Zoek.exe v5.0.0.0 Updated 18-01-2015 Tool run by Johan on zo 25/01/2015 at 10:15:28,48. Microsoft® Windows Vista™ Home Premium 6.0.6002 Service Pack 2 x64 Running in: Normal Mode Internet Access Detected Launched: C:\Users\Johan\Desktop\zoek.exe [Scan all users] [Script inserted] ==== System Restore Info ====================== 25/01/2015 10:17:44 Zoek.exe System Restore Point Created Succesfully. ==== Empty Folders Check ====================== C:\PROGRA~2\Hewlett-Packard deleted successfully C:\PROGRA~3\Malwarebytes' Anti-Malware (portable) deleted successfully C:\Users\Johan\AppData\Roaming\HpUpdate deleted successfully C:\Users\Johan\AppData\Roaming\IBKPRO deleted successfully C:\Users\Johan\AppData\Local\Viber deleted successfully ==== Deleting CLSID Registry Keys ====================== HKEY_USERS\S-1-5-21-1594584551-1216520639-2605066923-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DDE87865-83C5-48c4-8357-2F5B1AA84522} deleted successfully HKEY_USERS\S-1-5-21-1594584551-1216520639-2605066923-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{DDE87865-83C5-48c4-8357-2F5B1AA84522} deleted successfully HKEY_USERS\S-1-5-21-1594584551-1216520639-2605066923-1000\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233} deleted successfully HKEY_USERS\S-1-5-21-1594584551-1216520639-2605066923-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233} deleted successfully HKEY_USERS\S-1-5-21-1594584551-1216520639-2605066923-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{95B7759C-8C7F-4BF1-B163-73684A933233} deleted successfully HKEY_USERS\S-1-5-21-1594584551-1216520639-2605066923-1000\Software\Microsoft\Internet Explorer\Explorer Bars\{555D4D79-4BD2-4094-A395-CFC534424A05} deleted successfully HKEY_USERS\S-1-5-21-1594584551-1216520639-2605066923-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{555D4D79-4BD2-4094-A395-CFC534424A05} deleted successfully HKEY_USERS\S-1-5-21-1594584551-1216520639-2605066923-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{555D4D79-4BD2-4094-A395-CFC534424A05} deleted successfully HKEY_USERS\S-1-5-21-1594584551-1216520639-2605066923-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F4E39681-15F8-4fda-B8A3-B5C98378F2F3} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Extensions\{DDE87865-83C5-48c4-8357-2F5B1AA84522} deleted successfully HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233} deleted successfully ==== Deleting CLSID Registry Values ====================== HKEY_USERS\S-1-5-21-1594584551-1216520639-2605066923-1000\Software\Mozilla\Firefox\Extensions\smartwebprinting@hp.com deleted successfully HKEY_LOCAL_MACHINE\software\Wow6432Node\mozilla\Firefox\extensions\smartwebprinting@hp.com deleted successfully ==== Deleting Services ====================== HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\vToolbarUpdater18.1.10 deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\vToolbarUpdater18.1.10 deleted successfully ==== FireFox Fix ====================== ProfilePath: C:\Users\Johan\AppData\Roaming\Mozilla\Firefox\Profiles\pou3u1fa.default user.js not found ---- Lines ask.com removed from prefs.js ---- user_pref("avg.wtu.ext.setting_hp_list", "[{\"name\":\"AVG Secure Search\",\"value\":\"https://mysearch.avg.com\"},{\"name\":\"Google\",\"value\":\"ht ---- Lines mysearch removed from prefs.js ---- user_pref("avg.wtu.ext.extHomepage", "https://mysearch.avg.com?pid=wtu&sg=&cid=%7B5d86f225-eb52-4673-a01a-30a5bed11f35%7D&mid=9069acad751147d3a692d16b ---- Lines offers removed from prefs.js ---- user_pref("smi2bar002_002.leadsCatTimestampCountClickOffers", ""); user_pref("smi2bar002_002.leadsCatTimestampCountOffers", ""); ---- Lines smartwebprinting@hp.com removed from prefs.js ---- user_pref("extensions.smartwebprinting@hp.com.install-event-fired", true); ---- FireFox user.js and prefs.js backups ---- prefs_20152501_1029_.backup ==== Deleting Files \ Folders ====================== C:\PROGRA~3\Malwarebytes' Anti-Malware (portable) not found C:\Windows\syswow64\appdata deleted C:\Users\Johan\AppData\Local\AVG Web TuneUp deleted C:\PROGRA~2\Mozilla Firefox\browser\searchplugins\wtu-secure-search.xml deleted C:\PROGRA~2\Your Uninstaller! 7 deleted C:\Users\Johan\AppData\Roaming\burnaware.ini deleted C:\PROGRA~3\AVG Web TuneUp deleted C:\PROGRA~3\Avg_Update_1214tb deleted C:\PROGRA~3\AVG Security Toolbar deleted C:\PROGRA~3\AVG Secure Search deleted C:\Users\Johan\AppData\Local\edsinstaller.txt-20091202.log deleted C:\Users\Johan\AppData\LocalLow\AVG Web TuneUp deleted C:\Windows\sysWoW64\config\systemprofile\AppData\LocalLow\AVG Web TuneUp deleted C:\Windows\tasks\1214tbUpdateInfo.job deleted C:\windows\SysNative\tasks\1214tbUpdateInfo deleted C:\windows\SysNative\GroupPolicy\Machine deleted C:\windows\SysNative\GroupPolicy\User deleted C:\windows\SysNative\GroupPolicy\gpt.ini deleted C:\Users\Johan\AppData\Roaming\Mozilla\Firefox\Profiles\pou3u1fa.default\searchplugins\avg-secure-search.xml deleted "C:\PROGRA~2\AVG Web TuneUp\TBAPI.dll" deleted "C:\PROGRA~2\AVG Web TuneUp\vprot.exe" deleted "C:\PROGRA~2\COMMON~1\AVG Secure Search\DNTInstaller\18.1.10\avgdttbx.dll" deleted "C:\PROGRA~2\COMMON~1\AVG Secure Search\vToolbarUpdater\18.1.10\log4cplusU.dll" deleted "C:\PROGRA~2\AVG Web TuneUp" not deleted "C:\PROGRA~2\COMMON~1\AVG Secure Search" deleted "C:\PROGRA~2\COMMON~1\AVG Secure Search\DNTInstaller" deleted "C:\PROGRA~2\COMMON~1\AVG Secure Search\vToolbarUpdater" deleted "C:\PROGRA~2\COMMON~1\AVG Secure Search\DNTInstaller\18.1.10" deleted "C:\PROGRA~2\COMMON~1\AVG Secure Search\vToolbarUpdater\18.1.10" deleted ==== Files Recently Created / Modified ====================== ====== C:\Windows ==== 2015-01-18 19:35:34 F042EE4C8D66248D9B86DCF52ABAE416 256000 ----a-w- C:\Windows\PEV.exe 2015-01-18 19:35:34 9E05A9C264C8A908A8E79450FCBFF047 80412 ----a-w- C:\Windows\grep.exe 2015-01-18 19:35:34 5E832F4FAF5F481F2EAF3B3A48F603B8 68096 ----a-w- C:\Windows\zip.exe 2015-01-18 19:35:34 0297C72529807322B152F517FDB0A9FC 406528 ----a-w- C:\Windows\SWSC.exe 2015-01-18 19:35:34 0277C027A26428DB64EF4F64F52BB4FD 208896 ----a-w- C:\Windows\MBR.exe 2015-01-18 16:05:38 FE102874BE6F3115FF866A86A0EF4B22 131070 ------w- C:\Windows\hpqins00.dat.temp ====== C:\Users\Johan\AppData\Local\Temp ==== 2015-01-20 10:32:23 E80E26EBA7A918A136A36C497C7210F7 647168 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\util\ccc\PrintUtil.exe 2015-01-20 10:32:23 D03D10F7DED688FECF50F8FBF1EA9B8A 49920 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\drivers\dot4\win2000\hpzid412.sys 2015-01-20 10:32:23 BEFF67900D8641C6EDF2AC056669155D 134048 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\util\ccc\nld\Q283787_W2K_SP3_x86.EXE 2015-01-20 10:32:23 B76FDD8EC7120474E7BC9CAD400DAC6C 187392 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\drivers\dot4\amd64\winxp\hpzid412.sys 2015-01-20 10:32:23 B19A7590062683F02AA0593C65971726 50424 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\drivers\dot4\win2000\hpzs2k12.sys 2015-01-20 10:32:23 AFBDCE5DED406D095E9081DE7CA8E9B8 29696 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\drivers\dot4\amd64\winxp\hpzisc12.sys 2015-01-20 10:32:23 ABCB05CCDBF03000354B9553820E39F8 21568 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\drivers\dot4\win2000\hpzius12.sys 2015-01-20 10:32:23 9CD648066485F67A9A986058AD473DCC 545280 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\setup\usbready.exe 2015-01-20 10:32:23 9C64E107BCB20D9572F536107C90076C 352032 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\util\ccc\nld\WindowsXP-KB822603-x86-NLD.exe 2015-01-20 10:32:23 9B28887500DB96A433C9C9DED8FDC886 48640 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\drivers\dot4\amd64\winxp\hpzipr12.sys 2015-01-20 10:32:23 89F41658929393487B6B7D13C8528CE3 16496 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\drivers\dot4\win2000\hpzipr12.sys 2015-01-20 10:32:23 50FE01D0C502F3962843E9E70294C4D7 9712 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\drivers\dot4\win2000\hpzisc12.sys 2015-01-20 10:32:23 2543E557F686846F834BB4E212BE429F 513360 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\setup.exe 2015-01-20 10:32:23 0A57B5876530FEBB4EBF6AD501864F96 16800 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\drivers\dot4\winxp\hppaufd0.sys 2015-01-20 10:32:23 0013DD74CD20EBFB8C816D9DF7413D91 50688 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\drivers\dot4\amd64\winxp\hpzius12.sys 2015-01-20 10:32:22 F883D4A76DAF2D482AA1BC91BBC8C1B7 5009408 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\setup\HPZnui01.exe 2015-01-20 10:32:22 F872CC086000B64048F00A9D154CD813 460120 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\setup\HPZpsc01.exe 2015-01-20 10:32:22 F81E23DAE9822C3FCDD0E33EA5A03598 365912 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\setup\HPZnop01.exe 2015-01-20 10:32:22 F60606A88E77D062E76624DF1ED3B8C2 488792 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\setup\HPZmsi01.exe 2015-01-20 10:32:22 F3CD0459650E4C9AEF8F208C949F110B 374104 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\setup\HPZprl01.exe 2015-01-20 10:32:22 F159DDE6C148109E1C3BBA3C9597A55D 738648 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\setup\HPZshl01.exe 2015-01-20 10:32:22 EF32AF449B0CC2290DC636CB787ED2D9 660824 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\setup\HPZrein01.exe 2015-01-20 10:32:22 D0EF61E0A6EB919BA51229D14C3EF5D5 1821008 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\setup\wis\win2k_xp\instmsi.exe 2015-01-20 10:32:22 CE5E1703C69F6F006FAACEBA29024BC5 370008 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\setup\HPZwis01.exe 2015-01-20 10:32:22 B312C3A0F7742A715C5BECA4FBDA3594 648536 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\setup\HPZsui01.exe 2015-01-20 10:32:22 AD12DA6A6D1D6A331E3F556F660D7455 713304 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\setup\HPZmsi40.exe 2015-01-20 10:32:22 A9EC8C36920151EFA6A9A887EE746753 368640 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\setup\HPZnet01.exe 2015-01-20 10:32:22 96FDF523D20ED9FCB8D2A3D2CA4164AE 365912 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\setup\HPZwrp01.exe 2015-01-20 10:32:22 9168DAE2B5097584E92D2353296A4004 378200 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\setup\HPZtim01.exe 2015-01-20 10:32:22 8FF549F2502F7D703EFCD5C962A169DE 5494784 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\setup\HPZnui40.exe 2015-01-20 10:32:22 8E84B28849D64C211D26755E3D133E07 398680 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\setup\HPZrcn01.exe 2015-01-20 10:32:22 67E4C2CA3108C62EE0CDF3144D3F5725 644440 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\hpzsetup.exe 2015-01-20 10:32:22 6380594FD3B5EF4DA5B92D832A5EA611 828760 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\setup\HPZrcv01.exe 2015-01-20 10:32:22 4CFBD579F08E41C31D431F49E287C5A0 410968 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\setup\HPZpnp01.exe 2015-01-20 10:32:22 402473595219CA965437368DA54689C3 701784 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\setup\HPZwup01.exe 2015-01-20 10:32:22 3CD8D774E625B99F562BEDA207AD0EF0 323584 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\setup\HPZnfx01.exe 2015-01-20 10:32:22 36EA650027D6D9499EC5238DE7CCC2C4 1161560 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\setup\HPZshl40.exe 2015-01-20 10:32:22 266D08A02362BCC82FAA03669FCCAA89 365912 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\setup\HPZgat01.exe 2015-01-20 10:32:22 2543E557F686846F834BB4E212BE429F 513360 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\HPZstub.exe 2015-01-20 10:32:22 1F97C24FB702FBE13D733BE8E2D45FCE 570200 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\setup\HPZpnp40.exe 2015-01-20 10:32:22 1E6DF93164F39E501EED387EA5426A1E 1227096 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\setup\HPZscr40.exe 2015-01-20 10:32:22 1C34B840DF2F13EE1DB9A94673782178 331776 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\setup\hpzfwx01.exe 2015-01-20 10:32:22 1A8612283FFC32FF33E2F0C4CE1F0560 398680 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\setup\HPZpsl01.exe 2015-01-20 10:32:22 165D539F53C90543B2FEC1CC37E31CE6 787800 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\setup\HPZscr01.exe 2015-01-20 10:32:22 09BB014EC6BB244D02E6DD2E9E1D5711 564568 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\setup\HPZprl40.exe 2015-01-20 10:32:22 08D70165C5EC5B9B4BF31BA32DF9CEAF 697688 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\setup\HPZopt01.exe 2015-01-20 10:32:21 FD2AC44F545AE9F8018CF694A54D6303 44032 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\setup\msxml3r.dll 2015-01-20 10:32:21 F6D9CBDFEB52FFF219FEBBA32A2DF926 339968 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\setup\InternetUtil.dll 2015-01-20 10:32:21 F2A437FFD9A409351166D0E08B95DC32 28672 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\setup\network_x64\hpzscbi1BPDUSB.dll 2015-01-20 10:32:21 F116846E14799DF4053563E25184D7A4 28160 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\setup\network_x86\hpzscbi0SmrtK.dll 2015-01-20 10:32:21 F112138581E2A9A92C8C978A0A4B3F48 505344 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\drivers\scanner\x64\hpovst12.dll 2015-01-20 10:32:21 EE57197A1EFE2B97E09DA2A0AD51F85B 796160 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\setup\scan\Scan.msi 2015-01-20 10:32:21 E8B9CF793325B7A2E2A41D504EE62C9D 370008 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\setup\HPZarp01.exe 2015-01-20 10:32:21 E27805D3776923AD4792260EF9D9859C 774144 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\util\ccc\CCC_Uninstaller.exe 2015-01-20 10:32:21 E1B25834CB9E9699E0DD69E645FBAB8D 303104 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\drivers\scanner\x32\hpovst12.dll 2015-01-20 10:32:21 E1A62F2ECB86C6EA11033CC8C9AD3FB3 315392 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\setup\RulesEngine.dll 2015-01-20 10:32:21 DEC55DE66A5ECF4FEDD46867B216E3F3 3060568 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\setup\HPZdui40.exe 2015-01-20 10:32:21 D89162CFC543CFFFBB6FC9438EB72BE7 286720 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\drivers\dot4\win2000\hpzc3212.dll 2015-01-20 10:32:21 D199B1ADFFB14070E8C4DA9E879EDBEE 309760 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\drivers\dot4\win2000\difxapi.dll 2015-01-20 10:32:21 CDCC63E967D64ECE3729246720AF4FCC 479232 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\setup\network_x86\msvcm80.dll 2015-01-20 10:32:21 C8F4FFFAC6D0890F914A287749181316 364544 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\drivers\dot4\win2000\hppldcoi.dll 2015-01-20 10:32:21 C6257C26D0A098AEB103CB419D6F2E92 359256 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\hpzids40.dll 2015-01-20 10:32:21 BF432805F8B48FE62A3674C23DD7BBD7 30208 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\setup\network_x64\hpzscb01.dll 2015-01-20 10:32:21 BE05E9C9C6D7C0EE215F77C4C01333BF 2762072 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\setup\HPZdui01.exe 2015-01-20 10:32:21 BA16A0A898BA93C2F113C7B034DF015A 516096 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\setup\network_x64\msvcm80.dll 2015-01-20 10:32:21 B62D7808AB8C080A6C16648E91F7DFB3 302592 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\setup\netdevicemanager64\NetDeviceManager64.msi 2015-01-20 10:32:21 B15F560DFABB749B77C4D2C029DFFA67 16384 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\setup\network_x64\hpzscbi259Nop.dll 2015-01-20 10:32:21 B036FF2F8FD1DBAE6F0F52FA384D3002 18560 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\hpzuci12.dll 2015-01-20 10:32:21 ADDE290ED5A7676B058660CB5654A328 282624 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\hpzc3212.dll 2015-01-20 10:32:21 AAB24E8EE59CD27A0D48D4B6936D85C2 208896 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\setup\HPCommunication.dll 2015-01-20 10:32:21 AA2414A031DDC50871878289147DC72D 81920 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\util\ccc\hpqrrx08.exe 2015-01-20 10:32:21 A6F2474446119F6A4F06D4B8AF051B58 1406464 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\drivers\scanner\x64\hpotiop5.dll 2015-01-20 10:32:21 A633C5C7A8714917D89E72680B12004C 192512 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\util\ccc\FixErr1714.exe 2015-01-20 10:32:21 A5EDE80F526EFB490032582BD64FAA0F 313856 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\setup\software_min\ps_aio_02_software_min.msi 2015-01-20 10:32:21 A0611CD67C8D8A4A43079BE68B694A07 1118720 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\setup\msxml3.dll 2015-01-20 10:32:21 9CF069B0C6A1855214AC977044368CA3 326136 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\setup\toolbox\Toolbox.msi 2015-01-20 10:32:21 9C7A6F6E906A8E1115932B686AFD865A 524272 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\setup\x64\DIFxAPI.dll 2015-01-20 10:32:21 9B6CBB8C9BEB0E250A5983C41756D76C 729088 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\drivers\scanner\x32\hpowiax5.dll 2015-01-20 10:32:21 95F509896ECE127A557D3B9C58686685 13824 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\setup\network_x86\hpzscbi259Nop.dll 2015-01-20 10:32:21 84391B0634316538B9101E7146F3F156 242896 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\util\ccc\AccessDeniedUtility.exe 2015-01-20 10:32:21 824350E57498707D748153669E0A2F13 229376 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\drivers\scanner\x64\hpotpusd.dll 2015-01-20 10:32:21 8067F03474A3CF21E8FDA084C74FC33D 177152 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\setup\qfolder\QFolder.msi 2015-01-20 10:32:21 801E6A05397B1B07E199917CE7B44123 81920 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\setup\HPScripting.dll 2015-01-20 10:32:21 74EE667C18CBDDC8D10828DC954B39B5 970752 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\drivers\scanner\x32\hpotiop5.dll 2015-01-20 10:32:21 6F78EFBDC26AEFCB8F8435DCBB0BC31C 24064 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\setup\network_x86\hpzscbi1BPDUSB.dll 2015-01-20 10:32:21 6D17D727CB0D839A7F1799885CD3E5C0 123904 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\setup\network_x86\hpzscbi2Snmp.dll 2015-01-20 10:32:21 6C828CF61FC1AF7D62641F3D966C61AC 180736 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\setup\network_x64\hpzscbi2Snmp.dll 2015-01-20 10:32:21 6AA688FC42167E4AA39759E727D0467B 398680 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\setup\HPZcdl01.exe 2015-01-20 10:32:21 6AA0D62B4D20F3F81F3EC54516F8D6A0 319984 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\setup\difxapi.dll 2015-01-20 10:32:21 67D986BA233AA5670E3E48BE1AA02E1B 481280 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\drivers\dot4\amd64\winxp\hppldcoi.x64.dll 2015-01-20 10:32:21 64F7E836866B3878B63D377F975FC4A1 508928 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\drivers\dot4\amd64\winxp\difxapi.dll 2015-01-20 10:32:21 6050BCC1B23F3DF7A1876CBDCBAC8232 401462 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\setup\msvcp60.dll 2015-01-20 10:32:21 5FEFD614BBD3FFA3712B172F70B1FDE2 24576 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\setup\msxml3a.dll 2015-01-20 10:32:21 5CF74CFAE1FB5CC520CA6F677F5C899B 176128 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\setup\InstallMetrics.dll 2015-01-20 10:32:21 5AE0F01F02A03558DA0CBD249E4DF263 1097728 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\setup\network_x64\msvcp80.dll 2015-01-20 10:32:21 53F2DC1F776B25C8976E04B2C988CEF6 271704 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\hpzids01.dll 2015-01-20 10:32:21 4D82D94BC8F841A86BE496FE0902CD3F 487424 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\setup\network_x86\hpzscbi257usw.dll 2015-01-20 10:32:21 4884EE0D811B59348280087B6815E3A9 938496 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\drivers\scanner\x64\hpowiax5.dll 2015-01-20 10:32:21 465CEBD7DA2CEABA5E552FC9118A1415 822784 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\setup\network_x64\msvcr80.dll 2015-01-20 10:32:21 43306B1DD9D5BE4CD1433765A76CC8DC 376832 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\setup\DocCD.exe 2015-01-20 10:32:21 3D0FBEE8B16266CF068B15ABFCCCBC0B 36864 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\setup\network_x64\hpzscbi0SmrtK.dll 2015-01-20 10:32:21 341F935C38A0FCA593396EBB4C7D9E3E 540672 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\drivers\dot4\amd64\winxp\hppldcoi.dll 2015-01-20 10:32:21 313DD5F92D006121B63AE8A6083EC79B 872448 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\setup\network_x64\hpzscbi257usw.dll 2015-01-20 10:32:21 2BC650257FB0867ABD54FD460EC2BAFC 548864 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\setup\network_x86\msvcp80.dll 2015-01-20 10:32:21 2477F6A112D5CB85CCFBF1086A62F133 767320 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\setup\HPZchk01.exe 2015-01-20 10:32:21 1ACA1B8F4D4102F2D5D646593E607375 237568 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\drivers\scanner\x32\hpotpusd.dll 2015-01-20 10:32:21 19D335420C8943FADE12D575CF662940 319488 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\setup\HPeDiag.dll 2015-01-20 10:32:21 16D7DDF3B659F7CF1CB9F4DCFF4219F0 626688 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\setup\network_x86\msvcr80.dll 2015-01-20 10:32:21 15CB1487972AF0E7EDCF954BE4BD10F5 124016 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\setup\HPeSupport.dll 2015-01-20 10:32:21 0FB6367DB05A86B4B8850B881C54BB83 229376 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\drivers\scanner\x32\hpotsti1.dll 2015-01-20 10:32:21 09BB547FCF62B85C5A822F0EAB4CD059 22528 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\setup\network_x86\hpzscb01.dll 2015-01-20 10:32:20 F2F64D36815AC461A11115794E99CABC 505856 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\drivers\dot4\wrapper\cioum64.msi 2015-01-20 10:32:20 D6E3631E857F03C921B15534E5F8390D 312832 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\drivers\dot4\wrapper\cioum32.msi 2015-01-20 10:32:20 9C58F2F2569CC1174A8574A016BB0566 302592 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\setup\netdevicemanager\NetDeviceManager.msi ====== Java Cache ===== ====== C:\Windows\SysWOW64 ===== 2015-01-14 16:34:17 66BCFB248EF26CABCD955FB27A7D439B 93184 ----a-w- C:\Windows\SysWOW64\ncsi.dll 2015-01-14 16:34:17 16D4D2D721E6DB8518225A37674163F8 48640 ----a-w- C:\Windows\SysWOW64\nlaapi.dll ====== C:\Windows\SysWOW64\drivers ===== ====== C:\Windows\Sysnative ===== 2015-01-14 16:34:17 F0BD3A3E8E56866BFC9E5754C8401686 61440 ----a-w- C:\Windows\Sysnative\nlaapi.dll 2015-01-14 16:34:17 9DC33E66BB7E6470BFE8AA9EF5FBED43 205824 ----a-w- C:\Windows\Sysnative\nlasvc.dll 2015-01-14 16:34:12 EF321BEED9CF3DF60EBA29A1D618AD8A 178688 ----a-w- C:\Windows\Sysnative\profsvc.dll ====== C:\Windows\Sysnative\drivers ===== 2015-01-14 16:39:48 F0142D3C0505B1B6DB8591A49C005C16 139776 ----a-w- C:\Windows\Sysnative\drivers\mrxdav.sys ====== C:\Windows\Tasks ====== 2015-01-17 15:09:55 C0DF04B8BBB05E4EEC1D69C6D587ADA7 3102 ----a-w- C:\Windows\Sysnative\Tasks\{F5FE0AF3-3327-468E-A53C-8C764EA45D04} 2015-01-17 08:16:26 D6DB214401AC849D866D1F4FFC680CF3 3030 ----a-w- C:\Windows\Sysnative\Tasks\{41814B30-1F75-421F-B7F4-66776A4F0755} ====== C:\Windows\Temp ====== ======= C:\Program Files ===== ======= C:\PROGRA~2 ===== 2015-01-20 10:35:39 -------- d-----w- C:\PROGRA~2\COMMON~1\HP 2015-01-14 19:48:07 -------- d-----w- C:\PROGRA~2\HP ======= C: ===== 2015-01-20 05:33:24 14B9D882551EC9FFB3C51A7D94C4266C 333257 --sha-r- C:\bootmgr ====== C:\Users\Johan\AppData\Roaming ====== 2015-01-18 19:51:12 -------- d-----w- C:\Users\Public\AppData\Local\temp 2015-01-18 19:51:12 -------- d-----w- C:\Users\Default\AppData\Local\temp 2015-01-18 19:51:12 -------- d-----w- C:\Users\Default User\AppData\Local\temp ====== C:\Users\Johan ====== 2015-01-23 16:24:47 8045ABB21A3BDD66A48E1ED5C0F0EF6A 1222144 ----a-w- C:\Users\Johan\Desktop\RSITx64.exe ====== C: exe-files == 2015-01-23 16:24:47 8045ABB21A3BDD66A48E1ED5C0F0EF6A 1222144 ----a-w- C:\Users\Johan\Desktop\RSITx64.exe 2015-01-20 10:33:38 F81E23DAE9822C3FCDD0E33EA5A03598 365912 ----a-w- C:\Program Files (x86)\HP\Digital Imaging\{86D3D561-D1FD-4d57-8395-20030467E0F9}\setup\hpznop01.exe 2015-01-20 10:33:38 F60606A88E77D062E76624DF1ED3B8C2 488792 ----a-w- C:\Program Files (x86)\HP\Digital Imaging\{86D3D561-D1FD-4d57-8395-20030467E0F9}\setup\hpzmsi01.exe 2015-01-20 10:33:38 DEC55DE66A5ECF4FEDD46867B216E3F3 3060568 ----a-w- C:\Program Files (x86)\HP\Digital Imaging\{86D3D561-D1FD-4d57-8395-20030467E0F9}\setup\hpzdui40.exe 2015-01-20 10:33:38 8E84B28849D64C211D26755E3D133E07 398680 ----a-w- C:\Program Files (x86)\HP\Digital Imaging\{86D3D561-D1FD-4d57-8395-20030467E0F9}\setup\hpzrcn01.exe 2015-01-20 10:33:38 6AA688FC42167E4AA39759E727D0467B 398680 ----a-w- C:\Program Files (x86)\HP\Digital Imaging\{86D3D561-D1FD-4d57-8395-20030467E0F9}\setup\hpzcdl01.exe 2015-01-20 10:33:38 67E4C2CA3108C62EE0CDF3144D3F5725 644440 ----a-w- C:\Program Files (x86)\HP\Digital Imaging\{86D3D561-D1FD-4d57-8395-20030467E0F9}\hpzsetup.exe 2015-01-20 10:33:38 2543E557F686846F834BB4E212BE429F 513360 ----a-w- C:\Program Files (x86)\HP\Digital Imaging\{86D3D561-D1FD-4d57-8395-20030467E0F9}\hpzstub.exe 2015-01-20 10:33:38 1E6DF93164F39E501EED387EA5426A1E 1227096 ----a-w- C:\Program Files (x86)\HP\Digital Imaging\{86D3D561-D1FD-4d57-8395-20030467E0F9}\setup\hpzscr40.exe 2015-01-20 10:33:38 1A8612283FFC32FF33E2F0C4CE1F0560 398680 ----a-w- C:\Program Files (x86)\HP\Digital Imaging\{86D3D561-D1FD-4d57-8395-20030467E0F9}\setup\hpzpsl01.exe 2015-01-20 10:33:34 F60606A88E77D062E76624DF1ED3B8C2 488792 ----a-w- C:\Program Files (x86)\HP\Temp\{86D3D561-D1FD-4d57-8395-20030467E0F9}\setup\hpzmsi01.exe 2015-01-20 10:33:34 6380594FD3B5EF4DA5B92D832A5EA611 828760 ----a-w- C:\Program Files (x86)\HP\Temp\{86D3D561-D1FD-4d57-8395-20030467E0F9}\setup\hpzrcv01.exe 2015-01-20 10:33:34 2543E557F686846F834BB4E212BE429F 513360 ----a-w- C:\Program Files (x86)\HP\Temp\{86D3D561-D1FD-4d57-8395-20030467E0F9}\setup\hpzstub.exe 2015-01-20 10:33:34 1F97C24FB702FBE13D733BE8E2D45FCE 570200 ----a-w- C:\Program Files (x86)\HP\Digital Imaging\{86D3D561-D1FD-4d57-8395-20030467E0F9}\setup\hpzpnp40.exe 2015-01-20 10:33:34 1E6DF93164F39E501EED387EA5426A1E 1227096 ----a-w- C:\Program Files (x86)\HP\Temp\{86D3D561-D1FD-4d57-8395-20030467E0F9}\setup\hpzscr40.exe 2015-01-20 10:32:23 E80E26EBA7A918A136A36C497C7210F7 647168 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\util\ccc\PrintUtil.exe 2015-01-20 10:32:23 BEFF67900D8641C6EDF2AC056669155D 134048 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\util\ccc\nld\Q283787_W2K_SP3_x86.EXE 2015-01-20 10:32:23 9CD648066485F67A9A986058AD473DCC 545280 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\setup\usbready.exe 2015-01-20 10:32:23 9C64E107BCB20D9572F536107C90076C 352032 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\util\ccc\nld\WindowsXP-KB822603-x86-NLD.exe 2015-01-20 10:32:23 2543E557F686846F834BB4E212BE429F 513360 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\setup.exe 2015-01-20 10:32:22 F883D4A76DAF2D482AA1BC91BBC8C1B7 5009408 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\setup\HPZnui01.exe 2015-01-20 10:32:22 F872CC086000B64048F00A9D154CD813 460120 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\setup\HPZpsc01.exe 2015-01-20 10:32:22 F81E23DAE9822C3FCDD0E33EA5A03598 365912 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\setup\HPZnop01.exe 2015-01-20 10:32:22 F60606A88E77D062E76624DF1ED3B8C2 488792 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\setup\HPZmsi01.exe 2015-01-20 10:32:22 F3CD0459650E4C9AEF8F208C949F110B 374104 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\setup\HPZprl01.exe 2015-01-20 10:32:22 F159DDE6C148109E1C3BBA3C9597A55D 738648 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\setup\HPZshl01.exe 2015-01-20 10:32:22 EF32AF449B0CC2290DC636CB787ED2D9 660824 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\setup\HPZrein01.exe 2015-01-20 10:32:22 D0EF61E0A6EB919BA51229D14C3EF5D5 1821008 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\setup\wis\win2k_xp\instmsi.exe 2015-01-20 10:32:22 CE5E1703C69F6F006FAACEBA29024BC5 370008 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\setup\HPZwis01.exe 2015-01-20 10:32:22 B312C3A0F7742A715C5BECA4FBDA3594 648536 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\setup\HPZsui01.exe 2015-01-20 10:32:22 AD12DA6A6D1D6A331E3F556F660D7455 713304 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\setup\HPZmsi40.exe 2015-01-20 10:32:22 A9EC8C36920151EFA6A9A887EE746753 368640 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\setup\HPZnet01.exe 2015-01-20 10:32:22 96FDF523D20ED9FCB8D2A3D2CA4164AE 365912 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\setup\HPZwrp01.exe 2015-01-20 10:32:22 9168DAE2B5097584E92D2353296A4004 378200 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\setup\HPZtim01.exe 2015-01-20 10:32:22 8FF549F2502F7D703EFCD5C962A169DE 5494784 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\setup\HPZnui40.exe 2015-01-20 10:32:22 8E84B28849D64C211D26755E3D133E07 398680 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\setup\HPZrcn01.exe 2015-01-20 10:32:22 67E4C2CA3108C62EE0CDF3144D3F5725 644440 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\hpzsetup.exe 2015-01-20 10:32:22 6380594FD3B5EF4DA5B92D832A5EA611 828760 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\setup\HPZrcv01.exe 2015-01-20 10:32:22 4CFBD579F08E41C31D431F49E287C5A0 410968 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\setup\HPZpnp01.exe 2015-01-20 10:32:22 402473595219CA965437368DA54689C3 701784 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\setup\HPZwup01.exe 2015-01-20 10:32:22 3CD8D774E625B99F562BEDA207AD0EF0 323584 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\setup\HPZnfx01.exe 2015-01-20 10:32:22 36EA650027D6D9499EC5238DE7CCC2C4 1161560 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\setup\HPZshl40.exe 2015-01-20 10:32:22 266D08A02362BCC82FAA03669FCCAA89 365912 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\setup\HPZgat01.exe 2015-01-20 10:32:22 2543E557F686846F834BB4E212BE429F 513360 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\HPZstub.exe 2015-01-20 10:32:22 1F97C24FB702FBE13D733BE8E2D45FCE 570200 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\setup\HPZpnp40.exe 2015-01-20 10:32:22 1E6DF93164F39E501EED387EA5426A1E 1227096 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\setup\HPZscr40.exe 2015-01-20 10:32:22 1C34B840DF2F13EE1DB9A94673782178 331776 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\setup\hpzfwx01.exe 2015-01-20 10:32:22 1A8612283FFC32FF33E2F0C4CE1F0560 398680 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\setup\HPZpsl01.exe 2015-01-20 10:32:22 165D539F53C90543B2FEC1CC37E31CE6 787800 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\setup\HPZscr01.exe 2015-01-20 10:32:22 09BB014EC6BB244D02E6DD2E9E1D5711 564568 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\setup\HPZprl40.exe 2015-01-20 10:32:22 08D70165C5EC5B9B4BF31BA32DF9CEAF 697688 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\setup\HPZopt01.exe 2015-01-20 10:32:21 E8B9CF793325B7A2E2A41D504EE62C9D 370008 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\setup\HPZarp01.exe 2015-01-20 10:32:21 E27805D3776923AD4792260EF9D9859C 774144 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\util\ccc\CCC_Uninstaller.exe 2015-01-20 10:32:21 DEC55DE66A5ECF4FEDD46867B216E3F3 3060568 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\setup\HPZdui40.exe 2015-01-20 10:32:21 BE05E9C9C6D7C0EE215F77C4C01333BF 2762072 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\setup\HPZdui01.exe 2015-01-20 10:32:21 AA2414A031DDC50871878289147DC72D 81920 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\util\ccc\hpqrrx08.exe 2015-01-20 10:32:21 A633C5C7A8714917D89E72680B12004C 192512 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\util\ccc\FixErr1714.exe 2015-01-20 10:32:21 84391B0634316538B9101E7146F3F156 242896 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\util\ccc\AccessDeniedUtility.exe 2015-01-20 10:32:21 6AA688FC42167E4AA39759E727D0467B 398680 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\setup\HPZcdl01.exe 2015-01-20 10:32:21 43306B1DD9D5BE4CD1433765A76CC8DC 376832 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\setup\DocCD.exe 2015-01-20 10:32:21 2477F6A112D5CB85CCFBF1086A62F133 767320 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\setup\HPZchk01.exe 2015-01-19 08:04:56 5F7AE768CDD6E925A57E68D527101980 715038 ----a-w- C:\Program Files (x86)\GrabIt\unins000.exe 2015-01-18 19:35:34 F042EE4C8D66248D9B86DCF52ABAE416 256000 ----a-w- C:\Windows\PEV.exe 2015-01-18 19:35:34 9E05A9C264C8A908A8E79450FCBFF047 80412 ----a-w- C:\Windows\grep.exe 2015-01-18 19:35:34 5E832F4FAF5F481F2EAF3B3A48F603B8 68096 ----a-w- C:\Windows\zip.exe 2015-01-18 19:35:34 0297C72529807322B152F517FDB0A9FC 406528 ----a-w- C:\Windows\SWSC.exe 2015-01-18 19:35:34 0277C027A26428DB64EF4F64F52BB4FD 208896 ----a-w- C:\Windows\MBR.exe 2015-01-18 16:06:06 FC7023A0E2888477C83F2077E29A1B48 1140056 ----a-w- C:\Program Files (x86)\HP\Temp\{0E720B4A-B82A-474c-B95E-D7778590090D}\setup\hpzmsi01.exe 2015-01-18 16:06:06 F912ACCA19F66B019632ADB4BC704A10 513360 ----a-w- C:\Program Files (x86)\HP\Temp\{0E720B4A-B82A-474c-B95E-D7778590090D}\setup\setup.exe 2015-01-18 16:06:06 4E275A777F1104804A46D61389A040BE 1123672 ----a-w- C:\Program Files (x86)\HP\Temp\{0E720B4A-B82A-474c-B95E-D7778590090D}\setup\hpzscr01.exe 2015-01-18 16:06:06 42095155F79BB77F68E19F179454BF19 1250648 ----a-w- C:\Program Files (x86)\HP\Temp\{0E720B4A-B82A-474c-B95E-D7778590090D}\setup\hpzrcv01.exe 2015-01-18 15:57:20 CF03C8F6F6B0D71F6E5BCE167FCF7CA6 214360 ----a-w- C:\Users\Johan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\hpqtra08.exe === C: other files == 2015-01-20 10:32:23 D03D10F7DED688FECF50F8FBF1EA9B8A 49920 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\drivers\dot4\win2000\hpzid412.sys 2015-01-20 10:32:23 B76FDD8EC7120474E7BC9CAD400DAC6C 187392 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\drivers\dot4\amd64\winxp\hpzid412.sys 2015-01-20 10:32:23 B19A7590062683F02AA0593C65971726 50424 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\drivers\dot4\win2000\hpzs2k12.sys 2015-01-20 10:32:23 AFBDCE5DED406D095E9081DE7CA8E9B8 29696 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\drivers\dot4\amd64\winxp\hpzisc12.sys 2015-01-20 10:32:23 ABCB05CCDBF03000354B9553820E39F8 21568 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\drivers\dot4\win2000\hpzius12.sys 2015-01-20 10:32:23 9B28887500DB96A433C9C9DED8FDC886 48640 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\drivers\dot4\amd64\winxp\hpzipr12.sys 2015-01-20 10:32:23 89F41658929393487B6B7D13C8528CE3 16496 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\drivers\dot4\win2000\hpzipr12.sys 2015-01-20 10:32:23 50FE01D0C502F3962843E9E70294C4D7 9712 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\drivers\dot4\win2000\hpzisc12.sys 2015-01-20 10:32:23 0A57B5876530FEBB4EBF6AD501864F96 16800 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\drivers\dot4\winxp\hppaufd0.sys 2015-01-20 10:32:23 0013DD74CD20EBFB8C816D9DF7413D91 50688 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\drivers\dot4\amd64\winxp\hpzius12.sys 2015-01-20 10:32:15 E7855040371CF790E6C338B307FABFA3 1027 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\util\ccc\Uninstall_L2.bat 2015-01-20 10:32:15 D7A23282F3659BA7BD02A8864287624D 1360 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\util\ccc\Uninstall_L4.bat 2015-01-20 10:32:15 ADF2BD5B1EE255908BD611E98E9B053F 1004 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\util\ccc\Uninstall_L3.bat 2015-01-20 10:32:15 8C1D07931AF68EF0F9C6155B46232237 24 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\util\ccc\collect.bat 2015-01-20 10:32:15 6834B00412ED16511E60DC87560679F0 88 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\util\ccc\hposcrlr.bat 2015-01-20 10:32:15 22AD123BBE50EFF7F9CA636BC6124760 1332 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\util\ccc\Uninstall.bat 2015-01-20 10:32:15 05CD32D48F1CD80542F0830067411C95 879 ----a-w- C:\Users\Johan\AppData\Local\Temp\7zS2D15\util\ccc\Uninstall_L1.bat ==== Startup Registry Enabled ====================== [HKEY_USERS\S-1-5-21-1594584551-1216520639-2605066923-1000\Software\Microsoft\Windows\CurrentVersion\Run] "ehTray.exe"="C:\Windows\ehome\ehTray.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "vProt"="C:\Program Files (x86)\AVG Web TuneUp\vprot.exe" "StartCCC"="C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe MSRun" "AVG_UI"="C:\Program Files (x86)\AVG\AVG2015\avgui.exe /TRAYONLY" "APSDaemon"="C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "ehTray.exe"="C:\Windows\ehome\ehTray.exe" ==== Startup Registry Enabled x64 ====================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RtHDVCpl"="RAVCpl64.exe" "OODefragTray"="C:\Windows\system32\oodtray.exe" ==== Startup Registry Disabled ====================== [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run-] "ehTray.exe"="C:\\Windows\\ehome\\ehTray.exe" "Google Update"="\"C:\\Users\\Johan\\AppData\\Local\\Google\\Update\\GoogleUpdate.exe\" /c" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run-] "Adobe ARM"="\"C:\\Program Files (x86)\\Common Files\\Adobe\\ARM\\1.0\\AdobeARM.exe\"" "SunJavaUpdateSched"="\"C:\\Program Files (x86)\\Common Files\\Java\\Java Update\\jusched.exe\"" "QuickTime Task"="\"C:\\Program Files (x86)\\QuickTime\\QTTask.exe\" -atboottime" ==== Startup Registry Disabled x64 ====================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Acrobat Assistant 8.0] "key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="Acrobat Assistant 8.0" "hkey"="HKLM" "command"="\"C:\\Program Files (x86)\\Adobe\\Acrobat 11.0\\Acrobat\\Acrotray.exe\"" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Adobe ARM] "key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="Adobe ARM" "hkey"="HKLM" "command"="\"C:\\Program Files (x86)\\Common Files\\Adobe\\ARM\\1.0\\AdobeARM.exe\"" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\AdobeAAMUpdater-1.0] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="AdobeAAMUpdater-1.0" "hkey"="HKLM" "command"="\"C:\\Program Files (x86)\\Common Files\\Adobe\\OOBE\\PDApp\\UWA\\UpdaterStartupUtility.exe\"" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\AdobeCS4ServiceManager] "key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="AdobeCS4ServiceManager" "hkey"="HKLM" "command"="\"C:\\Program Files (x86)\\Common Files\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe\" -launchedbylogin" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Adobe_ID0ENQBO] "key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="Adobe_ID0ENQBO" "hkey"="HKLM" "command"="C:\\PROGRA~2\\COMMON~1\\Adobe\\ADOBEV~1\\Server\\bin\\VERSIO~2.EXE" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\CCleaner Monitoring] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="CCleaner Monitoring" "hkey"="HKCU" "command"="\"C:\\Program Files (x86)\\CCleaner\\CCleaner64.exe\" /MONITOR" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\HP Software Update] "key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="HP Software Update" "hkey"="HKLM" "command"="C:\\Program Files (x86)\\HP\\HP Software Update\\HPWuSchd2.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\hpqSRMon] "key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="hpqSRMon" "hkey"="HKLM" "command"="C:\\Program Files (x86)\\HP\\Digital Imaging\\bin\\hpqSRMon.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\NBAgent] "key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="NBAgent" "hkey"="HKLM" "command"="\"C:\\Program Files (x86)\\Nero\\Nero 10\\Nero BackItUp\\NBAgent.exe\" /WinStart" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\QuickTime Task] "key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="QuickTime Task" "hkey"="HKLM" "command"="\"C:\\Program Files (x86)\\QuickTime\\QTTask.exe\" -atboottime" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Skype] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="Skype" "hkey"="HKCU" "command"="\"C:\\Program Files (x86)\\Skype\\Phone\\Skype.exe\" /minimized /regrun" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\SpybotSD TeaTimer] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="SpybotSD TeaTimer" "hkey"="HKCU" "command"="C:\\Program Files (x86)\\Spybot - Search & Destroy\\TeaTimer.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\SUPERAntiSpyware] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="SUPERAntiSpyware" "hkey"="HKCU" "command"="C:\\Program Files\\SUPERAntiSpyware\\SUPERAntiSpyware.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk] "item"="HP Digital Imaging Monitor" "path"="C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\HP Digital Imaging Monitor.lnk" "backup"="C:\\Windows\\pss\\HP Digital Imaging Monitor.lnk.CommonStartup" "backupExtension"=".CommonStartup" "command"="C:\\PROGRA~2\\HP\\DIGITA~1\\bin\\hpqtra08.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Users^Johan^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 3.4.1.lnk] "item"="OpenOffice.org 3.4.1" "path"="C:\\Users\\Johan\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\OpenOffice.org 3.4.1.lnk" "backup"="C:\\Windows\\pss\\OpenOffice.org 3.4.1.lnk.Startup" "backupExtension"=".Startup" "command"="C:\\Program Files (x86)\\OpenOffice.org 3\\program\\quickstart.exe" ==== Startup Folders ====================== 2015-01-18 15:57:20 214360 ----a-w- C:\Users\Johan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\hpqtra08.exe 2015-01-18 15:57:21 1961 ----a-w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Install LastPass FF RunOnce.lnk 2015-01-18 15:57:21 1961 ----a-w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Install LastPass IE RunOnce.lnk 2015-01-18 15:57:21 928 ----a-w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\SmartCopy.lnk 2015-01-18 15:57:21 968 ----a-w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\SmartLauncher.lnk ==== Task Scheduler Jobs ====================== C:\Windows\tasks\Google Software Updater.job --a------ C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe [16/09/2011 10:24] C:\Windows\tasks\GoogleUpdateTaskMachineCore.job --a------ C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [17/06/2012 16:50] C:\Windows\tasks\GoogleUpdateTaskMachineUA.job --a------ C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [17/06/2012 16:50] C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1594584551-1216520639-2605066923-1000Core.job --a------ C:\Users\Johan\AppData\Local\Google\Update\GoogleUpdate.exe [21/10/2011 14:30] C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1594584551-1216520639-2605066923-1000UA.job --a------ C:\Users\Johan\AppData\Local\Google\Update\GoogleUpdate.exe [21/10/2011 14:30] ==== Other Scheduled Tasks ====================== "C:\Windows\SysNative\tasks\Ad-Aware Antivirus Scheduled Scan" [C:\PROGRA~2\AD-AWA~1\AdAwareLauncher.exe] "C:\Windows\SysNative\tasks\Ad-Aware Update (Weekly)" [C:\Program Files (x86)\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe] "C:\Windows\SysNative\tasks\Adobe Flash Player Updater" [C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe] "C:\Windows\SysNative\tasks\Adobe Reader and Acrobat Manager" [C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe] "C:\Windows\SysNative\tasks\Adobe-online actualiseringsprogramma" [C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe] "C:\Windows\SysNative\tasks\CCleanerSkipUAC" ["C:\Program Files (x86)\CCleaner\CCleaner.exe"] "C:\Windows\SysNative\tasks\Express Files Updater" [C:\Program Files (x86)\ExpressFiles\EFupdater.exe] "C:\Windows\SysNative\tasks\Google Software Updater" [C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe] "C:\Windows\SysNative\tasks\Google Updater and Installer" [C:\Users\Johan\AppData\Local\Google\Update\GoogleUpdate.exe] "C:\Windows\SysNative\tasks\GoogleUpdateTaskMachineCore" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe] "C:\Windows\SysNative\tasks\GoogleUpdateTaskMachineUA" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe] "C:\Windows\SysNative\tasks\GoogleUpdateTaskUserS-1-5-21-1594584551-1216520639-2605066923-1000Core" [C:\Users\Johan\AppData\Local\Google\Update\GoogleUpdate.exe] "C:\Windows\SysNative\tasks\GoogleUpdateTaskUserS-1-5-21-1594584551-1216520639-2605066923-1000UA" [C:\Users\Johan\AppData\Local\Google\Update\GoogleUpdate.exe] "C:\Windows\SysNative\tasks\HP-Online updateprogramma" [C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe] "C:\Windows\SysNative\tasks\Java Update Scheduler" [C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe] "C:\Windows\SysNative\tasks\TechSmith Updater" [C:\Program Files (x86)\Common Files\TechSmith Shared\Updater\TSCUpdClt.exe] "C:\Windows\SysNative\tasks\TuneUpUtilities_Task_BkGndMaintenance2013" [C:\Program Files (x86)\AVG\AVG PC TuneUp\OneClick.exe] "C:\Windows\SysNative\tasks\{235A85BA-6221-49AE-9A5C-66A99DFDD471}" [C:\Program Files (x86)\Skype\Phone\Skype.exe] "C:\Windows\SysNative\tasks\{E3DBB6A9-36E9-4034-9FAE-FBE726779179}" ["c:\program files (x86)\mozilla firefox\firefox.exe"] "C:\Windows\SysNative\tasks\Apple\AppleSoftwareUpdate" [C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe] "C:\Windows\SysNative\tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask" [%systemroot%\system32\sc.exe start osppsvc] ==== Firefox Start and Search pages ====================== ProfilePath: C:\Users\Johan\AppData\Roaming\Mozilla\Firefox\Profiles\pou3u1fa.default user_pref("browser.startup.homepage", "http://www.google.be/"); user_pref("browser.search.defaulturl", "https://www.google.com/search"); user_pref("browser.search.defaultengine", "Google"); user_pref("browser.search.selectedEngine", "AVG Secure Search"); user_pref("keyword.URL", "https://www.google.com/search"); ==== Firefox Extensions Registry ====================== [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions] "web2pdfextension@web2pdf.adobedotcom"="C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Browser\WCFirefoxExtn" [22/01/2014 18:04] ==== Firefox Extensions ====================== ProfilePath: C:\Users\Johan\AppData\Roaming\Mozilla\Firefox\Profiles\pou3u1fa.default - Adobe Acrobat - Create PDF - C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Browser\WCFirefoxExtn - Undetermined - {195A3098-0BD5-4e90-AE22-BA1C540AFD1E} - Undetermined - web2pdfextension@web2pdf.adobedotcom - Undetermined - support@lastpass.com - Undetermined - avg@toolbar - Undetermined - %ProfilePath%\extensions\5704458a1868deee20ca18ba9f31ec792e9c2a39fbe2160c901312f8fc97e3d8_lp.key - Undetermined - %ProfilePath%\extensions\5704458a1868deee20ca18ba9f31ec792e9c2a39fbe2160c901312f8fc97e3d8_lp.key - AVG Web TuneUp - %ProfilePath%\extensions\avg@toolbar - LastPass - %ProfilePath%\extensions\support@lastpass.com - Garmin Communicator - %ProfilePath%\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E} - Tab Mix Plus - %ProfilePath%\extensions\{dc572301-7619-498c-a57d-39143191b318}.xpi AppDir: C:\Program Files (x86)\Mozilla Firefox - Undetermined - %AppDir%\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} - Undetermined - %AppDir%\extensions\{B13721C7-F507-4982-B2E5-502A71474FED} - Undetermined - %AppDir%\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} - Undetermined - %AppDir%\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} - Java Console - %AppDir%\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} - Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} ==== Firefox Plugins ====================== Profilepath: C:\Users\Johan\AppData\Roaming\Mozilla\Firefox\Profiles\pou3u1fa.default 884705AD43780C86782935D5B1F1E4DE - C:\Users\Johan\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll - Google Talk Plugin Video Accelerator E85BC9AF3B4481B875F5A9BD73E8732F - C:\Users\Johan\AppData\Roaming\Mozilla\plugins\npo1d.dll - Google Talk Plugin Video Renderer 683B6A2376FA62A797A9DC83807CACA8 - C:\Users\Johan\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll - Google Talk Plugin CFAF7B67C78D09D79688AEDCA3D090E2 - C:\Users\Johan\AppData\Local\Google\Update\1.3.21.165\npGoogleUpdate3.dll - Google Update AB87EEFFD18F2BAAFC274E7075EA6C67 - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll - Windows Presentation Foundation / Windows Presentation Foundation ==== Deleted Firefox Extensions ====================== C:\Users\Johan\AppData\Roaming\Mozilla\Firefox\Profiles\pou3u1fa.default\extensions\avg@toolbar deleted ==== Chromium Look ====================== Google Chrome Version: 39.0.2171.99 (Up to date, latest Stable version: 39.0.2171.99) HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions efaidnbmnnnibpcajpcglclefindmkaj - C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Browser\WCChromeExtn\WCChromeExtn.crx[23/09/2012 20:43] Instant Notifications for Gmail - Johan\AppData\Local\Google\Chrome\User Data\Default\Extensions\adlgnpfgagimgadbaboilkbdnhbpegmd AVG Web TuneUp - Johan\AppData\Local\Google\Chrome\User Data\Default\Extensions\chfdnecihphmhljaaejmgoiahnihplgn Adobe Acrobat - Create PDF - Johan\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj Google Calendar - Johan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejjicmeblgpmajnghnpcppodonldlgfn Full Screen Weather - Johan\AppData\Local\Google\Chrome\User Data\Default\Extensions\fkkaebihfmbofclegkcfkkemepfehibg LastPass - Johan\AppData\Local\Google\Chrome\User Data\Default\Extensions\hdokiejnpimakedhajhdlcegeplioahd Google Mail Checker - Johan\AppData\Local\Google\Chrome\User Data\Default\Extensions\mihcahmgecmbnbcchbopgniflfhgnkff Google Wallet - Johan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda Gmail - Johan\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia ==== Chromium Fix ====================== C:\Users\Johan\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.olark.com_0.localstorage deleted successfully C:\Users\Johan\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.olark.com_0.localstorage-journal deleted successfully C:\Users\Johan\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_internetspeedtracker.dl.tb.ask.com_0.localstorage deleted successfully C:\Users\Johan\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_internetspeedtracker.dl.tb.ask.com_0.localstorage-journal deleted successfully C:\Users\Johan\AppData\Local\Google\Chrome\User Data\Default\Extensions\chfdnecihphmhljaaejmgoiahnihplgn deleted successfully C:\Users\Johan\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_chfdnecihphmhljaaejmgoiahnihplgn_0.localstorage deleted successfully C:\Users\Johan\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_chfdnecihphmhljaaejmgoiahnihplgn_0.localstorage-journal deleted successfully ==== Set IE to Default ====================== Old Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="https://www.google.be/" New Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="https://www.google.be/" ==== All HKCU SearchScopes ====================== HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes "DefaultScope"="{67A2568C-7A0A-4EED-AECC-B5405DE63B64}" {012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}" {0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC" {67A2568C-7A0A-4EED-AECC-B5405DE63B64} Google Url="http://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ACAW" ==== Reset Google Chrome ====================== C:\Users\Johan\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully C:\Users\Johan\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully ==== Deleting CLSID Registry Keys ====================== ==== Deleting CLSID Registry Values ====================== ==== shortcuts on Users Desktops ====================== C:\Users\Johan\Desktop\Internet Explorer (64-bit).lnk - C:\Program Files (x86)\Internet Explorer\iexplore.exe C:\Users\Johan\Desktop\Jaarkalender.lnk - S:\Allerlei\Backup\Backup Stick\Backups\Documenten\Jaarkalender.xls C:\Users\Johan\Desktop\OnderwegMetMotorhome.lnk - S:\Allerlei\Mobilhome\OnderwegMetMotorhome.xls ==== shortcuts in All Users Start Menu ====================== C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG\AVG 2015.lnk - C:\Program Files (x86)\AVG\AVG2015\avgui.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Garmin\BaseCamp (2D only).lnk - C:\Program Files (x86)\Garmin\BaseCamp\BaseCamp.exe /Disable3D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Garmin\BaseCamp.lnk - C:\Program Files (x86)\Garmin\BaseCamp\BaseCamp.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Garmin\MapInstall.lnk - C:\Garmin\Garmin\MapInstall.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Garmin\WebUpdater.lnk - C:\Garmin\WebUpdater\WebUpdater.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GrabIt\Changes.lnk - C:\Program Files (x86)\GrabIt\Changes.txt C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GrabIt\GrabIt.lnk - C:\Program Files (x86)\GrabIt\GrabIt.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GrabIt\License.lnk - C:\Program Files (x86)\GrabIt\License.txt C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GrabIt\Uninstall GrabIt.lnk - C:\Program Files (x86)\GrabIt\unins000.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JaVaWa\JaVaWa Device Manager\JaVaWa Device Manager.lnk - C:\Program Files (x86)\JaVaWa Device Manager\jdm.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JaVaWa\JaVaWa Device Manager\Verwijder JaVaWa Device Manager.lnk - C:\Program Files (x86)\JaVaWa Device Manager\unins000.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JaVaWa\JaVaWa GMTK\JaVaWa GMTK.lnk - C:\Program Files (x86)\JaVaWa GMTK\GMTK.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JaVaWa\JaVaWa GMTK\Verwijder JaVaWa GMTK.lnk - C:\Program Files (x86)\JaVaWa GMTK\unins000.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware\SUPERAntiSpyware Alternate Start.lnk - C:\Program Files\SUPERAntiSpyware\RUNSAS.EXE C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware\SUPERAntiSpyware Free Edition.lnk - C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware\SUPERAntiSpyware Registration-Activation.lnk - C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe /register C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TechSmith\Snagit 11 Editor.lnk - C:\Windows\Installer\{90D0FC4B-D653-4F49-BB97-A48C74A52E71}\Icon0E6ED661.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TechSmith\Snagit 11.lnk - C:\Windows\Installer\{90D0FC4B-D653-4F49-BB97-A48C74A52E71}\Icon0E6ED660.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Weerstation Online\Weerstation Online.lnk - C:\Program Files (x86)\nend software\Weerstation Online\Weerstation Online.exe ==== shortcuts in Quick Launch ====================== C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk - C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk - C:\Users\Default User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk - C:\Users\Default User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk - C:\Users\Johan\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Adobe Photoshop Elements 7.0.lnk - C:\Program Files (x86)\Adobe\Photoshop Elements 7.0\Photoshop Elements 7.0.exe C:\Users\Johan\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\BaseCamp.lnk - C:\Program Files (x86)\Garmin\BaseCamp\BaseCamp.exe C:\Users\Johan\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Belgacom Cloud.lnk - C:\Users\Johan\AppData\Local\F-Secure\Belgacom Cloud\Application\Belgacom Cloud.exe C:\Users\Johan\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Bureaublad tonen.lnk - C:\Users\Johan\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Bureaublad tonen.scf C:\Users\Johan\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Calculator.lnk - C:\Windows\system32\calc.exe C:\Users\Johan\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\DreamMail.lnk - C:\Program Files (x86)\DreamMail4\DM2005.exe C:\Users\Johan\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\EVEREST Ultimate Edition.lnk - C:\Program Files (x86)\Lavalys\EVEREST Ultimate Edition\everest.exe C:\Users\Johan\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\FlashFXP.lnk - C:\Program Files (x86)\FlashFXP 4\FlashFXP.exe C:\Users\Johan\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Users\Johan\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Earth.lnk - C:\Program Files (x86)\Google\Google Earth\client\googleearth.exe C:\Users\Johan\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\GrabIt.lnk - C:\Program Files (x86)\GrabIt\GrabIt.exe C:\Users\Johan\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\hausbuch2.lnk - C:\Softwarenetz\Huishoudboek\hausbuch2.exe C:\Users\Johan\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\IncrediMail.lnk - C:\Program Files (x86)\IncrediMail\Bin\IncMail.exe C:\Users\Johan\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Internet Explorer.lnk - C:\Program Files (x86)\Internet Explorer\iexplore.exe C:\Users\Johan\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Lopende documenten.lnk - S:\Allerlei\Documenten\Lopende documenten C:\Users\Johan\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\MapSource.lnk - C:\Garmin\Garmin\MapSource.exe C:\Users\Johan\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Excel 2007.lnk - C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\xlicons.exe C:\Users\Johan\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Outlook.lnk - C:\Program Files (x86)\Microsoft Office\Office12\OUTLOOK.EXE /recycle C:\Users\Johan\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Publisher 2007.lnk - C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pubs.exe C:\Users\Johan\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Microsoft Office SharePoint Designer 2007.lnk - C:\Windows\Installer\{90120000-0017-0000-0000-0000000FF1CE}\misc.exe C:\Users\Johan\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Word 2007.lnk - C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\wordicon.exe C:\Users\Johan\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Microsoft Works.LNK - C:\Program Files (x86)\Microsoft Works\MSWorks.exe C:\Users\Johan\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk - C:\Program Files (x86)\Mozilla Firefox\firefox.exe C:\Users\Johan\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Nero Express.lnk - C:\Windows\Installer\{70550193-1C22-445C-8FA4-564E155DB1A7}\NeroExpress.exe_81A8FD91A6494AD5B4998149EAAC7E7C.exe C:\Users\Johan\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Notepad.lnk - C:\Windows\system32\notepad.exe C:\Users\Johan\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\OpenOffice 4.1.1.lnk - C:\Program Files (x86)\OpenOffice 4\program\soffice.exe C:\Users\Johan\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Oracle VM VirtualBox.lnk - C:\Program Files\Oracle\VirtualBox\VirtualBox.exe C:\Users\Johan\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Picasa 3.lnk - C:\Program Files (x86)\Google\Picasa3\Picasa3.exe C:\Users\Johan\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Snagit 11 Editor.lnk - C:\Windows\Installer\{90D0FC4B-D653-4F49-BB97-A48C74A52E71}\Icon0E6ED661.exe C:\Users\Johan\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Snagit 11.lnk - C:\Windows\Installer\{90D0FC4B-D653-4F49-BB97-A48C74A52E71}\Icon0E6ED660.exe C:\Users\Johan\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\snelkoppelingen.lnk - C:\snelkoppelingen C:\Users\Johan\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Spotnet.lnk - C:\Program Files (x86)\Spotnet\Spotnet.exe C:\Users\Johan\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\virtualdj.lnk - C:\Program Files (x86)\VirtualDJ\virtualdj_trial.exe C:\Users\Johan\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Weerstation Online.lnk - C:\Program Files (x86)\nend software\Weerstation Online\Weerstation Online.exe C:\Users\Johan\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk - C:\Users\Johan\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Windows Calendar.lnk - C:\PROGRA~2\Windows Calendar\wincal.exe ==== Reset IE Proxy ====================== Value(s) before fix: "ProxyEnable"=dword:00000000 Value(s) after fix: "ProxyEnable"=dword:00000000 ==== Deleting Registry Keys ====================== HKEY_LOCAL_MACHINE\Software\Policies\Google deleted successfully HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update deleted successfully HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpqSRMon deleted successfully ==== Empty IE Cache ====================== C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot C:\Users\Johan\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully C:\Users\Johan\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\3RMG7D7F will be deleted at reboot C:\Users\Johan\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FCU25R1S will be deleted at reboot C:\Users\Johan\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LK5TV4FA will be deleted at reboot C:\Users\Johan\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QM9AC2MM will be deleted at reboot C:\Users\Johan\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot ==== Empty FireFox Cache ====================== C:\Users\Johan\AppData\Local\Mozilla\Firefox\Profiles\pou3u1fa.default\cache2 emptied successfully ==== Empty Chrome Cache ====================== C:\Users\Johan\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully ==== Empty All Flash Cache ====================== Flash Cache Emptied Successfully ==== Empty All Java Cache ====================== Java Cache cleared successfully ==== C:\zoek_backup content ====================== C:\zoek_backup (files=415 folders=161 111578892 bytes) ==== Empty Temp Folders ====================== C:\Users\Default\AppData\Local\temp emptied successfully C:\Users\Default User\AppData\Local\temp emptied successfully C:\Users\Johan\AppData\Local\Temp will be emptied at reboot C:\Users\Public\AppData\Local\temp emptied successfully C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully C:\Windows\Temp will be emptied at reboot ==== After Reboot ====================== ==== Empty Temp Folders ====================== C:\Windows\Temp successfully emptied C:\Users\Johan\AppData\Local\Temp successfully emptied ==== Empty Recycle Bin ====================== C:\$RECYCLE.BIN successfully emptied ==== Deleting Files / Folders ====================== "C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not found "C:\Users\Johan\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not deleted "C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not deleted "C:\PROGRA~2\AVG Web TuneUp" not found "C:\Users\Johan\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\3RMG7D7F" not found "C:\Users\Johan\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FCU25R1S" not found "C:\Users\Johan\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LK5TV4FA" not found "C:\Users\Johan\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QM9AC2MM" not found ==== EOF on zo 25/01/2015 at 10:44:31,80 ======================