Zoek.exe v5.0.0.0 Updated 18-01-2015 Tool run by gebruiker on di 20-01-2015 at 19:08:01,74. Microsoft Windows 8.1 6.3.9600 x64 Running in: Normal Mode Internet Access Detected Launched: C:\Users\gebruiker\Downloads\zoek.exe [Scan all users] [Script inserted] [Checkboxes used] ==== Older Logs ====================== C:\zoek-results2015-01-19-183637.log 32996 bytes ==== Deleting CLSID Registry Keys ====================== ==== Deleting CLSID Registry Values ====================== ==== Deleting Services ====================== ==== Deleting Files \ Folders ====================== C:\Program Files\Enigma Software Group deleted C:\Users\gebruiker\AppData\Local\Popcorn Time deleted C:\Users\gebruiker\AppData\Local\PopcornTimeDesktop deleted "C:\autoexec.bat" deleted ==== Files Recently Created / Modified ====================== ====== C:\WINDOWS ==== ====== C:\Users\GEBRUI~1\AppData\Local\Temp ==== ====== Java Cache ===== ====== C:\WINDOWS\SysWOW64 ===== 2015-01-19 18:08:45 A042349B7208BF8BED858B1E9B48B06D 98216 ----a-w- C:\WINDOWS\SysWOW64\WindowsAccessBridge-32.dll 2015-01-15 13:44:08 A4001C78F2806662B3BD91ACB44E6330 45 ----a-w- C:\WINDOWS\SysWOW64\initdebug.nfo 2015-01-14 13:12:01 DCE9FD22B136C127C85F285E083B928B 65536 ----a-w- C:\WINDOWS\SysWOW64\nlaapi.dll 2015-01-14 13:12:00 1F9C1925A85C6CC592C2FF612A610412 372408 ----a-w- C:\WINDOWS\SysWOW64\Faultrep.dll 2015-01-14 13:12:00 1EB1C1E43C1901865C5AE34A9771C069 448792 ----a-w- C:\WINDOWS\SysWOW64\wer.dll 2015-01-14 13:12:00 1275462A4337DBC5518859316BEF262C 413136 ----a-w- C:\WINDOWS\SysWOW64\WerFault.exe 2015-01-14 13:11:59 D9F17FC61102D89A67A2AA3DD21231F5 33584 ----a-w- C:\WINDOWS\SysWOW64\WerFaultSecure.exe 2015-01-14 13:11:59 BFFD9961B29DAB8084278DB2314D6027 33280 ----a-w- C:\WINDOWS\SysWOW64\werdiagcontroller.dll 2015-01-14 13:11:59 B5867FF96CD0F7712CB4985EAC9F9147 370424 ----a-w- C:\WINDOWS\SysWOW64\AudioSes.dll 2015-01-14 13:11:59 7C36A441C73F079781ABA8F3DAEDFB37 136296 ----a-w- C:\WINDOWS\SysWOW64\wermgr.exe 2015-01-14 13:11:59 7B2643AE85322EA168B0E760B73258FF 424544 ----a-w- C:\WINDOWS\SysWOW64\AudioEng.dll 2015-01-14 13:11:59 4B07B24705A9225EB565650569BDA26B 344536 ----a-w- C:\WINDOWS\SysWOW64\AUDIOKSE.dll ====== C:\WINDOWS\SysWOW64\drivers ===== ====== C:\WINDOWS\Sysnative ===== 2015-01-16 14:15:40 2BBE5D70A968DC31919373AE6824A4BD 372392 ----a-w- C:\WINDOWS\Sysnative\FNTCACHE.DAT 2015-01-14 13:12:01 FE11972797DED38CA55E88BD3579F6A2 360448 ----a-w- C:\WINDOWS\Sysnative\ncsi.dll 2015-01-14 13:12:01 E94EB2A95D7D016E119C4D6868788831 391680 ----a-w- C:\WINDOWS\Sysnative\nlasvc.dll 2015-01-14 13:12:01 6319232C1CE39AC35316CF51910EEEB5 86016 ----a-w- C:\WINDOWS\Sysnative\nlaapi.dll 2015-01-14 13:12:01 19424364D8C03B990C4281BE53963FD0 225280 ----a-w- C:\WINDOWS\Sysnative\profsvc.dll 2015-01-14 13:12:00 8EBC741DDE9409038262E2F317ED7CCE 535640 ----a-w- C:\WINDOWS\Sysnative\wer.dll 2015-01-14 13:12:00 6DCD12586353DC6307AC781045CA13A4 465320 ----a-w- C:\WINDOWS\Sysnative\WerFault.exe 2015-01-14 13:12:00 2C354FA91EF605007FD11BB89EED2266 413248 ----a-w- C:\WINDOWS\Sysnative\Faultrep.dll 2015-01-14 13:12:00 29A888F3136B2643E22113B5422B46F9 87040 ----a-w- C:\WINDOWS\Sysnative\TSWbPrxy.exe 2015-01-14 13:11:59 E24D3259769A0218FE19BB306821C2E5 394120 ----a-w- C:\WINDOWS\Sysnative\AUDIOKSE.dll 2015-01-14 13:11:59 D1E3B8D9130C70F6A3D4FDB52373FF34 37888 ----a-w- C:\WINDOWS\Sysnative\werdiagcontroller.dll 2015-01-14 13:11:59 A41B72F81B389786805CC4D5767B5FBC 531616 ----a-w- C:\WINDOWS\Sysnative\ci.dll 2015-01-14 13:11:59 9404704666256045F5BA9B290953B4D0 38264 ----a-w- C:\WINDOWS\Sysnative\WerFaultSecure.exe 2015-01-14 13:11:59 8779FDAE68BC948B0FE152E758CC8DA7 229888 ----a-w- C:\WINDOWS\Sysnative\AudioEndpointBuilder.dll 2015-01-14 13:11:59 770BAA636F3B61DA7E414421444F84FD 272248 ----a-w- C:\WINDOWS\Sysnative\audiodg.exe 2015-01-14 13:11:59 6F237EE5DDA34EAF3D9C79D4A283E250 482872 ----a-w- C:\WINDOWS\Sysnative\AudioEng.dll 2015-01-14 13:11:59 61EA45A645854FE81D8A924E2D93DFFE 911360 ----a-w- C:\WINDOWS\Sysnative\audiosrv.dll 2015-01-14 13:11:59 428F083690D7AAA012338FD5A0663EE3 500016 ----a-w- C:\WINDOWS\Sysnative\AudioSes.dll 2015-01-14 13:11:59 41C501FD9D42F3F04A8532C73E09F356 108944 ----a-w- C:\WINDOWS\Sysnative\EncDump.dll 2015-01-14 13:11:59 0BCDEB035B9346D3C3C6C8BB1AA7F38C 139984 ----a-w- C:\WINDOWS\Sysnative\wermgr.exe ====== C:\WINDOWS\Sysnative\drivers ===== 2015-01-14 13:12:00 F0CB6DB513CAC393D04A0FCE0A59E1BF 75776 ----a-w- C:\WINDOWS\Sysnative\drivers\ahcache.sys 2015-01-14 13:12:00 DB32958F0E704EFBF7F15161A569E39F 140800 ----a-w- C:\WINDOWS\Sysnative\drivers\mrxdav.sys 2014-12-26 14:57:44 34DFB4ACF03D95A51021D341CAA4E1B5 31376 ----a-w- C:\WINDOWS\Sysnative\drivers\nvpciflt.sys 2014-12-26 14:57:42 ED4D88A04D22E6B00DB6BC8FACDBAFED 10345280 ----a-w- C:\WINDOWS\Sysnative\drivers\nvlddmkm.sys 2014-12-26 14:46:54 DBFE7B2DF103F74AE51840B3C5F25FE9 38032 ----a-w- C:\WINDOWS\Sysnative\drivers\nvvad64v.sys ====== C:\WINDOWS\Tasks ====== 2015-01-15 15:25:51 513D5EEBBD57381D460DFE9D9FA4881A 3018 ----a-w- C:\WINDOWS\Sysnative\Tasks\SlimComputer Run ====== C:\WINDOWS\Temp ====== ======= C:\Program Files ===== ======= C:\PROGRA~2 ===== 2015-01-19 18:08:47 -------- d-----w- C:\PROGRA~2\COMMON~1\Java 2015-01-19 18:07:45 -------- d-----w- C:\PROGRA~2\Java 2015-01-15 15:34:30 -------- d-----w- C:\PROGRA~2\PrivaZer 2015-01-15 15:25:36 -------- d-----w- C:\PROGRA~2\SlimComputer ======= C: ===== ====== C:\Users\gebruiker\AppData\Roaming ====== 2015-01-19 18:33:32 -------- d-----w- C:\WINDOWS\serviceprofiles\networkservice\AppData\Local\Temp 2015-01-19 18:33:32 -------- d-----w- C:\WINDOWS\serviceprofiles\Localservice\AppData\Local\Temp 2015-01-19 18:33:32 -------- d-----w- C:\Users\Default\AppData\Local\Temp 2015-01-19 18:33:32 -------- d-----w- C:\Users\Default User\AppData\Local\Temp 2015-01-19 18:33:32 -------- d-----w- C:\Users\Administrator\AppData\Local\Temp 2015-01-19 18:33:31 -------- d-----w- C:\Users\gebruiker\AppData\Local\Temp 2015-01-19 18:24:06 -------- d-----w- C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\CrashDumps 2015-01-15 15:34:32 -------- d-----w- C:\Users\gebruiker\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PrivaZer 2015-01-15 15:34:30 -------- d-----w- C:\Users\gebruiker\AppData\Local\PrivaZer 2015-01-15 15:25:48 -------- d-----w- C:\Users\gebruiker\AppData\Local\SlimWare Utilities Inc 2015-01-12 15:12:13 -------- d-----w- C:\Users\gebruiker\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Popcorn Time 2015-01-12 15:11:02 -------- d-----w- C:\Users\gebruiker\AppData\Local\node-webkit ====== C:\Users\gebruiker ====== 2015-01-20 12:56:31 -------- d-----w- C:\WINDOWS\serviceprofiles\Localservice\winhttp 2015-01-19 18:08:20 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2015-01-19 18:07:56 -------- d-----w- C:\ProgramData\Oracle 2015-01-19 15:55:05 6DD947991853486DE376C12FF20A42F7 709564 ----a-w- C:\Users\gebruiker\Downloads\delfix_10.8.exe 2015-01-19 13:57:00 -------- d-----w- C:\Users\gebruiker\Start Menu 2015-01-15 15:34:31 -------- d-----w- C:\ProgramData\privazer 2015-01-15 15:25:36 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SlimComputer 2015-01-15 15:25:26 -------- d-----w- C:\Users\Public\Documents\Downloaded Installers 2015-01-15 13:44:09 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SpeedFan 2015-01-12 15:14:09 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Popcorn Time ====== C: exe-files == 2015-01-20 14:56:00 03DBB71DF9AE1A5E30EEED112BE67307 544 ----a-w- C:\$RECYCLE.BIN\S-1-5-21-2035609657-2241805967-4120172649-1002\$IHBO6QI.exe 2015-01-20 14:55:57 2245B6E3E0F317ED4081CD14752C29EB 544 ----a-w- C:\$RECYCLE.BIN\S-1-5-21-2035609657-2241805967-4120172649-1002\$IRVN9VX.exe 2015-01-19 22:39:21 8EBBAB4AE945947E6D4D37743F875025 432456 ----a-w- C:\Users\gebruiker\AppData\Local\NVIDIA\NvBackend\Packages\00006b79\CoProc update.19241512.exe 2015-01-19 18:08:24 75D477E868CA51EC1B09D730570F322B 0 ----a-we C:\ProgramData\Oracle\Java\javapath\javaw.exe 2015-01-19 18:08:24 691D49FB44EDE9788288CABE4F7E0DAF 0 ----a-we C:\ProgramData\Oracle\Java\javapath\javaws.exe 2015-01-19 18:08:23 AA3520FB0133A56BEE1DB34D74DBEF64 0 ----a-we C:\ProgramData\Oracle\Java\javapath\java.exe 2015-01-19 18:08:11 E3E6B18458FFB07CB24D7A0BA77C9FDF 15784 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_25\bin\pack200.exe 2015-01-19 18:08:11 DC197DCE6325CBAC905DE0D0E3BA3E8E 15784 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_25\bin\rmid.exe 2015-01-19 18:08:11 BB8C890E3E6372F2720709262BD42BF4 30632 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_25\bin\jabswitch.exe 2015-01-19 18:08:11 B719E0F43166037DF46B5CFBE60A5118 15784 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_25\bin\jjs.exe 2015-01-19 18:08:11 AA3520FB0133A56BEE1DB34D74DBEF64 176552 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_25\bin\java.exe 2015-01-19 18:08:11 A458E2535E46151690E53E2A03FAA711 15784 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_25\bin\keytool.exe 2015-01-19 18:08:11 9BFAEF308D50779F6B255CB7BA7DCA5A 15784 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_25\bin\kinit.exe 2015-01-19 18:08:11 7AB1F1B3FB6C3DACA34EA2F988CDF5AC 16296 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_25\bin\orbd.exe 2015-01-19 18:08:11 75EE99C7F0038C746D82C76221ECA4EF 16296 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_25\bin\policytool.exe 2015-01-19 18:08:11 75D477E868CA51EC1B09D730570F322B 176552 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_25\bin\javaw.exe 2015-01-19 18:08:11 74713E9C1B01B152DDD3A1A3519A3647 15784 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_25\bin\java-rmi.exe 2015-01-19 18:08:11 70E67429D2C011FD0419AF899A8D0D70 68520 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_25\bin\javacpl.exe 2015-01-19 18:08:11 691D49FB44EDE9788288CABE4F7E0DAF 272296 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_25\bin\javaws.exe 2015-01-19 18:08:11 67F763B09F4BC8689E6FA9761E068D74 159656 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_25\bin\unpack200.exe 2015-01-19 18:08:11 57E1F756FAA787623DFCD2C1B2AACC68 51112 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_25\bin\ssvagent.exe 2015-01-19 18:08:11 4367C05B0CF5553E71B34F51003D0615 76200 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_25\bin\jp2launcher.exe 2015-01-19 18:08:11 4109C4DB4BD48F5BF8115C7523A6B6F8 15784 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_25\bin\klist.exe 2015-01-19 18:08:11 33D2AF53E209DA3E2BA939EB89801DC0 16296 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_25\bin\rmiregistry.exe 2015-01-19 18:08:11 29E65AC6AFD8A0A9CAA361FF6F7B4886 16296 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_25\bin\servertool.exe 2015-01-19 18:08:11 28FC00F89631B0F6E1E9CA386FADD566 16296 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_25\bin\tnameserv.exe 2015-01-19 18:08:11 26C7F32186B1F0364CD06EA69227A79D 15784 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_25\bin\ktab.exe 2015-01-19 18:00:28 3A582BF6FD39DC6A52AAF316126B40BA 638888 ----a-w- C:\$RECYCLE.BIN\S-1-5-21-2035609657-2241805967-4120172649-1002\$RRVN9VX.exe 2015-01-19 15:55:05 6DD947991853486DE376C12FF20A42F7 709564 ----a-w- C:\Users\gebruiker\Downloads\delfix_10.8.exe 2015-01-19 13:54:24 B4CD9E8513C17C32224C70330A235296 3044736 ----a-w- C:\$RECYCLE.BIN\S-1-5-21-2035609657-2241805967-4120172649-1002\$RHBO6QI.exe 2015-01-17 22:36:42 EC5B12BBB332360C47EF670A553A0AB4 337896 ----a-w- C:\Users\gebruiker\AppData\Local\NVIDIA\NvBackend\Packages\00006b72\DRS update.19235457.exe 2015-01-17 20:11:11 0F901EE41FF20347C106D663F24931F9 679752 ----a-w- C:\Users\gebruiker\AppData\Local\Google\Chrome\User Data\SwReporter\2.6.2\software_reporter_tool.exe 2015-01-16 22:35:05 5BFA034E3117C744D782F2929D13FAE5 4741872 ----a-w- C:\Users\gebruiker\AppData\Local\NVIDIA\NvBackend\Packages\00006b3e\DAO.19233915.exe 2015-01-15 19:46:32 BA7DC0C9141BE7292CA7E744B6F19F26 897104 ----a-w- C:\Program Files (x86)\Google\Update\Download\{4DC8B4CA-1BDA-483E-B5FA-D3C12E15B62D}\39.0.2171.99\39.0.2171.99_39.0.2171.95_chrome_updater.exe 2015-01-15 15:34:31 9F0EA25BE25F4CE1A46847DF47524CA2 431752 ----a-w- C:\Program Files (x86)\PrivaZer\patch.exe 2015-01-15 15:34:31 25740BE6C005690C038CF8B692126AD6 14300296 ----a-w- C:\Program Files (x86)\PrivaZer\PrivaZer.exe 2015-01-15 15:34:31 218283D24DD622D063D26184FB471D3E 854664 ----a-w- C:\Program Files (x86)\PrivaZer\privazer_start.exe 2015-01-14 13:12:00 6DCD12586353DC6307AC781045CA13A4 465320 ----a-w- C:\Windows\System32\WerFault.exe 2015-01-14 13:12:00 29A888F3136B2643E22113B5422B46F9 87040 ----a-w- C:\Windows\System32\TSWbPrxy.exe 2015-01-14 13:12:00 1275462A4337DBC5518859316BEF262C 413136 ----a-w- C:\Windows\SysWOW64\WerFault.exe 2015-01-14 13:11:59 D9F17FC61102D89A67A2AA3DD21231F5 33584 ----a-w- C:\Windows\SysWOW64\WerFaultSecure.exe 2015-01-14 13:11:59 9404704666256045F5BA9B290953B4D0 38264 ----a-w- C:\Windows\System32\WerFaultSecure.exe 2015-01-14 13:11:59 7C36A441C73F079781ABA8F3DAEDFB37 136296 ----a-w- C:\Windows\SysWOW64\wermgr.exe 2015-01-14 13:11:59 770BAA636F3B61DA7E414421444F84FD 272248 ----a-w- C:\Windows\System32\audiodg.exe 2015-01-14 13:11:59 0BCDEB035B9346D3C3C6C8BB1AA7F38C 139984 ----a-w- C:\Windows\System32\wermgr.exe === C: other files == 2015-01-20 14:56:02 448581CC6FE6D534BA9254C606836511 544 ----a-w- C:\$RECYCLE.BIN\S-1-5-21-2035609657-2241805967-4120172649-1002\$IJW2S9Z.zip 2015-01-20 14:55:55 1CB76BA9623A0E1728274FD929CC1DF3 544 ----a-w- C:\$RECYCLE.BIN\S-1-5-21-2035609657-2241805967-4120172649-1002\$IH8MV0P.zip 2015-01-19 18:08:12 CE44A9D4918DCDC7CCCF5503BF4D7A3D 14130 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_25\lib\deploy\ffjcext.zip 2015-01-17 20:19:56 AFEAEBD1D5E40FB40B2CF5C09DDD289A 21344 ----a-w- C:\$RECYCLE.BIN\S-1-5-21-2035609657-2241805967-4120172649-1002\$RJW2S9Z.zip 2015-01-15 15:35:50 8B7D4D50E8A4E5C38583F30182894F3C 301 ----a-w- C:\Users\gebruiker\AppData\Local\PrivaZer\data_patch.tmp.doc.zip 2015-01-14 13:12:00 F0CB6DB513CAC393D04A0FCE0A59E1BF 75776 ----a-w- C:\Windows\System32\drivers\ahcache.sys 2015-01-14 13:12:00 DB32958F0E704EFBF7F15161A569E39F 140800 ----a-w- C:\Windows\System32\drivers\mrxdav.sys ==== Startup Registry Enabled ====================== [HKEY_USERS\S-1-5-21-2035609657-2241805967-4120172649-1002\Software\Microsoft\Windows\CurrentVersion\Run] "EPLTarget\P0000000000000000"="C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIIKE.EXE /EPT EPLTarget\P0000000000000000 /M XP-302 303 305 306 Series /EF HKCU" "Spotify"="C:\Users\gebruiker\AppData\Roaming\Spotify\Spotify.exe /uri spotify:autostart" "Spotify Web Helper"="C:\Users\gebruiker\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Adobe Reader Speed Launcher"="C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe" "Adobe ARM"="C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" "RemoteControl10"="C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe" "ASUSWebStorage"="C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.9.120\AsusWSPanel.exe /S" "PWRISOVM.EXE"="C:\Program Files (x86)\PowerISO\PWRISOVM.EXE -startup" "LogitechQuickCamRibbon"="C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe /hide" "Nikon Message Center 2"="C:\Program Files (x86)\Nikon\Nikon Message Center 2\NkMC2.exe -s" "BlueStacks Agent"="C:\Program Files (x86)\BlueStacks\HD-Agent.exe" "SunJavaUpdateSched"="C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "EPLTarget\P0000000000000000"="C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIIKE.EXE /EPT EPLTarget\P0000000000000000 /M XP-302 303 305 306 Series /EF HKCU" "Spotify"="C:\Users\gebruiker\AppData\Roaming\Spotify\Spotify.exe /uri spotify:autostart" "Spotify Web Helper"="C:\Users\gebruiker\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"="C:\\WINDOWS\\SysWOW64\\nvinit.dll" ==== Startup Registry Enabled x64 ====================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" "HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" "Persistence"="C:\WINDOWS\system32\igfxpers.exe" "RTHDVCPL"="C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s" "BtTray"="C:\Program Files (x86)\Bluetooth Suite\BtTray.exe" "BtvStack"="C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe" "ACMON"="C:\Program Files (x86)\ASUS\Splendid\ACMON.exe" "ShadowPlay"="C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\nvspcap64.dll,ShadowPlayOnSystemStart" "NvBackend"="C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"="?•o, C:\\Windows\\system32\\nvinitx.dll, C:\\WINDOWS\\system32\\nvinitx.dll" ==== Startup Registry Disabled x64 ====================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\AdobeARMservice] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\AdobeFlashPlayerUpdateSvc] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\ASLDRService] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\ASUS InstantOn] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\AtherosSvc] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\ATKGFNEXSrv] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\BstHdAndroidSvc] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\BstHdLogRotatorSvc] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\cphs] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\EpsonCustomerResearchParticipation] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\gupdate] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\gupdatem] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\Intel(R) Capability Licensing Service Interface] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\Intel(R) ME Service] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\jhi_service] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\LMS] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\MBAMScheduler] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\MBAMService] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\McComponentHostService] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\MozillaMaintenance] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\NvNetworkService] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\NvStreamSvc] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\nvsvc] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\UNS] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\ZAtheros Bt and Wlan Coex Agent] ==== Task Scheduler Jobs ====================== C:\WINDOWS\tasks\Adobe Flash Player Updater.job --a-------- [Undetermined Task] C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job --a-------- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [07-01-2014 21:00] C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job --a-------- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [07-01-2014 21:00] ==== Other Scheduled Tasks ====================== "C:\WINDOWS\SysNative\tasks\Adobe Flash Player Updater" [C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe] "C:\WINDOWS\SysNative\tasks\ASUS InstantOn Config" [C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnCfg.exe] "C:\WINDOWS\SysNative\tasks\ASUS Live Update" [C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe] "C:\WINDOWS\SysNative\tasks\ASUS P4G" [C:\Program Files\ASUS\P4G\BatteryLife.exe] "C:\WINDOWS\SysNative\tasks\ASUS Touchpad Launcher (x64)" [C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLauncher.exe] "C:\WINDOWS\SysNative\tasks\ASUS USB Charger Plus" ["C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe"] "C:\WINDOWS\SysNative\tasks\CCleanerSkipUAC" ["C:\Program Files\CCleaner\CCleaner.exe"] "C:\WINDOWS\SysNative\tasks\GoogleUpdateTaskMachineCore" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe] "C:\WINDOWS\SysNative\tasks\GoogleUpdateTaskMachineUA" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe] "C:\WINDOWS\SysNative\tasks\Norton WSC Integration" ["C:\Program Files (x86)\Norton Internet Security\Engine\21.6.0.32\WSCStub.exe"] "C:\WINDOWS\SysNative\tasks\SlimComputer Run" ["C:\Program Files (x86)\SlimComputer\SlimComputer.exe"] "C:\WINDOWS\SysNative\tasks\User_Feed_Synchronization-{5051A2B2-1CFE-4FBB-8DCC-859EBF622850}" [C:\WINDOWS\system32\msfeedssync.exe] "C:\WINDOWS\SysNative\tasks\Windows Update" [C:\Users\gebruiker\AppData\Local\32138782-9AE5-4CC7-9C0F-26E8B000E0A1\svchost.exe] "C:\WINDOWS\SysNative\tasks\Norton Family\Norton Error Analyzer" [C:\Program Files (x86)\Norton Family\Engine\2.9.5.26\SymErr.exe] "C:\WINDOWS\SysNative\tasks\Norton Family\Norton Error Processor" [C:\Program Files (x86)\Norton Family\Engine\2.9.5.26\SymErr.exe] "C:\WINDOWS\SysNative\tasks\Norton Internet Security\Norton Error Analyzer" [C:\Program Files (x86)\Norton Internet Security\Engine\21.6.0.32\SymErr.exe] "C:\WINDOWS\SysNative\tasks\Norton Internet Security\Norton Error Processor" [C:\Program Files (x86)\Norton Internet Security\Engine\21.6.0.32\SymErr.exe] ==== Firefox Extensions Registry ====================== [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions] "{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}"="C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_21.6.0.32\coFFPlgn" [20-01-2015 13:56] ==== Chromium Look ====================== Google Chrome Version: 39.0.2171.99 (Up to date, latest Stable version: 39.0.2171.99) HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions eblihieomkjeiobglmnbmidkajdcfkpa - No path found[] iikflkcanblccfahdhdonehdalibjnif - No path found[] mkfokfffehpeedafpekjeddnmnjhmcmk - C:\Program Files (x86)\Norton Internet Security\Engine\21.6.0.32\Exts\Chrome.crx[20-09-2014 09:52] Google Docs - gebruiker\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake Google Drive - gebruiker\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf YouTube - gebruiker\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo Google Search - gebruiker\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf AdBlock - gebruiker\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom TweetDeck by Twitter - gebruiker\AppData\Local\Google\Chrome\User Data\Default\Extensions\hbdpomandigafcibbmofojjchbcdagbl Norton Identity Safe - gebruiker\AppData\Local\Google\Chrome\User Data\Default\Extensions\iikflkcanblccfahdhdonehdalibjnif Google Wallet - gebruiker\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda Gmail - gebruiker\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia ==== Chromium Fix ====================== C:\Users\gebruiker\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.audienceinsights.net_0.localstorage deleted successfully C:\Users\gebruiker\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.audienceinsights.net_0.localstorage-journal deleted successfully C:\Users\gebruiker\AppData\Local\Google\Chrome\User Data\Default\Extensions\iikflkcanblccfahdhdonehdalibjnif deleted successfully ==== Set IE to Default ====================== Old Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://www.google.com" New Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://www.google.com" ==== All HKCU SearchScopes ====================== HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" {012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}" {0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC" ==== Deleting Registry Keys ====================== HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\Eblihieomkjeiobglmnbmidkajdcfkpa deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\Eblihieomkjeiobglmnbmidkajdcfkpa deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\Iikflkcanblccfahdhdonehdalibjnif deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\Iikflkcanblccfahdhdonehdalibjnif deleted successfully ==== Empty IE Cache ====================== C:\WINDOWS\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\gebruiker\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\Users\gebruiker\AppData\Local\Microsoft\Windows\INetCache\Low\Content.IE5 emptied successfully C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\WINDOWS\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\Users\gebruiker\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully C:\Users\gebruiker\AppData\Local\Microsoft\Windows\INetCache\Low\IE emptied successfully C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully ==== Empty FireFox Cache ====================== No FireFox Profiles found ==== Empty Chrome Cache ====================== C:\Users\gebruiker\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully ==== Empty All Flash Cache ====================== Flash Cache Emptied Successfully ==== Empty All Java Cache ====================== Java Cache cleared successfully ==== C:\zoek_backup content ====================== C:\zoek_backup (files=6013 folders=1237 398326764 bytes) ==== Empty Temp Folders ====================== C:\Users\Administrator\AppData\Local\Temp emptied successfully C:\Users\Default\AppData\Local\Temp emptied successfully C:\Users\Default User\AppData\Local\Temp emptied successfully C:\Users\gebruiker\AppData\Local\Temp will be emptied at reboot C:\WINDOWS\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully C:\WINDOWS\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully C:\WINDOWS\Temp will be emptied at reboot ==== After Reboot ====================== ==== Empty Temp Folders ====================== C:\WINDOWS\Temp successfully emptied C:\Users\GEBRUI~1\AppData\Local\Temp successfully emptied ==== Empty Recycle Bin ====================== C:\$RECYCLE.BIN successfully emptied ==== EOF on di 20-01-2015 at 19:37:04,01 ======================