Zoek.exe v5.0.0.1 Updated 31-December-2015 Tool run by Evert on do 12-05-2016 at 17:16:48,03. Microsoft Windows 10 Home 10.0.10586 x64 Running in: Normal Mode Internet Access Detected Launched: C:\Users\Evert\Desktop\zoek.exe [Scan all users] [Script inserted] [Checkboxes used] ==== Older Logs ====================== C:\zoek-results2016-05-10-153623.log 26931 bytes ==== Empty Folders Check ====================== C:\Users\Evert\AppData\Local\ActiveSync deleted successfully ==== Deleting CLSID Registry Keys ====================== ==== Deleting CLSID Registry Values ====================== ==== Deleting Services ====================== ==== Registry Fix Code x64 ====================== Windows Registry Editor Version 5.00 [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}] [HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run] ""=- ==== Deleting Files \ Folders ====================== C:\ProgramData\Avg_Update_0615tb not found C:\ProgramData\Avg_Update_1114avemptyfolderscheck not found C:\Program Files\KMSpico not found "C:\WINDOWS\tasks\0615tbUpdateInfo.job" not found "C:\WINDOWS\tasks\1114avUpdateInfo.job" not found "C:\Windows\Installer\3d9ec163.msi" not found ==== Files Recently Created / Modified ====================== ====== C:\WINDOWS ==== ====== C:\Users\Evert\AppData\Local\Temp ==== ====== Java Cache ===== ====== C:\WINDOWS\SysWOW64 ===== 2016-05-05 19:17:48 80FF3971C36D7BB2961C2EA1A1F59F6D 110528 ----a-w- C:\WINDOWS\SysWOW64\nvStreaming.exe 2016-05-05 19:17:42 7BBDCD84088D62A8F2FC5480060C649B 40216 ----a-w- C:\WINDOWS\SysWOW64\vulkaninfo.exe 2016-05-05 19:17:42 53E6114C45AC94307779A17DA9CB0007 130328 ----a-w- C:\WINDOWS\SysWOW64\vulkan-1.dll 2016-05-05 19:16:26 E3B618C98C037285474EC13982C573AB 632152 ----a-w- C:\WINDOWS\SysWOW64\nvEncMFTH264.dll 2016-05-05 19:16:26 D45FC752051F6FA04E760DDACE0770BC 379448 ----a-w- C:\WINDOWS\SysWOW64\NvIFROpenGL.dll 2016-05-05 19:16:26 CDCCD78A31942413A199858642C381A0 753208 ----a-w- C:\WINDOWS\SysWOW64\NvFBC.dll 2016-05-05 19:16:26 C0DBBDEB6B254928C6910CBEAED74F8B 348216 ----a-w- C:\WINDOWS\SysWOW64\nvDecMFTMjpeg.dll 2016-05-05 19:16:26 A898E865C3517B9F69E6450A7F450707 448824 ----a-w- C:\WINDOWS\SysWOW64\nvumdshim.dll 2016-05-05 19:16:26 9D3BB55FD93A4819A1D9DA2A66ECF2F6 2258368 ----a-w- C:\WINDOWS\SysWOW64\nvcuvid.dll 2016-05-05 19:16:26 922F4D0DD25C1BA27B5B2C3A4B23625F 129024 ----a-w- C:\WINDOWS\SysWOW64\nvoglshim32.dll 2016-05-05 19:16:26 75065BCE6839289DCD5E6B60B92F22FC 8659472 ----a-w- C:\WINDOWS\SysWOW64\nvptxJitCompiler.dll 2016-05-05 19:16:26 52BADC8300F7CCD983DC34C2C744ED69 25350712 ----a-w- C:\WINDOWS\SysWOW64\nvoglv32.dll 2016-05-05 19:16:26 4209F2CDC63B9A836909D611649C7EB6 317472 ----a-w- C:\WINDOWS\SysWOW64\nvEncodeAPI.dll 2016-05-05 19:16:26 363373D474AA3E8783F2656243A674F1 571912 ----a-w- C:\WINDOWS\SysWOW64\nvfatbinaryLoader.dll 2016-05-05 19:16:26 2700486839F549FF23FBC91797118D25 153392 ----a-w- C:\WINDOWS\SysWOW64\nvinit.dll 2016-05-05 19:16:26 22B6BA9F9EE27A416D9B2D62F1055A0D 694208 ----a-w- C:\WINDOWS\SysWOW64\NvIFR.dll 2016-05-05 19:16:26 1724F15E827B190C385038BD2263B614 17756440 ----a-w- C:\WINDOWS\SysWOW64\nvopencl.dll 2016-05-05 19:16:25 E3E265C1491955857AC9ECEFFC2E8793 17350288 ----a-w- C:\WINDOWS\SysWOW64\nvcuda.dll 2016-05-05 19:16:25 5B621FBA7F36E895CDB3DC87892D9A78 37567424 ----a-w- C:\WINDOWS\SysWOW64\nvcompiler.dll 2016-05-05 19:14:18 3CFC92C43EE7723A3CD0C84FDD2DCA2D 102976 ----a-w- C:\WINDOWS\SysWOW64\nvaudcap32v.dll ====== C:\WINDOWS\SysWOW64\drivers ===== ====== C:\WINDOWS\Sysnative ===== 2016-05-05 19:17:43 D229A1E1711898DA5436D05BA3DEBA17 130840 ----a-w- C:\WINDOWS\Sysnative\vulkan-1.dll 2016-05-05 19:17:43 3C8E05AAC52E1DD65861429A36F2E75C 45336 ----a-w- C:\WINDOWS\Sysnative\vulkaninfo.exe 2016-05-05 19:16:26 FF212A9C3B9C48D8B8FDEECF11E86661 379480 ----a-w- C:\WINDOWS\Sysnative\nvEncodeAPI64.dll 2016-05-05 19:16:26 F6865A8F09AD07CB37C26DB27CF44BF2 960056 ----a-w- C:\WINDOWS\Sysnative\NvFBC64.dll 2016-05-05 19:16:26 F56AA3500C18B3E4704F08666A86CFC1 17369768 ----a-w- C:\WINDOWS\Sysnative\nvd3dumx.dll 2016-05-05 19:16:26 E4211729549C06910967230617319F68 20906872 ----a-w- C:\WINDOWS\Sysnative\nvcuda.dll 2016-05-05 19:16:26 DFBDC9DFC6DF2159BFEACE4F1F7EFA82 1922496 ----a-w- C:\WINDOWS\Sysnative\nvdispco6436510.dll 2016-05-05 19:16:26 B3E795CF9ECBB93CC7E69ADDFA7BBBDA 385080 ----a-w- C:\WINDOWS\Sysnative\nvDecMFTMjpeg.dll 2016-05-05 19:16:26 93709BF4DB9970D56EB89BD2112CA399 175880 ----a-w- C:\WINDOWS\Sysnative\nvinitx.dll 2016-05-05 19:16:26 890D1AC7A4AEE74CB22DF7B760FAE518 887744 ----a-w- C:\WINDOWS\Sysnative\NvIFR64.dll 2016-05-05 19:16:26 72E72549771478AC79B1615919771EDD 786872 ----a-w- C:\WINDOWS\Sysnative\nvEncMFTH264.dll 2016-05-05 19:16:26 6FBC8B87091673C9482EDE6737B15C40 425016 ----a-w- C:\WINDOWS\Sysnative\NvIFROpenGL.dll 2016-05-05 19:16:26 6386A290E3A6D9625A1F30CCC6100D05 546328 ----a-w- C:\WINDOWS\Sysnative\nvumdshimx.dll 2016-05-05 19:16:26 54BCEC0147A89A3BFFE0D00C9F6FED0A 151368 ----a-w- C:\WINDOWS\Sysnative\nvoglshim64.dll 2016-05-05 19:16:26 402D92AD347DDA7D6C1C8AC6255FA226 10550736 ----a-w- C:\WINDOWS\Sysnative\nvptxJitCompiler.dll 2016-05-05 19:16:26 2CF8E23043A44BCC09C2091B9BFEDA1A 21365048 ----a-w- C:\WINDOWS\Sysnative\nvopencl.dll 2016-05-05 19:16:26 232A9EDF47BDCEEF0D91833655E5846F 678704 ----a-w- C:\WINDOWS\Sysnative\nvfatbinaryLoader.dll 2016-05-05 19:16:26 210030DF2D61602FFD284A33F77AFB78 1573432 ----a-w- C:\WINDOWS\Sysnative\nvdispgenco6436510.dll 2016-05-05 19:16:26 188D01B30D893BE78D3BD72E89C5CE31 2614208 ----a-w- C:\WINDOWS\Sysnative\nvcuvid.dll 2016-05-05 19:16:26 12E0E485FF23265B46DFB836DE50868D 31598136 ----a-w- C:\WINDOWS\Sysnative\nvoglv64.dll 2016-05-05 19:16:25 2906A7D98F6AF8BC7B97FC250E44AA70 42921920 ----a-w- C:\WINDOWS\Sysnative\nvcompiler.dll 2016-05-05 19:14:18 FDAEA352F1D8ED10AA1404B8AD9B6F50 113216 ----a-w- C:\WINDOWS\Sysnative\nvaudcap64v.dll ====== C:\WINDOWS\Sysnative\drivers ===== 2016-04-12 18:19:48 19BD8A88AAC580592668B070AC0727D9 2152280 ----a-w- C:\WINDOWS\Sysnative\drivers\ntfs.sys 2016-04-12 18:19:29 3B866F8CB10719A5AF9E410B1B149714 605440 ----a-w- C:\WINDOWS\Sysnative\drivers\cng.sys 2016-04-12 18:19:20 63C3F74DC398A1C1A77E39DFB9C312CA 1089888 ----a-w- C:\WINDOWS\Sysnative\drivers\http.sys 2016-04-12 18:19:14 083A727D784009F9CCFB120C7841B7AF 2403680 ----a-w- C:\WINDOWS\Sysnative\drivers\tcpip.sys 2016-04-12 18:19:12 28B8E1C6CBCF9FFE2FABFF3160C26ADF 258912 ----a-w- C:\WINDOWS\Sysnative\drivers\ufx01000.sys 2016-04-12 18:19:11 9E9D58F5E1702955B2F4D62996F80E8E 378208 ----a-w- C:\WINDOWS\Sysnative\drivers\USBXHCI.SYS 2016-04-12 18:19:10 E582DA849A58524E645545FB68B6625D 1152864 ----a-w- C:\WINDOWS\Sysnative\drivers\ndis.sys 2016-04-12 18:19:08 DA0807D87A62D076C29C4E30F1E84F46 26112 ----a-w- C:\WINDOWS\Sysnative\drivers\xinputhid.sys 2016-04-12 18:19:08 935823F79CBEDB91637B63D37E3A5A36 148480 ----a-w- C:\WINDOWS\Sysnative\drivers\dfsc.sys 2016-04-12 18:19:05 B24408471C1BCB17FC44F5B47EA8DEA3 277856 ----a-w- C:\WINDOWS\Sysnative\drivers\sdbus.sys 2016-04-12 18:19:05 AA4CD20708B7E0412A5316D7E2875103 530432 ----a-w- C:\WINDOWS\Sysnative\drivers\nwifi.sys 2016-04-12 18:19:05 2BC2E99623119521EEF7910A11D0FDE0 694784 ----a-w- C:\WINDOWS\Sysnative\drivers\WdiWiFi.sys 2016-04-12 18:19:04 8359F776CA899E761852F2293B724EAE 185184 ----a-w- C:\WINDOWS\Sysnative\drivers\dumpsd.sys 2016-04-12 18:18:59 249A563C48DFD9E42A37587653E003BB 83968 ----a-w- C:\WINDOWS\Sysnative\drivers\serial.sys 2016-04-12 18:18:58 0731E8F4D8D3B8D3FD98A46A8ABFE0A0 333824 ----a-w- C:\WINDOWS\Sysnative\drivers\portcls.sys ====== C:\WINDOWS\Tasks ====== ====== C:\WINDOWS\Temp ====== ======= C:\Program Files ===== 2016-05-09 16:51:15 -------- d-----w- C:\Program Files\trend micro ======= C:\PROGRA~2 ===== 2016-05-05 19:17:41 -------- d-----w- C:\PROGRA~2\VulkanRT ======= C: ===== ====== C:\Users\Evert\AppData\Roaming ====== ====== C:\Users\Evert ====== 2016-05-09 16:51:05 8045ABB21A3BDD66A48E1ED5C0F0EF6A 1222144 ----a-w- C:\Users\Evert\Downloads\RSITx64.exe 2016-05-08 20:51:22 F2F1C91711FE0E351FABB945205AB5A7 3615296 ----a-w- C:\Users\Evert\Downloads\adwcleaner_5.115.exe ====== C: exe-files == 2016-05-10 20:34:27 E8B364111F317A60DF073826E628FF6F 92824 ----atw- C:\Program Files (x86)\Google\Update\1.3.30.3\GoogleUpdateOnDemand.exe 2016-05-10 20:34:27 A425CDCEB9D26E9A5ABAFA259799D447 312472 ----atw- C:\Program Files (x86)\Google\Update\1.3.30.3\GoogleCrashHandler64.exe 2016-05-10 20:34:27 5AB2C2DBC3108A2F7275A2F232FA8036 987040 ----a-w- C:\Program Files (x86)\Google\Update\1.3.30.3\GoogleUpdateSetup.exe 2016-05-10 20:34:27 56FE3C885B0901601549E23E7A435984 250008 ----atw- C:\Program Files (x86)\Google\Update\1.3.30.3\GoogleCrashHandler.exe 2016-05-10 20:34:27 54D932590CEAB260ADC4FF79797B21D9 92824 ----atw- C:\Program Files (x86)\Google\Update\1.3.30.3\GoogleUpdateWebPlugin.exe 2016-05-10 20:34:27 50FCC5C822A6B4FC6F377EE9F9F37C7B 152216 ----atw- C:\Program Files (x86)\Google\Update\1.3.30.3\GoogleUpdate.exe 2016-05-10 20:34:27 13FF5C375BD0C702EA1252E79592692F 135832 ----atw- C:\Program Files (x86)\Google\Update\1.3.30.3\GoogleUpdateComRegisterShell64.exe 2016-05-10 20:34:27 108CB30A5B4C5247E414A3086458FCFC 92824 ----atw- C:\Program Files (x86)\Google\Update\1.3.30.3\GoogleUpdateBroker.exe 2016-05-10 20:34:26 5AB2C2DBC3108A2F7275A2F232FA8036 987040 ----a-w- C:\Program Files (x86)\Google\Update\Download\{430FD4D0-B729-4F61-AA34-91526481799D}\1.3.30.3\GoogleUpdateSetup.exe 2016-05-10 19:20:52 B44883D6D51C8161E99C08DDEB784545 161992 ----a-w- C:\Program Files\ESET\ESET NOD32 Antivirus\x86\CertImporter-1352.exe 2016-05-09 16:51:15 9A2347903D6EDB84C10F288BC0578C1C 388608 ----a-w- C:\Program Files\trend micro\Evert.exe 2016-05-09 16:51:05 8045ABB21A3BDD66A48E1ED5C0F0EF6A 1222144 ----a-w- C:\Users\Evert\Downloads\RSITx64.exe 2016-05-08 21:10:02 4E95AB8BEB2C8FD53B348EF4AD5121C5 149184 ----a-w- C:\Users\Evert\AppData\Local\Temp\D8E7AF68-58F3-4162-9426-6261F776DC5D\DismHost.exe 2016-05-08 20:51:22 F2F1C91711FE0E351FABB945205AB5A7 3615296 ----a-w- C:\Users\Evert\Downloads\adwcleaner_5.115.exe 2016-05-06 22:19:32 58327B7E7C4E325C66B7C4A5220CE5F4 242864 ----a-w- C:\Users\Evert\Downloads\Microsoft Office 2016 Professional Plus Updated 12-01-2016 by Den Spike Unattendeds _#169_ 2016\iV71Rq9y99TSr0P\Microsoft Office 2016 Professional Plus\AutoPlay\Docs\64bit\proplus.ww\ose.exe 2016-05-06 22:19:23 E133C2D85CFF4EDD7FE8E8F0F8BE6CDB 202928 ----a-w- C:\Users\Evert\Downloads\Microsoft Office 2016 Professional Plus Updated 12-01-2016 by Den Spike Unattendeds _#169_ 2016\iV71Rq9y99TSr0P\Microsoft Office 2016 Professional Plus\AutoPlay\Docs\32bit\proplus.ww\ose.exe 2016-05-06 22:19:22 92C34025207F2AA9FFD194F475103F68 262336 ----a-w- C:\Users\Evert\Downloads\Microsoft Office 2016 Professional Plus Updated 12-01-2016 by Den Spike Unattendeds _#169_ 2016\iV71Rq9y99TSr0P\Microsoft Office 2016 Professional Plus\AutoPlay\Docs\64bit\setup.exe 2016-05-06 22:19:22 6F581A41167D2D484FCBA20E6FC3C39A 236736 ----a-w- C:\Users\Evert\Downloads\Microsoft Office 2016 Professional Plus Updated 12-01-2016 by Den Spike Unattendeds _#169_ 2016\iV71Rq9y99TSr0P\Microsoft Office 2016 Professional Plus\AutoPlay\Docs\32bit\setup.exe 2016-05-06 22:19:20 871EC3010351C673A058F48603D9C0F3 6882304 ----a-w- C:\Users\Evert\Downloads\Microsoft Office 2016 Professional Plus Updated 12-01-2016 by Den Spike Unattendeds _#169_ 2016\iV71Rq9y99TSr0P\Microsoft Office 2016 Professional Plus\autorun.exe 2016-05-06 19:16:55 664C017173451A4E6BCEDD1868777AA9 632048 ----a-w- C:\Users\Evert\AppData\Local\NVIDIA\NvBackend\Packages\00008a8b\CoProc update.20729581.exe 2016-05-05 19:17:48 D87CEF41AE6070C4DB3B075E54E25C14 604608 ----a-w- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvstlink.exe 2016-05-05 19:17:48 D5AB520CA41AB8C1024B4973B652CC72 903104 ----a-w- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\NvStereoUtilityOGL.exe 2016-05-05 19:17:48 9441CB3073B0DCCAC8CEB608A60FDCBB 2420672 ----a-w- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvsttest.exe 2016-05-05 19:17:48 80FF3971C36D7BB2961C2EA1A1F59F6D 110528 ----a-w- C:\Windows\SysWOW64\nvStreaming.exe 2016-05-05 19:17:48 70180DC70B92C09724D095AE92E7EC8B 444352 ----a-w- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvstreg.exe 2016-05-05 19:17:48 6CD44328B36BE7BF82080AF5BBE129A5 324032 ----a-w- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvStInst.exe 2016-05-05 19:17:48 64F544F50A13A644D0E97AA06EA29D02 7853504 ----a-w- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\NVStWiz.exe 2016-05-05 19:17:48 0B6F82B5A3E51EF4FCB9590BDF476772 1709504 ----a-w- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvstview.exe 2016-05-05 19:17:47 0596DAFFF8A6709917E4BB80CD3A896B 424384 ----a-w- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe 2016-05-05 19:17:43 3C8E05AAC52E1DD65861429A36F2E75C 45336 ----a-w- C:\Windows\System32\vulkaninfo.exe 2016-05-05 19:17:42 7BBDCD84088D62A8F2FC5480060C649B 40216 ----a-w- C:\Windows\SysWOW64\vulkaninfo.exe 2016-05-05 19:16:27 AB476C89B36AE8CC615CBEF6EBA910AC 17143416 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\Display.3DVision.{54F7B966-8E28-4B8F-A33F-7CA1D8EFC7C3}\3DVision.exe 2016-05-05 19:16:26 712EB8847BE0EA7BCBAEAB32B273A5BF 13602064 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\Display.Driver.{A68E8849-7339-403E-B64D-F82E6799C08B}\VulkanRT-Installer.exe 2016-05-05 19:16:25 C6D10FC212F993EFF2E90EC370796330 458296 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\Display.Driver.{A68E8849-7339-403E-B64D-F82E6799C08B}\dbInstaller.exe 2016-05-05 19:16:25 C6D10FC212F993EFF2E90EC370796330 458296 ----a-w- C:\Program Files\NVIDIA Corporation\Drs\dbInstaller.exe 2016-05-05 19:16:25 A0B2FB5B980F53C4CA742041A57F47BD 97006360 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\Display.Driver.{A68E8849-7339-403E-B64D-F82E6799C08B}\NvCplSetupInt.exe 2016-05-05 19:16:06 85B5145B11316802CAFB124C0E2BAF2A 1881144 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\installer.{447AA8E4-5F68-4184-81D6-7745E5FEA070}\NVNetworkService.exe 2016-05-05 19:14:58 9A93245178D9DF8D386CDC4AB723E8DE 7874704 ----a-w- C:\Users\Evert\AppData\Local\NVIDIA\NvBackend\Packages\00008a80\DAO.20726304.exe 2016-05-05 19:14:15 5C985041974069E43952EAEAAE915270 422456 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\CoreTemp.{5887EF5B-754B-4C94-B3C2-547790F8900C}\setup.exe 2016-05-05 19:14:14 B6A2F63C7488E3D974D3F08CB1BD82B9 1881144 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\installer.{B238643B-28D0-45B9-BFD6-2B119C62E868}\NVNetworkService.exe 2016-05-05 16:54:48 E85C4B4B84B9DB390BB6C5626A79DF58 779704 ----a-w- C:\Users\Evert\AppData\Local\NVIDIA\NvBackend\ApplicationOntology\NvOAWrapperCache.exe 2016-05-05 16:54:46 78D3F1ADDEBCA45AEA42ECC11F2248AE 322488 ----a-w- C:\Users\Evert\AppData\Local\NVIDIA\NvBackend\ApplicationOntology\OAWrapper.exe === C: other files == 2016-05-10 15:36:28 0B28E9A8A36FD0718C261E7D19256852 4870 ----a-w- C:\Users\Evert\AppData\Local\Temp\xpi\tmp.zip 2016-05-05 19:16:27 73071A75C08872226A070CC1D0FF5F60 467912 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\Display.NVIRUSB.{E77B6783-79FA-43A2-8630-6F4EA000985B}\nvstusb64.sys 2016-05-05 19:16:27 670DA633CB393CF5DBD5C7DC20ACC169 451400 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\Display.NVIRUSB.{E77B6783-79FA-43A2-8630-6F4EA000985B}\nvstusb32.sys 2016-05-05 19:16:26 D812362E8AF615B521AD4DF19A93BD5A 205456 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\HDAudio.Driver.{1D496A80-3FFC-4C71-99DE-8BAA745C3E49}\nvhda64v.sys 2016-05-05 19:16:26 40025FE1F8BF91EE3575D8469D0773F8 138040 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\HDAudio.Driver.{1D496A80-3FFC-4C71-99DE-8BAA745C3E49}\nvhda32.sys 2016-05-05 19:16:26 2E918562FE52470B166EC28081AE43CA 170128 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\HDAudio.Driver.{1D496A80-3FFC-4C71-99DE-8BAA745C3E49}\nvhda32v.sys 2016-05-05 19:16:26 0743DBA6ABF06CC61F784D40BEF84CE3 170312 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\HDAudio.Driver.{1D496A80-3FFC-4C71-99DE-8BAA745C3E49}\nvhda64.sys 2016-05-05 19:14:19 9D9CAD70EA640AB8D3EB77BFAE6CABE2 28344 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\ShieldWirelessController.{09D2C2E0-22DF-42F5-9468-8F3001B90D67}\NVSWCFilter64.sys 2016-05-05 19:14:19 7ABD081BB7A1A8CF7E3B1E64183AB812 24760 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\ShieldWirelessController.{09D2C2E0-22DF-42F5-9468-8F3001B90D67}\NVSWCFilter32.sys 2016-05-05 19:14:18 F37FE6B15A987AEEC08EEF531F2FAED7 56384 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\VirtualAudio.Driver.{AD8F0783-148B-4D79-8568-582ECED44A0F}\nvvad64v.sys 2016-05-05 19:14:18 174AAAEB00A5982DF968824ED92D5621 50744 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\VirtualAudio.Driver.{AD8F0783-148B-4D79-8568-582ECED44A0F}\nvvad32v.sys 2016-05-05 19:14:15 A612D80B9A76CE7FB5003E476DBB6FD1 24120 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\CoreTemp.{5887EF5B-754B-4C94-B3C2-547790F8900C}\NVI2SystemService64.sys 2016-05-05 19:14:15 565E544FCC040FB4D6134AF7913E1DBF 23096 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\CoreTemp.{5887EF5B-754B-4C94-B3C2-547790F8900C}\NVI2SystemService32.sys ==== Startup Registry Enabled ====================== [HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "OneDriveSetup"="C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup" [HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "OneDriveSetup"="C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup" [HKEY_USERS\S-1-5-21-400018146-936695679-1400834466-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "OneDrive"="C:\Users\Evert\AppData\Local\Microsoft\OneDrive\OneDrive.exe /background" [HKEY_USERS\S-1-5-21-400018146-936695679-1400834466-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] "Uninstall C:\Users\Evert\AppData\Local\Microsoft\OneDrive\17.3.6201.1019_1\amd64"="C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q C:\Users\Evert\AppData\Local\Microsoft\OneDrive\17.3.6201.1019_1\amd64" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Sound Blaster Cinema 2"="C:\Program Files (x86)\Creative\Sound Blaster Cinema 2\Sound Blaster Cinema 2\SBCinema2.exe /r" "Super Charger"="C:\Program Files (x86)\MSI\Super Charger\Super Charger.exe" "CTStartup"="C:\Program Files (x86)\Creative\Splash Screen\CTEaxSpl.EXE /run" "ConnectionCenter"="C:\Program Files (x86)\Citrix\ICA Client\concentr.exe /startup" "Redirector"="C:\Program Files (x86)\Citrix\ICA Client\redirector.exe /startup" "Acrobat Assistant 8.0"="C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Acrotray.exe" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "OneDrive"="C:\Users\Evert\AppData\Local\Microsoft\OneDrive\OneDrive.exe /background" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce] "Uninstall C:\Users\Evert\AppData\Local\Microsoft\OneDrive\17.3.6201.1019_1\amd64"="C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q C:\Users\Evert\AppData\Local\Microsoft\OneDrive\17.3.6201.1019_1\amd64" ==== Startup Registry Enabled x64 ====================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Logitech Download Assistant"="C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch" "RTHDVCPL"="C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe -s" "MBCfg64"="C:\Windows\system32\RunDLL32.exe C:\Windows\system32\MBCfg64.dll,RunDLLEntry MBCfg64" "NvBackend"="C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe" "ShadowPlay"="C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\nvspcap64.dll,ShadowPlayOnSystemStart" "egui"="C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe /hide /waitservice" "AdobeAAMUpdater-1.0"="C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" ==== Task Scheduler Jobs ====================== C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job --a-------- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [31-01-2016 19:57] C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job --a-------- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [31-01-2016 19:57] ==== Other Scheduled Tasks ====================== "C:\WINDOWS\SysNative\tasks\Adobe Acrobat Update Task" [C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe] "C:\WINDOWS\SysNative\tasks\CreateChoiceProcessTask" [C:\Windows\BrowserChoice\browserchoice.exe] "C:\WINDOWS\SysNative\tasks\GoogleUpdateTaskMachineCore" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe] "C:\WINDOWS\SysNative\tasks\GoogleUpdateTaskMachineUA" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe] "C:\WINDOWS\SysNative\tasks\User_Feed_Synchronization-{966125EE-FD8B-48C2-AEF5-1FC65068780A}" [C:\Windows\system32\msfeedssync.exe] ==== Firefox Extensions Registry ====================== [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions] "web2pdfextension.15@web2pdf.adobedotcom"="C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn" [23-02-2016 20:44]