Zoek.exe v5.0.0.0 Updated 07-March-2014 Microsoft Windows 8.1 6.3.9600 x64 Running in: Normal Mode Internet Access Detected Launched: C:\Users\Johan&Linette\Desktop\zoek.exe [Scan all users] [Script inserted] [Checkboxes used] ==== Older Logs ====================== C:\zoek-results2014-03-21-174902.log 554 bytes C:\zoek-results2014-03-22-075536.log 326 bytes ==== Registry Fix Code ====================== Windows Registry Editor Version 5.00 [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31ad400d-1b06-4e33-a59a-90c2c140cba0}] ==== Files Recently Created / Modified ====================== ====== C:\WINDOWS ==== ====== Java Cache ===== ====== C:\WINDOWS\SysWOW64 ===== 2014-03-18 05:43:38 42433CDEC449D40F508752F2D487D8E4 478208 ----a-w- C:\WINDOWS\SysWOW64\SettingSyncHost.exe 2014-03-18 05:43:37 D292652F380DFC23897CB31B1940E56C 588800 ----a-w- C:\WINDOWS\SysWOW64\SettingSyncCore.dll 2014-03-18 05:43:32 3104FCDE0470E5D89C9991FC0EDDE57E 18643560 ----a-w- C:\WINDOWS\SysWOW64\shell32.dll 2014-03-18 05:43:31 9929F71938D9FCE4550BEB935071F0C8 13949440 ----a-w- C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll 2014-03-18 05:43:29 A00970DBAD7034523CF9D2C395A944B8 103936 ----a-w- C:\WINDOWS\SysWOW64\OEMLicense.dll 2014-03-18 05:43:29 716046CF7941B176C18AA58785899A2D 174592 ----a-w- C:\WINDOWS\SysWOW64\WSClient.dll 2014-03-18 05:43:28 A863A4DEF854D579C36EAA9DECF21C80 336896 ----a-w- C:\WINDOWS\SysWOW64\XpsGdiConverter.dll 2014-03-18 05:43:25 65ACE54B8EDA937EE7706733D27F40A8 802816 ----a-w- C:\WINDOWS\SysWOW64\MFMediaEngine.dll 2014-03-18 05:43:24 DBB6B2FA462A5E7029766B09ED9CDA73 381168 ----a-w- C:\WINDOWS\SysWOW64\mfsvr.dll 2014-03-18 05:43:24 CF8746715C1AA00C29F789825E321C7C 770560 ----a-w- C:\WINDOWS\SysWOW64\ReAgent.dll 2014-03-18 05:43:23 986ABF43F76F5B0E3557363FB4925C78 1472048 ----a-w- C:\WINDOWS\SysWOW64\ntdll.dll 2014-03-18 05:43:22 EC308077E9BEEDF523AE3D6BA042E016 630272 ----a-w- C:\WINDOWS\SysWOW64\MsSpellCheckingFacility.dll 2014-03-18 05:43:21 E2C1E49EBFB8EFA1AFF6966533BAD12B 140800 ----a-w- C:\WINDOWS\SysWOW64\easwrt.dll 2014-03-18 05:43:21 A7DE6E0B69826D5B6F5FF68AABCF7035 218112 ----a-w- C:\WINDOWS\SysWOW64\sti.dll 2014-03-13 16:09:51 6FB09BB5F1CB1724E94A83A6A520341F 105464 ----a-w- C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl 2014-03-13 16:09:50 58ECF21344E4E4CF1AEB4B00DDE2DA8A 693240 ----a-w- C:\WINDOWS\SysWOW64\FlashPlayerApp.exe 2014-03-13 06:18:23 70462E0A4E293FC80620AB945D8A59BB 17074688 ----a-w- C:\WINDOWS\SysWOW64\mshtml.dll 2014-03-13 06:18:20 4831AA1A6A112ACCEE240C9D5FA2108B 11266048 ----a-w- C:\WINDOWS\SysWOW64\ieframe.dll 2014-03-13 06:18:19 FC46FE32B043CA7251B1D707B91BA6A7 4244480 ----a-w- C:\WINDOWS\SysWOW64\jscript9.dll 2014-03-13 06:18:18 BD5E6C894130E7BB7ECE9A0925383068 2168320 ----a-w- C:\WINDOWS\SysWOW64\iertutil.dll 2014-03-13 06:18:17 AAFEAB4FC9D70253F8C7E353E879E8A2 1820160 ----a-w- C:\WINDOWS\SysWOW64\wininet.dll 2014-03-13 06:18:17 A045DAE4D242A9A50FF6902774C55BE0 524288 ----a-w- C:\WINDOWS\SysWOW64\msfeeds.dll 2014-03-13 06:18:17 0FF358906F2333B26267BC0064DC02C4 1156096 ----a-w- C:\WINDOWS\SysWOW64\urlmon.dll 2014-03-13 06:18:16 4605E0295C8E742B28FD63D255322795 703488 ----a-w- C:\WINDOWS\SysWOW64\ieapfltr.dll 2014-03-13 06:18:07 D34CE666D9BA3D5232609D3C15075B70 5770752 ----a-w- C:\WINDOWS\SysWOW64\mstscax.dll 2014-03-13 06:17:59 ECEBFCEF5799B57BFF242D24B27E4FE4 2143960 ----a-w- C:\WINDOWS\SysWOW64\mfcore.dll 2014-03-13 06:17:58 6C8AC5035C39C818624EFA962B24AB3D 1036288 ----a-w- C:\WINDOWS\SysWOW64\kernel32.dll 2014-03-13 06:17:58 34823DAA381423CAE81FEE7C2EEE52F4 669352 ----a-w- C:\WINDOWS\SysWOW64\mfmpeg2srcsnk.dll 2014-03-13 06:17:58 2A3626E0B7F5A5317902EBDAF2B4CCE0 1371824 ----a-w- C:\WINDOWS\SysWOW64\combase.dll 2014-03-13 06:17:58 17500825FE6C7094ACC6E7DC6B578399 369280 ----a-w- C:\WINDOWS\SysWOW64\Faultrep.dll 2014-03-13 06:17:57 FCD51A3EB7E47FBCE17382A95FD3AB35 2873344 ----a-w- C:\WINDOWS\SysWOW64\dbgeng.dll 2014-03-13 06:17:57 F5033F3C6F8E706D78ACB9351EBF7B3E 1238016 ----a-w- C:\WINDOWS\SysWOW64\dbghelp.dll 2014-03-13 06:17:57 878B3C936C3C2850A57C24C6F104EBC5 208896 ----a-w- C:\WINDOWS\SysWOW64\rdpencom.dll 2014-03-13 06:17:57 249DE8C6F690646CC8EC53D49ABC6BE9 408480 ----a-w- C:\WINDOWS\SysWOW64\WerFault.exe 2014-03-13 06:17:56 D4A17A8DEB194D77AD9651F0EE0C76EB 138752 ----a-w- C:\WINDOWS\SysWOW64\DWWIN.EXE 2014-03-13 06:17:56 3DA5CD1E3B9BDAF79731CB6CB1029CB3 53248 ----a-w- C:\WINDOWS\SysWOW64\tsgqec.dll 2014-03-13 06:17:54 D0B6EB329D696A5C2122352EAE722290 855552 ----a-w- C:\WINDOWS\SysWOW64\rdvidcrl.dll 2014-03-13 06:17:39 F80E8CF9E4A051C2CC338C85088A046C 488448 ----a-w- C:\WINDOWS\SysWOW64\qedit.dll ====== C:\WINDOWS\SysWOW64\drivers ===== ====== C:\WINDOWS\Sysnative ===== 2014-03-18 05:43:37 43D0F8E593ABD37B5BC9573EDD71EFEB 628736 ----a-w- C:\WINDOWS\Sysnative\SettingSyncHost.exe 2014-03-18 05:43:36 968FB3BA8E7DF0933A1CF593BD503F4A 461312 ----a-w- C:\WINDOWS\Sysnative\XpsGdiConverter.dll 2014-03-18 05:43:34 1D8F8BE07D2B06C32ADB4B08F0F2A357 749056 ----a-w- C:\WINDOWS\Sysnative\SettingSyncCore.dll 2014-03-18 05:43:33 FF73B88BA206966BD228320F664D4D92 21199256 ----a-w- C:\WINDOWS\Sysnative\shell32.dll 2014-03-18 05:43:30 04B5ADB034D17585D3BCFC6DE5CADFF8 18576384 ----a-w- C:\WINDOWS\Sysnative\Windows.UI.Xaml.dll 2014-03-18 05:43:29 68085A085DE8E3540EE8E02CAE575B2E 138240 ----a-w- C:\WINDOWS\Sysnative\OEMLicense.dll 2014-03-18 05:43:28 B88A70259DF2927787C0B766DD4CFB5C 206336 ----a-w- C:\WINDOWS\Sysnative\WSClient.dll 2014-03-18 05:43:25 E069B63DAD920D231FA8A141DFF43A8C 960512 ----a-w- C:\WINDOWS\Sysnative\MFMediaEngine.dll 2014-03-18 05:43:25 A95838FFFAEAA7500263D491575F7E0C 1214976 ----a-w- C:\WINDOWS\Sysnative\schedsvc.dll 2014-03-18 05:43:24 E80700EB046D0B82B694C98CF7231C08 481944 ----a-w- C:\WINDOWS\Sysnative\mfsvr.dll 2014-03-18 05:43:24 D03BF756457B6A1EB305B26046BB9B4D 914944 ----a-w- C:\WINDOWS\Sysnative\ReAgent.dll 2014-03-18 05:43:23 E287F157F7A0011D93179C64EF8ADCF2 376320 ----a-w- C:\WINDOWS\Sysnative\pnrpsvc.dll 2014-03-18 05:43:23 847CFF96ACB575CE73C0E2E86C6BA993 842752 ----a-w- C:\WINDOWS\Sysnative\MsSpellCheckingFacility.dll 2014-03-18 05:43:23 1FCA4E287F0ED13BF037A484AA2FE3B1 419160 ----a-w- C:\WINDOWS\Sysnative\hal.dll 2014-03-18 05:43:22 C8ACFF60C553E63949A79DC370B516E4 947712 ----a-w- C:\WINDOWS\Sysnative\reseteng.dll 2014-03-18 05:43:22 A0D3749BB1BC942C7D21C4D99E79A615 131160 ----a-w- C:\WINDOWS\Sysnative\easinvoker.exe 2014-03-18 05:43:22 3D136E8D4C0407D9C40FD8BDD649B587 1720560 ----a-w- C:\WINDOWS\Sysnative\ntdll.dll 2014-03-18 05:43:22 0B9FBEC5714523FF76DDFEB320FE2DF2 303616 ----a-w- C:\WINDOWS\Sysnative\sti.dll 2014-03-18 05:43:21 66F214C9E446407D78048681394820A6 178176 ----a-w- C:\WINDOWS\Sysnative\easwrt.dll 2014-03-13 06:18:26 695C842DAA76536CE44C336C9E27B25D 1507704 ----a-w- C:\WINDOWS\Sysnative\winload.exe 2014-03-13 06:18:26 1A1DDFD4BA6523979C76BE188984C3AC 1643584 ----a-w- C:\WINDOWS\Sysnative\winload.efi 2014-03-13 06:18:24 4E0709D9BB951AD1C22E4FF519B90839 23133696 ----a-w- C:\WINDOWS\Sysnative\mshtml.dll 2014-03-13 06:18:20 9C5ADB26632D46919ABB231CF7DE98B9 13051904 ----a-w- C:\WINDOWS\Sysnative\ieframe.dll 2014-03-13 06:18:19 76862AAF77C049EC20217FDC209F7F13 2765824 ----a-w- C:\WINDOWS\Sysnative\iertutil.dll 2014-03-13 06:18:18 DF79CE9B950C62677D232154E93A81C7 2334208 ----a-w- C:\WINDOWS\Sysnative\wininet.dll 2014-03-13 06:18:18 D378AB3C9178424588B55AC7B652D7F9 218624 ----a-w- C:\WINDOWS\Sysnative\ie4uinit.exe 2014-03-13 06:18:18 CF1C73DE1FADE3D3C44FCAF254F57DB2 5768704 ----a-w- C:\WINDOWS\Sysnative\jscript9.dll 2014-03-13 06:18:18 BA0A21F761CE5001DF712C51BF11F953 1393664 ----a-w- C:\WINDOWS\Sysnative\urlmon.dll 2014-03-13 06:18:17 E6ACA421DA3E50D7F0A31228F0C547B0 627200 ----a-w- C:\WINDOWS\Sysnative\msfeeds.dll 2014-03-13 06:18:16 48ED94DA88F65684B28FCD87C01288A7 817664 ----a-w- C:\WINDOWS\Sysnative\ieapfltr.dll 2014-03-13 06:18:11 C993A0B97BECD3AAF5158E3869878465 6353960 ----a-w- C:\WINDOWS\Sysnative\sppsvc.exe 2014-03-13 06:18:09 BAAD43360A7DF630ECC414671AEFA28C 6640640 ----a-w- C:\WINDOWS\Sysnative\mstscax.dll 2014-03-13 06:18:05 977F77CE98456F6B115E5360A1160449 2133208 ----a-w- C:\WINDOWS\Sysnative\mfcore.dll 2014-03-13 06:17:59 C039246195C736A602F581D29F18A43D 1928144 ----a-w- C:\WINDOWS\Sysnative\combase.dll 2014-03-13 06:17:58 CFADC50692A845BAC30940E203393219 1287064 ----a-w- C:\WINDOWS\Sysnative\kernel32.dll 2014-03-13 06:17:58 C7DFBE21051D5E44B479CBF74B968335 1486848 ----a-w- C:\WINDOWS\Sysnative\dbghelp.dll 2014-03-13 06:17:58 C7B69F90B823182CE6BE7C5374832DE5 764864 ----a-w- C:\WINDOWS\Sysnative\mfmpeg2srcsnk.dll 2014-03-13 06:17:58 B5D2EBAD81739185A91D210F5F01824B 407024 ----a-w- C:\WINDOWS\Sysnative\Faultrep.dll 2014-03-13 06:17:58 819A1E0F89B6AC222E9D95CA000A40B1 4175360 ----a-w- C:\WINDOWS\Sysnative\dbgeng.dll 2014-03-13 06:17:57 C83AFB0B285F293EDECF5EBDEC074A94 458616 ----a-w- C:\WINDOWS\Sysnative\WerFault.exe 2014-03-13 06:17:57 99453C649DC4B0BE6D062B701CD2917F 716288 ----a-w- C:\WINDOWS\Sysnative\swprv.dll 2014-03-13 06:17:57 94D79382FB796B0A8C90270654A70563 1057280 ----a-w- C:\WINDOWS\Sysnative\rdvidcrl.dll 2014-03-13 06:17:57 735CB57F806D292FB7ABE8BDFD3B5853 233920 ----a-w- C:\WINDOWS\Sysnative\mfps.dll 2014-03-13 06:17:57 724ADFEE7743C26C550ABFE04271DCFD 160256 ----a-w- C:\WINDOWS\Sysnative\DWWIN.EXE 2014-03-13 06:17:57 2684605E822359CBD1ED2BD2C8E76397 249856 ----a-w- C:\WINDOWS\Sysnative\rdpencom.dll 2014-03-13 06:17:56 AFCAB4DC692CCE37E283B00E2D7B438F 447488 ----a-w- C:\WINDOWS\Sysnative\sppcomapi.dll 2014-03-13 06:17:56 3FFEC6927D4017829A82ECDB277BB23E 64512 ----a-w- C:\WINDOWS\Sysnative\tsgqec.dll 2014-03-13 06:17:56 110BE5198A63D3FF3CE9C30F1DC12EC3 386722 ----a-w- C:\WINDOWS\Sysnative\ApnDatabase.xml 2014-03-13 06:17:39 05894DFC52A78C3B1DD5EF6F30FAD28C 586240 ----a-w- C:\WINDOWS\Sysnative\qedit.dll 2014-03-13 06:17:38 1A69D165DDA78A4329B854D4FEDAD132 4189184 ----a-w- C:\WINDOWS\Sysnative\win32k.sys ====== C:\WINDOWS\Sysnative\drivers ===== 2014-03-18 05:43:25 13B160C1913F012BD1615EB1398D3779 1530712 ----a-w- C:\WINDOWS\Sysnative\drivers\dxgkrnl.sys 2014-03-18 05:43:23 22EDC0DE06A0272DFA4C7B47B5D8E377 382808 ----a-w- C:\WINDOWS\Sysnative\drivers\dxgmms1.sys 2014-03-18 05:43:22 A1A5E79C0D1352AFDC08328A623DA051 408576 ----a-w- C:\WINDOWS\Sysnative\drivers\rdbss.sys 2014-03-18 05:43:21 D22EB844EB57D016CC34178AC86456DF 325464 -c--a-w- C:\WINDOWS\Sysnative\drivers\USBXHCI.SYS 2014-03-18 05:43:20 DF355EB0199198728027962DCFCDE5FB 121088 -c--a-w- C:\WINDOWS\Sysnative\drivers\USBAUDIO.sys 2014-03-13 06:17:59 ECC68BD5347BDE9631EE68274858A41F 2543960 ----a-w- C:\WINDOWS\Sysnative\drivers\tcpip.sys 2014-03-13 06:17:57 C85C075DE5B6D0FE116043054DE8EE02 311640 -c--a-w- C:\WINDOWS\Sysnative\drivers\volsnap.sys 2014-03-13 06:17:46 C52148456E0F6EAD9E903020A79207FC 236888 ----a-w- C:\WINDOWS\Sysnative\drivers\WdFilter.sys 2014-03-13 06:17:44 241895E8A9C158DF86E12FDD21033A32 35856 ----a-w- C:\WINDOWS\Sysnative\drivers\WdBoot.sys 2014-03-13 06:17:43 57F22324FAAF92ADF957B281E88F1743 124760 ----a-w- C:\WINDOWS\Sysnative\drivers\WdNisDrv.sys 2014-02-27 16:11:26 9FF2B30AF44E75746FED5FBDD8191DCC 25600 ----a-w- C:\WINDOWS\Sysnative\drivers\stmedit.sys ====== C:\WINDOWS\Tasks ====== 2014-03-13 20:33:33 6FBBB1DBFC00BD0DDAED2175025A34B4 5088 ----a-w- C:\WINDOWS\Sysnative\Tasks\Microsoft Office 15 Sync Maintenance for NIJSSE-Johan&Linette Nijsse ====== C:\WINDOWS\Temp ====== ======= C:\Program Files ===== 2014-03-21 16:55:31 -------- d-----w- C:\Program Files\trend micro 2014-03-13 15:46:29 -------- d-----w- C:\Program Files\Microsoft Office 15 ======= C:\PROGRA~2 ===== 2014-03-13 16:05:51 -------- d-----w- C:\PROGRA~2\COMMON~1\DESIGNER 2014-03-07 13:18:18 -------- d-----w- C:\PROGRA~2\Braingame 2014-03-07 06:50:28 -------- d-----w- C:\PROGRA~2\Filternet 2014-03-06 11:55:13 -------- d-----w- C:\PROGRA~2\ISO to USB 2014-03-01 17:06:39 -------- d-----w- C:\PROGRA~2\COMMON~1\Java 2014-02-25 18:47:40 -------- d-----w- C:\PROGRA~2\Freemake ======= C: ===== 2014-03-07 08:47:44 87A8127405B80098C1EA9A89CC725A95 5625473 ----a-w- C:\marline science.3ga 2014-03-21 16:55:37 51B36F2414AF9011A3F7E53E41A4D958 18499 ----a-w- C:\\rsit\info.txt 2014-03-21 16:55:32 9A2347903D6EDB84C10F288BC0578C1C 388608 ----a-w- C:\\Program Files\trend micro\Johan&Linette.exe 2014-03-21 16:55:31 -------- d-----w- C:\\Program Files\trend micro 2014-03-20 07:12:37 -------- d-----r- C:\\MSOCache\All Users 2014-03-18 15:27:38 F30A16105C6C685390074EE69BC175B0 10536864 ----a-w- C:\\Windows\Temp\MPENGINE.DLL 2014-03-18 15:27:38 30634821151BEC075CA85F37AC73AF04 432824 ----a-w- C:\\Windows\Temp\MPGEAR.DLL 2014-03-18 05:43:38 42433CDEC449D40F508752F2D487D8E4 478208 ----a-w- C:\\Windows\SysWOW64\SettingSyncHost.exe 2014-03-18 05:43:37 D292652F380DFC23897CB31B1940E56C 588800 ----a-w- C:\\Windows\SysWOW64\SettingSyncCore.dll 2014-03-18 05:43:37 43D0F8E593ABD37B5BC9573EDD71EFEB 628736 ----a-w- C:\\Windows\System32\SettingSyncHost.exe 2014-03-18 05:43:36 968FB3BA8E7DF0933A1CF593BD503F4A 461312 ----a-w- C:\\Windows\System32\XpsGdiConverter.dll 2014-03-18 05:43:34 1D8F8BE07D2B06C32ADB4B08F0F2A357 749056 ----a-w- C:\\Windows\System32\SettingSyncCore.dll 2014-03-18 05:43:33 FF73B88BA206966BD228320F664D4D92 21199256 ----a-w- C:\\Windows\System32\shell32.dll 2014-03-18 05:43:32 3104FCDE0470E5D89C9991FC0EDDE57E 18643560 ----a-w- C:\\Windows\SysWOW64\shell32.dll 2014-03-18 05:43:31 9929F71938D9FCE4550BEB935071F0C8 13949440 ----a-w- C:\\Windows\SysWOW64\Windows.UI.Xaml.dll 2014-03-18 05:43:30 04B5ADB034D17585D3BCFC6DE5CADFF8 18576384 ----a-w- C:\\Windows\System32\Windows.UI.Xaml.dll 2014-03-18 05:43:29 A00970DBAD7034523CF9D2C395A944B8 103936 ----a-w- C:\\Windows\SysWOW64\OEMLicense.dll 2014-03-18 05:43:29 716046CF7941B176C18AA58785899A2D 174592 ----a-w- C:\\Windows\SysWOW64\WSClient.dll 2014-03-18 05:43:29 68085A085DE8E3540EE8E02CAE575B2E 138240 ----a-w- C:\\Windows\System32\OEMLicense.dll 2014-03-18 05:43:28 B88A70259DF2927787C0B766DD4CFB5C 206336 ----a-w- C:\\Windows\System32\WSClient.dll 2014-03-18 05:43:28 A863A4DEF854D579C36EAA9DECF21C80 336896 ----a-w- C:\\Windows\SysWOW64\XpsGdiConverter.dll 2014-03-18 05:43:25 E069B63DAD920D231FA8A141DFF43A8C 960512 ----a-w- C:\\Windows\System32\MFMediaEngine.dll 2014-03-18 05:43:25 A95838FFFAEAA7500263D491575F7E0C 1214976 ----a-w- C:\\Windows\System32\schedsvc.dll 2014-03-18 05:43:25 65ACE54B8EDA937EE7706733D27F40A8 802816 ----a-w- C:\\Windows\SysWOW64\MFMediaEngine.dll 2014-03-18 05:43:24 E80700EB046D0B82B694C98CF7231C08 481944 ----a-w- C:\\Windows\System32\mfsvr.dll 2014-03-18 05:43:24 DBB6B2FA462A5E7029766B09ED9CDA73 381168 ----a-w- C:\\Windows\SysWOW64\mfsvr.dll 2014-03-18 05:43:24 D03BF756457B6A1EB305B26046BB9B4D 914944 ----a-w- C:\\Windows\System32\ReAgent.dll 2014-03-18 05:43:24 CF8746715C1AA00C29F789825E321C7C 770560 ----a-w- C:\\Windows\SysWOW64\ReAgent.dll 2014-03-18 05:43:23 E287F157F7A0011D93179C64EF8ADCF2 376320 ----a-w- C:\\Windows\System32\pnrpsvc.dll 2014-03-18 05:43:23 986ABF43F76F5B0E3557363FB4925C78 1472048 ----a-w- C:\\Windows\SysWOW64\ntdll.dll 2014-03-18 05:43:23 847CFF96ACB575CE73C0E2E86C6BA993 842752 ----a-w- C:\\Windows\System32\MsSpellCheckingFacility.dll 2014-03-18 05:43:23 1FCA4E287F0ED13BF037A484AA2FE3B1 419160 ----a-w- C:\\Windows\System32\hal.dll 2014-03-18 05:43:22 EC308077E9BEEDF523AE3D6BA042E016 630272 ----a-w- C:\\Windows\SysWOW64\MsSpellCheckingFacility.dll 2014-03-18 05:43:22 C8ACFF60C553E63949A79DC370B516E4 947712 ----a-w- C:\\Windows\System32\reseteng.dll 2014-03-18 05:43:22 A0D3749BB1BC942C7D21C4D99E79A615 131160 ----a-w- C:\\Windows\System32\easinvoker.exe 2014-03-18 05:43:22 3D136E8D4C0407D9C40FD8BDD649B587 1720560 ----a-w- C:\\Windows\System32\ntdll.dll 2014-03-18 05:43:22 0B9FBEC5714523FF76DDFEB320FE2DF2 303616 ----a-w- C:\\Windows\System32\sti.dll 2014-03-18 05:43:21 E2C1E49EBFB8EFA1AFF6966533BAD12B 140800 ----a-w- C:\\Windows\SysWOW64\easwrt.dll 2014-03-18 05:43:21 A7DE6E0B69826D5B6F5FF68AABCF7035 218112 ----a-w- C:\\Windows\SysWOW64\sti.dll 2014-03-18 05:43:21 66F214C9E446407D78048681394820A6 178176 ----a-w- C:\\Windows\System32\easwrt.dll 2014-03-13 16:09:50 58ECF21344E4E4CF1AEB4B00DDE2DA8A 693240 ----a-w- C:\\Windows\SysWOW64\FlashPlayerApp.exe 2014-03-13 16:04:27 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013 2014-03-13 15:46:29 -------- d-----w- C:\\Program Files\Microsoft Office 15 2014-03-13 06:18:26 695C842DAA76536CE44C336C9E27B25D 1507704 ----a-w- C:\\Windows\System32\winload.exe 2014-03-13 06:18:24 4E0709D9BB951AD1C22E4FF519B90839 23133696 ----a-w- C:\\Windows\System32\mshtml.dll 2014-03-13 06:18:23 70462E0A4E293FC80620AB945D8A59BB 17074688 ----a-w- C:\\Windows\SysWOW64\mshtml.dll 2014-03-13 06:18:21 A84F2595D001658C5261D1C9C40C19B8 999936 ----a-w- C:\\Program Files (x86)\Internet Explorer\networkinspection.dll 2014-03-13 06:18:21 85BC81949BA5AEF78DBA7CD6B5B7118F 1127424 ----a-w- C:\\Program Files\Internet Explorer\networkinspection.dll 2014-03-13 06:18:20 9C5ADB26632D46919ABB231CF7DE98B9 13051904 ----a-w- C:\\Windows\System32\ieframe.dll 2014-03-13 06:18:20 4831AA1A6A112ACCEE240C9D5FA2108B 11266048 ----a-w- C:\\Windows\SysWOW64\ieframe.dll 2014-03-13 06:18:19 FC46FE32B043CA7251B1D707B91BA6A7 4244480 ----a-w- C:\\Windows\SysWOW64\jscript9.dll 2014-03-13 06:18:19 889CF196E10503133D089DC2AD3969C4 259072 ----a-w- C:\\Program Files\Internet Explorer\F12Tools.dll 2014-03-13 06:18:19 76862AAF77C049EC20217FDC209F7F13 2765824 ----a-w- C:\\Windows\System32\iertutil.dll 2014-03-13 06:18:18 DF79CE9B950C62677D232154E93A81C7 2334208 ----a-w- C:\\Windows\System32\wininet.dll 2014-03-13 06:18:18 D378AB3C9178424588B55AC7B652D7F9 218624 ----a-w- C:\\Windows\System32\ie4uinit.exe 2014-03-13 06:18:18 CF1C73DE1FADE3D3C44FCAF254F57DB2 5768704 ----a-w- C:\\Windows\System32\jscript9.dll 2014-03-13 06:18:18 BD5E6C894130E7BB7ECE9A0925383068 2168320 ----a-w- C:\\Windows\SysWOW64\iertutil.dll 2014-03-13 06:18:18 BA0A21F761CE5001DF712C51BF11F953 1393664 ----a-w- C:\\Windows\System32\urlmon.dll 2014-03-13 06:18:18 943F670C54C3838272F8C9956EF07FD3 184320 ----a-w- C:\\Program Files (x86)\Internet Explorer\F12Tools.dll 2014-03-13 06:18:17 E6ACA421DA3E50D7F0A31228F0C547B0 627200 ----a-w- C:\\Windows\System32\msfeeds.dll 2014-03-13 06:18:17 AAFEAB4FC9D70253F8C7E353E879E8A2 1820160 ----a-w- C:\\Windows\SysWOW64\wininet.dll 2014-03-13 06:18:17 A045DAE4D242A9A50FF6902774C55BE0 524288 ----a-w- C:\\Windows\SysWOW64\msfeeds.dll 2014-03-13 06:18:17 0FF358906F2333B26267BC0064DC02C4 1156096 ----a-w- C:\\Windows\SysWOW64\urlmon.dll 2014-03-13 06:18:16 48ED94DA88F65684B28FCD87C01288A7 817664 ----a-w- C:\\Windows\System32\ieapfltr.dll 2014-03-13 06:18:16 4605E0295C8E742B28FD63D255322795 703488 ----a-w- C:\\Windows\SysWOW64\ieapfltr.dll 2014-03-13 06:18:11 C993A0B97BECD3AAF5158E3869878465 6353960 ----a-w- C:\\Windows\System32\sppsvc.exe 2014-03-13 06:18:09 BAAD43360A7DF630ECC414671AEFA28C 6640640 ----a-w- C:\\Windows\System32\mstscax.dll 2014-03-13 06:18:07 D34CE666D9BA3D5232609D3C15075B70 5770752 ----a-w- C:\\Windows\SysWOW64\mstscax.dll 2014-03-13 06:18:05 977F77CE98456F6B115E5360A1160449 2133208 ----a-w- C:\\Windows\System32\mfcore.dll 2014-03-13 06:17:59 ECEBFCEF5799B57BFF242D24B27E4FE4 2143960 ----a-w- C:\\Windows\SysWOW64\mfcore.dll 2014-03-13 06:17:59 C039246195C736A602F581D29F18A43D 1928144 ----a-w- C:\\Windows\System32\combase.dll 2014-03-13 06:17:58 CFADC50692A845BAC30940E203393219 1287064 ----a-w- C:\\Windows\System32\kernel32.dll 2014-03-13 06:17:58 C7DFBE21051D5E44B479CBF74B968335 1486848 ----a-w- C:\\Windows\System32\dbghelp.dll 2014-03-13 06:17:58 C7B69F90B823182CE6BE7C5374832DE5 764864 ----a-w- C:\\Windows\System32\mfmpeg2srcsnk.dll 2014-03-13 06:17:58 B5D2EBAD81739185A91D210F5F01824B 407024 ----a-w- C:\\Windows\System32\Faultrep.dll 2014-03-13 06:17:58 819A1E0F89B6AC222E9D95CA000A40B1 4175360 ----a-w- C:\\Windows\System32\dbgeng.dll 2014-03-13 06:17:58 6C8AC5035C39C818624EFA962B24AB3D 1036288 ----a-w- C:\\Windows\SysWOW64\kernel32.dll 2014-03-13 06:17:58 34823DAA381423CAE81FEE7C2EEE52F4 669352 ----a-w- C:\\Windows\SysWOW64\mfmpeg2srcsnk.dll 2014-03-13 06:17:58 2A3626E0B7F5A5317902EBDAF2B4CCE0 1371824 ----a-w- C:\\Windows\SysWOW64\combase.dll 2014-03-13 06:17:58 17500825FE6C7094ACC6E7DC6B578399 369280 ----a-w- C:\\Windows\SysWOW64\Faultrep.dll 2014-03-13 06:17:57 FCD51A3EB7E47FBCE17382A95FD3AB35 2873344 ----a-w- C:\\Windows\SysWOW64\dbgeng.dll 2014-03-13 06:17:57 F5033F3C6F8E706D78ACB9351EBF7B3E 1238016 ----a-w- C:\\Windows\SysWOW64\dbghelp.dll 2014-03-13 06:17:57 C83AFB0B285F293EDECF5EBDEC074A94 458616 ----a-w- C:\\Windows\System32\WerFault.exe 2014-03-13 06:17:57 99453C649DC4B0BE6D062B701CD2917F 716288 ----a-w- C:\\Windows\System32\swprv.dll 2014-03-13 06:17:57 94D79382FB796B0A8C90270654A70563 1057280 ----a-w- C:\\Windows\System32\rdvidcrl.dll 2014-03-13 06:17:57 878B3C936C3C2850A57C24C6F104EBC5 208896 ----a-w- C:\\Windows\SysWOW64\rdpencom.dll 2014-03-13 06:17:57 735CB57F806D292FB7ABE8BDFD3B5853 233920 ----a-w- C:\\Windows\System32\mfps.dll 2014-03-13 06:17:57 724ADFEE7743C26C550ABFE04271DCFD 160256 ----a-w- C:\\Windows\System32\DWWIN.EXE 2014-03-13 06:17:57 2684605E822359CBD1ED2BD2C8E76397 249856 ----a-w- C:\\Windows\System32\rdpencom.dll 2014-03-13 06:17:57 249DE8C6F690646CC8EC53D49ABC6BE9 408480 ----a-w- C:\\Windows\SysWOW64\WerFault.exe 2014-03-13 06:17:56 D4A17A8DEB194D77AD9651F0EE0C76EB 138752 ----a-w- C:\\Windows\SysWOW64\DWWIN.EXE 2014-03-13 06:17:56 AFCAB4DC692CCE37E283B00E2D7B438F 447488 ----a-w- C:\\Windows\System32\sppcomapi.dll 2014-03-13 06:17:56 3FFEC6927D4017829A82ECDB277BB23E 64512 ----a-w- C:\\Windows\System32\tsgqec.dll 2014-03-13 06:17:56 3DA5CD1E3B9BDAF79731CB6CB1029CB3 53248 ----a-w- C:\\Windows\SysWOW64\tsgqec.dll 2014-03-13 06:17:54 D0B6EB329D696A5C2122352EAE722290 855552 ----a-w- C:\\Windows\SysWOW64\rdvidcrl.dll 2014-03-13 06:17:39 F80E8CF9E4A051C2CC338C85088A046C 488448 ----a-w- C:\\Windows\SysWOW64\qedit.dll 2014-03-13 06:17:39 05894DFC52A78C3B1DD5EF6F30FAD28C 586240 ----a-w- C:\\Windows\System32\qedit.dll 2014-03-13 06:17:38 1A69D165DDA78A4329B854D4FEDAD132 4189184 ----a-w- C:\\Windows\System32\win32k.sys 2014-03-07 13:19:46 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Braingame 2014-03-07 13:18:18 -------- d-----w- C:\\Program Files (x86)\Braingame 2014-03-07 06:50:33 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Filternet 2014-03-07 06:50:28 -------- d-----w- C:\\Program Files (x86)\Filternet 2014-03-06 11:55:14 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ISO to USB 2014-03-06 11:55:13 -------- d-----w- C:\\Program Files (x86)\ISO to USB 2014-02-25 18:48:03 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Freemake 2014-02-25 18:48:01 -------- d-----w- C:\ProgramData\Freemake 2014-02-25 18:48:01 -------- d-----w- C:\\ProgramData\Freemake 2014-02-25 18:47:40 -------- d-----w- C:\\Program Files (x86)\Freemake ====== C: exe-files == 2014-03-21 16:55:32 9A2347903D6EDB84C10F288BC0578C1C 388608 ----a-w- C:\Program Files\trend micro\Johan&Linette.exe 2014-03-20 07:07:55 6AB585DAB91E7D88AAA1B562AFA9377C 217768 ----a-w- C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE15\MSOXMLED.EXE 2014-03-20 07:07:47 9C2D5C8701718BAF9E937AB0D6348A1B 548536 ----a-w- C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonX86\Microsoft Shared\OFFICE15\MSOSQM.EXE 2014-03-20 07:07:44 B27E7D8D028689D46B18D9B2FF6FCE2B 840400 ----a-w- C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonX86\Microsoft Shared\DW\DW20.EXE 2014-03-20 07:07:44 A8DC5CC29AD3B5608C4028A2FC64B8FD 3015336 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\WORDICON.EXE 2014-03-20 07:07:44 7BA52235E256DC309D5E808B6C358FDE 3685544 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\XLICONS.EXE 2014-03-20 07:07:37 BA00FB61367BE9A2381DB719B8C44D3E 283312 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\msoia.exe 2014-03-20 07:07:31 66EDCE45573F8673DF9379F119CFE343 90720 ----a-w- C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\MSOHTMED.EXE 2014-03-20 07:07:29 BE9C758721B33A78BC656C46C319AEE6 15968 ----a-w- C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonX86\Microsoft Shared\Smart Tag\SmartTagInstall.exe 2014-03-20 07:07:28 A26A02BE800686B88F69B76BE5EC7326 3509416 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\PPTICO.EXE 2014-03-20 07:07:14 B46CED842407A64AF8DCADD138AA5946 15016 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\dcf\Common.ShowHelp.exe 2014-03-20 07:07:06 11982DA3029BF90CF23A69B0C1AD84D0 78576 ----a-w- C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonX86\Microsoft Shared\OFFICE15\CSISYNCCLIENT.EXE 2014-03-20 07:07:04 86ABD59E7C4CF6BFA97651417625DC1D 7113432 ----a-w- C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE15\CMigrate.exe 2014-03-20 07:06:58 BAEA09EE9DEFB8A3935DB5EE0CF4A0F0 3748008 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\ACCICONS.EXE 2014-03-20 07:06:56 79F0E929756083D13F8B12BE81DDD435 49344 ----a-w- C:\Program Files\Microsoft Office 15\root\flattener\Flattener.exe 2014-03-20 07:06:54 3C683E054BBBA0298C0C832E8F31B460 39584 ----a-w- C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\AppSharingHookController64.exe 2014-03-20 07:06:13 9CEBD254DBD4F993FA725B1D24FBCA9A 207016 ----a-w- C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonX86\Microsoft Shared\OFFICE15\MSOXMLED.EXE 2014-03-20 07:06:10 906900B79D2E3E92E7AE7EBC9B033EB4 5282008 ----a-w- C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonX86\Microsoft Shared\OFFICE15\CMigrate.exe 2014-03-20 07:06:02 DE941F3CED149407E87C8A891A213EE7 9596592 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\PDFREFLOW.EXE 2014-03-20 07:05:52 60CDF4CE24508FD4229A2C13E9152ADC 871088 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\protocolhandler.exe 2014-03-20 07:05:51 B190C7EA0BFC6EB0BECB7EF50F93F25E 471784 ----a-w- C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonX86\Microsoft Shared\DW\DWTRIG20.EXE 2014-03-20 07:05:44 96EA29F53F0475C4189008DFA22A89C3 6077128 ----a-w- C:\Program Files\Microsoft Office 15\root\integration\OneDriveSetup.exe 2014-03-20 07:05:43 976032BC08E01FEB72B7DA3D130E406E 150704 ----a-w- C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonX86\Microsoft Shared\OFFICE15\FLTLDR.EXE 2014-03-20 07:05:39 D40360ABC2BB38EE202F145CAF204E99 614568 ----a-w- C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonX86\Microsoft Shared\OFFICE15\MSOICONS.EXE 2014-03-20 07:05:36 30B5F9FB0C35AE6B4A0851D24CE2EE8B 150600 ----a-w- C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonX86\Microsoft Shared\Source Engine\OSE.EXE 2014-03-20 07:05:10 5AA45B527D0D2F81981B612D67E55257 1052376 ----a-w- C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonX86\Microsoft Shared\OFFICE15\OLicenseHeartbeat.exe 2014-03-20 07:05:09 F74059079C0B2765D65F441A088A27EE 87240 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\NAMECONTROLSERVER.EXE 2014-03-20 07:05:09 DE9C861E206EAF7460EA661A972CE8B3 449216 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\MSOSYNC.EXE 2014-03-20 07:05:09 C272F3AE1507C4B980F0139769E3BEE4 228544 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\CLVIEW.EXE 2014-03-20 07:05:09 B4EDA8CED8EABBE6ED1A4FD72856364C 700064 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\MSQRY32.EXE 2014-03-20 07:05:09 89FCD7CB454386CEDEB5DFF98637830A 50392 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\SETLANG.EXE 2014-03-20 07:05:09 7EB78DC7EEAAFE9ECD788D1CCBC8EFAB 22592 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\Wordconv.exe 2014-03-20 07:05:09 737EA3265DCBB170BAC158CDE3E4044E 496320 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\MSOUC.EXE 2014-03-20 07:05:09 182315495531E8395EDA537739C87460 72384 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\MSOHTMED.EXE 2014-03-20 07:05:08 B68A2A445B1EA8DC4723B6BE66304785 515312 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\IEContentService.exe 2014-03-20 07:05:08 A74CDAB687DE7546311B812B53EC8E01 21921440 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\excelcnv.exe 2014-03-20 07:05:08 A3DA00344F6EB652E2F8F9FAC52E0D51 478936 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\SELFCERT.EXE 2014-03-20 07:05:08 10EF557CEBF0F1D19F48855133F5F7E8 194224 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\ONENOTEM.EXE 2014-03-20 07:05:08 03F8848F17FB20DAD7D643D9714049A9 4522688 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\GRAPH.EXE 2014-03-20 07:05:05 CD5D1F07737BAF90F92D6A437CDCEF36 40680 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\SCANPST.EXE 2014-03-20 07:05:04 F0B54CE877BE92DB307905FB49259266 33440 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\AppSharingHookController.exe 2014-03-20 07:05:04 E5F8713DBA4D8F2ABFBC5E0C7A345C18 1296080 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\OcPubMgr.exe 2014-03-20 07:05:04 56DC4D308DE1EF6198274660048AA29F 569592 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\ORGCHART.EXE 2014-03-20 07:05:04 3A2C7CE18457029CC91BDE20281FA9CD 1026728 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\misc.exe 2014-03-20 07:04:55 85E2E27495F52C4C36531D43BE9240EF 153256 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\CNFNOT32.EXE 2014-03-20 07:04:55 72218C42471E6D1C106876F9ABE70360 6482600 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\lynchtmlconv.exe 2014-03-20 07:04:55 65DAD88F354EFCB1DBA46A4EF9D58A0A 665248 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\UcMapi.exe 2014-03-20 07:04:55 587CD7A6BB885BA952D174872E4ED899 33968 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\msoev.exe 2014-03-20 07:04:55 32FE71AE4EE91571815CE2AE25613827 33976 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\msotd.exe 2014-03-20 07:04:54 B74555FD620D081FF7F9EBA0675EBF9C 526024 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\VPREVIEW.EXE 2014-03-20 07:04:05 F170BD726C1A6F671D1D9C36436255A8 578256 ----a-w- C:\Program Files\Microsoft Office 15\root\integration\Integrator.exe 2014-03-20 07:04:04 E2D5C4F5840450CA6AE01E316EB6648E 145064 ----a-w- C:\Program Files\Microsoft Office 15\root\client\AppVDllSurrogate64.exe 2014-03-20 07:04:04 98078DAB179FFB1F357467359FE61C03 311552 ----a-w- C:\Program Files\Microsoft Office 15\root\client\AppVLP.exe 2014-03-20 07:04:03 3FA9563D3B17BA815BE83F377471DF67 124056 ----a-w- C:\Program Files\Microsoft Office 15\root\client\AppVDllSurrogate32.exe 2014-03-20 07:02:42 A91EF581FCE15DD22AFACA095FF2A894 8367808 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\GROOVE.EXE 2014-03-20 07:02:42 8FD61DCE4D5D606E6BDF639BB9D4C8B4 1783976 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\INFOPATH.EXE 2014-03-20 07:02:42 713F53F2CD8B8539CF40D905826FDBC9 18943648 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\lync.exe 2014-03-20 07:02:41 87BCA29FD741011AD2994137CD6DCCC7 18919080 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\OUTLOOK.EXE 2014-03-20 07:02:40 B7E5324C04196EDA2B88639FA62D3EB8 1755816 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\ONENOTE.EXE 2014-03-20 07:02:39 2399755D8D4B095B08AE6A701A887295 15514792 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\MSACCESS.EXE 2014-03-20 06:25:18 5D13990A811A0DF1B5AF555CB881D510 1923232 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\WINWORD.EXE 2014-03-20 06:25:16 A8F5567DBC6C63FA2F74ACEA09F05CA6 1846872 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\POWERPNT.EXE 2014-03-20 06:25:14 EA534F953E499B175E4A32E0BFE1CB50 10744488 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\MSPUB.EXE 2014-03-20 06:25:13 1E69A61B1451FC8941097750F56579C8 25700512 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\EXCEL.EXE 2014-03-20 06:24:51 E2E1CBE5538C94DDC27F18E1F21708B5 934056 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\FIRSTRUN.EXE 2014-03-20 06:24:42 F9362E1DBABA93E104B0ECDA6D5C7012 90280 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\perfboost.exe 2014-03-19 08:05:04 57FFC647042C5CD7BE0CAF5787C16DF1 820424 ----a-w- C:\Program Files\Microsoft Office 15\ClientX64\officec2rclient.exe 2014-03-19 08:05:04 03F5F6B3FA0BACD7D385C5CE6D309F7A 2169016 ----a-w- C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe === C: other files == 2014-03-20 19:56:34 436B0F6143421C2B98ED8D1B99B3B868 14534 ----a-w- C:\Users\lieke_000\AppData\Local\Microsoft\Windows\INetCache\IE\4SXB4OHH\Outlook.zip 2014-03-20 07:10:15 6228BC27853F8B281D6892464D850173 86424 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\Ocomprivate.zip 2014-03-20 07:09:50 59634C7CA5ED0E9021EA004B00AE0C00 70525 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\Microsoft.Lync.Utilities.zip 2014-03-20 07:09:50 4F51304540C11D43F8EDEF3B7E2D6AE3 85318 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\Microsoft.Lync.Model.zip 2014-03-19 19:40:42 95125CDB81059005550903555D37CFE6 79979 ----a-w- C:\Users\Johan&Linette\AppData\Local\Microsoft\Windows\INetCache\Low\IE\SBUP6QW7\nos[1].zip 2014-03-18 16:38:09 95125CDB81059005550903555D37CFE6 79979 ----a-w- C:\Users\lieke_000\AppData\Local\Microsoft\Windows\INetCache\Low\IE\XDV8K6J9\nos[1].zip 2014-03-18 05:43:25 13B160C1913F012BD1615EB1398D3779 1530712 ----a-w- C:\Windows\System32\drivers\dxgkrnl.sys 2014-03-18 05:43:23 22EDC0DE06A0272DFA4C7B47B5D8E377 382808 ----a-w- C:\Windows\System32\drivers\dxgmms1.sys 2014-03-18 05:43:22 A1A5E79C0D1352AFDC08328A623DA051 408576 ----a-w- C:\Windows\System32\drivers\rdbss.sys 2014-03-18 05:43:21 D22EB844EB57D016CC34178AC86456DF 325464 -c--a-w- C:\Windows\System32\drivers\USBXHCI.SYS 2014-03-18 05:43:20 DF355EB0199198728027962DCFCDE5FB 121088 -c--a-w- C:\Windows\System32\drivers\USBAUDIO.sys ==== Startup Registry Enabled ====================== [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "COS"="C:\Program Files\COMODO\cCloud\cCloud.exe" [HKEY_USERS\S-1-5-21-1756456079-1928014174-753649899-1001\Software\Microsoft\Windows\CurrentVersion\Run] "DAEMON Tools Lite"="C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe -autorun" "GoogleDriveSync"="C:\Program Files (x86)\Google\Drive\googledrivesync.exe /autostart" "Google Update"="C:\Users\Johan&Linette\AppData\Local\Google\Update\GoogleUpdate.exe /c" "COS"="C:\Program Files\COMODO\cCloud\cCloud.exe" "Spotify Web Helper"="C:\Users\Johan&Linette\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" [HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run] "COS"="C:\Program Files\COMODO\cCloud\cCloud.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "BlueStacks Agent"="C:\Program Files (x86)\BlueStacks\HD-Agent.exe" "SunJavaUpdateSched"="C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" "CopyCurrentUserName-Path"="C:\Program Files (x86)\Filternet\bin\CopyCurrentUserName.exe" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "DAEMON Tools Lite"="C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe -autorun" "GoogleDriveSync"="C:\Program Files (x86)\Google\Drive\googledrivesync.exe /autostart" "Google Update"="C:\Users\Johan&Linette\AppData\Local\Google\Update\GoogleUpdate.exe /c" "COS"="C:\Program Files\COMODO\cCloud\cCloud.exe" "Spotify Web Helper"="C:\Users\Johan&Linette\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" ==== Startup Registry Enabled x64 ====================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" "HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" "Persistence"="C:\WINDOWS\system32\igfxpers.exe" "SynTPEnh"="%ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe " ==== Startup Registry Disabled x64 ====================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\cphs] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\gupdate] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\gupdatem] ==== Task Scheduler Jobs ====================== C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job --a-------- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [11-09-2013 05:36] C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job --a-------- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [11-09-2013 05:36] C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1756456079-1928014174-753649899-1001Core.job --a-------- C:\Users\JohanLinette\AppData\Local\Google\Update\GoogleUpdate.exe [] C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1756456079-1928014174-753649899-1001UA.job --a-------- C:\Users\JohanLinette\AppData\Local\Google\Update\GoogleUpdate.exe [] C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1756456079-1928014174-753649899-1005Core.job --a-------- C:\Users\lieke_000\AppData\Local\Google\Update\GoogleUpdate.exe [08-10-2013 11:41] C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1756456079-1928014174-753649899-1005UA.job --a-------- C:\Users\lieke_000\AppData\Local\Google\Update\GoogleUpdate.exe [08-10-2013 11:41] C:\WINDOWS\tasks\Synaptics TouchPad Enhancements.job --a-------- C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [20-12-2012 23:23] ==== Other Scheduled Tasks ====================== "C:\WINDOWS\SysNative\tasks\CCleanerSkipUAC" ["C:\Program Files\CCleaner\CCleaner.exe"] "C:\WINDOWS\SysNative\tasks\CreateChoiceProcessTask" [C:\Windows\BrowserChoice\browserchoice.exe] "C:\WINDOWS\SysNative\tasks\GoogleUpdateTaskMachineCore" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe] "C:\WINDOWS\SysNative\tasks\GoogleUpdateTaskMachineUA" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe] "C:\WINDOWS\SysNative\tasks\GoogleUpdateTaskUserS-1-5-21-1756456079-1928014174-753649899-1001Core" [C:\Users\Johan&Linette\AppData\Local\Google\Update\GoogleUpdate.exe] "C:\WINDOWS\SysNative\tasks\GoogleUpdateTaskUserS-1-5-21-1756456079-1928014174-753649899-1001UA" [C:\Users\Johan&Linette\AppData\Local\Google\Update\GoogleUpdate.exe] "C:\WINDOWS\SysNative\tasks\GoogleUpdateTaskUserS-1-5-21-1756456079-1928014174-753649899-1005Core" [C:\Users\lieke_000\AppData\Local\Google\Update\GoogleUpdate.exe] "C:\WINDOWS\SysNative\tasks\GoogleUpdateTaskUserS-1-5-21-1756456079-1928014174-753649899-1005UA" [C:\Users\lieke_000\AppData\Local\Google\Update\GoogleUpdate.exe] "C:\WINDOWS\SysNative\tasks\User_Feed_Synchronization-{17D30C5D-E3BD-40A9-ACD8-06FE19BC2A52}" [C:\WINDOWS\system32\msfeedssync.exe] "C:\WINDOWS\SysNative\tasks\User_Feed_Synchronization-{8355B284-5A28-4B27-8DF2-5D40A7FC0712}" [C:\WINDOWS\system32\msfeedssync.exe] "C:\WINDOWS\SysNative\tasks\User_Feed_Synchronization-{99D796A2-5E65-4A98-BFCE-A576DFB1DBBA}" [C:\WINDOWS\system32\msfeedssync.exe] "C:\WINDOWS\SysNative\tasks\User_Feed_Synchronization-{B94AF0C6-F0BD-46F0-8D21-6ACE6D90D28B}" [C:\WINDOWS\system32\msfeedssync.exe] ==== Firefox Extensions Registry ====================== [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions] "fmconverter@gmail.com"="C:\Program Files (x86)\Freemake\Freemake Video Converter\BrowserPlugin\Firefox" [25-02-2014 19:48] ==== Chrome Look ====================== HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions jbolfgndggfhhpbnkgnpjkfhinclbigj - C:\Program Files (x86)\Freemake\Freemake Video Converter\BrowserPlugin\Chrome\Freemake.Plugin.Chrome.crx[03-02-2014 12:46] ==== C:\zoek_backup content ====================== C:\zoek_backup (files=0 folders=0 0 bytes) ==== EOF on ma 24-03-2014 at 8:18:49,63 ======================