Zoek.exe v5.0.0.0 Updated 07-September-2015 Tool run by jaap on ma 07-09-2015 at 12:06:31,38. Microsoft Windows 10 Home 10.0.10240 x64 Running in: Normal Mode Internet Access Detected Launched: C:\Users\jaap\Desktop\zoek.exe [Scan all users] [Script inserted] ==== Older Logs ====================== C:\zoek-results2015-09-06-154813.log 44906 bytes ==== Deleting CLSID Registry Keys ====================== ==== Deleting CLSID Registry Values ====================== ==== Running Processes ====================== C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe C:\Program Files (x86)\Google\Update\1.3.28.13\GoogleCrashHandler.exe C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe C:\Program Files (x86)\Steam\Steam.exe C:\Program Files (x86)\Steam\bin\steamwebhelper.exe C:\Program Files (x86)\Common Files\Steam\SteamService.exe C:\Program Files (x86)\Steam\bin\steamwebhelper.exe C:\Program Files (x86)\Steam\bin\steamwebhelper.exe C:\Program Files (x86)\Mozilla Firefox\firefox.exe C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerPlugin_18_0_0_232.exe C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerPlugin_18_0_0_232.exe C:\Users\jaap\Desktop\zoek.exe C:\WINDOWS\SysWOW64\cmd.exe C:\WINDOWS\SysWOW64\cmd.exe C:\WINDOWS\SysWOW64\cmd.exe ==== Deleting Services ====================== ==== Deleting Files \ Folders ====================== C:\PROGRA~2\AVG deleted C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Avg deleted C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Avg deleted C:\Users\jaap\AppData\Local\Avg deleted "C:\Users\jaap\Downloads\TuneUpUtilities2013_nl-NL.exe" deleted ==== System Specs ====================== Windows: Windows Version 6.2 (Build 9200) Memory (RAM): 8085 MB CPU Info: Intel(R) Core(TM) i7-3632QM CPU @ 2.20GHz CPU Speed: 2210,8 MHz Sound Card: Luidsprekers / HP (IDT High Def | Display Adapters: Intel(R) HD Graphics 4000 | Intel(R) HD Graphics 4000 | Intel(R) HD Graphics 4000 Monitors: 1x; Generic PnP Monitor | Screen Resolution: 1366 X 768 - 32 bit Network: Network Present Network Adapters: Microsoft Wi-Fi Direct Virtual Adapter | Realtek PCIe FE Family Controller | Ralink RT3290 802.11bgn Wi-Fi Adapter CD / DVD Drives: 1x (E: | ) E: hp DVDRAM GT80N Ports: COM Ports NOT Present. LPT Port NOT Present. Mouse: 5 Button Wheel Mouse Present Hard Disks: C: 447,1GB | D: 16,8GB Hard Disks - Free: C: 84,2GB | D: 2,1GB Manufacturer *: Insyde BIOS Info: AT/AT COMPATIBLE | | HPQOEM - 1 Time Zone: West-Europa (standaardtijd) Motherboard *: Hewlett-Packard 183E Country: Nederland Language: NLD ==== System Specs (Software) ====================== Default Browser: Firefox 40.0.3 Internet Explorer Version: 11.0.10240.16431 Mozilla Firefox version: 40.0.3 (x86 nl) Adobe Reader version: 11.0.12.18 Sun Java version: 1.8.0_60 (32-bit) Sun Java version: 1.8.0_60 (64-bit) Flash Player version: 18.0.0.232 Shockwave Player version: 11.6.6r636 ==== Files Recently Created / Modified ====================== ====== C:\WINDOWS ==== 2015-08-19 14:29:47 F1CBCB7FA6F3B309639AA2D4EF74469C 4532304 ----a-w- C:\WINDOWS\explorer.exe 2015-08-11 19:38:00 986BC1A9E29A9E35C1D10D874616ACBB 215040 ----a-w- C:\WINDOWS\notepad.exe ====== C:\Users\jaap\AppData\Local\Temp ==== ====== Java Cache ===== ====== C:\WINDOWS\SysWOW64 ===== 2015-08-29 16:52:48 7AD77D21F1A7964240636BDA40B9480E 18806272 ----a-w- C:\WINDOWS\SysWOW64\edgehtml.dll 2015-08-29 16:52:45 0C6BA8C523BCC86D7CF16385419EE4D7 20857848 ----a-w- C:\WINDOWS\SysWOW64\shell32.dll 2015-08-29 16:52:43 A9AFC833BFA05645C7C5C4A2C9EA4515 1771592 ----a-w- C:\WINDOWS\SysWOW64\CoreUIComponents.dll 2015-08-29 16:52:43 3FFBA909D9F44E83105459076E01E066 963920 ----a-w- C:\WINDOWS\SysWOW64\LicenseManager.dll 2015-08-29 16:52:42 820C0126D90810B78F5417767DA4F487 1593344 ----a-w- C:\WINDOWS\SysWOW64\dwmcore.dll 2015-08-29 16:52:42 7CDC13C04C1038D6143B64CD2321B1F0 274432 ----a-w- C:\WINDOWS\SysWOW64\NetSetupShim.dll 2015-08-29 16:52:40 EBD8D48F8EF7E7BDCEEB176CAB1033E3 37376 ----a-w- C:\WINDOWS\SysWOW64\wfdprov.dll 2015-08-29 16:52:40 A5E98AB07AE94407058A4224F2A9504A 1226752 ----a-w- C:\WINDOWS\SysWOW64\wcnwiz.dll 2015-08-29 16:52:40 2A28095B1C625D3DE3C25E6696AC4504 100352 ----a-w- C:\WINDOWS\SysWOW64\WcnApi.dll 2015-08-29 16:52:39 FABFF0AA6B503B960BBCBCC7CF00350B 195584 ----a-w- C:\WINDOWS\SysWOW64\PackageStateRoaming.dll 2015-08-29 16:52:39 7EFF73E0CF886F43B0ABF9921189857E 95744 ----a-w- C:\WINDOWS\SysWOW64\fdWCN.dll ====== C:\WINDOWS\SysWOW64\drivers ===== ====== C:\WINDOWS\Sysnative ===== 2015-09-07 09:07:16 A3687E2657DF50B650F93F331072865B 16148 ----a-w- C:\WINDOWS\Sysnative\PC-JAAP_jaap_HistoryPrediction.bin 2015-08-29 16:52:51 41E92432E013F487360795621B5393C0 21875200 ----a-w- C:\WINDOWS\Sysnative\edgehtml.dll 2015-08-29 16:52:50 40B99AF1511BF6309E986278854740D1 22324656 ----a-w- C:\WINDOWS\Sysnative\shell32.dll 2015-08-29 16:52:46 BE1ADC0E59D13C4F9117D4AECC4B16A1 2498808 ----a-w- C:\WINDOWS\Sysnative\CoreUIComponents.dll 2015-08-29 16:52:46 8A74C66ECB29E05C4324B29536CB12EE 8019296 ----a-w- C:\WINDOWS\Sysnative\ntoskrnl.exe 2015-08-29 16:52:44 B7B20B07E6BDB3DCD78668E4F7BFABA9 1888768 ----a-w- C:\WINDOWS\Sysnative\dwmcore.dll 2015-08-29 16:52:44 93C8A57CF3EA747BB855FFFC511B5E50 1396064 ----a-w- C:\WINDOWS\Sysnative\LicenseManager.dll 2015-08-29 16:52:44 81904664D6E8532794F629427B02AF00 2225664 ----a-w- C:\WINDOWS\Sysnative\NetworkMobileSettings.dll 2015-08-29 16:52:43 EBB4649381ED8DFB47B929C673E3BFBF 859136 ----a-w- C:\WINDOWS\Sysnative\modernexecserver.dll 2015-08-29 16:52:43 994DB3BD0278B3136FD95F7E1C73A935 2235904 ----a-w- C:\WINDOWS\Sysnative\wuaueng.dll 2015-08-29 16:52:42 E4257DF7C5517E3996047F7ADDB208F5 8847 ----a-w- C:\WINDOWS\Sysnative\ResPriHMImageList 2015-08-29 16:52:42 B89FE628B72CEA4674787D13A87CEE9A 387584 ----a-w- C:\WINDOWS\Sysnative\NetSetupShim.dll 2015-08-29 16:52:42 ACA9EAA9CC52E8DA0784FE3B06E06265 609592 ----a-w- C:\WINDOWS\Sysnative\ci.dll 2015-08-29 16:52:42 5D046D71B18BEFB2E4D164C3DEEDD672 187392 ----a-w- C:\WINDOWS\Sysnative\NetSetupSvc.dll 2015-08-29 16:52:42 35EC6A4E7384E233CBB5EEFD3BC2204D 247296 ----a-w- C:\WINDOWS\Sysnative\facecredentialprovider.dll 2015-08-29 16:52:41 FB24F19E6CF491A060FA9645F2D3B67D 497664 ----a-w- C:\WINDOWS\Sysnative\WlanMediaManager.dll 2015-08-29 16:52:41 B32BD244B13DEC1DD050146B5F5466D7 1061888 ----a-w- C:\WINDOWS\Sysnative\reseteng.dll 2015-08-29 16:52:41 A108F6D878F2B95EAA00A088EDE0E598 1294336 ----a-w- C:\WINDOWS\Sysnative\wcnwiz.dll 2015-08-29 16:52:41 62CFDB1741D700E2292242B50F1EC1A9 168960 ----a-w- C:\WINDOWS\Sysnative\InstallAgent.exe 2015-08-29 16:52:41 5CE3C624FABA3154504DF9A2BD029A5E 50176 ----a-w- C:\WINDOWS\Sysnative\WcnNetsh.dll 2015-08-29 16:52:41 51F21A9A20563799AC159D22B316F5A9 77400 ----a-w- C:\WINDOWS\Sysnative\acmigration.dll 2015-08-29 16:52:41 0F7067F069D502954F4E9E3D3378585B 79872 ----a-w- C:\WINDOWS\Sysnative\BthRadioMedia.dll 2015-08-29 16:52:41 0ACF831DD03989CA9787621C04D73CFD 45568 ----a-w- C:\WINDOWS\Sysnative\wfdprov.dll 2015-08-29 16:52:41 0508F98561A23E184E653E3A61B49592 1234944 ----a-w- C:\WINDOWS\Sysnative\aitstatic.exe 2015-08-29 16:52:40 E407B70B9D21CA3967485D464A01BAE5 140288 ----a-w- C:\WINDOWS\Sysnative\WcnApi.dll 2015-08-29 16:52:40 4F9CBB4B6FC2D9D0EAC8234343BAA29D 2178560 ----a-w- C:\WINDOWS\Sysnative\AppXDeploymentServer.dll 2015-08-29 16:52:40 4814F85B61BB3FD9909F9E4726703ED4 1795072 ----a-w- C:\WINDOWS\Sysnative\AppXDeploymentExtensions.dll 2015-08-29 16:52:40 3C6F2EF4541A9CD98EFED7B8CE9D061F 112640 ----a-w- C:\WINDOWS\Sysnative\fdWCN.dll 2015-08-29 16:52:40 26E5D4CA29A7B33EAD6E4C07D7DD3FBF 193024 ----a-w- C:\WINDOWS\Sysnative\EnterpriseModernAppMgmtCSP.dll 2015-08-29 16:52:40 1D57DD1A716A1C2C71F0A53BD00B6AFD 2226688 ----a-w- C:\WINDOWS\Sysnative\wlansvc.dll 2015-08-29 16:52:40 01F1D71F291A64266E3B0DF60E6B6CE7 117760 ----a-w- C:\WINDOWS\Sysnative\dafWCN.dll 2015-08-29 16:52:39 D4D17FB8E003050BA38B85F335B71222 322048 ----a-w- C:\WINDOWS\Sysnative\vaultsvc.dll 2015-08-29 16:52:39 6FBC6166E73518A8FEF03DCEB5BC4F34 246272 ----a-w- C:\WINDOWS\Sysnative\PackageStateRoaming.dll ====== C:\WINDOWS\Sysnative\drivers ===== 2015-08-29 16:52:41 C67A03F54A1EA683F4880A481EE5FF6C 373072 ----a-w- C:\WINDOWS\Sysnative\drivers\USBXHCI.SYS 2015-08-29 16:52:41 A9991032F00FDE9D344FF95C01DBD390 929280 ----a-w- C:\WINDOWS\Sysnative\drivers\bthport.sys 2015-08-21 14:41:45 9298E1645E09679C362AF0C5BC9A5EB0 52208 ----a-w- C:\WINDOWS\Sysnative\drivers\ati2erec.dll 2015-08-19 14:29:34 AE7B7E1E95BFB9340B1956C98CA52C81 80720 ----a-w- C:\WINDOWS\Sysnative\drivers\stornvme.sys 2015-08-19 14:29:32 7680537006A420D7488E5057A8149F86 442208 ----a-w- C:\WINDOWS\Sysnative\drivers\storport.sys 2015-08-11 19:38:12 310334DAF2C455744703E2D582942DF3 1983840 ----a-w- C:\WINDOWS\Sysnative\drivers\dxgkrnl.sys 2015-08-11 19:38:05 024E17D876211501EEC41503A797BDCE 505696 ----a-w- C:\WINDOWS\Sysnative\drivers\dxgmms2.sys 2015-08-11 19:38:04 DAF957B25A35757E9D814611FAE8FE3B 237392 ----a-w- C:\WINDOWS\Sysnative\drivers\rdyboost.sys 2015-08-11 19:38:04 9B2039C5673EEBF1D4E34ABC0AFB88C7 685568 ----a-w- C:\WINDOWS\Sysnative\drivers\WdiWiFi.sys 2015-08-11 19:38:03 D5EC9413527B286CFEEB0294C53ABB95 102752 ----a-w- C:\WINDOWS\Sysnative\drivers\mountmgr.sys 2015-08-11 19:38:02 7E51F2AD1D729F5CDBB6BE21CB58FEB7 516960 ----a-w- C:\WINDOWS\Sysnative\drivers\USBHUB3.SYS 2015-08-11 19:38:01 78CA1FF6FE37EEFAFF99DD1C956AF60A 200528 ----a-w- C:\WINDOWS\Sysnative\drivers\wof.sys 2015-08-11 19:37:57 388F2A3C771B8BEE76FD1AAF9614D08E 52264 ----a-w- C:\WINDOWS\Sysnative\drivers\wpcfltr.sys 2015-08-11 19:37:56 988588C16A53C2581488C15FF18934BF 46432 ----a-w- C:\WINDOWS\Sysnative\drivers\msgpiowin32.sys 2015-08-11 19:37:52 E1652E25178FB1D48A10DBF377F3A63D 393568 ----a-w- C:\WINDOWS\Sysnative\drivers\dxgmms1.sys ====== C:\WINDOWS\Tasks ====== 2015-08-31 16:05:46 C642764EBD3158973BA804D1E2F0DFFA 3272 ----a-w- C:\WINDOWS\Sysnative\Tasks\{B4B91CD0-859D-4C5F-8E0C-D2FEA7AD0FF7} ====== C:\WINDOWS\Temp ====== ======= C:\Program Files ===== 2015-09-05 11:56:00 -------- d-----w- C:\Program Files\trend micro 2015-08-21 14:49:00 -------- d-----w- C:\Program Files\ATI Technologies ======= C:\PROGRA~2 ===== 2015-09-06 14:17:08 -------- d-----w- C:\PROGRA~2\COMMON~1\Java ======= C: ===== ====== C:\Users\jaap\AppData\Roaming ====== 2015-09-06 15:38:39 -------- d-----w- C:\Users\jaap\AppData\Local\Temp 2015-08-14 16:28:33 -------- d-----w- C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\dcpsvc 2015-08-09 11:16:10 -------- d-----w- C:\Users\jaap\AppData\Local\MicrosoftEdge 2015-08-08 19:20:34 -------- d-----w- C:\Users\jaap\AppData\Local\CEF 2015-08-08 14:34:55 -------- d-----w- C:\Users\jaap\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Popcorn Time 2015-08-08 14:33:04 -------- d-----w- C:\Users\jaap\AppData\Local\Popcorn Time ====== C:\Users\jaap ====== 2015-09-07 10:05:23 6E0ACBA3DF9D311E62CE9E7A5F0D120D 14258880 ----a-w- C:\Users\jaap\Downloads\mseinstall.exe 2015-09-06 14:16:58 -------- d-----w- C:\Users\jaap\.oracle_jre_usage 2015-09-06 14:08:44 6E6FAC98AF9E39E9131A236F8DAC8C75 584288 ----a-w- C:\Users\jaap\Downloads\JavaSetup8u60.exe 2015-09-05 11:55:47 8045ABB21A3BDD66A48E1ED5C0F0EF6A 1222144 ----a-w- C:\Users\jaap\Downloads\RSITx64.exe 2015-09-05 00:23:41 -------- d-----w- C:\ProgramData\AVG 2015-08-31 16:12:12 -------- d-----w- C:\ProgramData\TuneUp Software 2015-08-31 16:11:55 -------- d-sh--w- C:\ProgramData\{C4ABDBC8-1C81-42C9-BFFC-4A68511E9E4F} 2015-08-31 16:11:55 -------- d--h--w- C:\ProgramData\Common Files 2015-08-31 16:07:34 AB25777DE5188E05FCC19D3B3162D494 1701992 ----a-w- C:\Users\jaap\Downloads\BitTorrent.exe 2015-08-31 16:07:02 8C04216E4CFABA9FD3C56F094BA47FAA 1699936 ----a-w- C:\Users\jaap\Downloads\uTorrent.exe 2015-08-26 16:24:31 DC861ACED61BCA8185C6D0D62239EA23 146080 ----a-w- C:\Users\jaap\Downloads\SpotifySetup.exe 2015-08-22 06:29:27 -------- d-----w- C:\ProgramData\ATI 2015-08-21 14:49:18 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Catalyst Control Center ====== C: exe-files == === C: other files == ==== Startup Registry Enabled ====================== [HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "OneDriveSetup"="C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup" [HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "OneDriveSetup"="C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup" [HKEY_USERS\S-1-5-21-2364196584-3471848684-3867934997-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Spotify Web Helper"="C:\Users\jaap\AppData\Roaming\Spotify\SpotifyWebHelper.exe" "Google Update"="C:\Users\jaap\AppData\Local\Google\Update\GoogleUpdate.exe /c" "Spotify"="C:\Users\jaap\AppData\Roaming\Spotify\Spotify.exe -autostart -minimized" "OneDrive"="C:\Users\jaap\AppData\Local\Microsoft\OneDrive\OneDrive.exe /background" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "StartCCC"="C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe MSRun" "Raptr"="C:\Program Files (x86)\Raptr\raptrstub.exe --startup" "SunJavaUpdateSched"="C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "Spotify Web Helper"="C:\Users\jaap\AppData\Roaming\Spotify\SpotifyWebHelper.exe" "Google Update"="C:\Users\jaap\AppData\Local\Google\Update\GoogleUpdate.exe /c" "Spotify"="C:\Users\jaap\AppData\Roaming\Spotify\Spotify.exe -autostart -minimized" "OneDrive"="C:\Users\jaap\AppData\Local\Microsoft\OneDrive\OneDrive.exe /background" ==== Startup Registry Enabled x64 ====================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SysTrayApp"="C:\Program Files\IDT\WDM\sttray64.exe" "SynTPEnh"="%ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe " ==== Task Scheduler Jobs ====================== C:\WINDOWS\tasks\Adobe Flash Player Updater.job --a-------- C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [12-08-2015 10:17] C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job --a-------- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [27-08-2015 19:51] C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job --a-------- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [27-08-2015 19:51] C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2364196584-3471848684-3867934997-1001Core.job --a-------- C:\Users\jaap\AppData\Local\Google\Update\GoogleUpdate.exe [29-08-2015 15:54] C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2364196584-3471848684-3867934997-1001UA.job --a-------- C:\Users\jaap\AppData\Local\Google\Update\GoogleUpdate.exe [29-08-2015 15:54] C:\WINDOWS\tasks\HPCeeScheduleForjaap.job --a-------- C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [13-09-2010 23:15] C:\WINDOWS\tasks\MATLAB R2014a Startup Accelerator.job --a-------- C:\Program Files\MATLAB\R2014a\bin\win64\MATLABStartupAccelerator.exe [29-01-2014 12:39] C:\WINDOWS\tasks\Synaptics TouchPad Enhancements.job --a-------- C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [17-07-2015 07:51] ==== Other Scheduled Tasks ====================== "C:\WINDOWS\SysNative\tasks\Adobe Acrobat Update Task" [C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe] "C:\WINDOWS\SysNative\tasks\Adobe Flash Player Updater" [C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe] "C:\WINDOWS\SysNative\tasks\CCleanerSkipUAC" ["C:\Program Files\CCleaner\CCleaner.exe"] "C:\WINDOWS\SysNative\tasks\CLMLSvc_P2G8" [C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe] "C:\WINDOWS\SysNative\tasks\CLVDLauncher" [C:\Program Files (x86)\CyberLink\Power2Go8\CLVDLauncher.exe] "C:\WINDOWS\SysNative\tasks\GoogleUpdateTaskMachineCore" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe] "C:\WINDOWS\SysNative\tasks\GoogleUpdateTaskMachineUA" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe] "C:\WINDOWS\SysNative\tasks\GoogleUpdateTaskUserS-1-5-21-2364196584-3471848684-3867934997-1001Core" [C:\Users\jaap\AppData\Local\Google\Update\GoogleUpdate.exe] "C:\WINDOWS\SysNative\tasks\GoogleUpdateTaskUserS-1-5-21-2364196584-3471848684-3867934997-1001UA" [C:\Users\jaap\AppData\Local\Google\Update\GoogleUpdate.exe] "C:\WINDOWS\SysNative\tasks\HPCeeScheduleForjaap" [C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe] "C:\WINDOWS\SysNative\tasks\MATLAB R2014a Startup Accelerator" [C:\Program Files\MATLAB\R2014a\bin\win64\MATLABStartupAccelerator.exe] "C:\WINDOWS\SysNative\tasks\MirageAgent" [C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe] "C:\WINDOWS\SysNative\tasks\User_Feed_Synchronization-{2324A6A4-64B3-4E63-9277-89F2E426DAC4}" [C:\WINDOWS\system32\msfeedssync.exe] "C:\WINDOWS\SysNative\tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start" [C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe] "C:\WINDOWS\SysNative\tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis" [C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe] "C:\WINDOWS\SysNative\tasks\Hewlett-Packard\HP Support Assistant\Update Check" [C:\ProgramData\Hewlett-Packard\HP Support Framework\Resources\Updater7\HPSFUpdater.exe] "C:\WINDOWS\SysNative\tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker" [C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe] "C:\WINDOWS\SysNative\tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_DeviceScan" [C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe] "C:\WINDOWS\SysNative\tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask" [%systemroot%\system32\sc.exe start osppsvc] ==== Firefox Extensions ====================== ProfilePath: C:\Users\jaap\AppData\Roaming\Mozilla\Firefox\Profiles\wz7ngyf6.default-1419700321065 - Adblock Plus - %ProfilePath%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi AppDir: C:\Program Files (x86)\Mozilla Firefox - Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} ==== Firefox Plugins ====================== Profilepath: C:\Users\jaap\AppData\Roaming\Mozilla\Firefox\Profiles\wz7ngyf6.default-1419700321065 DAD55CEF682EAE6FA7B4C9487563A496 - C:\windows\SysWOW64\Adobe\Director\np32dsw_1166636.dll - Shockwave for Director / Shockwave for Director EC55112EDB2CE5BC2BFCACDB9C2150F4 - C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_232.dll - Shockwave Flash F542B4E8DF11DCF7C974548A2D2BD624 - C:\Users\jaap\AppData\Local\Google\Update\1.3.28.13\npGoogleUpdate3.dll - Google Update ==== Chromium Look ====================== Google Docs - jaap\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake Google Drive - jaap\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf YouTube - jaap\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo Google Cast - jaap\AppData\Local\Google\Chrome\User Data\Default\Extensions\boadgeojelhgndaghljhdicfkmllpafd Google Search - jaap\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf Google Wallet - jaap\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda Gmail - jaap\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia ==== Set IE to Default ====================== Old Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157" New Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157" ==== All HKCU SearchScopes ====================== HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" {012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}" {0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=HPNTDFJS" {D944BB61-2E34-4DBF-A683-47E505C587DC} eBay Url="http://rover.ebay.com/rover/1/1346-154357-12126-2/4?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms}" ==== HijackThis Entries ====================== O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_60\bin\ssv.dll O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_60\bin\jp2ssv.dll O2 - BHO: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun O4 - HKLM\..\Run: [Raptr] "C:\Program Files (x86)\Raptr\raptrstub.exe" --startup O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" O4 - HKCU\..\Run: [Spotify Web Helper] "C:\Users\jaap\AppData\Roaming\Spotify\SpotifyWebHelper.exe" O4 - HKCU\..\Run: [Google Update] "C:\Users\jaap\AppData\Local\Google\Update\GoogleUpdate.exe" /c O4 - HKCU\..\Run: [Spotify] "C:\Users\jaap\AppData\Roaming\Spotify\Spotify.exe" -autostart -minimized O4 - HKCU\..\Run: [OneDrive] "C:\Users\jaap\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'NETWORK SERVICE') O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\Program Files\Microsoft Office\Office14\EXCEL.EXE/3000 O9 - Extra button: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-103 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-102 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics O17 - HKLM\System\CCS\Services\Tcpip\..\{a9cd7276-1f65-413f-8e73-f0fb90502bc6}: NameServer = 208.67.222.222,208.67.220.220 O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Windows\SysWow64\skype4com.dll O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing) O23 - Service: AMD External Events Utility - Unknown owner - C:\WINDOWS\system32\atiesrxx.exe (file missing) O23 - Service: Bonjour-service (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe O23 - Service: @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000 (diagnosticshub.standardcollector.service) - Unknown owner - C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe (file missing) O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing) O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing) O23 - Service: Google Update-service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe O23 - Service: Google Update-service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe O23 - Service: HP Support Assistant Service - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe O23 - Service: HP Connected Remote Service (HPConnectedRemote) - Hewlett-Packard - C:\Program Files (x86)\Hewlett-Packard\HP Connected Remote\HPConnectedRemoteService.exe O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe O23 - Service: @oem13.inf,%hpservice_desc%;HP Service (hpsrv) - Unknown owner - C:\WINDOWS\system32\Hpservice.exe (file missing) O23 - Service: HPWMISVC - Hewlett-Packard Development Company, L.P. - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe O23 - Service: Intel(R) Rapid Storage Technologie (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe O23 - Service: Intel(R) Integrated Clock Controller Service - Intel(R) ICCS (ICCS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe O23 - Service: IconMan_R - Realsil Microelectronics Inc. - C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\WINDOWS\system32\IEEtwCollector.exe (file missing) O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService1.0.0.0) - Unknown owner - C:\WINDOWS\system32\igfxCUIService.exe (file missing) O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe O23 - Service: Intel(R) ME Service - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing) O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing) O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing) O23 - Service: @%SystemRoot%\System32\ngcsvc.dll,-100 (NgcSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing) O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing) O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing) O23 - Service: @%SystemRoot%\system32\SensorDataService.exe,-101 (SensorDataService) - Unknown owner - C:\WINDOWS\System32\SensorDataService.exe (file missing) O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing) O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing) O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing) O23 - Service: @%SystemRoot%\system32\stlang64.dll,-10101 (STacSV) - IDT, Inc. - C:\Program Files\IDT\WDM\STacSV64.exe O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe O23 - Service: SynTPEnh Caller Service (SynTPEnhService) - Synaptics Incorporated - C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing) O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing) O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing) O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing) O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing) O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing) O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing) O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing) O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing) ==== Empty IE Cache ====================== C:\WINDOWS\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\jaap\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\Users\jaap\AppData\Local\Microsoft\Windows\INetCache\Low\Content.IE5 emptied successfully C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\WINDOWS\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\Users\jaap\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully C:\Users\jaap\AppData\Local\Microsoft\Windows\INetCache\Low\IE emptied successfully C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully ==== Empty FireFox Cache ====================== C:\Users\jaap\AppData\Local\Mozilla\Firefox\Profiles\wz7ngyf6.default-1419700321065\cache2 emptied successfully ==== Empty Chrome Cache ====================== C:\Users\jaap\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully ==== Empty All Flash Cache ====================== No Flash Cache Found ==== Empty All Java Cache ====================== Java Cache cleared successfully ==== C:\zoek_backup content ====================== C:\zoek_backup (files=211 folders=157 113017426 bytes) ==== Empty Temp Folders ====================== C:\WINDOWS\Temp will be emptied at reboot ==== After Reboot ====================== ==== Empty Temp Folders ====================== C:\WINDOWS\Temp successfully emptied C:\Users\jaap\AppData\Local\Temp successfully emptied ==== Empty Recycle Bin ====================== C:\$RECYCLE.BIN successfully emptied ==== EOF on ma 07-09-2015 at 17:35:05,91 ======================