Zoek.exe v5.0.0.0 Updated 18-08-2014 Tool run by Mathieu on ma 18-08-2014 at 22:10:58,99. Microsoft Windows 8.1 6.3.9600 x64 Running in: Normal Mode Internet Access Detected Launched: C:\Users\Mathieu\Downloads\zoek.exe [Scan all users] [Script inserted] [Checkboxes used] ==== System Restore Info ====================== 18-8-2014 22:12:47 Zoek.exe System Restore Point Created Succesfully. ==== Empty Folders Check ====================== C:\PROGRA~3\Oracle deleted successfully C:\Users\Mathieu\AppData\Local\WarThunder deleted successfully C:\Users\Mathieu\AppData\Local\Windows Live deleted successfully ==== Deleting CLSID Registry Keys ====================== ==== Deleting CLSID Registry Values ====================== ==== Running Processes ====================== C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe C:\Program Files\Conexant\SA3\CxUtilSvc.exe C:\WINDOWS\SysWOW64\PnkBstrA.exe C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe C:\Program Files (x86)\Gyazo\GyStation.exe C:\Users\Mathieu\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe C:\Users\Mathieu\AppData\Roaming\Dropbox\bin\Dropbox.exe C:\Program Files (x86)\AVG\AVG2014\avgui.exe C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe C:\WINDOWS\SysWOW64\ctfmon.exe C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe C:\Program Files (x86)\Dell Update\DellUpService.exe C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe C:\Program Files (x86)\Dell Update\DellUpTray.exe C:\WINDOWS\sysWOW64\wbem\wmiprvse.exe C:\Program Files (x86)\Dell Backup and Recovery\SftService.exe C:\Program Files (x86)\Dell Backup and Recovery\Components\DBRUpdate\DBRUpd.exe C:\Program Files (x86)\Dell Backup and Recovery\TOASTER.EXE C:\WINDOWS\syswow64\wwahost.exe C:\Program Files (x86)\Steam\steam.exe C:\Program Files (x86)\Steam\bin\steamwebhelper.exe C:\Program Files (x86)\Common Files\Steam\SteamService.exe C:\Program Files (x86)\Steam\steamapps\common\War Thunder\aces.exe C:\Program Files (x86)\Steam\GameOverlayUI.exe C:\Program Files (x86)\Steam\bin\steamwebhelper.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Users\Mathieu\Downloads\zoek.exe C:\WINDOWS\SysWOW64\cmd.exe C:\WINDOWS\SysWOW64\cmd.exe C:\WINDOWS\SysWOW64\cmd.exe ==== Deleting Services ====================== ==== Deleting Files \ Folders ====================== C:\PROGRA~3\Package Cache deleted C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Search.lnk deleted C:\Users\Mathieu\Searches deleted C:\Users\Mathieu\Downloads\SoftonicDownloader_voor_guitar-pro.exe deleted C:\WINDOWS\Syswow64\SET4085.tmp deleted C:\Users\Mathieu\BT_Intel_W8.14_A00_Setup-XR83W_ZPE.exe deleted "C:\Users\Mathieu\AppData\Local\{0AFF02DE-4455-4964-8008-C32AFBE38495}" deleted "C:\Users\Mathieu\AppData\Local\{57260620-8825-4685-A78E-18EF0EC16480}" deleted "C:\Users\Mathieu\AppData\Local\{5BDA4AE2-3839-4A4E-BD5F-F7E169E28A5B}" deleted "C:\Users\Mathieu\AppData\Local\{8CAE2F62-206B-4A7F-9323-A21AC3E3250E}" deleted "C:\Users\Mathieu\AppData\Local\{982B7CE6-1464-45A8-AAD2-8A8F489AAB5E}" deleted "C:\Users\Mathieu\AppData\Local\{9E035B47-2774-4D03-A3EB-A71776491664}" deleted "C:\Users\Mathieu\AppData\Local\{CDD03C09-CC21-4FAB-B94F-1BBF8E9C33AA}" deleted "C:\Users\Mathieu\AppData\Local\{EA0483EF-359A-48E4-BAB7-C8F1F9251350}" deleted "C:\Users\Mathieu\AppData\Local\{F9DB8417-6996-429A-A850-B5BF2CCF2F9D}" deleted ==== System Specs ====================== Windows: Windows Version 6.2 (Build 9200) Memory (RAM): 8062 MB CPU Info: Intel(R) Core(TM) i5-3230M CPU @ 2.60GHz CPU Speed: 2595,0 MHz Sound Card: Luidsprekers (Conexant SmartAud | Display Adapters: Intel(R) HD Graphics 4000 | Intel(R) HD Graphics 4000 | Intel(R) HD Graphics 4000 Monitors: 1x; Generic PnP Monitor | Screen Resolution: 1536 X 864 - 32 bit Network: Network Present Network Adapters: Bluetooth-apparaat (Personal Area Network) #2 | Microsoft Wi-Fi Direct Virtual Adapter | Intel(R) Centrino(R) Wireless-N 2230 | Realtek PCIe GBE Family Controller CD / DVD Drives: 1x (D: | ) D: MATSHITADVD+-RW UJ8D1 Ports: COM Ports NOT Present. LPT Port NOT Present. Mouse: 8 Button Wheel Mouse Present Hard Disks: C: 915,5GB Hard Disks - Free: C: 434,0GB Manufacturer *: Dell Inc. BIOS Info: AT/AT COMPATIBLE | | DELL - 1 Time Zone: West-Europa (standaardtijd) Motherboard *: Dell Inc. 0PXH02 Country: Nederland Language: NLD ==== System Specs (Software) ====================== Anti-Virus: AVG AntiVirus Free Edition 2014 On-access scanning disabled (Outdated) Anti-Virus: Windows Defender On-access scanning disabled (Outdated) Anti-Spyware: Windows Defender disabled (Outdated) Anti-Spyware: AVG AntiVirus Free Edition 2014 disabled (Outdated) Default Browser: Google Chrome 36.0.1985.143 Internet Explorer Version: 11.0.9600.17239 Google Chrome version: 36.0.1985.143 Sun Java version: 1.7.0_67 (32-bit) Sun Java version: 1.7.0_51 (64-bit) ==== Files Recently Created / Modified ====================== ====== C:\WINDOWS ==== 2014-08-18 09:36:21 49E3548FD7073CDF413C1F70BF018D1E 911489025 ----a-w- C:\WINDOWS\MEMORY.DMP ====== C:\Users\Mathieu\AppData\Local\Temp ==== 2014-08-18 09:38:59 D11FB7A5078631BE2E183DC56FCD5375 43008 ----a-w- C:\Users\Mathieu\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpsu5i2p.dll ====== Java Cache ===== ====== C:\WINDOWS\SysWOW64 ===== 2014-08-15 12:13:55 8E58E88BE96C53ED639D4F779CCDD06B 704480 ----a-w- C:\WINDOWS\SysWOW64\FlashPlayerApp.exe 2014-08-15 12:13:55 217139672F2EF8EF3D1AD3E330779AF4 105440 ----a-w- C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl 2014-08-14 21:00:55 2C01D8EA2B0FA834597FCD96AAAE4F52 406400 ----a-w- C:\WINDOWS\SysWOW64\dxgi.dll 2014-08-14 21:00:48 E70C00791A18866BB23B3A652E3390A0 2001920 ----a-w- C:\WINDOWS\SysWOW64\inetcpl.cpl 2014-08-14 21:00:48 6D017C0E499443ACDE3D9B5DCD753F32 1169920 ----a-w- C:\WINDOWS\SysWOW64\urlmon.dll 2014-08-14 21:00:48 1A05CFA45B6AEBFCCC835DCF68CBD1D0 526336 ----a-w- C:\WINDOWS\SysWOW64\msfeeds.dll 2014-08-14 21:00:47 FF4A917DD7C387BD2715A5F67307FED1 2184704 ----a-w- C:\WINDOWS\SysWOW64\iertutil.dll 2014-08-14 21:00:47 90FF511B751A0327D07C4073760F1578 11772928 ----a-w- C:\WINDOWS\SysWOW64\ieframe.dll 2014-08-14 21:00:45 E9B28B60C0272E2E1E462E6FB38E6B55 367104 ----a-w- C:\WINDOWS\SysWOW64\dxtmsft.dll 2014-08-14 21:00:45 7C1BFC2ABE297BCA1A7BA77A8292C088 4204032 ----a-w- C:\WINDOWS\SysWOW64\jscript9.dll 2014-08-14 21:00:45 239575F9EA0D227516843EEE8B7342CA 239616 ----a-w- C:\WINDOWS\SysWOW64\dxtrans.dll 2014-08-14 21:00:45 18A3154606E3F8945956948A4E708007 704512 ----a-w- C:\WINDOWS\SysWOW64\ieapfltr.dll 2014-08-14 21:00:43 444EB30B1610A35FC99D62A91B2BCAA7 69632 ----a-w- C:\WINDOWS\SysWOW64\mshtmled.dll 2014-08-14 21:00:42 8453DDF167CE2986AA4AB04BC6824925 17524224 ----a-w- C:\WINDOWS\SysWOW64\mshtml.dll 2014-08-14 21:00:42 24FA5F74D3B4BA62539DF87285BA934E 597504 ----a-w- C:\WINDOWS\SysWOW64\jscript9diag.dll 2014-08-14 21:00:35 030041C8800A1781134B6EC3E3EF3F9C 291840 ----a-w- C:\WINDOWS\SysWOW64\iedkcs32.dll 2014-08-14 21:00:34 B945BAA81B4805AD6BDDF4D026DCFB47 1792512 ----a-w- C:\WINDOWS\SysWOW64\wininet.dll 2014-08-14 21:00:33 FEE3E022B00A5165ED645E38C1E6C776 60416 ----a-w- C:\WINDOWS\SysWOW64\JavaScriptCollectionAgent.dll 2014-08-14 21:00:32 272420427EB96EA052C719AA796C09F2 61952 ----a-w- C:\WINDOWS\SysWOW64\MshtmlDac.dll 2014-08-14 21:00:31 9D16B568E318F49535AD72539C9997C2 455168 ----a-w- C:\WINDOWS\SysWOW64\vbscript.dll 2014-08-14 20:59:39 128EC9879D462F89829E663417FE5DBD 710144 ----a-w- C:\WINDOWS\SysWOW64\rpcrt4.dll 2014-08-14 20:59:35 38045850ACB96313A1983A8803302906 35480 ----a-w- C:\WINDOWS\SysWOW64\TsWpfWrp.exe 2014-08-14 20:56:32 DB3ED0BA26D7C598481A23E7D06A370E 2344448 ----a-w- C:\WINDOWS\SysWOW64\Wpc.dll 2014-08-14 20:56:09 949E0E42DAAD0418513B44C31A697CA5 1797896 ----a-w- C:\WINDOWS\SysWOW64\d3d9.dll 2014-08-14 20:56:09 5BD2BD14753D3B0ADDE842CDF25A4C60 2144984 ----a-w- C:\WINDOWS\SysWOW64\mfcore.dll 2014-08-14 20:56:05 E65B5352AD0743F1F59BDA9466719EFE 265216 ----a-w- C:\WINDOWS\SysWOW64\SkyDriveShell.dll 2014-08-14 20:56:05 E28501E3A241DDC5DC65382E55661B1D 285696 ----a-w- C:\WINDOWS\SysWOW64\dhcpcore.dll 2014-08-14 20:56:05 1E14463F10B324B02EB2DA7415345D15 1473080 ----a-w- C:\WINDOWS\SysWOW64\ntdll.dll 2014-08-14 20:56:01 EA15CC7B75A2DE287E3B0C266A35490C 235008 ----a-w- C:\WINDOWS\SysWOW64\framedynos.dll 2014-08-14 20:56:01 E4783EB6A6B2D04F3B541B378E843617 229888 ----a-w- C:\WINDOWS\SysWOW64\dhcpcore6.dll 2014-08-14 20:56:00 0CCDFED2DFCD4FBA73EE989249379458 52736 ----a-w- C:\WINDOWS\SysWOW64\ncobjapi.dll 2014-08-14 20:55:58 A750BB0258ECF6265A903905A0B14EB3 198656 ----a-w- C:\WINDOWS\SysWOW64\WebClnt.dll 2014-08-14 20:55:58 4E07710A2C9EA43E7509BF7D0452430E 106496 ----a-w- C:\WINDOWS\SysWOW64\Robocopy.exe 2014-08-14 20:55:57 BEA7A26C2C22381B6DD88758352B9D9B 62976 ----a-w- C:\WINDOWS\SysWOW64\dhcpcsvc.dll 2014-08-14 20:55:57 BA6E52B0D82682EDE4B49D9CCC7D529B 207360 ----a-w- C:\WINDOWS\SysWOW64\framedyn.dll 2014-08-14 20:55:57 855D508F0053CEDC3BBAF2CB245A674A 1035264 ----a-w- C:\WINDOWS\SysWOW64\actxprxy.dll 2014-08-14 20:55:57 57E0A896C38C41C8B5B7F3127F8FD0D9 56320 ----a-w- C:\WINDOWS\SysWOW64\dhcpcsvc6.dll 2014-08-14 20:55:57 191B7F25BE13D9F9E56B2B4EA595AC62 11776 ----a-w- C:\WINDOWS\SysWOW64\d3d8thk.dll 2014-08-14 20:55:29 FBE8AE41ED2A9FE4C2DE069C522CA9C0 12711424 ----a-w- C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll 2014-08-14 20:55:28 854E970293BA92F9BB69FFD1CE051D9C 189016 ----a-w- C:\WINDOWS\SysWOW64\rsaenh.dll 2014-08-14 20:55:26 684CF6A72A8DF7D66D262AC4A6E07845 270848 ----a-w- C:\WINDOWS\SysWOW64\DaOtpCredentialProvider.dll 2014-08-14 20:55:18 DBC4D46A7DDC14D1D1ED4B613F9E41A4 1064448 ----a-w- C:\WINDOWS\SysWOW64\gdi32.dll 2014-08-14 20:55:17 86DB4BA87BAF3D467D04821602E586A9 3304448 ----a-w- C:\WINDOWS\SysWOW64\msi.dll 2014-08-14 20:55:17 16CDD058883E38FB43D582FB080F721A 2318336 ----a-w- C:\WINDOWS\SysWOW64\authui.dll 2014-08-14 20:55:16 F8D0951A75826AD557CFAC323A936AA6 281088 ----a-w- C:\WINDOWS\SysWOW64\msihnd.dll 2014-08-09 18:51:52 3331806A4E3026A4583C1565816CEA8E 9889352 ----a-w- C:\WINDOWS\SysWOW64\RtsUVStoricon.dll 2014-08-05 11:26:12 07EF2978A5BC36720378F95566697FD8 272808 ----a-w- C:\WINDOWS\SysWOW64\javaws.exe 2014-08-05 11:26:08 3BDEB17FE6390BFF1BF3A2D964DE8E48 175528 ----a-w- C:\WINDOWS\SysWOW64\javaw.exe 2014-08-05 11:26:08 11FD45A41DF45298686ED39062AABE2A 175528 ----a-w- C:\WINDOWS\SysWOW64\java.exe 2014-08-05 11:26:08 0F70F4DAF2BC5613EE75C9B2585CE67E 98216 ----a-w- C:\WINDOWS\SysWOW64\WindowsAccessBridge-32.dll ====== C:\WINDOWS\SysWOW64\drivers ===== ====== C:\WINDOWS\Sysnative ===== 2014-08-15 12:18:18 CB136B267569A62EF63D798BC90ABD5A 144 ----a-w- C:\WINDOWS\Sysnative\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat 2014-08-14 21:00:55 59EAFAE3A34B4925990A2E679CA91C5B 517528 ----a-w- C:\WINDOWS\Sysnative\dxgi.dll 2014-08-14 21:00:54 454978FB3D24DE5C4199162D5F81FBEE 2133504 ----a-w- C:\WINDOWS\Sysnative\dwmcore.dll 2014-08-14 21:00:48 FE7D99399F7761AA2695A7B1AD30DAAF 1431040 ----a-w- C:\WINDOWS\Sysnative\urlmon.dll 2014-08-14 21:00:47 1FD1F16C35946BA28FDEB40F18B7729D 631808 ----a-w- C:\WINDOWS\Sysnative\msfeeds.dll 2014-08-14 21:00:46 DB382D89D8004F40BD2C55BAE6A15B30 2774528 ----a-w- C:\WINDOWS\Sysnative\iertutil.dll 2014-08-14 21:00:46 39A85C005BCDEEF4092646EBBC2526AA 2087936 ----a-w- C:\WINDOWS\Sysnative\inetcpl.cpl 2014-08-14 21:00:46 1B26610C1659EF54ED000233FB96F20C 13547008 ----a-w- C:\WINDOWS\Sysnative\ieframe.dll 2014-08-14 21:00:45 F00D0AE7648CA45C6434E2885485BE0B 452096 ----a-w- C:\WINDOWS\Sysnative\dxtmsft.dll 2014-08-14 21:00:45 1DE8B71A1C7D8943034188556AF50B07 292864 ----a-w- C:\WINDOWS\Sysnative\dxtrans.dll 2014-08-14 21:00:44 BAC44396088ECC1C9021ED3E3345337C 846336 ----a-w- C:\WINDOWS\Sysnative\ieapfltr.dll 2014-08-14 21:00:44 920F690FC7424DE71888AA2E46E917EA 758272 ----a-w- C:\WINDOWS\Sysnative\jscript9diag.dll 2014-08-14 21:00:44 472C409F9B0FF67C1015F511C73E1889 5824512 ----a-w- C:\WINDOWS\Sysnative\jscript9.dll 2014-08-14 21:00:44 2639E152D246F2A651F09764807CA153 85504 ----a-w- C:\WINDOWS\Sysnative\mshtmled.dll 2014-08-14 21:00:43 ECA387DCD57F683C52171C766CF400F0 23645696 ----a-w- C:\WINDOWS\Sysnative\mshtml.dll 2014-08-14 21:00:35 8E71A5CB5312B8392D4DA4CA37BB5868 2266624 ----a-w- C:\WINDOWS\Sysnative\wininet.dll 2014-08-14 21:00:35 38D14F3D0A289050CA9BF8E98F37313F 333312 ----a-w- C:\WINDOWS\Sysnative\iedkcs32.dll 2014-08-14 21:00:34 52D2151908C2A6388B6561A373488F6F 692736 ----a-w- C:\WINDOWS\Sysnative\ie4uinit.exe 2014-08-14 21:00:33 19FA60D3AE1804A559306DE931A5B415 72704 ----a-w- C:\WINDOWS\Sysnative\JavaScriptCollectionAgent.dll 2014-08-14 21:00:32 C02C78DE9BB4E68F6C78B1588ADD6ADC 83968 ----a-w- C:\WINDOWS\Sysnative\MshtmlDac.dll 2014-08-14 21:00:31 6ED6DA2A04F8F0C9BDAD647284BAEFB6 548352 ----a-w- C:\WINDOWS\Sysnative\vbscript.dll 2014-08-14 20:59:40 1BB9CC78C91536CBA7B04B61ED0F85C4 1273184 ----a-w- C:\WINDOWS\Sysnative\rpcrt4.dll 2014-08-14 20:59:35 6DBE73C09215E281F4283641144110A5 35480 ----a-w- C:\WINDOWS\Sysnative\TsWpfWrp.exe 2014-08-14 20:56:32 E7DE316FEEFC79327CFAD8F527979CC0 3118080 ----a-w- C:\WINDOWS\Sysnative\Wpc.dll 2014-08-14 20:56:32 E2F4125BFAC99244088324A1841C0B83 3048880 ----a-w- C:\WINDOWS\Sysnative\WpcMon.exe 2014-08-14 20:56:32 6BC31FB4E24A962C98801D3687A984C0 2861056 ----a-w- C:\WINDOWS\Sysnative\WpcWebSync.dll 2014-08-14 20:56:32 04142EC4BDD7F502922914F65A5EE1D1 4756992 ----a-w- C:\WINDOWS\Sysnative\SyncEngine.dll 2014-08-14 20:56:31 BCCFB97B1B68DD18F2BDACFE37409386 716800 ----a-w- C:\WINDOWS\Sysnative\SkyDriveTelemetry.dll 2014-08-14 20:56:31 11FD8DDAB6014EECCE88F1F581604C30 1120256 ----a-w- C:\WINDOWS\Sysnative\SkyDrive.exe 2014-08-14 20:56:09 C1E44A99F7CF8C3A08CD5ADDF451636C 2125344 ----a-w- C:\WINDOWS\Sysnative\d3d9.dll 2014-08-14 20:56:07 EA432A85ABF371E14FB364D5F4405897 403968 ----a-w- C:\WINDOWS\Sysnative\vpnike.dll 2014-08-14 20:56:07 B6E947CE54A5AAD55484E0D3BC2D5948 1025536 ----a-w- C:\WINDOWS\Sysnative\localspl.dll 2014-08-14 20:56:07 0CD0356C5BBCFDC1B7BCEEDE74AB348B 2140888 ----a-w- C:\WINDOWS\Sysnative\mfcore.dll 2014-08-14 20:56:06 98D0985521BF8F7086EA9C860898A1EE 721408 ----a-w- C:\WINDOWS\Sysnative\fveapi.dll 2014-08-14 20:56:06 05DE04005CE0D84D0E6AD21CAEB369C6 353280 ----a-w- C:\WINDOWS\Sysnative\dhcpcore.dll 2014-08-14 20:56:05 D71845D255EA3FDC96A2DED98EE4C7D9 2844160 ----a-w- C:\WINDOWS\Sysnative\actxprxy.dll 2014-08-14 20:56:05 CED9FA1ECCF3E6B7028940FE22C69B40 1726224 ----a-w- C:\WINDOWS\Sysnative\ntdll.dll 2014-08-14 20:56:05 6B374D279DC423FE69DB8DD1401E84FC 301056 ----a-w- C:\WINDOWS\Sysnative\framedynos.dll 2014-08-14 20:56:05 61FE99A86352AD6E27FA480CDC8B225A 285696 ----a-w- C:\WINDOWS\Sysnative\SkyDriveShell.dll 2014-08-14 20:56:02 E07C80468D0C599BFF01D9D4EC7AEDC3 339456 ----a-w- C:\WINDOWS\Sysnative\bdesvc.dll 2014-08-14 20:56:02 10AC9494ECE22A2362E4E4D98C528D01 271872 ----a-w- C:\WINDOWS\Sysnative\dhcpcore6.dll 2014-08-14 20:56:01 FBB1841434072FFA76E4AD287448E34A 262656 ----a-w- C:\WINDOWS\Sysnative\framedyn.dll 2014-08-14 20:56:01 6CDCCD5323EEB8EBD66E02CB8C9C703F 118272 ----a-w- C:\WINDOWS\Sysnative\winbici.dll 2014-08-14 20:56:01 20FB137ADDE1255F15F265A7BD9579BE 827392 ----a-w- C:\WINDOWS\Sysnative\BFE.DLL 2014-08-14 20:56:01 1824052F17B12B5D7B21445B869EE9F2 71168 ----a-w- C:\WINDOWS\Sysnative\ncobjapi.dll 2014-08-14 20:55:58 D261A12A43D33122CB90E70D3BC1CC68 226816 ----a-w- C:\WINDOWS\Sysnative\WebClnt.dll 2014-08-14 20:55:58 7E1EBDB3424337ABB553F249A7811D94 87552 ----a-w- C:\WINDOWS\Sysnative\dhcpcsvc.dll 2014-08-14 20:55:58 2616E8E9C8B66A67CFB6197E9517A2F2 123392 ----a-w- C:\WINDOWS\Sysnative\Robocopy.exe 2014-08-14 20:55:57 DEA76F90F9777E3427D70E380222B23B 1063424 ----a-w- C:\WINDOWS\Sysnative\IKEEXT.DLL 2014-08-14 20:55:57 D3883FBCA97D10C8A39632D6CDDC6E85 65024 ----a-w- C:\WINDOWS\Sysnative\dhcpcsvc6.dll 2014-08-14 20:55:57 CFD6DBED27511D7A5FBE33AFA7E6B669 76800 ----a-w- C:\WINDOWS\Sysnative\BulkOperationHost.exe 2014-08-14 20:55:57 B7CC32E00C5C5152D221DF182827F58E 50745 ----a-w- C:\WINDOWS\Sysnative\srms.dat 2014-08-14 20:55:57 71BAEAFD05B3040173F5BBEA2CFE9607 997888 ----a-w- C:\WINDOWS\Sysnative\reseteng.dll 2014-08-14 20:55:31 50A49F3F16EF82E30BFB11E6B6A8F4A6 16871936 ----a-w- C:\WINDOWS\Sysnative\Windows.UI.Xaml.dll 2014-08-14 20:55:28 B312E157D20E727F30EAB3A250441B6F 284672 ----a-w- C:\WINDOWS\Sysnative\WUDFHost.exe 2014-08-14 20:55:28 313117AE2B0986ED7D3AA6AE10603239 216368 ----a-w- C:\WINDOWS\Sysnative\rsaenh.dll 2014-08-14 20:55:26 9CDC2059A23E3C9B57696178508777E7 99840 ----a-w- C:\WINDOWS\Sysnative\WUDFSvc.dll 2014-08-14 20:55:26 42D257559F97B30A94A027EB4555C62F 323584 ----a-w- C:\WINDOWS\Sysnative\DaOtpCredentialProvider.dll 2014-08-14 20:55:26 1A54E3DF2CBB8DBE8A17C87BB07E3A7E 209408 ----a-w- C:\WINDOWS\Sysnative\WUDFPlatform.dll 2014-08-14 20:55:26 08DCA300264238F9AE941302321F3D54 423768 ----a-w- C:\WINDOWS\Sysnative\hal.dll 2014-08-14 20:55:21 F381B380B7B2704EA4C0F8D8C49C1C50 623616 ----a-w- C:\WINDOWS\Sysnative\MDMAgent.exe 2014-08-14 20:55:18 A39C4AB750E0AD4431C7B7F46AB0EBED 4148224 ----a-w- C:\WINDOWS\Sysnative\win32k.sys 2014-08-14 20:55:18 87CEF71F9D5951C9379D2F956C07C37D 1336624 ----a-w- C:\WINDOWS\Sysnative\gdi32.dll 2014-08-14 20:55:18 00AD15C6BA3C337CB68A476C0AD05338 918528 ----a-w- C:\WINDOWS\Sysnative\MrmCoreR.dll 2014-08-14 20:55:17 68F887EF33C09CDA957A51ECE871D642 2642944 ----a-w- C:\WINDOWS\Sysnative\authui.dll 2014-08-14 20:55:17 28E0C3AAA68579ABD9A27B92DFD5F119 2790912 ----a-w- C:\WINDOWS\Sysnative\msi.dll 2014-08-14 20:55:16 10D8859CF01C1284603582ABD9B0482C 114520 ----a-w- C:\WINDOWS\Sysnative\consent.exe 2014-08-14 20:55:16 08914C8989AB93F5EC3A452D014E2C8D 356352 ----a-w- C:\WINDOWS\Sysnative\msihnd.dll 2014-08-09 19:11:03 3BC10FA856911EAE5FE7CD700FE137B5 451 ----a-w- C:\WINDOWS\Sysnative\{F33C3B9B-72AF-418A-B3FD-560646F7CDA2}.bat ====== C:\WINDOWS\Sysnative\drivers ===== 2014-08-14 21:00:54 313DCE665B57000B18CB26C6B6A10DFE 1557848 ----a-w- C:\WINDOWS\Sysnative\drivers\dxgkrnl.sys 2014-08-14 20:59:41 5C42CEE3E2018E1DFC6E3E17240A432A 206848 ----a-w- C:\WINDOWS\Sysnative\drivers\mrxsmb20.sys 2014-08-14 20:56:05 7A1A3F213CDB3363D179D5014272025D 402432 ----a-w- C:\WINDOWS\Sysnative\drivers\mrxsmb.sys 2014-08-14 20:56:01 674A4702E4E144E8710ED1A2EC6DD049 96768 ----a-w- C:\WINDOWS\Sysnative\drivers\agilevpn.sys 2014-08-14 20:55:58 65ED7B9CFEA893DF7748D5FF692690DE 38912 ----a-w- C:\WINDOWS\Sysnative\drivers\vwifimp.sys 2014-08-14 20:55:57 35BF5C5F5E3C9902C98978C7640574DA 71680 ----a-w- C:\WINDOWS\Sysnative\drivers\vwififlt.sys 2014-08-14 20:55:28 FE0ADF5028EB8C1339B66B3AEDE3FEF9 440664 ----a-w- C:\WINDOWS\Sysnative\drivers\usbport.sys 2014-08-14 20:55:28 93435654DCA210298BA0F986EB51C679 419672 ----a-w- C:\WINDOWS\Sysnative\drivers\usbhub.sys 2014-08-14 20:55:28 7CCBBCEE408A5DBE3FE47297DB5A6CFC 227840 ----a-w- C:\WINDOWS\Sysnative\drivers\WUDFRd.sys 2014-08-14 20:55:28 25AC0B50A71938890970E1508F107196 2518360 ----a-w- C:\WINDOWS\Sysnative\drivers\tcpip.sys 2014-08-14 20:55:26 D79920BE4E6683D3AB50F71457A4F6C6 27480 ----a-w- C:\WINDOWS\Sysnative\drivers\usbd.sys 2014-08-14 20:55:26 D537815E450A149752C15868392AD1F3 110592 ----a-w- C:\WINDOWS\Sysnative\drivers\WUDFPf.sys 2014-08-14 20:55:26 83C9C45D59C72FEFDAE9A5686BE31FEA 467800 ----a-w- C:\WINDOWS\Sysnative\drivers\USBHUB3.SYS 2014-08-14 20:55:26 48BA326A3DBA5B5BEB5F2777F4618696 89944 ----a-w- C:\WINDOWS\Sysnative\drivers\usbehci.sys 2014-08-14 20:55:26 064260B3A5868AC894A4943543BC7AB7 37376 ----a-w- C:\WINDOWS\Sysnative\drivers\usbuhci.sys 2014-08-09 18:51:52 28B356BAB74470786867BF4DC261E17C 329944 ----a-w- C:\WINDOWS\Sysnative\drivers\RtsUVStor.sys ====== C:\WINDOWS\Tasks ====== ====== C:\WINDOWS\Temp ====== ======= C:\Program Files ===== 2014-08-18 16:58:12 -------- d-----w- C:\Program Files\trend micro ======= C:\PROGRA~2 ===== 2014-08-09 18:49:15 -------- d-----w- C:\PROGRA~2\Dell Update 2014-08-09 18:40:48 -------- d-----w- C:\PROGRA~2\Dell Digital Delivery 2014-08-05 11:26:17 -------- d-----w- C:\PROGRA~2\COMMON~1\Java 2014-08-05 11:25:49 -------- d-----w- C:\PROGRA~2\Java ======= C: ===== ====== C:\Users\Mathieu\AppData\Roaming ====== ====== C:\Users\Mathieu ====== 2014-08-18 16:57:59 8045ABB21A3BDD66A48E1ED5C0F0EF6A 1222144 ----a-w- C:\Users\Mathieu\Downloads\RSITx64.exe 2014-08-18 09:38:16 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bluetooth Devices 2014-08-12 09:31:01 -------- d-sh--w- C:\Users\Mathieu\IntelGraphicsProfiles 2014-08-09 18:56:40 D92218A87D65ED8A92A68F3A4E3B3AC7 298261512 ----a-w- C:\Users\Mathieu\Downloads\Video_Driver_9NNDW_WN_13.151.0.0_A00.EXE 2014-08-09 18:56:19 951A78C3568E9B8122A454C58D5890AB 172356328 ----a-w- C:\Users\Mathieu\Downloads\Video_Driver_KK6CK_WN_10.18.10.3277_A00.EXE 2014-08-09 18:56:13 4F329BC5BCCEEDD251CF4739AA9E6E35 8447944 ----a-w- C:\Users\Mathieu\Downloads\System-Utilities_Driver_7VYC3_WN_3.0.0.1056_A01.EXE 2014-08-09 18:56:12 15A921B55DD285380FC7705A5CB60F99 23941272 ----a-w- C:\Users\Mathieu\Downloads\Serial-ATA_Driver_JX6H9_WN_12.8.0.1016_A00.EXE 2014-08-09 18:55:58 5A2808706430C8D02D1D2610D4CE1126 12186104 ----a-w- C:\Users\Mathieu\Downloads\Chipset_Driver_1TPVN_WN_9.4.0.1026_A00.EXE 2014-08-09 18:52:45 5BB1D01856399AEAEE0A1119EB37C54D 141640448 ----a-w- C:\Users\Mathieu\Downloads\Win64_153322.exe 2014-08-09 18:49:52 8017D08AADC78D53C2512280684F1771 78764200 ----a-w- C:\Users\Mathieu\Downloads\Chipset_Driver_D2CTT_WN_9.5.14.1724_A01 (1).EXE 2014-08-09 18:49:46 25C0500B9F82584426DD99A0134EA76D 27185280 ----a-w- C:\Users\Mathieu\Downloads\Application_G75PM_WN_10.15.026_A00.EXE 2014-08-09 18:49:33 3A376E9551D53DE288DFBA220816ADFF 18201488 ----a-w- C:\Users\Mathieu\Downloads\Chipset_Driver_65JF8_WN_6.2.9200.39052_A01 (1).EXE 2014-08-09 18:49:28 9B6F8B369A3B6EC31374D999AD51C490 330193192 ----a-w- C:\Users\Mathieu\Downloads\Audio_Driver_Y1116_WN_8.54.40.0_A00.EXE 2014-08-09 18:49:23 46366C0E678584900F0274ACAAC3F76D 48418192 ----a-w- C:\Users\Mathieu\Downloads\Input_Driver_KCKT5_WN_11.3.16.1_A07.EXE 2014-08-09 18:49:06 11AA4E05498BD80EC80C8225EA7196FA 680632 ----a-w- C:\Users\Mathieu\Downloads\DellUpdate.1.0.1059_ZPE.exe 2014-08-09 18:45:51 499AA12009FB9AF8333B427CF068FB86 52847944 ----a-w- C:\Users\Mathieu\Downloads\SteelSeriesEngine_3.2.6.exe 2014-08-09 18:43:36 8017D08AADC78D53C2512280684F1771 78764200 ----a-w- C:\Users\Mathieu\Downloads\Chipset_Driver_D2CTT_WN_9.5.14.1724_A01.EXE 2014-08-09 18:40:35 7E0253058F4B08706EE526763EA6558E 1274696 ----a-w- C:\Users\Mathieu\Downloads\DellDigitalDelivery.2.9.901.0_Install_ZPE.exe 2014-08-09 18:40:03 77CC0CB1F568304B321618650FC269A0 417824 ----a-w- C:\Users\Mathieu\Downloads\DellSystemDetect (1).exe ====== C: exe-files == 2014-08-18 16:58:12 9A2347903D6EDB84C10F288BC0578C1C 388608 ----a-w- C:\Program Files\trend micro\Mathieu.exe 2014-08-18 12:51:29 B5C26A6A92C9A6CD64399D2B06D29464 833728 ----a-w- C:\Program Files (x86)\Common Files\Steam\SteamServiceTmp.exe 2014-08-18 12:50:23 6CAC6807A07F5FB295E918D725AE093D 1520832 ----a-w- C:\Program Files (x86)\Steam\bin\steamwebhelper.exe 2014-08-18 10:34:30 B1B97114D180B5B1B05EB84F50441091 140464 ----a-w- C:\$SysReset\Temp\4BC14DF7-F537-4079-BCCB-2BBE0A15F6BA\DismHost.exe 2014-08-17 15:41:58 547DB2720C89ECCC4E597C751D4D0C83 262389688 ----a-w- C:\DELL\Drivers\X7NYM\Setup.exe 2014-08-17 15:40:56 0377F6A036C06AD61A2A1042FE3030D4 228000 ----a-w- C:\DELL\Drivers\XPKK3\Setup.exe 2014-08-15 12:49:36 5FE7916B9467C44999CBF4A060DCC44A 574120 ----a-w- C:\DELL\Drivers\6TMJ4\Setup.exe 2014-08-15 12:49:21 37B3C98D499DD9CEEF63F83D39031DD4 276288 ----a-w- C:\DELL\Drivers\6TMJ4\Packages\Drivers\Display\W8_INF\Intel\IntelCpHeciSvc.exe 2014-08-15 12:49:21 06511201A3ABC4A234EBDAE1A4271EE7 1059648 ----a-w- C:\DELL\Drivers\6TMJ4\Packages\Drivers\Display\W8_INF\Intel\igxpun.exe 2014-08-15 12:49:16 64F4DFB8161E393A7DB192D7F9B66EDB 269120 ----a-w- C:\DELL\Drivers\6TMJ4\Packages\Drivers\Display\W8_INF\Intel\igfxsrvc.exe 2014-08-15 12:49:16 1C9FF08531E37A0317EE37866929BBB6 144704 ----a-w- C:\DELL\Drivers\6TMJ4\Packages\Drivers\Display\W8_INF\Intel\igfxtray.exe 2014-08-15 12:49:05 E6CB698042FB77CC526720B7867EFE63 196416 ----a-w- C:\DELL\Drivers\6TMJ4\Packages\Drivers\Display\W8_INF\Intel\igfxext.exe 2014-08-15 12:49:05 B795A59BE3B2093A494EA6291A21373D 188224 ----a-w- C:\DELL\Drivers\6TMJ4\Packages\Drivers\Display\W8_INF\Intel\igfxpers.exe 2014-08-15 12:48:11 0DB71CCA0CC3A04AED92802E1416AD6A 180544 ----a-w- C:\DELL\Drivers\6TMJ4\Packages\Drivers\Display\W8_INF\Intel\hkcmd.exe 2014-08-15 12:47:57 84B2FCB1EDE8622F21A4B445D02F97F7 6225216 ----a-w- C:\DELL\Drivers\6TMJ4\Packages\Drivers\Display\W8_INF\Intel\GfxUI.exe 2014-08-15 12:44:43 283048742BEAADEA1B1C1C9B3DFC10F6 276288 ----a-w- C:\DELL\Drivers\6TMJ4\Packages\Drivers\Display\W86A_INF\Intel\IntelCpHeciSvc.exe 2014-08-15 12:44:42 A62ABD6C410D2D5A551F14F628554FC7 1059648 ----a-w- C:\DELL\Drivers\6TMJ4\Packages\Drivers\Display\W86A_INF\Intel\igxpun.exe 2014-08-15 12:44:38 7FD9842F81FA7DF4F9FCA7881C976EBE 170304 ----a-w- C:\DELL\Drivers\6TMJ4\Packages\Drivers\Display\W86A_INF\Intel\igfxtray.exe 2014-08-15 12:44:36 423A8E4FB52C08C8E71ACB082ADAAA79 509248 ----a-w- C:\DELL\Drivers\6TMJ4\Packages\Drivers\Display\W86A_INF\Intel\igfxsrvc.exe 2014-08-15 12:44:31 BB8F9CEA82D09F5375FC3A62B9F54ED1 440640 ----a-w- C:\DELL\Drivers\6TMJ4\Packages\Drivers\Display\W86A_INF\Intel\igfxpers.exe 2014-08-15 12:44:31 368F0850956A681F1B7A2679F55F8687 250688 ----a-w- C:\DELL\Drivers\6TMJ4\Packages\Drivers\Display\W86A_INF\Intel\igfxext.exe 2014-08-15 12:42:41 D6D38096A46B18E8F3E9D45B4CA38349 398656 ----a-w- C:\DELL\Drivers\6TMJ4\Packages\Drivers\Display\W86A_INF\Intel\hkcmd.exe 2014-08-15 12:42:30 424FB167195E9AD4DB004AEC1F7175A7 5899072 ----a-w- C:\DELL\Drivers\6TMJ4\Packages\Drivers\Display\W86A_INF\Intel\GfxUI.exe 2014-08-15 12:42:23 F62A8E37F1ADB8B28E259767F417AA47 184640 ----a-w- C:\DELL\Drivers\6TMJ4\Packages\Drivers\Display\W86A_INF\Intel\difx64.exe 2014-08-15 12:39:06 006F8A615020A4A17F5E63801485DF46 78152 ----a-w- C:\DELL\Drivers\6TMJ4\Packages\Apps\VC10RTx86\vcredist_x86\Setup.exe 2014-08-15 12:38:52 006F8A615020A4A17F5E63801485DF46 78152 ----a-w- C:\DELL\Drivers\6TMJ4\Packages\Apps\VC10RTx64\vcredist_x64\Setup.exe 2014-08-15 12:37:50 D3889D4E3DC3FF64093EDBAE67A81A58 184640 ----a-w- C:\DELL\Drivers\6TMJ4\Packages\Apps\IntelMedia1\WinW764a\x64\Drv64.exe 2014-08-15 12:37:48 B5E68932C64113C2B5BAC289026547FB 1059648 ----a-w- C:\DELL\Drivers\6TMJ4\Packages\Apps\IntelMedia1\WinW764a\Setup.exe 2014-08-15 12:36:35 2752A10A8145AE1DAA9C1D3B843E8B09 42306368 ----a-w- C:\DELL\Drivers\6TMJ4\Packages\Apps\IntelMedia1\WinW764a\OpenCL\OCLSetup.exe 2014-08-15 12:35:50 6F5651CB416F80E63BDCEE65A93EF243 1059648 ----a-w- C:\DELL\Drivers\6TMJ4\Packages\Apps\IntelMedia1\WinW7\Setup.exe 2014-08-15 12:34:39 7A63851F37239FCC9D32513F0179896E 42306368 ----a-w- C:\DELL\Drivers\6TMJ4\Packages\Apps\IntelMedia1\WinW7\OpenCL\OCLSetup.exe 2014-08-15 12:33:44 69E8191B87CD697849231A5A3915BFAE 723112 ----a-w- C:\DELL\Drivers\6TMJ4\Bin64\Setup.exe 2014-08-15 12:33:43 D5E593810D16358931CB98899D9F4D85 543400 ----a-w- C:\DELL\Drivers\6TMJ4\Bin64\ATISetup.exe 2014-08-15 12:33:43 3EC9D9A92F3AF6D1B4F6CEDA4E0AB0E4 574120 ----a-w- C:\DELL\Drivers\6TMJ4\Bin\Setup.exe 2014-08-15 12:33:43 03438E6837DE10128CDD2A6B88BBF241 5602984 ----a-w- C:\DELL\Drivers\6TMJ4\Bin64\InstallManagerApp.exe 2014-08-15 12:33:42 7FE17A2986C23942D46DEDC8BE191EB8 4815528 ----a-w- C:\DELL\Drivers\6TMJ4\Bin\InstallManagerApp.exe 2014-08-15 12:33:36 7DEFFD0DB0202E8AF3B5604CAB081169 430760 ----a-w- C:\DELL\Drivers\6TMJ4\Bin\ATISetup.exe 2014-08-14 21:00:48 771E149F97AA6679DEF79F0953414435 812176 ----a-w- C:\Program Files (x86)\Internet Explorer\iexplore.exe 2014-08-14 21:00:48 6A60D0D167D35A07646EBCF796D770B4 470016 ----a-w- C:\Program Files (x86)\Internet Explorer\ieinstal.exe 2014-08-14 21:00:47 7D709E893B53092E3F5995FF5C3061E2 483328 ----a-w- C:\Program Files\Internet Explorer\ieinstal.exe 2014-08-14 21:00:46 E8F1154367F708BD9E5BFD6A2112B4D3 810128 ----a-w- C:\Program Files\Internet Explorer\iexplore.exe 2014-08-14 20:25:55 C56CB929FDC62BA6AFA025C0DF95CA73 1836624 ----a-w- C:\Program Files (x86)\Google\Update\Download\{4DC8B4CA-1BDA-483E-B5FA-D3C12E15B62D}\36.0.1985.143\36.0.1985.143_36.0.1985.125_chrome_updater.exe 2014-08-14 10:08:11 A715DD1F4D7894100FBA9153048FDE1B 62992 ----a-w- C:\Program Files (x86)\AVG\AVG2014\avguirux.exe 2014-08-14 10:08:11 9B3A0BC81C174ADF77DC6869AC6BCDDD 15888 ----a-w- C:\Program Files (x86)\AVG\AVG2014\avgrdtestx.exe 2014-08-14 10:08:11 88950BBD830F5CCA4B18BD6AB3DD05FF 16912 ----a-w- C:\Program Files (x86)\AVG\AVG2014\avgrdtesta.exe 2014-08-14 10:08:11 4505C7EEC5B0FFA5C45A7450198CBCC0 6018176 ----a-w- C:\Program Files (x86)\AVG\AVG2014\avgmfapx.exe === C: other files == 2014-08-15 12:48:47 0A1DBEF41485ECE4968BBD11C52FBCEA 7397376 ----a-w- C:\DELL\Drivers\6TMJ4\Packages\Drivers\Display\W8_INF\Intel\igdkmd32.sys 2014-08-15 12:44:08 28388795BDF79464E8FDADB127671734 8982208 ----a-w- C:\DELL\Drivers\6TMJ4\Packages\Drivers\Display\W86A_INF\Intel\igdkmd64.sys 2014-08-15 12:39:19 752DD8A2D9292660D30D539D9AABAA57 23208 ----a-w- C:\DELL\Drivers\6TMJ4\Packages\Drivers\amdkmpfd\W8\amdkmpfd.sys 2014-08-15 12:39:19 02CF5AD93538CCE63EB09364EDD3DCF9 35496 ----a-w- C:\DELL\Drivers\6TMJ4\Packages\Drivers\amdkmpfd\W864A\amdkmpfd.sys 2014-08-15 12:35:50 F5495B38BFB9149925F54F65AB40EFBF 342528 ----a-w- C:\DELL\Drivers\6TMJ4\Packages\Apps\IntelMedia1\WinW764a\DisplayAudio\IntcDAud.sys 2014-08-15 12:34:01 6A6E1B319A47FA7AF2AE6B6815AE9854 289792 ----a-w- C:\DELL\Drivers\6TMJ4\Packages\Apps\IntelMedia1\WinW7\DisplayAudio\IntcDAud.sys 2014-08-15 12:33:43 7D7ED9D5FAD9583865A174663FED486F 31912 ----a-w- C:\DELL\Drivers\6TMJ4\Bin64\atdcm64a.sys 2014-08-15 12:33:32 8AB47F06533F4184B9363758E884B8F1 27560 ----a-w- C:\DELL\Drivers\6TMJ4\Bin\atidcmxx.sys ==== Startup Registry Enabled ====================== [HKEY_USERS\S-1-5-21-1276643562-1953218356-1936145314-1001\Software\Microsoft\Windows\CurrentVersion\Run] "Gyazo"="C:\Program Files (x86)\Gyazo\GyStation.exe" "Spotify Web Helper"="C:\Users\Mathieu\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" "HydraVisionDesktopManager"="C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe" "DellSystemDetect"="C:\Users\Mathieu\AppData\Local\Apps\2.0\DHPN81Y1.1GK\8X96LKOH.JGP\dell..tion_0f612f649c4a10af_0005.0009_14e1a3fbfbaf942c\DellSystemDetect.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RemoteControl10"="C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe" "AVG_UI"="C:\Program Files (x86)\AVG\AVG2014\avgui.exe /TRAYONLY" "StartCCC"="C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe MSRun" "SunJavaUpdateSched"="C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "Gyazo"="C:\Program Files (x86)\Gyazo\GyStation.exe" "Spotify Web Helper"="C:\Users\Mathieu\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" "HydraVisionDesktopManager"="C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe" "DellSystemDetect"="C:\Users\Mathieu\AppData\Local\Apps\2.0\DHPN81Y1.1GK\8X96LKOH.JGP\dell..tion_0f612f649c4a10af_0005.0009_14e1a3fbfbaf942c\DellSystemDetect.exe" ==== Startup Registry Enabled x64 ====================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SmartAudio"="C:\Program Files\CONEXANT\SA3\SACpl.exe /sa3 /nv:3.0+ /dne /s" "IntelTBRunOnce"="wscript.exe //b //nologo C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs" "BTMTrayAgent"="rundll32.exe C:\Program Files (x86)\Intel\Bluetooth\btmshellex.dll,TrayApp" "QuickSet"="C:\Program Files\Dell\QuickSet\QuickSet.exe" "IAStorIcon"="C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe 60" "ETDCtrl"="%ProgramFiles%\Elantech\ETDCtrl.exe " ==== Startup Folders ====================== 2014-04-22 14:12:18 1104 ----a-w- C:\Users\Mathieu\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk 2014-03-11 16:49:39 2246 ----a-w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\SteelSeries Engine 3.lnk ==== Task Scheduler Jobs ====================== C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job --a-------- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [16-02-2014 20:05] C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job --a-------- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [16-02-2014 20:05] ==== Other Scheduled Tasks ====================== "C:\WINDOWS\SysNative\tasks\CLMLSvc_P2G8" [C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe] "C:\WINDOWS\SysNative\tasks\CLVDLauncher" [C:\Program Files (x86)\CyberLink\Power2Go8\CLVDLauncher.exe] "C:\WINDOWS\SysNative\tasks\GoogleUpdateTaskMachineCore" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe] "C:\WINDOWS\SysNative\tasks\GoogleUpdateTaskMachineUA" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe] "C:\WINDOWS\SysNative\tasks\PCDEventLauncher" ["C:\Program Files\Dell Support Center\sessionchecker.exe"] "C:\WINDOWS\SysNative\tasks\PCDoctorBackgroundMonitorTask" ["C:\Program Files\Dell Support Center\uaclauncher.exe"] "C:\WINDOWS\SysNative\tasks\SystemToolsDailyTest" ["uaclauncher.exe"] "C:\WINDOWS\SysNative\tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask" [%systemroot%\system32\sc.exe start osppsvc] ==== Chrome Look ====================== Google Docs - Mathieu\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake Google Voice Search Hotword (Beta) - Mathieu\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn YouTube - Mathieu\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo AdBlock - Mathieu\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom Reddit Enhancement Suite - Mathieu\AppData\Local\Google\Chrome\User Data\Default\Extensions\kbmfpngjjgdllneeigpgjifpgocmfgmb Your Quality for YouTubeâ„¢ - Mathieu\AppData\Local\Google\Chrome\User Data\Default\Extensions\nfcilgimggemnogfigihdkmapdhhlbph Google Wallet - Mathieu\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda ==== Set IE to Default ====================== Old Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://dell13.msn.com" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes] "DefaultScope"="{A695C19F-5111-4A12-A477-7B20EC6D6DE7}" New Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://dell13.msn.com" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes] "DefaultScope"="{012E1000-F331-11DB-8314-0800200C9A66}" ==== All HKCU SearchScopes ====================== HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes {012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}" {0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC" {A695C19F-5111-4A12-A477-7B20EC6D6DE7} Unknown Url="Not_Found" ==== Deleting CLSID Registry Keys ====================== HKEY_USERS\S-1-5-21-1276643562-1953218356-1936145314-1001\Software\Microsoft\Internet Explorer\SearchScopes\{A695C19F-5111-4A12-A477-7B20EC6D6DE7} deleted successfully ==== Deleting CLSID Registry Values ====================== ==== HijackThis Entries ====================== F2 - REG:system.ini: UserInit=userinit.exe O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll O4 - HKLM\..\Run: [RemoteControl10] "C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe" O4 - HKLM\..\Run: [AVG_UI] "C:\Program Files (x86)\AVG\AVG2014\avgui.exe" /TRAYONLY O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" O4 - HKCU\..\Run: [Gyazo] C:\Program Files (x86)\Gyazo\GyStation.exe O4 - HKCU\..\Run: [Spotify Web Helper] "C:\Users\Mathieu\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" O4 - HKCU\..\Run: [HydraVisionDesktopManager] "C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe" O4 - HKCU\..\Run: [DellSystemDetect] C:\Users\Mathieu\AppData\Local\Apps\2.0\DHPN81Y1.1GK\8X96LKOH.JGP\dell..tion_0f612f649c4a10af_0005.0009_14e1a3fbfbaf942c\DellSystemDetect.exe O4 - Startup: Dropbox.lnk = Mathieu\AppData\Roaming\Dropbox\bin\Dropbox.exe O4 - Global Startup: SteelSeries Engine 3.lnk = C:\Program Files\SteelSeries\SteelSeries Engine 3\SteelSeriesEngine3.exe O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics O15 - Trusted Zone: *.dell.com O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing) O23 - Service: AMD External Events Utility - Unknown owner - C:\WINDOWS\system32\atiesrxx.exe (file missing) O23 - Service: Intel® Centrino® Wireless Bluetooth® + High Speed Service (AMPPALR3) - Intel Corporation - C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe O23 - Service: Bluetooth Device Monitor - Motorola Solutions, Inc. - C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe O23 - Service: Bluetooth OBEX Service - Motorola Solutions, Inc. - C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe O23 - Service: Intel(R) Centrino(R) Wireless Bluetooth(R) + High Speed Security Service (BTHSSecurityMgr) - Intel(R) Corporation - C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe O23 - Service: CxUtilSvc - Conexant Systems, Inc. - C:\Program Files\Conexant\SA3\CxUtilSvc.exe O23 - Service: Dell Digital Delivery Service (DellDigitalDelivery) - Dell Products, LP. - C:\Program Files (x86)\Dell Digital Delivery\DeliveryService.exe O23 - Service: Dell Update Service (DellUpdate) - Dell Inc. - C:\Program Files (x86)\Dell Update\DellUpService.exe O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing) O23 - Service: Elan Service (ETDService) - ELAN Microelectronics Corp. - C:\Program Files\Elantech\ETDService.exe O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing) O23 - Service: Google Update-service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe O23 - Service: Google Update-service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe O23 - Service: Intel(R) Integrated Clock Controller Service - Intel(R) ICCS (ICCS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\WINDOWS\system32\IEEtwCollector.exe (file missing) O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService1.0.0.0) - Unknown owner - C:\WINDOWS\system32\igfxCUIService.exe (file missing) O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe O23 - Service: Intel(R) Capability Licensing Service TCP IP Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe O23 - Service: Intel(R) Wireless Bluetooth(R) 4.0 Radio Management - Intel Corporation - c:\Program Files (x86)\Intel\Bluetooth\ibtrksrv.exe O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing) O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing) O23 - Service: Wireless PAN DHCP Server (MyWiFiDHCPDNS) - Unknown owner - C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing) O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing) O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing) O23 - Service: SoftThinks Agent Service (SftService) - SoftThinks SAS - C:\Program Files (x86)\Dell Backup and Recovery\SftService.exe O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing) O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing) O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing) O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe O23 - Service: Intel(R) Turbo Boost Technology Monitor 2.6 (TurboBoost) - Intel(R) Corporation - C:\Program Files\Intel\TurboBoost\TurboBoost.exe O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing) O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing) O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing) O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing) O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing) O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing) O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing) O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing) O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing) O23 - Service: Intel(R) PROSet/Wireless Zero Configuration Service (ZeroConfigService) - Intel® Corporation - C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe ==== Empty IE Cache ====================== C:\WINDOWS\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Mathieu\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\Users\Mathieu\AppData\Local\Microsoft\Windows\INetCache\Low\Content.IE5 emptied successfully C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully ==== Empty FireFox Cache ====================== No FireFox Profiles found ==== Empty Chrome Cache ====================== C:\Users\Mathieu\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully ==== Empty All Flash Cache ====================== Flash Cache Emptied Successfully ==== Empty All Java Cache ====================== Java Cache cleared successfully ==== C:\zoek_backup content ====================== C:\zoek_backup (files=41 folders=30 61637164 bytes) ==== Empty Temp Folders ====================== C:\Users\admin\AppData\Local\Temp emptied successfully C:\Users\Default\AppData\Local\Temp emptied successfully C:\Users\Default User\AppData\Local\Temp emptied successfully C:\Users\Mathieu\AppData\Local\Temp will be emptied at reboot C:\WINDOWS\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully C:\WINDOWS\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully C:\WINDOWS\Temp will be emptied at reboot ==== After Reboot ====================== ==== Empty Temp Folders ====================== C:\WINDOWS\Temp successfully emptied C:\Users\Mathieu\AppData\Local\Temp successfully emptied ==== Empty Recycle Bin ====================== C:\$RECYCLE.BIN successfully emptied ==== EOF on ma 18-08-2014 at 22:36:38,07 ======================