Zoek.exe v5.0.0.0 Updated 14-April-2014 Tool run by JEF on do 17-04-2014 at 10:23:45,48. Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x64 Running in: Normal Mode Internet Access Detected Launched: C:\Users\JEF\Downloads\zoek.exe [Scan all users] [Script inserted] [Checkboxes used] ==== System Restore Info ====================== 17-4-2014 10:25:00 Zoek.exe System Restore Point Created Succesfully. ==== Empty Folders Check ====================== C:\PROGRA~2\MSXML 4.0 deleted successfully C:\PROGRA~2\MyFree Codec deleted successfully C:\PROGRA~3\AVAST Software deleted successfully C:\PROGRA~3\Babylon deleted successfully C:\PROGRA~3\Browser Manager deleted successfully C:\PROGRA~3\{01BD4FC9-2F86-4706-A62E-774BB7E9D308} deleted successfully C:\PROGRA~3\{93E26451-CD9A-43A5-A2FA-C42392EA4001} deleted successfully C:\PROGRA~3\{C4ABDBC8-1C81-42C9-BFFC-4A68511E9E4F} deleted successfully C:\Users\JEF\AppData\Roaming\HpUpdate deleted successfully C:\Users\JEF\AppData\Roaming\Systweak deleted successfully C:\Users\JEF\AppData\Roaming\TP deleted successfully C:\Users\JEF\AppData\Roaming\uTorrent deleted successfully C:\Users\JEF\AppData\Roaming\Windows Live Writer deleted successfully C:\Users\JEF\AppData\Local\cache deleted successfully C:\Users\JEF\AppData\Local\Downloaded Installations deleted successfully C:\Users\JEF\AppData\Local\genienext deleted successfully C:\Users\JEF\AppData\Local\PackageAware deleted successfully C:\Users\JEF\AppData\Local\TBHostSupport deleted successfully ==== Deleting CLSID Registry Keys ====================== HKEY_USERS\S-1-5-21-1325376773-928895087-3028547245-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{872b5b88-9db5-4310-bdd0-ac189557e5f5} deleted successfully HKEY_USERS\S-1-5-21-1325376773-928895087-3028547245-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{872b5b88-9db5-4310-bdd0-ac189557e5f5} deleted successfully HKEY_USERS\S-1-5-21-1325376773-928895087-3028547245-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{28387537-e3f9-4ed7-860c-11e69af4a8a0} deleted successfully HKEY_USERS\S-1-5-21-1325376773-928895087-3028547245-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{28387537-e3f9-4ed7-860c-11e69af4a8a0} deleted successfully HKEY_USERS\S-1-5-21-1325376773-928895087-3028547245-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5CB02877-EFBC-4317-B608-9E24B11BAB40} deleted successfully HKEY_USERS\S-1-5-21-1325376773-928895087-3028547245-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{5CB02877-EFBC-4317-B608-9E24B11BAB40} deleted successfully HKEY_USERS\S-1-5-21-1325376773-928895087-3028547245-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{BE7A24F5-69CB-4708-B77B-B1EDA6043B95} deleted successfully HKEY_USERS\S-1-5-21-1325376773-928895087-3028547245-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{BE7A24F5-69CB-4708-B77B-B1EDA6043B95} deleted successfully HKEY_USERS\S-1-5-21-1325376773-928895087-3028547245-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{d2ce3e00-f94a-4740-988e-03dc2f38c34f} deleted successfully HKEY_USERS\S-1-5-21-1325376773-928895087-3028547245-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{d2ce3e00-f94a-4740-988e-03dc2f38c34f} deleted successfully HKEY_USERS\S-1-5-21-1325376773-928895087-3028547245-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EEE6C35C-6118-11DC-9C72-001320C79847} deleted successfully HKEY_USERS\S-1-5-21-1325376773-928895087-3028547245-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EEE6C35C-6118-11DC-9C72-001320C79847} deleted successfully HKEY_USERS\S-1-5-21-1325376773-928895087-3028547245-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8dcb7100-df86-4384-8842-8fa844297b3f} deleted successfully HKEY_USERS\S-1-5-21-1325376773-928895087-3028547245-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{8dcb7100-df86-4384-8842-8fa844297b3f} deleted successfully HKEY_USERS\S-1-5-21-1325376773-928895087-3028547245-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EEE6C35B-6118-11DC-9C72-001320C79847} deleted successfully HKEY_USERS\S-1-5-21-1325376773-928895087-3028547245-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EEE6C35B-6118-11DC-9C72-001320C79847} deleted successfully HKEY_USERS\S-1-5-21-1325376773-928895087-3028547245-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{6F001652-AF51-45C6-B029-86E0265A1851} deleted successfully HKEY_USERS\S-1-5-21-1325376773-928895087-3028547245-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{6F001652-AF51-45C6-B029-86E0265A1851} deleted successfully HKEY_USERS\S-1-5-21-1325376773-928895087-3028547245-1000\Software\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} deleted successfully HKEY_USERS\S-1-5-21-1325376773-928895087-3028547245-1000\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD21} deleted successfully HKEY_USERS\S-1-5-21-1325376773-928895087-3028547245-1000\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD22} deleted successfully HKEY_USERS\S-1-5-21-1325376773-928895087-3028547245-1000\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} deleted successfully HKEY_USERS\S-1-5-21-1325376773-928895087-3028547245-1000\Software\Microsoft\Internet Explorer\SearchScopes\{C2CFEC72-21A9-4457-B89D-6E7E6E446BD3} deleted successfully HKEY_USERS\S-1-5-21-1325376773-928895087-3028547245-1000\Software\Microsoft\Internet Explorer\SearchScopes\{C6AAA0D7-AE06-4401-9DBF-0C68E72A7D4D} deleted successfully HKEY_USERS\S-1-5-21-1325376773-928895087-3028547245-1000\Software\Microsoft\Internet Explorer\SearchScopes\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A} deleted successfully HKEY_USERS\S-1-5-21-1325376773-928895087-3028547245-1000\Software\Microsoft\Internet Explorer\SearchScopes\{D1F38E28-C7B4-4BC2-BB5A-59C773E6B05F} deleted successfully HKEY_USERS\S-1-5-21-1325376773-928895087-3028547245-1000\Software\Microsoft\Internet Explorer\SearchScopes\{EBF77B69-100C-40F1-877B-DB62DB34A4DC} deleted successfully HKEY_USERS\S-1-5-21-1325376773-928895087-3028547245-1000\Software\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847} deleted successfully HKEY_USERS\S-1-5-21-1325376773-928895087-3028547245-1000\Software\Microsoft\Internet Explorer\SearchScopes\{F22DE612-223E-4256-8CC9-6FB8DB4A21A1} deleted successfully HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{872b5b88-9db5-4310-bdd0-ac189557e5f5} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{872b5b88-9db5-4310-bdd0-ac189557e5f5} deleted successfully HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{28387537-e3f9-4ed7-860c-11e69af4a8a0} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{28387537-e3f9-4ed7-860c-11e69af4a8a0} deleted successfully HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{2EECD738-5844-4a99-B4B6-146BF802613B} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2EECD738-5844-4a99-B4B6-146BF802613B} deleted successfully HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{5CB02877-EFBC-4317-B608-9E24B11BAB40} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5CB02877-EFBC-4317-B608-9E24B11BAB40} deleted successfully HKEY_CLASSES_ROOT\CLSID\{BE7A24F5-69CB-4708-B77B-B1EDA6043B95} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BE7A24F5-69CB-4708-B77B-B1EDA6043B95} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BE7A24F5-69CB-4708-B77B-B1EDA6043B95} deleted successfully HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{d2ce3e00-f94a-4740-988e-03dc2f38c34f} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d2ce3e00-f94a-4740-988e-03dc2f38c34f} deleted successfully HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{EEE6C35C-6118-11DC-9C72-001320C79847} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EEE6C35C-6118-11DC-9C72-001320C79847} deleted successfully HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{8dcb7100-df86-4384-8842-8fa844297b3f} deleted successfully HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{98889811-442D-49dd-99D7-DC866BE87DBC} deleted successfully HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{EEE6C35B-6118-11DC-9C72-001320C79847} deleted successfully HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{6F001652-AF51-45C6-B029-86E0265A1851} deleted successfully ==== Deleting CLSID Registry Values ====================== HKEY_USERS\S-1-5-21-1325376773-928895087-3028547245-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{c95a4e8e-816d-4655-8c79-d736da1adb6d} deleted successfully HKEY_USERS\S-1-5-21-1325376773-928895087-3028547245-1000\Software\Microsoft\Internet Explorer\URLSearchHooks\{c95a4e8e-816d-4655-8c79-d736da1adb6d} deleted successfully HKEY_USERS\S-1-5-21-1325376773-928895087-3028547245-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{872b5b88-9db5-4310-bdd0-ac189557e5f5} deleted successfully HKEY_USERS\S-1-5-21-1325376773-928895087-3028547245-1000\Software\Microsoft\Internet Explorer\URLSearchHooks\{872b5b88-9db5-4310-bdd0-ac189557e5f5} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{872b5b88-9db5-4310-bdd0-ac189557e5f5} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{28387537-e3f9-4ed7-860c-11e69af4a8a0} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{8dcb7100-df86-4384-8842-8fa844297b3f} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{98889811-442D-49dd-99D7-DC866BE87DBC} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{EEE6C35B-6118-11DC-9C72-001320C79847} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{6F001652-AF51-45C6-B029-86E0265A1851} deleted successfully ==== Running Processes ====================== C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE C:\ProgramData\Mobistar Internet Everywhere\OnlineUpdate\ouc.exe C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe C:\Program Files (x86)\Sony\VAIO Event Service\VESMgr.exe C:\Program Files (x86)\Sony\VAIO Event Service\VESMgrSub.exe C:\Windows\SysWOW64\DllHost.exe C:\Windows\SysWOW64\DllHost.exe C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE C:\PROGRA~2\SearchProtect\Main\bin\CltMngSvc.exe C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe C:\Program Files (x86)\AVG\AVG2013\avgui.exe C:\Program Files (x86)\Sony\VAIO Event Service\VESMgrSub.exe C:\Program Files\Sony\VAIO Care\listener.exe C:\Program Files (x86)\Mozilla Firefox\firefox.exe C:\Program Files (x86)\AVG\AVG2013\avgcfgex.exe C:\Users\JEF\Downloads\zoek.exe C:\Windows\SysWOW64\cmd.exe C:\Windows\SysWOW64\cmd.exe C:\Windows\SysWOW64\cmd.exe ==== Deleting Services ====================== HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CltMngSvc deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\CltMngSvc deleted successfully ==== FireFox Fix ====================== ProfilePath: C:\Users\JEF\AppData\Roaming\Mozilla\Firefox\Profiles\3mu83j4a.default user.js not found ---- Lines conduit removed from prefs.js ---- user_pref("browser.newtab.url", "http://search.conduit.com/?ctid=CT3314958&octid=EB_ORIGINAL_CTID&SearchSource=69&CUI=&SSPV=&Lay=1&UM=2&UP=SP133A575C- ---- Lines mindspark removed from prefs.js ---- user_pref("extensions.toolbar.mindspark.hp.enabled", false); user_pref("extensions.toolbar.mindspark.hp.enabled.guid", ""); user_pref("extensions.toolbar.mindspark.lastInstalled", "allin1convert@mindspark.com"); ---- FireFox user.js and prefs.js backups ---- prefs_17-04-2014_1049_.backup ==== Registry Fix Code x64 ====================== Windows Registry Editor Version 5.00 [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BE7A24F5-69CB-4708-B77B-B1EDA6043B95}] [-HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{28387537-e3f9-4ed7-860c-11e69af4a8a0}] [-HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2EECD738-5844-4a99-B4B6-146BF802613B}] [-HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5CB02877-EFBC-4317-B608-9E24B11BAB40}] [-HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{872b5b88-9db5-4310-bdd0-ac189557e5f5}] [-HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d2ce3e00-f94a-4740-988e-03dc2f38c34f}] [-HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EEE6C35C-6118-11DC-9C72-001320C79847}] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "TBHostSupport"=- [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DATAMNGR] [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mobilegeni daemon] [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SweetIM] [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sweetpacks Communicator] [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^FastMediaConverter.lnk] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"= ==== Deleting Files \ Folders ====================== C:\Users\JEF\AppData\Local\TBHostSupport not found C:\PROGRA~3\{01BD4FC9-2F86-4706-A62E-774BB7E9D308} not found C:\PROGRA~3\{93E26451-CD9A-43A5-A2FA-C42392EA4001} not found C:\PROGRA~3\{C4ABDBC8-1C81-42C9-BFFC-4A68511E9E4F} not found "C:\Users\JEF\AppData\Roaming\Mozilla\Firefox\Profiles\3mu83j4a.default\searchplugins\ ask-web-search.xml" not found C:\Program Files (x86)\DVDVideoSoftTB deleted C:\Program Files (x86)\tuvaro deleted C:\Program Files (x86)\SweetIM deleted C:\Program Files (x86)\FastMediaConverter deleted C:\Users\JEF\AppData\Roaming\ftblauncher deleted C:\Program Files (x86)\Mobogenie deleted C:\Program Files (x86)\SearchProtect deleted C:\Users\JEF\daemonprocess.txt deleted C:\Users\JEF\.android deleted C:\PROGRA~2\Mozilla Firefox\user.js deleted C:\PROGRA~2\~BabylonToolbar deleted C:\PROGRA~2\BearShare Applications\Mediabar deleted C:\PROGRA~2\iMesh Applications deleted C:\PROGRA~2\MyPC Backup deleted C:\PROGRA~2\Conduit deleted C:\PROGRA~2\Search Results Toolbar deleted C:\PROGRA~2\COMMON~1\Spigot deleted C:\found.000 deleted C:\Users\JEF\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mobogenie.lnk deleted C:\Users\JEF\AppData\Roaming\newnext.me deleted C:\Users\JEF\AppData\Roaming\Babylon deleted C:\Users\JEF\AppData\Roaming\OpenCandy deleted C:\PROGRA~3\Ask deleted C:\PROGRA~3\boost_interprocess deleted C:\PROGRA~3\Wincert deleted C:\PROGRA~3\AVG Secure Search deleted C:\PROGRA~3\InstallMate deleted C:\PROGRA~3\Premium deleted C:\Users\JEF\AppData\Local\Ilivid Player deleted C:\Users\JEF\AppData\Local\CRE deleted C:\Users\JEF\AppData\Local\APN deleted C:\Users\JEF\AppData\Local\WhiteListing deleted C:\Users\JEF\AppData\Local\SearchProtect deleted C:\Users\JEF\AppData\Local\NativeMessaging deleted C:\Users\JEF\AppData\Local\Mobogenie deleted C:\Users\JEF\AppData\Local\Babylon deleted C:\Users\JEF\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mobogenie deleted C:\Windows\SysNative\roboot64.exe deleted C:\Users\JEF\Downloads\iLividSetup (1).exe deleted C:\Users\JEF\Downloads\iLividSetup (2).exe deleted C:\Users\JEF\Downloads\iLividSetup (3).exe deleted C:\Users\JEF\Downloads\iLividSetup.exe deleted C:\Users\JEF\Downloads\FreeYouTubeToMP3Converter.exe deleted C:\Users\JEF\Downloads\SoftonicDownloader_voor_firefox.exe deleted C:\Users\JEF\Downloads\SoftonicDownloader_voor_picasa (1).exe deleted C:\Users\JEF\Downloads\SoftonicDownloader_voor_picasa.exe deleted C:\Users\JEF\Downloads\SoftonicDownloader_voor_samsung-kies.exe deleted C:\Users\JEF\AppData\LocalLow\DVDVideoSoftTB deleted C:\Users\JEF\AppData\LocalLow\TB deleted C:\Users\JEF\AppData\LocalLow\mediabarim deleted C:\Users\JEF\AppData\LocalLow\DataMngr deleted C:\Users\JEF\AppData\LocalLow\PriceGong deleted C:\Users\JEF\AppData\LocalLow\Conduit deleted C:\Windows\sysWoW64\config\systemprofile\AppData\LocalLow\AVG Secure Search deleted C:\Windows\sysWoW64\config\systemprofile\AppData\LocalLow\Application Updater deleted C:\user.js deleted C:\END deleted C:\Windows\Syswow64\sho10F3.tmp deleted C:\Windows\Syswow64\shoAC41.tmp deleted C:\Windows\Syswow64\shoF850.tmp deleted C:\Windows\Syswow64\SearchProtect deleted C:\Users\JEF\Documents\Mobogenie deleted C:\Users\JEF\AppData\Roaming\Mozilla\Firefox\Profiles\3mu83j4a.default\searchplugins\ask-web-search.xml deleted C:\Users\JEF\AppData\Roaming\Mozilla\Firefox\Profiles\3mu83j4a.default\searchplugins\conduit-search.xml deleted C:\Windows\Installer\{7683B745-6060-41FD-AA75-0BBB383FEAD4} deleted "C:\Users\JEF\AppData\Roaming\Mozilla\Firefox\Profiles\3mu83j4a.default\searchplugins\my-homepage.xml" deleted "C:\Windows\Installer\e8b286.msi" deleted "C:\Users\JEF\AppData\Roaming\tuvaro\sqlite3.dll" deleted "C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE" deleted "C:\Users\JEF\AppData\Roaming\tuvaro" deleted "C:\Program Files (x86)\Microsoft\BingBar" not deleted "C:\PROGRA~3\SweetIM" deleted "C:\Users\JEF\AppData\Local\Conduit" deleted ==== System Specs ====================== Windows: Windows 7 Home Premium Edition (64-bit) Service Pack 1 (Build 7601) Memory (RAM): 4078 MB CPU Info: Intel(R) Pentium(R) CPU B950 @ 2.10GHz CPU Speed: 2130,9 MHz Sound Card: Speaker/HP (Conexant SmartAudio | Display Adapters: NVIDIA GeForce 410M | NVIDIA GeForce 410M | RDPDD Chained DD | RDP Encoder Mirror Driver | RDP Reflector Display Driver Monitors: 1x; Generic PnP Monitor | Screen Resolution: 1600 X 900 - 32 bit Network: Network Present Network Adapters: Microsoft Virtual WiFi Miniport Adapter #2 | Bluetooth Device (Personal Area Network) | Atheros AR9285 Wireless Network Adapter | Realtek PCIe GBE Family Controller CD / DVD Drives: 1x (E: | ) E: Optiarc DVD RW AD-7740H Ports: COM4 | COM3 LPT Port NOT Present. Mouse: 16 Button Wheel Mouse Present Hard Disks: C: 450,6GB | Q: 0,0MB Hard Disks - Free: C: 362,7GB | Q: 0,0MB Manufacturer *: INSYDE BIOS Info: AT/AT COMPATIBLE | 04/28/11 | Sony - 20110428 Time Zone: West-Europa (standaardtijd) Motherboard *: Sony Corporation VAIO Country: Nederland Language: NLD ==== System Specs (Software) ====================== Anti-Virus: AVG AntiVirus Free Edition 2013 On-access scanning disabled (Outdated) Anti-Spyware: Spybot - Search and Destroy disabled (Outdated) Anti-Spyware: AVG AntiVirus Free Edition 2013 disabled (Outdated) Default Browser: Firefox 28.0 Internet Explorer Version: 11.0.9600.17041 Mozilla Firefox version: 28.0 (x86 nl) Torch Browser version: 23.0.0.3116 Adobe Reader version: 10.1.9.22 Sun Java version: 1.7.0_11 (32-bit) Sun Java version: 1.6.0_22 (64-bit) Flash Player version: 12.0.0.77 ==== Files Recently Created / Modified ====================== ====== C:\Windows ==== ====== C:\Users\JEF\AppData\Local\Temp ==== 2014-04-16 09:07:16 B5853E9B0D3B6028A71ADF9626F56810 126264 ----a-w- C:\Users\JEF\AppData\Local\Temp\TUUUninstallHelper.exe ====== Java Cache ===== ====== C:\Windows\SysWOW64 ===== 2014-04-13 07:22:40 AA12D7A960DB78DD9690AB5B5DAE6586 440832 ----a-w- C:\Windows\SysWOW64\ieui.dll 2014-04-13 07:22:39 CE6921D33682C6C3DB8A45853CC69402 455168 ----a-w- C:\Windows\SysWOW64\vbscript.dll 2014-04-13 07:22:21 A127D17C354B473B0F4C6265538F5A2C 2724864 ----a-w- C:\Windows\SysWOW64\mshtml.tlb 2014-04-13 07:22:13 7E9FE7DB43BC204E44F159F843E35C15 367616 ----a-w- C:\Windows\SysWOW64\dxtmsft.dll 2014-04-13 07:22:13 34FC79C948EE2C5FD0CD699E7D7F91B7 244224 ----a-w- C:\Windows\SysWOW64\dxtrans.dll 2014-04-13 07:22:12 EDACA6C44D9CE200F899B7DB0F201DFF 164864 ----a-w- C:\Windows\SysWOW64\msrating.dll 2014-04-13 07:22:12 EBC35FE64056910A84485BEEB6DCCAC6 524288 ----a-w- C:\Windows\SysWOW64\msfeeds.dll 2014-04-13 07:22:12 31385A6CAA31BE9D07B0B32E5AA99ABB 43008 ----a-w- C:\Windows\SysWOW64\jsproxy.dll 2014-04-13 07:22:11 82287FCFFA4A2D60FD744E3FEB3192C5 61952 ----a-w- C:\Windows\SysWOW64\iesetup.dll 2014-04-13 07:22:11 21BF6759685FD193715B483F2B3F21B1 112128 ----a-w- C:\Windows\SysWOW64\ieUnatt.exe 2014-04-13 07:22:10 C9CA9803299EB6AFA34CB520BAAB083D 32256 ----a-w- C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2014-04-13 07:22:10 0FDC1A576A3F40420882C0F7C4A66EAD 32768 ----a-w- C:\Windows\SysWOW64\iernonce.dll 2014-04-13 07:22:07 BB185D4A9362AA17CBCEC0768CDBF249 704512 ----a-w- C:\Windows\SysWOW64\ieapfltr.dll 2014-04-13 07:22:07 6557B48D53D653CFCCE3CB1CFA53A8E1 51200 ----a-w- C:\Windows\SysWOW64\ieetwproxystub.dll 2014-04-13 07:22:07 0F4A295516781897FFB09B4CCF2E8798 592896 ----a-w- C:\Windows\SysWOW64\jscript9diag.dll 2014-04-13 07:22:02 E4E829EE073E046B0EB19B5FECB19B8C 1789440 ----a-w- C:\Windows\SysWOW64\wininet.dll 2014-04-13 07:22:02 05BD47136DE62FAFE9F95B40E4100144 2178048 ----a-w- C:\Windows\SysWOW64\iertutil.dll 2014-04-13 07:22:01 C4A383FD50FBD7E274DD41CF571DF898 1967104 ----a-w- C:\Windows\SysWOW64\inetcpl.cpl 2014-04-13 07:22:01 76F58DB8F85C125E0D6B3AA42F3BF1D0 1143808 ----a-w- C:\Windows\SysWOW64\urlmon.dll 2014-04-13 07:21:59 2AFBB91BBD2378933B26E6D68C140D1B 11745792 ----a-w- C:\Windows\SysWOW64\ieframe.dll 2014-04-13 07:21:58 EA85144F35EDE6EE25C484D4242FF2C8 17387008 ----a-w- C:\Windows\SysWOW64\mshtml.dll 2014-04-13 07:21:58 8C46360D6EF9D4C563FE834C4F287DA3 4254720 ----a-w- C:\Windows\SysWOW64\jscript9.dll 2014-04-09 07:32:31 76161B9D78A275F8F28DD67436013110 1114112 ----a-w- C:\Windows\SysWOW64\kernel32.dll 2014-04-09 07:32:30 2E1D6624EE2C3F454CADF09DC59E78B0 25600 ----a-w- C:\Windows\SysWOW64\setup16.exe 2014-04-09 07:32:28 1F76F7CB3C690ACB985C2FD419383B49 14336 ----a-w- C:\Windows\SysWOW64\ntvdm64.dll 2014-04-09 07:32:26 9F3D88540DB73F5213D5044CB50006DF 7680 ----a-w- C:\Windows\SysWOW64\instnm.exe 2014-04-09 07:32:26 1E886E327F37F34CC7465F1605D1F3CD 5120 ----a-w- C:\Windows\SysWOW64\wow32.dll 2014-04-09 07:32:25 A30AB03E7C837A17AC70E67E63B8E2F6 2048 ----a-w- C:\Windows\SysWOW64\user.exe ====== C:\Windows\SysWOW64\drivers ===== ====== C:\Windows\Sysnative ===== 2014-04-13 07:22:43 7446786E7092ABE122D372F95E6ED74B 574976 ----a-w- C:\Windows\Sysnative\ieui.dll 2014-04-13 07:22:39 FFF555C177D9F2B79B5C3146BED09FB1 548352 ----a-w- C:\Windows\Sysnative\vbscript.dll 2014-04-13 07:22:21 6A8AA25D37F89E40B834F34950E3B89B 2724864 ----a-w- C:\Windows\Sysnative\mshtml.tlb 2014-04-13 07:22:19 D6067F7EE060C5D6D79008AD591B4E3B 33792 ----a-w- C:\Windows\Sysnative\iernonce.dll 2014-04-13 07:22:19 964C89BC8A52A260D68C90FDDEB862E2 38400 ----a-w- C:\Windows\Sysnative\JavaScriptCollectionAgent.dll 2014-04-13 07:22:19 72116CC377FF4281B0132C397026D911 4096 ----a-w- C:\Windows\Sysnative\ieetwcollectorres.dll 2014-04-13 07:22:19 3F498856C68725717195C16568FE19D0 586240 ----a-w- C:\Windows\Sysnative\ie4uinit.exe 2014-04-13 07:22:13 E0D95345D1EBB54F28E958782B9C0CE0 453120 ----a-w- C:\Windows\Sysnative\dxtmsft.dll 2014-04-13 07:22:13 CFBA793F678EB3855052ECF99357A9A1 296960 ----a-w- C:\Windows\Sysnative\dxtrans.dll 2014-04-13 07:22:13 3F547245C78F4847B73EDDFD4A2F7E12 752640 ----a-w- C:\Windows\Sysnative\jscript9diag.dll 2014-04-13 07:22:12 E7161E2C66FF9B1E87C30FC9D2497ABB 195584 ----a-w- C:\Windows\Sysnative\msrating.dll 2014-04-13 07:22:12 CB57E934280D346AE0A9B053DAA284C5 51200 ----a-w- C:\Windows\Sysnative\jsproxy.dll 2014-04-13 07:22:12 75AD355828187145A60E3DC7BAF7B0F3 628736 ----a-w- C:\Windows\Sysnative\msfeeds.dll 2014-04-13 07:22:11 1BF215FF4DF6DE10D2F81A2CE85157D2 139264 ----a-w- C:\Windows\Sysnative\ieUnatt.exe 2014-04-13 07:22:10 A3F9A9E46BDDBB8B20B7CF3EEDB990F2 66048 ----a-w- C:\Windows\Sysnative\iesetup.dll 2014-04-13 07:22:09 37D0FB9E5E8EDA40B66FC3FB3D660261 23549440 ----a-w- C:\Windows\Sysnative\mshtml.dll 2014-04-13 07:22:06 EBAD8A4D048ED257E4A45F6356541F86 846336 ----a-w- C:\Windows\Sysnative\ieapfltr.dll 2014-04-13 07:22:06 915D8A9E112C97C90C654F792B6B28B9 48640 ----a-w- C:\Windows\Sysnative\ieetwproxystub.dll 2014-04-13 07:22:05 A3A132CBE48AF0324466469F2CAAE8A2 111616 ----a-w- C:\Windows\Sysnative\ieetwcollector.exe 2014-04-13 07:22:05 710FD0E362A1A5C087DB90C1BAC46411 940032 ----a-w- C:\Windows\Sysnative\MsSpellCheckingFacility.exe 2014-04-13 07:22:02 1F8534A19A66275C863DE17645CB2A13 2767360 ----a-w- C:\Windows\Sysnative\iertutil.dll 2014-04-13 07:22:01 F220BA78AB542C70211D73AE4729B2CD 2260480 ----a-w- C:\Windows\Sysnative\wininet.dll 2014-04-13 07:22:01 32417AE8280276968E5C551ED85D3525 1400832 ----a-w- C:\Windows\Sysnative\urlmon.dll 2014-04-13 07:22:00 A14BB2F5F6457738AAA11367F5172A05 13551104 ----a-w- C:\Windows\Sysnative\ieframe.dll 2014-04-13 07:22:00 1654093C8BD3342997D27B71684ACCE8 2043904 ----a-w- C:\Windows\Sysnative\inetcpl.cpl 2014-04-13 07:21:58 BF25489459C7A762DD7B3186C7E3984D 5784064 ----a-w- C:\Windows\Sysnative\jscript9.dll 2014-04-09 07:32:32 D2A513EE880D71BDE7F0257F38B9D019 1163264 ----a-w- C:\Windows\Sysnative\kernel32.dll 2014-04-09 07:32:32 2A107B611C91CD256466C58C0D776E9D 243712 ----a-w- C:\Windows\Sysnative\wow64.dll 2014-04-09 07:32:31 7434E01FBCA3CB86539C39412A31D5E1 362496 ----a-w- C:\Windows\Sysnative\wow64win.dll 2014-04-09 07:32:28 74959C718FF4594369645F35B7DF19C4 16384 ----a-w- C:\Windows\Sysnative\ntvdm64.dll 2014-04-09 07:32:28 0F090A77E664CB0F70AB8D3B230B760C 13312 ----a-w- C:\Windows\Sysnative\wow64cpu.dll ====== C:\Windows\Sysnative\drivers ===== 2014-04-09 07:32:38 B3222734D80013D2C73841B0C549FA63 27584 ----a-w- C:\Windows\Sysnative\drivers\Diskdump.sys 2014-04-09 07:32:38 A3F0BC5897F9D3786A3CB695B163633A 190912 ----a-w- C:\Windows\Sysnative\drivers\storport.sys 2014-04-09 07:32:38 96BB922A0981BC7432C8CF52B5410FE6 274880 ----a-w- C:\Windows\Sysnative\drivers\msiscsi.sys 2014-04-09 07:32:23 1A29A59A4C5BA6F8C85062A613B7E2B2 1684928 ----a-w- C:\Windows\Sysnative\drivers\ntfs.sys 2014-03-20 12:50:52 A8A6A0D0E9EF2AD528AE93647A84CDE9 240952 ----a-w- C:\Windows\Sysnative\drivers\avgtdia.sys ====== C:\Windows\Tasks ====== ====== C:\Windows\Temp ====== ======= C:\Program Files ===== 2014-04-16 16:33:58 -------- d-----w- C:\Program Files\trend micro ======= C:\PROGRA~2 ===== ======= C: ===== ====== C:\Users\JEF\AppData\Roaming ====== 2014-04-16 09:40:24 -------- d-----w- C:\Users\JEF\AppData\Local\Windows Live Writer 2014-04-14 09:16:37 -------- d-sh--w- C:\Users\JEF\AppData\Locallow\EmieUserList 2014-04-14 08:56:25 -------- d-sh--w- C:\Users\JEF\AppData\Local\EmieUserList 2014-04-14 08:56:25 -------- d-sh--w- C:\Users\JEF\AppData\Local\EmieSiteList 2014-04-14 08:30:56 -------- d-sh--w- C:\Users\JEF\AppData\Locallow\EmieSiteList 2014-04-05 05:55:27 -------- d-----w- C:\Users\JEF\AppData\Local\TB ====== C:\Users\JEF ====== 2014-04-16 16:33:29 662C39FC1E27131551D557862CEC47F0 935175 ----a-w- C:\Users\JEF\Downloads\RSITx64.exe 2014-04-16 09:19:05 6923AE4BC668E604081BE3D3723B4B31 24654088 ----a-w- C:\Users\JEF\Downloads\Firefox_Setup_27.0.1.exe 2014-04-15 09:56:52 565592D342E241EB6FCA351F9C810AE3 4787368 ----a-w- C:\Users\JEF\Downloads\ccsetup412.exe 2014-04-10 13:42:50 1A1203DFB6D4236BD5CAAAA0EA642317 2401074 ----a-w- C:\Users\JEF\Downloads\launcher^FTB_Launcher (2).exe 2014-04-10 13:22:52 1A1203DFB6D4236BD5CAAAA0EA642317 2401074 ----a-w- C:\Users\JEF\Downloads\launcher^FTB_Launcher (1).exe 2014-04-10 13:22:36 1A1203DFB6D4236BD5CAAAA0EA642317 2401074 ----a-w- C:\Users\JEF\Downloads\launcher^FTB_Launcher.exe 2014-04-09 07:23:44 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG ====== C: exe-files == 2014-04-17 08:22:04 54E3923D448FB81ED7F5BB06EC134798 544 ----a-w- C:\$Recycle.Bin\S-1-5-21-1325376773-928895087-3028547245-1000\$I2F633O.exe 2014-04-17 08:21:50 E95905CF25E282F8CA66542E7DA22084 544 ----a-w- C:\$Recycle.Bin\S-1-5-21-1325376773-928895087-3028547245-1000\$IASDBUD.exe 2014-04-17 08:21:50 B1D0EE833C8FA92A86560C668F440C27 544 ----a-w- C:\$Recycle.Bin\S-1-5-21-1325376773-928895087-3028547245-1000\$IJMIN14.exe 2014-04-17 08:21:50 A330FA4F7FC1479F4BA5065D7C2A7FAC 544 ----a-w- C:\$Recycle.Bin\S-1-5-21-1325376773-928895087-3028547245-1000\$I5C0N8E.exe 2014-04-17 08:21:50 23A4C26E14024048832B4471C99FD7AA 544 ----a-w- C:\$Recycle.Bin\S-1-5-21-1325376773-928895087-3028547245-1000\$I1VOQ3E.exe 2014-04-17 08:21:49 F45D278FDAF6033BD67777F31D1E1ECF 544 ----a-w- C:\$Recycle.Bin\S-1-5-21-1325376773-928895087-3028547245-1000\$I6J2B9V.exe 2014-04-17 08:21:49 F1BD15A9F03AB94310FDD7F5CD55BF11 544 ----a-w- C:\$Recycle.Bin\S-1-5-21-1325376773-928895087-3028547245-1000\$IZIVB0L.exe 2014-04-17 08:21:49 638DA42C2BB47ED50192DCE20D333B67 544 ----a-w- C:\$Recycle.Bin\S-1-5-21-1325376773-928895087-3028547245-1000\$I0FKSG9.exe 2014-04-17 08:21:49 1376648995897B2524CAE02F933060E8 544 ----a-w- C:\$Recycle.Bin\S-1-5-21-1325376773-928895087-3028547245-1000\$IZMK3DH.exe 2014-04-17 08:21:13 2ED2319F3DE13495AAA49B70A1467055 1285120 ----a-w- C:\$Recycle.Bin\S-1-5-21-1325376773-928895087-3028547245-1000\$R6J2B9V.exe 2014-04-17 08:20:07 2ED2319F3DE13495AAA49B70A1467055 1285120 ----a-w- C:\$Recycle.Bin\S-1-5-21-1325376773-928895087-3028547245-1000\$RZIVB0L.exe 2014-04-17 08:18:36 2ED2319F3DE13495AAA49B70A1467055 1285120 ----a-w- C:\$Recycle.Bin\S-1-5-21-1325376773-928895087-3028547245-1000\$RZMK3DH.exe 2014-04-17 08:17:32 2ED2319F3DE13495AAA49B70A1467055 1285120 ----a-w- C:\$Recycle.Bin\S-1-5-21-1325376773-928895087-3028547245-1000\$R0FKSG9.exe 2014-04-17 08:17:08 2ED2319F3DE13495AAA49B70A1467055 1285120 ----a-w- C:\$Recycle.Bin\S-1-5-21-1325376773-928895087-3028547245-1000\$R1VOQ3E.exe 2014-04-17 08:12:28 2ED2319F3DE13495AAA49B70A1467055 1285120 ----a-w- C:\$Recycle.Bin\S-1-5-21-1325376773-928895087-3028547245-1000\$R5C0N8E.exe 2014-04-17 08:10:05 2ED2319F3DE13495AAA49B70A1467055 1285120 ----a-w- C:\$Recycle.Bin\S-1-5-21-1325376773-928895087-3028547245-1000\$RASDBUD.exe 2014-04-17 08:09:07 2ED2319F3DE13495AAA49B70A1467055 1285120 ----a-w- C:\$Recycle.Bin\S-1-5-21-1325376773-928895087-3028547245-1000\$RJMIN14.exe 2014-04-17 08:06:03 2ED2319F3DE13495AAA49B70A1467055 1285120 ----a-w- C:\$Recycle.Bin\S-1-5-21-1325376773-928895087-3028547245-1000\$R2F633O.exe 2014-04-16 16:33:58 9A2347903D6EDB84C10F288BC0578C1C 388608 ----a-w- C:\Program Files\trend micro\JEF.exe 2014-04-16 16:33:29 662C39FC1E27131551D557862CEC47F0 935175 ----a-w- C:\Users\JEF\Downloads\RSITx64.exe 2014-04-16 09:19:05 6923AE4BC668E604081BE3D3723B4B31 24654088 ----a-w- C:\Users\JEF\Downloads\Firefox_Setup_27.0.1.exe 2014-04-16 09:07:16 B5853E9B0D3B6028A71ADF9626F56810 126264 ----a-w- C:\Users\JEF\AppData\Local\Temp\TUUUninstallHelper.exe 2014-04-15 09:56:52 565592D342E241EB6FCA351F9C810AE3 4787368 ----a-w- C:\Users\JEF\Downloads\ccsetup412.exe 2014-04-13 07:22:32 F972DDD19A10F53D74021DDEAC07CCA6 470016 ----a-w- C:\Program Files (x86)\Internet Explorer\ieinstal.exe 2014-04-13 07:22:32 E0155A11B26C7D5347069AB7ACB62D02 222720 ----a-w- C:\Program Files\Internet Explorer\ielowutil.exe 2014-04-13 07:22:32 C5C7E33308BAE18BD9F59F9A93E85D33 482816 ----a-w- C:\Program Files\Internet Explorer\ieinstal.exe 2014-04-13 07:22:32 BEA4E0C0BA936E8A3DB24D1A37BF70BE 222720 ----a-w- C:\Program Files (x86)\Internet Explorer\ielowutil.exe 2014-04-13 07:22:19 3F498856C68725717195C16568FE19D0 586240 ----a-w- C:\Windows\System32\ie4uinit.exe 2014-04-13 07:22:11 21BF6759685FD193715B483F2B3F21B1 112128 ----a-w- C:\Windows\SysWOW64\ieUnatt.exe 2014-04-13 07:22:11 1BF215FF4DF6DE10D2F81A2CE85157D2 139264 ----a-w- C:\Windows\System32\ieUnatt.exe 2014-04-13 07:22:05 A3A132CBE48AF0324466469F2CAAE8A2 111616 ----a-w- C:\Windows\System32\ieetwcollector.exe 2014-04-13 07:22:05 710FD0E362A1A5C087DB90C1BAC46411 940032 ----a-w- C:\Windows\System32\MsSpellCheckingFacility.exe 2014-04-13 07:22:01 EA8386CA87165460D39A1D29FF11080B 809680 ----a-w- C:\Program Files\Internet Explorer\iexplore.exe 2014-04-13 07:22:01 0667ED9F8E905E1F73DB60ACCEDCBCA7 811728 ----a-w- C:\Program Files (x86)\Internet Explorer\iexplore.exe 2014-04-11 15:18:18 57FD01A0DC56FB1ACC1B1F9EBA024755 581192 ----a-w- C:\Users\JEF\AppData\LocalLow\Unity\WebPlayer\UnityWebPlayerUpdate.exe 2014-04-11 15:18:18 490F1084B74452DB89832BA4D77DE420 740936 ----a-w- C:\Users\JEF\AppData\LocalLow\Unity\WebPlayer\UnityBugReporter.exe 2014-04-10 13:42:50 1A1203DFB6D4236BD5CAAAA0EA642317 2401074 ----a-w- C:\Users\JEF\Downloads\launcher^FTB_Launcher (2).exe 2014-04-10 13:22:52 1A1203DFB6D4236BD5CAAAA0EA642317 2401074 ----a-w- C:\Users\JEF\Downloads\launcher^FTB_Launcher (1).exe 2014-04-10 13:22:36 1A1203DFB6D4236BD5CAAAA0EA642317 2401074 ----a-w- C:\Users\JEF\Downloads\launcher^FTB_Launcher.exe 2014-04-10 10:54:10 B97A94D50F797EF00614BE4F25A7A631 548536 ----a-w- C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonX86\Microsoft Shared\OFFICE15\MSOSQM.EXE 2014-04-10 10:54:09 D4474A8F1545F5EA8910DF0A0BA3B2AA 840400 ----a-w- C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonX86\Microsoft Shared\DW\DW20.EXE 2014-04-10 10:54:04 847C42B6D3628881E8DF4B093631519D 78576 ----a-w- C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonX86\Microsoft Shared\OFFICE15\CSISYNCCLIENT.EXE 2014-04-10 10:54:03 49D6E55582897A2D7BE65248603F083E 7129304 ----a-w- C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE15\CMigrate.exe 2014-04-10 10:54:01 1368F38793FD367B450B47FEAEBF2DA2 39584 ----a-w- C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\AppSharingHookController64.exe 2014-04-10 10:53:59 C8F675B4F7AC2D31A44501F9939CF80A 5297368 ----a-w- C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonX86\Microsoft Shared\OFFICE15\CMigrate.exe 2014-04-10 10:53:57 55237AB507C8351C2DE903FB42BE82A7 9597104 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\PDFREFLOW.EXE 2014-04-10 10:53:56 FEAEB800E5632437644E9D131B9D6098 871088 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\protocolhandler.exe 2014-04-10 10:53:54 98C21A1E196BBC7DA76B35A8D1DC7B05 471784 ----a-w- C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonX86\Microsoft Shared\DW\DWTRIG20.EXE 2014-04-10 10:53:42 D6628D559F16663F62D2AAA95AC730ED 496320 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\MSOUC.EXE 2014-04-10 10:53:42 BC0035342F87B6E2B6E2EDEC540B35BF 478936 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\SELFCERT.EXE 2014-04-10 10:53:42 B250D11FFAFDF23DA54C717A05BC6C92 449216 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\MSOSYNC.EXE 2014-04-10 10:53:42 06F21309A380BC51D5991D3E951DB70A 1054424 ----a-w- C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonX86\Microsoft Shared\OFFICE15\OLicenseHeartbeat.exe 2014-04-10 10:53:37 D7571FB88C91A05300B1EC1835200C1C 515312 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\IEContentService.exe 2014-04-10 10:53:37 7D36DBF0B4355C4204C94F30C3821ED0 21922464 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\excelcnv.exe 2014-04-10 10:53:37 527428444DDE1288A502182F6B374B17 4522688 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\GRAPH.EXE 2014-04-10 10:53:36 589AEB7287893196D585A336570F028F 569592 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\ORGCHART.EXE 2014-04-10 10:53:36 23B85A0F237D3E439F98FA0B73EC490C 526024 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\VPREVIEW.EXE 2014-04-10 10:52:53 F0ECAEDB879431874D2315630BD05502 578256 ----a-w- C:\Program Files\Microsoft Office 15\root\Integration\Integrator.exe 2014-04-10 10:52:22 D31FE31FD11E05A0503B59D694FB65FD 18926248 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\OUTLOOK.EXE 2014-04-10 10:52:19 E7910B535B3F52A0C795DA90626E28E5 1757352 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\ONENOTE.EXE 2014-04-10 10:52:18 579ABA2979970978365E7615B593EBEF 15516840 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\MSACCESS.EXE 2014-04-10 10:52:07 35F84DF8A5B0941D7DE5A8CE1E1D5413 1923232 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\WINWORD.EXE 2014-04-10 10:52:05 DD76F47DFAB2AFE63B763B32636B9C60 25701024 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\EXCEL.EXE 2014-04-10 10:51:55 DF5AB1C45F8062054E2A9602A274A648 934056 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\FIRSTRUN.EXE === C: other files == 2014-04-17 08:22:04 5B69346FE56BA0B49456EF1A7F2324A1 544 ----a-w- C:\$Recycle.Bin\S-1-5-21-1325376773-928895087-3028547245-1000\$IWPDDZ6.zip 2014-04-17 08:21:50 E7AE7D57381A95BE52EFBDF3D770F1D1 544 ----a-w- C:\$Recycle.Bin\S-1-5-21-1325376773-928895087-3028547245-1000\$IN1M1LE.zip 2014-04-17 08:21:50 AE9C14DF6F90B066C999398AE00BCE21 544 ----a-w- C:\$Recycle.Bin\S-1-5-21-1325376773-928895087-3028547245-1000\$I2VEVAX.zip 2014-04-17 08:10:44 CAF42F8091300B332B58C047B5D85C6D 4095370 ----a-w- C:\$Recycle.Bin\S-1-5-21-1325376773-928895087-3028547245-1000\$R2VEVAX.zip 2014-04-17 08:10:34 CAF42F8091300B332B58C047B5D85C6D 4095370 ----a-w- C:\$Recycle.Bin\S-1-5-21-1325376773-928895087-3028547245-1000\$RN1M1LE.zip 2014-04-17 08:09:15 CAF42F8091300B332B58C047B5D85C6D 4095370 ----a-w- C:\$Recycle.Bin\S-1-5-21-1325376773-928895087-3028547245-1000\$RWPDDZ6.zip 2014-04-10 13:45:11 BA1C7F176C0BFC26DEAEC42B5C89D2C4 11329 ----a-w- C:\Users\JEF\Downloads\Monster\minecraft\mods\[1.6.4]StatusEffectHUDv1.19.zip 2014-04-10 13:45:10 F7FED83700375FED9FC961845945109A 70443 ----a-w- C:\Users\JEF\Downloads\Monster\minecraft\mods\[1.6.4]bspkrsCorev5.2.zip 2014-04-10 13:45:10 D3F6A5BF86864CDBE5FBDF6FFBB99AA5 11741 ----a-w- C:\Users\JEF\Downloads\Monster\minecraft\mods\[1.6.4]ArmorStatusHUDv1.15.zip 2014-04-10 13:45:10 AA89C00EBF0993AC8ECC2892F32A4A69 10651557 ----a-w- C:\Users\JEF\Downloads\Monster\minecraft\mods\Thaumcraft4.1.0f.zip 2014-04-10 13:45:10 8240B2B061DB4815E521CB056E5FCE2B 32444 ----a-w- C:\Users\JEF\Downloads\Monster\minecraft\mods\thaumcraftmobaspects-1.6.X-1e-build2.zip 2014-04-10 13:45:10 42790277280A0EF1AC66F2BE1AF82F43 948003 ----a-w- C:\Users\JEF\Downloads\Monster\minecraft\mods\Waila_1.5.1a.zip 2014-04-10 13:45:09 9A40FA69737542E4BA0D8CA990BDE811 2095323 ----a-w- C:\Users\JEF\Downloads\Monster\minecraft\mods\StevesCarts2.0.0.b10.zip 2014-04-10 13:45:09 87849EFE11AEFB593712CA45854F3C66 5498227 ----a-w- C:\Users\JEF\Downloads\Monster\minecraft\mods\RotaryCraft 1.6 v18b.zip 2014-04-10 13:45:09 5CA5771240081BF8E70505873905E336 221855 ----a-w- C:\Users\JEF\Downloads\Monster\minecraft\mods\roguelike-v1.3.0-forge-1.6.4.zip 2014-04-10 13:45:09 3E0E5A7545918BF5E3B0FA6223A5B734 959599 ----a-w- C:\Users\JEF\Downloads\Monster\minecraft\mods\ReactorCraft 1.6 v18.zip 2014-04-10 13:45:09 1D3EC17D87859740CA270D75A7642EF1 194829 ----a-w- C:\Users\JEF\Downloads\Monster\minecraft\mods\Sync2.1.1.zip 2014-04-10 13:45:09 033AB59ABD842AE1E99360CF3C62F18E 72865 ----a-w- C:\Users\JEF\Downloads\Monster\minecraft\mods\revamp-1.2.2.zip 2014-04-10 13:45:04 3A46872E6117BFF3AA1874608BC04F4D 345123 ----a-w- C:\Users\JEF\Downloads\Monster\minecraft\mods\PC_PowerConverters_ZS ed_2.4.0pre3_forge 965_mc 1.6.4.zip 2014-04-10 13:45:04 076162AE7DEBC0DAE697534E439FF499 950152 ----a-w- C:\Users\JEF\Downloads\Monster\minecraft\mods\PortalGun2.0.2.zip 2014-04-10 13:45:03 BBB4CB57D782EA2B9A54B08EC46D7CCD 130122 ----a-w- C:\Users\JEF\Downloads\Monster\minecraft\mods\Mimicry_1.3.8.2_forge 965_mc 1.6.4.zip 2014-04-10 13:45:03 8A97E3CC318FEAC11E9B19B8A3F825A5 1833436 ----a-w- C:\Users\JEF\Downloads\Monster\minecraft\mods\mystcraft-uni-1.6.4-0.10.12.01.zip 2014-04-10 13:44:59 6173CCEF97D9771DF20B9A15F101AE99 2391475 ----a-w- C:\Users\JEF\Downloads\Monster\minecraft\mods\magical_crops_1.6.4_3.2.0_BETA_15a.zip 2014-04-10 13:44:56 EE5E961144E56BF648323D5584144E16 290072 ----a-w- C:\Users\JEF\Downloads\Monster\minecraft\mods\Highlands2.1.7a_MC1.6.4.zip 2014-04-10 13:44:56 E70955CAD99FA6B4CD0F66DE357BACB3 819206 ----a-w- C:\Users\JEF\Downloads\Monster\minecraft\mods\IC2NuclearControl-1.6.2e-ic2-experimental.zip 2014-04-10 13:44:56 D40441F39AF2A8CB6AE708804C94CA16 139744 ----a-w- C:\Users\JEF\Downloads\Monster\minecraft\mods\GasCraft-2.0.4.3.zip 2014-04-10 13:44:56 B1579C38DC5D1CFE74C7CC6AF77B4BAA 133025 ----a-w- C:\Users\JEF\Downloads\Monster\minecraft\mods\ironchest-universal-1.6.4-5.4.1.697.zip 2014-04-10 13:44:56 A17A9C4DDF840482B916C59E3806C49F 622102 ----a-w- C:\Users\JEF\Downloads\Monster\minecraft\mods\JABBA_1.1.1a.zip 2014-04-10 13:44:56 6D6DECD8D8C36C82743E552F4F1E1D37 58458 ----a-w- C:\Users\JEF\Downloads\Monster\minecraft\mods\iChunUtil2.4.0.zip 2014-04-10 13:44:56 21AA1DAFC9DDA624BC8786CBE943241E 46693 ----a-w- C:\Users\JEF\Downloads\Monster\minecraft\mods\HopperDuctsMod1.2.2.zip 2014-04-10 13:44:56 10E51D365F9AA8281776799BDBFDD164 873265 ----a-w- C:\Users\JEF\Downloads\Monster\minecraft\mods\GeoStrata 1.6 v18.zip 2014-04-10 13:44:55 711FD193BDAA8B9CADAA5DD0A8FEA474 986473 ----a-w- C:\Users\JEF\Downloads\Monster\minecraft\mods\extrautils-1.0.3a.zip 2014-04-10 13:44:54 64A9F0FA95F416FB284AABC7EB23A827 157282 ----a-w- C:\Users\JEF\Downloads\Monster\minecraft\mods\ExpandedRedstone 1.6 v18.zip 2014-04-10 13:44:53 E2BED275489FFA7741EE247A11DBF142 1194610 ----a-w- C:\Users\JEF\Downloads\Monster\minecraft\mods\ComputerCraft1.58.zip 2014-04-10 13:44:53 D4EE9074EA08C55570AE5DEC5962BE07 813159 ----a-w- C:\Users\JEF\Downloads\Monster\minecraft\mods\EngineersToolbox-1.1.8.1.zip 2014-04-10 13:44:53 D0F4EA50F36BA82FC867C5122C3C07FE 300994 ----a-w- C:\Users\JEF\Downloads\Monster\minecraft\mods\1.6.4 DamageIndicatorsv2.9.2.3.zip 2014-04-10 13:44:53 CD7736872DF8AF0FB2625BE67D1968BE 1303763 ----a-w- C:\Users\JEF\Downloads\Monster\minecraft\mods\BiblioCraft[v1.5.5].zip 2014-04-10 13:44:53 B4171A695CBBDDA3ACA2F8617B88468A 352097 ----a-w- C:\Users\JEF\Downloads\Monster\minecraft\mods\BiblioWoods[BiomesOPlenty][v1.3].zip 2014-04-10 13:44:53 957B8A4255318EA4BFAD3AA26E770F40 563205 ----a-w- C:\Users\JEF\Downloads\Monster\minecraft\mods\BiblioWoods[Forestry][v1.3].zip 2014-04-10 13:44:53 779B3EC32E2108C6B0DC6521C07ACFAB 92787 ----a-w- C:\Users\JEF\Downloads\Monster\minecraft\mods\DyeTrees 1.6 v18.zip 2014-04-10 13:44:53 56104CDA2DA42307E57EA7A906FCBFEF 1064832 ----a-w- C:\Users\JEF\Downloads\Monster\minecraft\mods\DragonAPI 1.6 v18b.zip 2014-04-10 13:44:53 4C4AC773B820E0683CCB348B3F97ABA4 166549 ----a-w- C:\Users\JEF\Downloads\Monster\minecraft\mods\BiblioWoods[Highlands][v1.1].zip 2014-04-10 13:44:53 3C6EEFB070D5310DA42DAB30DD14B8C9 391439 ----a-w- C:\Users\JEF\Downloads\Monster\minecraft\mods\BiblioWoods[Natura][v1.1].zip 2014-04-10 13:44:53 2F882B88D381BAA87D6113391E2A1F97 7222936 ----a-w- C:\Users\JEF\Downloads\Monster\minecraft\mods\CraftHeraldry 1.0.3.zip 2014-04-10 13:44:53 1CFA3792C51555239C6CD4AA056F5A73 54326 ----a-w- C:\Users\JEF\Downloads\Monster\minecraft\mods\compactsolars-universal-1.6.4-4.4.19.278.zip 2014-04-10 13:44:53 0226EAF325F52CE207304DA0CD624BC3 287788 ----a-w- C:\Users\JEF\Downloads\Monster\minecraft\mods\EmasherResource-1.2.3.3.zip ==== Startup Registry Enabled ====================== [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun" [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun" [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce] "mctadmin"="C:\Windows\System32\mctadmin.exe" [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce] "mctadmin"="C:\Windows\System32\mctadmin.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "AVG_UI"="C:\Program Files (x86)\AVG\AVG2013\avgui.exe /TRAYONLY" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"="C:\\PROGRA~2\\SearchProtect\\SearchProtect\\bin\\SPVC32Loader.dll C:\\PROGRA~3\\Wincert\\WIN32C~1.DLL C:\\PROGRA~2\\IMESHA~1\\MediaBar\\Datamngr\\datamngr.dll C:\\PROGRA~2\\IMESHA~1\\MediaBar\\Datamngr\\IEBHO.dll " ==== Startup Registry Disabled x64 ====================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Adobe ARM] "key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="Adobe ARM" "hkey"="HKLM" "command"="\"C:\\Program Files (x86)\\Common Files\\Adobe\\ARM\\1.0\\AdobeARM.exe\"" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Adobe Reader Speed Launcher] "key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="Adobe Reader Speed Launcher" "hkey"="HKLM" "command"="\"C:\\Program Files (x86)\\Adobe\\Reader 10.0\\Reader\\Reader_sl.exe\"" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Apoint] "command"="C:\\Program Files\\Apoint\\Apoint.exe" "hkey"="HKLM" "item"="Apoint" "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\AthBtTray] "command"="\"C:\\Program Files (x86)\\Bluetooth Suite\\AthBtTray.exe\"" "hkey"="HKLM" "item"="AthBtTray" "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\AtherosBtStack] "command"="\"C:\\Program Files (x86)\\Bluetooth Suite\\BtvStack.exe\"" "hkey"="HKLM" "item"="AtherosBtStack" "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\CanonQuickMenu] "command"="C:\\Program Files (x86)\\Canon\\Quick Menu\\CNQMMAIN.EXE /logon" "hkey"="HKLM" "item"="CanonQuickMenu" "key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\cAudioFilterAgent] "command"="C:\\Program Files\\Conexant\\cAudioFilterAgent\\cAudioFilterAgent64.exe" "hkey"="HKLM" "item"="cAudioFilterAgent" "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\HP Software Update] "command"="C:\\Program Files (x86)\\Hp\\HP Software Update\\HPWuSchd2.exe" "hkey"="HKLM" "item"="HP Software Update" "key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\IAStorIcon] "command"="C:\\Program Files (x86)\\Intel\\Intel(R) Rapid Storage Technology\\IAStorIcon.exe" "hkey"="HKLM" "item"="IAStorIcon" "key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ISBMgr.exe] "command"="\"C:\\Program Files (x86)\\Sony\\ISB Utility\\ISBMgr.exe\"" "hkey"="HKLM" "item"="ISBMgr.exe" "key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\KiesTrayAgent] "command"="C:\\Program Files (x86)\\Samsung\\Kies\\KiesTrayAgent.exe" "hkey"="HKLM" "item"="KiesTrayAgent" "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\SDTray] "command"="\"C:\\Program Files (x86)\\Spybot - Search & Destroy 2\\SDTray.exe\"" "hkey"="HKLM" "item"="SDTray" "key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\SunJavaUpdateSched] "command"="\"C:\\Program Files (x86)\\Common Files\\Java\\Java Update\\jusched.exe\"" "hkey"="HKLM" "item"="SunJavaUpdateSched" "key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run" ==== Task Scheduler Jobs ====================== C:\Windows\tasks\Adobe Flash Player Updater.job --a------ C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [12-03-2014 21:32] C:\Windows\tasks\HP Photo Creations Communicator.job --a------ C:\ProgramData\HP Photo Creations\Communicator.exe [14-04-2013 08:22] ==== Other Scheduled Tasks ====================== "C:\Windows\SysNative\tasks\Adobe Flash Player Updater" [C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe] "C:\Windows\SysNative\tasks\CCleanerSkipUAC" ["C:\Program Files\CCleaner\CCleaner.exe"] "C:\Windows\SysNative\tasks\CreateChoiceProcessTask" [C:\Windows\System32\browserchoice.exe] "C:\Windows\SysNative\tasks\HP Photo Creations Communicator" [C:\ProgramData\HP Photo Creations\Communicator.exe] "C:\Windows\SysNative\tasks\HPCustParticipation HP Photosmart 5510 series" ["C:\Program Files\HP\HP Photosmart 5510 series\Bin\HPCustPartic.exe"] "C:\Windows\SysNative\tasks\SidebarExecute" [C:\Program Files\Windows Sidebar\sidebar.exe] "C:\Windows\SysNative\tasks\User_Feed_Synchronization-{5C497AA6-8DA4-4F51-9231-255D2BE41896}" [C:\Windows\system32\msfeedssync.exe] "C:\Windows\SysNative\tasks\User_Feed_Synchronization-{7AC4C5E4-FE2A-46C0-9EEF-7BB8909091ED}" [C:\Windows\system32\msfeedssync.exe] "C:\Windows\SysNative\tasks\{391704D7-67C7-4342-A33B-C0C10C757813}" ["c:\program files (x86)\google\chrome\application\chrome.exe"] "C:\Windows\SysNative\tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask" [%systemroot%\system32\sc.exe start osppsvc] "C:\Windows\SysNative\tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates" ["C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe"] "C:\Windows\SysNative\tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization" ["C:\Program Files (x86)\Spybot - Search & Destroy 2\SDImmunize.exe"] "C:\Windows\SysNative\tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system" ["C:\Program Files (x86)\Spybot - Search & Destroy 2\SDScan.exe"] "C:\Windows\SysNative\tasks\Sony Corporation\VAIO Care\VAIO Care" ["%ProgramFiles%\Sony\VAIO Care\VCsystray.exe"] "C:\Windows\SysNative\tasks\Sony Corporation\VAIO Care\VCOneClick" ["%ProgramFiles%\Sony\VAIO Care\VCOneClick.exe"] "C:\Windows\SysNative\tasks\Sony Corporation\VAIO Gate\StartExecuteProxy" ["%programfiles%\Sony\VAIO Gate\ExecutionProxy.exe"] "C:\Windows\SysNative\tasks\Sony Corporation\VAIO Gate\VAIO Gate" [C:\Program Files\Sony\VAIO Gate\VAIO Gate.exe] "C:\Windows\SysNative\tasks\Sony Corporation\VAIO Gate\VAIO Gate Restart" ["%ProgramFiles%\Sony\VAIO Gate\VAIO Gate.exe"] "C:\Windows\SysNative\tasks\Sony Corporation\VAIO Improvement\VAIOImprovementUploader" [C:\Program Files\Sony\VAIO Improvement\viuploader.exe] "C:\Windows\SysNative\tasks\Sony Corporation\VAIO Improvement Validation\VAIO Improvement Validation" [C:\Program Files\Sony\VAIO Improvement Validation\viv.exe] "C:\Windows\SysNative\tasks\Sony Corporation\VAIO Smart Network\VSN Logon Start" [C:\Program Files\Sony\VAIO Smart Network\VSNClient] "C:\Windows\SysNative\tasks\Sony Corporation\VAIO Update\Launch Application" [C:\Program Files\SONY\VAIO Update\ShellExeProxy.exe] "C:\Windows\SysNative\tasks\Sony Corporation\VAIO Update\VAIO Update" ["C:\Program Files\Sony\VAIO Update\VAIOUpdt.exe"] "C:\Windows\SysNative\tasks\Sony Corporation\VAIO Update\VAIO Update Self Repair" [C:\Program Files\Sony\VAIO Update\VUSR.exe] ==== Firefox Extensions Registry ====================== [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions] "quickprint@hp.com"="C:\Program Files (x86)\Hewlett-Packard\SmartPrint\QPExtension" [26-01-2011 15:27] ==== Firefox Extensions ====================== AppDir: C:\Program Files (x86)\Mozilla Firefox - Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} - Skype Click to Call - %AppDir%\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi ==== Firefox Plugins ====================== Profilepath: C:\Users\JEF\AppData\Roaming\Mozilla\Firefox\Profiles\3mu83j4a.default F6D12679B9112358AC705A1308156F59 - C:\Users\JEF\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll - Unity Player 95812430959AE88CDD0301AB3A71913B - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_77.dll - Shockwave Flash 18CF51689186AEB9D1D149AEB0E92D03 - C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL - Microsoft Office 2013 053E986A84F5EE271D38896B8079157D - C:\Windows\SysWOW64\npDeployJava1.dll - Java Deployment Toolkit 7.0.110.21 472DAEA6EEE84240DEA132C95C57EB68 - C:\ProgramData\Visan\plugins\npRLSecurePluginLayer.dll - RocketLife Secure Plug-In Layer 15E298B5EC5B89C5994A59863969D9FF - C:\Windows\SysWOW64\npmproxy.dll - Microsoft® Windows® Operating System ==== Chrome Look ====================== HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions cpcidiiiodpbjdkbhldlebfbnidpgaih - C:\Users\JEF\AppData\Local\CRE\cpcidiiiodpbjdkbhldlebfbnidpgaih.crx[] efceifepimncccpgehonijdpjigknafn - C:\Users\JEF\AppData\Local\CRE\efceifepimncccpgehonijdpjigknafn.crx[] kiplfnciaokpcennlkldkdaeaaomamof - C:\Users\JEF\AppData\Local\Torch\Plugins\TorchPlugin.crx[18-04-2013 07:16] lifbcibllhkdhoafpjfnlhfpfgnpldfl - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx[03-03-2014 09:53] omgjkafaoidbgamjoklhaiiciahohkbh - C:\Program Files (x86)\tuvaro\tuvaro\1.8.17.3\tuvaro.crx[] HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\Extensions cpcidiiiodpbjdkbhldlebfbnidpgaih - C:\Users\JEF\AppData\Local\CRE\cpcidiiiodpbjdkbhldlebfbnidpgaih.crx[] efceifepimncccpgehonijdpjigknafn - C:\Users\JEF\AppData\Local\CRE\efceifepimncccpgehonijdpjigknafn.crx[] nikpibnbobmbdbheedjfogjlikpgpnhp - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\DVDVideoSoftBrowserExtension.crx[] FLV Runner B2 - JEF\AppData\Local\Google\Chrome\User Data\Default\Extensions\cpcidiiiodpbjdkbhldlebfbnidpgaih FLV Runner B - JEF\AppData\Local\Google\Chrome\User Data\Default\Extensions\efceifepimncccpgehonijdpjigknafn Torch Share - JEF\AppData\Local\Google\Chrome\User Data\Default\Extensions\kiplfnciaokpcennlkldkdaeaaomamof Skype Click to Call - JEF\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl Google Wallet - JEF\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda Battlefield Play4Free - JEF\AppData\Local\Google\Chrome\User Data\Default\Extensions\oiokahphinmbmakkehgelkmpolmnbkdh Tuvaro Chrome Toolbar - JEF\AppData\Local\Google\Chrome\User Data\Default\Extensions\omgjkafaoidbgamjoklhaiiciahohkbh Ask Toolbar - JEF\AppData\Local\Torch\User Data\Default\Extensions\aaaalejpmnocmhmlbmlkjemekckoagne Google Drive - JEF\AppData\Local\Torch\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf YouTube - JEF\AppData\Local\Torch\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo DropToS - JEF\AppData\Local\Torch\User Data\Default\Extensions\cipmepknanmbbaneimacddfemfbfgpgo Google Search - JEF\AppData\Local\Torch\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf FLV Runner B - JEF\AppData\Local\Torch\User Data\Default\Extensions\efceifepimncccpgehonijdpjigknafn avast WebRep - JEF\AppData\Local\Torch\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda Torch Helper - JEF\AppData\Local\Torch\User Data\Default\Extensions\lecpjhggilhbceadobnggaagnpfpafhg Skype Click to Call - JEF\AppData\Local\Torch\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl Torch Music - JEF\AppData\Local\Torch\User Data\Default\Extensions\ohimbkoaphfnmekmfppijeblmkncneed Gmail - JEF\AppData\Local\Torch\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia ==== Chrome Fix ====================== C:\Users\JEF\AppData\Local\Google\Chrome\User Data\Default\Extensions\cpcidiiiodpbjdkbhldlebfbnidpgaih deleted successfully C:\Users\JEF\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_cpcidiiiodpbjdkbhldlebfbnidpgaih_0.localstorage deleted successfully C:\Users\JEF\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_cpcidiiiodpbjdkbhldlebfbnidpgaih_0 deleted successfully C:\Users\JEF\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\cpcidiiiodpbjdkbhldlebfbnidpgaih deleted successfully C:\Users\JEF\AppData\Local\Google\Chrome\User Data\Default\Extensions\efceifepimncccpgehonijdpjigknafn deleted successfully C:\Users\JEF\AppData\Local\Torch\User Data\Default\Extensions\efceifepimncccpgehonijdpjigknafn deleted successfully C:\Users\JEF\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_efceifepimncccpgehonijdpjigknafn_0.localstorage deleted successfully C:\Users\JEF\AppData\Local\Torch\User Data\Default\Local Storage\chrome-extension_efceifepimncccpgehonijdpjigknafn_0.localstorage deleted successfully C:\Users\JEF\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_efceifepimncccpgehonijdpjigknafn_0 deleted successfully C:\Users\JEF\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\efceifepimncccpgehonijdpjigknafn deleted successfully C:\Users\JEF\AppData\Local\Torch\User Data\Default\databases\chrome-extension_efceifepimncccpgehonijdpjigknafn_0 deleted successfully C:\Users\JEF\AppData\Local\Torch\User Data\Default\Local Extension Settings\efceifepimncccpgehonijdpjigknafn deleted successfully C:\Users\JEF\AppData\Local\Google\Chrome\User Data\Default\Extensions\omgjkafaoidbgamjoklhaiiciahohkbh deleted successfully C:\Users\JEF\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_omgjkafaoidbgamjoklhaiiciahohkbh_0.localstorage deleted successfully C:\Users\JEF\AppData\Local\Torch\User Data\Default\Extensions\aaaalejpmnocmhmlbmlkjemekckoagne deleted successfully ==== Set IE to Default ====================== Old Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://search.conduit.com?SearchSource=10&ctid=CT2269050&SSPV=&UP=SP133A575C-76A3-4980-97ED-B06E20442214" "Search Page"="http://www.google.com" "Default_Page_URL"="http://vaioportal.sony.eu" "Search Bar"="http://www.google.com/ie" "Default_Search_URL"="http://www.google.com/ie" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl] @="http://www.google.com/search?q=%s" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AboutURLs] "Tabs"="http://tuvaro.com/ws/?source=99ec39d5&tbp=homepage&toolbarid=base&u=d029e195000000000000b639e5c541a3" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\AboutURLs] "Tabs"="http://tuvaro.com/ws/?source=99ec39d5&tbp=homepage&toolbarid=base&u=d029e195000000000000b639e5c541a3" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search] "SearchAssistant"="http://www.google.com/ie" "Default_Search_URL"="http://www.google.com/ie" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes] "DefaultScope"="{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}] not found New Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896" "Search Bar"="http://go.microsoft.com/fwlink/?LinkId=54896" "Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896" "Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157" "Start Page"="http://www.google.com" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl] "(Default)"="http://search.msn.com/results.asp?q=%s" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AboutURLs] "Tabs"="res://ieframe.dll/tabswelcome.htm" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\AboutURLs] "Tabs"="res://ieframe.dll/tabswelcome.htm" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search] "Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896" "SearchAssistant"="http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes] "DefaultScope"="{6A1806CD-94D4-4689-BA73-E35EA1EA9990}" ==== All HKCU SearchScopes ====================== HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes {0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC" {46F304EF-9229-427E-8514-7853718175E4} eBay Url="http://rover.ebay.com/rover/1/1346-81661-16445-14/4?mpre=http://shop.ebay.nl/?oemInLn=ieSrch-Q311&_nkw={searchTerms}" {6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}" {CA50D9FA-A4F1-4D08-925F-7005B5795A42} Zinio Url="http://services.zinio.com/search?s={searchTerms}&rf=sonyslices" {FEFD42D2-0100-4D7A-9DE5-BC0296F51428} Google Url="http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8" ==== Deleting Registry Keys ====================== HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\547B38670606DF14AA57B0BB83F3AE4D deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\cpcidiiiodpbjdkbhldlebfbnidpgaih deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\efceifepimncccpgehonijdpjigknafn deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\omgjkafaoidbgamjoklhaiiciahohkbh deleted successfully HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\Extensions\cpcidiiiodpbjdkbhldlebfbnidpgaih deleted successfully HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\Extensions\efceifepimncccpgehonijdpjigknafn deleted successfully HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp deleted successfully HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Mobogenie deleted successfully HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\SearchProtect deleted successfully HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{7683B745-6060-41FD-AA75-0BBB383FEAD4} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\547B38670606DF14AA57B0BB83F3AE4D deleted successfully ==== HijackThis Entries ====================== F2 - REG:system.ini: UserInit=userinit.exe O2 - BHO: Canon Easy-WebPrint EX BHO - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll O2 - BHO: IESpeakDoc - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll O3 - Toolbar: Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll O4 - HKLM\..\Run: [AVG_UI] "C:\Program Files (x86)\AVG\AVG2013\avgui.exe" /TRAYONLY O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE') O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200 O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\Program Files\Microsoft Office 15\Root\Office15\EXCEL.EXE/3000 O8 - Extra context menu item: Se&nd to OneNote - res://C:\Program Files\Microsoft Office 15\Root\Office15\ONBttnIE.dll/105 O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra button: HP Smart Print - {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files (x86)\Hewlett-Packard\SmartPrint\smartprintsetup.exe O9 - Extra 'Tools' menuitem: SmartPrint - {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files (x86)\Hewlett-Packard\SmartPrint\smartprintsetup.exe O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIE.dll O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIE.dll O9 - Extra button: (no name) - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll O9 - Extra 'Tools' menuitem: Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIELinkedNotes.dll O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIELinkedNotes.dll O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics O16 - DPF: {1ABA5FAC-1417-422B-BA82-45C35E2C908B} (20-20 3D Viewer for IKEA) - http://kitchenplanner.ikea.com/be/Core/Player/2020PlayerAX_IKEA_Win32.cab O16 - DPF: {6E718D87-6909-4FCE-92D4-EDCB2F725727} (Navigram Control) - http://navigram.com/engine/v1140/Navigram.cab O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll O20 - AppInit_DLLs: C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC32Loader.dll C:\PROGRA~3\Wincert\WIN32C~1.DLL C:\PROGRA~2\IMESHA~1\MediaBar\Datamngr\datamngr.dll C:\PROGRA~2\IMESHA~1\MediaBar\Datamngr\IEBHO.dll O20 - Winlogon Notify: SDWinLogon - SDWinLogon.dll (file missing) O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing) O23 - Service: Atheros Bt&Wlan Coex Agent - Atheros - C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe O23 - Service: AtherosSvc - Atheros Commnucations - C:\Program Files (x86)\Bluetooth Suite\adminservice.exe O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe O23 - Service: Bing Bar Update Service (BBSvc) - Unknown owner - C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE (file missing) O23 - Service: DCDhcpService - Atheros Communication Inc. - C:\Program Files\Sony\VAIO Smart Network\WFDA\DCDhcpService.exe O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing) O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing) O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: HWDeviceService64.exe - Unknown owner - C:\ProgramData\DatacardService\HWDeviceService64.exe O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe O23 - Service: IconMan_R - Realsil Microelectronics Inc. - C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing) O23 - Service: Canon Inkjet Printer/Scanner/Fax Extended Survey Program (IJPLMSVC) - Unknown owner - C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe O23 - Service: lxdn_device - Unknown owner - C:\Windows\system32\lxdncoms.exe (file missing) O23 - Service: Mobistar Internet Everywhere. OUC (Mobistar Internet Everywhere. RunOuc) - Unknown owner - C:\Program Files (x86)\Mobistar Internet Everywhere\UpdateDog\ouc.exe O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing) O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: NVIDIA Driver Helper Service (NVSvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing) O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing) O23 - Service: VAIO Care Performance Service (SampleCollector) - Sony Corporation - C:\Program Files\Sony\VAIO Care\VCPerfService.exe O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: Spybot-S&D 2 Scanner Service (SDScannerService) - Safer-Networking Ltd. - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe O23 - Service: Spybot-S&D 2 Updating Service (SDUpdateService) - Safer-Networking Ltd. - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe O23 - Service: Spybot-S&D 2 Security Center Service (SDWSCService) - Safer-Networking Ltd. - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe O23 - Service: SeaPort - Unknown owner - C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE (file missing) O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing) O23 - Service: VAIO Content Importer (SOHCImp) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHCImp.exe O23 - Service: VAIO Device Searcher (SOHDs) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDs.exe O23 - Service: VAIO Entertainment Common Service (SpfService) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\SPF\SpfService64.exe O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing) O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing) O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe O23 - Service: CamMonitor (uCamMonitor) - ArcSoft, Inc. - C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing) O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files (x86)\Sony\VAIO Event Service\VESMgr.exe O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: VAIO Content Folder Watcher (VCFw) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe O23 - Service: VAIO Content Metadata Intelligent Analyzing Manager (VcmIAlzMgr) - Sony Corporation - C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe O23 - Service: VAIO Content Metadata Intelligent Network Service Manager (VcmINSMgr) - Sony Corporation - C:\Program Files\Sony\VCM Intelligent Network Service Manager\VcmINSMgr.exe O23 - Service: VAIO Content Metadata XML Interface (VcmXmlIfHelper) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper64.exe O23 - Service: VCService - Sony Corporation - C:\Program Files\Sony\VAIO Care\VCService.exe O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing) O23 - Service: VSNService - Sony Corporation - C:\Program Files\Sony\VAIO Smart Network\VSNService.exe O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing) O23 - Service: VUAgent - Sony Corporation - C:\Program Files\Sony\VAIO Update\VUAgent.exe O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing) O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing) O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing) O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing) ==== Empty IE Cache ====================== C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\JEF\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\JEF\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully ==== Empty FireFox Cache ====================== C:\Users\JEF\AppData\Local\Mozilla\Firefox\Profiles\3mu83j4a.default\Cache emptied successfully ==== Empty Chrome Cache ====================== C:\Users\JEF\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully C:\Users\JEF\AppData\Local\Torch\User Data\Default\Cache emptied successfully ==== Empty All Flash Cache ====================== Flash Cache Emptied Successfully ==== Empty All Java Cache ====================== Java Cache cleared successfully ==== C:\zoek_backup content ====================== C:\zoek_backup (files=11022 folders=2130 855027764 bytes) ==== Empty Temp Folders ====================== C:\Users\Default\AppData\Local\Temp emptied successfully C:\Users\Default User\AppData\Local\Temp emptied successfully C:\Users\JEF\AppData\Local\Temp will be emptied at reboot C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp will be emptied at reboot C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully C:\Windows\Temp will be emptied at reboot ==== After Reboot ====================== ==== Empty Temp Folders ====================== C:\Windows\Temp successfully emptied C:\Users\JEF\AppData\Local\Temp successfully emptied ==== Empty Recycle Bin ====================== C:\$RECYCLE.BIN successfully emptied ==== Deleting Files / Folders ====================== "C:\Program Files (x86)\Microsoft\BingBar" not found "C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp\Low" not deleted ==== EOF on do 17-04-2014 at 11:10:24,72 ======================