Zoek.exe v5.0.0.0 Updated 15-November-2014 Tool run by Yvonne on za 15-11-2014 at 20:18:01,31. Microsoft Windows 8.1 6.3.9600 x64 Running in: Normal Mode Internet Access Detected Launched: C:\Users\Yvonne\Downloads\zoek.exe [Scan all users] [Script inserted] [Checkboxes used] ==== System Restore Info ====================== 15-11-2014 20:20:47 Zoek.exe System Restore Point Created Succesfully. ==== Empty Folders Check ====================== C:\PROGRA~2\SearchProtect deleted successfully C:\Users\Yvonne\AppData\Roaming\hpqlog deleted successfully C:\Users\Yvonne\AppData\Roaming\The Complete Genealogy Reporter - FTB deleted successfully C:\Users\Yvonne\AppData\Local\Adobe deleted successfully C:\Users\Yvonne\AppData\Local\VirtualStore deleted successfully ==== Deleting CLSID Registry Keys ====================== HKEY_USERS\S-1-5-21-138855871-1310491556-297829154-1002\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} deleted successfully HKEY_USERS\S-1-5-21-138855871-1310491556-297829154-1002\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} deleted successfully HKEY_USERS\S-1-5-21-138855871-1310491556-297829154-1002\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2476} deleted successfully HKEY_USERS\S-1-5-21-138855871-1310491556-297829154-1002\Software\Microsoft\Internet Explorer\SearchScopes\{C050665A-2F87-477C-9F36-8016FB0B71C0} deleted successfully HKEY_USERS\S-1-5-21-138855871-1310491556-297829154-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2B45FC73-27FA-40D3-AFC1-1A2488E8AE48} deleted successfully HKEY_USERS\S-1-5-21-138855871-1310491556-297829154-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C9FD6A97-8482-46AB-A288-3421F51BCA49} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Extensions\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} deleted successfully ==== Deleting CLSID Registry Values ====================== ==== Running Processes ====================== C:\Windows\SysWOW64\tbaseprovisioning.exe C:\Program Files (x86)\PC Veilig\fshoster32.exe C:\Program Files (x86)\PC Veilig\apps\CCF_Reputation\fsorsp.exe C:\Program Files (x86)\PC Veilig\apps\ComputerSecurity\Anti-Virus\FSGK32.EXE C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPWMISVC.exe C:\Program Files (x86)\HTC\HTC Sync Manager\HSMServiceEntry.exe C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe C:\Program Files (x86)\PC Veilig\apps\ComputerSecurity\Common\FSMA32.EXE C:\Program Files (x86)\PC Veilig\apps\ComputerSecurity\Anti-Virus\fssm32.exe C:\Program Files (x86)\HTC\HTC Sync Manager\HTC Sync\adb.exe C:\Users\Yvonne\AppData\Local\Pokki\Engine\pokki.exe C:\Users\Yvonne\AppData\Local\Pokki\Engine\pokki.exe C:\Users\Yvonne\AppData\Local\Pokki\Engine\pokki.exe C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPMSGSVC.exe C:\Program Files (x86)\PC Veilig\fshoster32.exe C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe C:\Program Files (x86)\CyberLink\YouCam\YouCamService.exe C:\Program Files (x86)\PC Veilig\apps\ComputerSecurity\Common\FSM32.EXE C:\Program Files (x86)\MyHeritage\Bin\FTBCheckUpdates.exe C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe C:\Users\Yvonne\AppData\Local\Pokki\Engine\pokki.exe C:\Users\Yvonne\AppData\Local\Pokki\Engine\pokki.exe C:\Users\Yvonne\Downloads\zoek.exe C:\Windows\SysWOW64\cmd.exe C:\Windows\SysWOW64\cmd.exe C:\Windows\SysWOW64\cmd.exe ==== Deleting Services ====================== ==== FireFox Fix ====================== ProfilePath: C:\Users\Yvonne\AppData\Roaming\Mozilla\Firefox\Profiles\bnxm0rxo.default user.js not found ---- Lines search.net removed from prefs.js ---- user_pref("browser.search.defaultenginename", "default-search.net"); user_pref("browser.search.order.1", "default-search.net"); user_pref("browser.search.selectedEngine", "default-search.net"); user_pref("keyword.URL", "http://www.default-search.net/search?sid=476&aid=134&itype=n&ver=14368&tm=531&src=ds&p="); ---- FireFox user.js and prefs.js backups ---- prefs_15-11-2014_2045_.backup ==== Registry Fix Code x64 ====================== Windows Registry Editor Version 5.00 [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}] [-HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "Pokki"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"=- ==== Deleting Files \ Folders ====================== C:\Program Files (x86)\Common Files\DVDVideoSoft not found C:\Program Files (x86)\SearchProtect not found C:\Users\Yvonne\AppData\Roaming\gtk-2.0 deleted C:\Users\Yvonne\AppData\Roaming\FirefoxToolbar deleted C:\ProgramData\374311380 deleted C:\Users\Yvonne\AppData\Roaming\RHEng deleted C:\Users\Yvonne\AppData\Roaming\DVDVideoSoft deleted C:\Users\Yvonne\.android deleted C:\PROGRA~2\Mozilla Firefox\browser\searchplugins\default-search.xml deleted C:\install.exe deleted C:\PROGRA~3\Package Cache deleted C:\Users\Default\AppData\Local\Pokki deleted C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Search.lnk deleted C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PC App Store.lnk deleted C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Start Menu.lnk deleted C:\Users\Yvonne\Downloads\SoftonicDownloader_for_transcriber.exe deleted C:\Users\Yvonne\Downloads\SoftonicDownloader_voor_free-audio-converter.exe deleted C:\Windows\SysNative\config\systemprofile\Searches deleted C:\Users\Yvonne\Documents\Optimizer Pro deleted "C:\Users\Yvonne\AppData\Local\Pokki\analytics.db" deleted "C:\Users\Yvonne\AppData\Local\Pokki\engine_update.db" deleted "C:\Users\Yvonne\AppData\Local\Pokki\notifications.db" deleted "C:\Users\Yvonne\AppData\Local\Pokki\ocdeskband_0.dll" deleted "C:\Users\Yvonne\AppData\Local\Pokki\Engine\avcodec-54.dll" deleted "C:\Users\Yvonne\AppData\Local\Pokki\Engine\avformat-54.dll" deleted "C:\Users\Yvonne\AppData\Local\Pokki\Engine\avutil-51.dll" deleted "C:\Users\Yvonne\AppData\Local\Pokki\Engine\chrome_100_percent.pak" deleted "C:\Users\Yvonne\AppData\Local\Pokki\Engine\D3DCompiler_43.dll" deleted "C:\Users\Yvonne\AppData\Local\Pokki\Engine\d3dx9_43.dll" deleted "C:\Users\Yvonne\AppData\Local\Pokki\Engine\en-US.pak" deleted "C:\Users\Yvonne\AppData\Local\Pokki\Engine\icudt.dll" deleted "C:\Users\Yvonne\AppData\Local\Pokki\Engine\libEGL.dll" deleted "C:\Users\Yvonne\AppData\Local\Pokki\Engine\libGLESv2.dll" deleted "C:\Users\Yvonne\AppData\Local\Pokki\Engine\libPokki.dll" deleted "C:\Users\Yvonne\AppData\Local\Pokki\Engine\pokki.exe" deleted "C:\Users\Yvonne\AppData\Local\Pokki\Engine\ppGoogleNaClPluginChrome.dll" deleted "C:\Users\Yvonne\AppData\Local\Pokki\Engine\resources.pak" deleted "C:\Users\Yvonne\AppData\Local\Pokki\Pokkies\installed_pokkies.db" not deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\lockfile" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\007eaa96e076fa29392da025f3f00a1b78de9742\Cookies" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\007eaa96e076fa29392da025f3f00a1b78de9742\Network Action Predictor" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\007eaa96e076fa29392da025f3f00a1b78de9742\Visited Links" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\007eaa96e076fa29392da025f3f00a1b78de9742-websheet\Cookies" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\007eaa96e076fa29392da025f3f00a1b78de9742-websheet\Network Action Predictor" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\3427d172d24e84772d70149f8c9b4046fc37354c\Cookies" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\3427d172d24e84772d70149f8c9b4046fc37354c\Cookies-journal" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\3427d172d24e84772d70149f8c9b4046fc37354c\Network Action Predictor" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\3427d172d24e84772d70149f8c9b4046fc37354c\Visited Links" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\3427d172d24e84772d70149f8c9b4046fc37354c-websheet\Cookies" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\3427d172d24e84772d70149f8c9b4046fc37354c-websheet\Network Action Predictor" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\46cb28dc316c165b81c8bb852e61aebfafab644f\Cookies" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\46cb28dc316c165b81c8bb852e61aebfafab644f\Cookies-journal" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\46cb28dc316c165b81c8bb852e61aebfafab644f\Network Action Predictor" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\46cb28dc316c165b81c8bb852e61aebfafab644f\Visited Links" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\46cb28dc316c165b81c8bb852e61aebfafab644f-websheet\Cookies" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\46cb28dc316c165b81c8bb852e61aebfafab644f-websheet\Network Action Predictor" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\58bd11530e2721039947049b97d2917175d63478\Cookies" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\58bd11530e2721039947049b97d2917175d63478\Network Action Predictor" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\58bd11530e2721039947049b97d2917175d63478\Visited Links" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\58bd11530e2721039947049b97d2917175d63478-websheet\Cookies" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\58bd11530e2721039947049b97d2917175d63478-websheet\Network Action Predictor" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\8c0b14e60879f2548bd19e9389102cafe32945cf\Cookies" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\8c0b14e60879f2548bd19e9389102cafe32945cf\Network Action Predictor" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\8c0b14e60879f2548bd19e9389102cafe32945cf\Visited Links" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\8c0b14e60879f2548bd19e9389102cafe32945cf-websheet\Cookies" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\8c0b14e60879f2548bd19e9389102cafe32945cf-websheet\Network Action Predictor" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\a65116cdc0b4377bed428e280c19949d56248d11\Cookies" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\a65116cdc0b4377bed428e280c19949d56248d11\Cookies-journal" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\a65116cdc0b4377bed428e280c19949d56248d11\Network Action Predictor" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\a65116cdc0b4377bed428e280c19949d56248d11\Visited Links" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\a65116cdc0b4377bed428e280c19949d56248d11-websheet\Cookies" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\a65116cdc0b4377bed428e280c19949d56248d11-websheet\Network Action Predictor" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\Default\Cookies" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\Default\Network Action Predictor" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\Default\Shortcuts" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1\Cookies" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1\Cookies-journal" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1\Network Action Predictor" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1\Visited Links" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1-websheet\Cookies" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1-websheet\Network Action Predictor" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\notifications\Cookies" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\notifications\Network Action Predictor" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\notifications\QuotaManager" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\notifications\QuotaManager-journal" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\notifications\Visited Links" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\notifications-websheet\Cookies" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\notifications-websheet\Network Action Predictor" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\007eaa96e076fa29392da025f3f00a1b78de9742\Cache\data_0" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\007eaa96e076fa29392da025f3f00a1b78de9742\Cache\data_1" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\007eaa96e076fa29392da025f3f00a1b78de9742\Cache\data_2" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\007eaa96e076fa29392da025f3f00a1b78de9742\Cache\data_3" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\007eaa96e076fa29392da025f3f00a1b78de9742\Cache\index" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\007eaa96e076fa29392da025f3f00a1b78de9742\Extension State\000053.log" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\007eaa96e076fa29392da025f3f00a1b78de9742\Extension State\LOCK" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\007eaa96e076fa29392da025f3f00a1b78de9742\Extension State\MANIFEST-000052" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\007eaa96e076fa29392da025f3f00a1b78de9742\User StyleSheets\Custom.css" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\007eaa96e076fa29392da025f3f00a1b78de9742-websheet\Cache\data_0" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\007eaa96e076fa29392da025f3f00a1b78de9742-websheet\Cache\data_1" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\007eaa96e076fa29392da025f3f00a1b78de9742-websheet\Cache\data_2" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\007eaa96e076fa29392da025f3f00a1b78de9742-websheet\Cache\data_3" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\007eaa96e076fa29392da025f3f00a1b78de9742-websheet\Cache\index" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\007eaa96e076fa29392da025f3f00a1b78de9742-websheet\Extension State\000053.log" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\007eaa96e076fa29392da025f3f00a1b78de9742-websheet\Extension State\LOCK" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\007eaa96e076fa29392da025f3f00a1b78de9742-websheet\Extension State\MANIFEST-000052" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\3427d172d24e84772d70149f8c9b4046fc37354c\Cache\data_0" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\3427d172d24e84772d70149f8c9b4046fc37354c\Cache\data_1" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\3427d172d24e84772d70149f8c9b4046fc37354c\Cache\data_2" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\3427d172d24e84772d70149f8c9b4046fc37354c\Cache\data_3" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\3427d172d24e84772d70149f8c9b4046fc37354c\Cache\index" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\3427d172d24e84772d70149f8c9b4046fc37354c\Extension State\000053.log" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\3427d172d24e84772d70149f8c9b4046fc37354c\Extension State\LOCK" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\3427d172d24e84772d70149f8c9b4046fc37354c\Extension State\MANIFEST-000052" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\3427d172d24e84772d70149f8c9b4046fc37354c\Session Storage\000080.log" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\3427d172d24e84772d70149f8c9b4046fc37354c\Session Storage\000081.sst" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\3427d172d24e84772d70149f8c9b4046fc37354c\Session Storage\LOCK" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\3427d172d24e84772d70149f8c9b4046fc37354c\Session Storage\MANIFEST-000078" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\3427d172d24e84772d70149f8c9b4046fc37354c\User StyleSheets\Custom.css" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\3427d172d24e84772d70149f8c9b4046fc37354c-websheet\Cache\data_0" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\3427d172d24e84772d70149f8c9b4046fc37354c-websheet\Cache\data_1" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\3427d172d24e84772d70149f8c9b4046fc37354c-websheet\Cache\data_2" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\3427d172d24e84772d70149f8c9b4046fc37354c-websheet\Cache\data_3" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\3427d172d24e84772d70149f8c9b4046fc37354c-websheet\Cache\index" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\3427d172d24e84772d70149f8c9b4046fc37354c-websheet\Extension State\000053.log" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\3427d172d24e84772d70149f8c9b4046fc37354c-websheet\Extension State\LOCK" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\3427d172d24e84772d70149f8c9b4046fc37354c-websheet\Extension State\MANIFEST-000052" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\46cb28dc316c165b81c8bb852e61aebfafab644f\Cache\data_0" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\46cb28dc316c165b81c8bb852e61aebfafab644f\Cache\data_1" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\46cb28dc316c165b81c8bb852e61aebfafab644f\Cache\data_2" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\46cb28dc316c165b81c8bb852e61aebfafab644f\Cache\data_3" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\46cb28dc316c165b81c8bb852e61aebfafab644f\Cache\index" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\46cb28dc316c165b81c8bb852e61aebfafab644f\Extension State\000055.log" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\46cb28dc316c165b81c8bb852e61aebfafab644f\Extension State\LOCK" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\46cb28dc316c165b81c8bb852e61aebfafab644f\Extension State\MANIFEST-000054" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\46cb28dc316c165b81c8bb852e61aebfafab644f\Local Storage\file__0.localstorage" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\46cb28dc316c165b81c8bb852e61aebfafab644f\Local Storage\file__0.localstorage-journal" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\46cb28dc316c165b81c8bb852e61aebfafab644f\Media Cache\data_0" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\46cb28dc316c165b81c8bb852e61aebfafab644f\Media Cache\data_1" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\46cb28dc316c165b81c8bb852e61aebfafab644f\Media Cache\data_2" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\46cb28dc316c165b81c8bb852e61aebfafab644f\Media Cache\data_3" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\46cb28dc316c165b81c8bb852e61aebfafab644f\Media Cache\index" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\46cb28dc316c165b81c8bb852e61aebfafab644f\Session Storage\000043.log" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\46cb28dc316c165b81c8bb852e61aebfafab644f\Session Storage\LOCK" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\46cb28dc316c165b81c8bb852e61aebfafab644f\Session Storage\MANIFEST-000041" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\46cb28dc316c165b81c8bb852e61aebfafab644f\User StyleSheets\Custom.css" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\46cb28dc316c165b81c8bb852e61aebfafab644f-websheet\Cache\data_0" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\46cb28dc316c165b81c8bb852e61aebfafab644f-websheet\Cache\data_1" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\46cb28dc316c165b81c8bb852e61aebfafab644f-websheet\Cache\data_2" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\46cb28dc316c165b81c8bb852e61aebfafab644f-websheet\Cache\data_3" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\46cb28dc316c165b81c8bb852e61aebfafab644f-websheet\Cache\index" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\46cb28dc316c165b81c8bb852e61aebfafab644f-websheet\Extension State\000055.log" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\46cb28dc316c165b81c8bb852e61aebfafab644f-websheet\Extension State\LOCK" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\46cb28dc316c165b81c8bb852e61aebfafab644f-websheet\Extension State\MANIFEST-000054" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\58bd11530e2721039947049b97d2917175d63478\Cache\data_0" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\58bd11530e2721039947049b97d2917175d63478\Cache\data_1" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\58bd11530e2721039947049b97d2917175d63478\Cache\data_2" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\58bd11530e2721039947049b97d2917175d63478\Cache\data_3" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\58bd11530e2721039947049b97d2917175d63478\Cache\index" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\58bd11530e2721039947049b97d2917175d63478\Extension State\000053.log" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\58bd11530e2721039947049b97d2917175d63478\Extension State\LOCK" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\58bd11530e2721039947049b97d2917175d63478\Extension State\MANIFEST-000052" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\58bd11530e2721039947049b97d2917175d63478\User StyleSheets\Custom.css" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\58bd11530e2721039947049b97d2917175d63478-websheet\Cache\data_0" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\58bd11530e2721039947049b97d2917175d63478-websheet\Cache\data_1" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\58bd11530e2721039947049b97d2917175d63478-websheet\Cache\data_2" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\58bd11530e2721039947049b97d2917175d63478-websheet\Cache\data_3" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\58bd11530e2721039947049b97d2917175d63478-websheet\Cache\index" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\58bd11530e2721039947049b97d2917175d63478-websheet\Extension State\000053.log" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\58bd11530e2721039947049b97d2917175d63478-websheet\Extension State\LOCK" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\58bd11530e2721039947049b97d2917175d63478-websheet\Extension State\MANIFEST-000052" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\8c0b14e60879f2548bd19e9389102cafe32945cf\Cache\data_0" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\8c0b14e60879f2548bd19e9389102cafe32945cf\Cache\data_1" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\8c0b14e60879f2548bd19e9389102cafe32945cf\Cache\data_2" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\8c0b14e60879f2548bd19e9389102cafe32945cf\Cache\data_3" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\8c0b14e60879f2548bd19e9389102cafe32945cf\Cache\index" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\8c0b14e60879f2548bd19e9389102cafe32945cf\Extension State\000053.log" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\8c0b14e60879f2548bd19e9389102cafe32945cf\Extension State\LOCK" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\8c0b14e60879f2548bd19e9389102cafe32945cf\Extension State\MANIFEST-000052" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\8c0b14e60879f2548bd19e9389102cafe32945cf\Session Storage\000055.sst" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\8c0b14e60879f2548bd19e9389102cafe32945cf\Session Storage\000057.sst" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\8c0b14e60879f2548bd19e9389102cafe32945cf\Session Storage\000060.sst" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\8c0b14e60879f2548bd19e9389102cafe32945cf\Session Storage\000063.sst" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\8c0b14e60879f2548bd19e9389102cafe32945cf\Session Storage\000064.log" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\8c0b14e60879f2548bd19e9389102cafe32945cf\Session Storage\LOCK" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\8c0b14e60879f2548bd19e9389102cafe32945cf\Session Storage\MANIFEST-000062" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\8c0b14e60879f2548bd19e9389102cafe32945cf\User StyleSheets\Custom.css" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\8c0b14e60879f2548bd19e9389102cafe32945cf-websheet\Cache\data_0" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\8c0b14e60879f2548bd19e9389102cafe32945cf-websheet\Cache\data_1" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\8c0b14e60879f2548bd19e9389102cafe32945cf-websheet\Cache\data_2" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\8c0b14e60879f2548bd19e9389102cafe32945cf-websheet\Cache\data_3" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\8c0b14e60879f2548bd19e9389102cafe32945cf-websheet\Cache\index" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\8c0b14e60879f2548bd19e9389102cafe32945cf-websheet\Extension State\000053.log" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\8c0b14e60879f2548bd19e9389102cafe32945cf-websheet\Extension State\LOCK" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\8c0b14e60879f2548bd19e9389102cafe32945cf-websheet\Extension State\MANIFEST-000052" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\a65116cdc0b4377bed428e280c19949d56248d11\Cache\data_0" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\a65116cdc0b4377bed428e280c19949d56248d11\Cache\data_1" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\a65116cdc0b4377bed428e280c19949d56248d11\Cache\data_2" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\a65116cdc0b4377bed428e280c19949d56248d11\Cache\data_3" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\a65116cdc0b4377bed428e280c19949d56248d11\Cache\index" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\a65116cdc0b4377bed428e280c19949d56248d11\Extension State\000055.log" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\a65116cdc0b4377bed428e280c19949d56248d11\Extension State\LOCK" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\a65116cdc0b4377bed428e280c19949d56248d11\Extension State\MANIFEST-000054" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\a65116cdc0b4377bed428e280c19949d56248d11\User StyleSheets\Custom.css" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\a65116cdc0b4377bed428e280c19949d56248d11-websheet\Cache\data_0" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\a65116cdc0b4377bed428e280c19949d56248d11-websheet\Cache\data_1" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\a65116cdc0b4377bed428e280c19949d56248d11-websheet\Cache\data_2" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\a65116cdc0b4377bed428e280c19949d56248d11-websheet\Cache\data_3" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\a65116cdc0b4377bed428e280c19949d56248d11-websheet\Cache\index" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\a65116cdc0b4377bed428e280c19949d56248d11-websheet\Extension State\000055.log" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\a65116cdc0b4377bed428e280c19949d56248d11-websheet\Extension State\LOCK" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\a65116cdc0b4377bed428e280c19949d56248d11-websheet\Extension State\MANIFEST-000054" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\Default\Cache\data_0" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\Default\Cache\data_1" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\Default\Cache\data_2" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\Default\Cache\data_3" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\Default\Cache\index" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\Default\Extension State\000055.log" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\Default\Extension State\LOCK" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\Default\Extension State\MANIFEST-000054" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1\Cache\data_0" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1\Cache\data_1" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1\Cache\data_2" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1\Cache\data_3" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1\Cache\index" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1\Extension State\000055.log" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1\Extension State\LOCK" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1\Extension State\MANIFEST-000054" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1\Session Storage\000055.sst" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1\Session Storage\000057.sst" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1\Session Storage\000060.sst" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1\Session Storage\000061.log" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1\Session Storage\LOCK" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1\Session Storage\MANIFEST-000059" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1\User StyleSheets\Custom.css" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1-websheet\Cache\data_0" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1-websheet\Cache\data_1" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1-websheet\Cache\data_2" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1-websheet\Cache\data_3" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1-websheet\Cache\index" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1-websheet\Extension State\000055.log" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1-websheet\Extension State\LOCK" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1-websheet\Extension State\MANIFEST-000054" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\notifications\Cache\data_0" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\notifications\Cache\data_1" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\notifications\Cache\data_2" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\notifications\Cache\data_3" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\notifications\Cache\index" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\notifications\databases\Databases.db" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\notifications\Extension State\000055.log" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\notifications\Extension State\LOCK" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\notifications\Extension State\MANIFEST-000054" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\notifications\Local Storage\file__0.localstorage" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\notifications\Local Storage\file__0.localstorage-journal" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\notifications\User StyleSheets\Custom.css" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\notifications\databases\file__0\1" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\notifications-websheet\Cache\data_0" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\notifications-websheet\Cache\data_1" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\notifications-websheet\Cache\data_2" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\notifications-websheet\Cache\data_3" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\notifications-websheet\Cache\index" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\notifications-websheet\Extension State\000055.log" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\notifications-websheet\Extension State\LOCK" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\notifications-websheet\Extension State\MANIFEST-000054" deleted "C:\Users\Yvonne\AppData\Local\Pokki" not deleted "C:\Users\Yvonne\AppData\Local\Pokki\Engine" deleted "C:\Users\Yvonne\AppData\Local\Pokki\Pokkies" not deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\007eaa96e076fa29392da025f3f00a1b78de9742" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\007eaa96e076fa29392da025f3f00a1b78de9742-websheet" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\3427d172d24e84772d70149f8c9b4046fc37354c" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\3427d172d24e84772d70149f8c9b4046fc37354c-websheet" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\46cb28dc316c165b81c8bb852e61aebfafab644f" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\46cb28dc316c165b81c8bb852e61aebfafab644f-websheet" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\58bd11530e2721039947049b97d2917175d63478" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\58bd11530e2721039947049b97d2917175d63478-websheet" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\8c0b14e60879f2548bd19e9389102cafe32945cf" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\8c0b14e60879f2548bd19e9389102cafe32945cf-websheet" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\a65116cdc0b4377bed428e280c19949d56248d11" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\a65116cdc0b4377bed428e280c19949d56248d11-websheet" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\Default" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1-websheet" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\notifications" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\notifications-websheet" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\007eaa96e076fa29392da025f3f00a1b78de9742\Cache" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\007eaa96e076fa29392da025f3f00a1b78de9742\Extension State" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\007eaa96e076fa29392da025f3f00a1b78de9742\User StyleSheets" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\007eaa96e076fa29392da025f3f00a1b78de9742-websheet\Cache" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\007eaa96e076fa29392da025f3f00a1b78de9742-websheet\Extension State" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\3427d172d24e84772d70149f8c9b4046fc37354c\Cache" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\3427d172d24e84772d70149f8c9b4046fc37354c\Extension State" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\3427d172d24e84772d70149f8c9b4046fc37354c\Session Storage" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\3427d172d24e84772d70149f8c9b4046fc37354c\User StyleSheets" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\3427d172d24e84772d70149f8c9b4046fc37354c-websheet\Cache" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\3427d172d24e84772d70149f8c9b4046fc37354c-websheet\Extension State" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\46cb28dc316c165b81c8bb852e61aebfafab644f\Cache" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\46cb28dc316c165b81c8bb852e61aebfafab644f\Extension State" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\46cb28dc316c165b81c8bb852e61aebfafab644f\Local Storage" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\46cb28dc316c165b81c8bb852e61aebfafab644f\Media Cache" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\46cb28dc316c165b81c8bb852e61aebfafab644f\Session Storage" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\46cb28dc316c165b81c8bb852e61aebfafab644f\User StyleSheets" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\46cb28dc316c165b81c8bb852e61aebfafab644f-websheet\Cache" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\46cb28dc316c165b81c8bb852e61aebfafab644f-websheet\Extension State" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\58bd11530e2721039947049b97d2917175d63478\Cache" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\58bd11530e2721039947049b97d2917175d63478\Extension State" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\58bd11530e2721039947049b97d2917175d63478\User StyleSheets" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\58bd11530e2721039947049b97d2917175d63478-websheet\Cache" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\58bd11530e2721039947049b97d2917175d63478-websheet\Extension State" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\8c0b14e60879f2548bd19e9389102cafe32945cf\Cache" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\8c0b14e60879f2548bd19e9389102cafe32945cf\Extension State" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\8c0b14e60879f2548bd19e9389102cafe32945cf\Session Storage" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\8c0b14e60879f2548bd19e9389102cafe32945cf\User StyleSheets" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\8c0b14e60879f2548bd19e9389102cafe32945cf-websheet\Cache" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\8c0b14e60879f2548bd19e9389102cafe32945cf-websheet\Extension State" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\a65116cdc0b4377bed428e280c19949d56248d11\Cache" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\a65116cdc0b4377bed428e280c19949d56248d11\Extension State" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\a65116cdc0b4377bed428e280c19949d56248d11\User StyleSheets" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\a65116cdc0b4377bed428e280c19949d56248d11-websheet\Cache" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\a65116cdc0b4377bed428e280c19949d56248d11-websheet\Extension State" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\Default\Cache" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\Default\Extension State" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1\Cache" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1\Extension State" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1\Session Storage" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1\User StyleSheets" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1-websheet\Cache" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1-websheet\Extension State" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\notifications\Cache" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\notifications\databases" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\notifications\Extension State" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\notifications\Local Storage" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\notifications\User StyleSheets" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\notifications\databases\file__0" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\notifications-websheet\Cache" deleted "C:\Users\Yvonne\AppData\Local\Pokki\UserData\notifications-websheet\Extension State" deleted ==== System Specs ====================== Windows: Windows Version 6.2 (Build 9200) Memory (RAM): 3520 MB CPU Info: AMD E1-6010 APU with AMD Radeon R2 Graphics CPU Speed: 1351,6 MHz Sound Card: luidspreker/Hoofdtelefoon (Real | Display Adapters: AMD Radeon(TM) R2 Graphics | AMD Radeon(TM) R2 Graphics Monitors: 1x; Generic PnP Monitor | Screen Resolution: 1600 X 900 - 32 bit Network: Network Present Network Adapters: Microsoft Wi-Fi Direct Virtual Adapter | Realtek RTL8723BE 802.11 b/g/n Wi-Fi Adapter | Realtek PCIe FE Family Controller CD / DVD Drives: 1x (E: | ) E: hp DVDRAM GU90N Ports: COM Ports NOT Present. LPT Port NOT Present. Mouse: 5 Button Wheel Mouse Present Hard Disks: C: 446,6GB | D: 18,1GB Hard Disks - Free: C: 410,4GB | D: 1,8GB Manufacturer *: American Megatrends Inc. BIOS Info: AT/AT COMPATIBLE | | HPQOEM - 1072009 Time Zone: West-Europa (standaardtijd) Motherboard *: Hewlett-Packard 226A Country: Nederland Language: NLD ==== System Specs (Software) ====================== Anti-Virus: Computer Beveiliging On-access scanning disabled (Outdated) Anti-Virus: Windows Defender On-access scanning disabled (Outdated) Anti-Spyware: Computer Beveiliging disabled (Outdated) Anti-Spyware: Windows Defender disabled (Outdated) Default Browser: Firefox 33.1 Internet Explorer Version: 11.0.9600.17416 Mozilla Firefox version: 33.1 (x86 en-US) Flash Player version: 15.0.0.223 Shockwave Player version: 12.0.4r144 ==== Files Recently Created / Modified ====================== ====== C:\Windows ==== 2014-11-02 13:49:56 CED7EE72D5F05FE98A96806B4D1AA5FF 19637 ----a-w- C:\Windows\prodsett_copy.ini 2014-10-26 15:56:54 ACDBE1ED38167C8B01B8F63161BB2CEA 2374784 ----a-w- C:\Windows\explorer.exe ====== C:\Users\Yvonne\AppData\Local\Temp ==== 2014-11-14 15:48:21 A44F853FBA48CAF151F9840F6D9B7433 115120 ----a-w- C:\Users\Yvonne\AppData\Local\Temp\smw_FF.exe 2014-11-14 14:43:52 10FD5D9085A7EE8681B419432285359D 8737784 ----a-w- C:\Users\Yvonne\AppData\Local\Temp\SettingsManagerSetup.exe 2014-11-14 14:16:03 DD7F24DACD85EEDD221A55313E97DA10 5826632 ----a-w- C:\Users\Yvonne\AppData\Local\Temp\optprosetup.exe 2014-11-12 22:49:12 41CB698F967B4D9F2580EA2A21A5A710 107320 ----a-w- C:\Users\Yvonne\AppData\Local\Temp\{DE54845C-6540-44AE-983F-0E9CD198FE33}\ISBEW64.exe ====== Java Cache ===== ====== C:\Windows\SysWOW64 ===== 2014-11-11 20:38:40 07330241FD9D9A03811DDBDC4F9FD18F 19781632 ----a-w- C:\Windows\SysWOW64\mshtml.dll 2014-11-11 20:33:50 154532E0EC2317E6924A9D27F894FF2F 12819456 ----a-w- C:\Windows\SysWOW64\ieframe.dll 2014-11-11 20:33:07 3CA90FDAB95FB2B0D91249BEDE3DE0D9 4298240 ----a-w- C:\Windows\SysWOW64\jscript9.dll 2014-11-11 20:32:59 03D7DF4711B851EF286562F97429211D 1892864 ----a-w- C:\Windows\SysWOW64\wininet.dll 2014-11-11 20:32:55 027A2CF002AD94399B51C07E855E3B2B 1310208 ----a-w- C:\Windows\SysWOW64\urlmon.dll 2014-11-11 20:32:51 F169B03C4B9996708DB20FF0C875B4FF 880128 ----a-w- C:\Windows\SysWOW64\inetcomm.dll 2014-11-11 20:32:50 98D83B6B4FBA32C39585D1E07121BEA0 2277376 ----a-w- C:\Windows\SysWOW64\iertutil.dll 2014-11-11 20:32:48 8A88AD059EDC1014D5D6A472A6D1D66C 661504 ----a-w- C:\Windows\SysWOW64\jscript.dll 2014-11-11 20:32:44 8FC2FB51EB90E6AA582BDBA39C1935FD 620032 ----a-w- C:\Windows\SysWOW64\jscript9diag.dll 2014-11-11 20:32:43 A6145F4F8C69C3B46653B1C5E75A7BD6 688640 ----a-w- C:\Windows\SysWOW64\msfeeds.dll 2014-11-11 20:32:42 EF7A48E5955736BEECF0B0ABB478E90E 478208 ----a-w- C:\Windows\SysWOW64\ieui.dll 2014-11-11 20:32:40 E855B15E1BE0B58F84843D31F4CC4795 501248 ----a-w- C:\Windows\SysWOW64\vbscript.dll 2014-11-11 20:32:38 108D84EE2359C595CCEA32820A2D5405 2051072 ----a-w- C:\Windows\SysWOW64\inetcpl.cpl 2014-11-11 20:32:36 1BE74145FDF58734CFE968063533FBEC 708096 ----a-w- C:\Windows\SysWOW64\ieapfltr.dll 2014-11-11 20:32:35 7B0D22C64F9B6A8CD79EFADD29700693 285696 ----a-w- C:\Windows\SysWOW64\dxtrans.dll 2014-11-11 20:32:34 7BCC24D058205664BD700D272B169AEC 418304 ----a-w- C:\Windows\SysWOW64\dxtmsft.dll 2014-11-11 20:32:29 9F6204775EB03156B430FD095E3D0B5C 325632 ----a-w- C:\Windows\SysWOW64\iedkcs32.dll 2014-11-11 20:32:29 151E64E5D34DFB95D57B5B97C50DE64D 230400 ----a-w- C:\Windows\SysWOW64\webcheck.dll 2014-11-11 20:32:26 BE5EDCACB9E83C3695F650094367740C 99328 ----a-w- C:\Windows\SysWOW64\hlink.dll 2014-11-11 20:32:25 8DFBD587DBEBBC8EB50AD169DE88C449 340992 ----a-w- C:\Windows\SysWOW64\html.iec 2014-11-11 20:32:24 236AD481F1632F4CE7E9835FFD4AF41D 168960 ----a-w- C:\Windows\SysWOW64\msrating.dll 2014-11-11 20:32:22 ED5A4451A1A2777C6C5DB4238FD09078 115712 ----a-w- C:\Windows\SysWOW64\ieUnatt.exe 2014-11-11 20:32:22 DCFF6E5356CFF5B50BBA0FAAE01A0412 90624 ----a-w- C:\Windows\SysWOW64\iesysprep.dll 2014-11-11 20:32:22 8A109878FA68DD1A4C91D8D499797E22 128000 ----a-w- C:\Windows\SysWOW64\iepeers.dll 2014-11-11 20:32:21 45CDC0E37774D30BEE8C5F62CE30D599 1042944 ----a-w- C:\Windows\SysWOW64\actxprxy.dll 2014-11-11 20:32:21 1D391C687102569FD1EA154F0C1A4CE8 91136 ----a-w- C:\Windows\SysWOW64\inseng.dll 2014-11-11 20:32:20 615D259116D1B331911CE28C8CD1CCF3 73216 ----a-w- C:\Windows\SysWOW64\tdc.ocx 2014-11-11 20:32:19 0FEEFF4B96CA5972121F59525142A14E 52736 ----a-w- C:\Windows\SysWOW64\msfeedsbs.dll 2014-11-11 20:32:19 02FF387F6228169EDDCB41F5E4B1A4E4 47104 ----a-w- C:\Windows\SysWOW64\jsproxy.dll 2014-11-11 20:32:18 FC51834D5057B9D7847666AE88BC981C 130048 ----a-w- C:\Windows\SysWOW64\occache.dll 2014-11-11 20:32:18 971D57DFB6F3FBC98EB74D1AF8E3C13B 76288 ----a-w- C:\Windows\SysWOW64\mshtmled.dll 2014-11-11 20:32:17 F1313045CDCBBC4C90C34AEF67CEE088 112128 ----a-w- C:\Windows\SysWOW64\IEAdvpack.dll 2014-11-11 20:32:16 159199095C9959BE75E61C0FF947708F 152064 ----a-w- C:\Windows\SysWOW64\iexpress.exe 2014-11-11 20:32:15 FCAF49AE2E10EF3823262D10E7F2D0DE 60416 ----a-w- C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2014-11-11 20:32:14 8D1E12756ED6F1FDB026AD3CF264F90C 40448 ----a-w- C:\Windows\SysWOW64\imgutil.dll 2014-11-11 20:32:14 53E15B8DBD615567CA8895D65746C8D3 64000 ----a-w- C:\Windows\SysWOW64\MshtmlDac.dll 2014-11-11 20:32:13 59607FB7C6B84860CE2D1C5F7C57E052 47616 ----a-w- C:\Windows\SysWOW64\ieetwproxystub.dll 2014-11-11 20:32:12 316280CC22CBB15271A91D83CDFB73C3 27136 ----a-w- C:\Windows\SysWOW64\licmgr10.dll 2014-11-11 20:32:12 0812A503FF349D1DCEEB820B2E4FEE15 57344 ----a-w- C:\Windows\SysWOW64\pngfilt.dll 2014-11-11 20:32:11 EF7B7299A1D6604AD3CA2CE1BEF8C8F3 30720 ----a-w- C:\Windows\SysWOW64\iernonce.dll 2014-11-11 20:32:11 A66A88FFE53BBB9DDAACE0110A8232EC 137728 ----a-w- C:\Windows\SysWOW64\wextract.exe 2014-11-11 20:32:10 3C544C566EE7091AC52D4D9156C62687 235520 ----a-w- C:\Windows\SysWOW64\url.dll 2014-11-11 20:32:10 26F4BDB6EA83011885E217A51A4A3E68 62464 ----a-w- C:\Windows\SysWOW64\iesetup.dll 2014-11-11 20:32:07 3FA76B67F25D84B3C2A4E8A8C0919E6E 12800 ----a-w- C:\Windows\SysWOW64\mshta.exe 2014-11-11 20:32:07 1BD4CD20A25B4A3A5F7BAAC25E9D9202 11264 ----a-w- C:\Windows\SysWOW64\msfeedssync.exe 2014-11-11 20:30:18 5F333FDBF392850373C89BDA31EBEC1B 1346048 ----a-w- C:\Windows\SysWOW64\user32.dll 2014-11-11 20:30:15 3B45EA6108E48406828D4E015FF41DD0 12800 ----a-w- C:\Windows\SysWOW64\winshfhc.dll 2014-11-11 20:29:48 46FBD043A1688EFD6AC1395EE886AD33 3607040 ----a-w- C:\Windows\SysWOW64\msi.dll 2014-11-11 20:29:43 B09332CC976AC43EFF595B6F01AA275C 2459136 ----a-w- C:\Windows\SysWOW64\authui.dll 2014-11-11 20:29:42 48C20EB77757F22840FF4CED98D8DEB1 325120 ----a-w- C:\Windows\SysWOW64\msihnd.dll 2014-11-11 20:29:10 BC426A818B7F3DB5F509BC1B62FF1501 357376 ----a-w- C:\Windows\SysWOW64\schannel.dll 2014-11-11 20:29:09 B2AC9E081A847ACBD5B62BE25AF39DA1 88800 ----a-w- C:\Windows\SysWOW64\ncryptsslp.dll 2014-11-11 20:28:11 791BDC9FD3C95F92C7DB2162132C8645 324096 ----a-w- C:\Windows\SysWOW64\certcli.dll 2014-11-11 20:28:10 A22688490DCC2DA19441CA09EF7299BF 736768 ----a-w- C:\Windows\SysWOW64\adtschema.dll 2014-11-11 20:28:09 DDAAC7C966436938526D4CF4C6042A5C 154112 ----a-w- C:\Windows\SysWOW64\msaudite.dll 2014-11-11 20:27:50 F344D6066EA270AABABA83E2A6B6428F 723968 ----a-w- C:\Windows\SysWOW64\wuapi.dll 2014-11-11 20:27:49 DC523277A7EC2336A654960E08EB5BDC 81920 ----a-w- C:\Windows\SysWOW64\wudriver.dll 2014-11-11 20:27:49 529122F3ADC548F0CCBB6164D86FA116 124928 ----a-w- C:\Windows\SysWOW64\wuwebv.dll 2014-11-11 20:27:48 C17F3F1EE09758CF9D234B22B80A1006 25600 ----a-w- C:\Windows\SysWOW64\wups.dll 2014-11-11 20:27:48 514AEA6CF4B70FAA30A2BC4B4CC10A39 29696 ----a-w- C:\Windows\SysWOW64\wuapp.exe 2014-11-11 20:27:24 75D0FAD0165770819770628239BF57DB 602768 ----a-w- C:\Windows\SysWOW64\oleaut32.dll 2014-11-11 20:23:26 3BF6BEBD0A5666BDB426A734A4578D9B 1346048 ----a-w- C:\Windows\SysWOW64\msxml3.dll 2014-11-11 20:23:19 FACBA112943A89FBB8AC25085521924F 344536 ----a-w- C:\Windows\SysWOW64\AUDIOKSE.dll 2014-11-11 20:23:18 22B2920A0857BDD61B1331C30AD76F30 424544 ----a-w- C:\Windows\SysWOW64\AudioEng.dll 2014-11-11 20:23:18 0CBA301F325F922FAFB3B83AD3337BB2 370424 ----a-w- C:\Windows\SysWOW64\AudioSes.dll 2014-11-11 20:23:14 D1A07DE4DC408E5AA5CFBAE261919BDC 72192 ----a-w- C:\Windows\SysWOW64\packager.dll 2014-11-11 20:22:29 CA23E168518460519DC8D49EC6AD9550 18723112 ----a-w- C:\Windows\SysWOW64\shell32.dll 2014-11-11 20:22:04 1FB4389CA807D59B105B0827FCC8F768 11820544 ----a-w- C:\Windows\SysWOW64\twinui.dll 2014-11-11 20:22:02 1793FC07D568C930C04F9FF40FFF9A69 799744 ----a-w- C:\Windows\SysWOW64\MFMediaEngine.dll 2014-11-11 20:22:02 0EEE3F2278E447498B2CDBDF34C63C91 670384 ----a-w- C:\Windows\SysWOW64\mfmp4srcsnk.dll 2014-11-11 20:21:58 C1AD30D5E28B4291D4A16BC6944ABC0C 2030592 ----a-w- C:\Windows\SysWOW64\WsmSvc.dll 2014-11-11 20:21:57 A208DEE0CD61E24817C26D5A05503DA7 334336 ----a-w- C:\Windows\SysWOW64\puiobj.dll 2014-11-11 20:21:54 17FC09725FEE2546B96A938288509719 485376 ----a-w- C:\Windows\SysWOW64\untfs.dll 2014-11-11 20:21:46 46C1902654FF54C835E4C4E8C14B7F2A 239104 ----a-w- C:\Windows\SysWOW64\FXSAPI.dll 2014-11-03 12:20:37 59609ED124D91AFE76B131615DFCB326 2029056 ----a-w- C:\Windows\SysWOW64\PDFDocScout.DLL 2014-11-03 12:20:36 FB23C632BE3EECB4E1F59857EFAB857B 606208 ----a-w- C:\Windows\SysWOW64\HexUniRTFBox.ocx 2014-11-03 12:20:36 F04ADF34F2D3C589D2E5635C68FA8B3D 454656 ----a-w- C:\Windows\SysWOW64\PaintX.dll 2014-11-03 12:20:36 1AA06C81A0621E277E755B965B5E4B5F 372736 ----a-w- C:\Windows\SysWOW64\ijl15.dll 2014-11-03 12:20:35 F8D176DB5B14AED7C9B25E0640226BD1 258352 ----a-w- C:\Windows\SysWOW64\unicows.dll 2014-11-03 12:20:35 EB5F811C1F78005B3C147599A0CCCF51 608448 ----a-w- C:\Windows\SysWOW64\comctl32.ocx 2014-11-03 12:20:35 D329085A88A9019ED5700C0F04B3176E 137000 ----a-w- C:\Windows\SysWOW64\msmapi32.ocx ====== C:\Windows\SysWOW64\drivers ===== 2014-11-02 13:51:14 FCC27D6498B065AC2B7397623563A200 41024 ----a-w- C:\Windows\SysWOW64\drivers\fsbts.sys ====== C:\Windows\Sysnative ===== 2014-11-11 20:38:44 6432F143CDC9D73BD2BF832CAB2EDC01 25110016 ----a-w- C:\Windows\Sysnative\mshtml.dll 2014-11-11 20:34:25 BED4D30B7FF094E368333CE2D1CE3195 14390272 ----a-w- C:\Windows\Sysnative\ieframe.dll 2014-11-11 20:33:18 079FEE6FC11A74E4309B6A10931C1CB2 6040064 ----a-w- C:\Windows\Sysnative\jscript9.dll 2014-11-11 20:33:01 BF1FC65A307B31939ADF7F976FDE033C 2365440 ----a-w- C:\Windows\Sysnative\wininet.dll 2014-11-11 20:32:57 559E084EEBE44864493B2903433F19B3 1550336 ----a-w- C:\Windows\Sysnative\urlmon.dll 2014-11-11 20:32:54 22CBDB8810CBED0B4F5E4BE69D7E2AE8 2884096 ----a-w- C:\Windows\Sysnative\iertutil.dll 2014-11-11 20:32:53 46B5DD7C4B1851F59E48302185E076DF 1032704 ----a-w- C:\Windows\Sysnative\inetcomm.dll 2014-11-11 20:32:52 62D54F4673A6208C8CC147758122B3C3 2865152 ----a-w- C:\Windows\Sysnative\actxprxy.dll 2014-11-11 20:32:48 DE58DE2C6C8439B7174D6D3568AA4A80 814080 ----a-w- C:\Windows\Sysnative\jscript9diag.dll 2014-11-11 20:32:47 0D03DAD6BB183156C70F863D0F2FA55A 812544 ----a-w- C:\Windows\Sysnative\jscript.dll 2014-11-11 20:32:46 587DEBB59F5F14C9610966FB14A33607 633856 ----a-w- C:\Windows\Sysnative\ieui.dll 2014-11-11 20:32:45 200CEA827BDC503F00C0AED0EA227D49 800768 ----a-w- C:\Windows\Sysnative\msfeeds.dll 2014-11-11 20:32:41 258C3082AD82C1AAD335DA3FE2D3EB25 580096 ----a-w- C:\Windows\Sysnative\vbscript.dll 2014-11-11 20:32:36 175C139D51F99099D1BDA17794B02191 490496 ----a-w- C:\Windows\Sysnative\dxtmsft.dll 2014-11-11 20:32:35 F7522B00C823794F86ABD5BE1F3D6B09 316928 ----a-w- C:\Windows\Sysnative\dxtrans.dll 2014-11-11 20:32:34 62E2FCF45F349DE6CAFB3AA7E1D81DA4 2124288 ----a-w- C:\Windows\Sysnative\inetcpl.cpl 2014-11-11 20:32:33 BC3B7CCE855F9A8E7BC96F7062229A02 799232 ----a-w- C:\Windows\Sysnative\ieapfltr.dll 2014-11-11 20:32:31 A7F53772ECAE2F44B455D14F71179940 48640 ----a-w- C:\Windows\Sysnative\ieetwproxystub.dll 2014-11-11 20:32:30 853BB696932E4C48EE7034BFF1209A5A 262144 ----a-w- C:\Windows\Sysnative\webcheck.dll 2014-11-11 20:32:26 9CD8D475F462F82E6FD8BFCA7186ACD4 372736 ----a-w- C:\Windows\Sysnative\iedkcs32.dll 2014-11-11 20:32:25 F0A53129AE95A895EC8C4DC36E1797A2 108544 ----a-w- C:\Windows\Sysnative\hlink.dll 2014-11-11 20:32:24 FD7C8FAC461BED1FEEB808E477D884D4 716800 ----a-w- C:\Windows\Sysnative\ie4uinit.exe 2014-11-11 20:32:24 8AE1AC97407CD82D8389390C21430579 111616 ----a-w- C:\Windows\Sysnative\iesysprep.dll 2014-11-11 20:32:24 1C3C54FA2D620DF3093F356A56EC5957 144384 ----a-w- C:\Windows\Sysnative\ieUnatt.exe 2014-11-11 20:32:23 E40D3696BE4852956669C285038B37A6 114688 ----a-w- C:\Windows\Sysnative\ieetwcollector.exe 2014-11-11 20:32:23 AF28C90094C4C50F083599C10D2DC072 145408 ----a-w- C:\Windows\Sysnative\iepeers.dll 2014-11-11 20:32:21 2E475D2FCE0125FA0C486DB9D59E739B 417280 ----a-w- C:\Windows\Sysnative\html.iec 2014-11-11 20:32:20 C9AB2198141844D3DF96B4552CE9D5AB 77824 ----a-w- C:\Windows\Sysnative\JavaScriptCollectionAgent.dll 2014-11-11 20:32:20 A348DEFC16B6FBC88B7D61C3B861BCB1 107520 ----a-w- C:\Windows\Sysnative\inseng.dll 2014-11-11 20:32:20 00FB2FB8C27C834CF575BC415B80F995 87552 ----a-w- C:\Windows\Sysnative\tdc.ocx 2014-11-11 20:32:19 85E97591864F3125C5B08FB44E0E8078 60416 ----a-w- C:\Windows\Sysnative\msfeedsbs.dll 2014-11-11 20:32:19 2CEACC509889A095828F27115257408D 92160 ----a-w- C:\Windows\Sysnative\mshtmled.dll 2014-11-11 20:32:18 F79E5258AF040A8AD83C7C1273A071C3 54784 ----a-w- C:\Windows\Sysnative\jsproxy.dll 2014-11-11 20:32:17 70576D76A11DD5AE54E719297A315F90 88064 ----a-w- C:\Windows\Sysnative\MshtmlDac.dll 2014-11-11 20:32:16 3721721151DB49457B0FD35E0C04594C 199680 ----a-w- C:\Windows\Sysnative\msrating.dll 2014-11-11 20:32:15 DD8FD33C108F14681A410067AB21DDF3 152064 ----a-w- C:\Windows\Sysnative\occache.dll 2014-11-11 20:32:14 161BC2E883A8D8759A4DCF2A85AF9128 51200 ----a-w- C:\Windows\Sysnative\imgutil.dll 2014-11-11 20:32:13 D66D11191B48007179B0A77DC0717267 33280 ----a-w- C:\Windows\Sysnative\licmgr10.dll 2014-11-11 20:32:13 6096209CB47D61499C3608B9C25B073C 64512 ----a-w- C:\Windows\Sysnative\pngfilt.dll 2014-11-11 20:32:11 6A7F8D139610E5F3F158182778EF9275 34304 ----a-w- C:\Windows\Sysnative\iernonce.dll 2014-11-11 20:32:10 F54E1190251EB245183BF16D6C315613 237568 ----a-w- C:\Windows\Sysnative\url.dll 2014-11-11 20:32:09 CDC8A85EB301A8CBE55A81A1D55AF5E5 132096 ----a-w- C:\Windows\Sysnative\IEAdvpack.dll 2014-11-11 20:32:09 4B9C652BD0FD95A9E6123913C35519D6 143872 ----a-w- C:\Windows\Sysnative\wextract.exe 2014-11-11 20:32:08 E99E2E88BFE584184AE92B1F8995CE93 66560 ----a-w- C:\Windows\Sysnative\iesetup.dll 2014-11-11 20:32:07 CA2F3153EF3BCB0BD3A8984C933DF604 167424 ----a-w- C:\Windows\Sysnative\iexpress.exe 2014-11-11 20:32:06 A3871DED5ED88F59C0D1396761708F81 13824 ----a-w- C:\Windows\Sysnative\mshta.exe 2014-11-11 20:32:06 66585D645C4E23A0FD5124BD714AE020 12800 ----a-w- C:\Windows\Sysnative\msfeedssync.exe 2014-11-11 20:30:19 F0A117D19873FCDF801F082F33BFBB6C 1519488 ----a-w- C:\Windows\Sysnative\user32.dll 2014-11-11 20:30:15 668417ED63F9FBE7DD8D7A54B04279DA 14336 ----a-w- C:\Windows\Sysnative\winshfhc.dll 2014-11-11 20:29:47 EF745B98D81B8C462DB99FC8B5C4322A 3320320 ----a-w- C:\Windows\Sysnative\msi.dll 2014-11-11 20:29:45 D5B41A0C38408814A3E9BAC8C82B2E5B 2773504 ----a-w- C:\Windows\Sysnative\authui.dll 2014-11-11 20:29:42 D1A2E993DB1867C79177CCC9DB6337D0 116032 ----a-w- C:\Windows\Sysnative\consent.exe 2014-11-11 20:29:42 D0C15BC83B3D0AF4F9B1D70216D91794 428032 ----a-w- C:\Windows\Sysnative\msihnd.dll 2014-11-11 20:29:42 034ED41F13D9C1845C1E081F05B640DB 110080 ----a-w- C:\Windows\Sysnative\appinfo.dll 2014-11-11 20:29:10 F0CE4A653EEBA09509EAF93AE2226FA9 426496 ----a-w- C:\Windows\Sysnative\schannel.dll 2014-11-11 20:29:09 6DE50D5592C6EE18C87B0C2EEEDC1621 185856 ----a-w- C:\Windows\Sysnative\dpapisrv.dll 2014-11-11 20:29:09 622928F5A8045F8122F10561D6C35ED0 104336 ----a-w- C:\Windows\Sysnative\ncryptsslp.dll 2014-11-11 20:28:13 1D25CC0A9C480C5D56A5A6CF2B5DEB99 3547648 ----a-w- C:\Windows\Sysnative\rdpcorets.dll 2014-11-11 20:28:12 949E590B76018E4523FC71CE510ED9ED 1441792 ----a-w- C:\Windows\Sysnative\lsasrv.dll 2014-11-11 20:28:11 488CEA4F1B4D2446FFB7A94E3CB385FE 445440 ----a-w- C:\Windows\Sysnative\certcli.dll 2014-11-11 20:28:10 91E59FCB3B32DD84E5DCDA2EA1583807 736768 ----a-w- C:\Windows\Sysnative\adtschema.dll 2014-11-11 20:28:10 3D2D2EA099D98FE6B94C7D8C7992C08C 40448 ----a-w- C:\Windows\Sysnative\rfxvmt.dll 2014-11-11 20:28:09 A8484FB640E044858BA19FB4F13DD4CE 154112 ----a-w- C:\Windows\Sysnative\msaudite.dll 2014-11-11 20:28:08 D7B23B3154508256C9F434EF9B65B91D 131584 ----a-w- C:\Windows\Sysnative\rdpudd.dll 2014-11-11 20:27:53 DCD090318EC800CF6275C6835900B0C6 3557376 ----a-w- C:\Windows\Sysnative\wuaueng.dll 2014-11-11 20:27:51 BCC10D47920E83EAC8F2E7E2D414692E 894976 ----a-w- C:\Windows\Sysnative\wuapi.dll 2014-11-11 20:27:50 2585412FC573F298FCBFD6759F8C4C0F 1714176 ----a-w- C:\Windows\Sysnative\wucltux.dll 2014-11-11 20:27:49 E67B019D23320AA0C5F1E6DE5D30546A 407552 ----a-w- C:\Windows\Sysnative\WUSettingsProvider.dll 2014-11-11 20:27:49 5D67074419BBFDCA587C2E2A93743E8A 140288 ----a-w- C:\Windows\Sysnative\wuwebv.dll 2014-11-11 20:27:48 EA2DF5520D3623F353F43809A2F88086 55776 ----a-w- C:\Windows\Sysnative\wuauclt.exe 2014-11-11 20:27:48 CCE7F88AD038494253B485EC1B144EB3 60416 ----a-w- C:\Windows\Sysnative\wups.dll 2014-11-11 20:27:48 70AC0FA699C9420CB282CCF72993C2E1 51712 ----a-w- C:\Windows\Sysnative\wups2.dll 2014-11-11 20:27:48 2E66E7D4F1E39F7048A231AA60FD2532 95744 ----a-w- C:\Windows\Sysnative\wudriver.dll 2014-11-11 20:27:47 4D94560FD4982BB52C1FE64AE38E1A9F 35840 ----a-w- C:\Windows\Sysnative\wuapp.exe 2014-11-11 20:27:47 4A112AD7D9C7289FE9945D05E97019D0 17408 ----a-w- C:\Windows\Sysnative\wuaext.dll 2014-11-11 20:27:24 9A108C0A3092110F4651B3AFB9CC7B3D 789184 ----a-w- C:\Windows\Sysnative\oleaut32.dll 2014-11-11 20:23:25 93645AEBE163230A2ED5050C14AE6603 2149376 ----a-w- C:\Windows\Sysnative\msxml3.dll 2014-11-11 20:23:19 C0484CA5C7F87E38909746B63C7FC868 911360 ----a-w- C:\Windows\Sysnative\audiosrv.dll 2014-11-11 20:23:19 9C88C9397B44B76E5C9A44B8E2CE53A1 500016 ----a-w- C:\Windows\Sysnative\AudioSes.dll 2014-11-11 20:23:19 8085F95BB18A171E7221D2831BC08BC2 394120 ----a-w- C:\Windows\Sysnative\AUDIOKSE.dll 2014-11-11 20:23:18 DFDFDE2EA4B5CD0606BA6E56ECEE502D 272248 ----a-w- C:\Windows\Sysnative\audiodg.exe 2014-11-11 20:23:18 BB93DAAAE9006598935192B9CB65E475 108432 ----a-w- C:\Windows\Sysnative\EncDump.dll 2014-11-11 20:23:18 9F87516BF76C40B41D831F7D729A6044 482872 ----a-w- C:\Windows\Sysnative\AudioEng.dll 2014-11-11 20:23:18 7F70B1044272982AAEA7C16E83424770 226304 ----a-w- C:\Windows\Sysnative\AudioEndpointBuilder.dll 2014-11-11 20:23:16 B31C4917EC5EADE24A90DDAF37EA00E0 4182016 ----a-w- C:\Windows\Sysnative\win32k.sys 2014-11-11 20:23:14 84549E8C8BF76B293A7E625A98D4BCF9 81408 ----a-w- C:\Windows\Sysnative\packager.dll 2014-11-11 20:23:12 9E20A052D83A81AEC35B2EA29F32637A 391168 ----a-w- C:\Windows\Sysnative\devinv.dll 2014-11-11 20:23:12 91BB0DDA472733457072DA61178FA48E 228864 ----a-w- C:\Windows\Sysnative\aepdu.dll 2014-11-11 20:23:10 D18149850795E7203610CEE9491515F1 304128 ----a-w- C:\Windows\Sysnative\generaltel.dll 2014-11-11 20:23:10 22ED46DE0E684749DA1BD703526FAA26 537088 ----a-w- C:\Windows\Sysnative\aeinv.dll 2014-11-11 20:23:08 F00E643D9244F31ECF5DE8A98C2C5FC6 98816 ----a-w- C:\Windows\Sysnative\aepic.dll 2014-11-11 20:22:41 1D303CE5BCBD5B80BBA08321F28A3F86 21197152 ----a-w- C:\Windows\Sysnative\shell32.dll 2014-11-11 20:22:35 BCE66E78D388875B87286CA091E7075F 7484224 ----a-w- C:\Windows\Sysnative\ntoskrnl.exe 2014-11-11 20:22:21 1907823D5ACFD75D1D8C0D4318299726 2714112 ----a-w- C:\Windows\Sysnative\SettingsHandlers.dll 2014-11-11 20:22:16 C4306ADC38939CAC60EA38AAD9F170C0 13424128 ----a-w- C:\Windows\Sysnative\twinui.dll 2014-11-11 20:22:13 C88B63FE96DB4BCED65DD442BC8E77F5 1053184 ----a-w- C:\Windows\Sysnative\localspl.dll 2014-11-11 20:22:12 A208498C5CD750A1743C1AC8162A810F 941568 ----a-w- C:\Windows\Sysnative\MFMediaEngine.dll 2014-11-11 20:22:10 CA729FCE295895515A09BD6FF7903DC8 836176 ----a-w- C:\Windows\Sysnative\mfmp4srcsnk.dll 2014-11-11 20:22:02 50E96089F9BE352621997143A56C8E76 822272 ----a-w- C:\Windows\Sysnative\win32spl.dll 2014-11-11 20:21:59 9CE162EB9057CF079736F4DD00FC0D6C 2480128 ----a-w- C:\Windows\Sysnative\WsmSvc.dll 2014-11-11 20:21:58 5416C603B6C85CF0698E8A2A1D28BAA2 448512 ----a-w- C:\Windows\Sysnative\puiobj.dll 2014-11-11 20:21:54 8758F5DEBD2B950B2D56ED11F9E0B38F 545792 ----a-w- C:\Windows\Sysnative\untfs.dll 2014-11-11 20:21:51 6C118AEDD15FDBEAECC0E85C64B5B86B 615424 ----a-w- C:\Windows\Sysnative\FXSCOMEX.dll 2014-11-11 20:21:47 9C55CE9707B3CA29A6505BCDCC546390 275968 ----a-w- C:\Windows\Sysnative\FXSAPI.dll 2014-11-11 20:21:44 A92EF73B02686B7E6F070B486512DB88 389176 ----a-w- C:\Windows\Sysnative\ApnDatabase.xml ====== C:\Windows\Sysnative\drivers ===== 2014-11-12 22:37:49 D41D8CD98F00B204E9800998ECF8427E 0 ---ha-w- C:\Windows\Sysnative\drivers\Msft_User_WpdMtpDr_01_11_00.Wdf 2014-11-11 20:30:17 DE8D12B4C3F55FA2C5E9774314F6C58A 258368 ----a-w- C:\Windows\Sysnative\drivers\WdFilter.sys 2014-11-11 20:30:17 4AD874CDC812EC156265E451B6B09DAB 114496 ----a-w- C:\Windows\Sysnative\drivers\WdNisDrv.sys 2014-11-11 20:30:16 0359607177E5E9F6041136CC0A5CB0B6 35320 ----a-w- C:\Windows\Sysnative\drivers\WdBoot.sys 2014-11-11 20:28:11 6D2EE96150E35B9EA49F2B481DE0369A 177472 ----a-w- C:\Windows\Sysnative\drivers\ksecpkg.sys 2014-11-11 20:28:11 4E1207CE16E615B0B7A70DC889F4500E 563976 ----a-w- C:\Windows\Sysnative\drivers\cng.sys 2014-11-11 20:28:10 9F08A6608F98B5407E7DDBCF306573EF 27456 ----a-w- C:\Windows\Sysnative\drivers\rdpvideominiport.sys 2014-11-11 20:22:14 CCB3A2BB60FE5073F2DEA63FE83CF8FE 2497344 ----a-w- C:\Windows\Sysnative\drivers\tcpip.sys 2014-11-11 20:22:01 E3FCE2A6B3533D99A3B498504DF9CC47 474432 ----a-w- C:\Windows\Sysnative\drivers\netio.sys 2014-11-11 20:21:56 66732C13628BDB1AB0D6FD46027327C2 148800 ----a-w- C:\Windows\Sysnative\drivers\USBSTOR.SYS 2014-11-11 20:21:55 7F23E38C5B6448F91439E4066645191E 428864 ----a-w- C:\Windows\Sysnative\drivers\FWPKCLNT.SYS 2014-11-02 13:57:24 F59F2C574AA5D84477EB89F87C938F16 56016 ----a-w- C:\Windows\Sysnative\drivers\fsbts.sys 2014-10-29 23:21:33 6416E79A58A8FCC33A447A4DDDD3BF04 412160 ----a-w- C:\Windows\Sysnative\drivers\srv.sys 2014-10-29 23:21:29 038C77D577900EE39410662478BB0D50 2009920 ----a-w- C:\Windows\Sysnative\drivers\ntfs.sys 2014-10-29 23:21:27 5BED3AB69797C8786EF70AEA8C33748B 674816 ----a-w- C:\Windows\Sysnative\drivers\srv2.sys 2014-10-29 23:21:22 FF78D053A05E5A394F4E3C1816CC65A8 143680 -c--a-w- C:\Windows\Sysnative\drivers\usbccgp.sys 2014-10-29 23:21:18 240C5C3793206725AA05665851E8C214 412992 -c--a-w- C:\Windows\Sysnative\drivers\spaceport.sys 2014-10-29 23:21:15 64CA2B4A49A8EAF495E435623ECCE7DB 310080 -c--a-w- C:\Windows\Sysnative\drivers\volsnap.sys 2014-10-29 23:21:12 D047CD668E6277FD80F0C613946F034C 246272 ----a-w- C:\Windows\Sysnative\drivers\srvnet.sys 2014-10-29 23:21:12 26ACA481FAFEC59FE311D719E3027BBA 446976 ----a-w- C:\Windows\Sysnative\drivers\nwifi.sys 2014-10-29 23:21:11 1DD05F4857C2188744B9E864658949DD 295424 ----a-w- C:\Windows\Sysnative\drivers\ks.sys 2014-10-29 23:21:10 FEF0BC107812B36849741C3211BA6B60 419648 -c--a-w- C:\Windows\Sysnative\drivers\usbhub.sys 2014-10-29 23:21:03 E4B4BE2D7750849C07589DA0B0AABA01 1118040 ----a-w- C:\Windows\Sysnative\drivers\ndis.sys 2014-10-29 23:21:02 D4B7ED39C7900384D9E5C1283F1E7926 76800 -c--a-w- C:\Windows\Sysnative\drivers\hdaudbus.sys 2014-10-29 23:21:02 C910E5D18958914A66F0E45689D0B40A 206848 ----a-w- C:\Windows\Sysnative\drivers\mrxsmb20.sys 2014-10-29 23:21:02 B1AA3B19A2E596A59224F893E01A5A75 126464 ----a-w- C:\Windows\Sysnative\drivers\NdisImPlatform.sys 2014-10-29 23:20:52 91ED124E261EA8FAA1C0FFDF2A71B0C4 280384 -c--a-w- C:\Windows\Sysnative\drivers\pci.sys 2014-10-29 23:20:50 9C096BF5E10CA8BFA56F32522A89FAF1 79872 ----a-w- C:\Windows\Sysnative\drivers\IPMIDrv.sys 2014-10-29 23:20:31 25BB93167DEF270188072603F92A1EF5 118272 -c--a-w- C:\Windows\Sysnative\drivers\bthpan.sys 2014-10-27 00:24:57 8DF1254093B5C354CE725EB6B9B0DE19 146752 ----a-w- C:\Windows\Sysnative\drivers\msgpioclx.sys 2014-10-27 00:24:24 374E27295F0A9DCAA8FC96370F9BEEA5 563200 ----a-w- C:\Windows\Sysnative\drivers\afd.sys 2014-10-27 00:21:17 313DCE665B57000B18CB26C6B6A10DFE 1557848 ----a-w- C:\Windows\Sysnative\drivers\dxgkrnl.sys 2014-10-26 16:09:00 182561A14F2E93E81E66FE3700D17A5A 55328 ----a-w- C:\Windows\Sysnative\drivers\wpcfltr.sys 2014-10-26 15:59:00 7A1A3F213CDB3363D179D5014272025D 402432 ----a-w- C:\Windows\Sysnative\drivers\mrxsmb.sys 2014-10-26 15:58:53 674A4702E4E144E8710ED1A2EC6DD049 96768 ----a-w- C:\Windows\Sysnative\drivers\agilevpn.sys 2014-10-26 15:58:50 65ED7B9CFEA893DF7748D5FF692690DE 38912 ----a-w- C:\Windows\Sysnative\drivers\vwifimp.sys 2014-10-26 15:58:46 35BF5C5F5E3C9902C98978C7640574DA 71680 ----a-w- C:\Windows\Sysnative\drivers\vwififlt.sys 2014-10-26 15:54:58 97B9076611291AE4C4C107BC915BD026 1200640 -c--a-w- C:\Windows\Sysnative\drivers\bthport.sys 2014-10-26 15:54:53 65392F3F3F65E4C6CC82A0F4F8A0B051 468288 -c--a-w- C:\Windows\Sysnative\drivers\USBHUB3.SYS 2014-10-26 15:54:38 E0927EFA25D473367C3341B9F5969779 115712 ----a-w- C:\Windows\Sysnative\drivers\bridge.sys 2014-10-26 15:50:28 FE0ADF5028EB8C1339B66B3AEDE3FEF9 440664 -c--a-w- C:\Windows\Sysnative\drivers\usbport.sys 2014-10-26 15:50:28 7CCBBCEE408A5DBE3FE47297DB5A6CFC 227840 ----a-w- C:\Windows\Sysnative\drivers\WUDFRd.sys 2014-10-26 15:50:27 D537815E450A149752C15868392AD1F3 110592 ----a-w- C:\Windows\Sysnative\drivers\WUDFPf.sys 2014-10-26 15:50:26 D79920BE4E6683D3AB50F71457A4F6C6 27480 -c--a-w- C:\Windows\Sysnative\drivers\usbd.sys 2014-10-26 15:50:26 48BA326A3DBA5B5BEB5F2777F4618696 89944 -c--a-w- C:\Windows\Sysnative\drivers\usbehci.sys 2014-10-26 15:50:26 064260B3A5868AC894A4943543BC7AB7 37376 -c--a-w- C:\Windows\Sysnative\drivers\usbuhci.sys 2014-10-26 15:48:01 F152D55E497E12256290C43B31C7D0CE 589656 ----a-w- C:\Windows\Sysnative\drivers\fvevol.sys 2014-10-26 15:48:00 CADCE0D6C30427F70A4BFA426256F68C 337240 ----a-w- C:\Windows\Sysnative\drivers\Classpnp.sys 2014-10-26 15:47:59 D90AB68D0FAC9F357F663670FDBB511E 275800 -c--a-w- C:\Windows\Sysnative\drivers\msiscsi.sys 2014-10-26 15:47:58 4C1E71E37B56C768900B1FCF81205027 372568 ----a-w- C:\Windows\Sysnative\drivers\storport.sys 2014-10-26 15:47:57 6592D192E2823C043EDBC010E7774053 360792 ----a-w- C:\Windows\Sysnative\drivers\fltMgr.sys 2014-10-25 07:08:51 D41D8CD98F00B204E9800998ECF8427E 0 ---ha-w- C:\Windows\Sysnative\drivers\Msft_User_LocationProvider_01_11_00.Wdf ====== C:\Windows\Tasks ====== 2014-10-27 02:20:01 4C3CE6BFD56C1B0084B3FA0BB274A008 3828 ----a-w- C:\Windows\Sysnative\Tasks\Adobe Flash Player Updater 2014-10-27 02:20:01 225B56D06DB6DCBD66121F3AA85EAA85 940 ----a-w- C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-10-25 07:17:34 3E33FD497257D587200AE02FAAA72DF6 3954 ----a-w- C:\Windows\Sysnative\Tasks\User_Feed_Synchronization-{8AB3D51D-57CD-437A-B316-81A5AE10845C} 2014-10-25 07:05:22 6A73AE426322981640C2DEF444EBD128 3596 ----a-w- C:\Windows\Sysnative\Tasks\Optimize Start Menu Cache Files-S-1-5-21-138855871-1310491556-297829154-1002 2014-10-25 07:00:23 -------- d-----w- C:\Windows\Sysnative\Tasks\WPD ====== C:\Windows\Temp ====== ======= C:\Program Files ===== 2014-11-15 17:30:49 -------- d-----w- C:\Program Files\trend micro 2014-11-08 23:56:49 -------- d-----w- C:\Program Files\Microsoft Silverlight 2014-10-26 11:10:54 -------- d-----w- C:\Program Files\Microsoft Office ======= C:\PROGRA~2 ===== 2014-11-12 22:50:18 -------- d-----w- C:\PROGRA~2\COMMON~1\Nero 2014-11-12 22:49:15 -------- d-----w- C:\PROGRA~2\Spirent Communications 2014-11-12 22:46:29 -------- d-----w- C:\PROGRA~2\HTC 2014-11-08 23:56:49 -------- d-----w- C:\PROGRA~2\Microsoft Silverlight 2014-11-05 17:39:51 -------- d-----w- C:\PROGRA~2\yWriter5 2014-11-03 12:19:15 -------- d-----w- C:\PROGRA~2\MyHeritage 2014-11-02 13:44:21 -------- d-----w- C:\PROGRA~2\PC Veilig 2014-10-31 18:44:42 -------- d-----w- C:\PROGRA~2\COMMON~1\DESIGNER 2014-10-26 11:15:21 -------- d-----w- C:\PROGRA~2\Microsoft Works 2014-10-26 11:14:54 -------- d-----w- C:\PROGRA~2\Microsoft Visual Studio 2014-10-26 11:10:41 -------- d-----w- C:\PROGRA~2\Microsoft Visual Studio 8 2014-10-26 01:26:01 -------- d-----w- C:\PROGRA~2\WebSite X5 v10 - Evolution 2014-10-25 07:21:26 -------- d-----w- C:\PROGRA~2\Mozilla Maintenance Service ======= C: ===== ====== C:\Users\Yvonne\AppData\Roaming ====== 2014-11-15 18:56:25 -------- d-sh--w- C:\Users\Yvonne\AppData\Local\EmieBrowserModeList 2014-11-15 18:55:40 -------- d-sh--w- C:\Users\Yvonne\AppData\Locallow\EmieBrowserModeList 2014-11-14 14:45:58 -------- d-----w- C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TranscriberAG 2014-11-14 14:04:34 -------- d-----w- C:\Users\Yvonne\AppData\Roaming\Audacity 2014-11-12 22:51:22 -------- d-----w- C:\Users\Yvonne\AppData\Roaming\HTC 2014-11-12 22:50:50 -------- d-----w- C:\Users\Yvonne\AppData\Roaming\Apple Computer 2014-11-12 22:50:50 -------- d-----w- C:\Users\Yvonne\AppData\Local\Apple Computer 2014-11-12 22:50:49 -------- d-----w- C:\Users\Yvonne\AppData\Local\HTC MediaHub 2014-11-12 22:47:26 -------- d-----w- C:\Users\Yvonne\AppData\Local\Downloaded Installations 2014-11-05 17:40:21 -------- d-----w- C:\Users\Yvonne\AppData\Roaming\Spacejock Software 2014-11-05 17:39:58 -------- d-----w- C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Spacejock Software 2014-11-05 17:39:26 -------- d-----w- C:\Users\Yvonne\AppData\Local\Programs 2014-11-03 12:21:11 -------- d-----w- C:\Users\Yvonne\AppData\Roaming\MyHeritage 2014-11-03 12:20:39 -------- d-----w- C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MyHeritage.com 2014-11-02 13:50:44 -------- d-----w- C:\Windows\sysWoW64\config\systemprofile\AppData\Roaming\f-secure 2014-11-02 13:48:25 -------- d-----w- C:\Windows\serviceprofiles\networkservice\AppData\Local\F-Secure 2014-11-02 13:11:56 -------- d-s---w- C:\Windows\serviceprofiles\networkservice\AppData\Locallow\Microsoft 2014-11-01 01:28:11 -------- d-----w- C:\Windows\sysWoW64\config\systemprofile\AppData\Roaming\Microsoft 2014-10-29 22:51:03 -------- d-----w- C:\Users\Yvonne\AppData\Local\Pokki 2014-10-28 23:04:30 -------- d-----w- C:\Users\Default\AppData\Local\Microsoft Help 2014-10-28 23:04:30 -------- d-----w- C:\Users\Default User\AppData\Local\Microsoft Help 2014-10-27 19:18:45 DC447CF958F3ECEEB70C5AC2A5F5D0E2 129088 ----a-w- C:\Users\Yvonne\AppData\Local\GDIPFONTCACHEV1.DAT 2014-10-27 00:06:45 -------- d-s---w- C:\Windows\sysWoW64\config\systemprofile\AppData\Locallow\Microsoft 2014-10-26 12:16:55 -------- d-----w- C:\Users\Yvonne\AppData\Roaming\Identities 2014-10-26 11:09:42 -------- d-----w- C:\Users\Yvonne\AppData\Local\Microsoft Help 2014-10-26 03:05:05 -------- d-----w- C:\Users\Yvonne\AppData\Roaming\CyberLink 2014-10-26 01:36:27 -------- d-----w- C:\Users\Yvonne\AppData\Local\Incomedia 2014-10-25 07:21:36 -------- d-----w- C:\Users\Yvonne\AppData\Roaming\Mozilla 2014-10-25 07:21:36 -------- d-----w- C:\Users\Yvonne\AppData\Local\Mozilla 2014-10-25 07:18:20 -------- d-sh--w- C:\Users\Yvonne\AppData\Locallow\EmieUserList 2014-10-25 07:18:07 -------- d-sh--w- C:\Users\Yvonne\AppData\Local\EmieUserList 2014-10-25 07:18:07 -------- d-sh--w- C:\Users\Yvonne\AppData\Local\EmieSiteList 2014-10-25 07:17:30 -------- d-sh--w- C:\Users\Yvonne\AppData\Locallow\EmieSiteList 2014-10-25 07:08:54 -------- d-s---w- C:\Windows\serviceprofiles\Localservice\AppData\Locallow\Microsoft 2014-10-25 07:05:37 -------- d-----w- C:\Windows\serviceprofiles\Localservice\AppData\Local\PnrpSqm 2014-10-25 07:03:28 -------- d-----w- C:\Users\Yvonne\AppData\Roaming\Hewlett-Packard 2014-10-25 07:02:32 -------- d-----w- C:\Windows\serviceprofiles\Localservice\AppData\Roaming\PeerNetworking 2014-10-25 07:01:54 -------- d-----w- C:\Users\Yvonne\AppData\Local\CyberLink 2014-10-25 07:00:29 -------- d-----w- C:\Users\Yvonne\AppData\Local\Hewlett-Packard 2014-10-25 06:59:54 -------- d-----r- C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-10-25 06:59:54 -------- d-----r- C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2014-10-25 06:59:47 -------- d-----w- C:\Users\Yvonne\AppData\Roaming\Adobe 2014-10-25 06:59:30 -------- d-----w- C:\Users\Yvonne\AppData\Local\Packages 2014-10-25 06:59:19 -------- d-----w- C:\Users\Yvonne\AppData\Roaming\Synaptics 2014-10-25 06:58:54 -------- d-s---w- C:\Users\Yvonne\AppData\Locallow\Microsoft 2014-10-25 06:58:21 -------- d-----w- C:\Users\Yvonne\AppData\Local\Microsoft 2014-10-25 06:58:20 -------- d-s---w- C:\Users\Yvonne\AppData\Roaming\Microsoft 2014-10-25 06:58:20 -------- d-----w- C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance 2014-10-25 06:58:20 -------- d-----w- C:\Users\Yvonne\AppData\Local\Temp 2014-10-25 06:58:20 -------- d-----r- C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools 2014-10-25 06:58:20 -------- d-----r- C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories 2014-10-25 06:58:20 -------- d-----r- C:\Users\Yvonne\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility ====== C:\Users\Yvonne ====== 2014-11-15 17:29:57 8045ABB21A3BDD66A48E1ED5C0F0EF6A 1222144 ----a-w- C:\Users\Yvonne\Downloads\RSITx64.exe 2014-11-14 15:50:08 8DE9F588DFB1641F2C0EA05BD4B60605 218 ----a-w- C:\Users\Yvonne\.recently-used.xbel 2014-11-14 14:57:10 -------- d-----w- C:\Users\Yvonne\WorkAG 2014-11-14 14:57:09 -------- d-----w- C:\Users\Yvonne\.TransAG 2014-11-14 14:56:46 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TranscriberAG 2014-11-14 14:08:52 367268538061C648B0744C7D35BE73DB 69204344 ----a-w- C:\Users\Yvonne\Downloads\FreeStudio.exe 2014-11-14 14:01:52 79943BE44F8288EDC375E3599331F8FF 22892794 ----a-w- C:\Users\Yvonne\Downloads\audacity-win-2.0.6.exe 2014-11-12 22:49:28 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HTC 2014-11-12 22:45:34 -------- d-----w- C:\ProgramData\HTC 2014-11-08 23:56:54 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 2014-11-08 23:56:11 2EDE6612B7042D8582819CAB084E6883 13087456 ----a-w- C:\Users\Yvonne\Downloads\Silverlight_x64.exe 2014-11-05 17:39:04 78C99844546B6B09444357DD08E978BB 2142107 ----a-w- C:\Users\Yvonne\Downloads\yWriter5Full.exe 2014-11-03 12:21:11 -------- d-----w- C:\ProgramData\MyHeritage 2014-11-03 12:12:04 6ECF2174AC366D7E84D04DC3FFAC8633 36986424 ----a-w- C:\Users\Yvonne\Downloads\family_tree_builder_7138.exe 2014-11-02 13:44:46 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC Veilig 2014-11-02 12:55:01 -------- d-----w- C:\ProgramData\F-Secure 2014-11-02 12:54:41 14830F556A34906E10AEB43D139ACEE1 871464 ----a-w- C:\Users\Yvonne\Downloads\PCveilig.exe 2014-11-02 12:54:26 14830F556A34906E10AEB43D139ACEE1 871464 ----a-w- C:\Users\Yvonne\Downloads\PCveilig_CRRY-31Q5-DCN3-PHE0-RBLK_.exe 2014-10-26 11:17:12 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2014-10-26 11:09:36 -------- d-----w- C:\ProgramData\Microsoft Help 2014-10-26 01:36:05 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WebSite X5 v10 - Evolution 2014-10-25 07:21:27 -------- d-----w- C:\ProgramData\Mozilla 2014-10-25 07:05:29 -------- d---a-w- C:\Users\Yvonne\OneDrive 2014-10-25 06:59:54 -------- d-----r- C:\Users\Yvonne\Searches 2014-10-25 06:59:53 -------- d-----r- C:\Users\Yvonne\Contacts 2014-10-25 06:58:52 6FC234AD3752E1267B34FB12BCD6718B 20 --sh--w- C:\Users\Yvonne\ntuser.ini 2014-10-25 06:58:20 -------- d--h--w- C:\Users\Yvonne\AppData 2014-10-25 06:58:20 -------- d-----r- C:\Users\Yvonne\Videos 2014-10-25 06:58:20 -------- d-----r- C:\Users\Yvonne\Saved Games 2014-10-25 06:58:20 -------- d-----r- C:\Users\Yvonne\Pictures 2014-10-25 06:58:20 -------- d-----r- C:\Users\Yvonne\Music 2014-10-25 06:58:20 -------- d-----r- C:\Users\Yvonne\Links 2014-10-25 06:58:20 -------- d-----r- C:\Users\Yvonne\Favorites 2014-10-25 06:58:20 -------- d-----r- C:\Users\Yvonne\Downloads 2014-10-25 06:58:20 -------- d-----r- C:\Users\Yvonne\Documents 2014-10-25 06:58:20 -------- d-----r- C:\Users\Yvonne\Desktop 2014-10-25 06:46:08 -------- d--h--r- C:\Users\Public\AccountPictures ====== C: exe-files == 2014-11-15 17:30:56 9A2347903D6EDB84C10F288BC0578C1C 388608 ----a-w- C:\Program Files\trend micro\Yvonne.exe 2014-11-14 15:51:44 09A7C1FB08D69B6B18A12471077DD27C 544 ----a-w- C:\$Recycle.Bin\S-1-5-21-138855871-1310491556-297829154-1002\$IQ78HYA.exe 2014-11-14 15:50:23 8E0E08EAA8CE5CF59B35F14DC51ACF8C 544 ----a-w- C:\$Recycle.Bin\S-1-5-21-138855871-1310491556-297829154-1002\$IYBM3M5.exe 2014-11-14 15:48:21 F75218DE6A663362B1432E10827C503D 27272432 ----a-w- C:\$Recycle.Bin\S-1-5-21-138855871-1310491556-297829154-1002\$RQ78HYA.exe 2014-11-14 14:43:52 0842AED83A7D1C9BF44A7752DE298CD3 46406878 ----a-w- C:\$Recycle.Bin\S-1-5-21-138855871-1310491556-297829154-1002\$RYBM3M5.exe 2014-11-14 14:15:52 E3990388EBDB77E2B6B853AB6C0F2DD7 6004728 ----a-w- C:\Users\Yvonne\AppData\Local\Microsoft\Windows\INetCache\IE\0YAW2RN3\OptimizerPro[1].exe 2014-11-14 14:10:42 8A15089480AE0CC703BF3A8C1D7922E6 7475096 ----a-w- C:\Users\Yvonne\AppData\Local\Microsoft\Windows\INetCache\IE\HQW7U1AR\SPSetup[1].exe 2014-11-14 14:10:38 D41D8CD98F00B204E9800998ECF8427E 0 ----a-w- C:\Users\Yvonne\AppData\Local\Microsoft\Windows\INetCache\IE\H29TE9W0\spstub[1].exe 2014-11-14 14:10:38 AE9DC93C1788422A2AFFA1F804F498A6 177432 ----a-w- C:\Users\Yvonne\AppData\Local\Microsoft\Windows\INetCache\IE\1LA7U6M4\spstub[1].exe 2014-11-12 22:45:35 18D4794703F8ADCFF38DDF51074E002A 136049912 ----a-w- C:\ProgramData\HTC\HTC MediaHub\HSMSetup\HSMSetup.exe 2014-11-11 20:32:17 5AC6DB399DE418E3955F0CA4567BDD37 813712 ----a-w- C:\Program Files\Internet Explorer\iexplore.exe 2014-11-11 20:32:15 5F1B1148C830C0F149A476A58CE0D09D 815248 ----a-w- C:\Program Files (x86)\Internet Explorer\iexplore.exe 2014-11-11 20:32:13 8D7C6EE90630126F79275BAC5FE16E51 468992 ----a-w- C:\Program Files (x86)\Internet Explorer\ieinstal.exe 2014-11-11 20:32:11 8CFC152DF5D4FCFD621EF3E231999D03 484352 ----a-w- C:\Program Files\Internet Explorer\ieinstal.exe 2014-11-11 20:32:09 CFB15ED916904B30D32DFDE29B67CDCC 25600 ----a-w- C:\Program Files (x86)\Internet Explorer\ExtExport.exe 2014-11-11 20:32:08 CC5C5634FA72689449B4BF7960AC1AD5 222720 ----a-w- C:\Program Files\Internet Explorer\ielowutil.exe 2014-11-11 20:32:08 6A16741182E4C1E83636053C81CE344E 221184 ----a-w- C:\Program Files (x86)\Internet Explorer\ielowutil.exe === C: other files == 2014-11-14 22:43:10 FCD25445C1A3E24E25DCF2E3D1F1367B 92817 ----a-w- C:\Users\Yvonne\AppData\Local\Microsoft\Windows\INetCache\Low\IE\C6HZWCKF\System.Windows.Controls[1].zip 2014-11-14 22:43:10 ECDC5F4BFF60A1A0341A0A1152185681 13485 ----a-w- C:\Users\Yvonne\AppData\Local\Microsoft\Windows\INetCache\Low\IE\FHVYBS22\System.ComponentModel.Composition.Initialization[1].zip 2014-11-14 22:43:10 CDF45276041F6B24B930A9A08CE081BE 39445 ----a-w- C:\Users\Yvonne\AppData\Local\Microsoft\Windows\INetCache\Low\IE\OI6R9IHG\System.ServiceModel.Web.Extensions[1].zip 2014-11-14 22:43:10 7E0428585CE011773183B0EB40218AEC 119240 ----a-w- C:\Users\Yvonne\AppData\Local\Microsoft\Windows\INetCache\Low\IE\C6HZWCKF\System.Xml.Serialization[1].zip 2014-11-14 22:43:10 77857A69AD319C70114D2856CFB14866 23573 ----a-w- C:\Users\Yvonne\AppData\Local\Microsoft\Windows\INetCache\Low\IE\OI6R9IHG\System.Windows.Controls.Data.Input[1].zip 2014-11-14 22:43:10 5BF38779F83CA64C33AC237555664E54 35271 ----a-w- C:\Users\Yvonne\AppData\Local\Microsoft\Windows\INetCache\Low\IE\OI6R9IHG\System.ServiceModel.DomainServices.Client.Web[1].zip 2014-11-14 22:43:10 234A644C9D46BEDB966DB2ADDCDBA808 25710 ----a-w- C:\Users\Yvonne\AppData\Local\Microsoft\Windows\INetCache\Low\IE\OI6R9IHG\System.ComponentModel.DataAnnotations[1].zip 2014-11-14 22:43:10 0DD83955982BDBC087F15C57F036824F 86709 ----a-w- C:\Users\Yvonne\AppData\Local\Microsoft\Windows\INetCache\Low\IE\FHVYBS22\System.ComponentModel.Composition[1].zip 2014-11-14 22:43:10 02333CFFBA7D54D2D338452764DDBE42 73130 ----a-w- C:\Users\Yvonne\AppData\Local\Microsoft\Windows\INetCache\Low\IE\OI6R9IHG\System.ServiceModel.DomainServices.Client[1].zip 2014-11-13 21:17:45 EC7FBD94FD4DC982996B55244EDB54D8 180329 ----a-w- C:\Users\Yvonne\AppData\Local\Microsoft\Windows\INetCache\Low\IE\39V8UVIJ\Microsoft.CSharp[1].zip 2014-11-12 22:49:33 F47CEC45FB85791D4AB237563AD0FA8F 33736 ----a-w- C:\Program Files (x86)\HTC\HTC Driver\Driver Files\Win8_x64\androidusb.sys 2014-11-12 22:49:33 B8B1B284362E1D8135112573395D5DA5 36928 ----a-w- C:\Program Files (x86)\HTC\HTC Driver\Driver Files\Win8_x64\htcnprot.sys 2014-11-12 22:49:33 7C7C986776D00E575BFBDE5DCBDC615D 121800 ----a-w- C:\Program Files (x86)\HTC\HTC Driver\Driver Files\Win8_x64\HtcVComV64.sys 2014-11-12 20:26:06 D60F4AC93A0149BBE211C69938AEF0C4 544 ----a-w- C:\$Recycle.Bin\S-1-5-21-138855871-1310491556-297829154-1002\$I96CBN2.zip 2014-11-12 20:25:32 DC66ADFF6EA4F7747C27773C8FFAB1E5 10329084 ----a-w- C:\$Recycle.Bin\S-1-5-21-138855871-1310491556-297829154-1002\$R96CBN2.zip 2014-11-11 20:30:17 DE8D12B4C3F55FA2C5E9774314F6C58A 258368 ----a-w- C:\Windows\System32\drivers\WdFilter.sys 2014-11-11 20:30:17 4AD874CDC812EC156265E451B6B09DAB 114496 ----a-w- C:\Windows\System32\drivers\WdNisDrv.sys 2014-11-11 20:30:16 0359607177E5E9F6041136CC0A5CB0B6 35320 ----a-w- C:\Windows\System32\drivers\WdBoot.sys 2014-11-11 20:28:11 6D2EE96150E35B9EA49F2B481DE0369A 177472 ----a-w- C:\Windows\System32\drivers\ksecpkg.sys 2014-11-11 20:28:11 4E1207CE16E615B0B7A70DC889F4500E 563976 ----a-w- C:\Windows\System32\drivers\cng.sys 2014-11-11 20:28:10 9F08A6608F98B5407E7DDBCF306573EF 27456 ----a-w- C:\Windows\System32\drivers\rdpvideominiport.sys 2014-11-11 20:23:16 B31C4917EC5EADE24A90DDAF37EA00E0 4182016 ----a-w- C:\Windows\System32\win32k.sys 2014-11-11 20:22:14 CCB3A2BB60FE5073F2DEA63FE83CF8FE 2497344 ----a-w- C:\Windows\System32\drivers\tcpip.sys 2014-11-11 20:22:01 E3FCE2A6B3533D99A3B498504DF9CC47 474432 ----a-w- C:\Windows\System32\drivers\netio.sys 2014-11-11 20:21:56 66732C13628BDB1AB0D6FD46027327C2 148800 ----a-w- C:\Windows\System32\drivers\USBSTOR.SYS 2014-11-11 20:21:55 7F23E38C5B6448F91439E4066645191E 428864 ----a-w- C:\Windows\System32\drivers\FWPKCLNT.SYS ==== Startup Registry Enabled ====================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "StartCCC"="C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe MSRun" "AccelerometerSysTrayApplet"="C:\Program Files (x86)\Hewlett-Packard\HP 3D DriveGuard\AccelerometerST.exe" "HPMessageService"="C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPMSGSVC.exe" "GrooveMonitor"="C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" "F-Secure Hoster (4582601)"="C:\Program Files (x86)\PC Veilig\fshoster32.exe -app -hosterid:1" "F-Secure Manager"="C:\Program Files (x86)\PC Veilig\apps\ComputerSecurity\Common\FSM32.EXE /splash" "Family Tree Builder Update"="C:\Program Files (x86)\MyHeritage\Bin\FTBCheckUpdates.exe" ==== Startup Registry Enabled x64 ====================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RTHDVCPL"="C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe -s" "SimplePass"="C:\Program Files\Hewlett-Packard\SimplePass\ClientCore.exe /hideui" "OPBHOBroker"="C:\Program Files\Hewlett-Packard\SimplePass\OPBHOBroker.exe" "OPBHOBrokerDesktop"="C:\Program Files\Hewlett-Packard\SimplePass\OPBHOBrokerDsktop.exe" "SynTPEnh"="%ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe " [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] "NCPluginUpdater"="C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\NCPluginUpdater.exe Update" ==== Task Scheduler Jobs ====================== C:\Windows\tasks\Adobe Flash Player Updater.job --a-------- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [11-11-2014 21:25] ==== Other Scheduled Tasks ====================== "C:\Windows\SysNative\tasks\Adobe Flash Player Updater" [C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe] "C:\Windows\SysNative\tasks\User_Feed_Synchronization-{8AB3D51D-57CD-437A-B316-81A5AE10845C}" [C:\Windows\system32\msfeedssync.exe] "C:\Windows\SysNative\tasks\YCMServiceAgent" [C:\Program Files (x86)\CyberLink\YouCam\YouCamService.exe] "C:\Windows\SysNative\tasks\Hewlett-Packard\HP CoolSense\HP CoolSense Start at Logon" [C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe] "C:\Windows\SysNative\tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start" [C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe] "C:\Windows\SysNative\tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis" [C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe] "C:\Windows\SysNative\tasks\Hewlett-Packard\HP Support Assistant\Update Check" [C:\ProgramData\Hewlett-Packard\HP Support Framework\Resources\Updater7\HPSFUpdater.exe] "C:\Windows\SysNative\tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker" [C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe] "C:\Windows\SysNative\tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_DeviceScan" [C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe] ==== Firefox Extensions ====================== ProfilePath: C:\Users\Yvonne\AppData\Roaming\Mozilla\Firefox\Profiles\bnxm0rxo.default - Undetermined - exif_viewer@mozilla.doslash.org - Exif Viewer - %ProfilePath%\extensions\exif_viewer@mozilla.doslash.org.xpi AppDir: C:\Program Files (x86)\Mozilla Firefox - Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} ==== Firefox Plugins ====================== Profilepath: C:\Users\Yvonne\AppData\Roaming\Mozilla\Firefox\Profiles\bnxm0rxo.default 67D325B5AEB28E381B84E8DE1A90C7A8 - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_223.dll - Shockwave Flash 0C0C5C207121C7A78414A8250E8E099A - C:\windows\SysWOW64\Adobe\Director\np32dsw_1204144.dll - Shockwave for Director / Shockwave for Director ==== Set IE to Default ====================== Old Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://www.google.nl/" New Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://www.google.nl/" ==== All HKCU SearchScopes ====================== HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" {012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}" {0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02" ==== HijackThis Entries ====================== F2 - REG:system.ini: UserInit=userinit.exe O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll O2 - BHO: Evernote extension - {92EF2EAD-A7CE-4424-B0DB-499CF856608E} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll O2 - BHO: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun O4 - HKLM\..\Run: [AccelerometerSysTrayApplet] C:\Program Files (x86)\Hewlett-Packard\HP 3D DriveGuard\AccelerometerST.exe O4 - HKLM\..\Run: [HPMessageService] C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPMSGSVC.exe O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" O4 - HKLM\..\Run: [F-Secure Hoster (4582601)] "C:\Program Files (x86)\PC Veilig\fshoster32.exe" -app -hosterid:1 O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files (x86)\PC Veilig\apps\ComputerSecurity\Common\FSM32.EXE" /splash O4 - HKLM\..\Run: [Family Tree Builder Update] C:\Program Files (x86)\MyHeritage\Bin\FTBCheckUpdates.exe O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000 O8 - Extra context menu item: Free YouTube Download - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\freeytvdownloader.htm O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\freeytmp3downloader.htm O9 - Extra button: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-103 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-102 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe O9 - Extra button: Verzenden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: Verz&enden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL O9 - Extra button: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\\EvernoteIERes\AddNote.html O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\\EvernoteIERes\AddNote.html O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll O20 - AppInit_DLLs: O23 - Service: AdaptiveSleepService - Unknown owner - C:\Program Files\ATI Technologies\ATI.ACE\A4\AdaptiveSleepService.exe O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing) O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing) O23 - Service: AMD FUEL Service - Advanced Micro Devices, Inc. - C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe O23 - Service: Bonjour-service (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: BTDevManager - Unknown owner - C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTDevMgr.exe O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing) O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing) O23 - Service: F-Secure Dll Hoster (fshoster) - F-Secure Corporation - C:\Program Files (x86)\PC Veilig\fshoster32.exe O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files (x86)\PC Veilig\apps\ComputerSecurity\Common\FSMA32.EXE O23 - Service: F-Secure ORSP Client (FSORSPClient) - F-Secure Corporation - C:\Program Files (x86)\PC Veilig\apps\CCF_Reputation\fsorsp.exe O23 - Service: HP Support Assistant Service - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe O23 - Service: @oem14.inf,%hpservice_desc%;HP Service (hpsrv) - Unknown owner - C:\Windows\system32\Hpservice.exe (file missing) O23 - Service: HPWMISVC - Hewlett-Packard Development Company, L.P. - C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPWMISVC.exe O23 - Service: HTCMonitorService - Nero AG - C:\Program Files (x86)\HTC\HTC Sync Manager\HSMServiceEntry.exe O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing) O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing) O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: HP SimplePass Service (omniserv) - Softex Inc. - C:\Program Files\Hewlett-Packard\SimplePass\OmniServ.exe O23 - Service: Internet Pass-Through Service (PassThru Service) - Unknown owner - C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing) O23 - Service: Realtek Audio Service (RtkAudioService) - Realtek Semiconductor - C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing) O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing) O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing) O23 - Service: SynTPEnh Caller Service (SynTPEnhService) - Synaptics Incorporated - C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe O23 - Service: tbaseprovisioning - Advanced Micro Devices, Inc. - C:\Windows\SysWOW64\tbaseprovisioning.exe O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing) O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing) O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing) O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing) O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing) O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing) O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing) O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing) ==== Empty IE Cache ====================== C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Yvonne\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\Users\Yvonne\AppData\Local\Microsoft\Windows\INetCache\Low\Content.IE5 emptied successfully C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\Users\Yvonne\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully C:\Users\Yvonne\AppData\Local\Microsoft\Windows\INetCache\Low\IE emptied successfully C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully ==== Empty FireFox Cache ====================== C:\Users\Yvonne\AppData\Local\Mozilla\Firefox\Profiles\bnxm0rxo.default\cache2 emptied successfully ==== Empty Chrome Cache ====================== No Chrome User Data found ==== Empty All Flash Cache ====================== Flash Cache Emptied Successfully ==== Empty All Java Cache ====================== No Java Cache Found ==== C:\zoek_backup content ====================== C:\zoek_backup (files=10601 folders=515 543019838 bytes) ==== Empty Temp Folders ====================== C:\Users\Default\AppData\Local\Temp emptied successfully C:\Users\Default User\AppData\Local\Temp emptied successfully C:\Users\Yvonne\AppData\Local\Temp will be emptied at reboot C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully C:\Windows\Temp will be emptied at reboot ==== After Reboot ====================== ==== Empty Temp Folders ====================== C:\Windows\Temp successfully emptied C:\Users\Yvonne\AppData\Local\Temp successfully emptied ==== Empty Recycle Bin ====================== C:\$RECYCLE.BIN successfully emptied ==== Deleting Files / Folders ====================== "C:\Users\Yvonne\AppData\Local\Pokki\Pokkies\installed_pokkies.db" not found "C:\Users\Yvonne\AppData\Local\Pokki" not found ==== EOF on za 15-11-2014 at 21:05:20,37 ======================