Zoek.exe v5.0.0.0 Updated 04-May-2015 Tool run by Dejonckheere on zo 05/07/2015 at 12:31:26,10. Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x64 Running in: Normal Mode Internet Access Detected Launched: C:\Users\Dejonckheere\Desktop\zoek.exe [Scan all users] [Script inserted] ==== Older Logs ====================== C:\zoek-results2015-07-04-090437.log 151363 bytes C:\zoek-results2015-07-04-094910.log 212785 bytes ==== Empty Folders Check ====================== C:\Users\Dejonckheere\AppData\Roaming\postgresql deleted successfully ==== Deleting CLSID Registry Keys ====================== ==== Deleting CLSID Registry Values ====================== ==== Deleting Services ====================== HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\PicexaService deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PicexaService deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Eventlog\Application\PicexaService deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\PicexaService deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Updater Service deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Updater Service deleted successfully ==== Registry Fix Code x64 ====================== Windows Registry Editor Version 5.00 [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "Advanced SystemCare 8"=- [HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run] "Advanced SystemCare 8"=- [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"=- [-HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\AccelerateTab_is1] ==== Deleting Files \ Folders ====================== C:\\ProgramData\\LolliScan not found C:\Program Files (x86)\IObit\Driver Booster not found C:\Program Files (x86)\IObit\Game Booster 3 not found C:\Program Files (x86)\IObit\Smart Defrag 4 not found C:\Program Files (x86)\IObit\IObit Uninstaller not found C:\Users\Dejonckheere\AppData\Roaming\Mozilla\Firefox\Profiles\y48hc4sg.default-1425317072247\extensions\adremoveext@adremoveext.net not found C:\Users\Dejonckheere\AppData\Roaming\Mozilla\Firefox\Profiles\y48hc4sg.default-1425317072247\extensions\iobitascsurfingprotection@iobit.com not found C:\asc_rdflag deleted C:\Users\postgres.DEJONCKHEERE-PC\AppData\Roaming\TuneUp Software deleted C:\Users\postgres.DEJONCKHEERE-PC\AppData\Roaming\IObit deleted C:\Windows\SysNative\tasks\Driver Booster SkipUAC (Dejonckheere) deleted C:\Program Files\Enigma Software Group\SpyHunter deleted "C:\Users\Public\Desktop\Smart Defrag 4.lnk" deleted "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Smart Defrag 4\Smart Defrag 4.lnk" deleted "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Smart Defrag 4\Verwijder Smart Defrag 4.lnk" deleted ==== Files Recently Created / Modified ====================== ====== C:\Windows ==== ====== C:\Users\DEJONC~1\AppData\Local\Temp ==== 2015-07-05 10:03:59 D9348DB92AB4E5B94F005F0F651DE2B1 43008 ----a-w- C:\Users\Dejonckheere\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpdase6u.dll ====== Java Cache ===== ====== C:\Windows\SysWOW64 ===== 2015-06-25 21:01:29 F4AFDB5ABEA0C9079E8193E24D1DB21D 1174528 ----a-w- C:\Windows\SysWOW64\crypt32.dll 2015-06-25 21:01:29 D864C283FFD7C080FDC25FD4C798FF8D 103936 ----a-w- C:\Windows\SysWOW64\cryptnet.dll 2015-06-25 21:01:29 588D52C2D0E60EE71FD5A64407865B10 179200 ----a-w- C:\Windows\SysWOW64\wintrust.dll 2015-06-25 21:01:29 33F67BBCC3C0499D3F3382473114CFA8 143872 ----a-w- C:\Windows\SysWOW64\cryptsvc.dll 2015-06-25 20:59:37 F26680AF396F89F7ABFDA1D1D6B62011 285696 ----a-w- C:\Windows\SysWOW64\dxtrans.dll 2015-06-25 20:59:37 DB254D50B4527C2821C537E0587B44E8 12829696 ----a-w- C:\Windows\SysWOW64\ieframe.dll 2015-06-25 20:59:37 975421AC32F9F6E27A58F75DAB4B5871 19607040 ----a-w- C:\Windows\SysWOW64\mshtml.dll 2015-06-25 20:59:37 8C8B8C78C0CCD5D36ABCB115B0B581E1 2724864 ----a-w- C:\Windows\SysWOW64\mshtml.tlb 2015-06-25 20:59:37 6B7210618D7E2CE0404ECF748701253A 76288 ----a-w- C:\Windows\SysWOW64\mshtmled.dll 2015-06-25 20:59:37 2DED8A99E45053C42DD21D6937D3960C 689152 ----a-w- C:\Windows\SysWOW64\msfeeds.dll 2015-06-25 20:59:37 1A628C1F5470F0AF21E37E425026F27A 478208 ----a-w- C:\Windows\SysWOW64\ieui.dll 2015-06-25 20:59:37 17B0852D8202A872C3E6D01B518B6A4E 418304 ----a-w- C:\Windows\SysWOW64\dxtmsft.dll 2015-06-25 20:59:36 FB5C9234E4BF6BDAF4A954763A4582BA 168960 ----a-w- C:\Windows\SysWOW64\msrating.dll 2015-06-25 20:59:36 EF853EA2A6A7BD891CCF31B0C2915352 341504 ----a-w- C:\Windows\SysWOW64\html.iec 2015-06-25 20:59:36 E4EB138060BAE0DBAB1A3B71A3141FE7 1950720 ----a-w- C:\Windows\SysWOW64\wininet.dll 2015-06-25 20:59:36 E21AE910DF0C5CB7D46D8FA17A4567DE 115712 ----a-w- C:\Windows\SysWOW64\ieUnatt.exe 2015-06-25 20:59:36 C93AE4D14AEF5169791B35D97AE7C9FC 47104 ----a-w- C:\Windows\SysWOW64\jsproxy.dll 2015-06-25 20:59:36 C27C8CACEBC712BE2AD791715E9734EC 664064 ----a-w- C:\Windows\SysWOW64\jscript.dll 2015-06-25 20:59:36 B6D8148C1C697A7BF04EE0FE82408B6A 710144 ----a-w- C:\Windows\SysWOW64\ieapfltr.dll 2015-06-25 20:59:36 9F6066005D8B8620598085C7499E9B70 64000 ----a-w- C:\Windows\SysWOW64\MshtmlDac.dll 2015-06-25 20:59:36 96837E5864777688477AF6DE2332C06D 503808 ----a-w- C:\Windows\SysWOW64\vbscript.dll 2015-06-25 20:59:36 927E38A35E4DFC4E294BD130BAA6F759 2278912 ----a-w- C:\Windows\SysWOW64\iertutil.dll 2015-06-25 20:59:36 8C3A03295F56D1FFB51D9D05DA42B12D 47616 ----a-w- C:\Windows\SysWOW64\ieetwproxystub.dll 2015-06-25 20:59:36 85E21CCF38166E0D6DE2E42D9D3823BD 1155072 ----a-w- C:\Windows\SysWOW64\mshtmlmedia.dll 2015-06-25 20:59:36 81C1182A9EE7AC4D21187811DE66A7D0 30720 ----a-w- C:\Windows\SysWOW64\iernonce.dll 2015-06-25 20:59:36 7DBCBB1647B7CD71E2039C1B50A12717 620032 ----a-w- C:\Windows\SysWOW64\jscript9diag.dll 2015-06-25 20:59:36 7C9F8DB66A56306C5BBE97F9FC0F01EF 342736 ----a-w- C:\Windows\SysWOW64\iedkcs32.dll 2015-06-25 20:59:36 5C06EE62F06E990E9521EA80B8D4D4B8 62464 ----a-w- C:\Windows\SysWOW64\iesetup.dll 2015-06-25 20:59:36 53E9614ADFA6A40A452BA014CEF6F261 1309696 ----a-w- C:\Windows\SysWOW64\urlmon.dll 2015-06-25 20:59:36 4ABEEF30EA5B9F4718312DCB60B6C9BC 2052608 ----a-w- C:\Windows\SysWOW64\inetcpl.cpl 2015-06-25 20:59:36 3FD7E6DB5D81FE400DB4D81D278596E6 4305920 ----a-w- C:\Windows\SysWOW64\jscript9.dll 2015-06-25 20:59:36 185490A6C3BEDAC5EF547314F68AB07B 60416 ----a-w- C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2015-06-25 20:56:38 58788565442368B0615DDAF1D452B843 530432 ----a-w- C:\Windows\SysWOW64\comctl32.dll 2015-06-25 20:54:07 DA27A4EA7B7C77FAFDB3F94D83E310C1 12625408 ----a-w- C:\Windows\SysWOW64\wmploc.DLL 2015-06-25 20:54:07 A98E8F79C738CAF23C152DBCABD978FE 11411456 ----a-w- C:\Windows\SysWOW64\wmp.dll 2015-06-25 20:54:07 605E9B2CFA3445ED7716D0B345EE21EC 8192 ----a-w- C:\Windows\SysWOW64\spwmp.dll 2015-06-25 20:54:07 2401379E0610D15FAB78A4B1646F5B8D 4096 ----a-w- C:\Windows\SysWOW64\msdxm.ocx 2015-06-25 20:54:07 2401379E0610D15FAB78A4B1646F5B8D 4096 ----a-w- C:\Windows\SysWOW64\dxmasf.dll 2015-06-25 15:58:13 48435D12B45AB1F954CB579D1EA15D52 329360 ----a-w- C:\Windows\SysWOW64\SRCOM.dll 2015-06-25 15:58:11 90057B1D85470C7FF99F9BAD02615265 555664 ----a-w- C:\Windows\SysWOW64\SECOMN32.DLL 2015-06-25 15:58:09 604368B9C7AB04BA6E99457F50121D73 2532568 ----a-w- C:\Windows\SysWOW64\RltkAPO.dll ====== C:\Windows\SysWOW64\drivers ===== ====== C:\Windows\Sysnative ===== 2015-06-25 21:02:32 53405CDA694982E5C6A0E9454AC1D407 493504 ----a-w- C:\Windows\Sysnative\mcupdate_GenuineIntel.dll 2015-06-25 21:01:29 C5752F5CE47B6B00F914AE91087C0CB4 229376 ----a-w- C:\Windows\Sysnative\wintrust.dll 2015-06-25 21:01:29 7EE0A3B9E904AF4744E4D8F00CB5CA32 140288 ----a-w- C:\Windows\Sysnative\cryptnet.dll 2015-06-25 21:01:29 7BC3E861F7E8EB543A630090FAE779E0 188416 ----a-w- C:\Windows\Sysnative\cryptsvc.dll 2015-06-25 21:01:29 71187FA11F58012C188453877E16EB8B 1480192 ----a-w- C:\Windows\Sysnative\crypt32.dll 2015-06-25 20:59:37 AE5A2843B4A2E1E558B9EE13EF62CCE5 14404096 ----a-w- C:\Windows\Sysnative\ieframe.dll 2015-06-25 20:59:37 ACD6FE6C82B93813F023FC01A51CB940 92160 ----a-w- C:\Windows\Sysnative\mshtmled.dll 2015-06-25 20:59:37 8909A24DA8B5C426CF6595BA843B6CC5 490496 ----a-w- C:\Windows\Sysnative\dxtmsft.dll 2015-06-25 20:59:37 86FDFEA67833DB261EC01A777594EDCF 316928 ----a-w- C:\Windows\Sysnative\dxtrans.dll 2015-06-25 20:59:37 35622F5A652C4E16774234DCA0026E74 633856 ----a-w- C:\Windows\Sysnative\ieui.dll 2015-06-25 20:59:37 083BCA14FCE290D682D8DAC9372CBF23 801280 ----a-w- C:\Windows\Sysnative\msfeeds.dll 2015-06-25 20:59:36 FF84182188CA8F0DC28CFED06C9B7816 2125824 ----a-w- C:\Windows\Sysnative\inetcpl.cpl 2015-06-25 20:59:36 D202078FBA3A77B85D39669EE4110DE2 389840 ----a-w- C:\Windows\Sysnative\iedkcs32.dll 2015-06-25 20:59:36 CFA52E2FE8E623042A1EEF96EB1B9481 6026240 ----a-w- C:\Windows\Sysnative\jscript9.dll 2015-06-25 20:59:36 AFF5C12099B87FA645F8867701729894 54784 ----a-w- C:\Windows\Sysnative\jsproxy.dll 2015-06-25 20:59:36 A29BAFC1543F9D2234AFFFEA9BCE76C8 24917504 ----a-w- C:\Windows\Sysnative\mshtml.dll 2015-06-25 20:59:36 9E2B8C0601E3D460F78F0233B509CE4F 34304 ----a-w- C:\Windows\Sysnative\iernonce.dll 2015-06-25 20:59:36 9DB8E01D5A546FAFCACE95489E351186 48640 ----a-w- C:\Windows\Sysnative\ieetwproxystub.dll 2015-06-25 20:59:36 83781DF625A4448B39410D7FA2BDC48D 816640 ----a-w- C:\Windows\Sysnative\jscript.dll 2015-06-25 20:59:36 7F8F9AE03D1BA4354671E05F07A40F1A 800768 ----a-w- C:\Windows\Sysnative\ieapfltr.dll 2015-06-25 20:59:36 73509D13542A90E260F45D1D6D4100A8 114688 ----a-w- C:\Windows\Sysnative\ieetwcollector.exe 2015-06-25 20:59:36 70D24021ED327CE7FFA9DEE327BB4C6B 720384 ----a-w- C:\Windows\Sysnative\ie4uinit.exe 2015-06-25 20:59:36 6E295C7364DAEB151CC0E98434B6AC92 2885632 ----a-w- C:\Windows\Sysnative\iertutil.dll 2015-06-25 20:59:36 6ABFC5736EC920C4436F32111F5CBCEE 1545728 ----a-w- C:\Windows\Sysnative\urlmon.dll 2015-06-25 20:59:36 5F8EE9311ECF078CD9426874FFAD660C 66560 ----a-w- C:\Windows\Sysnative\iesetup.dll 2015-06-25 20:59:36 57DFACB53ED16190EF732E2430B39741 968704 ----a-w- C:\Windows\Sysnative\MsSpellCheckingFacility.exe 2015-06-25 20:59:36 4BD747AAF01C480901B3E777EC48826B 77824 ----a-w- C:\Windows\Sysnative\JavaScriptCollectionAgent.dll 2015-06-25 20:59:36 4A5A84B457C72E79A64AE4036EC6BB0E 1359360 ----a-w- C:\Windows\Sysnative\mshtmlmedia.dll 2015-06-25 20:59:36 417F80E4AFBA1AA9EBBD618F1C6D9165 2426880 ----a-w- C:\Windows\Sysnative\wininet.dll 2015-06-25 20:59:36 3C3E159F284F51D55DB59C3D0B843979 2724864 ----a-w- C:\Windows\Sysnative\mshtml.tlb 2015-06-25 20:59:36 3854BFE1C0F14872C94501421CC40813 814080 ----a-w- C:\Windows\Sysnative\jscript9diag.dll 2015-06-25 20:59:36 36F3718E67F442F54AB4A39DCDD8FD19 4096 ----a-w- C:\Windows\Sysnative\ieetwcollectorres.dll 2015-06-25 20:59:36 33B5F1A727FACDEA7CDA0E35FFAADDCF 584192 ----a-w- C:\Windows\Sysnative\vbscript.dll 2015-06-25 20:59:36 2BC2D3A41BB755487FD55C09938F00BC 417792 ----a-w- C:\Windows\Sysnative\html.iec 2015-06-25 20:59:36 16091938F6CDBCCCBA1CBE24600121BC 88064 ----a-w- C:\Windows\Sysnative\MshtmlDac.dll 2015-06-25 20:59:36 0EDA3219FA027A486AA11269355AB279 144384 ----a-w- C:\Windows\Sysnative\ieUnatt.exe 2015-06-25 20:59:36 06A8CE6C3AE6B7916F026B0EFDDCAAA5 199680 ----a-w- C:\Windows\Sysnative\msrating.dll 2015-06-25 20:56:38 51F89CE2D0FEC66070354504E6C4C3E4 633856 ----a-w- C:\Windows\Sysnative\comctl32.dll 2015-06-25 20:55:42 1EE2DBA5AD2E5EB618C7FB187C2CFDF4 3206144 ----a-w- C:\Windows\Sysnative\win32k.sys 2015-06-25 20:54:07 9D80A82B0BB77AC3EF6A87FA0C534E20 14635008 ----a-w- C:\Windows\Sysnative\wmp.dll 2015-06-25 20:54:07 834FD7C31EA16D59CC3B2DC60F2F2620 9728 ----a-w- C:\Windows\Sysnative\spwmp.dll 2015-06-25 20:54:07 51ECEE70F33601310DDEF3EEE39550D3 12625920 ----a-w- C:\Windows\Sysnative\wmploc.DLL 2015-06-25 20:54:07 1A8C5D4BE449E4A9D8667A341E535E22 5120 ----a-w- C:\Windows\Sysnative\msdxm.ocx 2015-06-25 20:54:07 1A8C5D4BE449E4A9D8667A341E535E22 5120 ----a-w- C:\Windows\Sysnative\dxmasf.dll 2015-06-25 16:01:27 8A9268F2536ABDEE5C6C9868DB69BA49 110080 ----a-w- C:\Windows\Sysnative\DelayAPO.dll 2015-06-25 15:58:13 EC05C33DF2CF20D839FE3650505ED6ED 734376 ----a-w- C:\Windows\Sysnative\sltech64.dll 2015-06-25 15:58:13 E8474A2323DD53B12EB3BB840A2CB306 3262184 ----a-w- C:\Windows\Sysnative\YamahaAE2.dll 2015-06-25 15:58:13 D47D28D2AD44318805CF5EF15665D570 1413776 ----a-w- C:\Windows\Sysnative\SRRPTR64.dll 2015-06-25 15:58:13 BDA340F6BC694D6BC94F7EFA35F3BC68 213432 ----a-w- C:\Windows\Sysnative\tossaemaxapo64.dll 2015-06-25 15:58:13 A5F6491F71A0DAF25140CA915600AB37 454288 ----a-w- C:\Windows\Sysnative\SRAPO64.dll 2015-06-25 15:58:13 48435D12B45AB1F954CB579D1EA15D52 329360 ----a-w- C:\Windows\Sysnative\SRCOM.dll 2015-06-25 15:58:13 2E4C258CB2FF3D249FD0ABBCABC664A1 250536 ----a-w- C:\Windows\Sysnative\slprp64.dll 2015-06-25 15:58:13 18F4327F7A659F4B1017C0E4C03EB50B 369296 ----a-w- C:\Windows\Sysnative\SRCOM64.dll 2015-06-25 15:58:12 EFF9255F47AD4AC10340B44B2A14E0A7 858256 ----a-w- C:\Windows\Sysnative\SEHDRA64.dll 2015-06-25 15:58:12 DBB99601D716F92CDD97CE4E60865319 943784 ----a-w- C:\Windows\Sysnative\sl3apo64.dll 2015-06-25 15:58:12 6F8B108E8B57AC88F90D6EA13B2A1755 1104040 ----a-w- C:\Windows\Sysnative\slcnt64.dll 2015-06-25 15:58:11 B723902784FD6BBE1A7FB5E387D68530 2918104 ----a-w- C:\Windows\Sysnative\RtPgEx64.dll 2015-06-25 15:58:11 986E3BE81352583A1FCEF6103904570F 684176 ----a-w- C:\Windows\Sysnative\SECOMN64.dll 2015-06-25 15:58:11 5644066210DE0CEA1BE04913E1FEE50E 2702040 ----a-w- C:\Windows\Sysnative\RTSnMg64.cpl 2015-06-25 15:58:11 4D4C12D652F710644EBA72D321072019 435856 ----a-w- C:\Windows\Sysnative\SEAPO64.dll 2015-06-25 15:58:10 AF70978706F94E1453E68F81C123CA80 3218800 ----a-w- C:\Windows\Sysnative\RtkApi64.dll 2015-06-25 15:58:10 889EC74FB5B4D63AD48CD0022991186A 168816 ----a-w- C:\Windows\Sysnative\RtkCfg64.dll 2015-06-25 15:58:10 4A1CA878196886743FE0E84F02C2C1DA 631000 ----a-w- C:\Windows\Sysnative\RtDataProc64.dll 2015-06-25 15:58:09 F19DEA58B0BFAF51C8E1E86C7991E2AE 2847448 ----a-w- C:\Windows\Sysnative\RltkAPO64.dll 2015-06-25 15:58:09 DB2595B0C44FA57F33618601F6F20CE4 5706688 ----a-w- C:\Windows\Sysnative\NAHIMICV2apo.dll 2015-06-25 15:58:09 CD3F906FFA6CC16B27DADB0B913C83A7 72113152 ----a-w- C:\Windows\Sysnative\RCoRes64.dat 2015-06-25 15:58:09 B137260DFE752B0B838E0EE488162219 1316056 ----a-w- C:\Windows\Sysnative\RTCOM64.dll 2015-06-25 15:58:09 329451F353E580BE5D6A1228779AB0C4 1739992 ----a-w- C:\Windows\Sysnative\RCoInstII64.dll 2015-06-25 15:58:08 CF5C73F640839D19EDA9D14046531163 12975360 ----a-w- C:\Windows\Sysnative\MaxxVoiceAPO3064.dll 2015-06-25 15:58:08 6C100BAE708BD61F65932087D9A69ECA 12834736 ----a-w- C:\Windows\Sysnative\MaxxVoiceAPO4064.dll 2015-06-25 15:58:07 CD2A9C650A6441544E4E4EB0B6F7C16E 2789808 ----a-w- C:\Windows\Sysnative\MaxxAudioAPO7064.dll 2015-06-25 15:58:07 B9178219A1B69431A12ED114B409E8C9 328816 ----a-w- C:\Windows\Sysnative\ICEsoundAPO64.dll 2015-06-25 15:58:07 4D87D76E686BAEFD24FE5D3F6913E543 3182104 ----a-w- C:\Windows\Sysnative\FMAPO64.dll 2015-06-25 15:58:07 039B309A4CB1BC2F906399464F380F22 1365768 ----a-w- C:\Windows\Sysnative\MaxxAudioAPO6064.dll 2015-06-25 15:58:06 DE67ADEAC731C1ED3BD76527AB530BA5 315736 ----a-w- C:\Windows\Sysnative\DDPO64A.dll 2015-06-25 15:58:06 CAC823DDBB6E785DB76906BFCCFE55AF 261464 ----a-w- C:\Windows\Sysnative\DDPA64.dll 2015-06-25 15:58:06 C71D1DAFA22B5D3B71853783E5AA09D2 7087448 ----a-w- C:\Windows\Sysnative\DDPP64A.dll 2015-06-25 15:58:06 5CD51590C1FD47301D2DA1DE7A70253D 1559744 ----a-w- C:\Windows\Sysnative\CX64APO.dll 2015-06-25 15:58:06 52B5ADE064EC99FD5FF740CF35BB4907 336144 ----a-w- C:\Windows\Sysnative\DDPO64AF3.dll 2015-06-25 15:58:06 1EA86BB2AA1717F105544F9DCD7DD590 284944 ----a-w- C:\Windows\Sysnative\DDPA64F3.dll 2015-06-25 15:58:06 03B3FDBF4E7336EA01EB1F80B8A06820 6242576 ----a-w- C:\Windows\Sysnative\DDPP64AF3.dll 2015-06-25 15:58:06 01E7B306CBBEAEFB32118FB229CE200F 1933584 ----a-w- C:\Windows\Sysnative\DDPD64AF3.dll 2015-06-25 15:58:06 018EFD4A9BF6FDA0F1AA3A6DE5712CD9 1939800 ----a-w- C:\Windows\Sysnative\DDPD64A.dll ====== C:\Windows\Sysnative\drivers ===== 2015-06-25 16:03:52 F0F9FB46B79AD902BB317493C44C6F53 69568 ----a-w- C:\Windows\Sysnative\drivers\TosRfSnd.sys 2015-06-25 16:01:27 ED38B8924DE8C806A2A1C12C4F61E9CF 94720 ----a-w- C:\Windows\Sysnative\drivers\AtihdW76.sys 2015-06-25 15:58:10 D63E2B47D1BCB63CCCEF8F591CEDAEE5 4464344 ----a-w- C:\Windows\Sysnative\drivers\RTKVHD64.sys 2015-06-25 15:58:09 0CDDEA5B4E709CB32715C0B630D7F888 2048372 ----a-w- C:\Windows\Sysnative\drivers\RTAIODAT.DAT 2015-06-17 05:29:49 BF69D973523D539A35807946C6DA7E16 95680 ----a-w- C:\Windows\Sysnative\drivers\ksecdd.sys 2015-06-17 05:29:49 272C27711C8AA6E7815EE33F8ACA9C66 155584 ----a-w- C:\Windows\Sysnative\drivers\ksecpkg.sys 2015-06-17 05:24:58 36E0DDD19038C92B7C7709BFA03F813F 69888 ----a-w- C:\Windows\Sysnative\drivers\stream.sys ====== C:\Windows\Tasks ====== 2015-06-18 19:10:54 C46AAF3D962CA0C876000F856DC32FF5 4036 ----a-w- C:\Windows\Sysnative\Tasks\DropboxUpdateTaskUserS-1-5-21-1676756398-211950510-2368295547-1001UA 2015-06-18 19:10:54 715E130FC6C6F6E3F2BA3C13BFC59BD6 1052 ----a-w- C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-1676756398-211950510-2368295547-1001UA.job 2015-06-18 19:10:53 A08E21C4F3626E6D9A98FDD3FD1B0222 1000 ----a-w- C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-1676756398-211950510-2368295547-1001Core.job 2015-06-18 19:10:53 64BC659E9AEEA524E1ACAF90B4D15E55 3640 ----a-w- C:\Windows\Sysnative\Tasks\DropboxUpdateTaskUserS-1-5-21-1676756398-211950510-2368295547-1001Core ====== C:\Windows\Temp ====== ======= C:\Program Files ===== 2015-07-03 15:54:39 -------- d-----w- C:\Program Files\trend micro ======= C:\PROGRA~2 ===== ======= C: ===== ====== C:\Users\Dejonckheere\AppData\Roaming ====== 2015-07-04 09:41:46 -------- d-----w- C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp 2015-07-04 09:41:46 -------- d-----w- C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp 2015-07-04 09:41:46 -------- d-----w- C:\Users\TEMP\AppData\Local\Temp 2015-07-04 09:41:46 -------- d-----w- C:\Users\postgres\AppData\Local\Temp 2015-07-04 09:41:46 -------- d-----w- C:\Users\postgres.DEJONCKHEERE-PC\AppData\Local\Temp 2015-07-04 09:41:46 -------- d-----w- C:\Users\POSTGR~1.DEJ\AppData\Local\Temp 2015-07-04 09:41:46 -------- d-----w- C:\Users\Dejonckheere\AppData\Local\Temp 2015-07-04 09:41:46 -------- d-----w- C:\Users\Default\AppData\Local\Temp 2015-07-04 09:41:46 -------- d-----w- C:\Users\Default User\AppData\Local\Temp 2015-06-18 19:12:07 -------- d-----w- C:\Users\Dejonckheere\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2015-06-18 19:10:39 -------- d-----w- C:\Users\Dejonckheere\AppData\Local\Dropbox ====== C:\Users\Dejonckheere ====== 2015-06-18 19:10:39 -------- d-----w- C:\ProgramData\Dropbox ====== C: exe-files == 2015-07-03 15:54:40 9A2347903D6EDB84C10F288BC0578C1C 388608 ----a-w- C:\Program Files\trend micro\Dejonckheere.exe === C: other files == ==== Startup Registry Enabled ====================== [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun" [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun" [HKEY_USERS\S-1-5-21-1676756398-211950510-2368295547-1006\Software\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun" [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce] "FlashPlayerUpdate"="C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_11_2_202_235_ActiveX.exe -update activex" [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce] "mctadmin"="C:\Windows\System32\mctadmin.exe" [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce] "mctadmin"="C:\Windows\System32\mctadmin.exe" [HKEY_USERS\S-1-5-21-1676756398-211950510-2368295547-1006\Software\Microsoft\Windows\CurrentVersion\RunOnce] "mctadmin"="C:\Windows\System32\mctadmin.exe" "ScrSav"="C:\Program Files (x86)\Acer\Screensaver\run_Acer.exe /default" [HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\RunOnce] "FlashPlayerUpdate"="C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_11_2_202_235_ActiveX.exe -update activex" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"="C:\\ProgramData\\LolliScan\\LolliScan32.dll" ==== Startup Registry Enabled x64 ====================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RTHDVCPL"="C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s" ==== Startup Registry Disabled ====================== [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run-] "Adobe ARM"="\"C:\\Program Files (x86)\\Common Files\\Adobe\\ARM\\1.0\\AdobeARM.exe\"" ==== Startup Registry Disabled x64 ====================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Acer ePower Management] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="Acer ePower Management" "hkey"="HKLM" "command"="C:\\Program Files\\Acer\\Acer ePower Management\\ePowerTray.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Adobe ARM] "key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="Adobe ARM" "hkey"="HKLM" "command"="\"C:\\Program Files (x86)\\Common Files\\Adobe\\ARM\\1.0\\AdobeARM.exe\"" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\BackupManagerTray] "key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="BackupManagerTray" "hkey"="HKLM" "command"="\"C:\\Program Files (x86)\\NewTech Infosystems\\Acer Backup Manager\\BackupManagerTray.exe\" -h -k" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\BrStsMon00] "key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="BrStsMon00" "hkey"="HKLM" "command"="C:\\Program Files (x86)\\Browny02\\Brother\\BrStMonW.exe /AUTORUN" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ControlCenter4] "key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="ControlCenter4" "hkey"="HKLM" "command"="C:\\Program Files (x86)\\ControlCenter4\\BrCcBoot.exe /autorun" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\EgisTecLiveUpdate] "key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="EgisTecLiveUpdate" "hkey"="HKLM" "command"="\"C:\\Program Files (x86)\\EgisTec Egis Software Update\\EgisUpdate.exe\"" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Steam] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="Steam" "hkey"="HKCU" "command"="\"C:\\Program Files (x86)\\Steam\\Steam.exe\" -silent" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Users^Dejonckheere^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Bouwsoft Beheer.lnk] "item"="Bouwsoft Beheer" "path"="C:\\Users\\Dejonckheere\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\Bouwsoft Beheer.lnk" "backup"="C:\\Windows\\pss\\Bouwsoft Beheer.lnk.Startup" "backupExtension"=".Startup" "command"="C:\\PROGRA~2\\Bouwsoft\\Tools\\WERKST~1\\beheer.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\Akamai] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\WMPNetworkSvc] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\WPCSvc] ==== Startup Folders ====================== 2015-05-12 05:11:31 1122 ----a-w- C:\Users\Dejonckheere\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk 2015-06-26 18:29:34 1028 ----a-w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth Manager.lnk ==== Task Scheduler Jobs ====================== C:\Windows\tasks\DropboxUpdateTaskUserS-1-5-21-1676756398-211950510-2368295547-1001Core.job --a------ C:\Users\Dejonckheere\AppData\Local\Dropbox\Update\DropboxUpdate.exe [18/06/2015 21:10] C:\Windows\tasks\DropboxUpdateTaskUserS-1-5-21-1676756398-211950510-2368295547-1001UA.job --a------ C:\Users\Dejonckheere\AppData\Local\Dropbox\Update\DropboxUpdate.exe [18/06/2015 21:10] C:\Windows\tasks\GoogleUpdateTaskMachineCore.job --a------ C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [] C:\Windows\tasks\GoogleUpdateTaskMachineUA.job --a------ C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [] ==== Other Scheduled Tasks ====================== "C:\Windows\SysNative\tasks\Adobe-online actualiseringsprogramma" [C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe] "C:\Windows\SysNative\tasks\CreateChoiceProcessTask" [C:\Windows\System32\browserchoice.exe] "C:\Windows\SysNative\tasks\DropboxUpdateTaskUserS-1-5-21-1676756398-211950510-2368295547-1001Core" [C:\Users\Dejonckheere\AppData\Local\Dropbox\Update\DropboxUpdate.exe] "C:\Windows\SysNative\tasks\DropboxUpdateTaskUserS-1-5-21-1676756398-211950510-2368295547-1001UA" [C:\Users\Dejonckheere\AppData\Local\Dropbox\Update\DropboxUpdate.exe] "C:\Windows\SysNative\tasks\Game_Booster_AutoUpdate" [C:\Program Files (x86)\IObit\Game Booster 3\AutoUpdate.exe] "C:\Windows\SysNative\tasks\GoogleUpdateTaskMachineCore" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe] "C:\Windows\SysNative\tasks\GoogleUpdateTaskMachineUA" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe] "C:\Windows\SysNative\tasks\SidebarExecute" [C:\Program Files\Windows Sidebar\sidebar.exe] "C:\Windows\SysNative\tasks\SmartDefrag4_Startup" [C:\Program Files (x86)\IObit\Smart Defrag 4\SmartDefrag.exe] "C:\Windows\SysNative\tasks\SmartDefrag4_Update" [C:\Program Files (x86)\IObit\Smart Defrag 4\AutoUpdate.exe] "C:\Windows\SysNative\tasks\SpyHunter4Startup" ["C:\Program Files\Enigma Software Group\SpyHunter\Spyhunter4.exe"] "C:\Windows\SysNative\tasks\Uninstaller_SkipUac_Administrator" [C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe] "C:\Windows\SysNative\tasks\Uninstaller_SkipUac_Dejonckheere" [C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe] "C:\Windows\SysNative\tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask" [%systemroot%\system32\sc.exe start osppsvc] ==== Firefox Start and Search pages ====================== ProfilePath: C:\Users\DEJONC~1\AppData\Roaming\Mozilla\Firefox\Profiles\y48hc4sg.default-1425317072247 user_pref("browser.startup.homepage", "www.ddejonckheere.be"); ==== Firefox Extensions ====================== ProfilePath: C:\Users\DEJONC~1\AppData\Roaming\Mozilla\Firefox\Profiles\y48hc4sg.default-1425317072247 - Undetermined - C:\Users\Dejonckheere\AppData\Roaming\Mozilla\Firefox\Profiles\y48hc4sg.default-1425317072247\extensions\adremoveext@adremoveext.net - Undetermined - C:\Users\Dejonckheere\AppData\Roaming\Mozilla\Firefox\Profiles\y48hc4sg.default-1425317072247\extensions\iobitascsurfingprotection@iobit.com ==== Firefox Plugins ====================== Profilepath: C:\Users\Dejonckheere\AppData\Roaming\Mozilla\Firefox\Profiles\y48hc4sg.default-1425317072247 AD76B0F3348914E133455E52743C839D - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1216156.dll - Shockwave for Director / Shockwave for Director 4390CCD3790F8D9C427C0C29590C62D7 - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_145.dll - Shockwave Flash C62322C77D1AAB77B1CF1130FCC3673A - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_305.dll - Shockwave Flash ==== Reset Google Chrome ====================== Nothing found to reset ==== C:\zoek_backup content ====================== C:\zoek_backup (files=1164 folders=172 449582768 bytes) ==== EOF on zo 05/07/2015 at 12:38:59,16 ======================