Zoek.exe Version 4.0.0.2 Updated 03-June-2013 Tool run by Robin on do 13/06/2013 at 17:34:45,31. Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x64 Running in: Normal Mode Internet Access Detected ==== Files Recently Created / Modified ====================== ====== C:\windows ==== 2013-06-11 22:39:08 E185BDA84E5F03F4E1D8DCA30E209277 1912 ----a-w- C:\windows\epplauncher.mif ====== C:\Users\Robin\AppData\Local\Temp ==== ====== C:\windows\SysWOW64 ===== 2013-06-12 12:33:24 C5AAC3D1300AAF47726030D55FAB36A0 391168 ----a-w- C:\windows\SysWOW64\ieui.dll 2013-06-12 12:33:24 ADE7AE4478D5B2095FDE6FAB86B300E6 2706432 ----a-w- C:\windows\SysWOW64\mshtml.tlb 2013-06-12 12:33:22 DD09C65E52F3D5574F9774EE0D4DAA57 33280 ----a-w- C:\windows\SysWOW64\iernonce.dll 2013-06-12 12:33:22 A10E7B582DEA86572510CB73CCCECA34 61440 ----a-w- C:\windows\SysWOW64\iesetup.dll 2013-06-12 12:33:21 CE3EC9D85ED88ED4AD948B90BB9ED31D 71680 ----a-w- C:\windows\SysWOW64\RegisterIEPKEYs.exe 2013-06-12 12:33:21 9593EA1AE5F39C1174B532213D47664B 109056 ----a-w- C:\windows\SysWOW64\iesysprep.dll 2013-06-12 12:33:20 21B16760CB0D7D7A6DAC89285203DD8F 2046976 ----a-w- C:\windows\SysWOW64\iertutil.dll 2013-06-12 12:33:19 0FEED965B909BA2D210CE78C21626A69 493056 ----a-w- C:\windows\SysWOW64\msfeeds.dll 2013-06-12 12:33:18 091C7153A1292F19BE34FAC07FFF12EC 690688 ----a-w- C:\windows\SysWOW64\jscript.dll 2013-06-12 12:33:17 97FA62873FF759574B20DF39FF22CC27 2877440 ----a-w- C:\windows\SysWOW64\jscript9.dll 2013-06-12 12:33:16 D6515FEDDF987CAA7B4EFA826AD4C82F 1141248 ----a-w- C:\windows\SysWOW64\urlmon.dll 2013-06-12 12:33:13 4395AC0BC02009AFAAB01368BA38AF30 39424 ----a-w- C:\windows\SysWOW64\jsproxy.dll 2013-06-12 12:33:13 2473CA6595A2659D7039A4A89FECA269 1767936 ----a-w- C:\windows\SysWOW64\wininet.dll 2013-06-12 12:33:12 CB6DE2477C9E03159A637AC4D255C598 13760512 ----a-w- C:\windows\SysWOW64\ieframe.dll 2013-06-12 12:33:05 69A03AB053CAD761E51BAE1B01F95F55 14327808 ----a-w- C:\windows\SysWOW64\mshtml.dll 2013-06-12 10:35:00 FC415B303B1ECF80B5F130A1F7203D02 492544 ----a-w- C:\windows\SysWOW64\win32spl.dll 2013-06-12 10:34:51 45FBAFFA68CBC29AC2563985CEE72B9C 24576 ----a-w- C:\windows\SysWOW64\cryptdlg.dll 2013-06-12 10:34:44 5B2E4E90C04FB9AE9F2C5E99FF59B283 1230336 ----a-w- C:\windows\SysWOW64\WindowsCodecs.dll 2013-06-12 10:34:37 0D52559AEF4AA5EAC82F530617032283 903168 ----a-w- C:\windows\SysWOW64\certutil.exe 2013-06-12 10:34:30 92245C959E5BC378809D2CC5E9F6E9C7 1160192 ----a-w- C:\windows\SysWOW64\crypt32.dll 2013-06-12 10:34:29 8A8B277067C22F4BF6AA9A31692FC4D3 103936 ----a-w- C:\windows\SysWOW64\cryptnet.dll 2013-06-12 10:34:28 3897DFF247D9ED0006190349DE264E14 140288 ----a-w- C:\windows\SysWOW64\cryptsvc.dll 2013-06-12 10:34:27 CC917AC4D3F8756FF13174980B474791 43008 ----a-w- C:\windows\SysWOW64\certenc.dll 2013-06-12 10:34:00 6DE66FE7C526637E74CD066461C7C871 1505280 ----a-w- C:\windows\SysWOW64\d3d11.dll ====== C:\windows\SysWOW64\drivers ===== ====== C:\windows\Sysnative ===== 2013-06-12 12:33:25 F827BD7A09F9FCDF76AB2C3E27650E71 2706432 ----a-w- C:\windows\Sysnative\mshtml.tlb 2013-06-12 12:33:23 711AF614B8CE85F137E3E4B895559ED0 526336 ----a-w- C:\windows\Sysnative\ieui.dll 2013-06-12 12:33:22 8C42F591EA3D14004C0684ADD177941B 39936 ----a-w- C:\windows\Sysnative\iernonce.dll 2013-06-12 12:33:22 146A64604D96E82B03CD57B214E66632 67072 ----a-w- C:\windows\Sysnative\iesetup.dll 2013-06-12 12:33:21 D575B8A1E28747D8562A7EB0D95AAD74 51712 ----a-w- C:\windows\Sysnative\ie4uinit.exe 2013-06-12 12:33:21 6D1CD9151AC8E10B6B7DBEAAD89A2E56 89600 ----a-w- C:\windows\Sysnative\RegisterIEPKEYs.exe 2013-06-12 12:33:21 5C9D6C25054683CEEC28935C1DDB03DF 136704 ----a-w- C:\windows\Sysnative\iesysprep.dll 2013-06-12 12:33:20 9ACD5BC528F8FFA885EFF895A95B35C4 2648064 ----a-w- C:\windows\Sysnative\iertutil.dll 2013-06-12 12:33:19 4A420CB5E499E484B1E5E1CE010E6896 603136 ----a-w- C:\windows\Sysnative\msfeeds.dll 2013-06-12 12:33:18 C928E6CC4DF7ED4620BAB3CE96262632 855552 ----a-w- C:\windows\Sysnative\jscript.dll 2013-06-12 12:33:18 396D851E3B6ECB9990718C25567ABBB9 3958784 ----a-w- C:\windows\Sysnative\jscript9.dll 2013-06-12 12:33:15 BF11B116409376F070A00D7978C03643 1365504 ----a-w- C:\windows\Sysnative\urlmon.dll 2013-06-12 12:33:13 5AD28C210D17029694554420022E1074 53248 ----a-w- C:\windows\Sysnative\jsproxy.dll 2013-06-12 12:33:12 12716D987D475B051F35895659159705 2241024 ----a-w- C:\windows\Sysnative\wininet.dll 2013-06-12 12:33:10 38026FA060E7802D1ACBA462E4CEAA54 15404544 ----a-w- C:\windows\Sysnative\ieframe.dll 2013-06-12 12:33:08 945C49FA10B96570DFE37CFB145A1D10 19233792 ----a-w- C:\windows\Sysnative\mshtml.dll 2013-06-12 10:35:01 67CF11E00D026A5C0C88EA5F84D501E5 751104 ----a-w- C:\windows\Sysnative\win32spl.dll 2013-06-12 10:34:52 C06FAAF13E37CE482F612AFF2D2331F3 30720 ----a-w- C:\windows\Sysnative\cryptdlg.dll 2013-06-12 10:34:44 3D7BB6DD7A87B3E36E44CA94444247A8 1424384 ----a-w- C:\windows\Sysnative\WindowsCodecs.dll 2013-06-12 10:34:37 4586B77B18FA9A8518AF76CA8FD247D9 1192448 ----a-w- C:\windows\Sysnative\certutil.exe 2013-06-12 10:34:31 A96D5ECA5742603E0E345C4F6B801F5E 1464320 ----a-w- C:\windows\Sysnative\crypt32.dll 2013-06-12 10:34:30 D8129C49798CBBFB2E4351D4B7B8EF9C 184320 ----a-w- C:\windows\Sysnative\cryptsvc.dll 2013-06-12 10:34:30 2C4C22EA1735F21F355EB1A39832F7DF 139776 ----a-w- C:\windows\Sysnative\cryptnet.dll 2013-06-12 10:34:27 189B0BAE1B0EDD51CEF1CD3F4CDEE02E 52224 ----a-w- C:\windows\Sysnative\certenc.dll 2013-06-12 10:34:01 4C92EB7535CAA1681A77D928FBF9771F 1887232 ----a-w- C:\windows\Sysnative\d3d11.dll ====== C:\windows\Sysnative\drivers ===== 2013-06-12 10:35:05 9849EA3843A2ADBDD1497E97A85D8CAE 1910632 ----a-w- C:\windows\Sysnative\drivers\tcpip.sys 2013-05-16 06:29:05 AF2E16242AA723F68F461B6EAE2EAD3D 983400 ----a-w- C:\windows\Sysnative\drivers\dxgkrnl.sys 2013-05-16 06:29:05 1F04CFB79DD5FB7694468CE3FB3DCC31 265064 ----a-w- C:\windows\Sysnative\drivers\dxgmms1.sys ====== C:\windows\Tasks ====== ====== C:\windows\Temp ====== ======= C:\Program Files ===== ======= C:\Program Files (x86) ===== 2013-05-28 06:41:49 -------- d-----w- C:\Program Files (x86)\Common Files\Skype 2013-05-20 07:13:11 -------- d-----w- C:\Program Files (x86)\Common Files\BioWare ======= C: ===== ====== C:\Users\Robin\AppData\Roaming ====== 2013-06-13 13:20:19 -------- d-----w- C:\users\Robin\AppData\Local\Roxio 2013-05-20 07:16:07 -------- d-----w- C:\users\Robin\AppData\Local\SWTORPerf 2013-05-20 07:12:36 -------- d-----w- C:\users\hedev\AppData\Local\Temp ====== C:\Users\Robin ====== 2013-06-11 22:37:51 3C381DB78BA2EA0F5DF599BD052AEE09 13504464 ----a-w- C:\Users\Robin\Downloads\mseinstall.exe 2013-05-28 06:41:49 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype 2013-05-20 07:12:36 -------- d-----w- C:\Users\hedev\AppData ====== C: exe-files == 2013-06-12 12:33:20 07DFD28E57879554D054464EE4A5662D 770648 ----a-w- C:\Program Files (x86)\Internet Explorer\iexplore.exe 2013-06-12 12:33:19 EDC77CF787FA015205936C9A3228486E 775256 ----a-w- C:\Program Files\Internet Explorer\iexplore.exe === C: other files == ==== Startup Registry Enabled ====================== [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun" [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun" [HKEY_USERS\S-1-5-21-1807347547-2428687172-3078923314-1000\Software\Microsoft\Windows\CurrentVersion\Run] "LightScribe Control Panel"="C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden" "Google Update"="C:\Users\Robin\AppData\Local\Google\Update\GoogleUpdate.exe /c" "swg"="C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" "MediaGet2"="C:\Users\Robin\AppData\Local\MediaGet2\mediaget.exe --minimized" "Akamai NetSession Interface"="C:\Users\Robin\AppData\Local\Akamai\netsession_win.exe" "Facebook Update"="C:\Users\Robin\AppData\Local\Facebook\Update\FacebookUpdate.exe /c /nocrashserver" "Pando Media Booster"="C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe" "Skype"="C:\Program Files (x86)\Skype\Phone\Skype.exe /minimized /regrun" [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce] "mctadmin"="C:\Windows\System32\mctadmin.exe" [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce] "mctadmin"="C:\Windows\System32\mctadmin.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IAStorIcon"="C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" "WirelessAssistant"="C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" "NortonOnlineBackup"="C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe" "QLBController"="C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe /start" "HP Software Update"="C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe" "SweetIM"="C:\Program Files (x86)\SweetIM\Messenger\SweetIM.exe" "Coupon Alert Search Scope Monitor"="C:\PROGRA~2\COUPON~2\bar\1.bin\2psrchmn.exe /m=2 /w /h" "CouponAlert_2p Browser Plugin Loader"="C:\PROGRA~2\COUPON~2\bar\1.bin\2pbrmon.exe" "APSDaemon"="C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" "iTunesHelper"="C:\Program Files (x86)\iTunes\iTunesHelper.exe" "SunJavaUpdateSched"="C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" "AVG_UI"="C:\Program Files (x86)\AVG\AVG2013\avgui.exe /TRAYONLY" "beid"="C:\Program Files (x86)\Belgium Identity Card\beid35gui.exe /startup" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "LightScribe Control Panel"="C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden" "Google Update"="C:\Users\Robin\AppData\Local\Google\Update\GoogleUpdate.exe /c" "swg"="C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" "MediaGet2"="C:\Users\Robin\AppData\Local\MediaGet2\mediaget.exe --minimized" "Akamai NetSession Interface"="C:\Users\Robin\AppData\Local\Akamai\netsession_win.exe" "Facebook Update"="C:\Users\Robin\AppData\Local\Facebook\Update\FacebookUpdate.exe /c /nocrashserver" "Pando Media Booster"="C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe" "Skype"="C:\Program Files (x86)\Skype\Phone\Skype.exe /minimized /regrun" ==== Startup Registry Enabled x64 ====================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IgfxTray"="C:\windows\system32\igfxtray.exe" "HotKeysCmds"="C:\windows\system32\hkcmd.exe" "Persistence"="C:\windows\system32\igfxpers.exe" "BTMTrayAgent"="rundll32.exe C:\Program Files\Motorola\Bluetooth\btmshell.dll,TrayApp" "MSC"="c:\Program Files\Microsoft Security Client\msseces.exe -hide -runkey" "SynTPEnh"="%ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe " "SysTrayApp"="C:\Program Files\IDT\WDM\sttray64.exe" ==== Startup Folders ====================== 2013-04-30 15:24:53 1049 ----a-w- C:\users\Robin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk 2012-09-23 07:06:35 1334 ----a-w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\SolidWorks Background Downloader.lnk ==== Task Scheduler Jobs ====================== C:\windows\tasks\FacebookUpdateTaskUserS-1-5-21-1807347547-2428687172-3078923314-1000Core.job --a------ C:\Users\Robin\AppData\Local\Facebook\Update\FacebookUpdate.exe [11/07/2012 23:36] C:\windows\tasks\FacebookUpdateTaskUserS-1-5-21-1807347547-2428687172-3078923314-1000UA.job --a------ C:\Users\Robin\AppData\Local\Facebook\Update\FacebookUpdate.exe [11/07/2012 23:36] C:\windows\tasks\GlaryInitialize.job --a------ C:w6C:\Program Files (x86)\Glary Utilities\initialize.exe [] C:\windows\tasks\GoogleUpdateTaskMachineCore.job --a------ C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [08/08/2011 15:09] C:\windows\tasks\GoogleUpdateTaskMachineUA.job --a------ C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [08/08/2011 15:09] C:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-1807347547-2428687172-3078923314-1000Core.job --a------ C:\Users\Robin\AppData\Local\Google\Update\GoogleUpdate.exe [09/09/2011 19:22] C:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-1807347547-2428687172-3078923314-1000UA.job --a------ C:\Users\Robin\AppData\Local\Google\Update\GoogleUpdate.exe [09/09/2011 19:22] C:\windows\tasks\HPCeeScheduleForRobin.job --a------ [Undertermined Task] ==== EOF on do 13/06/2013 at 17:41:44,52 ======================