Zoek.exe v5.0.0.0 Updated 23-09-2015 Tool run by Eigenaar on za 26/09/2015 at 9:51:40,42. Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x64 Running in: Normal Mode Internet Access Detected Launched: C:\Users\Eigenaar\Desktop\zoek.exe [Scan all users] [Script inserted] [Checkboxes used] ==== System Restore Info ====================== 26/09/2015 9:54:01 Zoek.exe System Restore Point Created Successfully. ==== Torpig Check ====================== HKEY_CLASSES_ROOT\Directory\shellex\CopyHookHandlers\FileSystem {217FC9C0-3AEA-1069-A2DB-08002B30309D} %SystemRoot%\system32\shell32.dll HKEY_CLASSES_ROOT\Directory\shellex\CopyHookHandlers\Sharing {40dd6e20-7c17-11ce-a804-00aa003ca9f6} %SystemRoot%\system32\ntshrui.dll ==== Empty Folders Check ====================== C:\Program Files\log deleted successfully C:\PROGRA~3\DAEMON Tools Lite deleted successfully C:\Users\Eigenaar\AppData\Roaming\DAEMON Tools Lite deleted successfully C:\Users\Eigenaar\AppData\Local\EmieBrowserModeList deleted successfully C:\Users\Eigenaar\AppData\Local\EmieSiteList deleted successfully C:\Users\Eigenaar\AppData\Local\EmieUserList deleted successfully C:\Users\Eigenaar\AppData\Local\Sparta deleted successfully C:\Users\Mike\AppData\Local\EmieBrowserModeList deleted successfully C:\Users\Mike\AppData\Local\EmieSiteList deleted successfully C:\Users\Mike\AppData\Local\EmieUserList deleted successfully C:\Users\Mike\AppData\Local\NokiaAccount deleted successfully C:\Users\Mike\AppData\Local\{000ADDA1-0260-4C43-9B1F-B0D35BE23BC2} deleted successfully C:\Users\Mike\AppData\Local\{00327533-E6D2-4645-A4DA-6D5E08707C02} deleted successfully C:\Users\Mike\AppData\Local\{03B39A45-E90D-4A4B-8F41-4D006C32DF1F} deleted successfully C:\Users\Mike\AppData\Local\{0433AF23-CF09-47C5-9B3F-9D8727C7B83D} deleted successfully C:\Users\Mike\AppData\Local\{044E07D4-781D-4D1D-BDDC-B9A2068C0712} deleted successfully C:\Users\Mike\AppData\Local\{048C0C14-0D8A-488A-9161-25FFA3D481D9} deleted successfully C:\Users\Mike\AppData\Local\{04AA93CB-F910-47AD-A23E-2C4457E8C4F2} deleted successfully C:\Users\Mike\AppData\Local\{04C464B3-F7BA-4FE8-ACC3-BC98F3FB7EBB} deleted successfully C:\Users\Mike\AppData\Local\{0553C360-A733-44CB-8EB8-9D4086A570CA} deleted successfully C:\Users\Mike\AppData\Local\{056516D5-DCD9-496A-97A2-9D318FB5DF13} deleted successfully C:\Users\Mike\AppData\Local\{066B42CC-8775-4BBA-857E-AC700ADEB59D} deleted successfully C:\Users\Mike\AppData\Local\{06ABA94E-C407-437A-9E6F-67A0564BC941} deleted successfully C:\Users\Mike\AppData\Local\{06EC3298-F0A0-43AD-BFE7-AD8340EE358B} deleted successfully C:\Users\Mike\AppData\Local\{0731A0BE-A590-49FB-9EBB-95FEC8FDDEDD} deleted successfully C:\Users\Mike\AppData\Local\{07A67AD9-9D87-428A-82A5-EF3BEBE8DD00} deleted successfully C:\Users\Mike\AppData\Local\{085026E6-F5AB-452E-8DA0-1D711FE2B49F} deleted successfully C:\Users\Mike\AppData\Local\{0897F7A5-CDEF-4DAD-82F6-8457B1046A5C} deleted successfully C:\Users\Mike\AppData\Local\{0A35D768-79AB-4ACD-8936-3DA02D3A7D52} deleted successfully C:\Users\Mike\AppData\Local\{0C82CCC3-82AE-4DA8-9797-99D09F02F54D} deleted successfully C:\Users\Mike\AppData\Local\{0D3164C6-258B-45B0-9540-CD024CC502A6} deleted successfully C:\Users\Mike\AppData\Local\{0D4C08C7-70BA-4915-A4F3-CB6502F5CC3A} deleted successfully C:\Users\Mike\AppData\Local\{0DAFA134-AE5D-4B77-870B-A85F1B6CD134} deleted successfully C:\Users\Mike\AppData\Local\{0DEB4F91-3C0B-428D-A9D0-C143E9AB4821} deleted successfully C:\Users\Mike\AppData\Local\{106D584E-5A83-4464-97BC-27D2883AB270} deleted successfully C:\Users\Mike\AppData\Local\{1209C357-22BE-4CAF-8326-7F0066A5FB35} deleted successfully C:\Users\Mike\AppData\Local\{13700287-58E1-40E8-A5B9-7879ADA6BC5F} deleted successfully C:\Users\Mike\AppData\Local\{1441C3F9-3C26-496B-B487-A0ACBCB9A785} deleted successfully C:\Users\Mike\AppData\Local\{14C050E6-D34F-40F9-A113-D750B740F7B4} deleted successfully C:\Users\Mike\AppData\Local\{1528D426-3B76-481A-B538-C4904CAA7775} deleted successfully C:\Users\Mike\AppData\Local\{1620D4E6-1D78-4D23-B480-4AFE4103B660} deleted successfully C:\Users\Mike\AppData\Local\{16B7C71A-E49C-47CE-9393-82D5C0BE566F} deleted successfully C:\Users\Mike\AppData\Local\{17750A20-EEB7-423A-98DA-5A27F525FFB2} deleted successfully C:\Users\Mike\AppData\Local\{17936F2F-249D-471F-AA0C-9A5E4480C61E} deleted successfully C:\Users\Mike\AppData\Local\{17D31791-0F1B-49B6-8712-D35AA276E0C5} deleted successfully C:\Users\Mike\AppData\Local\{180DD2C4-002A-4D9F-A99C-0B99EF3440F6} deleted successfully C:\Users\Mike\AppData\Local\{18650311-12C8-40B1-8A5B-AE2358B619C2} deleted successfully C:\Users\Mike\AppData\Local\{18D14119-7A70-406B-814C-3269DCB63A35} deleted successfully C:\Users\Mike\AppData\Local\{1A18874B-4AC2-422D-810F-25F72A3EC032} deleted successfully C:\Users\Mike\AppData\Local\{1A757821-7097-4BD9-B5F8-1292152B59BE} deleted successfully C:\Users\Mike\AppData\Local\{1AF193A1-52D8-4D59-8C98-744625BCC69E} deleted successfully C:\Users\Mike\AppData\Local\{1B116FE8-4B94-47DD-AA3B-54A42B36166F} deleted successfully C:\Users\Mike\AppData\Local\{1B1A4CA5-AF8C-468C-920A-ED29532F4C12} deleted successfully C:\Users\Mike\AppData\Local\{1B580B86-87D0-4DC6-BE9F-687148EE70C5} deleted successfully C:\Users\Mike\AppData\Local\{1C7BB6E3-33EB-42C0-A5AB-531E0C8EABBC} deleted successfully C:\Users\Mike\AppData\Local\{1C99979B-6245-4C81-BF95-A272C0B112E0} deleted successfully C:\Users\Mike\AppData\Local\{1CB046AA-4FAB-444A-9D4B-E54361730E5C} deleted successfully C:\Users\Mike\AppData\Local\{1CEEE651-53C5-497B-80BC-08D16E2DFD6B} deleted successfully C:\Users\Mike\AppData\Local\{1F8983FA-D205-4260-B287-699D4273FB1E} deleted successfully C:\Users\Mike\AppData\Local\{2077D856-B513-4CBF-88A9-CA0F283B8A63} deleted successfully C:\Users\Mike\AppData\Local\{209D7CB3-A43C-465D-8477-1A59805EC3D5} deleted successfully C:\Users\Mike\AppData\Local\{212DAC7E-6F33-448C-8B22-85EECAB2FCE0} deleted successfully C:\Users\Mike\AppData\Local\{215FF02E-D6C8-4383-A597-BEB470911351} deleted successfully C:\Users\Mike\AppData\Local\{22873D38-D5BA-4B81-B9BF-FAFE747A14C3} deleted successfully C:\Users\Mike\AppData\Local\{22C4EC7F-B9D0-4E79-B7A1-456AD8031B21} deleted successfully C:\Users\Mike\AppData\Local\{23D0C1EC-81BC-4D79-AABC-B4305FFAF60F} deleted successfully C:\Users\Mike\AppData\Local\{2545B4A6-9094-4411-BFA7-FD0161DC6E88} deleted successfully C:\Users\Mike\AppData\Local\{25700849-BB15-4786-9027-326449C24892} deleted successfully C:\Users\Mike\AppData\Local\{2608D934-E2AA-4D14-82A2-04A8BE891140} deleted successfully C:\Users\Mike\AppData\Local\{2610B361-C1E9-44ED-AD8B-9602AE6CEDFD} deleted successfully C:\Users\Mike\AppData\Local\{262238E6-7CAD-4BFE-8608-472B2A6F474F} deleted successfully C:\Users\Mike\AppData\Local\{286F0D67-A6BF-4BB3-BFB4-3ACF14123E71} deleted successfully C:\Users\Mike\AppData\Local\{2955066D-6DFF-4C49-8948-E53B2D9349A6} deleted successfully C:\Users\Mike\AppData\Local\{298B1BE5-6FD7-4217-A92D-8DB466F0E666} deleted successfully C:\Users\Mike\AppData\Local\{2B1D80D6-CBBA-4BD6-B095-11D68493433B} deleted successfully C:\Users\Mike\AppData\Local\{2B36C9DD-466C-4E42-B6C1-EC7DAB126516} deleted successfully C:\Users\Mike\AppData\Local\{2B533D49-3AE4-4338-98D6-3F4217EC2D7E} deleted successfully C:\Users\Mike\AppData\Local\{2BAE47C6-E976-4D11-B6EB-36BCDB7AD1FE} deleted successfully C:\Users\Mike\AppData\Local\{2C44E52C-3DDB-49D5-BD09-4B446C8AF232} deleted successfully C:\Users\Mike\AppData\Local\{2C91BF02-3357-4F05-ABAB-F322D8FA2F9F} deleted successfully C:\Users\Mike\AppData\Local\{2D0D4985-1BFE-4762-8D1C-9323D0B6CEFA} deleted successfully C:\Users\Mike\AppData\Local\{2EC01A54-A5F5-4FC3-A161-6B75C813DAB8} deleted successfully C:\Users\Mike\AppData\Local\{2EC42364-1E36-4B84-8B74-B7BF7F2528F5} deleted successfully C:\Users\Mike\AppData\Local\{300B1F78-1417-40BF-9EF2-120F7F25D7A2} deleted successfully C:\Users\Mike\AppData\Local\{309F3870-F192-4B24-9C70-A1E69390C5C8} deleted successfully C:\Users\Mike\AppData\Local\{310A2137-F891-461F-A0F8-2C1B9FA70497} deleted successfully C:\Users\Mike\AppData\Local\{317A07E5-E0E8-4B13-B884-BDE6CBE35668} deleted successfully C:\Users\Mike\AppData\Local\{31C19DE5-2AC4-4B9D-ADE7-D1AF7BFFF930} deleted successfully C:\Users\Mike\AppData\Local\{320F991A-CE83-4ADA-9A2E-E51CFACBB7DA} deleted successfully C:\Users\Mike\AppData\Local\{327ACFF2-0350-42AA-A322-28FB860592F4} deleted successfully C:\Users\Mike\AppData\Local\{331A2990-326E-4858-8BB8-1112CBB96BC7} deleted successfully C:\Users\Mike\AppData\Local\{34A70E5A-6AA7-4004-A2B9-66AC40D72B72} deleted successfully C:\Users\Mike\AppData\Local\{35C0FDA0-096F-4BFD-AA09-4433B90D9E3F} deleted successfully C:\Users\Mike\AppData\Local\{35CFF879-2367-4309-9F50-33A414D82F01} deleted successfully C:\Users\Mike\AppData\Local\{374D52CE-22C1-40D2-9F1E-1F0DBF8567EF} deleted successfully C:\Users\Mike\AppData\Local\{386E0E5A-6D9E-4048-B4DD-ED289C48EFB4} deleted successfully C:\Users\Mike\AppData\Local\{395EC7C7-265B-4454-BA1A-BD565AD626C3} deleted successfully C:\Users\Mike\AppData\Local\{39CA4610-AB4C-4520-8CCE-8D1C65AEDB60} deleted successfully C:\Users\Mike\AppData\Local\{3A6D95FD-341F-4281-AD89-708C8F804E21} deleted successfully C:\Users\Mike\AppData\Local\{3C85EBCC-46A2-4A83-A4E3-5F58C528C4D3} deleted successfully C:\Users\Mike\AppData\Local\{3D1A9E3E-ACBE-4F5D-8EE0-CD744E0C11A0} deleted successfully C:\Users\Mike\AppData\Local\{3E7F5DED-5F51-4D27-A0EC-BEC8DAF9AB60} deleted successfully C:\Users\Mike\AppData\Local\{3FB69643-B4EF-4917-A841-1FB97C3A663E} deleted successfully C:\Users\Mike\AppData\Local\{3FD72DFB-0391-49D5-BBCC-51E2892C55A0} deleted successfully C:\Users\Mike\AppData\Local\{4088A334-429D-4F56-9147-11297076DE2D} deleted successfully C:\Users\Mike\AppData\Local\{411A1241-8C0E-44E4-AB71-67E190825F0B} deleted successfully C:\Users\Mike\AppData\Local\{41919397-43CF-4501-A221-4764488E1DB5} deleted successfully C:\Users\Mike\AppData\Local\{421482B6-F049-41B6-A57F-8E2B4948EAC1} deleted successfully C:\Users\Mike\AppData\Local\{42A432E8-7A20-4636-832F-AF9D0C03BF58} deleted successfully C:\Users\Mike\AppData\Local\{43F4EB35-2129-4ED1-9AEB-0F7DCA82A118} deleted successfully C:\Users\Mike\AppData\Local\{44214B4C-975B-46E9-851D-F175AF7272DB} deleted successfully C:\Users\Mike\AppData\Local\{443F1D8C-A5A3-45AE-BC0D-BADD97AA1C97} deleted successfully C:\Users\Mike\AppData\Local\{4502CF0F-3D60-4E47-A84C-CD05E8CD7569} deleted successfully C:\Users\Mike\AppData\Local\{47885915-8A92-4B41-A03E-6E62DF7BE7A3} deleted successfully C:\Users\Mike\AppData\Local\{485AC7FB-EF5A-4E2D-96E0-FA60151F978B} deleted successfully C:\Users\Mike\AppData\Local\{4869E9C0-ABD2-4114-A527-0133DF2B17A1} deleted successfully C:\Users\Mike\AppData\Local\{486F6F4F-88EC-426B-B793-C43469F459B2} deleted successfully C:\Users\Mike\AppData\Local\{48BEE5A9-21C5-445D-BA6D-62815AFF5DDF} deleted successfully C:\Users\Mike\AppData\Local\{4923A59A-CE87-4D60-B511-CEC8833E4186} deleted successfully C:\Users\Mike\AppData\Local\{49641A38-5DED-4661-82EC-F56A00E145DF} deleted successfully C:\Users\Mike\AppData\Local\{4C0BD8A1-DAD4-4B04-A529-6E2CAAEC46DB} deleted successfully C:\Users\Mike\AppData\Local\{4D05A3E9-AE2F-4B02-81DF-0133F3BE048B} deleted successfully C:\Users\Mike\AppData\Local\{4D2D8FC3-2A4E-4DB1-86E7-C4D87A753289} deleted successfully C:\Users\Mike\AppData\Local\{53657275-9FAB-4161-9497-13BC37F8C97A} deleted successfully C:\Users\Mike\AppData\Local\{5414DE2D-96FA-4CB3-8C2A-5F16BB462047} deleted successfully C:\Users\Mike\AppData\Local\{5418B6E5-90C2-4046-923F-D0678A0080A3} deleted successfully C:\Users\Mike\AppData\Local\{5453863F-E043-465D-BAC7-0E7B047300EB} deleted successfully C:\Users\Mike\AppData\Local\{54CA0F04-C61C-4654-BF77-6D3EEE8390B3} deleted successfully C:\Users\Mike\AppData\Local\{56FF0FFF-1F7C-4E0F-B4CB-604713350A3F} deleted successfully C:\Users\Mike\AppData\Local\{57901360-4059-4C0B-9F54-6F8F559877FE} deleted successfully C:\Users\Mike\AppData\Local\{57DE35B3-C6CF-4C22-8739-499E5BB63E43} deleted successfully C:\Users\Mike\AppData\Local\{58D1AE46-A154-4094-939C-1E3744EB4A6C} deleted successfully C:\Users\Mike\AppData\Local\{5B8683FE-68BC-41D1-A79E-373CA15A12ED} deleted successfully C:\Users\Mike\AppData\Local\{5CBA169B-CBF2-4882-82A0-AA29DE0A55EF} deleted successfully C:\Users\Mike\AppData\Local\{5CE4A961-E4AA-4A9B-9899-E2A07A13F4C1} deleted successfully C:\Users\Mike\AppData\Local\{5ED734F1-2391-4139-AED3-F4FEEF74D4F9} deleted successfully C:\Users\Mike\AppData\Local\{60ADDD6F-590E-4627-9300-45C0A6D32974} deleted successfully C:\Users\Mike\AppData\Local\{60C274BE-E13D-4ED3-B9E6-A3F14B0A11D2} deleted successfully C:\Users\Mike\AppData\Local\{61892DF1-CACA-4726-B40A-11EA3F83D025} deleted successfully C:\Users\Mike\AppData\Local\{61921B7A-C452-43FC-A4CA-20D778642213} deleted successfully C:\Users\Mike\AppData\Local\{62F9857D-F54C-4278-9E2C-6F85F34AC87E} deleted successfully C:\Users\Mike\AppData\Local\{645A874C-DB6A-4188-B286-0F0BE58F09FF} deleted successfully C:\Users\Mike\AppData\Local\{65B0A029-C6C9-4768-8481-81206DF7C403} deleted successfully C:\Users\Mike\AppData\Local\{6610471F-C433-4869-B827-86685F6DD1FD} deleted successfully C:\Users\Mike\AppData\Local\{6630114E-4155-4EE3-99F6-B3592CBA87A9} deleted successfully C:\Users\Mike\AppData\Local\{67335E8F-35BD-4236-9CBE-3099FADCC9A1} deleted successfully C:\Users\Mike\AppData\Local\{67690016-B085-4FAF-AF56-B4E0F4C56704} deleted successfully C:\Users\Mike\AppData\Local\{68341D19-457C-4553-803B-5191E953AB97} deleted successfully C:\Users\Mike\AppData\Local\{693D950C-8604-4686-B32C-4EE49A16B474} deleted successfully C:\Users\Mike\AppData\Local\{693EB4E1-49D8-4B3C-8AA0-E5BC10AC3158} deleted successfully C:\Users\Mike\AppData\Local\{694C982E-3028-4BF9-BD0E-637123E6A15A} deleted successfully C:\Users\Mike\AppData\Local\{6AA5B420-49D8-419C-8263-C414CD903FBB} deleted successfully C:\Users\Mike\AppData\Local\{6B5D4C51-96D0-4D8F-AFB9-24798E1DAD9D} deleted successfully C:\Users\Mike\AppData\Local\{6B90778F-DC01-4971-9D97-750D936C23E5} deleted successfully C:\Users\Mike\AppData\Local\{6DAAEEB9-C558-4500-AE34-077519D7C5A2} deleted successfully C:\Users\Mike\AppData\Local\{6EE7209D-80F3-4C92-B4D3-614759AF6B00} deleted successfully C:\Users\Mike\AppData\Local\{707AB89A-CDBF-418A-B1AD-D8CD9DD56118} deleted successfully C:\Users\Mike\AppData\Local\{7133E89C-8348-47AB-8E20-F5A9EFB2CC29} deleted successfully C:\Users\Mike\AppData\Local\{71E7DD1C-B42A-4059-BF6B-10759A02B161} deleted successfully C:\Users\Mike\AppData\Local\{74CD8BC0-24BB-4A3A-9BFE-59AD2D3831D7} deleted successfully C:\Users\Mike\AppData\Local\{7526A443-7784-43FD-9F2B-2E8D6E302A1A} deleted successfully C:\Users\Mike\AppData\Local\{770E2B47-9CF6-491A-86C2-4A0E5A63E68D} deleted successfully C:\Users\Mike\AppData\Local\{77404DD7-83B1-43AB-AFD9-EE6FFCAB4494} deleted successfully C:\Users\Mike\AppData\Local\{77F4FE01-2827-4262-8A8C-61BBBB05521F} deleted successfully C:\Users\Mike\AppData\Local\{77FDA8FD-AC10-4231-A2D1-B5C0239BCD5C} deleted successfully C:\Users\Mike\AppData\Local\{78F1D636-44A8-409F-800B-3FF67011BAEA} deleted successfully C:\Users\Mike\AppData\Local\{7A9D707A-246A-4C4F-A90D-9D6DC2B510FA} deleted successfully C:\Users\Mike\AppData\Local\{7AAE2F8A-246A-48F9-927C-B5A3AC6A0C3E} deleted successfully C:\Users\Mike\AppData\Local\{7B490ECA-50BD-468C-BF30-CC5CD2FB15FA} deleted successfully C:\Users\Mike\AppData\Local\{7B771B87-4BF4-4876-AF52-5295176EE81A} deleted successfully C:\Users\Mike\AppData\Local\{7C413121-3D39-43E9-9941-BCFA209B09C0} deleted successfully C:\Users\Mike\AppData\Local\{7D2004CE-FE0A-4E3D-8359-5FA661B7C890} deleted successfully C:\Users\Mike\AppData\Local\{7D90CA3A-BB46-48EF-A974-DEAD87651592} deleted successfully C:\Users\Mike\AppData\Local\{7DC59A06-10F1-4E46-9BBE-A0BF6ABB8B92} deleted successfully C:\Users\Mike\AppData\Local\{7F7EEC74-2AC9-4247-9CE8-B7A7625AB140} deleted successfully C:\Users\Mike\AppData\Local\{80227F5F-6FC5-4F61-81EF-3D4248653380} deleted successfully C:\Users\Mike\AppData\Local\{8067985B-81C6-412E-A053-79281393DE66} deleted successfully C:\Users\Mike\AppData\Local\{806B44EB-F0D3-4E43-A498-1F32B8C462A9} deleted successfully C:\Users\Mike\AppData\Local\{81B0D418-1F1B-484A-9003-E6E2C92EAB63} deleted successfully C:\Users\Mike\AppData\Local\{81D6C61B-3826-429B-A89C-578EF696D967} deleted successfully C:\Users\Mike\AppData\Local\{850BB695-1DD1-40A9-90CD-4DBF20E6FC6A} deleted successfully C:\Users\Mike\AppData\Local\{8623DC9C-E13F-45A6-98D8-4B870B114350} deleted successfully C:\Users\Mike\AppData\Local\{8780F342-3CCA-4996-8467-87CDF14F28D9} deleted successfully C:\Users\Mike\AppData\Local\{891C7FA7-5540-4F33-864F-4BEE2A690366} deleted successfully C:\Users\Mike\AppData\Local\{89487FE8-DFFD-4F8D-ABBC-D53BDDE399AB} deleted successfully C:\Users\Mike\AppData\Local\{89E9BFB0-A646-461A-B7DC-9E7FB174F9E5} deleted successfully C:\Users\Mike\AppData\Local\{89FDD7F6-D91B-4F5F-AB6E-A41186720604} deleted successfully C:\Users\Mike\AppData\Local\{8A7D5014-E4E1-4BFC-8110-63AF94EAF264} deleted successfully C:\Users\Mike\AppData\Local\{8ABDEE6F-DB38-4C72-BBCF-E45C7DB6F2D0} deleted successfully C:\Users\Mike\AppData\Local\{8AC52B14-6081-417C-BBA1-3F0C4BBD6DEB} deleted successfully C:\Users\Mike\AppData\Local\{8B5F5093-A7BB-4BD6-84B8-5BC9A39AD429} deleted successfully C:\Users\Mike\AppData\Local\{8C9F61E9-B928-49D1-88FA-2B697EBF63EE} deleted successfully C:\Users\Mike\AppData\Local\{8CDA65DF-A311-4B34-B76F-D0BB2C2146E9} deleted successfully C:\Users\Mike\AppData\Local\{8E2FA312-C136-48F4-843A-D7513971B118} deleted successfully C:\Users\Mike\AppData\Local\{8EC157AB-5BAB-4079-9E0A-119E9E58C23E} deleted successfully C:\Users\Mike\AppData\Local\{931A95CC-AC29-4171-86AE-EACFDC0FE58F} deleted successfully C:\Users\Mike\AppData\Local\{937E25EB-09E7-4F34-AEA1-00F9DE5544EC} deleted successfully C:\Users\Mike\AppData\Local\{93CFFC0E-5DA4-4C3C-8663-38BFA9E0287C} deleted successfully C:\Users\Mike\AppData\Local\{93D18366-FACB-4F70-96A7-671577919AA2} deleted successfully C:\Users\Mike\AppData\Local\{950724B9-54C3-4FD8-A698-73A981545F40} deleted successfully C:\Users\Mike\AppData\Local\{954083CC-B686-4874-B012-48BCE171BCF7} deleted successfully C:\Users\Mike\AppData\Local\{9540A4C5-42FE-4105-A58B-CE4F3A564816} deleted successfully C:\Users\Mike\AppData\Local\{95ED9956-2752-410D-BDB6-D3689DAC00DB} deleted successfully C:\Users\Mike\AppData\Local\{96FA1423-81D0-475C-93A3-6EDA2B4C6457} deleted successfully C:\Users\Mike\AppData\Local\{9816C6D5-8FA9-473C-8641-83E683C2BB2F} deleted successfully C:\Users\Mike\AppData\Local\{989204DF-A8C7-417E-9F8C-25CA48DC9047} deleted successfully C:\Users\Mike\AppData\Local\{990F2EED-F5AA-42AE-B4A7-87D553AABFE4} deleted successfully C:\Users\Mike\AppData\Local\{992AED18-0EDA-47E8-A4EF-5311D7633DD0} deleted successfully C:\Users\Mike\AppData\Local\{9964799B-76B9-43A8-9492-0FFDD737B66A} deleted successfully C:\Users\Mike\AppData\Local\{998E8827-8D27-40BC-B192-067013543F3E} deleted successfully C:\Users\Mike\AppData\Local\{9B014344-9A1B-47ED-9C23-672FDF7E0C4A} deleted successfully C:\Users\Mike\AppData\Local\{9B208C23-3815-45BE-B0A4-FAD7D3420F2D} deleted successfully C:\Users\Mike\AppData\Local\{9B5D9ADA-1AC9-4692-91B1-9570F27A0F61} deleted successfully C:\Users\Mike\AppData\Local\{9CF8149B-F7B8-4710-B7A2-0FAB41E966E2} deleted successfully C:\Users\Mike\AppData\Local\{9D3BC887-33D6-44E7-83BB-791BB6771B10} deleted successfully C:\Users\Mike\AppData\Local\{9EA86BE2-8EF4-4F21-BE18-74FB3939F068} deleted successfully C:\Users\Mike\AppData\Local\{A00A37D6-1A63-4A47-8EE0-6848F17D36C7} deleted successfully C:\Users\Mike\AppData\Local\{A0D943E5-38AA-44D5-AF1A-DBC87E4EC3CA} deleted successfully C:\Users\Mike\AppData\Local\{A1245FBF-3FBE-42FD-95BF-BF55A636F10A} deleted successfully C:\Users\Mike\AppData\Local\{A16875BB-3943-4D6D-AC08-D367635CC655} deleted successfully C:\Users\Mike\AppData\Local\{A220601C-AE8F-4947-93CD-8866CB943251} deleted successfully C:\Users\Mike\AppData\Local\{A2350954-9D0E-4E82-8467-47D1BC6791C6} deleted successfully C:\Users\Mike\AppData\Local\{A5A791E3-D68B-477D-B0CA-D86B07AB9F93} deleted successfully C:\Users\Mike\AppData\Local\{A6A12FE1-512A-470D-B24D-299DEB91D87B} deleted successfully C:\Users\Mike\AppData\Local\{A6A5B532-DB9B-4C5E-B996-FE5176CADBBA} deleted successfully C:\Users\Mike\AppData\Local\{A74BAA52-88B4-4374-BEF2-242C407A7D4D} deleted successfully C:\Users\Mike\AppData\Local\{A7FE6697-C9BD-414A-B396-C0262AD38A8B} deleted successfully C:\Users\Mike\AppData\Local\{A87FA222-519E-4B05-A386-7748E41A7EFB} deleted successfully C:\Users\Mike\AppData\Local\{A8A90C7F-F7C4-48FE-99E4-BE81D39D82F4} deleted successfully C:\Users\Mike\AppData\Local\{A992481D-F2CC-462B-A1BF-B0673B6922D6} deleted successfully C:\Users\Mike\AppData\Local\{A9A5E99E-77BE-4182-9D92-2C34B1F9B6D4} deleted successfully C:\Users\Mike\AppData\Local\{AA22F3D2-D23B-4526-A314-4BAB2A299219} deleted successfully C:\Users\Mike\AppData\Local\{AAC8DE55-FECF-45FE-82A6-DCE2ACBC2DCA} deleted successfully C:\Users\Mike\AppData\Local\{AC71261B-C21C-484A-8591-6D5345D1196A} deleted successfully C:\Users\Mike\AppData\Local\{AE6CD7AB-8154-449F-91EE-2926A35BB282} deleted successfully C:\Users\Mike\AppData\Local\{AEC10066-7903-4E22-9D07-3CCF6F614C4F} deleted successfully C:\Users\Mike\AppData\Local\{AF85A926-AB4A-4980-82E0-C9D0BA32D811} deleted successfully C:\Users\Mike\AppData\Local\{B07153AF-1054-4AE3-99D0-438B140C7478} deleted successfully C:\Users\Mike\AppData\Local\{B3295291-BF83-4FFF-AAAE-1C5D455467E1} deleted successfully C:\Users\Mike\AppData\Local\{B4635E02-BE2B-4A67-AA85-5A46BBC8F24F} deleted successfully C:\Users\Mike\AppData\Local\{B4651A98-2849-49A2-848C-71794CC9460D} deleted successfully C:\Users\Mike\AppData\Local\{B51DD303-FD61-48D2-ACF7-F230CB2F05DD} deleted successfully C:\Users\Mike\AppData\Local\{B5B2A824-879C-43AD-B810-551A86FED498} deleted successfully C:\Users\Mike\AppData\Local\{B72CE51D-D300-4D4D-A11B-62617C06C23D} deleted successfully C:\Users\Mike\AppData\Local\{B8B17932-CB54-48A9-9C12-DEFC5A502B43} deleted successfully C:\Users\Mike\AppData\Local\{BA0605D5-4D6D-4059-B587-CC806B5CAB56} deleted successfully C:\Users\Mike\AppData\Local\{BAF0BABA-15B5-4559-8F7E-9611ECEC509A} deleted successfully C:\Users\Mike\AppData\Local\{BC63CEB3-0959-424A-99F7-9E8E34E3D475} deleted successfully C:\Users\Mike\AppData\Local\{BD2CD5EF-8433-4927-9610-CCBFC3C46C1D} deleted successfully C:\Users\Mike\AppData\Local\{BDBB0C23-D2E7-4816-85EF-1920714681E1} deleted successfully C:\Users\Mike\AppData\Local\{BEA5AB6D-D00A-4977-8192-D4AFB0CCBF9B} deleted successfully C:\Users\Mike\AppData\Local\{BF3B92E5-395C-4FA3-8244-4388D6553C04} deleted successfully C:\Users\Mike\AppData\Local\{C03337CA-4B65-45DA-812E-15D1F0BD93AD} deleted successfully C:\Users\Mike\AppData\Local\{C03EE8DE-61F2-4F6D-85D1-40103289E8B7} deleted successfully C:\Users\Mike\AppData\Local\{C0F692F8-6C13-49FF-870C-DA07DDEC6D15} deleted successfully C:\Users\Mike\AppData\Local\{C198C6ED-33FE-4B4A-B0A6-1F2EB7368CD2} deleted successfully C:\Users\Mike\AppData\Local\{C1F32339-7677-4156-90F7-1C981874BDC2} deleted successfully C:\Users\Mike\AppData\Local\{C21E7762-5636-4031-B4F6-C22CABED7CEA} deleted successfully C:\Users\Mike\AppData\Local\{C4FB84E3-FC60-425A-81A7-4CE201C5FF59} deleted successfully C:\Users\Mike\AppData\Local\{C58EC582-FF9F-4469-B2E5-4E4378AB607E} deleted successfully C:\Users\Mike\AppData\Local\{C69A05C5-3B01-456D-BFF6-8C02043FFD6E} deleted successfully C:\Users\Mike\AppData\Local\{C6B0AABF-0CB7-4D53-9830-4F59B2A12F21} deleted successfully C:\Users\Mike\AppData\Local\{C7FF948A-4789-4A86-957A-5E216AB0630A} deleted successfully C:\Users\Mike\AppData\Local\{CA26617C-4351-4AF9-9FFE-26A55DC559C7} deleted successfully C:\Users\Mike\AppData\Local\{CA41AFCB-F76B-4241-9E43-C63D4544F998} deleted successfully C:\Users\Mike\AppData\Local\{CAEFD379-8EE3-453C-8FF2-5FE2E8CBBE28} deleted successfully C:\Users\Mike\AppData\Local\{CB151FAA-2DC3-4666-843F-1B326C1078C6} deleted successfully C:\Users\Mike\AppData\Local\{CBFA458B-9FFC-4B7A-B9B6-4C47C962506F} deleted successfully C:\Users\Mike\AppData\Local\{CEF173F7-4F22-460C-AAC8-A0B95A78784C} deleted successfully C:\Users\Mike\AppData\Local\{CF4CFD05-4201-490B-8100-0403940CD133} deleted successfully C:\Users\Mike\AppData\Local\{D00E05A5-C928-4B9B-933A-AEBAAAD883E6} deleted successfully C:\Users\Mike\AppData\Local\{D3C6F8E1-2E27-4695-8FC3-CD873FDB6835} deleted successfully C:\Users\Mike\AppData\Local\{D3F62622-D081-427A-A7F4-6B9B66D1D7DF} deleted successfully C:\Users\Mike\AppData\Local\{D449C0EC-BCAE-42E8-A816-6F2C1BE270F5} deleted successfully C:\Users\Mike\AppData\Local\{D4BCE852-820B-405D-BBA6-2942C20E532A} deleted successfully C:\Users\Mike\AppData\Local\{D508F05B-B1D2-4C65-8563-DFF7B515D5B0} deleted successfully C:\Users\Mike\AppData\Local\{D59BEBC5-CEA2-4F14-A02E-56A04B4F0B7A} deleted successfully C:\Users\Mike\AppData\Local\{D7475FF4-EB62-45ED-8297-0C17187560F5} deleted successfully C:\Users\Mike\AppData\Local\{D92358D5-5963-4A85-8981-30D9CAFB41BB} deleted successfully C:\Users\Mike\AppData\Local\{D92BF9FE-FE7D-49B0-AF88-87C108E157B4} deleted successfully C:\Users\Mike\AppData\Local\{DA0014F2-E9E1-4752-9604-4D39C18F7355} deleted successfully C:\Users\Mike\AppData\Local\{DE44F611-E17A-41C9-86B0-D9FE4CEE5987} deleted successfully C:\Users\Mike\AppData\Local\{DFAFFEBC-AC30-4225-A277-1FD145808B9B} deleted successfully C:\Users\Mike\AppData\Local\{E052BCF9-339D-49CA-A3EF-553C24DCBF36} deleted successfully C:\Users\Mike\AppData\Local\{E11812E2-14CC-4338-A734-5CCB2C36E2E5} deleted successfully C:\Users\Mike\AppData\Local\{E18C5AA2-9105-43E1-B998-75DB8A4E4F7F} deleted successfully C:\Users\Mike\AppData\Local\{E24644AF-3CC3-4432-8340-17E78E84BE96} deleted successfully C:\Users\Mike\AppData\Local\{E2665B2F-1333-4D91-BF2C-775A7E0B463B} deleted successfully C:\Users\Mike\AppData\Local\{E41CEB61-985D-4B50-8BDD-A5EFDA71318C} deleted successfully C:\Users\Mike\AppData\Local\{E5EC504A-FCD4-42BD-A008-00C638B9DCDE} deleted successfully C:\Users\Mike\AppData\Local\{E63F24E6-F303-4302-B705-2BD520DB6D19} deleted successfully C:\Users\Mike\AppData\Local\{E7076C8A-6081-4FEE-817B-79AE26B7AF09} deleted successfully C:\Users\Mike\AppData\Local\{E777BA9A-298E-4F4E-9889-A0D4068B3B80} deleted successfully C:\Users\Mike\AppData\Local\{E7E08654-69D5-4295-8CF4-95D0748E8B63} deleted successfully C:\Users\Mike\AppData\Local\{E947C52F-4C55-4707-8573-7B804C97139B} deleted successfully C:\Users\Mike\AppData\Local\{EA597A07-978E-407A-B31F-74364F252255} deleted successfully C:\Users\Mike\AppData\Local\{EAB5CFA8-3CEB-40B7-9DDF-5173782ADA50} deleted successfully C:\Users\Mike\AppData\Local\{EC7DEA0B-3082-4FB8-BD9C-FD948CCDB31A} deleted successfully C:\Users\Mike\AppData\Local\{ED75A78E-77C2-4F39-A2DD-1FCA80785FEE} deleted successfully C:\Users\Mike\AppData\Local\{EF8DB68E-A22C-435F-B1D0-914957901078} deleted successfully C:\Users\Mike\AppData\Local\{F0955037-FF03-4701-8D2D-474567D5A624} deleted successfully C:\Users\Mike\AppData\Local\{F1518084-908C-457B-9B3F-E9CCA000F367} deleted successfully C:\Users\Mike\AppData\Local\{F40031EC-AEC4-4701-94A8-E97CCC43D4D0} deleted successfully C:\Users\Mike\AppData\Local\{F60353F9-FB9D-47EA-8FB1-CC3E0A32263C} deleted successfully C:\Users\Mike\AppData\Local\{F973E55D-AE09-4D59-A338-AC0C01625C76} deleted successfully C:\Users\Mike\AppData\Local\{FA062E75-CE5C-4072-850D-53E877925516} deleted successfully C:\Users\Mike\AppData\Local\{FB24AB99-740F-4576-8CDB-7F8BAA74B3F4} deleted successfully C:\Users\Mike\AppData\Local\{FBA5B448-A08B-439C-8001-1AAC12A0121C} deleted successfully C:\Users\Mike\AppData\Local\{FC663E38-8CD9-488E-A7F6-FA844E4119A4} deleted successfully C:\Users\Mike\AppData\Local\{FC923A5C-209D-4DAA-97AA-29200370722D} deleted successfully C:\Users\Mike\AppData\Local\{FCACAEE5-1E15-4870-AB74-BFB2A29F44DC} deleted successfully C:\Users\Mike\AppData\Local\{FCE13D3B-8FE3-4381-9D5D-6AD2FB751A63} deleted successfully C:\Users\Mike\AppData\Local\{FD29F95D-8657-46EE-BEB4-05B56D17ABE8} deleted successfully C:\Users\Mike\AppData\Local\{FE929CC3-F891-439E-B421-05383415411F} deleted successfully C:\Users\Mike\AppData\Local\{FEC7E93B-FF41-4625-9638-7789B9DA886A} deleted successfully C:\Users\Mike\AppData\Local\{FF4A34EE-F72C-415E-B967-B481073F98C5} deleted successfully C:\Users\Mike\AppData\Local\{FF76DA98-F0EA-4875-8430-F06A5D5E31BF} deleted successfully ==== Deleting CLSID Registry Keys ====================== HKEY_USERS\S-1-5-21-3810738976-3084446121-2423524701-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233} deleted successfully HKEY_USERS\S-1-5-21-3810738976-3084446121-2423524701-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{95B7759C-8C7F-4BF1-B163-73684A933233} deleted successfully HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233} deleted successfully ==== Deleting CLSID Registry Values ====================== ==== Deleting Services ====================== HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\vToolbarUpdater40.1.6 deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\vToolbarUpdater40.1.6 deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WtuSystemSupport deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\WtuSystemSupport deleted successfully ==== Registry Fix Code x64 ====================== Windows Registry Editor Version 5.00 Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}] [HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run] "vProt"=- ==== Deleting Files \ Folders ====================== C:\Users\Eigenaar\AppData\Local\AVG Web TuneUp deleted C:\Users\Mike\AppData\Local\AVG Web TuneUp deleted C:\PROGRA~2\COMMON~1\DVDVideoSoft\bin deleted C:\PROGRA~3\AVG Web TuneUp deleted C:\PROGRA~3\AVG Security Toolbar deleted C:\PROGRA~3\YTD Video Downloader deleted C:\PROGRA~3\AVG Secure Search deleted C:\PROGRA~3\{01BD4FC9-2F86-4706-A62E-774BB7E9D308} deleted C:\PROGRA~3\Package Cache deleted C:\Users\Eigenaar\AppData\Local\Unity deleted C:\Users\Mike\AppData\Local\Unity deleted C:\ProgramData\Microsoft\Windows\Start Menu\Programs\YTD Video Downloader deleted C:\Users\Eigenaar\AppData\LocalLow\Unity deleted C:\Users\Eigenaar\AppData\LocalLow\AVG Web TuneUp deleted C:\Users\Mike\AppData\LocalLow\Unity deleted C:\Users\Mike\AppData\LocalLow\AVG Web TuneUp deleted C:\Windows\sysWoW64\config\systemprofile\AppData\LocalLow\AVG Web TuneUp deleted C:\Windows\SysNative\config\systemprofile\Searches deleted "C:\Windows\Installer\e1d376.msi" deleted "C:\Program Files (x86)\AVG Web TuneUp\avgcefrend.exe" deleted "C:\Program Files (x86)\AVG Web TuneUp\icudt.dll" deleted "C:\Program Files (x86)\AVG Web TuneUp\libcef.dll" deleted "C:\Program Files (x86)\AVG Web TuneUp\vprot.exe" deleted "C:\PROGRA~2\AVG Web TuneUp\avgcefrend.exe" deleted "C:\PROGRA~2\AVG Web TuneUp\icudt.dll" deleted "C:\PROGRA~2\AVG Web TuneUp\libcef.dll" deleted "C:\PROGRA~2\AVG Web TuneUp\vprot.exe" deleted "C:\Program Files (x86)\AVG Web TuneUp\locales\en-US.pak" deleted "C:\PROGRA~2\AVG Web TuneUp\locales\en-US.pak" deleted "C:\PROGRA~2\COMMON~1\AVG Secure Search\DNTInstaller\40.1.6\avgdttbx.dll" deleted "C:\PROGRA~2\COMMON~1\AVG Secure Search\vToolbarUpdater\40.1.6\log4cplusU.dll" deleted "C:\Program Files (x86)\AVG Web TuneUp" deleted "C:\PROGRA~2\AVG Web TuneUp" deleted "C:\PROGRA~2\COMMON~1\AVG Secure Search" deleted "C:\Program Files (x86)\AVG Web TuneUp\locales" deleted "C:\PROGRA~2\AVG Web TuneUp\locales" deleted "C:\PROGRA~2\COMMON~1\AVG Secure Search\DNTInstaller" deleted "C:\PROGRA~2\COMMON~1\AVG Secure Search\vToolbarUpdater" deleted "C:\PROGRA~2\COMMON~1\AVG Secure Search\DNTInstaller\40.1.6" deleted "C:\PROGRA~2\COMMON~1\AVG Secure Search\vToolbarUpdater\40.1.6" deleted ==== Files Recently Created / Modified ====================== ====== C:\Windows ==== ====== C:\Users\Eigenaar\AppData\Local\Temp ==== ====== Java Cache ===== 2015-09-14 12:20:46 415FC9732A3F4D89A0E01251CD66E136 646 ----a-w- C:\Users\Eigenaar\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\17\49a00451-6b569d02 2015-09-14 12:20:46 29603D6ABAC057A9C6D30169A5AC243A 425 ----a-w- C:\Users\Eigenaar\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\17\49a00451-aa56bb018d5de3a531ee91cc4857f0f479656e5370ebf87789e721aaaf530ebc-6.0.lap 2015-09-14 12:20:45 415FC9732A3F4D89A0E01251CD66E136 646 ----a-w- C:\Users\Eigenaar\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\18\3cb32f52-679f5bfc 2015-09-14 15:49:32 39864788BD482290FA3263B1AA5BC313 9289 ----a-w- C:\Users\Eigenaar\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\2\23ac4802-393b0f08 2015-09-14 12:21:26 D022C2717EA020C8583B141FDEF54F24 452 ----a-w- C:\Users\Eigenaar\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\22\50969556-c5b1ec7d4e8a132c006d6b2cf30a124389d456c4d9b32c9e768cf3bc7a0aae94-6.0.lap 2015-09-14 12:20:59 C1BBA7F1278F193AB584FFF460DB5E2A 17878 ----a-w- C:\Users\Eigenaar\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\35\47c58863-6629a974 2015-09-14 12:21:28 D497DD2F1685B10E7DA52F383BB6E42B 423 ----a-w- C:\Users\Eigenaar\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\42\2e4c72ea-341e4c6b 2015-09-14 12:20:46 34FA8033B50A3F99D3AB8209C72C0ABA 6860 ----a-w- C:\Users\Eigenaar\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\43\1ca2666b-2f13a644 ====== C:\Windows\SysWOW64 ===== 2015-09-22 10:35:31 C05114B0BDF2470F7F4A1B2128540062 97888 ----a-w- C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2015-09-22 07:23:46 90E480789256D852FA3EADD39D56FDDA 6131200 ----a-w- C:\Windows\SysWOW64\mstscax.dll 2015-09-22 07:23:45 AF0EC95144F76EA4B40A7ED1DD34616C 856064 ----a-w- C:\Windows\SysWOW64\rdvidcrl.dll 2015-09-22 07:23:45 A27593907607A692D0DE105DE29BBC33 53248 ----a-w- C:\Windows\SysWOW64\tsgqec.dll 2015-09-19 06:15:41 AB5EFB103DB01C1912C9D2F545EA5621 17920 ----a-w- C:\Windows\SysWOW64\wksprtPS.dll 2015-09-19 06:15:41 2EFB1279E7BEA7D12D9F4D6508D27880 50176 ----a-w- C:\Windows\SysWOW64\MsRdpWebAccess.dll 2015-09-19 06:15:40 4676AAA9DDF52A50C829FEDB4EA81E54 1068544 ----a-w- C:\Windows\SysWOW64\mstsc.exe 2015-09-19 06:14:21 8999F18D38D55E34D356796507FFD639 192000 ----a-w- C:\Windows\SysWOW64\rdpendp_winip.dll 2015-09-19 06:12:08 EF5FC09E1FF10F2F88FE0588D955D766 172032 ----a-w- C:\Windows\SysWOW64\wdigest.dll 2015-09-19 06:12:08 E72B1F594E8CEEC03BBAB39C45A5A467 50176 ----a-w- C:\Windows\SysWOW64\auditpol.exe 2015-09-19 06:12:08 E6D4634BC2E13322727283EEC677853C 36864 ----a-w- C:\Windows\SysWOW64\cryptbase.dll 2015-09-19 06:12:08 B489B00556C6C2031DFDAE81BA6DF60D 259584 ----a-w- C:\Windows\SysWOW64\msv1_0.dll 2015-09-19 06:12:08 AEC6E5459A89A9D42E6E7BA7D21FDFFF 221184 ----a-w- C:\Windows\SysWOW64\ncrypt.dll 2015-09-19 06:12:08 A84651315C2CBB67686B4176E515FAFD 665088 ----a-w- C:\Windows\SysWOW64\rpcrt4.dll 2015-09-19 06:12:08 9340E0DD985AD87B77B7FA6A5D31F849 65536 ----a-w- C:\Windows\SysWOW64\TSpkg.dll 2015-09-19 06:12:08 816C0A6A88EF9DCE8DD515F18A3FEEC5 552960 ----a-w- C:\Windows\SysWOW64\kerberos.dll 2015-09-19 06:12:08 7DDE339472915CD45D47E92C22E7B69A 96768 ----a-w- C:\Windows\SysWOW64\sspicli.dll 2015-09-19 06:12:08 727BCDD53B58B6CB79589672F63A0206 17408 ----a-w- C:\Windows\SysWOW64\credssp.dll 2015-09-19 06:12:08 449A23270388C656437453E06A876BBA 22016 ----a-w- C:\Windows\SysWOW64\secur32.dll 2015-09-19 06:12:08 31F7525FB731186382A8A33DA036DACB 248832 ----a-w- C:\Windows\SysWOW64\schannel.dll 2015-09-19 06:12:08 310D778D78B9D54855F89DC9A939920B 686080 ----a-w- C:\Windows\SysWOW64\adtschema.dll 2015-09-19 06:12:07 D2B72093C10FA706AD2D59A9CA4A6075 60416 ----a-w- C:\Windows\SysWOW64\msobjs.dll 2015-09-19 06:12:07 260D649FAE6E63A84F8AA9A7163B8C09 146432 ----a-w- C:\Windows\SysWOW64\msaudite.dll 2015-09-19 06:09:21 CBF3CFC9EE1FD29707D95C63A5E7A78B 19808 ----a-w- C:\Windows\SysWOW64\api-ms-win-crt-multibyte-l1-1-0.dll 2015-09-19 06:09:21 C1096DA4634AD3356A10C00B24F53393 22368 ----a-w- C:\Windows\SysWOW64\api-ms-win-crt-math-l1-1-0.dll 2015-09-19 06:09:21 B23936CF83DAC4B64660A88711B5234A 12128 ----a-w- C:\Windows\SysWOW64\api-ms-win-crt-locale-l1-1-0.dll 2015-09-19 06:09:21 9F9FE5F52E9B2AD655C896B849883B1A 12128 ----a-w- C:\Windows\SysWOW64\api-ms-win-crt-utility-l1-1-0.dll 2015-09-19 06:09:21 9D66FCC681389EC619D4E801F1DDBB2F 17760 ----a-w- C:\Windows\SysWOW64\api-ms-win-crt-stdio-l1-1-0.dll 2015-09-19 06:09:21 94FEB4417CF3E39C8C58A1B73620687E 66400 ----a-w- C:\Windows\SysWOW64\api-ms-win-crt-private-l1-1-0.dll 2015-09-19 06:09:21 8E534F49C77D787DB69BABFF931A497A 12640 ----a-w- C:\Windows\SysWOW64\api-ms-win-crt-conio-l1-1-0.dll 2015-09-19 06:09:21 85CEBA9A21CE5D51B35EF2DE9EBFBAC4 12128 ----a-w- C:\Windows\SysWOW64\api-ms-win-crt-environment-l1-1-0.dll 2015-09-19 06:09:21 80BEB858D2EEE9CA657647B599E5D844 11616 ----a-w- C:\Windows\SysWOW64\api-ms-win-eventing-provider-l1-1-0.dll 2015-09-19 06:09:21 73CED8B30963E54D262DAE2559116E46 13664 ----a-w- C:\Windows\SysWOW64\api-ms-win-crt-filesystem-l1-1-0.dll 2015-09-19 06:09:21 6C7F782FDBF9AEFFE7663FA1579A610E 17760 ----a-w- C:\Windows\SysWOW64\api-ms-win-crt-string-l1-1-0.dll 2015-09-19 06:09:21 5B55E9A1360A6C52CC988DA6804D6CA2 901264 ----a-w- C:\Windows\SysWOW64\ucrtbase.dll 2015-09-19 06:09:21 4669249FB01EA369C7FD40A530966FA1 12640 ----a-w- C:\Windows\SysWOW64\api-ms-win-crt-heap-l1-1-0.dll 2015-09-19 06:09:21 408019E57D3D2DA62A9F28389EED0AC1 16224 ----a-w- C:\Windows\SysWOW64\api-ms-win-crt-runtime-l1-1-0.dll 2015-09-19 06:09:21 39F9D0F1B698D53D78C79576C7C60526 14176 ----a-w- C:\Windows\SysWOW64\api-ms-win-crt-time-l1-1-0.dll 2015-09-19 06:09:21 33E8CCBE05123C8146CD16293B688417 15712 ----a-w- C:\Windows\SysWOW64\api-ms-win-crt-convert-l1-1-0.dll 2015-09-19 06:09:21 00A0A24BB2E9AADE11494B627EB164C4 12640 ----a-w- C:\Windows\SysWOW64\api-ms-win-crt-process-l1-1-0.dll ====== C:\Windows\SysWOW64\drivers ===== ====== C:\Windows\Sysnative ===== 2015-09-22 07:23:46 C01DC60229F41D33AF2DF4162EDA0F44 7077376 ----a-w- C:\Windows\Sysnative\mstscax.dll 2015-09-22 07:23:46 2686F572B3CAF633C4A350A3671835F2 429568 ----a-w- C:\Windows\Sysnative\wksprt.exe 2015-09-22 07:23:45 CDA122FCC691D14D3971A83AB035156D 62976 ----a-w- C:\Windows\Sysnative\tsgqec.dll 2015-09-22 07:23:45 35A97817FDA4C8F421D8478DCCF045B1 1057792 ----a-w- C:\Windows\Sysnative\rdvidcrl.dll 2015-09-21 09:49:26 F6D23F6707CAEA235E4C84A4AC87EB2A 3180544 ----a-w- C:\Windows\Sysnative\rdpcorets.dll 2015-09-21 09:49:25 960D313FFBC9C4C14D9DFDB1FEB21CBD 16384 ----a-w- C:\Windows\Sysnative\RdpGroupPolicyExtension.dll 2015-09-21 09:49:25 15C3986C015EA186BCB4E6096528D656 243200 ----a-w- C:\Windows\Sysnative\rdpudd.dll 2015-09-21 09:49:01 2A9C3ADBC3B9D061CACDEFFBED67683C 87040 ----a-w- C:\Windows\Sysnative\TSWbPrxy.exe 2015-09-19 06:15:43 DDED7C5558B3AE09F568945281A9A6D1 44544 ----a-w- C:\Windows\Sysnative\TsUsbGDCoInstaller.dll 2015-09-19 06:15:41 FEC6178962DFF33074D39CA907971405 12800 ----a-w- C:\Windows\Sysnative\TsUsbRedirectionGroupPolicyExtension.dll 2015-09-19 06:15:41 7BD2E6E2458A5B95F8341244C7FC7DD4 18944 ----a-w- C:\Windows\Sysnative\wksprtPS.dll 2015-09-19 06:15:41 108C257D765AAD2E6EC46557DA0B02BD 13824 ----a-w- C:\Windows\Sysnative\TsUsbRedirectionGroupPolicyControl.exe 2015-09-19 06:15:40 8E75B1112C374EBDF18FD640DA2F0655 1147392 ----a-w- C:\Windows\Sysnative\mstsc.exe 2015-09-19 06:15:40 149A388C17F04AD1F99B477A43BE1A9F 56832 ----a-w- C:\Windows\Sysnative\MsRdpWebAccess.dll 2015-09-19 06:14:21 D346E07D62E3D4BEAB040939744EC31B 228864 ----a-w- C:\Windows\Sysnative\rdpendp_winip.dll 2015-09-19 06:12:08 E8E54B8E62A30AC7FDCEE2AD348FEAD2 64000 ----a-w- C:\Windows\Sysnative\auditpol.exe 2015-09-19 06:12:08 E537A63257864B3DEDAFEA92FBE1625B 22016 ----a-w- C:\Windows\Sysnative\credssp.dll 2015-09-19 06:12:08 E3B7582BF4DD671D114043D69F8336A9 309760 ----a-w- C:\Windows\Sysnative\ncrypt.dll 2015-09-19 06:12:08 BC964CF12BFD6F6B8F7DCAB432554210 729088 ----a-w- C:\Windows\Sysnative\kerberos.dll 2015-09-19 06:12:08 B4F260193AE55D1A0374E7DED43E4D35 1216512 ----a-w- C:\Windows\Sysnative\rpcrt4.dll 2015-09-19 06:12:08 AD0C2F9769CA412401C2AEDADB2E6335 1461760 ----a-w- C:\Windows\Sysnative\lsasrv.dll 2015-09-19 06:12:08 A23363F7B8FA96C16A31CE98CE309938 210944 ----a-w- C:\Windows\Sysnative\wdigest.dll 2015-09-19 06:12:08 7531A905D6B6D1142A6C4021F2C747F5 136192 ----a-w- C:\Windows\Sysnative\sspicli.dll 2015-09-19 06:12:08 69505EB2EBA5015C293A52FFC86CAC5D 686080 ----a-w- C:\Windows\Sysnative\adtschema.dll 2015-09-19 06:12:08 641B00D68ADC4F220FE6D8E00337AE02 342016 ----a-w- C:\Windows\Sysnative\schannel.dll 2015-09-19 06:12:08 5623E3D330D3F429AD576D8E7D393BD0 28160 ----a-w- C:\Windows\Sysnative\secur32.dll 2015-09-19 06:12:08 3E9BDCA3994E2B6B6AC16BAA76722934 31232 ----a-w- C:\Windows\Sysnative\lsass.exe 2015-09-19 06:12:08 2D9B515D321B5ED17B02F2BD3DC768CD 29184 ----a-w- C:\Windows\Sysnative\sspisrv.dll 2015-09-19 06:12:08 2CE2E6C71FD01B1DF8992EE5768A8CAD 22528 ----a-w- C:\Windows\Sysnative\icaapi.dll 2015-09-19 06:12:08 22F7CB0A82F50F20BCD44DCC414E7CF4 86528 ----a-w- C:\Windows\Sysnative\TSpkg.dll 2015-09-19 06:12:08 21BE8E5D81D4F330771E491AF50F91A9 44032 ----a-w- C:\Windows\Sysnative\cryptbase.dll 2015-09-19 06:12:08 0617F25844F5F1BBB6830FBA511CFA1B 315392 ----a-w- C:\Windows\Sysnative\msv1_0.dll 2015-09-19 06:12:07 17B56F4EF54ECDBC769C4EBEFB75C0BC 146432 ----a-w- C:\Windows\Sysnative\msaudite.dll 2015-09-19 06:12:07 08254FE5E8D4B4AD05B649D521FC8958 60416 ----a-w- C:\Windows\Sysnative\msobjs.dll 2015-09-19 06:09:21 F97E7878A2B372291B1269D80327BBF6 12640 ----a-w- C:\Windows\Sysnative\api-ms-win-crt-heap-l1-1-0.dll 2015-09-19 06:09:21 ED14B64C94F543974B7FDC592FA0594B 12640 ----a-w- C:\Windows\Sysnative\api-ms-win-crt-conio-l1-1-0.dll 2015-09-19 06:09:21 ECCF5973B80D771A79643732017CEA9A 17760 ----a-w- C:\Windows\Sysnative\api-ms-win-crt-string-l1-1-0.dll 2015-09-19 06:09:21 E9F6D776545843A9817D8ACF38D06D09 19808 ----a-w- C:\Windows\Sysnative\api-ms-win-crt-multibyte-l1-1-0.dll 2015-09-19 06:09:21 CC337898E64D9078CB697AC19F995C7F 12128 ----a-w- C:\Windows\Sysnative\api-ms-win-crt-utility-l1-1-0.dll 2015-09-19 06:09:21 BBAE7B5436D6D1B0FC967FF67E35415F 16224 ----a-w- C:\Windows\Sysnative\api-ms-win-crt-runtime-l1-1-0.dll 2015-09-19 06:09:21 AF851DFD0D9FECB76FF2B403F3C30F5B 12128 ----a-w- C:\Windows\Sysnative\api-ms-win-crt-environment-l1-1-0.dll 2015-09-19 06:09:21 761DDD8669A661D57D9CF9C335949C06 12128 ----a-w- C:\Windows\Sysnative\api-ms-win-crt-locale-l1-1-0.dll 2015-09-19 06:09:21 6631C212F79350458589A5281374B38B 12640 ----a-w- C:\Windows\Sysnative\api-ms-win-crt-process-l1-1-0.dll 2015-09-19 06:09:21 653CB5DF3CEC6A4A0E402B33D8AA5C08 63840 ----a-w- C:\Windows\Sysnative\api-ms-win-crt-private-l1-1-0.dll 2015-09-19 06:09:21 56556659C691DD043DBE24B0A195D64C 20832 ----a-w- C:\Windows\Sysnative\api-ms-win-crt-math-l1-1-0.dll 2015-09-19 06:09:21 53E9526AF1FDCE39F799BFE9217397A8 17760 ----a-w- C:\Windows\Sysnative\api-ms-win-crt-stdio-l1-1-0.dll 2015-09-19 06:09:21 32B2264317EA6200DA5DEEEC7DCB0EEB 11616 ----a-w- C:\Windows\Sysnative\api-ms-win-eventing-provider-l1-1-0.dll 2015-09-19 06:09:21 2381E189321EAD521FF71E72D08A6B17 984448 ----a-w- C:\Windows\Sysnative\ucrtbase.dll 2015-09-19 06:09:21 1908861649E67CDC20C563C234A89914 15712 ----a-w- C:\Windows\Sysnative\api-ms-win-crt-convert-l1-1-0.dll 2015-09-19 06:09:21 0F143310FADE4DE116070A3917A79C18 13664 ----a-w- C:\Windows\Sysnative\api-ms-win-crt-filesystem-l1-1-0.dll 2015-09-19 06:09:21 090DD0BB2BDDEE3EAAE5B6FF15FAE209 14176 ----a-w- C:\Windows\Sysnative\api-ms-win-crt-time-l1-1-0.dll ====== C:\Windows\Sysnative\drivers ===== 2015-09-19 06:15:41 E9981ECE8D894CEF7038FD1D040EB426 56832 ----a-w- C:\Windows\Sysnative\drivers\TsUsbFlt.sys 2015-09-19 06:14:22 313F68E1A3E6345A4F47A36B07062F34 19456 ----a-w- C:\Windows\Sysnative\drivers\rdpvideominiport.sys 2015-09-19 06:12:08 DB8E6BA1D110A4E40D48612E9009E366 159232 ----a-w- C:\Windows\Sysnative\drivers\mrxsmb.sys 2015-09-19 06:12:08 5E7E31C6426F000AF29E7C452826AF5E 129024 ----a-w- C:\Windows\Sysnative\drivers\mrxsmb20.sys 2015-09-19 06:12:08 2737840E7F6F6FF439966A67A35D59F8 157016 ----a-w- C:\Windows\Sysnative\drivers\ksecpkg.sys 2015-09-19 06:12:08 24432705B02BC1EFC42A83F93BA202A3 290816 ----a-w- C:\Windows\Sysnative\drivers\mrxsmb10.sys 2015-09-19 06:12:08 1DAC21EC0705A6AFEFACCE265798F0F9 97112 ----a-w- C:\Windows\Sysnative\drivers\ksecdd.sys 2015-09-19 06:12:08 19BEDA57F3E0A06B8D5EB6D619BD5624 39936 ----a-w- C:\Windows\Sysnative\drivers\tssecsrv.sys 2015-09-09 09:49:32 A0711D119BA4B48A1470C768D301013E 61440 ----a-w- C:\Windows\Sysnative\drivers\appid.sys ====== C:\Windows\Tasks ====== 2015-09-22 10:33:07 0E973A9C7B06353BE65EB172030D7754 3154 ----a-w- C:\Windows\Sysnative\Tasks\{CA8D1253-D567-4946-9729-7D6C96A0D808} ====== C:\Windows\Temp ====== ======= C:\Program Files ===== 2015-09-25 16:50:16 -------- d-----w- C:\Program Files\trend micro ======= C:\PROGRA~2 ===== 2015-09-22 10:35:49 -------- d-----w- C:\PROGRA~2\COMMON~1\Java 2015-09-18 12:22:48 -------- d-----w- C:\PROGRA~2\COMMON~1\Skype ======= C: ===== ====== C:\Users\Eigenaar\AppData\Roaming ====== 2015-09-17 17:16:09 -------- d-----w- C:\Users\Eigenaar\AppData\Local\CEF 2015-09-15 15:42:25 -------- d-----w- C:\Users\Mike\AppData\Roaming\Sun 2015-09-14 12:17:59 -------- d-----w- C:\Users\Eigenaar\AppData\Roaming\Sun 2015-09-14 12:17:19 -------- d-----w- C:\Users\Eigenaar\AppData\Locallow\Oracle ====== C:\Users\Eigenaar ====== 2015-09-22 10:35:30 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2015-09-22 10:29:11 6E6FAC98AF9E39E9131A236F8DAC8C75 584288 ----a-w- C:\Users\Eigenaar\Downloads\JavaSetup8u60.exe 2015-09-18 12:22:48 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype 2015-09-15 15:42:23 -------- d-----w- C:\Users\Mike\.oracle_jre_usage 2015-09-14 12:17:58 -------- d-----w- C:\Users\Eigenaar\.oracle_jre_usage ====== C: exe-files == 2015-09-25 16:50:16 9A2347903D6EDB84C10F288BC0578C1C 388608 ----a-w- C:\Program Files\trend micro\Eigenaar.exe 2015-09-23 12:13:48 F051A6D1D7D27C094928DB1157291E5A 2934864 ----a-w- C:\Program Files (x86)\Google\Update\Install\{177AB848-7E10-4C6A-951B-7325DE08BBBF}\45.0.2454.99_45.0.2454.93_chrome_updater.exe 2015-09-23 12:13:48 F051A6D1D7D27C094928DB1157291E5A 2934864 ----a-w- C:\Program Files (x86)\Google\Update\Download\{4DC8B4CA-1BDA-483E-B5FA-D3C12E15B62D}\45.0.2454.99\45.0.2454.99_45.0.2454.93_chrome_updater.exe 2015-09-22 10:35:31 BC949C957CEB9FAFDF0F3949CDDF1A72 0 ----a-we C:\ProgramData\Oracle\Java\javapath\java.exe 2015-09-22 10:35:31 7080B965215703EA1340C3C4903C7D73 0 ----a-we C:\ProgramData\Oracle\Java\javapath\javaws.exe 2015-09-22 10:35:31 5DC0128E8A2017E82289191820C736A5 0 ----a-we C:\ProgramData\Oracle\Java\javapath\javaw.exe 2015-09-22 10:35:27 E408E46C5DD2D03A7474AA12BAABEFEE 15968 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_60\bin\klist.exe 2015-09-22 10:35:27 D94C31E9C9C9A1273CC67DC6FFAF9984 15968 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_60\bin\policytool.exe 2015-09-22 10:35:27 BDFF5086FC1F20E631A070EEF43A7BEC 16480 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_60\bin\tnameserv.exe 2015-09-22 10:35:27 BC949C957CEB9FAFDF0F3949CDDF1A72 191584 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_60\bin\java.exe 2015-09-22 10:35:27 B9DE149653ED8B9C5C6CB68131AB66D2 15968 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_60\bin\jjs.exe 2015-09-22 10:35:27 B804A4E31F4BAD4D5BA05FE684756BA2 15968 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_60\bin\servertool.exe 2015-09-22 10:35:27 8C6BDB56CD4DEED1AF2790D37B54CFE9 68192 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_60\bin\javacpl.exe 2015-09-22 10:35:27 86CC77A8189758834CF83F7F2FEA5162 15968 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_60\bin\java-rmi.exe 2015-09-22 10:35:27 7A0DE452F677EF2971C7B75B0267B6ED 50784 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_60\bin\ssvagent.exe 2015-09-22 10:35:27 7080B965215703EA1340C3C4903C7D73 274016 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_60\bin\javaws.exe 2015-09-22 10:35:27 6A5A2FDB6D09E02A3283C55237DA10F6 159328 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_60\bin\unpack200.exe 2015-09-22 10:35:27 606A24A64E164B345A79F8F22A5DAC6F 15968 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_60\bin\pack200.exe 2015-09-22 10:35:27 5DC0128E8A2017E82289191820C736A5 191584 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_60\bin\javaw.exe 2015-09-22 10:35:27 5A503CFE5B553A9721A469FCC9CE8562 15968 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_60\bin\rmiregistry.exe 2015-09-22 10:35:27 3292748E640429C2682484BD23D43F6B 15968 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_60\bin\rmid.exe 2015-09-22 10:35:27 30387BE3E5D04FE969B731441C89D2D8 15968 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_60\bin\ktab.exe 2015-09-22 10:35:27 262BBCE84B9C8784CC5A5E1975898022 30304 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_60\bin\jabswitch.exe 2015-09-22 10:35:27 21B5D297A9191E4D833BB39456CEDAD0 15968 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_60\bin\kinit.exe 2015-09-22 10:35:27 0FCF9F3D9518B90FB58CC950FA33998C 76896 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_60\bin\jp2launcher.exe 2015-09-22 10:35:27 0F6E0DD1263ACB2A1AC559BB7742B54D 15968 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_60\bin\keytool.exe 2015-09-22 10:35:27 08427EADE480F21412696582170B1167 16480 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_60\bin\orbd.exe 2015-09-22 10:29:11 6E6FAC98AF9E39E9131A236F8DAC8C75 584288 ----a-w- C:\Users\Eigenaar\Downloads\JavaSetup8u60.exe 2015-09-22 07:23:46 2686F572B3CAF633C4A350A3671835F2 429568 ----a-w- C:\Windows\System32\wksprt.exe 2015-09-21 09:49:01 2A9C3ADBC3B9D061CACDEFFBED67683C 87040 ----a-w- C:\Windows\System32\TSWbPrxy.exe === C: other files == 2015-09-22 10:35:27 4E221C69F3B103481534D1B6CB6A90DD 14130 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_60\lib\deploy\ffjcext.zip ==== Startup Registry Enabled ====================== [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "GarminExpressTrayApp"="C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe" [HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run] "GarminExpressTrayApp"="C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "StartCCC"="C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe MSRun" "AVG_UI"="C:\Program Files (x86)\AVG\AVG2015\avgui.exe /TRAYONLY" "GrooveMonitor"="C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" "EEventManager"="C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe" "DivXMediaServer"="C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe" "DivXUpdate"="C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe /CHECKNOW" "SunJavaUpdateSched"="C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" "FUFAXRCV"=""C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXRCV.exe"" "FUFAXSTM"=""C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe"" ==== Startup Registry Enabled x64 ====================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RtHDVCpl"="C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s" "WrtMon.exe"="C:\Windows\system32\spool\drivers\x64\3\WrtMon.exe" ==== Startup Registry Disabled ====================== [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run-] "GarminExpressTrayApp"="\"C:\\Program Files (x86)\\Garmin\\Express Tray\\ExpressTray.exe\"" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run-] "Adobe ARM"="\"C:\\Program Files (x86)\\Common Files\\Adobe\\ARM\\1.0\\AdobeARM.exe\"" "SunJavaUpdateSched"="\"C:\\Program Files (x86)\\Common Files\\Java\\Java Update\\jusched.exe\"" ==== Startup Registry Disabled x64 ====================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Corel Photo Downloader] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="Corel Photo Downloader" "hkey"="HKCU" "command"="\"C:\\Program Files (x86)\\Common Files\\Corel\\Corel PhotoDownloader\\Corel Photo Downloader.exe\" -startup" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\DAEMON Tools Lite] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="DAEMON Tools Lite" "hkey"="HKCU" "command"="\"C:\\Program Files (x86)\\DAEMON Tools Lite\\DTLite.exe\" -autorun" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\GarminExpressTrayApp] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="GarminExpressTrayApp" "hkey"="HKCU" "command"="\"C:\\Program Files (x86)\\Garmin\\Express Tray\\ExpressTray.exe\"" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}" "hkey"="HKCU" "command"="\"C:\\Program Files (x86)\\Common Files\\Nero\\Lib\\NMIndexStoreSvr.exe\" ASO-616B5711-6DAE-4795-A05F-39A1E5104020" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\NBKeyScan] "key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="NBKeyScan" "hkey"="HKLM" "command"="\"C:\\Program Files (x86)\\Nero\\Nero8\\Nero BackItUp\\NBKeyScan.exe\"" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\NokiaMServer] "key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="NokiaMServer" "hkey"="HKLM" "command"="C:\\Program Files (x86)\\Common Files\\Nokia\\MPlatform\\NokiaMServer /watchfiles startup" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\NokiaOviSuite2] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="NokiaOviSuite2" "hkey"="HKCU" "command"="C:\\Program Files (x86)\\Nokia\\Nokia Ovi Suite\\NokiaOviSuite.exe -tray" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\QuickTime Task] "key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="QuickTime Task" "hkey"="HKLM" "command"="\"C:\\Program Files (x86)\\QuickTime\\QTTask.exe\" -atboottime" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\SunJavaUpdateSched] "key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="SunJavaUpdateSched" "hkey"="HKLM" "command"="\"C:\\Program Files (x86)\\Common Files\\Java\\Java Update\\jusched.exe\"" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Users^Eigenaar^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 3.2 .lnk] "path"="C:\\Users\\Eigenaar\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\OpenOffice.org 3.2 .lnk" "backup"="C:\\Windows\\pss\\OpenOffice.org 3.2 .lnk.Startup" "backupExtension"=".Startup" "command"="C:\\PROGRA~2\\OPENOF~1.ORG\\program\\QUICKS~1.EXE " "item"="OpenOffice.org 3.2 " [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\bthserv] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\Fax] ==== Startup Folders ====================== 2011-10-30 07:47:34 1239 ----a-w- C:\Users\Mike\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.2 .lnk ==== Task Scheduler Jobs ====================== C:\Windows\tasks\Adobe Flash Player Updater.job --a------ [Undetermined Task] C:\Windows\tasks\GoogleUpdateTaskMachineCore.job --a------ [Undetermined Task] C:\Windows\tasks\GoogleUpdateTaskMachineUA.job --a------ [Undetermined Task] ==== Other Scheduled Tasks ====================== "C:\Windows\SysNative\tasks\Adobe Acrobat Update Task" [C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe] "C:\Windows\SysNative\tasks\Adobe Flash Player Updater" [C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe] "C:\Windows\SysNative\tasks\Adobe Reader and Acrobat Manager" [C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe] "C:\Windows\SysNative\tasks\CCleanerSkipUAC" ["C:\Program Files\CCleaner\CCleaner.exe"] "C:\Windows\SysNative\tasks\CreateChoiceProcessTask" [C:\Windows\System32\browserchoice.exe] "C:\Windows\SysNative\tasks\GarminUpdaterTask" [C:\Program Files (x86)\Garmin\Express SelfUpdater\ExpressSelfUpdater.exe] "C:\Windows\SysNative\tasks\GoogleUpdateTaskMachineCore" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe] "C:\Windows\SysNative\tasks\GoogleUpdateTaskMachineUA" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe] "C:\Windows\SysNative\tasks\Java(TM) Platform SE Auto Updater" [C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe] "C:\Windows\SysNative\tasks\Patch My PC" [C:\Users\Eigenaar\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SKODKKZH\patchmypc.exe] "C:\Windows\SysNative\tasks\SidebarExecute" [C:\Program Files\Windows Sidebar\sidebar.exe] "C:\Windows\SysNative\tasks\User_Feed_Synchronization-{33F2B61C-D031-4AA3-9A6A-42CE4B690F46}" [C:\Windows\system32\msfeedssync.exe] "C:\Windows\SysNative\tasks\User_Feed_Synchronization-{E7548407-2244-4F10-A20F-17224E01D31D}" [C:\Windows\system32\msfeedssync.exe] "C:\Windows\SysNative\tasks\{27E9C185-AD6F-4667-B47F-8830584BE920}" [C:\Program Files (x86)\RapidSolution\Audials 8\AudialsStarter.exe] "C:\Windows\SysNative\tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask" [%systemroot%\system32\sc.exe start osppsvc] ==== Folders in C:\PROGRA~3 0-6 Months Old ====================== 2015-04-17 18:21:03 -------- d-----w- C:\PROGRA~3\Samsung ==== Firefox Extensions Registry ====================== [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions] "belgiumeid@eid.belgium.be"="C:\Program Files\Mozilla Firefox\extensions\belgiumeid@eid.belgium.be" [] [HKEY_CURRENT_USER\Software\Mozilla\Firefox\Extensions] "{B64D9B05-48E1-4CEB-BF58-E0643994E900}"="C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff" [30/11/2014 14:56] ==== Chromium Look ====================== Google Chrome Version: 45.0.2454.99 HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions lifbcibllhkdhoafpjfnlhfpfgnpldfl - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx[01/05/2015 11:17] Google Docs - Eigenaar\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake Google Drive - Eigenaar\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf YouTube - Eigenaar\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo Google Search - Eigenaar\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf Google Wallet - Eigenaar\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda Gmail - Eigenaar\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia Google Slides - Mike\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek Google Docs - Mike\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake Google Drive - Mike\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf YouTube - Mike\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo Google Search - Mike\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf Google Sheets - Mike\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap Google Docs Offline - Mike\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi Skype Click to Call - Mike\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl Chrome Web Store Payments - Mike\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda Gmail - Mike\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia ==== Set IE to Default ====================== Old Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="https://www.google.be/webhp?tab=ww" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AboutURLs] "Tabs"="res://ieframe.dll/tabswelcome.htm" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\AboutURLs] "Tabs"="res://ieframe.dll/tabswelcome.htm" New Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="https://www.google.be/webhp?tab=ww" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AboutURLs] "Tabs"="about:newtab" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\AboutURLs] "Tabs"="about:newtab" ==== All HKCU SearchScopes ====================== HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes "DefaultScope"="{7CC325CE-44B5-4AFD-B40E-19B02BB0A973}" {012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}" {0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC" {6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="https://www.google.com/search?q={searchTerms}" {7CC325CE-44B5-4AFD-B40E-19B02BB0A973} Google Url="http://www.google.be/search?hl=nl&q={searchTerms}&sourceid=ie8&rls=com.microsoft:{language}:{referrer:source}&ie={inputEncoding?}&oe={outputEncoding?}&rlz=1I7MXGB_nlBE613" ==== Deleting CLSID Registry Keys ====================== ==== Deleting CLSID Registry Values ====================== ==== Deleting Registry Keys ====================== HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\AB1DAB1E8E0C810429187E2D6C0B4747 deleted successfully HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\AVG Web TuneUp deleted successfully HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\UnityWebPlayer deleted successfully HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{E1BAD1BA-C0E8-4018-9281-E7D2C6B07474} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\AB1DAB1E8E0C810429187E2D6C0B4747 deleted successfully HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite deleted successfully HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaOviSuite2 deleted successfully ==== Empty IE Cache ====================== C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Eigenaar\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully C:\Users\Mike\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Mike\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Eigenaar\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0IMHH2X3 will be deleted at reboot C:\Users\Eigenaar\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GTDRGN7X will be deleted at reboot C:\Users\Eigenaar\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SKODKKZH will be deleted at reboot C:\Users\Eigenaar\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UEF4YR0P will be deleted at reboot ==== Empty FireFox Cache ====================== No FireFox Profiles found ==== Empty Chrome Cache ====================== C:\Users\Eigenaar\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully C:\Users\Mike\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully ==== Empty All Flash Cache ====================== Flash Cache Emptied Successfully ==== Empty All Java Cache ====================== Java Cache cleared successfully ==== C:\zoek_backup content ====================== C:\zoek_backup (files=979 folders=185 714075586 bytes) ==== Empty Temp Folders ====================== C:\Users\Default\AppData\Local\Temp emptied successfully C:\Users\Default User\AppData\Local\Temp emptied successfully C:\Users\Eigenaar\AppData\Local\Temp will be emptied at reboot C:\Users\Mike\AppData\Local\Temp emptied successfully C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp will be emptied at reboot C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully C:\Windows\Temp will be emptied at reboot ==== After Reboot ====================== ==== Empty Temp Folders ====================== C:\Windows\Temp successfully emptied C:\Users\Eigenaar\AppData\Local\Temp successfully emptied ==== Empty Recycle Bin ====================== C:\$RECYCLE.BIN successfully emptied ==== Deleting Files / Folders ====================== "C:\Users\Eigenaar\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0IMHH2X3" not found "C:\Users\Eigenaar\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GTDRGN7X" not found "C:\Users\Eigenaar\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SKODKKZH" not found "C:\Users\Eigenaar\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UEF4YR0P" not found "C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp\Low" not deleted ==== EOF on za 26/09/2015 at 10:21:49,16 ======================