Zoek.exe v5.0.0.0 Updated 31-12-2014 Tool run by Hugo on vr 02/01/2015 at 22:13:31,28. Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x64 Running in: Normal Mode Internet Access Detected Launched: C:\Users\Hugo\Downloads\zoek.exe [Scan all users] [Script inserted] ==== Older Logs ====================== C:\zoek-results2014-12-28-205406.log 90215 bytes C:\zoek-results2014-12-29-104135.log 57696 bytes ==== Empty Folders Check ====================== C:\Users\Hugo\AppData\Local\Wisdom-soft deleted successfully ==== Deleting CLSID Registry Keys ====================== ==== Deleting CLSID Registry Values ====================== ==== Running Processes ====================== C:\Program Files\Dell\DellDock\DockLogin.exe C:\Prey\platform\windows\cronsvc.exe C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe C:\Program Files (x86)\Blaze Media Pro\NMSAccess32.exe C:\Windows\system32\DRIVERS\o2flash.exe C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe c:\program files (x86)\real\realplayer\RPDS\Bin\rpdsvc.exe C:\Program Files (x86)\Real\UpdateService\RealPlayerUpdateSvc.exe C:\Program Files (x86)\Google\Update\1.3.25.11\GoogleCrashHandler.exe C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe C:\Program Files (x86)\Wisdom-soft ScreenHunter 6.0 Free\ScreenHunter.exe C:\Program Files (x86)\Microsoft Office\Office12\OUTLOOK.EXE C:\Users\Hugo\Downloads\zoek.exe C:\Windows\SysWOW64\cmd.exe C:\Windows\SysWOW64\cmd.exe C:\Windows\SysWOW64\cmd.exe C:\ProgramData\HP Photo Creations\Communicator.exe ==== Deleting Services ====================== ==== Registry Fix Code x64 ====================== Windows Registry Editor Version 5.00 • [HKEY_USERS\S-1-5-21-380040671-3701161090-3446401283-1001\Software\iolo\System Mechanic\Startup Manager\Configuration\Disabled\Registry\HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] • "DATAMNGR"=- • "Browser companion helper"=- ==== Deleting Files \ Folders ====================== • c:\Users\All Users\dtdata not found "• C:\Windows\SysNative\tasks\Default2Check" not found "• C:\Windows\SysNative\tasks\DefaultCheck" not found "• C:\Windows\SysNative\tasks\DefaultReg" not found ==== System Specs ====================== Windows: Windows 7 Home Premium Edition (64-bit) Service Pack 1 (Build 7601) Memory (RAM): 3957 MB CPU Info: Intel(R) Core(TM) i5 CPU M 450 @ 2.40GHz CPU Speed: 2428,6 MHz Sound Card: Luidsprekers / Koptelefoon (IDT | Luidsprekers (MusCAudio) | Luidsprekers (MusCAudio) | Luidsprekers (MusCAudio) | Luidsprekers (MusCAudio) | Luidsprekers (MusCAudio) | Luidsprekers (MusCAudio) | Luidsprekers (MusCAudio) | Luidsprekers (MusCAudio) | Luidsprekers (MusCAudio) | Luidsprekers (MusCAudio) | Luidsprekers (MusCAudio) | Luidsprekers (MusCAudio) | Luidsprekers (MusCAudio) | Luidsprekers (MusCAudio) | Luidsprekers (MusCAudio) | Luidsprekers (MusCAudio) | Display Adapters: ATI Mobility Radeon HD 5650 | ATI Mobility Radeon HD 5650 | RDPDD Chained DD | RDP Encoder Mirror Driver | RDP Reflector Display Driver Monitors: 2x; Algemeen PnP-beeldscherm | Dell 1708FP-BLK(Analog) | Screen Resolution: 1600 X 900 - 32 bit Network: Network Present Network Adapters: Dell draadloze 1397 WLAN Mini-kaart | Realtek PCIe GBE Family Controller CD / DVD Drives: 1x (E: | ) E: TSSTcorpDVD+-RW TS-T633C Ports: COM Ports NOT Present. LPT Port NOT Present. Mouse: 8 Button Wheel Mouse Present Hard Disks: C: 451,1GB | D: 465,8GB | G: 232,8GB Hard Disks - Free: C: 345,4GB | D: 23,4GB | G: 93,9GB Manufacturer *: Dell Inc. BIOS Info: AT/AT COMPATIBLE | 03/24/11 | DELL - 6040000 Time Zone: Romance (standaardtijd) Motherboard *: Dell Inc. 0KVMW2 Country: Belgi‰ Language: NLB ==== System Specs (Software) ====================== Anti-Virus: Microsoft Security Essentials On-access scanning disabled (Outdated) Anti-Spyware: Microsoft Security Essentials disabled (Outdated) Anti-Spyware: Windows Defender disabled (Outdated) Default Browser: Google Chrome 39.0.2171.95 Internet Explorer Version: 11.0.9600.17501 Google Chrome version: 39.0.2171.95 Adobe Reader version: 9.1.0.2009022700 Flash Player version: 15.0.0.246 Shockwave Player version: 11.5.8r612 ==== Files Recently Created / Modified ====================== ====== C:\Windows ==== 2014-12-25 14:49:12 E185BDA84E5F03F4E1D8DCA30E209277 1912 ----a-w- C:\Windows\epplauncher.mif ====== C:\Users\Hugo\AppData\Local\Temp ==== 2014-12-29 19:03:26 443E13846997C537E8F5ED61130AB705 149504 ----a-r- C:\Users\Hugo\AppData\Local\Temp\GLB1A2B.EXE 2014-12-29 18:50:49 71FF02E70598D2318BDBD11AC5D35A57 55083472 ----a-w- C:\Users\Hugo\AppData\Local\Temp\Garmin Software Updates\BaseCamp.exe 2014-12-29 16:02:50 B600DE404F4D6C5A1AB9A033739A21AA 41984 ----a-w- C:\Users\Hugo\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpvvjaag.dll ====== Java Cache ===== ====== C:\Windows\SysWOW64 ===== ====== C:\Windows\SysWOW64\drivers ===== ====== C:\Windows\Sysnative ===== 2014-12-25 22:39:07 1E583D74D35A8C6A7FAF537C94C844D2 5005688 ----a-w- C:\Windows\Sysnative\.crusader ====== C:\Windows\Sysnative\drivers ===== 2014-12-25 23:10:11 545EE654B04D52AF2E7F5F393D1F7D75 43664 ----a-w- C:\Windows\Sysnative\drivers\hitmanpro37.sys 2014-12-25 15:05:24 26C43960C99EE861A5D0EDC4DCF3B1C3 129752 ----a-w- C:\Windows\Sysnative\drivers\MBAMSwissArmy.sys 2014-12-25 15:03:19 CA43F8904E24BBE49982E4C0B29E6579 25816 ----a-w- C:\Windows\Sysnative\drivers\mbam.sys 2014-12-25 15:03:19 A646C2DDB8C46E9B20A326FAF566646C 63704 ----a-w- C:\Windows\Sysnative\drivers\mwac.sys 2014-12-25 15:03:19 478CC94C937D235CB0A96AB8F2359D81 93400 ----a-w- C:\Windows\Sysnative\drivers\mbamchameleon.sys 2014-12-10 15:47:04 70988118145F5F10EF24720B97F35F65 119296 ----a-w- C:\Windows\Sysnative\drivers\tdx.sys ====== C:\Windows\Tasks ====== 2014-12-29 19:23:44 3F716E378EC339E7C14040E797F2BF8D 3156 ----a-w- C:\Windows\Sysnative\Tasks\{7B35112D-9B0E-4B24-8E85-91A350AD9B41} ====== C:\Windows\Temp ====== ======= C:\Program Files ===== 2014-12-25 22:06:51 -------- d-----w- C:\Program Files\trend micro ======= C:\PROGRA~2 ===== 2014-12-29 19:03:20 -------- d-----w- C:\PROGRA~2\Snagit32 2014-12-29 08:48:27 -------- d-----w- C:\PROGRA~2\COMMON~1\Java ======= C: ===== ====== C:\Users\Hugo\AppData\Roaming ====== 2014-12-29 10:06:45 -------- d-----w- C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp 2014-12-29 10:06:45 -------- d-----w- C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp 2014-12-29 10:06:45 -------- d-----w- C:\Users\Jessie\AppData\Local\Temp 2014-12-29 10:06:45 -------- d-----w- C:\Users\Hugo\AppData\Local\Temp 2014-12-29 10:06:45 -------- d-----w- C:\Users\Default\AppData\Local\Temp 2014-12-29 10:06:45 -------- d-----w- C:\Users\Default User\AppData\Local\Temp 2014-12-29 08:55:20 -------- d-----w- C:\Windows\SysNative\config\systemprofile\AppData\Locallow\Sun 2014-12-22 09:30:33 -------- d-sh--w- C:\Users\Hugo\AppData\Locallow\EmieBrowserModeList 2014-12-22 08:31:36 -------- d-sh--w- C:\Users\Jessie\AppData\Local\EmieBrowserModeList 2014-12-22 08:13:39 -------- d-sh--w- C:\Users\Jessie\AppData\Locallow\EmieBrowserModeList ====== C:\Users\Hugo ====== 2014-12-29 10:06:40 138F6492F066F7DAB4DFE4FB612A574D 1311 ----a-w- C:\Users\Hugo\Documents\folderchk.vbs 2014-12-29 09:28:38 -------- d-----w- C:\ProgramData\Sun 2014-12-29 09:25:20 3A582BF6FD39DC6A52AAF316126B40BA 638888 ----a-w- C:\Users\Hugo\Downloads\chromeinstall-8u25 (1).exe 2014-12-29 08:47:49 -------- d-----w- C:\ProgramData\Oracle 2014-12-29 08:45:28 3A582BF6FD39DC6A52AAF316126B40BA 638888 ----a-w- C:\Users\Hugo\Downloads\chromeinstall-8u25.exe 2014-12-25 22:06:27 8045ABB21A3BDD66A48E1ED5C0F0EF6A 1222144 ----a-w- C:\Users\Hugo\Downloads\RSITx64.exe 2014-12-25 21:49:44 -------- d-----w- C:\ProgramData\HitmanPro 2014-12-25 21:48:12 00FD7C6BEDEE9B24B0DB02B68B07AD54 11222744 ----a-w- C:\Users\Hugo\Downloads\hitmanpro_x64.exe 2014-12-25 14:58:47 3BD59D6C407AB1F6DDD7C5D9BD727469 20447072 ----a-w- C:\Users\Hugo\Downloads\mbam-setup-2.0.4.1028.exe 2014-12-25 14:43:03 14CB257C6D044B6D3FD965DE2B9DADC9 14105760 ----a-w- C:\Users\Hugo\Downloads\mseinstall (1).exe 2014-12-25 14:42:45 14CB257C6D044B6D3FD965DE2B9DADC9 14105760 ----a-w- C:\Users\Hugo\Downloads\mseinstall.exe ====== C: exe-files == 2015-01-02 13:08:11 7E57F119FA1C81FEFCEEB00073F25D5A 652648 ----a-w- C:\Program Files\My Dell\Setup_nltd.exe 2015-01-02 13:06:27 D22E4A5C59C778CD037313EB5BDD8CCD 16976 ----a-w- C:\Users\Hugo\AppData\Roaming\PCDr\Update\Rules\cae79b09-9fa0-409e-a789-713bb9ed9f88\appupdaterrules_dell\AddCertificate.exe 2015-01-02 13:04:18 D22E4A5C59C778CD037313EB5BDD8CCD 16976 ----a-w- C:\Users\Hugo\AppData\Roaming\PCDr\Update\Rules\88453f7c-2348-4163-ab25-abda046efa98\appupdaterrules_dell\AddCertificate.exe 2014-12-31 13:08:32 D22E4A5C59C778CD037313EB5BDD8CCD 16976 ----a-w- C:\Users\Hugo\AppData\Roaming\PCDr\Update\Rules\aaf241df-096d-4241-981b-92d2bd12b8ac\appupdaterrules_dell\AddCertificate.exe 2014-12-31 13:05:42 D22E4A5C59C778CD037313EB5BDD8CCD 16976 ----a-w- C:\Users\Hugo\AppData\Roaming\PCDr\Update\Rules\151c1c62-4a34-45ee-ab84-c284f84d4715\appupdaterrules_dell\AddCertificate.exe 2014-12-30 13:12:57 D22E4A5C59C778CD037313EB5BDD8CCD 16976 ----a-w- C:\Users\Hugo\AppData\Roaming\PCDr\Update\Rules\1166d673-1497-4746-8138-bb50351987ea\appupdaterrules_dell\AddCertificate.exe 2014-12-30 13:09:57 D22E4A5C59C778CD037313EB5BDD8CCD 16976 ----a-w- C:\Users\Hugo\AppData\Roaming\PCDr\Update\Rules\c86082a7-9846-49d2-9b7d-3e2fc15ee2a3\appupdaterrules_dell\AddCertificate.exe 2014-12-29 19:03:26 443E13846997C537E8F5ED61130AB705 149504 ----a-r- C:\Users\Hugo\AppData\Local\Temp\GLB1A2B.EXE 2014-12-29 19:03:26 443E13846997C537E8F5ED61130AB705 149504 ----a-r- C:\Program Files (x86)\Snagit32\UNWISE.EXE 2014-12-29 19:03:25 9085154943D6FBE37920437F7945A24D 1802240 ----a-r- C:\Program Files (x86)\Snagit32\Studio.exe 2014-12-29 19:03:24 D17D1A23EA65D257E058E417EEDE1617 860160 ----a-r- C:\Program Files (x86)\Snagit32\SnagIt32.exe 2014-12-29 19:03:24 3775B7CD59C113352A51A1D0DA1E5217 105264 ----a-r- C:\Program Files (x86)\Snagit32\SIUNINST.EXE 2014-12-29 18:50:49 71FF02E70598D2318BDBD11AC5D35A57 55083472 ----a-w- C:\Users\Hugo\AppData\Local\Temp\Garmin Software Updates\BaseCamp.exe 2014-12-29 18:50:49 71FF02E70598D2318BDBD11AC5D35A57 55083472 ----a-w- C:\Users\Hugo\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1PH4MPET\BaseCamp_446[1].exe 2014-12-29 13:08:39 D22E4A5C59C778CD037313EB5BDD8CCD 16976 ----a-w- C:\Users\Hugo\AppData\Roaming\PCDr\Update\Rules\01f04518-d989-4d6b-acf9-f7ba34e9002d\appupdaterrules_dell\AddCertificate.exe 2014-12-29 13:05:36 D22E4A5C59C778CD037313EB5BDD8CCD 16976 ----a-w- C:\Users\Hugo\AppData\Roaming\PCDr\Update\Rules\e2524023-27ad-4ff5-b381-5af03bc3ca1f\appupdaterrules_dell\AddCertificate.exe 2014-12-29 09:25:20 3A582BF6FD39DC6A52AAF316126B40BA 638888 ----a-w- C:\Users\Hugo\Downloads\chromeinstall-8u25 (1).exe 2014-12-29 08:45:28 3A582BF6FD39DC6A52AAF316126B40BA 638888 ----a-w- C:\Users\Hugo\Downloads\chromeinstall-8u25.exe 2014-12-28 21:03:42 0F901EE41FF20347C106D663F24931F9 679752 ----a-w- C:\Users\Hugo\AppData\Local\Google\Chrome\User Data\SwReporter\2.6.2\software_reporter_tool.exe 2014-12-27 19:56:16 A61B6EA4731AB439AFFC58B53A6830C6 6852688 ----a-w- C:\Program Files (x86)\Google\Update\Download\{4DC8B4CA-1BDA-483E-B5FA-D3C12E15B62D}\39.0.2171.95\39.0.2171.95_38.0.2125.104_chrome_updater.exe 2014-12-27 19:50:56 87EB5AFD21E52CB08883E04605B55829 880784 ----a-w- C:\Program Files (x86)\Google\Update\1.3.25.11\GoogleUpdateSetup.exe 2014-12-27 19:50:56 5B4ED5734945619EE3BCDB9825D2F526 51080 ----atw- C:\Program Files (x86)\Google\Update\1.3.25.11\GoogleUpdateOnDemand.exe 2014-12-27 19:50:56 06036279056145E0F08FC095CB789E6A 51080 ----atw- C:\Program Files (x86)\Google\Update\1.3.25.11\GoogleUpdateBroker.exe 2014-12-27 19:50:50 EDD3E562684CB4C50704B471BEAB1F86 114568 ----atw- C:\Program Files (x86)\Google\Update\1.3.25.11\GoogleUpdateComRegisterShell64.exe 2014-12-27 19:50:50 7161E8E31B7FD3B1CE083C2CA5FD5F44 285064 ----atw- C:\Program Files (x86)\Google\Update\1.3.25.11\GoogleCrashHandler64.exe 2014-12-27 19:50:49 F172AD4E906D97ED8F071896FC6789DC 107912 ----atw- C:\Program Files (x86)\Google\Update\1.3.25.11\GoogleUpdate.exe 2014-12-27 19:50:49 CB8C1CC4F46FBAC78150754D77460C73 230792 ----atw- C:\Program Files (x86)\Google\Update\1.3.25.11\GoogleCrashHandler.exe 2014-12-27 19:50:45 87EB5AFD21E52CB08883E04605B55829 880784 ----a-w- C:\Program Files (x86)\Google\Update\Download\{430FD4D0-B729-4F61-AA34-91526481799D}\1.3.25.11\GoogleUpdateSetup.exe === C: other files == 2015-01-02 13:06:29 A1FE3E89F1A3B31EF0820EF374592252 62445 ----a-w- C:\Users\Hugo\AppData\Roaming\PCDr\Update\Rules\9fce1ec7-980f-4aa1-be9d-8dba09cd2ed9\withSigneddll-PCDoctor_6422.40_windows_appupdaterrules_dell\withSigneddll-PCDoctor_6422.40_windows_appupdaterrules_dell.zip 2015-01-02 13:06:29 A1FE3E89F1A3B31EF0820EF374592252 62445 ----a-w- C:\Users\Hugo\AppData\Roaming\PCDr\Update\Rules\1215a7a5-a9cf-42df-bd7c-52dd5b533239\withSigneddll-PCDoctor_6422.40_windows_appupdaterrules_dell\withSigneddll-PCDoctor_6422.40_windows_appupdaterrules_dell.zip 2015-01-02 13:06:28 A1FE3E89F1A3B31EF0820EF374592252 62445 ----a-w- C:\Users\Hugo\AppData\Roaming\PCDr\Update\Rules\8eaed0a9-1840-4c03-a787-03958cfaab36\withSigneddll-PCDoctor_6422.40_windows_appupdaterrules_dell\withSigneddll-PCDoctor_6422.40_windows_appupdaterrules_dell.zip 2015-01-02 13:06:28 A1FE3E89F1A3B31EF0820EF374592252 62445 ----a-w- C:\Users\Hugo\AppData\Roaming\PCDr\Update\Rules\89661957-418a-416f-8642-f0527aedb081\withSigneddll-PCDoctor_6422.40_windows_appupdaterrules_dell\withSigneddll-PCDoctor_6422.40_windows_appupdaterrules_dell.zip 2015-01-02 13:06:28 A1FE3E89F1A3B31EF0820EF374592252 62445 ----a-w- C:\Users\Hugo\AppData\Roaming\PCDr\Update\Rules\34fd85f6-6609-450b-8740-2269f1b4975b\withSigneddll-PCDoctor_6422.40_windows_appupdaterrules_dell\withSigneddll-PCDoctor_6422.40_windows_appupdaterrules_dell.zip 2015-01-02 13:06:27 1D9B575A4DE26B262EA8C76109CCFB1D 59018 ----a-w- C:\Users\Hugo\AppData\Roaming\PCDr\Update\Rules\cae79b09-9fa0-409e-a789-713bb9ed9f88\appupdaterrules_dell\appupdaterrules_dell.zip 2015-01-02 13:04:21 A1FE3E89F1A3B31EF0820EF374592252 62445 ----a-w- C:\Users\Hugo\AppData\Roaming\PCDr\Update\Rules\d5bf3cad-619f-4c24-8010-9891e2096ab5\withSigneddll-PCDoctor_6422.40_windows_appupdaterrules_dell\withSigneddll-PCDoctor_6422.40_windows_appupdaterrules_dell.zip 2015-01-02 13:04:21 A1FE3E89F1A3B31EF0820EF374592252 62445 ----a-w- C:\Users\Hugo\AppData\Roaming\PCDr\Update\Rules\c99c0ac0-2971-4d6d-a2a3-6980926c83bc\withSigneddll-PCDoctor_6422.40_windows_appupdaterrules_dell\withSigneddll-PCDoctor_6422.40_windows_appupdaterrules_dell.zip 2015-01-02 13:04:20 A1FE3E89F1A3B31EF0820EF374592252 62445 ----a-w- C:\Users\Hugo\AppData\Roaming\PCDr\Update\Rules\f275f905-7581-471e-926c-b686fc5f6282\withSigneddll-PCDoctor_6422.40_windows_appupdaterrules_dell\withSigneddll-PCDoctor_6422.40_windows_appupdaterrules_dell.zip 2015-01-02 13:04:19 A1FE3E89F1A3B31EF0820EF374592252 62445 ----a-w- C:\Users\Hugo\AppData\Roaming\PCDr\Update\Rules\dd84710d-6776-4d21-bd51-5d051f255471\withSigneddll-PCDoctor_6422.40_windows_appupdaterrules_dell\withSigneddll-PCDoctor_6422.40_windows_appupdaterrules_dell.zip 2015-01-02 13:04:19 A1FE3E89F1A3B31EF0820EF374592252 62445 ----a-w- C:\Users\Hugo\AppData\Roaming\PCDr\Update\Rules\1f511700-92dd-414c-962d-b3abdac6bbd9\withSigneddll-PCDoctor_6422.40_windows_appupdaterrules_dell\withSigneddll-PCDoctor_6422.40_windows_appupdaterrules_dell.zip 2015-01-02 13:04:18 1D9B575A4DE26B262EA8C76109CCFB1D 59018 ----a-w- C:\Users\Hugo\AppData\Roaming\PCDr\Update\Rules\88453f7c-2348-4163-ab25-abda046efa98\appupdaterrules_dell\appupdaterrules_dell.zip 2015-01-02 13:02:52 70C807DA850D07B5F22D31BCBDAB8C5E 38856 ----a-w- C:\ProgramData\PCDr\6261\AddOnDownloaderCache\zipped\481fbe3e-ec08-4d5a-94ea-95c753609e7c.zip 2015-01-02 13:02:51 406C66876F48BFD35FE9C30C6E7CAFA0 38823 ----a-w- C:\ProgramData\PCDr\6261\AddOnDownloaderCache\zipped\c74b2d1b-fd92-4f74-8532-20f83f9afd65.zip 2015-01-02 13:02:51 0F3C51F9FC945D6E68CC4801DABE79F0 38954 ----a-w- C:\ProgramData\PCDr\6261\AddOnDownloaderCache\zipped\5c57a158-1254-45f6-b629-b2debbf1fd29.zip 2014-12-31 13:08:47 A1FE3E89F1A3B31EF0820EF374592252 62445 ----a-w- C:\Users\Hugo\AppData\Roaming\PCDr\Update\Rules\30085726-0923-4b0a-8452-875d14c75fcd\withSigneddll-PCDoctor_6422.40_windows_appupdaterrules_dell\withSigneddll-PCDoctor_6422.40_windows_appupdaterrules_dell.zip 2014-12-31 13:08:45 A1FE3E89F1A3B31EF0820EF374592252 62445 ----a-w- C:\Users\Hugo\AppData\Roaming\PCDr\Update\Rules\88c838eb-61c5-4d6c-90d0-05012630b75f\withSigneddll-PCDoctor_6422.40_windows_appupdaterrules_dell\withSigneddll-PCDoctor_6422.40_windows_appupdaterrules_dell.zip 2014-12-31 13:08:42 A1FE3E89F1A3B31EF0820EF374592252 62445 ----a-w- C:\Users\Hugo\AppData\Roaming\PCDr\Update\Rules\4ed51f5e-feec-4435-921a-682034a528c1\withSigneddll-PCDoctor_6422.40_windows_appupdaterrules_dell\withSigneddll-PCDoctor_6422.40_windows_appupdaterrules_dell.zip 2014-12-31 13:08:39 A1FE3E89F1A3B31EF0820EF374592252 62445 ----a-w- C:\Users\Hugo\AppData\Roaming\PCDr\Update\Rules\5221be7e-85c7-40db-8093-75bc5021eb5b\withSigneddll-PCDoctor_6422.40_windows_appupdaterrules_dell\withSigneddll-PCDoctor_6422.40_windows_appupdaterrules_dell.zip 2014-12-31 13:08:35 A1FE3E89F1A3B31EF0820EF374592252 62445 ----a-w- C:\Users\Hugo\AppData\Roaming\PCDr\Update\Rules\c25d3202-4b2f-42e5-9892-c1551ff91750\withSigneddll-PCDoctor_6422.40_windows_appupdaterrules_dell\withSigneddll-PCDoctor_6422.40_windows_appupdaterrules_dell.zip 2014-12-31 13:08:32 1D9B575A4DE26B262EA8C76109CCFB1D 59018 ----a-w- C:\Users\Hugo\AppData\Roaming\PCDr\Update\Rules\aaf241df-096d-4241-981b-92d2bd12b8ac\appupdaterrules_dell\appupdaterrules_dell.zip 2014-12-31 13:05:58 A1FE3E89F1A3B31EF0820EF374592252 62445 ----a-w- C:\Users\Hugo\AppData\Roaming\PCDr\Update\Rules\b8acd959-1d38-4556-96bd-40e11dfd8799\withSigneddll-PCDoctor_6422.40_windows_appupdaterrules_dell\withSigneddll-PCDoctor_6422.40_windows_appupdaterrules_dell.zip 2014-12-31 13:05:55 A1FE3E89F1A3B31EF0820EF374592252 62445 ----a-w- C:\Users\Hugo\AppData\Roaming\PCDr\Update\Rules\0413377b-2f85-4096-870d-7a4b73ec1f68\withSigneddll-PCDoctor_6422.40_windows_appupdaterrules_dell\withSigneddll-PCDoctor_6422.40_windows_appupdaterrules_dell.zip 2014-12-31 13:05:52 A1FE3E89F1A3B31EF0820EF374592252 62445 ----a-w- C:\Users\Hugo\AppData\Roaming\PCDr\Update\Rules\148c6aef-74d1-42f0-999b-a6cbaccae5cd\withSigneddll-PCDoctor_6422.40_windows_appupdaterrules_dell\withSigneddll-PCDoctor_6422.40_windows_appupdaterrules_dell.zip 2014-12-31 13:05:49 A1FE3E89F1A3B31EF0820EF374592252 62445 ----a-w- C:\Users\Hugo\AppData\Roaming\PCDr\Update\Rules\e0c6db4a-cf54-44df-9253-018e24c21f97\withSigneddll-PCDoctor_6422.40_windows_appupdaterrules_dell\withSigneddll-PCDoctor_6422.40_windows_appupdaterrules_dell.zip 2014-12-31 13:05:46 A1FE3E89F1A3B31EF0820EF374592252 62445 ----a-w- C:\Users\Hugo\AppData\Roaming\PCDr\Update\Rules\e52f0ea0-428b-4edc-ac9d-d4e816a0b277\withSigneddll-PCDoctor_6422.40_windows_appupdaterrules_dell\withSigneddll-PCDoctor_6422.40_windows_appupdaterrules_dell.zip 2014-12-31 13:05:42 1D9B575A4DE26B262EA8C76109CCFB1D 59018 ----a-w- C:\Users\Hugo\AppData\Roaming\PCDr\Update\Rules\151c1c62-4a34-45ee-ab84-c284f84d4715\appupdaterrules_dell\appupdaterrules_dell.zip 2014-12-30 13:13:11 A1FE3E89F1A3B31EF0820EF374592252 62445 ----a-w- C:\Users\Hugo\AppData\Roaming\PCDr\Update\Rules\7665c79f-acf7-4c8c-a5da-bad2338d684e\withSigneddll-PCDoctor_6422.40_windows_appupdaterrules_dell\withSigneddll-PCDoctor_6422.40_windows_appupdaterrules_dell.zip 2014-12-30 13:13:08 A1FE3E89F1A3B31EF0820EF374592252 62445 ----a-w- C:\Users\Hugo\AppData\Roaming\PCDr\Update\Rules\501c4d94-0f1e-43f4-b156-1041c3b45b22\withSigneddll-PCDoctor_6422.40_windows_appupdaterrules_dell\withSigneddll-PCDoctor_6422.40_windows_appupdaterrules_dell.zip 2014-12-30 13:13:06 A1FE3E89F1A3B31EF0820EF374592252 62445 ----a-w- C:\Users\Hugo\AppData\Roaming\PCDr\Update\Rules\1cb6fdd5-bc97-4383-99b4-fcbeeea41006\withSigneddll-PCDoctor_6422.40_windows_appupdaterrules_dell\withSigneddll-PCDoctor_6422.40_windows_appupdaterrules_dell.zip 2014-12-30 13:13:03 A1FE3E89F1A3B31EF0820EF374592252 62445 ----a-w- C:\Users\Hugo\AppData\Roaming\PCDr\Update\Rules\b9becba7-7c4a-4c0e-b145-8748fb709be3\withSigneddll-PCDoctor_6422.40_windows_appupdaterrules_dell\withSigneddll-PCDoctor_6422.40_windows_appupdaterrules_dell.zip 2014-12-30 13:13:00 A1FE3E89F1A3B31EF0820EF374592252 62445 ----a-w- C:\Users\Hugo\AppData\Roaming\PCDr\Update\Rules\5edb09da-ea7b-481d-a959-c5ee2699ba8b\withSigneddll-PCDoctor_6422.40_windows_appupdaterrules_dell\withSigneddll-PCDoctor_6422.40_windows_appupdaterrules_dell.zip 2014-12-30 13:12:57 1D9B575A4DE26B262EA8C76109CCFB1D 59018 ----a-w- C:\Users\Hugo\AppData\Roaming\PCDr\Update\Rules\1166d673-1497-4746-8138-bb50351987ea\appupdaterrules_dell\appupdaterrules_dell.zip 2014-12-30 13:10:23 A1FE3E89F1A3B31EF0820EF374592252 62445 ----a-w- C:\Users\Hugo\AppData\Roaming\PCDr\Update\Rules\267bf1bd-3c3e-4533-9fad-4ade2a39c092\withSigneddll-PCDoctor_6422.40_windows_appupdaterrules_dell\withSigneddll-PCDoctor_6422.40_windows_appupdaterrules_dell.zip 2014-12-30 13:10:20 A1FE3E89F1A3B31EF0820EF374592252 62445 ----a-w- C:\Users\Hugo\AppData\Roaming\PCDr\Update\Rules\e91f82d9-9f71-4a84-9c71-9edd022c88f3\withSigneddll-PCDoctor_6422.40_windows_appupdaterrules_dell\withSigneddll-PCDoctor_6422.40_windows_appupdaterrules_dell.zip 2014-12-30 13:10:17 A1FE3E89F1A3B31EF0820EF374592252 62445 ----a-w- C:\Users\Hugo\AppData\Roaming\PCDr\Update\Rules\00fe9cec-d9f6-44c1-b699-09f534998eca\withSigneddll-PCDoctor_6422.40_windows_appupdaterrules_dell\withSigneddll-PCDoctor_6422.40_windows_appupdaterrules_dell.zip 2014-12-30 13:10:14 A1FE3E89F1A3B31EF0820EF374592252 62445 ----a-w- C:\Users\Hugo\AppData\Roaming\PCDr\Update\Rules\cbaae909-d949-4755-b5b4-e7a13f5867bc\withSigneddll-PCDoctor_6422.40_windows_appupdaterrules_dell\withSigneddll-PCDoctor_6422.40_windows_appupdaterrules_dell.zip 2014-12-30 13:10:11 A1FE3E89F1A3B31EF0820EF374592252 62445 ----a-w- C:\Users\Hugo\AppData\Roaming\PCDr\Update\Rules\06ac7c63-5f69-4001-a9b0-2057c045860a\withSigneddll-PCDoctor_6422.40_windows_appupdaterrules_dell\withSigneddll-PCDoctor_6422.40_windows_appupdaterrules_dell.zip 2014-12-30 13:09:57 1D9B575A4DE26B262EA8C76109CCFB1D 59018 ----a-w- C:\Users\Hugo\AppData\Roaming\PCDr\Update\Rules\c86082a7-9846-49d2-9b7d-3e2fc15ee2a3\appupdaterrules_dell\appupdaterrules_dell.zip 2014-12-29 18:42:48 CD6FA33EB72869ED58013932813FCD0D 1221496 ----a-w- C:\Users\Hugo\Downloads\dwars-door-frankrijk.zip 2014-12-29 13:08:54 A1FE3E89F1A3B31EF0820EF374592252 62445 ----a-w- C:\Users\Hugo\AppData\Roaming\PCDr\Update\Rules\58b7eb8d-257c-4a43-96eb-321741739e4c\withSigneddll-PCDoctor_6422.40_windows_appupdaterrules_dell\withSigneddll-PCDoctor_6422.40_windows_appupdaterrules_dell.zip 2014-12-29 13:08:51 A1FE3E89F1A3B31EF0820EF374592252 62445 ----a-w- C:\Users\Hugo\AppData\Roaming\PCDr\Update\Rules\047101ff-ade0-4299-b5fd-3d4ad7931280\withSigneddll-PCDoctor_6422.40_windows_appupdaterrules_dell\withSigneddll-PCDoctor_6422.40_windows_appupdaterrules_dell.zip 2014-12-29 13:08:48 A1FE3E89F1A3B31EF0820EF374592252 62445 ----a-w- C:\Users\Hugo\AppData\Roaming\PCDr\Update\Rules\2279aa75-d1e1-477c-9260-71e84e244352\withSigneddll-PCDoctor_6422.40_windows_appupdaterrules_dell\withSigneddll-PCDoctor_6422.40_windows_appupdaterrules_dell.zip 2014-12-29 13:08:45 A1FE3E89F1A3B31EF0820EF374592252 62445 ----a-w- C:\Users\Hugo\AppData\Roaming\PCDr\Update\Rules\204aa417-6d5e-47ec-ba31-212b7a797ecb\withSigneddll-PCDoctor_6422.40_windows_appupdaterrules_dell\withSigneddll-PCDoctor_6422.40_windows_appupdaterrules_dell.zip 2014-12-29 13:08:42 A1FE3E89F1A3B31EF0820EF374592252 62445 ----a-w- C:\Users\Hugo\AppData\Roaming\PCDr\Update\Rules\468c6a5c-7691-4cd5-9f67-ae9e2f9f90cf\withSigneddll-PCDoctor_6422.40_windows_appupdaterrules_dell\withSigneddll-PCDoctor_6422.40_windows_appupdaterrules_dell.zip 2014-12-29 13:08:38 1D9B575A4DE26B262EA8C76109CCFB1D 59018 ----a-w- C:\Users\Hugo\AppData\Roaming\PCDr\Update\Rules\01f04518-d989-4d6b-acf9-f7ba34e9002d\appupdaterrules_dell\appupdaterrules_dell.zip 2014-12-29 13:06:03 A1FE3E89F1A3B31EF0820EF374592252 62445 ----a-w- C:\Users\Hugo\AppData\Roaming\PCDr\Update\Rules\60ae5c8e-f472-4d38-9b3c-03e301140c07\withSigneddll-PCDoctor_6422.40_windows_appupdaterrules_dell\withSigneddll-PCDoctor_6422.40_windows_appupdaterrules_dell.zip 2014-12-29 13:06:00 A1FE3E89F1A3B31EF0820EF374592252 62445 ----a-w- C:\Users\Hugo\AppData\Roaming\PCDr\Update\Rules\91e2c456-6f17-43b6-9692-f7fa87aaf453\withSigneddll-PCDoctor_6422.40_windows_appupdaterrules_dell\withSigneddll-PCDoctor_6422.40_windows_appupdaterrules_dell.zip 2014-12-29 13:05:57 A1FE3E89F1A3B31EF0820EF374592252 62445 ----a-w- C:\Users\Hugo\AppData\Roaming\PCDr\Update\Rules\cf197283-23c4-4dc3-9359-064ee708a557\withSigneddll-PCDoctor_6422.40_windows_appupdaterrules_dell\withSigneddll-PCDoctor_6422.40_windows_appupdaterrules_dell.zip 2014-12-29 13:05:54 A1FE3E89F1A3B31EF0820EF374592252 62445 ----a-w- C:\Users\Hugo\AppData\Roaming\PCDr\Update\Rules\00e2d9f5-15a1-473e-b579-2788e46b856e\withSigneddll-PCDoctor_6422.40_windows_appupdaterrules_dell\withSigneddll-PCDoctor_6422.40_windows_appupdaterrules_dell.zip 2014-12-29 13:05:51 A1FE3E89F1A3B31EF0820EF374592252 62445 ----a-w- C:\Users\Hugo\AppData\Roaming\PCDr\Update\Rules\01bcce8f-a4e6-4688-a66a-54d13a4ead50\withSigneddll-PCDoctor_6422.40_windows_appupdaterrules_dell\withSigneddll-PCDoctor_6422.40_windows_appupdaterrules_dell.zip 2014-12-29 13:05:36 1D9B575A4DE26B262EA8C76109CCFB1D 59018 ----a-w- C:\Users\Hugo\AppData\Roaming\PCDr\Update\Rules\e2524023-27ad-4ff5-b381-5af03bc3ca1f\appupdaterrules_dell\appupdaterrules_dell.zip 2014-12-29 10:06:40 138F6492F066F7DAB4DFE4FB612A574D 1311 ----a-w- C:\Users\Hugo\Documents\folderchk.vbs ==== Startup Registry Enabled ====================== [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "GarminExpressTrayApp"="C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe" [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun" [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun" [HKEY_USERS\S-1-5-21-380040671-3701161090-3446401283-1001\Software\iolo\System Mechanic\Startup Manager\Configuration\Disabled\Registry\HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "msnmsgr"="C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe /background" [HKEY_USERS\S-1-5-21-380040671-3701161090-3446401283-1001\Software\iolo\System Mechanic\Startup Manager\Configuration\Disabled\Registry\HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] "QuickTime Task"="C:\Program Files (x86)\QuickTime\QTTask.exe -atboottime" "Adobe Reader Speed Launcher"="C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" "DATAMNGR"="C:\PROGRA~2\BEARSH~1\MediaBar\Datamngr\DATAMN~1.EXE" "Browser companion helper"="C:\Program Files (x86)\BrowserCompanion\BCHelper.exe /T=3 /CHI=clbfjfbnelcflpgpklppgplejolacbej" [HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run] "GarminExpressTrayApp"="C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe" [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce] "mctadmin"="C:\Windows\System32\mctadmin.exe" [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce] "mctadmin"="C:\Windows\System32\mctadmin.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "StartCCC"="c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe MSRun" "Dell Webcam Central"="C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe /mode2" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] "C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe"="C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe" ==== Startup Registry Enabled x64 ====================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Broadcom Wireless Manager UI"="C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.exe" "QuickSet"="C:\Program Files\Dell\QuickSet\QuickSet.exe" "MSC"="c:\Program Files\Microsoft Security Client\msseces.exe -hide -runkey" "SynTPEnh"="%ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe " "SysTrayApp"="C:\Program Files\IDT\WDM\sttray64.exe" ==== Startup Registry Disabled ====================== [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run-] "HP Software Update"="C:\\Program Files (x86)\\Hp\\HP Software Update\\HPWuSchd2.exe" "TkBellExe"="\"c:\\program files (x86)\\real\\realplayer\\Update\\realsched.exe\" -osboot" "SunJavaUpdateSched"="\"C:\\Program Files (x86)\\Common Files\\Java\\Java Update\\jusched.exe\"" ==== Startup Registry Disabled x64 ====================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\beid] "command"="\"C:\\Program Files (x86)\\Belgium Identity Card\\beid35gui.exe\" /startup" "hkey"="HKLM" "item"="beid" "key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Desktop Disc Tool] "command"="\"c:\\Program Files (x86)\\Roxio\\Roxio Burn\\RoxioBurnLauncher.exe\"" "hkey"="HKLM" "item"="Desktop Disc Tool" "key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\GrooveMonitor] "command"="\"C:\\Program Files (x86)\\Microsoft Office\\Office12\\GrooveMonitor.exe\"" "hkey"="HKLM" "item"="GrooveMonitor" "key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Kaspersky Security Scan.lnk] "backup"="C:\\Windows\\pss\\Kaspersky Security Scan.lnk.CommonStartup" "backupExtension"=".CommonStartup" "command"="C:\\Program Files (x86)\\Kaspersky Security Scan\\KSS.exe" "item"="Kaspersky Security Scan" "path"="C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\Kaspersky Security Scan.lnk" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^RealPlayer Cloud Service UI.lnk] "backup"="C:\\Windows\\pss\\RealPlayer Cloud Service UI.lnk.CommonStartup" "backupExtension"=".CommonStartup" "command"="C:\\Program Files (x86)\\Real\\RealPlayer\\RPDS\\Bin64\\rpsystray.exe" "item"="RealPlayer Cloud Service UI" "path"="C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\RealPlayer Cloud Service UI.lnk" ==== Task Scheduler Jobs ====================== C:\Windows\tasks\Adobe Flash Player Updater.job --a------ C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [10/12/2014 18:05] C:\Windows\tasks\GoogleUpdateTaskMachineCore.job --a------ C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [14/10/2014 20:53] C:\Windows\tasks\GoogleUpdateTaskMachineUA.job --a------ C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [14/10/2014 20:53] C:\Windows\tasks\HP Photo Creations Communicator.job --a------ C:\ProgramData\HP Photo Creations\Communicator.exe [23/08/2011 10:11] ==== Other Scheduled Tasks ====================== "C:\Windows\SysNative\tasks\Adobe Flash Player Updater" [C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe] "C:\Windows\SysNative\tasks\CreateChoiceProcessTask" [C:\Windows\System32\browserchoice.exe] "C:\Windows\SysNative\tasks\Default2Check" [c:\Users\All Users\dtdata\R003.exe] "C:\Windows\SysNative\tasks\DefaultCheck" [c:\Users\All Users\dtdata\R002.exe] "C:\Windows\SysNative\tasks\DefaultReg" [c:\Users\All Users\dtdata\R001.exe] "C:\Windows\SysNative\tasks\GarminUpdaterTask" [C:\Program Files (x86)\Garmin\Express Self Updater\ExpressSelfUpdater.exe] "C:\Windows\SysNative\tasks\GoogleUpdateTaskMachineCore" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe] "C:\Windows\SysNative\tasks\GoogleUpdateTaskMachineUA" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe] "C:\Windows\SysNative\tasks\HP Photo Creations Communicator" [C:\ProgramData\HP Photo Creations\Communicator.exe] "C:\Windows\SysNative\tasks\HP-Online updateprogramma" [C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe] "C:\Windows\SysNative\tasks\HPCustParticipation HP Photosmart Plus B210 series" ["C:\Program Files\HP\HP Photosmart Plus B210 series\Bin\HPCustPartic.exe"] "C:\Windows\SysNative\tasks\Java Update Scheduler" [C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe] "C:\Windows\SysNative\tasks\LoJack for Laptops Install" ["%PROGRAMFILES(x86)%\Absolute Software\LoJack Install\FactoryInstaller.exe"] "C:\Windows\SysNative\tasks\PCDEventLauncherTask" ["C:\Program Files\My Dell\sessionchecker.exe"] "C:\Windows\SysNative\tasks\PCDoctorBackgroundMonitorTask" ["C:\Program Files\My Dell\uaclauncher.exe"] "C:\Windows\SysNative\tasks\Real Player-online actualiseringsprogramma" [c:\program files (x86)\real\realplayer\Update\realsched.exe] "C:\Windows\SysNative\tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-380040671-3701161090-3446401283-1001" [C:\Program Files (x86)\RealNetworks\RealDownloader\realupgrade.exe] "C:\Windows\SysNative\tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-380040671-3701161090-3446401283-1001" [C:\Program Files (x86)\RealNetworks\RealDownloader\realupgrade.exe] "C:\Windows\SysNative\tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-380040671-3701161090-3446401283-1001" [C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe] "C:\Windows\SysNative\tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-380040671-3701161090-3446401283-1001" [C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe] "C:\Windows\SysNative\tasks\RealUpgradeLogonTaskS-1-5-21-380040671-3701161090-3446401283-1001" [C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe] "C:\Windows\SysNative\tasks\RealUpgradeScheduledTaskS-1-5-21-380040671-3701161090-3446401283-1001" [C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe] "C:\Windows\SysNative\tasks\SidebarExecute" [C:\Program Files (x86)\Windows Sidebar\sidebar.exe] "C:\Windows\SysNative\tasks\SystemToolsDailyTest" ["uaclauncher.exe"] "C:\Windows\SysNative\tasks\TuneUpUtilities_Task_BkGndMaintenance2013" [C:\Program Files (x86)\TuneUp Utilities 2013\OneClick.exe] "C:\Windows\SysNative\tasks\{E104EE34-DD4C-4B46-8DDF-B22F5F44DCA5}" [C:\Program Files (x86)\HP\HP Photosmart Plus B210 series\bin\HPScan.exe] "C:\Windows\SysNative\tasks\{E9B04D6F-219A-4665-AA2C-9A00DE57E891}" [C:\Program Files (x86)\HP\HP Photosmart Plus B210 series\bin\HPScan.exe] "C:\Windows\SysNative\tasks\D7R9S1M1\Administrator - Start WLAN Tray Applet" [C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.EXE] "C:\Windows\SysNative\tasks\NCH Software\expresszipShakeIcon" [C:\Program Files (x86)\NCH Software\ExpressZip\ExpressZip.exe] "C:\Windows\SysNative\tasks\NCH Software\PhotoPadReminder" [C:\Program Files (x86)\NCH Software\PhotoPad\PhotoPad.exe] "C:\Windows\SysNative\tasks\NCH Software\pixillionShakeIcon" [C:\Program Files (x86)\NCH Software\Pixillion\Pixillion.exe] ==== Firefox Extensions Registry ====================== [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions] "{1DD9AC48-0855-4AE7-9934-159B4377FFA2}"="C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext" [14/07/2014 20:36] ==== Chromium Look ====================== Google Chrome Version: 39.0.2171.95 (Up to date, latest Stable version: 39.0.2171.95) HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions idhngdhcfkoamngbedgpaokgjbnpdiji - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Chrome\Ext\realdownloader.crx[10/06/2014 16:54] Google Wallet - Hugo\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda RealDownloader - Jessie\AppData\Local\Google\Chrome\User Data\Default\Extensions\idhngdhcfkoamngbedgpaokgjbnpdiji ==== Chromium Startpages ====================== C:\Users\Jessie\AppData\Local\Google\Chrome\User Data\Default\Preferences "homepage": "http://www.google.com", ==== Set IE to Default ====================== Old Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157" New Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157" ==== All HKCU SearchScopes ====================== HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes "DefaultScope"="{6A1806CD-94D4-4689-BA73-E35EA1EA9990}" {012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}" {081230F8-EA50-42A9-983C-D22ABC2EED3B} FreeRIP Url="http://www.qemit.com/toolbar/hub.php?a=sb&did=8&pid=0&lan=nl&day=0&ver=1.01&q={searchTerms}" {6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7SKPT_nlBE425" {9A435D61-E7C2-4D91-B41A-FA549A6D4468} Google Url="http://www.google.nl/search?hl=nl&q={searchTerms}&rlz=1I7SKPT_nlBE425" {A2C5D2EF-091F-42C9-900C-DE11762ABE15} Google Url="http://www.google.nl/search?hl=nl&q={searchTerms}&rlz=1I7SKPT_nlBE425" ==== HijackThis Entries ====================== F2 - REG:system.ini: UserInit=userinit.exe, O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: RealNetworks Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files (x86)\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll O2 - BHO: Aanmeldhulp voor Microsoft-account - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll O4 - HKLM\..\Run: [StartCCC] "c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun O4 - HKLM\..\Run: [Dell Webcam Central] "C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" /mode2 O4 - HKLM\..\RunOnce: ["C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe"] "C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe" O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-18\..\Run: [GarminExpressTrayApp] "C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe" (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [GarminExpressTrayApp] "C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe" (User 'Default user') O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra button: Verzenden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MIF5BA~1\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: Verz&enden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MIF5BA~1\Office12\ONBttnIE.dll O9 - Extra button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll O9 - Extra 'Tools' menuitem: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MIF5BA~1\Office12\REFIEBAR.DLL O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics O16 - DPF: Garmin Communicator Plug-In - https://static.garmincdn.com/gcp/ie/4.0.4.0/GarminAxControl_32.CAB O16 - DPF: {19D6A3D5-EA50-4C3B-88F0-79627C325570} - http://iloapp.mobiele-signaalgevers.be/gallery/executable/IlosoftMultipleImageUpload.dll O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab O16 - DPF: {DC6FEBC5-0A2D-458A-A01B-5DB15EEC4305} - http://webc.mobiele-signaalgevers.be/auth/controls/IlosoftImageUpload.dll O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL O18 - Protocol: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - (no file) O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_0057cbec48a2d7cf\AESTSr64.exe O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing) O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing) O23 - Service: Cron Service for Prey (CronService) - Fork Ltd. - C:\Prey\platform\windows\cronsvc.exe O23 - Service: Dock Login Service (DockLoginService) - Stardock Corporation - C:\Program Files\Dell\DellDock\DockLogin.exe O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing) O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing) O23 - Service: Garmin Core Update Service - Garmin Ltd or its subsidiaries - C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe O23 - Service: Google Updateservice (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe O23 - Service: Google Update-service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing) O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing) O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: NitroPDFReaderDriverCreatorReadSpool3 (NitroReaderDriverReadSpool3) - Nitro PDF Software - C:\Program Files\Common Files\Nitro\Reader\3.0\NitroPDFReaderDriverService3x64.exe O23 - Service: NMSAccess - Unknown owner - C:\Program Files (x86)\Blaze Media Pro\NMSAccess32.exe O23 - Service: O2FLASH - Unknown owner - C:\Windows\system32\DRIVERS\o2flash.exe (file missing) O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: RealNetworks Downloader Resolver Service - Unknown owner - C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe O23 - Service: RealPlayer Cloud Service - RealNetworks, Inc. - c:\program files (x86)\real\realplayer\RPDS\Bin\rpdsvc.exe O23 - Service: RealPlayer Update Service (RealPlayerUpdateSvc) - Unknown owner - C:\Program Files (x86)\Real\UpdateService\RealPlayerUpdateSvc.exe O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing) O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: ServiceLayer - Nokia - C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe O23 - Service: SMServer - SMServer - C:\Windows\SysWOW64\snmvtsvc.exe O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing) O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing) O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing) O23 - Service: Audio Service (STacSV) - IDT, Inc. - C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_0057cbec48a2d7cf\STacSV64.exe O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesService64.exe O23 - Service: TurboBoost - Intel(R) Corporation - C:\Program Files\Intel\TurboBoost\TurboBoost.exe O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing) O23 - Service: Intel(R) Management & Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing) O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing) O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing) O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing) O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRYSVC.EXE O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing) O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing) ==== Empty IE Cache ====================== C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Hugo\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Jessie\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Jessie\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully ==== Empty FireFox Cache ====================== No FireFox Profiles found ==== Empty Chrome Cache ====================== C:\Users\Hugo\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully C:\Users\Jessie\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully ==== Empty All Flash Cache ====================== Flash Cache Emptied Successfully ==== Empty All Java Cache ====================== Java Cache cleared successfully ==== C:\zoek_backup content ====================== ==== Empty Temp Folders ====================== C:\Users\Default\AppData\Local\Temp emptied successfully C:\Users\Default User\AppData\Local\Temp emptied successfully C:\Users\Hugo\AppData\Local\Temp will be emptied at reboot C:\Users\Jessie\AppData\Local\Temp emptied successfully C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully C:\Windows\Temp will be emptied at reboot ==== After Reboot ====================== ==== Empty Temp Folders ====================== C:\Windows\Temp successfully emptied C:\Users\Hugo\AppData\Local\Temp successfully emptied ==== Empty Recycle Bin ====================== C:\$RECYCLE.BIN successfully emptied ==== EOF on za 03/01/2015 at 0:15:38,25 ======================