Zoek.exe v5.0.0.0 Updated 28-12-2014 Tool run by Jonas on ma 29/12/2014 at 16:24:32,62. Microsoft Windows 8.1 6.3.9600 x64 Running in: Normal Mode Internet Access Detected Launched: C:\Users\Jonas\Desktop\zoek.exe [Scan all users] [Script inserted] [Checkboxes used] ==== System Restore Info ====================== 29/12/2014 16:26:48 Zoek.exe System Restore Point Created Succesfully. ==== Empty Folders Check ====================== C:\PROGRA~2\AGEIA Technologies deleted successfully C:\Users\Jonas\AppData\Local\VirtualStore deleted successfully ==== Deleting CLSID Registry Keys ====================== ==== Deleting CLSID Registry Values ====================== ==== Running Processes ====================== C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files\Lenovo\Communications Utility\AVControlCenter32.exe C:\Program Files\Lenovo\Communications Utility\avfaudiosw.exe C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBService.exe C:\Program Files\Lenovo\SettingsDependency\SettingsService.exe C:\windows\SysWOW64\NLSSRV32.EXE C:\Program Files (x86)\Lenovo\QuickControl\QuickControlMasterSvc.exe C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe C:\Program Files (x86)\Lenovo\QuickControl\QuickControlService.exe C:\Program Files (x86)\Lenovo\QuickControl\QuickControlInput.exe C:\Program Files (x86)\Lenovo\QuickControl\QuickControlInput.exe C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe C:\Program Files (x86)\Lenovo\LocationAware\loctaskmgr.exe C:\Program Files (x86)\Norton Internet Security\Engine\21.6.0.32\NIS.exe C:\Program Files (x86)\Norton Internet Security\Engine\21.6.0.32\NIS.exe C:\Program Files (x86)\Lenovo\QuickControl\QuickControl.exe C:\Program Files (x86)\Lenovo\LocationAware\lpdagent.exe C:\Program Files\Lenovo\Lenovo Mobile Hotspot\MobileHotspotclient.exe C:\Program Files (x86)\Skype\Phone\Skype.exe C:\Users\Jonas\AppData\Local\Pokki\Engine\HostAppService.exe C:\Users\Jonas\AppData\Roaming\Dropbox\bin\Dropbox.exe C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBConsole.exe C:\Program Files (x86)\iTunes\iTunesHelper.exe C:\Program Files (x86)\Citrix\ICA Client\concentr.exe C:\Program Files (x86)\Citrix\Receiver\Receiver.exe C:\Program Files (x86)\Citrix\ICA Client\redirector.exe C:\Users\Jonas\AppData\Local\Pokki\Engine\HostAppService.exe C:\Program Files (x86)\Citrix\SelfServicePlugin\SelfServicePlugin.exe C:\Program Files (x86)\Citrix\ICA Client\wfcrun32.exe C:\PROGRAM FILES (x86)\Cyberlink\PowerDVD10\PDVD10Serv.exe C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe C:\Program Files\Lenovo\Lenovo Solution Center\LSCNotify.exe C:\Program Files\Lenovo\Communications Utility\tpknrres.exe C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AcroRd32.exe C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AcroRd32.exe C:\Program Files\Lenovo\Communications Utility\vcamsvc.exe C:\Program Files\Lenovo\Communications Utility\cammute.exe C:\Program Files\Lenovo\Communications Utility\vcamsvchlpr.exe C:\Program Files\Lenovo\Communications Utility\tpknrsvc.exe C:\Users\Jonas\Desktop\zoek.exe C:\WINDOWS\SysWOW64\cmd.exe C:\WINDOWS\SysWOW64\cmd.exe C:\WINDOWS\SysWOW64\cmd.exe C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AcroRd32.exe C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AcroRd32.exe C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AcroRd32.exe C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AcroRd32.exe C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AcroRd32.exe C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AcroRd32.exe C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AcroRd32.exe C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AcroRd32.exe C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AcroRd32.exe C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AcroRd32.exe ==== Deleting Services ====================== ==== Deleting Files \ Folders ====================== C:\Users\Public\Pokki deleted C:\Users\Jonas\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\PC App Store.lnk deleted C:\Users\Jonas\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Start Menu.lnk deleted C:\PROGRA~3\Package Cache deleted C:\Users\Default\AppData\Local\Pokki deleted C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Search.lnk deleted C:\Users\Jonas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PC App Store.lnk deleted C:\Users\Jonas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Start Menu.lnk deleted C:\WINDOWS\SysNative\config\systemprofile\Searches deleted "C:\WINDOWS\Installer\a1d606.msi" deleted "C:\Users\Jonas\AppData\Local\Pokki\analytics.db" not deleted "C:\Users\Jonas\AppData\Local\Pokki\engine_update.db" not deleted "C:\Users\Jonas\AppData\Local\Pokki\notifications.db" deleted "C:\Users\Jonas\AppData\Local\Pokki\Engine\avcodec-54.dll" deleted "C:\Users\Jonas\AppData\Local\Pokki\Engine\avformat-54.dll" deleted "C:\Users\Jonas\AppData\Local\Pokki\Engine\avutil-51.dll" deleted "C:\Users\Jonas\AppData\Local\Pokki\Engine\chrome_100_percent.pak" deleted "C:\Users\Jonas\AppData\Local\Pokki\Engine\en-US.pak" deleted "C:\Users\Jonas\AppData\Local\Pokki\Engine\HostAppService.exe" deleted "C:\Users\Jonas\AppData\Local\Pokki\Engine\HostAppServiceUpdater.exe" deleted "C:\Users\Jonas\AppData\Local\Pokki\Engine\icudt.dll" deleted "C:\Users\Jonas\AppData\Local\Pokki\Engine\libPokki.dll" deleted "C:\Users\Jonas\AppData\Local\Pokki\Engine\ppGoogleNaClPluginChrome.dll" deleted "C:\Users\Jonas\AppData\Local\Pokki\Engine\resources.pak" deleted "C:\Users\Jonas\AppData\Local\Pokki\Engine\StartMenuIndexer.exe" deleted "C:\Users\Jonas\AppData\Local\Pokki\Pokkies\installed_pokkies.db" deleted "C:\Users\Jonas\AppData\Local\Pokki\UserData\lockfile" deleted "C:\Users\Jonas\AppData\Local\Pokki\UserData\Default\Cookies" deleted "C:\Users\Jonas\AppData\Local\Pokki\UserData\Default\Network Action Predictor" deleted "C:\Users\Jonas\AppData\Local\Pokki\UserData\Default\Shortcuts" deleted "C:\Users\Jonas\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1\Cookies" deleted "C:\Users\Jonas\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1\Cookies-journal" deleted "C:\Users\Jonas\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1\Network Action Predictor" deleted "C:\Users\Jonas\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1\Visited Links" deleted "C:\Users\Jonas\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1-websheet\Cookies" deleted "C:\Users\Jonas\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1-websheet\Network Action Predictor" deleted "C:\Users\Jonas\AppData\Local\Pokki\UserData\notifications\Cookies" deleted "C:\Users\Jonas\AppData\Local\Pokki\UserData\notifications\Network Action Predictor" deleted "C:\Users\Jonas\AppData\Local\Pokki\UserData\notifications\QuotaManager" deleted "C:\Users\Jonas\AppData\Local\Pokki\UserData\notifications\QuotaManager-journal" deleted "C:\Users\Jonas\AppData\Local\Pokki\UserData\notifications\Visited Links" deleted "C:\Users\Jonas\AppData\Local\Pokki\UserData\notifications-websheet\Cookies" deleted "C:\Users\Jonas\AppData\Local\Pokki\UserData\notifications-websheet\Network Action Predictor" deleted "C:\Users\Jonas\AppData\Local\Pokki\UserData\Default\Cache\data_0" deleted "C:\Users\Jonas\AppData\Local\Pokki\UserData\Default\Cache\data_1" deleted "C:\Users\Jonas\AppData\Local\Pokki\UserData\Default\Cache\data_2" deleted "C:\Users\Jonas\AppData\Local\Pokki\UserData\Default\Cache\data_3" deleted "C:\Users\Jonas\AppData\Local\Pokki\UserData\Default\Cache\index" deleted "C:\Users\Jonas\AppData\Local\Pokki\UserData\Default\Extension State\000011.log" deleted "C:\Users\Jonas\AppData\Local\Pokki\UserData\Default\Extension State\LOCK" deleted "C:\Users\Jonas\AppData\Local\Pokki\UserData\Default\Extension State\MANIFEST-000010" deleted "C:\Users\Jonas\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1\Cache\data_0" deleted "C:\Users\Jonas\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1\Cache\data_1" deleted "C:\Users\Jonas\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1\Cache\data_2" deleted "C:\Users\Jonas\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1\Cache\data_3" deleted "C:\Users\Jonas\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1\Cache\index" deleted "C:\Users\Jonas\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1\Extension State\000011.log" deleted "C:\Users\Jonas\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1\Extension State\LOCK" deleted "C:\Users\Jonas\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1\Extension State\MANIFEST-000010" deleted "C:\Users\Jonas\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1\Session Storage\000055.sst" deleted "C:\Users\Jonas\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1\Session Storage\000057.sst" deleted "C:\Users\Jonas\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1\Session Storage\000060.sst" deleted "C:\Users\Jonas\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1\Session Storage\000061.log" deleted "C:\Users\Jonas\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1\Session Storage\LOCK" deleted "C:\Users\Jonas\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1\Session Storage\MANIFEST-000059" deleted "C:\Users\Jonas\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1\User StyleSheets\Custom.css" deleted "C:\Users\Jonas\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1-websheet\Cache\data_0" deleted "C:\Users\Jonas\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1-websheet\Cache\data_1" deleted "C:\Users\Jonas\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1-websheet\Cache\data_2" deleted "C:\Users\Jonas\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1-websheet\Cache\data_3" deleted "C:\Users\Jonas\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1-websheet\Cache\index" deleted "C:\Users\Jonas\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1-websheet\Extension State\000011.log" deleted "C:\Users\Jonas\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1-websheet\Extension State\LOCK" deleted "C:\Users\Jonas\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1-websheet\Extension State\MANIFEST-000010" deleted "C:\Users\Jonas\AppData\Local\Pokki\UserData\notifications\Cache\data_0" deleted "C:\Users\Jonas\AppData\Local\Pokki\UserData\notifications\Cache\data_1" deleted "C:\Users\Jonas\AppData\Local\Pokki\UserData\notifications\Cache\data_2" deleted "C:\Users\Jonas\AppData\Local\Pokki\UserData\notifications\Cache\data_3" deleted "C:\Users\Jonas\AppData\Local\Pokki\UserData\notifications\Cache\index" deleted "C:\Users\Jonas\AppData\Local\Pokki\UserData\notifications\databases\Databases.db" deleted "C:\Users\Jonas\AppData\Local\Pokki\UserData\notifications\Extension State\000011.log" deleted "C:\Users\Jonas\AppData\Local\Pokki\UserData\notifications\Extension State\LOCK" deleted "C:\Users\Jonas\AppData\Local\Pokki\UserData\notifications\Extension State\MANIFEST-000010" deleted "C:\Users\Jonas\AppData\Local\Pokki\UserData\notifications\User StyleSheets\Custom.css" deleted "C:\Users\Jonas\AppData\Local\Pokki\UserData\notifications\databases\file__0\1" deleted "C:\Users\Jonas\AppData\Local\Pokki\UserData\notifications-websheet\Cache\data_0" deleted "C:\Users\Jonas\AppData\Local\Pokki\UserData\notifications-websheet\Cache\data_1" deleted "C:\Users\Jonas\AppData\Local\Pokki\UserData\notifications-websheet\Cache\data_2" deleted "C:\Users\Jonas\AppData\Local\Pokki\UserData\notifications-websheet\Cache\data_3" deleted "C:\Users\Jonas\AppData\Local\Pokki\UserData\notifications-websheet\Cache\index" deleted "C:\Users\Jonas\AppData\Local\Pokki\UserData\notifications-websheet\Extension State\000011.log" deleted "C:\Users\Jonas\AppData\Local\Pokki\UserData\notifications-websheet\Extension State\LOCK" deleted "C:\Users\Jonas\AppData\Local\Pokki\UserData\notifications-websheet\Extension State\MANIFEST-000010" deleted "C:\Users\Jonas\AppData\Local\Pokki" not deleted "C:\Users\Jonas\AppData\Local\Pokki\Engine" not deleted "C:\Users\Jonas\AppData\Local\Pokki\Pokkies" deleted "C:\Users\Jonas\AppData\Local\Pokki\UserData" deleted "C:\Users\Jonas\AppData\Local\Pokki\UserData\Default" deleted "C:\Users\Jonas\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1" deleted "C:\Users\Jonas\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1-websheet" deleted "C:\Users\Jonas\AppData\Local\Pokki\UserData\notifications" deleted "C:\Users\Jonas\AppData\Local\Pokki\UserData\notifications-websheet" deleted "C:\Users\Jonas\AppData\Local\Pokki\UserData\Default\Cache" deleted "C:\Users\Jonas\AppData\Local\Pokki\UserData\Default\Extension State" deleted "C:\Users\Jonas\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1\Cache" deleted "C:\Users\Jonas\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1\Extension State" deleted "C:\Users\Jonas\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1\Session Storage" deleted "C:\Users\Jonas\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1\User StyleSheets" deleted "C:\Users\Jonas\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1-websheet\Cache" deleted "C:\Users\Jonas\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1-websheet\Extension State" deleted "C:\Users\Jonas\AppData\Local\Pokki\UserData\notifications\Cache" deleted "C:\Users\Jonas\AppData\Local\Pokki\UserData\notifications\databases" deleted "C:\Users\Jonas\AppData\Local\Pokki\UserData\notifications\Extension State" deleted "C:\Users\Jonas\AppData\Local\Pokki\UserData\notifications\User StyleSheets" deleted "C:\Users\Jonas\AppData\Local\Pokki\UserData\notifications\databases\file__0" deleted "C:\Users\Jonas\AppData\Local\Pokki\UserData\notifications-websheet\Cache" deleted "C:\Users\Jonas\AppData\Local\Pokki\UserData\notifications-websheet\Extension State" deleted ==== System Specs ====================== Windows: Windows Version 6.2 (Build 9200) Memory (RAM): 8088 MB CPU Info: Intel(R) Core(TM) i7-4702MQ CPU @ 2.20GHz CPU Speed: 2243,2 MHz Sound Card: Speakers (Conexant 20751 SmartA | Display Adapters: Intel(R) HD Graphics 4600 | Intel(R) HD Graphics 4600 | Intel(R) HD Graphics 4600 | NVIDIA GeForce GT 740M Monitors: 1x; ThinkPad Display 1920x1080 | Screen Resolution: 1536 X 864 - 32 bit Network: Network Present Network Adapters: Microsoft Hosted Network Virtual Adapter | Microsoft Wi-Fi Direct Virtual Adapter | Bluetooth-apparaat (Personal Area Network) | Realtek PCIe GBE Family Controller | Intel(R) Wireless-N 7260 CD / DVD Drives: 1x (D: | ) D: HL-DT-STDVDRAM GU90N Ports: COM Ports NOT Present. LPT Port NOT Present. Mouse: 5 Button Wheel Mouse Present Hard Disks: C: 912,2GB Hard Disks - Free: C: 857,8GB Manufacturer *: LENOVO BIOS Info: AT/AT COMPATIBLE | | LENOVO - 2120 Time Zone: GMT (standaardtijd) Motherboard *: LENOVO 20C60044MB Country: Belgi‰ Language: NLB ==== System Specs (Software) ====================== Anti-Virus: Windows Defender On-access scanning disabled (Outdated) Anti-Virus: Norton Internet Security On-access scanning disabled (Outdated) Anti-Spyware: Norton Internet Security disabled (Outdated) Anti-Spyware: Windows Defender disabled (Outdated) Firewall: Norton Internet Security disabled Internet Explorer Version: 11.0.9600.17498 Google Chrome version: 39.0.2171.95 Adobe Reader version: 11.0.10.32 ==== Files Recently Created / Modified ====================== ====== C:\WINDOWS ==== 2014-11-30 05:38:08 ACDBE1ED38167C8B01B8F63161BB2CEA 2374784 ----a-w- C:\WINDOWS\explorer.exe 2014-11-30 05:12:14 9B2C4A2B498F91D769AD53FAB4794D1A 28578 ----a-w- C:\WINDOWS\diagwrn.xml 2014-11-30 05:12:14 9B2C4A2B498F91D769AD53FAB4794D1A 28578 ----a-w- C:\WINDOWS\diagerr.xml ====== C:\Users\Jonas\AppData\Local\Temp ==== 2014-12-28 20:48:22 97511FE2CA09CC2E06C3CD6519C3494E 43008 ----a-w- C:\Users\Jonas\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpk8tvyc.dll 2014-12-26 19:57:01 EE37818F0A03217201E6BF432D60A268 95168336 ----a-w- C:\Users\Jonas\AppData\Local\Temp\oct267F.tmp.exe ====== Java Cache ===== ====== C:\WINDOWS\SysWOW64 ===== ====== C:\WINDOWS\SysWOW64\drivers ===== ====== C:\WINDOWS\Sysnative ===== ====== C:\WINDOWS\Sysnative\drivers ===== 2014-12-28 13:45:45 D41D8CD98F00B204E9800998ECF8427E 0 ---ha-w- C:\WINDOWS\Sysnative\drivers\Msft_User_WpdMtpDr_01_11_00.Wdf 2014-12-12 19:34:34 FCF77211FAE72F3CB020A2CF51047114 29496 ----a-w- C:\WINDOWS\Sysnative\drivers\LnvHIDHW.sys 2014-12-03 19:33:15 D41D8CD98F00B204E9800998ECF8427E 0 ---ha-w- C:\WINDOWS\Sysnative\drivers\Msft_Kernel_ldiagio_uefi_01009.Wdf 2014-11-30 23:27:21 D41D8CD98F00B204E9800998ECF8427E 0 ---ha-w- C:\WINDOWS\Sysnative\drivers\Msft_User_wbf_vfs_lvcmn_01_09_00.Wdf 2014-11-30 18:53:01 8E98D21EE06192492A5671A6144D092F 33240 ----a-w- C:\WINDOWS\Sysnative\drivers\GEARAspiWDM.sys 2014-11-30 05:38:46 8DF1254093B5C354CE725EB6B9B0DE19 146752 ----a-w- C:\WINDOWS\Sysnative\drivers\msgpioclx.sys 2014-11-30 05:37:33 7A1A3F213CDB3363D179D5014272025D 402432 ----a-w- C:\WINDOWS\Sysnative\drivers\mrxsmb.sys 2014-11-30 05:37:32 674A4702E4E144E8710ED1A2EC6DD049 96768 ----a-w- C:\WINDOWS\Sysnative\drivers\agilevpn.sys 2014-11-30 05:37:32 65ED7B9CFEA893DF7748D5FF692690DE 38912 ----a-w- C:\WINDOWS\Sysnative\drivers\vwifimp.sys 2014-11-30 05:37:32 35BF5C5F5E3C9902C98978C7640574DA 71680 ----a-w- C:\WINDOWS\Sysnative\drivers\vwififlt.sys 2014-11-30 05:37:15 D537815E450A149752C15868392AD1F3 110592 ----a-w- C:\WINDOWS\Sysnative\drivers\WUDFPf.sys 2014-11-30 05:37:15 7CCBBCEE408A5DBE3FE47297DB5A6CFC 227840 ----a-w- C:\WINDOWS\Sysnative\drivers\WUDFRd.sys 2014-11-30 05:32:26 D41D8CD98F00B204E9800998ECF8427E 0 ---ha-w- C:\WINDOWS\Sysnative\drivers\Msft_User_LocationProvider_01_11_00.Wdf 2014-11-30 05:07:35 D41D8CD98F00B204E9800998ECF8427E 0 ---ha-w- C:\WINDOWS\Sysnative\drivers\Msft_Kernel_SynTP_01009.Wdf 2014-11-30 05:06:25 D41D8CD98F00B204E9800998ECF8427E 0 ---ha-w- C:\WINDOWS\Sysnative\drivers\Msft_Kernel_Smb_driver_Intel_01009.Wdf 2014-11-30 05:06:21 D41D8CD98F00B204E9800998ECF8427E 0 ---ha-w- C:\WINDOWS\Sysnative\drivers\Msft_User_WpdFs_01_11_00.Wdf 2014-11-30 05:04:55 D41D8CD98F00B204E9800998ECF8427E 0 ---ha-w- C:\WINDOWS\Sysnative\drivers\Msft_Kernel_btmhsf_01011.Wdf 2014-11-29 20:00:51 B02118A776C368F7EE1A8CC81378D265 153920 -c--a-w- C:\WINDOWS\Sysnative\drivers\dumpsd.sys 2014-11-29 20:00:51 A770340FC02B999EF0DE6C2A6BC8437C 39744 -c--a-w- C:\WINDOWS\Sysnative\drivers\intelpep.sys 2014-11-29 20:00:51 7B7C482CF48E6EE33664340D1A78E6FE 238912 -c--a-w- C:\WINDOWS\Sysnative\drivers\sdbus.sys 2014-11-29 20:00:51 24A8DFC07E4BAF29AEA26E383D4CC886 86336 ----a-w- C:\WINDOWS\Sysnative\drivers\pdc.sys 2014-11-29 20:00:23 DE8D12B4C3F55FA2C5E9774314F6C58A 258368 ----a-w- C:\WINDOWS\Sysnative\drivers\WdFilter.sys 2014-11-29 20:00:23 4AD874CDC812EC156265E451B6B09DAB 114496 ----a-w- C:\WINDOWS\Sysnative\drivers\WdNisDrv.sys 2014-11-29 20:00:23 0359607177E5E9F6041136CC0A5CB0B6 35320 ----a-w- C:\WINDOWS\Sysnative\drivers\WdBoot.sys 2014-11-29 20:00:10 9F08A6608F98B5407E7DDBCF306573EF 27456 ----a-w- C:\WINDOWS\Sysnative\drivers\rdpvideominiport.sys 2014-11-29 20:00:10 6D2EE96150E35B9EA49F2B481DE0369A 177472 ----a-w- C:\WINDOWS\Sysnative\drivers\ksecpkg.sys 2014-11-29 20:00:10 4E1207CE16E615B0B7A70DC889F4500E 563976 ----a-w- C:\WINDOWS\Sysnative\drivers\cng.sys 2014-11-29 19:58:13 E3FCE2A6B3533D99A3B498504DF9CC47 474432 ----a-w- C:\WINDOWS\Sysnative\drivers\netio.sys 2014-11-29 19:58:13 CCB3A2BB60FE5073F2DEA63FE83CF8FE 2497344 ----a-w- C:\WINDOWS\Sysnative\drivers\tcpip.sys 2014-11-29 19:58:13 7F23E38C5B6448F91439E4066645191E 428864 ----a-w- C:\WINDOWS\Sysnative\drivers\FWPKCLNT.SYS 2014-11-29 19:58:13 66732C13628BDB1AB0D6FD46027327C2 148800 -c--a-w- C:\WINDOWS\Sysnative\drivers\USBSTOR.SYS ====== C:\WINDOWS\Tasks ====== 2014-12-24 11:28:56 B63AD96D5AB77552EFDB7D2277C3B0CB 3886 ----a-w- C:\WINDOWS\Sysnative\Tasks\Adobe Acrobat Update Task 2014-12-20 17:40:00 A938A448CD4495582E6434B26EB761D8 3718 ----a-w- C:\WINDOWS\Sysnative\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 2014-11-30 18:52:20 -------- d-----w- C:\WINDOWS\Sysnative\Tasks\Apple 2014-11-30 18:30:57 5BAEA1E6D5F55463CC63F2E8E12ABAF8 5034 ----a-w- C:\WINDOWS\Sysnative\Tasks\Microsoft Office 15 Sync Maintenance for Jonas-PC-Jonas Jonas-PC 2014-11-30 05:30:55 CB21EF6287890B5EECEFC984652EEADE 3958 ----a-w- C:\WINDOWS\Sysnative\Tasks\User_Feed_Synchronization-{E89FCE8C-2CA5-4090-9DB2-9B476FFC876D} 2014-11-30 05:07:35 6CD95EB30842454C2667BB48061004EC 264 ----a-w- C:\WINDOWS\Tasks\Synaptics TouchPad Enhancements.job 2014-11-30 02:20:34 FEC680B2D8001422633515E8DBE88AD9 3808 ----a-w- C:\WINDOWS\Sysnative\Tasks\GoogleUpdateTaskMachineCore 2014-11-30 02:20:34 F928423A2771743F9F69E473518E21C3 4044 ----a-w- C:\WINDOWS\Sysnative\Tasks\GoogleUpdateTaskMachineUA 2014-11-30 02:20:34 2367F7A7B74747D1A3FF82048ACA46F3 1068 ----a-w- C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job 2014-11-30 02:20:34 0FAC073C79C2892CF0750CC62A27708C 1072 ----a-w- C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job 2014-11-30 02:10:19 1B4CE629D7980B78377F72E7168FAF94 3550 ----a-w- C:\WINDOWS\Sysnative\Tasks\CreateChoiceProcessTask 2014-11-29 23:29:14 F8B8B14310D2288B1DDE4D6491F24EB1 3600 ----a-w- C:\WINDOWS\Sysnative\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2856834796-3624118678-1303184682-1002 2014-11-29 22:33:01 -------- d-----w- C:\WINDOWS\Sysnative\Tasks\WPD ====== C:\WINDOWS\Temp ====== ======= C:\Program Files ===== 2014-12-29 10:03:33 -------- d-----w- C:\Program Files\trend micro 2014-11-30 23:52:09 -------- d-----w- C:\Program Files\Google 2014-11-30 19:24:37 -------- d-----w- C:\Program Files\Microsoft.NET 2014-11-30 18:52:37 -------- d-----w- C:\Program Files\iTunes 2014-11-30 18:52:37 -------- d-----w- C:\Program Files\iPod 2014-11-30 18:52:11 -------- d-----w- C:\Program Files\Common Files\Apple 2014-11-30 18:52:03 -------- d-----w- C:\Program Files\Bonjour 2014-11-30 18:23:33 -------- d-----w- C:\Program Files\Common Files\DESIGNER 2014-11-30 18:22:33 -------- d-----w- C:\Program Files\Microsoft SQL Server 2014-11-30 18:20:28 -------- d-----w- C:\Program Files\Microsoft Analysis Services 2014-11-30 18:20:21 -------- d-----w- C:\Program Files\Microsoft Office 2014-11-30 05:06:31 -------- d-----w- C:\Program Files\NVIDIA Corporation 2014-11-30 05:06:26 -------- d-----w- C:\Program Files\CONEXANT 2014-11-30 05:06:25 -------- d-----w- C:\Program Files\Synaptics 2014-11-30 05:05:03 -------- d-----w- C:\Program Files\Intel 2014-11-29 22:43:01 -------- d-----w- C:\Program Files\Common Files\Intel 2014-11-29 19:54:32 -------- d-----w- C:\Program Files\Reference Assemblies 2014-11-29 19:54:32 -------- d-----w- C:\Program Files\MSBuild ======= C:\PROGRA~2 ===== 2014-11-30 23:51:42 -------- d-----w- C:\PROGRA~2\COMMON~1\Adobe 2014-11-30 22:26:50 -------- d-----w- C:\PROGRA~2\COMMON~1\Citrix 2014-11-30 22:26:50 -------- d-----w- C:\PROGRA~2\Citrix 2014-11-30 18:52:37 -------- d-----w- C:\PROGRA~2\iTunes 2014-11-30 18:52:18 -------- d-----w- C:\PROGRA~2\Apple Software Update 2014-11-30 18:52:03 -------- d-----w- C:\PROGRA~2\Bonjour 2014-11-30 18:51:51 -------- d-----w- C:\PROGRA~2\COMMON~1\Apple 2014-11-30 18:23:12 -------- d-----w- C:\PROGRA~2\Microsoft SQL Server 2014-11-30 18:20:28 -------- d-----w- C:\PROGRA~2\Microsoft Analysis Services 2014-11-30 05:06:31 -------- d-----w- C:\PROGRA~2\NVIDIA Corporation 2014-11-30 05:06:11 -------- d-----w- C:\PROGRA~2\Intel 2014-11-30 05:05:00 -------- d-----w- C:\PROGRA~2\COMMON~1\Intel 2014-11-30 02:20:33 -------- d-----w- C:\PROGRA~2\Google 2014-11-29 23:29:38 -------- d-----w- C:\PROGRA~2\COMMON~1\Skype 2014-11-29 23:29:38 -------- d-----r- C:\PROGRA~2\Skype 2014-11-29 23:19:33 -------- d-----w- C:\PROGRA~2\TeamViewer 2014-11-29 22:43:01 -------- d-----w- C:\PROGRA~2\Cisco 2014-11-29 19:54:34 -------- d-----w- C:\PROGRA~2\Reference Assemblies 2014-11-29 19:54:34 -------- d-----w- C:\PROGRA~2\MSBuild ======= C: ===== 2014-11-30 05:30:28 4289B519463666B7436841DB9CF78AD6 1744 ----a-w- C:\{3B570426-DC6E-4DA4-8223-4EC7C42DC7C3} 2014-11-29 22:44:57 D41D8CD98F00B204E9800998ECF8427E 0 ----a-w- C:\Recovery.txt ====== C:\Users\Jonas\AppData\Roaming ====== 2014-12-17 11:25:09 -------- d-----w- C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Roaming\Microsoft 2014-12-17 11:25:09 -------- d-----r- C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-12-17 11:25:09 -------- d-----r- C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2014-12-17 11:25:03 -------- d-----w- C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Programs 2014-12-12 19:33:42 -------- d-----w- C:\Users\Jonas\AppData\Local\CrashDumps 2014-12-12 19:30:40 -------- d-----w- C:\Users\Jonas\AppData\Local\Programs 2014-12-03 19:33:08 -------- d-----w- C:\Users\Jonas\AppData\Roaming\LSC 2014-11-30 23:52:38 -------- d-----w- C:\Users\Jonas\AppData\Locallow\Adobe 2014-11-30 23:50:57 -------- d-----w- C:\Users\Jonas\AppData\Local\Adobe 2014-11-30 22:27:15 -------- d-----w- C:\Users\Jonas\AppData\Roaming\ICAClient 2014-11-30 22:26:50 -------- d-----w- C:\Users\Jonas\AppData\Local\Citrix 2014-11-30 19:39:11 -------- d-----w- C:\Users\Jonas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2014-11-30 19:36:37 -------- d-----w- C:\Users\Jonas\AppData\Roaming\Dropbox 2014-11-30 19:15:59 -------- d-----w- C:\Users\Default\AppData\Local\Microsoft Help 2014-11-30 19:15:59 -------- d-----w- C:\Users\Default User\AppData\Local\Microsoft Help 2014-11-30 18:53:25 -------- d-----w- C:\Users\Jonas\AppData\Roaming\Apple Computer 2014-11-30 18:53:25 -------- d-----w- C:\Users\Jonas\AppData\Local\Apple Computer 2014-11-30 18:52:20 -------- d-----w- C:\Users\Jonas\AppData\Local\Apple 2014-11-30 18:52:15 -------- d-----w- C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Roaming\Apple Computer 2014-11-30 18:20:23 -------- d-----w- C:\Users\Jonas\AppData\Local\Microsoft Help 2014-11-30 05:33:17 -------- d-sh--w- C:\Users\Jonas\AppData\Locallow\EmieUserList 2014-11-30 05:33:17 -------- d-sh--w- C:\Users\Jonas\AppData\Locallow\EmieBrowserModeList 2014-11-30 05:32:27 -------- d-s---w- C:\WINDOWS\serviceprofiles\Localservice\AppData\Locallow\Microsoft 2014-11-30 05:30:55 -------- d-sh--w- C:\Users\Jonas\AppData\Local\EmieUserList 2014-11-30 05:30:55 -------- d-sh--w- C:\Users\Jonas\AppData\Local\EmieSiteList 2014-11-30 05:30:55 -------- d-sh--w- C:\Users\Jonas\AppData\Local\EmieBrowserModeList 2014-11-30 05:30:53 -------- d-sh--w- C:\Users\Jonas\AppData\Locallow\EmieSiteList 2014-11-30 05:27:15 -------- d-----w- C:\Users\Jonas\AppData\Roaming\Identities 2014-11-30 05:27:06 -------- d-s---w- C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Locallow\Microsoft 2014-11-30 05:25:28 -------- d-s---w- C:\WINDOWS\SysNative\config\systemprofile\AppData\Locallow\Microsoft 2014-11-30 05:24:58 -------- d-----w- C:\WINDOWS\SysNative\config\systemprofile\AppData\Roaming\Adobe 2014-11-30 05:20:58 -------- d-s---w- C:\WINDOWS\SysNative\config\systemprofile\AppData\Roaming\Microsoft 2014-11-30 05:20:52 -------- d-----w- C:\WINDOWS\SysNative\config\systemprofile\AppData\Roaming\Intel 2014-11-30 05:12:23 -------- d-s---w- C:\Users\UpdatusUser\AppData\Roaming\Microsoft 2014-11-30 05:12:23 -------- d-----w- C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance 2014-11-30 05:12:23 -------- d-----w- C:\Users\UpdatusUser\AppData\Local\Temp 2014-11-30 05:12:23 -------- d-----w- C:\Users\UpdatusUser\AppData\Local\Microsoft 2014-11-30 05:12:23 -------- d-----r- C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools 2014-11-30 05:12:23 -------- d-----r- C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories 2014-11-30 05:12:23 -------- d-----r- C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility 2014-11-30 05:12:22 -------- d-s---w- C:\Users\Jonas\AppData\Roaming\Microsoft 2014-11-30 05:12:22 -------- d-----w- C:\Users\Jonas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance 2014-11-30 05:12:22 -------- d-----w- C:\Users\Jonas\AppData\Local\Temp 2014-11-30 05:12:22 -------- d-----w- C:\Users\Jonas\AppData\Local\Microsoft 2014-11-30 05:12:22 -------- d-----r- C:\Users\Jonas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools 2014-11-30 05:12:22 -------- d-----r- C:\Users\Jonas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories 2014-11-30 05:12:22 -------- d-----r- C:\Users\Jonas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility 2014-11-30 05:07:08 -------- d-----w- C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Microsoft 2014-11-30 02:20:27 -------- d-----w- C:\Users\Jonas\AppData\Local\Google 2014-11-30 02:20:02 -------- d-----w- C:\Users\Jonas\AppData\Local\Apps 2014-11-29 23:29:50 -------- d-----w- C:\Users\Jonas\AppData\Local\Skype 2014-11-29 23:29:46 -------- d-----w- C:\Users\Jonas\AppData\Roaming\Skype 2014-11-29 22:39:31 -------- d-----w- C:\WINDOWS\serviceprofiles\Localservice\AppData\Local\PnrpSqm 2014-11-29 22:39:26 -------- d-----w- C:\WINDOWS\serviceprofiles\Localservice\AppData\Roaming\PeerNetworking 2014-11-29 22:35:20 -------- d-----w- C:\Users\Jonas\AppData\Locallow\Microsoft 2014-11-29 22:34:20 -------- d-----w- C:\Users\Jonas\AppData\Roaming\Nitro PDF 2014-11-29 22:33:22 -------- d-----w- C:\Users\Jonas\AppData\Local\Lenovo 2014-11-29 22:33:20 -------- d-----w- C:\Users\Jonas\AppData\Roaming\Lenovo 2014-11-29 22:33:13 -------- d-----w- C:\Users\Jonas\AppData\Local\Absolute_Software 2014-11-29 22:33:12 9E017D385FB15D1B6DF61CA8D44CD639 20704 ----a-w- C:\Users\Jonas\AppData\Roaming\AbsoluteReminder.xml 2014-11-29 22:32:51 -------- d-----r- C:\Users\Jonas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-11-29 22:32:51 -------- d-----r- C:\Users\Jonas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2014-11-29 22:32:49 -------- d-----w- C:\Users\Jonas\AppData\Roaming\Adobe 2014-11-29 22:32:45 -------- d-----w- C:\Users\Jonas\AppData\Local\Power2Go 2014-11-29 22:32:24 F147BD8482D99A765BAB0A1699ECF1E0 377 ----a-w- C:\Users\Jonas\AppData\Local\RegisteredPackageInformation.xml 2014-11-29 22:32:12 -------- d-----w- C:\Users\Jonas\AppData\Local\Packages 2014-11-29 22:32:08 -------- d-----w- C:\Users\Jonas\AppData\Roaming\Intel 2014-11-29 22:31:51 -------- d-----w- C:\Users\Jonas\AppData\Local\Pokki ====== C:\Users\Jonas ====== 2014-12-29 10:03:21 8045ABB21A3BDD66A48E1ED5C0F0EF6A 1222144 ----a-w- C:\Users\Jonas\Desktop\RSITx64.exe 2014-12-17 11:25:09 -------- d-----r- C:\WINDOWS\sysWoW64\config\systemprofile\Videos 2014-12-17 11:25:09 -------- d-----r- C:\WINDOWS\sysWoW64\config\systemprofile\Searches 2014-12-17 11:25:09 -------- d-----r- C:\WINDOWS\sysWoW64\config\systemprofile\Saved Games 2014-12-17 11:25:09 -------- d-----r- C:\WINDOWS\sysWoW64\config\systemprofile\Pictures 2014-12-17 11:25:09 -------- d-----r- C:\WINDOWS\sysWoW64\config\systemprofile\OneDrive 2014-12-17 11:25:09 -------- d-----r- C:\WINDOWS\sysWoW64\config\systemprofile\Music 2014-12-17 11:25:09 -------- d-----r- C:\WINDOWS\sysWoW64\config\systemprofile\Links 2014-12-17 11:25:09 -------- d-----r- C:\WINDOWS\sysWoW64\config\systemprofile\Favorites 2014-12-17 11:25:09 -------- d-----r- C:\WINDOWS\sysWoW64\config\systemprofile\Downloads 2014-12-17 11:25:09 -------- d-----r- C:\WINDOWS\sysWoW64\config\systemprofile\Documents 2014-12-17 11:25:09 -------- d-----r- C:\WINDOWS\sysWoW64\config\systemprofile\Desktop 2014-12-17 11:25:09 -------- d-----r- C:\WINDOWS\sysWoW64\config\systemprofile\Contacts 2014-12-03 02:21:17 1AAD73875A6A0707AAE5BE29868AA51C 8318844 ----a-w- C:\Users\Jonas\Ex_Ante_or_Preventative_102_TFEU.pdf 2014-11-30 23:52:06 -------- d-----w- C:\ProgramData\Google 2014-11-30 22:27:07 -------- d-----w- C:\ProgramData\Citrix 2014-11-30 19:39:52 -------- d-----r- C:\Users\Jonas\Dropbox 2014-11-30 18:53:23 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes 2014-11-30 18:52:37 -------- d-----w- C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7 2014-11-30 18:52:37 -------- d-----w- C:\ProgramData\Apple Computer 2014-11-30 18:51:51 -------- d-----w- C:\ProgramData\Apple 2014-11-30 18:33:32 -------- d---a-w- C:\Users\Jonas\OneDrive 2014-11-30 18:24:02 -------- d-----r- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013 2014-11-30 18:20:20 -------- d-----w- C:\ProgramData\Microsoft Help 2014-11-30 06:07:46 65243433DEEC2A970EAC80E0F7553643 355 ----a-w- C:\Users\Jonas\Prullenbak - Snelkoppeling.lnk 2014-11-30 05:27:34 -------- d-sh--w- C:\Users\Jonas\IntelGraphicsProfiles 2014-11-30 05:27:05 6FC234AD3752E1267B34FB12BCD6718B 20 --sh--w- C:\Users\Jonas\ntuser.ini 2014-11-30 05:16:24 -------- d-----w- C:\Users\Default\Roaming 2014-11-30 05:12:23 -------- d--h--w- C:\Users\UpdatusUser\AppData 2014-11-30 05:12:23 -------- d-----r- C:\Users\UpdatusUser\Favorites 2014-11-30 05:12:23 -------- d-----r- C:\Users\UpdatusUser\Desktop 2014-11-30 05:12:22 -------- d--h--w- C:\Users\Jonas\AppData 2014-11-30 05:12:22 -------- d-----r- C:\Users\Jonas\Favorites 2014-11-30 05:12:22 -------- d-----r- C:\Users\Jonas\Documents 2014-11-30 05:12:22 -------- d-----r- C:\Users\Jonas\Desktop 2014-11-30 05:07:21 -------- d-----w- C:\ProgramData\NVIDIA 2014-11-30 05:06:39 -------- d-----w- C:\ProgramData\NVIDIA Corporation 2014-11-30 05:06:26 -------- d-----w- C:\ProgramData\Conexant 2014-11-30 02:21:08 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome 2014-11-29 23:29:39 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype 2014-11-29 23:29:36 -------- d-----w- C:\ProgramData\Skype 2014-11-29 22:43:04 -------- d-----r- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel PROSet Wireless 2014-11-29 22:32:51 -------- d-----r- C:\Users\Jonas\Searches 2014-11-29 22:32:51 -------- d-----r- C:\Users\Jonas\Contacts 2014-11-29 22:31:51 -------- d-----w- C:\Users\Jonas\Roaming 2014-11-29 22:31:51 -------- d-----r- C:\Users\Jonas\Videos 2014-11-29 22:31:51 -------- d-----r- C:\Users\Jonas\Saved Games 2014-11-29 22:31:51 -------- d-----r- C:\Users\Jonas\Pictures 2014-11-29 22:31:51 -------- d-----r- C:\Users\Jonas\Music 2014-11-29 22:31:51 -------- d-----r- C:\Users\Jonas\Links 2014-11-29 22:31:51 -------- d-----r- C:\Users\Jonas\Downloads 2014-11-29 22:28:24 -------- d--h--r- C:\Users\Public\AccountPictures ====== C: exe-files == 2014-12-29 10:51:27 8045ABB21A3BDD66A48E1ED5C0F0EF6A 1222144 ----a-r- C:\Users\Jonas\AppData\Local\Microsoft\Windows\FileHistory\Data\268\C\Users\Jonas\Desktop\RSITx64.exe 2014-12-29 10:03:33 9A2347903D6EDB84C10F288BC0578C1C 388608 ----a-w- C:\Program Files\trend micro\Jonas.exe 2014-12-29 10:03:21 8045ABB21A3BDD66A48E1ED5C0F0EF6A 1222144 ----a-w- C:\Users\Jonas\Desktop\RSITx64.exe 2014-12-26 19:57:01 EE37818F0A03217201E6BF432D60A268 95168336 ----a-w- C:\Users\Jonas\AppData\Local\Temp\oct267F.tmp.exe 2014-12-24 11:28:51 516C021FEBEDE2962C9252DF85606C76 382168 ----a-w- C:\ProgramData\Adobe\ARM\S\26\AdobeARMHelper.exe === C: other files == 2014-12-29 10:19:19 F4DA597E44C66E9F71ECC00A2E5C4048 743108130 ----a-w- C:\Users\Jonas\Dropbox\microsoft office\OfficeProPlus2013-64bit-NL.zip ==== Startup Registry Enabled ====================== [HKEY_USERS\S-1-5-21-2856834796-3624118678-1303184682-1002\Software\Microsoft\Windows\CurrentVersion\Run] "Skype"="C:\Program Files (x86)\Skype\Phone\Skype.exe /minimized /regrun" "Pokki"=""%LOCALAPPDATA%\Pokki\Engine\HostAppServiceUpdater.exe" /LOGON" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IMSS"="C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe" "Fastboot"="C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBConsole.exe /analysis" "iTunesHelper"="C:\Program Files (x86)\iTunes\iTunesHelper.exe" "ConnectionCenter"="C:\Program Files (x86)\Citrix\ICA Client\concentr.exe /startup" "Redirector"="C:\Program Files (x86)\Citrix\ICA Client\redirector.exe /startup" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "Skype"="C:\Program Files (x86)\Skype\Phone\Skype.exe /minimized /regrun" "Pokki"=""%LOCALAPPDATA%\Pokki\Engine\HostAppServiceUpdater.exe" /LOGON" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"="C:\\WINDOWS\\SysWOW64\\nvinit.dll" ==== Startup Registry Enabled x64 ====================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RtsCM"="RTSCM64.EXE" "IgfxTray"="C:\windows\system32\igfxtray.exe" "HotKeysCmds"="C:\windows\system32\hkcmd.exe" "Persistence"="C:\windows\system32\igfxpers.exe" "LenovoOptMouseUpdate"="C:\Program Files\Lenovo\HOTKEY\extapsup.exe" "BTMTrayAgent"="rundll32.exe C:\Program Files (x86)\Intel\Bluetooth\btmshellex.dll,TrayApp" "cAudioFilterAgent"="C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe" "ForteConfig"="C:\Program Files\Conexant\ForteConfig\fmapp.exe" "SmartAudio"="C:\Program Files\CONEXANT\SAII\SACpl.exe /t" "TpShocks"="TpShocks.exe" "LnvMobHotspotClient"="C:\Program Files\Lenovo\Lenovo Mobile Hotspot\MobileHotspotclient.exe" "LENOVO.TPKNRRES"="rundll32.exe C:\Program Files\Lenovo\Communications Utility\LibStartStub.dll,AVStartupStub" "SynTPEnh"="%ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe " [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"="C:\\windows\\system32\\nvinitx.dll" ==== Startup Folders ====================== 2014-11-30 19:39:21 1158 ----a-w- C:\Users\Jonas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ==== Task Scheduler Jobs ====================== C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job --a-------- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [30/11/2014 02:20] C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job --a-------- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [30/11/2014 02:20] C:\WINDOWS\tasks\Synaptics TouchPad Enhancements.job --a-------- C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [09/07/2013 06:02] ==== Other Scheduled Tasks ====================== "C:\WINDOWS\SysNative\tasks\Absolute Reminder" ["%PROGRAMFILES(x86)%\Absolute Software\Absolute Reminder\AbsoluteReminder.exe"] "C:\WINDOWS\SysNative\tasks\Adobe Acrobat Update Task" [C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe] "C:\WINDOWS\SysNative\tasks\CLMLSvc" [C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe] "C:\WINDOWS\SysNative\tasks\CreateChoiceProcessTask" [C:\Windows\BrowserChoice\browserchoice.exe] "C:\WINDOWS\SysNative\tasks\GoogleUpdateTaskMachineCore" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe] "C:\WINDOWS\SysNative\tasks\GoogleUpdateTaskMachineUA" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe] "C:\WINDOWS\SysNative\tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473" [C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe] "C:\WINDOWS\SysNative\tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473-Logon" ["C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe"] "C:\WINDOWS\SysNative\tasks\Norton WSC Integration" ["C:\Program Files (x86)\Norton Internet Security\Engine\21.6.0.32\WSCStub.exe"] "C:\WINDOWS\SysNative\tasks\PMTask" [C:\PROGRA~2\ThinkPad\UTILIT~1\PwmIdTsv.exe] "C:\WINDOWS\SysNative\tasks\StartPowerDVDService" ["C:\PROGRAM FILES (x86)\Cyberlink\PowerDVD10\PDVD10Serv.exe"] "C:\WINDOWS\SysNative\tasks\Synaptics TouchPad Enhancements" ["C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"] "C:\WINDOWS\SysNative\tasks\User_Feed_Synchronization-{E89FCE8C-2CA5-4090-9DB2-9B476FFC876D}" [C:\WINDOWS\system32\msfeedssync.exe] "C:\WINDOWS\SysNative\tasks\Apple\AppleSoftwareUpdate" [C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe] "C:\WINDOWS\SysNative\tasks\Lenovo\Experience Improvement" [C:\Program Files\Lenovo\ExperienceImprovement\LenovoExperienceImprovement.exe] "C:\WINDOWS\SysNative\tasks\Lenovo\Lenovo Customer Feedback Program" ["%ProgramFiles%\Lenovo\Customer Feedback Program\Lenovo.TVT.CustomerFeedback.Agent.exe"] "C:\WINDOWS\SysNative\tasks\Lenovo\Lenovo Settings Power" ["C:\WINDOWS\system32\rundll32.exe" "C:\Program Files (x86)\ThinkPad\Utilities\PWMTR64V.dll",PwrMgrBkGndMonitor] "C:\WINDOWS\SysNative\tasks\Lenovo\Lenovo Solution Center Launcher" [%programfiles%\lenovo\lenovo solution center\App\LSCService.exe] "C:\WINDOWS\SysNative\tasks\Lenovo\LenovoDependencyVersionTask" [C:\Program Files\lenovo\SystemAgent\DependencyVersion.exe] "C:\WINDOWS\SysNative\tasks\Lenovo\LenovoMachineInformation" [C:\Program Files\lenovo\SystemAgent\MachineInformation.exe] "C:\WINDOWS\SysNative\tasks\Lenovo\LenovoUserguidesCopy" [C:\Program Files\lenovo\SystemAgent\UserguidesCopy.exe] "C:\WINDOWS\SysNative\tasks\Lenovo\LenovoWarrantyChinaTask" [C:\Program Files\lenovo\SystemAgent\ChinaWarrantyService.exe] "C:\WINDOWS\SysNative\tasks\Lenovo\LSC\Lenovo Solution Center Notifications" [%programfiles%\Lenovo\Lenovo Solution Center\LSCNotify.exe] "C:\WINDOWS\SysNative\tasks\Lenovo\LSC\LSCHardwareScan" ["C:\Program Files\Lenovo\Lenovo Solution Center\LSC.exe" -diag HWScan] "C:\WINDOWS\SysNative\tasks\Lenovo\LSC\RebootCountTask" ["C:\Program Files\Lenovo\Lenovo Solution Center\App\LSCService.exe"] "C:\WINDOWS\SysNative\tasks\Lenovo\LSC\Time72Task" ["C:\Program Files\Lenovo\Lenovo Solution Center\App\LSCService.exe"] "C:\WINDOWS\SysNative\tasks\Norton Internet Security\Norton Error Analyzer" [C:\Program Files (x86)\Norton Internet Security\Engine\21.6.0.32\SymErr.exe] "C:\WINDOWS\SysNative\tasks\Norton Internet Security\Norton Error Processor" [C:\Program Files (x86)\Norton Internet Security\Engine\21.6.0.32\SymErr.exe] "C:\WINDOWS\SysNative\tasks\TVT\TVSUUpdateTask" ["C:\Program Files (x86)\Lenovo\System Update\tvsuShim.exe"] ==== Firefox Extensions Registry ====================== [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions] "{BBDA0591-3099-440a-AA10-41764D9DB4DB}"="C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_21.5.0.19\IPSFF" [30/11/2014 18:44] ==== Chromium Look ====================== Google Chrome Version: 39.0.2171.95 (Up to date, latest Stable version: 39.0.2171.95) HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions iikflkcanblccfahdhdonehdalibjnif - No path found[] mkfokfffehpeedafpekjeddnmnjhmcmk - C:\Program Files (x86)\Norton Internet Security\Engine\21.6.0.32\Exts\Chrome.crx[20/09/2014 08:52] Google Slides - Jonas\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek Google Docs - Jonas\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake Google Drive - Jonas\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf YouTube - Jonas\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo Google Search - Jonas\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf Google Sheets - Jonas\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap Norton Identity Safe - Jonas\AppData\Local\Google\Chrome\User Data\Default\Extensions\iikflkcanblccfahdhdonehdalibjnif Norton Security Toolbar - Jonas\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk Google Wallet - Jonas\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda Gmail - Jonas\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia ==== Set IE to Default ====================== Old Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="https://www.google.com/" New Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="https://www.google.com/" ==== All HKCU SearchScopes ====================== HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes "DefaultScope"="{0E21F5DF-F3E5-487A-BE61-52480D9B7469}" {012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}" {0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02" {069336BA-DE31-4419-B9E4-0D66864C2A1E} Google Url="http://www.google.be/search?hl=nl&q={searchTerms}&sourceid=ie8&rls=com.microsoft:{language}:{referrer:source}&ie={inputEncoding?}&oe={outputEncoding?}&rlz=" {0E21F5DF-F3E5-487A-BE61-52480D9B7469} (www.google.be) Google Url="http://www.google.be/search?hl=nl&q={searchTerms}&sourceid=ie8&rls=com.microsoft:{language}:{referrer:source}&ie={inputEncoding?}&oe={outputEncoding?}" {C122F81C-F81C-42E1-AF73-8E6458909466} Unknown Url="Not_Found" ==== Deleting CLSID Registry Keys ====================== HKEY_USERS\S-1-5-21-2856834796-3624118678-1303184682-1002\Software\Microsoft\Internet Explorer\SearchScopes\{C122F81C-F81C-42E1-AF73-8E6458909466} deleted successfully ==== Deleting CLSID Registry Values ====================== ==== Deleting Registry Keys ====================== HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\ED77BE5C789DA434DB25DEDB12DDD18A deleted successfully HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{C5EB77DE-D987-434A-BD52-EDBD21DD1DA8} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\ED77BE5C789DA434DB25DEDB12DDD18A deleted successfully ==== HijackThis Entries ====================== F2 - REG:system.ini: UserInit=userinit.exe O2 - BHO: Lync Click to Call BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll O2 - BHO: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\21.6.0.32\coIEPlg.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll O2 - BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\PROGRA~2\MICROS~1\Office15\GROOVEEX.DLL O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\21.6.0.32\coIEPlg.dll O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll O4 - HKLM\..\Run: [IMSS] "C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe" O4 - HKLM\..\Run: [Fastboot] "C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBConsole.exe" /analysis O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [CitrixReceiver] "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Citrix\Receiver Updater.lnk" O4 - HKLM\..\Run: [ConnectionCenter] "C:\Program Files (x86)\Citrix\ICA Client\concentr.exe" /startup O4 - HKLM\..\Run: [Redirector] "C:\Program Files (x86)\Citrix\ICA Client\redirector.exe" /startup O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun O4 - HKCU\..\Run: [Pokki] "%LOCALAPPDATA%\Pokki\Engine\HostAppServiceUpdater.exe" /LOGON O4 - Startup: Dropbox.lnk = C:\Users\Jonas\AppData\Roaming\Dropbox\bin\Dropbox.exe O9 - Extra button: Verzenden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll O9 - Extra 'Tools' menuitem: &Verzenden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll O9 - Extra button: Lync - klikken om te bellen - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll O9 - Extra 'Tools' menuitem: Lync - klikken om te bellen - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll O9 - Extra button: &Gekoppelde notities van OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll O9 - Extra 'Tools' menuitem: &Gekoppelde notities van OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll O9 - Extra button: Skype Click to Call settings - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files (x86)\Microsoft Office\Office15\MSOSB.DLL O18 - Protocol: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll O18 - Filter: application/x-ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll O18 - Filter: application/x-ica; charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll O18 - Filter: application/x-ica; charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll O18 - Filter: application/x-ica; charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll O18 - Filter: application/x-ica; charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll O18 - Filter: application/x-ica; charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll O18 - Filter: application/x-ica; charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll O18 - Filter: application/x-ica; charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll O18 - Filter: application/x-ica;charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll O18 - Filter: application/x-ica;charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll O18 - Filter: application/x-ica;charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll O18 - Filter: application/x-ica;charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll O18 - Filter: application/x-ica;charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll O18 - Filter: application/x-ica;charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll O18 - Filter: application/x-ica;charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll O18 - Filter hijack: ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll O18 - Filter hijack: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\MSOXMLMF.DLL O20 - AppInit_DLLs: C:\WINDOWS\SysWOW64\nvinit.dll O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing) O23 - Service: Intel® Centrino® Wireless Bluetooth® + High Speed Service (AMPPALR3) - Intel Corporation - C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe O23 - Service: AVControlCenter - Lenovo Corporation - C:\Program Files\Lenovo\Communications Utility\AVControlCenter32.exe O23 - Service: Bluetooth Device Monitor - Motorola Solutions, Inc. - C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe O23 - Service: Bluetooth OBEX Service - Motorola Solutions, Inc. - C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe O23 - Service: Bonjour-service (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: BrcmSetSecurity - Intel - C:\Program Files\Intel Corporation\Intel WiDi\BrcmSetSecurity.exe O23 - Service: Intel(R) Centrino(R) Wireless Bluetooth(R) + High Speed Security Service (BTHSSecurityMgr) - Intel(R) Corporation - C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe O23 - Service: Conexant Audio Message Service (CxAudMsg) - Unknown owner - C:\windows\system32\CxAudMsg64.exe (file missing) O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing) O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe O23 - Service: ExpressCache - Condusiv Technologies - C:\Program Files\Condusiv Technologies\ExpressCache\ExpressCache.exe O23 - Service: FastbootService - Lenovo - C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBService.exe O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing) O23 - Service: Google Update-service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe O23 - Service: Google Update-service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: @oem46.inf,%ibm.svcDesc0%;Lenovo PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe (file missing) O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\WINDOWS\system32\IEEtwCollector.exe (file missing) O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService1.0.0.0) - Unknown owner - C:\WINDOWS\system32\igfxCUIService.exe (file missing) O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe O23 - Service: Intel(R) Capability Licensing Service TCP IP Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe O23 - Service: Intel(R) Wireless Bluetooth(R) 4.0 Radio Management - Intel Corporation - C:\Program Files (x86)\Intel\Bluetooth\ibtrksrv.exe O23 - Service: Intel(R) Small Business Advantage (intelsba) - Intel Corporation - C:\Program Files\Intel\Intel(R) Small Business Advantage\Service\Intel.SmallBusinessAdvantage.WindowsService.exe O23 - Service: iPod-service (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: Intel(R) Smart Connect Technology Agent (ISCTAgent) - Unknown owner - C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe O23 - Service: Intel(R) Update Manager (iumsvc) - Unknown owner - C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing) O23 - Service: Lenovo QuickSnip Service - LENOVO INCORPORATED. - C:\Program Files\lenovo\QuickSnipService\QuickSnipService.exe O23 - Service: Lenovo Settings Service - Lenovo Group Limited - C:\Program Files\Lenovo\SettingsDependency\SettingsService.exe O23 - Service: Lenovo System Agent Service - LENOVO INCORPORATED. - C:\Program Files\lenovo\SystemAgent\SystemAgentService.exe O23 - Service: Lenovo AVFramework Camera Privacy Controller (LENOVO.CAMMUTE) - Lenovo Corporation - C:\Program Files\Lenovo\Communications Utility\cammute.exe O23 - Service: Lenovo Microphone Mute (LENOVO.MICMUTE) - Lenovo Group Limited - C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe O23 - Service: Lenovo AVFramework Microphone Volume Controller and Dolby Interface (LENOVO.TPKNRSVC) - Lenovo Group Limited - C:\Program Files\Lenovo\Communications Utility\tpknrsvc.exe O23 - Service: Lenovo AVFramework Virtual Camera Controller Service (LENOVO.TVTVCAM) - Lenovo Corporation - C:\Program Files\Lenovo\Communications Utility\vcamsvc.exe O23 - Service: Lenovo Auto Scroll (Lenovo.VIRTSCRLSVC) - Lenovo Group Limited - C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe O23 - Service: Lenovo Settings Mobile Hotspot Service (LnvHotSpotSvc) - Lenovo - C:\Program Files\Lenovo\Lenovo Mobile Hotspot\LnvHotSpotSvc.exe O23 - Service: LocationTaskManager - Unknown owner - C:\Program Files (x86)\Lenovo\LocationAware\loctaskmgr.exe O23 - Service: LSCWinService - Unknown owner - C:\Program Files\Lenovo\Lenovo Solution Center\App\LSCWinService.exe O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing) O23 - Service: Wireless PAN DHCP Server (MyWiFiDHCPDNS) - Unknown owner - C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing) O23 - Service: Norton Internet Security (NIS) - Symantec Corporation - C:\Program Files (x86)\Norton Internet Security\Engine\21.6.0.32\NIS.exe O23 - Service: NitroPDFDriverCreatorReadSpool8 (NitroDriverReadSpool8) - Nitro PDF Software - C:\Program Files\Common Files\Nitro\Pro\8.0\NitroPDFDriverService8x64.exe O23 - Service: Nalpeiron Licensing Service (nlsX86cc) - Nalpeiron Ltd. - C:\windows\SysWOW64\NLSSRV32.EXE O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\WINDOWS\system32\nvvsvc.exe (file missing) O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe O23 - Service: Lenovo Settings Power Service (Power Manager DBC Service) - Lenovo - C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE O23 - Service: Lenovo QuickControl Master Service (QuickControlMasterSvc) - Lenovo Group Limited - C:\Program Files (x86)\Lenovo\QuickControl\QuickControlMasterSvc.exe O23 - Service: Lenovo QuickControl Service (QuickControlService) - Lenovo Group Limited - C:\Program Files (x86)\Lenovo\QuickControl\QuickControlService.exe O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing) O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing) O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing) O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing) O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing) O23 - Service: System Update (SUService) - Unknown owner - C:\Program Files (x86)\Lenovo\System Update\SUService.exe O23 - Service: TeamViewer 9 (TeamViewer9) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe O23 - Service: ThinkPad HDD APS Logging Service (TPHDEXLGSVC) - Unknown owner - C:\WINDOWS\System32\TPHDEXLG64.exe (file missing) O23 - Service: Lenovo Hotkey Client Loader (TPHKLOAD) - Lenovo Group Limited - C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing) O23 - Service: ValBioService - Validity Sensors, Inc. - C:\Program Files\Lenovo Fingerprint Reader\ValBioService.exe O23 - Service: Validity WBF Policy Service (valWBFPolicyService) - Unknown owner - C:\WINDOWS\system32\valWBFPolicyService.exe (file missing) O23 - Service: @oem83.inf,%BioSyncService_SvcDesc%;BiometricSensorDataSynchronization (valWbioSyncSvc) - Unknown owner - C:\WINDOWS\system32\valWbioSyncSvc.exe (file missing) O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing) O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing) O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing) O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing) O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing) O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing) O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing) O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing) O23 - Service: Intel(R) PROSet/Wireless Zero Configuration Service (ZeroConfigService) - Intel® Corporation - C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe ==== Empty IE Cache ====================== C:\WINDOWS\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Jonas\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\Users\Jonas\AppData\Local\Microsoft\Windows\INetCache\Low\Content.IE5 emptied successfully C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\WINDOWS\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\Users\Jonas\AppData\Local\Microsoft\Windows\INetCache\Low\IE emptied successfully C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully C:\Users\Jonas\AppData\Local\Microsoft\Windows\INetCache\IE\E5Y72KBH will be deleted at reboot ==== Empty FireFox Cache ====================== No FireFox Profiles found ==== Empty Chrome Cache ====================== C:\Users\Jonas\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully ==== Empty All Flash Cache ====================== Flash Cache Emptied Successfully ==== Empty All Java Cache ====================== No Java Cache Found ==== C:\zoek_backup content ====================== C:\zoek_backup (files=12035 folders=201 684376387 bytes) ==== Empty Temp Folders ====================== C:\Users\Default\AppData\Local\Temp emptied successfully C:\Users\Default User\AppData\Local\Temp emptied successfully C:\Users\Jonas\AppData\Local\Temp will be emptied at reboot C:\Users\UpdatusUser\AppData\Local\Temp emptied successfully C:\WINDOWS\serviceprofiles\networkservice\AppData\Local\Temp will be emptied at reboot C:\WINDOWS\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully C:\WINDOWS\Temp will be emptied at reboot ==== After Reboot ====================== ==== Empty Temp Folders ====================== C:\WINDOWS\Temp successfully emptied C:\Users\Jonas\AppData\Local\Temp successfully emptied ==== Empty Recycle Bin ====================== C:\$RECYCLE.BIN successfully emptied ==== Deleting Files / Folders ====================== "C:\Users\Jonas\AppData\Local\Pokki\analytics.db" not found "C:\Users\Jonas\AppData\Local\Pokki\engine_update.db" not found "C:\Users\Jonas\AppData\Local\Pokki" not found "C:\Users\Jonas\AppData\Local\Microsoft\Windows\INetCache\IE\E5Y72KBH" not found "C:\WINDOWS\serviceprofiles\networkservice\AppData\Local\Temp\Low" not deleted ==== EOF on ma 29/12/2014 at 17:10:06,83 ======================