Zoek.exe v5.0.0.0 Updated 19-10-2014 Tool run by Ronald on wo 22-10-2014 at 11:29:46,37. Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x86 Running in: Normal Mode Internet Access Detected Launched: C:\Users\Ronald\Downloads\zoek.exe [Scan all users] [Script inserted] ==== System Restore Info ====================== 22-10-2014 11:31:46 Zoek.exe System Restore Point Created Succesfully. ==== Empty Folders Check ====================== C:\Program Files\VideoLAN deleted successfully C:\PROGRA~2\Oracle deleted successfully C:\PROGRA~2\{6CDCEBFA-D5FA-4ED0-A11F-AC1F8BD76DF2} deleted successfully C:\PROGRA~2\{FE8D473A-6F06-4F99-B5F4-BED72B2A038C} deleted successfully ==== Files Recently Created / Modified ====================== ====== C:\Windows ==== 2014-09-30 10:58:12 8B88EBBB05A0E56B7DCC708498C02B3E 2616320 ----a-w- C:\Windows\explorer.exe 2014-09-28 11:58:35 BA3AFC9419A11D6C28E80ECD524F0380 308 ----a-w- C:\Windows\setup.iss 2014-09-28 11:02:06 E185BDA84E5F03F4E1D8DCA30E209277 1912 ----a-w- C:\Windows\epplauncher.mif 2014-09-28 10:22:47 E9BF58E95AF5E1D1BED4A84F092AECEB 1698408 ------r- C:\Windows\RtlExUpd.dll 2014-09-28 10:21:01 718FECF22BF4BD4FC05B79AA4BEC75D0 1769 ----a-w- C:\Windows\Language_trs.ini 2014-09-28 10:20:58 0552886AEB8554F1C234214B69AE19E4 28398 ----a-w- C:\Windows\Ascd_tmp.ini ====== C:\Users\Ronald\AppData\Local\Temp ==== 2014-10-17 12:48:02 51C40019D2417A27D0DEB3267839F64B 9170496 ----a-w- C:\Users\Ronald\AppData\Local\Temp\EPSON\Download\Resource\EWP12000.exe 2014-10-14 09:51:21 201C9FB4248C88E6BFCEC38810A06318 5806440 ----a-w- C:\Users\Ronald\AppData\Local\Temp\EPSON\Download\Resource\CESU4310.exe ====== Java Cache ===== ====== C:\Windows\system32 ===== 2014-10-16 22:50:35 1333DD61BA97EE3F9DF23A0D65A70AA0 230912 ----a-w- C:\Windows\System32\generaltel.dll 2014-10-16 22:50:34 975CB5016F5C5520607F6CA6768F161B 302592 ----a-w- C:\Windows\System32\aeinv.dll 2014-10-16 22:50:34 0F655F9B3EBB3E05698B8F905F48953C 396288 ----a-w- C:\Windows\System32\aepdu.dll 2014-10-16 22:50:33 348289FDF17FB4A1F23091F9463642D6 2379264 ----a-w- C:\Windows\System32\win32k.sys 2014-10-16 22:50:29 37C395C075E6FA66623C82DE50A8FAED 372736 ----a-w- C:\Windows\System32\rastls.dll 2014-10-16 22:50:28 DF59F2510EDABBF216FA837D5D964106 51200 ----a-w- C:\Windows\System32\ieetwproxystub.dll 2014-10-16 22:50:28 B74B348D13134D67B4F68ADDDC76A447 43008 ----a-w- C:\Windows\System32\jsproxy.dll 2014-10-16 22:50:28 97F2F82BF0B4AF86A85FFDD78DFDC87D 60416 ----a-w- C:\Windows\System32\JavaScriptCollectionAgent.dll 2014-10-16 22:50:28 8F390C7AA11DF00FC3EF86FA72A939D2 646144 ----a-w- C:\Windows\System32\MsSpellCheckingFacility.exe 2014-10-16 22:50:28 8C8B6144B47FE37724590CA832ED26CA 108032 ----a-w- C:\Windows\System32\ieetwcollector.exe 2014-10-16 22:50:27 DF4BA130BD41F29A894E026E456B8481 454656 ----a-w- C:\Windows\System32\vbscript.dll 2014-10-16 22:50:27 CEA291F4C62ECBE1565EC4B37D9AF088 4096 ----a-w- C:\Windows\System32\ieetwcollectorres.dll 2014-10-16 22:50:27 B5B1C277E46A5B0E2FC63E5FC5624CE5 365056 ----a-w- C:\Windows\System32\dxtmsft.dll 2014-10-16 22:50:27 AA103FEAD721863B86A1B1260948E662 112128 ----a-w- C:\Windows\System32\ieUnatt.exe 2014-10-16 22:50:27 7AE80F921027CF88CB9D0433088A3E55 1810944 ----a-w- C:\Windows\System32\wininet.dll 2014-10-16 22:50:26 410BECCA3354D471E45344F0754CC0E4 243200 ----a-w- C:\Windows\System32\dxtrans.dll 2014-10-16 22:50:26 201EAFA3F17BE4990999C28657212D8E 69632 ----a-w- C:\Windows\System32\mshtmled.dll 2014-10-16 22:50:26 158690737381C49120165A7F3F5D13EB 440320 ----a-w- C:\Windows\System32\ieui.dll 2014-10-16 22:50:25 8E8E6E7B4CC27B92F40F74E29C1F6290 1068032 ----a-w- C:\Windows\System32\mshtmlmedia.dll 2014-10-16 22:50:25 6D4DD5706C297234F457B9D9018C493F 61952 ----a-w- C:\Windows\System32\MshtmlDac.dll 2014-10-16 22:50:25 55A400FDB21D157E947A0EE65AEDB1B3 2187264 ----a-w- C:\Windows\System32\iertutil.dll 2014-10-16 22:50:24 D03EB7605435FE24ADE670661A932651 4201472 ----a-w- C:\Windows\System32\jscript9.dll 2014-10-16 22:50:24 BD66BA5A924DCC8392CFAEB67131A246 597504 ----a-w- C:\Windows\System32\jscript9diag.dll 2014-10-16 22:50:23 F91E55DA404B834648A3B0A2477C10DB 17484800 ----a-w- C:\Windows\System32\mshtml.dll 2014-10-16 22:50:22 FBE852643EDEB9D6D6502AFE6017CD64 678400 ----a-w- C:\Windows\System32\ieapfltr.dll 2014-10-16 22:50:22 D78C4DB153874DB7AC6AA6A03BE38B66 331448 ----a-w- C:\Windows\System32\iedkcs32.dll 2014-10-16 22:50:22 AF31CC5BAEB4916C0AF9AB062CFE8DA2 677888 ----a-w- C:\Windows\System32\ie4uinit.exe 2014-10-16 22:50:22 604C67F58747D6A333EA641BCCC2C842 32768 ----a-w- C:\Windows\System32\iernonce.dll 2014-10-16 22:50:22 3065FF6794A7FDC882F0DA8B6230AB6E 1190400 ----a-w- C:\Windows\System32\urlmon.dll 2014-10-16 22:50:21 B89F5D2B3D3BC730FAB93CFCD931742F 607744 ----a-w- C:\Windows\System32\msfeeds.dll 2014-10-16 22:50:21 835807E2AC0A8FA15B9A2EA80E2D5169 2017280 ----a-w- C:\Windows\System32\inetcpl.cpl 2014-10-16 22:50:21 58EC068116BCE16A94B1B2C429A35E41 2724864 ----a-w- C:\Windows\System32\mshtml.tlb 2014-10-16 22:50:20 EF94FA1F3D90520CCA4AE65D639A9E62 11807232 ----a-w- C:\Windows\System32\ieframe.dll 2014-10-16 22:50:20 8FAA1E45198C4ECEC691326B7F5E71C5 61952 ----a-w- C:\Windows\System32\iesetup.dll 2014-10-16 22:50:20 2409C41081D657A3FABE3659BB989AFB 164864 ----a-w- C:\Windows\System32\msrating.dll 2014-10-16 22:50:17 D5D5BBF6AA45D820BAA0BD1303B8AAF6 81560 ----a-w- C:\Windows\System32\mscories.dll 2014-10-16 22:50:17 A139A5E6B34F136405B030EA04595A20 156824 ----a-w- C:\Windows\System32\mscorier.dll 2014-10-16 22:50:17 8580484193CE0A0788830FBAB97CF13B 1131664 ----a-w- C:\Windows\System32\dfshim.dll 2014-10-16 22:50:15 06FC8A93A4FA1F42A3D1D06694F2B339 419992 ----a-w- C:\Windows\System32\locale.nls 2014-10-16 22:50:14 F1886C30C3E4A7C5513525CBA665AA31 6144 ----a-w- C:\Windows\System32\KBDTAT.DLL 2014-10-16 22:50:14 EB3D06A9EDFDFD12228AD7A9F24D15D6 5632 ----a-w- C:\Windows\System32\KBDRU.DLL 2014-10-16 22:50:14 40FFC65117C4AC69D33DEC6D567392FD 6144 ----a-w- C:\Windows\System32\KBDYAK.DLL 2014-10-16 22:50:14 33DB506498E0419CD50B144DE7CCFC75 6144 ----a-w- C:\Windows\System32\KBDBASH.DLL 2014-10-16 22:50:14 1235259E135F87BF4AE5864A818E1513 6144 ----a-w- C:\Windows\System32\KBDRU1.DLL 2014-10-16 22:50:12 3ABACF6D4EBEA5EF3014FEFA1D8FF5F8 3221504 ----a-w- C:\Windows\System32\mstscax.dll 2014-10-16 22:50:12 0DBD0B4D4766CADEB8C30242A0611395 1051136 ----a-w- C:\Windows\System32\mstsc.exe 2014-10-16 22:50:11 FD67683FBA9B2C4BB551780BD8846F64 157696 ----a-w- C:\Windows\System32\winsta.dll 2014-10-16 22:50:11 E05E31F7BF577228E27CFFCA5B54ABBD 523264 ----a-w- C:\Windows\System32\termsrv.dll 2014-10-16 22:50:11 DB1D6751689B4A7EE2439C64F2ADF1C9 17408 ----a-w- C:\Windows\System32\credssp.dll 2014-10-16 22:50:11 B4203FC65D4C0D7A0B7A02AFD13472BB 130048 ----a-w- C:\Windows\System32\rdpcorekmts.dll 2014-10-16 22:50:11 97896EE4254176CFDD9010B5B243B89F 131584 ----a-w- C:\Windows\System32\aaclient.dll 2014-10-16 22:50:11 13829161C1297F4170A5546430147BBD 65536 ----a-w- C:\Windows\System32\TSpkg.dll 2014-10-16 22:50:07 3888D02CE6413C2A06D903DE1C778BF5 2363904 ----a-w- C:\Windows\System32\msi.dll 2014-10-16 22:50:02 C120855C1133DF8FFD5E0C04A7E70B67 67072 ----a-w- C:\Windows\System32\packager.dll ====== C:\Windows\system32\drivers ===== 2014-10-16 22:50:11 CD9214A6AE17D188D17C3CF8CB9CC693 184320 ----a-w- C:\Windows\System32\drivers\rdpwd.sys 2014-10-16 22:50:11 6C5139E4283249518F7743D7043775B3 31232 ----a-w- C:\Windows\System32\drivers\tssecsrv.sys 2014-09-30 15:20:48 D41D8CD98F00B204E9800998ECF8427E 0 ---ha-w- C:\Windows\System32\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf 2014-09-30 10:58:39 F991AB9CC6B908DB552166768176896A 76288 ----a-w- C:\Windows\System32\drivers\USBSTOR.SYS 2014-09-30 10:58:39 D320BF87125326F996D4904FE24300FC 80256 ----a-w- C:\Windows\System32\drivers\amdsata.sys 2014-09-30 10:58:39 B3E25EE28883877076E0E1FF877D02E0 117120 ----a-w- C:\Windows\System32\drivers\nvraid.sys 2014-09-30 10:58:39 5CD5F9A5444E6CDCB0AC89BD62D8B76E 332160 ----a-w- C:\Windows\System32\drivers\iaStorV.sys 2014-09-30 10:58:39 46387FB17B086D16DEA267D5BE23A2F2 22400 ----a-w- C:\Windows\System32\drivers\amdxata.sys 2014-09-30 10:58:39 4380E59A170D88C4F1022EFF6719A8A4 143744 ----a-w- C:\Windows\System32\drivers\nvstor.sys 2014-09-28 15:46:34 867C301E8B790040AE9CF6486E8041DF 155136 ----a-w- C:\Windows\System32\drivers\WUDFRd.sys 2014-09-28 15:46:34 06E6F32C8D0A3F66D956F57B43A2E070 66560 ----a-w- C:\Windows\System32\drivers\WUDFPf.sys 2014-09-28 15:46:32 933222B19FF3E7EA5F65517EA1F7D57E 3 ----a-w- C:\Windows\System32\drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf 2014-09-28 15:44:02 7DAE5EBCC80E45D3253F4923DC424D05 19824 ----a-w- C:\Windows\System32\drivers\fs_rec.sys 2014-09-28 15:28:29 E306A24D9694C724FA2491278BF50FDB 196328 ----a-w- C:\Windows\System32\drivers\fvevol.sys 2014-09-28 15:28:00 3583A5A8CC2E682BFFBD4630D0FEC08B 730048 ----a-w- C:\Windows\System32\drivers\dxgkrnl.sys 2014-09-28 15:28:00 0EC652D17AB4607745FB4E6958E8FAB6 219072 ----a-w- C:\Windows\System32\drivers\dxgmms1.sys 2014-09-28 15:27:36 ED80D303102A746D30C1684B387BCBF1 33280 ----a-w- C:\Windows\System32\drivers\RNDISMP.sys 2014-09-28 15:27:36 8C9C922D71F1CD4DEF73F186416B7896 712048 ----a-w- C:\Windows\System32\drivers\ndis.sys 2014-09-28 15:25:38 DEE7EDA5AAA96C4C68A1F098F5145799 187840 ----a-w- C:\Windows\System32\drivers\FWPKCLNT.SYS 2014-09-28 15:25:38 5DBD4F73E2A52FEED61DBAB3752E329C 240576 ----a-w- C:\Windows\System32\drivers\netio.sys 2014-09-28 15:25:38 5579DD18546999F5D0EC39D018726C6B 1294272 ----a-w- C:\Windows\System32\drivers\tcpip.sys 2014-09-28 15:25:27 E4C2764065D66EA1D2D3EBC28FE99C46 311808 ----a-w- C:\Windows\System32\drivers\srv.sys 2014-09-28 15:25:27 BE6BD660CAA6F291AE06A718A4FA8ABC 114688 ----a-w- C:\Windows\System32\drivers\srvnet.sys 2014-09-28 15:25:27 03F0545BD8D4C77FA0AE1CEEDFCC71AB 310272 ----a-w- C:\Windows\System32\drivers\srv2.sys 2014-09-28 15:25:25 FE8A57C8E04EDD3AA8ADD8F3C8F65297 15872 ----a-w- C:\Windows\System32\drivers\usb8023.sys 2014-09-28 15:25:22 EB6137D696A9B4E9718AC6F8641CB4C9 177152 ----a-w- C:\Windows\System32\drivers\portcls.sys 2014-09-28 15:25:22 9842041E2F5ACE1E2F5FB4EF02053DC8 81408 ----a-w- C:\Windows\System32\drivers\drmk.sys 2014-09-28 15:24:53 3EEBD3BD93DA46A26E89893C7AB2FF3B 35328 ----a-w- C:\Windows\System32\drivers\tcpipreg.sys 2014-09-28 15:24:45 FC6B21DB4B5B398AB93DBE59CBF11036 36352 ----a-w- C:\Windows\System32\drivers\usbscan.sys 2014-09-28 15:24:45 F1B27299F547D452EDAEF01FC187CB91 25728 ----a-w- C:\Windows\System32\drivers\hidparse.sys 2014-09-28 15:24:45 50ABE682EBE752EAF62B18790D6D491C 55808 ----a-w- C:\Windows\System32\drivers\hidclass.sys 2014-09-28 15:24:20 D0B388DA1D111A34366E04EB4A5DD156 338944 ----a-w- C:\Windows\System32\drivers\afd.sys 2014-09-28 15:24:07 F1A449D762657230629D8BFC107ABC14 149440 ----a-w- C:\Windows\System32\drivers\storport.sys 2014-09-28 15:24:07 EB34CE31FABD4DC4343FD2AD16D2CAF9 234432 ----a-w- C:\Windows\System32\drivers\msiscsi.sys 2014-09-28 15:24:07 5FB4F271032B6435F3B2252F577A4815 27072 ----a-w- C:\Windows\System32\drivers\Diskdump.sys 2014-09-28 15:23:53 21F4B24ACFC79A483515BD986DD9043F 115712 ----a-w- C:\Windows\System32\drivers\mrxdav.sys 2014-09-28 15:23:27 B81F204D146000BE76651A50670A5E9E 96768 ----a-w- C:\Windows\System32\drivers\mrxsmb20.sys 2014-09-28 15:23:27 6D17A4791ACA19328C685D256349FEFC 223744 ----a-w- C:\Windows\System32\drivers\mrxsmb10.sys 2014-09-28 15:23:27 5D16C921E3671636C0EBA3BBAAC5FD25 123904 ----a-w- C:\Windows\System32\drivers\mrxsmb.sys 2014-09-28 15:23:13 C8DFF8D07755A66C7A4A738930F0FEAC 1212352 ----a-w- C:\Windows\System32\drivers\ntfs.sys 2014-09-28 15:23:12 3F34A1B4C5F6475F320C275E63AFCE9B 56176 ----a-w- C:\Windows\System32\drivers\partmgr.sys 2014-09-28 15:22:50 DDCE686D76C2B4DB435A3AF5BD0E691D 133056 ----a-w- C:\Windows\System32\drivers\ataport.sys 2014-09-28 15:22:00 2352AB5F9F8F097BF9D41D5A4718A041 86016 ----a-w- C:\Windows\System32\drivers\usbcir.sys 2014-09-28 15:03:19 D3964885F0A11ACF51DA3AAA776973B2 136640 ----a-w- C:\Windows\System32\drivers\ksecpkg.sys 2014-09-28 15:03:19 85449EEBE8F8EBD6481EFBF0F352B4EB 369848 ----a-w- C:\Windows\System32\drivers\cng.sys 2014-09-28 15:03:19 4120DA10AA42A9996F4575DB9E3E6E6E 67520 ----a-w- C:\Windows\System32\drivers\ksecdd.sys 2014-09-28 15:03:16 933222B19FF3E7EA5F65517EA1F7D57E 3 ----a-w- C:\Windows\System32\drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf 2014-09-28 15:03:16 48704647CD2E9DAA2EB81BDE6D029EDB 47720 ----a-w- C:\Windows\System32\drivers\WdfLdr.sys 2014-09-28 15:03:16 25944D2CC49E0A6C581D02A74B7D6645 527064 ----a-w- C:\Windows\System32\drivers\Wdf01000.sys 2014-09-28 15:03:11 8F2DA3028D5FCBD1A060A3DE64CD6506 69632 ----a-w- C:\Windows\System32\drivers\bowser.sys 2014-09-28 15:02:54 D40855F89B69305140BBD7E9A3BA2DA6 43520 ----a-w- C:\Windows\System32\drivers\usbehci.sys 2014-09-28 15:02:54 0803FBA9FE829D61AE26EC0BCC910C46 76288 ----a-w- C:\Windows\System32\drivers\usbccgp.sys 2014-09-28 15:02:53 EDF2DF71C4F1E13A6AC75F5224DE655A 258560 ----a-w- C:\Windows\System32\drivers\usbhub.sys 2014-09-28 15:02:53 EC2C5AF37B76D7B58C642CB74423DB7A 284672 ----a-w- C:\Windows\System32\drivers\usbport.sys 2014-09-28 15:02:53 74F805AB12EB0E3E49E469F19FF02640 6016 ----a-w- C:\Windows\System32\drivers\usbd.sys 2014-09-28 12:17:49 D41D8CD98F00B204E9800998ECF8427E 0 ---ha-w- C:\Windows\System32\drivers\Msft_User_WpdFs_01_09_00.Wdf 2014-09-28 10:35:37 2C2C5AFE7EE4F620D69C23C0617651A8 24576 ----a-w- C:\Windows\System32\drivers\tdtcp.sys 2014-09-28 10:28:49 B090D844D1356787CED6315A505CFEE1 8192 ----a-w- C:\Windows\System32\drivers\IntelMEFWVer.dll 2014-09-28 10:28:18 D86AC00883B9C98B570E7643AAF8E554 41088 ----a-w- C:\Windows\System32\drivers\HECI.sys 2014-09-28 10:27:36 696D41B94FB11F425E6F730F8DBEAE7A 10540032 ----a-w- C:\Windows\System32\drivers\igdkmd32.sys 2014-09-28 10:24:40 5283B9A27FF230F2FF70D92451FF409A 394856 ----a-w- C:\Windows\System32\drivers\Rt86win7.sys 2014-09-28 10:22:58 6BEA3C6C9B0DC7BB92A54154796895B7 3525352 ----a-w- C:\Windows\System32\drivers\RTKVHDA.sys ====== C:\Windows\Tasks ====== 2014-10-09 11:34:53 43AE3736D7692F4E38ACF3C8295C5AD8 3878 ----a-w- C:\Windows\system32\Tasks\Adobe Flash Player Updater 2014-10-09 11:34:53 2F518579906A6CACAEAC9680B8A646EE 940 ----a-w- C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-10-07 20:10:57 11CB66AFBA6747006D52DE0ABCBB2EC8 3680 ----a-w- C:\Windows\system32\Tasks\Java(TM) Platform SE Auto Updater 2014-10-01 12:45:11 B0EA0EAEB4E57D0FB56A51150EA773A6 3670 ----a-w- C:\Windows\system32\Tasks\Adobe Reader and Acrobat Manager 2014-09-30 11:04:38 7AF288FE0349A1045C5BE98508430BB6 2750 ----a-w- C:\Windows\system32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2013 2014-09-28 23:46:34 744AE5A2B1E7FD45ECA22A0E283F02AB 3966 ----a-w- C:\Windows\system32\Tasks\User_Feed_Synchronization-{4FF99BF0-2695-4B50-B75B-5A00AB39DC04} 2014-09-28 16:45:57 577C286923E467C23DCBBFE830CF34B6 3540 ----a-w- C:\Windows\system32\Tasks\CreateChoiceProcessTask ====== C:\Windows\Temp ====== ======= C:\Program Files ===== 2014-10-22 07:51:18 -------- d-----w- C:\Program Files\trend micro 2014-10-07 19:27:15 -------- d-----w- C:\Program Files\Common Files\Java 2014-10-07 19:26:53 -------- d-----w- C:\Program Files\Java 2014-10-07 18:34:20 -------- d-----w- C:\Program Files\GreenTree Applications 2014-09-29 20:44:25 -------- d-----w- C:\Program Files\Microsoft Silverlight 2014-09-29 07:41:09 -------- d-----w- C:\Program Files\Common Files\Adobe 2014-09-29 07:41:09 -------- d-----w- C:\Program Files\Adobe 2014-09-28 21:49:23 -------- d-----w- C:\Program Files\ABN AMRO e.dentifier2 2014-09-28 16:01:04 -------- d-----w- C:\Program Files\Microsoft.NET 2014-09-28 12:05:18 -------- d-----w- C:\Program Files\Common Files\EPSON 2014-09-28 12:01:02 -------- d-----w- C:\Program Files\Common Files\ABBYY 2014-09-28 12:01:02 -------- d-----w- C:\Program Files\ABBYY FineReader 9.0 Sprint 2014-09-28 11:56:37 -------- d-----w- C:\Program Files\EPSON Software 2014-09-28 11:54:57 -------- d-----w- C:\Program Files\epson 2014-09-28 11:37:50 -------- d-----w- C:\Program Files\AVG 2014-09-28 10:28:38 -------- d-----w- C:\Program Files\Common Files\postureAgent 2014-09-28 10:27:57 -------- d-----w- C:\Program Files\Common Files\Intel 2014-09-28 10:22:53 -------- d--h--w- C:\Program Files\InstallShield Installation Information 2014-09-28 10:22:53 -------- d-----w- C:\Program Files\Realtek 2014-09-28 10:22:48 -------- d--h--w- C:\Program Files\Temp 2014-09-28 10:22:45 -------- d-----w- C:\Program Files\Common Files\InstallShield 2014-09-28 10:22:07 -------- d-----w- C:\Program Files\Intel ======= C: ===== ====== C:\Users\Ronald\AppData\Roaming ====== 2014-10-17 12:50:03 -------- d-----w- C:\Users\Ronald\AppData\Locallow\EPSON 2014-10-07 19:33:02 -------- d-----w- C:\Users\Ronald\AppData\Roaming\vlc 2014-10-07 19:25:55 -------- d-----w- C:\Users\Ronald\AppData\Locallow\Sun 2014-09-29 11:53:56 -------- d-----w- C:\Windows\system32\config\systemprofile\AppData\Roaming\AVG 2014-09-29 07:42:32 -------- d-----w- C:\Users\Ronald\AppData\Locallow\Adobe 2014-09-28 12:32:48 -------- d-----w- C:\Users\Ronald\AppData\Local\Adobe 2014-09-28 12:16:48 -------- d-----w- C:\Users\Ronald\AppData\Roaming\Epson 2014-09-28 12:02:15 -------- d-----w- C:\Users\Ronald\AppData\Local\ABBYY 2014-09-28 11:38:21 -------- d-----w- C:\Windows\system32\config\systemprofile\AppData\Local\Avg 2014-09-28 11:38:14 -------- d-----w- C:\Users\Ronald\AppData\Roaming\AVG 2014-09-28 11:38:14 -------- d-----w- C:\Users\Ronald\AppData\Local\Avg 2014-09-28 11:20:09 -------- d-----w- C:\Windows\system32\config\systemprofile\AppData\Roaming\TuneUp Software 2014-09-28 11:20:09 -------- d-----w- C:\Windows\system32\config\systemprofile\AppData\Local\TuneUp Software 2014-09-28 11:19:39 -------- d-----w- C:\Users\Ronald\AppData\Roaming\TuneUp Software 2014-09-28 11:19:39 -------- d-----w- C:\Users\Ronald\AppData\Local\TuneUp Software 2014-09-28 11:02:07 DFBF6E7E1044BD448BD8744265D1B820 58016 ----a-w- C:\Users\Ronald\AppData\Local\GDIPFONTCACHEV1.DAT 2014-09-28 10:53:41 -------- d-sh--w- C:\Users\Ronald\AppData\Locallow\EmieUserList 2014-09-28 10:53:29 -------- d-sh--w- C:\Users\Ronald\AppData\Local\EmieUserList 2014-09-28 10:53:29 -------- d-sh--w- C:\Users\Ronald\AppData\Local\EmieSiteList 2014-09-28 10:53:24 -------- d-sh--w- C:\Users\Ronald\AppData\Locallow\EmieSiteList 2014-09-28 10:53:03 -------- d-----w- C:\Users\Ronald\AppData\Roaming\Adobe 2014-09-28 10:32:19 -------- d-s---w- C:\Users\Ronald\AppData\Locallow\Microsoft 2014-09-28 10:28:53 -------- d-----w- C:\Windows\serviceprofiles\Localservice\AppData\Local\PnrpSqm 2014-09-28 10:28:17 -------- d-----w- C:\Users\Ronald\AppData\Roaming\InstallShield 2014-09-28 10:26:51 -------- d-----w- C:\Windows\serviceprofiles\Localservice\AppData\Roaming\PeerNetworking 2014-09-28 10:19:23 -------- d-----r- C:\Users\Ronald\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-09-28 10:19:23 -------- d-----r- C:\Users\Ronald\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2014-09-28 10:19:14 -------- d-----w- C:\Users\Ronald\AppData\Roaming\Identities 2014-09-28 10:19:07 -------- d-----w- C:\Users\Ronald\AppData\Local\VirtualStore 2014-09-28 10:19:03 -------- d-s---w- C:\Users\Ronald\AppData\Roaming\Microsoft 2014-09-28 10:19:03 -------- d-----w- C:\Users\Ronald\AppData\Roaming\Media Center Programs 2014-09-28 10:19:03 -------- d-----w- C:\Users\Ronald\AppData\Local\Temp 2014-09-28 10:19:03 -------- d-----w- C:\Users\Ronald\AppData\Local\Microsoft 2014-09-28 10:19:03 -------- d-----r- C:\Users\Ronald\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance 2014-09-28 10:19:03 -------- d-----r- C:\Users\Ronald\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories ====== C:\Users\Ronald ====== 2014-10-07 19:27:16 -------- d-----w- C:\ProgramData\Sun 2014-10-07 19:27:02 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2014-09-30 12:07:55 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 2014-09-29 23:34:33 -------- d-----r- C:\Windows\system32\config\systemprofile\Searches 2014-09-28 21:49:23 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ABN AMRO e.dentifier2 2014-09-28 16:20:06 -------- d-----w- C:\ProgramData\Adobe 2014-09-28 12:01:58 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ABBYY FineReader 9.0 Sprint 2014-09-28 12:01:02 -------- d-----w- C:\ProgramData\ABBYY 2014-09-28 11:59:36 -------- d-----w- C:\ProgramData\UDL 2014-09-28 11:57:17 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Epson Software 2014-09-28 11:55:13 -------- d-----w- C:\ProgramData\EPSON 2014-09-28 11:54:58 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EPSON 2014-09-28 11:38:28 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG PC TuneUp 2015 2014-09-28 11:34:44 -------- d-----w- C:\ProgramData\AVG 2014-09-28 11:17:17 -------- d--h--w- C:\ProgramData\Common Files 2014-09-28 11:17:14 -------- d-----w- C:\ProgramData\TuneUp Software 2014-09-28 10:19:23 -------- d-----r- C:\Users\Ronald\Searches 2014-09-28 10:19:13 -------- d-----r- C:\Users\Ronald\Contacts 2014-09-28 10:19:03 6FC234AD3752E1267B34FB12BCD6718B 20 --sh--w- C:\Users\Ronald\ntuser.ini 2014-09-28 10:19:03 -------- d--h--w- C:\Users\Ronald\AppData 2014-09-28 10:19:03 -------- d-----r- C:\Users\Ronald\Videos 2014-09-28 10:19:03 -------- d-----r- C:\Users\Ronald\Saved Games 2014-09-28 10:19:03 -------- d-----r- C:\Users\Ronald\Pictures 2014-09-28 10:19:03 -------- d-----r- C:\Users\Ronald\Music 2014-09-28 10:19:03 -------- d-----r- C:\Users\Ronald\Links 2014-09-28 10:19:03 -------- d-----r- C:\Users\Ronald\Favorites 2014-09-28 10:19:03 -------- d-----r- C:\Users\Ronald\Downloads 2014-09-28 10:19:03 -------- d-----r- C:\Users\Ronald\Documents 2014-09-28 10:19:03 -------- d-----r- C:\Users\Ronald\Desktop ====== C: exe-files == 2014-10-22 07:51:19 9A2347903D6EDB84C10F288BC0578C1C 388608 ----a-w- C:\Program Files\trend micro\Ronald.exe 2014-10-17 12:48:02 51C40019D2417A27D0DEB3267839F64B 9170496 ----a-w- C:\Users\Ronald\AppData\Local\Temp\EPSON\Download\Resource\EWP12000.exe 2014-10-16 22:50:34 F11D36A08D5A3F23D0DFE90A1BE15FE2 42656 ----a-w- C:\Windows\System32\CompatTel\wicainventory.exe 2014-10-16 22:50:34 113D9258E5B69187A804AEF6B39647B8 138912 ----a-w- C:\Windows\System32\CompatTel\QueryAppBlock.exe 2014-10-16 22:50:28 8F390C7AA11DF00FC3EF86FA72A939D2 646144 ----a-w- C:\Windows\System32\MsSpellCheckingFacility.exe 2014-10-16 22:50:28 8C8B6144B47FE37724590CA832ED26CA 108032 ----a-w- C:\Windows\System32\ieetwcollector.exe 2014-10-16 22:50:27 AA103FEAD721863B86A1B1260948E662 112128 ----a-w- C:\Windows\System32\ieUnatt.exe 2014-10-16 22:50:22 AF31CC5BAEB4916C0AF9AB062CFE8DA2 677888 ----a-w- C:\Windows\System32\ie4uinit.exe 2014-10-16 22:50:22 54C9747BB0A64F4D9D401E4648363386 222720 ----a-w- C:\Program Files\Internet Explorer\ielowutil.exe 2014-10-16 22:50:21 53E24F2DB97EFAF85FE093AA254790EC 470528 ----a-w- C:\Program Files\Internet Explorer\ieinstal.exe 2014-10-16 22:50:19 F9F310F9FB7F294F00ABDD03453D8CEE 812736 ----a-w- C:\Program Files\Internet Explorer\iexplore.exe 2014-10-16 22:50:12 0DBD0B4D4766CADEB8C30242A0611395 1051136 ----a-w- C:\Windows\System32\mstsc.exe === C: other files == 2014-10-22 09:28:33 E9DA0037BE5CF11304B5A62E66BFC049 544 ----a-w- C:\$Recycle.Bin\S-1-5-21-1713141829-3285270229-1384493382-1000\$I3TOQ4Q.zip 2014-10-22 09:23:51 27879DB26EA08385F188A80A8B49BCBC 4114148 ----a-w- C:\$Recycle.Bin\S-1-5-21-1713141829-3285270229-1384493382-1000\$R3TOQ4Q.zip 2014-10-16 22:50:33 348289FDF17FB4A1F23091F9463642D6 2379264 ----a-w- C:\Windows\System32\win32k.sys 2014-10-16 22:50:11 CD9214A6AE17D188D17C3CF8CB9CC693 184320 ----a-w- C:\Windows\System32\drivers\rdpwd.sys 2014-10-16 22:50:11 6C5139E4283249518F7743D7043775B3 31232 ----a-w- C:\Windows\System32\drivers\tssecsrv.sys ==== Startup Registry Enabled ====================== [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun" [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun" [HKEY_USERS\S-1-5-21-1713141829-3285270229-1384493382-1000\Software\Microsoft\Windows\CurrentVersion\Run] "EPLTarget\P0000000000000000"="C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATIINE.EXE /EPT EPLTarget\P0000000000000000 /M XP-102 103 Series" [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce] "mctadmin"="C:\Windows\System32\mctadmin.exe" [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce] "mctadmin"="C:\Windows\System32\mctadmin.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RTHDVCPL"="C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s" "IgfxTray"="C:\Windows\system32\igfxtray.exe" "HotKeysCmds"="C:\Windows\system32\hkcmd.exe" "Persistence"="C:\Windows\system32\igfxpers.exe" "MSC"="c:\Program Files\Microsoft Security Client\msseces.exe -hide -runkey" "EEventManager"="C:\Program Files\Epson Software\Event Manager\EEventManager.exe" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "EPLTarget\P0000000000000000"="C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATIINE.EXE /EPT EPLTarget\P0000000000000000 /M XP-102 103 Series" ==== Startup Registry Disabled ====================== [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run-] "Adobe ARM"="\"C:\\Program Files\\Common Files\\Adobe\\ARM\\1.0\\AdobeARM.exe\"" "SunJavaUpdateSched"="\"C:\\Program Files\\Common Files\\Java\\Java Update\\jusched.exe\"" ==== Task Scheduler Jobs ====================== C:\Windows\tasks\Adobe Flash Player Updater.job --a------ C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [16-10-2014 17:57] ==== Other Scheduled Tasks ====================== "C:\Windows\system32\tasks\Adobe Flash Player Updater" [C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe] "C:\Windows\system32\tasks\Adobe Reader and Acrobat Manager" [C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe] "C:\Windows\system32\tasks\CreateChoiceProcessTask" [C:\Windows\System32\browserchoice.exe] "C:\Windows\system32\tasks\Java(TM) Platform SE Auto Updater" [C:\Program Files\Common Files\Java\Java Update\jusched.exe] "C:\Windows\system32\tasks\TuneUpUtilities_Task_BkGndMaintenance2013" [C:\Program Files\AVG\AVG PC TuneUp\OneClick.exe] "C:\Windows\system32\tasks\User_Feed_Synchronization-{4FF99BF0-2695-4B50-B75B-5A00AB39DC04}" [C:\Windows\system32\msfeedssync.exe] ==== Firefox Extensions Registry ====================== [HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions] "e-webprint@epson.com"="C:\Program Files\Epson Software\E-Web Print\Firefox Add-on" [17-10-2014 14:48] ==== C:\zoek_backup content ====================== C:\zoek_backup (files=0 folders=0 0 bytes) ==== EOF on wo 22-10-2014 at 11:34:26,81 ======================