Zoek.exe v5.0.0.0 Updated 14-April-2014 Tool run by els_v_000 on wo 14/05/2014 at 18:16:19,19. Microsoft Windows 8.1 6.3.9600 x64 Running in: Normal Mode Internet Access Detected Launched: C:\Users\els_v_000\Downloads\zoek (1).exe [Scan all users] [Script inserted] [Checkboxes used] ==== Running Processes ====================== C:\WINDOWS\system32\wininit.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe -k DcomLaunch C:\WINDOWS\system32\svchost.exe -k RPCSS C:\WINDOWS\system32\dwm.exe C:\WINDOWS\system32\nvvsvc.exe C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe C:\WINDOWS\system32\nvvsvc.exe C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted C:\WINDOWS\system32\svchost.exe -k netsvcs C:\WINDOWS\system32\svchost.exe -k LocalService C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted C:\WINDOWS\system32\svchost.exe -k NetworkService C:\Program Files (x86)\PHotkey\GFNEXSrv.exe C:\WINDOWS\system32\WLANExt.exe C:\WINDOWS\system32\conhost.exe C:\WINDOWS\System32\spoolsv.exe C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe C:\Program Files (x86)\CyberLink\PowerDVD10\Device\MediaServer\CLMSMonitorService.exe C:\Program Files (x86)\CyberLink\PowerDVD10\Device\MediaServer\CLMSServer.exe C:\Program Files\Intel\WiFi\bin\EvtEng.exe C:\Program Files\Intel\iCLS Client\HeciServer.exe C:\WINDOWS\system32\dashost.exe C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe C:\Program Files (x86)\PasswordBox\pbbtnService.exe C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe C:\Program Files\CyberLink\Shared files\RichVideo64.exe C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\WINDOWS\system32\taskhostex.exe C:\WINDOWS\system32\taskeng.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files (x86)\Avg Secure Update\AVG-Secure-Search-Update_0414c.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\wbem\wmiprvse.exe C:\WINDOWS\system32\wbem\unsecapp.exe C:\Program Files (x86)\PHotkey\PHotkey.exe C:\Program Files (x86)\PHotkey\MsgTranAgt.exe C:\Program Files (x86)\PHotkey\MsgTranAgt64.exe C:\Program Files (x86)\PHotkey\ATouch64.exe C:\Program Files (x86)\PHotkey\POSD.exe C:\Program Files (x86)\PHotkey\GPMTray.exe C:\Program Files\NVIDIA Corporation\Display\nvtray.exe C:\WINDOWS\system32\SearchIndexer.exe C:\Windows\System32\skydrive.exe C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe C:\WINDOWS\system32\igfxsrvc.exe C:\Windows\System32\igfxpers.exe C:\Users\els_v_000\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe C:\Program Files (x86)\Avg Secure Update\AVG-Secure-Search-Update_0414c.exe C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe C:\Program Files (x86)\AVG\AVG2014\avgui.exe C:\WINDOWS\SysWOW64\ctfmon.exe C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE C:\Program Files (x86)\PHotkey\HCSynApi.exe C:\WINDOWS\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe C:\Windows\System32\SettingSyncHost.exe C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Windows\System32\RuntimeBroker.exe C:\Program Files\WindowsApps\Microsoft.Reader_6.3.9654.17044_x64__8wekyb3d8bbwe\glcnd.exe C:\Program Files (x86)\AVG\AVG2014\avgcsrva.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\WINDOWS\system32\SearchProtocolHost.exe C:\WINDOWS\system32\SearchFilterHost.exe C:\Users\els_v_000\Downloads\zoek (1).exe C:\WINDOWS\system32\conhost.exe C:\WINDOWS\system32\wbem\wmiprvse.exe ==== System Restore Info ====================== 14/05/2014 18:20:29 Zoek.exe System Restore Point Created Succesfully. ==== Empty Folders Check ====================== C:\Users\els_v_000\AppData\Local\PackageStaging deleted successfully C:\Users\els_v_000\AppData\Local\Unity deleted successfully C:\Users\els_v_000\AppData\Local\VirtualStore deleted successfully ==== Deleting CLSID Registry Keys ====================== HKEY_USERS\S-1-5-21-1407927307-1300775257-3377467435-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233} deleted successfully HKEY_USERS\S-1-5-21-1407927307-1300775257-3377467435-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{95B7759C-8C7F-4BF1-B163-73684A933233} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233} deleted successfully ==== Deleting CLSID Registry Values ====================== ==== Installed Programs ====================== Ashampoo AppLauncher (Medion) v.1.0.0 AVG 2014 CCleaner CyberLink LabelPrint 2.5 CyberLink MediaEspresso 6.5 CyberLink PhotoDirector 3 CyberLink PhotoNow CyberLink Power2Go 8 CyberLink PowerDirector CyberLink PowerDVD 10 CyberLink PowerDVD Copy 1.5 CyberLink PowerRecover CyberLink YouCam 5 D3DX10 Dolby Home Theater v4 Fotogalerie Galerie de photos Google Chrome Google Update Helper Intel PROSet Wireless Intel(R) Management Engine Components Intel(R) Processor Graphics Intel(R) PROSet/Wireless for Bluetooth(R) + High Speed Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology Intel(R) Rapid Storage Technology Intel(R) SDK for OpenCL - CPU Only Runtime Package Intel(R) WiDi Intel© PROSet/Wireless WiFi Software Intel© Trusted Connect Service Client Mediathek Medion Home Cinema 10 Microsoft Application Error Reporting Microsoft Office Professional Plus 2013 - nl-nl Microsoft Silverlight Microsoft SQL Server 2005 Compact Edition [ENU] Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 Movie Maker MSVCRT MSVCRT110 MSVCRT110_amd64 NVIDIA-configuratiescherm 331.65 NVIDIA 3D Vision stuurprogramma 331.65 NVIDIA Grafisch stuurprogramma 331.65 NVIDIA Install Application NVIDIA Optimus 1.10.8 NVIDIA Stereoscopic 3D Driver NVIDIA Update Components Office 15 Click-to-Run Extensibility Component Office 15 Click-to-Run Licensing Component Office 15 Click-to-Run Localization Component PHotkey Photo Common Photo Gallery QuickLaunch Raccolta foto Realtek Ethernet Controller Driver Realtek High Definition Audio Driver Realtek USB 2.0 Card Reader Spotify Synaptics Pointing Device Driver Visual Studio 2012 x64 Redistributables Visual Studio 2012 x86 Redistributables VLC media player 2.1.3 Windows Live Windows Live Communications Platform Windows Live Essentials Windows Live Installer Windows Live Photo Common Windows Live PIMT Platform Windows Live SOXE Windows Live SOXE Definitions Windows Live UX Platform Windows Live UX Platform Language Pack ==== Deleting Services ====================== ==== Registry Fix Code ====================== Windows Registry Editor Version 5.00 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "AVG-Secure-Search-Update_0414c"=- ==== Registry Fix Code x64 ====================== Windows Registry Editor Version 5.00 [-HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}] ==== Deleting Files \ Folders ====================== C:\PROGRA~2\AVG SafeGuard toolbar deleted C:\WINDOWS\sysWoW64\config\systemprofile\AppData\LocalLow\AVG SafeGuard toolbar deleted C:\WINDOWS\tasks\AVG-Secure-Search-Update_0414c_rel.job deleted C:\WINDOWS\tasks\AVG-Secure-Search-Update_0414c_rmv.job deleted C:\windows\SysNative\tasks\AVG-Secure-Search-Update_0414c_rel deleted C:\windows\SysNative\tasks\AVG-Secure-Search-Update_0414c_rmv deleted "C:\Program Files (x86)\Avg Secure Update\AVG-Secure-Search-Update_0414c.exe" deleted ==== System Specs ====================== Windows: Windows Version 6.2 (Build 9200) Memory (RAM): 3978 MB CPU Info: Intel(R) Core(TM) i3-3120M CPU @ 2.50GHz CPU Speed: 2566,4 MHz Sound Card: Speakers (Realtek High Definiti | Realtek Digital Output (Realtek | Display Adapters: Intel(R) HD Graphics 4000 | Intel(R) HD Graphics 4000 | Intel(R) HD Graphics 4000 | NVIDIA GeForce GT 635M Monitors: 1x; Generic PnP Monitor | Screen Resolution: 1366 X 768 - 32 bit Network: Network Present Network Adapters: Microsoft Wi-Fi Direct Virtual Adapter | Intel(R) Centrino(R) Wireless-N 2230 | Realtek PCIe GBE Family-controller CD / DVD Drives: 1x (E: | ) E: TSSTcorpCDDVDW SN-208BB Ports: COM Ports NOT Present. LPT Port NOT Present. Mouse: 5 Button Wheel Mouse Present Hard Disks: C: 869,5GB | D: 60,0GB Hard Disks - Free: C: 803,2GB | D: 41,4GB Manufacturer *: American Megatrends Inc. BIOS Info: AT/AT COMPATIBLE | | MEDION - 1 Time Zone: Romance (standaardtijd) Motherboard *: Medion Akoya P6638 Country: Belgi‰ Language: NLB ==== System Specs (Software) ====================== Anti-Virus: AVG AntiVirus Free Edition 2014 On-access scanning disabled (Outdated) Anti-Spyware: AVG AntiVirus Free Edition 2014 disabled (Outdated) Default Browser: Google Chrome 34.0.1847.131 Internet Explorer Version: 11.0.9600.17105 Google Chrome version: 34.0.1847.131 ==== Files Recently Created / Modified ====================== ====== C:\WINDOWS ==== 2014-05-04 15:43:01 81394C91B7B5A7C799E249AE82491F13 2373784 ----a-w- C:\WINDOWS\explorer.exe ====== C:\Users\ELS_V_~1\AppData\Local\Temp ==== ====== Java Cache ===== ====== C:\WINDOWS\SysWOW64 ===== 2014-05-05 13:10:45 5869FBC754578A59C8C8635B99DB79DE 17384448 ----a-w- C:\WINDOWS\SysWOW64\mshtml.dll 2014-05-05 13:08:32 B5B3334F177CED627C2D7FE38235B6B1 2724864 ----a-w- C:\WINDOWS\SysWOW64\mshtml.tlb 2014-05-04 15:43:17 E7CCE55B7B97FC832F50104F1B889DE8 18679216 ----a-w- C:\WINDOWS\SysWOW64\shell32.dll 2014-05-04 15:43:08 27626FCB303C319FB9CCE15195A85CBC 5833728 ----a-w- C:\WINDOWS\SysWOW64\Windows.UI.Search.dll 2014-05-04 15:43:08 2169BB3BA0596881EE717A93EC60037D 35328 ----a-w- C:\WINDOWS\SysWOW64\Windows.Shell.Search.UriHandler.dll 2014-05-04 15:43:07 59B7E02F7800461CCDF115989AA108EE 11791360 ----a-w- C:\WINDOWS\SysWOW64\twinui.dll 2014-05-04 15:43:03 595653478434F2A8451EDA55CD954CED 1036288 ----a-w- C:\WINDOWS\SysWOW64\kernel32.dll 2014-05-04 15:43:00 119E091B5386379BC5AA598BE9440C75 2088160 ----a-w- C:\WINDOWS\SysWOW64\explorer.exe 2014-05-04 15:42:59 B4AAA9FD65FE6C83DCA2A230993CD893 2317824 ----a-w- C:\WINDOWS\SysWOW64\authui.dll 2014-05-04 15:42:57 EE7A35A24E496B41C8C9D10F31256A7C 828928 ----a-w- C:\WINDOWS\SysWOW64\twinui.appcore.dll 2014-05-04 15:42:57 21DDC5D6CFAC0A5FEE3B364A9B58A7CB 1764864 ----a-w- C:\WINDOWS\SysWOW64\dwmcore.dll 2014-05-04 15:42:55 E815C307EAF205E705A81A166FE87DB8 801792 ----a-w- C:\WINDOWS\SysWOW64\MFMediaEngine.dll 2014-05-04 15:42:55 2BDB085AA7ECA65D1793D150CEC960AF 1095488 ----a-w- C:\WINDOWS\SysWOW64\ole32.dll 2014-05-04 15:42:54 F14FFBD3C4862D385A001D5901717F91 888320 ----a-w- C:\WINDOWS\SysWOW64\Windows.Media.dll 2014-05-04 15:42:54 9264B57E8C0BCCA14F92EBA56B9B5106 800256 ----a-w- C:\WINDOWS\SysWOW64\ReAgent.dll 2014-05-04 15:42:54 775C3D06C408F4F093254B39637A6F1E 755712 ----a-w- C:\WINDOWS\SysWOW64\kerberos.dll 2014-05-04 15:42:53 FF0EE1B87E5DD7A82F7BB124D5CA8BB6 494592 ----a-w- C:\WINDOWS\SysWOW64\dnsapi.dll 2014-05-04 15:42:53 9BE4E10619FF30FAF796A55C418598DF 388408 ----a-w- C:\WINDOWS\SysWOW64\mfsvr.dll 2014-05-04 15:42:53 978F30B2763003341A405BD5EC107354 839168 ----a-w- C:\WINDOWS\SysWOW64\SearchFolder.dll 2014-05-04 15:42:53 67F3D0E0D8F009FF665A0E452C6F13E8 629760 ----a-w- C:\WINDOWS\SysWOW64\MrmCoreR.dll 2014-05-04 15:42:52 7C0E08F3F04ED8874E19DD23753DE2C6 356864 ----a-w- C:\WINDOWS\SysWOW64\wlidprov.dll 2014-05-04 15:42:51 F9EA1AF4C99275C56B47F2C1F436B5E9 1066496 ----a-w- C:\WINDOWS\SysWOW64\gdi32.dll 2014-05-04 15:42:51 268295FE5235105DE0D6FA92A5082C00 305768 ----a-w- C:\WINDOWS\SysWOW64\AUDIOKSE.dll 2014-05-04 15:42:51 25BBBE926A40DFC775292EE0F30E53A1 1200296 ----a-w- C:\WINDOWS\SysWOW64\propsys.dll 2014-05-04 15:42:50 FF841AB46649E68B8BEBE8E249AF9C04 326024 ----a-w- C:\WINDOWS\SysWOW64\AudioSes.dll 2014-05-04 15:42:50 D30975FD233E399744E2FB083F5E5545 222720 ----a-w- C:\WINDOWS\SysWOW64\dcomp.dll 2014-05-04 15:42:50 C06B6C8E002EDB492D93F2494E32F9CA 605184 ----a-w- C:\WINDOWS\SysWOW64\rasapi32.dll 2014-05-04 15:42:49 EB40EFEBE9EB4ACA3DD950A1AFA0F51B 171008 ----a-w- C:\WINDOWS\SysWOW64\SensorsApi.dll 2014-05-04 15:42:49 B4309F7821BDE5A31E1E4FB24ED97C5C 197632 ----a-w- C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll 2014-05-04 15:42:49 B3F1B6A3CC07E967B60584E7454B0890 390488 ----a-w- C:\WINDOWS\SysWOW64\netcfgx.dll 2014-05-04 15:42:49 155A7DA4DE39E78CD9D336E99644D794 300544 ----a-w- C:\WINDOWS\SysWOW64\wlanmsm.dll 2014-05-04 15:42:47 FE85E0B190DD141E4826FEC9F015FA18 139776 ----a-w- C:\WINDOWS\SysWOW64\AppxAllUserStore.dll 2014-05-04 15:42:47 FB32EF390BCAC55E11E0C5D12F4C9A45 1816576 ----a-w- C:\WINDOWS\SysWOW64\Display.dll 2014-05-04 15:42:47 F8DA43B0D93865B5DC8ADA71EDD29E2D 406512 ----a-w- C:\WINDOWS\SysWOW64\AudioEng.dll 2014-05-04 15:42:46 BD9306F715EA9B959EDB892614F6D581 94016 ----a-w- C:\WINDOWS\SysWOW64\userenv.dll 2014-05-04 15:42:46 5B8D7F29CA815E6DB156DF9853F0472D 2030080 ----a-w- C:\WINDOWS\SysWOW64\WsmSvc.dll 2014-05-04 15:42:46 0303523E283AB4D03590C9AE56A8386A 355832 ----a-w- C:\WINDOWS\SysWOW64\mfreadwrite.dll 2014-05-04 15:42:45 AFFB4EB53FC1D04495C8A5EC80B1EBCD 264192 ----a-w- C:\WINDOWS\SysWOW64\FWPUCLNT.DLL 2014-05-04 15:42:45 AF2A68F7890A680DAE0637EC49456A7B 85504 ----a-w- C:\WINDOWS\SysWOW64\davclnt.dll 2014-05-04 15:42:45 411201FFB3882554D5B833E6EC2EC649 254976 ----a-w- C:\WINDOWS\SysWOW64\pdh.dll 2014-05-04 15:42:45 22A64005AEA00E1BD5B1B19FB3566D11 230400 ----a-w- C:\WINDOWS\SysWOW64\wlanapi.dll 2014-05-04 15:42:45 1AFACFDB26C1B81586801AFF8BB0ABF1 222720 ----a-w- C:\WINDOWS\SysWOW64\spp.dll 2014-05-04 15:42:44 91F6883B61C0E5BEAE9B734D8E46829B 386560 ----a-w- C:\WINDOWS\SysWOW64\wlangpui.dll 2014-05-04 15:42:44 75DE8AED4FE16D07E7E22208BA88F0C5 887296 ----a-w- C:\WINDOWS\SysWOW64\aclui.dll 2014-05-04 15:42:44 37725B5D560398E5BF4DAF85E4F89249 70656 ----a-w- C:\WINDOWS\SysWOW64\w32tm.exe 2014-05-04 15:42:44 1FE14EDDEED70613E3A032182C7796FB 27136 ----a-w- C:\WINDOWS\SysWOW64\CredentialMigrationHandler.dll 2014-05-04 15:42:44 1CB5B87BF19380FB7208787C99C23965 98816 ----a-w- C:\WINDOWS\SysWOW64\drvinst.exe 2014-05-04 15:42:43 B918D220FCD67E5A4AF05018515E4C14 172544 ----a-w- C:\WINDOWS\SysWOW64\ReInfo.dll 2014-05-04 15:42:43 6FA6FA25BF69C0870BC24DBCE0CA304D 313344 ----a-w- C:\WINDOWS\SysWOW64\clusapi.dll 2014-05-04 15:42:43 59BB015A6FEB79D7911005D3E5F8C770 402432 ----a-w- C:\WINDOWS\SysWOW64\Windows.Graphics.Printing.dll 2014-05-04 15:42:43 503281E8561B81FC080887ECAF5F5E31 151040 ----a-w- C:\WINDOWS\SysWOW64\Windows.Devices.Scanners.dll 2014-05-04 15:42:42 A82DF6AB70BF4558B58D0B2827B61C3C 33792 ----a-w- C:\WINDOWS\SysWOW64\sxproxy.dll 2014-05-04 15:42:42 6F389E3C60FD27DA4322F78D2233E1FC 567296 ----a-w- C:\WINDOWS\SysWOW64\nshwfp.dll 2014-05-04 15:42:41 FBA4497DEBB5C07F5FA230618857A329 58368 ----a-w- C:\WINDOWS\SysWOW64\l2gpstore.dll 2014-05-04 15:42:41 E30E1007658BF21C1A71E6D47C712303 731648 ----a-w- C:\WINDOWS\SysWOW64\adtschema.dll 2014-05-04 15:42:41 97C5BA39BFD2C5BE09EA1FA3988BAAE2 11264 ----a-w- C:\WINDOWS\SysWOW64\wlanhlp.dll 2014-05-01 12:58:14 B9BFD6CE08BA3F9AB7BA3D19622824D6 164864 ----a-w- C:\WINDOWS\SysWOW64\msrating.dll 2014-05-01 12:45:15 BF816BA40B8B0BD2661D03DBDC2A6531 32768 ----a-w- C:\WINDOWS\SysWOW64\iernonce.dll 2014-05-01 12:44:23 7A2D384A9B072FE4E86341A01880AD08 51200 ----a-w- C:\WINDOWS\SysWOW64\ieetwproxystub.dll 2014-05-01 12:43:54 BAC704E260557DD80157594C3F5F3F5C 43008 ----a-w- C:\WINDOWS\SysWOW64\jsproxy.dll 2014-05-01 12:43:19 D4589A3246497F13CF3A901D9B117974 112128 ----a-w- C:\WINDOWS\SysWOW64\ieUnatt.exe ====== C:\WINDOWS\SysWOW64\drivers ===== ====== C:\WINDOWS\Sysnative ===== 2014-05-05 13:10:47 A98DA2EC1E56CF52C682D072F77D9874 23547904 ----a-w- C:\WINDOWS\Sysnative\mshtml.dll 2014-05-05 13:08:28 94C59DD02BC7EA0E421055B9946CA861 2724864 ----a-w- C:\WINDOWS\Sysnative\mshtml.tlb 2014-05-04 15:43:21 E5DA9DD3E5972CE969EA445492954280 16875520 ----a-w- C:\WINDOWS\Sysnative\Windows.UI.Xaml.dll 2014-05-04 15:43:19 411550CE9952B9B30C5A82CDDAD623C0 21232792 ----a-w- C:\WINDOWS\Sysnative\shell32.dll 2014-05-04 15:43:14 8596E6030C8DE66439DDF21C7F7B5006 40960 ----a-w- C:\WINDOWS\Sysnative\Windows.Shell.Search.UriHandler.dll 2014-05-04 15:43:14 80F4C728FC12B324156486806AB3357E 8653824 ----a-w- C:\WINDOWS\Sysnative\Windows.UI.Search.dll 2014-05-04 15:43:13 EE95B732BB098C5E874D53AD1E00EF51 13286400 ----a-w- C:\WINDOWS\Sysnative\twinui.dll 2014-05-04 15:43:09 2B12310DF8299D5ED5978FFBE3DA80B1 6641152 ----a-w- C:\WINDOWS\Sysnative\mstscax.dll 2014-05-04 15:43:03 F3523E611AB0B0977B048263A12DCF2A 1291200 ----a-w- C:\WINDOWS\Sysnative\kernel32.dll 2014-05-04 15:43:03 C5746CE22A4338896338A48687CB9345 4268544 ----a-w- C:\WINDOWS\Sysnative\SyncEngine.dll 2014-05-04 15:43:03 398990EFC34218C3B6C4E6384502083B 2900992 ----a-w- C:\WINDOWS\Sysnative\msftedit.dll 2014-05-04 15:43:02 1B2CAD40A6FD2E9DC336F3A338293B29 2331000 ----a-w- C:\WINDOWS\Sysnative\msxml6.dll 2014-05-04 15:43:01 6EF180C3695A4C1745F4A32E1D9EE8A9 2641920 ----a-w- C:\WINDOWS\Sysnative\authui.dll 2014-05-04 15:43:00 F7529BD3FFAC9C33D15F6DE3B7353B03 1306624 ----a-w- C:\WINDOWS\Sysnative\AppXDeploymentServer.dll 2014-05-04 15:43:00 8E5C2B32EE4166A3084B133183A00F2A 2141912 ----a-w- C:\WINDOWS\Sysnative\d3d11.dll 2014-05-04 15:43:00 5886CF4473849179FC8D2831CD629340 2133504 ----a-w- C:\WINDOWS\Sysnative\dwmcore.dll 2014-05-04 15:42:59 CFE7F0267B0C3077042FF291949B5546 1063424 ----a-w- C:\WINDOWS\Sysnative\IKEEXT.DLL 2014-05-04 15:42:58 62E1AE59F9F40BB70C4D7EDCC0CE34F1 1054208 ----a-w- C:\WINDOWS\Sysnative\twinui.appcore.dll 2014-05-04 15:42:58 332E5E35DE9E8175A9550501E57E0612 1542768 ----a-w- C:\WINDOWS\Sysnative\ole32.dll 2014-05-04 15:42:57 5A917027826D759CC3238C7D3CEC3438 1527296 ----a-w- C:\WINDOWS\Sysnative\wlansvc.dll 2014-05-04 15:42:57 4F6908A61CBC7FD263BB424671431623 1129472 ----a-w- C:\WINDOWS\Sysnative\SearchFolder.dll 2014-05-04 15:42:56 9A71BD2E4B8EB550D0022AFDF8616014 834048 ----a-w- C:\WINDOWS\Sysnative\audiosrv.dll 2014-05-04 15:42:56 8279E6B065626951DA5F3BD0B4E28001 1230336 ----a-w- C:\WINDOWS\Sysnative\Windows.Media.dll 2014-05-04 15:42:56 7CDB6060224CFAD4D5AC49FFC5414F41 939520 ----a-w- C:\WINDOWS\Sysnative\kerberos.dll 2014-05-04 15:42:56 05ED31A8FD97247D5B786F62988F2535 958464 ----a-w- C:\WINDOWS\Sysnative\MFMediaEngine.dll 2014-05-04 15:42:55 C58594E368B935CD001FC3F503D23A6B 1023488 ----a-w- C:\WINDOWS\Sysnative\localspl.dll 2014-05-04 15:42:55 1B7F53CBD0429CC3EE15A545F5E2BF62 918528 ----a-w- C:\WINDOWS\Sysnative\MrmCoreR.dll 2014-05-04 15:42:54 E797B1571003E524526F384CE5EE3555 1466864 ----a-w- C:\WINDOWS\Sysnative\propsys.dll 2014-05-04 15:42:54 42F4D353A2AC24F7112FB4D6BD2D4F7C 1339240 ----a-w- C:\WINDOWS\Sysnative\gdi32.dll 2014-05-04 15:42:54 2C727D11CDF4F8B2477FC2B1B305ECB9 512000 ----a-w- C:\WINDOWS\Sysnative\wlidprov.dll 2014-05-04 15:42:54 06E5962471CFC5890F6B7AB2BF527250 950784 ----a-w- C:\WINDOWS\Sysnative\ReAgent.dll 2014-05-04 15:42:53 88225B3D5685777AFAA1297FD612DF9A 518552 ----a-w- C:\WINDOWS\Sysnative\dxgi.dll 2014-05-04 15:42:53 6DD2D6B8CA1250A7C12D0042396D1892 492256 ----a-w- C:\WINDOWS\Sysnative\mfsvr.dll 2014-05-04 15:42:52 FAF28A6151A26D94555E0EE518762479 364640 ----a-w- C:\WINDOWS\Sysnative\AUDIOKSE.dll 2014-05-04 15:42:52 C253B8484DCABB3EBE6D60E67CADB373 356848 ----a-w- C:\WINDOWS\Sysnative\dcomp.dll 2014-05-04 15:42:52 6031CF57D972421469B15770AF8FF942 467504 ----a-w- C:\WINDOWS\Sysnative\AudioSes.dll 2014-05-04 15:42:51 D790CBCB9C38320B4438D697AA33FF55 720896 ----a-w- C:\WINDOWS\Sysnative\fveapi.dll 2014-05-04 15:42:51 D5C3776CBD8BC307DCCA3FD4CE667A37 324096 ----a-w- C:\WINDOWS\Sysnative\SessEnv.dll 2014-05-04 15:42:51 BBE15881FE11BE37112F8320C41DAFB9 827392 ----a-w- C:\WINDOWS\Sysnative\BFE.DLL 2014-05-04 15:42:51 7C75BF2879AEAD311DAE25CB5F1A2C83 669696 ----a-w- C:\WINDOWS\Sysnative\rasapi32.dll 2014-05-04 15:42:51 5BCABCE516486337E39DDD005BCBB1CA 1656832 ----a-w- C:\WINDOWS\Sysnative\GdiPlus.dll 2014-05-04 15:42:50 B8EB489B9CB8E4E29D3B5FA33F59F7EB 721408 ----a-w- C:\WINDOWS\Sysnative\SkyDriveTelemetry.dll 2014-05-04 15:42:50 A2BF5D466853422C143571064C7DD94F 252928 ----a-w- C:\WINDOWS\Sysnative\AppXDeploymentClient.dll 2014-05-04 15:42:50 A1C6BA515120C44E8D5A1EA3E927C7C2 291840 ----a-w- C:\WINDOWS\Sysnative\Windows.Devices.Sensors.dll 2014-05-04 15:42:50 65A3992EC59D8D33D7622E3AF4C50DBF 247296 ----a-w- C:\WINDOWS\Sysnative\SensorsApi.dll 2014-05-04 15:42:50 5BD3A2351BEFCAC8757626271F8EFA89 339456 ----a-w- C:\WINDOWS\Sysnative\bdesvc.dll 2014-05-04 15:42:50 5AEFB4F09549545FA3BBD58A6FFF4962 924160 ----a-w- C:\WINDOWS\Sysnative\AppXDeploymentExtensions.dll 2014-05-04 15:42:50 50126883FF1D1F690FE477B0B6593DAA 872448 ----a-w- C:\WINDOWS\Sysnative\SkyDrive.exe 2014-05-04 15:42:49 F83D49F4B10E813A1F9AC8B92F16592D 201216 ----a-w- C:\WINDOWS\Sysnative\AudioEndpointBuilder.dll 2014-05-04 15:42:49 F14178562B63C54D3183839F77FB9542 370176 ----a-w- C:\WINDOWS\Sysnative\wlanmsm.dll 2014-05-04 15:42:49 E64AD4877B41F1DB4CC3C99BA8372857 463264 ----a-w- C:\WINDOWS\Sysnative\AudioEng.dll 2014-05-04 15:42:49 DD5DF99540AB97806DF63B1494C809A8 488280 ----a-w- C:\WINDOWS\Sysnative\netcfgx.dll 2014-05-04 15:42:49 C8D6344BDE2691A196E61C0D3372EAB7 2479616 ----a-w- C:\WINDOWS\Sysnative\WsmSvc.dll 2014-05-04 15:42:49 C54F6C4594F54BC8F189A6FD4BFB7B2E 621568 ----a-w- C:\WINDOWS\Sysnative\MDMAgent.exe 2014-05-04 15:42:48 BC6849C62DB407573C6AD8CB1A4D2628 115200 ----a-w- C:\WINDOWS\Sysnative\umpnpmgr.dll 2014-05-04 15:42:48 97A8DD53D83D5DAC15EDAB1320D305B4 244888 ----a-w- C:\WINDOWS\Sysnative\audiodg.exe 2014-05-04 15:42:48 8183820F2D9648A619AA3200EFC62D0B 299008 ----a-w- C:\WINDOWS\Sysnative\pdh.dll 2014-05-04 15:42:48 50874EAD26534D475096765A48B90518 334848 ----a-w- C:\WINDOWS\Sysnative\MDEServer.exe 2014-05-04 15:42:48 4DD9C026AAB3C12A5BF7FF9A0C038422 186368 ----a-w- C:\WINDOWS\Sysnative\dafWfdProvider.dll 2014-05-04 15:42:47 48F25CC79C6CCFD4B776C8FDA9ED7271 160768 ----a-w- C:\WINDOWS\Sysnative\AppxAllUserStore.dll 2014-05-04 15:42:47 3ED1FD93AA4C381A374C3835CF7A5C92 201216 ----a-w- C:\WINDOWS\Sysnative\ReInfo.dll 2014-05-04 15:42:47 2DE56913AE88DF760F279264023908BC 1843712 ----a-w- C:\WINDOWS\Sysnative\Display.dll 2014-05-04 15:42:47 19F84D6153C06FE71203517BDAC9EA9F 102912 ----a-w- C:\WINDOWS\Sysnative\davclnt.dll 2014-05-04 15:42:46 A9B68F20F1E6E62B189C7C4815EB42B9 296960 ----a-w- C:\WINDOWS\Sysnative\wlanapi.dll 2014-05-04 15:42:46 A40262C252A65BAD0186D9DDBB3083DA 1015808 ----a-w- C:\WINDOWS\Sysnative\aclui.dll 2014-05-04 15:42:46 7A61F17976F7C5077D9862E4EC25BB3E 360512 ----a-w- C:\WINDOWS\Sysnative\mfreadwrite.dll 2014-05-04 15:42:46 5ABA673EF6433BE68AAE77AE5C5FAFAA 412672 ----a-w- C:\WINDOWS\Sysnative\FWPUCLNT.DLL 2014-05-04 15:42:46 18297BC1CE8A0C0BF9A703A3C45DACC1 462336 ----a-w- C:\WINDOWS\Sysnative\wlangpui.dll 2014-05-04 15:42:46 14BEA911F78B44E47CBD18210E541A43 212992 ----a-w- C:\WINDOWS\Sysnative\cdd.dll 2014-05-04 15:42:45 B29B13914A2692EA6A6E9E1D6FFB9760 298496 ----a-w- C:\WINDOWS\Sysnative\WSDMon.dll 2014-05-04 15:42:45 94CD5DE7D2989AA64594F1925339C97E 542208 ----a-w- C:\WINDOWS\Sysnative\Windows.Graphics.Printing.dll 2014-05-04 15:42:45 81AF2BB862A3C6DDB9F2E3A7956B0417 425984 ----a-w- C:\WINDOWS\Sysnative\clusapi.dll 2014-05-04 15:42:45 279DC249C295E8B7CD5FFB966007E1D9 110592 ----a-w- C:\WINDOWS\Sysnative\drvinst.exe 2014-05-04 15:42:45 0633C74EFAAEF72FCC33B86CB86B2ED5 79360 ----a-w- C:\WINDOWS\Sysnative\w32tm.exe 2014-05-04 15:42:45 06304D50B5228BF1EB6E829A72A629DB 271872 ----a-w- C:\WINDOWS\Sysnative\spp.dll 2014-05-04 15:42:44 FF94F2D1E80D09FEE3B90A263759163A 210944 ----a-w- C:\WINDOWS\Sysnative\fveapibase.dll 2014-05-04 15:42:44 DF621C527179BB0A60CDA371AEFD098E 57856 ----a-w- C:\WINDOWS\Sysnative\drvcfg.exe 2014-05-04 15:42:44 CC6F6A993FE36A55AF8207B9393407D6 325632 ----a-w- C:\WINDOWS\Sysnative\LocationApi.dll 2014-05-04 15:42:44 9F83D40B242C7CD2868DBF7550F3FF4C 86016 ----a-w- C:\WINDOWS\Sysnative\RMapi.dll 2014-05-04 15:42:44 9F0759C6D691E7030BF33105EDA2C690 30208 ----a-w- C:\WINDOWS\Sysnative\CredentialMigrationHandler.dll 2014-05-04 15:42:44 5F58A221937B5D58E33F4B21AEF92210 192000 ----a-w- C:\WINDOWS\Sysnative\Windows.Devices.Scanners.dll 2014-05-04 15:42:43 9A1ECF6480039B6E2062B739BBD0C4F7 64512 ----a-w- C:\WINDOWS\Sysnative\tsgqec.dll 2014-05-04 15:42:43 7563B7860E857D463C407085EC1BE731 100352 ----a-w- C:\WINDOWS\Sysnative\BitLockerDeviceEncryption.exe 2014-05-04 15:42:43 6DEA7E51085C4CEC311DBD5A1AF8C759 717312 ----a-w- C:\WINDOWS\Sysnative\nshwfp.dll 2014-05-04 15:42:43 1DCD97010190EF9377E77AB0A846C720 115200 ----a-w- C:\WINDOWS\Sysnative\DevPropMgr.dll 2014-05-04 15:42:43 0D092AAF47629E6FD77597FCA58625EE 1057280 ----a-w- C:\WINDOWS\Sysnative\rdvidcrl.dll 2014-05-04 15:42:42 FD786AFD9B85D65E5FD6B86944BB1D9A 443904 ----a-w- C:\WINDOWS\Sysnative\wlansec.dll 2014-05-04 15:42:42 EEA0EB275D329DAA7EAA397417477C8F 794112 ----a-w- C:\WINDOWS\Sysnative\fvewiz.dll 2014-05-04 15:42:42 C1D7A9932D7F468534F1913FB1F65572 40448 ----a-w- C:\WINDOWS\Sysnative\SetNetworkLocation.dll 2014-05-04 15:42:42 71133C77DD8089DA3F74813F90361F81 83968 ----a-w- C:\WINDOWS\Sysnative\sxproxy.dll 2014-05-04 15:42:41 938DC1C1D13682C01886F365E6682CA7 11264 ----a-w- C:\WINDOWS\Sysnative\wlanhlp.dll 2014-05-04 15:42:41 8DAE6957A4F0EC461575F68239E0A13E 69120 ----a-w- C:\WINDOWS\Sysnative\l2gpstore.dll 2014-05-04 15:42:41 7043428E344AF62EC540BDF49317D321 99328 ----a-w- C:\WINDOWS\Sysnative\BdeHdCfgLib.dll 2014-05-04 15:42:41 12B0701B1CEC1A7BB0E4C71D97661E23 387210 ----a-w- C:\WINDOWS\Sysnative\ApnDatabase.xml 2014-05-04 15:42:41 04D6FAB6BE09C83DF591D58E1FBADA59 274944 ----a-w- C:\WINDOWS\Sysnative\WsmWmiPl.dll 2014-05-01 12:58:09 B2F436D19A6513345E9F556CE962B84D 195584 ----a-w- C:\WINDOWS\Sysnative\msrating.dll 2014-05-01 12:44:43 F48C144251B36850B67AB8E6D9E20E92 111616 ----a-w- C:\WINDOWS\Sysnative\ieetwcollector.exe 2014-05-01 12:44:43 E1593B9C098F079DCED37016DC9DF685 48640 ----a-w- C:\WINDOWS\Sysnative\ieetwproxystub.dll 2014-05-01 12:44:43 C2CB1454F0D6BFDF584395A41C223BDF 4096 ----a-w- C:\WINDOWS\Sysnative\ieetwcollectorres.dll 2014-05-01 12:43:42 4F51BFB5DF7249D1CFC37010895E609C 139264 ----a-w- C:\WINDOWS\Sysnative\ieUnatt.exe 2014-05-01 12:42:33 3A2F218FE379B984E3C2EEDC6BB04ADF 233912 ----a-w- C:\WINDOWS\Sysnative\mfps.dll 2014-05-01 12:41:34 6BD4079F6EC3B875674C9E988AA24CDF 33792 ----a-w- C:\WINDOWS\Sysnative\iernonce.dll 2014-05-01 12:41:33 7871E35AC5640F4296B5C497CCAAA2AF 66048 ----a-w- C:\WINDOWS\Sysnative\iesetup.dll ====== C:\WINDOWS\Sysnative\drivers ===== 2014-05-04 15:43:19 179A41249055D5F039F1B6703F3B6D2B 376152 ----a-w- C:\WINDOWS\Sysnative\drivers\clfs.sys 2014-05-04 15:43:05 7FC5667DF73D4B04AA457CC3A4180E09 157016 ----a-w- C:\WINDOWS\Sysnative\drivers\wof.sys 2014-05-04 15:43:01 C7D252742946DD395670649742FBD73D 1557848 ----a-w- C:\WINDOWS\Sysnative\drivers\dxgkrnl.sys 2014-05-04 15:42:52 4030CB06B8D963A45CED9E60C9F2A11E 379224 ----a-w- C:\WINDOWS\Sysnative\drivers\dxgmms1.sys 2014-05-04 15:42:49 647C7652FA19F98CADF2BFDA2164BFEC 443392 ----a-w- C:\WINDOWS\Sysnative\drivers\nwifi.sys 2014-05-04 15:42:45 BFBE1C5F57FE7A885673A1962D5532B7 136024 ----a-w- C:\WINDOWS\Sysnative\drivers\wfplwfs.sys 2014-05-04 15:42:45 41CF802064F72E55F50CA0A221FD36D4 49152 ----a-w- C:\WINDOWS\Sysnative\drivers\tcpipreg.sys 2014-05-04 15:42:43 1D55DADC22D21883A2F80297F5A5AE48 140288 ----a-w- C:\WINDOWS\Sysnative\drivers\mrxdav.sys 2014-05-04 13:38:40 6140163BFE9D8F2DFDBA088ED5521C13 119512 ----a-w- C:\WINDOWS\Sysnative\drivers\MBAMSwissArmy.sys 2014-04-29 19:59:23 3595FBDF25F8BA6256072D103937D7D6 311640 ----a-w- C:\WINDOWS\Sysnative\drivers\volsnap.sys 2014-04-29 19:57:31 F21B77B4D74092A543807D3CEB711A88 1118552 ----a-w- C:\WINDOWS\Sysnative\drivers\ndis.sys 2014-04-29 19:57:21 9539F7917B4B6D92C90F0FAA6B86C605 539992 ----a-w- C:\WINDOWS\Sysnative\drivers\acpi.sys 2014-04-29 19:56:57 B2BD017231836DA9F63F41E3A075D73E 590168 ----a-w- C:\WINDOWS\Sysnative\drivers\fvevol.sys 2014-04-29 19:56:32 A26AEC49F318FEE141DDDB2C5F99B3E6 249688 ----a-w- C:\WINDOWS\Sysnative\drivers\rdyboost.sys 2014-04-29 19:56:24 233A4C961703D6B3EBA4EC1A3E85AACE 298496 ----a-w- C:\WINDOWS\Sysnative\drivers\ks.sys 2014-04-29 19:56:18 275AFE3FA35E8D78BE97695DF49817C6 280920 ----a-w- C:\WINDOWS\Sysnative\drivers\pci.sys 2014-04-29 19:56:13 87765EF43C33BE342F4ACB0E3FBF89A6 384856 ----a-w- C:\WINDOWS\Sysnative\drivers\spaceport.sys 2014-04-29 19:56:11 8685379B82AC81187813225905531D1E 272896 ----a-w- C:\WINDOWS\Sysnative\drivers\portcls.sys 2014-04-29 19:56:08 EA23453240137F6773174E0D93F61A69 148824 ----a-w- C:\WINDOWS\Sysnative\drivers\USBSTOR.SYS 2014-04-29 19:56:06 46D1DF775FFF14585218BBE16E5B2C9A 360792 ----a-w- C:\WINDOWS\Sysnative\drivers\fltMgr.sys 2014-04-29 19:55:36 8F39AFEB255487932DFF14D9E0E0FC24 372568 ----a-w- C:\WINDOWS\Sysnative\drivers\storport.sys 2014-04-29 19:55:32 52E483A3701A5A61A75A06993720347D 551256 ----a-w- C:\WINDOWS\Sysnative\drivers\vhdmp.sys 2014-04-29 19:55:12 FDEC5799BA499D18AFA3A540538866E7 236888 ----a-w- C:\WINDOWS\Sysnative\drivers\sdbus.sys 2014-04-29 19:55:05 D22EB844EB57D016CC34178AC86456DF 325464 ----a-w- C:\WINDOWS\Sysnative\drivers\USBXHCI.SYS 2014-04-29 19:55:03 DDEE191AB32DFC22C6465002ECDF5EE4 124416 ----a-w- C:\WINDOWS\Sysnative\drivers\luafv.sys 2014-04-29 19:55:02 0ECEE590F2E2EF969FB74A6FC583A1E6 663040 ----a-w- C:\WINDOWS\Sysnative\drivers\PEAuth.sys 2014-04-29 19:54:56 0527EF6E23B9FAB37DDCBC479C6CFA28 167424 ----a-w- C:\WINDOWS\Sysnative\drivers\rfcomm.sys 2014-04-29 19:54:55 02836172141D3AFA35B07679E253E503 151384 ----a-w- C:\WINDOWS\Sysnative\drivers\dumpsd.sys 2014-04-29 19:54:44 EF3AE7773394DF49CE74AF78A1C8D23D 146776 ----a-w- C:\WINDOWS\Sysnative\drivers\msgpioclx.sys 2014-04-29 19:54:41 BCFD8B149B3ADF92D0DB1E909CAF0265 79192 ----a-w- C:\WINDOWS\Sysnative\drivers\fileinfo.sys 2014-04-29 19:54:39 E515A287C8FAE901EB8FB42F168E14F2 924504 ----a-w- C:\WINDOWS\Sysnative\drivers\refs.sys 2014-04-29 19:54:39 AB8CD3914AD779C15B27DDD9F53F7434 1200640 ----a-w- C:\WINDOWS\Sysnative\drivers\bthport.sys 2014-04-29 19:54:37 38A82F4EE8C416A6744B6D30381ED768 33280 ----a-w- C:\WINDOWS\Sysnative\drivers\BasicRender.sys 2014-04-29 19:54:35 D30C67473A2E229662D21F27EAA9AAA5 226304 ----a-w- C:\WINDOWS\Sysnative\drivers\BthLEEnum.sys 2014-04-29 19:54:35 0B1E929D11A8E358106955603FAC65E8 79192 ----a-w- C:\WINDOWS\Sysnative\drivers\sdstor.sys 2014-04-29 19:54:17 61A1C2641321A6B89A2B41C5D481EF48 71888 ----a-w- C:\WINDOWS\Sysnative\drivers\dumpfve.sys 2014-04-29 19:54:12 C1F564F324685C088ECAB1933576CF91 54816 ----a-w- C:\WINDOWS\Sysnative\drivers\wpcfltr.sys 2014-04-29 19:54:07 B034A41891A36457B994307DFA772293 189784 ----a-w- C:\WINDOWS\Sysnative\drivers\UCX01000.SYS 2014-04-29 19:53:57 9DDCA7F18983C5410DEFF79F819DF93C 994136 ----a-w- C:\WINDOWS\Sysnative\drivers\http.sys 2014-04-29 19:53:27 9CC0003FB8ED3763B977B43F1012FF63 54272 ----a-w- C:\WINDOWS\Sysnative\drivers\watchdog.sys 2014-04-29 19:53:26 23E75BED9076F856B36F5F934BBD5795 81920 ----a-w- C:\WINDOWS\Sysnative\drivers\BTHUSB.SYS 2014-04-25 20:58:38 1C80517BE6836A812F6A9B99B8321351 2013016 ----a-w- C:\WINDOWS\Sysnative\drivers\ntfs.sys 2014-04-25 20:56:22 FEEFE783D87C9063CDAC6DBDCF95F533 2519384 ----a-w- C:\WINDOWS\Sysnative\drivers\tcpip.sys 2014-04-25 20:54:44 E62EAEF0BAC9DD61BF22D4A7F2F18571 679424 ----a-w- C:\WINDOWS\Sysnative\drivers\srv2.sys 2014-04-25 20:54:18 C997E6A37BA8915224B3FB5024A34F69 402944 ----a-w- C:\WINDOWS\Sysnative\drivers\mrxsmb.sys 2014-04-25 20:54:08 4627C1FBF2802425A408A2D2AF28CF85 565536 ----a-w- C:\WINDOWS\Sysnative\drivers\cng.sys 2014-04-25 20:54:05 466BDC0006103F2547D308DD3CD64398 245760 ----a-w- C:\WINDOWS\Sysnative\drivers\srvnet.sys 2014-04-25 20:54:00 AC408FA243471C25CDE435C3B83536A9 337752 ----a-w- C:\WINDOWS\Sysnative\drivers\Classpnp.sys 2014-04-25 20:53:52 CFC52C49BEFE4D70D87FFA900EAB9777 467800 ----a-w- C:\WINDOWS\Sysnative\drivers\USBHUB3.SYS 2014-04-25 20:53:44 F88CC88F4A6D8476F1664E805CA18CC2 180056 ----a-w- C:\WINDOWS\Sysnative\drivers\ksecpkg.sys 2014-04-25 20:53:36 A03F362C5557E238CBFA914689C77248 134144 ----a-w- C:\WINDOWS\Sysnative\drivers\dfsc.sys 2014-04-25 20:53:35 C48CDFD48A43E4AEC8170E1E50A3FACD 428888 ----a-w- C:\WINDOWS\Sysnative\drivers\FWPKCLNT.SYS 2014-04-25 20:53:31 8DB8EAB9D0C6A5DF0BDCADEA239220B4 33280 ----a-w- C:\WINDOWS\Sysnative\drivers\hidusb.sys 2014-04-25 20:53:23 ABB7341766902F5AAB45E15F34D19E15 111616 ----a-w- C:\WINDOWS\Sysnative\drivers\hidclass.sys 2014-04-25 20:53:04 FD9C9E9E3F0ED51502C7E8C066BE26B9 79360 ----a-w- C:\WINDOWS\Sysnative\drivers\IPMIDrv.sys 2014-04-25 20:53:04 3E28B99198B514DFEB152EACF913025E 283648 ----a-w- C:\WINDOWS\Sysnative\drivers\mrxsmb10.sys 2014-04-18 13:01:30 B7E17B7733C4266F140DD356817E5678 237336 ----a-w- C:\WINDOWS\Sysnative\drivers\avgidsdrivera.sys ====== C:\WINDOWS\Tasks ====== ====== C:\WINDOWS\Temp ====== ======= C:\Program Files ===== 2014-05-10 14:06:54 -------- d-----w- C:\Program Files\trend micro ======= C:\PROGRA~2 ===== 2014-04-26 11:34:34 -------- d-----w- C:\PROGRA~2\Avg Secure Update ======= C: ===== ====== C:\Users\els_v_000\AppData\Roaming ====== ====== C:\Users\els_v_000 ====== 2014-05-10 14:06:19 662C39FC1E27131551D557862CEC47F0 935175 ----a-w- C:\Users\els_v_000\Downloads\RSITx64.exe 2014-05-04 13:35:24 302103AF95A8F43AD85F80DAE14BDB9C 17305616 ----a-w- C:\Users\els_v_000\Downloads\mbam-setup-2.0.1.1004.exe ====== C: exe-files == 2014-05-14 16:37:54 FB171CA1B348AD25101B0BCFFDFEF89A 544 ----a-w- C:\$Recycle.Bin\S-1-5-21-1407927307-1300775257-3377467435-1003\$IH3X446.exe 2014-05-14 16:15:20 2ED2319F3DE13495AAA49B70A1467055 1285120 ----a-w- C:\$Recycle.Bin\S-1-5-21-1407927307-1300775257-3377467435-1003\$RH3X446.exe 2014-05-11 14:23:17 E87ECDFB931367CC1C6F4B4A14C6BE92 337408 ----a-w- C:\Users\els_v_000\AppData\Local\Packages\DexatiLLC.VintagePhotoCamera_3pcn3rnr550dy\AC\Microsoft\CLR_v4.0_32\NativeImages\VintagePhoto\8e9cf912f4b0d208b1e4666a19887102\VintagePhoto.ni.exe 2014-05-10 17:09:38 31F061DE42B01EFDA005F1B860C32304 367616 ----a-w- C:\Users\els_v_000\AppData\Local\Packages\CNGStudios.FireDrillRun_hmay7ffzsjc6w\AC\Microsoft\CLR_v4.0_32\NativeImages\WinMetroRunner\30e4b99a25b0ff11f03775dede2b491d\WinMetroRunner.ni.exe 2014-05-10 17:09:18 C8B45DC9DBA2F7EAE7B3D62230ED4C00 79872 ----a-w- C:\Users\els_v_000\AppData\Local\Packages\AceViral.comltd.AngryGranRun_av30ceye3ja8t\AC\Microsoft\CLR_v4.0_32\NativeImages\Template\b20b06dc4a9c6053c0039dda044711c2\Template.ni.exe 2014-05-10 17:09:16 A97D9BBCD7AE3058E74892D12B635AB7 107520 ----a-w- C:\Users\els_v_000\AppData\Local\Packages\53267Brainstorm.WheresWaldo_dqdhfj1tb6en6\AC\Microsoft\CLR_v4.0_32\NativeImages\Waldo\583c3d4fe289755e3e968856e157b1f8\Waldo.ni.exe 2014-05-10 17:09:02 B24F95D882B2CD5AB12E04C048AB8EEB 1590272 ----a-w- C:\Users\els_v_000\AppData\Local\Packages\32988BernardoZamora.GuessTheColorHD_1fgex2kbsn6g8\AC\Microsoft\CLR_v4.0_32\NativeImages\ColorMania\28ff638d844299f3f523824f19d4e09a\ColorMania.ni.exe 2014-05-10 15:15:46 D941EBADC13BBCDFC8B0EC485BFAC89B 1034240 ----a-w- C:\Users\els_v_000\AppData\Local\Packages\Telenet.Yelo_c5vekn1z7ww04\AC\Microsoft\CLR_v4.0\NativeImages\Yelo\dd8d076f3d5411e9a5e645b785b5d436\Yelo.ni.exe 2014-05-10 15:15:01 8B0AB2F3BA292AFA629E151DDB386137 263168 ----a-w- C:\Users\els_v_000\AppData\Local\Packages\ShazamEntertainmentLtd.Shazam_pqbynwjfrbcg4\AC\Microsoft\CLR_v4.0\NativeImages\ShazamApp\2db1fddb59034b15d615d1d3d47e39ac\ShazamApp.ni.exe 2014-05-10 15:14:41 585660B5FC6285EC015F0818354D81A5 918016 ----a-w- C:\Users\els_v_000\AppData\Local\Packages\Ingenify.GuesstheTVShow_ttw4g35v4x5tm\AC\Microsoft\CLR_v4.0\NativeImages\IngenifyW8\62bbfe577622cf096334e028a91ce360\IngenifyW8.ni.exe 2014-05-10 15:14:22 169DC9B3BDB2CC304E80E5A7DF00D30A 918016 ----a-w- C:\Users\els_v_000\AppData\Local\Packages\Ingenify.GuesstheSong_ttw4g35v4x5tm\AC\Microsoft\CLR_v4.0\NativeImages\IngenifyW8\0720e0d6b60aaa0c373b4ea87e35d8d8\IngenifyW8.ni.exe 2014-05-10 15:13:44 E8A79D1831ECD87A3B7CD871938C5395 1931776 ----a-w- C:\Users\els_v_000\AppData\Local\Packages\AdobeSystemsIncorporated.AdobePhotoshopExpress_ynb6jyjzte8ga\AC\Microsoft\CLR_v4.0\NativeImages\PSExpress\2011f05173c33b1065d46200be99474c\PSExpress.ni.exe 2014-05-10 15:13:15 A9B80D76CF738F70B68901069C0CB80B 7493632 ----a-w- C:\Users\els_v_000\AppData\Local\Packages\9E2F88E3.Twitter_wgeqdkkx372wm\AC\Microsoft\CLR_v4.0\NativeImages\Twitter-Win8\442a60685a1ac777c231ee1e2c7e3a52\Twitter-Win8.ni.exe 2014-05-10 15:12:56 0DCA119D7E9F6F088172A3C9FAFA8FCD 861696 ----a-w- C:\Users\els_v_000\AppData\Local\Packages\53543Nocodesoft.MyTetris_z140ett1a786e\AC\Microsoft\CLR_v4.0\NativeImages\MyTetris\e046265531c9101dff02962270cff369\MyTetris.ni.exe 2014-05-10 15:12:45 E903A8C350857DCEAB195B1036F128B2 538112 ----a-w- C:\Users\els_v_000\AppData\Local\Packages\27870Beigomon.TrafficJam_tbvvv74jxvaz8\AC\Microsoft\CLR_v4.0\NativeImages\TrafficPuzzleM\e965202df744ba113f0edbe8d6fe4090\TrafficPuzzleM.ni.exe 2014-05-10 14:06:54 9A2347903D6EDB84C10F288BC0578C1C 388608 ----a-w- C:\Program Files\trend micro\els_v_000.exe 2014-05-10 14:06:19 662C39FC1E27131551D557862CEC47F0 935175 ----a-w- C:\Users\els_v_000\Downloads\RSITx64.exe 2014-05-10 10:44:47 6FC454773ABF8DE9A33B35E03525140D 51080 ----atw- C:\Program Files (x86)\Google\Update\1.3.24.7\GoogleUpdateOnDemand.exe 2014-05-10 10:44:47 49B70FBEEC01A69CA9AC115C109E9CDD 51080 ----atw- C:\Program Files (x86)\Google\Update\1.3.24.7\GoogleUpdateBroker.exe 2014-05-10 10:44:46 BE472797288F53AA9F56974B1A1FC18F 918672 ----a-w- C:\Program Files (x86)\Google\Update\1.3.24.7\GoogleUpdateSetup.exe 2014-05-10 10:44:43 D893431503D5112DC3B799DF963D2AC8 114568 ----atw- C:\Program Files (x86)\Google\Update\1.3.24.7\GoogleUpdateComRegisterShell64.exe 2014-05-10 10:44:43 D5A444B63637EC0932172C6719A10252 263048 ----atw- C:\Program Files (x86)\Google\Update\1.3.24.7\GoogleCrashHandler.exe 2014-05-10 10:44:43 720546B84ED5229E1584C8F3533A2F12 328072 ----atw- C:\Program Files (x86)\Google\Update\1.3.24.7\GoogleCrashHandler64.exe 2014-05-10 10:44:43 506708142BC63DABA64F2D3AD1DCD5BF 116648 ----atw- C:\Program Files (x86)\Google\Update\1.3.24.7\GoogleUpdate.exe 2014-05-10 10:44:41 BE472797288F53AA9F56974B1A1FC18F 918672 ----a-w- C:\Program Files (x86)\Google\Update\Download\{430FD4D0-B729-4F61-AA34-91526481799D}\1.3.24.7\GoogleUpdateSetup.exe 2014-05-07 16:51:54 7CE4229848C137AAA10F21D2C3ECF875 5961264 ----a-w- C:\Program Files (x86)\AVG\AVG2014\avgcrema.exe === C: other files == ==== Startup Registry Enabled ====================== [HKEY_USERS\S-1-5-21-1407927307-1300775257-3377467435-1003\Software\Microsoft\Windows\CurrentVersion\Run] "RESTART_STICKY_NOTES"="C:\Windows\System32\StikyNot.exe" "Spotify Web Helper"="C:\Users\els_v_000\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" "Spotify"="C:\Users\els_v_000\AppData\Roaming\Spotify\spotify.exe /uri spotify:autostart" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "CLMLServer_For_P2G8"="C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe" "CLVirtualDrive"="C:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe /R" "RemoteControl10"="C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe" "YouCam Service"="C:\Program Files (x86)\CyberLink\YouCam\YouCamService.exe /s" "AVG_UI"="C:\Program Files (x86)\AVG\AVG2014\avgui.exe /TRAYONLY" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "RESTART_STICKY_NOTES"="C:\Windows\System32\StikyNot.exe" "Spotify Web Helper"="C:\Users\els_v_000\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" "Spotify"="C:\Users\els_v_000\AppData\Roaming\Spotify\spotify.exe /uri spotify:autostart" ==== Startup Registry Enabled x64 ====================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RtHDVCpl"="C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s" "RtHDVBg_Dolby"="C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe /FORPCEE4 " "IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" "HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" "Persistence"="C:\WINDOWS\system32\igfxpers.exe" "BTMTrayAgent"="rundll32.exe C:\Program Files (x86)\Intel\Bluetooth\btmshellex.dll,TrayApp" "SynTPEnh"="%ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe " [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"="C:\\Windows\\system32\\nvinitx.dll" ==== Startup Folders ====================== 2014-03-04 18:40:39 1133 ----a-w- C:\Users\els_v_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Verzenden naar OneNote.lnk ==== Task Scheduler Jobs ====================== C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job --a-------- [Undetermined Task] C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job --a-------- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [14/02/2014 15:29] C:\WINDOWS\tasks\Synaptics TouchPad Enhancements.job --a-------- C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [21/09/2012 10:55] ==== Other Scheduled Tasks ====================== "C:\WINDOWS\SysNative\tasks\CCleanerSkipUAC" ["C:\Program Files\CCleaner\CCleaner.exe"] "C:\WINDOWS\SysNative\tasks\CreateChoiceProcessTask" [C:\Windows\BrowserChoice\browserchoice.exe] "C:\WINDOWS\SysNative\tasks\Dolby Selector" [C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe] "C:\WINDOWS\SysNative\tasks\GoogleUpdateTaskMachineCore" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe] "C:\WINDOWS\SysNative\tasks\GoogleUpdateTaskMachineUA" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe] "C:\WINDOWS\SysNative\tasks\Synaptics TouchPad Enhancements" [\Program Files\Synaptics\SynTP\SynTPEnh.exe] ==== Chrome Look ====================== Google Wallet - els_v_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda ==== Set IE to Default ====================== Old Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://lenovo13.msn.com" New Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://lenovo13.msn.com" ==== All HKCU SearchScopes ====================== HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" {0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE11SR" {6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}" {F155994D-987F-4BD6-A0AE-DBFA24F894AE} Bing Url="http://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MALNJS" ==== HijackThis Entries ====================== F2 - REG:system.ini: UserInit=userinit.exe O2 - BHO: Lync Click to Call BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll O2 - BHO: PasswordBox Helper - {5DB69B97-934B-451D-94DB-32EF802A01CD} - C:\Program Files (x86)\PasswordBox\Application\pbbtn.dll O2 - BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL O4 - HKLM\..\Run: [CLMLServer_For_P2G8] "C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe" O4 - HKLM\..\Run: [CLVirtualDrive] "C:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe" /R O4 - HKLM\..\Run: [RemoteControl10] "C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe" O4 - HKLM\..\Run: [YouCam Service] "C:\Program Files (x86)\CyberLink\YouCam\YouCamService.exe" /s O4 - HKLM\..\Run: [AVG_UI] "C:\Program Files (x86)\AVG\AVG2014\avgui.exe" /TRAYONLY O4 - HKCU\..\Run: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe O4 - HKCU\..\Run: [Spotify Web Helper] "C:\Users\els_v_000\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" O4 - HKCU\..\Run: [Spotify] "C:\Users\els_v_000\AppData\Roaming\Spotify\spotify.exe" /uri spotify:autostart O4 - Startup: Verzenden naar OneNote.lnk = C:\Program Files\Microsoft Office 15\root\office15\ONENOTEM.EXE O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\Program Files\Microsoft Office 15\Root\Office15\EXCEL.EXE/3000 O8 - Extra context menu item: Se&nd to OneNote - res://C:\Program Files\Microsoft Office 15\Root\Office15\ONBttnIE.dll/105 O8 - Extra context menu item: Verzenden naar Bluetooth - C:\Program Files (x86)\Intel\Bluetooth\btSendToObject.htm O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIE.dll O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIE.dll O9 - Extra button: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll O9 - Extra 'Tools' menuitem: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIELinkedNotes.dll O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIELinkedNotes.dll O9 - Extra button: eBay.be - {0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - http://rover.ebay.com/rover/1/1553-154558-44482-6/4 (file missing) (HKCU) O9 - Extra 'Tools' menuitem: eBay.be - {0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - http://rover.ebay.com/rover/1/1553-154558-44482-6/4 (file missing) (HKCU) O9 - Extra button: Verzenden naar Bluetooth - {2F56DCAA-153B-4479-B4E2-547405B34FB9} - C:\Program Files (x86)\Intel\Bluetooth\btSendToPage.htm (HKCU) O9 - Extra 'Tools' menuitem: Verzenden naar Bluetooth - {2F56DCAA-153B-4479-B4E2-547405B34FB9} - C:\Program Files (x86)\Intel\Bluetooth\btSendToPage.htm (HKCU) O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing) O23 - Service: Intel® Centrino® Wireless Bluetooth® + High Speed Service (AMPPALR3) - Intel Corporation - C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe O23 - Service: Bluetooth Device Monitor - Motorola Solutions, Inc. - C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe O23 - Service: Bluetooth OBEX Service - Motorola Solutions, Inc. - C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe O23 - Service: Intel(R) Centrino(R) Wireless Bluetooth(R) + High Speed Security Service (BTHSSecurityMgr) - Intel(R) Corporation - C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe O23 - Service: CyberLink PowerDVD 10 MS Monitor Service - CyberLink - C:\Program Files (x86)\CyberLink\PowerDVD10\Device\MediaServer\CLMSMonitorService.exe O23 - Service: CyberLink PowerDVD 10 MS Service - CyberLink - C:\Program Files (x86)\CyberLink\PowerDVD10\Device\MediaServer\CLMSServer.exe O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing) O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing) O23 - Service: GFNEX Service (GFNEXSrv) - Unknown owner - C:\Program Files (x86)\PHotkey\GFNEXSrv.exe O23 - Service: Google Update-service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe O23 - Service: Google Update-service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\WINDOWS\system32\IEEtwCollector.exe (file missing) O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing) O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing) O23 - Service: Wireless PAN DHCP Server (MyWiFiDHCPDNS) - Unknown owner - C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing) O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\WINDOWS\system32\nvvsvc.exe (file missing) O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe O23 - Service: PasswordBox - PasswordBox, Inc. - C:\Program Files (x86)\PasswordBox\pbbtnService.exe O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe O23 - Service: Cyberlink RichVideo64 Service(CRVS) (RichVideo64) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo64.exe O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing) O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing) O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing) O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing) O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing) O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing) O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing) O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing) O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing) O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing) O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing) O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing) O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing) O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing) O23 - Service: Intel(R) PROSet/Wireless Zero Configuration Service (ZeroConfigService) - Intel® Corporation - C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe ==== Empty IE Cache ====================== C:\WINDOWS\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\els_v_000\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\Users\els_v_000\AppData\Local\Microsoft\Windows\INetCache\Low\Content.IE5 emptied successfully C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\WINDOWS\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully ==== Empty FireFox Cache ====================== No FireFox Profiles found ==== Empty Chrome Cache ====================== C:\Users\els_v_000\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully ==== Empty All Flash Cache ====================== Flash Cache Emptied Successfully ==== Empty All Java Cache ====================== No Java Cache Found ==== C:\zoek_backup content ====================== C:\zoek_backup (files=26 folders=3 6438379 bytes) ==== Empty Temp Folders ====================== C:\Users\Administrator\AppData\Local\Temp emptied successfully C:\Users\Default\AppData\Local\Temp emptied successfully C:\Users\Default User\AppData\Local\Temp emptied successfully C:\Users\els_v_000\AppData\Local\Temp will be emptied at reboot C:\Users\Steven\AppData\Local\Temp emptied successfully C:\Users\UpdatusUser\AppData\Local\Temp emptied successfully C:\WINDOWS\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully C:\WINDOWS\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully C:\WINDOWS\Temp will be emptied at reboot ==== After Reboot ====================== ==== Empty Temp Folders ====================== C:\WINDOWS\Temp successfully emptied C:\Users\ELS_V_~1\AppData\Local\Temp successfully emptied ==== Empty Recycle Bin ====================== C:\$RECYCLE.BIN successfully emptied ==== Deleting Files / Folders ====================== "C:\Program Files (x86)\Avg Secure Update\AVG-Secure-Search-Update_0414c.exesearch" not found ==== EOF on wo 14/05/2014 at 18:51:33,04 ======================