Zoek.exe v5.0.0.0 Updated 14-April-2014 Tool run by Gebruiker on wo 16/04/2014 at 17:44:47,13. Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x64 Running in: Normal Mode Internet Access Detected Launched: C:\Users\Gebruiker\Desktop\zoek.exe [Scan all users] [Script inserted] [Checkboxes used] ==== System Restore Info ====================== ==== Empty Folders Check ====================== C:\PROGRA~2\COMMON~1\BOONTY Shared deleted successfully C:\PROGRA~2\COMMON~1\Symantec Shared deleted successfully C:\Program Files\log deleted successfully C:\PROGRA~3\Freemake deleted successfully C:\PROGRA~3\Oracle deleted successfully C:\PROGRA~3\Sony deleted successfully C:\Users\Gebruiker\AppData\Roaming\WinRAR deleted successfully C:\Users\Gebruiker\AppData\Local\DriverTuner deleted successfully C:\Users\Gebruiker\AppData\Local\Windows Live deleted successfully ==== Deleting CLSID Registry Keys ====================== ==== Deleting CLSID Registry Values ====================== ==== Deleting Services ====================== ==== Registry Fix Code x64 ====================== Windows Registry Editor Version 5.00 [-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"=- ==== Deleting Files \ Folders ====================== C:\Users\Gebruiker\.android deleted C:\Users\Gebruiker\AppData\Roaming\burnaware.ini deleted C:\Users\Gebruiker\AppData\Local\cache deleted C:\Windows\Syswow64\RegistryHelperLM.ocx deleted ==== Files Recently Created / Modified ====================== ====== C:\Windows ==== ====== C:\Users\GEBRUI~1\AppData\Local\Temp ==== ====== Java Cache ===== 2014-04-08 12:43:07 C1BBA7F1278F193AB584FFF460DB5E2A 17878 ----a-w- C:\Users\Gebruiker\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\12\eef218c-7fb894aa 2014-04-08 12:43:04 415FC9732A3F4D89A0E01251CD66E136 646 ----a-w- C:\Users\Gebruiker\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\17\49a00451-603df785 2014-04-08 12:43:03 415FC9732A3F4D89A0E01251CD66E136 646 ----a-w- C:\Users\Gebruiker\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\31\34e05d1f-5127fe8e 2014-04-08 12:43:04 34FA8033B50A3F99D3AB8209C72C0ABA 6860 ----a-w- C:\Users\Gebruiker\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\43\1ca2666b-72db06b8 ====== C:\Windows\SysWOW64 ===== 2014-04-14 17:39:46 AA12D7A960DB78DD9690AB5B5DAE6586 440832 ----a-w- C:\Windows\SysWOW64\ieui.dll 2014-04-14 17:39:45 CE6921D33682C6C3DB8A45853CC69402 455168 ----a-w- C:\Windows\SysWOW64\vbscript.dll 2014-04-14 17:39:43 A127D17C354B473B0F4C6265538F5A2C 2724864 ----a-w- C:\Windows\SysWOW64\mshtml.tlb 2014-04-14 17:39:41 7E9FE7DB43BC204E44F159F843E35C15 367616 ----a-w- C:\Windows\SysWOW64\dxtmsft.dll 2014-04-14 17:39:41 34FC79C948EE2C5FD0CD699E7D7F91B7 244224 ----a-w- C:\Windows\SysWOW64\dxtrans.dll 2014-04-14 17:39:40 EDACA6C44D9CE200F899B7DB0F201DFF 164864 ----a-w- C:\Windows\SysWOW64\msrating.dll 2014-04-14 17:39:40 EBC35FE64056910A84485BEEB6DCCAC6 524288 ----a-w- C:\Windows\SysWOW64\msfeeds.dll 2014-04-14 17:39:40 31385A6CAA31BE9D07B0B32E5AA99ABB 43008 ----a-w- C:\Windows\SysWOW64\jsproxy.dll 2014-04-14 17:39:39 C9CA9803299EB6AFA34CB520BAAB083D 32256 ----a-w- C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2014-04-14 17:39:39 82287FCFFA4A2D60FD744E3FEB3192C5 61952 ----a-w- C:\Windows\SysWOW64\iesetup.dll 2014-04-14 17:39:39 21BF6759685FD193715B483F2B3F21B1 112128 ----a-w- C:\Windows\SysWOW64\ieUnatt.exe 2014-04-14 17:39:39 0FDC1A576A3F40420882C0F7C4A66EAD 32768 ----a-w- C:\Windows\SysWOW64\iernonce.dll 2014-04-14 17:39:37 BB185D4A9362AA17CBCEC0768CDBF249 704512 ----a-w- C:\Windows\SysWOW64\ieapfltr.dll 2014-04-14 17:39:37 6557B48D53D653CFCCE3CB1CFA53A8E1 51200 ----a-w- C:\Windows\SysWOW64\ieetwproxystub.dll 2014-04-14 17:39:37 0F4A295516781897FFB09B4CCF2E8798 592896 ----a-w- C:\Windows\SysWOW64\jscript9diag.dll 2014-04-14 17:39:35 E4E829EE073E046B0EB19B5FECB19B8C 1789440 ----a-w- C:\Windows\SysWOW64\wininet.dll 2014-04-14 17:39:35 C4A383FD50FBD7E274DD41CF571DF898 1967104 ----a-w- C:\Windows\SysWOW64\inetcpl.cpl 2014-04-14 17:39:35 76F58DB8F85C125E0D6B3AA42F3BF1D0 1143808 ----a-w- C:\Windows\SysWOW64\urlmon.dll 2014-04-14 17:39:35 05BD47136DE62FAFE9F95B40E4100144 2178048 ----a-w- C:\Windows\SysWOW64\iertutil.dll 2014-04-14 17:39:33 EA85144F35EDE6EE25C484D4242FF2C8 17387008 ----a-w- C:\Windows\SysWOW64\mshtml.dll 2014-04-14 17:39:33 2AFBB91BBD2378933B26E6D68C140D1B 11745792 ----a-w- C:\Windows\SysWOW64\ieframe.dll 2014-04-14 17:39:32 8C46360D6EF9D4C563FE834C4F287DA3 4254720 ----a-w- C:\Windows\SysWOW64\jscript9.dll 2014-04-11 16:35:05 F3F99A772EC3D9435B93D220E40436AE 72440 ------w- C:\Windows\SysWOW64\pxhpinst.exe 2014-04-11 16:35:05 D5823799FD16223806A86CFBC9223377 116472 ------w- C:\Windows\SysWOW64\pxcpyi64.exe 2014-04-11 16:35:05 C578134E37B9EABE7A6BF38242908E4F 770048 ----a-w- C:\Windows\SysWOW64\CDDBUISony.dll 2014-04-11 16:35:05 C4498BB288D462DA5D6A407C937526F0 589824 ----a-w- C:\Windows\SysWOW64\CddbMusicIDSony.dll 2014-04-11 16:35:05 C1E66615103CC72472906BEF5DF3275A 64760 ------w- C:\Windows\SysWOW64\pxinsa64.exe 2014-04-11 16:35:05 A7A7EA4F2BEB67194C5330D4AEDE3BD3 1329912 ------w- C:\Windows\SysWOW64\pxsfs.dll 2014-04-11 16:35:05 9DFD7CA53B06658DECAA35E7A76D2C98 118520 ------w- C:\Windows\SysWOW64\pxinsi64.exe 2014-04-11 16:35:05 9B2451220ACE914651EF2668EDF94D64 655360 ----a-w- C:\Windows\SysWOW64\CDDBControlSony.dll 2014-04-11 16:35:05 990C465293B7D53E8E83E367BACA1848 64760 ------w- C:\Windows\SysWOW64\pxcpya64.exe 2014-04-11 16:35:05 896A134ECD0CF1C75318409B1EDB1895 73728 ----a-w- C:\Windows\SysWOW64\CddbLinkSony.dll 2014-04-11 16:35:05 2D15091A0530A7F008D4AEA6E1BA1F9A 129784 ------w- C:\Windows\SysWOW64\pxafs.dll 2014-04-11 16:35:05 0AC0241362ED728A75695A9CD09082F6 532480 ----a-w- C:\Windows\SysWOW64\CddbPlaylist2Sony.dll 2014-04-11 16:35:04 46DCF5255134254D4D34AA4C7503B9B5 379640 ------w- C:\Windows\SysWOW64\pxwave.dll 2014-04-11 16:35:04 454CB3FCA343B5612E808ABA75311273 39672 ------w- C:\Windows\SysWOW64\vxblock.dll 2014-04-11 16:35:04 408BF95B64BB699ECFC7795C61B2C0B3 183032 ------w- C:\Windows\SysWOW64\pxmas.dll 2014-04-11 16:35:04 3D77F22936F9DC46E7DC4978D45C262B 527096 ------w- C:\Windows\SysWOW64\px.dll 2014-04-11 16:35:04 14FE9514EE2B3D21C2D6C94A6CB9B707 498424 ------w- C:\Windows\SysWOW64\pxdrv.dll 2014-04-09 17:01:17 B60F64D60603B3E5E9C1B142947A88E1 443080 ----a-w- C:\Windows\SysWOW64\GSService.exe 2014-04-09 08:57:45 A30AB03E7C837A17AC70E67E63B8E2F6 2048 ----a-w- C:\Windows\SysWOW64\user.exe 2014-04-09 08:57:45 9F3D88540DB73F5213D5044CB50006DF 7680 ----a-w- C:\Windows\SysWOW64\instnm.exe 2014-04-09 08:57:45 76161B9D78A275F8F28DD67436013110 1114112 ----a-w- C:\Windows\SysWOW64\kernel32.dll 2014-04-09 08:57:45 2E1D6624EE2C3F454CADF09DC59E78B0 25600 ----a-w- C:\Windows\SysWOW64\setup16.exe 2014-04-09 08:57:45 1F76F7CB3C690ACB985C2FD419383B49 14336 ----a-w- C:\Windows\SysWOW64\ntvdm64.dll 2014-04-09 08:57:45 1E886E327F37F34CC7465F1605D1F3CD 5120 ----a-w- C:\Windows\SysWOW64\wow32.dll ====== C:\Windows\SysWOW64\drivers ===== 2014-04-11 16:35:26 98F3ABC312BC0C660BA3F3B47782455E 35319 ----a-w- C:\Windows\SysWOW64\drivers\NETMD031.sys 2014-04-11 16:35:26 986ACDECE933131288F1957DC359865F 38951 ----a-w- C:\Windows\SysWOW64\drivers\NETMDUSB.sys 2014-04-11 16:35:26 55621D89CE500092CB3F136BED3C2854 36679 ----a-w- C:\Windows\SysWOW64\drivers\NETMD052.sys 2014-04-11 16:35:26 417334447945C9E111FFD881F7BF4D08 36232 ----a-w- C:\Windows\SysWOW64\drivers\NETMD033.sys ====== C:\Windows\Sysnative ===== 2014-04-14 17:39:47 7446786E7092ABE122D372F95E6ED74B 574976 ----a-w- C:\Windows\Sysnative\ieui.dll 2014-04-14 17:39:46 FFF555C177D9F2B79B5C3146BED09FB1 548352 ----a-w- C:\Windows\Sysnative\vbscript.dll 2014-04-14 17:39:43 6A8AA25D37F89E40B834F34950E3B89B 2724864 ----a-w- C:\Windows\Sysnative\mshtml.tlb 2014-04-14 17:39:42 D6067F7EE060C5D6D79008AD591B4E3B 33792 ----a-w- C:\Windows\Sysnative\iernonce.dll 2014-04-14 17:39:42 964C89BC8A52A260D68C90FDDEB862E2 38400 ----a-w- C:\Windows\Sysnative\JavaScriptCollectionAgent.dll 2014-04-14 17:39:42 72116CC377FF4281B0132C397026D911 4096 ----a-w- C:\Windows\Sysnative\ieetwcollectorres.dll 2014-04-14 17:39:42 3F498856C68725717195C16568FE19D0 586240 ----a-w- C:\Windows\Sysnative\ie4uinit.exe 2014-04-14 17:39:41 E0D95345D1EBB54F28E958782B9C0CE0 453120 ----a-w- C:\Windows\Sysnative\dxtmsft.dll 2014-04-14 17:39:41 CFBA793F678EB3855052ECF99357A9A1 296960 ----a-w- C:\Windows\Sysnative\dxtrans.dll 2014-04-14 17:39:41 3F547245C78F4847B73EDDFD4A2F7E12 752640 ----a-w- C:\Windows\Sysnative\jscript9diag.dll 2014-04-14 17:39:40 E7161E2C66FF9B1E87C30FC9D2497ABB 195584 ----a-w- C:\Windows\Sysnative\msrating.dll 2014-04-14 17:39:40 CB57E934280D346AE0A9B053DAA284C5 51200 ----a-w- C:\Windows\Sysnative\jsproxy.dll 2014-04-14 17:39:40 75AD355828187145A60E3DC7BAF7B0F3 628736 ----a-w- C:\Windows\Sysnative\msfeeds.dll 2014-04-14 17:39:39 A3F9A9E46BDDBB8B20B7CF3EEDB990F2 66048 ----a-w- C:\Windows\Sysnative\iesetup.dll 2014-04-14 17:39:39 1BF215FF4DF6DE10D2F81A2CE85157D2 139264 ----a-w- C:\Windows\Sysnative\ieUnatt.exe 2014-04-14 17:39:38 37D0FB9E5E8EDA40B66FC3FB3D660261 23549440 ----a-w- C:\Windows\Sysnative\mshtml.dll 2014-04-14 17:39:36 EBAD8A4D048ED257E4A45F6356541F86 846336 ----a-w- C:\Windows\Sysnative\ieapfltr.dll 2014-04-14 17:39:36 A3A132CBE48AF0324466469F2CAAE8A2 111616 ----a-w- C:\Windows\Sysnative\ieetwcollector.exe 2014-04-14 17:39:36 915D8A9E112C97C90C654F792B6B28B9 48640 ----a-w- C:\Windows\Sysnative\ieetwproxystub.dll 2014-04-14 17:39:36 710FD0E362A1A5C087DB90C1BAC46411 940032 ----a-w- C:\Windows\Sysnative\MsSpellCheckingFacility.exe 2014-04-14 17:39:35 F220BA78AB542C70211D73AE4729B2CD 2260480 ----a-w- C:\Windows\Sysnative\wininet.dll 2014-04-14 17:39:35 32417AE8280276968E5C551ED85D3525 1400832 ----a-w- C:\Windows\Sysnative\urlmon.dll 2014-04-14 17:39:35 1F8534A19A66275C863DE17645CB2A13 2767360 ----a-w- C:\Windows\Sysnative\iertutil.dll 2014-04-14 17:39:34 A14BB2F5F6457738AAA11367F5172A05 13551104 ----a-w- C:\Windows\Sysnative\ieframe.dll 2014-04-14 17:39:34 1654093C8BD3342997D27B71684ACCE8 2043904 ----a-w- C:\Windows\Sysnative\inetcpl.cpl 2014-04-14 17:39:32 BF25489459C7A762DD7B3186C7E3984D 5784064 ----a-w- C:\Windows\Sysnative\jscript9.dll 2014-04-09 08:57:45 D2A513EE880D71BDE7F0257F38B9D019 1163264 ----a-w- C:\Windows\Sysnative\kernel32.dll 2014-04-09 08:57:45 74959C718FF4594369645F35B7DF19C4 16384 ----a-w- C:\Windows\Sysnative\ntvdm64.dll 2014-04-09 08:57:45 7434E01FBCA3CB86539C39412A31D5E1 362496 ----a-w- C:\Windows\Sysnative\wow64win.dll 2014-04-09 08:57:45 2A107B611C91CD256466C58C0D776E9D 243712 ----a-w- C:\Windows\Sysnative\wow64.dll 2014-04-09 08:57:45 0F090A77E664CB0F70AB8D3B230B760C 13312 ----a-w- C:\Windows\Sysnative\wow64cpu.dll ====== C:\Windows\Sysnative\drivers ===== 2014-04-11 16:35:05 F3B76C18AFA4E9053CABAEC601A71431 3584 ------w- C:\Windows\Sysnative\drivers\cdralw2k.sys 2014-04-11 16:35:05 E4B1040C951BFCCFE38821DEDE653F2B 3584 ------w- C:\Windows\Sysnative\drivers\cdr4_xp.sys 2014-04-11 16:35:05 5D6C8E778F0218FCD2CCA0EFBC9766CA 52760 ------w- C:\Windows\Sysnative\drivers\PxHlpa64.sys 2014-04-09 17:01:26 DC8DA1D0E82B583EF7CB2F97F7981CA6 34504 ----a-w- C:\Windows\Sysnative\drivers\WmaCAudio.sys 2014-04-09 08:57:47 96BB922A0981BC7432C8CF52B5410FE6 274880 ----a-w- C:\Windows\Sysnative\drivers\msiscsi.sys 2014-04-09 08:57:46 B3222734D80013D2C73841B0C549FA63 27584 ----a-w- C:\Windows\Sysnative\drivers\Diskdump.sys 2014-04-09 08:57:46 A3F0BC5897F9D3786A3CB695B163633A 190912 ----a-w- C:\Windows\Sysnative\drivers\storport.sys 2014-04-09 08:57:43 1A29A59A4C5BA6F8C85062A613B7E2B2 1684928 ----a-w- C:\Windows\Sysnative\drivers\ntfs.sys ====== C:\Windows\Tasks ====== 2014-04-09 13:58:21 A63EB05BF05F68C3F8E22B419C561C61 3166 ----a-w- C:\Windows\Sysnative\Tasks\{CB7FFCAB-21A8-4FA4-A20B-E7DA6EEDD506} 2014-04-09 13:55:11 742DE919D877F2649936CE896591BAB5 3170 ----a-w- C:\Windows\Sysnative\Tasks\{A09C0C9A-0F14-412B-BA76-C407342D8AB2} 2014-04-06 15:00:10 1B834727983073D744013AF78E4B5ACD 3172 ----a-w- C:\Windows\Sysnative\Tasks\{C66532AA-90D3-4919-B1DC-506A5AADF330} 2014-03-29 13:26:17 -------- d-----w- C:\Windows\Sysnative\Tasks\2BrightSparks 2014-03-29 13:17:04 0848DA0B3CD6174F1CCC843B0C192A98 3166 ----a-w- C:\Windows\Sysnative\Tasks\{8BB79E59-4C38-4FDF-B308-8FC2DFDAD4A9} ====== C:\Windows\Temp ====== ======= C:\Program Files ===== 2014-04-16 15:30:47 -------- d-----w- C:\Program Files\trend micro ======= C:\PROGRA~2 ===== 2014-04-11 16:34:14 -------- d-----w- C:\PROGRA~2\Sony 2014-04-11 16:33:10 -------- d-----w- C:\PROGRA~2\COMMON~1\Sony Shared 2014-04-09 17:01:16 -------- d-----w- C:\PROGRA~2\WMAConvert 2014-04-09 16:21:41 -------- d-----w- C:\PROGRA~2\NCH Software ======= C: ===== ====== C:\Users\Gebruiker\AppData\Roaming ====== 2014-04-15 07:45:01 -------- d-sh--w- C:\Users\Gebruiker\AppData\Locallow\EmieUserList 2014-04-15 07:44:57 -------- d-sh--w- C:\Users\Gebruiker\AppData\Local\EmieUserList 2014-04-15 07:44:57 -------- d-sh--w- C:\Users\Gebruiker\AppData\Local\EmieSiteList 2014-04-15 07:44:54 -------- d-sh--w- C:\Users\Gebruiker\AppData\Locallow\EmieSiteList 2014-04-11 16:37:59 -------- d-----w- C:\Windows\sysWoW64\config\systemprofile\AppData\Roaming\Sony Corporation 2014-04-11 16:33:11 -------- d-----w- C:\Users\Gebruiker\AppData\Roaming\Sony Corporation 2014-04-09 17:04:46 -------- d-----w- C:\Users\Gebruiker\AppData\Local\WMAConvert 2014-04-08 14:56:59 -------- d-----w- C:\Users\Gebruiker\AppData\Roaming\Publish Providers 2014-04-08 14:17:54 -------- d-----w- C:\Users\Gebruiker\AppData\Local\Sony 2014-04-08 14:17:07 -------- d-----w- C:\Users\Gebruiker\AppData\Roaming\Sony 2014-04-08 14:13:32 -------- d-----w- C:\Users\Gebruiker\AppData\Roaming\rmi 2014-03-29 13:26:09 -------- d-----w- C:\Users\Gebruiker\AppData\Roaming\2BrightSparks ====== C:\Users\Gebruiker ====== 2014-04-11 17:27:28 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SonicStage 2014-04-11 16:38:07 -------- d-----w- C:\ProgramData\SonicStage 2014-04-11 16:34:53 -------- d-----w- C:\ProgramData\Sony Corporation 2014-04-06 15:23:36 -------- d-----w- C:\ProgramData\NCH Software 2014-04-06 14:58:52 F06CA7A90EFC5F194F03515D81422C70 983320 ----a-w- C:\Users\Gebruiker\Downloads\sonicstage [1].exe ====== C: exe-files == 2014-04-16 15:44:09 E7FF88E8332C118C474DFF0843C0769F 544 ----a-w- C:\$RECYCLE.BIN\S-1-5-21-3843751949-1623791028-3433357071-1000\$IU8X2KK.exe 2014-04-16 15:30:49 9A2347903D6EDB84C10F288BC0578C1C 388608 ----a-w- C:\Program Files\trend micro\Gebruiker.exe 2014-04-16 15:28:39 662C39FC1E27131551D557862CEC47F0 935175 ----a-w- C:\$RECYCLE.BIN\S-1-5-21-3843751949-1623791028-3433357071-1000\$RU8X2KK.exe 2014-04-14 17:39:45 E0155A11B26C7D5347069AB7ACB62D02 222720 ----a-w- C:\Program Files\Internet Explorer\ielowutil.exe 2014-04-14 17:39:45 BEA4E0C0BA936E8A3DB24D1A37BF70BE 222720 ----a-w- C:\Program Files (x86)\Internet Explorer\ielowutil.exe 2014-04-14 17:39:44 F972DDD19A10F53D74021DDEAC07CCA6 470016 ----a-w- C:\Program Files (x86)\Internet Explorer\ieinstal.exe 2014-04-14 17:39:44 C5C7E33308BAE18BD9F59F9A93E85D33 482816 ----a-w- C:\Program Files\Internet Explorer\ieinstal.exe 2014-04-14 17:39:42 3F498856C68725717195C16568FE19D0 586240 ----a-w- C:\Windows\System32\ie4uinit.exe 2014-04-14 17:39:39 21BF6759685FD193715B483F2B3F21B1 112128 ----a-w- C:\Windows\SysWOW64\ieUnatt.exe 2014-04-14 17:39:39 1BF215FF4DF6DE10D2F81A2CE85157D2 139264 ----a-w- C:\Windows\System32\ieUnatt.exe 2014-04-14 17:39:36 A3A132CBE48AF0324466469F2CAAE8A2 111616 ----a-w- C:\Windows\System32\ieetwcollector.exe 2014-04-14 17:39:36 710FD0E362A1A5C087DB90C1BAC46411 940032 ----a-w- C:\Windows\System32\MsSpellCheckingFacility.exe 2014-04-14 17:39:35 EA8386CA87165460D39A1D29FF11080B 809680 ----a-w- C:\Program Files\Internet Explorer\iexplore.exe 2014-04-14 17:39:35 0667ED9F8E905E1F73DB60ACCEDCBCA7 811728 ----a-w- C:\Program Files (x86)\Internet Explorer\iexplore.exe 2014-04-11 17:27:32 FBDA3A577E7220BDB6268A50B65F4599 102400 ----a-w- C:\Program Files (x86)\Common Files\Sony Shared\AVLib\SsDbConnection.exe 2014-04-11 17:27:29 DF1084369BB585C942B2833F07C1561D 816696 ----a-w- C:\Program Files (x86)\Sony\SonicStage\OMG2OMA.exe 2014-04-11 17:27:29 B4B2758DFA670D16899844CCE84C3AF4 1201720 ----a-w- C:\Program Files (x86)\Sony\SonicStage\Omgbkup.exe 2014-04-11 17:27:29 A8E1FA44ECE595C5079C71C27C8BBD99 5961272 ----a-w- C:\Program Files (x86)\Sony\SonicStage\Omgjbox.exe 2014-04-11 17:27:29 55441807D77662649AE4A1F59D493FAB 603704 ----a-w- C:\Program Files (x86)\Sony\SonicStage\Ojbsir.exe 2014-04-11 17:27:29 51F8BB1D69E7FA5F1861F360BBE503CF 603704 ----a-w- C:\Program Files (x86)\Sony\SonicStage\Omg1to2.exe 2014-04-11 17:27:28 CF0B15AB9FE311D3EDD0228682D1DA29 65536 ----a-w- C:\Program Files (x86)\Sony\SonicStage\JETCOMP.exe 2014-04-11 17:27:28 C11889D3188261C58F03292E151E457D 38456 ----a-w- C:\Program Files (x86)\Sony\SonicStage\AppReg.exe 2014-04-11 17:27:28 977AAA4398D7D6FA65D973F5B3F54E40 112184 ----a-w- C:\Program Files (x86)\Sony\SonicStage\Data\Temp\Module\Common Files\Sony Shared\AVLib\SsBeSvc.exe 2014-04-11 17:27:28 977AAA4398D7D6FA65D973F5B3F54E40 112184 ----a-w- C:\Program Files (x86)\Common Files\Sony Shared\AVLib\SsBeSvc.exe 2014-04-11 17:27:28 756E371B3B86A3D3039926D32EAC0E8D 75320 ----a-w- C:\Program Files (x86)\Sony\SonicStage\Data\Temp\Module\Common Files\Sony Shared\AVLib\SSScsiSV.exe 2014-04-11 17:27:28 756E371B3B86A3D3039926D32EAC0E8D 75320 ----a-w- C:\Program Files (x86)\Common Files\Sony Shared\AVLib\SSScsiSV.exe 2014-04-11 17:27:28 0F30B7AC2B0505ADC1E9325916365DF0 117200 ----a-w- C:\Program Files (x86)\Sony\SonicStage\Data\Temp\setup.exe 2014-04-11 17:27:28 0F30B7AC2B0505ADC1E9325916365DF0 117200 ----a-w- C:\Program Files (x86)\InstallShield Installation Information\{A0EB195B-5876-48E6-879D-33D4B2102610}\setup.exe 2014-04-11 16:35:25 61F6193135358D2BDC35C9343A1DA532 28672 ----a-w- C:\Program Files (x86)\Sony\Personal Audio Driver\CopyInf.exe 2014-04-11 16:35:25 57C8AB8909CE62190AEECE7FA301F5B1 155648 ----a-w- C:\Program Files (x86)\Sony\Personal Audio Driver\UnUsb.exe 2014-04-11 16:35:25 1108B166160D6023AF76435B074052B6 455600 ----a-w- C:\Program Files (x86)\InstallShield Installation Information\{73F1BDB7-11E1-11D5-9DC6-00C04F2FC33B}\setup.exe 2014-04-11 16:35:05 F3F99A772EC3D9435B93D220E40436AE 72440 ------w- C:\Windows\SysWOW64\pxhpinst.exe 2014-04-11 16:35:05 D5823799FD16223806A86CFBC9223377 116472 ------w- C:\Windows\SysWOW64\pxcpyi64.exe 2014-04-11 16:35:05 C1E66615103CC72472906BEF5DF3275A 64760 ------w- C:\Windows\SysWOW64\pxinsa64.exe 2014-04-11 16:35:05 9DFD7CA53B06658DECAA35E7A76D2C98 118520 ------w- C:\Windows\SysWOW64\pxinsi64.exe 2014-04-11 16:35:05 990C465293B7D53E8E83E367BACA1848 64760 ------w- C:\Windows\SysWOW64\pxcpya64.exe 2014-04-11 16:34:56 D38FAF17685FCD1F2FFA3B62739225F4 476728 ----a-w- C:\Program Files (x86)\Sony\SonicStage\SSAAD.exe 2014-04-11 16:34:48 E903505E79CED3178B296FC59C4E43D3 5632 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\10\01\Intel32\DotNetInstaller.exe 2014-04-11 16:34:45 3F213B4FC70EBC5F43CAAE8F5E8C91B2 311296 ----a-w- C:\Program Files (x86)\InstallShield Installation Information\{8ED3A392-28F1-4375-97AC-BF275B5855F9}\IS_Setup.exe 2014-04-11 16:33:10 EFF334C3CA0F320710D26F14C5C6EF93 118784 ----a-w- C:\Program Files (x86)\Common Files\Sony Shared\StopMusicServer\StopMusicServer.exe 2014-04-11 16:33:10 1AEB989E361AF85F5099DE3DA25457F4 56320 ----a-w- C:\Program Files (x86)\InstallShield Installation Information\{067D27FF-720F-421F-80E9-CF724DC5E072}\Setup.exe 2014-04-11 16:33:06 BF25EB6A1E0AA2FFF0CB190270B95418 610436 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe 2014-04-11 09:40:17 8FAE9109245E4B4FF42704ECFB86F1B6 8704216 ----a-w- C:\Users\Gebruiker\AppData\Local\Google\Update\Download\{4DC8B4CA-1BDA-483E-B5FA-D3C12E15B62D}\34.0.1847.116\34.0.1847.116_33.0.1750.154_chrome_updater.exe 2014-04-09 17:01:17 B60F64D60603B3E5E9C1B142947A88E1 443080 ----a-w- C:\Windows\SysWOW64\GSService.exe 2014-04-09 16:24:11 2B25475C24B096E1B7DB765BCDB4569E 155136 ----a-w- C:\Program Files (x86)\NCH Software\Components\oggenc\oggenc.exe 2014-04-09 16:21:42 1F083F5A820468E5438C32419525B798 110592 ----a-w- C:\Program Files (x86)\NCH Software\Components\mp3el\mp3enc.exe === C: other files == 2014-04-11 16:35:26 98F3ABC312BC0C660BA3F3B47782455E 35319 ----a-w- C:\Windows\SysWOW64\drivers\NETMD031.sys 2014-04-11 16:35:26 986ACDECE933131288F1957DC359865F 38951 ----a-w- C:\Windows\SysWOW64\drivers\NETMDUSB.sys 2014-04-11 16:35:26 55621D89CE500092CB3F136BED3C2854 36679 ----a-w- C:\Windows\SysWOW64\drivers\NETMD052.sys 2014-04-11 16:35:26 417334447945C9E111FFD881F7BF4D08 36232 ----a-w- C:\Windows\SysWOW64\drivers\NETMD033.sys 2014-04-11 16:35:25 98F3ABC312BC0C660BA3F3B47782455E 35319 ----a-w- C:\Program Files (x86)\Sony\Personal Audio Driver\NETMD031.sys 2014-04-11 16:35:25 986ACDECE933131288F1957DC359865F 38951 ----a-w- C:\Program Files (x86)\Sony\Personal Audio Driver\NETMDUSB.sys 2014-04-11 16:35:25 55621D89CE500092CB3F136BED3C2854 36679 ----a-w- C:\Program Files (x86)\Sony\Personal Audio Driver\NETMD052.sys 2014-04-11 16:35:25 417334447945C9E111FFD881F7BF4D08 36232 ----a-w- C:\Program Files (x86)\Sony\Personal Audio Driver\NETMD033.sys 2014-04-11 16:35:05 F3B76C18AFA4E9053CABAEC601A71431 3584 ------w- C:\Windows\System32\drivers\cdralw2k.sys 2014-04-11 16:35:05 E4B1040C951BFCCFE38821DEDE653F2B 3584 ------w- C:\Windows\System32\drivers\cdr4_xp.sys 2014-04-11 16:35:05 5D6C8E778F0218FCD2CCA0EFBC9766CA 52760 ------w- C:\Windows\System32\drivers\PxHlpa64.sys 2014-04-09 17:01:26 DC8DA1D0E82B583EF7CB2F97F7981CA6 34504 ----a-w- C:\Windows\System32\drivers\WmaCAudio.sys ==== Startup Registry Enabled ====================== [HKEY_USERS\S-1-5-21-3843751949-1623791028-3433357071-1000\Software\Microsoft\Windows\CurrentVersion\Run] "Google Update"="C:\Users\Gebruiker\AppData\Local\Google\Update\GoogleUpdate.exe /c" "Facebook Update"="C:\Users\Gebruiker\AppData\Local\Facebook\Update\FacebookUpdate.exe /c /nocrashserver" "HydraVisionDesktopManager"="C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe" "TomTomHOME.exe"="C:\Program Files (x86)\TomTom HOME 2\TomTomHOMERunner.exe -s" "SsAAD.exe"="C:\PROGRA~2\Sony\SONICS~1\SsAAD.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "BrMfcWnd"="C:\Program Files (x86)\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN" "ControlCenter3"="C:\Program Files (x86)\Brother\ControlCenter3\brctrcen.exe /autorun" "GrooveMonitor"="C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" "THX TruStudio NB Settings"="C:\Program Files (x86)\Creative\THX TruStudio\THXNBSet\THXAudNB.exe /r" "UpdReg"="C:\Windows\UpdReg.EXE" "XFastUsb"="C:\Program Files (x86)\XFastUsb\XFastUsb.exe" "APVXDWIN"="C:\Program Files (x86)\Panda Security\Panda Internet Security 2014\APVXDWIN.EXE /s" "SCANINICIO"="C:\Program Files (x86)\Panda Security\Panda Internet Security 2014\Inicio.exe" "StartCCC"="C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe MSRun" "Adobe ARM"="C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" "SunJavaUpdateSched"="C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "Google Update"="C:\Users\Gebruiker\AppData\Local\Google\Update\GoogleUpdate.exe /c" "Facebook Update"="C:\Users\Gebruiker\AppData\Local\Facebook\Update\FacebookUpdate.exe /c /nocrashserver" "HydraVisionDesktopManager"="C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe" "TomTomHOME.exe"="C:\Program Files (x86)\TomTom HOME 2\TomTomHOMERunner.exe -s" "SsAAD.exe"="C:\PROGRA~2\Sony\SONICS~1\SsAAD.exe" ==== Startup Registry Enabled x64 ====================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RTHDVCPL"="C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s" "THXCfg64"="C:\Windows\system32\RunDLL32.exe C:\Windows\system32\THXCfg64.dll,RunDLLEntry THXCfg64" "Logitech Download Assistant"="C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch" ==== Startup Folders ====================== 2013-05-14 17:45:03 991 ----a-w- C:\Users\Gebruiker\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\PopTray.lnk ==== Task Scheduler Jobs ====================== C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-3843751949-1623791028-3433357071-1000Core.job --a------ C:\Users\Gebruiker\AppData\Local\Facebook\Update\FacebookUpdate.exe [09/03/2013 22:33] C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-3843751949-1623791028-3433357071-1000UA.job --a------ C:\Users\Gebruiker\AppData\Local\Facebook\Update\FacebookUpdate.exe [09/03/2013 22:33] C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3843751949-1623791028-3433357071-1000Core.job --a------ C:\Users\Gebruiker\AppData\Local\Google\Update\GoogleUpdate.exe [14/05/2012 16:36] C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3843751949-1623791028-3433357071-1000UA.job --a------ C:\Users\Gebruiker\AppData\Local\Google\Update\GoogleUpdate.exe [14/05/2012 16:36] ==== Other Scheduled Tasks ====================== "C:\Windows\SysNative\tasks\AsrXTU" [C:\Program Files (x86)\ASRock Utility\AXTU\Bin\AsrXTU.exe] "C:\Windows\SysNative\tasks\CCleanerSkipUAC" ["C:\Program Files\CCleaner\CCleaner.exe"] "C:\Windows\SysNative\tasks\FacebookUpdateTaskUserS-1-5-21-3843751949-1623791028-3433357071-1000Core" [C:\Users\Gebruiker\AppData\Local\Facebook\Update\FacebookUpdate.exe] "C:\Windows\SysNative\tasks\FacebookUpdateTaskUserS-1-5-21-3843751949-1623791028-3433357071-1000UA" [C:\Users\Gebruiker\AppData\Local\Facebook\Update\FacebookUpdate.exe] "C:\Windows\SysNative\tasks\GoogleUpdateTaskUserS-1-5-21-3843751949-1623791028-3433357071-1000Core" [C:\Users\Gebruiker\AppData\Local\Google\Update\GoogleUpdate.exe] "C:\Windows\SysNative\tasks\GoogleUpdateTaskUserS-1-5-21-3843751949-1623791028-3433357071-1000UA" [C:\Users\Gebruiker\AppData\Local\Google\Update\GoogleUpdate.exe] "C:\Windows\SysNative\tasks\SidebarExecute" [C:\Program Files (x86)\Windows Sidebar\sidebar.exe] "C:\Windows\SysNative\tasks\{03165DF6-264B-4764-B7C5-F6460949C973}" [C:\Program Files (x86)\XFastUsb\XFastUsb.exe] "C:\Windows\SysNative\tasks\{69CB54CA-FA50-43A3-B548-B62CC5121BDC}" [C:\Program Files (x86)\XFastUsb\XFastUsb.exe] "C:\Windows\SysNative\tasks\{825AA3CA-DAD8-4074-AFF2-B201D3BFA90E}" ["c:\users\gebruiker\appdata\local\google\chrome\application\chrome.exe"] "C:\Windows\SysNative\tasks\{89B23FEA-48B9-4B3B-9048-34EF9823F59E}" [C:\Program Files (x86)\XFastUsb\XFastUsb.exe] "C:\Windows\SysNative\tasks\{A333D075-D689-4546-95EC-BA503EC8BE46}" [C:\Program Files (x86)\XFastUsb\XFastUsb.exe] "C:\Windows\SysNative\tasks\{AEDBD729-10A3-4A10-9CCA-58D908721C16}" [C:\Program Files (x86)\XFastUsb\XFastUsb.exe] "C:\Windows\SysNative\tasks\{BA7C2A8F-C1F2-4898-AA73-EDED94BCB180}" ["c:\users\gebruiker\appdata\local\google\chrome\application\chrome.exe"] "C:\Windows\SysNative\tasks\{BB86A209-53D1-4246-B356-C4F29C80642F}" [C:\Program Files (x86)\XFastUsb\XFastUsb.exe] "C:\Windows\SysNative\tasks\{C525B27D-143C-49EE-BE39-33A1816F9452}" [C:\Program Files (x86)\XFastUsb\XFastUsb.exe] "C:\Windows\SysNative\tasks\{CCEF9A1A-8717-4EB4-B8EB-178202C272FC}" [C:\Program Files (x86)\XFastUsb\XFastUsb.exe] "C:\Windows\SysNative\tasks\{F6D1FF3A-A868-4D9F-BE0E-71F66B35A509}" [C:\Program Files\Speccy\Speccy64.exe] ==== Firefox Extensions Registry ====================== [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions] "belgiumeid@eid.belgium.be"="C:\Program Files\Mozilla Firefox\extensions\belgiumeid@eid.belgium.be" [] ==== Firefox Extensions ====================== ProfilePath: C:\Users\GEBRUI~1\AppData\Roaming\TomTom\HOME\Profiles\s9pqxxuy.default - Map status indicator - C:\Program Files (x86)\TomTom HOME 2\xul\extensions\MapShare-status@tomtom.com - TomTom HOME default theme - C:\Program Files (x86)\TomTom HOME 2\xul\extensions\baseTheme@tomtom.com - Emulator - %ProfilePath%\extensions\Navcore.9.430.890926@tomtom.com - Emulator - %ProfilePath%\extensions\Navcore.9.465.1074274@tomtom.com - Emulator - %ProfilePath%\extensions\Navcore.9.510.1234792@tomtom.com AppDir: C:\Program Files (x86)\Mozilla Firefox - Belgium eID - %AppDir%\extensions\belgiumeid@eid.belgium.be ==== Firefox Plugins ====================== ==== Chrome Look ====================== Google Drive - Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf YouTube - Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo Google Search - Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf Google Wallet - Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda Gmail - Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia ==== Set IE to Default ====================== Old Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://google.be/" "Use Search Asst"="yes" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchUrl] "Default"="www.google.com" [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\SearchUrl] "Default"="www.google.com" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl] "Default"="www.google.com" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes] "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}] not found New Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://google.be/" "Use Search Asst"="no" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchUrl] "(Default)"="http://search.msn.com/results.asp?q=%s" [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\SearchUrl] "(Default)"="http://search.msn.com/results.asp?q=%s" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl] "(Default)"="http://search.msn.com/results.asp?q=%s" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes] "DefaultScope"="{6A1806CD-94D4-4689-BA73-E35EA1EA9990}" ==== All HKCU SearchScopes ====================== HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes {0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC" {6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}" ==== Deleting CLSID Registry Keys ====================== ==== Deleting CLSID Registry Values ====================== ==== Empty IE Cache ====================== C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Gebruiker\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Gebruiker\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully ==== Empty FireFox Cache ====================== No FireFox Profiles found ==== Empty Chrome Cache ====================== C:\Users\Gebruiker\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully ==== Empty All Flash Cache ====================== Flash Cache Emptied Successfully ==== Empty All Java Cache ====================== Java Cache cleared successfully ==== C:\zoek_backup content ====================== ==== Empty Temp Folders ====================== C:\Users\Default\AppData\Local\Temp emptied successfully C:\Users\Default User\AppData\Local\Temp emptied successfully C:\Users\Gebruiker\AppData\Local\Temp will be emptied at reboot C:\Users\Public\AppData\Local\Temp emptied successfully C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully C:\Windows\Temp will be emptied at reboot ==== After Reboot ====================== ==== Empty Temp Folders ====================== C:\Windows\Temp successfully emptied C:\Users\GEBRUI~1\AppData\Local\Temp successfully emptied ==== Empty Recycle Bin ====================== C:\$RECYCLE.BIN successfully emptied ==== EOF on wo 16/04/2014 at 18:22:38,00 ======================