\Google\Update\1.3.28.15\GoogleCrashHandler64.exe"
"C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPHelper.exe"
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\WINDOWS\System32\Taskmgr.exe" /3
"C:\Windows\System32\SettingSyncHost.exe" -Embedding
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="2184.0.1044175873\1659441401" --supports-dual-gpus=false --gpu-driver-bug-workarounds=2,20,45 --disable-accelerated-video-decode --gpu-vendor-id=0x8086 --gpu-device-id=0x0156 --gpu-driver-vendor="Intel Corporation" --gpu-driver-version=10.18.10.3308 --ignored=" --type=renderer " /prefetch:822062411
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=nl --force-fieldtrials="AffiliationBasedMatching/Enabled/AppBannerTriggering/Control/AudioProcessing48kHzSupport/Default/*AutofillClassifier/Enabled/CaptivePortalInterstitial/Enabled/*ChildAccountDetection/Disabled/ChromeDashboard/Default/ChromotingQUIC/Disabled/*ClientSideDetectionModel/Model0/*DomRel-Enable/enable/*EmbeddedSearch/Group10 pct:1a stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableGoogleCachedCopyTextExperiment/Button/EnableSessionCrashedBubbleUI/Enabled/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/*GoogleNow/Enable/*IconNTP/Default/InstanceID/Enabled/IntelligentSessionRestore/Enabled2/*NetworkQualityEstimator/Enabled/*NewProfileManagement/Enabled/NewVideoRendererTrial/Enabled/*OmniboxBundledExperimentV1/Unused_2/*PasswordGeneration/Disabled/PasswordLinkInSettings/Enabled/*PluginPowerSaver/Enabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/FlagDisabled/RefreshTokenDeviceId/Enabled/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/Off/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingReportPhishingErrorLink/Disabled/SafeBrowsingSocialEngineeringStrings/Enabled/*SdchPersistence/Disabled/SessionRestoreBackgroundLoading/Restore/SlimmingPaint/EnableSlimmingPaint/SyncBackingDatabase32K/Enabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_01/*UMA-Uniformity-Trial-50-Percent/default/*UseDelayAgnosticAEC/DefaultEnabled/VarationsServiceControl/Interval_30min/VoiceTrigger/Install/WebRTC-UDPSocketNonBlockingIO/Default/" --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-delegated-renderer --num-raster-threads=1 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553 --disable-accelerated-video-decode --channel="2184.1.1129687291\1163667144" --font-cache-shared-handle=2060 /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=nl --force-fieldtrials="AffiliationBasedMatching/Enabled/AppBannerTriggering/Control/AudioProcessing48kHzSupport/Default/*AutofillClassifier/Enabled/CaptivePortalInterstitial/Enabled/*ChildAccountDetection/Disabled/ChromeDashboard/Default/ChromotingQUIC/Disabled/*ClientSideDetectionModel/Model0/*DomRel-Enable/enable/*EmbeddedSearch/Group10 pct:1a stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableGoogleCachedCopyTextExperiment/Button/EnableSessionCrashedBubbleUI/Enabled/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/*GoogleNow/Enable/*IconNTP/Default/InstanceID/Enabled/*IntelligentSessionRestore/Enabled2/*NetworkQualityEstimator/Enabled/*NewProfileManagement/Enabled/NewVideoRendererTrial/Enabled/*OmniboxBundledExperimentV1/Unused_2/*PasswordGeneration/Disabled/PasswordLinkInSettings/Enabled/*PluginPowerSaver/Enabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/FlagDisabled/RefreshTokenDeviceId/Enabled/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/Off/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingReportPhishingErrorLink/Disabled/SafeBrowsingSocialEngineeringStrings/Enabled/*SdchPersistence/Disabled/SessionRestoreBackgroundLoading/Restore/*SlimmingPaint/EnableSlimmingPaint/SyncBackingDatabase32K/Enabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_01/*UMA-Uniformity-Trial-50-Percent/default/*UseDelayAgnosticAEC/DefaultEnabled/VarationsServiceControl/Interval_30min/VoiceTrigger/Install/WebRTC-UDPSocketNonBlockingIO/Default/" --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-delegated-renderer --num-raster-threads=1 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553 --disable-accelerated-video-decode --channel="2184.2.872266928\1031067489" --font-cache-shared-handle=2236 /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=nl --force-fieldtrials="AffiliationBasedMatching/Enabled/AppBannerTriggering/Control/AudioProcessing48kHzSupport/Default/*AutofillClassifier/Enabled/CaptivePortalInterstitial/Enabled/*ChildAccountDetection/Disabled/ChromeDashboard/Default/ChromotingQUIC/Disabled/*ClientSideDetectionModel/Model0/*DomRel-Enable/enable/*EmbeddedSearch/Group10 pct:1a stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableGoogleCachedCopyTextExperiment/Button/EnableSessionCrashedBubbleUI/Enabled/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/*GoogleNow/Enable/*IconNTP/Default/InstanceID/Enabled/*IntelligentSessionRestore/Enabled2/*NetworkQualityEstimator/Enabled/*NewProfileManagement/Enabled/NewVideoRendererTrial/Enabled/*OmniboxBundledExperimentV1/Unused_2/*PasswordGeneration/Disabled/PasswordLinkInSettings/Enabled/*PluginPowerSaver/Enabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/FlagDisabled/*RefreshTokenDeviceId/Enabled/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/Off/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingReportPhishingErrorLink/Disabled/SafeBrowsingSocialEngineeringStrings/Enabled/*SdchPersistence/Disabled/SessionRestoreBackgroundLoading/Restore/*SlimmingPaint/EnableSlimmingPaint/SyncBackingDatabase32K/Enabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_01/*UMA-Uniformity-Trial-50-Percent/default/*UseDelayAgnosticAEC/DefaultEnabled/*VarationsServiceControl/Interval_30min/VoiceTrigger/Install/WebRTC-UDPSocketNonBlockingIO/Default/" --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-delegated-renderer --num-raster-threads=1 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553 --disable-accelerated-video-decode --channel="2184.3.421807437\1505660024" --font-cache-shared-handle=2296 /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=nl --force-fieldtrials="AffiliationBasedMatching/Enabled/AppBannerTriggering/Control/AudioProcessing48kHzSupport/Default/*AutofillClassifier/Enabled/CaptivePortalInterstitial/Enabled/*ChildAccountDetection/Disabled/ChromeDashboard/Default/ChromotingQUIC/Disabled/*ClientSideDetectionModel/Model0/*DomRel-Enable/enable/*EmbeddedSearch/Group10 pct:1a stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableGoogleCachedCopyTextExperiment/Button/EnableSessionCrashedBubbleUI/Enabled/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/*GoogleNow/Enable/*IconNTP/Default/InstanceID/Enabled/*IntelligentSessionRestore/Enabled2/*NetworkQualityEstimator/Enabled/*NewProfileManagement/Enabled/NewVideoRendererTrial/Enabled/*OmniboxBundledExperimentV1/Unused_2/*PasswordGeneration/Disabled/PasswordLinkInSettings/Enabled/*PluginPowerSaver/Enabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/FlagDisabled/*RefreshTokenDeviceId/Enabled/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/Off/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingReportPhishingErrorLink/Disabled/SafeBrowsingSocialEngineeringStrings/Enabled/*SdchPersistence/Disabled/SessionRestoreBackgroundLoading/Restore/*SlimmingPaint/EnableSlimmingPaint/SyncBackingDatabase32K/Enabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_01/*UMA-Uniformity-Trial-50-Percent/default/*UseDelayAgnosticAEC/DefaultEnabled/*VarationsServiceControl/Interval_30min/VoiceTrigger/Install/WebRTC-UDPSocketNonBlockingIO/Default/" --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-delegated-renderer --num-raster-threads=1 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553 --disable-accelerated-video-decode --channel="2184.4.2131816502\274522201" --font-cache-shared-handle=2428 /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=nl --force-fieldtrials="AffiliationBasedMatching/Enabled/AppBannerTriggering/Control/AudioProcessing48kHzSupport/Default/*AutofillClassifier/Enabled/CaptivePortalInterstitial/Enabled/*ChildAccountDetection/Disabled/ChromeDashboard/Default/ChromotingQUIC/Disabled/*ClientSideDetectionModel/Model0/*DomRel-Enable/enable/*EmbeddedSearch/Group10 pct:1a stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableGoogleCachedCopyTextExperiment/Button/EnableSessionCrashedBubbleUI/Enabled/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/*GoogleNow/Enable/*IconNTP/Default/InstanceID/Enabled/*IntelligentSessionRestore/Enabled2/*NetworkQualityEstimator/Enabled/*NewProfileManagement/Enabled/NewVideoRendererTrial/Enabled/*OmniboxBundledExperimentV1/Unused_2/*PasswordGeneration/Disabled/PasswordLinkInSettings/Enabled/*PluginPowerSaver/Enabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/FlagDisabled/*RefreshTokenDeviceId/Enabled/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/Off/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingReportPhishingErrorLink/Disabled/SafeBrowsingSocialEngineeringStrings/Enabled/*SdchPersistence/Disabled/SessionRestoreBackgroundLoading/Restore/*SlimmingPaint/EnableSlimmingPaint/SyncBackingDatabase32K/Enabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_01/*UMA-Uniformity-Trial-50-Percent/default/*UseDelayAgnosticAEC/DefaultEnabled/*VarationsServiceControl/Interval_30min/VoiceTrigger/Install/WebRTC-UDPSocketNonBlockingIO/Default/" --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-delegated-renderer --num-raster-threads=1 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553 --disable-accelerated-video-decode --channel="2184.5.2004004358\1327276051" --font-cache-shared-handle=2568 /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=nl --force-fieldtrials="*AffiliationBasedMatching/Enabled/AppBannerTriggering/Control/AudioProcessing48kHzSupport/Default/*AutofillClassifier/Enabled/CaptivePortalInterstitial/Enabled/*ChildAccountDetection/Disabled/*ChromeDashboard/Default/ChromotingQUIC/Disabled/*ClientSideDetectionModel/Model0/*DomRel-Enable/enable/*EmbeddedSearch/Group10 pct:1a stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableGoogleCachedCopyTextExperiment/Button/EnableSessionCrashedBubbleUI/Enabled/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/*GoogleNow/Enable/*IconNTP/Default/InstanceID/Enabled/*IntelligentSessionRestore/Enabled2/*NetworkQualityEstimator/Enabled/*NewProfileManagement/Enabled/NewVideoRendererTrial/Enabled/*OmniboxBundledExperimentV1/Unused_2/*PasswordGeneration/Disabled/PasswordLinkInSettings/Enabled/*PluginPowerSaver/Enabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/FlagDisabled/*RefreshTokenDeviceId/Enabled/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/Off/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingReportPhishingErrorLink/Disabled/SafeBrowsingSocialEngineeringStrings/Enabled/*SdchPersistence/Disabled/SessionRestoreBackgroundLoading/Restore/*SlimmingPaint/EnableSlimmingPaint/SyncBackingDatabase32K/Enabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_01/*UMA-Uniformity-Trial-50-Percent/default/*UseDelayAgnosticAEC/DefaultEnabled/*VarationsServiceControl/Interval_30min/VoiceTrigger/Install/WebRTC-UDPSocketNonBlockingIO/Default/" --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-delegated-renderer --num-raster-threads=1 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553 --disable-accelerated-video-decode --channel="2184.8.1406706666\1819091165" --font-cache-shared-handle=5920 /prefetch:673131151
"C:\WINDOWS\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe2_ Global\UsGthrCtrlFltPipeMssGthrPipe2 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\WINDOWS\system32\SearchFilterHost.exe" 0 580 584 592 65536 588
C:\WINDOWS\system32\wbem\wmiprvse.exe
"C:\Users\--------\Downloads\RSITx64.exe"

======Scheduled tasks folder======

C:\WINDOWS\tasks\AutoKMS.job - C:\AutoKMS\AutoKMS.exe
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\WINDOWS\tasks\JJkobB1IDzpAmgs7fEaeu3Lz.job - C:\Users\\AppData\Roaming\JJkobB1IDzpAmgs7fEaeu3Lz.exe --c=PKySPknB2ZYuNcu6X21kalQ00GP+sWskjOy37muQAtHo2cZd7ODDjmQ3nFxlCnldk/8Xt3dKK3OYxMb1LQCxaosyKM9UrfNO/+yokVnfkURfEp1T5ISh3C+LR/7+urvk0rBgz+LnqfRwnDq8sR5JoRSaN+pHHTrPICQ/qUcJQM0nEz7CVLnwuHWQnbj+UeOufRaiAjHfSGi9fRiIPjXKKQur/h+35mYF/IeaWuGW3oaKdsESsDspV8er2ieNaPvD0BTVhOpPdBScvdyBK/EBbnGn7tDnnzvOEvGzhq2Kjm6/Rc8gHdkZGjoVzqGDqnq504Ik125dTvfPqTNHBpR1NQ==
C:\WINDOWS\tasks\SCUPMEXJRMGTLWNN.job - C:\ProgramData\Service1291\Service1291.exe
C:\WINDOWS\tasks\To9snHJTu9MfknCK2.job - C:\Users\-------\AppData\Roaming\To9snHJTu9MfknCK2.exe --c=dPvfXC99+ICoaKvB8RISXz0uCpIIRReTZQsX6SQl9AG2RrcnRBXxT6fzRYliV7/3f8gUyeMlIFQFbIVLnda58Et/OZIicA8jPqpQK6A/Ty9FJVxoYDCZOiDNAYcNuEKVdwWJi6vuQkXkAiuGLTnI2OEsHhA1wKk3md5MCruoskE6IZL2Ea/YMgSQc3zMqfQZCtkRpDZkFx5Fc3hwQs99NgHqIooMGmr2SncuQ1yNuJhPPUZSvpof74gOXjOwa40uLdtIBBDGPwyGzTjJsvwAQUrfkaZkgtTU0CANisnn7wDz8yz7qnGcGc6iBDbeYidosIjXI5XgQSvtDZDi08XJHw==
C:\WINDOWS\tasks\xrRu9rYrwaGYn5dBfmct4.job - C:\Users\--------\AppData\Roaming\xrRu9rYrwaGYn5dBfmct4.exe --c=HL7APoIYKxGKrSMM0V1cpdHpUtm3Qd/EDm2rUzlFOnXncmCMLuSvZ18CAULUh6ZQpM6CpsX7QVxVmR9bVYbS+xLs4a6PT5OIK1nrncz8klJYTrq0dfyzrq91NmfFyLeLkQOSmmh+lvFBTYJaS+Nvx+GjwrEcp8pZLFx6Fy00l0kJHy/IknASb4M/fMlzAipemh77rbV7NoLgAqaVrC29x3M2mqD7rX+hdJAwy2F9Y2EXj0cpEh8WVqoyOp1SeY5fLSPGwn/lCodXRAKPKyP8JAdvXTI27zk2NVdFurA6gIltP/W3cd4dO4LJrF+Z3uL5rNTLL+IVLCKWDVABSOoC/Q==

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Skype for Business Browser Helper - C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2015-09-29 219304]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft SkyDrive Pro Browser Helper - C:\PROGRA~1\MICROS~1\Office15\GROOVEEX.DLL [2015-09-15 2339032]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Skype for Business Browser Helper - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2015-09-29 153768]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL [2013-03-06 562904]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft SkyDrive Pro Browser Helper - C:\PROGRA~2\MICROS~1\Office15\GROOVEEX.DLL [2015-09-15 1733240]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG-Secure-Search-Update_1213b"=C:\Users\---------\AppData\Roaming\AVG 1213b Campaign\AVG-Secure-Search-Update-1213b.exe /PROMPT /mid=0ad2ebd4570847d3a1ead929287094b5-73440893cb96ed969db31e71e22350bc29e1ac33 /CMPID=1213b []
"OneDrive"=C:\Users\--------\AppData\Local\Microsoft\OneDrive\OneDrive.exe [2015-10-04 405584]
"GoogleChromeAutoLaunch_BC5241188ADF05F5293078119CA0F67C"=C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [2015-10-09 811848]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ACMON]
C:\Program Files (x86)\ASUS\Splendid\ACMON.exe [2012-08-24 107192]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Akamai NetSession Interface]
C:\Users\-----------\AppData\Local\Akamai\netsession_win.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASUSWebStorage]
C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.9.120\AsusWSPanel.exe [2012-08-28 3417984]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Autodesk Sync]
C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe [2013-02-05 1081224]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG8_TRAY]
C:\PROGRA~2\AVG\AVG8\avgtray.exe [2015-01-31 2042208]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG_UI]
C:\Program Files (x86)\AVG\AVG2014\avgui.exe /TRAYONLY []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BlueStacks Agent]
C:\Program Files (x86)\BlueStacks\HD-Agent.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\chromebrowser]
C:\WINDOWS\chromebrowser.exe [2015-10-25 1850117]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite Automount]
C:\Program Files\DAEMON Tools Lite\DTAgent.exe -autorun []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Pro Agent]
C:\Program Files (x86)\DAEMON Tools Pro\DTAgent.exe -autorun []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Ultra Agent]
C:\Program Files (x86)\DAEMON Tools Ultra\DTAgent.exe -autorun []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DisableS3S4]
c:\windows\temp\DisableS3S464\sethigh.cmd []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXMediaServer]
C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate]
C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe /CHECKNOW []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EPSON Stylus DX4000]
C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIBEE.EXE [2007-10-09 213504]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EPSON Stylus DX4000 Series]
C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_IATIBEE.EXE [2007-10-09 213504]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Everything]
C:\Program Files (x86)\Everything\Everything.exe -startup []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GarminExpressTrayApp]
C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\gmsd_nl_005010123]
C:\Program Files (x86)\gmsd_nl_005010123\gmsd_nl_005010123.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GoogleChromeAutoLaunch_A5C151045E29D23696D8D17733E9EDF3]
C:\Program Files (x86)\MyBrowser\MyBrowser\Application\mybrowser.exe --no-startup-window []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GoogleChromeAutoLaunch_BC5241188ADF05F5293078119CA0F67C]
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [2015-10-09 811848]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
C:\WINDOWS\system32\hkcmd.exe [2013-10-01 771032]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
C:\WINDOWS\system32\igfxtray.exe [2013-10-01 391128]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mcui_exe]
C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MFARestart]
C:\ProgramData\MFAData\pack\avgrunasx.exe /usereg []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence]
C:\WINDOWS\system32\igfxpers.exe [2013-10-01 769496]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDVCPL]
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2012-09-28 13197456]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SmartWeb]
C:\Users\--------\AppData\Local\SmartWeb\SmartWebHelper.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [2012-11-01 5629312]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent]
C:\Users\----------\AppData\Roaming\uTorrent\uTorrent.exe [2015-10-13 1822048]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\vProt]
C:\Program Files (x86)\AVG SafeGuard toolbar\vprot.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^----------^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Dropbox.lnk]
/systemstartup []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxdev.dll [2013-10-01 623104]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\!SASCORE]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\acwfp]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"EnableLUA"=0
"ConsentPromptBehaviorAdmin"=0
"PromptOnSecureDesktop"=0

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
""=
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"VIDC.YUY2"=msyuv.dll
"vidc.i420"=iyuv_32.dll
"msacm.msgsm610"=msgsm32.acm
"msacm.msg711"=msg711.acm
"VIDC.YVYU"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"wavemapper"=msacm32.drv
"midimapper"=midimap.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"vidc.msvc"=msvidc32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
.scr - open - C:\WINDOWS\system32\notepad.exe "%1"
.scr - install -
.scr - config -

======List of files/folders created in the last 1 month======

2015-10-25 19:26:35 ----D---- C:\rsit
2015-10-25 19:26:35 ----D---- C:\Program Files\trend micro
2015-10-25 19:20:45 ----D---- C:\Program Files (x86)\mbot_nl_014010123
2015-10-25 19:17:16 ----A---- C:\WINDOWS\SYSWOW64\acovcnt.exe
2015-10-25 17:59:12 ----A---- C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys
2015-10-25 17:58:52 ----D---- C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-10-25 17:58:52 ----A---- C:\WINDOWS\system32\drivers\mwac.sys
2015-10-25 17:58:52 ----A---- C:\WINDOWS\system32\drivers\mbamchameleon.sys
2015-10-25 17:58:52 ----A---- C:\WINDOWS\system32\drivers\mbam.sys
2015-10-25 16:48:54 ----D---- C:\Program Files (x86)\globalUpdate
2015-10-25 16:48:53 ----A---- C:\ProgramData\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat
2015-10-25 16:47:26 ----D---- C:\Program Files (x86)\Fast-Search
2015-10-25 16:46:27 ----D---- C:\ProgramData\28341ff220e0446c9fff27c4493d622e
2015-10-25 16:39:31 ----D---- C:\Program Files (x86)\Super Optimizer
2015-10-25 16:38:15 ----D---- C:\Users\--------\AppData\Roaming\Opera Software
2015-10-25 16:36:34 ----D---- C:\Program Files (x86)\Opera
2015-10-25 16:33:07 ----D---- C:\Users\----------\AppData\Roaming\DivX
2015-10-25 16:30:33 ----A---- C:\WINDOWS\chromebrowser.exe
2015-10-16 21:28:42 ----A---- C:\WINDOWS\system32\invagent.dll
2015-10-16 21:28:42 ----A---- C:\WINDOWS\system32\generaltel.dll
2015-10-16 21:28:42 ----A---- C:\WINDOWS\system32\devinv.dll
2015-10-16 21:28:42 ----A---- C:\WINDOWS\system32\CompatTelRunner.exe
2015-10-16 21:28:42 ----A---- C:\WINDOWS\system32\appraiser.dll
2015-10-16 21:28:42 ----A---- C:\WINDOWS\system32\aeinv.dll
2015-10-16 21:28:41 ----A---- C:\WINDOWS\system32\acmigration.dll
2015-10-16 21:27:15 ----A---- C:\WINDOWS\SYSWOW64\KernelBase.dll
2015-10-16 21:27:15 ----A---- C:\WINDOWS\SYSWOW64\advapi32.dll
2015-10-16 21:27:15 ----A---- C:\WINDOWS\system32\KernelBase.dll
2015-10-16 21:27:15 ----A---- C:\WINDOWS\system32\advapi32.dll
2015-10-16 21:26:54 ----A---- C:\WINDOWS\system32\NcdAutoSetup.dll
2015-10-16 21:26:53 ----A---- C:\WINDOWS\SYSWOW64\ucrtbase.dll
2015-10-16 21:26:53 ----A---- C:\WINDOWS\SYSWOW64\api-ms-win-crt-utility-l1-1-0.dll
2015-10-16 21:26:53 ----A---- C:\WINDOWS\SYSWOW64\api-ms-win-crt-time-l1-1-0.dll
2015-10-16 21:26:53 ----A---- C:\WINDOWS\SYSWOW64\api-ms-win-crt-stdio-l1-1-0.dll
2015-10-16 21:26:53 ----A---- C:\WINDOWS\SYSWOW64\api-ms-win-crt-runtime-l1-1-0.dll
2015-10-16 21:26:53 ----A---- C:\WINDOWS\SYSWOW64\api-ms-win-crt-process-l1-1-0.dll
2015-10-16 21:26:53 ----A---- C:\WINDOWS\SYSWOW64\api-ms-win-crt-private-l1-1-0.dll
2015-10-16 21:26:53 ----A---- C:\WINDOWS\SYSWOW64\api-ms-win-crt-filesystem-l1-1-0.dll
2015-10-16 21:26:53 ----A---- C:\WINDOWS\SYSWOW64\api-ms-win-crt-environment-l1-1-0.dll
2015-10-16 21:26:53 ----A---- C:\WINDOWS\SYSWOW64\api-ms-win-crt-convert-l1-1-0.dll
2015-10-16 21:26:53 ----A---- C:\WINDOWS\SYSWOW64\api-ms-win-crt-conio-l1-1-0.dll
2015-10-16 21:26:53 ----A---- C:\WINDOWS\system32\ucrtbase.dll
2015-10-16 21:26:53 ----A---- C:\WINDOWS\system32\api-ms-win-crt-utility-l1-1-0.dll
2015-10-16 21:26:53 ----A---- C:\WINDOWS\system32\api-ms-win-crt-stdio-l1-1-0.dll
2015-10-16 21:26:53 ----A---- C:\WINDOWS\system32\api-ms-win-crt-runtime-l1-1-0.dll
2015-10-16 21:26:53 ----A---- C:\WINDOWS\system32\api-ms-win-crt-process-l1-1-0.dll
2015-10-16 21:26:53 ----A---- C:\WINDOWS\system32\api-ms-win-crt-private-l1-1-0.dll
2015-10-16 21:26:53 ----A---- C:\WINDOWS\system32\api-ms-win-crt-locale-l1-1-0.dll
2015-10-16 21:26:53 ----A---- C:\WINDOWS\system32\api-ms-win-crt-environment-l1-1-0.dll
2015-10-16 21:26:53 ----A---- C:\WINDOWS\system32\api-ms-win-crt-convert-l1-1-0.dll
2015-10-16 21:26:52 ----A---- C:\WINDOWS\SYSWOW64\api-ms-win-crt-string-l1-1-0.dll
2015-10-16 21:26:52 ----A---- C:\WINDOWS\SYSWOW64\api-ms-win-crt-multibyte-l1-1-0.dll
2015-10-16 21:26:52 ----A---- C:\WINDOWS\SYSWOW64\api-ms-win-crt-math-l1-1-0.dll
2015-10-16 21:26:52 ----A---- C:\WINDOWS\SYSWOW64\api-ms-win-crt-locale-l1-1-0.dll
2015-10-16 21:26:52 ----A---- C:\WINDOWS\SYSWOW64\api-ms-win-crt-heap-l1-1-0.dll
2015-10-16 21:26:52 ----A---- C:\WINDOWS\system32\api-ms-win-crt-time-l1-1-0.dll
2015-10-16 21:26:52 ----A---- C:\WINDOWS\system32\api-ms-win-crt-string-l1-1-0.dll
2015-10-16 21:26:52 ----A---- C:\WINDOWS\system32\api-ms-win-crt-multibyte-l1-1-0.dll
2015-10-16 21:26:52 ----A---- C:\WINDOWS\system32\api-ms-win-crt-math-l1-1-0.dll
2015-10-16 21:26:52 ----A---- C:\WINDOWS\system32\api-ms-win-crt-heap-l1-1-0.dll
2015-10-16 21:26:52 ----A---- C:\WINDOWS\system32\api-ms-win-crt-filesystem-l1-1-0.dll
2015-10-16 21:26:52 ----A---- C:\WINDOWS\system32\api-ms-win-crt-conio-l1-1-0.dll
2015-10-16 21:26:27 ----A---- C:\WINDOWS\SYSWOW64\d2d1.dll
2015-10-16 21:26:26 ----A---- C:\WINDOWS\system32\d2d1.dll
2015-10-13 21:10:16 ----A---- C:\WINDOWS\system32\shell32.dll
2015-10-13 21:10:14 ----A---- C:\WINDOWS\SYSWOW64\shell32.dll
2015-10-13 21:10:11 ----A---- C:\WINDOWS\system32\ntoskrnl.exe
2015-10-13 21:10:10 ----A---- C:\WINDOWS\system32\winresume.exe
2015-10-13 21:10:10 ----A---- C:\WINDOWS\system32\winload.exe
2015-10-13 21:10:08 ----A---- C:\WINDOWS\SYSWOW64\ntdll.dll
2015-10-13 21:10:08 ----A---- C:\WINDOWS\system32\ntdll.dll
2015-10-13 21:10:08 ----A---- C:\WINDOWS\system32\fveapi.dll
2015-10-13 21:10:08 ----A---- C:\WINDOWS\system32\bdesvc.dll
2015-10-13 21:09:32 ----A---- C:\WINDOWS\system32\mshtml.dll
2015-10-13 21:09:30 ----A---- C:\WINDOWS\SYSWOW64\mshtml.dll
2015-10-13 21:09:09 ----A---- C:\WINDOWS\system32\jscript9.dll
2015-10-13 21:09:07 ----A---- C:\WINDOWS\system32\ieframe.dll
2015-10-13 21:09:05 ----A---- C:\WINDOWS\SYSWOW64\jscript9.dll
2015-10-13 21:09:04 ----A---- C:\WINDOWS\SYSWOW64\ieframe.dll
2015-10-13 21:09:02 ----A---- C:\WINDOWS\SYSWOW64\iertutil.dll
2015-10-13 21:09:02 ----A---- C:\WINDOWS\system32\wininet.dll
2015-10-13 21:09:02 ----A---- C:\WINDOWS\system32\iertutil.dll
2015-10-13 21:09:01 ----A---- C:\WINDOWS\SYSWOW64\wininet.dll
2015-10-13 21:09:01 ----A---- C:\WINDOWS\SYSWOW64\dxtmsft.dll
2015-10-13 21:09:01 ----A---- C:\WINDOWS\system32\ieui.dll
2015-10-13 21:09:01 ----A---- C:\WINDOWS\system32\dxtrans.dll
2015-10-13 21:09:01 ----A---- C:\WINDOWS\system32\dxtmsft.dll
2015-10-13 21:09:00 ----A---- C:\WINDOWS\SYSWOW64\jscript.dll
2015-10-13 21:09:00 ----A---- C:\WINDOWS\SYSWOW64\ieui.dll
2015-10-13 21:09:00 ----A---- C:\WINDOWS\SYSWOW64\dxtrans.dll
2015-10-13 21:09:00 ----A---- C:\WINDOWS\system32\urlmon.dll
2015-10-13 21:09:00 ----A---- C:\WINDOWS\system32\jscript.dll
2015-10-13 21:08:59 ----A---- C:\WINDOWS\SYSWOW64\vbscript.dll
2015-10-13 21:08:59 ----A---- C:\WINDOWS\SYSWOW64\urlmon.dll
2015-10-13 21:08:59 ----A---- C:\WINDOWS\SYSWOW64\mshtmled.dll
2015-10-13 21:08:59 ----A---- C:\WINDOWS\system32\vbscript.dll
2015-10-13 21:08:59 ----A---- C:\WINDOWS\system32\mshtmled.dll
2015-10-13 21:08:58 ----A---- C:\WINDOWS\system32\msfeeds.dll
2015-10-13 21:08:58 ----A---- C:\WINDOWS\system32\ie4uinit.exe
2015-10-13 21:08:57 ----A---- C:\WINDOWS\SYSWOW64\msfeeds.dll
2015-10-13 21:08:57 ----A---- C:\WINDOWS\system32\webcheck.dll
2015-10-13 21:08:56 ----A---- C:\WINDOWS\SYSWOW64\webcheck.dll
2015-10-13 21:08:56 ----A---- C:\WINDOWS\system32\iedkcs32.dll
2015-10-13 21:08:55 ----A---- C:\WINDOWS\SYSWOW64\MshtmlDac.dll
2015-10-13 21:08:55 ----A---- C:\WINDOWS\SYSWOW64\inetcomm.dll
2015-10-13 21:08:55 ----A---- C:\WINDOWS\SYSWOW64\iedkcs32.dll
2015-10-13 21:08:55 ----A---- C:\WINDOWS\system32\inetcomm.dll
2015-10-13 21:08:54 ----A---- C:\WINDOWS\SYSWOW64\ieapfltr.dll
2015-10-13 21:08:54 ----A---- C:\WINDOWS\system32\MshtmlDac.dll
2015-10-13 21:08:54 ----A---- C:\WINDOWS\system32\ieapfltr.dll
2015-10-13 21:06:33 ----A---- C:\WINDOWS\system32\wuaueng.dll
2015-10-13 21:06:32 ----A---- C:\WINDOWS\SYSWOW64\wuapi.dll
2015-10-13 21:06:32 ----A---- C:\WINDOWS\system32\wucltux.dll
2015-10-13 21:06:32 ----A---- C:\WINDOWS\system32\wuauclt.exe
2015-10-13 21:06:32 ----A---- C:\WINDOWS\system32\wuapi.dll
2015-10-13 21:06:31 ----A---- C:\WINDOWS\SYSWOW64\wudriver.dll
2015-10-13 21:06:31 ----A---- C:\WINDOWS\SYSWOW64\wuapp.exe
2015-10-13 21:06:31 ----A---- C:\WINDOWS\system32\WUSettingsProvider.dll
2015-10-13 21:06:31 ----A---- C:\WINDOWS\system32\wudriver.dll
2015-10-13 21:06:31 ----A---- C:\WINDOWS\system32\wuapp.exe
2015-10-13 21:06:30 ----A---- C:\WINDOWS\SYSWOW64\wuwebv.dll
2015-10-13 21:06:30 ----A---- C:\WINDOWS\system32\wuwebv.dll
2015-10-04 13:30:49 ----A---- C:\WINDOWS\SYSWOW64\InkEd.dll
2015-10-04 13:30:49 ----A---- C:\WINDOWS\system32\InkEd.dll
2015-10-04 13:30:46 ----A---- C:\WINDOWS\system32\consent.exe
2015-10-04 13:30:36 ----A---- C:\WINDOWS\system32\UtcResources.dll
2015-10-04 13:30:34 ----A---- C:\WINDOWS\system32\diagtrack.dll
2015-10-04 13:30:33 ----A---- C:\WINDOWS\SYSWOW64\tdh.dll
2015-10-04 13:30:33 ----A---- C:\WINDOWS\system32\tdh.dll
2015-10-04 13:29:58 ----A---- C:\WINDOWS\system32\msxml6.dll
2015-10-04 13:29:57 ----A---- C:\WINDOWS\SYSWOW64\msxml6.dll
2015-10-04 13:29:56 ----A---- C:\WINDOWS\SYSWOW64\msxml3.dll
2015-10-04 13:29:56 ----A---- C:\WINDOWS\system32\msxml3.dll
2015-10-04 13:27:17 ----A---- C:\WINDOWS\system32\SettingsHandlers.dll
2015-10-04 13:27:15 ----A---- C:\WINDOWS\system32\taskeng.exe
2015-10-04 13:27:15 ----A---- C:\WINDOWS\system32\schtasks.exe
2015-10-04 13:27:15 ----A---- C:\WINDOWS\system32\schedsvc.dll
2015-10-04 13:27:14 ----A---- C:\WINDOWS\SYSWOW64\taskeng.exe
2015-10-04 13:27:14 ----A---- C:\WINDOWS\SYSWOW64\schtasks.exe
2015-10-04 13:26:52 ----A---- C:\WINDOWS\system32\Windows.UI.Immersive.dll
2015-10-04 13:26:50 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Immersive.dll
2015-10-04 13:26:50 ----A---- C:\WINDOWS\system32\SettingSync.dll
2015-10-04 13:26:50 ----A---- C:\WINDOWS\system32\authui.dll
2015-10-04 13:26:49 ----A---- C:\WINDOWS\SYSWOW64\shacct.dll
2015-10-04 13:26:49 ----A---- C:\WINDOWS\SYSWOW64\SettingSync.dll
2015-10-04 13:26:49 ----A---- C:\WINDOWS\SYSWOW64\authui.dll
2015-10-04 13:26:49 ----A---- C:\WINDOWS\system32\shacct.dll
2015-10-04 13:26:46 ----A---- C:\WINDOWS\system32\profsvc.dll
2015-10-04 13:26:45 ----A---- C:\WINDOWS\SYSWOW64\gdi32.dll
2015-10-04 13:26:45 ----A---- C:\WINDOWS\system32\gdi32.dll
2015-10-04 13:26:35 ----A---- C:\WINDOWS\system32\tzsync.exe
2015-10-04 13:25:42 ----A---- C:\WINDOWS\SYSWOW64\appidapi.dll
2015-10-04 13:25:42 ----A---- C:\WINDOWS\system32\appidsvc.dll
2015-10-04 13:25:42 ----A---- C:\WINDOWS\system32\appidapi.dll
2015-10-04 13:25:12 ----A---- C:\WINDOWS\system32\win32k.sys
2015-10-04 13:25:11 ----A---- C:\WINDOWS\SYSWOW64\atmfd.dll
2015-10-04 13:25:11 ----A---- C:\WINDOWS\system32\atmfd.dll
2015-10-04 13:25:10 ----A---- C:\WINDOWS\SYSWOW64\atmlib.dll
2015-10-04 13:25:10 ----A---- C:\WINDOWS\system32\atmlib.dll

======List of files/folders modified in the last 1 month======

2015-10-25 19:26:48 ----D---- C:\WINDOWS\system32\sru
2015-10-25 19:26:36 ----D---- C:\WINDOWS\Temp
2015-10-25 19:26:35 ----RD---- C:\Program Files
2015-10-25 19:26:32 ----D---- C:\WINDOWS\Prefetch
2015-10-25 19:20:45 ----RD---- C:\Program Files (x86)
2015-10-25 19:18:21 ----A---- C:\WINDOWS\system32\ServiceFilter.ini
2015-10-25 19:18:18 ----SHD---- C:\WINDOWS\Installer
2015-10-25 19:18:17 ----SHD---- C:\Config.Msi
2015-10-25 19:18:16 ----D---- C:\WINDOWS\system32\Tasks
2015-10-25 19:18:10 ----A---- C:\WINDOWS\SYSWOW64\log.txt
2015-10-25 19:17:16 ----D---- C:\WINDOWS\SysWOW64
2015-10-25 19:16:00 ----HD---- C:\ProgramData
2015-10-25 19:15:58 ----D---- C:\WINDOWS\system32\drivers
2015-10-25 19:15:58 ----D---- C:\WINDOWS\CbsTemp
2015-10-25 19:15:04 ----D---- C:\Users\-------------\AppData\Roaming\uTorrent
2015-10-25 19:09:46 ----D---- C:\WINDOWS\Tasks
2015-10-25 17:55:38 ----D---- C:\Users\---------------\AppData\Roaming\vlc
2015-10-25 17:55:33 ----D---- C:\Program Files (x86)\VideoLAN
2015-10-25 17:43:03 ----D---- C:\ProgramData\Adobe
2015-10-25 17:43:03 ----D---- C:\Program Files (x86)\Adobe
2015-10-25 17:42:20 ----D---- C:\Program Files (x86)\3D Home Architect
2015-10-25 17:41:34 ----D---- C:\Program Files (x86)\4Videosoft Studio
2015-10-25 17:40:35 ----D---- C:\Program Files (x86)\ASUS
2015-10-25 17:38:07 ----D---- C:\Program Files (x86)\Common Files
2015-10-25 17:27:26 ----D---- C:\ProgramData\DivX
2015-10-25 17:27:25 ----D---- C:\Program Files (x86)\DivX
2015-10-25 17:22:14 ----RD---- C:\WINDOWS\System32
2015-10-25 17:16:00 ----D---- C:\WINDOWS\system32\NDF
2015-10-25 17:08:25 ----D---- C:\Program Files (x86)\ColorByNumbers
2015-10-25 17:05:35 ----D---- C:\WINDOWS\Inf
2015-10-25 17:05:35 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2015-10-25 16:55:55 ----D---- C:\WINDOWS\WinSxS
2015-10-25 16:52:45 ----D---- C:\ProgramData\Nova Development
2015-10-25 16:50:53 ----D---- C:\WINDOWS\system32\config
2015-10-25 16:44:45 ----D---- C:\WINDOWS\apppatch
2015-10-25 16:42:50 ----D---- C:\WINDOWS\AppReadiness
2015-10-25 16:42:49 ----HD---- C:\Program Files\WindowsApps
2015-10-25 16:38:53 ----D---- C:\Windows
2015-10-25 16:37:25 ----SD---- C:\Users\-----------\AppData\Roaming\Microsoft
2015-10-25 16:36:58 ----D---- C:\WINDOWS\system32\drivers\etc
2015-10-25 16:34:10 ----SD---- C:\ProgramData\Microsoft
2015-10-25 16:15:06 ----SD---- C:\WINDOWS\system32\CompatTel
2015-10-25 16:15:05 ----D---- C:\WINDOWS\system32\appraiser
2015-10-25 16:15:04 ----D---- C:\WINDOWS\system32\CodeIntegrity
2015-10-25 16:15:03 ----RD---- C:\WINDOWS\ToastData
2015-10-25 16:15:03 ----D---- C:\WINDOWS\system32\Boot
2015-10-25 16:15:02 ----D---- C:\Program Files\Internet Explorer
2015-10-25 16:15:02 ----D---- C:\Program Files (x86)\Internet Explorer
2015-10-25 16:14:59 ----D---- C:\WINDOWS\system32\nl-NL
2015-10-25 16:14:50 ----D---- C:\WINDOWS\system32\MRT
2015-10-25 16:07:35 ----A---- C:\WINDOWS\system32\MRT.exe
2015-10-25 16:06:57 ----SHD---- C:\System Volume Information
2015-10-17 04:38:47 ----D---- C:\WINDOWS\Microsoft.NET
2015-10-16 22:02:55 ----D---- C:\ProgramData\Microsoft Help
2015-10-16 21:52:26 ----A---- C:\WINDOWS\win.ini
2015-10-16 21:37:25 ----RSD---- C:\WINDOWS\assembly
2015-10-16 21:24:24 ----D---- C:\WINDOWS\system32\catroot2
2015-10-16 05:51:29 ----A---- C:\WINDOWS\SYSWOW64\FlashPlayerApp.exe
2015-10-11 18:20:57 ----D---- C:\WINDOWS\system32\DriverStore
2015-10-10 20:46:15 ----D---- C:\WINDOWS\rescache
2015-10-10 19:32:29 ----SD---- C:\WINDOWS\SYSWOW64\GWX
2015-10-10 19:32:29 ----SD---- C:\WINDOWS\system32\GWX
2015-10-05 21:57:52 ----D---- C:\Program Files\Windows Journal
2015-10-05 21:57:48 ----D---- C:\WINDOWS\PolicyDefinitions
2015-10-04 17:57:52 ----HD---- C:\$AVG8.VAULT$
2015-10-04 15:37:15 ----D---- C:\WINDOWS\SYSWOW64\nl-NL

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 AvgRkx64;avgrkx64.sys; C:\WINDOWS\System32\Drivers\avgrkx64.sys [2015-01-31 14856]
R0 iaStorA;iaStorA; C:\WINDOWS\System32\drivers\iaStorA.sys [2012-09-14 647736]
R1 ATKWMIACPIIO;ATKWMIACPI Driver; \??\C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [2011-09-07 17536]
R1 AvgLdx64;AVG AVI Loader Driver x64; C:\WINDOWS\System32\Drivers\avgldx64.sys [2015-01-31 427016]
R1 AvgMfx64;AVG On-access Scanner Minifilter Driver x64; C:\WINDOWS\System32\Drivers\avgmfx64.sys [2015-01-31 33416]
R1 AvgTdiA;AVG8 Network Redirector x64; C:\WINDOWS\System32\Drivers\avgtdia.sys [2015-01-31 133640]
R1 SASDIFSV;SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [2011-07-22 14928]
R1 SASKUTIL;SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [2011-07-12 12368]
R1 vwififlt;@%SystemRoot%\System32\drivers\vwififlt.sys,-259; C:\WINDOWS\system32\DRIVERS\vwififlt.sys [2014-04-30 71680]
R2 ASMMAP64;ASMMAP64; \??\C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [2009-07-02 15416]
R3 ATP;@oem4.inf,%PS2.DeviceDesc%;ASUS PS/2 Port Input Device; C:\WINDOWS\System32\drivers\AsusTP.sys [2012-11-20 62848]
R3 HIDSwitch;@oem7.inf,%ASSW.DisplayName%;ASUS Wireless Radio Control; C:\WINDOWS\System32\drivers\AsHIDSwitch64.sys [2012-05-31 21152]
R3 igfx;igfx; C:\WINDOWS\system32\DRIVERS\igdkmd64.sys [2013-10-01 4177920]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RTKVHD64.sys [2012-10-16 4177680]
R3 IntcDAud;@oem19.inf,%IntcDAud.SvcDesc%;Intel(R) Display Audio; C:\WINDOWS\system32\DRIVERS\IntcDAud.sys [2012-11-15 342528]
R3 iwdbus;@oem26.inf,%iwdbus.SVCDESC%;IWD Bus Enumerator; C:\WINDOWS\System32\drivers\iwdbus.sys [2013-08-22 26008]
R3 kbfiltr;@oem6.inf,%kbfiltr.SvcDesc%;Keyboard Filter; C:\WINDOWS\System32\drivers\kbfiltr.sys [2012-08-02 14992]
R3 MBAMProtector;MBAMProtector; \??\C:\WINDOWS\system32\drivers\mbam.sys [2015-10-05 25816]
R3 MBAMSwissArmy;MBAMSwissArmy; \??\C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [2015-10-25 192216]
R3 MEIx64;@oem20.inf,%HECI_SvcDesc%;Intel(R) Management Engine Interface ; C:\WINDOWS\System32\drivers\HECIx64.sys [2012-07-02 62784]
R3 netr28x;@netr28x.inf,%Generic.Service.DispName%;Ralink 802.11n stuurprogramma voor Extensible draadloze netwerken; C:\WINDOWS\system32\DRIVERS\netr28x.sys [2013-07-25 2607792]
R3 RSBASTOR;@oem23.inf,%Rts5208%;Realtek PCIE CardReader Driver - BA; C:\WINDOWS\system32\DRIVERS\RtsBaStor.sys [2012-10-08 298640]
R3 RTL8168;@netrt630x64.inf,%rtl8168.Service.DispName%;Realtek 8168 NT-stuurprogramma; C:\WINDOWS\system32\DRIVERS\Rt630x64.sys [2013-06-18 591360]
R3 usbvideo;@usbvideo.inf,%USBVideo.SvcDesc%;USB Video Device (WDM); C:\WINDOWS\System32\Drivers\usbvideo.sys [2014-06-21 212736]
R3 vwifimp;@%SystemRoot%\System32\drivers\vwifimp.sys,-261; C:\WINDOWS\system32\DRIVERS\vwifimp.sys [2014-04-30 38912]
S3 dg_ssudbus;@oem1.inf,%ssud.Service.DeviceDesc%;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\WINDOWS\system32\DRIVERS\ssudbus.sys [2014-01-22 108800]
S3 dtlitescsibus;@oem30.inf,%DTLITESCSIBUS.DeviceDesc%;DAEMON Tools Lite Virtual SCSI Bus; C:\WINDOWS\System32\drivers\dtlitescsibus.sys [2015-07-19 30264]
S3 dtproscsibus;@oem9.inf,%DTPROSCSIBUS.DeviceDesc%;DAEMON Tools Pro Virtual SCSI Bus; C:\WINDOWS\System32\drivers\dtproscsibus.sys [2015-07-19 30352]
S3 intaud_WaveExtensible;@oem25.inf,%INTAUD_WEX.SvcDesc%;Intel WiDi Audio Device; C:\WINDOWS\system32\drivers\intelaud.sys [2013-08-22 39320]
S3 MBAMWebAccessControl;MBAMWebAccessControl; \??\C:\WINDOWS\system32\drivers\mwac.sys [2015-10-05 64216]
S3 ssudmdm;@oem2.inf,%ssud.Service.Name%;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.); C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [2014-01-22 206080]
S3 tap0901;@oem11.inf,%DeviceDescription%;TAP-Windows Adapter V9; C:\WINDOWS\system32\DRIVERS\tap0901.sys [2013-08-22 40664]
S3 usb_rndisx;@netrndis.inf,%usb_rndis.Service.DispName%;USB RNDIS-adapter; C:\WINDOWS\system32\DRIVERS\usb8023x.sys [2013-08-22 20992]
S3 WDC_SAM;@oem31.inf,%WDC_SAM_ServiceName%;WD SCSI Pass Thru driver; C:\WINDOWS\System32\drivers\wdcsam64.sys [2015-04-29 23200]
S3 WinUsb;@wpdmtp.inf,%WinUsb.SvcDesc%;WinUsb; C:\WINDOWS\System32\drivers\WinUsb.sys [2013-08-22 78848]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AFBAgent;AFBAgent; C:\Windows\system32\FBAgent.exe [2012-12-07 1221808]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\WINDOWS\System32\svchost.exe [2014-10-29 38792]
R3 !SASCORE;SAS Core Service; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [2012-07-11 140672]
R3 ASLDRService;ASLDR Service; C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe [2012-10-05 110976]
R3 ASUS InstantOn;ASUS InstantOn Service; C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe [2012-04-13 277120]
R3 ATKGFNEXSrv;ATKGFNEX Service; C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe [2011-11-21 96896]
R3 Autodesk Content Service;Autodesk Content Service; C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe [2012-12-13 12288]
R3 avg8wd;AVG8 WatchDog; C:\PROGRA~2\AVG\AVG8\avgwdsvc.exe [2015-01-31 297752]
R3 EPSON_PM_RPCV4_01;EPSON V3 Service4(01); C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RPB.EXE [2007-01-11 126464]
R3 IconMan_R;IconMan_R; C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe [2012-09-13 2466448]
R3 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [2012-04-20 635104]
R3 Intel(R) ME Service;Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [2012-06-27 129856]
R3 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2012-06-25 166720]
R3 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2012-07-17 277824]
R3 UNS;Intel(R) Management and Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2012-07-17 365376]
S2 gupdate;Google Update-service (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-31 144200]
S3 BthHFSrv;@%SystemRoot%\System32\BthHFSrv.dll,-103; C:\WINDOWS\System32\svchost.exe [2014-10-29 38792]
S3 cphs;Intel(R) Content Protection HECI Service; C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe [2013-10-01 279000]
S3 FlexNet Licensing Service 64;FlexNet Licensing Service 64; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2014-06-12 1471792]
S3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2013-08-03 43696]
S3 gupdatem;Google Update-service (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-31 144200]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-03 69632]
S3 MBAMService;MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [2015-10-05 1135416]
S3 ose64;Office 64 Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2014-01-23 178760]

-----------------EOF-----------------



info.txt logfile of random's system information tool 1.10 2015-10-25 19:26:55

======MBR======

0x00000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000001B3DA504000000000200EEFFFFFF01000000AFEA422500000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000055AA
 
nuuub
PC Web Plus - Member
PC Web Plus - Member
Onderwerp Auteur
Berichten: 20
Lid geworden op: zo 25 okt, 2015 19:40:44
Kennisniveau: (3) Expert
OS: windows
AV: avg
AM: superantispyware
FW: avg

Re: continue live installation shit

zo 25 okt, 2015 19:53:59

Het vervolg:

======Uninstall list======

4Videosoft MKV Video Converter-->"C:\Program Files (x86)\4Videosoft Studio\4Videosoft MKV Video Converter\unins000.exe"
Adobe Digital Editions 4.0-->"C:\Program Files (x86)\Adobe\Adobe Digital Editions 4.0\uninstall.exe"
Adobe Shockwave Player 12.1-->"C:\WINDOWS\SysWOW64\Adobe\Shockwave 12\uninstaller.exe"
ASUS Instant Connect-->MsiExec.exe /I{89ECB85A-D933-4CEA-9116-5CBC9C2ED95B}
ASUS InstantOn-->MsiExec.exe /I{749F674B-2674-47E8-879C-5626A06B2A91}
ASUS LifeFrame3-->MsiExec.exe /X{1DBD1F12-ED93-49C0-A7CC-56CBDE488158}
ASUS Power4Gear Hybrid-->MsiExec.exe /I{9B6239BF-4E85-4590-8D72-51E30DB1A9AA}
ASUS Smart Gesture-->MsiExec.exe /I{4D3286A6-F6AB-498A-82A4-E4F040529F3D}
ASUS Splendid Video Enhancement Technology-->MsiExec.exe /X{0969AF05-4FF6-4C00-9406-43599238DE0D}
ASUS WebStorage Sync Agent-->C:\Program Files (x86)\ASUS\WebStorage Sync Agent\uninst.exe
ATK Package-->MsiExec.exe /I{AB5C933E-5C7D-4D30-B314-9C83A49B94BE}
AutoCAD 2014 - English-->C:\Program Files\Autodesk\AutoCAD 2014\Setup\en-us\Setup\Setup.exe /P {5783F2D7-D001-0000-0102-0060B0CE6BBA} /M ACAD /language en-US
Autodesk 360-->MsiExec.exe /X{52B28CAD-F49D-47BA-9FFE-29C2E85F0D0B}
Autodesk App Manager-->MsiExec.exe /X{C070121A-C8C5-4D52-9A7D-D240631BD433}
Autodesk AutoCAD 2014 - English-->C:\Program Files\Autodesk\AutoCAD 2014\Setup\en-us\Setup\Setup.exe /P {5783F2D7-D001-0000-0102-0060B0CE6BBA} /M ACAD /language en-US
Autodesk Content Service Language Pack-->MsiExec.exe /X{62F029AB-85F2-0001-866A-9FC0DD99DDBC}
Autodesk Content Service-->C:\Program Files (x86)\Autodesk\Content Service\Setup\Setup.exe /P {62F029AB-85F2-0000-866A-9FC0DD99DDBC} /M ContentService /LANG en-US
Autodesk Featured Apps-->MsiExec.exe /X{F732FEDA-7713-4428-934B-EF83B8DD65D0}
Autodesk Material Library 2014-->MsiExec.exe /I{644F9B19-A462-499C-BF4D-300ABC2A28B1}
Autodesk Material Library Base Resolution Image Library 2014-->MsiExec.exe /I{51BF3210-B825-4092-8E0D-66D689916E02}
Autodesk ReCap-->C:\Program Files\Autodesk\Autodesk ReCap\Setup\Setup.exe /P {31ABA3F2-0000-1033-0102-111D43815377} /M Autodesk_ReCap /LANG en-US
AVG 8.5-->C:\Program Files (x86)\AVG\AVG8\setup.exe /UNINSTALL
Definition Update for Microsoft Office 2013 (KB3085580) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{5BE6110B-D613-48FC-A397-5EF0ED448FB3}" "1033" "0"
Definition Update for Microsoft Office 2013 (KB3085580) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{91150000-0051-0000-1000-0000000FF1CE}" "{5BE6110B-D613-48FC-A397-5EF0ED448FB3}" "1043" "0"
EPSON-printersoftware-->C:\WINDOWS\system32\spool\DRIVERS\x64\3\EPUPDATE.EXE /R
Free YouTube Downloader 4.0.344-->"C:\Program Files (x86)\Free YouTube Downloader\unins000.exe"
Google Chrome-->"C:\Program Files (x86)\Google\Chrome\Application\46.0.2490.71\Installer\setup.exe" --uninstall --multi-install --chrome --system-level
Google Earth-->MsiExec.exe /X{4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}
Google Update Helper-->MsiExec.exe /I{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}
Intel(R) Management Engine Components-->C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\Uninstall\setup.exe -uninstall
Intel(R) Processor Graphics-->C:\Program Files (x86)\Intel\Intel(R) Processor Graphics\Uninstall\setup.exe -uninstall
Intel(R) SDK for OpenCL - CPU Only Runtime Package-->C:\Program Files (x86)\Intel\OpenCL SDK\2.0\Uninstall\setup.exe -uninstall
Intel® Trusted Connect Service Client-->MsiExec.exe /I{F4404AFD-2EF3-40C1-8C09-29E5F3B6972B}
Malwarebytes Anti-Malware versie 2.2.0.1024-->"C:\Program Files (x86)\Malwarebytes Anti-Malware\unins000.exe"
Microsoft Access MUI (English) 2013-->MsiExec.exe /X{90150000-0015-0409-1000-0000000FF1CE}
Microsoft Access Setup Metadata MUI (English) 2013-->MsiExec.exe /X{90150000-0117-0409-1000-0000000FF1CE}
Microsoft DCF MUI (English) 2013-->MsiExec.exe /X{90150000-0090-0409-1000-0000000FF1CE}
Microsoft Excel MUI (English) 2013-->MsiExec.exe /X{90150000-0016-0409-1000-0000000FF1CE}
Microsoft Groove MUI (English) 2013-->MsiExec.exe /X{90150000-00BA-0409-1000-0000000FF1CE}
Microsoft InfoPath MUI (English) 2013-->MsiExec.exe /X{90150000-0044-0409-1000-0000000FF1CE}
Microsoft Lync MUI (English) 2013-->MsiExec.exe /X{90150000-012B-0409-1000-0000000FF1CE}
Microsoft Office 32-bit Components 2013-->MsiExec.exe /X{90150000-00C1-0000-1000-0000000FF1CE}
Microsoft Office Korrekturhilfen 2013 - Deutsch-->MsiExec.exe /X{90150000-001F-0407-1000-0000000FF1CE}
Microsoft Office OSM MUI (Dutch) 2013-->MsiExec.exe /X{90150000-00E1-0413-1000-0000000FF1CE}
Microsoft Office OSM MUI (English) 2013-->MsiExec.exe /X{90150000-00E1-0409-1000-0000000FF1CE}
Microsoft Office OSM UX MUI (English) 2013-->MsiExec.exe /X{90150000-00E2-0409-1000-0000000FF1CE}
Microsoft Office Professional Plus 2013-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Office Setup Controller\setup.exe" /uninstall PROPLUS /dll OSETUP.DLL
Microsoft Office Professional Plus 2013-->MsiExec.exe /X{90150000-0011-0000-1000-0000000FF1CE}
Microsoft Office Proofing (Dutch) 2013-->MsiExec.exe /X{90150000-002C-0413-1000-0000000FF1CE}
Microsoft Office Proofing (English) 2013-->MsiExec.exe /X{90150000-002C-0409-1000-0000000FF1CE}
Microsoft Office Proofing Tools 2013 - English-->MsiExec.exe /X{90150000-001F-0409-1000-0000000FF1CE}
Microsoft Office Proofing Tools 2013 - Español-->MsiExec.exe /X{90150000-001F-0C0A-1000-0000000FF1CE}
Microsoft Office Proofing Tools 2013 - Nederlands-->MsiExec.exe /X{90150000-001F-0413-1000-0000000FF1CE}
Microsoft Office Shared 32-bit MUI (Dutch) 2013-->MsiExec.exe /X{90150000-00C1-0413-1000-0000000FF1CE}
Microsoft Office Shared 32-bit MUI (English) 2013-->MsiExec.exe /X{90150000-00C1-0409-1000-0000000FF1CE}
Microsoft Office Shared MUI (Dutch) 2013-->MsiExec.exe /X{90150000-006E-0413-1000-0000000FF1CE}
Microsoft Office Shared MUI (English) 2013-->MsiExec.exe /X{90150000-006E-0409-1000-0000000FF1CE}
Microsoft Office Shared Setup Metadata MUI (English) 2013-->MsiExec.exe /X{90150000-0115-0409-1000-0000000FF1CE}
Microsoft Office Single Image 2010-->MsiExec.exe /X{90140000-003D-0000-0000-0000000FF1CE}
Microsoft OneNote MUI (English) 2013-->MsiExec.exe /X{90150000-00A1-0409-1000-0000000FF1CE}
Microsoft Outlook MUI (English) 2013-->MsiExec.exe /X{90150000-001A-0409-1000-0000000FF1CE}
Microsoft PowerPoint MUI (English) 2013-->MsiExec.exe /X{90150000-0018-0409-1000-0000000FF1CE}
Microsoft Publisher MUI (English) 2013-->MsiExec.exe /X{90150000-0019-0409-1000-0000000FF1CE}
Microsoft Visio MUI (Dutch) 2013-->MsiExec.exe /X{90150000-0054-0413-1000-0000000FF1CE}
Microsoft Visio Professional 2013-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Office Setup Controller\setup.exe" /uninstall VISPROR /dll OSETUP.DLL
Microsoft Visio Professional 2013-->MsiExec.exe /X{91150000-0051-0000-1000-0000000FF1CE}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148-->MsiExec.exe /X{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161-->MsiExec.exe /X{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17-->MsiExec.exe /X{9A25302D-30C0-39D9-BD6F-21E6EC160475}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148-->MsiExec.exe /X{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161-->MsiExec.exe /X{9BE518E6-ECC6-35A9-88E4-87755C07200F}
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219-->MsiExec.exe /X{1D8E6291-B0D5-35EC-8441-6616F567A0F7}
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219-->MsiExec.exe /X{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005-->"C:\ProgramData\Package Cache\{ce085a78-074e-4823-8dc1-8a721b94b76d}\vcredist_x86.exe" /uninstall
Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005-->MsiExec.exe /X{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}
Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005-->MsiExec.exe /X{13A4EE12-23EA-3371-91EE-EFB36DDFFF3E}
Microsoft Visual Studio 2010 Tools for Office Runtime (x64)-->C:\Program Files\Common Files\Microsoft Shared\VSTO\10.0\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)\install.exe
Microsoft Visual Studio 2010 Tools for Office Runtime (x64)-->MsiExec.exe /X{9495AEB4-AB97-39DE-8C42-806EEF75ECA7}
Microsoft Word MUI (English) 2013-->MsiExec.exe /X{90150000-001B-0409-1000-0000000FF1CE}
Outils de vérification linguistique 2013 de Microsoft Office - Français-->MsiExec.exe /X{90150000-001F-040C-1000-0000000FF1CE}
Prezi-->MsiExec.exe /I{63B8F931-2BF3-4D5D-9C28-E2EF88D83DFD}
Ralink RT2860 Wireless LAN Card-->C:\Program Files (x86)\InstallShield Installation Information\{8FC4F1DD-F7FD-4766-804D-3C8FF1D309B0}\setup.exe -runfromtemp -l0x0009 -removeonly
Realtek Ethernet Controller Driver-->C:\Program Files (x86)\InstallShield Installation Information\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}\setup.exe -runfromtemp -l0x0409 -removeonly
Realtek High Definition Audio Driver-->C:\Program Files\Realtek\Audio\HDA\RtlUpd64.exe -r -m -nrg2709
Realtek PCIE Card Reader-->"C:\Program Files (x86)\InstallShield Installation Information\{C1594429-8296-4652-BF54-9DBE4932A44C}\setup.exe" -runfromtemp -removeonly
Security Update for Microsoft Excel 2013 (KB3085583) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{4B0EFCCF-AA10-45A5-9C2E-B4EAB373527D}" "1033" "0"
Security Update for Microsoft Excel 2013 (KB3085583) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0016-0409-1000-0000000FF1CE}" "{4B0EFCCF-AA10-45A5-9C2E-B4EAB373527D}" "1033" "0"
Security Update for Microsoft Excel 2013 (KB3085583) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0018-0409-1000-0000000FF1CE}" "{4B0EFCCF-AA10-45A5-9C2E-B4EAB373527D}" "1033" "0"
Security Update for Microsoft Excel 2013 (KB3085583) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-001B-0409-1000-0000000FF1CE}" "{4B0EFCCF-AA10-45A5-9C2E-B4EAB373527D}" "1033" "0"
Security Update for Microsoft Excel 2013 (KB3085583) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-00C1-0409-1000-0000000FF1CE}" "{4B0EFCCF-AA10-45A5-9C2E-B4EAB373527D}" "1033" "0"
Security Update for Microsoft Excel 2013 (KB3085583) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-00C1-0413-1000-0000000FF1CE}" "{4B0EFCCF-AA10-45A5-9C2E-B4EAB373527D}" "1043" "0"
Security Update for Microsoft Office 2013 (KB2910941) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{43ECCB82-45DF-4800-8930-0689BF91F765}" "1033" "0"
Security Update for Microsoft Office 2013 (KB3039734) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{FB8031A1-6407-43C0-8AE5-4BD452FA42F0}" "1033" "0"
Security Update for Microsoft Office 2013 (KB3039734) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{91150000-0051-0000-1000-0000000FF1CE}" "{FB8031A1-6407-43C0-8AE5-4BD452FA42F0}" "1043" "0"
Security Update for Microsoft Office 2013 (KB3039798) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{05F0956E-88D3-4437-BE87-E2B0CA491BE8}" "1033" "0"
Security Update for Microsoft Office 2013 (KB3039798) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-00C1-0000-1000-0000000FF1CE}" "{05F0956E-88D3-4437-BE87-E2B0CA491BE8}" "1033" "0"
Security Update for Microsoft Office 2013 (KB3039798) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-00C1-0000-1000-0000000FF1CE}" "{05F0956E-88D3-4437-BE87-E2B0CA491BE8}" "1043" "0"
Security Update for Microsoft Office 2013 (KB3039798) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{91150000-0051-0000-1000-0000000FF1CE}" "{05F0956E-88D3-4437-BE87-E2B0CA491BE8}" "1043" "0"
Security Update for Microsoft Office 2013 (KB3054816) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{D8AD4AD9-80FA-4D64-A847-B23948D49A6D}" "1033" "0"
Security Update for Microsoft Office 2013 (KB3054816) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{91150000-0051-0000-1000-0000000FF1CE}" "{D8AD4AD9-80FA-4D64-A847-B23948D49A6D}" "1043" "0"
Security Update for Microsoft Office 2013 (KB3054932) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-006E-0409-1000-0000000FF1CE}" "{9299431B-3574-4156-B37C-B5E22719FCC2}" "1033" "0"
Security Update for Microsoft Office 2013 (KB3054932) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-006E-0413-1000-0000000FF1CE}" "{9299431B-3574-4156-B37C-B5E22719FCC2}" "1043" "0"
Service Pack 1 for Microsoft Office 2013 (KB2850036) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{D82063A8-7C8C-4C3B-A9BB-95138CA55D26}" "1033" "0"
Service Pack 1 for Microsoft Office 2013 (KB2850036) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0015-0409-1000-0000000FF1CE}" "{6227D1A8-9E29-463F-8DE6-1CFA1FFF8ECE}" "1033" "0"
Service Pack 1 for Microsoft Office 2013 (KB2850036) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0016-0409-1000-0000000FF1CE}" "{6227D1A8-9E29-463F-8DE6-1CFA1FFF8ECE}" "1033" "0"
Service Pack 1 for Microsoft Office 2013 (KB2850036) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0018-0409-1000-0000000FF1CE}" "{6227D1A8-9E29-463F-8DE6-1CFA1FFF8ECE}" "1033" "0"
Service Pack 1 for Microsoft Office 2013 (KB2850036) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0019-0409-1000-0000000FF1CE}" "{6227D1A8-9E29-463F-8DE6-1CFA1FFF8ECE}" "1033" "0"
Service Pack 1 for Microsoft Office 2013 (KB2850036) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-001A-0409-1000-0000000FF1CE}" "{6227D1A8-9E29-463F-8DE6-1CFA1FFF8ECE}" "1033" "0"
Service Pack 1 for Microsoft Office 2013 (KB2850036) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-001B-0409-1000-0000000FF1CE}" "{6227D1A8-9E29-463F-8DE6-1CFA1FFF8ECE}" "1033" "0"
Service Pack 1 for Microsoft Office 2013 (KB2850036) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-001F-0C0A-1000-0000000FF1CE}" "{4BF13B26-3A95-4E42-900A-DEB16FDA75A0}" "1033" "0"
Service Pack 1 for Microsoft Office 2013 (KB2850036) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-002C-0409-1000-0000000FF1CE}" "{C5D14A1B-6E3E-491A-96C6-ABDEEEC4E97D}" "1033" "0"
Service Pack 1 for Microsoft Office 2013 (KB2850036) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0044-0409-1000-0000000FF1CE}" "{6227D1A8-9E29-463F-8DE6-1CFA1FFF8ECE}" "1033" "0"
Service Pack 1 for Microsoft Office 2013 (KB2850036) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-006E-0409-1000-0000000FF1CE}" "{D7E879E6-B505-4DA2-BFEE-53A55E7C8E38}" "1033" "0"
Service Pack 1 for Microsoft Office 2013 (KB2850036) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0090-0409-1000-0000000FF1CE}" "{6227D1A8-9E29-463F-8DE6-1CFA1FFF8ECE}" "1033" "0"
Service Pack 1 for Microsoft Office 2013 (KB2850036) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-00A1-0409-1000-0000000FF1CE}" "{6227D1A8-9E29-463F-8DE6-1CFA1FFF8ECE}" "1033" "0"
Service Pack 1 for Microsoft Office 2013 (KB2850036) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-00BA-0409-1000-0000000FF1CE}" "{6227D1A8-9E29-463F-8DE6-1CFA1FFF8ECE}" "1033" "0"
Service Pack 1 for Microsoft Office 2013 (KB2850036) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-00C1-0409-1000-0000000FF1CE}" "{E4F470B2-3601-4E1C-B291-D6B580F53136}" "1033" "0"
Service Pack 1 for Microsoft Office 2013 (KB2850036) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-00E1-0409-1000-0000000FF1CE}" "{6227D1A8-9E29-463F-8DE6-1CFA1FFF8ECE}" "1033" "0"
Service Pack 1 for Microsoft Office 2013 (KB2850036) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-00E2-0409-1000-0000000FF1CE}" "{6227D1A8-9E29-463F-8DE6-1CFA1FFF8ECE}" "1033" "0"
Service Pack 1 for Microsoft Office 2013 (KB2850036) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0115-0409-1000-0000000FF1CE}" "{D7E879E6-B505-4DA2-BFEE-53A55E7C8E38}" "1033" "0"
Service Pack 1 for Microsoft Office 2013 (KB2850036) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0117-0409-1000-0000000FF1CE}" "{6227D1A8-9E29-463F-8DE6-1CFA1FFF8ECE}" "1033" "0"
Service Pack 1 for Microsoft Office 2013 (KB2850036) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-012B-0409-1000-0000000FF1CE}" "{6227D1A8-9E29-463F-8DE6-1CFA1FFF8ECE}" "1033" "0"
Shared C Run-time for x64-->MsiExec.exe /I{EF79C448-6946-4D71-8134-03407888C054}
SketchUp Import for AutoCAD 2014-->MsiExec.exe /X{644E9589-F73A-49A4-AC61-A953B9DE5669}
SUPERAntiSpyware-->"C:\Program Files\SUPERAntiSpyware\Uninstall.exe"
swMSM-->MsiExec.exe /I{612C34C7-5E90-47D8-9B5C-0F717DD82726}
Taalpakket voor Microsoft Visual Studio 2010 Tools for Office Runtime (x64) - NLD-->C:\Program Files\Common Files\Microsoft Shared\VSTO\10.0\Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - NLD\install.exe
Update for Microsoft Access 2013 (KB3085503) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{08B86615-1181-4A9C-A7B9-BBE31E2BD466}" "1033" "0"
Update for Microsoft Access 2013 (KB3085503) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0015-0409-1000-0000000FF1CE}" "{08B86615-1181-4A9C-A7B9-BBE31E2BD466}" "1033" "0"
Update for Microsoft Office 2013 (KB2760344) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{EF77B4A6-DFEC-4010-A87D-9B6BF87FABEC}" "1033" "0"
Update for Microsoft Office 2013 (KB2760344) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{91150000-0051-0000-1000-0000000FF1CE}" "{EF77B4A6-DFEC-4010-A87D-9B6BF87FABEC}" "1043" "0"
Update for Microsoft Office 2013 (KB2760371) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{25DEA344-FF6F-41BD-B88F-5242BB8E80E1}" "1033" "0"
Update for Microsoft Office 2013 (KB2760544) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{62857CDD-2985-4939-91BA-19ED0B0031A5}" "1033" "0"
Update for Microsoft Office 2013 (KB2880487) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{76379D52-B506-4634-8404-8E1718DF1430}" "1033" "0"
Update for Microsoft Office 2013 (KB2880487) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{91150000-0051-0000-1000-0000000FF1CE}" "{76379D52-B506-4634-8404-8E1718DF1430}" "1043" "0"
Update for Microsoft Office 2013 (KB2881076) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{F492C757-000C-4745-BD8F-AD03F029C6BB}" "1033" "0"
Update for Microsoft Office 2013 (KB2881076) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0016-0409-1000-0000000FF1CE}" "{F492C757-000C-4745-BD8F-AD03F029C6BB}" "1033" "0"
Update for Microsoft Office 2013 (KB2881076) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0090-0409-1000-0000000FF1CE}" "{F492C757-000C-4745-BD8F-AD03F029C6BB}" "1033" "0"
Update for Microsoft Office 2013 (KB2883095) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{EADBF225-163E-406B-B11A-26ECCCAB5A0E}" "1033" "0"
Update for Microsoft Office 2013 (KB2889863) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{82D6A9DF-894F-488F-A0C3-54A37A6E7B2A}" "1033" "0"
Update for Microsoft Office 2013 (KB2899522) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{A4E88D96-814F-4183-8DB2-BA3EC2B7E434}" "1033" "0"
Update for Microsoft Office 2013 (KB2899522) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{91150000-0051-0000-1000-0000000FF1CE}" "{A4E88D96-814F-4183-8DB2-BA3EC2B7E434}" "1043" "0"
Update for Microsoft Office 2013 (KB2975869) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{14A52226-59E1-428F-83CF-C0D8A467A303}" "1033" "0"
Update for Microsoft Office 2013 (KB2975869) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-006E-0409-1000-0000000FF1CE}" "{14A52226-59E1-428F-83CF-C0D8A467A303}" "1033" "0"
Update for Microsoft Office 2013 (KB2975869) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-006E-0413-1000-0000000FF1CE}" "{14A52226-59E1-428F-83CF-C0D8A467A303}" "1043" "0"
Update for Microsoft Office 2013 (KB2975869) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{91150000-0051-0000-1000-0000000FF1CE}" "{14A52226-59E1-428F-83CF-C0D8A467A303}" "1043" "0"
Update for Microsoft Office 2013 (KB3023052) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{A472CEA9-44BA-4ADD-8AD1-589B2F0240EE}" "1033" "0"
Update for Microsoft Office 2013 (KB3023052) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-006E-0413-1000-0000000FF1CE}" "{A472CEA9-44BA-4ADD-8AD1-589B2F0240EE}" "1043" "0"
Update for Microsoft Office 2013 (KB3023052) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{91150000-0051-0000-1000-0000000FF1CE}" "{A472CEA9-44BA-4ADD-8AD1-589B2F0240EE}" "1043" "0"
Update for Microsoft Office 2013 (KB3039701) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{8A6AEFA2-8003-4FD6-8EF7-DEAD1C07803C}" "1033" "0"
Update for Microsoft Office 2013 (KB3039701) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{91150000-0051-0000-1000-0000000FF1CE}" "{8A6AEFA2-8003-4FD6-8EF7-DEAD1C07803C}" "1043" "0"
Update for Microsoft Office 2013 (KB3039718) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{88E8FA4B-38D9-496D-86D8-BB84E9AB520D}" "1033" "0"
Update for Microsoft Office 2013 (KB3039718) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{91150000-0051-0000-1000-0000000FF1CE}" "{88E8FA4B-38D9-496D-86D8-BB84E9AB520D}" "1043" "0"
Update for Microsoft Office 2013 (KB3039720) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{C08DDD68-F534-45A4-B876-4B8C2C43A744}" "1033" "0"
Update for Microsoft Office 2013 (KB3039720) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0015-0409-1000-0000000FF1CE}" "{C08DDD68-F534-45A4-B876-4B8C2C43A744}" "1033" "0"
Update for Microsoft Office 2013 (KB3039720) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0016-0409-1000-0000000FF1CE}" "{C08DDD68-F534-45A4-B876-4B8C2C43A744}" "1033" "0"
Update for Microsoft Office 2013 (KB3039720) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0018-0409-1000-0000000FF1CE}" "{C08DDD68-F534-45A4-B876-4B8C2C43A744}" "1033" "0"
Update for Microsoft Office 2013 (KB3039720) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0019-0409-1000-0000000FF1CE}" "{C08DDD68-F534-45A4-B876-4B8C2C43A744}" "1033" "0"
Update for Microsoft Office 2013 (KB3039720) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-001A-0409-1000-0000000FF1CE}" "{C08DDD68-F534-45A4-B876-4B8C2C43A744}" "1033" "0"
Update for Microsoft Office 2013 (KB3039720) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-001B-0409-1000-0000000FF1CE}" "{C08DDD68-F534-45A4-B876-4B8C2C43A744}" "1033" "0"
Update for Microsoft Office 2013 (KB3039720) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-001F-0407-1000-0000000FF1CE}" "{C08DDD68-F534-45A4-B876-4B8C2C43A744}" "1043" "0"
Update for Microsoft Office 2013 (KB3039720) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-001F-0409-1000-0000000FF1CE}" "{C08DDD68-F534-45A4-B876-4B8C2C43A744}" "1033" "0"
Update for Microsoft Office 2013 (KB3039720) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-001F-0409-1000-0000000FF1CE}" "{C08DDD68-F534-45A4-B876-4B8C2C43A744}" "1043" "0"
Update for Microsoft Office 2013 (KB3039720) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-001F-040C-1000-0000000FF1CE}" "{C08DDD68-F534-45A4-B876-4B8C2C43A744}" "1033" "0"
Update for Microsoft Office 2013 (KB3039720) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-001F-040C-1000-0000000FF1CE}" "{C08DDD68-F534-45A4-B876-4B8C2C43A744}" "1043" "0"
Update for Microsoft Office 2013 (KB3039720) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-001F-0413-1000-0000000FF1CE}" "{C08DDD68-F534-45A4-B876-4B8C2C43A744}" "1043" "0"
Update for Microsoft Office 2013 (KB3039720) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-001F-0C0A-1000-0000000FF1CE}" "{C08DDD68-F534-45A4-B876-4B8C2C43A744}" "1033" "0"
Update for Microsoft Office 2013 (KB3039720) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-002C-0409-1000-0000000FF1CE}" "{C08DDD68-F534-45A4-B876-4B8C2C43A744}" "1033" "0"
Update for Microsoft Office 2013 (KB3039720) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-002C-0413-1000-0000000FF1CE}" "{C08DDD68-F534-45A4-B876-4B8C2C43A744}" "1043" "0"
Update for Microsoft Office 2013 (KB3039720) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0044-0409-1000-0000000FF1CE}" "{C08DDD68-F534-45A4-B876-4B8C2C43A744}" "1033" "0"
Update for Microsoft Office 2013 (KB3039720) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0054-0413-1000-0000000FF1CE}" "{C08DDD68-F534-45A4-B876-4B8C2C43A744}" "1043" "0"
Update for Microsoft Office 2013 (KB3039720) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-006E-0409-1000-0000000FF1CE}" "{C08DDD68-F534-45A4-B876-4B8C2C43A744}" "1033" "0"
Update for Microsoft Office 2013 (KB3039720) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-006E-0413-1000-0000000FF1CE}" "{C08DDD68-F534-45A4-B876-4B8C2C43A744}" "1043" "0"
Update for Microsoft Office 2013 (KB3039720) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0090-0409-1000-0000000FF1CE}" "{C08DDD68-F534-45A4-B876-4B8C2C43A744}" "1033" "0"
Update for Microsoft Office 2013 (KB3039720) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-00A1-0409-1000-0000000FF1CE}" "{C08DDD68-F534-45A4-B876-4B8C2C43A744}" "1033" "0"
Update for Microsoft Office 2013 (KB3039720) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-00BA-0409-1000-0000000FF1CE}" "{C08DDD68-F534-45A4-B876-4B8C2C43A744}" "1033" "0"
Update for Microsoft Office 2013 (KB3039720) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-00C1-0000-1000-0000000FF1CE}" "{C08DDD68-F534-45A4-B876-4B8C2C43A744}" "1033" "0"
Update for Microsoft Office 2013 (KB3039720) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-00C1-0000-1000-0000000FF1CE}" "{C08DDD68-F534-45A4-B876-4B8C2C43A744}" "1043" "0"
Update for Microsoft Office 2013 (KB3039720) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-00C1-0409-1000-0000000FF1CE}" "{C08DDD68-F534-45A4-B876-4B8C2C43A744}" "1033" "0"
Update for Microsoft Office 2013 (KB3039720) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-00C1-0413-1000-0000000FF1CE}" "{C08DDD68-F534-45A4-B876-4B8C2C43A744}" "1043" "0"
Update for Microsoft Office 2013 (KB3039720) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-00E1-0409-1000-0000000FF1CE}" "{C08DDD68-F534-45A4-B876-4B8C2C43A744}" "1033" "0"
Update for Microsoft Office 2013 (KB3039720) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-00E1-0413-1000-0000000FF1CE}" "{C08DDD68-F534-45A4-B876-4B8C2C43A744}" "1043" "0"
Update for Microsoft Office 2013 (KB3039720) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-00E2-0409-1000-0000000FF1CE}" "{C08DDD68-F534-45A4-B876-4B8C2C43A744}" "1033" "0"
Update for Microsoft Office 2013 (KB3039720) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0115-0409-1000-0000000FF1CE}" "{C08DDD68-F534-45A4-B876-4B8C2C43A744}" "1033" "0"
Update for Microsoft Office 2013 (KB3039720) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0117-0409-1000-0000000FF1CE}" "{C08DDD68-F534-45A4-B876-4B8C2C43A744}" "1033" "0"
Update for Microsoft Office 2013 (KB3039720) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-012B-0409-1000-0000000FF1CE}" "{C08DDD68-F534-45A4-B876-4B8C2C43A744}" "1033" "0"
Update for Microsoft Office 2013 (KB3039720) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{91150000-0051-0000-1000-0000000FF1CE}" "{C08DDD68-F534-45A4-B876-4B8C2C43A744}" "1043" "0"
Update for Microsoft Office 2013 (KB3039739) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{AFF17D1D-61FB-4F35-86B8-074884BDD0A6}" "1033" "0"
Update for Microsoft Office 2013 (KB3039739) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0016-0409-1000-0000000FF1CE}" "{AFF17D1D-61FB-4F35-86B8-074884BDD0A6}" "1033" "0"
Update for Microsoft Office 2013 (KB3039762) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{D2724845-C07A-448F-A580-3CD65760D22A}" "1033" "0"
Update for Microsoft Office 2013 (KB3039762) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{91150000-0051-0000-1000-0000000FF1CE}" "{D2724845-C07A-448F-A580-3CD65760D22A}" "1043" "0"
Update for Microsoft Office 2013 (KB3039766) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{881BA890-D29E-4212-ADDC-A92BE0FBA444}" "1033" "0"
Update for Microsoft Office 2013 (KB3039766) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{91150000-0051-0000-1000-0000000FF1CE}" "{881BA890-D29E-4212-ADDC-A92BE0FBA444}" "1043" "0"
Update for Microsoft Office 2013 (KB3039778) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{59474240-80FF-4640-A723-777334B81D28}" "1033" "0"
Update for Microsoft Office 2013 (KB3039778) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{91150000-0051-0000-1000-0000000FF1CE}" "{59474240-80FF-4640-A723-777334B81D28}" "1043" "0"
Update for Microsoft Office 2013 (KB3039787) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{1A7A50DC-82E4-4415-B5AE-C9090BAB06E4}" "1033" "0"
Update for Microsoft Office 2013 (KB3039800) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{949A0DB9-8915-4B0F-902F-732EE7BA7A7E}" "1033" "0"
Update for Microsoft Office 2013 (KB3054783) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{4F73DEDD-E1B8-43A4-B999-D18C134D22B5}" "1033" "0"
Update for Microsoft Office 2013 (KB3054783) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{91150000-0051-0000-1000-0000000FF1CE}" "{4F73DEDD-E1B8-43A4-B999-D18C134D22B5}" "1043" "0"
Update for Microsoft Office 2013 (KB3054785) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{A4970C67-6BF6-470D-9A66-BD7488A56F2E}" "1033" "0"
Update for Microsoft Office 2013 (KB3054785) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-00C1-0000-1000-0000000FF1CE}" "{A4970C67-6BF6-470D-9A66-BD7488A56F2E}" "1033" "0"
Update for Microsoft Office 2013 (KB3054785) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-00C1-0000-1000-0000000FF1CE}" "{A4970C67-6BF6-470D-9A66-BD7488A56F2E}" "1043" "0"
Update for Microsoft Office 2013 (KB3054785) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{91150000-0051-0000-1000-0000000FF1CE}" "{A4970C67-6BF6-470D-9A66-BD7488A56F2E}" "1043" "0"
Update for Microsoft Office 2013 (KB3054805) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{89114288-5452-4A0B-AFFA-264E346B15D6}" "1033" "0"
Update for Microsoft Office 2013 (KB3054805) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{91150000-0051-0000-1000-0000000FF1CE}" "{89114288-5452-4A0B-AFFA-264E346B15D6}" "1043" "0"
Update for Microsoft Office 2013 (KB3054856) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{65B377E4-0004-4060-A2EE-EC38AD73EF92}" "1033" "0"
Update for Microsoft Office 2013 (KB3054935) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{875E1573-787C-4DAD-94E8-347D0406A1AD}" "1033" "0"
Update for Microsoft Office 2013 (KB3054935) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{91150000-0051-0000-1000-0000000FF1CE}" "{875E1573-787C-4DAD-94E8-347D0406A1AD}" "1043" "0"
Update for Microsoft Office 2013 (KB3054941) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{254C2485-E897-484F-B5ED-F3CB82FAFBA4}" "1033" "0"
Update for Microsoft Office 2013 (KB3054941) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{91150000-0051-0000-1000-0000000FF1CE}" "{254C2485-E897-484F-B5ED-F3CB82FAFBA4}" "1043" "0"
Update for Microsoft Office 2013 (KB3055011) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-001F-0407-1000-0000000FF1CE}" "{8F98D5E9-1F7E-4848-9431-CEE5E1E51313}" "1043" "0"
Update for Microsoft Office 2013 (KB3055011) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-001F-0409-1000-0000000FF1CE}" "{D05C001E-B0A0-4903-BC14-F34CB4A775C1}" "1033" "0"
Update for Microsoft Office 2013 (KB3055011) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-001F-0409-1000-0000000FF1CE}" "{D05C001E-B0A0-4903-BC14-F34CB4A775C1}" "1043" "0"
Update for Microsoft Office 2013 (KB3055011) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-001F-040C-1000-0000000FF1CE}" "{10F2DDD0-7C3D-49DE-8629-94CF0B9BEE1F}" "1033" "0"
Update for Microsoft Office 2013 (KB3055011) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-001F-040C-1000-0000000FF1CE}" "{10F2DDD0-7C3D-49DE-8629-94CF0B9BEE1F}" "1043" "0"
Update for Microsoft Office 2013 (KB3055011) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-001F-0413-1000-0000000FF1CE}" "{64AE5B75-17FB-46FB-8A15-1B0136CD3D44}" "1043" "0"
Update for Microsoft Office 2013 (KB3055011) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-001F-0C0A-1000-0000000FF1CE}" "{85DF6525-67BB-4716-8145-EA9245071FB1}" "1033" "0"
Update for Microsoft Office 2013 (KB3085479) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{585AE578-D6B8-4D3B-8281-D36E165C0F17}" "1033" "0"
Update for Microsoft Office 2013 (KB3085479) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{91150000-0051-0000-1000-0000000FF1CE}" "{585AE578-D6B8-4D3B-8281-D36E165C0F17}" "1043" "0"
Update for Microsoft Office 2013 (KB3085493) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{572934A4-C018-4D51-AA2C-F6F85B1E9129}" "1033" "0"
Update for Microsoft Office 2013 (KB3085493) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{91150000-0051-0000-1000-0000000FF1CE}" "{572934A4-C018-4D51-AA2C-F6F85B1E9129}" "1043" "0"
Update for Microsoft Office 2013 (KB3085506) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{F2858C55-53C1-4AA0-9DF5-E240E15F01BE}" "1033" "0"
Update for Microsoft Office 2013 (KB3085506) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{91150000-0051-0000-1000-0000000FF1CE}" "{F2858C55-53C1-4AA0-9DF5-E240E15F01BE}" "1043" "0"
Update for Microsoft Office 2013 (KB3085563) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{AF90ADA3-90C4-4DE5-BF2F-4A3D000EDF18}" "1033" "0"
Update for Microsoft Office 2013 (KB3085563) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{91150000-0051-0000-1000-0000000FF1CE}" "{AF90ADA3-90C4-4DE5-BF2F-4A3D000EDF18}" "1043" "0"
Update for Microsoft Office 2013 (KB3085566) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{C464AA4E-3D91-4594-BF8C-0932647565D6}" "1033" "0"
Update for Microsoft Office 2013 (KB3085566) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-006E-0409-1000-0000000FF1CE}" "{C464AA4E-3D91-4594-BF8C-0932647565D6}" "1033" "0"
Update for Microsoft Office 2013 (KB3085566) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-006E-0413-1000-0000000FF1CE}" "{C464AA4E-3D91-4594-BF8C-0932647565D6}" "1043" "0"
Update for Microsoft Office 2013 (KB3085566) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-00C1-0000-1000-0000000FF1CE}" "{C464AA4E-3D91-4594-BF8C-0932647565D6}" "1033" "0"
Update for Microsoft Office 2013 (KB3085566) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-00C1-0000-1000-0000000FF1CE}" "{C464AA4E-3D91-4594-BF8C-0932647565D6}" "1043" "0"
Update for Microsoft Office 2013 (KB3085566) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{91150000-0051-0000-1000-0000000FF1CE}" "{C464AA4E-3D91-4594-BF8C-0932647565D6}" "1043" "0"
Update for Microsoft Office 2013 (KB3085576) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{16C2873A-BDCE-4865-A381-9FEF1C7A5A27}" "1033" "0"
Update for Microsoft Office 2013 (KB3085576) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-006E-0409-1000-0000000FF1CE}" "{16C2873A-BDCE-4865-A381-9FEF1C7A5A27}" "1033" "0"
Update for Microsoft Office 2013 (KB3085576) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-006E-0413-1000-0000000FF1CE}" "{16C2873A-BDCE-4865-A381-9FEF1C7A5A27}" "1043" "0"
Update for Microsoft Office 2013 (KB3085576) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-00C1-0000-1000-0000000FF1CE}" "{16C2873A-BDCE-4865-A381-9FEF1C7A5A27}" "1033" "0"
Update for Microsoft Office 2013 (KB3085576) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-00C1-0000-1000-0000000FF1CE}" "{16C2873A-BDCE-4865-A381-9FEF1C7A5A27}" "1043" "0"
Update for Microsoft Office 2013 (KB3085576) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{91150000-0051-0000-1000-0000000FF1CE}" "{16C2873A-BDCE-4865-A381-9FEF1C7A5A27}" "1043" "0"
Update for Microsoft Office 2013 (KB3085585) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{168EBD50-D98D-4037-A559-58E074D42382}" "1033" "0"
Update for Microsoft Office 2013 (KB3085585) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-00C1-0000-1000-0000000FF1CE}" "{168EBD50-D98D-4037-A559-58E074D42382}" "1033" "0"
Update for Microsoft Office 2013 (KB3085585) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-00C1-0000-1000-0000000FF1CE}" "{168EBD50-D98D-4037-A559-58E074D42382}" "1043" "0"
Update for Microsoft Office 2013 (KB3085585) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{91150000-0051-0000-1000-0000000FF1CE}" "{168EBD50-D98D-4037-A559-58E074D42382}" "1043" "0"
Update for Microsoft OneDrive for Business (KB3085509) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{B7AB75C5-A709-4615-B182-825EC32AAF2F}" "1033" "0"
Update for Microsoft OneDrive for Business (KB3085509) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-00BA-0409-1000-0000000FF1CE}" "{B7AB75C5-A709-4615-B182-825EC32AAF2F}" "1033" "0"
Update for Microsoft OneDrive for Business (KB3085509) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-00C1-0000-1000-0000000FF1CE}" "{B7AB75C5-A709-4615-B182-825EC32AAF2F}" "1033" "0"
 
nuuub
PC Web Plus - Member
PC Web Plus - Member
Onderwerp Auteur
Berichten: 20
Lid geworden op: zo 25 okt, 2015 19:40:44
Kennisniveau: (3) Expert
OS: windows
AV: avg
AM: superantispyware
FW: avg

Re: continue live installation shit

zo 25 okt, 2015 19:54:16

Het vervolg:

Update for Microsoft OneDrive for Business (KB3085509) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-00C1-0000-1000-0000000FF1CE}" "{B7AB75C5-A709-4615-B182-825EC32AAF2F}" "1043" "0"
Update for Microsoft OneDrive for Business (KB3085509) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-00C1-0409-1000-0000000FF1CE}" "{B7AB75C5-A709-4615-B182-825EC32AAF2F}" "1033" "0"
Update for Microsoft OneDrive for Business (KB3085509) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-00C1-0413-1000-0000000FF1CE}" "{B7AB75C5-A709-4615-B182-825EC32AAF2F}" "1043" "0"
Update for Microsoft OneNote 2013 (KB3085574) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{F8C73489-6451-4604-A874-99CDC4F8E932}" "1033" "0"
Update for Microsoft OneNote 2013 (KB3085574) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-00A1-0409-1000-0000000FF1CE}" "{F8C73489-6451-4604-A874-99CDC4F8E932}" "1033" "0"
Update for Microsoft OneNote 2013 (KB3085574) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-00C1-0000-1000-0000000FF1CE}" "{F8C73489-6451-4604-A874-99CDC4F8E932}" "1033" "0"
Update for Microsoft OneNote 2013 (KB3085574) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-00C1-0000-1000-0000000FF1CE}" "{F8C73489-6451-4604-A874-99CDC4F8E932}" "1043" "0"
Update for Microsoft Outlook 2013 (KB3085579) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{DFFAF541-E4D9-4A70-897B-48BE221C526E}" "1033" "0"
Update for Microsoft Outlook 2013 (KB3085579) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-001A-0409-1000-0000000FF1CE}" "{DFFAF541-E4D9-4A70-897B-48BE221C526E}" "1033" "0"
Update for Microsoft Outlook 2013 (KB3085579) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{91150000-0051-0000-1000-0000000FF1CE}" "{DFFAF541-E4D9-4A70-897B-48BE221C526E}" "1043" "0"
Update for Microsoft Outlook Social Connector 2013 (KB3054854) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{0B5649CA-AD84-4970-9FCE-548A3EF323ED}" "1033" "0"
Update for Microsoft Outlook Social Connector 2013 (KB3054854) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-001A-0409-1000-0000000FF1CE}" "{0B5649CA-AD84-4970-9FCE-548A3EF323ED}" "1033" "0"
Update for Microsoft PowerPoint 2013 (KB3085564) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{8D099887-EE43-4ED9-AAB7-F93AADB67E75}" "1033" "0"
Update for Microsoft PowerPoint 2013 (KB3085564) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0018-0409-1000-0000000FF1CE}" "{8D099887-EE43-4ED9-AAB7-F93AADB67E75}" "1033" "0"
Update for Microsoft Project 2013 (KB3085590) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-00C1-0000-1000-0000000FF1CE}" "{F6BF3C30-01FB-4A47-B117-D479982A0DD6}" "1033" "0"
Update for Microsoft Project 2013 (KB3085590) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-00C1-0000-1000-0000000FF1CE}" "{F6BF3C30-01FB-4A47-B117-D479982A0DD6}" "1043" "0"
Update for Microsoft Publisher 2013 (KB3023050) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{65B84138-5B82-44B7-B895-568FCC40BB42}" "1033" "0"
Update for Microsoft Publisher 2013 (KB3023050) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0019-0409-1000-0000000FF1CE}" "{65B84138-5B82-44B7-B895-568FCC40BB42}" "1033" "0"
Update for Microsoft Visio 2013 (KB3085569) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{796D43D0-EF0A-4AD9-BEF7-84B26EBC8EA6}" "1033" "0"
Update for Microsoft Visio 2013 (KB3085569) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0054-0413-1000-0000000FF1CE}" "{796D43D0-EF0A-4AD9-BEF7-84B26EBC8EA6}" "1043" "0"
Update for Microsoft Visio 2013 (KB3085569) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{91150000-0051-0000-1000-0000000FF1CE}" "{796D43D0-EF0A-4AD9-BEF7-84B26EBC8EA6}" "1043" "0"
Update for Microsoft Visio Viewer 2013 (KB2817301) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{8E5CD68A-CDF8-4930-88DF-B7778B1871A9}" "1033" "0"
Update for Microsoft Visio Viewer 2013 (KB2817301) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-006E-0409-1000-0000000FF1CE}" "{8E5CD68A-CDF8-4930-88DF-B7778B1871A9}" "1033" "0"
Update for Microsoft Visio Viewer 2013 (KB2817301) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-006E-0413-1000-0000000FF1CE}" "{8E5CD68A-CDF8-4930-88DF-B7778B1871A9}" "1043" "0"
Update for Microsoft Visio Viewer 2013 (KB2817301) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{91150000-0051-0000-1000-0000000FF1CE}" "{8E5CD68A-CDF8-4930-88DF-B7778B1871A9}" "1043" "0"
Update for Microsoft Word 2013 (KB2878319) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{BC51FE30-3A56-4802-8D9E-E9BC05B56B49}" "1033" "0"
Update for Microsoft Word 2013 (KB3085573) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{FB54FFAF-01D6-44BA-BEF7-08A554FAD748}" "1033" "0"
Update for Microsoft Word 2013 (KB3085573) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-001A-0409-1000-0000000FF1CE}" "{FB54FFAF-01D6-44BA-BEF7-08A554FAD748}" "1033" "0"
Update for Microsoft Word 2013 (KB3085573) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-001B-0409-1000-0000000FF1CE}" "{FB54FFAF-01D6-44BA-BEF7-08A554FAD748}" "1033" "0"
Update for Microsoft Word 2013 (KB3085573) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-012B-0409-1000-0000000FF1CE}" "{FB54FFAF-01D6-44BA-BEF7-08A554FAD748}" "1033" "0"
Update for Skype for Business 2015 (KB2889853) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-012B-0409-1000-0000000FF1CE}" "{40930C8E-A677-414C-A72F-DFDEB10738FB}" "1033" "0"
Update for Skype for Business 2015 (KB3085581) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{6BCC80EE-3B68-4110-8D47-23E04FB6D08D}" "1033" "0"
Update for Skype for Business 2015 (KB3085581) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-00C1-0000-1000-0000000FF1CE}" "{6BCC80EE-3B68-4110-8D47-23E04FB6D08D}" "1033" "0"
Update for Skype for Business 2015 (KB3085581) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-00C1-0000-1000-0000000FF1CE}" "{6BCC80EE-3B68-4110-8D47-23E04FB6D08D}" "1043" "0"
Update for Skype for Business 2015 (KB3085581) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-012B-0409-1000-0000000FF1CE}" "{6BCC80EE-3B68-4110-8D47-23E04FB6D08D}" "1033" "0"
VC80CRTRedist - 8.0.50727.6195-->MsiExec.exe /I{933B4015-4618-4716-A828-5289FC03165F}
Visual Studio 2010 x64 Redistributables-->MsiExec.exe /I{21B133D6-5979-47F0-BE1C-F6A6B304693F}
Visual Studio 2012 x64 Redistributables-->MsiExec.exe /I{8C775E70-A791-4DA8-BCC3-6AB7136F4484}
Visual Studio 2012 x86 Redistributables-->MsiExec.exe /I{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}
Winamp-->"C:\Program Files (x86)\Winamp\UninstWA.exe"
Windows Driver Package - ASUS (ATP) Mouse (11/09/2012 1.0.0.153)-->C:\PROGRA~1\DIFX\4A7292~1\dpinst.exe /u C:\Windows\System32\DriverStore\FileRepository\asustp.inf_amd64_c8afc71cb1fe0404\asustp.inf
WinFlash-->MsiExec.exe /X{8F21291E-0444-4B1D-B9F9-4370A73E346D}
WinRAR 4.20 (64-bit)-->C:\Program Files\WinRAR\uninstall.exe
YTD Video Downloader 4.8.9-->"C:\Program Files (x86)\GreenTree Applications\YTD Video Downloader\uninstall.exe"

======System event log======

Computer Name: --------
Event Code: 26
Message: Toepassingspop-up: Microsoft Visual C++ Debug Library : Debug Error!

Program: C:\Windows\system32\FBAgent.exe
Module: C:\Windows\system32\FBAgent.exe
File:

Run-Time Check Failure #2 - Stack around the variable 'wszSectionName' was corrupted.

(Press Retry to debug the application)
Record Number: 5788
Source Name: Application Popup
Time Written: 20131014091013.737705-000
Event Type: Informatie
User: NT AUTHORITY\SYSTEM

Computer Name: --------
Event Code: 26
Message: Toepassingspop-up: Microsoft Visual C++ Debug Library : Debug Error!

Program: C:\Windows\system32\FBAgent.exe
Module: C:\Windows\system32\FBAgent.exe
File:

Run-Time Check Failure #2 - Stack around the variable 'wszSectionName' was corrupted.

(Press Retry to debug the application)
Record Number: 5787
Source Name: Application Popup
Time Written: 20131014091009.862503-000
Event Type: Informatie
User: NT AUTHORITY\SYSTEM

Computer Name: ---------
Event Code: 16
Message: De toegangsgeschiedenis in component \??\C:\Users\------------\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\Settings\settings.dat is gewist, waarbij 24 sleutels zijn bijgewerkt en 2 gewijzigde pagina's zijn gemaakt.
Record Number: 5786
Source Name: Microsoft-Windows-Kernel-General
Time Written: 20131014091007.346745-000
Event Type: Informatie
User: --------\---------

Computer Name: ----------
Event Code: 26
Message: Toepassingspop-up: Microsoft Visual C++ Debug Library : Debug Error!

Program: C:\Windows\system32\FBAgent.exe
Module: C:\Windows\system32\FBAgent.exe
File:

Run-Time Check Failure #2 - Stack around the variable 'wszSectionName' was corrupted.

(Press Retry to debug the application)
Record Number: 5785
Source Name: Application Popup
Time Written: 20131014091003.705930-000
Event Type: Informatie
User: NT AUTHORITY\SYSTEM

Computer Name: ---------
Event Code: 7040
Message: Het opstarttype van de service BlueStacks Android Service is gewijzigd van automatisch starten in starten op aanvraag.
Record Number: 5784
Source Name: Service Control Manager
Time Written: 20131014091003.065273-000
Event Type: Informatie
User: NT AUTHORITY\SYSTEM

=====Application event log=====

Computer Name: --------
Event Code: 1005
Message: Gegevens voor het Programma voor verbetering van de gebruikerservaring zijn samengevoegd in bestanden die voor analyse naar Microsoft worden verzonden. Deze bestanden worden alleen verzonden als de gebruiker deelneemt aan het Windows-programma voor verbetering van de gebruikerservaring.
Record Number: 40590
Source Name: Microsoft-Windows-CEIP
Time Written: 20141202185710.000000-000
Event Type: Informatie
User:

Computer Name: Studiebol
Event Code: 1001
Message: Foutbucket 90800913837, type 5
Naam van gebeurtenis: WindowsUpdateFailure2
Antwoord: Niet beschikbaar
Id van CAB-bestand: 0

Handtekening van probleem:
P1: 7.9.9600.17404
P2: 80240055
P3: EC7D0E7D-BB3F-4674-AF02-A32293A19F5F
P4: Download
P5: 101
P6: Unmanaged {117CAB2D-82B1-4B5A-A08C-4D62DBEE7782}
P7: 0
P8:
P9:
P10:

Toegevoegde bestanden:

Deze bestanden zijn mogelijk hier beschikbaar:
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\NonCritical_7.9.9600.17404_4517e7ad1c564c3e66bedc50671e7618e3a6c31_00000000_1e1f9aea

Analysesymbool:
Opnieuw zoeken naar oplossing: 0
Rapport-id: c6af1510-7a54-11e4-beb3-08606e947d46
Rapportstatus: 0
Opgedeelde bucket: ff9ea6adc03ad4b6bec3e91e625f3f76
Record Number: 40589
Source Name: Windows Error Reporting
Time Written: 20141202185607.000000-000
Event Type: Informatie
User:

Computer Name: ------
Event Code: 1001
Message: Foutbucket , type 0
Naam van gebeurtenis: WindowsUpdateFailure2
Antwoord: Niet beschikbaar
Id van CAB-bestand: 0

Handtekening van probleem:
P1: 7.9.9600.17404
P2: 80240055
P3: EC7D0E7D-BB3F-4674-AF02-A32293A19F5F
P4: Download
P5: 101
P6: Unmanaged {117CAB2D-82B1-4B5A-A08C-4D62DBEE7782}
P7: 0
P8:
P9:
P10:

Toegevoegde bestanden:

Deze bestanden zijn mogelijk hier beschikbaar:
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_7.9.9600.17404_4517e7ad1c564c3e66bedc50671e7618e3a6c31_00000000_cab_18079712

Analysesymbool:
Opnieuw zoeken naar oplossing: 0
Rapport-id: c6af1510-7a54-11e4-beb3-08606e947d46
Rapportstatus: 4
Opgedeelde bucket:
Record Number: 40588
Source Name: Windows Error Reporting
Time Written: 20141202185606.000000-000
Event Type: Informatie
User:

Computer Name: ----------
Event Code: 1001
Message: Foutbucket , type 0
Naam van gebeurtenis: WindowsUpdateFailure2
Antwoord: Niet beschikbaar
Id van CAB-bestand: 0

Handtekening van probleem:
P1: 7.9.9600.17404
P2: 80240055
P3: EC7D0E7D-BB3F-4674-AF02-A32293A19F5F
P4: Download
P5: 101
P6: Unmanaged {117CAB2D-82B1-4B5A-A08C-4D62DBEE7782}
P7: 0
P8:
P9:
P10:

Toegevoegde bestanden:

Deze bestanden zijn mogelijk hier beschikbaar:


Analysesymbool:
Opnieuw zoeken naar oplossing: 0
Rapport-id: c6af1510-7a54-11e4-beb3-08606e947d46
Rapportstatus: 262144
Opgedeelde bucket:
Record Number: 40587
Source Name: Windows Error Reporting
Time Written: 20141202185606.000000-000
Event Type: Informatie
User:

Computer Name: --------
Event Code: 903
Message: De Software Protection-service is gestopt.

Record Number: 40586
Source Name: Microsoft-Windows-Security-SPP
Time Written: 20141202185601.000000-000
Event Type: Informatie
User:

=====Security event log=====

Computer Name: -------
Event Code: 4797
Message: Er is geprobeerd een query uit te voeren op het bestaan van een blanco wachtwoord voor een account.

Onderwerp:
Beveiligings-id: S-1-5-19
Accountnaam: LOCAL SERVICE
Accountdomein: NT AUTHORITY
Aanmeldings-id: 0x3E5

Extra informatie:
Werkstation beller: ----------
Naam doelaccount: Administrator
Domein doelaccount: -------
Record Number: 87397
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20150118133517.156306-000
Event Type: Controle geslaagd
User:

Computer Name: ----------
Event Code: 4797
Message: Er is geprobeerd een query uit te voeren op het bestaan van een blanco wachtwoord voor een account.

Onderwerp:
Beveiligings-id: S-1-5-19
Accountnaam: LOCAL SERVICE
Accountdomein: NT AUTHORITY
Aanmeldings-id: 0x3E5

Extra informatie:
Werkstation beller: --------
Naam doelaccount: ---------
Domein doelaccount: ---------
Record Number: 87396
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20150118133517.134390-000
Event Type: Controle geslaagd
User:

Computer Name: ----------
Event Code: 4797
Message: Er is geprobeerd een query uit te voeren op het bestaan van een blanco wachtwoord voor een account.

Onderwerp:
Beveiligings-id: S-1-5-19
Accountnaam: LOCAL SERVICE
Accountdomein: NT AUTHORITY
Aanmeldings-id: 0x3E5

Extra informatie:
Werkstation beller: --------
Naam doelaccount: ---------
Domein doelaccount: --------
Record Number: 87395
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20150118133517.133389-000
Event Type: Controle geslaagd
User:

Computer Name: -------
Event Code: 4797
Message: Er is geprobeerd een query uit te voeren op het bestaan van een blanco wachtwoord voor een account.

Onderwerp:
Beveiligings-id: S-1-5-19
Accountnaam: LOCAL SERVICE
Accountdomein: NT AUTHORITY
Aanmeldings-id: 0x3E5

Extra informatie:
Werkstation beller: -------
Naam doelaccount: HomeGroupUser$
Domein doelaccount: ---------
Record Number: 87394
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20150118133517.131887-000
Event Type: Controle geslaagd
User:

Computer Name: --------
Event Code: 4797
Message: Er is geprobeerd een query uit te voeren op het bestaan van een blanco wachtwoord voor een account.

Onderwerp:
Beveiligings-id: S-1-5-19
Accountnaam: LOCAL SERVICE
Accountdomein: NT AUTHORITY
Aanmeldings-id: 0x3E5

Extra informatie:
Werkstation beller: ------
Naam doelaccount: Gast
Domein doelaccount: ------
Record Number: 87393
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20150118133517.130387-000
Event Type: Controle geslaagd
User:

======Environment variables======

"FP_NO_HOST_CHECK"=NO
"USERNAME"=SYSTEM
"ComSpec"=%SystemRoot%\system32\cmd.exe
"TMP"=%SystemRoot%\TEMP
"OS"=Windows_NT
"windir"=%SystemRoot%
"PROCESSOR_ARCHITECTURE"=AMD64
"TEMP"=%SystemRoot%\TEMP
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
"PSModulePath"=%SystemRoot%\system32\WindowsPowerShell\v1.0\Modules\
"NUMBER_OF_PROCESSORS"=2
"PROCESSOR_LEVEL"=6
"PROCESSOR_IDENTIFIER"=Intel64 Family 6 Model 58 Stepping 9, GenuineIntel
"PROCESSOR_REVISION"=3a09
"Path"=C:\Program Files (x86)\Intel\iCLS Client\;C:\Program Files\Intel\iCLS Client\;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Intel\OpenCL SDK\2.0\bin\x86;C:\Program Files (x86)\Intel\OpenCL SDK\2.0\bin\x64;C:\Program Files\Intel\Intel(R) Management Engine Components\DAL;C:\Program Files\Intel\Intel(R) Management Engine Components\IPT;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT
"configsetroot"=%SystemRoot%\ConfigSetRoot
"CM2014DIR"=C:\Program Files (x86)\Common Files\Autodesk Shared\Materials\
"ILBDIR"=C:\Program Files (x86)\Common Files\Autodesk Shared\Materials\

-----------------EOF-----------------

Please help me :pray:
 
nuuub
PC Web Plus - Member
PC Web Plus - Member
Onderwerp Auteur
Berichten: 20
Lid geworden op: zo 25 okt, 2015 19:40:44
Kennisniveau: (3) Expert
OS: windows
AV: avg
AM: superantispyware
FW: avg

Re: continue live installation shit

zo 25 okt, 2015 20:18:27

hierbij met zelfe log-files als bijlage
Je hebt niet voldoende permissies om de bijlagen van dit bericht te bekijken.
 
PeterJ
Security Helper
Security Helper
Berichten: 6912
Lid geworden op: zo 17 mar, 2013 23:40:56

Re: continue live installation shit

zo 25 okt, 2015 20:48:27

Hallo en welkom,

Post aub alle logbestanden als bijlage.
Verander aub niets in de logbestanden. We kunnen verder niets met je gebruikersnaam of computernaam.
Het maakt de kans op fouten in de aangeboden fixen alleen maar groter!

Stap 1:
Sluit alle openstaande programma's.
De-installeer via Configuratiescherm - Programma's en onderdelen:
    Free YouTube Downloader 4.0.344

Stap 2:
Download Afbeelding Zoek.zip naar het bureaublad.
  • Schakel je antivirus- en antispywareprogramma's uit, mogelijk kunnen ze conflicteren met zoek.exe
    (hier of hier) kan je lezen hoe je dat doet.
  • Wanneer je internet browser of virusscanner een melding geeft dat dit bestand onveilig zou zijn kan je dat negeren, het is namelijk een onterechte waarschuwing.
  • Pak het bestand Zoek.zip uit en verplaats Zoek.exe naar je bureaublad.
  • Windows XP: Dubbelklik op Zoek.exe om de tool te starten.
  • Windows Vista,7,8,8.1 en 10: Rechtsklik op Zoek.exe en klik op Als administrator uitvoeren.
  • Wacht geduldig totdat Zoek verschijnt, dit zal maximaal 1 minuut duren.
  • Kopieer nu onderstaande code en plak die in het grote invulvenster:
  • Note: Dit script is speciaal bedoeld voor deze PC, gebruik dit dan ook niet op andere PC's met een gelijkaardig probleem.
    standardsearch;
    installedprogs;
    emptyjava;
    emptyflash;
    emptyiecache;
    emptyffcache;
    emptychrcache;
    msconfigcheck;
    C:\WINDOWS\tasks\JJkobB1IDzpAmgs7fEaeu3Lz.job;f
    C:\WINDOWS\tasks\SCUPMEXJRMGTLWNN.job;f
    C:\WINDOWS\tasks\To9snHJTu9MfknCK2.job;f
    C:\WINDOWS\tasks\xrRu9rYrwaGYn5dBfmct4.job;f
    C:\Users\-------\AppData\Roaming\JJkobB1IDzpAmgs7fEaeu3Lz.exe;virustotal
    C:\ProgramData\Service1291;fs
    C:\Users\-------\AppData\Roaming\To9snHJTu9MfknCK2.exe;f
    C:\Users\--------\AppData\Roaming\xrRu9rYrwaGYn5dBfmct4.exe;f
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run];r
    "AVG-Secure-Search-Update_1213b"=-;r
    C:\Users\---------\AppData\Roaming\AVG 1213b Campaign;fs
    C:\Program Files (x86)\gmsd_nl_005010123;fs
    C:\Program Files (x86)\MyBrowser;fs
    C:\Program Files (x86)\AVG SafeGuard toolbar;fs
    C:\Program Files (x86)\mbot_nl_014010123;fs
    C:\Program Files (x86)\globalUpdate;fs
    C:\ProgramData\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat;f
    C:\Program Files (x86)\Fast-Search;fs
    C:\ProgramData\28341ff220e0446c9fff27c4493d622e;fs
    C:\Program Files (x86)\Super Optimizer;fs
    C:\Users\--------\AppData\Roaming\Opera Software;fs
    C:\Program Files (x86)\Opera;fs
    C:\WINDOWS\chromebrowser.exe;fp
  • :warning_icon: Let op: Vervang in bovenstaant script de streepjes ------ door je gebruikersnaam!!!
  • Klik nu op de knop "Run Script".
  • Wacht nu geduldig af tot er een logje opent (dit kan na een herstart zijn als deze benodigd is).
  • Mocht er geen logje verschijnen, start Zoek.exe dan opnieuw en klik op zoek-results.log, de log verschijnt dan alsnog.
  • Sluit het geopende logje.
  • Post het bestand c:\zoek-results.log als bijlage in je volgend bericht.
  • Op het bureaublad zal nu tevens een bestand genaamd "sample_<datum>_<tijdstip>.zip" staan.
  • Upload dit bestand naar http://www.filedropper.com en plaats het linkje in je volgend bericht.
Member of UNITE (Unified Network of Instructors and Trusted Eliminators.)
 
nuuub
PC Web Plus - Member
PC Web Plus - Member
Onderwerp Auteur
Berichten: 20
Lid geworden op: zo 25 okt, 2015 19:40:44
Kennisniveau: (3) Expert
OS: windows
AV: avg
AM: superantispyware
FW: avg

Re: continue live installation shit

ma 02 nov, 2015 22:42:10

Je hebt niet voldoende permissies om de bijlagen van dit bericht te bekijken.
 
PeterJ
Security Helper
Security Helper
Berichten: 6912
Lid geworden op: zo 17 mar, 2013 23:40:56

Re: continue live installation shit

di 03 nov, 2015 00:09:58

Waarom heb je AVG 8.5 geïnstalleerd terwijl er sporen van het nieuwere AVG 2014 aanwezig zijn ?

Stap 1:
Start Google Chrome.
Klik op de knop met de 3 liggende streepjes.
Klik op Instellingen.
Klik op Geavanceerde instellingen weergeven....
Vink de instelling uit zoals op onderstaande afbeelding:
Afbeelding

Stap 2:
Start Zoek opnieuw:
  • Schakel je antivirus- en antispywareprogramma's uit, mogelijk kunnen ze conflicteren met zoek.exe
    (hier of hier) kan je lezen hoe je dat doet.
  • Windows XP: Dubbelklik op Zoek.exe om de tool te starten.
  • Windows Vista,7,8,8.1 en 10: Rechtsklik op Zoek.exe en klik op Als Administrator uitvoeren.
  • Kopieer nu onderstaande code en plak die in het invulvenster:
  • Note: Dit script is speciaal bedoeld voor deze PC, gebruik dit dan ook niet op andere PC's met een gelijkaardig probleem.
    C:\Users\JANSEB~1\AppData\Local\Temp\msconfig.exe;fp
    C:\Users\JanSebastiaan\AppData\Local\Temp\beefhiiiij.exe;fp
    C:\Users\JanSebastiaan\AppData\Local\Temp\is45637729\1475077_stp\gvstb.exe;fp
    C:\Users\JanSebastiaan\AppData\Local\Temp\81445787044\S1BALE1PSw==10700.exe;fp
    C:\Users\JanSebastiaan\AppData\Local\globalUpdate;fs
    C:\Users\JanSebastiaan\AppData\Local\Opera Software;fs
    C:\Users\JanSebastiaan\Downloads\vlc-2-2-1-win32 (1).exe;f
    C:\Users\JanSebastiaan\Downloads\RSITx64 (1).exe;f
    [HKEY_USERS\S-1-5-21-4241106707-3168080580-4119086984-1001\Software\Microsoft\Windows\CurrentVersion\Run];r
    "GoogleChromeAutoLaunch_BC5241188ADF05F5293078119CA0F67C"=-;r
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run];r
    "GoogleChromeAutoLaunch_BC5241188ADF05F5293078119CA0F67C"=-;r
    C:\Program Files\McAfee.com;fs
    C:\Users\JanSebastiaan\AppData\Local\SmartWeb;fs
    C:\WINDOWS\tasks\AutoKMS.job;f
    shortcutfix;
  • Klik nu op de knop "Run Script".
  • Wacht nu geduldig af tot er een logje opent (dit kan na een herstart zijn als deze benodigd is).
  • Mocht er geen logje verschijnen, start Zoek.exe dan opnieuw en klik op zoek-results.log, de log verschijnt dan alsnog.
  • Sluit het geopende logje.
  • Post het bestand c:\zoek-results.log als bijlage in je volgend bericht.
  • Op het bureaublad zal nu tevens een nieuw bestand genaamd "sample_<datum>_<tijdstip>.zip" staan.
  • Upload dit bestand naar http://www.filedropper.com en plaats het linkje in je volgend bericht.
Member of UNITE (Unified Network of Instructors and Trusted Eliminators.)
 
nuuub
PC Web Plus - Member
PC Web Plus - Member
Onderwerp Auteur
Berichten: 20
Lid geworden op: zo 25 okt, 2015 19:40:44
Kennisniveau: (3) Expert
OS: windows
AV: avg
AM: superantispyware
FW: avg

Re: continue live installation shit

zo 08 nov, 2015 16:25:02

Geef me linkje voor downloaden (via piratebay ofsu) nieuwe AVG en ik installeer um ff...
 
nuuub
PC Web Plus - Member
PC Web Plus - Member
Onderwerp Auteur
Berichten: 20
Lid geworden op: zo 25 okt, 2015 19:40:44
Kennisniveau: (3) Expert
OS: windows
AV: avg
AM: superantispyware
FW: avg

Re: continue live installation shit

zo 08 nov, 2015 17:19:18

Je hebt niet voldoende permissies om de bijlagen van dit bericht te bekijken.
 
PeterJ
Security Helper
Security Helper
Berichten: 6912
Lid geworden op: zo 17 mar, 2013 23:40:56

Re: continue live installation shit

zo 08 nov, 2015 18:30:52

Stap 1:
Start Zoek opnieuw:
  • Schakel je antivirus- en antispywareprogramma's uit, mogelijk kunnen ze conflicteren met zoek.exe
    (hier of hier) kan je lezen hoe je dat doet.
  • Windows XP: Dubbelklik op Zoek.exe om de tool te starten.
  • Windows Vista,7,8,8.1 en 10: Rechtsklik op Zoek.exe en klik op Als Administrator uitvoeren.
  • Kopieer nu onderstaande code en plak die in het invulvenster:
  • Note: Dit script is speciaal bedoeld voor deze PC, gebruik dit dan ook niet op andere PC's met een gelijkaardig probleem.
    autoclean;
  • Klik nu op de knop "Run Script".
  • Wacht nu geduldig af tot er een logje opent (dit kan na een herstart zijn als deze benodigd is).
  • Mocht er geen logje verschijnen, start Zoek.exe dan opnieuw en klik op zoek-results.log, de log verschijnt dan alsnog.
  • Sluit het geopende logje.
  • Post het bestand c:\zoek-results.log als bijlage in je volgend bericht.

Stap 2:
Download Afbeelding AdwCleaner by Xplode naar je bureaublad.

Sluit alle openstaande programma's.
Windows XP: Dubbelklik op AdwCleaner.
Windows Vista,7,8,8.1 en 10: Rechtsklik op AdwCleaner en klik op 'Als administrator uitvoeren...'.

Klik op Scannen.
Na het scannen, klik op Verwijderen.
In het venster '- AdwCleaner – Programma's sluiten -' klik op OK.

Tijdens de opruim-actie zullen de snelkoppelingen verdwijnen, dit is normaal.
Na het verwijderen verschijnen 2 meldingen:
In het venster '- AdwCleaner – Informatie -' klik op OK.
In het venster '- AdwCleaner – Herstart benodigd -' klik op OK.

Nadat de computer herstart is, opent een logbestand.
Sluit het logbestand.
Post het bestand C:\AdwCleaner\AdwCleaner[C1].txt als bijlage in je volgend bericht.

Stap 3:
Download Afbeelding esetsmartinstaller_enu.exe.
Dubbelklik erop om het te starten.
Vink aan YES, I accept the Terms of Use.
Klik op Start
Selecteer "Enable detection of potentially unwanted applications".
Klik op "Advanced Settings".
Zet een vinkje bij:
- Remove found threats
- Scan archives
- Scan for potentially unsafe applications
- Enable Anti-Stealth technology

Let op: Schakel nu eerst je eigen virusscanner uit, het scannen met ESET gaat dan sneller.
Klik op Start
De computer wordt nu gescand. Dit kan een poos duren...
Na het scannen kan je het venster sluiten.
Let op: Schakel nu eerst je eigen virusscanner weer in.
Ga met de verkenner naar de map "C:\Program Files\ESET\ESET Online Scanner" of "C:\Program Files (x86)\ESET\ESET Online Scanner", afhankelijk van de Windows versie.
Post het daar aanwezige bestand log.txt als bijlage in je volgend bericht.
Member of UNITE (Unified Network of Instructors and Trusted Eliminators.)
 
nuuub
PC Web Plus - Member
PC Web Plus - Member
Onderwerp Auteur
Berichten: 20
Lid geworden op: zo 25 okt, 2015 19:40:44
Kennisniveau: (3) Expert
OS: windows
AV: avg
AM: superantispyware
FW: avg

Re: continue live installation shit

zo 10 jan, 2016 13:35:48

Hoe lang gaat dit nog door?

Heeft iemand nog een leuke virus / spy / spam scanner ?
Je hebt niet voldoende permissies om de bijlagen van dit bericht te bekijken.
 
PeterJ
Security Helper
Security Helper
Berichten: 6912
Lid geworden op: zo 17 mar, 2013 23:40:56

Re: continue live installation shit

zo 10 jan, 2016 13:53:24

Hoe lang gaat dit nog door?
Zolang het nodig is. Mijn vorige post was ±2 maanden geleden.
De gebruikte tools hebben nog wat opgeschoond.

Het gebruik van cracks, hacktools en dergelijke is niet aan te raden.

Zijn er nog problemen merkbaar ?
Member of UNITE (Unified Network of Instructors and Trusted Eliminators.)
 
nuuub
PC Web Plus - Member
PC Web Plus - Member
Onderwerp Auteur
Berichten: 20
Lid geworden op: zo 25 okt, 2015 19:40:44
Kennisniveau: (3) Expert
OS: windows
AV: avg
AM: superantispyware
FW: avg

Re: continue live installation shit

zo 10 jan, 2016 14:03:42

Ja. Heb tijdens het internet browsen continue een zoekbalk 'Find People" die in mijn scherm getoond wordt en niet weg geklikt kan worden.
 
PeterJ
Security Helper
Security Helper
Berichten: 6912
Lid geworden op: zo 17 mar, 2013 23:40:56

Re: continue live installation shit

zo 10 jan, 2016 14:27:09

Herstel de "Google Chrome" instellingen. Hoe je dat doet lees je HIER.

Enige verbetering nu ?
Member of UNITE (Unified Network of Instructors and Trusted Eliminators.)

Wie is er online

Gebruikers op dit forum: Geen geregistreerde gebruikers en 7 gasten