Zoek.exe v5.0.0.0 Updated 14-September-2014 Tool run by Vaste on wo 17/09/2014 at 11:02:01,20. Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x64 Running in: Normal Mode Internet Access Detected Launched: C:\Users\Vaste\Desktop\zoek.exe [Scan all users] [Script inserted] ==== System Restore Info ====================== 17/09/2014 11:03:25 Zoek.exe System Restore Point Created Succesfully. ==== Empty Folders Check ====================== C:\PROGRA~2\AGEIA Technologies deleted successfully C:\PROGRA~2\MSXML 4.0 deleted successfully C:\Program Files\log deleted successfully C:\PROGRA~3\Freemake deleted successfully C:\PROGRA~3\Oracle deleted successfully C:\Users\Vaste\AppData\Roaming\QuickScan deleted successfully ==== Deleting CLSID Registry Keys ====================== ==== Deleting CLSID Registry Values ====================== ==== Deleting Services ====================== HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Update service deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Update service deleted successfully ==== Deleting Files \ Folders ====================== C:\Program Files (x86)\Popcorn Time deleted ==== Files Recently Created / Modified ====================== ====== C:\Windows ==== ====== C:\Users\Vaste\AppData\Local\Temp ==== 2014-09-17 07:53:29 3F512AF8DB108FCA028BA731CE0B4700 224408 ----a-w- C:\Users\Vaste\AppData\Local\Temp\{AC76BA86-7AD7-1043-7B44-AB0000000001}\FixTransforms.exe 2014-09-17 07:52:42 D11FB7A5078631BE2E183DC56FCD5375 43008 ----a-w- C:\Users\Vaste\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpud_jfk.dll ====== Java Cache ===== 2014-09-02 10:10:22 2924D22CA1E53E9C343075291D5A7A2F 101 ----a-w- C:\Users\Vaste\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\17\197a0b11-f573e69f2388dbadee5e7243329f089645079ea65589e99c30074255f8855ab6-6.0.lap 2014-09-02 10:12:03 14B33B2B94DB955990459293FC1C7220 807 ----a-w- C:\Users\Vaste\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\18\687ac712-3f90aa6a 2014-09-02 10:12:03 92A9A2D4A4A19FCAD211C3E59A8D3D8A 7343 ----a-w- C:\Users\Vaste\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\30\2c3cccde-4fe934d0 2014-09-02 10:10:15 92A9A2D4A4A19FCAD211C3E59A8D3D8A 7343 ----a-w- C:\Users\Vaste\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\30\7e17e25e-55f9b1f5 2014-09-02 10:10:51 B5483D1E9EB04B6D61F956E4A7CBA526 135516 ----a-w- C:\Users\Vaste\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\43\2b6ccb6b-1de1e5d8 2014-09-02 10:10:15 14B33B2B94DB955990459293FC1C7220 807 ----a-w- C:\Users\Vaste\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\51\66c84eb3-27420aaf 2014-09-02 10:10:24 6707E6C4520AA530CCFBEF6EE8CC4AA7 414390 ----a-w- C:\Users\Vaste\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\57\3bbe1039-15bd31c5 2014-09-02 10:10:15 C8F40408D73F14765E2953D6B0F64B32 722 ----a-w- C:\Users\Vaste\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\6\2666ee86-2cbbf9b4 2014-09-02 10:10:15 8F9BAA9EF7CDCF9DC5ED0E1464EACC53 105 ----a-w- C:\Users\Vaste\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\6\2666ee86-9741a20189fb94b70bc887793603abe92ed27ae9c22405809d79870e5f9049dd-6.0.lap 2014-09-02 10:12:18 6707E6C4520AA530CCFBEF6EE8CC4AA7 414390 ----a-w- C:\Users\Vaste\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\6\6b6941c6-717c5a15 2014-09-02 10:12:03 C8F40408D73F14765E2953D6B0F64B32 722 ----a-w- C:\Users\Vaste\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\63\35cd4f3f-704369a5 2014-09-02 10:12:03 11C214252A2270BD7F5E977CA25383EE 456 ----a-w- C:\Users\Vaste\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\63\35cd4f3f-ec75a99c7a9ae11ee5d9ed9f0dad9d8b3d5e9f33d88e9523fb409ffe448666a3-6.0.lap 2014-09-02 10:12:17 9D9B7EC08BAD830A072A231B9D07D634 455 ----a-w- C:\Users\Vaste\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\7\1d58b207-abaf3bb26e68df8455dc95d86945157e665c9d93d39f00e380abb6350d2941de-6.0.lap ====== C:\Windows\SysWOW64 ===== 2014-09-10 20:03:15 297EF1AB73B8FCE76BCA1365C2E49AFC 440320 ----a-w- C:\Windows\SysWOW64\ieui.dll 2014-09-10 20:03:14 E3D7B3F64C30994409BDF8E48048A854 2724864 ----a-w- C:\Windows\SysWOW64\mshtml.tlb 2014-09-10 20:03:14 6DD476318F524D2DCB73AFEB2EE27B4A 61952 ----a-w- C:\Windows\SysWOW64\MshtmlDac.dll 2014-09-10 20:03:13 CC8F34B345DA638D77BB48C035DA628D 164864 ----a-w- C:\Windows\SysWOW64\msrating.dll 2014-09-10 20:03:13 84E96F4AF8A7748A3DE7C3EBBC6768E5 365056 ----a-w- C:\Windows\SysWOW64\dxtmsft.dll 2014-09-10 20:03:13 4F2EDC301EC63F803C0FDB6CC87EDA24 454656 ----a-w- C:\Windows\SysWOW64\vbscript.dll 2014-09-10 20:03:13 42F6F28D4885505F687CAF0459FF9F90 112128 ----a-w- C:\Windows\SysWOW64\ieUnatt.exe 2014-09-10 20:03:13 010DFAF3EF93994B805BAA1493D47973 243200 ----a-w- C:\Windows\SysWOW64\dxtrans.dll 2014-09-10 20:03:12 D603AC77E17E5B9583E382F2EE0381A7 43008 ----a-w- C:\Windows\SysWOW64\jsproxy.dll 2014-09-10 20:03:12 AA595171932ACC79DA9851067DCBDABF 32768 ----a-w- C:\Windows\SysWOW64\iernonce.dll 2014-09-10 20:03:12 8D4FCAB2643DFEF68040B70F1EDCCBC5 327872 ----a-w- C:\Windows\SysWOW64\iedkcs32.dll 2014-09-10 20:03:12 7C3D593AB1E2F5E5687D97772EF99AC7 61952 ----a-w- C:\Windows\SysWOW64\iesetup.dll 2014-09-10 20:03:12 13C2C87C35E52AAB1B439FB2E26DF2DE 69632 ----a-w- C:\Windows\SysWOW64\mshtmled.dll 2014-09-10 20:03:12 074646C5A979DE79133DE4A8530A9C5D 603136 ----a-w- C:\Windows\SysWOW64\msfeeds.dll 2014-09-10 20:03:11 77F79126444896B5867E6761490735B8 60416 ----a-w- C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2014-09-10 20:03:11 5074835337862817DB3726558D0908DE 51200 ----a-w- C:\Windows\SysWOW64\ieetwproxystub.dll 2014-09-10 20:03:11 2E2E40E5D92EEA979548E307C5781038 597504 ----a-w- C:\Windows\SysWOW64\jscript9diag.dll 2014-09-10 20:03:10 88EBB8526981D03C5777AB0A4AEBA8B4 1068032 ----a-w- C:\Windows\SysWOW64\mshtmlmedia.dll 2014-09-10 20:03:10 1D8C086A39B9794D7131384586811B25 678400 ----a-w- C:\Windows\SysWOW64\ieapfltr.dll 2014-09-10 20:03:09 FD96C05DE700F5FD26273D6DDB6495A7 2185728 ----a-w- C:\Windows\SysWOW64\iertutil.dll 2014-09-10 20:03:08 D58988722C72D265B51A54103DFC2C6F 1812992 ----a-w- C:\Windows\SysWOW64\wininet.dll 2014-09-10 20:03:07 77B7DDF91F3ED2CDB6CF60224EE13433 4232704 ----a-w- C:\Windows\SysWOW64\jscript9.dll 2014-09-10 20:03:07 6A3A809CA7A8F40C89E6F1D301898A66 2014208 ----a-w- C:\Windows\SysWOW64\inetcpl.cpl 2014-09-10 20:03:07 41010A88B70A2168F801DC19EBD4CB4F 1190400 ----a-w- C:\Windows\SysWOW64\urlmon.dll 2014-09-10 20:03:06 A3560FAFC1686D5EE9830B33B5C74B66 11769856 ----a-w- C:\Windows\SysWOW64\ieframe.dll 2014-09-10 20:03:06 7BF1CE9240CB9DD27C3E30733176EB8E 17455104 ----a-w- C:\Windows\SysWOW64\mshtml.dll 2014-09-10 19:49:22 2413D2216D08FAF7D7178D9E0B481AEB 2285056 ----a-w- C:\Windows\SysWOW64\msmpeg2vdec.dll 2014-09-10 16:52:34 A8DDB7ACB122FC36FF0D7C9B3099A380 793600 ----a-w- C:\Windows\SysWOW64\TSWorkspace.dll 2014-09-10 16:52:20 79896A78039C9A63C56197843CFBAD0B 1987584 ----a-w- C:\Windows\SysWOW64\d3d10warp.dll 2014-09-10 16:52:12 B094390B6B2D0456821384771020870B 22016 ----a-w- C:\Windows\SysWOW64\secur32.dll 2014-09-10 16:52:12 1B85FA0D0A93C011B76678733F39DB6C 550912 ----a-w- C:\Windows\SysWOW64\kerberos.dll 2014-09-10 16:52:12 10826DA2FC073702AEAB93AF3D73B066 96768 ----a-w- C:\Windows\SysWOW64\sspicli.dll ====== C:\Windows\SysWOW64\drivers ===== ====== C:\Windows\Sysnative ===== 2014-09-10 20:03:15 9EFF09364ABDC86770FA0B1BCC9CA3C3 596480 ----a-w- C:\Windows\Sysnative\ieui.dll 2014-09-10 20:03:14 EF79F0B9E0F277F5797C475DF4248B97 83968 ----a-w- C:\Windows\Sysnative\MshtmlDac.dll 2014-09-10 20:03:14 A0600300428AB73664050659E738F11F 33792 ----a-w- C:\Windows\Sysnative\iernonce.dll 2014-09-10 20:03:14 1BE1D1942825BE2146941DA274D2B92F 2724864 ----a-w- C:\Windows\Sysnative\mshtml.tlb 2014-09-10 20:03:14 0113777A28BEC88A50C2566F346E4B58 72704 ----a-w- C:\Windows\Sysnative\JavaScriptCollectionAgent.dll 2014-09-10 20:03:13 EE6B22396FA99639A163B1B7E9736669 4096 ----a-w- C:\Windows\Sysnative\ieetwcollectorres.dll 2014-09-10 20:03:13 E76C23C71345ACBC65ED8F6E87AD01D1 195584 ----a-w- C:\Windows\Sysnative\msrating.dll 2014-09-10 20:03:13 786ECD92C9D77F571134283E0FABAF1A 289280 ----a-w- C:\Windows\Sysnative\dxtrans.dll 2014-09-10 20:03:13 641068C626DE3AD348871D0D7931A3FA 547328 ----a-w- C:\Windows\Sysnative\vbscript.dll 2014-09-10 20:03:13 4CF33E458BAEDA917CAE9F2E8338479C 446464 ----a-w- C:\Windows\Sysnative\dxtmsft.dll 2014-09-10 20:03:13 305D5395A65D00C74A94AEA40E9909E9 758272 ----a-w- C:\Windows\Sysnative\jscript9diag.dll 2014-09-10 20:03:13 2D95BDB699FA1D531B642EA18464FE05 139264 ----a-w- C:\Windows\Sysnative\ieUnatt.exe 2014-09-10 20:03:12 C07D636B0237172345E68AE8B70A2984 51200 ----a-w- C:\Windows\Sysnative\jsproxy.dll 2014-09-10 20:03:12 C067D863FCD53B91A5BF78AE1CE88E54 85504 ----a-w- C:\Windows\Sysnative\mshtmled.dll 2014-09-10 20:03:12 A1BB4CFB25F7CE1D4F67DD71111823AA 374968 ----a-w- C:\Windows\Sysnative\iedkcs32.dll 2014-09-10 20:03:12 68B0077C0D09D1B669A260F2921FD6B9 66048 ----a-w- C:\Windows\Sysnative\iesetup.dll 2014-09-10 20:03:12 33BAC6F66DB5FE5F7E20D41B025F490E 707072 ----a-w- C:\Windows\Sysnative\ie4uinit.exe 2014-09-10 20:03:12 2AEFBA4339A34C8EF021B49D23D1F1DF 727040 ----a-w- C:\Windows\Sysnative\msfeeds.dll 2014-09-10 20:03:11 920BD93A0B64657A20CA66C2EBB167EA 23591424 ----a-w- C:\Windows\Sysnative\mshtml.dll 2014-09-10 20:03:10 698C19E198F832E071778A1427E942C8 111616 ----a-w- C:\Windows\Sysnative\ieetwcollector.exe 2014-09-10 20:03:10 5A0C72B9D3CCA42D8AB74890C19443B2 940032 ----a-w- C:\Windows\Sysnative\MsSpellCheckingFacility.exe 2014-09-10 20:03:10 4C8838D7C13E9080AF4B548CA791896B 1249280 ----a-w- C:\Windows\Sysnative\mshtmlmedia.dll 2014-09-10 20:03:10 227303FC6E95547EA274F4337BBC7278 48640 ----a-w- C:\Windows\Sysnative\ieetwproxystub.dll 2014-09-10 20:03:10 1439630B47D717960D59423958754394 775168 ----a-w- C:\Windows\Sysnative\ieapfltr.dll 2014-09-10 20:03:08 F6304AACC5744016770C8C797CAA2AF7 5833728 ----a-w- C:\Windows\Sysnative\jscript9.dll 2014-09-10 20:03:08 75498A52C2AE248DEE5BDF5209768963 2793984 ----a-w- C:\Windows\Sysnative\iertutil.dll 2014-09-10 20:03:08 39EBB9708453036A74C30C9A294023FF 2310656 ----a-w- C:\Windows\Sysnative\wininet.dll 2014-09-10 20:03:07 FECA80905D551074E1A9298BD98103B7 1447424 ----a-w- C:\Windows\Sysnative\urlmon.dll 2014-09-10 20:03:07 97752927B6E2401011A96E0D6082E403 2104832 ----a-w- C:\Windows\Sysnative\inetcpl.cpl 2014-09-10 20:03:06 BA56C68CCB912C4C08C97DD32C47AD31 13588480 ----a-w- C:\Windows\Sysnative\ieframe.dll 2014-09-10 19:49:22 3469B9FAE899139FEE7356E91693376A 2777088 ----a-w- C:\Windows\Sysnative\msmpeg2vdec.dll 2014-09-10 16:52:35 EFF3FF9D9E5BFD2A05390D959A1C3AD0 1031168 ----a-w- C:\Windows\Sysnative\TSWorkspace.dll 2014-09-10 16:52:21 224C2EEBAAF39CD93DE5332DBE5E5A95 2565120 ----a-w- C:\Windows\Sysnative\d3d10warp.dll 2014-09-10 16:52:12 EE4B105F1DBE1E864AFC72E7F0315432 1460736 ----a-w- C:\Windows\Sysnative\lsasrv.dll 2014-09-10 16:52:12 33EF550DCCC58C93F5B65FD75BAD9832 728064 ----a-w- C:\Windows\Sysnative\kerberos.dll 2014-09-10 16:52:06 E2BCB58869598B392D6A78953F61A2D9 578048 ----a-w- C:\Windows\Sysnative\aepdu.dll 2014-09-10 16:52:06 88BC88D0BDFB6BBE5765D5ABB233C110 424448 ----a-w- C:\Windows\Sysnative\aeinv.dll ====== C:\Windows\Sysnative\drivers ===== 2014-08-21 00:51:38 86FF84D35A39432357CEDB06CFADAC90 62848 ----a-w- C:\Windows\Sysnative\drivers\a38usb.sys ====== C:\Windows\Tasks ====== ====== C:\Windows\Temp ====== ======= C:\Program Files ===== 2014-09-16 13:27:15 -------- d-----w- C:\Program Files\trend micro ======= C:\PROGRA~2 ===== 2014-09-08 18:09:19 -------- d-----w- C:\PROGRA~2\COMMON~1\Skype 2014-09-02 10:08:46 -------- d-----w- C:\PROGRA~2\COMMON~1\Java ======= C: ===== ====== C:\Users\Vaste\AppData\Roaming ====== 2014-08-30 08:11:05 -------- d-----w- C:\Users\Vaste\AppData\Roaming\PopcornTime 2014-08-29 06:58:58 -------- d-----w- C:\Users\Vaste\AppData\Roaming\Curse Client 2014-08-29 06:57:20 -------- d-----w- C:\Users\Vaste\AppData\Roaming\Curse ====== C:\Users\Vaste ====== 2014-09-16 13:26:28 8045ABB21A3BDD66A48E1ED5C0F0EF6A 1222144 ----a-w- C:\Users\Vaste\Desktop\RSITx64.exe 2014-09-08 18:09:19 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype ====== C: exe-files == 2014-09-17 08:36:10 2052943167D874B7B61A0A04A0315849 277616 ----a-w- C:\Users\Vaste\AppData\Local\Mozilla\updates\E7CF176E110C211B\updates\0\updater.exe 2014-09-17 07:53:29 3F512AF8DB108FCA028BA731CE0B4700 224408 ----a-w- C:\Users\Vaste\AppData\Local\Temp\{AC76BA86-7AD7-1043-7B44-AB0000000001}\FixTransforms.exe 2014-09-16 18:59:07 910646F84FB819FD50D5BBFD6C30D06B 1177456 ----a-w- C:\Program Files (x86)\MediaHuman\YouTube to MP3 Converter\unins000.exe 2014-09-16 13:27:19 9A2347903D6EDB84C10F288BC0578C1C 388608 ----a-w- C:\Program Files\trend micro\Vaste.exe 2014-09-16 13:26:28 8045ABB21A3BDD66A48E1ED5C0F0EF6A 1222144 ----a-w- C:\Users\Vaste\Desktop\RSITx64.exe 2014-09-16 12:18:19 F2E1B9CBACF89B79F1EAF7F0034EAC1B 10120 ------w- C:\Users\Vaste\AppData\Local\Apps\2.0\OTRLOVNE.LVM\YD234M7A.RRX\inst...app_4fe91ede9f9bdca3_0001.0003_220833ca61e45306\clickonce_bootstrap.exe 2014-09-16 12:18:19 901AC7A94B75648F4084A37640473271 895120 ----a-w- C:\Users\Vaste\AppData\Local\Apps\2.0\OTRLOVNE.LVM\YD234M7A.RRX\inst...app_4fe91ede9f9bdca3_0001.0003_220833ca61e45306\GoogleUpdateSetup.exe 2014-09-16 12:18:19 901AC7A94B75648F4084A37640473271 895120 ----a-w- C:\Users\Vaste\AppData\Local\Apps\2.0\OTRLOVNE.LVM\YD234M7A.RRX\clic...exe_4fe91ede9f9bdca3_0001.0003_none_b13295ce3920a12c\GoogleUpdateSetup.exe 2014-09-11 14:02:56 36D18FA362CF62694BE5455F458FFB4E 15912440 ----a-w- C:\Riot Games\League of Legends\RADS\projects\lol_game_client\releases\0.0.0.250\deploy\League of Legends.exe 2014-09-11 14:00:08 50E165BEC0EF211ECB25CC55295D48DC 1712120 ----a-w- C:\Riot Games\League of Legends\RADS\projects\lol_patcher\releases\0.0.0.6\deploy\rPipe.exe 2014-09-11 14:00:08 0D8769B388B139C9F58BCAFE1899691A 4070904 ----a-w- C:\Riot Games\League of Legends\RADS\projects\lol_patcher\releases\0.0.0.6\deploy\LoLPatcher.exe 2014-09-10 20:03:14 ED689CF5DA7A0374D2A8E3A8550522F7 483328 ----a-w- C:\Program Files\Internet Explorer\ieinstal.exe 2014-09-10 20:03:14 665256B575BF83E4B188BE73450C5C29 470016 ----a-w- C:\Program Files (x86)\Internet Explorer\ieinstal.exe 2014-09-10 20:03:14 4DABFE3A9D3C67E9D9AD83C7F8FAD855 222720 ----a-w- C:\Program Files (x86)\Internet Explorer\ielowutil.exe 2014-09-10 20:03:14 0D75A74E925F00D9F256F6A53733DAF8 222720 ----a-w- C:\Program Files\Internet Explorer\ielowutil.exe 2014-09-10 20:03:13 42F6F28D4885505F687CAF0459FF9F90 112128 ----a-w- C:\Windows\SysWOW64\ieUnatt.exe 2014-09-10 20:03:13 2D95BDB699FA1D531B642EA18464FE05 139264 ----a-w- C:\Windows\System32\ieUnatt.exe 2014-09-10 20:03:12 33BAC6F66DB5FE5F7E20D41B025F490E 707072 ----a-w- C:\Windows\System32\ie4uinit.exe 2014-09-10 20:03:10 698C19E198F832E071778A1427E942C8 111616 ----a-w- C:\Windows\System32\ieetwcollector.exe 2014-09-10 20:03:10 5A0C72B9D3CCA42D8AB74890C19443B2 940032 ----a-w- C:\Windows\System32\MsSpellCheckingFacility.exe 2014-09-10 20:03:07 EEA63B8CF19E59C4A51AD2D9A59DDA25 812216 ----a-w- C:\Program Files (x86)\Internet Explorer\iexplore.exe 2014-09-10 20:03:07 9540F3F5489747E71101E8AC9850CC79 810168 ----a-w- C:\Program Files\Internet Explorer\iexplore.exe 2014-09-10 16:52:06 1386CD9322CD4A673FF96BF136D91633 31232 ----a-w- C:\Windows\System32\CompatTel\wicainventory.exe 2014-09-10 16:52:06 0C3028324C475485D6C24D626D9149C3 176288 ----a-w- C:\Windows\System32\CompatTel\QueryAppBlock.exe === C: other files == 2014-09-16 14:01:27 E1EA8293EA5B0AED6F362FE93C801112 544 ----a-w- C:\$Recycle.Bin\S-1-5-21-2371546590-1343770695-238948823-1000\$INJEJXY.zip 2014-09-16 13:51:57 F63E1E0BF4BBCAA6C8EEA58DA28AB0E6 27835375 ----a-w- C:\$Recycle.Bin\S-1-5-21-2371546590-1343770695-238948823-1000\$RNJEJXY.zip ==== Startup Registry Enabled ====================== [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "Autodesk Sync"="C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe" [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun" [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun" [HKEY_USERS\S-1-5-21-2371546590-1343770695-238948823-1000\Software\Microsoft\Windows\CurrentVersion\Run] "TBPanel"="C:\Program Files (x86)\Vtune\TBPanel.exe /A" "Steam"="C:\Program Files (x86)\Steam\steam.exe -silent" "Akamai NetSession Interface"="C:\Users\Vaste\AppData\Local\Akamai\netsession_win.exe" "Autodesk Sync"="C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe" "DAEMON Tools Lite"="C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe -autorun" "Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe /autoRun" "BitTorrent"="C:\Users\Vaste\AppData\Roaming\BitTorrent\BitTorrent.exe" "Skype"="C:\Program Files (x86)\Skype\Phone\Skype.exe /minimized /regrun" [HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run] "Autodesk Sync"="C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe" [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce] "mctadmin"="C:\Windows\System32\mctadmin.exe" [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce] "mctadmin"="C:\Windows\System32\mctadmin.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SoundMAXPnP"="C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe" "TurboV"="C:\Program Files\ASUS\TurboV\TurboV.exe -b" "APSDaemon"="C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" "iTunesHelper"="C:\Program Files (x86)\iTunes\iTunesHelper.exe" "Adobe ARM"="C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" "SunJavaUpdateSched"="C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "TBPanel"="C:\Program Files (x86)\Vtune\TBPanel.exe /A" "Steam"="C:\Program Files (x86)\Steam\steam.exe -silent" "Akamai NetSession Interface"="C:\Users\Vaste\AppData\Local\Akamai\netsession_win.exe" "Autodesk Sync"="C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe" "DAEMON Tools Lite"="C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe -autorun" "Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe /autoRun" "BitTorrent"="C:\Users\Vaste\AppData\Roaming\BitTorrent\BitTorrent.exe" "Skype"="C:\Program Files (x86)\Skype\Phone\Skype.exe /minimized /regrun" ==== Startup Registry Enabled x64 ====================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Bdagent"="C:\Program Files\Bitdefender\Bitdefender 2013\bdagent.exe" "Nvtmru"="C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe" "BCSSync"="C:\Program Files\Microsoft Office\Office14\BCSSync.exe /DelayServices" "SoundMAX"="C:\Program Files (x86)\Analog Devices\SoundMAX\soundmax.exe /tray" "Logitech Download Assistant"="C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch" "Launch LCore"="C:\Program Files\Logitech Gaming Software\LCore.exe /minimized" ==== Startup Folders ====================== 2014-08-29 06:59:00 1035 ----a-w- C:\Users\Vaste\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Curse.lnk 2014-07-25 17:09:35 1042 ----a-w- C:\Users\Vaste\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ==== Task Scheduler Jobs ====================== C:\Windows\tasks\Adobe Flash Player Updater.job --a------ [Undetermined Task] C:\Windows\tasks\MATLAB R2013b Startup Accelerator.job --a------ [Undetermined Task] ==== Other Scheduled Tasks ====================== "C:\Windows\SysNative\tasks\Adobe Flash Player Updater" [C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe] "C:\Windows\SysNative\tasks\MATLAB R2013b Startup Accelerator" [C:\Program Files\MATLAB\R2013b\bin\win64\MATLABStartupAccelerator.exe] "C:\Windows\SysNative\tasks\Razer_Game_Booster_AutoUpdate" [C:\Program Files (x86)\Razer\Razer Game Booster\AutoUpdate.exe] "C:\Windows\SysNative\tasks\ASUS\ASUS SIX Engine" [C:\Program Files\ASUS\Six Engine\SixEngine.exe] "C:\Windows\SysNative\tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask" [%systemroot%\system32\sc.exe start osppsvc] ==== Firefox Extensions Registry ====================== [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions] "belgiumeid@eid.belgium.be"="C:\Program Files\Mozilla Firefox\extensions\belgiumeid@eid.belgium.be" [] ==== Firefox Extensions ====================== ProfilePath: C:\Users\Vaste\AppData\Roaming\Mozilla\Firefox\Profiles\vweg6gdx.default - Adblock Plus - %ProfilePath%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi AppDir: C:\Program Files (x86)\Mozilla Firefox - Belgium eID - %AppDir%\extensions\belgiumeid@eid.belgium.be - Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} - Skype Click to Call - %AppDir%\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi ==== Firefox Plugins ====================== Profilepath: C:\Users\Vaste\AppData\Roaming\Mozilla\Firefox\Profiles\vweg6gdx.default DFC9460CC37E5C414DC4680B10C19E7A - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll - Shockwave Flash ==== Chromium Look ====================== HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions lifbcibllhkdhoafpjfnlhfpfgnpldfl - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx[14/07/2014 18:22] ==== Deleting CLSID Registry Keys ====================== ==== Deleting CLSID Registry Values ====================== ==== C:\zoek_backup content ====================== C:\zoek_backup (files=383 folders=24 151909066 bytes) ==== EOF on wo 17/09/2014 at 11:10:37,49 ======================