Zoek.exe v5.0.0.0 Updated 08-April-2015 Tool run by Gert on wo 22/04/2015 at 4:19:28.43. Microsoft Windows 7 Ultimate 6.1.7601 Service Pack 1 x64 Running in: Normal Mode Internet Access Detected Launched: C:\Users\Gert\Desktop\zoek.exe [Scan all users] [Script inserted] [Checkboxes used] ==== System Restore Info ====================== 22/04/2015 4:23:34 Zoek.exe System Restore Point Created Successfully. ==== Empty Folders Check ====================== C:\PROGRA~2\bugwatcher deleted successfully C:\PROGRA~2\FMF deleted successfully C:\PROGRA~2\Right Brain Interface deleted successfully C:\PROGRA~2\The Latest Versions of Google deleted successfully C:\PROGRA~3\AVAST Software deleted successfully C:\Users\Gert\AppData\Local\VirtualStore deleted successfully ==== Deleting CLSID Registry Keys ====================== HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Extensions\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} deleted successfully HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} deleted successfully ==== Deleting CLSID Registry Values ====================== ==== Deleting Services ====================== ==== Registry Fix Code x64 ====================== Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run] "portGbal"=- ==== Deleting Files \ Folders ====================== C:\PROGRA~2\bugwatcher not found C:\PROGRA~2\FMF not found C:\PROGRA~2\Right Brain Interface not found C:\PROGRA~2\The Latest Versions of Google not found C:\windows\SysNative\FMFP9TU36APK214J9BTBNM not found C:\Program Files (x86)\bugwatcher not found "C:\Users\Gert\AppData\Roaming\BYAIAMUF.exe" not found C:\PROGRA~2\keePItBroawse deleted C:\PROGRA~2\Find My Bookmarks deleted C:\PROGRA~2\ws deleted C:\ProgramData\{705703d0-3cbb-b179-7057-703d03cb0f40} deleted C:\ProgramData\{83bbc312-4edc-b32c-83bb-bc3124ed0c49} deleted C:\ProgramData\14805162304170585651 deleted C:\Users\Gert\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\startup\Marina__2013__XVID_720p_HQ_AC3_DD5.1__NL_Subs_.avi.lnk deleted C:\PROGRA~3\ItsMyApp deleted C:\Users\Gert\AppData\Roaming\appdataFr3.bin deleted C:\Users\Gert\AppData\Roaming\pecodec.dll deleted C:\PROGRA~3\InstallMate deleted C:\Users\Gert\AppData\LocalLow\{1EAAF9AF-DE1B-54B8-37AD-3159180578D0} deleted C:\Users\Gert\AppData\LocalLow\{8C3C76BE-E4A9-C6A0-ECD9-D5DB5F0C595A} deleted C:\Users\Gert\AppData\LocalLow\{BD8EB446-8566-0B02-F6FA-B0E3FB95D067} deleted "C:\Windows\tasks\BYAIAMUF.job" deleted "C:\Users\Gert\AppData\Roaming\BYAIAMUF" deleted "C:\Windows\tasks\BYAIAMUF.job" deleted "C:\Windows\SysNative\tasks\BYAIAMUF" deleted "C:\ProgramData\{b6dff0fd-128f-2b9e-b6df-ff0fd128c3f4}\c012ee9e360a9343" not deleted "C:\ProgramData\{b6dff0fd-128f-2b9e-b6df-ff0fd128c3f4}\def48cb11de7497" not deleted "C:\ProgramData\{b6dff0fd-128f-2b9e-b6df-ff0fd128c3f4}\Marina__2013__XVID_720p_HQ_AC3_DD5.1__NL_Subs_.avi.exe" deleted "C:\PROGRA~3\{b6dff0fd-128f-2b9e-b6df-ff0fd128c3f4}\c012ee9e360a9343" not deleted "C:\PROGRA~3\{b6dff0fd-128f-2b9e-b6df-ff0fd128c3f4}\def48cb11de7497" not deleted "C:\PROGRA~3\{b6dff0fd-128f-2b9e-b6df-ff0fd128c3f4}\Marina__2013__XVID_720p_HQ_AC3_DD5.1__NL_Subs_.avi.exe" deleted "C:\ProgramData\{b6dff0fd-128f-2b9e-b6df-ff0fd128c3f4}" not deleted "C:\PROGRA~3\{b6dff0fd-128f-2b9e-b6df-ff0fd128c3f4}" not deleted ==== Files Recently Created / Modified ====================== ====== C:\Windows ==== 2015-04-13 20:10:36 CA2A8AF1DBAD0F31F9B33A2827DFBC16 207 ----a-w- C:\Windows\tweaking.com-regbackup-GERTLAP-Windows-7-Ultimate-(64-bit).dat ====== C:\Users\Gert\AppData\Local\Temp ==== 2015-04-17 16:51:38 EB3F8534322D883F4A61274210551662 43008 ----a-w- C:\Users\Gert\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpoen2oy.dll 2015-04-17 15:03:03 B0E2B7813094940E791B0D6123E782D8 562088 ----a-w- C:\Users\Gert\AppData\Local\Temp\jre-8u45-windows-au.exe 2015-04-13 22:31:34 10FFABC748D68C40B68F883058C9B932 50225 ----a-w- C:\Users\Gert\AppData\Local\Temp\81428964290\T0pETExR10700.exe 2015-04-13 22:29:13 5005300F7B153459699671D2EC796DAC 719888 ----a-w- C:\Users\Gert\AppData\Local\Temp\Firmware__7123_il57161.exe 2015-04-13 22:28:14 D1BA5C647561DC7F8096D228FF02B6E0 224256 ----a-w- C:\Users\Gert\AppData\Local\Temp\~ldAA05\fgrs\tmp\CrashReport.exe 2015-04-13 22:28:14 A96619564071DF84CC892752DF062A6D 86016 ------w- C:\Users\Gert\AppData\Local\Temp\~ldAA05\fgrs\tmp\RegWrite.exe 2015-04-13 20:09:33 FDD26A402322F212DCA153FF8B1FFB6E 78816 ----a-w- C:\Users\Gert\AppData\Local\Temp\jrt\tweaking.com_registry_backup_portable\pcwintech_tasksch.dll 2015-04-13 20:09:33 E0DC8C6BBC787B972A9A468648DBFD85 1008128 ----a-w- C:\Users\Gert\AppData\Local\Temp\jrt\libiconv2.dll 2015-04-13 20:09:33 DC7A3BC0FC185CD68848DC6F7D7B026B 40960 ----a-w- C:\Users\Gert\AppData\Local\Temp\jrt\tweaking.com_registry_backup_portable\SSubTmr6.dll 2015-04-13 20:09:33 D202BAA425176287017FFE1FB5D1B77C 103424 ----a-w- C:\Users\Gert\AppData\Local\Temp\jrt\libintl3.dll 2015-04-13 20:09:33 A107DE2D120C0571B544EEC53D1971AB 1406208 ----a-w- C:\Users\Gert\AppData\Local\Temp\jrt\tweaking.com_registry_backup_portable\TweakingRegistryBackup.exe 2015-04-13 20:09:33 57CAC848FA14AE38F14F9441F8933282 140288 ----a-w- C:\Users\Gert\AppData\Local\Temp\jrt\pcre3.dll 2015-04-13 20:09:33 547C43567AB8C08EB30F6C6BACB479A3 79360 ----a-w- C:\Users\Gert\AppData\Local\Temp\jrt\regex2.dll 2015-04-13 20:09:33 1B128828BF5E4353811B6DA58156B7F4 6656 ----a-w- C:\Users\Gert\AppData\Local\Temp\jrt\tweaking.com_registry_backup_portable\files\dosdev.exe 2015-04-13 19:19:39 45914892734A397593C69679CD437F5C 711168 ----a-w- C:\Users\Gert\AppData\Local\Temp\Txnogam=Gamblock.PreventBlockGamblingPkeygen__10609_il221058.exe 2015-04-13 18:51:14 67EDC5F6B09705DBB8AFCBEC4D52A96A 519680 ----a-w- C:\Users\Gert\AppData\Local\Temp\msupdate71\msvcrt.dll 2015-04-11 23:00:12 1F376124150BC66C3671B3F75406A913 2556928 ----a-w- C:\Users\Gert\AppData\Local\Temp\5040\temp\KingfisherAccess.xyz.exe ====== Java Cache ===== ====== C:\Windows\SysWOW64 ===== 2015-04-15 11:45:33 E981C27FA6C2F45C135DB4AF78D6FE1F 92672 ----a-w- C:\Windows\SysWOW64\wudriver.dll 2015-04-15 11:45:33 C7E498E41D92CF8C2EAED9995781A7F7 29696 ----a-w- C:\Windows\SysWOW64\wups.dll 2015-04-15 11:45:33 9D68CE45935C439D5082ECB56902124D 566784 ----a-w- C:\Windows\SysWOW64\wuapi.dll 2015-04-15 11:45:33 751C4859FD46A1461B3FB57252F541D8 33792 ----a-w- C:\Windows\SysWOW64\wuapp.exe 2015-04-15 11:45:33 031C03C9639CE0D294695968C68A5775 173056 ----a-w- C:\Windows\SysWOW64\wuwebv.dll 2015-04-15 11:45:24 2B381229CCACA02AFF9D27B09073E523 311808 ----a-w- C:\Windows\SysWOW64\gdi32.dll 2015-04-15 11:45:13 B56B43F63E087649DB11288590C06B0C 14373376 ----a-w- C:\Windows\SysWOW64\mshtml.dll 2015-04-15 11:45:11 C595472C049C342798F71BB1A28BF8E7 13767680 ----a-w- C:\Windows\SysWOW64\ieframe.dll 2015-04-15 11:45:09 B2E4D1A446BA1BAFF74F90A97A5C7E48 1181696 ----a-w- C:\Windows\SysWOW64\urlmon.dll 2015-04-15 11:45:09 8E756F3DA62C1C4B27386B16350CA92C 1441280 ----a-w- C:\Windows\SysWOW64\inetcpl.cpl 2015-04-15 11:45:09 2998832C2741DA50AECB4918A5C3D1DE 1763328 ----a-w- C:\Windows\SysWOW64\wininet.dll 2015-04-15 11:45:08 FB310E1FD364B4C409F7A5777E65D266 109056 ----a-w- C:\Windows\SysWOW64\iesysprep.dll 2015-04-15 11:45:08 FAACF20B4E1832633CAAA162F4C72B7B 493056 ----a-w- C:\Windows\SysWOW64\msfeeds.dll 2015-04-15 11:45:08 611E2914CA0714A7C9533488553A9453 2864640 ----a-w- C:\Windows\SysWOW64\jscript9.dll 2015-04-15 11:45:07 C3B714492E2C8277C999E035442F8BB3 2055680 ----a-w- C:\Windows\SysWOW64\iertutil.dll 2015-04-15 11:45:07 BF3C88256C698FF1C7C986BD36550F11 226816 ----a-w- C:\Windows\SysWOW64\iedkcs32.dll 2015-04-15 11:45:07 8B3F5746480A983582449D6D42198D8A 391168 ----a-w- C:\Windows\SysWOW64\ieui.dll 2015-04-15 11:45:06 69B334A984AC5504DB33F0932BCF0D7E 523776 ----a-w- C:\Windows\SysWOW64\vbscript.dll 2015-04-15 11:45:06 4DC5C16FDDCFE474321F4A5ABE484B49 690688 ----a-w- C:\Windows\SysWOW64\jscript.dll 2015-04-15 11:45:04 FC66B75EAB2D15551F5632B107818EC8 33280 ----a-w- C:\Windows\SysWOW64\iernonce.dll 2015-04-15 11:45:04 C1E3790C8A05C9FA7931A26048576F5D 357888 ----a-w- C:\Windows\SysWOW64\dxtmsft.dll 2015-04-15 11:45:04 9C330289F11A575EA853DC1A66CE3036 226816 ----a-w- C:\Windows\SysWOW64\dxtrans.dll 2015-04-15 11:45:04 3BAAFA932463A79C9932CF27629C1EF7 163840 ----a-w- C:\Windows\SysWOW64\msrating.dll 2015-04-15 11:45:04 1D4F2706A928E0FA3230FA9E9A6DCB32 80384 ----a-w- C:\Windows\SysWOW64\mshtmled.dll 2015-04-15 11:45:03 8CBC91467A1CA066580BF180D841C374 361984 ----a-w- C:\Windows\SysWOW64\html.iec 2015-04-15 11:45:03 89F6BFF6982FD771B72815EC669613DE 39424 ----a-w- C:\Windows\SysWOW64\jsproxy.dll 2015-04-15 11:45:03 0421DC13D11967F439BB8132914EC9C4 61440 ----a-w- C:\Windows\SysWOW64\iesetup.dll 2015-04-15 11:45:02 3BF02AA1121467362696867EF38613CA 2706432 ----a-w- C:\Windows\SysWOW64\mshtml.tlb 2015-04-15 11:45:02 1F44C25394222A09F77C91174259FB73 71680 ----a-w- C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2015-04-15 11:45:00 DA5B856A037872BE089CA6967C7050C5 1237504 ----a-w- C:\Windows\SysWOW64\msxml3.dll 2015-04-15 11:45:00 78492CF3C3697FB5AF4EAABB2BAF8595 2048 ----a-w- C:\Windows\SysWOW64\msxml3r.dll 2015-04-15 11:44:51 32B9FEE479FF55234ED6BCF1D7976189 1309696 ----a-w- C:\Windows\SysWOW64\ntdll.dll 2015-04-15 11:44:51 11896E75E1A118ABFAD126BEB650A189 3920824 ----a-w- C:\Windows\SysWOW64\ntoskrnl.exe 2015-04-15 11:44:49 A6A644BFAE31F111F35F8C3C7BA2A8A0 3976632 ----a-w- C:\Windows\SysWOW64\ntkrnlpa.exe 2015-04-15 11:44:49 99DE8BADC0E85C9AB4A8301A3723FFEA 1114112 ----a-w- C:\Windows\SysWOW64\kernel32.dll 2015-04-15 11:44:48 BC09159AFF6639DB2CB28058731199F0 248832 ----a-w- C:\Windows\SysWOW64\schannel.dll 2015-04-15 11:44:47 DB7CFA08957C94F6CFAA0DBB8BE4B906 550912 ----a-w- C:\Windows\SysWOW64\kerberos.dll 2015-04-15 11:44:46 56977F27A96383E2A6C8BACEFC17E9CA 259584 ----a-w- C:\Windows\SysWOW64\msv1_0.dll 2015-04-15 11:44:46 2DE438AE95C59FB33B3E4E34827C1100 221184 ----a-w- C:\Windows\SysWOW64\ncrypt.dll 2015-04-15 11:44:45 E6A73ED322D8D0E85589894157F81940 25600 ----a-w- C:\Windows\SysWOW64\setup16.exe 2015-04-15 11:44:45 A057B61F8A553F6DA38563597FA3676B 65536 ----a-w- C:\Windows\SysWOW64\TSpkg.dll 2015-04-15 11:44:45 655C88135254C78E6FB66B6C2F6AC5DA 172032 ----a-w- C:\Windows\SysWOW64\wdigest.dll 2015-04-15 11:44:44 A169307F0105183092F2AEDA9A8BD15D 43008 ----a-w- C:\Windows\SysWOW64\srclient.dll 2015-04-15 11:44:44 6F8CEB8115737D2E049804B191AE41A9 50176 ----a-w- C:\Windows\SysWOW64\auditpol.exe 2015-04-15 11:44:44 06C69684C3730E1A31DF06D4DD4042BC 14336 ----a-w- C:\Windows\SysWOW64\ntvdm64.dll 2015-04-15 11:44:43 C2A7AEA0A0FF0E7284632902FF9BD73A 96768 ----a-w- C:\Windows\SysWOW64\sspicli.dll 2015-04-15 11:44:43 6A9FFEF19C4F8F2E9082A50BB07ECDF1 22016 ----a-w- C:\Windows\SysWOW64\secur32.dll 2015-04-15 11:44:43 52C84F726B8B84634F2E666C49076CDE 274944 ----a-w- C:\Windows\SysWOW64\KernelBase.dll 2015-04-15 11:44:43 47A1F23EE40C2389FCD53E9D5CEA3430 17408 ----a-w- C:\Windows\SysWOW64\credssp.dll 2015-04-15 11:44:42 0FF9EEFF3EFC725FD90AD2CDA5A96776 5120 ----a-w- C:\Windows\SysWOW64\wow32.dll 2015-04-15 11:44:31 FC898E44379D877DE92D869E713528CD 7680 ----a-w- C:\Windows\SysWOW64\instnm.exe 2015-04-15 11:44:31 C557EB6CD735B4EE5076EA289B02CEAC 6656 ----a-w- C:\Windows\SysWOW64\apisetschema.dll 2015-04-15 11:44:31 53C485BC8BBD41877F58AEB89412F5D7 2048 ----a-w- C:\Windows\SysWOW64\user.exe 2015-04-15 11:44:30 2E0F849B7BF17969E45881FA4EB9B487 686080 ----a-w- C:\Windows\SysWOW64\adtschema.dll 2015-04-15 11:44:29 C0693456929F40833B9CC36C9CF7E3A8 146432 ----a-w- C:\Windows\SysWOW64\msaudite.dll 2015-04-15 11:44:26 4B21D227B191A6305087BDD6BB19220F 60416 ----a-w- C:\Windows\SysWOW64\msobjs.dll 2015-04-15 11:43:46 D824C1C235349B67E652A5CA70D1AA49 58880 ----a-w- C:\Windows\SysWOW64\clfsw32.dll 2015-04-13 23:47:24 D24D027C69A4112C5782C173254510A4 298 ----a-w- C:\Windows\SysWOW64\.crusader 2015-04-13 22:24:05 F461F8627D7644F415743B4EF2370D67 512 ----a-w- C:\Windows\SysWOW64\restore.bat 2015-04-13 22:24:04 C98E68721CAE114EFFBAEE2F5AA1EA78 365056 ----a-w- C:\Windows\SysWOW64\BfLibcurlx64.dll 2015-04-13 22:24:04 2D9E50D0D4FA1D537003F41696C1B5A8 177152 ----a-w- C:\Windows\SysWOW64\agsecure.dll 2015-04-13 22:24:03 17528F772BD20D1BA66AE0CF114980ED 606584 ----a-w- C:\Windows\SysWOW64\BfUpdater.exe 2015-04-13 19:26:24 974696E8C06F773F4C70330CCD030034 4 ----a-w- C:\Windows\SysWOW64\029B560A371F4E00AB32838EBC01B9E7 ====== C:\Windows\SysWOW64\drivers ===== 2015-04-13 21:04:11 7EAB073BF5949ED639660787A01B623D 30616 ----a-w- C:\Windows\SysWOW64\drivers\hitmanpro37.sys ====== C:\Windows\Sysnative ===== 2015-04-15 11:45:33 C5D90D20035928387FE27E4485EE463F 36864 ----a-w- C:\Windows\Sysnative\wuapp.exe 2015-04-15 11:45:32 AECC03D0A794619E15FF1CB92D65EF9E 191488 ----a-w- C:\Windows\Sysnative\wuwebv.dll 2015-04-15 11:45:32 AEA602B4036CF95522818E911654F52E 135168 ----a-w- C:\Windows\Sysnative\wuauclt.exe 2015-04-15 11:45:32 95A9A336CFF6AC51B33BBFDBEA6D848B 60416 ----a-w- C:\Windows\Sysnative\WinSetupUI.dll 2015-04-15 11:45:32 6C21C983C1F83900DBEDE51DCA247B72 696320 ----a-w- C:\Windows\Sysnative\wuapi.dll 2015-04-15 11:45:32 6BAC8DCC6C58755A1B9E6D3B04C28FC5 12288 ----a-w- C:\Windows\Sysnative\wu.upgrade.ps.dll 2015-04-15 11:45:32 2ADEA6F221BBF0992FDF9A3E25BA9F59 98304 ----a-w- C:\Windows\Sysnative\wudriver.dll 2015-04-15 11:45:32 2A77BD58F0A8D3743D4299434390922E 35328 ----a-w- C:\Windows\Sysnative\wups.dll 2015-04-15 11:45:32 21DF773EF8EFEF531E7E0BF477E03047 3298816 ----a-w- C:\Windows\Sysnative\wucltux.dll 2015-04-15 11:45:32 21CA4277E6918B019525ECCD748EF401 37376 ----a-w- C:\Windows\Sysnative\wups2.dll 2015-04-15 11:45:32 0814A74C853F50B354F08F83DDA9F7FB 2553856 ----a-w- C:\Windows\Sysnative\wuaueng.dll 2015-04-15 11:45:25 72098048AB8AE2CAFA4ECE35D5051D62 404480 ----a-w- C:\Windows\Sysnative\gdi32.dll 2015-04-15 11:45:23 E72C92A252EC4B230287BC6E06F24296 957952 ----a-w- C:\Windows\Sysnative\appraiser.dll 2015-04-15 11:45:23 7150E809474BBD4D4AD24B13FA2454E5 1239720 ----a-w- C:\Windows\Sysnative\aitstatic.exe 2015-04-15 11:45:23 5D0A492C42A43DCF73284F2865519712 30720 ----a-w- C:\Windows\Sysnative\acmigration.dll 2015-04-15 11:45:23 3FCD3FE7F58935A85ACC33019129358E 419840 ----a-w- C:\Windows\Sysnative\devinv.dll 2015-04-15 11:45:23 0E0723E6D064ACD3D603BEF93EE0B950 769536 ----a-w- C:\Windows\Sysnative\invagent.dll 2015-04-15 11:45:23 05ED759DD0821294F05A41F6A8F1E18F 726528 ----a-w- C:\Windows\Sysnative\generaltel.dll 2015-04-15 11:45:22 826A7F422014E4762C700B4254F5C588 1111552 ----a-w- C:\Windows\Sysnative\aeinv.dll 2015-04-15 11:45:22 205EE22E14A9848FB2266FF035BE0C9C 192000 ----a-w- C:\Windows\Sysnative\aepic.dll 2015-04-15 11:45:21 3F0FFBA1765470F979D57F88248070CA 227328 ----a-w- C:\Windows\Sysnative\aepdu.dll 2015-04-15 11:45:17 E0AED0202A8B74D9D460B123EA426A0C 19292672 ----a-w- C:\Windows\Sysnative\mshtml.dll 2015-04-15 11:45:13 FAE80D6499ECB6A8AA90395587304338 15409152 ----a-w- C:\Windows\Sysnative\ieframe.dll 2015-04-15 11:45:10 11306EED81A8F0A48AFBB3960FFAD07E 2237952 ----a-w- C:\Windows\Sysnative\wininet.dll 2015-04-15 11:45:09 A2CCA77B51F2EE47782FFC7032683DAB 1409024 ----a-w- C:\Windows\Sysnative\urlmon.dll 2015-04-15 11:45:08 F124B3624629B873AF58895459D45AFA 3959296 ----a-w- C:\Windows\Sysnative\jscript9.dll 2015-04-15 11:45:08 9CA76669EFAF752C8466399B2C85EE7F 1509376 ----a-w- C:\Windows\Sysnative\inetcpl.cpl 2015-04-15 11:45:08 970FF660EF8AD2226F961956EDE5995D 2656256 ----a-w- C:\Windows\Sysnative\iertutil.dll 2015-04-15 11:45:07 6622A3B2B32401D5DDF8C0AD8DE3EC62 136704 ----a-w- C:\Windows\Sysnative\iesysprep.dll 2015-04-15 11:45:07 543EBCED2F2F56FD3EB89D48990797B4 255488 ----a-w- C:\Windows\Sysnative\iedkcs32.dll 2015-04-15 11:45:07 4CE94E6EE991630FD55A039408265B5E 603136 ----a-w- C:\Windows\Sysnative\msfeeds.dll 2015-04-15 11:45:06 AC61CF7133735CF0B515CE9CF76FFFCF 855552 ----a-w- C:\Windows\Sysnative\jscript.dll 2015-04-15 11:45:06 836CD26ADF5DA10298170E5F48007E68 600576 ----a-w- C:\Windows\Sysnative\vbscript.dll 2015-04-15 11:45:06 7F1089E6686B3B6701B938541F758ABE 526336 ----a-w- C:\Windows\Sysnative\ieui.dll 2015-04-15 11:45:05 D934C9077EDA71804EBE651DE66CE34F 281600 ----a-w- C:\Windows\Sysnative\dxtrans.dll 2015-04-15 11:45:04 413913937E61131A39C1E7EF44619C9D 39936 ----a-w- C:\Windows\Sysnative\iernonce.dll 2015-04-15 11:45:04 37945B4D9C7E269805233FF059D9FEAE 51712 ----a-w- C:\Windows\Sysnative\ie4uinit.exe 2015-04-15 11:45:04 2B899BC489D7950AE1491D944135E09C 197120 ----a-w- C:\Windows\Sysnative\msrating.dll 2015-04-15 11:45:04 08108FCC6B3A139B28E4AF5D24F81737 97280 ----a-w- C:\Windows\Sysnative\mshtmled.dll 2015-04-15 11:45:03 D3F731B732ED37ADA1C4EA8C9520375D 441856 ----a-w- C:\Windows\Sysnative\html.iec 2015-04-15 11:45:03 52F2AD86F9803866CA534B223C1CFCCC 53248 ----a-w- C:\Windows\Sysnative\jsproxy.dll 2015-04-15 11:45:03 48D9D404297B2A1413BA6BE2CA4A73CA 67072 ----a-w- C:\Windows\Sysnative\iesetup.dll 2015-04-15 11:45:03 441BCB8344E15F3BF42852A9C365BF59 89600 ----a-w- C:\Windows\Sysnative\RegisterIEPKEYs.exe 2015-04-15 11:45:03 0FD08EAF7EF87E5D352937AE207C46AA 451584 ----a-w- C:\Windows\Sysnative\dxtmsft.dll 2015-04-15 11:45:02 9FDA50FEE3BE68E1626AF04D70722648 2706432 ----a-w- C:\Windows\Sysnative\mshtml.tlb 2015-04-15 11:45:00 2AA1704C1475AD9D18560AD07BDA66DF 2048 ----a-w- C:\Windows\Sysnative\msxml3r.dll 2015-04-15 11:45:00 0B85F3551337FE233477DA31545DC45C 1882624 ----a-w- C:\Windows\Sysnative\msxml3.dll 2015-04-15 11:44:53 DCB7D8034C773ADB660FA8F1139AC0A0 5557696 ----a-w- C:\Windows\Sysnative\ntoskrnl.exe 2015-04-15 11:44:53 96C2380819EBAC0BF592A7E8977E9E8A 1727904 ----a-w- C:\Windows\Sysnative\ntdll.dll 2015-04-15 11:44:51 E75074EFBE3C24FBC95C7C1985E08FDE 1163264 ----a-w- C:\Windows\Sysnative\kernel32.dll 2015-04-15 11:44:51 B47C4E8E9AF9044F9D59443196D54608 424448 ----a-w- C:\Windows\Sysnative\KernelBase.dll 2015-04-15 11:44:49 CBEFBE487F0C09EE0F8AC5299447450E 362496 ----a-w- C:\Windows\Sysnative\wow64win.dll 2015-04-15 11:44:49 5EA8A53A243ED52DA1F705D000854B2A 341504 ----a-w- C:\Windows\Sysnative\schannel.dll 2015-04-15 11:44:48 6DEDB5E0258998C01C26280DBDB2A4B9 1461760 ----a-w- C:\Windows\Sysnative\lsasrv.dll 2015-04-15 11:44:47 F87B5878D7621A16A0A5CF1D94BE5A53 503808 ----a-w- C:\Windows\Sysnative\srcore.dll 2015-04-15 11:44:47 EA32F4EA3AE06EDD122FBCD5A489E457 215040 ----a-w- C:\Windows\Sysnative\winsrv.dll 2015-04-15 11:44:47 B00F1AC213172C557EF84F71E4DF5EA3 243712 ----a-w- C:\Windows\Sysnative\wow64.dll 2015-04-15 11:44:47 A32CA33E8692DA882133341AF31A4C36 338432 ----a-w- C:\Windows\Sysnative\conhost.exe 2015-04-15 11:44:47 8E615D40A652999B224EDBBFA7B4035B 728064 ----a-w- C:\Windows\Sysnative\kerberos.dll 2015-04-15 11:44:47 5E9E31A2F213E757184EB2CA4B562E6C 296960 ----a-w- C:\Windows\Sysnative\rstrui.exe 2015-04-15 11:44:46 F36EF8DBE5CE842B8F04515BF422DFB4 314880 ----a-w- C:\Windows\Sysnative\msv1_0.dll 2015-04-15 11:44:46 CB33B9F21F06764DCA561FC194823199 309760 ----a-w- C:\Windows\Sysnative\ncrypt.dll 2015-04-15 11:44:46 7220246418A40D3BF7470058A2DB939A 210944 ----a-w- C:\Windows\Sysnative\wdigest.dll 2015-04-15 11:44:45 CACB6D061EAAE5CEB9203A26127843AF 64000 ----a-w- C:\Windows\Sysnative\auditpol.exe 2015-04-15 11:44:45 CA4FC33FB22D92368A0B221092B46374 31232 ----a-w- C:\Windows\Sysnative\lsass.exe 2015-04-15 11:44:45 799E731B83F911A6220E678722A73DDF 86528 ----a-w- C:\Windows\Sysnative\TSpkg.dll 2015-04-15 11:44:45 234529666FB5BBE12343FF58380E8234 136192 ----a-w- C:\Windows\Sysnative\sspicli.dll 2015-04-15 11:44:45 0B6514A14631E41DE4D6D40D1C80BE68 112640 ----a-w- C:\Windows\Sysnative\smss.exe 2015-04-15 11:44:44 CFDA43CD05B94C4853042E4A9561B156 43520 ----a-w- C:\Windows\Sysnative\csrsrv.dll 2015-04-15 11:44:44 C631969919195C040E135CC380018A65 29184 ----a-w- C:\Windows\Sysnative\sspisrv.dll 2015-04-15 11:44:44 5905040249D279F61AE988A7F5F0D241 22016 ----a-w- C:\Windows\Sysnative\credssp.dll 2015-04-15 11:44:44 2ABF1BA930E5CE0017D6197A06B03E07 50176 ----a-w- C:\Windows\Sysnative\srclient.dll 2015-04-15 11:44:44 1150C2D3C72887571581DF6D0E58540D 16384 ----a-w- C:\Windows\Sysnative\ntvdm64.dll 2015-04-15 11:44:43 DE328CD9E0678A55880C2189EE5BDBDC 13312 ----a-w- C:\Windows\Sysnative\wow64cpu.dll 2015-04-15 11:44:43 978BC01DD41125DED32AC03925A16578 28160 ----a-w- C:\Windows\Sysnative\secur32.dll 2015-04-15 11:44:31 39D0217773202CF09F13C1E420CBA6CA 6656 ----a-w- C:\Windows\Sysnative\apisetschema.dll 2015-04-15 11:44:30 3474740668B86841E999893D9314193E 686080 ----a-w- C:\Windows\Sysnative\adtschema.dll 2015-04-15 11:44:29 55BF60184106FCF60B999CDEB4EACB2E 146432 ----a-w- C:\Windows\Sysnative\msaudite.dll 2015-04-15 11:44:26 88B6EDA230EFEFC780AF717AA9640CAD 60416 ----a-w- C:\Windows\Sysnative\msobjs.dll 2015-04-15 11:43:47 745DE455E02693423B1B78F448D52961 79360 ----a-w- C:\Windows\Sysnative\clfsw32.dll 2015-04-15 11:43:47 404B7DF9CA4D1CB675045AF220FF3285 367552 ----a-w- C:\Windows\Sysnative\clfs.sys ====== C:\Windows\Sysnative\drivers ===== 2015-04-17 15:48:17 E9CD058C79EA15B4AA93E259FA713B07 136408 ----a-w- C:\Windows\Sysnative\drivers\MBAMSwissArmy.sys 2015-04-17 15:47:51 CF12E148C6FC151335B7D7FE03F1C7A2 25816 ----a-w- C:\Windows\Sysnative\drivers\mbam.sys 2015-04-17 15:47:51 68C3B11D1ED8C97648BEEFEC37E93E74 107736 ----a-w- C:\Windows\Sysnative\drivers\mbamchameleon.sys 2015-04-17 15:47:51 0CE2F3E26C770CBAEB50787A2C1FD09E 63704 ----a-w- C:\Windows\Sysnative\drivers\mwac.sys 2015-04-15 11:44:46 1FA627E63195BF3BF636BFEF0D7190D4 155576 ----a-w- C:\Windows\Sysnative\drivers\ksecpkg.sys 2015-04-15 11:44:46 063C09DB965E3DFD6F4F08416F6DB8F5 95672 ----a-w- C:\Windows\Sysnative\drivers\ksecdd.sys 2015-04-15 11:43:48 F61634BEC53F73702A10DE69F6DCAF57 754688 ----a-w- C:\Windows\Sysnative\drivers\http.sys ====== C:\Windows\Tasks ====== 2015-04-13 19:46:19 6239023CA963C4C61989ED0F8D5B003B 3138 ----a-w- C:\Windows\Sysnative\Tasks\{E851EB05-4541-4747-A1DD-B4462DF4EBFC} ====== C:\Windows\Temp ====== ======= C:\Program Files ===== 2015-04-20 15:36:13 -------- d-----w- C:\Program Files\trend micro ======= C:\PROGRA~2 ===== 2015-04-15 00:01:43 -------- d-----w- C:\PROGRA~2\PDF Eraser 2015-04-13 21:03:18 -------- d-----w- C:\PROGRA~2\HitmanPro ======= C: ===== ====== C:\Users\Gert\AppData\Roaming ====== 2015-04-14 23:42:13 -------- d-----w- C:\Users\Gert\AppData\Roaming\YCanPDF 2015-03-31 23:24:59 -------- d-----w- C:\Users\Gert\AppData\Roaming\tiger ====== C:\Users\Gert ====== 2015-04-17 22:52:34 D04376DEA3BBC55AFCE362707815789A 6420600 ----a-w- C:\Users\Gert\Downloads\FileZilla_3.10.3_win64-setup.exe 2015-04-17 15:43:34 -------- d-----w- C:\Users\Gert\Tracing 2015-04-15 00:01:46 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDF Eraser ====== C: exe-files == 2015-04-20 15:36:13 9A2347903D6EDB84C10F288BC0578C1C 388608 ----a-w- C:\Program Files\trend micro\Gert.exe 2015-04-17 22:52:34 D04376DEA3BBC55AFCE362707815789A 6420600 ----a-w- C:\Users\Gert\Downloads\FileZilla_3.10.3_win64-setup.exe 2015-04-17 15:03:03 B0E2B7813094940E791B0D6123E782D8 562088 ----a-w- C:\Users\Gert\AppData\Local\Temp\jre-8u45-windows-au.exe 2015-04-15 11:45:33 C5D90D20035928387FE27E4485EE463F 36864 ----a-w- C:\Windows\System32\wuapp.exe 2015-04-15 11:45:33 751C4859FD46A1461B3FB57252F541D8 33792 ----a-w- C:\Windows\SysWOW64\wuapp.exe 2015-04-15 11:45:32 AEA602B4036CF95522818E911654F52E 135168 ----a-w- C:\Windows\System32\wuauclt.exe 2015-04-15 11:45:23 7150E809474BBD4D4AD24B13FA2454E5 1239720 ----a-w- C:\Windows\System32\aitstatic.exe 2015-04-15 11:45:23 17D815AD21D4325CD589E57A9582E311 70840 ----a-w- C:\Windows\System32\CompatTel\diagtrackrunner.exe 2015-04-15 11:45:21 8D06AAF1723B514C412187C5B8B67EEF 46752 ----a-w- C:\Windows\System32\CompatTel\wicainventory.exe 2015-04-15 11:45:21 4AC38FC4C6894B21698A99B9129B1EA4 161952 ----a-w- C:\Windows\System32\CompatTel\QueryAppBlock.exe 2015-04-15 11:45:09 56E8376E528552545F24A7CFF2B95C63 775320 ----a-w- C:\Program Files\Internet Explorer\iexplore.exe 2015-04-15 11:45:09 480BB68DF3C368C3F7492D4BA1E1CAFB 770704 ----a-w- C:\Program Files (x86)\Internet Explorer\iexplore.exe 2015-04-15 11:45:07 E143DEA0C0FA2049C85BAD1888F8C117 485888 ----a-w- C:\Program Files\Internet Explorer\ieinstal.exe 2015-04-15 11:45:07 B6029A23F5EE419D96D38B2981D4C829 470528 ----a-w- C:\Program Files (x86)\Internet Explorer\ieinstal.exe 2015-04-15 11:45:04 37945B4D9C7E269805233FF059D9FEAE 51712 ----a-w- C:\Windows\System32\ie4uinit.exe 2015-04-15 11:45:03 E9A254D1239E386033E4811486BD0BAF 223744 ----a-w- C:\Program Files\Internet Explorer\ielowutil.exe 2015-04-15 11:45:03 441BCB8344E15F3BF42852A9C365BF59 89600 ----a-w- C:\Windows\System32\RegisterIEPKEYs.exe 2015-04-15 11:45:03 0788DC9E092D1D58AF43F5043F17BC99 222208 ----a-w- C:\Program Files (x86)\Internet Explorer\ielowutil.exe 2015-04-15 11:45:02 1F44C25394222A09F77C91174259FB73 71680 ----a-w- C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2015-04-15 11:44:53 DCB7D8034C773ADB660FA8F1139AC0A0 5557696 ----a-w- C:\Windows\System32\ntoskrnl.exe 2015-04-15 11:44:51 11896E75E1A118ABFAD126BEB650A189 3920824 ----a-w- C:\Windows\SysWOW64\ntoskrnl.exe 2015-04-15 11:44:49 A6A644BFAE31F111F35F8C3C7BA2A8A0 3976632 ----a-w- C:\Windows\SysWOW64\ntkrnlpa.exe 2015-04-15 11:44:47 A32CA33E8692DA882133341AF31A4C36 338432 ----a-w- C:\Windows\System32\conhost.exe 2015-04-15 11:44:47 5E9E31A2F213E757184EB2CA4B562E6C 296960 ----a-w- C:\Windows\System32\rstrui.exe 2015-04-15 11:44:45 E6A73ED322D8D0E85589894157F81940 25600 ----a-w- C:\Windows\SysWOW64\setup16.exe 2015-04-15 11:44:45 CACB6D061EAAE5CEB9203A26127843AF 64000 ----a-w- C:\Windows\System32\auditpol.exe 2015-04-15 11:44:45 CA4FC33FB22D92368A0B221092B46374 31232 ----a-w- C:\Windows\System32\lsass.exe 2015-04-15 11:44:45 0B6514A14631E41DE4D6D40D1C80BE68 112640 ----a-w- C:\Windows\System32\smss.exe 2015-04-15 11:44:44 6F8CEB8115737D2E049804B191AE41A9 50176 ----a-w- C:\Windows\SysWOW64\auditpol.exe 2015-04-15 11:44:31 FC898E44379D877DE92D869E713528CD 7680 ----a-w- C:\Windows\SysWOW64\instnm.exe 2015-04-15 11:44:31 53C485BC8BBD41877F58AEB89412F5D7 2048 ----a-w- C:\Windows\SysWOW64\user.exe === C: other files == 2015-04-22 01:50:59 B831536A4C08D56B42542438C381A308 952350 ----a-w- C:\Users\Gert\Desktop\Master bedrijfscommunicatie\Thesis\Gebruik van FB bij jongvolwassenen ivh tot sociaal kapitaal\Voortgangsnota masterproef\Feedback\Documenten gesprek Anna Berbers 20 april.zip 2015-04-22 01:26:44 F42B1B96DEA25D1EFCA1A797BBDCC7DA 463106 ----a-w- C:\Users\Gert\Dropbox\Apps\UpdraftPlus\backup_2015-04-22-0221_Uw_Copywriter_c31f63f0f2cf-others.zip 2015-04-22 01:26:41 68925DC9EACF4AEFC29692EB12527023 14608493 ----a-w- C:\Users\Gert\Dropbox\Apps\UpdraftPlus\backup_2015-04-22-0221_Uw_Copywriter_c31f63f0f2cf-uploads.zip 2015-04-22 01:25:19 8E0689FB8F044751E1C099631C1C449D 2536985 ----a-w- C:\Users\Gert\Dropbox\Apps\UpdraftPlus\backup_2015-04-22-0221_Uw_Copywriter_c31f63f0f2cf-themes.zip 2015-04-22 01:25:13 BACE7E8327984CCDD58B1CFA7DBA0A98 13274972 ----a-w- C:\Users\Gert\Dropbox\Apps\UpdraftPlus\backup_2015-04-22-0221_Uw_Copywriter_c31f63f0f2cf-plugins.zip 2015-04-18 01:38:22 06F2F181BE748AE0DFC3D85734423528 2477932 ----a-w- C:\Users\Gert\Dropbox\BELANGRIJK!\Work (18-04-2015)\Blauwzwartfans\Mysql database.zip 2015-04-18 01:37:44 A8DEA469C446B94A96B04F9C095D5F8B 1313 ----a-w- C:\Users\Gert\Dropbox\BELANGRIJK!\Work (18-04-2015)\Newsfun\Wordpress regelmatige backup Newsfun\settings.zip 2015-04-18 01:37:42 34E1829D4FF2F5F8F0EE481C806CACDA 4096 ---ha-w- C:\Users\Gert\Dropbox\BELANGRIJK!\Work (18-04-2015)\Newsfun\Wordpress regelmatige backup Newsfun\._settings.zip 2015-04-18 01:36:50 0C93A55B3FE8D37F5DA51E6274840F8A 26391128 ----a-w- C:\Users\Gert\Dropbox\BELANGRIJK!\Work (18-04-2015)\Gratis Beleggen\Werkzaamheden Kevin van den Burg\Theme changes\wiseguys_v3.1.zip 2015-04-18 01:36:38 0C93A55B3FE8D37F5DA51E6274840F8A 26391128 ----a-w- C:\Users\Gert\Dropbox\BELANGRIJK!\Work (18-04-2015)\Gratis Beleggen\Updaten thema via uitleg forum\Bestanden doorsturen naar Willem\wiseguys_v3.1.zip 2015-04-18 01:36:37 A7F16C19DBEE550E6858DDDD82836EAD 25795539 ----a-w- C:\Users\Gert\Dropbox\BELANGRIJK!\Work (18-04-2015)\Gratis Beleggen\Updaten thema via uitleg forum\Bestanden doorsturen naar Willem\wiseguys_v2.4.zip 2015-04-18 01:35:42 1A9761FE97BE9808AAD43799945BEC87 23730977 ----a-w- C:\Users\Gert\Dropbox\BELANGRIJK!\Work (18-04-2015)\Gratis Beleggen\Updaten thema via uitleg forum\Backup WP bestanden 25 december 2014\gratisbeleggen.be\public_html\wp-content\updraft\backup_2014-12-24-2342_non_alpha_name_37383e0d9ddb-uploads.zip 2015-04-18 01:35:40 88449264C9EC46D07A858E8EF6F7887E 22974416 ----a-w- C:\Users\Gert\Dropbox\BELANGRIJK!\Work (18-04-2015)\Gratis Beleggen\Updaten thema via uitleg forum\Backup WP bestanden 25 december 2014\gratisbeleggen.be\public_html\wp-content\updraft\backup_2014-12-23-2347_non_alpha_name_a932f3ca9fe5-uploads.zip 2015-04-18 01:35:40 45EE43DF6800656DD393A42D833EBA69 15123040 ----a-w- C:\Users\Gert\Dropbox\BELANGRIJK!\Work (18-04-2015)\Gratis Beleggen\Updaten thema via uitleg forum\Backup WP bestanden 25 december 2014\gratisbeleggen.be\public_html\wp-content\updraft\backup_2014-12-24-2342_non_alpha_name_37383e0d9ddb-plugins.zip 2015-04-18 01:35:40 431578050E107BAF0F2C22D2F71A542E 27285663 ----a-w- C:\Users\Gert\Dropbox\BELANGRIJK!\Work (18-04-2015)\Gratis Beleggen\Updaten thema via uitleg forum\Backup WP bestanden 25 december 2014\gratisbeleggen.be\public_html\wp-content\updraft\backup_2014-12-24-2342_non_alpha_name_37383e0d9ddb-themes.zip 2015-04-18 01:35:40 1D3D4B0D1D45DD4D90F0751B68A0D5E1 11834 ----a-w- C:\Users\Gert\Dropbox\BELANGRIJK!\Work (18-04-2015)\Gratis Beleggen\Updaten thema via uitleg forum\Backup WP bestanden 25 december 2014\gratisbeleggen.be\public_html\wp-content\updraft\backup_2014-12-24-2342_non_alpha_name_37383e0d9ddb-others.zip 2015-04-18 01:35:38 EC453B2A0F347B012D31FE5F73B4C299 27285663 ----a-w- C:\Users\Gert\Dropbox\BELANGRIJK!\Work (18-04-2015)\Gratis Beleggen\Updaten thema via uitleg forum\Backup WP bestanden 25 december 2014\gratisbeleggen.be\public_html\wp-content\updraft\backup_2014-12-23-2347_non_alpha_name_a932f3ca9fe5-themes.zip 2015-04-18 01:35:36 C6581AC00AE3845685C56E51043E9EB3 15123040 ----a-w- C:\Users\Gert\Dropbox\BELANGRIJK!\Work (18-04-2015)\Gratis Beleggen\Updaten thema via uitleg forum\Backup WP bestanden 25 december 2014\gratisbeleggen.be\public_html\wp-content\updraft\backup_2014-12-23-2347_non_alpha_name_a932f3ca9fe5-plugins.zip 2015-04-18 01:35:35 2824971F81E5E1F1E7A7583AD6ED377E 11834 ----a-w- C:\Users\Gert\Dropbox\BELANGRIJK!\Work (18-04-2015)\Gratis Beleggen\Updaten thema via uitleg forum\Backup WP bestanden 25 december 2014\gratisbeleggen.be\public_html\wp-content\updraft\backup_2014-12-23-2347_non_alpha_name_a932f3ca9fe5-others.zip 2015-04-18 01:35:33 ABFBD29F94A2BDD9BF3C5607D7FCCF15 27211771 ----a-w- C:\Users\Gert\Dropbox\BELANGRIJK!\Work (18-04-2015)\Gratis Beleggen\Updaten thema via uitleg forum\Backup WP bestanden 25 december 2014\gratisbeleggen.be\public_html\wp-content\updraft\backup_2014-05-13-0122_non_alpha_name_299b57802ef5-themes.zip 2015-04-18 01:35:33 202AE08F8FBE64CBD5F308CAAB24BF22 1958410 ----a-w- C:\Users\Gert\Dropbox\BELANGRIJK!\Work (18-04-2015)\Gratis Beleggen\Updaten thema via uitleg forum\Backup WP bestanden 25 december 2014\gratisbeleggen.be\public_html\wp-content\updraft\backup_2014-05-13-0122_non_alpha_name_299b57802ef5-uploads.zip 2015-04-18 01:35:32 E6A86936D1F0689A9A29F99AF5511CC8 9949 ----a-w- C:\Users\Gert\Dropbox\BELANGRIJK!\Work (18-04-2015)\Gratis Beleggen\Updaten thema via uitleg forum\Backup WP bestanden 25 december 2014\gratisbeleggen.be\public_html\wp-content\updraft\backup_2014-05-13-0122_non_alpha_name_299b57802ef5-others.zip 2015-04-18 01:35:32 2B7AE602C05010477C3DD0E834347472 12141268 ----a-w- C:\Users\Gert\Dropbox\BELANGRIJK!\Work (18-04-2015)\Gratis Beleggen\Updaten thema via uitleg forum\Backup WP bestanden 25 december 2014\gratisbeleggen.be\public_html\wp-content\updraft\backup_2014-05-13-0122_non_alpha_name_299b57802ef5-plugins.zip 2015-04-18 01:35:14 6B37B27B7CDAD867CF1109C223EE45FF 924180 ----a-w- C:\Users\Gert\Dropbox\BELANGRIJK!\Work (18-04-2015)\Gratis Beleggen\Updaten thema via uitleg forum\Backup WP bestanden 25 december 2014\gratisbeleggen.be\public_html\wp-content\themes\wiseguys\install\revslider\revslider.zip 2015-04-18 01:33:48 F4CE7E0425DB300324ECCFD6C6BD1D88 21153 ----a-w- C:\Users\Gert\Dropbox\BELANGRIJK!\Work (18-04-2015)\Gratis Beleggen\Updaten thema via uitleg forum\Backup WP bestanden 25 december 2014\gratisbeleggen.be\public_html\wp-content\plugins\revslider\rs-plugin\js.zip 2015-04-17 15:48:17 E9CD058C79EA15B4AA93E259FA713B07 136408 ----a-w- C:\Windows\System32\drivers\MBAMSwissArmy.sys 2015-04-17 15:47:51 CF12E148C6FC151335B7D7FE03F1C7A2 25816 ----a-w- C:\Windows\System32\drivers\mbam.sys 2015-04-17 15:47:51 68C3B11D1ED8C97648BEEFEC37E93E74 107736 ----a-w- C:\Windows\System32\drivers\mbamchameleon.sys 2015-04-17 15:47:51 0CE2F3E26C770CBAEB50787A2C1FD09E 63704 ----a-w- C:\Windows\System32\drivers\mwac.sys 2015-04-15 20:57:08 06F2F181BE748AE0DFC3D85734423528 2477932 ----a-w- C:\Users\Gert\Desktop\Work\Blauwzwartfans\Mysql database.zip 2015-04-15 20:18:42 6D9663531E4F459C766B9BC2F268A80A 49964314 ----a-w- C:\Users\Gert\AppData\Roaming\Skype\My Skype Received Files\Blauwzwartfans.zip 2015-04-15 11:45:21 7EBB5DAD11B1D0B12317A191C8325991 21128 ----a-w- C:\Windows\System32\appraiser\nxquery.sys 2015-04-15 11:44:46 1FA627E63195BF3BF636BFEF0D7190D4 155576 ----a-w- C:\Windows\System32\drivers\ksecpkg.sys 2015-04-15 11:44:46 063C09DB965E3DFD6F4F08416F6DB8F5 95672 ----a-w- C:\Windows\System32\drivers\ksecdd.sys 2015-04-15 11:43:48 F61634BEC53F73702A10DE69F6DCAF57 754688 ----a-w- C:\Windows\System32\drivers\http.sys 2015-04-15 11:43:47 404B7DF9CA4D1CB675045AF220FF3285 367552 ----a-w- C:\Windows\System32\clfs.sys 2015-04-15 09:36:03 AEEFE65A2E81FCAA4B1B8DC2DE9D83F1 14608493 ----a-w- C:\Users\Gert\Dropbox\Apps\UpdraftPlus\backup_2015-04-15-0511_Uw_Copywriter_b0917b017b7f-uploads.zip 2015-04-15 09:36:00 718DAEFC32B2119B0602811E77B4C2CF 13274972 ----a-w- C:\Users\Gert\Dropbox\Apps\UpdraftPlus\backup_2015-04-15-0511_Uw_Copywriter_b0917b017b7f-plugins.zip 2015-04-15 09:35:28 FDA7B7F256C13E8888C166ABAA7FAF9D 2536985 ----a-w- C:\Users\Gert\Dropbox\Apps\UpdraftPlus\backup_2015-04-15-0511_Uw_Copywriter_b0917b017b7f-themes.zip 2015-04-15 09:35:28 19F6E7C7FD2DE3316BCCF8DF26002A3D 463106 ----a-w- C:\Users\Gert\Dropbox\Apps\UpdraftPlus\backup_2015-04-15-0511_Uw_Copywriter_b0917b017b7f-others.zip ==== Startup Registry Enabled ====================== [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun" [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun" [HKEY_USERS\S-1-5-21-2233490464-3742433080-2635956842-1000\Software\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe /autoRun" "Facebook Update"="C:\Users\Gert\AppData\Local\Facebook\Update\FacebookUpdate.exe /c /nocrashserver" "iCloudServices"="C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe" "ApplePhotoStreams"="C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe" "GoogleChromeAutoLaunch_32E6EDDFE2E53411D374648DC59D1FA4"="C:\Program Files (x86)\Google\Chrome\Application\chrome.exe --no-startup-window" [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce] "mctadmin"="C:\Windows\System32\mctadmin.exe" [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce] "mctadmin"="C:\Windows\System32\mctadmin.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "BCSSync"="C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe /DelayServices" "PWRISOVM.EXE"="C:\Program Files (x86)\PowerISO\PWRISOVM.EXE -startup" "IAStorIcon"="C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" "USB3MON"="C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe" "StartCCC"="C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe MSRun" "Adobe ARM"="C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" "SwitchBoard"="C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" "AdobeCS6ServiceManager"="C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe -launchedbylogin" "ShStatEXE"="C:\Program Files (x86)\McAfee\VirusScan Enterprise\SHSTAT.EXE /STANDALONE" "McAfeeUpdaterUI"="C:\Program Files (x86)\McAfee\Common Framework\udaterui.exe /StartedFromRunKey" "APSDaemon"="C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" "iTunesHelper"="C:\Program Files (x86)\iTunes\iTunesHelper.exe" "SunJavaUpdateSched"="C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe /autoRun" "Facebook Update"="C:\Users\Gert\AppData\Local\Facebook\Update\FacebookUpdate.exe /c /nocrashserver" "iCloudServices"="C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe" "ApplePhotoStreams"="C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe" "GoogleChromeAutoLaunch_32E6EDDFE2E53411D374648DC59D1FA4"="C:\Program Files (x86)\Google\Chrome\Application\chrome.exe --no-startup-window" ==== Startup Registry Enabled x64 ====================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "TosVolRegulator"="C:\Program Files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe" "IntelWirelessWiMAX"="C:\Program Files\Intel\WiMAX\Bin\WiMAXCU.exe /tasktray /nosplash" "AdobeAAMUpdater-1.0"="C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" "Connectify Hotspot"="C:\Program Files (x86)\Connectify\Connectify.exe autorun" "Connectify Dispatch"="C:\Program Files (x86)\Connectify\DispatchUI.exe autorun" "SynTPEnh"="%ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe " ==== Startup Folders ====================== 2013-09-26 10:48:34 1139 ----a-w- C:\Users\Gert\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ==== Task Scheduler Jobs ====================== C:\Windows\tasks\Adobe Flash Player Updater.job --a------ C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [14/04/2015 22:12] C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-2233490464-3742433080-2635956842-1000Core.job --a------ C:\Users\Gert\AppData\Local\Facebook\Update\FacebookUpdate.exe [13/11/2013 18:01] C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-2233490464-3742433080-2635956842-1000UA.job --a------ C:\Users\Gert\AppData\Local\Facebook\Update\FacebookUpdate.exe [13/11/2013 18:01] C:\Windows\tasks\GoogleUpdateTaskMachineCore.job --a------ C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [22/09/2013 22:15] C:\Windows\tasks\GoogleUpdateTaskMachineUA.job --a------ C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [22/09/2013 22:15] C:\Windows\tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job --a------ C:\Program Files (x86)\Intel\IntelR ME FW Recovery Agent\bin\Bootstrap.exe [] C:\Windows\tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job --a------ C:\Program Files (x86)\Intel\IntelR ME FW Recovery Agent\bin\Bootstrap.exe [] ==== Other Scheduled Tasks ====================== "C:\Windows\SysNative\tasks\Adobe Flash Player Updater" [C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe] "C:\Windows\SysNative\tasks\AdobeAAMUpdater-1.0-GertLAP-Gert" [C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe] "C:\Windows\SysNative\tasks\CreateChoiceProcessTask" [C:\Windows\System32\browserchoice.exe] "C:\Windows\SysNative\tasks\FacebookUpdateTaskUserS-1-5-21-2233490464-3742433080-2635956842-1000Core" [C:\Users\Gert\AppData\Local\Facebook\Update\FacebookUpdate.exe] "C:\Windows\SysNative\tasks\FacebookUpdateTaskUserS-1-5-21-2233490464-3742433080-2635956842-1000UA" [C:\Users\Gert\AppData\Local\Facebook\Update\FacebookUpdate.exe] "C:\Windows\SysNative\tasks\GoogleUpdateTaskMachineCore" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe] "C:\Windows\SysNative\tasks\GoogleUpdateTaskMachineUA" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe] "C:\Windows\SysNative\tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d" [C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe] "C:\Windows\SysNative\tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon" [C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe] "C:\Windows\SysNative\tasks\Apple\AppleSoftwareUpdate" [C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe] "C:\Windows\SysNative\tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask" [%systemroot%\system32\sc.exe start osppsvc] ==== Firefox Extensions Registry ====================== [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions] "{D19CA586-DD6C-4a0a-96F8-14644F340D60}"="C:\Program Files (x86)\Common Files\McAfee\SystemCore" [27/09/2013 16:54] ==== Fake Chromium Profiles Check ====================== Fake profile C:\Users\Administrator\AppData\Local\Google\Chrome deleted Fake profile C:\Users\Administrator\AppData\Local\Google\Chrome SxS deleted Fake profile C:\Users\Administrator\AppData\Local\Comodo\Dragon deleted Fake profile C:\Users\Gast\AppData\Local\Google\Chrome deleted Fake profile C:\Users\Gast\AppData\Local\Google\Chrome SxS deleted Fake profile C:\Users\Gast\AppData\Local\Comodo\Dragon deleted Fake profile C:\Users\Gert\AppData\Local\Google\Chrome SxS deleted Fake profile C:\Users\Gert\AppData\Local\Comodo\Dragon deleted Fake profile C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome deleted Fake profile C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome SxS deleted Fake profile C:\Users\HomeGroupUser$\AppData\Local\Comodo\Dragon deleted ==== Chromium Look ====================== Google Docs - Gert\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake Google Drive - Gert\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf YouTube - Gert\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo CDR - Gert\AppData\Local\Google\Chrome\User Data\Default\Extensions\bmfgflaeaflocilaaldbddgifhjkhfge Google Search - Gert\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf Kotnet Login - Gert\AppData\Local\Google\Chrome\User Data\Default\Extensions\ffdmhfbpjgldhcjpndjohjoiailndlog AdBlock - Gert\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom Google Wallet - Gert\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda Pub Toolbar - Gert\AppData\Local\Google\Chrome\User Data\Default\Extensions\omioeahgfecgfpfldejlnideemfidnkc Gmail - Gert\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia ==== Chromium Fix ====================== C:\Users\Gert\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.metrolyrics.com_0.localstorage deleted successfully C:\Users\Gert\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.metrolyrics.com_0.localstorage-journal deleted successfully C:\Users\Gert\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_www.superfish.com_0.localstorage deleted successfully C:\Users\Gert\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_www.superfish.com_0.localstorage-journal deleted successfully C:\Users\Gert\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_shoppingcart.aliexpress.com_0.localstorage deleted successfully C:\Users\Gert\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_shoppingcart.aliexpress.com_0.localstorage-journal deleted successfully C:\Users\Gert\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_shoppingervaring.nl_0.localstorage deleted successfully C:\Users\Gert\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_shoppingervaring.nl_0.localstorage-journal deleted successfully C:\Users\Gert\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.thelabelfinder.com_0.localstorage deleted successfully C:\Users\Gert\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.thelabelfinder.com_0.localstorage-journal deleted successfully C:\Users\Gert\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.vipfilefinder.com_0.localstorage deleted successfully C:\Users\Gert\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.vipfilefinder.com_0.localstorage-journal deleted successfully C:\Users\Gert\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static0.hln.be_0.localstorage deleted successfully C:\Users\Gert\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static0.hln.be_0.localstorage-journal deleted successfully C:\Users\Gert\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static1.hln.be_0.localstorage deleted successfully C:\Users\Gert\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static1.hln.be_0.localstorage-journal deleted successfully C:\Users\Gert\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static2.hln.be_0.localstorage deleted successfully C:\Users\Gert\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static2.hln.be_0.localstorage-journal deleted successfully C:\Users\Gert\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static3.hln.be_0.localstorage deleted successfully C:\Users\Gert\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static3.hln.be_0.localstorage-journal deleted successfully C:\Users\Gert\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.olark.com_0.localstorage deleted successfully C:\Users\Gert\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.olark.com_0.localstorage-journal deleted successfully C:\Users\Gert\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_services.pho.to_0.localstorage deleted successfully C:\Users\Gert\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_services.pho.to_0.localstorage-journal deleted successfully C:\Users\Gert\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_services.powerreviews.com_0.localstorage deleted successfully C:\Users\Gert\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_services.powerreviews.com_0.localstorage-journal deleted successfully C:\Users\Gert\AppData\Local\Google\Chrome\User Data\Default\Extensions\omioeahgfecgfpfldejlnideemfidnkc deleted successfully ==== Set IE to Default ====================== Old Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://www.google.com" "Default_Page_URL"="http://www.google.com" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main] "Default_Search_URL"="http://www.google.com" "Default_Page_URL"="http://www.google.com" "Start Page"="http://www.google.com" "Search Page"="http://www.google.com" [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main] "Default_Search_URL"="http://www.google.com" "Default_Page_URL"="http://www.google.com" "Start Page"="http://www.google.com" "Search Page"="http://www.google.com" New Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157" "Start Page"="http://www.google.com" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main] "Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896" "Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896" "Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157" "Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157" [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main] "Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896" "Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896" "Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157" "Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157" ==== All HKCU SearchScopes ====================== HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" {012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}" {0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC" ==== Deleting CLSID Registry Keys ====================== HKEY_USERS\S-1-5-21-2233490464-3742433080-2635956842-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8E5E2654-AD2D-48BF-AC2D-D17F00898D06} deleted successfully HKEY_USERS\S-1-5-21-2233490464-3742433080-2635956842-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{8E5E2654-AD2D-48BF-AC2D-D17F00898D06} deleted successfully HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{8E5E2654-AD2D-48BF-AC2D-D17F00898D06} deleted successfully ==== Deleting CLSID Registry Values ====================== ==== Deleting Registry Keys ====================== HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\761a81d7-5adb-4758-9405-0e24086c132b deleted successfully HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ff3c7e26-92c4-4fde-83b8-b977d1c981dd deleted successfully HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{7E5F1AE7-4863-4B6C-A987-0041A5BC3811} deleted successfully ==== Empty IE Cache ====================== C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Gert\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Gert\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully ==== Empty FireFox Cache ====================== No FireFox Profiles found ==== Empty Chrome Cache ====================== C:\Users\Gert\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully ==== Empty All Flash Cache ====================== Flash Cache Emptied Successfully ==== Empty All Java Cache ====================== Java Cache cleared successfully ==== C:\zoek_backup content ====================== C:\zoek_backup (files=303 folders=65 22468956 bytes) ==== Empty Temp Folders ====================== C:\Users\Default\AppData\Local\Temp emptied successfully C:\Users\Default User\AppData\Local\Temp emptied successfully C:\Users\Gert\AppData\Local\Temp will be emptied at reboot C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully C:\Windows\Temp will be emptied at reboot ==== After Reboot ====================== ==== Empty Temp Folders ====================== C:\Windows\Temp successfully emptied C:\Users\Gert\AppData\Local\Temp successfully emptied ==== Empty Recycle Bin ====================== C:\$RECYCLE.BIN successfully emptied ==== Deleting Files / Folders ====================== "C:\ProgramData\{b6dff0fd-128f-2b9e-b6df-ff0fd128c3f4}\c012ee9e360a9343" not found "C:\ProgramData\{b6dff0fd-128f-2b9e-b6df-ff0fd128c3f4}\def48cb11de7497" not found "C:\PROGRA~3\{b6dff0fd-128f-2b9e-b6df-ff0fd128c3f4}\c012ee9e360a9343" not found "C:\PROGRA~3\{b6dff0fd-128f-2b9e-b6df-ff0fd128c3f4}\def48cb11de7497" not found "C:\ProgramData\{b6dff0fd-128f-2b9e-b6df-ff0fd128c3f4}" not found "C:\PROGRA~3\{b6dff0fd-128f-2b9e-b6df-ff0fd128c3f4}" not found ==== EOF on wo 22/04/2015 at 4:56:56.87 ======================