Zoek.exe v5.0.0.0 Updated 15-08-2014 Tool run by Hans on za 16-08-2014 at 0:26:48,74. Microsoft Windows 8.1 6.3.9600 x64 Running in: Normal Mode Internet Access Detected Launched: C:\Users\Hans\Downloads\zoek.exe [Scan all users] [Script inserted] ==== Older Logs ====================== C:\zoek-results1.log 2989 bytes C:\zoek-results2014-08-15-223132.log 36939 bytes C:\zoek-results2014-08-16-002515.log 770 bytes ==== Empty Folders Check ====================== C:\Users\Hans\AppData\Roaming\JOWOOD TRANSPORT GIANT user guide ==== Deleting CLSID Registry Keys ====================== ==== Deleting CLSID Registry Values ====================== ==== Deleting Services ====================== ==== Deleting Files \ Folders ====================== C:\Users\Hans\Searches deleted ==== Files Recently Created / Modified ====================== ====== C:\WINDOWS ==== ====== C:\Users\Hans\AppData\Local\Temp ==== 2014-08-16 00:26:49 D11FB7A5078631BE2E183DC56FCD5375 43008 ----a-w- C:\Users\Hans\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpkqjfdp.dll ====== Java Cache ===== ====== C:\WINDOWS\SysWOW64 ===== 2014-08-13 19:56:08 FF4A917DD7C387BD2715A5F67307FED1 2184704 ----a-w- C:\WINDOWS\SysWOW64\iertutil.dll 2014-08-13 19:56:08 E70C00791A18866BB23B3A652E3390A0 2001920 ----a-w- C:\WINDOWS\SysWOW64\inetcpl.cpl 2014-08-13 19:56:08 6D017C0E499443ACDE3D9B5DCD753F32 1169920 ----a-w- C:\WINDOWS\SysWOW64\urlmon.dll 2014-08-13 19:56:08 1A05CFA45B6AEBFCCC835DCF68CBD1D0 526336 ----a-w- C:\WINDOWS\SysWOW64\msfeeds.dll 2014-08-13 19:56:07 90FF511B751A0327D07C4073760F1578 11772928 ----a-w- C:\WINDOWS\SysWOW64\ieframe.dll 2014-08-13 19:56:06 E9B28B60C0272E2E1E462E6FB38E6B55 367104 ----a-w- C:\WINDOWS\SysWOW64\dxtmsft.dll 2014-08-13 19:56:06 239575F9EA0D227516843EEE8B7342CA 239616 ----a-w- C:\WINDOWS\SysWOW64\dxtrans.dll 2014-08-13 19:56:05 7C1BFC2ABE297BCA1A7BA77A8292C088 4204032 ----a-w- C:\WINDOWS\SysWOW64\jscript9.dll 2014-08-13 19:56:05 18A3154606E3F8945956948A4E708007 704512 ----a-w- C:\WINDOWS\SysWOW64\ieapfltr.dll 2014-08-13 19:56:03 444EB30B1610A35FC99D62A91B2BCAA7 69632 ----a-w- C:\WINDOWS\SysWOW64\mshtmled.dll 2014-08-13 19:56:03 24FA5F74D3B4BA62539DF87285BA934E 597504 ----a-w- C:\WINDOWS\SysWOW64\jscript9diag.dll 2014-08-13 19:56:02 8453DDF167CE2986AA4AB04BC6824925 17524224 ----a-w- C:\WINDOWS\SysWOW64\mshtml.dll 2014-08-13 19:55:57 030041C8800A1781134B6EC3E3EF3F9C 291840 ----a-w- C:\WINDOWS\SysWOW64\iedkcs32.dll 2014-08-13 19:55:56 FEE3E022B00A5165ED645E38C1E6C776 60416 ----a-w- C:\WINDOWS\SysWOW64\JavaScriptCollectionAgent.dll 2014-08-13 19:55:56 B945BAA81B4805AD6BDDF4D026DCFB47 1792512 ----a-w- C:\WINDOWS\SysWOW64\wininet.dll 2014-08-13 19:55:56 9D16B568E318F49535AD72539C9997C2 455168 ----a-w- C:\WINDOWS\SysWOW64\vbscript.dll 2014-08-13 19:55:56 272420427EB96EA052C719AA796C09F2 61952 ----a-w- C:\WINDOWS\SysWOW64\MshtmlDac.dll 2014-08-13 19:55:54 128EC9879D462F89829E663417FE5DBD 710144 ----a-w- C:\WINDOWS\SysWOW64\rpcrt4.dll 2014-08-13 19:55:38 2C01D8EA2B0FA834597FCD96AAAE4F52 406400 ----a-w- C:\WINDOWS\SysWOW64\dxgi.dll 2014-08-13 19:55:37 38045850ACB96313A1983A8803302906 35480 ----a-w- C:\WINDOWS\SysWOW64\TsWpfWrp.exe 2014-08-13 19:55:33 DB3ED0BA26D7C598481A23E7D06A370E 2344448 ----a-w- C:\WINDOWS\SysWOW64\Wpc.dll 2014-08-13 19:55:30 949E0E42DAAD0418513B44C31A697CA5 1797896 ----a-w- C:\WINDOWS\SysWOW64\d3d9.dll 2014-08-13 19:55:30 5BD2BD14753D3B0ADDE842CDF25A4C60 2144984 ----a-w- C:\WINDOWS\SysWOW64\mfcore.dll 2014-08-13 19:55:29 EA15CC7B75A2DE287E3B0C266A35490C 235008 ----a-w- C:\WINDOWS\SysWOW64\framedynos.dll 2014-08-13 19:55:29 E65B5352AD0743F1F59BDA9466719EFE 265216 ----a-w- C:\WINDOWS\SysWOW64\SkyDriveShell.dll 2014-08-13 19:55:29 E4783EB6A6B2D04F3B541B378E843617 229888 ----a-w- C:\WINDOWS\SysWOW64\dhcpcore6.dll 2014-08-13 19:55:29 E28501E3A241DDC5DC65382E55661B1D 285696 ----a-w- C:\WINDOWS\SysWOW64\dhcpcore.dll 2014-08-13 19:55:29 BA6E52B0D82682EDE4B49D9CCC7D529B 207360 ----a-w- C:\WINDOWS\SysWOW64\framedyn.dll 2014-08-13 19:55:29 A750BB0258ECF6265A903905A0B14EB3 198656 ----a-w- C:\WINDOWS\SysWOW64\WebClnt.dll 2014-08-13 19:55:29 855D508F0053CEDC3BBAF2CB245A674A 1035264 ----a-w- C:\WINDOWS\SysWOW64\actxprxy.dll 2014-08-13 19:55:29 4E07710A2C9EA43E7509BF7D0452430E 106496 ----a-w- C:\WINDOWS\SysWOW64\Robocopy.exe 2014-08-13 19:55:29 1E14463F10B324B02EB2DA7415345D15 1473080 ----a-w- C:\WINDOWS\SysWOW64\ntdll.dll 2014-08-13 19:55:29 0CCDFED2DFCD4FBA73EE989249379458 52736 ----a-w- C:\WINDOWS\SysWOW64\ncobjapi.dll 2014-08-13 19:55:28 BEA7A26C2C22381B6DD88758352B9D9B 62976 ----a-w- C:\WINDOWS\SysWOW64\dhcpcsvc.dll 2014-08-13 19:55:28 57E0A896C38C41C8B5B7F3127F8FD0D9 56320 ----a-w- C:\WINDOWS\SysWOW64\dhcpcsvc6.dll 2014-08-13 19:55:28 191B7F25BE13D9F9E56B2B4EA595AC62 11776 ----a-w- C:\WINDOWS\SysWOW64\d3d8thk.dll 2014-08-13 19:55:21 FBE8AE41ED2A9FE4C2DE069C522CA9C0 12711424 ----a-w- C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll 2014-08-13 19:55:21 854E970293BA92F9BB69FFD1CE051D9C 189016 ----a-w- C:\WINDOWS\SysWOW64\rsaenh.dll 2014-08-13 19:55:21 684CF6A72A8DF7D66D262AC4A6E07845 270848 ----a-w- C:\WINDOWS\SysWOW64\DaOtpCredentialProvider.dll 2014-08-13 19:55:19 DBC4D46A7DDC14D1D1ED4B613F9E41A4 1064448 ----a-w- C:\WINDOWS\SysWOW64\gdi32.dll 2014-08-13 19:54:18 86DB4BA87BAF3D467D04821602E586A9 3304448 ----a-w- C:\WINDOWS\SysWOW64\msi.dll 2014-08-13 19:54:18 16CDD058883E38FB43D582FB080F721A 2318336 ----a-w- C:\WINDOWS\SysWOW64\authui.dll 2014-08-13 19:54:17 F8D0951A75826AD557CFAC323A936AA6 281088 ----a-w- C:\WINDOWS\SysWOW64\msihnd.dll ====== C:\WINDOWS\SysWOW64\drivers ===== ====== C:\WINDOWS\Sysnative ===== 2014-08-13 19:56:08 FE7D99399F7761AA2695A7B1AD30DAAF 1431040 ----a-w- C:\WINDOWS\Sysnative\urlmon.dll 2014-08-13 19:56:08 1FD1F16C35946BA28FDEB40F18B7729D 631808 ----a-w- C:\WINDOWS\Sysnative\msfeeds.dll 2014-08-13 19:56:07 39A85C005BCDEEF4092646EBBC2526AA 2087936 ----a-w- C:\WINDOWS\Sysnative\inetcpl.cpl 2014-08-13 19:56:06 DB382D89D8004F40BD2C55BAE6A15B30 2774528 ----a-w- C:\WINDOWS\Sysnative\iertutil.dll 2014-08-13 19:56:06 1B26610C1659EF54ED000233FB96F20C 13547008 ----a-w- C:\WINDOWS\Sysnative\ieframe.dll 2014-08-13 19:56:05 F00D0AE7648CA45C6434E2885485BE0B 452096 ----a-w- C:\WINDOWS\Sysnative\dxtmsft.dll 2014-08-13 19:56:05 2639E152D246F2A651F09764807CA153 85504 ----a-w- C:\WINDOWS\Sysnative\mshtmled.dll 2014-08-13 19:56:05 1DE8B71A1C7D8943034188556AF50B07 292864 ----a-w- C:\WINDOWS\Sysnative\dxtrans.dll 2014-08-13 19:56:04 BAC44396088ECC1C9021ED3E3345337C 846336 ----a-w- C:\WINDOWS\Sysnative\ieapfltr.dll 2014-08-13 19:56:04 920F690FC7424DE71888AA2E46E917EA 758272 ----a-w- C:\WINDOWS\Sysnative\jscript9diag.dll 2014-08-13 19:56:04 472C409F9B0FF67C1015F511C73E1889 5824512 ----a-w- C:\WINDOWS\Sysnative\jscript9.dll 2014-08-13 19:56:03 ECA387DCD57F683C52171C766CF400F0 23645696 ----a-w- C:\WINDOWS\Sysnative\mshtml.dll 2014-08-13 19:55:57 8E71A5CB5312B8392D4DA4CA37BB5868 2266624 ----a-w- C:\WINDOWS\Sysnative\wininet.dll 2014-08-13 19:55:57 38D14F3D0A289050CA9BF8E98F37313F 333312 ----a-w- C:\WINDOWS\Sysnative\iedkcs32.dll 2014-08-13 19:55:56 C02C78DE9BB4E68F6C78B1588ADD6ADC 83968 ----a-w- C:\WINDOWS\Sysnative\MshtmlDac.dll 2014-08-13 19:55:56 6ED6DA2A04F8F0C9BDAD647284BAEFB6 548352 ----a-w- C:\WINDOWS\Sysnative\vbscript.dll 2014-08-13 19:55:56 52D2151908C2A6388B6561A373488F6F 692736 ----a-w- C:\WINDOWS\Sysnative\ie4uinit.exe 2014-08-13 19:55:56 19FA60D3AE1804A559306DE931A5B415 72704 ----a-w- C:\WINDOWS\Sysnative\JavaScriptCollectionAgent.dll 2014-08-13 19:55:54 1BB9CC78C91536CBA7B04B61ED0F85C4 1273184 ----a-w- C:\WINDOWS\Sysnative\rpcrt4.dll 2014-08-13 19:55:38 59EAFAE3A34B4925990A2E679CA91C5B 517528 ----a-w- C:\WINDOWS\Sysnative\dxgi.dll 2014-08-13 19:55:38 454978FB3D24DE5C4199162D5F81FBEE 2133504 ----a-w- C:\WINDOWS\Sysnative\dwmcore.dll 2014-08-13 19:55:37 6DBE73C09215E281F4283641144110A5 35480 ----a-w- C:\WINDOWS\Sysnative\TsWpfWrp.exe 2014-08-13 19:55:34 E7DE316FEEFC79327CFAD8F527979CC0 3118080 ----a-w- C:\WINDOWS\Sysnative\Wpc.dll 2014-08-13 19:55:34 E2F4125BFAC99244088324A1841C0B83 3048880 ----a-w- C:\WINDOWS\Sysnative\WpcMon.exe 2014-08-13 19:55:33 BCCFB97B1B68DD18F2BDACFE37409386 716800 ----a-w- C:\WINDOWS\Sysnative\SkyDriveTelemetry.dll 2014-08-13 19:55:33 6BC31FB4E24A962C98801D3687A984C0 2861056 ----a-w- C:\WINDOWS\Sysnative\WpcWebSync.dll 2014-08-13 19:55:33 11FD8DDAB6014EECCE88F1F581604C30 1120256 ----a-w- C:\WINDOWS\Sysnative\SkyDrive.exe 2014-08-13 19:55:33 04142EC4BDD7F502922914F65A5EE1D1 4756992 ----a-w- C:\WINDOWS\Sysnative\SyncEngine.dll 2014-08-13 19:55:30 EA432A85ABF371E14FB364D5F4405897 403968 ----a-w- C:\WINDOWS\Sysnative\vpnike.dll 2014-08-13 19:55:30 CED9FA1ECCF3E6B7028940FE22C69B40 1726224 ----a-w- C:\WINDOWS\Sysnative\ntdll.dll 2014-08-13 19:55:30 C1E44A99F7CF8C3A08CD5ADDF451636C 2125344 ----a-w- C:\WINDOWS\Sysnative\d3d9.dll 2014-08-13 19:55:30 B6E947CE54A5AAD55484E0D3BC2D5948 1025536 ----a-w- C:\WINDOWS\Sysnative\localspl.dll 2014-08-13 19:55:30 98D0985521BF8F7086EA9C860898A1EE 721408 ----a-w- C:\WINDOWS\Sysnative\fveapi.dll 2014-08-13 19:55:30 0CD0356C5BBCFDC1B7BCEEDE74AB348B 2140888 ----a-w- C:\WINDOWS\Sysnative\mfcore.dll 2014-08-13 19:55:30 05DE04005CE0D84D0E6AD21CAEB369C6 353280 ----a-w- C:\WINDOWS\Sysnative\dhcpcore.dll 2014-08-13 19:55:29 FBB1841434072FFA76E4AD287448E34A 262656 ----a-w- C:\WINDOWS\Sysnative\framedyn.dll 2014-08-13 19:55:29 E07C80468D0C599BFF01D9D4EC7AEDC3 339456 ----a-w- C:\WINDOWS\Sysnative\bdesvc.dll 2014-08-13 19:55:29 DEA76F90F9777E3427D70E380222B23B 1063424 ----a-w- C:\WINDOWS\Sysnative\IKEEXT.DLL 2014-08-13 19:55:29 D71845D255EA3FDC96A2DED98EE4C7D9 2844160 ----a-w- C:\WINDOWS\Sysnative\actxprxy.dll 2014-08-13 19:55:29 D3883FBCA97D10C8A39632D6CDDC6E85 65024 ----a-w- C:\WINDOWS\Sysnative\dhcpcsvc6.dll 2014-08-13 19:55:29 D261A12A43D33122CB90E70D3BC1CC68 226816 ----a-w- C:\WINDOWS\Sysnative\WebClnt.dll 2014-08-13 19:55:29 7E1EBDB3424337ABB553F249A7811D94 87552 ----a-w- C:\WINDOWS\Sysnative\dhcpcsvc.dll 2014-08-13 19:55:29 6CDCCD5323EEB8EBD66E02CB8C9C703F 118272 ----a-w- C:\WINDOWS\Sysnative\winbici.dll 2014-08-13 19:55:29 6B374D279DC423FE69DB8DD1401E84FC 301056 ----a-w- C:\WINDOWS\Sysnative\framedynos.dll 2014-08-13 19:55:29 61FE99A86352AD6E27FA480CDC8B225A 285696 ----a-w- C:\WINDOWS\Sysnative\SkyDriveShell.dll 2014-08-13 19:55:29 2616E8E9C8B66A67CFB6197E9517A2F2 123392 ----a-w- C:\WINDOWS\Sysnative\Robocopy.exe 2014-08-13 19:55:29 20FB137ADDE1255F15F265A7BD9579BE 827392 ----a-w- C:\WINDOWS\Sysnative\BFE.DLL 2014-08-13 19:55:29 1824052F17B12B5D7B21445B869EE9F2 71168 ----a-w- C:\WINDOWS\Sysnative\ncobjapi.dll 2014-08-13 19:55:29 10AC9494ECE22A2362E4E4D98C528D01 271872 ----a-w- C:\WINDOWS\Sysnative\dhcpcore6.dll 2014-08-13 19:55:28 CFD6DBED27511D7A5FBE33AFA7E6B669 76800 ----a-w- C:\WINDOWS\Sysnative\BulkOperationHost.exe 2014-08-13 19:55:28 B7CC32E00C5C5152D221DF182827F58E 50745 ----a-w- C:\WINDOWS\Sysnative\srms.dat 2014-08-13 19:55:28 71BAEAFD05B3040173F5BBEA2CFE9607 997888 ----a-w- C:\WINDOWS\Sysnative\reseteng.dll 2014-08-13 19:55:22 50A49F3F16EF82E30BFB11E6B6A8F4A6 16871936 ----a-w- C:\WINDOWS\Sysnative\Windows.UI.Xaml.dll 2014-08-13 19:55:21 B312E157D20E727F30EAB3A250441B6F 284672 ----a-w- C:\WINDOWS\Sysnative\WUDFHost.exe 2014-08-13 19:55:21 9CDC2059A23E3C9B57696178508777E7 99840 ----a-w- C:\WINDOWS\Sysnative\WUDFSvc.dll 2014-08-13 19:55:21 42D257559F97B30A94A027EB4555C62F 323584 ----a-w- C:\WINDOWS\Sysnative\DaOtpCredentialProvider.dll 2014-08-13 19:55:21 313117AE2B0986ED7D3AA6AE10603239 216368 ----a-w- C:\WINDOWS\Sysnative\rsaenh.dll 2014-08-13 19:55:21 1A54E3DF2CBB8DBE8A17C87BB07E3A7E 209408 ----a-w- C:\WINDOWS\Sysnative\WUDFPlatform.dll 2014-08-13 19:55:21 08DCA300264238F9AE941302321F3D54 423768 ----a-w- C:\WINDOWS\Sysnative\hal.dll 2014-08-13 19:55:20 00AD15C6BA3C337CB68A476C0AD05338 918528 ----a-w- C:\WINDOWS\Sysnative\MrmCoreR.dll 2014-08-13 19:55:19 F381B380B7B2704EA4C0F8D8C49C1C50 623616 ----a-w- C:\WINDOWS\Sysnative\MDMAgent.exe 2014-08-13 19:55:19 A39C4AB750E0AD4431C7B7F46AB0EBED 4148224 ----a-w- C:\WINDOWS\Sysnative\win32k.sys 2014-08-13 19:55:19 87CEF71F9D5951C9379D2F956C07C37D 1336624 ----a-w- C:\WINDOWS\Sysnative\gdi32.dll 2014-08-13 19:54:18 68F887EF33C09CDA957A51ECE871D642 2642944 ----a-w- C:\WINDOWS\Sysnative\authui.dll 2014-08-13 19:54:18 28E0C3AAA68579ABD9A27B92DFD5F119 2790912 ----a-w- C:\WINDOWS\Sysnative\msi.dll 2014-08-13 19:54:17 10D8859CF01C1284603582ABD9B0482C 114520 ----a-w- C:\WINDOWS\Sysnative\consent.exe 2014-08-13 19:54:17 08914C8989AB93F5EC3A452D014E2C8D 356352 ----a-w- C:\WINDOWS\Sysnative\msihnd.dll ====== C:\WINDOWS\Sysnative\drivers ===== 2014-08-13 19:55:38 5C42CEE3E2018E1DFC6E3E17240A432A 206848 ----a-w- C:\WINDOWS\Sysnative\drivers\mrxsmb20.sys 2014-08-13 19:55:38 313DCE665B57000B18CB26C6B6A10DFE 1557848 ----a-w- C:\WINDOWS\Sysnative\drivers\dxgkrnl.sys 2014-08-13 19:55:29 7A1A3F213CDB3363D179D5014272025D 402432 ----a-w- C:\WINDOWS\Sysnative\drivers\mrxsmb.sys 2014-08-13 19:55:29 674A4702E4E144E8710ED1A2EC6DD049 96768 ----a-w- C:\WINDOWS\Sysnative\drivers\agilevpn.sys 2014-08-13 19:55:29 65ED7B9CFEA893DF7748D5FF692690DE 38912 ----a-w- C:\WINDOWS\Sysnative\drivers\vwifimp.sys 2014-08-13 19:55:28 35BF5C5F5E3C9902C98978C7640574DA 71680 ----a-w- C:\WINDOWS\Sysnative\drivers\vwififlt.sys 2014-08-13 19:55:21 FE0ADF5028EB8C1339B66B3AEDE3FEF9 440664 -c--a-w- C:\WINDOWS\Sysnative\drivers\usbport.sys 2014-08-13 19:55:21 D79920BE4E6683D3AB50F71457A4F6C6 27480 -c--a-w- C:\WINDOWS\Sysnative\drivers\usbd.sys 2014-08-13 19:55:21 D537815E450A149752C15868392AD1F3 110592 ----a-w- C:\WINDOWS\Sysnative\drivers\WUDFPf.sys 2014-08-13 19:55:21 93435654DCA210298BA0F986EB51C679 419672 -c--a-w- C:\WINDOWS\Sysnative\drivers\usbhub.sys 2014-08-13 19:55:21 83C9C45D59C72FEFDAE9A5686BE31FEA 467800 -c--a-w- C:\WINDOWS\Sysnative\drivers\USBHUB3.SYS 2014-08-13 19:55:21 7CCBBCEE408A5DBE3FE47297DB5A6CFC 227840 ----a-w- C:\WINDOWS\Sysnative\drivers\WUDFRd.sys 2014-08-13 19:55:21 48BA326A3DBA5B5BEB5F2777F4618696 89944 -c--a-w- C:\WINDOWS\Sysnative\drivers\usbehci.sys 2014-08-13 19:55:21 25AC0B50A71938890970E1508F107196 2518360 ----a-w- C:\WINDOWS\Sysnative\drivers\tcpip.sys 2014-08-13 19:55:21 064260B3A5868AC894A4943543BC7AB7 37376 -c--a-w- C:\WINDOWS\Sysnative\drivers\usbuhci.sys 2014-07-17 09:23:14 B4BDE3F758A34658A37DFED3D9783CD8 88480 ----a-w- C:\WINDOWS\Sysnative\drivers\atksgt.sys 2014-07-17 09:23:14 955982BF4421B77722196552B62E8DC2 46400 ----a-w- C:\WINDOWS\Sysnative\drivers\lirsgt.sys ====== C:\WINDOWS\Tasks ====== 2014-08-11 19:19:25 -------- d-----w- C:\WINDOWS\Sysnative\Tasks\hela ====== C:\WINDOWS\Temp ====== ======= C:\Program Files ===== 2014-08-15 19:47:40 -------- d-----w- C:\Program Files\trend micro 2014-08-14 16:03:48 -------- d-----w- C:\Program Files\JAM Software 2014-08-04 17:22:26 -------- d-----w- C:\Program Files\Atari ======= C:\PROGRA~2 ===== 2014-08-11 19:19:25 -------- d-----w- C:\PROGRA~2\hela 2014-08-10 19:14:21 -------- d-----w- C:\PROGRA~2\DiskDiagnostic 2014-07-24 10:26:22 -------- d-----w- C:\PROGRA~2\EZ YouTube Video Downloader ======= C: ===== ====== C:\Users\Hans\AppData\Roaming ====== 2014-08-15 22:30:49 -------- d-----w- C:\WINDOWS\serviceprofiles\networkservice\AppData\Local\Temp 2014-08-15 22:30:49 -------- d-----w- C:\WINDOWS\serviceprofiles\Localservice\AppData\Local\Temp 2014-08-15 22:30:49 -------- d-----w- C:\Users\UpdatusUser\AppData\Local\Temp 2014-08-15 22:30:49 -------- d-----w- C:\Users\Hans\AppData\Local\Temp 2014-08-15 22:30:49 -------- d-----w- C:\Users\Default\AppData\Local\Temp 2014-08-15 22:30:49 -------- d-----w- C:\Users\Default User\AppData\Local\Temp 2014-08-14 16:03:53 -------- d-----w- C:\Users\Hans\AppData\Roaming\JAM Software 2014-08-13 14:27:32 -------- d-----w- C:\Users\Hans\AppData\Roaming\BitTorrent 2014-07-26 17:29:07 -------- d-----w- C:\Users\Hans\AppData\Local\ChromeTabExtension 2014-07-24 10:24:57 -------- d-----w- C:\Users\Hans\AppData\Roaming\PAGET TRADING 9158 user guide ====== C:\Users\Hans ====== 2014-08-15 19:47:30 8045ABB21A3BDD66A48E1ED5C0F0EF6A 1222144 ----a-w- C:\Users\Hans\Downloads\RSITx64.exe 2014-08-14 16:03:49 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TreeSize Professional 2014-08-14 16:03:04 -------- d-----w- C:\ProgramData\Licenses 2014-08-13 14:27:27 9A1CA65644B3C1A882AADC23EA6961BC 1948248 ----a-w- C:\Users\Hans\Downloads\BitTorrent.exe 2014-08-04 17:25:18 -------- d-----w- C:\ProgramData\Tages 2014-08-04 17:25:18 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Codename Panzers Cold War 2014-07-26 17:29:05 0AB2892547DBF057AC5F049A12613B08 761485 ----a-w- C:\ProgramData\ChromeTabExtension.crx ====== C: exe-files == 2014-08-15 19:47:41 9A2347903D6EDB84C10F288BC0578C1C 388608 ----a-w- C:\Program Files\trend micro\Hans.exe 2014-08-15 19:47:30 8045ABB21A3BDD66A48E1ED5C0F0EF6A 1222144 ----a-w- C:\Users\Hans\Downloads\RSITx64.exe 2014-08-15 11:38:16 E6DA59066F99F5FE0A0E6C69141E1A7E 2214299 ----a-w- C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE\Setup_EZ_YouTube_Video_Downloader_v1.2.1[7].exe 2014-08-15 11:32:21 942AE2FD99027A91E6B421BDC7F9F874 414624 ----a-w- C:\ProgramData\NVIDIA\Updatus\Packages\00006046\updatus.18784877_RUNASUSER.exe 2014-08-15 08:57:34 E6DA59066F99F5FE0A0E6C69141E1A7E 2214299 ----a-w- C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE\Setup_EZ_YouTube_Video_Downloader_v1.2.1[6].exe 2014-08-14 16:03:48 F5AFC53D6EB290D5A4AA4696C09F8EFD 13453712 ----a-w- C:\Program Files\JAM Software\TreeSize Professional\TreeSize.exe 2014-08-14 16:03:48 E61817C16C4E70FE7708D3D4E9DBE9FA 1253248 ----a-w- C:\Program Files\JAM Software\TreeSize Professional\unins000.exe 2014-08-14 11:02:26 C56CB929FDC62BA6AFA025C0DF95CA73 1836624 ----a-w- C:\Program Files (x86)\Google\Update\Download\{4DC8B4CA-1BDA-483E-B5FA-D3C12E15B62D}\36.0.1985.143\36.0.1985.143_36.0.1985.125_chrome_updater.exe 2014-08-13 19:56:08 771E149F97AA6679DEF79F0953414435 812176 ----a-w- C:\Program Files (x86)\Internet Explorer\iexplore.exe 2014-08-13 19:56:08 6A60D0D167D35A07646EBCF796D770B4 470016 ----a-w- C:\Program Files (x86)\Internet Explorer\ieinstal.exe 2014-08-13 19:56:07 E8F1154367F708BD9E5BFD6A2112B4D3 810128 ----a-w- C:\Program Files\Internet Explorer\iexplore.exe 2014-08-13 19:56:07 7D709E893B53092E3F5995FF5C3061E2 483328 ----a-w- C:\Program Files\Internet Explorer\ieinstal.exe 2014-08-13 19:55:56 52D2151908C2A6388B6561A373488F6F 692736 ----a-w- C:\Windows\System32\ie4uinit.exe 2014-08-13 19:55:37 6DBE73C09215E281F4283641144110A5 35480 ----a-w- C:\Windows\System32\TsWpfWrp.exe 2014-08-13 19:55:37 38045850ACB96313A1983A8803302906 35480 ----a-w- C:\Windows\SysWOW64\TsWpfWrp.exe 2014-08-13 19:55:34 E2F4125BFAC99244088324A1841C0B83 3048880 ----a-w- C:\Windows\System32\WpcMon.exe 2014-08-13 19:55:33 11FD8DDAB6014EECCE88F1F581604C30 1120256 ----a-w- C:\Windows\System32\SkyDrive.exe 2014-08-13 19:55:30 9289A1927350EA1F7FD4D4DC64D3F32F 1408504 ----a-w- C:\Windows\Camera\Camera.exe 2014-08-13 19:55:29 FEF22922E4FA075C6C1FFF4385D74A95 99136 ----a-w- C:\Windows\FileManager\FileManager.exe 2014-08-13 19:55:29 A83FCE24AE4103F9DA32E8707C4B4C43 124928 ----a-w- C:\Windows\SysWOW64\wbem\WMIADAP.exe 2014-08-13 19:55:29 4E07710A2C9EA43E7509BF7D0452430E 106496 ----a-w- C:\Windows\SysWOW64\Robocopy.exe 2014-08-13 19:55:29 34215162FF8440E3342071D5A7FDCB3C 1192280 ----a-w- C:\Windows\Boot\PCAT\memtest.exe 2014-08-13 19:55:29 2616E8E9C8B66A67CFB6197E9517A2F2 123392 ----a-w- C:\Windows\System32\Robocopy.exe 2014-08-13 19:55:29 1064CF2438DC44A13EFD13551915586D 321024 ----a-w- C:\Windows\System32\IME\SHARED\ImeBroker.exe 2014-08-13 19:55:29 0C8AF6461266A72BE61552BB42BC13D8 361496 ----a-w- C:\Windows\FileManager\PhotosApp.exe 2014-08-13 19:55:28 CFD6DBED27511D7A5FBE33AFA7E6B669 76800 ----a-w- C:\Windows\System32\BulkOperationHost.exe 2014-08-13 19:55:28 A09657B30C532DCF848F2B33404EF190 166400 ----a-w- C:\Windows\System32\wbem\WMIADAP.exe 2014-08-13 19:55:21 B312E157D20E727F30EAB3A250441B6F 284672 ----a-w- C:\Windows\System32\WUDFHost.exe 2014-08-13 19:55:19 F381B380B7B2704EA4C0F8D8C49C1C50 623616 ----a-w- C:\Windows\System32\MDMAgent.exe 2014-08-13 19:54:17 10D8859CF01C1284603582ABD9B0482C 114520 ----a-w- C:\Windows\System32\consent.exe 2014-08-13 14:29:18 9A1CA65644B3C1A882AADC23EA6961BC 1948248 ----a-w- C:\Users\Hans\AppData\Roaming\BitTorrent\updates\7.9.2_32895.exe 2014-08-13 14:29:18 9A1CA65644B3C1A882AADC23EA6961BC 1948248 ----a-w- C:\Users\Hans\AppData\Roaming\BitTorrent\BitTorrent.exe 2014-08-13 14:27:27 9A1CA65644B3C1A882AADC23EA6961BC 1948248 ----a-w- C:\Users\Hans\Downloads\BitTorrent.exe 2014-08-13 11:25:18 0AABF77ABFA5B5629EA56D930B6F6477 413032 ----a-w- C:\ProgramData\NVIDIA\Updatus\Packages\00006011\updatus.18774435_RUNASUSER.exe 2014-08-13 11:05:11 E6DA59066F99F5FE0A0E6C69141E1A7E 2214299 ----a-w- C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE\Setup_EZ_YouTube_Video_Downloader_v1.2.1[5].exe 2014-08-13 10:31:13 9CDD63D4063830B31CEEC77254D631FD 26882240 ----a-w- C:\Users\Hans\AppData\Local\clear.fi\Portal\AcerPortal.exe 2014-08-13 10:31:13 4737533A81861E85A6DC998A9D5938E0 1667840 ----a-w- C:\Users\Hans\AppData\Local\clear.fi\Portal\AcerPortalSetup.exe 2014-08-11 19:19:25 FA18DBA95112B34EE16B60E415F4CE4E 850944 ----a-w- C:\Program Files (x86)\hela\hela.exe 2014-08-10 21:12:10 1072B35C16ACE7525B208AD23B9DC5B2 64492 ----a-w- C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE\Setup_EZ_YouTube_Video_Downloader_v1.2.1[4].exe 2014-08-10 19:14:43 E6DA59066F99F5FE0A0E6C69141E1A7E 2214299 ----a-w- C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE\Setup_EZ_YouTube_Video_Downloader_v1.2.1[3].exe 2014-08-10 19:14:21 E8EE1259D3E0EE900D9C4E7B00E38D22 334848 ----a-w- C:\Program Files (x86)\DiskDiagnostic\DiskDiagnostic.exe === C: other files == 2014-08-16 00:26:44 82F5C942549405F61A8808D0EA0FA9E2 25575 ----a-w- C:\Users\Hans\AppData\Local\Temp\_MEI60962\resources\chrome_ext\apdfllckaahabafndbhieahigkjlhalf_live.crx 2014-08-13 19:55:38 5C42CEE3E2018E1DFC6E3E17240A432A 206848 ----a-w- C:\Windows\System32\drivers\mrxsmb20.sys 2014-08-13 19:55:38 313DCE665B57000B18CB26C6B6A10DFE 1557848 ----a-w- C:\Windows\System32\drivers\dxgkrnl.sys 2014-08-13 19:55:29 7A1A3F213CDB3363D179D5014272025D 402432 ----a-w- C:\Windows\System32\drivers\mrxsmb.sys 2014-08-13 19:55:29 674A4702E4E144E8710ED1A2EC6DD049 96768 ----a-w- C:\Windows\System32\drivers\agilevpn.sys 2014-08-13 19:55:29 65ED7B9CFEA893DF7748D5FF692690DE 38912 ----a-w- C:\Windows\System32\drivers\vwifimp.sys 2014-08-13 19:55:28 35BF5C5F5E3C9902C98978C7640574DA 71680 ----a-w- C:\Windows\System32\drivers\vwififlt.sys 2014-08-13 19:55:21 FE0ADF5028EB8C1339B66B3AEDE3FEF9 440664 -c--a-w- C:\Windows\System32\drivers\usbport.sys 2014-08-13 19:55:21 D79920BE4E6683D3AB50F71457A4F6C6 27480 -c--a-w- C:\Windows\System32\drivers\usbd.sys 2014-08-13 19:55:21 D537815E450A149752C15868392AD1F3 110592 ----a-w- C:\Windows\System32\drivers\WUDFPf.sys 2014-08-13 19:55:21 93435654DCA210298BA0F986EB51C679 419672 -c--a-w- C:\Windows\System32\drivers\usbhub.sys 2014-08-13 19:55:21 83C9C45D59C72FEFDAE9A5686BE31FEA 467800 -c--a-w- C:\Windows\System32\drivers\USBHUB3.SYS 2014-08-13 19:55:21 7CCBBCEE408A5DBE3FE47297DB5A6CFC 227840 ----a-w- C:\Windows\System32\drivers\WUDFRd.sys 2014-08-13 19:55:21 48BA326A3DBA5B5BEB5F2777F4618696 89944 -c--a-w- C:\Windows\System32\drivers\usbehci.sys 2014-08-13 19:55:21 25AC0B50A71938890970E1508F107196 2518360 ----a-w- C:\Windows\System32\drivers\tcpip.sys 2014-08-13 19:55:21 064260B3A5868AC894A4943543BC7AB7 37376 -c--a-w- C:\Windows\System32\drivers\usbuhci.sys 2014-08-13 19:55:19 A39C4AB750E0AD4431C7B7F46AB0EBED 4148224 ----a-w- C:\Windows\System32\win32k.sys ==== Startup Registry Enabled ====================== [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "Bitdefender Wallet Agent"="C:\Program Files\Bitdefender\Bitdefender\pmbxag.exe" "Bitdefender Wallet"="C:\Program Files\Bitdefender\Bitdefender\pwdmanui.exe --hidden --nowizard" "Bitdefender Agent Wallet-toepassing"="C:\Program Files\Bitdefender\Bitdefender\antispam32\bdapppassmgr.exe" [HKEY_USERS\S-1-5-21-2308228885-3134594808-8001095-1002\Software\Microsoft\Windows\CurrentVersion\Run] "GoogleDriveSync"="C:\Program Files (x86)\Google\Drive\googledrivesync.exe /autostart" "AcerCloud"="C:\Program Files (x86)\Acer\Acer Portal\acpanel_win.exe startup" "Bitdefender Wallet Agent"="C:\Program Files\Bitdefender\Bitdefender\pmbxag.exe" "Bitdefender Agent Wallet-toepassing"="C:\Program Files\Bitdefender\Bitdefender\antispam32\bdapppassmgr.exe" "Bitdefender Wallet"="C:\Program Files\Bitdefender\Bitdefender\pwdmanui.exe --hidden --nowizard" "SkyDrive"="C:\Users\Hans\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe /background" "RoboForm"="C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run] "Bitdefender Wallet Agent"="C:\Program Files\Bitdefender\Bitdefender\pmbxag.exe" "Bitdefender Wallet"="C:\Program Files\Bitdefender\Bitdefender\pwdmanui.exe --hidden --nowizard" "Bitdefender Agent Wallet-toepassing"="C:\Program Files\Bitdefender\Bitdefender\antispam32\bdapppassmgr.exe" [HKEY_USERS\S-1-5-21-2308228885-3134594808-8001095-1001\Software\Microsoft\Windows\CurrentVersion\RunOnce] "WAB Migrate"="%ProgramFiles%\Windows Mail\wab.exe /Upgrade" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "HP Software Update"="C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe" "BlueStacks Agent"="C:\Program Files (x86)\BlueStacks\HD-Agent.exe" "SunJavaUpdateSched"="C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" "BacKGround Agent"="C:\Program Files (x86)\Acer\AOP Framework\BackgroundAgent.exe" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "GoogleDriveSync"="C:\Program Files (x86)\Google\Drive\googledrivesync.exe /autostart" "AcerCloud"="C:\Program Files (x86)\Acer\Acer Portal\acpanel_win.exe startup" "Bitdefender Wallet Agent"="C:\Program Files\Bitdefender\Bitdefender\pmbxag.exe" "Bitdefender Agent Wallet-toepassing"="C:\Program Files\Bitdefender\Bitdefender\antispam32\bdapppassmgr.exe" "Bitdefender Wallet"="C:\Program Files\Bitdefender\Bitdefender\pwdmanui.exe --hidden --nowizard" "SkyDrive"="C:\Users\Hans\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe /background" "RoboForm"="C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] "BtvStack"="C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"="c:\\windows\\syswow64\\nvinit.dll" ==== Startup Registry Enabled x64 ====================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" "HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" "Persistence"="C:\WINDOWS\system32\igfxpers.exe" "RtHDVCpl"="C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s" "RtHDVBg_Dolby"="C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe /FORPCEE4 " "Classic Start Menu"="C:\Program Files\Classic Shell\ClassicStartMenu.exe -autorun" "BCSSync"="C:\Program Files\Microsoft Office\Office14\BCSSync.exe /DelayServices" "Bdagent"="C:\Program Files\Bitdefender\Bitdefender\bdagent.exe" "SynTPEnh"="%ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe " [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] "BtvStack"="C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"="C:\\Windows\\system32\\nvinitx.dll" ==== Startup Folders ====================== 2014-01-24 23:34:01 1064 ----a-w- C:\Users\Hans\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk 2014-04-09 22:42:26 1242 ----a-w- C:\Users\Hans\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MailWasherPro.lnk 2014-07-04 10:24:07 1784 ----a-w- C:\Users\Hans\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Samsung Magician.lnk 2014-07-04 14:00:17 2038 ----a-w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\DigiScan.lnk 2014-02-08 21:51:05 2103 ----a-w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk 2014-04-09 22:36:52 1156 ----a-w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\MailWasherPro.lnk ==== Task Scheduler Jobs ====================== C:\WINDOWS\tasks\AutoKMS.job --a-------- C:\Windows\AutoKMS\AutoKMS.exe [24-01-2014 23:24] C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job --a-------- [Undetermined Task] C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job --a-------- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [24-01-2014 23:32] C:\WINDOWS\tasks\Synaptics TouchPad Enhancements.job --a-------- C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [17-01-2013 04:41] ==== Other Scheduled Tasks ====================== "C:\WINDOWS\SysNative\tasks\AcerCloud" [C:\Program Files (x86)\Acer\Acer Portal\AcerPortal.exe] "C:\WINDOWS\SysNative\tasks\ALU" [C:\Program Files (x86)\Acer\Live Updater\updater.exe] "C:\WINDOWS\SysNative\tasks\ALUAgent" [C:\Program Files (x86)\Acer\Live Updater\liveupdater_agent.exe] "C:\WINDOWS\SysNative\tasks\AutoKMS" [C:\Windows\AutoKMS\AutoKMS.exe] "C:\WINDOWS\SysNative\tasks\Bitdefender Autoscan" [C:\Program Files\Bitdefender\Bitdefender\mtasklaunch.exe] "C:\WINDOWS\SysNative\tasks\CCleanerSkipUAC" ["C:\Program Files\CCleaner\CCleaner.exe"] "C:\WINDOWS\SysNative\tasks\CreateChoiceProcessTask" [C:\Windows\BrowserChoice\browserchoice.exe] "C:\WINDOWS\SysNative\tasks\Dolby Selector" [C:\Dolby PCEE4\pcee4.exe] "C:\WINDOWS\SysNative\tasks\GoogleUpdateTaskMachineCore" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe] "C:\WINDOWS\SysNative\tasks\GoogleUpdateTaskMachineUA" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe] "C:\WINDOWS\SysNative\tasks\Launch Manager" ["C:\Program Files\Acer\Acer Launch Manager\LMLauncher.exe"] "C:\WINDOWS\SysNative\tasks\Open URL by RoboForm" [C:\WINDOWS\system32\rundll32.exe url.dll,FileProtocolHandler "http://www.roboform.com/test-pass.html?aaa=KICMHMMJIMPMJMLMOJOJCNNMLMKJJJCNLMJMHMPMCNNJPMNJHMCNPMKJMJLJNJNMJJGMKMHMJMKMJNJICMIMCNGMCNOMFMGMCNOMOMCNGMJMPMPMFMJMCNNMCNGMNMPMPMCNNMJNPICMHMFMEKMICNJJCKFMOMNMMMJNHICMEKMICNJJCKJNBJCMHLOJBJMIJNKJCMJNNICMJNDJCMBJDJ"] "C:\WINDOWS\SysNative\tasks\Power Management" ["C:\Program Files\Acer\Acer Power Management\ePowerTray.exe"] "C:\WINDOWS\SysNative\tasks\Run RoboForm TaskBar Icon" [C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe] "C:\WINDOWS\SysNative\tasks\SamsungMagician" ["C:\Program Files (x86)\Samsung\Samsung Magician\Samsung Magician.exe"] "C:\WINDOWS\SysNative\tasks\Synaptics TouchPad Enhancements" [\Program Files\Synaptics\SynTP\SynTPEnh.exe] "C:\WINDOWS\SysNative\tasks\User_Feed_Synchronization-{70E9756A-C609-4976-ACCF-726599BD2C6A}" [C:\WINDOWS\system32\msfeedssync.exe] "C:\WINDOWS\SysNative\tasks\hela\hela" [C:\Program Files (x86)\hela\hela.exe] "C:\WINDOWS\SysNative\tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask" [%systemroot%\system32\sc.exe start osppsvc] ==== Firefox Extensions Registry ====================== [HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions] "{8167E8F2-A770-4EFB-BA53-8A511051CD9B}"="C:\Program Files (x86)\EZ YouTube Video Downloader\{8167E8F2-A770-4EFB-BA53-8A511051CD9B}" [15-08-2014 11:38] [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions] "{8167E8F2-A770-4EFB-BA53-8A511051CD9B}"="C:\Program Files (x86)\EZ YouTube Video Downloader\{8167E8F2-A770-4EFB-BA53-8A511051CD9B}" [15-08-2014 11:38] ==== Firefox Extensions ====================== ProfilePath: C:\Users\Hans\AppData\Roaming\Mozilla\Firefox\Profiles\r0virwe7.default - EZ YouTube Video Downloader - C:\Program Files (x86)\EZ YouTube Video Downloader\{8167E8F2-A770-4EFB-BA53-8A511051CD9B} AppDir: C:\Program Files (x86)\Mozilla Firefox - Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} ==== Firefox Plugins ====================== ==== Chrome Look ====================== HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions ccahoghmggldkcdjiebjkidpfongdfbl - C:\Program Files\Bitdefender\Bitdefender\Antispam32\pmbxcr.crx[11-04-2014 15:12] Bitdefender Wallet - Hans\AppData\Local\Google\Chrome\User Data\Default\Extensions\ccahoghmggldkcdjiebjkidpfongdfbl AdBlock - Hans\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom ==== Chromium Startpages ====================== C:\Users\Hans\AppData\Local\Google\Chrome\User Data\Default\Preferences "startup_urls": [ "https://www.google.nl/" ], ==== Set IE to Default ====================== Old Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="https://www.google.nl/?gws_rd=ssl" New Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="https://www.google.nl/?gws_rd=ssl" ==== All HKCU SearchScopes ====================== HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes "DefaultScope"="{9bb2c1cc-4a7d-4cd5-bce9-0ca5f9ff8391}" {012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}" {0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE11SR" {9bb2c1cc-4a7d-4cd5-bce9-0ca5f9ff8391} wow search Url="http://wow.utop.it/?q={searchTerms}" ==== Empty IE Cache ====================== C:\WINDOWS\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Hans\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\Users\Hans\AppData\Local\Microsoft\Windows\INetCache\Low\Content.IE5 emptied successfully C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\WINDOWS\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully ==== Empty FireFox Cache ====================== C:\Users\Hans\AppData\Local\Mozilla\Firefox\Profiles\r0virwe7.default\Cache emptied successfully ==== Empty Chrome Cache ====================== C:\Users\Hans\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully ==== Empty All Flash Cache ====================== Flash Cache Emptied Successfully ==== Empty All Java Cache ====================== Java Cache cleared successfully ==== C:\zoek_backup content ====================== C:\zoek_backup (files=1966 folders=200 468606927 bytes) ==== Empty Temp Folders ====================== C:\Users\Default\AppData\Local\Temp emptied successfully C:\Users\Default User\AppData\Local\Temp emptied successfully C:\Users\Hans\AppData\Local\Temp will be emptied at reboot C:\Users\UpdatusUser\AppData\Local\Temp emptied successfully C:\WINDOWS\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully C:\WINDOWS\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully C:\WINDOWS\Temp will be emptied at reboot ==== After Reboot ====================== ==== Empty Temp Folders ====================== C:\WINDOWS\Temp successfully emptied C:\Users\Hans\AppData\Local\Temp successfully emptied ==== Empty Recycle Bin ====================== C:\$RECYCLE.BIN successfully emptied ==== EOF on za 16-08-2014 at 0:35:52,25 ======================