Zoek.exe v5.0.0.1 Updated 31-December-2015 Tool run by Jan-Paul Roussel on ma 02-05-2016 at 13:46:59,56. Microsoft Windows 10 Home 10.0.10586 x64 Running in: Normal Mode Internet Access Detected Launched: C:\Users\Jan-Paul Roussel\Downloads\zoek.exe [Scan all users] [Script inserted] ==== System Restore Info ====================== 2-5-2016 13:48:04 Zoek.exe System Restore Point Created Successfully. ==== Empty Folders Check ====================== C:\PROGRA~2\Wondershare deleted successfully C:\PROGRA~3\Comms deleted successfully C:\PROGRA~3\SoftwareDistribution deleted successfully C:\Users\DefaultAppPool\AppData\LocalLow deleted successfully C:\Users\Jan-Paul Roussel\AppData\Local\ActiveSync deleted successfully C:\Users\Jan-Paul Roussel\AppData\Local\Adobe deleted successfully C:\Users\Jan-Paul Roussel\AppData\Local\calibre-cache deleted successfully C:\Users\Jan-Paul Roussel\AppData\Local\EmieBrowserModeList deleted successfully C:\Users\Jan-Paul Roussel\AppData\Local\EmieSiteList deleted successfully C:\Users\Jan-Paul Roussel\AppData\Local\EmieUserList deleted successfully ==== Deleting CLSID Registry Keys ====================== ==== Deleting CLSID Registry Values ====================== ==== Installed Programs ====================== 7-Zip 9.20 ActKey AMD Catalyst Control Center AMD Fuel ASUS VGA Driver ATI AVIVO64 Codecs ATI Catalyst Install Manager calibre Catalyst Control Center - Branding Catalyst Control Center Core Implementation Catalyst Control Center Graphics Full Existing Catalyst Control Center Graphics Full New Catalyst Control Center Graphics Light Catalyst Control Center Graphics Previews Vista Catalyst Control Center InstallProxy Catalyst Control Center Localization All ccc-core-static ccc-utility64 CCC Help Chinese Standard CCC Help Chinese Traditional CCC Help Czech CCC Help Danish CCC Help Dutch CCC Help English CCC Help Finnish CCC Help French CCC Help German CCC Help Greek CCC Help Hungarian CCC Help Italian CCC Help Japanese CCC Help Korean CCC Help Norwegian CCC Help Polish CCC Help Portuguese CCC Help Russian CCC Help Spanish CCC Help Swedish CCC Help Thai CCC Help Turkish CrystalDiskInfo 6.3.2 D3DX10 DVDFab Media Player 2 Easy PC Optimizer Emsisoft Anti-Malware Etron USB3.0 Host Controller Google Earth Google Update Helper IBM SPSS Statistics 19 Junk Mail filter update Microsoft .NET Framework 4.5.2 Microsoft .NET Framework 4.5.2 (NLD) Microsoft Application Error Reporting Microsoft DVD App Installation for Microsoft.WindowsDVDPlayer_2019.6.13291.0_neutral_~_8wekyb3d8bbwe (x64) Microsoft Silverlight Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2005 Redistributable (x64) Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.50727 Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.61030 Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.50727 Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.61030 Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.50727 Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61030 Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.50727 Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61030 MKV Player 2.1.21 MKVCleaver x64 MKVToolNix 8.4.0 (64bit) MSVCRT MSVCRT_amd64 MSVCRT110 MSVCRT110_amd64 NEC Electronics USB 3.0 Host Controller Driver Nero Micro v10.5.10500 OKI ActKey OKI Color Swatch Utility OKI MC5(3)x2/ES5(3)4x2 Scanner OpenOffice 4.1.1 Photo Common Realtek High Definition Audio Driver ScannerDriver SDFormatter Sean O'Connor's Windows Games version August 2011 SpeedFan (remove only) SumatraPDF Verzoek of wijziging voorlopige aanslag 2015 VidCoder 1.5.31 (x64) Vuze WBFS Manager 3.0 WBFS to ISO Windows Live Communications Platform Windows Live Essentials Windows Live ID Sign-in Assistant Windows Live Installer Windows Live Mail Windows Live MIME IFilter Windows Live Photo Common Windows Live PIMT Platform Windows Live SOXE Windows Live SOXE Definitions Windows Live UX Platform Windows Live UX Platform Language Pack Windows Live Writer Windows Live Writer Resources WordStorm Lite version 1.0 ==== Running Processes ====================== C:\Program Files (x86)\Google\Update\1.3.29.5\GoogleCrashHandler.exe C:\Program Files (x86)\Okidata\ActKey\Network Configuration.exe C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeHost.exe C:\Users\Jan-Paul Roussel\Downloads\zoek.exe C:\WINDOWS\SysWOW64\cmd.exe C:\WINDOWS\SysWOW64\cmd.exe C:\WINDOWS\SysWOW64\cmd.exe ==== Deleting Services ====================== ==== Deleting Files \ Folders ====================== C:\PROGRA~2\Wondershare not found C:\Users\Jan-Paul Roussel\AppData\Local\Wondershare deleted C:\Users\Jan-Paul Roussel\AppData\Roaming\calibre deleted C:\PROGRA~2\Bubble Shooter Premium Edition deleted C:\PROGRA~2\COMMON~1\Wondershare deleted C:\ul_format.exe deleted C:\PROGRA~3\Wondershare Video Converter Ultimate deleted C:\PROGRA~3\Package Cache deleted C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Search.lnk deleted C:\Users\Jan-Paul Roussel\ul_format.exe deleted ==== System Specs ====================== Windows: Windows Version 6.2 (Build 9200) Memory (RAM): 4096 MB CPU Info: AMD Athlon(tm) II X4 640 Processor CPU Speed: 3096,9 MHz Sound Card: Luidsprekers (Realtek High Defi | AMD HDMI Output (AMD High Defin | Realtek Digital Output (Realtek | Display Adapters: AMD Radeon HD 5700 Series | AMD Radeon HD 5700 Series Monitors: 1x; Generic PnP Monitor | Screen Resolution: 1920 X 1080 - 32 bit Network: Network Present Network Adapters: Realtek PCIe GBE Family Controller CD / DVD Drives: 1x (D: | ) D: TSSTcorpCDDVDW SH-S223C Ports: COM1 LPT Port NOT Present. Mouse: 3 Button Wheel Mouse Present Hard Disks: C: 118,8GB | E: 931,5GB Hard Disks - Free: C: 91,6GB | E: 423,4GB Manufacturer *: American Megatrends Inc. BIOS Info: AT/AT COMPATIBLE | 08/16/32 | 091410 - 20100914 Time Zone: West-Europa (standaardtijd) Motherboard *: ASRock 870 Extreme3 Country: Nederland Language: NLD ==== System Specs (Software) ====================== Internet Explorer Version: 11.212.10586.0 ==== Files Recently Created / Modified ====================== ====== C:\WINDOWS ==== 2016-04-27 07:44:24 1936F2FA9DF0568CBD69C0BFFB265EAB 432133567 ----a-w- C:\WINDOWS\MEMORY.DMP ====== C:\Users\JAN-PA~1\AppData\Local\Temp ==== ====== Java Cache ===== ====== C:\WINDOWS\SysWOW64 ===== ====== C:\WINDOWS\SysWOW64\drivers ===== ====== C:\WINDOWS\Sysnative ===== ====== C:\WINDOWS\Sysnative\drivers ===== 2016-04-13 07:26:31 19BD8A88AAC580592668B070AC0727D9 2152280 ----a-w- C:\WINDOWS\Sysnative\drivers\ntfs.sys 2016-04-13 07:26:05 3B866F8CB10719A5AF9E410B1B149714 605440 ----a-w- C:\WINDOWS\Sysnative\drivers\cng.sys 2016-04-13 07:25:54 63C3F74DC398A1C1A77E39DFB9C312CA 1089888 ----a-w- C:\WINDOWS\Sysnative\drivers\http.sys 2016-04-13 07:25:46 083A727D784009F9CCFB120C7841B7AF 2403680 ----a-w- C:\WINDOWS\Sysnative\drivers\tcpip.sys 2016-04-13 07:25:44 28B8E1C6CBCF9FFE2FABFF3160C26ADF 258912 ----a-w- C:\WINDOWS\Sysnative\drivers\ufx01000.sys 2016-04-13 07:25:43 9E9D58F5E1702955B2F4D62996F80E8E 378208 ----a-w- C:\WINDOWS\Sysnative\drivers\USBXHCI.SYS 2016-04-13 07:25:42 E582DA849A58524E645545FB68B6625D 1152864 ----a-w- C:\WINDOWS\Sysnative\drivers\ndis.sys 2016-04-13 07:25:40 DA0807D87A62D076C29C4E30F1E84F46 26112 ----a-w- C:\WINDOWS\Sysnative\drivers\xinputhid.sys 2016-04-13 07:25:40 935823F79CBEDB91637B63D37E3A5A36 148480 ----a-w- C:\WINDOWS\Sysnative\drivers\dfsc.sys 2016-04-13 07:25:36 B24408471C1BCB17FC44F5B47EA8DEA3 277856 ----a-w- C:\WINDOWS\Sysnative\drivers\sdbus.sys 2016-04-13 07:25:36 AA4CD20708B7E0412A5316D7E2875103 530432 ----a-w- C:\WINDOWS\Sysnative\drivers\nwifi.sys 2016-04-13 07:25:36 2BC2E99623119521EEF7910A11D0FDE0 694784 ----a-w- C:\WINDOWS\Sysnative\drivers\WdiWiFi.sys 2016-04-13 07:25:35 8359F776CA899E761852F2293B724EAE 185184 ----a-w- C:\WINDOWS\Sysnative\drivers\dumpsd.sys 2016-04-13 07:25:28 249A563C48DFD9E42A37587653E003BB 83968 ----a-w- C:\WINDOWS\Sysnative\drivers\serial.sys 2016-04-13 07:25:26 0731E8F4D8D3B8D3FD98A46A8ABFE0A0 333824 ----a-w- C:\WINDOWS\Sysnative\drivers\portcls.sys ====== C:\WINDOWS\Tasks ====== 2016-04-27 07:55:32 6BCDC2BA60D8B54949DE659BFB26D997 3446 ----a-w- C:\WINDOWS\Sysnative\Tasks\Easy PC Optimizer Scheduled Scan - Jan-Paul Roussel 2016-04-27 07:55:32 5E9F110D3885A1E88B43499A668F9829 438 ----a-w- C:\WINDOWS\Tasks\Easy PC Optimizer Scheduled Scan - Jan-Paul Roussel.job ====== C:\WINDOWS\Temp ====== ======= C:\Program Files ===== 2016-05-02 10:19:36 -------- d-----w- C:\Program Files\trend micro ======= C:\PROGRA~2 ===== 2016-04-27 07:55:18 -------- d---a-w- C:\PROGRA~2\Easy PC Optimizer ======= C: ===== ====== C:\Users\Jan-Paul Roussel\AppData\Roaming ====== ====== C:\Users\Jan-Paul Roussel ====== 2016-05-02 10:18:13 8045ABB21A3BDD66A48E1ED5C0F0EF6A 1222144 ----a-w- C:\Users\Jan-Paul Roussel\Downloads\RSITx64.exe 2016-04-27 07:55:19 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Easy PC Optimizer 2016-04-27 07:54:26 8F9EB301071630612F1EEBECDC52E901 4131608 ----a-w- C:\Users\Jan-Paul Roussel\Downloads\easypcoptimizersetup.exe 2016-04-07 18:25:01 6FC234AD3752E1267B34FB12BCD6718B 20 --sha-w- C:\Users\DefaultAppPool\ntuser.ini ====== C: exe-files == 2016-05-02 10:19:36 9A2347903D6EDB84C10F288BC0578C1C 388608 ----a-w- C:\Program Files\trend micro\Jan-Paul Roussel.exe 2016-05-02 10:18:13 8045ABB21A3BDD66A48E1ED5C0F0EF6A 1222144 ----a-w- C:\Users\Jan-Paul Roussel\Downloads\RSITx64.exe 2016-04-27 22:33:16 CED2D95CDFB95F534484BC8BC8193BF6 1186304 ----a-w- C:\Users\Jan-Paul Roussel\Documents\action replay\r4cce.exe 2016-04-27 18:23:27 B42CE3233DD339A9C21C73759A54AA53 1179648 ----a-w- C:\Users\Jan-Paul Roussel\Documents\nintendo wifi connector\NintendoWFCReg\SoftAP\NintendoWFCReg.exe 2016-04-27 18:23:27 6DD1CD2DF5933B3A492144A448981ACB 329568 ----a-w- C:\Users\Jan-Paul Roussel\Documents\nintendo wifi connector\NintendoWFCReg\SoftAP\SoftAPUninst.exe 2016-04-27 18:23:26 C781705E7D845DE11A1912ED9793FA95 208896 ----a-w- C:\Users\Jan-Paul Roussel\Documents\nintendo wifi connector\NintendoWFCReg\MDRIVER\mdriver.exe 2016-04-27 18:23:26 3DDA97FCA3BADEF0871E5499FC6C16BE 253952 ----a-w- C:\Users\Jan-Paul Roussel\Documents\nintendo wifi connector\NintendoWFCReg\SoftAP\DEVREMOVE.exe 2016-04-27 18:23:26 13BE9BD065E9B4F921978F00CC4881C7 391008 ----a-w- C:\Users\Jan-Paul Roussel\Documents\nintendo wifi connector\NintendoWFCReg\setup.exe 2016-04-27 17:56:17 1108B166160D6023AF76435B074052B6 455600 ----a-w- C:\Users\Jan-Paul Roussel\Downloads\RT2500USB_XP_v2.1.1.15_vista-7_v3.1.3_Incl_NintWiFiUSB\RT2500USB_XP_v2.1.1.15_vista-7_v3.1.3_Incl_NintWiFiUSB\setup.exe 2016-04-27 07:55:19 C7D075A1FD7529237D775B11F7749199 2767336 ----a-w- C:\Program Files (x86)\Easy PC Optimizer\EPIC.exe 2016-04-27 07:55:19 5433C4248193B28501C6E785CE0016AC 715752 ----a-w- C:\Program Files (x86)\Easy PC Optimizer\unins000.exe 2016-04-27 07:54:26 8F9EB301071630612F1EEBECDC52E901 4131608 ----a-w- C:\Users\Jan-Paul Roussel\Downloads\easypcoptimizersetup.exe 2016-04-26 09:14:30 4E95AB8BEB2C8FD53B348EF4AD5121C5 149184 ----a-w- C:\Users\Jan-Paul Roussel\AppData\Local\Temp\AEE8FF7C-5C7B-450D-AF8F-D35B087B9AEB\DismHost.exe === C: other files == 2016-04-27 22:28:31 061F9BEE4366C74F26CF820853B75E69 688677 ----a-w- C:\Users\Jan-Paul Roussel\Downloads\r4cce086.zip 2016-04-27 18:23:28 3FB98D6E8099431805373EFE31E6211A 163328 ----a-w- C:\Users\Jan-Paul Roussel\Documents\nintendo wifi connector\NintendoWFCReg\U2G54\WinVista\rt25usbap.sys 2016-04-27 18:23:28 3FB98D6E8099431805373EFE31E6211A 163328 ----a-w- C:\Users\Jan-Paul Roussel\Documents\nintendo wifi connector\NintendoWFCReg\U2G54\Win2000\rt25usbap.sys 2016-04-27 17:56:17 9DB6177BEFFD7D48A83ED2B40E96DA72 244096 ----a-w- C:\Users\Jan-Paul Roussel\Downloads\RT2500USB_XP_v2.1.1.15_vista-7_v3.1.3_Incl_NintWiFiUSB\RT2500USB_XP_v2.1.1.15_vista-7_v3.1.3_Incl_NintWiFiUSB\9x\rt25u98.sys 2016-04-27 17:56:17 5A54D765D6092B23D47AD9DBF7F6D7E4 306016 ----a-w- C:\Users\Jan-Paul Roussel\Downloads\RT2500USB_XP_v2.1.1.15_vista-7_v3.1.3_Incl_NintWiFiUSB\RT2500USB_XP_v2.1.1.15_vista-7_v3.1.3_Incl_NintWiFiUSB\w7\netr70.sys 2016-04-27 17:56:17 5A54D765D6092B23D47AD9DBF7F6D7E4 306016 ----a-w- C:\Users\Jan-Paul Roussel\Downloads\RT2500USB_XP_v2.1.1.15_vista-7_v3.1.3_Incl_NintWiFiUSB\RT2500USB_XP_v2.1.1.15_vista-7_v3.1.3_Incl_NintWiFiUSB\vista\netr70.sys 2016-04-27 17:56:17 3641E624C8C5D5EA089AE9B5340B5B79 388448 ----a-w- C:\Users\Jan-Paul Roussel\Downloads\RT2500USB_XP_v2.1.1.15_vista-7_v3.1.3_Incl_NintWiFiUSB\RT2500USB_XP_v2.1.1.15_vista-7_v3.1.3_Incl_NintWiFiUSB\w7\netr7064.sys 2016-04-27 17:56:17 3641E624C8C5D5EA089AE9B5340B5B79 388448 ----a-w- C:\Users\Jan-Paul Roussel\Downloads\RT2500USB_XP_v2.1.1.15_vista-7_v3.1.3_Incl_NintWiFiUSB\RT2500USB_XP_v2.1.1.15_vista-7_v3.1.3_Incl_NintWiFiUSB\vista\netr7064.sys 2016-04-27 17:56:17 34D321AFC3E9DF56E5A77B9F8B38C71F 245760 ----a-w- C:\Users\Jan-Paul Roussel\Downloads\RT2500USB_XP_v2.1.1.15_vista-7_v3.1.3_Incl_NintWiFiUSB\RT2500USB_XP_v2.1.1.15_vista-7_v3.1.3_Incl_NintWiFiUSB\xp64\rt2500usb.sys 2016-04-27 17:56:17 25FB8164D26474C3E13423FD6EE60B1B 241408 ----a-w- C:\Users\Jan-Paul Roussel\Downloads\RT2500USB_XP_v2.1.1.15_vista-7_v3.1.3_Incl_NintWiFiUSB\RT2500USB_XP_v2.1.1.15_vista-7_v3.1.3_Incl_NintWiFiUSB\2k-xp\rt2500usb.sys ==== Startup Registry Enabled ====================== [HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "OneDriveSetup"="C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup" [HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "OneDriveSetup"="C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup" [HKEY_USERS\S-1-5-21-4253024609-774802139-2139193332-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "OneDrive"="C:\Users\Jan-Paul Roussel\AppData\Local\Microsoft\OneDrive\OneDrive.exe /background" [HKEY_USERS\S-1-5-21-4253024609-774802139-2139193332-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] "Uninstall C:\Users\Jan-Paul Roussel\AppData\Local\Microsoft\OneDrive\17.3.6281.1202\amd64"="C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q C:\Users\Jan-Paul Roussel\AppData\Local\Microsoft\OneDrive\17.3.6281.1202\amd64" "Uninstall C:\Users\Jan-Paul Roussel\AppData\Local\Microsoft\OneDrive\17.3.6281.1202"="C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q C:\Users\Jan-Paul Roussel\AppData\Local\Microsoft\OneDrive\17.3.6281.1202" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "StartCCC"="C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe MSRun" "NUSB3MON"="C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" "emsisoft anti-malware"="c:\program files (x86)\emsisoft anti-malware\a2guard.exe /d=60" "Wondershare Helper Compact.exe"="C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe" "DelaypluginInstall"="C:\ProgramData\Wondershare\Video Converter Ultimate\DelayPluginI.exe" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "OneDrive"="C:\Users\Jan-Paul Roussel\AppData\Local\Microsoft\OneDrive\OneDrive.exe /background" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce] "Uninstall C:\Users\Jan-Paul Roussel\AppData\Local\Microsoft\OneDrive\17.3.6281.1202\amd64"="C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q C:\Users\Jan-Paul Roussel\AppData\Local\Microsoft\OneDrive\17.3.6281.1202\amd64" "Uninstall C:\Users\Jan-Paul Roussel\AppData\Local\Microsoft\OneDrive\17.3.6281.1202"="C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q C:\Users\Jan-Paul Roussel\AppData\Local\Microsoft\OneDrive\17.3.6281.1202" ==== Startup Registry Enabled x64 ====================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RtHDVCpl"="C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s" "Network Configuration"="C:\Program Files (x86)\Okidata\ActKey\Network Configuration.exe /RunWithOS" "emsisoft anti-malware"="c:\program files (x86)\emsisoft anti-malware\a2guard.exe /d=60" ==== Task Scheduler Jobs ====================== C:\WINDOWS\tasks\Adobe Flash Player Updater.job --a-------- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [16-07-2015 02:55] C:\WINDOWS\tasks\Easy PC Optimizer Scheduled Scan - Jan-Paul Roussel.job --a-------- C:\Program Files (x86)\Easy PC Optimizer\EPIC.exe [18-04-2016 09:21] C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job --a-------- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [05-08-2015 20:47] C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job --a-------- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [05-08-2015 20:47] ==== Other Scheduled Tasks ====================== "C:\WINDOWS\SysNative\tasks\Adobe Flash Player Updater" [C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe] "C:\WINDOWS\SysNative\tasks\Easy PC Optimizer Scheduled Scan - Jan-Paul Roussel" [C:\Program Files (x86)\Easy PC Optimizer\EPIC.exe] "C:\WINDOWS\SysNative\tasks\GoogleUpdateTaskMachineCore" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe] "C:\WINDOWS\SysNative\tasks\GoogleUpdateTaskMachineUA" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe] "C:\WINDOWS\SysNative\tasks\User_Feed_Synchronization-{FEADD56C-C843-421E-A804-08F7DA4B96B6}" [C:\WINDOWS\system32\msfeedssync.exe] ==== Chromium Look ====================== ==== Set IE to Default ====================== Old Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://msn.com/" New Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://msn.com/" ==== All HKLM and HKCU SearchScopes ====================== HKLM\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" HKLM\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC HKLM\Wow6432Node\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" HKLM\Wow6432Node\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC HKCU\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" HKCU\SearchScopes\{012E1000-F331-11DB-8314-0800200C9A66} - http://www.google.com/search?q={searchTerms} HKCU\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02 HKCU\SearchScopes\{1119605A-974A-4C1E-9E1A-E1B0E353EBB2} - No_Url_Value ==== HijackThis Entries ====================== F2 - REG:system.ini: UserInit= O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun O4 - HKLM\..\Run: [NUSB3MON] "C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" O4 - HKLM\..\Run: [emsisoft anti-malware] "c:\program files (x86)\emsisoft anti-malware\a2guard.exe" /d=60 O4 - HKLM\..\Run: [Wondershare Helper Compact.exe] C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe O4 - HKLM\..\Run: [DelaypluginInstall] C:\ProgramData\Wondershare\Video Converter Ultimate\DelayPluginI.exe O4 - HKCU\..\Run: [OneDrive] "C:\Users\Jan-Paul Roussel\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background O4 - HKCU\..\RunOnce: [Uninstall C:\Users\Jan-Paul Roussel\AppData\Local\Microsoft\OneDrive\17.3.6281.1202\amd64] C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Jan-Paul Roussel\AppData\Local\Microsoft\OneDrive\17.3.6281.1202\amd64" O4 - HKCU\..\RunOnce: [Uninstall C:\Users\Jan-Paul Roussel\AppData\Local\Microsoft\OneDrive\17.3.6281.1202] C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Jan-Paul Roussel\AppData\Local\Microsoft\OneDrive\17.3.6281.1202" O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'NETWORK SERVICE') O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll O18 - Protocol: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll O23 - Service: Emsisoft Protection Service (a2AntiMalware) - Emsisoft Ltd - C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing) O23 - Service: AMD External Events Utility - Unknown owner - C:\WINDOWS\system32\atiesrxx.exe (file missing) O23 - Service: AMD FUEL Service - Advanced Micro Devices, Inc. - C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe O23 - Service: @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000 (diagnosticshub.standardcollector.service) - Unknown owner - C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe (file missing) O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing) O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing) O23 - Service: Google Update-service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe O23 - Service: Google Update-service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\WINDOWS\system32\IEEtwCollector.exe (file missing) O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing) O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing) O23 - Service: @mqutil.dll,-6102 (MSMQ) - Unknown owner - C:\WINDOWS\system32\mqsvc.exe (file missing) O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing) O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing) O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing) O23 - Service: @%SystemRoot%\system32\SensorDataService.exe,-101 (SensorDataService) - Unknown owner - C:\WINDOWS\System32\SensorDataService.exe (file missing) O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing) O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing) O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing) O23 - Service: @%SystemRoot%\system32\TieringEngineService.exe,-702 (TieringEngineService) - Unknown owner - C:\WINDOWS\system32\TieringEngineService.exe (file missing) O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing) O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing) O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing) O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing) O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing) O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing) O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing) O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing) O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing) ==== Empty IE Cache ====================== C:\WINDOWS\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Jan-Paul Roussel\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\Users\Jan-Paul Roussel\AppData\Local\Microsoft\Windows\INetCache\Low\Content.IE5 emptied successfully C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\Users\Jan-Paul Roussel\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully C:\Users\Jan-Paul Roussel\AppData\Local\Microsoft\Windows\INetCache\Low\IE emptied successfully C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully ==== Empty FireFox Cache ====================== No FireFox Profiles found ==== Empty Chrome Cache ====================== No Chrome User Data found ==== Empty All Flash Cache ====================== No Flash Cache Found ==== Empty All Java Cache ====================== No Java Cache Found ==== C:\zoek_backup content ====================== C:\zoek_backup (files=91 folders=65 85317413 bytes) ==== Empty Temp Folders ====================== C:\WINDOWS\Temp will be emptied at reboot ==== After Reboot ====================== ==== Empty Temp Folders ====================== C:\WINDOWS\Temp successfully emptied C:\Users\JAN-PA~1\AppData\Local\Temp successfully emptied ==== Empty Recycle Bin ====================== C:\$RECYCLE.BIN successfully emptied ==== EOF on ma 02-05-2016 at 14:15:23,10 ======================