Zoek.exe v5.0.0.0 Updated 24-11-2014 Tool run by DELL on di 25-11-2014 at 10:07:55,33. Microsoft Windows 7 Ultimate 6.1.7601 Service Pack 1 x64 Running in: Normal Mode Internet Access Detected Launched: C:\Users\DELL\Desktop\zoek.exe [Scan all users] [Script inserted] ==== System Restore Info ====================== 25-11-2014 10:17:19 Zoek.exe System Restore Point Created Succesfully. ==== Empty Folders Check ====================== C:\PROGRA~2\AVS4YOU deleted successfully C:\PROGRA~2\Freemake deleted successfully C:\PROGRA~2\GUMB80A.tmp deleted successfully C:\PROGRA~2\Nuance deleted successfully C:\PROGRA~2\COMMON~1\EPSON deleted successfully C:\Users\DELL\AppData\Roaming\AdobeUM deleted successfully C:\Users\DELL\AppData\Roaming\Extensions deleted successfully C:\Users\DELL\AppData\Roaming\IBKPRO deleted successfully C:\Users\DELL\AppData\Roaming\Malwarebytes deleted successfully C:\Users\DELL\AppData\Roaming\Recordpad deleted successfully C:\Users\DELL\AppData\Local\CrashDumps deleted successfully C:\Users\DELL\AppData\Local\Samsung deleted successfully ==== Deleting CLSID Registry Keys ====================== HKEY_USERS\S-1-5-21-2412325288-324325390-2824101589-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110611511119} deleted successfully HKEY_USERS\S-1-5-21-2412325288-324325390-2824101589-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110611331113} deleted successfully ==== Deleting CLSID Registry Values ====================== HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Approved Extensions\{033BE5FC-ED4C-48A0-8F07-E0128384D828} deleted successfully HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\Approved Extensions\{033BE5FC-ED4C-48A0-8F07-E0128384D828} deleted successfully HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\Approved Extensions\{033BE5FC-ED4C-48A0-8F07-E0128384D828} deleted successfully HKEY_USERS\S-1-5-21-2412325288-324325390-2824101589-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{5347542D-5637-006A-76A7-7A786E7484D7} deleted successfully HKEY_USERS\S-1-5-21-2412325288-324325390-2824101589-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{434D452D-5637-006A-76A7-7A786E7484D7} deleted successfully HKEY_USERS\S-1-5-21-2412325288-324325390-2824101589-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{2318C2B1-4965-11D4-9B18-009027A5CD4F} deleted successfully ==== Deleting Services ====================== HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\stdmfpam deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\stdmfpam deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\51cdb72 deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\51cdb72 deleted successfully ==== Deleting Files \ Folders ====================== C:\Program Files (x86)\HomeTab not found "C:\Users\DELL\AppData\Roaming\BWQNWU.exe" not found "C:\Users\DELL\AppData\Roaming\CILDFBNG.exe" not found "C:\Users\DELL\AppData\Roaming\DMIFJ.exe" not found "C:\Users\DELL\AppData\Roaming\EQOMP.exe" not found "C:\Users\DELL\AppData\Roaming\FUOBXQ.exe" not found "C:\Users\DELL\AppData\Roaming\GPZDXRR.exe" not found "C:\Users\DELL\AppData\Roaming\PD.exe" not found "C:\Users\DELL\AppData\Roaming\PTZB.exe" not found "C:\Program Files (x86)\GUMB80A.tmp" not found C:\Users\DELL\AppData\Roaming\smileyswelove deleted C:\Users\DELL\AppData\Roaming\{37E99E86-D615-4B08-937F-F8F935C455F3}_ANZHUANG deleted C:\Program Files (x86)\0ca45c95134d deleted C:\Users\DELL\AppData\Roaming\AdvancedSystemProtector deleted C:\Program Files (x86)\Maxiget deleted "C:\Windows\tasks\BWQNWU.job" deleted "C:\Windows\tasks\CILDFBNG.job" deleted "C:\Windows\tasks\DMIFJ.job" deleted "C:\Windows\tasks\EQOMP.job" deleted "C:\Windows\tasks\FUOBXQ.job" deleted "C:\Windows\tasks\GPZDXRR.job" deleted "C:\Windows\tasks\PD.job" deleted "C:\Windows\tasks\PTZB.job" deleted "C:\windows\SysNative\drivers\b786bdb3c67d.sys" deleted "C:\windows\SysNative\drivers\76805E7F.sys" deleted ==== Files Recently Created / Modified ====================== ====== C:\Windows ==== 2014-11-23 19:13:39 F6804E30422C24BEBCF8DD529EFE041F 34368 ----a-w- C:\Windows\Launcher.exe 2014-11-04 20:23:52 28A0682524FBCC6AC05E46C8EA7FF3EA 2007 ----a-w- C:\Windows\patsearch.bin ====== C:\Users\DELL\AppData\Local\Temp ==== 2014-11-24 10:52:51 D426485FB122354E762F247F76077291 297704 ----a-w- C:\Users\DELL\AppData\Local\Temp\OnlineBackup.exe 2014-11-23 19:57:03 FF5ACD7969A89B6C1682B70C2A9E79F1 5049128 ----a-w- C:\Users\DELL\AppData\Local\Temp\tbuC154.exe 2014-11-23 19:21:18 A85803F6531D08A201FA19FC9728B508 380800 ----a-w- C:\Users\DELL\AppData\Local\Temp\91887.exe.exe 2014-11-23 19:05:44 F5CCF424BD96A3F3840B4A05BA1A304A 6941856 ----a-w- C:\Users\DELL\AppData\Local\Temp\ZOG\Setup.exe 2014-11-23 19:05:39 534C768A4B8B5BD2FC3096CCB4DBD998 286072 ----a-w- C:\Users\DELL\AppData\Local\Temp\ET\pjr_webssearches.exe 2014-11-23 19:05:38 97584BBDF74291BF09A634D4578DB5D5 557265 ----a-w- C:\Users\DELL\AppData\Local\Temp\a7bc2d5c051e4aa48afc1c90b5483107\523aa5da768e41b8be8835bab89db3281103\trustedwinman.exe 2014-11-23 19:05:36 97584BBDF74291BF09A634D4578DB5D5 557265 ----a-w- C:\Users\DELL\AppData\Local\Temp\a7bc2d5c051e4aa48afc1c90b5483107\d3b103374abe4e2d835d2b02ccba71e51077\winsrvinst.exe 2014-11-23 19:05:33 97584BBDF74291BF09A634D4578DB5D5 557265 ----a-w- C:\Users\DELL\AppData\Local\Temp\a7bc2d5c051e4aa48afc1c90b5483107\07e9e2789e5a4bedaa4d11626a36ae861135\winman.exe 2014-11-23 19:05:31 97584BBDF74291BF09A634D4578DB5D5 557265 ----a-w- C:\Users\DELL\AppData\Local\Temp\a7bc2d5c051e4aa48afc1c90b5483107\be7d544b39314b81a58656b9283a082738\wsint.exe 2014-11-23 19:05:28 97584BBDF74291BF09A634D4578DB5D5 557265 ----a-w- C:\Users\DELL\AppData\Local\Temp\a7bc2d5c051e4aa48afc1c90b5483107\467c795afffd427384c076f5ed645b791120\wsrv.exe 2014-11-23 19:05:26 97584BBDF74291BF09A634D4578DB5D5 557265 ----a-w- C:\Users\DELL\AppData\Local\Temp\a7bc2d5c051e4aa48afc1c90b5483107\0743f4d7aab943abb7033f9d0f0489ed1110\trustedwinman.exe 2014-11-23 19:05:24 97584BBDF74291BF09A634D4578DB5D5 557265 ----a-w- C:\Users\DELL\AppData\Local\Temp\a7bc2d5c051e4aa48afc1c90b5483107\ed947c254d30423c809d20d3e82647161067\winsrvinst.exe 2014-11-23 19:05:21 97584BBDF74291BF09A634D4578DB5D5 557265 ----a-w- C:\Users\DELL\AppData\Local\Temp\a7bc2d5c051e4aa48afc1c90b5483107\19ae5dd0efff4cd081c3739da98b16d71108\winman.exe 2014-11-23 10:32:42 2E8A5736739C6D23F5CBAE22973A1E3A 6553144 ----a-w- C:\Users\DELL\AppData\Local\Temp\SpotifyUninstall.exe 2014-11-23 08:17:02 97584BBDF74291BF09A634D4578DB5D5 557265 ----a-w- C:\Users\DELL\AppData\Local\Temp\a7bc2d5c051e4aa48afc1c90b5483107\iman2.exe 2014-11-22 08:51:46 C43B6A05E93D1868E698D9932ACAFF06 2031627 ------w- C:\Users\DELL\AppData\Local\Temp\ir_ext_temp_2\AutoPlay\Docs\Incredimail2 Plus Build 5254 Vista-Win7-Win8 64bit.exe 2014-11-20 10:45:59 FBCFAC06AC0856355D8AA0C510CEE0B2 219712 ----a-w- C:\Users\DELL\AppData\Local\Temp\1636604\program files\IncrediMail\Bin\ssce5432.dll 2014-11-20 10:45:59 D4AE1F377120F1B507FABAEA562F9C93 373072 ----a-w- C:\Users\DELL\AppData\Local\Temp\1636604\IncrediMailSetup_nl.exe 2014-11-20 10:45:59 6C234E10D2106AE0F7BA1083F18DE91F 326136 ----a-w- C:\Users\DELL\AppData\Local\Temp\1636604\program files\IncrediMail\Bin\wflash3.dll 2014-11-20 10:45:59 53C79D39B8F01CBD1A604347FED901D9 72256 ----a-w- C:\Users\DELL\AppData\Local\Temp\1636604\program files\IncrediMail\Bin\wlessfp1.dll 2014-11-20 10:45:59 2C6B52EC35A269D52336D504DE3BB7EB 2826752 ----a-w- C:\Users\DELL\AppData\Local\Temp\1636604\IncrediMail.msi 2014-11-20 10:45:58 E40583FF024F5AD26E533E28BD31F15B 476736 ----a-w- C:\Users\DELL\AppData\Local\Temp\1636604\program files\IncrediMail\Bin\sqlite3.dll 2014-11-20 10:45:58 D0E96E6617FC4F7C5AD5F2CE71D3B1A4 584256 ----a-w- C:\Users\DELL\AppData\Local\Temp\1636604\program files\IncrediMail\Bin\SftTree_IX86_U_60.dll 2014-11-20 10:45:58 BE586EABCB291DB7C6FBD32776BB34BD 109040 ----a-w- C:\Users\DELL\AppData\Local\Temp\1636604\program files\IncrediMail\Bin\PMC.dll 2014-11-20 10:45:58 5F7C96491A369F1158E1E238C999030F 555512 ----a-w- C:\Users\DELL\AppData\Local\Temp\1636604\program files\IncrediMail\Bin\msvcp80.dll 2014-11-20 10:45:58 457308E73E502E1816D084914BB157BB 633336 ----a-w- C:\Users\DELL\AppData\Local\Temp\1636604\program files\IncrediMail\Bin\msvcr80.dll 2014-11-20 10:45:57 DD6993AA53BE0BB62125ECE8ABF2D4E8 53824 ----a-w- C:\Users\DELL\AppData\Local\Temp\1636604\program files\IncrediMail\Bin\IncMailRU.dll 2014-11-20 10:45:57 D66D368B5BB2DC54C76621B242391437 162368 ----a-w- C:\Users\DELL\AppData\Local\Temp\1636604\program files\IncrediMail\Bin\ImWrappU.dll 2014-11-20 10:45:57 A82DFE2DBAB9BDB46E866F84BD16514E 1099760 ----a-w- C:\Users\DELL\AppData\Local\Temp\1636604\program files\IncrediMail\Bin\mfc80u.dll 2014-11-20 10:45:57 6DC4C1C1C9E6BD70C6A9C0592C6B4BE4 1460800 ----a-w- C:\Users\DELL\AppData\Local\Temp\1636604\program files\IncrediMail\Bin\ImViewU.dll 2014-11-20 10:45:57 269E04BF602E08E084919C44C3B45D7C 301632 ----a-w- C:\Users\DELL\AppData\Local\Temp\1636604\program files\IncrediMail\Bin\ImViewRU.dll 2014-11-20 10:45:56 E27EB2B6DD1174886A47CCE3911AA006 1583680 ----a-w- C:\Users\DELL\AppData\Local\Temp\1636604\program files\IncrediMail\Bin\ImSuppU.dll 2014-11-20 10:45:56 C74B38E781818C82D6A2B32509F5A278 1464896 ----a-w- C:\Users\DELL\AppData\Local\Temp\1636604\program files\IncrediMail\Bin\ImUtilsU.dll 2014-11-20 10:45:56 AAC72AE4766AF2F25B8A2FF004797516 645696 ----a-w- C:\Users\DELL\AppData\Local\Temp\1636604\program files\IncrediMail\Bin\ImSpoolU.dll 2014-11-20 10:45:56 9A170A97A629567368437F8EB3D9EE47 739904 ----a-w- C:\Users\DELL\AppData\Local\Temp\1636604\program files\IncrediMail\Bin\ImSuppRU.dll 2014-11-20 10:45:56 22AA09F00843203D461C41B5384D11F4 133696 ----a-w- C:\Users\DELL\AppData\Local\Temp\1636604\program files\IncrediMail\Bin\ImShExtU.dll 2014-11-20 10:45:56 0781438C75BFEBCF2B91001C245BA8F3 277056 ----a-w- C:\Users\DELL\AppData\Local\Temp\1636604\program files\IncrediMail\Bin\ImToolsU.dll 2014-11-20 10:45:55 FB4F89936EF6669069E233019556C0D0 1141312 ----a-w- C:\Users\DELL\AppData\Local\Temp\1636604\program files\IncrediMail\Bin\ImMangrU.dll 2014-11-20 10:45:55 AA4189182A6DB80831DA898B622C5756 96832 ----a-w- C:\Users\DELL\AppData\Local\Temp\1636604\program files\IncrediMail\Bin\ImNtUtilU.dll 2014-11-20 10:45:55 8387ABECDBDEBCDE54624CEB58697CC7 37952 ----a-w- C:\Users\DELL\AppData\Local\Temp\1636604\program files\IncrediMail\Bin\ImpCntRU.dll 2014-11-20 10:45:55 7E667B2746F8DFD32876A269FCE0439F 207424 ----a-w- C:\Users\DELL\AppData\Local\Temp\1636604\program files\IncrediMail\Bin\ImNotfyRU.dll 2014-11-20 10:45:55 72129B8CB12CA2D49AD8AD397709A135 29760 ----a-w- C:\Users\DELL\AppData\Local\Temp\1636604\program files\IncrediMail\Bin\ImSearchU.dll 2014-11-20 10:45:55 444CEE59A151DB324EDB623BA57258E0 47680 ----a-w- C:\Users\DELL\AppData\Local\Temp\1636604\program files\IncrediMail\Bin\ImMapiU.dll 2014-11-20 10:45:55 426E5DD4900771B00D362044334E86B7 399936 ----a-w- C:\Users\DELL\AppData\Local\Temp\1636604\program files\IncrediMail\Bin\ImServU.dll 2014-11-20 10:45:55 25094EEB6FBE5DE83598FD3681B45CB9 645696 ----a-w- C:\Users\DELL\AppData\Local\Temp\1636604\program files\IncrediMail\Bin\ImParserU.dll 2014-11-20 10:45:55 1ED25AAD349834F6FA15293661770A92 162368 ----a-w- C:\Users\DELL\AppData\Local\Temp\1636604\program files\IncrediMail\Bin\ImNotfyU.dll 2014-11-20 10:45:55 1D42949E34EE9E8EF29056517E0DCB04 67136 ----a-w- C:\Users\DELL\AppData\Local\Temp\1636604\program files\IncrediMail\Bin\ImPackrRU.dll 2014-11-20 10:45:54 B7402E1706FE7251795960255C4B28A8 621120 ----a-w- C:\Users\DELL\AppData\Local\Temp\1636604\program files\IncrediMail\Bin\ImLookU.dll 2014-11-20 10:45:54 1B295D6040E8583C86BFCA60F7F2BA83 567872 ----a-w- C:\Users\DELL\AppData\Local\Temp\1636604\program files\IncrediMail\Bin\ImMangrRU.dll 2014-11-20 10:45:53 B3BB5569DACE5DBDFB2019366EE06CEA 195136 ----a-w- C:\Users\DELL\AppData\Local\Temp\1636604\program files\IncrediMail\Bin\ImKeysU.dll 2014-11-20 10:45:53 8DB983D32971725307CD9887DE613B6C 330304 ----a-w- C:\Users\DELL\AppData\Local\Temp\1636604\program files\IncrediMail\Bin\ImLcRU.dll 2014-11-20 10:45:53 26848C6ABA0B20C755C3CE7332009E83 268864 ----a-w- C:\Users\DELL\AppData\Local\Temp\1636604\program files\IncrediMail\Bin\ImLookExU.dll 2014-11-20 10:45:53 20541B1AEE98EED03DA9526FF7D36DF7 309824 ----a-w- C:\Users\DELL\AppData\Local\Temp\1636604\program files\IncrediMail\Bin\ImJunkU.dll 2014-11-20 10:45:52 EA79F80B691D115EFDB0BDF5C200CA45 522816 ----a-w- C:\Users\DELL\AppData\Local\Temp\1636604\program files\IncrediMail\Bin\ImFoldrsU.dll 2014-11-20 10:45:52 CFF35BCCF03FC60D4A2FE2F3D765A803 1116736 ----a-w- C:\Users\DELL\AppData\Local\Temp\1636604\program files\IncrediMail\Bin\ImFeatU.dll 2014-11-20 10:45:52 CC7E8E8BA9B3FE24B8E6E520CF26102C 47168 ----a-w- C:\Users\DELL\AppData\Local\Temp\1636604\program files\IncrediMail\Bin\ImImprtRU.dll 2014-11-20 10:45:52 7DB5BCB94A488C73D900C801C934CF57 33272 ----a-w- C:\Users\DELL\AppData\Local\Temp\1636604\program files\IncrediMail\Bin\IMHttpComm.dll 2014-11-20 10:45:52 789ADB28C0A076462A56EC674C7FDBC0 715328 ----a-w- C:\Users\DELL\AppData\Local\Temp\1636604\program files\IncrediMail\Bin\ImImprtU.dll 2014-11-20 10:45:51 F17884F92A96DA5F633CC23FBB0D83FA 80448 ----a-w- C:\Users\DELL\AppData\Local\Temp\1636604\program files\IncrediMail\Bin\ImAppRU.dll 2014-11-20 10:45:51 BB9D9DCEDDB7A6F25826DCEF0BFDDDFA 842304 ----a-w- C:\Users\DELL\AppData\Local\Temp\1636604\program files\IncrediMail\Bin\ImFeatRU.dll 2014-11-20 10:45:51 9E3217B7EB7D717EA76ED89C00E85C52 88640 ----a-w- C:\Users\DELL\AppData\Local\Temp\1636604\program files\IncrediMail\Bin\ImDbU.dll 2014-11-20 10:45:51 9561D23C19F4563ECB8E248162A7AE1C 318016 ----a-w- C:\Users\DELL\AppData\Local\Temp\1636604\program files\IncrediMail\Bin\ImABU.dll 2014-11-20 10:45:51 292B83EF1C1A835A9E6D86485B8F166C 121408 ----a-w- C:\Users\DELL\AppData\Local\Temp\1636604\program files\IncrediMail\Bin\ImAnimU.dll 2014-11-20 10:45:51 1DB78473EE69B45E9EB43AA08FAE2F56 133696 ----a-w- C:\Users\DELL\AppData\Local\Temp\1636604\program files\IncrediMail\Bin\ImComUtlU.dll 2014-11-20 10:45:50 CB22326C307FAD675324CFE5521D9050 113216 ----a-w- C:\Users\DELL\AppData\Local\Temp\1636604\program files\IncrediMail\Bin\Im3dU.dll 2014-11-20 10:45:49 F7350B698C6411B9B7441C4746C20D19 3144256 ----a-w- C:\Users\DELL\AppData\Local\Temp\1636604\program files\IncrediMail\Bin\dten600.dll 2014-11-20 10:45:49 81E0C054D6D9A551EBD15C09BCDC081E 356928 ----a-w- C:\Users\DELL\AppData\Local\Temp\1636604\program files\IncrediMail\Bin\d3drm.dll 2014-11-20 10:45:49 771A5E7CF4C19F3DE5D36B19284F1FC6 367168 ----a-w- C:\Users\DELL\AppData\Local\Temp\1636604\program files\IncrediMail\Bin\IncMail.exe 2014-11-20 10:45:49 67493420606F53E7FAFE6AF3CCBED0CC 980304 ----a-w- C:\Users\DELL\AppData\Local\Temp\1636604\program files\IncrediMail\Bin\AE\ActionEngine.dll 2014-11-20 10:45:48 EA875DD472E0BACF4038D7FE73DDCBD5 105024 ----a-w- C:\Users\DELL\AppData\Local\Temp\1636604\program files\IncrediMail\Bin\ImPackr.exe 2014-11-20 10:45:48 D9D7FA5367EAAEF892EE70FFB4B3E719 43832 ----a-w- C:\Users\DELL\AppData\Local\Temp\1636604\program files\IncrediMail\Bin\ImSc.exe 2014-11-20 10:45:48 87601D20B7376919907523928A63047D 113216 ----a-w- C:\Users\DELL\AppData\Local\Temp\1636604\program files\IncrediMail\Bin\ImpCnt.exe 2014-11-20 10:45:48 4D651B52402D1C3F43F46E22E5B11830 121408 ----a-w- C:\Users\DELL\AppData\Local\Temp\1636604\program files\IncrediMail\Bin\ImSetup.exe 2014-11-20 10:45:48 165BA93DE26255CBAA475B18AB7558FC 68160 ----a-w- C:\Users\DELL\AppData\Local\Temp\1636604\program files\IncrediMail\Bin\ImLpp.exe 2014-11-20 10:45:48 0159784F3D45BE836D022283E9317595 260672 ----a-w- C:\Users\DELL\AppData\Local\Temp\1636604\program files\IncrediMail\Bin\ImNotfy.exe 2014-11-20 10:45:47 9C7A96F02FBB9114DA9226D95E78F89B 129520 ----a-w- C:\Users\DELL\AppData\Local\Temp\1636604\program files\IncrediMail\Bin\ImBpp.exe 2014-11-20 10:45:47 4EC8448DFE16588F56EA5B61C53CE802 309824 ----a-w- C:\Users\DELL\AppData\Local\Temp\1636604\program files\IncrediMail\Bin\ImLc.exe 2014-11-20 10:45:45 5C543230B376A57A8690C7119423F146 264768 ----a-w- C:\Users\DELL\AppData\Local\Temp\1636604\program files\IncrediMail\Bin\ImApp.exe 2014-11-20 10:45:36 0C93718599A68D1E5A0E76A706874833 26960 ----a-w- C:\Users\DELL\AppData\Local\Temp\1636604\program files\IncrediMail\Bin\AE\aeldr.exe 2014-11-20 10:29:26 C43B6A05E93D1868E698D9932ACAFF06 2031627 ------w- C:\Users\DELL\AppData\Local\Temp\ir_ext_temp_0\AutoPlay\Docs\Incredimail2 Plus Build 5254 Vista-Win7-Win8 64bit.exe 2014-11-19 12:12:51 9FE0E27EE94C064B3E99A7ED0336105F 13231360 ----a-w- C:\Users\DELL\AppData\Local\Temp\ReimagePackage.exe 2014-11-19 12:12:05 A1C75D80A10F062D75C558C80CE9D74D 366216 ----a-w- C:\Users\DELL\AppData\Local\Temp\390813.exe.exe 2014-11-19 10:08:48 F1E994BD5C745F5403098727B3684273 2129408 ----a-w- C:\Users\DELL\AppData\Local\Temp\RarSFX0\curl.exe 2014-11-19 09:43:03 67CFA6C2CDAC459BC571B26F68ADCA38 1023 ----a-w- C:\Users\DELL\AppData\Local\Temp\8A93tmp\vopackage.exe 2014-11-19 09:43:02 EBDE644B14E74DC432ACD0DC31AB9222 404480 ----a-w- C:\Users\DELL\AppData\Local\Temp\8DE4tmp\launcher__11002_il336305.exe 2014-11-19 09:43:02 C8713DD1C2CA432017719FF49399EE28 1023 ----a-w- C:\Users\DELL\AppData\Local\Temp\8C5Btmp\cloud_backup_setup.exe 2014-11-19 09:43:01 C19096BE9688101A1DA4691F38FD07FA 1023 ----a-w- C:\Users\DELL\AppData\Local\Temp\8A94tmp\easyspeedpc.exe 2014-11-19 09:43:01 7FE4F077A944C6495C7E449CF5E82892 9207 ----a-w- C:\Users\DELL\AppData\Local\Temp\8C5Ctmp\salus_1_0_0_1.exe 2014-11-19 09:43:01 7CC77EDF779BEFC6A8B5C2B4FC8595BE 27621 ----a-w- C:\Users\DELL\AppData\Local\Temp\8A92tmp\jfilemanagersetup.exe 2014-11-19 09:43:01 708E079D9F2FA1A539728F90888AD5D9 25575 ----a-w- C:\Users\DELL\AppData\Local\Temp\8B8Ftmp\setup.exe 2014-11-19 09:43:01 37B655DA45B5C05BEB9CF86A94F7DD1E 27621 ----a-w- C:\Users\DELL\AppData\Local\Temp\8C5Dtmp\mybestofferstoday.exe 2014-11-19 09:43:01 15BBEC7015DF0D39B3C05411B076D3E3 1023 ----a-w- C:\Users\DELL\AppData\Local\Temp\8A91tmp\setup.exe 2014-11-19 09:42:39 D426485FB122354E762F247F76077291 297704 ----a-w- C:\Users\DELL\AppData\Local\Temp\BackupSetup.exe 2014-11-19 09:42:33 5E6F7A1CF793D1C16C05139649D11B43 290241 ----a-w- C:\Users\DELL\AppData\Local\Temp\1333tmp\vopackage.exe 2014-11-19 09:42:30 EBDE644B14E74DC432ACD0DC31AB9222 404480 ----a-w- C:\Users\DELL\AppData\Local\Temp\1349tmp\launcher__11002_il336305.exe 2014-11-19 09:42:29 C27E418EE71E218F5944FAB069C7A233 2203422 ----a-w- C:\Users\DELL\AppData\Local\Temp\1330tmp\jfilemanagersetup.exe 2014-11-19 09:42:29 AF37247590F4E4B8A8A214A091EA6067 73816 ----a-w- C:\Users\DELL\AppData\Local\Temp\1331tmp\cloud_backup_setup.exe 2014-11-19 09:42:29 3E5F242A3527E5FFCC2F610A916F0158 62200 ----a-w- C:\Users\DELL\AppData\Local\Temp\1335tmp\easyspeedpc.exe 2014-11-18 19:12:45 639349D25FBB0709BDD346707B8CA697 148460448 ----a-w- C:\Users\DELL\AppData\Local\Temp\m2Temp\20141118-201240\SetupKPNServiceTool.exe 2014-11-18 14:58:33 19DB9C15D2A4218D2141A778DE84DAED 2680448 ----a-w- C:\Users\DELL\AppData\Local\Temp\{3F470DC3-9B77-4ABD-9C86-5FBB514F47F6}_emergency.exe 2014-11-15 11:18:11 19337EC743E4E9436B834664B66D5766 672536 ----a-w- C:\Users\DELL\AppData\Local\Temp\ImInstaller\IncrediBackup_install.exe 2014-11-15 11:18:09 8978782AD89750DA8D6AB44C4255EA8E 959944 ----a-w- C:\Users\DELL\AppData\Local\Temp\ImInstaller\IncrediBackup_installer.exe 2014-11-15 10:49:32 5E2D98B34A9046B0011C67A062453567 12924992 ------w- C:\Users\DELL\AppData\Local\Temp\ir_ext_temp_1\AutoPlay\Docs\IncrediMailSetup_nl.exe 2014-11-13 03:36:30 86264ECE66D2A631C997F14C364594B3 210214 ----a-w- C:\Users\DELL\AppData\Local\Temp\ms.exe 2014-11-11 15:06:19 F9DCD30267BC8D0C22D46ACB5C50ED99 4543488 ---ha-w- C:\Users\DELL\AppData\Local\Temp\8a70eF4505\temp\setupytb.exe 2014-11-11 15:05:30 6930658BCAB14A57ACF7F86BA3086EC9 4625408 ---ha-w- C:\Users\DELL\AppData\Local\Temp\8a70eF4505\temp\setupespl.exe 2014-11-11 11:48:36 7BFB3BE3E7B0AEA2B8D3DF8FB28E11C7 85856 ----a-w- C:\Users\DELL\AppData\Local\Temp\IeSearchProvider5642328578757809374.exe 2014-11-11 11:43:28 33C89FD5D5D19227DE0F5CD4A0D73722 541696 ----a-w- C:\Users\DELL\AppData\Local\Temp\sqlite-3.7.2-sqlitejdbc.dll 2014-11-11 11:35:22 B1957B038895642DF9F662326E7D4DDC 903080 ----a-w- C:\Users\DELL\AppData\Local\Temp\jreInstall.exe ====== Java Cache ===== 2014-11-14 12:04:14 D41D8CD98F00B204E9800998ECF8427E 0 ----a-w- C:\Users\DELL\AppData\LocalLow\Sun\Java\Deployment\SystemCache\6.0\32\6c34baa0-2fedb041 ====== C:\Windows\SysWOW64 ===== 2014-11-19 07:31:34 98B3C919C6B9C5F810FF2CAFA339822B 186880 ----a-w- C:\Windows\SysWOW64\pku2u.dll 2014-11-19 07:31:32 ADFB31FA72AFE0298A60BF4AC1045A42 550912 ----a-w- C:\Windows\SysWOW64\kerberos.dll 2014-11-12 08:14:45 980EEEE8815DA7593708774D1225BD35 681984 ----a-w- C:\Windows\SysWOW64\adtschema.dll 2014-11-12 08:14:44 9AB39ADD28C7C1A685B1EA8C6A25CF08 146432 ----a-w- C:\Windows\SysWOW64\msaudite.dll 2014-11-12 08:14:44 9216ABFD53F5EC1F35C3554AD1A175DE 22016 ----a-w- C:\Windows\SysWOW64\secur32.dll 2014-11-12 08:14:43 13E5B1CD503A4B21E9F0A2D55A00198B 96768 ----a-w- C:\Windows\SysWOW64\sspicli.dll 2014-11-12 08:13:40 B6273619A3DF28F03B64E911E45A6AB2 30720 ----a-w- C:\Windows\SysWOW64\iernonce.dll 2014-11-12 08:13:40 5D5640C34C4A97467F77489DBB157568 47616 ----a-w- C:\Windows\SysWOW64\ieetwproxystub.dll 2014-11-12 08:13:38 A6E51BDCB8F4B84E874F918F0452763D 76288 ----a-w- C:\Windows\SysWOW64\mshtmled.dll 2014-11-12 08:13:37 FB56C76FEA44693752BD99D7D9930ABA 341168 ----a-w- C:\Windows\SysWOW64\iedkcs32.dll 2014-11-12 08:13:36 843BD9DAF03ABB6761DEE6D155301F28 60416 ----a-w- C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2014-11-12 08:13:36 4772DB007FFBD4BBE3F526704BCA67FE 1310208 ----a-w- C:\Windows\SysWOW64\urlmon.dll 2014-11-12 08:13:35 66F4FFDBCD501260ABC198317D2B0D10 285696 ----a-w- C:\Windows\SysWOW64\dxtrans.dll 2014-11-12 08:13:34 93074C4FA92A8399404D032F6AF72C1B 19781632 ----a-w- C:\Windows\SysWOW64\mshtml.dll 2014-11-12 08:13:34 26EE6C9780A8FC872C60F9E35D7EBD4B 688640 ----a-w- C:\Windows\SysWOW64\msfeeds.dll 2014-11-12 08:13:33 5E01004CBC35A78FE2AB4016CCAD4760 708096 ----a-w- C:\Windows\SysWOW64\ieapfltr.dll 2014-11-12 08:13:33 5972510EF1C6097D9C14C17387A5EDB2 2724864 ----a-w- C:\Windows\SysWOW64\mshtml.tlb 2014-11-12 08:13:33 19D68FDEE62519C5A0387EB4E88A01EF 62464 ----a-w- C:\Windows\SysWOW64\iesetup.dll 2014-11-12 08:13:32 FA310BD4A5DE904445DDDE54C5A654F2 2277376 ----a-w- C:\Windows\SysWOW64\iertutil.dll 2014-11-12 08:13:32 7748B3DDDC92C7FC11F7462DB872E8E7 2051072 ----a-w- C:\Windows\SysWOW64\inetcpl.cpl 2014-11-12 08:13:31 8A46404AC1AEB22AA2D4C906D0FC86C2 620032 ----a-w- C:\Windows\SysWOW64\jscript9diag.dll 2014-11-12 08:13:31 6DDC0F44A70976C492CB1666BA9A7912 47104 ----a-w- C:\Windows\SysWOW64\jsproxy.dll 2014-11-12 08:13:30 4F8CD74CD69A94ED1A5D7E837A356F4E 115712 ----a-w- C:\Windows\SysWOW64\ieUnatt.exe 2014-11-12 08:13:29 A1A2EE55A2C69F79AED00973E604B9C4 418304 ----a-w- C:\Windows\SysWOW64\dxtmsft.dll 2014-11-12 08:13:29 8585BC27224F97458C186AA085B754A7 478208 ----a-w- C:\Windows\SysWOW64\ieui.dll 2014-11-12 08:13:28 36EE0A2A981617610F921BCBB997DB06 12819456 ----a-w- C:\Windows\SysWOW64\ieframe.dll 2014-11-12 08:13:26 4169C6A6613856D69224498620F0C2B5 1155072 ----a-w- C:\Windows\SysWOW64\mshtmlmedia.dll 2014-11-12 08:13:25 AE39939F1E25401B9A4952A7A8D372AC 4298240 ----a-w- C:\Windows\SysWOW64\jscript9.dll 2014-11-12 08:13:25 9ED3132B7F0D36FA9911721E8B2CB968 501248 ----a-w- C:\Windows\SysWOW64\vbscript.dll 2014-11-12 08:13:25 6DD7D61A8EF3DFEC4FAEFEB395E77424 1892864 ----a-w- C:\Windows\SysWOW64\wininet.dll 2014-11-12 08:13:23 755D0A90CFC4BCB178D7070B0351F0AE 64000 ----a-w- C:\Windows\SysWOW64\MshtmlDac.dll 2014-11-12 08:13:23 139E85C4E5DF322AE1BF6544D8C32B0A 168960 ----a-w- C:\Windows\SysWOW64\msrating.dll 2014-11-12 08:12:48 537184E7306E06BB22C5B93D2AFA4DF8 1237504 ----a-w- C:\Windows\SysWOW64\msxml3.dll 2014-11-12 08:12:47 09FA271EE1F9AD68B2D1C1C210F4B71F 2048 ----a-w- C:\Windows\SysWOW64\msxml3r.dll 2014-11-12 08:12:45 5FDBDEECA34E73325D87C5ACD16A3EEC 701440 ----a-w- C:\Windows\SysWOW64\IMJP10K.DLL 2014-11-12 08:12:42 FD79B005E849DF3D7E9B5EB7A637C528 374784 ----a-w- C:\Windows\SysWOW64\AudioEng.dll 2014-11-12 08:12:42 8D338464B851DDD76E2B876A3E09EB70 442880 ----a-w- C:\Windows\SysWOW64\AUDIOKSE.dll 2014-11-12 08:12:41 AA7325057A1E1CC401798C0B1238E182 195584 ----a-w- C:\Windows\SysWOW64\AudioSes.dll 2014-11-12 08:12:35 8CFAEFCD7F1E004950FCAE870A501B3E 248832 ----a-w- C:\Windows\SysWOW64\schannel.dll 2014-11-12 08:12:34 8FE6AB488ECDC60930CE973A7051B0D4 221184 ----a-w- C:\Windows\SysWOW64\ncrypt.dll 2014-11-12 08:12:33 B580A6B9932669DE703001AEE66D5BB1 259584 ----a-w- C:\Windows\SysWOW64\msv1_0.dll 2014-11-12 08:12:32 9CEA80FFC617E6B6DD7B52E6225C0D38 65536 ----a-w- C:\Windows\SysWOW64\TSpkg.dll 2014-11-12 08:12:32 37BC079204BF9B087D6DE6B728908B4B 172032 ----a-w- C:\Windows\SysWOW64\wdigest.dll 2014-11-12 08:12:27 8205E55DFB11809E5F2AAD1C48840535 17408 ----a-w- C:\Windows\SysWOW64\credssp.dll 2014-11-12 08:11:55 0F39AC3274312EFFD03928291E8BA7CA 67584 ----a-w- C:\Windows\SysWOW64\packager.dll 2014-11-12 08:11:45 CB55B9AAB060C803BE4AD229AA0FEC28 2363904 ----a-w- C:\Windows\SysWOW64\msi.dll 2014-11-12 08:10:47 EDA54D2E17C0271D2CDA946ABE344110 571904 ----a-w- C:\Windows\SysWOW64\oleaut32.dll 2014-11-11 11:39:03 D7324EB1EDCB8990F8522DE0311359E9 867240 ----a-w- C:\Windows\SysWOW64\npDeployJava1.dll 2014-11-11 11:39:03 2A7915FBC3601CDF5F4C2F6528A501FB 789416 ----a-w- C:\Windows\SysWOW64\deployJava1.dll ====== C:\Windows\SysWOW64\drivers ===== ====== C:\Windows\Sysnative ===== 2014-11-19 07:31:34 8A8CB073A4B9F9D97CFA8CA9C1C851CE 728064 ----a-w- C:\Windows\Sysnative\kerberos.dll 2014-11-19 07:31:34 1306E6A1BF4D506CD687DF9F947270F2 241152 ----a-w- C:\Windows\Sysnative\pku2u.dll 2014-11-12 08:14:46 008CD4EBFABCF78D0F19B3778492648C 683520 ----a-w- C:\Windows\Sysnative\termsrv.dll 2014-11-12 08:14:45 58F87BF5659C8EBC61EB439C916F2F9A 681984 ----a-w- C:\Windows\Sysnative\adtschema.dll 2014-11-12 08:14:44 C4C1B73FC2FF151BA08E1EAFDE2A2FAF 1460736 ----a-w- C:\Windows\Sysnative\lsasrv.dll 2014-11-12 08:14:44 7184AEACDA13E64B10F84E9DD79C8A01 146432 ----a-w- C:\Windows\Sysnative\msaudite.dll 2014-11-12 08:13:38 7293701905DF1F40760C851F20DDC9EC 114688 ----a-w- C:\Windows\Sysnative\ieetwcollector.exe 2014-11-12 08:13:38 1F3794CE1AEA5DA12ACF90210EAE4ECB 48640 ----a-w- C:\Windows\Sysnative\ieetwproxystub.dll 2014-11-12 08:13:37 854B230F5D77486B67D809FFB8A10C7E 2724864 ----a-w- C:\Windows\Sysnative\mshtml.tlb 2014-11-12 08:13:37 4E47ABA3C6C5032446A2AF7EFD026037 716800 ----a-w- C:\Windows\Sysnative\ie4uinit.exe 2014-11-12 08:13:37 26BC4EC95E363DD59171710E22108F15 34304 ----a-w- C:\Windows\Sysnative\iernonce.dll 2014-11-12 08:13:35 33098C85B789630865CD3F5D22FB0DFC 77824 ----a-w- C:\Windows\Sysnative\JavaScriptCollectionAgent.dll 2014-11-12 08:13:32 56651A76C63DAF2C593F1F767FC8A856 1550336 ----a-w- C:\Windows\Sysnative\urlmon.dll 2014-11-12 08:13:32 1C216980E7D21100A357B52B3C45F78D 388272 ----a-w- C:\Windows\Sysnative\iedkcs32.dll 2014-11-12 08:13:31 E17C34BECCD1388E9B386A9F82F01222 4096 ----a-w- C:\Windows\Sysnative\ieetwcollectorres.dll 2014-11-12 08:13:29 C6A719FD0B07B2DD0ADACD07636F4BAD 968704 ----a-w- C:\Windows\Sysnative\MsSpellCheckingFacility.exe 2014-11-12 08:13:29 2A1A7F17C906941334C6A67E935F214B 316928 ----a-w- C:\Windows\Sysnative\dxtrans.dll 2014-11-12 08:13:28 1E30BECF0DB35481588FB72C9CF97CA2 800768 ----a-w- C:\Windows\Sysnative\msfeeds.dll 2014-11-12 08:13:27 BD708EBEDB35E474F1A19747154ACC47 799232 ----a-w- C:\Windows\Sysnative\ieapfltr.dll 2014-11-12 08:13:27 6507CA9349500A535AF70670F248E525 66560 ----a-w- C:\Windows\Sysnative\iesetup.dll 2014-11-12 08:13:26 BA4EC6139B8830BBA9CC5D065CA5796C 2884096 ----a-w- C:\Windows\Sysnative\iertutil.dll 2014-11-12 08:13:26 5C9D58591D0091630452B04F35527240 2124288 ----a-w- C:\Windows\Sysnative\inetcpl.cpl 2014-11-12 08:13:25 31F2A5ECFD2C75F970A3007ACD5627C7 54784 ----a-w- C:\Windows\Sysnative\jsproxy.dll 2014-11-12 08:13:24 08BCDD6C9E23D00309F359620461DFE8 144384 ----a-w- C:\Windows\Sysnative\ieUnatt.exe 2014-11-12 08:13:22 69602F6259598A7837CB83D3608FE293 633856 ----a-w- C:\Windows\Sysnative\ieui.dll 2014-11-12 08:13:22 277A4735954F1BF29EE3D138A5251BFE 490496 ----a-w- C:\Windows\Sysnative\dxtmsft.dll 2014-11-12 08:13:20 154B8555A118BCFD95F358390E418B00 14390272 ----a-w- C:\Windows\Sysnative\ieframe.dll 2014-11-12 08:13:19 98088A13F65BE35DA3693F264740CEEC 1359360 ----a-w- C:\Windows\Sysnative\mshtmlmedia.dll 2014-11-12 08:13:19 7EE5FBD190BF5B27F7977EA6CBF0DCAC 92160 ----a-w- C:\Windows\Sysnative\mshtmled.dll 2014-11-12 08:13:18 F208D7FB40FD80EA9F123BABF687359C 6040064 ----a-w- C:\Windows\Sysnative\jscript9.dll 2014-11-12 08:13:18 B6DC4597FF946B0C8B29650A71F52D4E 580096 ----a-w- C:\Windows\Sysnative\vbscript.dll 2014-11-12 08:13:18 7EC80DB959695D4F927D2D601DA59F35 814080 ----a-w- C:\Windows\Sysnative\jscript9diag.dll 2014-11-12 08:13:17 6FC2819A4F80AAB2DADEDFC1EFEE3C3F 2365440 ----a-w- C:\Windows\Sysnative\wininet.dll 2014-11-12 08:13:15 EE3592B010E3F69D141323E592C01A1A 199680 ----a-w- C:\Windows\Sysnative\msrating.dll 2014-11-12 08:13:15 4B6D9AB2ECD11AF5F6B1C42D938E0A85 88064 ----a-w- C:\Windows\Sysnative\MshtmlDac.dll 2014-11-12 08:13:11 BBD6A636AAA65D874F3863280CD8373D 25110016 ----a-w- C:\Windows\Sysnative\mshtml.dll 2014-11-12 08:12:48 364ECFF4ABD9D575F4F7CF7EB7928EF3 1882624 ----a-w- C:\Windows\Sysnative\msxml3.dll 2014-11-12 08:12:47 D005697F0467BBDDAB7638496DA5DB52 2048 ----a-w- C:\Windows\Sysnative\msxml3r.dll 2014-11-12 08:12:46 1FEBD408F32DFC523882E7DA5AC57819 878080 ----a-w- C:\Windows\Sysnative\IMJP10K.DLL 2014-11-12 08:12:42 FAFCB80D42A65964B6F4945283B8C10F 296448 ----a-w- C:\Windows\Sysnative\AudioSes.dll 2014-11-12 08:12:42 DE3E38431B00C2EA247C53675DCF01A0 680960 ----a-w- C:\Windows\Sysnative\audiosrv.dll 2014-11-12 08:12:42 B1BB7B91C3C878FDB2874138CE81C4EF 284672 ----a-w- C:\Windows\Sysnative\EncDump.dll 2014-11-12 08:12:42 A2C9E45F4069A002E985D1563D16813B 440832 ----a-w- C:\Windows\Sysnative\AudioEng.dll 2014-11-12 08:12:42 9383B21A4B77C130940262DDC5F3F49B 500224 ----a-w- C:\Windows\Sysnative\AUDIOKSE.dll 2014-11-12 08:12:36 A71B81AC2C14ABA013CCF1225D9E3E36 342016 ----a-w- C:\Windows\Sysnative\schannel.dll 2014-11-12 08:12:35 109CC0DF72CC07A6CB59D2995255A1DA 309760 ----a-w- C:\Windows\Sysnative\ncrypt.dll 2014-11-12 08:12:33 55F0CF40479A1FC89CFA578909A540F2 210944 ----a-w- C:\Windows\Sysnative\wdigest.dll 2014-11-12 08:12:33 47C48C705F4F1EFC99B50B43AE4301FE 314880 ----a-w- C:\Windows\Sysnative\msv1_0.dll 2014-11-12 08:12:32 DF30FC54FFF79BC744B22A4850A3CF92 86528 ----a-w- C:\Windows\Sysnative\TSpkg.dll 2014-11-12 08:12:28 336BA030AB7B05300CB0B5C6AFB27176 22016 ----a-w- C:\Windows\Sysnative\credssp.dll 2014-11-12 08:11:55 934735F508E297504460935B71E99F0B 77824 ----a-w- C:\Windows\Sysnative\packager.dll 2014-11-12 08:11:52 93C055B6AAD76360A60CB7E59A491531 3198976 ----a-w- C:\Windows\Sysnative\win32k.sys 2014-11-12 08:11:46 2720C94ADCC1727A66365CCB1CE456C4 3241984 ----a-w- C:\Windows\Sysnative\msi.dll 2014-11-12 08:10:48 B938AF16A521C913791C6F7AFF032757 861696 ----a-w- C:\Windows\Sysnative\oleaut32.dll ====== C:\Windows\Sysnative\drivers ===== 2014-11-12 08:14:45 41774FF331F609EF442B7398EE6202B1 155064 ----a-w- C:\Windows\Sysnative\drivers\ksecpkg.sys 2014-11-04 20:23:26 D41D8CD98F00B204E9800998ECF8427E 0 ---ha-w- C:\Windows\Sysnative\drivers\Msft_Kernel_webinstrNew_01009.Wdf ====== C:\Windows\Tasks ====== 2014-11-24 10:54:21 1AD2F72E7ED8C26612EF6BF52B6F8016 4010 ----a-w- C:\Windows\Sysnative\Tasks\LaunchSignup 2014-11-23 19:22:20 7212187B662452DC550B8C473C95DFBF 3438 ----a-w- C:\Windows\Sysnative\Tasks\DoctorPC_Popup 2014-11-23 19:22:18 29E5081198CEF619D18807D2D8E57204 3174 ----a-w- C:\Windows\Sysnative\Tasks\DoctorPC_Start 2014-11-23 19:13:56 -------- d-----w- C:\Windows\Sysnative\Tasks\SystemSockets 2014-11-23 19:13:53 -------- d-----w- C:\Windows\Sysnative\Tasks\Browser Updater 2014-11-23 19:13:50 -------- d-----w- C:\Windows\Sysnative\Tasks\ProtectedSearch 2014-11-19 09:46:42 C1A39FBC56EAF45E8CA7D30CCA7EAF26 3484 ----a-w- C:\Windows\Sysnative\Tasks\HostSecure3 2014-11-19 09:46:32 C0EF73B3D65B26B3169A2D0D7673B62D 3484 ----a-w- C:\Windows\Sysnative\Tasks\HostSecure2 2014-11-19 09:45:55 17F860EFECEE5AEDF30A5710E045E4FC 3294 ----a-w- C:\Windows\Sysnative\Tasks\SecureHost 2014-11-04 20:29:10 0667498DF7E8BC37D4BBD62C9CBC315E 3150 ----a-w- C:\Windows\Sysnative\Tasks\{FD5F5F50-A37F-42F3-93AD-7C539D2E4962} 2014-10-30 14:39:37 -------- d-----w- C:\Windows\Sysnative\Tasks\2BrightSparks ====== C:\Windows\Temp ====== ======= C:\Program Files ===== 2014-10-30 19:07:23 -------- d-----w- C:\Program Files\CDisplayEx 2014-10-30 18:55:04 -------- d-----w- C:\Program Files\FileViewPro 2014-10-29 12:19:20 -------- d-----w- C:\Program Files\Calibre2 ======= C:\PROGRA~2 ===== 2014-11-24 10:54:35 -------- d-----w- C:\PROGRA~2\globalUpdate 2014-11-23 19:21:37 -------- d-----w- C:\PROGRA~2\doctorpclab.com 2014-11-20 21:48:21 -------- d-----w- C:\PROGRA~2\f552dd4c52e3 2014-11-19 12:12:14 -------- d-----w- C:\PROGRA~2\Reimageplus.com 2014-11-11 11:36:26 -------- d-----w- C:\PROGRA~2\Java ======= C: ===== ====== C:\Users\DELL\AppData\Roaming ====== 2014-11-24 10:54:35 -------- d-----w- C:\Users\DELL\AppData\Local\globalUpdate 2014-11-24 10:13:03 -------- d-----w- C:\Users\DELL\AppData\Locallow\Dr. PC 2014-11-23 19:22:14 -------- d-----w- C:\Users\DELL\AppData\Local\Doctor_PC 2014-11-23 19:21:37 -------- d-----w- C:\Users\DELL\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\doctorpclab.com 2014-11-23 19:13:07 -------- d-----w- C:\Users\DELL\AppData\Locallow\smileyswelove 2014-11-19 11:02:10 -------- d-----r- C:\Users\DELL\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-11-19 10:08:16 -------- d-----w- C:\Windows\sysWoW64\config\systemprofile\AppData\Roaming\Fighters 2014-11-19 09:45:54 -------- d-----w- C:\Users\DELL\AppData\Roaming\itesing 2014-11-15 09:58:39 -------- d-sh--w- C:\Users\DELL\AppData\Local\EmieBrowserModeList 2014-11-15 09:57:44 -------- d-sh--w- C:\Users\DELL\AppData\Locallow\EmieBrowserModeList 2014-11-11 11:35:25 -------- d-----w- C:\Users\DELL\AppData\Locallow\Sun 2014-10-30 18:58:33 -------- d-----w- C:\Users\DELL\AppData\Local\FileViewPro 2014-10-30 18:58:22 -------- d-----w- C:\Users\DELL\AppData\Roaming\IsolatedStorage 2014-10-30 14:39:36 -------- d-----w- C:\Users\DELL\AppData\Roaming\2BrightSparks ====== C:\Users\DELL ====== 2014-11-25 07:12:17 8045ABB21A3BDD66A48E1ED5C0F0EF6A 1222144 ----a-w- C:\Users\DELL\Downloads\RSITx64.exe 2014-11-24 09:45:58 5A6F21141B846BD3CE1ED0BD0F19C3AF 2148864 ----a-w- C:\Users\DELL\Desktop\adwcleaner_4.102.exe 2014-11-24 09:44:47 5A6F21141B846BD3CE1ED0BD0F19C3AF 2148864 ----a-w- C:\Users\DELL\Downloads\adwcleaner_4.102.exe 2014-11-18 19:38:09 -------- d-----w- C:\Users\Public\Documents\kpn 2014-11-18 19:18:26 -------- dc-h--w- C:\ProgramData\{40571C04-FADC-4CD9-AA4C-CF43208480CA} 2014-11-11 11:39:24 -------- d-----w- C:\ProgramData\Sun 2014-11-04 20:23:29 8D169D7D8D6CABD7BE728ECB34847873 536 --sha-r- C:\ProgramData\ntuser.pol 2014-11-03 08:32:08 -------- d-----w- C:\ProgramData\Google 2014-10-30 19:07:26 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CDisplayEx 2014-10-30 18:58:23 -------- d-----w- C:\ProgramData\IsolatedStorage 2014-10-29 12:19:10 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\calibre 64bit - E-book Management ====== C: exe-files == 2014-11-23 19:21:37 CB0C71BB0AEA25B032D6A6DC370E05B6 59869 ----a-w- C:\Program Files (x86)\doctorpclab.com\uninst.exe 2014-11-20 20:47:32 6F540FBEE087A02BBC6B32C4C718AF15 72933 ----a-w- C:\Program Files (x86)\f552dd4c52e3\uninstall.exe 2014-11-19 12:12:15 DFC105C4E7B76E78042A44E454C6ED4A 757064 ----a-w- C:\Program Files (x86)\Reimageplus.com\ReimageRepair.exe 2014-11-18 19:18:18 5899DF23A4ED3875EA6CA7AAF90283F6 505344 ------w- C:\Program Files (x86)\KPN\Servicetool\KIA\Drivers\TG122n\DevInst.exe 2014-11-18 19:18:07 6AB89866536F04A9AD37A6A6142575EB 7424928 ------w- C:\Program Files (x86)\KPN\Servicetool\Update\M2Updater.exe 2014-11-18 19:18:07 59078BF75DBE6990DBC80391361C74A5 29519776 ------w- C:\Program Files (x86)\KPN\Servicetool\KIA\Browser\Setup_FF_NDL.exe 2014-11-18 19:18:07 35F35D32EB17D7A1E7585D7127E7F159 4182432 ------w- C:\Program Files (x86)\KPN\Servicetool\FFAddOn.exe 2014-11-18 19:18:07 359626AB3B6E332A72A120A6889512D9 24153656 ------w- C:\Program Files (x86)\KPN\Servicetool\KIA\Browser\chrome_installer.exe 2014-11-18 19:18:05 9D30D5BF3E5AE346927852A90565986B 25097624 ------w- C:\Program Files (x86)\KPN\Servicetool\KIA\KPN_IA.exe 2014-11-18 19:18:04 C4AC7802C74B5C58D47EB707A1B0F203 48445848 ------w- C:\Program Files (x86)\KPN\Servicetool\BBO\KPN_BBO.exe 2014-11-18 19:18:03 BD37860E6214571F2FBFC48EC38199C7 8837568 ------w- C:\Program Files (x86)\KPN\Servicetool\PDF_Viewer\m2PDFViewer.exe 2014-11-18 19:18:03 B2319BA271391F8290D2E55DC99A8C38 9764504 ------w- C:\Program Files (x86)\KPN\Servicetool\WNA\KPN_WNA.exe 2014-11-18 19:18:03 7BD7B7F7F80826E0EB79BA78CC5464BC 4155808 ------w- C:\Program Files (x86)\KPN\Servicetool\KPNServicetool_Printer.exe 2014-11-18 19:18:01 CB2CEF3A14CF3D95F5E0B840C751E8F4 13449120 ------w- C:\Program Files (x86)\KPN\Servicetool\KPNServicetool_Repair.exe 2014-11-18 19:18:01 AF34D3ECA4A2D13EEEA360D3C6667404 10490784 ------w- C:\Program Files (x86)\KPN\Servicetool\KPNServicetool_Launcher.exe 2014-11-18 19:18:01 3EF2D7EA44F5408AEDFB3A398650DA5D 7544736 ------w- C:\Program Files (x86)\KPN\Servicetool\KPNServicetool.exe === C: other files == 2014-11-23 19:05:19 A2379219D0E3EF3F7F5FCE4EB9F2E220 539945 ----a-w- C:\Users\DELL\AppData\Local\Temp\a7bc2d5c051e4aa48afc1c90b5483107\iman2.zip 2014-11-22 09:22:03 3590E68B8BBA33A5274B71E5EEB4323C 1945983 ----a-r- C:\Users\DELL\AppData\Local\IM\Identities\{C340EC92-0EA4-4428-B3F7-A1EA59668E07}\Message Store\Attachments\Brijs Stefan - De engelenmaker.zip 2014-11-19 13:47:36 B5DC3FB3155318CEBAAECDE846BFB59D 661855 ----a-w- C:\Users\DELL\Downloads\cs_filter.zip 2014-11-18 19:18:19 B3F36B4B3F192EA87DDC119F3A0B3E45 694888 ------w- C:\Program Files (x86)\KPN\Servicetool\KIA\Drivers\TG122n\rtl8192su.sys ==== Startup Registry Enabled ====================== [HKEY_USERS\S-1-5-21-2412325288-324325390-2824101589-1000\Software\Microsoft\Windows\CurrentVersion\Run] "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe" "Spotify Web Helper"="C:\Users\DELL\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" "ApplePhotoStreams"="C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe" "iCloudServices"="C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe" "Google Update"="C:\Users\DELL\AppData\Local\Google\Update\GoogleUpdate.exe /c" "OfficeSyncProcess"="C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE" "AppleIEDAV"="C:\Program Files (x86)\Common Files\Apple\Internet Services\AppleIEDAV.exe" "Simple Sticky Notes"="C:\Program Files (x86)\Simnet\Simple Sticky Notes\ssn.exe" "EPLTarget\P0000000000000002"="C:\Windows\system32\spool\DRIVERS\x64\3\E_YATIHTU.EXE /EPT EPLTarget\P0000000000000002 /M Epson Stylus Office BX535WD" "EPLTarget\P0000000000000003"="C:\Windows\system32\spool\DRIVERS\x64\3\E_YATIHTU.EXE /EPT EPLTarget\P0000000000000003 /M Epson Stylus Office BX535WD" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "TrueImageMonitor.exe"="C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe" "EEventManager"="C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe" "Standby"="c:\Program Files (x86)\Common Files\Corel\Standby\Standby.exe -START" "APSDaemon"="C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" "BCSSync"="C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe /DelayServices" "iTunesHelper"="C:\Program Files (x86)\iTunes\iTunesHelper.exe" "QuickTime Task"="C:\Program Files (x86)\QuickTime\QTTask.exe -atboottime" "Servicetool"="C:\Program Files (x86)\KPN\Servicetool\KPNServicetool_Launcher.exe /auto" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe" "Spotify Web Helper"="C:\Users\DELL\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" "ApplePhotoStreams"="C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe" "iCloudServices"="C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe" "Google Update"="C:\Users\DELL\AppData\Local\Google\Update\GoogleUpdate.exe /c" "OfficeSyncProcess"="C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE" "AppleIEDAV"="C:\Program Files (x86)\Common Files\Apple\Internet Services\AppleIEDAV.exe" "Simple Sticky Notes"="C:\Program Files (x86)\Simnet\Simple Sticky Notes\ssn.exe" "EPLTarget\P0000000000000002"="C:\Windows\system32\spool\DRIVERS\x64\3\E_YATIHTU.EXE /EPT EPLTarget\P0000000000000002 /M Epson Stylus Office BX535WD" "EPLTarget\P0000000000000003"="C:\Windows\system32\spool\DRIVERS\x64\3\E_YATIHTU.EXE /EPT EPLTarget\P0000000000000003 /M Epson Stylus Office BX535WD" ==== Startup Registry Enabled x64 ====================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IgfxTray"="C:\Windows\system32\igfxtray.exe" "HotKeysCmds"="C:\Windows\system32\hkcmd.exe" "Persistence"="C:\Windows\system32\igfxpers.exe" "Acronis Scheduler2 Service"="C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe" "MSC"="c:\Program Files\Microsoft Security Client\msseces.exe -hide -runkey" "HostSecurePlugin"="C:\Program Files (x86)\Host Secure\HostSecure.exe" "HostSecurePlugin3"="C:\Program Files (x86)\Host Secure\HostSecure.exe" ==== Startup Folders ====================== 2013-01-10 21:05:31 2048 ----a-w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk ==== Task Scheduler Jobs ====================== C:\Windows\tasks\Adobe Flash Player Updater.job --a------ C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [12-11-2014 17:39] C:\Windows\tasks\GoogleUpdateTaskMachineCore.job --a------ C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [] C:\Windows\tasks\GoogleUpdateTaskMachineUA.job --a------ C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [] C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2412325288-324325390-2824101589-1000Core.job --a------ [Undetermined Task] C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2412325288-324325390-2824101589-1000UA.job --a------ [Undetermined Task] ==== Other Scheduled Tasks ====================== "C:\Windows\SysNative\tasks\0" [c:\program files (x86)\internet explorer\iexplore.exe] "C:\Windows\SysNative\tasks\4470" [wscript.exe C:\Users\DELL\AppData\Local\Temp\launchie.vbs //B] "C:\Windows\SysNative\tasks\Adobe Flash Player Updater" [C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe] "C:\Windows\SysNative\tasks\Apple Diagnostics" [C:\Program Files (x86)\Common Files\Apple\Internet Services\EReporter.exe] "C:\Windows\SysNative\tasks\DoctorPC_Popup" [C:\Program Files (x86)\Doctor PC\Splash.exe] "C:\Windows\SysNative\tasks\DoctorPC_Start" [C:\Program Files (x86)\Doctor PC\DoctorPC.exe] "C:\Windows\SysNative\tasks\GoogleUpdateTaskMachineCore" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe] "C:\Windows\SysNative\tasks\GoogleUpdateTaskMachineUA" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe] "C:\Windows\SysNative\tasks\GoogleUpdateTaskUserS-1-5-21-2412325288-324325390-2824101589-1000Core" [C:\Users\DELL\AppData\Local\Google\Update\GoogleUpdate.exe] "C:\Windows\SysNative\tasks\GoogleUpdateTaskUserS-1-5-21-2412325288-324325390-2824101589-1000UA" [C:\Users\DELL\AppData\Local\Google\Update\GoogleUpdate.exe] "C:\Windows\SysNative\tasks\HostSecure2" [C:\Program] "C:\Windows\SysNative\tasks\HostSecure3" [C:\Program] "C:\Windows\SysNative\tasks\LaunchSignup" [C:\Program Files (x86)\MyPC Backup\Signup Wizard.exe] "C:\Windows\SysNative\tasks\SecureHost" [C:\Program] "C:\Windows\SysNative\tasks\{2CEBD3C1-8B80-4E17-80E7-E35F56793018}" [C:\Users\DELL\Desktop\nummer psp15\nummer psp15.exe] "C:\Windows\SysNative\tasks\{5E8F5F64-C672-480A-B9D7-D5A97D528A31}" [C:\Users\DELL\Desktop\regedit.exe] "C:\Windows\SysNative\tasks\{6C3C0A90-402B-4F5E-A829-BE630018D5CB}" [C:\Program Files (x86)\byLight\2020\2020.exe] "C:\Windows\SysNative\tasks\{768738BE-F51C-41B2-9CEC-36AFD5B77F1B}" [C:\Users\DELL\Desktop\nummer psp15\nummer psp15.exe] "C:\Windows\SysNative\tasks\{858E836B-9B19-40B5-9F3A-877C201715F1}" [C:\Users\DELL\Desktop\nummer psp15\nummer psp15.exe] "C:\Windows\SysNative\tasks\{98A8F3EF-38EE-4563-BA85-8B04001F4E19}" [C:\Users\DELL\Documents\Eyecandy3.1\Eyecandy3.1\301PATCH.EXE] "C:\Windows\SysNative\tasks\{9AA12B15-FC4B-4F3A-BF15-155BA3B69259}" [C:\Users\DELL\Desktop\nummer psp15\nummer psp15.exe] "C:\Windows\SysNative\tasks\{9CA753FE-D476-4B0F-A38E-16EE3BB1EFD2}" [C:\Users\DELL\Desktop\nummer psp15\nummer psp15.exe] "C:\Windows\SysNative\tasks\{BB4B5DE4-3F8E-492A-ACA4-1F04645E72E6}" [C:\Users\DELL\Desktop\nummer psp15\nummer psp15.exe] "C:\Windows\SysNative\tasks\{CFDF3649-0DFB-4067-BA86-0A9EF7EBCFB4}" [C:\Users\DELL\Desktop\nummer psp15\nummer psp15.exe] "C:\Windows\SysNative\tasks\{D9DAAC0D-443B-47CB-85DD-C0C9CB174264}" [C:\Users\DELL\Documents\Eyecandy3.1\Eyecandy3.1\301PATCH.EXE] "C:\Windows\SysNative\tasks\{F2627C0D-8562-4900-ADCA-98FBA40D1DA8}" [C:\Users\DELL\Documents\Eyecandy3.1\Eyecandy3.1\301PATCH.EXE] "C:\Windows\SysNative\tasks\Apple\AppleSoftwareUpdate" [C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe] "C:\Windows\SysNative\tasks\Browser Updater\Browser Updater" ["C:\Program Files (x86)\HomeTab\WBrowserUpdate.exe"] "C:\Windows\SysNative\tasks\NCH Swift Sound\soundtapShakeIcon" [C:\Program Files (x86)\NCH Swift Sound\SoundTap\SoundTap.exe] "C:\Windows\SysNative\tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask" [%systemroot%\system32\sc.exe start osppsvc] "C:\Windows\SysNative\tasks\ProtectedSearch\Protected Search" ["C:\Program Files (x86)\HomeTab\WBrowserKeeper.exe"] "C:\Windows\SysNative\tasks\SystemSockets\SystemSockets" ["C:\Program Files (x86)\HomeTab\WConnectorProductivity.exe"] ==== Firefox Extensions Registry ====================== [HKEY_CURRENT_USER\Software\Mozilla\Firefox\Extensions] "{B64D9B05-48E1-4CEB-BF58-E0643994E900}"="C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff" [20-01-2014 21:39] ==== Firefox Extensions ====================== ProfilePath: C:\Users\DELL\AppData\Roaming\Mozilla\Firefox\Profiles\vvyzlx5u.default - chineseperakungmailcom - %ProfilePath%\extensions\chineseperakun@gmail.com - Undetermined - %ProfilePath%\extensions\staged - Undetermined - %ProfilePath%\extensions\{35106bca-6c78-48c7-ac28-56df30b51d2a} ProfilePath: C:\Users\DELL\AppData\Roaming\Thunderbird\Profiles\yee9j9v7.default - Undetermined - %ProfilePath%\extensions\staged-xpis - Statusbar Date - %ProfilePath%\extensions\statusbardate@webspirited.com.xpi - Instrument Test - %ProfilePath%\extensions\tbtestpilot@labs.mozilla.com.xpi AppDir: C:\Program Files (x86)\Mozilla Firefox - Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} ==== Firefox Plugins ====================== ==== C:\zoek_backup content ====================== C:\zoek_backup (files=487 folders=166 64399347 bytes) ==== EOF on di 25-11-2014 at 10:28:55,88 ======================