Zoek.exe v5.0.0.0 Updated 14-April-2014 Tool run by Michelle on do 17-04-2014 at 8:02:16,87. Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x86 Running in: Normal Mode Internet Access Detected Launched: C:\Users\Michelle\Desktop\zoek.exe [Scan all users] [Script inserted] [Checkboxes used] ==== System Restore Info ====================== 17-4-2014 8:05:15 Zoek.exe System Restore Point Created Succesfully. ==== Empty Folders Check ====================== C:\Program Files\Malwarebytes' Anti-Malware deleted successfully C:\Program Files\Symantec deleted successfully C:\PROGRA~2\Oracle deleted successfully C:\Users\Michelle\AppData\Roaming\Malwarebytes deleted successfully C:\Users\Michelle\AppData\Local\CrashDumps deleted successfully ==== Deleting CLSID Registry Keys ====================== ==== Deleting CLSID Registry Values ====================== ==== Deleting Services ====================== ==== Registry Fix Code ====================== Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] ""=- [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iLivid] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"=- [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bpsvc.exe] [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browsersafeguard.exe] [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dprotectsvc.exe] [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\protectedsearch.exe] [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rjatydimofu.exe] [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotection.exe] [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotector.exe] [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\snapdo.exe] [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst32.exe] [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst64.exe] [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\utiljumpflip.exe] ==== Deleting Files \ Folders ====================== C:\Users\Michelle\AppData\Local\iLivid not found C:\Program Files\Common Files\DVDVideoSoft\bin deleted C:\Users\Michelle\AppData\LocalLow\DataMngr deleted C:\Windows\system32\sasnative32.exe deleted ==== Files Recently Created / Modified ====================== ====== C:\Windows ==== ====== C:\Users\Michelle\AppData\Local\Temp ==== ====== Java Cache ===== 2014-04-17 04:22:29 C1BBA7F1278F193AB584FFF460DB5E2A 17878 ----a-w- C:\Users\Michelle\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\12\eef218c-70d33fb2 2014-04-17 04:22:25 415FC9732A3F4D89A0E01251CD66E136 646 ----a-w- C:\Users\Michelle\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\17\49a00451-1b7c9af7 2014-04-17 04:22:25 B0E91612C88AC7190C74790DEB9BC5BF 425 ----a-w- C:\Users\Michelle\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\17\49a00451-aa56bb018d5de3a531ee91cc4857f0f479656e5370ebf87789e721aaaf530ebc-6.0.lap 2014-04-17 04:22:23 415FC9732A3F4D89A0E01251CD66E136 646 ----a-w- C:\Users\Michelle\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\18\3cb32f52-44c7c04a 2014-04-17 04:22:26 34FA8033B50A3F99D3AB8209C72C0ABA 6860 ----a-w- C:\Users\Michelle\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\43\1ca2666b-4e7316bd ====== C:\Windows\system32 ===== 2014-04-17 04:21:11 6EA69D2312F3571F6F8BEADD224165E8 264616 ----a-w- C:\Windows\System32\javaws.exe 2014-04-17 04:21:02 B42338F92D3BDADA79B6BE553E72587C 94632 ----a-w- C:\Windows\System32\WindowsAccessBridge.dll 2014-04-17 04:21:02 9533FE0A942E00114047140B42DF8E3D 175016 ----a-w- C:\Windows\System32\java.exe 2014-04-17 04:21:02 37C15684482B4D596316735DCEEE939A 175528 ----a-w- C:\Windows\System32\javaw.exe 2014-04-16 18:34:32 F37167FCDB661FD4B54CAD4755ABDD61 32256 ----a-w- C:\Windows\System32\TsUsbGDCoInstaller.dll 2014-04-16 18:34:31 D60E27D4BD5A91FCD17D2CB27F86738E 12800 ----a-w- C:\Windows\System32\TsUsbRedirectionGroupPolicyControl.exe 2014-04-16 18:34:30 AB5EFB103DB01C1912C9D2F545EA5621 17920 ----a-w- C:\Windows\System32\wksprtPS.dll 2014-04-16 18:34:30 A90F47CDCC0898733596B5070039FC15 14336 ----a-w- C:\Windows\System32\TsUsbRedirectionGroupPolicyExtension.dll 2014-04-16 18:34:30 8DEEE20D8D30E9B0FBDCA31E58A027BD 53248 ----a-w- C:\Windows\System32\tsgqec.dll 2014-04-16 18:34:30 2EFB1279E7BEA7D12D9F4D6508D27880 50176 ----a-w- C:\Windows\System32\MsRdpWebAccess.dll 2014-04-16 18:34:29 AF40D823F3B03C7899AEF2293F84D0D7 76288 ----a-w- C:\Windows\System32\TSWbPrxy.exe 2014-04-16 18:34:29 A5FE03D57097A45B8E7A4A09C9B78695 5698048 ----a-w- C:\Windows\System32\mstscax.dll 2014-04-16 18:34:29 5E676B296B762E211D83B87635F2C330 855552 ----a-w- C:\Windows\System32\rdvidcrl.dll 2014-04-16 18:34:29 4676AAA9DDF52A50C829FEDB4EA81E54 1068544 ----a-w- C:\Windows\System32\mstsc.exe 2014-04-16 18:34:29 0FC6922517964E9D90DE84DC86F63E40 350208 ----a-w- C:\Windows\System32\wksprt.exe 2014-04-16 18:33:19 CE6921D33682C6C3DB8A45853CC69402 455168 ----a-w- C:\Windows\System32\vbscript.dll 2014-04-16 18:33:18 AA12D7A960DB78DD9690AB5B5DAE6586 440832 ----a-w- C:\Windows\System32\ieui.dll 2014-04-16 18:33:17 A127D17C354B473B0F4C6265538F5A2C 2724864 ----a-w- C:\Windows\System32\mshtml.tlb 2014-04-16 18:33:15 EDACA6C44D9CE200F899B7DB0F201DFF 164864 ----a-w- C:\Windows\System32\msrating.dll 2014-04-16 18:33:15 BB185D4A9362AA17CBCEC0768CDBF249 704512 ----a-w- C:\Windows\System32\ieapfltr.dll 2014-04-16 18:33:15 116632CE6DF92EA78C2B849E1279B1FA 4096 ----a-w- C:\Windows\System32\ieetwcollectorres.dll 2014-04-16 18:33:14 EBC35FE64056910A84485BEEB6DCCAC6 524288 ----a-w- C:\Windows\System32\msfeeds.dll 2014-04-16 18:33:14 7E9FE7DB43BC204E44F159F843E35C15 367616 ----a-w- C:\Windows\System32\dxtmsft.dll 2014-04-16 18:33:14 31385A6CAA31BE9D07B0B32E5AA99ABB 43008 ----a-w- C:\Windows\System32\jsproxy.dll 2014-04-16 18:33:13 E5E97E94DD9D69D8EE90CFA96156CD8A 575488 ----a-w- C:\Windows\System32\ie4uinit.exe 2014-04-16 18:33:13 34FC79C948EE2C5FD0CD699E7D7F91B7 244224 ----a-w- C:\Windows\System32\dxtrans.dll 2014-04-16 18:33:12 C9CA9803299EB6AFA34CB520BAAB083D 32256 ----a-w- C:\Windows\System32\JavaScriptCollectionAgent.dll 2014-04-16 18:33:12 82287FCFFA4A2D60FD744E3FEB3192C5 61952 ----a-w- C:\Windows\System32\iesetup.dll 2014-04-16 18:33:12 21BF6759685FD193715B483F2B3F21B1 112128 ----a-w- C:\Windows\System32\ieUnatt.exe 2014-04-16 18:33:12 0FDC1A576A3F40420882C0F7C4A66EAD 32768 ----a-w- C:\Windows\System32\iernonce.dll 2014-04-16 18:33:11 BECAA526B8A1823A36A1BA123B8C41A9 646144 ----a-w- C:\Windows\System32\MsSpellCheckingFacility.exe 2014-04-16 18:33:11 6557B48D53D653CFCCE3CB1CFA53A8E1 51200 ----a-w- C:\Windows\System32\ieetwproxystub.dll 2014-04-16 18:33:11 2101D94DED769CE86A3DE1152F4FCDF5 108032 ----a-w- C:\Windows\System32\ieetwcollector.exe 2014-04-16 18:33:11 0F4A295516781897FFB09B4CCF2E8798 592896 ----a-w- C:\Windows\System32\jscript9diag.dll 2014-04-16 18:33:07 E4E829EE073E046B0EB19B5FECB19B8C 1789440 ----a-w- C:\Windows\System32\wininet.dll 2014-04-16 18:33:07 76F58DB8F85C125E0D6B3AA42F3BF1D0 1143808 ----a-w- C:\Windows\System32\urlmon.dll 2014-04-16 18:33:07 05BD47136DE62FAFE9F95B40E4100144 2178048 ----a-w- C:\Windows\System32\iertutil.dll 2014-04-16 18:33:06 C4A383FD50FBD7E274DD41CF571DF898 1967104 ----a-w- C:\Windows\System32\inetcpl.cpl 2014-04-16 18:33:05 2AFBB91BBD2378933B26E6D68C140D1B 11745792 ----a-w- C:\Windows\System32\ieframe.dll 2014-04-16 18:33:04 EA85144F35EDE6EE25C484D4242FF2C8 17387008 ----a-w- C:\Windows\System32\mshtml.dll 2014-04-16 18:33:04 8C46360D6EF9D4C563FE834C4F287DA3 4254720 ----a-w- C:\Windows\System32\jscript9.dll 2014-04-16 18:27:57 AAB5D8C5ABE71873DC19ED004EF25009 792576 ----a-w- C:\Windows\System32\TSWorkspace.dll 2014-04-14 19:19:51 F74FFA7654702F81884BDB41EB80DAC2 868352 ----a-w- C:\Windows\System32\kernel32.dll ====== C:\Windows\system32\drivers ===== 2014-04-16 22:07:31 661B911FA04E73FB073FF9B1C9BD2E05 107736 ----a-w- C:\Windows\System32\drivers\MBAMSwissArmy.sys 2014-04-16 18:34:30 C6A5FBD4977305E1FA23E02C042DB463 49152 ----a-w- C:\Windows\System32\drivers\TsUsbFlt.sys 2014-04-14 19:19:53 F1A449D762657230629D8BFC107ABC14 149440 ----a-w- C:\Windows\System32\drivers\storport.sys 2014-04-14 19:19:53 EB34CE31FABD4DC4343FD2AD16D2CAF9 234432 ----a-w- C:\Windows\System32\drivers\msiscsi.sys 2014-04-14 19:19:53 5FB4F271032B6435F3B2252F577A4815 27072 ----a-w- C:\Windows\System32\drivers\Diskdump.sys 2014-04-14 19:19:51 C8DFF8D07755A66C7A4A738930F0FEAC 1212352 ----a-w- C:\Windows\System32\drivers\ntfs.sys ====== C:\Windows\Tasks ====== 2014-03-27 13:18:10 91F30ACF40C3C4DBBB96BCC08B785082 3878 ----a-w- C:\Windows\system32\Tasks\Adobe Flash Player Updater 2014-03-27 13:18:10 36344EEC09C2943A64AA0CDF701F8BA3 940 ----a-w- C:\Windows\Tasks\Adobe Flash Player Updater.job ====== C:\Windows\Temp ====== ======= C:\Program Files ===== 2014-04-17 05:42:56 -------- d-----w- C:\Program Files\CrystalDiskInfo 2014-04-17 04:33:13 -------- d-----w- C:\Program Files\trend micro 2014-04-17 04:21:22 -------- d-----w- C:\Program Files\Common Files\Java ======= C: ===== ====== C:\Users\Michelle\AppData\Roaming ====== 2014-04-16 20:56:12 -------- d-sh--w- C:\Users\Michelle\AppData\Locallow\EmieUserList 2014-04-16 20:50:02 -------- d-sh--w- C:\Users\Michelle\AppData\Local\EmieUserList 2014-04-16 20:50:02 -------- d-sh--w- C:\Users\Michelle\AppData\Local\EmieSiteList 2014-04-16 20:16:16 -------- d-sh--w- C:\Users\Michelle\AppData\Locallow\EmieSiteList 2014-04-16 18:31:41 -------- d-s---w- C:\Users\UpdatusUser\AppData\Roaming\Microsoft 2014-04-16 18:31:41 -------- d-----w- C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HomeCinema 2014-04-16 18:31:41 -------- d-----w- C:\Users\UpdatusUser\AppData\Roaming\Media Center Programs 2014-04-16 18:31:41 -------- d-----w- C:\Users\UpdatusUser\AppData\Local\Temp 2014-04-16 18:31:41 -------- d-----w- C:\Users\UpdatusUser\AppData\Local\Microsoft Help 2014-04-16 18:31:41 -------- d-----w- C:\Users\UpdatusUser\AppData\Local\Microsoft 2014-04-16 18:31:41 -------- d-----r- C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance 2014-04-16 18:31:41 -------- d-----r- C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories ====== C:\Users\Michelle ====== 2014-04-17 05:42:57 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CrystalDiskInfo 2014-04-17 04:32:13 69CA82A7482A00D8EE063D2B97FC4338 781383 ----a-w- C:\Users\Michelle\Desktop\RSIT.exe 2014-04-17 04:21:02 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2014-04-16 18:31:42 -------- d-----w- C:\Users\UpdatusUser\Searches 2014-04-16 18:31:42 -------- d-----w- C:\Users\UpdatusUser\Contacts 2014-04-16 18:31:41 6FC234AD3752E1267B34FB12BCD6718B 20 --sh--w- C:\Users\UpdatusUser\ntuser.ini 2014-04-16 18:31:41 -------- d--h--w- C:\Users\UpdatusUser\AppData 2014-04-16 18:31:41 -------- d-----w- C:\Users\UpdatusUser\Saved Games 2014-04-16 18:31:41 -------- d-----r- C:\Users\UpdatusUser\Videos 2014-04-16 18:31:41 -------- d-----r- C:\Users\UpdatusUser\Pictures 2014-04-16 18:31:41 -------- d-----r- C:\Users\UpdatusUser\Music 2014-04-16 18:31:41 -------- d-----r- C:\Users\UpdatusUser\Links 2014-04-16 18:31:41 -------- d-----r- C:\Users\UpdatusUser\Favorites 2014-04-16 18:31:41 -------- d-----r- C:\Users\UpdatusUser\Downloads 2014-04-16 18:31:41 -------- d-----r- C:\Users\UpdatusUser\Documents 2014-04-16 18:31:41 -------- d-----r- C:\Users\UpdatusUser\Desktop ====== C: exe-files == 2014-04-17 05:42:57 CFB53367C3EE3712EC2D4544147F67E3 1015256 ----a-w- C:\Program Files\CrystalDiskInfo\DiskInfo.exe 2014-04-17 05:42:57 58D792999661319566219EF469647D5B 46552 ----a-w- C:\Program Files\CrystalDiskInfo\CdiResource\AlertMail.exe 2014-04-17 05:42:56 7ACD99EE21D72D86406CB936868879B6 1274479 ----a-w- C:\Program Files\CrystalDiskInfo\unins000.exe 2014-04-17 04:33:14 9A2347903D6EDB84C10F288BC0578C1C 388608 ----a-w- C:\Program Files\trend micro\Michelle.exe 2014-04-17 04:32:13 69CA82A7482A00D8EE063D2B97FC4338 781383 ----a-w- C:\Users\Michelle\Desktop\RSIT.exe 2014-04-17 04:21:11 6EA69D2312F3571F6F8BEADD224165E8 264616 ----a-w- C:\Windows\System32\javaws.exe 2014-04-17 04:21:02 9533FE0A942E00114047140B42DF8E3D 175016 ----a-w- C:\Windows\System32\java.exe 2014-04-17 04:21:02 37C15684482B4D596316735DCEEE939A 175528 ----a-w- C:\Windows\System32\javaw.exe 2014-04-17 04:18:34 3842C46F2FBC7522EF625F1833530804 145408 ----a-w- C:\Users\Michelle\AppData\LocalLow\Sun\Java\jre1.7.0_55\lzma.exe 2014-04-16 18:34:31 D60E27D4BD5A91FCD17D2CB27F86738E 12800 ----a-w- C:\Windows\System32\TsUsbRedirectionGroupPolicyControl.exe 2014-04-16 18:34:29 AF40D823F3B03C7899AEF2293F84D0D7 76288 ----a-w- C:\Windows\System32\TSWbPrxy.exe 2014-04-16 18:34:29 4676AAA9DDF52A50C829FEDB4EA81E54 1068544 ----a-w- C:\Windows\System32\mstsc.exe 2014-04-16 18:34:29 0FC6922517964E9D90DE84DC86F63E40 350208 ----a-w- C:\Windows\System32\wksprt.exe 2014-04-16 18:33:13 E5E97E94DD9D69D8EE90CFA96156CD8A 575488 ----a-w- C:\Windows\System32\ie4uinit.exe 2014-04-16 18:33:12 21BF6759685FD193715B483F2B3F21B1 112128 ----a-w- C:\Windows\System32\ieUnatt.exe 2014-04-16 18:33:11 BECAA526B8A1823A36A1BA123B8C41A9 646144 ----a-w- C:\Windows\System32\MsSpellCheckingFacility.exe 2014-04-16 18:33:11 2101D94DED769CE86A3DE1152F4FCDF5 108032 ----a-w- C:\Windows\System32\ieetwcollector.exe 2014-04-16 18:33:07 F972DDD19A10F53D74021DDEAC07CCA6 470016 ----a-w- C:\Program Files\Internet Explorer\ieinstal.exe 2014-04-16 18:33:07 BEA4E0C0BA936E8A3DB24D1A37BF70BE 222720 ----a-w- C:\Program Files\Internet Explorer\ielowutil.exe 2014-04-16 18:33:06 0667ED9F8E905E1F73DB60ACCEDCBCA7 811728 ----a-w- C:\Program Files\Internet Explorer\iexplore.exe 2014-04-16 18:32:51 97B5936437A408F0A10CBE10C38C7BB9 295840 ----a-w- C:\ProgramData\NVIDIA\Updatus\Packages\00005234\drsupdate.17125755_RUNASUSER.exe 2014-04-16 18:32:30 0CF88A0DCD52961A0841CF7C0ED8D925 407328 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\installer.{4F0CA033-68B4-40A7-BAB1-615BD73D7BE3}\setup.exe 2014-04-16 18:31:54 0CF88A0DCD52961A0841CF7C0ED8D925 407328 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\installer.{8A4A4DAA-23B8-43A5-9361-37D18E49B14F}\setup.exe 2014-04-16 18:31:38 889EFA27900362F02C3642C4246D29CB 1163040 ----a-w- C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\ComUpdatus.exe 2014-04-16 18:31:38 4BAE67FFDC0E1AE2B4FB5FC21F07B65C 1364256 ----a-w- C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe 2014-04-16 18:31:38 12A4E92F5E20D5C76665C6E8C7AA6E7B 190752 ----a-w- C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\WLMerger.exe 2014-04-16 18:31:16 91AABD6600D3CDE1C5347C9BE15C9462 62240 ----a-w- C:\Program Files\NVIDIA Corporation\Display\nvsmartmaxapp.exe 2014-04-16 18:31:00 E97C9FC9A11F907E4C55B552A271BD6A 407328 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.{9C6BEBD8-EC9B-4CD9-8E44-8A3C514E2697}\setup.exe 2014-04-16 18:31:00 76D00DF731D23A541E89F7A27F672941 916768 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.{9C6BEBD8-EC9B-4CD9-8E44-8A3C514E2697}\nvxdsync.exe 2014-04-16 18:30:59 FCE54BAD203738C1FEE9FC33AFD6A305 1821984 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.{9C6BEBD8-EC9B-4CD9-8E44-8A3C514E2697}\NvTray.exe 2014-04-16 18:30:59 FAEFC55E4F7CED7DE6CB9EE5BC8827F9 662816 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.{9C6BEBD8-EC9B-4CD9-8E44-8A3C514E2697}\nvvsvc.exe 2014-04-16 18:30:59 91AABD6600D3CDE1C5347C9BE15C9462 62240 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.{9C6BEBD8-EC9B-4CD9-8E44-8A3C514E2697}\nvSmartMaxapp.exe 2014-04-16 18:30:59 764DAB39F855F489F8B042FF40BFDF34 5919520 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\Display.ControlPanel.{9C6BEBD8-EC9B-4CD9-8E44-8A3C514E2697}\nvcplui.exe 2014-04-16 18:30:51 E97C9FC9A11F907E4C55B552A271BD6A 407328 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\installer.{1CB664C4-4C86-4348-8A76-0E52B2D2BE5B}\setup.exe 2014-04-16 18:30:20 DA056D8CFAFF91965AA41B6978462787 29274816 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\Display.Driver.{B5B8046F-E231-49DB-B51C-1813336D9892}\NvCplSetupEng.exe 2014-04-16 18:30:20 B12A490B9F29FC2A8DFAD0103B8B9448 76096 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\Display.Driver.{B5B8046F-E231-49DB-B51C-1813336D9892}\nvsetup.exe 2014-04-16 18:30:20 889EFA27900362F02C3642C4246D29CB 1163040 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\NVIDIA.Update.{6DD68118-5B12-4678-AE93-D28BF08FFAD4}\ComUpdatus.exe 2014-04-16 18:30:20 54AD323F61A494ADDAC49919FD0C43BC 216864 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\Display.Driver.{B5B8046F-E231-49DB-B51C-1813336D9892}\dbInstaller.exe 2014-04-16 18:30:20 4BAE67FFDC0E1AE2B4FB5FC21F07B65C 1364256 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\NVIDIA.Update.{6DD68118-5B12-4678-AE93-D28BF08FFAD4}\daemonu.exe 2014-04-16 18:30:20 4663BE214179E94FFE00DC65AC6B04BB 71189848 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\Display.Driver.{B5B8046F-E231-49DB-B51C-1813336D9892}\NvCplSetupInt.exe 2014-04-16 18:30:20 12A4E92F5E20D5C76665C6E8C7AA6E7B 190752 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\NVIDIA.Update.{6DD68118-5B12-4678-AE93-D28BF08FFAD4}\WLMerger.exe 2014-04-16 18:29:39 0CF88A0DCD52961A0841CF7C0ED8D925 407328 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\installer.{131AA985-B58F-422B-9E55-BB30338E51CA}\setup.exe 2014-04-16 18:29:35 8CCE738AABA114CA933108BC5F5E8FD7 470632 ----a-w- C:\Windows\Temp\nvStInst.exe 2014-04-14 14:23:43 8FAE9109245E4B4FF42704ECFB86F1B6 8704216 ----a-w- C:\Program Files\Google\Update\Download\{4DC8B4CA-1BDA-483E-B5FA-D3C12E15B62D}\34.0.1847.116\34.0.1847.116_33.0.1750.154_chrome_updater.exe === C: other files == 2014-04-16 22:07:31 661B911FA04E73FB073FF9B1C9BD2E05 107736 ----a-w- C:\Windows\System32\drivers\MBAMSwissArmy.sys 2014-04-16 18:34:31 7E6E0797EB91F1D63641058416044313 26880 ----a-w- C:\Windows\System32\DriverStore\FileRepository\tsgenericusbdriver.inf_x86_neutral_9002d2f3f0cfc5e0\TsUsbGD.sys 2014-04-16 18:34:30 C6A5FBD4977305E1FA23E02C042DB463 49152 ----a-w- C:\Windows\System32\drivers\TsUsbFlt.sys 2014-04-16 18:32:58 FBEC0FD36ED61EFEE1E3063281EAB984 161056 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\HDAudio.Driver.{574942E0-0BBB-44B5-AF21-CE2871B14353}\nvhda32v.sys 2014-04-16 18:32:58 EFC9A7307691E3C3DB8D2AA81A778356 128672 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\HDAudio.Driver.{574942E0-0BBB-44B5-AF21-CE2871B14353}\nvhda32.sys 2014-04-16 18:32:58 916F3222ADCB635B64660FA235502A51 162592 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\HDAudio.Driver.{574942E0-0BBB-44B5-AF21-CE2871B14353}\nvhda64.sys 2014-04-16 18:32:58 6C1E27A52FCACBE347AE22B5E56C94B6 450848 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\Display.NVIRUSB.{5B51934C-3E82-488A-934D-EEFA8DDBBACE}\nvstusb64.sys 2014-04-16 18:32:58 554964B900AE2954B8B589B6287034AC 196384 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\HDAudio.Driver.{574942E0-0BBB-44B5-AF21-CE2871B14353}\nvhda64v.sys 2014-04-16 18:32:58 24CCD6E1D5FD8D27C65961EBCDC9AAF1 434592 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\Display.NVIRUSB.{5B51934C-3E82-488A-934D-EEFA8DDBBACE}\nvstusb32.sys 2014-04-16 18:32:27 FBEC0FD36ED61EFEE1E3063281EAB984 161056 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\HDAudio.Driver.{7EEAC283-AA54-4481-A038-69D82D5CAD45}\nvhda32v.sys 2014-04-16 18:32:27 EFC9A7307691E3C3DB8D2AA81A778356 128672 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\HDAudio.Driver.{7EEAC283-AA54-4481-A038-69D82D5CAD45}\nvhda32.sys 2014-04-16 18:32:27 916F3222ADCB635B64660FA235502A51 162592 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\HDAudio.Driver.{7EEAC283-AA54-4481-A038-69D82D5CAD45}\nvhda64.sys 2014-04-16 18:32:27 6C1E27A52FCACBE347AE22B5E56C94B6 450848 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\Display.NVIRUSB.{91A3EA09-8FFA-4888-8DDA-905D6BA1E804}\nvstusb64.sys 2014-04-16 18:32:27 554964B900AE2954B8B589B6287034AC 196384 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\HDAudio.Driver.{7EEAC283-AA54-4481-A038-69D82D5CAD45}\nvhda64v.sys 2014-04-16 18:32:27 24CCD6E1D5FD8D27C65961EBCDC9AAF1 434592 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\Display.NVIRUSB.{91A3EA09-8FFA-4888-8DDA-905D6BA1E804}\nvstusb32.sys 2014-04-14 19:19:53 F1A449D762657230629D8BFC107ABC14 149440 ----a-w- C:\Windows\System32\drivers\storport.sys 2014-04-14 19:19:53 EB34CE31FABD4DC4343FD2AD16D2CAF9 234432 ----a-w- C:\Windows\System32\DriverStore\FileRepository\iscsi.inf_x86_neutral_128be931e3e98b62\msiscsi.sys 2014-04-14 19:19:53 EB34CE31FABD4DC4343FD2AD16D2CAF9 234432 ----a-w- C:\Windows\System32\drivers\msiscsi.sys 2014-04-14 19:19:53 5FB4F271032B6435F3B2252F577A4815 27072 ----a-w- C:\Windows\System32\drivers\Diskdump.sys 2014-04-14 19:19:51 C8DFF8D07755A66C7A4A738930F0FEAC 1212352 ----a-w- C:\Windows\System32\drivers\ntfs.sys ==== Startup Registry Enabled ====================== [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun" [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun" [HKEY_USERS\S-1-5-21-289552252-3632903440-3116316817-1000\Software\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe /autoRun" [HKEY_USERS\S-1-5-21-289552252-3632903440-3116316817-1003\Software\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun" [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce] "mctadmin"="C:\Windows\System32\mctadmin.exe" [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce] "mctadmin"="C:\Windows\System32\mctadmin.exe" [HKEY_USERS\S-1-5-21-289552252-3632903440-3116316817-1003\Software\Microsoft\Windows\CurrentVersion\RunOnce] "mctadmin"="C:\Windows\System32\mctadmin.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "HP Software Update"="C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe" "APSDaemon"="C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe" "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" "SunJavaUpdateSched"="C:\Program Files\Common Files\Java\Java Update\jusched.exe" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe /autoRun" ==== Startup Registry Disabled ====================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\iLivid] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="iLivid" "hkey"="HKCU" "command"="\"C:\\Users\\Michelle\\AppData\\Local\\iLivid\\iLivid.exe\" -autorun" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Skype] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="Skype" "hkey"="HKCU" "command"="\"C:\\Program Files\\Skype\\Phone\\Skype.exe\" /minimized /regrun" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\RichVideo] ==== Startup Folders ====================== 2013-04-05 11:45:09 1280 ----a-w- C:\Users\Michelle\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Schermopname en Snel starten.lnk ==== Task Scheduler Jobs ====================== C:\Windows\tasks\Adobe Flash Player Updater.job --a------ C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [27-03-2014 15:18] C:\Windows\tasks\GoogleUpdateTaskMachineCore.job --a------ C:\Program Files\Google\Update\GoogleUpdate.exe [04-04-2013 00:16] C:\Windows\tasks\GoogleUpdateTaskMachineUA.job --a------ C:\Program Files\Google\Update\GoogleUpdate.exe [04-04-2013 00:16] ==== Other Scheduled Tasks ====================== "C:\Windows\system32\tasks\Adobe Flash Player Updater" [C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe] "C:\Windows\system32\tasks\CCleanerSkipUAC" ["C:\Program Files\CCleaner\CCleaner.exe"] "C:\Windows\system32\tasks\CreateChoiceProcessTask" [C:\Windows\System32\browserchoice.exe] "C:\Windows\system32\tasks\GoogleUpdateTaskMachineCore" [C:\Program Files\Google\Update\GoogleUpdate.exe] "C:\Windows\system32\tasks\GoogleUpdateTaskMachineUA" [C:\Program Files\Google\Update\GoogleUpdate.exe] "C:\Windows\system32\tasks\HPCustParticipation HP Officejet Pro 8500 A910" ["C:\Program Files\HP\HP Officejet Pro 8500 A910\Bin\HPCustPartic.exe"] "C:\Windows\system32\tasks\Norton WSC Integration" ["C:\Program Files\Norton Internet Security\Engine\21.2.0.38\WSCStub.exe"] "C:\Windows\system32\tasks\{CA0EAA64-4E6B-455A-8206-8925BCFCE655}" ["c:\program files\google\chrome\application\chrome.exe"] "C:\Windows\system32\tasks\Apple\AppleSoftwareUpdate" [C:\Program Files\Apple Software Update\SoftwareUpdate.exe] "C:\Windows\system32\tasks\Norton Internet Security\Norton Error Analyzer" [C:\Program Files\Norton Internet Security\Engine\21.2.0.38\SymErr.exe] "C:\Windows\system32\tasks\Norton Internet Security\Norton Error Processor" [C:\Program Files\Norton Internet Security\Engine\21.2.0.38\SymErr.exe] ==== Firefox Extensions Registry ====================== [HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions] "{BBDA0591-3099-440a-AA10-41764D9DB4DB}"="C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_21.1.0.18\IPSFF" [19-11-2013 17:03] ==== Chrome Look ====================== HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions aaaaabcbmongicmdegkmmfgdickgnnob - C:\Users\Michelle\AppData\Local\ilividmoviestoolbarha\GC\toolbar.crx[] mkfokfffehpeedafpekjeddnmnjhmcmk - C:\Program Files\Norton Internet Security\Engine\21.2.0.38\Exts\Chrome.crx[11-03-2014 22:44] Google Docs - Michelle\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake Google Drive - Michelle\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf YouTube - Michelle\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo Google Search - Michelle\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf Norton Identity Protection - Michelle\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk Google Wallet - Michelle\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda Gmail - Michelle\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia ==== Set IE to Default ====================== Old Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="https://www.google.nl/" New Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="https://www.google.nl/" ==== All HKCU SearchScopes ====================== HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes "DefaultScope"="{6A1806CD-94D4-4689-BA73-E35EA1EA9990}" {0633EE93-D776-472f-A0FF-E1416B8B2E3A} Unknown Url="Not_Found" {6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}" ==== Deleting CLSID Registry Keys ====================== HKEY_USERS\S-1-5-21-289552252-3632903440-3116316817-1000\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} deleted successfully ==== Deleting CLSID Registry Values ====================== ==== Deleting Registry Keys ====================== HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\aaaaabcbmongicmdegkmmfgdickgnnob deleted successfully HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iLivid deleted successfully ==== Empty IE Cache ====================== C:\Users\Michelle\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Michelle\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully ==== Empty FireFox Cache ====================== No FireFox Profiles found ==== Empty Chrome Cache ====================== C:\Users\Michelle\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully ==== Empty All Flash Cache ====================== Flash Cache Emptied Successfully ==== Empty All Java Cache ====================== Java Cache cleared successfully ==== C:\zoek_backup content ====================== C:\zoek_backup (files=121 folders=23 13938647 bytes) ==== Empty Temp Folders ====================== C:\Users\Default\AppData\Local\Temp emptied successfully C:\Users\Default User\AppData\Local\Temp emptied successfully C:\Users\Michelle\AppData\Local\Temp will be emptied at reboot C:\Users\UpdatusUser\AppData\Local\Temp emptied successfully C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully C:\Windows\Temp will be emptied at reboot ==== After Reboot ====================== ==== Empty Temp Folders ====================== C:\Windows\Temp successfully emptied C:\Users\Michelle\AppData\Local\Temp successfully emptied ==== Empty Recycle Bin ====================== C:\$RECYCLE.BIN successfully emptied ==== EOF on do 17-04-2014 at 8:22:06,87 ======================