Zoek.exe v5.0.0.0 Updated 27-09-2014 Tool run by Riekie on za 27-09-2014 at 23:58:58,59. Microsoft Windows 8.1 6.3.9600 x64 Running in: Normal Mode Internet Access Detected Launched: C:\Users\Riekie\Favorites\Downloads\zoek.exe [Scan all users] [Script inserted] ==== System Restore Info ====================== 28-9-2014 00:02:06 Zoek.exe System Restore Point Created Succesfully. ==== Empty Folders Check ====================== C:\Program Files\AVAST Software C:\PROGRA~3\Babylon C:\PROGRA~3\{01BD4FC9-2F86-4706-A62E-774BB7E9D308} C:\Users\Riekie\AppData\Roaming\AVAST Software ==== Deleting CLSID Registry Keys ====================== HKEY_CLASSES_ROOT\CLSID\{8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA} deleted successfully HKEY_CLASSES_ROOT\CLSID\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA} deleted successfully ==== Deleting CLSID Registry Values ====================== HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{318A227B-5E9F-45BD-8999-7F8F10CA4CF5} deleted successfully HKEY_LOCAL_MACHINE\software\Wow6432Node\mozilla\Firefox\extensions\wrc@avast.com deleted successfully ==== Deleting Services ====================== ==== Deleting Files \ Folders ====================== C:\PROGRA~3\{01BD4FC9-2F86-4706-A62E-774BB7E9D308} deleted C:\Users\Riekie\AppData\Roaming\Babylon deleted C:\PROGRA~3\Babylon deleted C:\Users\Riekie\AppData\Local\Babylon deleted ==== Files Recently Created / Modified ====================== ====== C:\WINDOWS ==== 2014-09-15 13:00:37 ACDBE1ED38167C8B01B8F63161BB2CEA 2374784 ----a-w- C:\WINDOWS\explorer.exe ====== C:\Users\Riekie\AppData\Local\Temp ==== 2014-09-26 15:01:52 67F1A8EC327EAE5821BABA596674EEB4 158008 ----a-w- C:\Users\Riekie\AppData\Local\Temp\TUUUninstallHelper.exe ====== Java Cache ===== ====== C:\WINDOWS\SysWOW64 ===== 2014-09-17 12:36:40 14B4AC47D6A5450BD07B5DD165DED069 25400 ----a-w- C:\WINDOWS\SysWOW64\authuitu.dll 2014-09-15 20:11:19 CA573004E12C7D5F474D3614F5532074 706016 ----a-w- C:\WINDOWS\SysWOW64\FlashPlayerApp.exe 2014-09-15 20:11:19 0F945C84360FA65F1B074DB471730E34 105440 ----a-w- C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl 2014-09-15 13:00:39 195822ACCDAA2B4815DD01BAFC335595 2084520 ----a-w- C:\WINDOWS\SysWOW64\explorer.exe 2014-09-15 12:59:33 A1EE5C4A020DB9A8DB216C660C3FBDBE 11818496 ----a-w- C:\WINDOWS\SysWOW64\twinui.dll 2014-09-15 12:57:30 C0281344E7702939DCE4A17734269E58 1038336 ----a-w- C:\WINDOWS\SysWOW64\actxprxy.dll 2014-09-15 12:57:30 1E4CD5DB4F61DF2A9053C8B9A46B4013 50176 ----a-w- C:\WINDOWS\SysWOW64\UXInit.dll 2014-09-15 12:55:37 F6570EFB5DD5CFC33A0C9D3B4C05069E 2318336 ----a-w- C:\WINDOWS\SysWOW64\authui.dll 2014-09-15 12:55:29 02E324E880F6E54187A2B3C9F53DD70E 12730880 ----a-w- C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll 2014-09-15 12:55:26 7E4A478662336EE2AF81C97345A407B6 18760328 ----a-w- C:\WINDOWS\SysWOW64\shell32.dll 2014-09-15 12:55:17 2CDBF4B60E89CD711476FAB1EB9A4999 5777408 ----a-w- C:\WINDOWS\SysWOW64\mstscax.dll 2014-09-15 12:55:00 495B4CA2AF924CE5C08BBC9D5E7E1103 2145472 ----a-w- C:\WINDOWS\SysWOW64\mfcore.dll 2014-09-15 12:54:59 AA3E2CEECFCD89D49FF902ECAD197946 2071552 ----a-w- C:\WINDOWS\SysWOW64\d3d10warp.dll 2014-09-15 12:54:45 69567319D077611FFF5A07BDCDF2A400 889344 ----a-w- C:\WINDOWS\SysWOW64\Windows.Media.dll 2014-09-15 12:54:45 5EE87C7E41A2BFF787FD5B8C5BA91EAF 674512 ----a-w- C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll 2014-09-15 12:54:43 B1D05869BF218949BDC5F695D3A8A7EB 5833216 ----a-w- C:\WINDOWS\SysWOW64\Windows.UI.Search.dll 2014-09-15 12:54:42 B393F30C63DCD1A0D6977A8E27A42A57 707536 ----a-w- C:\WINDOWS\SysWOW64\mfplat.dll 2014-09-15 12:54:39 E011C6CA6921FAC88F8B163C68E554BF 2410976 ----a-w- C:\WINDOWS\SysWOW64\WMVDECOD.DLL 2014-09-15 12:54:32 D32E7F10D61EFF5A26FB806934FB1088 1029632 ----a-w- C:\WINDOWS\SysWOW64\mispace.dll 2014-09-15 12:54:31 D39BD0DB9D91A4376F759282B2C276AE 1057792 ----a-w- C:\WINDOWS\SysWOW64\printui.dll 2014-09-15 12:54:31 0C666352A0F9C61AB07019D3928463ED 391000 ----a-w- C:\WINDOWS\SysWOW64\netcfgx.dll 2014-09-15 12:54:29 0120A5300040B9A1E459A03B364A74D5 1741824 ----a-w- C:\WINDOWS\SysWOW64\SRH.dll 2014-09-15 12:54:24 190228E527C47A96D9B865F07BF2EC19 889856 ----a-w- C:\WINDOWS\SysWOW64\aclui.dll 2014-09-15 12:54:23 3EAE3411A4A492C253A88534209E3045 355800 ----a-w- C:\WINDOWS\SysWOW64\mfreadwrite.dll 2014-09-15 12:54:23 3362D78214C5B0A5CAE9E5C1692FA12B 474112 ----a-w- C:\WINDOWS\SysWOW64\AppxPackaging.dll 2014-09-15 12:54:22 86A8EEFADBDDA52474456818D76DFAAA 302080 ----a-w- C:\WINDOWS\SysWOW64\wlanmsm.dll 2014-09-15 12:54:20 427A26A303BBF3736B054244EAFFAA4D 439296 ----a-w- C:\WINDOWS\SysWOW64\Windows.Devices.Bluetooth.dll 2014-09-15 12:54:18 F7A00AA3EA30F2F923C1F8A0DE76A113 180720 ----a-w- C:\WINDOWS\SysWOW64\mftranscode.dll 2014-09-15 12:54:18 9D75171689317D82FBF8B155FCF34AE8 371712 ----a-w- C:\WINDOWS\SysWOW64\winspool.drv 2014-09-15 12:54:18 3C120DEE84D42246A17A917B2B934A36 513544 ----a-w- C:\WINDOWS\SysWOW64\locale.nls 2014-09-15 12:54:17 FB970EC73EAB710FE1F529C139E258A0 477200 ----a-w- C:\WINDOWS\SysWOW64\SHCore.dll 2014-09-15 12:54:11 6ADEF3CCE9788849FA7F8D28A85B2833 540672 ----a-w- C:\WINDOWS\SysWOW64\comdlg32.dll 2014-09-15 12:54:08 42A350B81E0E9A427D7366E1E8BFBADC 198656 ----a-w- C:\WINDOWS\SysWOW64\WebClnt.dll 2014-09-15 12:54:07 05B976CBCB4ADE4D3F4E75DAD196EECD 313856 ----a-w- C:\WINDOWS\SysWOW64\clusapi.dll 2014-09-15 12:54:05 ACB131E8AB530C71841FEA38AE6E6707 328704 ----a-w- C:\WINDOWS\SysWOW64\puiobj.dll 2014-09-15 12:54:04 95719EC346E3A9FDD87662BE886EB200 1817088 ----a-w- C:\WINDOWS\SysWOW64\Display.dll 2014-09-15 12:54:04 7BB5166433C5319CED9E8D05A0C5F7E8 230400 ----a-w- C:\WINDOWS\SysWOW64\wlanapi.dll 2014-09-15 12:54:03 FEC1F6C1F496944BC40D995957D971CF 1404416 ----a-w- C:\WINDOWS\SysWOW64\storagewmi.dll 2014-09-15 12:54:02 19C5844B56BCA187625D2CFA9A7C1144 127544 ----a-w- C:\WINDOWS\SysWOW64\winmmbase.dll 2014-09-15 12:54:01 8A5A7AB46513F9FA75E7223471084645 667136 ----a-w- C:\WINDOWS\SysWOW64\wuapi.dll 2014-09-15 12:54:01 0F3DF44347B0051D30B23EED12973D8C 210944 ----a-w- C:\WINDOWS\SysWOW64\wisp.dll 2014-09-15 12:53:58 F19F4DF5361132D5E19FBE1A0DCDC80B 335680 ----a-w- C:\WINDOWS\SysWOW64\bcryptprimitives.dll 2014-09-15 12:53:57 704AA3D6466B2070D321C63C99368448 95232 ----a-w- C:\WINDOWS\SysWOW64\AppxSip.dll 2014-09-15 12:53:56 8FC068ACF45786301D04CED5B58A13E3 1319936 ----a-w- C:\WINDOWS\SysWOW64\wsecedit.dll 2014-09-15 12:53:55 A0E20B50D66FDF786BC2324499F7C482 195584 ----a-w- C:\WINDOWS\SysWOW64\prnntfy.dll 2014-09-15 12:53:54 E5FB6044A36E74484DA958AC17FA9504 1290752 ----a-w- C:\WINDOWS\SysWOW64\XpsPrint.dll 2014-09-15 12:53:54 21A13082B44A898B8DCC54972B2B5C31 128568 ----a-w- C:\WINDOWS\SysWOW64\winmm.dll 2014-09-15 12:53:53 558838A9A51259F3E76030E3E997A72A 162816 ----a-w- C:\WINDOWS\SysWOW64\puiapi.dll 2014-09-15 12:53:52 E1F38BF986C7285AB13FB369243A41E0 448000 ----a-w- C:\WINDOWS\SysWOW64\VAN.dll 2014-09-15 12:53:52 D9ABDEC0BDCD1FE7391EF756A2A9107B 180208 ----a-w- C:\WINDOWS\SysWOW64\SndVol.exe 2014-09-15 12:53:52 2F6410A7641BE1196DC423025F208285 98048 ----a-w- C:\WINDOWS\SysWOW64\dwmapi.dll 2014-09-15 12:53:51 BEE3C4EC1F92C62E4CF018EAEB8074E1 756224 ----a-w- C:\WINDOWS\SysWOW64\WSShared.dll 2014-09-15 12:53:49 1FA2D34A17E366C269FBE94DE06B177F 855552 ----a-w- C:\WINDOWS\SysWOW64\rdvidcrl.dll 2014-09-15 12:53:48 DA5AD8EA1331015BCC2FCFB1B7EE4EBC 168960 ----a-w- C:\WINDOWS\SysWOW64\iasnap.dll 2014-09-15 12:53:47 FC36740153F03C81ADA5B5EEF22C8064 1048064 ----a-w- C:\WINDOWS\SysWOW64\gpedit.dll 2014-09-15 12:53:47 EBA5466233255ADAF7D5501F0CC2B9CF 189016 ----a-w- C:\WINDOWS\SysWOW64\rsaenh.dll 2014-09-15 12:53:45 1CD80290AEB1DA851B6AA9B9822F25F2 779264 ----a-w- C:\WINDOWS\SysWOW64\osk.exe 2014-09-15 12:53:44 CB587DCB837D0367B43584855BD22F25 432128 ----a-w- C:\WINDOWS\SysWOW64\Windows.Networking.dll 2014-09-15 12:53:44 0836AC3FEF8E7380D1973E6DB14E31A7 459264 ----a-w- C:\WINDOWS\SysWOW64\SettingSync.dll 2014-09-15 12:53:43 710A55B8443155F1FF09E07C2E44D79D 200192 ----a-w- C:\WINDOWS\SysWOW64\DafPrintProvider.dll 2014-09-15 12:53:41 F7CA5639A235A1E2071500B4D1FCC6F8 51200 ----a-w- C:\WINDOWS\SysWOW64\wshbth.dll 2014-09-15 12:53:40 14D03A4F5F0AFCDB93CAFB68B77ACDB6 288768 ----a-w- C:\WINDOWS\SysWOW64\stobject.dll 2014-09-15 12:53:39 F1FCD3780D71FD21EAA2A42D3A924B1F 832512 ----a-w- C:\WINDOWS\SysWOW64\ActionCenter.dll 2014-09-15 12:53:38 FE166ADB02C1E146005789C17E065143 8192 ----a-w- C:\WINDOWS\SysWOW64\KBDRUM.DLL 2014-09-15 12:53:38 DA84B73474C3D02B453E6FAC0F38DBFB 26112 ----a-w- C:\WINDOWS\SysWOW64\wups.dll 2014-09-15 12:53:37 8A073508726DE4A69ED702A7A6082808 1351168 ----a-w- C:\WINDOWS\SysWOW64\GdiPlus.dll 2014-09-15 12:53:37 5232DEDED1A958814344D564F6C9C632 344576 ----a-w- C:\WINDOWS\SysWOW64\schannel.dll 2014-09-15 12:53:36 A39251FAE3189E1AE1F0DF0884D37E2A 1361408 ----a-w- C:\WINDOWS\SysWOW64\user32.dll 2014-09-15 12:53:36 0A6ABB521CDCE96D3A50939CF7964E24 206336 ----a-w- C:\WINDOWS\SysWOW64\powercfg.cpl 2014-09-15 12:53:35 FB38126A24BDC4912C175C4C430E911C 7168 ----a-w- C:\WINDOWS\SysWOW64\KBDRU1.DLL 2014-09-15 12:53:35 A40516F4443996DC92350D6890546E4A 7168 ----a-w- C:\WINDOWS\SysWOW64\KBDYAK.DLL 2014-09-15 12:53:35 44AABDB92C816F112E054FC3523B51E8 7168 ----a-w- C:\WINDOWS\SysWOW64\KBDBASH.DLL 2014-09-15 12:53:35 35D1AA379B4C2873F1DD62EDCA740C19 6656 ----a-w- C:\WINDOWS\SysWOW64\KBDRU.DLL 2014-09-15 12:53:29 C5D013B0C8F019F950B7E7451A57034E 318976 ----a-w- C:\WINDOWS\SysWOW64\certcli.dll 2014-09-15 12:53:29 594CEF2E9CD8A5BB8310B3844614C127 7168 ----a-w- C:\WINDOWS\SysWOW64\KBDTAT.DLL 2014-09-15 12:53:28 7D6731C5BA01769612A3EDC42A7C931B 79872 ----a-w- C:\WINDOWS\SysWOW64\BluetoothApis.dll 2014-09-15 12:53:26 CA16D3794D44C57CBFBE0CE5530FFED8 80896 ----a-w- C:\WINDOWS\SysWOW64\wudriver.dll 2014-09-15 12:53:25 DB46A1A84AEC3A7F0FBA4E20320F3159 7168 ----a-w- C:\WINDOWS\SysWOW64\KBDTT102.DLL 2014-09-15 11:46:33 B8F28AAC003060E3B125D2447CFC19E2 164864 ----a-w- C:\WINDOWS\SysWOW64\msrating.dll 2014-09-15 11:46:31 6A06EB11F1E5BDAA795DAE7838F9FE20 43008 ----a-w- C:\WINDOWS\SysWOW64\jsproxy.dll 2014-09-15 11:46:22 B5B3334F177CED627C2D7FE38235B6B1 2724864 ----a-w- C:\WINDOWS\SysWOW64\mshtml.tlb 2014-09-15 11:46:10 260D6B421E5551E8BA75D16B5CA90D9A 51200 ----a-w- C:\WINDOWS\SysWOW64\ieetwproxystub.dll 2014-09-15 11:46:08 7D6B20C69CC8EECB8F31D4FAF913BBE8 112128 ----a-w- C:\WINDOWS\SysWOW64\ieUnatt.exe 2014-09-15 11:46:07 D9F5B424C307B195E16A9B0A21E53BCC 61952 ----a-w- C:\WINDOWS\SysWOW64\iesetup.dll 2014-09-15 11:46:07 0E7B7C9F483300F9FF97C6A1E4BC4F57 32768 ----a-w- C:\WINDOWS\SysWOW64\iernonce.dll 2014-09-15 11:45:16 1E2AEB0238F0FE156FC1E4EE918446DD 61952 ----a-w- C:\WINDOWS\SysWOW64\MshtmlDac.dll 2014-09-15 11:45:12 B9361205DC3168E724E6288F64D0D867 69632 ----a-w- C:\WINDOWS\SysWOW64\mshtmled.dll 2014-09-15 11:45:09 1C9DF9ABA72C6F6ED0AAAD9AC3F0DAC5 454656 ----a-w- C:\WINDOWS\SysWOW64\vbscript.dll 2014-09-15 11:45:04 332E39115D7AE6071357E453574FCD48 365056 ----a-w- C:\WINDOWS\SysWOW64\dxtmsft.dll 2014-09-15 11:45:03 089A1B20B83F147184D28E8633DC0F5E 243200 ----a-w- C:\WINDOWS\SysWOW64\dxtrans.dll 2014-09-15 11:45:01 734FB412C293001F7777DEF89BC510BF 603136 ----a-w- C:\WINDOWS\SysWOW64\msfeeds.dll 2014-09-15 11:45:01 6A89CC35530F7021B91571D2C2DF7009 312320 ----a-w- C:\WINDOWS\SysWOW64\iedkcs32.dll 2014-09-15 11:44:59 96C9E7D834583F5F48CC0390F7755CE1 678400 ----a-w- C:\WINDOWS\SysWOW64\ieapfltr.dll 2014-09-15 11:44:59 4E9D7F3948E0B1DB2F861A0C9BA186AB 597504 ----a-w- C:\WINDOWS\SysWOW64\jscript9diag.dll 2014-09-15 11:44:59 2BFB1103B7D2B45A094B0600CDD775F3 60416 ----a-w- C:\WINDOWS\SysWOW64\JavaScriptCollectionAgent.dll 2014-09-15 11:44:47 A98F492B4C63CA5E11DAAEB36A0CEFCE 2185728 ----a-w- C:\WINDOWS\SysWOW64\iertutil.dll 2014-09-15 11:44:47 1A03F9B1D9F0493B18B1E648F4F82D4F 1812992 ----a-w- C:\WINDOWS\SysWOW64\wininet.dll 2014-09-15 11:44:46 6DBE009D0DECBD8F1F170366332BE432 1190400 ----a-w- C:\WINDOWS\SysWOW64\urlmon.dll 2014-09-15 11:44:45 26E85EDDE755D489A20CC67C4DAAD8BC 2014208 ----a-w- C:\WINDOWS\SysWOW64\inetcpl.cpl 2014-09-15 11:44:41 7E1AB823D5F57E18392A2C6BC7466B07 11769856 ----a-w- C:\WINDOWS\SysWOW64\ieframe.dll 2014-09-15 11:44:39 FA5275F6BE4D2615B754F06E7CF228DB 17455104 ----a-w- C:\WINDOWS\SysWOW64\mshtml.dll 2014-09-15 11:44:37 6D6E5210CA43AAC67082C69A8BA53705 4232704 ----a-w- C:\WINDOWS\SysWOW64\jscript9.dll 2014-09-15 11:34:51 4C48253C6A21CCEBA071B58A5CDF17C1 875688 ----a-w- C:\WINDOWS\SysWOW64\msvcr120_clr0400.dll ====== C:\WINDOWS\SysWOW64\drivers ===== ====== C:\WINDOWS\Sysnative ===== 2014-09-17 12:36:42 15769709C5496E36CE5C0D217142B2E8 40248 ----a-w- C:\WINDOWS\Sysnative\TURegOpt.exe 2014-09-17 12:36:41 D197381CEAFCAF5541081DAE00D27FE4 29496 ----a-w- C:\WINDOWS\Sysnative\authuitu.dll 2014-09-15 13:00:46 E09BF40AA766B183F0F385C96B37D9E5 299520 ----a-w- C:\WINDOWS\Sysnative\WSDMon.dll 2014-09-15 13:00:45 DA947D89F64B72A40F678AAAE76F7564 205824 ----a-w- C:\WINDOWS\Sysnative\tcpmon.dll 2014-09-15 13:00:39 00CD1254837739E310505EBCB19F7971 796672 ----a-w- C:\WINDOWS\Sysnative\uDWM.dll 2014-09-15 13:00:33 91AEA2A8671DDDFA526604B2379867F3 13423104 ----a-w- C:\WINDOWS\Sysnative\twinui.dll 2014-09-15 12:57:30 A4EE37B24370FABA65EF64FF24B5539E 2860032 ----a-w- C:\WINDOWS\Sysnative\actxprxy.dll 2014-09-15 12:57:29 04AE20974DF91DC7B9075FC5A126B77C 68096 ----a-w- C:\WINDOWS\Sysnative\UXInit.dll 2014-09-15 12:55:41 49EEC8569BF200C95A38D00766AFB830 16874496 ----a-w- C:\WINDOWS\Sysnative\Windows.UI.Xaml.dll 2014-09-15 12:55:36 8AE5205957F635FCB7A7760D266F3493 2642944 ----a-w- C:\WINDOWS\Sysnative\authui.dll 2014-09-15 12:55:31 4190C13A849F5D35F0B0CA445E05045D 21266336 ----a-w- C:\WINDOWS\Sysnative\shell32.dll 2014-09-15 12:55:22 7832D9F9F97E536DE374585BE4EA2CD8 6649344 ----a-w- C:\WINDOWS\Sysnative\mstscax.dll 2014-09-15 12:55:19 057CE99444311A71F71188A89C4C3EDE 8652800 ----a-w- C:\WINDOWS\Sysnative\Windows.UI.Search.dll 2014-09-15 12:55:18 BB832E06EE4F5585C15C441FE953DFF5 7424320 ----a-w- C:\WINDOWS\Sysnative\ntoskrnl.exe 2014-09-15 12:55:16 CC59B18DEC31120F9957ABA55EC49FAC 2389504 ----a-w- C:\WINDOWS\Sysnative\d3d10warp.dll 2014-09-15 12:55:15 74637F054A1DA40DA7C0A939094AFED7 2696704 ----a-w- C:\WINDOWS\Sysnative\SettingsHandlers.dll 2014-09-15 12:55:03 AD3137A754F60D369C176EF4DD5084A0 2141920 ----a-w- C:\WINDOWS\Sysnative\mfcore.dll 2014-09-15 12:54:58 69DB09F0263C637DA8568D404842466A 1261056 ----a-w- C:\WINDOWS\Sysnative\gpsvc.dll 2014-09-15 12:54:57 3F5EF31C6AA204B099EE76497DF80A26 1532416 ----a-w- C:\WINDOWS\Sysnative\wlansvc.dll 2014-09-15 12:54:56 61BF52E9FFAB27A0B6D621BE26088373 1600000 ----a-w- C:\WINDOWS\Sysnative\workfolderssvc.dll 2014-09-15 12:54:52 11FA35E24D76F62BD3E64D43B12656EF 1231872 ----a-w- C:\WINDOWS\Sysnative\Windows.Media.dll 2014-09-15 12:54:49 1670A274ED1A815311BA33CD27B0D0E8 907776 ----a-w- C:\WINDOWS\Sysnative\iphlpsvc.dll 2014-09-15 12:54:46 7A136EFAB2E4DF9A897E0333C51B54B8 818624 ----a-w- C:\WINDOWS\Sysnative\mfmp4srcsnk.dll 2014-09-15 12:54:46 3EB052F70F739728F89E2AEE2652E8CA 1029632 ----a-w- C:\WINDOWS\Sysnative\localspl.dll 2014-09-15 12:54:43 8200B4C323229AA1F47C87EB37207E36 2574208 ----a-w- C:\WINDOWS\Sysnative\WMVDECOD.DLL 2014-09-15 12:54:42 C40DE04CE3A8905EB8048B5CE0951DF0 882136 ----a-w- C:\WINDOWS\Sysnative\mfplat.dll 2014-09-15 12:54:41 AEAD37FA03D6E90638D8A4DC30E50408 2050560 ----a-w- C:\WINDOWS\Sysnative\SRH.dll 2014-09-15 12:54:41 17E700D2F6671196D0512BF806BB6435 1182208 ----a-w- C:\WINDOWS\Sysnative\printui.dll 2014-09-15 12:54:40 D24002EB2F4A8A04897703067E81CC5D 3465216 ----a-w- C:\WINDOWS\Sysnative\wuaueng.dll 2014-09-15 12:54:37 0A3E1B697F6ACB7BC1C898DC14A96EC7 1287680 ----a-w- C:\WINDOWS\Sysnative\mispace.dll 2014-09-15 12:54:35 4301A4D673F1ACB195C4F30B306B70B9 1992192 ----a-w- C:\WINDOWS\Sysnative\XpsPrint.dll 2014-09-15 12:54:33 B2C26168E74EA51BF65518A309B08C19 770048 ----a-w- C:\WINDOWS\Sysnative\WorkfoldersControl.dll 2014-09-15 12:54:33 A9C015F01499761908DE61F172FAF65D 486744 ----a-w- C:\WINDOWS\Sysnative\netcfgx.dll 2014-09-15 12:54:32 0A7F97DE49DB63E01CBCA067F4DA7AB8 544768 ----a-w- C:\WINDOWS\Sysnative\AppxPackaging.dll 2014-09-15 12:54:30 A4CF0D2FF18BF8D128389AF26410FD8B 1018368 ----a-w- C:\WINDOWS\Sysnative\aclui.dll 2014-09-15 12:54:27 BF6897E960C08E9FDD41B80726C61C2F 371200 ----a-w- C:\WINDOWS\Sysnative\wlanmsm.dll 2014-09-15 12:54:27 793EACA6BAE9F481C2059BCB3743EB4A 324096 ----a-w- C:\WINDOWS\Sysnative\srvsvc.dll 2014-09-15 12:54:25 8DC2979BC54C585BA5A4C9E6FABCD1B4 360480 ----a-w- C:\WINDOWS\Sysnative\mfreadwrite.dll 2014-09-15 12:54:25 42FEA9E0BA9761D9E65A4F167D91515B 795136 ----a-w- C:\WINDOWS\Sysnative\spoolsv.exe 2014-09-15 12:54:22 79EFAEE6FBD8ABC066B944E1A7A605BB 645592 ----a-w- C:\WINDOWS\Sysnative\SHCore.dll 2014-09-15 12:54:20 01409F85BB9DB87E102B415EC91DD6C1 438272 ----a-w- C:\WINDOWS\Sysnative\puiobj.dll 2014-09-15 12:54:18 7740658736BD07FC121EACB3CA7C9194 2397184 ----a-w- C:\WINDOWS\Sysnative\storagewmi.dll 2014-09-15 12:54:18 3C120DEE84D42246A17A917B2B934A36 513544 ----a-w- C:\WINDOWS\Sysnative\locale.nls 2014-09-15 12:54:17 FF1CB6C5D9288DAAA0DADAD6B1E35085 205512 ----a-w- C:\WINDOWS\Sysnative\mftranscode.dll 2014-09-15 12:54:17 D0AD65EE089F735BF546ABFE28D192C0 621056 ----a-w- C:\WINDOWS\Sysnative\comdlg32.dll 2014-09-15 12:54:17 D01BA613D268DAD03DD32A0DC5FD24DF 287232 ----a-w- C:\WINDOWS\Sysnative\usbmon.dll 2014-09-15 12:54:17 8EE8CA953542A8E70A841C453BC15196 427008 ----a-w- C:\WINDOWS\Sysnative\clusapi.dll 2014-09-15 12:54:17 0FA02FD5BEF2B8FBA63B40746360E9C6 828416 ----a-w- C:\WINDOWS\Sysnative\wuapi.dll 2014-09-15 12:54:16 91B18D7A1702ED589E67C6C81052B955 226816 ----a-w- C:\WINDOWS\Sysnative\WebClnt.dll 2014-09-15 12:54:16 70696A95F26778CFCB106ECEAA40F4D9 1519560 ----a-w- C:\WINDOWS\Sysnative\winload.exe 2014-09-15 12:54:16 40CC457FB140B509B50F96DAD9D8F80B 1660048 ----a-w- C:\WINDOWS\Sysnative\winload.efi 2014-09-15 12:54:14 D249C3A58A4FCF755EF4C94F7047E015 449536 ----a-w- C:\WINDOWS\Sysnative\defragsvc.dll 2014-09-15 12:54:14 835261C17478103B73F4FFB8454AF849 268288 ----a-w- C:\WINDOWS\Sysnative\wisp.dll 2014-09-15 12:54:14 5B6B32E83E371739B13AA67E260DC5C4 487936 ----a-w- C:\WINDOWS\Sysnative\winspool.drv 2014-09-15 12:54:12 23F0DE75890E604B9DED5625EFA907FD 1417216 ----a-w- C:\WINDOWS\Sysnative\lsasrv.dll 2014-09-15 12:54:11 C80D4D7AF450F7CAD615FF1D7B40D7AD 1488008 ----a-w- C:\WINDOWS\Sysnative\winresume.efi 2014-09-15 12:54:11 3663F0BB881A16A689F33A21C1A3C76B 1356840 ----a-w- C:\WINDOWS\Sysnative\winresume.exe 2014-09-15 12:54:10 FE7E47BE6E0D9EF4F24D81381A829CEC 1463808 ----a-w- C:\WINDOWS\Sysnative\wsecedit.dll 2014-09-15 12:54:08 EF1F8B57323E5D3FC6A0A25F98F90DBC 220160 ----a-w- C:\WINDOWS\Sysnative\profsvc.dll 2014-09-15 12:54:07 A055D7D686F1CB5CBEDCFBB4C6DC9E2E 1519488 ----a-w- C:\WINDOWS\Sysnative\user32.dll 2014-09-15 12:54:06 9D50C0B29FB20DF0A8FD197B332894B7 160600 ----a-w- C:\WINDOWS\Sysnative\winmmbase.dll 2014-09-15 12:54:06 693CC2794DEFB8493ABFF68D509DACC4 127488 ----a-w- C:\WINDOWS\Sysnative\WiFiDisplay.dll 2014-09-15 12:54:06 618A19EB31ECA7B7F2AA0207BAF598A5 84480 ----a-w- C:\WINDOWS\Sysnative\wpdbusenum.dll 2014-09-15 12:54:05 EA10272605422080EE2FAB142A75120D 356864 ----a-w- C:\WINDOWS\Sysnative\conhost.exe 2014-09-15 12:54:05 D069B88549B986C15731AE79F8D6C258 3360768 ----a-w- C:\WINDOWS\Sysnative\rdpcorets.dll 2014-09-15 12:54:05 AE27E63B6A4AFCF4EBCCE8AC4A96C0EF 806400 ----a-w- C:\WINDOWS\Sysnative\win32spl.dll 2014-09-15 12:54:04 CD8CA57C36E596875865F451393C7C66 576512 ----a-w- C:\WINDOWS\Sysnative\SettingSync.dll 2014-09-15 12:54:04 1C683FB45C6CE0BB8A74BB0B1392599D 505344 ----a-w- C:\WINDOWS\Sysnative\VAN.dll 2014-09-15 12:54:04 0B1A9F6F9D2891C0F8783C0444D27DD0 1057280 ----a-w- C:\WINDOWS\Sysnative\rdvidcrl.dll 2014-09-15 12:54:03 F8A869262251B011A21DEC79AC1F3F5D 1844224 ----a-w- C:\WINDOWS\Sysnative\Display.dll 2014-09-15 12:54:03 D62B6C0A254EADB94C138600E6DB6048 388608 ----a-w- C:\WINDOWS\Sysnative\WUSettingsProvider.dll 2014-09-15 12:54:03 793DE7C6B82804D5973C43484F527849 117248 ----a-w- C:\WINDOWS\Sysnative\AppxSip.dll 2014-09-15 12:54:03 2C38FF9DE23A3BB335A95099622AB603 65536 ----a-w- C:\WINDOWS\Sysnative\WorkFoldersGPExt.dll 2014-09-15 12:54:02 9A3AF816758D144B097AE477D99F7D79 834560 ----a-w- C:\WINDOWS\Sysnative\osk.exe 2014-09-15 12:54:02 02FE7859AD2DEAD7E9E3C7BF5F484204 211216 ----a-w- C:\WINDOWS\Sysnative\SndVol.exe 2014-09-15 12:54:00 504DDEF8526CECAAD886D5AC5656DF1A 387896 ----a-w- C:\WINDOWS\Sysnative\bcryptprimitives.dll 2014-09-15 12:54:00 12C0733F955E15C3C37DD24C9C7D796A 263680 ----a-w- C:\WINDOWS\Sysnative\DafPrintProvider.dll 2014-09-15 12:53:59 83E7C4DA3BF4A21C3F809A506245CAEF 233888 ----a-w- C:\WINDOWS\Sysnative\mfps.dll 2014-09-15 12:53:58 CCC106273D4265A9091AA7B619DCC5DA 595456 ----a-w- C:\WINDOWS\Sysnative\Windows.Networking.dll 2014-09-15 12:53:58 9D43D7E80DBC2B733BB652CABD6BAC9C 116736 ----a-w- C:\WINDOWS\Sysnative\httpprxm.dll 2014-09-15 12:53:58 7DEAD28D8FB9BCAE4A153A57338315E7 123920 ----a-w- C:\WINDOWS\Sysnative\winmm.dll 2014-09-15 12:53:57 A6CB3CBF88DF671AC85FA9AABC33137F 125472 ----a-w- C:\WINDOWS\Sysnative\dwmapi.dll 2014-09-15 12:53:57 1922AAE64BCD761A0377F6981FC67736 721408 ----a-w- C:\WINDOWS\Sysnative\twinapi.dll 2014-09-15 12:53:56 20657ACF2AE5B2E25EEFC597A34AFDED 1705472 ----a-w- C:\WINDOWS\Sysnative\wucltux.dll 2014-09-15 12:53:56 1A5835F2E6B49A83F0AEAD17B4537AF7 1656832 ----a-w- C:\WINDOWS\Sysnative\GdiPlus.dll 2014-09-15 12:53:56 118A11C89FAD244A2B85DA7EDC3E9683 215552 ----a-w- C:\WINDOWS\Sysnative\prnntfy.dll 2014-09-15 12:53:56 0C9F6C826973FF777951FFB15F7A52B5 923136 ----a-w- C:\WINDOWS\Sysnative\WSShared.dll 2014-09-15 12:53:55 FD807B56AECFD89E4A46960C261D78BF 1089024 ----a-w- C:\WINDOWS\Sysnative\gpedit.dll 2014-09-15 12:53:55 97F24AEACAD9C9038BEC5B2BA1ADA94C 187392 ----a-w- C:\WINDOWS\Sysnative\WorkFoldersShell.dll 2014-09-15 12:53:54 A8732AFE4DB47114355ABB285ED776D2 187392 ----a-w- C:\WINDOWS\Sysnative\puiapi.dll 2014-09-15 12:53:53 572EBBCDBBA56736F4C0B5487AE7BFA5 220160 ----a-w- C:\WINDOWS\Sysnative\iasnap.dll 2014-09-15 12:53:52 CCD0DF268D9C9F5287B66565B4258FD6 59392 ----a-w- C:\WINDOWS\Sysnative\wups.dll 2014-09-15 12:53:52 85ED08FAD9D17EC76A02B5C4AEEDBB00 75776 ----a-w- C:\WINDOWS\Sysnative\adhsvc.dll 2014-09-15 12:53:50 28E8D340402C130427F2901004B7FA99 321536 ----a-w- C:\WINDOWS\Sysnative\stobject.dll 2014-09-15 12:53:50 0AB5085FE30F8F6942A2126BCFC1A606 263400 ----a-w- C:\WINDOWS\Sysnative\SystemSettingsAdminFlows.exe 2014-09-15 12:53:49 6ECFFE49AA43A74DC15701EFE6355621 92160 ----a-w- C:\WINDOWS\Sysnative\dab.dll 2014-09-15 12:53:49 31C2E53FE0C039C1BF0F15154D8596E7 53248 ----a-w- C:\WINDOWS\Sysnative\AppxSysprep.dll 2014-09-15 12:53:49 2B1C2CB5C97962C521CD806F0C86D2FE 102912 ----a-w- C:\WINDOWS\Sysnative\wcmcsp.dll 2014-09-15 12:53:48 FA86C3F979EF9CCCCED109B05DEBDD46 432640 ----a-w- C:\WINDOWS\Sysnative\wwanconn.dll 2014-09-15 12:53:48 3AB9868E0E78AD9CD501B83D7C293125 54752 ----a-w- C:\WINDOWS\Sysnative\wuauclt.exe 2014-09-15 12:53:47 53F4FC66B94804BBF2016922CD826891 878592 ----a-w- C:\WINDOWS\Sysnative\ActionCenter.dll 2014-09-15 12:53:46 B540693968BCA57F595A7B08DB4B46C3 216368 ----a-w- C:\WINDOWS\Sysnative\rsaenh.dll 2014-09-15 12:53:46 AEDF08DDF4EA929FEDBC0A1CCF01F287 296960 ----a-w- C:\WINDOWS\Sysnative\wlanapi.dll 2014-09-15 12:53:45 2E80E960F1D376A502E9811B20621F2A 427520 ----a-w- C:\WINDOWS\Sysnative\schannel.dll 2014-09-15 12:53:45 1E01725D557B5325E8C99F712E7D4A7E 50688 ----a-w- C:\WINDOWS\Sysnative\wups2.dll 2014-09-15 12:53:44 69AF7212845FFCD0AA1F0FC5D51FB809 63488 ----a-w- C:\WINDOWS\Sysnative\wshbth.dll 2014-09-15 12:53:42 A7762A36F92E57E41B0356EF5C672473 659968 ----a-w- C:\WINDOWS\Sysnative\Windows.Devices.Bluetooth.dll 2014-09-15 12:53:42 809B36AF48D7BC9B37E1522889F6160F 1126912 ----a-w- C:\WINDOWS\Sysnative\SearchFolder.dll 2014-09-15 12:53:42 3A80675FF8524B09817000B6A2E35B7A 18432 ----a-w- C:\WINDOWS\Sysnative\wlansvcpal.dll 2014-09-15 12:53:42 041A999E4FF9A7CDBE67357751881FB8 134144 ----a-w- C:\WINDOWS\Sysnative\browser.dll 2014-09-15 12:53:39 EB2BB6EC7AEBBDD04FAB8E8D6FCEDAA6 183808 ----a-w- C:\WINDOWS\Sysnative\Defrag.exe 2014-09-15 12:53:39 CB9CEAB473897BE1E8C827D4F4EB1311 207360 ----a-w- C:\WINDOWS\Sysnative\powercfg.cpl 2014-09-15 12:53:38 2067AF0531ACD5D28BD49DB30DF109CE 8192 ----a-w- C:\WINDOWS\Sysnative\KBDRUM.DLL 2014-09-15 12:53:36 6A9650BDC13F1A770F20E7B99D29EE3D 6656 ----a-w- C:\WINDOWS\Sysnative\KBDRU.DLL 2014-09-15 12:53:36 454A0735E836FBC31C064FED6C120B46 7168 ----a-w- C:\WINDOWS\Sysnative\KBDRU1.DLL 2014-09-15 12:53:36 3429360674DA1E70F638924A6D5985CC 7168 ----a-w- C:\WINDOWS\Sysnative\KBDYAK.DLL 2014-09-15 12:53:36 0AC5A816A01D0115588D4B997842780E 7168 ----a-w- C:\WINDOWS\Sysnative\KBDBASH.DLL 2014-09-15 12:53:35 A4DE7868879498A4E4CBB12788FAA3E8 105472 ----a-w- C:\WINDOWS\Sysnative\BluetoothApis.dll 2014-09-15 12:53:30 1A2486F88B4F68FCCE7E01DF34869929 436224 ----a-w- C:\WINDOWS\Sysnative\certcli.dll 2014-09-15 12:53:29 997E5E28492F02036E5C7BA6DB66ABDC 7168 ----a-w- C:\WINDOWS\Sysnative\KBDTAT.DLL 2014-09-15 12:53:29 933C63C9003379F56BA4AF4149440FC8 226304 ----a-w- C:\WINDOWS\Sysnative\SndVolSSO.dll 2014-09-15 12:53:29 6317C9DB4282CEAA3BAB131BC3839B2A 308736 ----a-w- C:\WINDOWS\Sysnative\compstui.dll 2014-09-15 12:53:29 4F6203CBBEFB9FBFA859246682849A24 1144320 ----a-w- C:\WINDOWS\Sysnative\wwanmm.dll 2014-09-15 12:53:28 A9CE2C192B4C7E7151011A56DB2C7B40 132608 ----a-w- C:\WINDOWS\Sysnative\rdpudd.dll 2014-09-15 12:53:27 A5141DD172927F04732F5B6BFBE49C15 443904 ----a-w- C:\WINDOWS\Sysnative\wlansec.dll 2014-09-15 12:53:26 D8683834163E00E252CAC57BB6025036 93696 ----a-w- C:\WINDOWS\Sysnative\wudriver.dll 2014-09-15 12:53:26 B279922BCFD0E178068B159D85C5CDBE 2100736 ----a-w- C:\WINDOWS\Sysnative\SystemSettingsAdminFlowUI.dll 2014-09-15 12:53:25 68270DE9415C8F8139242D38417B49BE 7168 ----a-w- C:\WINDOWS\Sysnative\KBDTT102.DLL 2014-09-15 12:53:25 575CB39AD4DC2F4C92341F2D377DCAE0 387391 ----a-w- C:\WINDOWS\Sysnative\ApnDatabase.xml 2014-09-15 11:46:14 94C59DD02BC7EA0E421055B9946CA861 2724864 ----a-w- C:\WINDOWS\Sysnative\mshtml.tlb 2014-09-15 11:46:11 FCFAEDF0AA1A78A1875FDB798598408B 48640 ----a-w- C:\WINDOWS\Sysnative\ieetwproxystub.dll 2014-09-15 11:46:11 E77092C38028EB0A5C461B3436E0A6D5 4096 ----a-w- C:\WINDOWS\Sysnative\ieetwcollectorres.dll 2014-09-15 11:46:11 E129D34089E70215B65EA611F802FA9A 111616 ----a-w- C:\WINDOWS\Sysnative\ieetwcollector.exe 2014-09-15 11:46:09 338415F2E9A188875B6E43B5269620B0 139264 ----a-w- C:\WINDOWS\Sysnative\ieUnatt.exe 2014-09-15 11:46:06 FD08F8BA2437A85F500EFFE3FD3158A6 33792 ----a-w- C:\WINDOWS\Sysnative\iernonce.dll 2014-09-15 11:46:05 C1E2C16D58D76323800C3EE5E2C5095A 66048 ----a-w- C:\WINDOWS\Sysnative\iesetup.dll 2014-09-15 11:45:59 1D1D7F52EC84294859642A4309FE648E 195584 ----a-w- C:\WINDOWS\Sysnative\msrating.dll 2014-09-15 11:45:57 790FD40601502C5FE8213D4F335DA0BD 51200 ----a-w- C:\WINDOWS\Sysnative\jsproxy.dll 2014-09-15 11:45:16 343A53C71F8CE8DE172880F210BF50CB 83968 ----a-w- C:\WINDOWS\Sysnative\MshtmlDac.dll 2014-09-15 11:45:12 E7852ACED4314BF475DE89C388247CAD 85504 ----a-w- C:\WINDOWS\Sysnative\mshtmled.dll 2014-09-15 11:45:10 550531ED60E7AD5CA02EDB0FAFA6280B 72704 ----a-w- C:\WINDOWS\Sysnative\JavaScriptCollectionAgent.dll 2014-09-15 11:45:10 0B52D185504457310D42B5413783D6DC 758272 ----a-w- C:\WINDOWS\Sysnative\jscript9diag.dll 2014-09-15 11:45:09 19FB8104F320C31BB0E34D5A926ECD1C 547328 ----a-w- C:\WINDOWS\Sysnative\vbscript.dll 2014-09-15 11:45:04 910AAE6634F7C809E93EE0341C850180 289280 ----a-w- C:\WINDOWS\Sysnative\dxtrans.dll 2014-09-15 11:45:04 7F733479C6DC92B649B2B1298EE6D6B6 446464 ----a-w- C:\WINDOWS\Sysnative\dxtmsft.dll 2014-09-15 11:45:02 F519886D6075BFF0286793B3891E0675 727040 ----a-w- C:\WINDOWS\Sysnative\msfeeds.dll 2014-09-15 11:45:01 B2AA93A6FC3BB1EFBF25410DAA6BB1D2 359424 ----a-w- C:\WINDOWS\Sysnative\iedkcs32.dll 2014-09-15 11:45:01 1FA34F04CB4529000AD818268F059D3E 707072 ----a-w- C:\WINDOWS\Sysnative\ie4uinit.exe 2014-09-15 11:44:58 E86022F8AE3F9251459C744E175309F9 775168 ----a-w- C:\WINDOWS\Sysnative\ieapfltr.dll 2014-09-15 11:44:55 47942CCF5A5CD57AE1BB44F17725A912 23591424 ----a-w- C:\WINDOWS\Sysnative\mshtml.dll 2014-09-15 11:44:48 30C355249224173151874A7B86A8BB66 2310656 ----a-w- C:\WINDOWS\Sysnative\wininet.dll 2014-09-15 11:44:46 7F88F6790401199B2C9C932FD91965F9 2793984 ----a-w- C:\WINDOWS\Sysnative\iertutil.dll 2014-09-15 11:44:46 4C56EBB6A31E8323D3CBBC476C81B998 1447424 ----a-w- C:\WINDOWS\Sysnative\urlmon.dll 2014-09-15 11:44:45 4EBE88D6CC494B9BE3705B400562A587 2104832 ----a-w- C:\WINDOWS\Sysnative\inetcpl.cpl 2014-09-15 11:44:43 3EC77C4625862483BFCF4CEE1231EED7 13588480 ----a-w- C:\WINDOWS\Sysnative\ieframe.dll 2014-09-15 11:44:38 5107C9AEF01636FF8A04E8F28CF7C316 5833728 ----a-w- C:\WINDOWS\Sysnative\jscript9.dll 2014-09-15 11:36:00 D3AE5DB16EAF913860EC28654CE00E6B 1212928 ----a-w- C:\WINDOWS\Sysnative\schedsvc.dll 2014-09-15 11:34:50 8BB7548307EE6147137993A410D64387 869544 ----a-w- C:\WINDOWS\Sysnative\msvcr120_clr0400.dll ====== C:\WINDOWS\Sysnative\drivers ===== 2014-09-15 12:55:02 FEBAA7D782E30882FFF1CBCBBE8AD467 2515264 ----a-w- C:\WINDOWS\Sysnative\drivers\tcpip.sys 2014-09-15 12:54:44 6416E79A58A8FCC33A447A4DDDD3BF04 412160 ----a-w- C:\WINDOWS\Sysnative\drivers\srv.sys 2014-09-15 12:54:41 038C77D577900EE39410662478BB0D50 2009920 ----a-w- C:\WINDOWS\Sysnative\drivers\ntfs.sys 2014-09-15 12:54:38 5BED3AB69797C8786EF70AEA8C33748B 674816 ----a-w- C:\WINDOWS\Sysnative\drivers\srv2.sys 2014-09-15 12:54:36 77E1D08EF3BFB923F2EDC3FC8089E08E 475968 ----a-w- C:\WINDOWS\Sysnative\drivers\netio.sys 2014-09-15 12:54:33 97B9076611291AE4C4C107BC915BD026 1200640 -c--a-w- C:\WINDOWS\Sysnative\drivers\bthport.sys 2014-09-15 12:54:28 240C5C3793206725AA05665851E8C214 412992 -c--a-w- C:\WINDOWS\Sysnative\drivers\spaceport.sys 2014-09-15 12:54:23 FF78D053A05E5A394F4E3C1816CC65A8 143680 -c--a-w- C:\WINDOWS\Sysnative\drivers\usbccgp.sys 2014-09-15 12:54:21 64CA2B4A49A8EAF495E435623ECCE7DB 310080 -c--a-w- C:\WINDOWS\Sysnative\drivers\volsnap.sys 2014-09-15 12:54:16 65392F3F3F65E4C6CC82A0F4F8A0B051 468288 -c--a-w- C:\WINDOWS\Sysnative\drivers\USBHUB3.SYS 2014-09-15 12:54:09 D047CD668E6277FD80F0C613946F034C 246272 ----a-w- C:\WINDOWS\Sysnative\drivers\srvnet.sys 2014-09-15 12:54:08 26ACA481FAFEC59FE311D719E3027BBA 446976 ----a-w- C:\WINDOWS\Sysnative\drivers\nwifi.sys 2014-09-15 12:54:01 9C096BF5E10CA8BFA56F32522A89FAF1 79872 ----a-w- C:\WINDOWS\Sysnative\drivers\IPMIDrv.sys 2014-09-15 12:53:59 E4B4BE2D7750849C07589DA0B0AABA01 1118040 ----a-w- C:\WINDOWS\Sysnative\drivers\ndis.sys 2014-09-15 12:53:58 D4B7ED39C7900384D9E5C1283F1E7926 76800 -c--a-w- C:\WINDOWS\Sysnative\drivers\hdaudbus.sys 2014-09-15 12:53:58 C910E5D18958914A66F0E45689D0B40A 206848 ----a-w- C:\WINDOWS\Sysnative\drivers\mrxsmb20.sys 2014-09-15 12:53:58 B1AA3B19A2E596A59224F893E01A5A75 126464 ----a-w- C:\WINDOWS\Sysnative\drivers\NdisImPlatform.sys 2014-09-15 12:53:56 E0927EFA25D473367C3341B9F5969779 115712 ----a-w- C:\WINDOWS\Sysnative\drivers\bridge.sys 2014-09-15 12:53:51 91ED124E261EA8FAA1C0FFDF2A71B0C4 280384 -c--a-w- C:\WINDOWS\Sysnative\drivers\pci.sys 2014-09-15 12:53:51 1DD05F4857C2188744B9E864658949DD 295424 ----a-w- C:\WINDOWS\Sysnative\drivers\ks.sys 2014-09-15 12:53:30 25BB93167DEF270188072603F92A1EF5 118272 -c--a-w- C:\WINDOWS\Sysnative\drivers\bthpan.sys 2014-09-15 12:43:27 8DF1254093B5C354CE725EB6B9B0DE19 146752 ----a-w- C:\WINDOWS\Sysnative\drivers\msgpioclx.sys ====== C:\WINDOWS\Tasks ====== 2014-09-24 14:14:03 1E820B536DBBFD743262166B7467A301 3108 ----a-w- C:\WINDOWS\Sysnative\Tasks\{C9133731-DE17-41C6-AAF3-2840E72F77CC} 2014-09-18 11:47:13 E7169BF52C33D1B083F40E7EF64C22EE 2762 ----a-w- C:\WINDOWS\Sysnative\Tasks\TuneUpUtilities_Task_BkGndMaintenance2013 ====== C:\WINDOWS\Temp ====== ======= C:\Program Files ===== ======= C:\PROGRA~2 ===== 2014-09-24 14:16:10 -------- d-----w- C:\PROGRA~2\COMMON~1\Skype 2014-09-24 14:16:10 -------- d-----r- C:\PROGRA~2\Skype 2014-09-24 14:10:22 -------- d-----w- C:\PROGRA~2\SkypeWebPlugin ======= C: ===== ====== C:\Users\Riekie\AppData\Roaming ====== 2014-09-27 07:46:30 -------- d-----w- C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Avg2015 2014-09-27 07:39:32 -------- d-----w- C:\Users\Riekie\AppData\Local\Avg2015 2014-09-24 14:17:11 -------- d-----w- C:\Users\Riekie\AppData\Local\Skype 2014-09-24 14:17:04 -------- d-----w- C:\Users\Riekie\AppData\Roaming\Skype 2014-09-18 12:11:20 -------- d-s---w- C:\Users\Riekie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OpenOffice 4.1.1 2014-09-17 12:36:44 -------- d-----w- C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Avg ====== C:\Users\Riekie ====== 2014-09-24 14:16:10 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype 2014-09-24 14:13:59 -------- d-----w- C:\ProgramData\Skype 2014-09-18 12:13:04 -------- d-----w- C:\Users\Public\Documents\sun ====== C: exe-files == 2014-09-23 06:21:33 F9E4B109A9D327D1239E491E29578A2E 550584 ----a-w- C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonX86\Microsoft Shared\OFFICE15\MSOSQM.EXE 2014-09-23 06:21:28 F79A490D9614CA9B8FC23409AF817EBA 5624016 ----a-w- C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonX86\Microsoft Shared\OFFICE15\CMigrate.exe 2014-09-23 06:21:27 AD6502512DAB0512295F9051514343BB 474336 ----a-w- C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonX86\Microsoft Shared\DW\DWTRIG20.EXE 2014-09-23 06:21:27 13ACDC68FAD1BE0E6E44A47E0EB5C475 842440 ----a-w- C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonX86\Microsoft Shared\DW\DW20.EXE 2014-09-23 06:21:25 167E713975F87CFDC5F05D5ED08FBD85 7651536 ----a-w- C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE15\CMigrate.exe 2014-09-23 06:21:21 2ECE1C04DD7280A82A0EC1A259016B54 874160 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\protocolhandler.exe 2014-09-23 06:21:20 4BCE37BACBAB333187BB6E0F0B9F4C43 9597096 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\PDFREFLOW.EXE 2014-09-23 06:21:02 1FA58353814828F9B3D31CB01BFFCE6D 81648 ----a-w- C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonX86\Microsoft Shared\OFFICE15\CSISYNCCLIENT.EXE 2014-09-23 06:21:00 B9E8AE87F0DEDB2E6C164E4BFEA02E7C 39576 ----a-w- C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\AppSharingHookController64.exe 2014-09-23 06:21:00 A789DDA5192980D81DBB01D55811DEA9 49848 ----a-w- C:\Program Files\Microsoft Office 15\root\flattener\Flattener.exe 2014-09-23 06:20:48 54571FBCF53B33B8AD89C86FDFDF5CFA 449216 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\MSOSYNC.EXE 2014-09-23 06:20:45 F5D36DD4F4954883E1C3FF45FD2CA245 21931672 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\excelcnv.exe 2014-09-23 06:20:45 E2CD290381C86BE22C0628FBD17FE0C8 517360 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\IEContentService.exe 2014-09-23 06:20:44 BCDBD0DCD1A079CE468DA0E881F3C767 4522688 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\GRAPH.EXE 2014-09-23 06:20:44 8F2576BF4A07EDC6EB475ED0D9AF6A15 569584 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\ORGCHART.EXE 2014-09-23 06:20:39 5EFF8107B969FFED8FD43CF784E3041A 1090768 ----a-w- C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonX86\Microsoft Shared\OFFICE15\OLicenseHeartbeat.exe 2014-09-23 06:20:36 D679931089526AF06B9D15A8A44EB53F 228544 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\CLVIEW.EXE 2014-09-23 06:20:36 4DEEDF0559E2A5E8A3B32220975A490B 497848 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\MSOUC.EXE 2014-09-23 06:20:36 1B9CE92B611FFB9304405248D541A837 480984 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\SELFCERT.EXE 2014-09-23 06:20:35 98D3A7B6EC8360577B8E5FBD413FA713 153248 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\CNFNOT32.EXE 2014-09-23 06:20:35 4883FFDFC482CE29D50E34750C592C22 528576 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\VPREVIEW.EXE 2014-09-23 06:20:26 4E28F3BDCF66DEB0C3E9E2D6A8BBFBEE 18945704 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\OUTLOOK.EXE 2014-09-23 06:20:19 03DED553CB47ECF6C87A9DF0A17391EA 1762976 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\ONENOTE.EXE 2014-09-23 06:20:16 18605ECCA0701DBC114739A8E58E0626 15518888 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\MSACCESS.EXE 2014-09-23 06:19:49 B950312617FB5EE9DD30C6A9B3B6EADE 311552 ----a-w- C:\Program Files\Microsoft Office 15\root\client\AppVLP.exe 2014-09-23 06:19:49 8FF1A393FD0CF4E888C4EBC73AF4F252 590536 ----a-w- C:\Program Files\Microsoft Office 15\root\integration\Integrator.exe 2014-09-23 06:19:49 33DFE1A4E0072E6815D653AABC0A8444 124072 ----a-w- C:\Program Files\Microsoft Office 15\root\client\AppVDllSurrogate32.exe 2014-09-23 06:19:48 C419E73483ADA429BF4693D77CE49279 145056 ----a-w- C:\Program Files\Microsoft Office 15\root\client\AppVDllSurrogate64.exe 2014-09-23 06:19:36 3B3EBE7EE88DC7C3B35E6672F764EC37 10760352 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\MSPUB.EXE 2014-09-23 06:19:29 18B22B1B507B4ED6F4A0DBF68198D394 25705120 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\EXCEL.EXE 2014-09-23 06:18:37 80C830207A104F6C1BDE91D0D86D8685 195240 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\ONENOTEM.EXE 2014-09-23 06:16:59 1F081FC968D71544B5692178607FD682 991904 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\FIRSTRUN.EXE 2014-09-23 06:16:54 C5BF5684F342C194120B4587E125CC00 205472 ----a-w- C:\Program Files\Microsoft Office 15\ClientX64\AppVShNotify.exe 2014-09-23 06:16:54 8D8D475017ACA6960DBC150C1391B7B9 249000 ----a-w- C:\Program Files\Microsoft Office 15\ClientX64\mavinject32.exe 2014-09-23 06:16:04 EDAD3D6932E4CB7D92F19FEE0238C29D 2428088 ----a-w- C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe 2014-09-23 06:16:04 C5B220E9B4552D7C282CF605EAC5576E 867520 ----a-w- C:\Program Files\Microsoft Office 15\ClientX64\officec2rclient.exe 2014-09-23 06:16:04 55E59C8A534CAA8C86E5FE4B048E5777 849120 ----a-w- C:\Program Files\Microsoft Office 15\ClientX64\integratedoffice.exe 2014-09-23 06:16:03 19CE32F5C6F9437C8402E04E4B938C7E 1460896 ----a-w- C:\Program Files\Microsoft Office 15\ClientX64\appvcleaner.exe === C: other files == ==== Startup Registry Enabled ====================== [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "GarminExpressTrayApp"="C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe" [HKEY_USERS\S-1-5-21-2871391618-1465616402-3070090435-1001\Software\Microsoft\Windows\CurrentVersion\Run] "StartMenuX"="C:\Program Files\Start Menu X\StartMenuX.exe" "GarminExpressTrayApp"="C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe" "Skype"="C:\Program Files (x86)\Skype\Phone\Skype.exe /minimized /regrun" [HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run] "GarminExpressTrayApp"="C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Dolby Home Theater v4"="C:\Dolby PCEE4\pcee4.exe -autostart" "APSDaemon"="C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" "Adobe ARM"="C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" "AVG_UI"="C:\Program Files (x86)\AVG\AVG2014\avgui.exe /TRAYONLY" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "StartMenuX"="C:\Program Files\Start Menu X\StartMenuX.exe" "GarminExpressTrayApp"="C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe" "Skype"="C:\Program Files (x86)\Skype\Phone\Skype.exe /minimized /regrun" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] "BtvStack"="C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\BtvStack.exe" ==== Startup Registry Enabled x64 ====================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" "HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" "Persistence"="C:\WINDOWS\system32\igfxpers.exe" "Apoint"="C:\Program Files\Apoint2K\Apoint.exe" "RtHDVCpl"="C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s" "RtHDVBg_Dolby"="C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe /FORPCEE4 " "BtPreLoad"="C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\BtPreLoad.exe" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] "BtvStack"="C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\BtvStack.exe" ==== Startup Folders ====================== 2014-04-09 21:29:52 1133 ----a-w- C:\Users\Riekie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Verzenden naar OneNote.lnk ==== Task Scheduler Jobs ====================== C:\WINDOWS\tasks\Adobe Flash Player Updater.job --a-------- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [15-09-2014 12:43] C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job --a-------- [Undetermined Task] C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job --a-------- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [19-11-2013 15:29] ==== Other Scheduled Tasks ====================== "C:\WINDOWS\SysNative\tasks\Adobe Flash Player Updater" [C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe] "C:\WINDOWS\SysNative\tasks\Adobe-online actualiseringsprogramma" [C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe] "C:\WINDOWS\SysNative\tasks\ALU" [C:\Program Files (x86)\Acer\Live Updater\updater.exe] "C:\WINDOWS\SysNative\tasks\ALUAgent" [C:\Program Files (x86)\Acer\Live Updater\liveupdater_agent.exe] "C:\WINDOWS\SysNative\tasks\CCleanerSkipUAC" ["C:\Program Files\CCleaner\CCleaner.exe"] "C:\WINDOWS\SysNative\tasks\CreateChoiceProcessTask" [C:\Windows\BrowserChoice\browserchoice.exe] "C:\WINDOWS\SysNative\tasks\GarminUpdaterTask" [C:\Program Files (x86)\Garmin\Express Self Updater\ExpressSelfUpdater.exe] "C:\WINDOWS\SysNative\tasks\GoogleUpdateTaskMachineCore" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe] "C:\WINDOWS\SysNative\tasks\GoogleUpdateTaskMachineUA" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe] "C:\WINDOWS\SysNative\tasks\iuBrowserIEAgent" ["C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuBrowserIEAgent.exe"] "C:\WINDOWS\SysNative\tasks\iuEmailOutlookAgent" ["C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuEmailOutlookAgent.exe"] "C:\WINDOWS\SysNative\tasks\Power Management" ["C:\Program Files\Acer\Acer Power Management\ePowerTray.exe"] "C:\WINDOWS\SysNative\tasks\TuneUpUtilities_Task_BkGndMaintenance2013" [C:\Program Files (x86)\AVG\AVG PC TuneUp\OneClick.exe] "C:\WINDOWS\SysNative\tasks\{C9133731-DE17-41C6-AAF3-2840E72F77CC}" ["c:\program files (x86)\google\chrome\application\chrome.exe"] ==== Firefox Extensions ====================== ==== Firefox Plugins ====================== ==== Chromium Look ====================== HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions gomekmidlodglbbmalcneegieacbdmki - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx[] lifbcibllhkdhoafpjfnlhfpfgnpldfl - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx[14-07-2014 18:22] Google Docs - Riekie\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake Google Drive - Riekie\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf YouTube - Riekie\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo Google Search - Riekie\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf Skype Click to Call - Riekie\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl Google Wallet - Riekie\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda Gmail - Riekie\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia ==== Set IE to Default ====================== Old Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://acer13.msn.com/" New Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://acer13.msn.com/" ==== All HKCU SearchScopes ====================== HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes "DefaultScope"="{012E1000-F331-11DB-8314-0800200C9A66}" {012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}" {0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE11SR" {6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}" {8B08C8CE-F1C7-4E52-9C21-05986D1F1DC0} Google Url="http://www.google.nl/search?hl=nl&q={searchTerms}" {8C8BDECA-373C-43B4-B852-B148C64FFFF7} Bing Url="http://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MAARJS" ==== Reset Google Chrome ====================== C:\Users\Riekie\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully C:\Users\Riekie\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully ==== Deleting Registry Keys ====================== HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\gomekmidlodglbbmalcneegieacbdmki deleted successfully ==== Empty IE Cache ====================== C:\WINDOWS\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Riekie\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\Users\Riekie\AppData\Local\Microsoft\Windows\INetCache\Low\Content.IE5 emptied successfully C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\WINDOWS\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully ==== Empty FireFox Cache ====================== No FireFox Cache found ==== Empty Chrome Cache ====================== C:\Users\Riekie\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully ==== Empty All Flash Cache ====================== Flash Cache Emptied Successfully ==== Empty All Java Cache ====================== No Java Cache Found ==== C:\zoek_backup content ====================== C:\zoek_backup (files=3 folders=5 64983 bytes) ==== Empty Temp Folders ====================== C:\Users\Default\AppData\Local\Temp emptied successfully C:\Users\Default User\AppData\Local\Temp emptied successfully C:\Users\Riekie\AppData\Local\Temp will be emptied at reboot C:\WINDOWS\serviceprofiles\networkservice\AppData\Local\Temp will be emptied at reboot C:\WINDOWS\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully C:\WINDOWS\Temp will be emptied at reboot ==== After Reboot ====================== ==== Empty Temp Folders ====================== C:\WINDOWS\Temp successfully emptied C:\Users\Riekie\AppData\Local\Temp successfully emptied ==== Empty Recycle Bin ====================== C:\$RECYCLE.BIN successfully emptied ==== Deleting Files / Folders ====================== "C:\WINDOWS\serviceprofiles\networkservice\AppData\Local\Temp\Low" not deleted ==== EOF on zo 28-09-2014 at 1:08:12,14 ======================