Zoek.exe v5.0.0.0 Updated 24-12-2014 Tool run by Patrick on vr 26/12/2014 at 17:53:53,78. Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x64 Running in: Normal Mode Internet Access Detected Launched: C:\Users\Patrick\Desktop\zoek.exe [Scan all users] [Script inserted] [Checkboxes used] ==== Older Logs ====================== C:\zoek-results2014-08-09-092633.log 26133 bytes ==== Empty Folders Check ====================== C:\PROGRA~2\AGEIA Technologies deleted successfully C:\PROGRA~2\COMMON~1\Pegasus Imaging deleted successfully C:\PROGRA~3\ProcessLasso deleted successfully C:\PROGRA~3\Web Page Maker deleted successfully C:\Users\Patrick\AppData\Roaming\BandExtend deleted successfully C:\Users\Patrick\AppData\Roaming\DiskDefrag deleted successfully C:\Users\Patrick\AppData\Roaming\New Version Available deleted successfully C:\Users\Patrick\AppData\Roaming\Opera Software deleted successfully C:\Users\Patrick\AppData\Roaming\Vso deleted successfully C:\Users\Patrick\AppData\Roaming\Wise Care 365 deleted successfully C:\Users\Patrick\AppData\Local\Opera Software deleted successfully C:\Users\Patrick\AppData\Local\STARGAZE_IMAGE_CACHE deleted successfully ==== Deleting CLSID Registry Keys ====================== HKEY_USERS\S-1-5-21-3130560279-3158009234-3752583673-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{eb65ab77-ebb2-4a75-9561-4d960a3fc6f3} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Extensions\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} deleted successfully HKEY_CLASSES_ROOT\CLSID\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} deleted successfully HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{eb65ab77-ebb2-4a75-9561-4d960a3fc6f3} deleted successfully ==== Deleting CLSID Registry Values ====================== ==== Running Processes ====================== C:\Program Files (x86)\AVG\AVG2014\avgfws.exe C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe C:\Program Files (x86)\Bonjour\mDNSResponder.exe C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe C:\Program Files (x86)\Blue Jet Button\bjb.exe C:\Program Files (x86)\EaseUS\Todo Backup\bin\Agent.exe C:\Program Files (x86)\Google\Update\1.3.25.11\GoogleCrashHandler.exe C:\Program Files (x86)\Softland\FBackup 5\bService.exe C:\Users\Patrick\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe C:\Program Files (x86)\AVG\AVG2014\avgui.exe C:\Program Files (x86)\Samsung\Easy Settings\MovieColorEnhancer.exe C:\Program Files (x86)\Samsung\Easy Settings\EasySpeedUpManager.exe C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe C:\Program Files (x86)\Samsung\Easy Settings\SmartSetting.exe C:\Program Files (x86)\AnVir Task Manager Pro\anvir.exe C:\windows\SysWOW64\ctfmon.exe C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe C:\Program Files (x86)\Samsung\Easy Settings\SamsungDeviceConfiguration.exe C:\ProgramData\Samsung\SW Update Service\SWMAgent.exe C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe C:\Program Files (x86)\EaseUS\Todo Backup\bin\TodoBackupService.exe C:\Program Files\Sandboxie\32\SbieSvc.exe C:\Program Files (x86)\CuteReminderEnterprise\CuteReminder.exe C:\Program Files (x86)\PopTrayU\PopTrayU.exe C:\Users\Patrick\Desktop\zoek.exe C:\windows\SysWOW64\cmd.exe C:\windows\SysWOW64\cmd.exe C:\windows\SysWOW64\cmd.exe ==== Deleting Services ====================== ==== Deleting Files \ Folders ====================== C:\Users\Patrick\AppData\Roaming\Mozilla\Firefox\Profiles\yl7oer8n.default\extensions\{4BBDD651-70CF-4821-84F8-2B918CF89CA3} deleted C:\Users\Patrick\AppData\Roaming\Mozilla\Firefox\Profiles\yl7oer8n.default\extensions\{DAD0F81A-CF67-4eed-98D6-26F6E47274CA} deleted C:\Users\Patrick\AppData\Roaming\Mozilla\Firefox\Profiles\yl7oer8n.default\extensions\superstart@enjoyfreeware.org deleted C:\install.exe deleted C:\PROGRA~3\OpenBitCoin deleted C:\PROGRA~3\Sony Corporation deleted C:\PROGRA~3\Package Cache deleted C:\windows\SysNative\config\systemprofile\Searches deleted C:\windows\SysNative\GroupPolicy\Machine deleted C:\windows\SysNative\GroupPolicy\User deleted C:\windows\SysNative\GroupPolicy\GPT.INI deleted C:\windows\Syswow64\GroupPolicy\gpt.ini deleted "C:\Users\Patrick\AppData\Roaming\Mozilla\Firefox\Profiles\yl7oer8n.default\searchplugins\ixquick---nederlands.xml" deleted "C:\ProgramData\T23J7" deleted "C:\ProgramData\V93GE" deleted ==== System Specs ====================== Windows: Windows 7 Home Premium Edition (64-bit) Service Pack 1 (Build 7601) Memory (RAM): 8088 MB CPU Info: Intel(R) Core(TM) i7-3610QM CPU @ 2.30GHz CPU Speed: 2290,8 MHz Sound Card: Luidsprekers (Realtek High Defi | Display Adapters: Intel(R) HD Graphics 4000 | Intel(R) HD Graphics 4000 | Intel(R) HD Graphics 4000 | NVIDIA GeForce GT 650M | RDPDD Chained DD | RDP Encoder Mirror Driver | RDP Reflector Display Driver Monitors: 1x; Algemeen PnP-beeldscherm | Screen Resolution: 1280 X 720 - 32 bit Network: Network Present Network Adapters: Microsoft Virtual WiFi Miniport Adapter | Intel(R) Centrino(R) Advanced-N 6235 | Realtek PCIe GBE Family Controller #2 | Bluetooth Device (Personal Area Network) CD / DVD Drives: 1x (E: | ) E: SlimtypeDVD A DS8A8SH Ports: COM3 | COM4 | COM7 | COM6 LPT Port NOT Present. Mouse: 5 Button Wheel Mouse Present Hard Disks: C: 906,5GB | D: 758,2GB | Z: 173,3GB Hard Disks - Free: C: 772,9GB | D: 425,5GB | Z: 116,7GB Manufacturer *: American Megatrends Inc. BIOS Info: AT/AT COMPATIBLE | 06/17/14 | SECCSD - 1072009 Time Zone: Romance (standaardtijd) Motherboard *: SAMSUNG ELECTRONICS CO., LTD. SAMSUNG_NP1234567890 Country: Belgi‰ Language: NLB ==== System Specs (Software) ====================== Anti-Virus: AVG Internet Security 2014 On-access scanning disabled (Outdated) Anti-Spyware: Windows Defender disabled (Outdated) Anti-Spyware: AVG Internet Security 2014 disabled (Outdated) Firewall: AVG Internet Security 2014 disabled Default Browser: Firefox 34.0.5 Internet Explorer Version: 11.0.9600.17501 Mozilla Firefox version: 33.1 (x86 nl) Mozilla Firefox version: 34.0.5 (x86 nl) Google Chrome version: 39.0.2171.95 Adobe Reader version: 11.0.10.32 Sun Java version: 1.8.0 (64-bit) Flash Player version: 16.0.0.235 Shockwave Player version: 12.0.3r133 ==== Files Recently Created / Modified ====================== ====== C:\windows ==== 2014-12-20 14:51:48 6BBC2F7580C62F27E50EAC52D620B5AB 326 ----a-w- C:\windows\Pexplore.ini 2014-12-20 14:51:48 4ED8A429BF3F8F98BDC35FE446F8E316 1918 ----a-w- C:\windows\if42le.ini ====== C:\Users\Patrick\AppData\Local\Temp ==== ====== Java Cache ===== ====== C:\windows\SysWOW64 ===== 2014-12-18 07:22:25 0481346D0EF668C0D4FF69A7BBEFA846 115712 ----a-w- C:\windows\SysWOW64\ieUnatt.exe ====== C:\windows\SysWOW64\drivers ===== ====== C:\windows\Sysnative ===== 2014-12-18 07:22:25 5564883BFB523D5078A5B1FE3128FD63 144384 ----a-w- C:\windows\Sysnative\ieUnatt.exe 2014-12-13 13:58:53 EDA94A7898252382DD71FC08D8B1382B 312728 ----a-w- C:\windows\Sysnative\javaws.exe ====== C:\windows\Sysnative\drivers ===== 2014-12-17 07:26:04 26C43960C99EE861A5D0EDC4DCF3B1C3 129752 ----a-w- C:\windows\Sysnative\drivers\4A97235A.sys 2014-12-10 17:28:27 70988118145F5F10EF24720B97F35F65 119296 ----a-w- C:\windows\Sysnative\drivers\tdx.sys ====== C:\windows\Tasks ====== 2014-12-13 13:52:37 -------- d-----w- C:\windows\Sysnative\Tasks\Softland ====== C:\windows\Temp ====== ======= C:\Program Files ===== 2014-12-26 12:09:47 -------- d-----w- C:\Program Files\Inpaint 2014-12-20 20:09:38 -------- d-----w- C:\Program Files\SilverFast Application 2014-12-07 13:43:02 -------- d-----w- C:\Program Files\Pinnacle 2014-12-03 09:48:02 -------- d-----w- C:\Program Files\BatchInpaint ======= C:\PROGRA~2 ===== 2014-12-26 12:09:08 -------- d-----w- C:\PROGRA~2\TeoreX 2014-12-20 14:51:32 -------- d-----w- C:\PROGRA~2\COMMON~1\NewSoft 2014-12-20 14:51:28 -------- d-----w- C:\PROGRA~2\NewSoft ======= C: ===== ====== C:\Users\Patrick\AppData\Roaming ====== 2014-12-20 20:11:54 -------- d-----w- C:\Users\Patrick\AppData\Roaming\LaserSoft Imaging 2014-12-20 20:09:56 -------- d-----w- C:\Users\Patrick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\LaserSoft Imaging 2014-12-20 14:52:44 -------- d-----w- C:\Users\Patrick\AppData\Local\NewSoft 2014-12-20 09:35:52 407AAB8C27CF7081EECE071C90A65B83 17 ----a-w- C:\Users\Patrick\AppData\Local\resmon.resmoncfg 2014-12-19 16:55:15 97B899B3164B8B42892458C59F22D0A7 180768 ----a-w- C:\Users\Patrick\AppData\Local\GDIPFONTCACHEV1.DAT 2014-12-17 08:59:38 2420432C1B9FD66A8A329ED472926971 12994 ----a-w- C:\Users\Patrick\AppData\Roaming\Door lijstscheidingstekens gescheiden waarden (Windows).CAL 2014-12-13 14:06:38 -------- d-----w- C:\Users\Patrick\AppData\Roaming\Wise Auto Shutdown 2014-12-13 13:54:17 -------- d-----w- C:\Users\Patrick\AppData\Locallow\Oracle 2014-12-13 09:42:45 -------- d-----w- C:\Users\UpdatusUser\AppData\Local\temp 2014-12-13 09:42:45 -------- d-----w- C:\Users\TEMP\AppData\Local\temp 2014-12-13 09:42:45 -------- d-----w- C:\Users\TEMP.Patrick-PC\AppData\Local\temp 2014-12-13 09:42:45 -------- d-----w- C:\Users\TEMP.Patrick-PC.003\AppData\Local\temp 2014-12-13 09:42:45 -------- d-----w- C:\Users\TEMP.Patrick-PC.002\AppData\Local\temp 2014-12-13 09:42:45 -------- d-----w- C:\Users\TEMP.Patrick-PC.001\AppData\Local\temp 2014-12-13 09:42:45 -------- d-----w- C:\Users\TEMP.Patrick-PC.000\AppData\Local\temp 2014-12-13 09:42:45 -------- d-----w- C:\Users\Public\AppData\Local\temp 2014-12-13 09:42:45 -------- d-----w- C:\Users\Default\AppData\Local\temp 2014-12-13 08:22:51 -------- d-----w- C:\Users\Patrick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup (Delayed by AnVir) 2014-12-07 13:55:48 -------- d-----w- C:\Users\Patrick\AppData\Local\Pinnacle_Studio_18 ====== C:\Users\Patrick ====== 2014-12-26 12:09:48 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Inpaint 2014-12-26 09:57:23 -------- d-----w- C:\ProgramData\Uninstall 2014-12-20 20:09:39 -------- d-----w- C:\ProgramData\LaserSoft Imaging 2014-12-20 14:51:48 -------- d-----w- C:\ProgramData\Newsoft 2014-12-20 14:51:47 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NewSoft 2014-12-13 13:52:19 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FBackup 5 2014-12-13 13:52:02 -------- d-----w- C:\ProgramData\regid.2006-01.com.fbackup 2014-12-07 13:43:02 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Pinnacle Studio 18 2014-12-03 09:48:03 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BatchInpaint ====== C: exe-files == 2014-12-26 12:09:47 D1F1F426F32C2C9A72DB290BFFA72030 14495744 ----a-w- C:\Program Files\Inpaint\Inpaint.exe 2014-12-26 12:09:47 2DDD0C7982404E59D526CDBF8FDE51B2 719816 ----a-w- C:\Program Files\Inpaint\unins000.exe 2014-12-26 09:57:23 AE6554FA15F1C2D952DAFCE0CAEDFD90 5845224 ----a-w- C:\ProgramData\Uninstall\{0BCCDCE5-D1AD-47A9-8864-D2A411403D89}\setup.exe 2014-12-23 17:01:25 CBD288A589D22A6BF4B3DC4B5F55275B 307606328 ----a-w- C:\ProgramData\NVIDIA Corporation\NetService\e9eb0ea8-02db-4a97-9fdf-10c078d73ea9\347.09-notebook-win8-win7-64bit-international-whql-g.exe 2014-12-22 07:40:58 6D04EAF213113F309F7CEB66EB63DCD9 189216 ----a-w- C:\Program Files (x86)\Glary Utilities 5\fileencrypt.exe 2014-12-22 06:57:52 724501913340393F48B0020B32E8E59B 22816 ----a-w- C:\Program Files (x86)\Glary Utilities 5\Native\wxp_x86\RegBootDefrag.exe 2014-12-22 06:57:50 B742EF63B83BC37816188371A2AE7367 101664 ----a-w- C:\Program Files (x86)\Glary Utilities 5\Native\wxp_x86\BootDefrag.exe 2014-12-22 06:57:48 505F6A556CFCDE7306AA8F7721017E45 28960 ----a-w- C:\Program Files (x86)\Glary Utilities 5\Native\wxp_x64\RegBootDefrag.exe 2014-12-22 06:57:46 0756B42699CA071F3D44531E04D5E67F 118048 ----a-w- C:\Program Files (x86)\Glary Utilities 5\Native\wxp_x64\BootDefrag.exe 2014-12-22 06:57:42 939E03E4B357558D0A7439E60C1A4CC7 101664 ----a-w- C:\Program Files (x86)\Glary Utilities 5\Native\wnet_x86\BootDefrag.exe 2014-12-22 06:57:40 C3ED349FDCD9CD3EADD33FFC4621BD5A 118048 ----a-w- C:\Program Files (x86)\Glary Utilities 5\Native\wnet_x64\BootDefrag.exe 2014-12-22 06:57:34 D09DCFAD8C3DF840C72A238BEC779E8C 101664 ----a-w- C:\Program Files (x86)\Glary Utilities 5\Native\wlh_x86\BootDefrag.exe 2014-12-22 06:57:32 B4D23E77D4D54C37BB50EC038C0E151C 118048 ----a-w- C:\Program Files (x86)\Glary Utilities 5\Native\wlh_x64\BootDefrag.exe 2014-12-22 06:57:30 360ABE9C77B7DAF560183D0229CF7FD2 101664 ----a-w- C:\Program Files (x86)\Glary Utilities 5\Native\win7_x86\BootDefrag.exe 2014-12-22 06:57:26 7C95E1540B8FED83C52D042AD068D92D 118048 ----a-w- C:\Program Files (x86)\Glary Utilities 5\Native\win7_x64\BootDefrag.exe 2014-12-22 06:57:22 24026AA275551FC15A7AF3165C007E97 17184 ----a-w- C:\Program Files (x86)\Glary Utilities 5\x64\Unistall.exe 2014-12-22 06:57:16 AD0EFFD227DF0A77DB9828DB0B027309 135968 ----a-w- C:\Program Files (x86)\Glary Utilities 5\x64\Win64ShellLink.exe 2014-12-22 06:57:12 C7D0F09C287910FA9EBBE2CA931058F0 63776 ----a-w- C:\Program Files (x86)\Glary Utilities 5\upgrade.exe 2014-12-22 06:57:04 AC9C053AD965624D01278487D4905E68 334624 ----a-w- C:\Program Files (x86)\Glary Utilities 5\Uninstaller.exe 2014-12-22 06:57:00 CC5C52D23755903B85A43A2FAB4DF971 412448 ----a-w- C:\Program Files (x86)\Glary Utilities 5\SoftwareUpdate.exe 2014-12-22 06:56:38 C55D7CD13AAEF1893F79E7C374EE6E00 36640 ----a-w- C:\Program Files (x86)\Glary Utilities 5\TracksEraser.exe 2014-12-22 06:56:30 54B7434A7A725DCAF5DEEC4CCAA6BDB6 518432 ----a-w- C:\Program Files (x86)\Glary Utilities 5\sysinfo.exe 2014-12-22 06:56:16 146432E458B86C55F31B5BDF488E742F 37152 ----a-w- C:\Program Files (x86)\Glary Utilities 5\StartupManager.exe 2014-12-22 06:56:04 CF96F7B51ED638244C18163847CC23EA 36640 ----a-w- C:\Program Files (x86)\Glary Utilities 5\SpyRemover.exe 2014-12-22 06:55:52 394AD85090E3F696982E12C4D2FB6B94 141088 ----a-w- C:\Program Files (x86)\Glary Utilities 5\shredder.exe 2014-12-22 06:55:28 C16F10293E0F6D7D1B9F5691B7BD9D87 37152 ----a-w- C:\Program Files (x86)\Glary Utilities 5\RestoreCenter.exe 2014-12-22 06:55:20 2B2D5A0014DFA50A39A4C36646387672 37152 ----a-w- C:\Program Files (x86)\Glary Utilities 5\RegistryCleaner.exe 2014-12-22 06:55:16 FCA90D845544C5EF0A27818D4677CB90 95008 ----a-w- C:\Program Files (x86)\Glary Utilities 5\regdefrag.exe 2014-12-22 06:55:14 AD75571149693D226A6877DEB7330BF4 346912 ----a-w- C:\Program Files (x86)\Glary Utilities 5\QuickSearch.exe 2014-12-22 06:55:10 F860C176A904B837512F6C595A46E340 326944 ----a-w- C:\Program Files (x86)\Glary Utilities 5\procmgr.exe 2014-12-22 06:55:08 95C1AE2FC48D7823E27335E1F3E62909 135968 ----a-w- C:\Program Files (x86)\Glary Utilities 5\PortableMaker.exe 2014-12-22 06:55:04 6F0615F2E6627D898ED9C7EBBD60F33E 227616 ----a-w- C:\Program Files (x86)\Glary Utilities 5\OneClickMaintenance.exe 2014-12-22 06:54:58 0D465B214FCE91D277E57CB148AFF202 402720 ----a-w- C:\Program Files (x86)\Glary Utilities 5\MemfilesService.exe 2014-12-22 06:54:52 7E4233181572EC0847214265FF192D1E 122656 ----a-w- C:\Program Files (x86)\Glary Utilities 5\memdefrag.exe 2014-12-22 06:54:32 E13438A1ECA97ACF1B1F4ED655686FE8 64288 ----a-w- C:\Program Files (x86)\Glary Utilities 5\joinExe.exe 2014-12-22 06:54:12 0FC54078FBE8CEC2C89D46CB6C3F1C60 377120 ----a-w- C:\Program Files (x86)\Glary Utilities 5\Integrator_Portable.exe 2014-12-22 06:54:10 38D0D9F298F8B2F5F327A1AA229AE87D 846624 ----a-w- C:\Program Files (x86)\Glary Utilities 5\Integrator.exe 2014-12-22 06:54:06 E6FD9663B8E57C1A90E5DF743E39EA1D 101664 ----a-w- C:\Program Files (x86)\Glary Utilities 5\Initialize.exe 2014-12-22 06:54:02 1B2D2119DA013E335EB89671BC645C7F 777504 ----a-w- C:\Program Files (x86)\Glary Utilities 5\iehelper.exe 2014-12-22 06:53:58 692CE8793AD9187B4C10FD86D6648F50 63776 ----a-w- C:\Program Files (x86)\Glary Utilities 5\gsd.exe 2014-12-22 06:53:48 6A43FDFE94F0781EAD6AAD9A1A4F555F 1469216 ----a-w- C:\Program Files (x86)\Glary Utilities 5\FileUndelete.exe 2014-12-22 06:53:44 93F64D3A4D71D1EB2DD48BFBAECC28CE 103200 ----a-w- C:\Program Files (x86)\Glary Utilities 5\filesplitter.exe 2014-12-22 06:53:34 1DBC08A233BB5AEE92BFF37751292A43 386848 ----a-w- C:\Program Files (x86)\Glary Utilities 5\EncryptExe.exe 2014-12-22 06:53:30 DD1C96210E1C72133EBACA1A1425F4C6 218912 ----a-w- C:\Program Files (x86)\Glary Utilities 5\EmptyFolderFinder.exe 2014-12-22 06:53:24 BB6B8BCCC8025221987DD57F70204CC0 381216 ----a-w- C:\Program Files (x86)\Glary Utilities 5\dupefinder.exe 2014-12-22 06:53:22 44D1962C40AB7A8F605F697A15EBA652 558368 ----a-w- C:\Program Files (x86)\Glary Utilities 5\DriverBackup.exe 2014-12-22 06:53:20 BBE94AE90A9E5A88DD734434F962CF93 400672 ----a-w- C:\Program Files (x86)\Glary Utilities 5\DiskDefrag.exe 2014-12-22 06:53:18 69463BF72544B94C1110FF749B74375F 36640 ----a-w- C:\Program Files (x86)\Glary Utilities 5\DiskCleaner.exe 2014-12-22 06:53:14 E3501FE11DF6D382C193A21B43263C7A 385824 ----a-w- C:\Program Files (x86)\Glary Utilities 5\DiskAnalysis.exe 2014-12-22 06:53:00 09E817BF04E1382C80ADCDCB78CE1B75 958752 ----a-w- C:\Program Files (x86)\Glary Utilities 5\CrashReport.exe 2014-12-22 06:52:38 10F3EA607510BD4EC8B2578D63CFCA5C 137504 ----a-w- C:\Program Files (x86)\Glary Utilities 5\cmm.exe 2014-12-22 06:52:36 A07F980C439BF70DB6DEFC8056DFE58F 36640 ----a-w- C:\Program Files (x86)\Glary Utilities 5\CheckUpdate.exe 2014-12-22 06:52:32 E9205865BBC2A563249662B5C0CB51CA 68384 ----a-w- C:\Program Files (x86)\Glary Utilities 5\CheckDiskProgress.exe 2014-12-22 06:52:30 74677A7C3829006CA4644FB3789A2D2D 36640 ----a-w- C:\Program Files (x86)\Glary Utilities 5\CheckDisk.exe 2014-12-22 06:52:14 F179CB560B6BF22E7ABC5680555EADB2 498464 ----a-w- C:\Program Files (x86)\Glary Utilities 5\AutoUpdate.exe 2014-12-20 20:23:22 205E775B4B2C165922203A390B115523 40747600 ----a-w- C:\Program Files (x86)\Google\Update\Download\{4DC8B4CA-1BDA-483E-B5FA-D3C12E15B62D}\39.0.2171.95\39.0.2171.95_chrome_installer.exe 2014-12-20 20:11:36 3C892D030282EBC93539E8945275EBFD 143617 ----a-w- C:\Program Files\SilverFast Application\SilverFast 8\uninst.exe 2014-12-20 19:17:10 5B4ED5734945619EE3BCDB9825D2F526 51080 ----atw- C:\Program Files (x86)\Google\Update\1.3.25.11\GoogleUpdateOnDemand.exe 2014-12-20 19:17:10 06036279056145E0F08FC095CB789E6A 51080 ----atw- C:\Program Files (x86)\Google\Update\1.3.25.11\GoogleUpdateBroker.exe 2014-12-20 19:17:07 87EB5AFD21E52CB08883E04605B55829 880784 ----a-w- C:\Program Files (x86)\Google\Update\1.3.25.11\GoogleUpdateSetup.exe 2014-12-20 19:16:43 EDD3E562684CB4C50704B471BEAB1F86 114568 ----atw- C:\Program Files (x86)\Google\Update\1.3.25.11\GoogleUpdateComRegisterShell64.exe 2014-12-20 19:16:40 7161E8E31B7FD3B1CE083C2CA5FD5F44 285064 ----atw- C:\Program Files (x86)\Google\Update\1.3.25.11\GoogleCrashHandler64.exe 2014-12-20 19:16:37 CB8C1CC4F46FBAC78150754D77460C73 230792 ----atw- C:\Program Files (x86)\Google\Update\1.3.25.11\GoogleCrashHandler.exe 2014-12-20 19:16:25 F172AD4E906D97ED8F071896FC6789DC 107912 ----atw- C:\Program Files (x86)\Google\Update\1.3.25.11\GoogleUpdate.exe 2014-12-20 19:16:13 87EB5AFD21E52CB08883E04605B55829 880784 ----a-w- C:\Program Files (x86)\Google\Update\Download\{430FD4D0-B729-4F61-AA34-91526481799D}\1.3.25.11\GoogleUpdateSetup.exe 2014-12-20 14:51:46 64E5D045C95892F46542FDD0A2685AC1 407632 ----a-w- C:\Program Files (x86)\NewSoft\Presto! ImageFolio 4\Pexplore.exe 2014-12-20 14:51:32 C804DF0E0E65F27B49160331892CCCA4 1427608 ----a-w- C:\Program Files (x86)\NewSoft\Presto! ImageFolio 4\if42le.exe 2014-12-20 14:51:31 E2D4BA3248CB1DCB51383267868715E5 69632 ----a-w- C:\Program Files (x86)\NewSoft\Presto! ImageFolio 4\TWUNK_32.EXE 2014-12-20 14:51:31 74B8802CE5CD6F4E7AC83152E0E17D25 48560 ----a-w- C:\Program Files (x86)\NewSoft\Presto! ImageFolio 4\TWUNK_16.EXE 2014-12-20 14:51:28 BEF1E6A9B97045EC3F2B9CF34ACB6810 121064 ----a-w- C:\Program Files (x86)\InstallShield Installation Information\{783033B0-D8E6-11D5-9293-0050BA073EEC}\setup.exe 2014-12-20 14:51:28 065E87E0023961EA86798629B613D505 30800 ----a-w- C:\Program Files (x86)\NewSoft\Presto! ImageFolio 4\Eraser.exe 2014-12-20 14:49:43 BB0F3EB5117F6DE265E6AFF38C2AFA9E 63488 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\ISBEW64.exe 2014-12-20 14:49:42 D186D961E211E4FD7F7C3A02A864CBE5 5632 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\DotNetInstaller.exe === C: other files == ==== Startup Registry Enabled ====================== [HKEY_USERS\S-1-5-21-3130560279-3158009234-3752583673-1001\Software\Microsoft\Windows\CurrentVersion\Run] "Blue Jet Button"="C:\Program Files (x86)\Blue Jet Button\bjb.exe" "GUDelayStartup"="C:\Program Files (x86)\Glary Utilities 5\StartupManager.exe -delayrun" "CCleaner Monitoring"="C:\Program Files\CCleaner\CCleaner64.exe /MONITOR" "Spotify Web Helper"="C:\Users\Patrick\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" [HKEY_USERS\S-1-5-21-3130560279-3158009234-3752583673-1001\Software\Microsoft\Windows\CurrentVersion\runonce] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "AVG_UI"="C:\Program Files (x86)\AVG\AVG2014\avgui.exe /TRAYONLY" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "Blue Jet Button"="C:\Program Files (x86)\Blue Jet Button\bjb.exe" "GUDelayStartup"="C:\Program Files (x86)\Glary Utilities 5\StartupManager.exe -delayrun" "CCleaner Monitoring"="C:\Program Files\CCleaner\CCleaner64.exe /MONITOR" "Spotify Web Helper"="C:\Users\Patrick\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"="c:\\Windows\\SysWOW64\\nvinit.dll C:\\Windows\\SysWOW64\\nvinit.dll C:\\Windows\\SysWOW64\\nvinit.dll C:\\Windows\\SysWOW64\\nvinit.dll C:\\Windows\\SysWOW64\\nvinit.dll,C:\\windows\\SysWOW64\\nvinit.dll" ==== Startup Registry Enabled x64 ====================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NvBackend"="C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"="C:\\Windows\\System32\\nvinitx.dll C:\\Windows\\System32\\nvinitx.dll,C:\\windows\\system32\\nvinitx.dll" ==== Startup Registry Disabled ====================== [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run-] "BitTorrent"="\"C:\\Users\\Patrick\\AppData\\Roaming\\BitTorrent\\BitTorrent.exe\" /MINIMIZED" "Spotify Web Helper"="\"C:\\Users\\Patrick\\AppData\\Roaming\\Spotify\\Data\\SpotifyWebHelper.exe\"" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run-] "SunJavaUpdateSched"="\"C:\\Program Files (x86)\\Common Files\\Java\\Java Update\\jusched.exe\"" "Adobe ARM"="\"C:\\Program Files (x86)\\Common Files\\Adobe\\ARM\\1.0\\AdobeARM.exe\"" ==== Startup Registry Disabled x64 ====================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\BTMTrayAgent] "command"="rundll32.exe \"C:\\Program Files (x86)\\Intel\\Bluetooth\\btmshell.dll\",TrayApp" "hkey"="HKLM" "item"="BTMTrayAgent" "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\OpwareSE4] "command"="\"C:\\Program Files (x86)\\ScanSoft\\OmniPageSE4\\OpwareSE4.exe\"" "hkey"="HKLM" "item"="OpwareSE4" "key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\RtHDVCpl] "command"="C:\\Program Files\\Realtek\\Audio\\HDA\\RAVCpl64.exe -s" "hkey"="HKLM" "item"="RtHDVCpl" "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\SSBkgdUpdate] "command"="\"C:\\Program Files (x86)\\Common Files\\Scansoft Shared\\SSBkgdUpdate\\SSBkgdupdate.exe\" -Embedding -boot" "hkey"="HKLM" "item"="SSBkgdUpdate" "key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\SynTPEnh] "command"="C:\\Program Files\\Synaptics\\SynTP\\SynTPEnh.exe" "hkey"="HKLM" "item"="SynTPEnh" "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" ==== Task Scheduler Jobs ====================== C:\windows\tasks\Adobe Flash Player Updater.job --a------ C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [13/12/2014 14:50] C:\windows\tasks\CCleanerClean.job --a------ C:\Program Files\CCleaner\CCleaner.exe [30/10/2014 15:45] C:\windows\tasks\FacebookUpdateTaskUserS-1-5-21-3130560279-3158009234-3752583673-1001Core.job --a------ C:\Users\Patrick\AppData\Local\Facebook\Update\FacebookUpdate.exe [07/03/2014 17:56] C:\windows\tasks\FacebookUpdateTaskUserS-1-5-21-3130560279-3158009234-3752583673-1001UA.job --a------ C:\Users\Patrick\AppData\Local\Facebook\Update\FacebookUpdate.exe [07/03/2014 17:56] C:\windows\tasks\GlaryInitialize 5.job --a------ [Undetermined Task] C:\windows\tasks\GoogleUpdateTaskMachineCore.job --a------ [Undetermined Task] C:\windows\tasks\GoogleUpdateTaskMachineUA.job --a------ [Undetermined Task] C:\windows\tasks\Wise Memory Optimizer Task.job --a------ C:\Program Files (x86)\Wise\Wise Memory Optimizer\WiseMemoryOptimzer.exe [02/09/2014 09:54] ==== Other Scheduled Tasks ====================== "C:\windows\SysNative\tasks\Adobe Flash Player Updater" [C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe] "C:\windows\SysNative\tasks\Adobe online update program" [C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe] "C:\windows\SysNative\tasks\advSRS5" ["C:\Program Files (x86)\Samsung\Samsung Recovery Solution 5\WCScheduler.exe"] "C:\windows\SysNative\tasks\AnVir Task Manager" [C:\Program Files (x86)\AnVir Task Manager Pro\anvir.exe] "C:\windows\SysNative\tasks\CCleanerClean" [C:\Program Files\CCleaner\CCleaner.exe] "C:\windows\SysNative\tasks\CCleanerSkipUAC" ["C:\Program Files\CCleaner\CCleaner.exe"] "C:\windows\SysNative\tasks\EasyBatteryManager" ["%ProgramFiles(x86)%\Samsung\Easy Settings\EBM\EasyBatteryMgr4.exe"] "C:\windows\SysNative\tasks\EasyDisplayMgr" ["C:\Program Files (x86)\Samsung\Easy Settings\dmhkcore.exe"] "C:\windows\SysNative\tasks\EasySettings" ["C:\Program Files (x86)\Samsung\Easy Settings\sSettings.exe"] "C:\windows\SysNative\tasks\EasySettings_config" ["C:\Program Files (x86)\Samsung\Easy Settings\sSettings.exe"] "C:\windows\SysNative\tasks\EasySpeedUpManager" ["%programfiles(x86)%\Samsung\Easy Settings\EasySpeedUpManager.exe"] "C:\windows\SysNative\tasks\EasySupportCenter" ["%ProgramFiles%\Samsung\Easy Support Center\SamoyedAgent.exe"] "C:\windows\SysNative\tasks\FacebookUpdateTaskUserS-1-5-21-3130560279-3158009234-3752583673-1001Core" [C:\Users\Patrick\AppData\Local\Facebook\Update\FacebookUpdate.exe] "C:\windows\SysNative\tasks\FacebookUpdateTaskUserS-1-5-21-3130560279-3158009234-3752583673-1001UA" [C:\Users\Patrick\AppData\Local\Facebook\Update\FacebookUpdate.exe] "C:\windows\SysNative\tasks\GlaryInitialize 5" [C:\Program Files (x86)\Glary Utilities 5\Initialize.exe] "C:\windows\SysNative\tasks\GoogleUpdateTaskMachineCore" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe] "C:\windows\SysNative\tasks\GoogleUpdateTaskMachineUA" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe] "C:\windows\SysNative\tasks\GU5SkipUAC" [C:\Program Files (x86)\Glary Utilities 5\Integrator.exe] "C:\windows\SysNative\tasks\Java Update Scheduler" [C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe] "C:\windows\SysNative\tasks\MirageAgent" [C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe] "C:\windows\SysNative\tasks\MovieColorEnhancer" ["%programfiles(x86)%\Samsung\Easy Settings\MovieColorEnhancer.exe"] "C:\windows\SysNative\tasks\SAgent" ["%ProgramFiles%\Samsung\S Agent\CommonAgent.exe"] "C:\windows\SysNative\tasks\SCCSpeedBoot" ["%programfiles(x86)%\Samsung\Easy Settings\SCCSpeedBoot.exe"] "C:\windows\SysNative\tasks\SmartDefrag3_Update" [C:\Program Files (x86)\IObit\Smart Defrag 3\AutoUpdate.exe] "C:\windows\SysNative\tasks\SmartSetting" ["%programfiles(x86)%\Samsung\Easy Settings\SmartSetting.exe"] "C:\windows\SysNative\tasks\SpyHunter4Startup" ["C:\Program Files\Enigma Software Group\SpyHunter\Spyhunter4.exe"] "C:\windows\SysNative\tasks\Wise Memory Optimizer Task" [C:\Program Files (x86)\Wise\Wise Memory Optimizer\WiseMemoryOptimzer.exe] "C:\windows\SysNative\tasks\WLANStartup" ["%programfiles(x86)%\Samsung\Easy Settings\WLANStartup.exe"] ==== Firefox Start and Search pages ====================== ProfilePath: C:\Users\Patrick\AppData\Roaming\Mozilla\Firefox\Profiles\yl7oer8n.default user_pref("browser.startup.homepage", "about:superstart"); ==== Firefox Extensions ====================== ProfilePath: C:\Users\Patrick\AppData\Roaming\Mozilla\Firefox\Profiles\yl7oer8n.default - Undetermined - {DAD0F81A-CF67-4eed-98D6-26F6E47274CA} - Undetermined - {1A2D0EC4-75F5-4c91-89C4-3656F6E44B68} - Undetermined - superstart@enjoyfreeware.org - Undetermined - thumbnailZoom@dadler.github.com - Undetermined - {4BBDD651-70CF-4821-84F8-2B918CF89CA3} - Thumbnail Zoom Plus - %ProfilePath%\extensions\thumbnailZoom@dadler.github.com.xpi - Flagfox - %ProfilePath%\extensions\{1018e4d6-728f-4b20-ad56-37578a4de76b}.xpi - Image Zoom - %ProfilePath%\extensions\{1A2D0EC4-75F5-4c91-89C4-3656F6E44B68}.xpi - Adblock Plus - %ProfilePath%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi ProfilePath: C:\Users\Patrick\AppData\Roaming\TomTom\HOME\Profiles\a0rb66g0.default - Undetermined - C:\Program Files (x86)\TomTom HOME 2\xul\extensions\MapShare-status@tomtom.com - Undetermined - C:\Program Files (x86)\TomTom HOME 2\xul\extensions\baseTheme@tomtom.com AppDir: C:\Program Files (x86)\Mozilla Firefox - Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} ==== Firefox Plugins ====================== Profilepath: C:\Users\Patrick\AppData\Roaming\Mozilla\Firefox\Profiles\yl7oer8n.default 424899266BA430CCE5DDB6C1B4BE1B99 - C:\windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_235.dll - Shockwave Flash 77B8694352764F6079A2332FAD7FD426 - C:\Users\Patrick\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll - Unity Player FF0D6F82A0EC13952E83B9439100E45D - C:\Users\Patrick\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll - Facebook Video Calling Plugin AE7B288233C212C62CD544BF768C45E6 - C:\windows\SysWOW64\Adobe\Director\np32dsw_1203133.dll - Shockwave for Director / Shockwave for Director ==== Fake Chromium Profiles Check ====================== Fake profile C:\windows\sysWoW64\config\systemprofile\AppData\Local\Google\Chrome deleted ==== Chromium Look ====================== Google Chrome Version: 39.0.2171.95 (Up to date, latest Stable version: 39.0.2171.95) Last updated at time on date - Patrick\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb Google Wallet - Patrick\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda ==== Chromium Startpages ====================== C:\Users\Patrick\AppData\Local\Google\Chrome\User Data\Default\Preferences "homepage": "https://www.google.be/", "startup_urls": [ "https://www.google.be/" ], ==== Set IE to Default ====================== Old Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main] "Default_Search_URL"="http://www.google.com" "Default_Page_URL"="http://www.google.com" "Start Page"="http://www.google.com" "Search Page"="http://www.google.com" [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main] "Default_Search_URL"="http://www.google.com" "Default_Page_URL"="http://www.google.com" "Start Page"="http://www.google.com" "Search Page"="http://www.google.com" New Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://www.google.com" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main] "Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896" "Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896" "Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157" "Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157" [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main] "Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896" "Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896" "Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157" "Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157" ==== All HKCU SearchScopes ====================== HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" {012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}" {0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC" {C5F32B02-E182-4D1D-BD16-A11FEE4B1CD5} Google Url="https://www.google.com/search?q={searchTerms}" ==== HijackThis Entries ====================== O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_25\bin\ssv.dll O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_25\bin\jp2ssv.dll O4 - HKLM\..\Run: [AVG_UI] "C:\Program Files (x86)\AVG\AVG2014\avgui.exe" /TRAYONLY O4 - HKCU\..\Run: [Blue Jet Button] C:\Program Files (x86)\Blue Jet Button\bjb.exe O4 - HKCU\..\Run: [GUDelayStartup] "C:\Program Files (x86)\Glary Utilities 5\StartupManager.exe" -delayrun O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR O4 - HKCU\..\Run: [Spotify Web Helper] "C:\Users\Patrick\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" O9 - Extra button: @C:\windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\windows\WindowsMobile\INetRepl.dll O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\windows\WindowsMobile\INetRepl.dll O9 - Extra 'Tools' menuitem: @C:\windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\windows\WindowsMobile\INetRepl.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics O18 - Protocol: linkscanner - (no CLSID) - (no file) O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL O20 - AppInit_DLLs: c:\Windows\SysWOW64\nvinit.dll C:\Windows\SysWOW64\nvinit.dll C:\Windows\SysWOW64\nvinit.dll C:\Windows\SysWOW64\nvinit.dll C:\Windows\SysWOW64\nvinit.dll,C:\windows\SysWOW64\nvinit.dll O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\windows\System32\alg.exe (file missing) O23 - Service: Intel® Centrino® Wireless Bluetooth® + High Speed Service (AMPPALR3) - Intel Corporation - C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe O23 - Service: AVG Firewall (avgfws) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2014\avgfws.exe O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe O23 - Service: Bluetooth Device Monitor - Intel Corporation - C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe O23 - Service: Bluetooth Media Service - Intel Corporation - C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe O23 - Service: Bluetooth OBEX Service - Intel Corporation - C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe O23 - Service: Bonjour-service (Bonjour Service) - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe O23 - Service: Intel(R) Centrino(R) Wireless Bluetooth(R) + High Speed Security Service (BTHSSecurityMgr) - Intel(R) Corporation - C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\windows\SysWow64\IntelCpHeciSvc.exe O23 - Service: EaseUS Agent Service (EaseUS Agent) - CHENGDU YIWO Tech Development Co., Ltd - C:\Program Files (x86)\EaseUS\Todo Backup\bin\Agent.exe O23 - Service: Easy Launcher - Samsung Electronics CO., LTD. - C:\Program Files (x86)\Samsung\Easy Settings\CmdServer\EasyLauncher.exe O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\windows\System32\lsass.exe (file missing) O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\windows\system32\fxssvc.exe (file missing) O23 - Service: FBackup 5 Service (FBackup5Srv) - Softland - C:\Program Files (x86)\Softland\FBackup 5\bService.exe O23 - Service: Remote Connections Service (FlexService) - BitMicro Software Corporation - C:\Program Files (x86)\RapidBIT\cisvc.exe O23 - Service: Genie Timeline Service (GenieTimelineService) - Genie9 - C:\Program Files\Genie9\Genie Timeline\GenieTimelineService.exe O23 - Service: NVIDIA GeForce Experience Service (GfExperienceService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe O23 - Service: Google Update-service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe O23 - Service: Google Update-service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\windows\system32\IEEtwCollector.exe (file missing) O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService1.0.0.0) - Unknown owner - C:\windows\system32\igfxCUIService.exe (file missing) O23 - Service: PIXMA Extended Survey Program (IJPLMSVC) - Unknown owner - C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE O23 - Service: Intel(R) ME Service - Unknown owner - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\windows\system32\lsass.exe (file missing) O23 - Service: Kaspersky Security Scan Service (KSS) - Kaspersky Lab ZAO - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Scan 2.0\kss.exe O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\windows\System32\msdtc.exe (file missing) O23 - Service: Wireless PAN DHCP Server (MyWiFiDHCPDNS) - Unknown owner - C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe O23 - Service: NVIDIA Network Service (NvNetworkService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe O23 - Service: NVIDIA Streamer Service (NvStreamSvc) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\windows\system32\nvvsvc.exe (file missing) O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\windows\system32\lsass.exe (file missing) O23 - Service: Macrium Reflect Image Mounting Service (ReflectService.exe) - Paramount Software UK Ltd - C:\Program Files\Macrium\Reflect\ReflectService.exe O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\windows\system32\locator.exe (file missing) O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\windows\system32\lsass.exe (file missing) O23 - Service: SamsungDeviceConfiguration (SamsungDeviceConfigurationWinService) - Unknown owner - C:\Program Files (x86)\Samsung\Easy Settings\SamsungDeviceConfiguration.exe O23 - Service: Sandboxie Service (SbieSvc) - Sandboxie Holdings, LLC - C:\Program Files\Sandboxie\SbieSvc.exe O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\windows\System32\spoolsv.exe (file missing) O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\windows\system32\sppsvc.exe (file missing) O23 - Service: SW Update Service (SWUpdateService) - Samsung Electronics CO., LTD. - C:\ProgramData\Samsung\SW Update Service\SWMAgent.exe O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\windows\system32\UI0Detect.exe (file missing) O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\windows\system32\lsass.exe (file missing) O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\windows\System32\vds.exe (file missing) O23 - Service: Volume Shadow Copy (VSS) - Unknown owner - C:\windows\system32\vssvc.exe (file missing) O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\windows\system32\Wat\WatAdminSvc.exe (file missing) O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\windows\system32\wbengine.exe (file missing) O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\windows\system32\wbem\WmiApSrv.exe (file missing) O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing) O23 - Service: Intel(R) PROSet/Wireless Zero Configuration Service (ZeroConfigService) - Intel® Corporation - C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe ==== Empty IE Cache ====================== C:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Patrick\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully C:\windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully ==== Empty FireFox Cache ====================== No FireFox Cache found ==== Empty Chrome Cache ====================== C:\Users\Patrick\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully ==== Empty All Flash Cache ====================== Flash Cache Emptied Successfully ==== Empty All Java Cache ====================== Java Cache cleared successfully ==== C:\zoek_backup content ====================== C:\zoek_backup (files=2340 folders=258 377732397 bytes) ==== Empty Temp Folders ====================== C:\Users\Default\AppData\Local\temp emptied successfully C:\Users\Patrick\AppData\Local\Temp will be emptied at reboot C:\Users\Public\AppData\Local\temp emptied successfully C:\Users\TEMP\AppData\Local\temp emptied successfully C:\Users\TEMP.Patrick-PC\AppData\Local\temp emptied successfully C:\Users\TEMP.Patrick-PC.000\AppData\Local\temp emptied successfully C:\Users\TEMP.Patrick-PC.001\AppData\Local\temp emptied successfully C:\Users\TEMP.Patrick-PC.002\AppData\Local\temp emptied successfully C:\Users\TEMP.Patrick-PC.003\AppData\Local\temp emptied successfully C:\Users\UpdatusUser\AppData\Local\temp emptied successfully C:\windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully C:\windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully C:\windows\Temp will be emptied at reboot ==== After Reboot ====================== ==== Empty Temp Folders ====================== C:\windows\Temp successfully emptied C:\Users\Patrick\AppData\Local\Temp successfully emptied ==== Empty Recycle Bin ====================== C:\$RECYCLE.BIN successfully emptied ==== Deleting Files / Folders ====================== "C:\Users\Patrick\AppData\Roaming\Malwarebytes" not deleted ==== EOF on vr 26/12/2014 at 18:27:46,88 ======================