Zoek.exe v5.0.0.0 Updated 13-February-2015 Tool run by Russo on za 14/02/2015 at 10:04:52,62. Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x64 Running in: Normal Mode Internet Access Detected Launched: C:\Users\Russo\Desktop\zoek.exe [Scan all users] [Script inserted] [Checkboxes used] ==== System Restore Info ====================== 14/02/2015 10:07:26 Zoek.exe System Restore Point Created Succesfully. ==== Empty Folders Check ====================== C:\Users\Administrator\AppData\Local\Comodo deleted successfully C:\Users\Administrator\AppData\Local\Google deleted successfully C:\Users\Gast\AppData\Local\Comodo deleted successfully C:\Users\Gast\AppData\Local\Google deleted successfully C:\Users\HomeGroupUser$\AppData\Local\Comodo deleted successfully C:\Users\HomeGroupUser$\AppData\Local\Google deleted successfully C:\Users\Russo\AppData\Local\Comodo deleted successfully C:\Users\UpdatusUser\AppData\Local\Comodo deleted successfully C:\Users\UpdatusUser\AppData\Local\Google deleted successfully ==== Deleting CLSID Registry Keys ====================== HKEY_USERS\S-1-5-21-131269725-1011391668-984031021-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{04ED6914-63CD-40F8-97BC-BE23DC8AF7BF} deleted successfully ==== Deleting CLSID Registry Values ====================== ==== Deleting Services ====================== ==== Registry Fix Code ====================== Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] ""=- ==== Deleting Files \ Folders ====================== C:\Users\Russo\AppData\Local\SoftonicAssistant not found "C:\windows\zoek-delete.exe" not found C:\windows\SysNative\config\systemprofile\Searches deleted "C:\DelFix.txt" deleted ==== Files Recently Created / Modified ====================== ====== C:\windows ==== ====== C:\Users\Russo\AppData\Local\Temp ==== 2015-02-14 09:04:50 17947503B7EAA0AF4914B4B6EFBC1A01 20480 ----a-w- C:\Users\Russo\AppData\Local\Temp\DaS_21.exe ====== Java Cache ===== ====== C:\windows\SysWOW64 ===== 2015-02-13 13:48:40 79CD788F17C0D836180BD89730DB8F87 113756392 ----a-w- C:\windows\SysWOW64\MRT.exe 2015-02-13 12:33:03 4FD3763F3917201856B0CBCE310003EA 4300800 ----a-w- C:\windows\SysWOW64\jscript9.dll 2015-02-13 12:33:03 01BD2653F2185218837CF4A175617F8A 620032 ----a-w- C:\windows\SysWOW64\jscript9diag.dll 2015-02-11 12:00:12 B63A6FF4339C9B701A93D3973C7FB6D2 550912 ----a-w- C:\windows\SysWOW64\kerberos.dll 2015-02-11 12:00:12 7C893DBA0A58855A99DA68B751FD223B 248832 ----a-w- C:\windows\SysWOW64\schannel.dll 2015-02-11 12:00:11 7D94A9161E8432B8521E60E064B1D737 259584 ----a-w- C:\windows\SysWOW64\msv1_0.dll 2015-02-11 12:00:10 F3F6BE20A03215209B61CA85B4A83E1F 65536 ----a-w- C:\windows\SysWOW64\TSpkg.dll 2015-02-11 12:00:10 3BB446DE24501FEA5FDB9A9DB23A22AE 221184 ----a-w- C:\windows\SysWOW64\ncrypt.dll 2015-02-11 12:00:09 C256EFD3655EC782F8094E96094E8F9E 17408 ----a-w- C:\windows\SysWOW64\credssp.dll 2015-02-11 12:00:09 A12D64A94EC57079C2D96A741CB4FF53 172032 ----a-w- C:\windows\SysWOW64\wdigest.dll 2015-02-11 12:00:03 E1A4D24281526DDFEA418F729CDA9DC6 30720 ----a-w- C:\windows\SysWOW64\iernonce.dll 2015-02-11 12:00:03 D87759889FE7BCAE4461439139E62BAA 76288 ----a-w- C:\windows\SysWOW64\mshtmled.dll 2015-02-11 12:00:03 B0F7BD3492C2D60A70F15AEADCE1E2A6 47616 ----a-w- C:\windows\SysWOW64\ieetwproxystub.dll 2015-02-11 12:00:02 94B1F7CE1AAA5542923E0AD63C4D0050 60416 ----a-w- C:\windows\SysWOW64\JavaScriptCollectionAgent.dll 2015-02-11 12:00:02 8FBC9680719ACDA9351B67D906C682F4 688640 ----a-w- C:\windows\SysWOW64\msfeeds.dll 2015-02-11 12:00:02 8E8137569741D3693F88DDF94CC38C20 1307136 ----a-w- C:\windows\SysWOW64\urlmon.dll 2015-02-11 12:00:02 74EA6C792F57E453261DA210C1BCEB53 342712 ----a-w- C:\windows\SysWOW64\iedkcs32.dll 2015-02-11 12:00:02 6FA05244FD2E40A3DC08337146B3C425 285696 ----a-w- C:\windows\SysWOW64\dxtrans.dll 2015-02-11 12:00:02 3B9EF1B8E154D202D32A7765E2F33554 64000 ----a-w- C:\windows\SysWOW64\MshtmlDac.dll 2015-02-11 12:00:01 61C74D794C14E9FC94D93F5F0F72A3F9 19740160 ----a-w- C:\windows\SysWOW64\mshtml.dll 2015-02-11 12:00:00 FD6AF61AF029B9BC2CF4EFF57CDD5821 710144 ----a-w- C:\windows\SysWOW64\ieapfltr.dll 2015-02-11 12:00:00 AD3F5926EC2C1F21FB45D1CDED6E2A47 2052608 ----a-w- C:\windows\SysWOW64\inetcpl.cpl 2015-02-11 12:00:00 9A91F9B5035F54C2D0BA92CF9B16EE34 2277888 ----a-w- C:\windows\SysWOW64\iertutil.dll 2015-02-11 12:00:00 5FB7E9786F70F4072663746072C9E6CE 62464 ----a-w- C:\windows\SysWOW64\iesetup.dll 2015-02-11 12:00:00 47B26D89EF9973E2DD586D0C827F61A9 2724864 ----a-w- C:\windows\SysWOW64\mshtml.tlb 2015-02-11 11:59:59 EF05E63ACC834470A07A2E73D519B5FA 418304 ----a-w- C:\windows\SysWOW64\dxtmsft.dll 2015-02-11 11:59:59 994E7459260D315573DD72783D1B78A7 478208 ----a-w- C:\windows\SysWOW64\ieui.dll 2015-02-11 11:59:59 55A84600EAAF8F1D3F0E6206E2EF6D48 47104 ----a-w- C:\windows\SysWOW64\jsproxy.dll 2015-02-11 11:59:59 28B2D3CB1B4306D476200D80AF7D87AD 115712 ----a-w- C:\windows\SysWOW64\ieUnatt.exe 2015-02-11 11:59:58 78A1A938D51D4F83A772123B93EE1612 12829184 ----a-w- C:\windows\SysWOW64\ieframe.dll 2015-02-11 11:59:57 180168942E4A133C55E7BBF17DA3C142 1155072 ----a-w- C:\windows\SysWOW64\mshtmlmedia.dll 2015-02-11 11:59:56 F285D499EC42969D963CA49EADA63218 1888256 ----a-w- C:\windows\SysWOW64\wininet.dll 2015-02-11 11:59:56 9DEE691C8FDBC2DE6957F1AE873C78FC 503296 ----a-w- C:\windows\SysWOW64\vbscript.dll 2015-02-11 11:59:56 6F10743069DFFC56DEE079204960844E 168960 ----a-w- C:\windows\SysWOW64\msrating.dll 2015-02-11 11:58:30 793F6658ED65839FDB2957A4884CB63C 1230336 ----a-w- C:\windows\SysWOW64\WindowsCodecs.dll 2015-02-11 11:58:26 F312300F29620F74E3AF3AF018151935 96768 ----a-w- C:\windows\SysWOW64\sspicli.dll 2015-02-11 11:58:26 F2A743912D404A8866362836CFE7A648 686080 ----a-w- C:\windows\SysWOW64\adtschema.dll 2015-02-11 11:58:26 F29BC66CE4A5507A49FB20744A056E61 22016 ----a-w- C:\windows\SysWOW64\secur32.dll 2015-02-11 11:58:26 4E6934926B4C923CC0FF61C6D77814EF 50176 ----a-w- C:\windows\SysWOW64\auditpol.exe 2015-02-11 11:58:26 43791D2F736C4E9BE9FE0B33A1E92A5D 60416 ----a-w- C:\windows\SysWOW64\msobjs.dll 2015-02-11 11:58:25 36F152AE2F64B12771A44EA77124332B 146432 ----a-w- C:\windows\SysWOW64\msaudite.dll 2015-02-11 11:58:22 E365C7B3EBB96451D3C9DF6B6B6900C2 179200 ----a-w- C:\windows\SysWOW64\wintrust.dll 2015-02-11 11:58:22 623E143F2DF17C0106A9988F5D7DC878 143872 ----a-w- C:\windows\SysWOW64\cryptsvc.dll 2015-02-11 11:58:22 0C96A745A76C7DD75C5503E86D968E49 1174528 ----a-w- C:\windows\SysWOW64\crypt32.dll 2015-02-11 11:58:13 A208DAC2932649CFF82A6A684D8BB1F6 571904 ----a-w- C:\windows\SysWOW64\oleaut32.dll 2015-02-11 11:57:57 B3BC38B886CA53C92D52EF724A9F0D45 308224 ----a-w- C:\windows\SysWOW64\scesrv.dll 2015-02-11 11:57:53 6D227897A458DA8A9518DACDC88F1947 3917760 ----a-w- C:\windows\SysWOW64\ntoskrnl.exe 2015-02-11 11:57:53 62C93E47A424A8EC79F3CF1719A2DCC6 3972544 ----a-w- C:\windows\SysWOW64\ntkrnlpa.exe 2015-02-11 11:57:52 97B7E7E3356F7F7FE5B948AB3ED707DD 43008 ----a-w- C:\windows\SysWOW64\srclient.dll 2015-02-02 11:49:29 A64711C9CF690718EADA750370EC5EB2 4659712 ----a-w- C:\windows\SysWOW64\Redemption.dll ====== C:\windows\SysWOW64\drivers ===== ====== C:\windows\Sysnative ===== 2015-02-13 12:33:02 D363FBB2D0223956FF61ADBDBF5499B1 814080 ----a-w- C:\windows\Sysnative\jscript9diag.dll 2015-02-13 12:33:02 16ACAA0C01F31B39F39446188F6A3593 6041600 ----a-w- C:\windows\Sysnative\jscript9.dll 2015-02-11 12:00:16 B5746809407BDEB18D9D4769CD9FF24E 414720 ----a-w- C:\windows\Sysnative\devinv.dll 2015-02-11 12:00:16 64EAD6C9D342E7E0CFCA3559FCBFDDAC 894976 ----a-w- C:\windows\Sysnative\appraiser.dll 2015-02-11 12:00:16 5C09611AB8D508CC252BB2D5A069D1AC 1098752 ----a-w- C:\windows\Sysnative\aeinv.dll 2015-02-11 12:00:16 5632EB9633EACCC323CEA2C03A0B4133 762368 ----a-w- C:\windows\Sysnative\invagent.dll 2015-02-11 12:00:16 47709F1B718859ED8AB5EA3EA3974BEB 609280 ----a-w- C:\windows\Sysnative\generaltel.dll 2015-02-11 12:00:15 7150E809474BBD4D4AD24B13FA2454E5 1239720 ----a-w- C:\windows\Sysnative\aitstatic.exe 2015-02-11 12:00:14 EF4FA1D31D146EA0C04D16E75FCA6BCF 192000 ----a-w- C:\windows\Sysnative\aepic.dll 2015-02-11 12:00:14 7F2F9AACF457CE48CDDBD643FC53487C 227328 ----a-w- C:\windows\Sysnative\aepdu.dll 2015-02-11 12:00:12 DDACB408E607655EC64269706BFD504C 341504 ----a-w- C:\windows\Sysnative\schannel.dll 2015-02-11 12:00:11 C1F9E139B8AE80803CE44DC0377CA342 728064 ----a-w- C:\windows\Sysnative\kerberos.dll 2015-02-11 12:00:11 6A06BCED1DF1CFE8A32E7D10ABAA7188 314880 ----a-w- C:\windows\Sysnative\msv1_0.dll 2015-02-11 12:00:10 A46A6C5AD462071B718EBF3C9E117849 309760 ----a-w- C:\windows\Sysnative\ncrypt.dll 2015-02-11 12:00:10 8F33880F1863BE3925D3A0121FAC5E8F 86528 ----a-w- C:\windows\Sysnative\TSpkg.dll 2015-02-11 12:00:10 5350A548BEC957978B7014CDFF091542 210944 ----a-w- C:\windows\Sysnative\wdigest.dll 2015-02-11 12:00:09 22E30E28865C32C3CF4F4E0E7E277FDC 22016 ----a-w- C:\windows\Sysnative\credssp.dll 2015-02-11 12:00:03 71EBA93C5322A52A7E177E03E1AE7161 48640 ----a-w- C:\windows\Sysnative\ieetwproxystub.dll 2015-02-11 12:00:03 01A314677CC80041A63ED109B56A76B0 114688 ----a-w- C:\windows\Sysnative\ieetwcollector.exe 2015-02-11 12:00:02 F42B1DAAB5B7621341243878180446CD 34304 ----a-w- C:\windows\Sysnative\iernonce.dll 2015-02-11 12:00:02 92BD5080B81EDFA32B0CEE8B923D62C3 77824 ----a-w- C:\windows\Sysnative\JavaScriptCollectionAgent.dll 2015-02-11 12:00:02 8076BB31004C1D763D5D4AEF9F0BDD4B 718848 ----a-w- C:\windows\Sysnative\ie4uinit.exe 2015-02-11 12:00:02 68A2B96528F58D995882FBEB4D9658A5 2724864 ----a-w- C:\windows\Sysnative\mshtml.tlb 2015-02-11 12:00:00 CB2528D522FF1F5A7BF9B27D2FB250FF 1548288 ----a-w- C:\windows\Sysnative\urlmon.dll 2015-02-11 12:00:00 1D824B5A200C284E1A546C2C50704471 389808 ----a-w- C:\windows\Sysnative\iedkcs32.dll 2015-02-11 11:59:59 DF39C79DFC1C063493D2DB9B3237B29F 316928 ----a-w- C:\windows\Sysnative\dxtrans.dll 2015-02-11 11:59:59 97F037E09A706ACDA681D740DEE16AE4 968704 ----a-w- C:\windows\Sysnative\MsSpellCheckingFacility.exe 2015-02-11 11:59:59 76DB5845E168173BBA2D3CCC4B363E42 801280 ----a-w- C:\windows\Sysnative\msfeeds.dll 2015-02-11 11:59:59 2E4F8664B54426C2F5523665B279E984 4096 ----a-w- C:\windows\Sysnative\ieetwcollectorres.dll 2015-02-11 11:59:58 7A388AFC6885D22F4D988EE9B8D1291A 800768 ----a-w- C:\windows\Sysnative\ieapfltr.dll 2015-02-11 11:59:58 512DD29CE6CDCB22EA615286DA7022E7 66560 ----a-w- C:\windows\Sysnative\iesetup.dll 2015-02-11 11:59:57 A7A3775B0014B165D75A00A1F632E4B5 2885632 ----a-w- C:\windows\Sysnative\iertutil.dll 2015-02-11 11:59:57 15842FB41A3BF2A2F5071518B38C957A 2125824 ----a-w- C:\windows\Sysnative\inetcpl.cpl 2015-02-11 11:59:56 A7814E76ED4ACE0694A83F6E4B6A7272 144384 ----a-w- C:\windows\Sysnative\ieUnatt.exe 2015-02-11 11:59:56 6916B0663357B183B120D1A4DD7DDAB0 54784 ----a-w- C:\windows\Sysnative\jsproxy.dll 2015-02-11 11:59:55 E0F76B5B904E4F448641B2B506496351 14401024 ----a-w- C:\windows\Sysnative\ieframe.dll 2015-02-11 11:59:55 D7922F3AC6BF1EA77240E0061D648174 490496 ----a-w- C:\windows\Sysnative\dxtmsft.dll 2015-02-11 11:59:55 CA3F410410DE9E5234217D33B9628224 633856 ----a-w- C:\windows\Sysnative\ieui.dll 2015-02-11 11:59:54 A04F0C4A0B80C92F92E854E7157D6466 92160 ----a-w- C:\windows\Sysnative\mshtmled.dll 2015-02-11 11:59:54 4CE68D160D80AF6C9FDB5C60BA087DA5 1359360 ----a-w- C:\windows\Sysnative\mshtmlmedia.dll 2015-02-11 11:59:53 BF57C911895454A8874E9DFA5716C624 584192 ----a-w- C:\windows\Sysnative\vbscript.dll 2015-02-11 11:59:53 9DFE41A69DF70AAB75CB5BA8C1109EA2 2358272 ----a-w- C:\windows\Sysnative\wininet.dll 2015-02-11 11:59:52 47162151E35EA0B7152B7C841FA21FDB 88064 ----a-w- C:\windows\Sysnative\MshtmlDac.dll 2015-02-11 11:59:52 4701399F7BA312353ADE8225F6EB512B 199680 ----a-w- C:\windows\Sysnative\msrating.dll 2015-02-11 11:59:51 CD726C899BD9A398E8420564A957320B 25056256 ----a-w- C:\windows\Sysnative\mshtml.dll 2015-02-11 11:58:30 4861B9AF67E1B0154A55FDE4B3A61EB9 1424384 ----a-w- C:\windows\Sysnative\WindowsCodecs.dll 2015-02-11 11:58:26 E0105F3B5B1C4B0F5B3D788A13504EC6 31232 ----a-w- C:\windows\Sysnative\lsass.exe 2015-02-11 11:58:26 C97662B6752BFEF07C565D96E8ECC98F 1461760 ----a-w- C:\windows\Sysnative\lsasrv.dll 2015-02-11 11:58:26 94C6BCF9212E20866AC1558A32E9F228 28160 ----a-w- C:\windows\Sysnative\secur32.dll 2015-02-11 11:58:26 857CED230A6B87E84FCA04B472A3CB1A 136192 ----a-w- C:\windows\Sysnative\sspicli.dll 2015-02-11 11:58:26 6EAD88B508E4785F4AFDFD24F76E8839 686080 ----a-w- C:\windows\Sysnative\adtschema.dll 2015-02-11 11:58:26 51BB93FF96AE3882B4AF7CA11000D3A3 64000 ----a-w- C:\windows\Sysnative\auditpol.exe 2015-02-11 11:58:26 2EE57F4491A402C04FCAA7D012493884 29184 ----a-w- C:\windows\Sysnative\sspisrv.dll 2015-02-11 11:58:26 1798826FE9FFEA9E93E74A5868559D4A 60416 ----a-w- C:\windows\Sysnative\msobjs.dll 2015-02-11 11:58:25 BE4927689BA39E18A104986CB1363C97 146432 ----a-w- C:\windows\Sysnative\msaudite.dll 2015-02-11 11:58:22 E5AF792AB409F600D416CB257C84305D 1480192 ----a-w- C:\windows\Sysnative\crypt32.dll 2015-02-11 11:58:22 7FC292D1527EDFEBA2576B6789DE6AB5 229376 ----a-w- C:\windows\Sysnative\wintrust.dll 2015-02-11 11:58:22 19D511CC455C19DE1ADF60E6C39C85B6 187904 ----a-w- C:\windows\Sysnative\cryptsvc.dll 2015-02-11 11:58:13 AE4FEDD98096C09A8A86E021FC5E9D67 861696 ----a-w- C:\windows\Sysnative\oleaut32.dll 2015-02-11 11:57:57 FE72C89986E1BA32AD926A820491F23F 406528 ----a-w- C:\windows\Sysnative\scesrv.dll 2015-02-11 11:57:54 9819614CA9EFB5A96493B379170B9D89 5554112 ----a-w- C:\windows\Sysnative\ntoskrnl.exe 2015-02-11 11:57:52 F7A3018D8F1825427BC11E912D5287CD 296960 ----a-w- C:\windows\Sysnative\rstrui.exe 2015-02-11 11:57:52 D6CDCAF84810641D1D2B455750825ACA 50176 ----a-w- C:\windows\Sysnative\srclient.dll 2015-02-11 11:57:52 0147AA370862201A443752351F135D31 503808 ----a-w- C:\windows\Sysnative\srcore.dll 2015-02-11 11:57:38 DF07110F77639E73D0537188703F44F6 3201536 ----a-w- C:\windows\Sysnative\win32k.sys ====== C:\windows\Sysnative\drivers ===== 2015-02-11 11:58:26 E45CDE1C8340DFEDF1D6724263F39E5B 458824 ----a-w- C:\windows\Sysnative\drivers\cng.sys 2015-02-11 11:58:26 C60C6B9A2E50B0404F6789C62B428C03 95680 ----a-w- C:\windows\Sysnative\drivers\ksecdd.sys 2015-02-11 11:58:26 78D152A9FD5747FF6AA89C79F0346F62 155072 ----a-w- C:\windows\Sysnative\drivers\ksecpkg.sys ====== C:\windows\Tasks ====== ====== C:\windows\Temp ====== ======= C:\Program Files ===== 2015-02-13 09:30:38 -------- d-----w- C:\Program Files\trend micro ======= C:\PROGRA~2 ===== 2015-02-13 13:49:53 -------- d-----w- C:\PROGRA~2\Microsoft Windows 7 Upgrade Advisor ======= C: ===== ====== C:\Users\Russo\AppData\Roaming ====== 2015-02-13 13:50:40 -------- d-----w- C:\Users\Russo\AppData\Local\Microsoft Corporation 2015-02-13 09:56:58 -------- d-----w- C:\windows\serviceprofiles\networkservice\AppData\Local\Temp 2015-02-13 09:56:58 -------- d-----w- C:\windows\serviceprofiles\Localservice\AppData\Local\Temp 2015-02-13 09:56:58 -------- d-----w- C:\Users\UpdatusUser\AppData\Local\Temp 2015-02-13 09:56:58 -------- d-----w- C:\Users\Russo\AppData\Local\Temp 2015-02-13 09:56:58 -------- d-----w- C:\Users\Default\AppData\Local\Temp 2015-02-13 09:56:58 -------- d-----w- C:\Users\Default User\AppData\Local\Temp 2015-02-02 12:13:49 -------- d-----w- C:\Users\Russo\AppData\Local\Flixtor 2015-02-02 11:51:55 -------- d-----w- C:\Users\Russo\AppData\Roaming\Samsung 2015-02-02 10:57:10 -------- d-----w- C:\Users\Russo\AppData\Local\Popcorn-Time 2015-02-02 10:57:04 -------- d-----w- C:\Users\Russo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Popcorn Time 2015-02-02 10:56:01 -------- d-----w- C:\Users\Russo\AppData\Local\Popcorn Time ====== C:\Users\Russo ====== 2015-02-13 10:01:40 8045ABB21A3BDD66A48E1ED5C0F0EF6A 1222144 ----a-w- C:\Users\Russo\Desktop\RSITx64.exe 2015-02-02 11:52:00 -------- d-----w- C:\Users\Public\Documents\CrashDump ====== C: exe-files == 2015-02-14 09:04:50 17947503B7EAA0AF4914B4B6EFBC1A01 20480 ----a-w- C:\Users\Russo\AppData\Local\Temp\DaS_21.exe 2015-02-13 13:48:40 79CD788F17C0D836180BD89730DB8F87 113756392 ----a-w- C:\Windows\SysWOW64\MRT.exe 2015-02-13 13:47:34 5013C48E99E451B95A30FC98C89AEC33 38804664 ----a-w- C:\Users\Russo\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SVTSSGK8\Windows-KB890830-V5.21 (1).exe 2015-02-13 13:46:44 E9CFB613C83655A06712EB1989E86BEC 8665360 ----a-w- C:\Users\Russo\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SVTSSGK8\Windows7UpgradeAdvisorSetup (1).exe 2015-02-13 10:01:40 8045ABB21A3BDD66A48E1ED5C0F0EF6A 1222144 ----a-w- C:\Users\Russo\Desktop\RSITx64.exe 2015-02-13 09:30:41 9A2347903D6EDB84C10F288BC0578C1C 388608 ----a-w- C:\Program Files\trend micro\Russo.exe 2015-02-11 12:00:15 B62B7F2ACDEDF61F4DAA1FF2A6BB247A 67240 ----a-w- C:\Windows\System32\CompatTel\diagtrackrunner.exe 2015-02-11 12:00:15 8D06AAF1723B514C412187C5B8B67EEF 46752 ----a-w- C:\Windows\System32\CompatTel\wicainventory.exe 2015-02-11 12:00:15 7150E809474BBD4D4AD24B13FA2454E5 1239720 ----a-w- C:\Windows\System32\aitstatic.exe 2015-02-11 12:00:14 4AC38FC4C6894B21698A99B9129B1EA4 161952 ----a-w- C:\Windows\System32\CompatTel\QueryAppBlock.exe 2015-02-11 12:00:03 01A314677CC80041A63ED109B56A76B0 114688 ----a-w- C:\Windows\System32\ieetwcollector.exe 2015-02-11 12:00:02 D674809F9EC7D6A409F553C0DF91E825 221184 ----a-w- C:\Program Files (x86)\Internet Explorer\ielowutil.exe 2015-02-11 12:00:02 8076BB31004C1D763D5D4AEF9F0BDD4B 718848 ----a-w- C:\Windows\System32\ie4uinit.exe 2015-02-11 12:00:00 8111C559DAD3A40200AE916874E7E62A 468992 ----a-w- C:\Program Files (x86)\Internet Explorer\ieinstal.exe 2015-02-11 12:00:00 4089C6F953C024E16BC2361F471864D7 222720 ----a-w- C:\Program Files\Internet Explorer\ielowutil.exe 2015-02-11 11:59:59 97F037E09A706ACDA681D740DEE16AE4 968704 ----a-w- C:\Windows\System32\MsSpellCheckingFacility.exe 2015-02-11 11:59:59 363BC25BACB34E9D40441968B1B3D5BE 815288 ----a-w- C:\Program Files (x86)\Internet Explorer\iexplore.exe 2015-02-11 11:59:59 28B2D3CB1B4306D476200D80AF7D87AD 115712 ----a-w- C:\Windows\SysWOW64\ieUnatt.exe 2015-02-11 11:59:57 3FB445C7BF7E342391FF3875413CCC33 484352 ----a-w- C:\Program Files\Internet Explorer\ieinstal.exe 2015-02-11 11:59:57 2D4AB594AABBEBA938F36BA1BC71C3F6 813744 ----a-w- C:\Program Files\Internet Explorer\iexplore.exe 2015-02-11 11:59:56 A7814E76ED4ACE0694A83F6E4B6A7272 144384 ----a-w- C:\Windows\System32\ieUnatt.exe 2015-02-11 11:58:26 E0105F3B5B1C4B0F5B3D788A13504EC6 31232 ----a-w- C:\Windows\System32\lsass.exe 2015-02-11 11:58:26 51BB93FF96AE3882B4AF7CA11000D3A3 64000 ----a-w- C:\Windows\System32\auditpol.exe 2015-02-11 11:58:26 4E6934926B4C923CC0FF61C6D77814EF 50176 ----a-w- C:\Windows\SysWOW64\auditpol.exe 2015-02-11 11:57:54 9819614CA9EFB5A96493B379170B9D89 5554112 ----a-w- C:\Windows\System32\ntoskrnl.exe 2015-02-11 11:57:53 6D227897A458DA8A9518DACDC88F1947 3917760 ----a-w- C:\Windows\SysWOW64\ntoskrnl.exe 2015-02-11 11:57:53 62C93E47A424A8EC79F3CF1719A2DCC6 3972544 ----a-w- C:\Windows\SysWOW64\ntkrnlpa.exe 2015-02-11 11:57:52 F7A3018D8F1825427BC11E912D5287CD 296960 ----a-w- C:\Windows\System32\rstrui.exe === C: other files == 2015-02-13 21:10:12 76CDB2BAD9582D23C1F6F4D868218D6C 22 ----a-w- C:\Users\Russo\AppData\Local\Temp\avastBCLTMP\{8feff364-6a5f-4966-a917-a3ac28411659}.zip 2015-02-13 12:30:36 8175157C1A22290451FD12D1B07BC5EF 318365 ----a-w- C:\Users\Russo\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\N7UMH3EX\game4[1].zip 2015-02-13 12:30:30 5AE21E7E4FA1E9BFE1F7F627B77E2D78 1160032 ----a-w- C:\Users\Russo\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\38NBSC3O\diorama4[1].zip 2015-02-13 12:30:29 BA1C9736AF583F41044208B58266B41B 53102 ----a-w- C:\Users\Russo\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\38NBSC3O\preloader[1].zip 2015-02-13 12:30:29 A432690FE0C5E1728BF9CEDFCBCCE927 2800803 ----a-w- C:\Users\Russo\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\38NBSC3O\diorama_common[1].zip 2015-02-13 12:30:29 4515EA8CBBCF5ED9667F4E3992D4F693 1796163 ----a-w- C:\Users\Russo\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\38NBSC3O\bootstrap[1].zip 2015-02-13 12:30:29 0D53353E726F0691454144D6DF283045 193427 ----a-w- C:\Users\Russo\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\S65BZ7DA\localization[1].zip 2015-02-13 12:30:28 3EE175700A933A4E0BA10E90E1F397D9 149435 ----a-w- C:\Users\Russo\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\S65BZ7DA\init[1].zip 2015-02-11 11:58:26 E45CDE1C8340DFEDF1D6724263F39E5B 458824 ----a-w- C:\Windows\System32\drivers\cng.sys 2015-02-11 11:58:26 C60C6B9A2E50B0404F6789C62B428C03 95680 ----a-w- C:\Windows\System32\drivers\ksecdd.sys 2015-02-11 11:58:26 78D152A9FD5747FF6AA89C79F0346F62 155072 ----a-w- C:\Windows\System32\drivers\ksecpkg.sys 2015-02-11 11:57:38 DF07110F77639E73D0537188703F44F6 3201536 ----a-w- C:\Windows\System32\win32k.sys ==== Startup Registry Enabled ====================== [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun" [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun" [HKEY_USERS\S-1-5-21-131269725-1011391668-984031021-1000\Software\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun" [HKEY_USERS\S-1-5-21-131269725-1011391668-984031021-1001\Software\Microsoft\Windows\CurrentVersion\Run] "iCloudServices"="C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe" "SoftonicAssistant"="C:\Users\Russo\AppData\Local\SoftonicAssistant\SoftonicAssistant.exe" [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce] "mctadmin"="C:\Windows\System32\mctadmin.exe" [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce] "mctadmin"="C:\Windows\System32\mctadmin.exe" [HKEY_USERS\S-1-5-21-131269725-1011391668-984031021-1000\Software\Microsoft\Windows\CurrentVersion\RunOnce] "mctadmin"="C:\Windows\System32\mctadmin.exe" [HKEY_USERS\S-1-5-21-131269725-1011391668-984031021-1001\Software\Microsoft\Windows\CurrentVersion\RunOnce] "Uninstall C:\Users\Russo\AppData\Local\Microsoft\SkyDrive\17.0.4023.1211_1\amd64"="C:\windows\system32\cmd.exe /q /c rmdir /s /q C:\Users\Russo\AppData\Local\Microsoft\SkyDrive\17.0.4023.1211_1\amd64" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "AvastUI.exe"="C:\Program Files\AVAST Software\Avast\AvastUI.exe /nogui" "HP Software Update"="C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "iCloudServices"="C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe" "SoftonicAssistant"="C:\Users\Russo\AppData\Local\SoftonicAssistant\SoftonicAssistant.exe" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce] "Uninstall C:\Users\Russo\AppData\Local\Microsoft\SkyDrive\17.0.4023.1211_1\amd64"="C:\windows\system32\cmd.exe /q /c rmdir /s /q C:\Users\Russo\AppData\Local\Microsoft\SkyDrive\17.0.4023.1211_1\amd64" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"=" C:\\PROGRA~2\\SETTIN~1\\systemk\\syskldr.dll " ==== Startup Registry Enabled x64 ====================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "BTMTrayAgent"="rundll32.exe C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll,TrayApp" "ETDCtrl"="%ProgramFiles%\Elantech\ETDCtrl.exe " ==== Startup Registry Disabled x64 ====================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Adobe ARM] "key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="Adobe ARM" "hkey"="HKLM" "command"="\"C:\\Program Files (x86)\\Common Files\\Adobe\\ARM\\1.0\\AdobeARM.exe\"" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ApplePhotoStreams] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="ApplePhotoStreams" "hkey"="HKCU" "command"="C:\\Program Files (x86)\\Common Files\\Apple\\Internet Services\\ApplePhotoStreams.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\iCloudDrive] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="iCloudDrive" "hkey"="HKCU" "command"="C:\\Program Files (x86)\\Common Files\\Apple\\Internet Services\\iCloudDrive.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\iCloudServices] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="iCloudServices" "hkey"="HKCU" "command"="C:\\Program Files (x86)\\Common Files\\Apple\\Internet Services\\iCloudServices.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\iTunesHelper] "key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="iTunesHelper" "hkey"="HKLM" "command"="\"C:\\Program Files (x86)\\iTunes\\iTunesHelper.exe\"" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\QuickTime Task] "key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="QuickTime Task" "hkey"="HKLM" "command"="\"C:\\Program Files (x86)\\QuickTime\\QTTask.exe\" -atboottime" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\RtHDVCpl] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="RtHDVCpl" "hkey"="HKLM" "command"="C:\\Program Files\\Realtek\\Audio\\HDA\\RAVCpl64.exe -s" ==== Task Scheduler Jobs ====================== C:\windows\tasks\Adobe Flash Player Updater.job --a------ C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [04/02/2015 21:34] C:\windows\tasks\GoogleUpdateTaskMachineCore.job --a------ C:2D6C:\ProgramC:FilesC:x86\Google\Update\GoogleUpdate.exe [] C:\windows\tasks\GoogleUpdateTaskMachineUA.job --a------ C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [] ==== Other Scheduled Tasks ====================== "C:\windows\SysNative\tasks\Adobe Acrobat Update Task" [C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe] "C:\windows\SysNative\tasks\Adobe Flash Player Updater" [C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe] "C:\windows\SysNative\tasks\advSRS5" ["C:\Program Files (x86)\Samsung\Samsung Recovery Solution 5\WCScheduler.exe"] "C:\windows\SysNative\tasks\CCleanerSkipUAC" ["C:\Program Files\CCleaner\CCleaner.exe"] "C:\windows\SysNative\tasks\CreateChoiceProcessTask" [C:\Windows\System32\browserchoice.exe] "C:\windows\SysNative\tasks\Easy Software Manager Agent" ["%ProgramFiles(x86)%\Samsung\Easy Software Manager\SWMAgent.exe"] "C:\windows\SysNative\tasks\EasyBatteryManager" ["%ProgramFiles(x86)%\Samsung\Easy Settings\EBM\EasyBatteryMgr4.exe"] "C:\windows\SysNative\tasks\EasyDisplayMgr" ["C:\Program Files (x86)\Samsung\Easy Settings\dmhkcore.exe"] "C:\windows\SysNative\tasks\EasySpeedUpManager" ["%programfiles(x86)%\Samsung\Easy Settings\EasySpeedUpManager.exe"] "C:\windows\SysNative\tasks\GoogleUpdateTaskMachineCore" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe] "C:\windows\SysNative\tasks\GoogleUpdateTaskMachineUA" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe] "C:\windows\SysNative\tasks\MovieColorEnhancer" ["%programfiles(x86)%\Samsung\Easy Settings\MovieColorEnhancer.exe"] "C:\windows\SysNative\tasks\SamsungSupportCenter" [%programfiles(x86)%\Samsung\Easy Support Center\SSCKbdHk.exe] "C:\windows\SysNative\tasks\SmartSetting" ["%programfiles(x86)%\Samsung\Easy Settings\SmartSetting.exe"] "C:\windows\SysNative\tasks\{7062B1A6-2F27-4B9B-A886-31D1D8276896}" [C:\Users\Russo\Downloads\torbrowser-install-3.6.2_nl.exe] "C:\windows\SysNative\tasks\Apple\AppleSoftwareUpdate" [C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe] "C:\windows\SysNative\tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask" [%systemroot%\system32\sc.exe start osppsvc] ==== Firefox Extensions Registry ====================== [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions] "wrc@avast.com"="C:\Program Files\AVAST Software\Avast\WebRep\FF" [29/01/2015 21:01] [HKEY_CURRENT_USER\Software\Mozilla\Firefox\Extensions] "magicplayer@torrentstream.org"="C:\Users\Russo\AppData\Roaming\ACEStream\extensions\firefox\magicplayer@torrentstream.org" [14/09/2014 14:55] ==== Chromium Look ====================== Google Chrome Version: 38.0.2125.111 (Possible outdated, latest Stable version: 40.0.2214.111) HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions eofcbnmajmjmplflapaojjnihcjkigck - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChromeSp.crx[26/11/2014 08:50] gomekmidlodglbbmalcneegieacbdmki - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx[26/11/2014 08:50] HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\Extensions kpckgflgdapkpabemgkielbefdildaio - C:\Users\Russo\AppData\Roaming\ACEStream\extensions\chrome_new\magicplayer.crx[28/01/2014 09:13] Torrent Search - Russo\AppData\Local\Google\Chrome\User Data\Default\Extensions\afbpdhiclgghnffhkinjikglgmolhpee Google Docs - Russo\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake Google Drive - Russo\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf Splendid - Russo\AppData\Local\Google\Chrome\User Data\Default\Extensions\bdfkbdkkfmmckaadapdipihjfaacnkgd Radio Italy - Radio Italia - Russo\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhnaahdkfcggkalikdncbadinkkbhaej YouTube - Russo\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo Facebook - Russo\AppData\Local\Google\Chrome\User Data\Default\Extensions\boeajhmfdjldchidhphikilcgdacljfm Pool - Russo\AppData\Local\Google\Chrome\User Data\Default\Extensions\cedbddnnmhgnedpamoenmdkhnpnfbpjb Google Search - Russo\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf Torrent Turbo Search App - Russo\AppData\Local\Google\Chrome\User Data\Default\Extensions\eegbffmjdkflkcfncpfjjbggbdlnbdif Avast Online Security - Russo\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki Kapaza.be - Russo\AppData\Local\Google\Chrome\User Data\Default\Extensions\ijmlcekpfnipcbdknmokfpogbehgcgkn Free online speed typing tests find whats your WPM words per minute speed improve your typing skills and practice typing. - Russo\AppData\Local\Google\Chrome\User Data\Default\Extensions\jkcieoaeooeidmpaopkpjpjfakidlabm Google Play - Russo\AppData\Local\Google\Chrome\User Data\Default\Extensions\komhbcfkdcgmcdoenjcjheifdiabikfi Magic Player - Russo\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpckgflgdapkpabemgkielbefdildaio Free soccer manager game with thousands of real opponents. Manage your favourite football club to glory against your friends. - Russo\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpemkngoajegcbamebdmnkjoalpofpbj Google Maps - Russo\AppData\Local\Google\Chrome\User Data\Default\Extensions\lneaknkopdijkpnocmklfnjbeapigfbh Google Wallet - Russo\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda Background Tab - Russo\AppData\Local\Google\Chrome\User Data\Default\Extensions\oehpjpccmlcalbenfhnacjeocbjdonic Outlook.com - Russo\AppData\Local\Google\Chrome\User Data\Default\Extensions\pfpeapihoiogbcmdmnibeplnikfnhoge Gmail - Russo\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia ==== Set IE to Default ====================== Old Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://www.google.be/" New Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://www.google.be/" ==== All HKCU SearchScopes ====================== HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes "DefaultScope"="{7A7734E7-DC06-420C-B0A2-E3CC6CD0709F}" {006ee092-9658-4fd6-bd8e-a21a348e59f5} Bing Url="http://www.bing.com/search?q={searchTerms}" {012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}" {0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE11SR" {7A7734E7-DC06-420C-B0A2-E3CC6CD0709F} Google Url="https://www.google.com/search?q={searchTerms}" ==== Empty IE Cache ====================== C:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Russo\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Russo\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully C:\windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully ==== Empty FireFox Cache ====================== No FireFox Profiles found ==== Empty Chrome Cache ====================== C:\Users\Russo\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully ==== Empty All Flash Cache ====================== Flash Cache Emptied Successfully ==== Empty All Java Cache ====================== No Java Cache Found ==== C:\zoek_backup content ====================== C:\zoek_backup (files=4 folders=1 1396 bytes) ==== Empty Temp Folders ====================== C:\Users\Default\AppData\Local\Temp emptied successfully C:\Users\Default User\AppData\Local\Temp emptied successfully C:\Users\Russo\AppData\Local\Temp will be emptied at reboot C:\Users\UpdatusUser\AppData\Local\Temp emptied successfully C:\windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully C:\windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully C:\windows\Temp will be emptied at reboot ==== After Reboot ====================== ==== Empty Temp Folders ====================== C:\windows\Temp successfully emptied C:\Users\Russo\AppData\Local\Temp successfully emptied ==== Empty Recycle Bin ====================== C:\$RECYCLE.BIN successfully emptied ==== EOF on za 14/02/2015 at 10:27:32,28 ======================