Zoek.exe v5.0.0.0 Updated 27-01-2015 Tool run by Mourad on di 03-02-2015 at 11:30:21,45. Microsoft Windows 8.1 6.3.9600 x64 Running in: Normal Mode Internet Access Detected Launched: C:\Users\Mourad\Downloads\zoek(1).exe [Scan all users] [Script inserted] [Checkboxes used] ==== System Restore Info ====================== 3-2-2015 11:32:39 Zoek.exe System Restore Point Created Succesfully. ==== Empty Folders Check ====================== C:\PROGRA~3\ALM deleted successfully C:\Users\Mourad\AppData\Local\cache deleted successfully C:\Users\Mourad\AppData\Local\softthinks deleted successfully ==== Deleting CLSID Registry Keys ====================== HKEY_USERS\S-1-5-21-3063571080-120727185-186101101-1002\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00805E79-F62A-772C-912A-75420967BE61} deleted successfully HKEY_USERS\S-1-5-21-3063571080-120727185-186101101-1002\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{00805E79-F62A-772C-912A-75420967BE61} deleted successfully HKEY_USERS\S-1-5-21-3063571080-120727185-186101101-1002\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EF7093C9-C9CA-D638-8C50-0A40F5B208CC} deleted successfully HKEY_USERS\S-1-5-21-3063571080-120727185-186101101-1002\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EF7093C9-C9CA-D638-8C50-0A40F5B208CC} deleted successfully HKEY_USERS\S-1-5-21-3063571080-120727185-186101101-1002\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{482B29E6-87B5-8701-C677-F2ADA89FAFFC} deleted successfully HKEY_USERS\S-1-5-21-3063571080-120727185-186101101-1002\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{482B29E6-87B5-8701-C677-F2ADA89FAFFC} deleted successfully HKEY_USERS\S-1-5-21-3063571080-120727185-186101101-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F4E39681-15F8-4fda-B8A3-B5C98378F2F3} deleted successfully HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{00805E79-F62A-772C-912A-75420967BE61} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{00805E79-F62A-772C-912A-75420967BE61} deleted successfully HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{EF7093C9-C9CA-D638-8C50-0A40F5B208CC} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EF7093C9-C9CA-D638-8C50-0A40F5B208CC} deleted successfully HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{482B29E6-87B5-8701-C677-F2ADA89FAFFC} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{482B29E6-87B5-8701-C677-F2ADA89FAFFC} deleted successfully ==== Deleting CLSID Registry Values ====================== ==== Installed Programs ====================== ęTorrent Adobe AIR Adobe Download Assistant Adobe Flash Player 16 NPAPI Adobe Flash Professional CS6 Adobe Help Manager Adobe Illustrator CS6 Adobe Photoshop CS6 Adobe Reader XI (11.0.10) - Nederlands Adobe Refresh Manager Adobe Widget Browser Apache CouchDB 1.6.0 Apple Application Support Apple Software Update Bonjour Boot2Docker for Windows version 1.4.1 CyberLink LabelPrint 2.5 CyberLink Media Suite 10 CyberLink Media Suite Essentials CyberLink Power2Go 8 CyberLink PowerDirector 10 CyberLink PowerDVD 10 D3DX10 Definition Update for Microsoft Office 2010 (KB2910899) 32-Bit Edition Dell Backup and Recovery Dell Digital Delivery Dell System Detect Dell System Detect Bootstrapper Dell Touchpad Dropbox Git version 1.9.4-preview20140929 GlassFish Server Open Source Edition 4.0 GlassFish Server Open Source Edition 4.1 Google Chrome Google Drive Google Talk Plugin Google Update Helper Intel(R) Control Center Intel(R) Management Engine Components Intel(R) PROSet/Wireless for Bluetooth(R) + High Speed Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology Intel(R) Rapid Start Technology Intel(R) Rapid Storage Technology Intel© Hardware Accelerated Execution Manager Intel© PROSet/Wireless WiFi Software Intel© Trusted Connect Service Client Intel© Turbo Boost Technologie monitor 2.6 iTunes Java 8 Update 31 Java 8 Update 31 (64-bit) Java Auto Updater Java SE Development Kit 8 Update 31 (64-bit) McAfee AntiVirus Plus McAfee SiteAdvisor Microsoft Application Error Reporting Microsoft Office Access MUI (Dutch) 2010 Microsoft Office Excel MUI (Dutch) 2010 Microsoft Office Home and Student 2010 Microsoft Office Office 64-bit Components 2010 Microsoft Office OneNote MUI (Dutch) 2010 Microsoft Office Outlook MUI (Dutch) 2010 Microsoft Office PowerPoint MUI (Dutch) 2010 Microsoft Office Proof (Dutch) 2010 Microsoft Office Proof (English) 2010 Microsoft Office Proof (French) 2010 Microsoft Office Proof (German) 2010 Microsoft Office Proofing (Dutch) 2010 Microsoft Office Publisher MUI (Dutch) 2010 Microsoft Office Shared 64-bit MUI (Dutch) 2010 Microsoft Office Shared MUI (Dutch) 2010 Microsoft Office Single Image 2010 Microsoft Office Word MUI (Dutch) 2010 Microsoft Silverlight Microsoft SQL Server 2005 Compact Edition [ENU] Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 Microsoft_VC80_CRT_x86 Microsoft_VC90_CRT_x86 Movie Maker Mozilla Firefox 35.0.1 (x86 nl) Mozilla Maintenance Service MSVCRT MSVCRT110 MSVCRT110_amd64 My Dell MySQL Connector C++ 1.1.3 MySQL Connector J MySQL Connector Net 6.7.4 MySQL Connector/ODBC 5.2 MySQL Documents 5.6 MySQL Examples and Samples 5.6 MySQL For Excel 1.1.3 MySQL Installer MySQL Notifier 1.1.4 MySQL Server 5.6 MySQL Utilities MySQL Workbench 6.0 CE NetBeans IDE 7.4 NetBeans IDE 8.0 NetBeans IDE 8.0.2 Node.js Notepad++ NVIDIA-configuratiescherm 327.02 NVIDIA 3D Vision controllerstuurprogramma 326.01 NVIDIA 3D Vision stuurprogramma 327.02 NVIDIA Grafisch stuurprogramma 327.02 NVIDIA HD Audio-stuurprogramma 1.3.26.4 NVIDIA Install Application NVIDIA Stereoscopic 3D Driver NVIDIA Update 1.10.8 NVIDIA Update Components Oracle VM VirtualBox 4.3.20 PDF Architect 2 PDF Architect 2 View Module PDF Settings CS6 PDFCreator Photo Common Photo Gallery Prepros 4.2.0 Quickset64 Rapport Realtek Card Reader Secure Download Manager Security Update for Microsoft Excel 2010 (KB2910902) 32-Bit Edition Security Update for Microsoft Office 2010 (KB2553154) 32-Bit Edition Security Update for Microsoft Office 2010 (KB2553284) 32-Bit Edition Security Update for Microsoft Office 2010 (KB2687423) 32-Bit Edition Security Update for Microsoft Office 2010 (KB2760781) 32-Bit Edition Security Update for Microsoft Office 2010 (KB2810073) 32-Bit Edition Security Update for Microsoft Office 2010 (KB2850016) 32-Bit Edition Security Update for Microsoft Office 2010 (KB2880971) 32-Bit Edition Security Update for Microsoft Office 2010 (KB2881071) 32-Bit Edition Security Update for Microsoft Word 2010 (KB2899519) 32-Bit Edition Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition Shared C Run-time for x64 System Requirements Lab for Intel tools-linux tools-windows Trusteer Eindpuntbeveiliging Update for Microsoft Access 2010 (KB2553446) 32-Bit Edition Update for Microsoft Excel 2010 (KB2589348) 32-Bit Edition Update for Microsoft Filter Pack 2.0 (KB2878281) 32-Bit Edition Update for Microsoft InfoPath 2010 (KB2817369) 32-Bit Edition Update for Microsoft Office 2010 (KB2553140) 32-Bit Edition Update for Microsoft Office 2010 (KB2589298) 32-Bit Edition Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition Update for Microsoft Office 2010 (KB2589375) 32-Bit Edition Update for Microsoft Office 2010 (KB2589386) 32-Bit Edition Update for Microsoft Office 2010 (KB2597087) 32-Bit Edition Update for Microsoft Office 2010 (KB2597089) 32-Bit Edition Update for Microsoft Office 2010 (KB2687275) 32-Bit Edition Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition Update for Microsoft Office 2010 (KB2794737) 32-Bit Edition Update for Microsoft Office 2010 (KB2825635) 32-Bit Edition Update for Microsoft Office 2010 (KB2837581) 32-Bit Edition Update for Microsoft Office 2010 (KB2837602) 32-Bit Edition Update for Microsoft Office 2010 (KB2837606) 32-Bit Edition Update for Microsoft Office 2010 (KB2883019) 32-Bit Edition Update for Microsoft Office 2010 (KB2889818) 32-Bit Edition Update for Microsoft Office 2010 (KB2889828) 32-Bit Edition Update for Microsoft Office 2010 (KB2910896) 32-Bit Edition Update for Microsoft OneNote 2010 (KB2597088) 32-Bit Edition Update for Microsoft Outlook 2010 (KB2687567) 32-Bit Edition Update for Microsoft PowerPoint 2010 (KB2880517) 32-Bit Edition Update for Microsoft SharePoint Workspace 2010 (KB2760601) 32-Bit Edition Update for Microsoft Visio 2010 (KB2880526) 32-Bit Edition Update for Microsoft Visio Viewer 2010 (KB2837587) 32-Bit Edition Video Download Capture V4.3.0 VLC media player 2.1.1 VMware Player VoiceOver Kit Windows 7 USB/DVD Download Tool Windows Live Communications Platform Windows Live Essentials Windows Live Installer Windows Live Photo Common Windows Live PIMT Platform Windows Live SOXE Windows Live SOXE Definitions Windows Live UX Platform Windows Live UX Platform Language Pack ==== Running Processes ====================== C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe D:\CouchDB\erts-5.10.3\bin\erlsrv.exe D:\CouchDB\erts-5.10.3\bin\erl.exe D:\CouchDB\ERTS-5~1.3\bin\epmd.exe C:\Windows\SysWOW64\irstrtsv.exe C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe C:\WINDOWS\SysWOW64\vmnat.exe C:\Program Files (x86)\VMware\VMware Player\vmware-authd.exe C:\WINDOWS\SysWOW64\vmnetdhcp.exe d:\CouchDB\lib\os_mon-2.2.13\priv\bin\win32sysinfo.exe C:\Program Files (x86)\Intel\irstrt\RapidStartConfig.exe C:\Program Files (x86)\Google\Update\1.3.25.11\GoogleCrashHandler.exe C:\Program Files (x86)\Google\Drive\googledrivesync.exe C:\Program Files (x86)\Trusteer\Rapport\bin\RapportService.exe C:\Program Files (x86)\Google\Drive\googledrivesync.exe C:\Users\Mourad\AppData\Roaming\Dropbox\bin\Dropbox.exe D:\iTunesHelper.exe C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE C:\WINDOWS\syswow64\wwahost.exe C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe C:\Program Files (x86)\Dell Backup and Recovery\sftservice.exe C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe C:\Program Files (x86)\Dell Backup and Recovery\COMPONENTS\DBRUPDATE\DBRUPD.EXE C:\Program Files (x86)\Dell Backup and Recovery\TOASTER.EXE C:\Users\Mourad\Downloads\zoek(1).exe C:\WINDOWS\SysWOW64\cmd.exe C:\WINDOWS\SysWOW64\cmd.exe C:\WINDOWS\SysWOW64\cmd.exe c:\PROGRA~2\mcafee\SITEAD~1\saui.exe ==== Deleting Services ====================== ==== FireFox Fix ====================== Deleted from C:\Users\Mourad\AppData\Roaming\Mozilla\Firefox\Profiles\0\prefs.js: Added to C:\Users\Mourad\AppData\Roaming\Mozilla\Firefox\Profiles\0\prefs.js: user_pref("browser.startup.homepage", "about:home"); user_pref("browser.newtab.url", "about:newtab"); Deleted from C:\Users\Mourad\AppData\Roaming\Mozilla\Firefox\Profiles\xvq7urvn.default\prefs.js: Added to C:\Users\Mourad\AppData\Roaming\Mozilla\Firefox\Profiles\xvq7urvn.default\prefs.js: user_pref("browser.startup.homepage", "about:home"); user_pref("browser.newtab.url", "about:newtab"); ProfilePath: C:\Users\Mourad\AppData\Roaming\Mozilla\Firefox\Profiles\0 user.js not found ---- FireFox user.js and prefs.js backups ---- prefs_03-02-2015_1154_.backup ProfilePath: C:\Users\Mourad\AppData\Roaming\Mozilla\Firefox\Profiles\xvq7urvn.default user.js not found ---- Lines astrmndasr removed from prefs.js ---- user_pref("extensions.astrmndasr.aflt", "ast_wnzp01_14_40_ff"); user_pref("extensions.astrmndasr.AL", 0); user_pref("extensions.astrmndasr.appId", "{9CB2CD61-FFA0-406C-9D2D-8FDE6F4A4D8A}"); user_pref("extensions.astrmndasr.cd", "2XzuyEtN2Y1L1QzuyCtDtAyC0D0DtB0DtB0EzztBtAzzyC0DtN0D0Tzu0StCtDtDzytN1L2XzutAtFtBtFtCtFyDtN1L1CzutCyEtBzytDyD1V1 user_pref("extensions.astrmndasr.cr", "1299174204"); user_pref("extensions.astrmndasr.dfltLng", ""); user_pref("extensions.astrmndasr.dfltSrch", true); user_pref("extensions.astrmndasr.dnsErr", true); user_pref("extensions.astrmndasr.excTlbr", false); user_pref("extensions.astrmndasr.hmpg", true); user_pref("extensions.astrmndasr.id", "6036DD2D2E82386D"); user_pref("extensions.astrmndasr.instlDay", "16348"); user_pref("extensions.astrmndasr.instlRef", "142905_a"); user_pref("extensions.astrmndasr.prdct", "astrmndasr"); user_pref("extensions.astrmndasr.tlbrId", ""); user_pref("extensions.astrmndasr.vrsn", ""); user_pref("extensions.astrmndasr.vrsni", ""); user_pref("extensions.astrmndasr_i.newTab", true); user_pref("extensions.astrmndasr_i.smplGrp", "none"); user_pref("extensions.astrmndasr_i.vrsnTs", "21:8:30"); ---- FireFox user.js and prefs.js backups ---- prefs_03-02-2015_1154_.backup ==== Registry Fix Code x64 ====================== Windows Registry Editor Version 5.00 [-HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{00805E79-F62A-772C-912A-75420967BE61}] [-HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{482B29E6-87B5-8701-C677-F2ADA89FAFFC}] [-HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EF7093C9-C9CA-D638-8C50-0A40F5B208CC}] ==== Deleting Files \ Folders ====================== C:\ProgramData\Zoomex not found C:\Program Files (x86)\Torntv V6.0 not found C:\PROGRA~3\WoW Worldwide Software LTD deleted C:\Users\Mourad\.android deleted C:\prefs.js deleted C:\PROGRA~3\InstallMate deleted C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Search.lnk deleted C:\Users\Mourad\Downloads\adt-bundle-windows-x86_64-20131030.zip deleted C:\WINDOWS\tasks\Torntv V6.0-firefoxinstaller.job deleted C:\windows\SysNative\tasks\Torntv V6.0-firefoxinstaller deleted C:\windows\SysNative\tasks\ZoomExUpdaterTask{FA9BA2C8-C96F-410A-8917-A9829B88863C} deleted C:\WINDOWS\tasks\ZoomExUpdaterTask{FA9BA2C8-C96F-410A-8917-A9829B88863C}.job deleted "C:\DelFix.txt" deleted ==== System Specs ====================== Windows: Windows Version 6.2 (Build 9200) Memory (RAM): 8120 MB CPU Info: Intel(R) Core(TM) i7-3630QM CPU @ 2.40GHz CPU Speed: 2395,8 MHz Sound Card: Luidsprekers (Apowersoft_AudioD | Display Adapters: NVIDIA GeForce GT 650M | NVIDIA GeForce GT 650M | NVIDIA GeForce GT 650M | NVIDIA GeForce GT 650M Monitors: 1x; Generic PnP Monitor | Screen Resolution: 1920 X 1080 - 32 bit Network: Network Present Network Adapters: Microsoft Wi-Fi Direct Virtual Adapter | Realtek PCIe FE Family-controller | Intel(R) Centrino(R) Wireless-N 2230 | VMware Virtual Ethernet Adapter for VMnet1 | VMware Virtual Ethernet Adapter for VMnet8 | VirtualBox Host-Only Ethernet Adapter | VirtualBox Host-Only Ethernet Adapter #2 CD / DVD Drives: 1x (E: | ) E: HL-DT-STDVDRWBD CT40N Ports: COM Ports NOT Present. LPT Port NOT Present. Mouse: 16 Button Wheel Mouse Present Hard Disks: C: 646,5GB | D: 698,5GB | X: 11,9GB | Y: 500,0MB Hard Disks - Free: C: 530,0GB | D: 694,5GB | X: 284,0MB | Y: 218,6MB Manufacturer *: Dell Inc. BIOS Info: AT/AT COMPATIBLE | | DELL - 2 Time Zone: West-Europa (standaardtijd) Motherboard *: Dell Inc. 00MT1R Country: Nederland Language: NLD ==== System Specs (Software) ====================== Anti-Virus: McAfee Antivirus en antispyware On-access scanning disabled (Outdated) Anti-Virus: Windows Defender On-access scanning disabled (Outdated) Anti-Spyware: McAfee Antivirus en antispyware disabled (Outdated) Anti-Spyware: Windows Defender disabled (Outdated) Firewall: McAfee Firewall disabled Default Browser: Firefox 35.0.1 Internet Explorer Version: 11.0.9600.17498 Mozilla Firefox version: 35.0.1 (x86 nl) Google Chrome version: 40.0.2214.93 Adobe Reader version: 11.0.10.32 Sun Java version: 1.8.0_31 (32-bit) Sun Java version: 1.8.0_31 (64-bit) Flash Player version: 16.0.0.296 ==== Files Recently Created / Modified ====================== ====== C:\WINDOWS ==== ====== C:\Users\Mourad\AppData\Local\Temp ==== 2015-02-03 09:23:37 97511FE2CA09CC2E06C3CD6519C3494E 43008 ----a-w- C:\Users\Mourad\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpaensq5.dll 2015-01-27 17:51:12 E07AD3AA0A179D0CD171760BB7C3C71F 22869088 ----a-w- C:\Users\Mourad\AppData\Local\Temp\tmpdunjmg\googledrivesync.exe ====== Java Cache ===== 2015-02-03 09:42:18 E8B5776652AC64D5A7E813FFDF154A90 424 ----a-w- C:\Users\Mourad\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\17\49a00451-aa56bb018d5de3a531ee91cc4857f0f479656e5370ebf87789e721aaaf530ebc-6.0.lap 2015-02-03 09:42:17 415FC9732A3F4D89A0E01251CD66E136 646 ----a-w- C:\Users\Mourad\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\18\3cb32f52-75f6d7a1 ====== C:\WINDOWS\SysWOW64 ===== 2015-02-03 09:28:12 13D186FA6F19823C598335443CE233BC 98216 ----a-w- C:\WINDOWS\SysWOW64\WindowsAccessBridge-32.dll ====== C:\WINDOWS\SysWOW64\drivers ===== ====== C:\WINDOWS\Sysnative ===== 2015-02-03 10:20:52 BD6CF5354EAE95D6C2807E6DAE79D3FF 111016 ----a-w- C:\WINDOWS\Sysnative\WindowsAccessBridge-64.dll ====== C:\WINDOWS\Sysnative\drivers ===== 2015-02-03 10:44:25 2A801DFB1C278104D6AFB23C456C0E89 916024 ----a-w- C:\WINDOWS\Sysnative\drivers\VBoxDrv.sys 2015-02-03 10:44:12 46970F66C3F19421C37CCCDC7C2F176A 128080 ----a-w- C:\WINDOWS\Sysnative\drivers\VBoxUSBMon.sys 2015-01-14 10:30:14 F0CB6DB513CAC393D04A0FCE0A59E1BF 75776 ----a-w- C:\WINDOWS\Sysnative\drivers\ahcache.sys 2015-01-14 10:30:14 DB32958F0E704EFBF7F15161A569E39F 140800 ----a-w- C:\WINDOWS\Sysnative\drivers\mrxdav.sys ====== C:\WINDOWS\Tasks ====== ====== C:\WINDOWS\Temp ====== ======= C:\Program Files ===== 2015-02-03 10:44:09 -------- d-----w- C:\Program Files\Oracle 2015-02-03 08:23:06 -------- d-----w- C:\Program Files\trend micro ======= C:\PROGRA~2 ===== 2015-02-03 09:28:13 -------- d-----w- C:\PROGRA~2\COMMON~1\Java ======= C: ===== ====== C:\Users\Mourad\AppData\Roaming ====== 2015-01-19 11:47:33 -------- d-----w- C:\Users\Mourad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows 7 USB DVD Download Tool ====== C:\Users\Mourad ====== 2015-02-03 10:51:15 -------- d-----w- C:\Users\Mourad\VirtualBox VMs 2015-02-03 10:51:14 -------- d-----w- C:\Users\Mourad\.VirtualBox 2015-02-03 10:51:14 -------- d-----w- C:\Users\Mourad\.ssh 2015-02-03 10:51:13 -------- d-----w- C:\Users\Mourad\.boot2docker 2015-02-03 10:44:49 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Docker 2015-02-03 10:44:25 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Oracle VM VirtualBox 2015-02-03 10:41:38 873A0D6E06186E0FCBC4F587A0689F27 127942912 ----a-w- C:\Users\Mourad\Downloads\docker-install.exe 2015-02-03 10:19:22 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java Development Kit 2015-02-03 10:18:10 B499D326511AAC7EEA2F74D81B72E7F6 178639264 ----a-w- C:\Users\Mourad\Downloads\jdk-8u31-windows-x64.exe 2015-02-03 09:27:52 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2015-02-03 09:20:28 -------- d-----w- C:\ProgramData\Sun 2015-02-03 09:13:16 6713E17AFCB3A28191A747DC8C475721 639912 ----a-w- C:\Users\Mourad\Downloads\jxpiinstall.exe 2015-02-03 08:22:40 8045ABB21A3BDD66A48E1ED5C0F0EF6A 1222144 ----a-w- C:\Users\Mourad\Downloads\RSITx64.exe ====== C: exe-files == 2015-02-03 10:41:38 873A0D6E06186E0FCBC4F587A0689F27 127942912 ----a-w- C:\Users\Mourad\Downloads\docker-install.exe 2015-02-03 10:20:32 FA78A9BBAF7352401B7F982464160448 16808 ----a-w- C:\Program Files\Java\jre1.8.0_31\bin\rmiregistry.exe 2015-02-03 10:20:32 F951A8D249C943E7ECDF66D2FE16CDCD 191400 ----a-w- C:\Program Files\Java\jre1.8.0_31\bin\javaw.exe 2015-02-03 10:20:32 F40410CE27DE0823A93B2BD4BFE4F3F6 319912 ----a-w- C:\Program Files\Java\jre1.8.0_31\bin\javaws.exe 2015-02-03 10:20:32 F37694550A132DB95F52A14D65C3BF7D 16296 ----a-w- C:\Program Files\Java\jre1.8.0_31\bin\kinit.exe 2015-02-03 10:20:32 F1D678998EDEAE9DF3300E6521A119F2 77224 ----a-w- C:\Program Files\Java\jre1.8.0_31\bin\javacpl.exe 2015-02-03 10:20:32 CB836597AE26F0D031CF7A0C934EC218 16296 ----a-w- C:\Program Files\Java\jre1.8.0_31\bin\pack200.exe 2015-02-03 10:20:32 C7FDEF85040A4602C3547E4C5B700CF9 15784 ----a-w- C:\Program Files\Java\jre1.8.0_31\bin\keytool.exe 2015-02-03 10:20:32 B9BAB51EDBBF27E480A07F904124F810 197544 ----a-w- C:\Program Files\Java\jre1.8.0_31\bin\unpack200.exe 2015-02-03 10:20:32 B53F3B97AA13A200F8DB5BFA2684F953 16808 ----a-w- C:\Program Files\Java\jre1.8.0_31\bin\servertool.exe 2015-02-03 10:20:32 B4614F21174A2F1DAA5394062885C8E5 16296 ----a-w- C:\Program Files\Java\jre1.8.0_31\bin\ktab.exe 2015-02-03 10:20:32 886C21FEA39553EA786355C58379AB75 16296 ----a-w- C:\Program Files\Java\jre1.8.0_31\bin\tnameserv.exe 2015-02-03 10:20:32 713DBD861EC396B286A1970A4F0F6951 16808 ----a-w- C:\Program Files\Java\jre1.8.0_31\bin\policytool.exe 2015-02-03 10:20:32 5657E104B156F043BC002C3EDC1C79E4 16296 ----a-w- C:\Program Files\Java\jre1.8.0_31\bin\orbd.exe 2015-02-03 10:20:32 4AE110AC85558EF04CB3677754A98427 66472 ----a-w- C:\Program Files\Java\jre1.8.0_31\bin\ssvagent.exe 2015-02-03 10:20:32 3B65C09A8A823334CE0EB9AA3F9BDFE5 15784 ----a-w- C:\Program Files\Java\jre1.8.0_31\bin\rmid.exe 2015-02-03 10:20:32 12B174AA182C0C98ACAE637EEA9C52A0 190888 ----a-w- C:\Program Files\Java\jre1.8.0_31\bin\java.exe 2015-02-03 10:20:32 0F19A5EE1E440C0F05554FA3A48EF000 100264 ----a-w- C:\Program Files\Java\jre1.8.0_31\bin\jp2launcher.exe 2015-02-03 10:20:32 06CE06172AA1185E701647429A9C18C9 15784 ----a-w- C:\Program Files\Java\jre1.8.0_31\bin\jjs.exe 2015-02-03 10:20:32 03597BDF891C9FDB3A4F1C2DA591A4C4 16296 ----a-w- C:\Program Files\Java\jre1.8.0_31\bin\klist.exe 2015-02-03 10:20:31 6E23278A38DCB78C29B19386B1D509DC 34216 ----a-w- C:\Program Files\Java\jre1.8.0_31\bin\jabswitch.exe 2015-02-03 10:20:31 1125B37F1D6BAF143AF129831B06D1BD 15784 ----a-w- C:\Program Files\Java\jre1.8.0_31\bin\java-rmi.exe 2015-02-03 10:19:11 85D231F805EBF607A302181D4B310380 158600 ----a-w- C:\Program Files\Java\jdk1.8.0_31\lib\visualvm\platform\lib\nbexec.exe 2015-02-03 10:19:11 1440D0458DC074CDFEFEF6749099823B 216968 ----a-w- C:\Program Files\Java\jdk1.8.0_31\lib\visualvm\platform\lib\nbexec64.exe 2015-02-03 10:19:07 D5FA8E44D397EE6287C64EDF46FC8B0A 197512 ----a-w- C:\Program Files\Java\jdk1.8.0_31\jre\bin\unpack200.exe 2015-02-03 10:19:07 D1A54D502771DB0B2430E20BAFBA1621 16776 ----a-w- C:\Program Files\Java\jdk1.8.0_31\jre\bin\servertool.exe 2015-02-03 10:19:07 9FAACFFB0A70ABFBE86AFD49B87890F0 16264 ----a-w- C:\Program Files\Java\jdk1.8.0_31\jre\bin\tnameserv.exe 2015-02-03 10:19:07 28D722C096764DE42A13595636B37550 66440 ----a-w- C:\Program Files\Java\jdk1.8.0_31\jre\bin\ssvagent.exe 2015-02-03 10:19:06 D8A7441B3DD5D269B3942777FFECFCEC 15752 ----a-w- C:\Program Files\Java\jdk1.8.0_31\jre\bin\keytool.exe 2015-02-03 10:19:06 C7A068FD569B9525B95245F29041CEC7 100232 ----a-w- C:\Program Files\Java\jdk1.8.0_31\jre\bin\jp2launcher.exe 2015-02-03 10:19:06 921E4A6177CEF3472DCDC2F8B316B179 16776 ----a-w- C:\Program Files\Java\jdk1.8.0_31\jre\bin\rmiregistry.exe 2015-02-03 10:19:06 80B375FF19BD81207A446FA7BC66DA03 16776 ----a-w- C:\Program Files\Java\jdk1.8.0_31\jre\bin\policytool.exe 2015-02-03 10:19:06 7B7DDD4AC1C0144D114B182FC748A8D7 16264 ----a-w- C:\Program Files\Java\jdk1.8.0_31\jre\bin\kinit.exe 2015-02-03 10:19:06 719130369394993ECB082C661223BEAD 16264 ----a-w- C:\Program Files\Java\jdk1.8.0_31\jre\bin\ktab.exe 2015-02-03 10:19:06 5DFE0704D3563D91A943C9D1FD079757 16264 ----a-w- C:\Program Files\Java\jdk1.8.0_31\jre\bin\orbd.exe 2015-02-03 10:19:06 56D4DA7908FBFC633F2F1C323CBC3891 15752 ----a-w- C:\Program Files\Java\jdk1.8.0_31\jre\bin\rmid.exe 2015-02-03 10:19:06 4EFC0ED34FC49979DC2ABD46399F6AEA 15752 ----a-w- C:\Program Files\Java\jdk1.8.0_31\jre\bin\jjs.exe 2015-02-03 10:19:06 1D5D9C2DB042E0A5E9F6A0484F727BBF 16264 ----a-w- C:\Program Files\Java\jdk1.8.0_31\jre\bin\pack200.exe 2015-02-03 10:19:06 12817B942F47B7D462C02CD5DF2830B8 16264 ----a-w- C:\Program Files\Java\jdk1.8.0_31\jre\bin\klist.exe 2015-02-03 10:19:03 FD680E882065529A70F3E9548AC5F2EA 77192 ----a-w- C:\Program Files\Java\jdk1.8.0_31\jre\bin\javacpl.exe 2015-02-03 10:19:03 F7C6757D78B7715AEE683CB466EBDE21 16776 ----a-w- C:\Program Files\Java\jdk1.8.0_31\bin\rmiregistry.exe 2015-02-03 10:19:03 F754AE533AE877E7349FE1EFA1268E7E 16264 ----a-w- C:\Program Files\Java\jdk1.8.0_31\bin\appletviewer.exe 2015-02-03 10:19:03 EED843556A79C4BC656E03FB517F8B8A 15752 ----a-w- C:\Program Files\Java\jdk1.8.0_31\bin\javap.exe 2015-02-03 10:19:03 E6278C1963F7DFD77F18807E89041BD8 15752 ----a-w- C:\Program Files\Java\jdk1.8.0_31\bin\javadoc.exe 2015-02-03 10:19:03 E36E3EB63385C6CA8D9B75E8D8A6DC7E 15752 ----a-w- C:\Program Files\Java\jdk1.8.0_31\bin\jps.exe 2015-02-03 10:19:03 E16306AF356F426C3C60403D7B7FE796 94600 ----a-w- C:\Program Files\Java\jdk1.8.0_31\bin\javafxpackager.exe 2015-02-03 10:19:03 DDDC300E8CA40AC1F7DB64B83C27558D 15752 ----a-w- C:\Program Files\Java\jdk1.8.0_31\bin\keytool.exe 2015-02-03 10:19:03 DA91EAC495F9536F06B70237F8272238 15752 ----a-w- C:\Program Files\Java\jdk1.8.0_31\bin\java-rmi.exe 2015-02-03 10:19:03 D7D8ADFD09BDC0EC27A7853ADF5AA5E6 15752 ----a-w- C:\Program Files\Java\jdk1.8.0_31\bin\javac.exe 2015-02-03 10:19:03 D3A5ED999530962AFD17209F55010515 16264 ----a-w- C:\Program Files\Java\jdk1.8.0_31\bin\idlj.exe 2015-02-03 10:19:03 D117FC472F72C2C4000267EB11E3945E 16264 ----a-w- C:\Program Files\Java\jdk1.8.0_31\bin\extcheck.exe 2015-02-03 10:19:03 CF513760CE8EA38EA7C3BB7BD760514D 94600 ----a-w- C:\Program Files\Java\jdk1.8.0_31\bin\javapackager.exe 2015-02-03 10:19:03 C8BEC1D4017A6F2B7B6A6B6CADD6780C 15752 ----a-w- C:\Program Files\Java\jdk1.8.0_31\bin\javah.exe 2015-02-03 10:19:03 C66437266EE2D1095D9B871D49DE4A10 16776 ----a-w- C:\Program Files\Java\jdk1.8.0_31\bin\servertool.exe 2015-02-03 10:19:03 C1021311FAB535114F8927DEE1A302B7 15752 ----a-w- C:\Program Files\Java\jdk1.8.0_31\bin\jdeps.exe 2015-02-03 10:19:03 BA3919DE65057F2C55B33C4BB36E972C 15752 ----a-w- C:\Program Files\Java\jdk1.8.0_31\bin\rmid.exe 2015-02-03 10:19:03 B7A32C3B401100FE1116D6F49EA9816D 190856 ----a-w- C:\Program Files\Java\jdk1.8.0_31\jre\bin\java.exe 2015-02-03 10:19:03 B415EA866D12060CB5997DEB1D861ECE 16264 ----a-w- C:\Program Files\Java\jdk1.8.0_31\bin\jinfo.exe 2015-02-03 10:19:03 B2A5A530F40B355E821DD98D6CFA48ED 15752 ----a-w- C:\Program Files\Java\jdk1.8.0_31\bin\wsgen.exe 2015-02-03 10:19:03 B26CDFF8BC08E3AECCDFFF01332A948E 16264 ----a-w- C:\Program Files\Java\jdk1.8.0_31\bin\serialver.exe 2015-02-03 10:19:03 B1CABD28AAEE6AA5E5BACEB2EE5690D3 191368 ----a-w- C:\Program Files\Java\jdk1.8.0_31\jre\bin\javaw.exe 2015-02-03 10:19:03 B109DD496319A43D1ABF2C3546E2628C 190856 ----a-w- C:\Program Files\Java\jdk1.8.0_31\bin\java.exe 2015-02-03 10:19:03 AF5BCA6D2CD54D4E98346AE028A1B999 15752 ----a-w- C:\Program Files\Java\jdk1.8.0_31\bin\rmic.exe 2015-02-03 10:19:03 AF51E76EE88D1F40163FAE42CE388F6D 16264 ----a-w- C:\Program Files\Java\jdk1.8.0_31\bin\jstack.exe 2015-02-03 10:19:03 9BA93D4A6EAAA598928B9837D7B692F6 16776 ----a-w- C:\Program Files\Java\jdk1.8.0_31\bin\native2ascii.exe 2015-02-03 10:19:03 9B8B9C9C34E1A472983DDCC18487E834 15752 ----a-w- C:\Program Files\Java\jdk1.8.0_31\bin\jjs.exe 2015-02-03 10:19:03 98FA3DD590E0728D2A9FB9DEBC4A5024 16264 ----a-w- C:\Program Files\Java\jdk1.8.0_31\bin\ktab.exe 2015-02-03 10:19:03 98B41A4533418E614579E77583392C9F 321928 ----a-w- C:\Program Files\Java\jdk1.8.0_31\bin\jmc.exe 2015-02-03 10:19:03 96CCB20149139864BEE8A0B81E7FD0FE 15752 ----a-w- C:\Program Files\Java\jdk1.8.0_31\jre\bin\java-rmi.exe 2015-02-03 10:19:03 9026AAA9045E835DD9C6AD22490245FD 16264 ----a-w- C:\Program Files\Java\jdk1.8.0_31\bin\klist.exe 2015-02-03 10:19:03 8E871DA326372A15CBF86BBA5A36FE56 16264 ----a-w- C:\Program Files\Java\jdk1.8.0_31\bin\wsimport.exe 2015-02-03 10:19:03 8C0A9722B6F9182C7550F51FEB39D6E3 197000 ----a-w- C:\Program Files\Java\jdk1.8.0_31\bin\jvisualvm.exe 2015-02-03 10:19:03 7E5BF9345D59EE6DA5915EE1B12899B1 16264 ----a-w- C:\Program Files\Java\jdk1.8.0_31\bin\kinit.exe 2015-02-03 10:19:03 7C9D60723CD3C0C82801FA78DC4A8B99 16264 ----a-w- C:\Program Files\Java\jdk1.8.0_31\bin\schemagen.exe 2015-02-03 10:19:03 7340D3AA5CFC2B5713F4A7F82954539E 16264 ----a-w- C:\Program Files\Java\jdk1.8.0_31\bin\pack200.exe 2015-02-03 10:19:03 5FEB2E3CCE8DBCDE370DB1CB8FA52189 15752 ----a-w- C:\Program Files\Java\jdk1.8.0_31\bin\jar.exe 2015-02-03 10:19:03 5F1ACCB06BD1F13C72F61AE1979029A8 16264 ----a-w- C:\Program Files\Java\jdk1.8.0_31\bin\tnameserv.exe 2015-02-03 10:19:03 5EAA7FA9B9E72553DFF7C0D6125A3CF4 16776 ----a-w- C:\Program Files\Java\jdk1.8.0_31\bin\policytool.exe 2015-02-03 10:19:03 56AA60E1CC41C20816C930EC0B1C89DB 16264 ----a-w- C:\Program Files\Java\jdk1.8.0_31\bin\orbd.exe 2015-02-03 10:19:03 4E04A5092E44EDED35D2F644CA425AFC 15752 ----a-w- C:\Program Files\Java\jdk1.8.0_31\bin\xjc.exe 2015-02-03 10:19:03 48D6C3A2C55B7B06B8D6C084C801D186 16776 ----a-w- C:\Program Files\Java\jdk1.8.0_31\bin\jconsole.exe 2015-02-03 10:19:03 430C1425441A79C912FB30B2CBC395CA 319880 ----a-w- C:\Program Files\Java\jdk1.8.0_31\bin\javaws.exe 2015-02-03 10:19:03 3FE7B6AE5291C91A5C2382F1BF34C435 16776 ----a-w- C:\Program Files\Java\jdk1.8.0_31\bin\jrunscript.exe 2015-02-03 10:19:03 375884657DCFC0A5006FD88A211DE046 16264 ----a-w- C:\Program Files\Java\jdk1.8.0_31\bin\jmap.exe 2015-02-03 10:19:03 374A1B12E6E6434BCE1B1BC1BB5F8897 34184 ----a-w- C:\Program Files\Java\jdk1.8.0_31\bin\jabswitch.exe 2015-02-03 10:19:03 30E30DE9C496A87E9E5B9FFFA0A3D3D6 16264 ----a-w- C:\Program Files\Java\jdk1.8.0_31\bin\jarsigner.exe 2015-02-03 10:19:03 28287FE6AAB74D77CB2425B5EFE96F6A 15752 ----a-w- C:\Program Files\Java\jdk1.8.0_31\bin\jstat.exe 2015-02-03 10:19:03 27A1E6F1CA31CDA0C815D8DD3DD0078E 15752 ----a-w- C:\Program Files\Java\jdk1.8.0_31\bin\jcmd.exe 2015-02-03 10:19:03 275A177AD3E22610B27A1D7DF44F601C 16264 ----a-w- C:\Program Files\Java\jdk1.8.0_31\bin\jsadebugd.exe 2015-02-03 10:19:03 25711FF3C733B6E21D3B12462795D4E0 197512 ----a-w- C:\Program Files\Java\jdk1.8.0_31\bin\unpack200.exe 2015-02-03 10:19:03 24DC5FB01059064D66F251CA906A078C 15752 ----a-w- C:\Program Files\Java\jdk1.8.0_31\bin\jhat.exe 2015-02-03 10:19:03 1713E643335EB203376936C61F245835 15752 ----a-w- C:\Program Files\Java\jdk1.8.0_31\bin\jstatd.exe 2015-02-03 10:19:03 11EC583EA1D0223DB738EA57D8A866B0 319880 ----a-w- C:\Program Files\Java\jdk1.8.0_31\jre\bin\javaws.exe 2015-02-03 10:19:03 0E21D66520FCDD4097D2D470DF38E7EC 34184 ----a-w- C:\Program Files\Java\jdk1.8.0_31\jre\bin\jabswitch.exe 2015-02-03 10:19:03 09A19E0BEEE9D8B9E38F19B4311D0486 191368 ----a-w- C:\Program Files\Java\jdk1.8.0_31\bin\javaw.exe 2015-02-03 10:19:03 02DCA0B01D205A87AC79CEDB52C8DAE0 16264 ----a-w- C:\Program Files\Java\jdk1.8.0_31\bin\jdb.exe 2015-02-03 10:18:10 B499D326511AAC7EEA2F74D81B72E7F6 178639264 ----a-w- C:\Users\Mourad\Downloads\jdk-8u31-windows-x64.exe 2015-02-03 09:27:53 F951A8D249C943E7ECDF66D2FE16CDCD 0 ----a-we C:\ProgramData\Oracle\Java\javapath\javaw.exe 2015-02-03 09:27:53 F40410CE27DE0823A93B2BD4BFE4F3F6 0 ----a-we C:\ProgramData\Oracle\Java\javapath\javaws.exe 2015-02-03 09:27:53 12B174AA182C0C98ACAE637EEA9C52A0 0 ----a-we C:\ProgramData\Oracle\Java\javapath\java.exe 2015-02-03 09:27:47 F9D744CD9BC58F287F8FA59D32508EDD 16296 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_31\bin\orbd.exe 2015-02-03 09:27:47 DBB5C8AE19ACFA2857CFB90C7305AC56 51112 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_31\bin\ssvagent.exe 2015-02-03 09:27:47 DA34E76DE9CD93471F24E7BD43139958 15784 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_31\bin\kinit.exe 2015-02-03 09:27:47 CDB1FE0DCF2ADB755EBF65C8AEBBC871 16296 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_31\bin\servertool.exe 2015-02-03 09:27:47 AF82EA1498FEC5C49B8A1AE5AA0A5F6C 77224 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2launcher.exe 2015-02-03 09:27:47 A8884FB8246655C84F110E77DF5E1B4A 15784 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_31\bin\ktab.exe 2015-02-03 09:27:47 90C02BD6D01BBC1C620323F9E330E89C 15784 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_31\bin\jjs.exe 2015-02-03 09:27:47 8B6DF9CD28359C5E819446FD79CE3948 16296 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_31\bin\rmiregistry.exe 2015-02-03 09:27:47 7479DA0BED071427A3F0017AC51CC27B 159656 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_31\bin\unpack200.exe 2015-02-03 09:27:47 69BD74EE834B5629226BF89468B8020B 15784 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_31\bin\keytool.exe 2015-02-03 09:27:47 5F7C51E0DCA813D647F14FC12AE675F2 16296 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_31\bin\policytool.exe 2015-02-03 09:27:47 577F5DCBA4DE4C345631873670F84E79 16296 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_31\bin\tnameserv.exe 2015-02-03 09:27:47 52C8B9FD016E6317FDB151296FF90877 272296 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_31\bin\javaws.exe 2015-02-03 09:27:47 3E72E1AB196855916E2065C604674631 176552 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_31\bin\javaw.exe 2015-02-03 09:27:47 39685FC75B6FB2144E793595F1AB111D 15784 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_31\bin\pack200.exe 2015-02-03 09:27:47 2F77C9862B1A2401278C4A5B932DA69D 15784 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_31\bin\klist.exe 2015-02-03 09:27:47 0FB2ACAC796B166F6486B593B604A3FF 15784 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_31\bin\rmid.exe 2015-02-03 09:27:46 F5EA785B2BCC08DC28CBC2D96E05F2C1 68520 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_31\bin\javacpl.exe 2015-02-03 09:27:46 DF1C8EDDAF14D2960A06A9DF7B2D0A89 15784 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_31\bin\java-rmi.exe 2015-02-03 09:27:46 B0D46640968F989830413EB88F43E0D0 176552 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_31\bin\java.exe 2015-02-03 09:27:46 063A1044A451660B159426B9C5E75957 30632 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_31\bin\jabswitch.exe 2015-02-03 09:13:16 6713E17AFCB3A28191A747DC8C475721 639912 ----a-w- C:\Users\Mourad\Downloads\jxpiinstall.exe 2015-02-03 08:23:07 9A2347903D6EDB84C10F288BC0578C1C 388608 ----a-w- C:\Program Files\trend micro\Mourad.exe 2015-02-03 08:22:40 8045ABB21A3BDD66A48E1ED5C0F0EF6A 1222144 ----a-w- C:\Users\Mourad\Downloads\RSITx64.exe 2015-01-27 17:51:12 E07AD3AA0A179D0CD171760BB7C3C71F 22869088 ----a-w- C:\Users\Mourad\AppData\Local\Temp\tmpdunjmg\googledrivesync.exe 2015-01-27 14:50:10 FD965425319A2F00F38E86656112B7F0 101192 ----a-w- C:\Users\Mourad\AppData\Local\Google\Google Talk Plugin\googletalkplugin.exe === C: other files == 2015-02-03 10:44:25 2A801DFB1C278104D6AFB23C456C0E89 916024 -c--a-w- C:\Windows\System32\DRVSTORE\VBoxDrv_35508BAE4D918497FF77CDEED80DDB8BD8D9F072\VBoxDrv.sys 2015-02-03 10:44:25 2A801DFB1C278104D6AFB23C456C0E89 916024 ----a-w- C:\Windows\System32\drivers\VBoxDrv.sys 2015-02-03 10:44:12 46970F66C3F19421C37CCCDC7C2F176A 128080 -c--a-w- C:\Windows\System32\DRVSTORE\VBoxUSBMon_B077CC037AAFF8B8408D6AB5CC31592038309F2B\VBoxUSBMon.sys 2015-02-03 10:44:12 46970F66C3F19421C37CCCDC7C2F176A 128080 ----a-w- C:\Windows\System32\drivers\VBoxUSBMon.sys 2015-02-03 10:20:32 CE38122121C784E6380EF424637DBC3F 14130 ----a-w- C:\Program Files\Java\jre1.8.0_31\lib\deploy\ffjcext.zip 2015-02-03 10:19:07 CE38122121C784E6380EF424637DBC3F 14130 ----a-w- C:\Program Files\Java\jdk1.8.0_31\jre\lib\deploy\ffjcext.zip 2015-02-03 10:19:03 EADACDA8143EEF2B6B4D980951E3DD2F 1387 ----a-w- C:\Program Files\Java\jdk1.8.0_31\db\bin\dblook.bat 2015-02-03 10:19:03 DF3D54E32E15A19252ABC233C15E89AD 1284 ----a-w- C:\Program Files\Java\jdk1.8.0_31\db\bin\setNetworkClientCP.bat 2015-02-03 10:19:03 A5C4E1441A3C4FFC212894B48927F2E4 2426 ----a-w- C:\Program Files\Java\jdk1.8.0_31\db\bin\derby_common.bat 2015-02-03 10:19:03 A40B148E94D379D685C5680E9C2237F2 1389 ----a-w- C:\Program Files\Java\jdk1.8.0_31\db\bin\sysinfo.bat 2015-02-03 10:19:03 9C163DC5EE82C1406B972C91C3AF6C48 1397 ----a-w- C:\Program Files\Java\jdk1.8.0_31\db\bin\startNetworkServer.bat 2015-02-03 10:19:03 8B60A818AFAF28D6990ED8DBC38C7629 1273 ----a-w- C:\Program Files\Java\jdk1.8.0_31\db\bin\setNetworkServerCP.bat 2015-02-03 10:19:03 80F3240EC26153182653BC231E91D195 1403 ----a-w- C:\Program Files\Java\jdk1.8.0_31\db\bin\stopNetworkServer.bat 2015-02-03 10:19:03 354BAED360255170A65BD8165F022FD3 1278 ----a-w- C:\Program Files\Java\jdk1.8.0_31\db\bin\setEmbeddedCP.bat 2015-02-03 10:19:03 2A74A9CF4026183DFF9FD1CF5C484ACC 5025517 ----a-w- C:\Program Files\Java\jdk1.8.0_31\javafx-src.zip 2015-02-03 10:19:03 23CDC9E9ADF8A10F40DD845397036C94 1379 ----a-w- C:\Program Files\Java\jdk1.8.0_31\db\bin\ij.bat 2015-02-03 10:19:03 1384CD0AF6BBD83C2F01BD56E30309DC 1413 ----a-w- C:\Program Files\Java\jdk1.8.0_31\db\bin\NetworkServerControl.bat 2015-02-03 09:27:47 3315140254247E248C3531F159C79109 14130 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_31\lib\deploy\ffjcext.zip 2015-02-03 09:23:33 DE0983FE4B830699312D35A990B3AE1B 1945 ----a-w- C:\Users\Mourad\AppData\Local\Temp\_MEI54002\resources\chrome_ext\nknebiagdodnminbdpflhpkgfpeijdbf_live.crx 2015-02-03 09:23:33 82F5C942549405F61A8808D0EA0FA9E2 25575 ----a-w- C:\Users\Mourad\AppData\Local\Temp\_MEI54002\resources\chrome_ext\apdfllckaahabafndbhieahigkjlhalf_live.crx 2015-02-03 06:26:02 8AE45D20A9419CB3C80A9929F86BBEF6 34765517 ----a-r- C:\Users\Mourad\AppData\Local\Microsoft\Windows\FileHistory\Data\1418\C\Users\Mourad\Documents\NetBeansProjects\bva-develop.zip 2015-02-03 06:21:21 8AE45D20A9419CB3C80A9929F86BBEF6 34765517 ----a-r- C:\Users\Mourad\AppData\Local\Microsoft\Windows\FileHistory\Data\1418\C\Users\Mourad\Documents\Lynda.com\bva-develop.zip 2015-02-02 22:31:06 8AE45D20A9419CB3C80A9929F86BBEF6 34765517 ----a-w- C:\Users\Mourad\Documents\NetBeansProjects\bva-develop.zip 2015-02-02 22:30:49 8AE45D20A9419CB3C80A9929F86BBEF6 34765517 ----a-w- C:\Users\Mourad\Documents\Lynda.com\bva-develop.zip 2015-02-02 22:23:52 3CF63B29AEDE49F6B65039EEF848E0B4 681179 ----a-r- C:\Users\Mourad\AppData\Local\Microsoft\Windows\FileHistory\Data\1417\C\Users\Mourad\Documents\NetBeansProjects\platform-develop.zip 2015-02-02 22:23:43 3CF63B29AEDE49F6B65039EEF848E0B4 681179 ----a-r- C:\Users\Mourad\AppData\Local\Microsoft\Windows\FileHistory\Data\1417\C\Users\Mourad\Documents\Lynda.com\platform-develop.zip 2015-02-02 22:17:21 3CF63B29AEDE49F6B65039EEF848E0B4 681179 ----a-w- C:\Users\Mourad\Documents\NetBeansProjects\platform-develop.zip 2015-02-02 22:17:07 3CF63B29AEDE49F6B65039EEF848E0B4 681179 ----a-w- C:\Users\Mourad\Documents\Lynda.com\platform-develop.zip 2015-02-02 22:15:34 8AE45D20A9419CB3C80A9929F86BBEF6 34765517 ----a-w- C:\Users\Mourad\Downloads\bva-develop(1).zip 2015-02-02 22:08:33 8AE45D20A9419CB3C80A9929F86BBEF6 34765517 ----a-w- C:\Users\Mourad\Downloads\bva-develop.zip 2015-02-02 22:06:18 3CF63B29AEDE49F6B65039EEF848E0B4 681179 ----a-w- C:\Users\Mourad\Downloads\platform-develop.zip 2015-02-01 11:16:16 DE0983FE4B830699312D35A990B3AE1B 1945 ----a-w- C:\Users\Mourad\AppData\Local\Temp\_MEI55842\resources\chrome_ext\nknebiagdodnminbdpflhpkgfpeijdbf_live.crx 2015-02-01 11:16:16 82F5C942549405F61A8808D0EA0FA9E2 25575 ----a-w- C:\Users\Mourad\AppData\Local\Temp\_MEI55842\resources\chrome_ext\apdfllckaahabafndbhieahigkjlhalf_live.crx 2015-01-29 17:12:59 2687C8D3A6B617F1BA45171867C48963 5362841 ----a-r- C:\Users\Mourad\AppData\Local\Microsoft\Windows\FileHistory\Data\1396\C\Users\Mourad\Documents\Lynda.com\Datastructures HVA\Sorting&Searching\S&S.zip 2015-01-29 17:04:08 2687C8D3A6B617F1BA45171867C48963 5362841 ------r- C:\Users\Mourad\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\LiveComm\60450d5323dd525d\120712-0049\Att\20001c6a\S&S.zip 2015-01-27 17:51:38 DE0983FE4B830699312D35A990B3AE1B 1945 ----a-w- C:\Users\Mourad\AppData\Local\Temp\_MEI54402\resources\chrome_ext\nknebiagdodnminbdpflhpkgfpeijdbf_live.crx 2015-01-27 17:51:38 82F5C942549405F61A8808D0EA0FA9E2 25575 ----a-w- C:\Users\Mourad\AppData\Local\Temp\_MEI54402\resources\chrome_ext\apdfllckaahabafndbhieahigkjlhalf_live.crx ==== Startup Registry Enabled ====================== [HKEY_USERS\S-1-5-21-3063571080-120727185-186101101-1002\Software\Microsoft\Windows\CurrentVersion\Run] "GoogleDriveSync"="C:\Program Files (x86)\Google\Drive\googledrivesync.exe /autostart" "MySQL Notifier"="D:\MySQL Notifier 1.1.4\MySqlNotifier.exe" "Google Update"="C:\Users\Mourad\AppData\Local\Google\Update\GoogleUpdate.exe /c" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IAStorIcon"="C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe 60" "CLMLServer_For_P2G8"="C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe" "CLVirtualDrive"="C:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe /R" "RemoteControl10"="C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe" "BDRegion"="C:\Program Files (x86)\Cyberlink\Shared files\brs.exe" "mcui_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey" "AdobeCS6ServiceManager"="C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe -launchedbylogin" "SwitchBoard"="C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" "APSDaemon"="C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" "mcpltui_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey" "iTunesHelper"="D:\iTunesHelper.exe" "SunJavaUpdateSched"="C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "GoogleDriveSync"="C:\Program Files (x86)\Google\Drive\googledrivesync.exe /autostart" "MySQL Notifier"="D:\MySQL Notifier 1.1.4\MySqlNotifier.exe" "Google Update"="C:\Users\Mourad\AppData\Local\Google\Update\GoogleUpdate.exe /c" ==== Startup Registry Enabled x64 ====================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Apoint"="C:\Program Files\DellTPad\Apoint.exe" "QuickSet"="c:\Program Files\Dell\QuickSet\QuickSet.exe" "IntelTBRunOnce"="wscript.exe //b //nologo C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs" "BTMTrayAgent"="rundll32.exe C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll,TrayApp" "AdobeAAMUpdater-1.0"="C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" "SysTrayApp"="C:\Program Files\IDT\WDM\sttray64.exe" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"="C:\\PROGRA~2\\NVIDIA~1\\3DVISI~1\\NVSTIN~1.DLL" ==== Startup Folders ====================== 2014-09-09 09:14:00 1185 ----a-w- C:\Users\Mourad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk 2013-03-22 15:45:14 1298 ----a-w- C:\Users\Mourad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Schermopname en Snel starten.lnk ==== Task Scheduler Jobs ====================== C:\WINDOWS\tasks\Adobe Flash Player Updater.job --a-------- C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [24-01-2015 21:52] C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job --a-------- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [24-08-2013 09:59] C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job --a-------- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [24-08-2013 09:59] C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-3063571080-120727185-186101101-1002Core.job --a-------- C:\Users\Mourad\AppData\Local\Google\Update\GoogleUpdate.exe [07-02-2014 09:32] C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-3063571080-120727185-186101101-1002UA.job --a-------- C:\Users\Mourad\AppData\Local\Google\Update\GoogleUpdate.exe [07-02-2014 09:32] ==== Other Scheduled Tasks ====================== "C:\WINDOWS\SysNative\tasks\0" [c:\program files\internet explorer\iexplore.exe] "C:\WINDOWS\SysNative\tasks\4797" [wscript.exe C:\Users\Mourad\AppData\Local\Temp\launchie.vbs //B] "C:\WINDOWS\SysNative\tasks\Adobe Acrobat Update Task" [C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe] "C:\WINDOWS\SysNative\tasks\Adobe Flash Player Updater" [C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe] "C:\WINDOWS\SysNative\tasks\AdobeAAMUpdater-1.0-M-Mourad" [C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe] "C:\WINDOWS\SysNative\tasks\CreateChoiceProcessTask" [C:\Windows\BrowserChoice\browserchoice.exe] "C:\WINDOWS\SysNative\tasks\GoogleUpdateTaskMachineCore" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe] "C:\WINDOWS\SysNative\tasks\GoogleUpdateTaskMachineUA" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe] "C:\WINDOWS\SysNative\tasks\GoogleUpdateTaskUserS-1-5-21-3063571080-120727185-186101101-1002Core" [C:\Users\Mourad\AppData\Local\Google\Update\GoogleUpdate.exe] "C:\WINDOWS\SysNative\tasks\GoogleUpdateTaskUserS-1-5-21-3063571080-120727185-186101101-1002UA" [C:\Users\Mourad\AppData\Local\Google\Update\GoogleUpdate.exe] "C:\WINDOWS\SysNative\tasks\PCDEventLauncherTask" ["C:\Program Files\My Dell\sessionchecker.exe"] "C:\WINDOWS\SysNative\tasks\PCDoctorBackgroundMonitorTask" ["C:\Program Files\My Dell\uaclauncher.exe"] "C:\WINDOWS\SysNative\tasks\SystemToolsDailyTest" ["uaclauncher.exe"] "C:\WINDOWS\SysNative\tasks\Apple\AppleSoftwareUpdate" [C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe] "C:\WINDOWS\SysNative\tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask" [%systemroot%\system32\sc.exe start osppsvc] ==== Firefox Start and Search pages ====================== ProfilePath: C:\Users\Mourad\AppData\Roaming\Mozilla\Firefox\Profiles\0 user_pref("browser.startup.homepage", "about:home"); user_pref("browser.newtab.url", "about:newtab"); ProfilePath: C:\Users\Mourad\AppData\Roaming\Mozilla\Firefox\Profiles\xvq7urvn.default user_pref("browser.startup.homepage", "about:home"); user_pref("browser.newtab.url", "about:newtab"); ==== Firefox Extensions Registry ====================== [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions] "{4ED1F68A-5463-4931-9384-8FFF5ED91D92}"="C:\Program Files (x86)\McAfee\SiteAdvisor" [15-01-2015 12:26] ==== Firefox Extensions ====================== ProfilePath: C:\Users\Mourad\AppData\Roaming\Mozilla\Firefox\Profiles\xvq7urvn.default - McAfee SiteAdvisor - C:\Program Files (x86)\McAfee\SiteAdvisor - Undetermined - adblockpopups@jessehakanen.net - Undetermined - {4ED1F68A-5463-4931-9384-8FFF5ED91D92} - Adblock Plus Pop-up Addon - %ProfilePath%\extensions\adblockpopups@jessehakanen.net.xpi - Firebug - %ProfilePath%\extensions\firebug@software.joehewitt.com.xpi - Scrum for Trello - %ProfilePath%\extensions\jid0-5H6AniOsKhO4eJ4UyLgZRRf0PIU@jetpack.xpi AppDir: C:\Program Files (x86)\Mozilla Firefox - Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} ==== Firefox Plugins ====================== Profilepath: C:\Users\Mourad\AppData\Roaming\Mozilla\Firefox\Profiles\xvq7urvn.default 2D684F0DDF782C73847BED9503250991 - C:\Users\Mourad\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll - Google Talk Plugin 6C3E34E303DBDCB9F7EC1F7A7F6B1629 - C:\Users\Mourad\AppData\Roaming\Mozilla\plugins\npo1d.dll - Google Talk Plugin Video Renderer 0FC325593893749364EC4A733E7D9100 - C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_296.dll - Shockwave Flash D2377C9458EFEB094E38B8C874AA214C - C:\Users\Mourad\AppData\Local\Google\Update\1.3.25.11\npGoogleUpdate3.dll - Google Update B5371D2C9017EEE216B5361D600B3543 - D:\Mozilla Plugins\npitunes.dll - iTunes Application Detector ==== Chromium Look ====================== Google Chrome Version: 40.0.2214.93 (Up to date, latest Stable version: 40.0.2214.93) HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions adbhhndkbleegagglikfkdooghnmmjgb - C:\ProgramData\Zoomex\adbhhndkbleegagglikfkdooghnmmjgb.crx[] fheoggkfdfchfphceeifdbepaooicaho - No path found[] gnpfmnkmkeeenehaljllbcclgalhkdao - C:\ProgramData\Zoomex\gnpfmnkmkeeenehaljllbcclgalhkdao.crx[] ilnhngmhamjdggfilcknhkjkndpiekpb - C:\ProgramData\Zoomex\ilnhngmhamjdggfilcknhkjkndpiekpb.crx[] imkiookfjjmddnoibbkpbhpekffimhim - C:\ProgramData\Zoomex\imkiookfjjmddnoibbkpbhpekffimhim.crx[] HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\Extensions lmjegmlicamnimmfhcmpkclmigmmcbeh - No path found[] Google Docs - Mourad\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake Google Drive - Mourad\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf YouTube - Mourad\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo Google Search - Mourad\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf SiteAdvisor - Mourad\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho Google Drive App Launcher - Mourad\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh Hangouts - Mourad\AppData\Local\Google\Chrome\User Data\Default\Extensions\nckgahadagoaajjgafhacjanaoiihapd Google Wallet - Mourad\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda Gmail - Mourad\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia ==== Set IE to Default ====================== Old Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main] "Default_Search_URL"="http://www.google.com" "Search Page"="http://www.google.com" [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main] "Default_Search_URL"="http://www.google.com" "Search Page"="http://www.google.com" New Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main] "Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896" "Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896" [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main] "Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896" "Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896" ==== All HKCU SearchScopes ====================== HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" {012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}" {0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC" ==== Reset Google Chrome ====================== C:\Users\Mourad\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully C:\Users\Mourad\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully ==== Deleting Registry Keys ====================== HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{01665124-8AD8-C831-57E9-4EC35F9968A4} deleted successfully HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{8CB927BA-F1B6-AE09-40BB-C50007815BBC} deleted successfully HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{96243C4B-4CEC-DBA4-3D79-AA774FFE7162} deleted successfully HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{C11C0F78-8E57-F78F-1042-57741ED3877F} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\adbhhndkbleegagglikfkdooghnmmjgb deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\gnpfmnkmkeeenehaljllbcclgalhkdao deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\ilnhngmhamjdggfilcknhkjkndpiekpb deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\imkiookfjjmddnoibbkpbhpekffimhim deleted successfully ==== HijackThis Entries ====================== F2 - REG:system.ini: UserInit=userinit.exe O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll O4 - HKLM\..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe "C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" 60 O4 - HKLM\..\Run: [CLMLServer_For_P2G8] "C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe" O4 - HKLM\..\Run: [CLVirtualDrive] "C:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe" /R O4 - HKLM\..\Run: [RemoteControl10] "C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe" O4 - HKLM\..\Run: [BDRegion] C:\Program Files (x86)\Cyberlink\Shared files\brs.exe O4 - HKLM\..\Run: [mcui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey O4 - HKLM\..\Run: [AdobeCS6ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" -launchedbylogin O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" O4 - HKLM\..\Run: [mcpltui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey O4 - HKLM\..\Run: [iTunesHelper] "D:\iTunesHelper.exe" O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" O4 - HKCU\..\Run: [DellSystemDetect] C:\Users\Mourad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dell\Dell System Detect.appref-ms O4 - HKCU\..\Run: [GoogleDriveSync] "C:\Program Files (x86)\Google\Drive\googledrivesync.exe" /autostart O4 - HKCU\..\Run: [MySQL Notifier] D:\MySQL Notifier 1.1.4\MySqlNotifier.exe O4 - HKCU\..\Run: [Google Update] "C:\Users\Mourad\AppData\Local\Google\Update\GoogleUpdate.exe" /c O4 - Startup: Dropbox.lnk = Mourad\AppData\Roaming\Dropbox\bin\Dropbox.exe O4 - Startup: Intel® Turbo Boost Technologie monitor 2.6.lnk = C:\Program Files\Intel\TurboBoost\SignalIslandUi.exe O4 - Startup: OneNote 2010 Schermopname en Snel starten.lnk = C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE O8 - Extra context menu item: &Verzenden naar OneNote - res://C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105 O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000 O8 - Extra context menu item: Verzenden naar Bluetooth - C:\Program Files (x86)\Intel\Bluetooth\btSendToObject.htm O9 - Extra button: Verzenden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll O9 - Extra 'Tools' menuitem: &Verzenden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll O9 - Extra button: &Gekoppelde notities van OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll O9 - Extra 'Tools' menuitem: &Gekoppelde notities van OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll O9 - Extra button: Verzenden naar Bluetooth - {2F56DCAA-153B-4479-B4E2-547405B34FB9} - C:\Program Files (x86)\Intel\Bluetooth\btSendToPage.htm (HKCU) O9 - Extra 'Tools' menuitem: Verzenden naar Bluetooth - {2F56DCAA-153B-4479-B4E2-547405B34FB9} - C:\Program Files (x86)\Intel\Bluetooth\btSendToPage.htm (HKCU) O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics O15 - Trusted Zone: *.dell.com O18 - Protocol: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll O18 - Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\PROGRA~2\mcafee\msc\mcsniepl.dll O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing) O23 - Service: Intel® Centrino® Wireless Bluetooth® + High Speed Service (AMPPALR3) - Intel Corporation - C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe O23 - Service: Apache CouchDB (Apache CouchDB01cf8b86d6658650) - Unknown owner - D:\CouchDB\erts-5.10.3\bin\erlsrv.exe O23 - Service: Bluetooth Device Monitor - Motorola Solutions, Inc. - C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe O23 - Service: Bluetooth OBEX Service - Motorola Solutions, Inc. - C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe O23 - Service: Bonjour-service (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: Intel(R) Centrino(R) Wireless Bluetooth(R) + High Speed Security Service (BTHSSecurityMgr) - Intel(R) Corporation - C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe O23 - Service: CyberLink Product - 2012/12/11 14:52:03 (CLKMSVC10_38F51D56) - CyberLink - C:\Program Files (x86)\CyberLink\PowerDVD10\NavFilter\kmsvc.exe O23 - Service: Dell Digital Delivery Service (DellDigitalDelivery) - Dell Products, LP. - C:\Program Files (x86)\Dell Digital Delivery\DeliveryService.exe O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing) O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing) O23 - Service: Google Update-service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe O23 - Service: Google Update-service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe O23 - Service: McAfee Home Network (HomeNetSvc) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe O23 - Service: Intel(R) Rapid Storage Technologie (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\WINDOWS\system32\IEEtwCollector.exe (file missing) O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe O23 - Service: iPod-service (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: Intel(R) Rapid Start Technology Service (irstrtsv) - Intel Corporation - C:\Windows\SysWOW64\irstrtsv.exe O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing) O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe O23 - Service: McAfee SiteAdvisor Service - McAfee, Inc. - C:\Program Files (x86)\McAfee\SiteAdvisor\McSACore.exe O23 - Service: McAfee AP Service (McAPExe) - McAfee, Inc. - C:\Program Files\McAfee\MSC\McAPExe.exe O23 - Service: McAfee Personal Firewall Service (McMPFSvc) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe O23 - Service: McAfee VirusScan Announcer (McNaiAnn) - McAfee, Inc. - C:\Program Files\Common Files\mcafee\Platform\McSvcHost\McSvHost.exe O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\Program Files\mcafee\VirusScan\mcods.exe O23 - Service: McAfee Platform Services (mcpltsvc) - McAfee, Inc. - C:\Program Files\Common Files\mcafee\Platform\McSvcHost\McSvHost.exe O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - C:\Program Files\Common Files\mcafee\Platform\McSvcHost\McSvHost.exe O23 - Service: McAfee Anti-Malware Core (mfecore) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe O23 - Service: McAfee Firewall Core Service (mfefire) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe O23 - Service: McAfee Validation Trust Protection Service (mfevtp) - Unknown owner - C:\WINDOWS\system32\mfevtps.exe (file missing) O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing) O23 - Service: MySQL56 - Unknown owner - D:/MySQL.exe (file missing) O23 - Service: Wireless PAN DHCP Server (MyWiFiDHCPDNS) - Unknown owner - C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing) O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\WINDOWS\system32\nvvsvc.exe (file missing) O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe O23 - Service: PDF Architect 2 - pdfforge GmbH - C:\Program Files (x86)\PDF Architect 2\ws.exe O23 - Service: pdfforge CrashHandler - pdfforge GmbH - C:\Program Files (x86)\PDF Architect 2\crash-handler-ws.exe O23 - Service: Rapport Management Service (RapportMgmtService) - IBM Corp. - C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing) O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing) O23 - Service: SoftThinks Agent Service (SftService) - SoftThinks SAS - C:\Program Files (x86)\Dell Backup and Recovery\sftservice.exe O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing) O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing) O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing) O23 - Service: @%SystemRoot%\system32\stlang64.dll,-10101 (STacSV) - IDT, Inc. - C:\Program Files\IDT\WDM\STacSV64.exe O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe O23 - Service: Intel(R) Turbo Boost Technology Monitor 2.6 (TurboBoost) - Intel(R) Corporation - C:\Program Files\Intel\TurboBoost\TurboBoost.exe O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing) O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing) O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing) O23 - Service: VMware Authorization Service (VMAuthdService) - VMware, Inc. - C:\Program Files (x86)\VMware\VMware Player\vmware-authd.exe O23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - C:\WINDOWS\system32\vmnetdhcp.exe O23 - Service: VMware USB Arbitration Service (VMUSBArbService) - VMware, Inc. - C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe O23 - Service: VMware NAT Service - VMware, Inc. - C:\WINDOWS\system32\vmnat.exe O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing) O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing) O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing) O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing) O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing) O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing) O23 - Service: Intel(R) PROSet/Wireless Zero Configuration Service (ZeroConfigService) - Intel® Corporation - C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe ==== Empty IE Cache ====================== C:\WINDOWS\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Mourad\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\Users\Mourad\AppData\Local\Microsoft\Windows\INetCache\Low\Content.IE5 emptied successfully C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\WINDOWS\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\Users\Mourad\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully C:\Users\Mourad\AppData\Local\Microsoft\Windows\INetCache\Low\IE emptied successfully C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully ==== Empty FireFox Cache ====================== C:\Users\Mourad\AppData\Local\Mozilla\Firefox\Profiles\xvq7urvn.default\cache2 emptied successfully ==== Empty Chrome Cache ====================== C:\Users\Mourad\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully ==== Empty All Flash Cache ====================== Flash Cache Emptied Successfully ==== Empty All Java Cache ====================== Java Cache cleared successfully ==== C:\zoek_backup content ====================== C:\zoek_backup (files=87 folders=16 1417852556 bytes) ==== Empty Temp Folders ====================== C:\Users\Default\AppData\Local\Temp emptied successfully C:\Users\Default User\AppData\Local\Temp emptied successfully C:\Users\Mourad\AppData\Local\Temp will be emptied at reboot C:\Users\UpdatusUser\AppData\Local\Temp emptied successfully C:\WINDOWS\serviceprofiles\networkservice\AppData\Local\Temp will be emptied at reboot C:\WINDOWS\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully C:\WINDOWS\Temp will be emptied at reboot ==== After Reboot ====================== ==== Empty Temp Folders ====================== C:\WINDOWS\Temp successfully emptied C:\Users\Mourad\AppData\Local\Temp successfully emptied ==== Empty Recycle Bin ====================== C:\$RECYCLE.BIN successfully emptied ==== Deleting Files / Folders ====================== "C:\WINDOWS\serviceprofiles\networkservice\AppData\Local\Temp\ib324B.tmp" not found "C:\WINDOWS\serviceprofiles\networkservice\AppData\Local\Temp\ib324C.tmp" not found "C:\WINDOWS\serviceprofiles\networkservice\AppData\Local\Temp\ib325C.tmp" not found "C:\WINDOWS\serviceprofiles\networkservice\AppData\Local\Temp\ib328C.tmp" not found "C:\WINDOWS\serviceprofiles\networkservice\AppData\Local\Temp\ib34B0.tmp" not found ==== EOF on di 03-02-2015 at 12:17:58,12 ======================