Zoek.exe v5.0.0.0 Updated 18-February-2015 Tool run by Bakkers on do 19-02-2015 at 17:03:47,00. Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x64 Running in: Normal Mode Internet Access Detected Launched: C:\Users\Bakkers\Downloads\zoek(1).exe [Scan all users] [Script inserted] [Checkboxes used] ==== System Restore Info ====================== 19-2-2015 17:06:01 Zoek.exe System Restore Point Created Succesfully. ==== Empty Folders Check ====================== C:\PROGRA~2\MarkAny deleted successfully C:\PROGRA~2\MSXML 4.0 deleted successfully C:\PROGRA~2\Samsung deleted successfully C:\Users\Bakkers\AppData\Roaming\TP deleted successfully C:\Users\Bakkers\AppData\Roaming\VMware deleted successfully ==== Deleting CLSID Registry Keys ====================== HKEY_USERS\S-1-5-21-745457908-2367857168-3363508758-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{d2ce3e00-f94a-4740-988e-03dc2f38c34f} deleted successfully HKEY_USERS\S-1-5-21-745457908-2367857168-3363508758-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{d2ce3e00-f94a-4740-988e-03dc2f38c34f} deleted successfully HKEY_USERS\S-1-5-21-745457908-2367857168-3363508758-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8dcb7100-df86-4384-8842-8fa844297b3f} deleted successfully HKEY_USERS\S-1-5-21-745457908-2367857168-3363508758-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{8dcb7100-df86-4384-8842-8fa844297b3f} deleted successfully HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{d2ce3e00-f94a-4740-988e-03dc2f38c34f} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d2ce3e00-f94a-4740-988e-03dc2f38c34f} deleted successfully HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{8dcb7100-df86-4384-8842-8fa844297b3f} deleted successfully HKEY_CLASSES_ROOT\CLSID\{ae07101b-46d4-4a98-af68-0333ea26e113} deleted successfully HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{ae07101b-46d4-4a98-af68-0333ea26e113} deleted successfully ==== Deleting CLSID Registry Values ====================== HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{8dcb7100-df86-4384-8842-8fa844297b3f} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{ae07101b-46d4-4a98-af68-0333ea26e113} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{ae07101b-46d4-4a98-af68-0333ea26e113} deleted successfully ==== Deleting Services ====================== ==== FireFox Fix ====================== ProfilePath: C:\Users\Bakkers\AppData\Roaming\Mozilla\Firefox\Profiles\g0nrecc9.default user.js not found ---- Lines helperbar removed from prefs.js ---- user_pref("extensions.helperbar.DockingPositionDown", false); user_pref("extensions.helperbar.SmartbarDisabled", false); user_pref("extensions.helperbar.SmartbarStateMinimaized", false); user_pref("extensions.helperbar.Visibility", true); user_pref("extensions.helperbar.countryiso", "nl"); user_pref("extensions.helperbar.installationid", "c0884bf6-d26d-1264-8584-64343a0df0ad"); user_pref("extensions.helperbar.installdate", "02/11/2013"); ---- Lines browser.startup.page removed from prefs.js ---- user_pref("browser.startup.page", 0); ---- FireFox user.js and prefs.js backups ---- prefs_19-02-2015_1728_.backup ==== Registry Fix Code x64 ====================== Windows Registry Editor Version 5.00 [-HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d2ce3e00-f94a-4740-988e-03dc2f38c34f}] ==== Deleting Files \ Folders ====================== C:\Program Files (x86)\Microsoft\BingBar deleted C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk deleted C:\Windows\SysNative\config\systemprofile\Searches deleted ==== Files Recently Created / Modified ====================== ====== C:\Windows ==== ====== C:\Users\Bakkers\AppData\Local\Temp ==== ====== Java Cache ===== 2015-02-19 15:54:25 C1BBA7F1278F193AB584FFF460DB5E2A 17878 ----a-w- C:\Users\Bakkers\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\12\eef218c-30be651f 2015-02-19 15:54:04 415FC9732A3F4D89A0E01251CD66E136 646 ----a-w- C:\Users\Bakkers\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\17\49a00451-7e046221 2015-02-19 15:54:04 2CB7DA4CE775E8F31BB1F275B1C64E60 424 ----a-w- C:\Users\Bakkers\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\17\49a00451-aa56bb018d5de3a531ee91cc4857f0f479656e5370ebf87789e721aaaf530ebc-6.0.lap 2015-02-19 15:54:03 415FC9732A3F4D89A0E01251CD66E136 646 ----a-w- C:\Users\Bakkers\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\18\3cb32f52-7268855e 2015-02-19 15:54:05 34FA8033B50A3F99D3AB8209C72C0ABA 6860 ----a-w- C:\Users\Bakkers\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\43\1ca2666b-272f4c8a ====== C:\Windows\SysWOW64 ===== 2015-02-19 15:52:59 13D186FA6F19823C598335443CE233BC 98216 ----a-w- C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2015-02-19 09:29:58 AEBCEA8A46A42FCFE4EA92186745EE69 89960 ----a-w- C:\Windows\SysWOW64\SQSRVRES.DLL 2015-02-19 09:29:58 45676E87AD75D5E4B63C4D975E1184A7 73064 ----a-w- C:\Windows\SysWOW64\perf-MSSQL$MSSMLBIZ-sqlctr10.3.5500.0.dll 2015-02-17 17:08:20 DDE994E9159497D0D5AB2CDF66D1EAD6 76800 ----a-w- C:\Windows\SysWOW64\wdi.dll 2015-02-12 13:59:50 4FD3763F3917201856B0CBCE310003EA 4300800 ----a-w- C:\Windows\SysWOW64\jscript9.dll 2015-02-12 13:59:50 01BD2653F2185218837CF4A175617F8A 620032 ----a-w- C:\Windows\SysWOW64\jscript9diag.dll 2015-02-11 17:25:15 793F6658ED65839FDB2957A4884CB63C 1230336 ----a-w- C:\Windows\SysWOW64\WindowsCodecs.dll 2015-02-11 17:25:06 E1A4D24281526DDFEA418F729CDA9DC6 30720 ----a-w- C:\Windows\SysWOW64\iernonce.dll 2015-02-11 17:25:06 D87759889FE7BCAE4461439139E62BAA 76288 ----a-w- C:\Windows\SysWOW64\mshtmled.dll 2015-02-11 17:25:06 B0F7BD3492C2D60A70F15AEADCE1E2A6 47616 ----a-w- C:\Windows\SysWOW64\ieetwproxystub.dll 2015-02-11 17:25:06 3B9EF1B8E154D202D32A7765E2F33554 64000 ----a-w- C:\Windows\SysWOW64\MshtmlDac.dll 2015-02-11 17:25:05 94B1F7CE1AAA5542923E0AD63C4D0050 60416 ----a-w- C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2015-02-11 17:25:05 8FBC9680719ACDA9351B67D906C682F4 688640 ----a-w- C:\Windows\SysWOW64\msfeeds.dll 2015-02-11 17:25:05 8E8137569741D3693F88DDF94CC38C20 1307136 ----a-w- C:\Windows\SysWOW64\urlmon.dll 2015-02-11 17:25:05 74EA6C792F57E453261DA210C1BCEB53 342712 ----a-w- C:\Windows\SysWOW64\iedkcs32.dll 2015-02-11 17:25:05 6FA05244FD2E40A3DC08337146B3C425 285696 ----a-w- C:\Windows\SysWOW64\dxtrans.dll 2015-02-11 17:25:05 61C74D794C14E9FC94D93F5F0F72A3F9 19740160 ----a-w- C:\Windows\SysWOW64\mshtml.dll 2015-02-11 17:25:04 FD6AF61AF029B9BC2CF4EFF57CDD5821 710144 ----a-w- C:\Windows\SysWOW64\ieapfltr.dll 2015-02-11 17:25:04 EF05E63ACC834470A07A2E73D519B5FA 418304 ----a-w- C:\Windows\SysWOW64\dxtmsft.dll 2015-02-11 17:25:04 AD3F5926EC2C1F21FB45D1CDED6E2A47 2052608 ----a-w- C:\Windows\SysWOW64\inetcpl.cpl 2015-02-11 17:25:04 9A91F9B5035F54C2D0BA92CF9B16EE34 2277888 ----a-w- C:\Windows\SysWOW64\iertutil.dll 2015-02-11 17:25:04 994E7459260D315573DD72783D1B78A7 478208 ----a-w- C:\Windows\SysWOW64\ieui.dll 2015-02-11 17:25:04 78A1A938D51D4F83A772123B93EE1612 12829184 ----a-w- C:\Windows\SysWOW64\ieframe.dll 2015-02-11 17:25:04 5FB7E9786F70F4072663746072C9E6CE 62464 ----a-w- C:\Windows\SysWOW64\iesetup.dll 2015-02-11 17:25:04 55A84600EAAF8F1D3F0E6206E2EF6D48 47104 ----a-w- C:\Windows\SysWOW64\jsproxy.dll 2015-02-11 17:25:04 47B26D89EF9973E2DD586D0C827F61A9 2724864 ----a-w- C:\Windows\SysWOW64\mshtml.tlb 2015-02-11 17:25:04 28B2D3CB1B4306D476200D80AF7D87AD 115712 ----a-w- C:\Windows\SysWOW64\ieUnatt.exe 2015-02-11 17:25:02 F285D499EC42969D963CA49EADA63218 1888256 ----a-w- C:\Windows\SysWOW64\wininet.dll 2015-02-11 17:25:02 9DEE691C8FDBC2DE6957F1AE873C78FC 503296 ----a-w- C:\Windows\SysWOW64\vbscript.dll 2015-02-11 17:25:02 6F10743069DFFC56DEE079204960844E 168960 ----a-w- C:\Windows\SysWOW64\msrating.dll 2015-02-11 17:25:02 180168942E4A133C55E7BBF17DA3C142 1155072 ----a-w- C:\Windows\SysWOW64\mshtmlmedia.dll 2015-02-11 17:24:22 B63A6FF4339C9B701A93D3973C7FB6D2 550912 ----a-w- C:\Windows\SysWOW64\kerberos.dll 2015-02-11 17:24:22 7D94A9161E8432B8521E60E064B1D737 259584 ----a-w- C:\Windows\SysWOW64\msv1_0.dll 2015-02-11 17:24:22 7C893DBA0A58855A99DA68B751FD223B 248832 ----a-w- C:\Windows\SysWOW64\schannel.dll 2015-02-11 17:24:22 3BB446DE24501FEA5FDB9A9DB23A22AE 221184 ----a-w- C:\Windows\SysWOW64\ncrypt.dll 2015-02-11 17:24:21 F3F6BE20A03215209B61CA85B4A83E1F 65536 ----a-w- C:\Windows\SysWOW64\TSpkg.dll 2015-02-11 17:24:21 C256EFD3655EC782F8094E96094E8F9E 17408 ----a-w- C:\Windows\SysWOW64\credssp.dll 2015-02-11 17:24:21 A12D64A94EC57079C2D96A741CB4FF53 172032 ----a-w- C:\Windows\SysWOW64\wdigest.dll 2015-02-11 17:24:03 A208DAC2932649CFF82A6A684D8BB1F6 571904 ----a-w- C:\Windows\SysWOW64\oleaut32.dll 2015-02-11 17:23:45 0C96A745A76C7DD75C5503E86D968E49 1174528 ----a-w- C:\Windows\SysWOW64\crypt32.dll 2015-02-11 17:23:20 F2A743912D404A8866362836CFE7A648 686080 ----a-w- C:\Windows\SysWOW64\adtschema.dll 2015-02-11 17:23:19 F312300F29620F74E3AF3AF018151935 96768 ----a-w- C:\Windows\SysWOW64\sspicli.dll 2015-02-11 17:23:19 F29BC66CE4A5507A49FB20744A056E61 22016 ----a-w- C:\Windows\SysWOW64\secur32.dll 2015-02-11 17:23:19 4E6934926B4C923CC0FF61C6D77814EF 50176 ----a-w- C:\Windows\SysWOW64\auditpol.exe 2015-02-11 17:23:19 43791D2F736C4E9BE9FE0B33A1E92A5D 60416 ----a-w- C:\Windows\SysWOW64\msobjs.dll 2015-02-11 17:23:19 36F152AE2F64B12771A44EA77124332B 146432 ----a-w- C:\Windows\SysWOW64\msaudite.dll 2015-02-11 17:22:58 F5142E9A99F44F9CC19A8AF31761F7F9 3221504 ----a-w- C:\Windows\SysWOW64\mstscax.dll 2015-02-11 17:22:57 B3AC14EA18DD0EE517703A86963AED18 131584 ----a-w- C:\Windows\SysWOW64\aaclient.dll 2015-02-11 17:22:01 B3BC38B886CA53C92D52EF724A9F0D45 308224 ----a-w- C:\Windows\SysWOW64\scesrv.dll 2015-02-11 17:21:41 62C93E47A424A8EC79F3CF1719A2DCC6 3972544 ----a-w- C:\Windows\SysWOW64\ntkrnlpa.exe 2015-02-11 17:21:40 6D227897A458DA8A9518DACDC88F1947 3917760 ----a-w- C:\Windows\SysWOW64\ntoskrnl.exe 2015-02-11 17:21:33 97B7E7E3356F7F7FE5B948AB3ED707DD 43008 ----a-w- C:\Windows\SysWOW64\srclient.dll ====== C:\Windows\SysWOW64\drivers ===== ====== C:\Windows\Sysnative ===== 2015-02-17 17:08:20 D713D6446DDBB474D801F361B4B186EA 950272 ----a-w- C:\Windows\Sysnative\perftrack.dll 2015-02-17 17:08:20 C6F7473B55510F0B93961DA03D8E3B38 91136 ----a-w- C:\Windows\Sysnative\wdi.dll 2015-02-17 17:08:20 AA7079AD52B8BFBAE94167D54C32F84F 29696 ----a-w- C:\Windows\Sysnative\powertracker.dll 2015-02-12 13:59:49 D363FBB2D0223956FF61ADBDBF5499B1 814080 ----a-w- C:\Windows\Sysnative\jscript9diag.dll 2015-02-12 13:59:49 16ACAA0C01F31B39F39446188F6A3593 6041600 ----a-w- C:\Windows\Sysnative\jscript9.dll 2015-02-11 17:25:19 64EAD6C9D342E7E0CFCA3559FCBFDDAC 894976 ----a-w- C:\Windows\Sysnative\appraiser.dll 2015-02-11 17:25:19 5C09611AB8D508CC252BB2D5A069D1AC 1098752 ----a-w- C:\Windows\Sysnative\aeinv.dll 2015-02-11 17:25:19 47709F1B718859ED8AB5EA3EA3974BEB 609280 ----a-w- C:\Windows\Sysnative\generaltel.dll 2015-02-11 17:25:18 B5746809407BDEB18D9D4769CD9FF24E 414720 ----a-w- C:\Windows\Sysnative\devinv.dll 2015-02-11 17:25:18 7F2F9AACF457CE48CDDBD643FC53487C 227328 ----a-w- C:\Windows\Sysnative\aepdu.dll 2015-02-11 17:25:18 7150E809474BBD4D4AD24B13FA2454E5 1239720 ----a-w- C:\Windows\Sysnative\aitstatic.exe 2015-02-11 17:25:18 5632EB9633EACCC323CEA2C03A0B4133 762368 ----a-w- C:\Windows\Sysnative\invagent.dll 2015-02-11 17:25:17 EF4FA1D31D146EA0C04D16E75FCA6BCF 192000 ----a-w- C:\Windows\Sysnative\aepic.dll 2015-02-11 17:25:16 4861B9AF67E1B0154A55FDE4B3A61EB9 1424384 ----a-w- C:\Windows\Sysnative\WindowsCodecs.dll 2015-02-11 17:25:06 71EBA93C5322A52A7E177E03E1AE7161 48640 ----a-w- C:\Windows\Sysnative\ieetwproxystub.dll 2015-02-11 17:25:06 68A2B96528F58D995882FBEB4D9658A5 2724864 ----a-w- C:\Windows\Sysnative\mshtml.tlb 2015-02-11 17:25:06 01A314677CC80041A63ED109B56A76B0 114688 ----a-w- C:\Windows\Sysnative\ieetwcollector.exe 2015-02-11 17:25:05 F42B1DAAB5B7621341243878180446CD 34304 ----a-w- C:\Windows\Sysnative\iernonce.dll 2015-02-11 17:25:05 92BD5080B81EDFA32B0CEE8B923D62C3 77824 ----a-w- C:\Windows\Sysnative\JavaScriptCollectionAgent.dll 2015-02-11 17:25:05 8076BB31004C1D763D5D4AEF9F0BDD4B 718848 ----a-w- C:\Windows\Sysnative\ie4uinit.exe 2015-02-11 17:25:04 DF39C79DFC1C063493D2DB9B3237B29F 316928 ----a-w- C:\Windows\Sysnative\dxtrans.dll 2015-02-11 17:25:04 CB2528D522FF1F5A7BF9B27D2FB250FF 1548288 ----a-w- C:\Windows\Sysnative\urlmon.dll 2015-02-11 17:25:04 97F037E09A706ACDA681D740DEE16AE4 968704 ----a-w- C:\Windows\Sysnative\MsSpellCheckingFacility.exe 2015-02-11 17:25:04 76DB5845E168173BBA2D3CCC4B363E42 801280 ----a-w- C:\Windows\Sysnative\msfeeds.dll 2015-02-11 17:25:04 2E4F8664B54426C2F5523665B279E984 4096 ----a-w- C:\Windows\Sysnative\ieetwcollectorres.dll 2015-02-11 17:25:04 1D824B5A200C284E1A546C2C50704471 389808 ----a-w- C:\Windows\Sysnative\iedkcs32.dll 2015-02-11 17:25:03 A7A3775B0014B165D75A00A1F632E4B5 2885632 ----a-w- C:\Windows\Sysnative\iertutil.dll 2015-02-11 17:25:03 7A388AFC6885D22F4D988EE9B8D1291A 800768 ----a-w- C:\Windows\Sysnative\ieapfltr.dll 2015-02-11 17:25:03 512DD29CE6CDCB22EA615286DA7022E7 66560 ----a-w- C:\Windows\Sysnative\iesetup.dll 2015-02-11 17:25:03 15842FB41A3BF2A2F5071518B38C957A 2125824 ----a-w- C:\Windows\Sysnative\inetcpl.cpl 2015-02-11 17:25:02 A7814E76ED4ACE0694A83F6E4B6A7272 144384 ----a-w- C:\Windows\Sysnative\ieUnatt.exe 2015-02-11 17:25:02 6916B0663357B183B120D1A4DD7DDAB0 54784 ----a-w- C:\Windows\Sysnative\jsproxy.dll 2015-02-11 17:25:01 E0F76B5B904E4F448641B2B506496351 14401024 ----a-w- C:\Windows\Sysnative\ieframe.dll 2015-02-11 17:25:01 D7922F3AC6BF1EA77240E0061D648174 490496 ----a-w- C:\Windows\Sysnative\dxtmsft.dll 2015-02-11 17:25:01 CA3F410410DE9E5234217D33B9628224 633856 ----a-w- C:\Windows\Sysnative\ieui.dll 2015-02-11 17:25:00 A04F0C4A0B80C92F92E854E7157D6466 92160 ----a-w- C:\Windows\Sysnative\mshtmled.dll 2015-02-11 17:25:00 4CE68D160D80AF6C9FDB5C60BA087DA5 1359360 ----a-w- C:\Windows\Sysnative\mshtmlmedia.dll 2015-02-11 17:24:59 BF57C911895454A8874E9DFA5716C624 584192 ----a-w- C:\Windows\Sysnative\vbscript.dll 2015-02-11 17:24:59 9DFE41A69DF70AAB75CB5BA8C1109EA2 2358272 ----a-w- C:\Windows\Sysnative\wininet.dll 2015-02-11 17:24:58 47162151E35EA0B7152B7C841FA21FDB 88064 ----a-w- C:\Windows\Sysnative\MshtmlDac.dll 2015-02-11 17:24:58 4701399F7BA312353ADE8225F6EB512B 199680 ----a-w- C:\Windows\Sysnative\msrating.dll 2015-02-11 17:24:57 CD726C899BD9A398E8420564A957320B 25056256 ----a-w- C:\Windows\Sysnative\mshtml.dll 2015-02-11 17:24:22 DDACB408E607655EC64269706BFD504C 341504 ----a-w- C:\Windows\Sysnative\schannel.dll 2015-02-11 17:24:22 C1F9E139B8AE80803CE44DC0377CA342 728064 ----a-w- C:\Windows\Sysnative\kerberos.dll 2015-02-11 17:24:22 A46A6C5AD462071B718EBF3C9E117849 309760 ----a-w- C:\Windows\Sysnative\ncrypt.dll 2015-02-11 17:24:22 6A06BCED1DF1CFE8A32E7D10ABAA7188 314880 ----a-w- C:\Windows\Sysnative\msv1_0.dll 2015-02-11 17:24:22 5350A548BEC957978B7014CDFF091542 210944 ----a-w- C:\Windows\Sysnative\wdigest.dll 2015-02-11 17:24:21 8F33880F1863BE3925D3A0121FAC5E8F 86528 ----a-w- C:\Windows\Sysnative\TSpkg.dll 2015-02-11 17:24:21 22E30E28865C32C3CF4F4E0E7E277FDC 22016 ----a-w- C:\Windows\Sysnative\credssp.dll 2015-02-11 17:24:03 AE4FEDD98096C09A8A86E021FC5E9D67 861696 ----a-w- C:\Windows\Sysnative\oleaut32.dll 2015-02-11 17:23:47 E5AF792AB409F600D416CB257C84305D 1480192 ----a-w- C:\Windows\Sysnative\crypt32.dll 2015-02-11 17:23:20 C97662B6752BFEF07C565D96E8ECC98F 1461760 ----a-w- C:\Windows\Sysnative\lsasrv.dll 2015-02-11 17:23:20 6EAD88B508E4785F4AFDFD24F76E8839 686080 ----a-w- C:\Windows\Sysnative\adtschema.dll 2015-02-11 17:23:19 E0105F3B5B1C4B0F5B3D788A13504EC6 31232 ----a-w- C:\Windows\Sysnative\lsass.exe 2015-02-11 17:23:19 BE4927689BA39E18A104986CB1363C97 146432 ----a-w- C:\Windows\Sysnative\msaudite.dll 2015-02-11 17:23:19 94C6BCF9212E20866AC1558A32E9F228 28160 ----a-w- C:\Windows\Sysnative\secur32.dll 2015-02-11 17:23:19 857CED230A6B87E84FCA04B472A3CB1A 136192 ----a-w- C:\Windows\Sysnative\sspicli.dll 2015-02-11 17:23:19 51BB93FF96AE3882B4AF7CA11000D3A3 64000 ----a-w- C:\Windows\Sysnative\auditpol.exe 2015-02-11 17:23:19 2EE57F4491A402C04FCAA7D012493884 29184 ----a-w- C:\Windows\Sysnative\sspisrv.dll 2015-02-11 17:23:19 1798826FE9FFEA9E93E74A5868559D4A 60416 ----a-w- C:\Windows\Sysnative\msobjs.dll 2015-02-11 17:22:58 2A25F5ACA9DCAF9AE9570DED13A8E078 3722752 ----a-w- C:\Windows\Sysnative\mstscax.dll 2015-02-11 17:22:01 FE72C89986E1BA32AD926A820491F23F 406528 ----a-w- C:\Windows\Sysnative\scesrv.dll 2015-02-11 17:21:51 9819614CA9EFB5A96493B379170B9D89 5554112 ----a-w- C:\Windows\Sysnative\ntoskrnl.exe 2015-02-11 17:21:34 F7A3018D8F1825427BC11E912D5287CD 296960 ----a-w- C:\Windows\Sysnative\rstrui.exe 2015-02-11 17:21:34 0147AA370862201A443752351F135D31 503808 ----a-w- C:\Windows\Sysnative\srcore.dll 2015-02-11 17:21:33 D6CDCAF84810641D1D2B455750825ACA 50176 ----a-w- C:\Windows\Sysnative\srclient.dll 2015-02-11 17:21:05 DF07110F77639E73D0537188703F44F6 3201536 ----a-w- C:\Windows\Sysnative\win32k.sys ====== C:\Windows\Sysnative\drivers ===== 2015-02-19 09:00:51 29F981739E50305128022CBE10B3659C 197704 ----a-w- C:\Windows\Sysnative\drivers\HipShieldK.sys 2015-02-11 17:23:20 E45CDE1C8340DFEDF1D6724263F39E5B 458824 ----a-w- C:\Windows\Sysnative\drivers\cng.sys 2015-02-11 17:23:20 C60C6B9A2E50B0404F6789C62B428C03 95680 ----a-w- C:\Windows\Sysnative\drivers\ksecdd.sys 2015-02-11 17:23:19 78D152A9FD5747FF6AA89C79F0346F62 155072 ----a-w- C:\Windows\Sysnative\drivers\ksecpkg.sys ====== C:\Windows\Tasks ====== 2015-02-06 13:29:10 E2212C53CEA7B15546C7C67854CB94F0 1056 ----a-w- C:\Windows\Tasks\GoogleUpdateTaskMachineUA1d04210e3fa3007.job 2015-02-06 13:29:10 30563557206CD7424662520DEF297AEE 4052 ----a-w- C:\Windows\Sysnative\Tasks\GoogleUpdateTaskMachineUA1d04210e3fa3007 ====== C:\Windows\Temp ====== ======= C:\Program Files ===== 2015-02-19 12:42:43 -------- d-----w- C:\Program Files\trend micro ======= C:\PROGRA~2 ===== 2015-02-19 15:53:05 -------- d-----w- C:\PROGRA~2\COMMON~1\Java 2015-02-19 15:51:52 -------- d-----w- C:\PROGRA~2\Java 2015-02-19 09:21:05 -------- d-----w- C:\PROGRA~2\COMMON~1\Adobe 2015-02-04 14:57:11 -------- d-----w- C:\PROGRA~2\Sonos ======= C: ===== ====== C:\Users\Bakkers\AppData\Roaming ====== 2015-02-19 09:40:52 -------- d-----w- C:\Windows\SysNative\config\systemprofile\AppData\Locallow\Sun 2015-02-04 15:25:33 -------- d-----w- C:\Users\Bakkers\AppData\Local\Sonos,_Inc ====== C:\Users\Bakkers ====== 2015-02-19 15:52:21 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2015-02-19 15:42:06 -------- d-----w- C:\ProgramData\Sun 2015-02-19 15:40:49 6713E17AFCB3A28191A747DC8C475721 639912 ----a-w- C:\Users\Bakkers\Downloads\jxpiinstall(2).exe 2015-02-19 15:38:34 6713E17AFCB3A28191A747DC8C475721 639912 ----a-w- C:\Users\Bakkers\Downloads\jxpiinstall(1).exe 2015-02-19 12:32:01 8045ABB21A3BDD66A48E1ED5C0F0EF6A 1222144 ----a-w- C:\Users\Bakkers\Desktop\RSITx64.exe 2015-02-19 09:36:58 -------- d-----w- C:\ProgramData\Oracle 2015-02-19 09:34:54 6713E17AFCB3A28191A747DC8C475721 639912 ----a-w- C:\Users\Bakkers\Downloads\jxpiinstall.exe 2015-02-04 14:57:15 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sonos 2015-02-04 14:55:52 -------- d-----w- C:\ProgramData\Sonos,_Inc ====== C: exe-files == 2015-02-19 15:52:25 B0D46640968F989830413EB88F43E0D0 0 ----a-we C:\ProgramData\Oracle\Java\javapath\java.exe 2015-02-19 15:52:25 52C8B9FD016E6317FDB151296FF90877 0 ----a-we C:\ProgramData\Oracle\Java\javapath\javaws.exe 2015-02-19 15:52:25 3E72E1AB196855916E2065C604674631 0 ----a-we C:\ProgramData\Oracle\Java\javapath\javaw.exe 2015-02-19 15:52:08 F9D744CD9BC58F287F8FA59D32508EDD 16296 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_31\bin\orbd.exe 2015-02-19 15:52:08 DBB5C8AE19ACFA2857CFB90C7305AC56 51112 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_31\bin\ssvagent.exe 2015-02-19 15:52:08 DA34E76DE9CD93471F24E7BD43139958 15784 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_31\bin\kinit.exe 2015-02-19 15:52:08 CDB1FE0DCF2ADB755EBF65C8AEBBC871 16296 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_31\bin\servertool.exe 2015-02-19 15:52:08 A8884FB8246655C84F110E77DF5E1B4A 15784 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_31\bin\ktab.exe 2015-02-19 15:52:08 8B6DF9CD28359C5E819446FD79CE3948 16296 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_31\bin\rmiregistry.exe 2015-02-19 15:52:08 7479DA0BED071427A3F0017AC51CC27B 159656 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_31\bin\unpack200.exe 2015-02-19 15:52:08 69BD74EE834B5629226BF89468B8020B 15784 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_31\bin\keytool.exe 2015-02-19 15:52:08 5F7C51E0DCA813D647F14FC12AE675F2 16296 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_31\bin\policytool.exe 2015-02-19 15:52:08 577F5DCBA4DE4C345631873670F84E79 16296 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_31\bin\tnameserv.exe 2015-02-19 15:52:08 39685FC75B6FB2144E793595F1AB111D 15784 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_31\bin\pack200.exe 2015-02-19 15:52:08 2F77C9862B1A2401278C4A5B932DA69D 15784 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_31\bin\klist.exe 2015-02-19 15:52:08 0FB2ACAC796B166F6486B593B604A3FF 15784 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_31\bin\rmid.exe 2015-02-19 15:52:07 AF82EA1498FEC5C49B8A1AE5AA0A5F6C 77224 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2launcher.exe 2015-02-19 15:52:07 90C02BD6D01BBC1C620323F9E330E89C 15784 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_31\bin\jjs.exe 2015-02-19 15:52:06 F5EA785B2BCC08DC28CBC2D96E05F2C1 68520 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_31\bin\javacpl.exe 2015-02-19 15:52:06 DF1C8EDDAF14D2960A06A9DF7B2D0A89 15784 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_31\bin\java-rmi.exe 2015-02-19 15:52:06 B0D46640968F989830413EB88F43E0D0 176552 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_31\bin\java.exe 2015-02-19 15:52:06 52C8B9FD016E6317FDB151296FF90877 272296 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_31\bin\javaws.exe 2015-02-19 15:52:06 3E72E1AB196855916E2065C604674631 176552 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_31\bin\javaw.exe 2015-02-19 15:52:06 063A1044A451660B159426B9C5E75957 30632 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_31\bin\jabswitch.exe 2015-02-19 15:40:49 6713E17AFCB3A28191A747DC8C475721 639912 ----a-w- C:\Users\Bakkers\Downloads\jxpiinstall(2).exe 2015-02-19 15:38:34 6713E17AFCB3A28191A747DC8C475721 639912 ----a-w- C:\Users\Bakkers\Downloads\jxpiinstall(1).exe 2015-02-19 12:42:49 9A2347903D6EDB84C10F288BC0578C1C 388608 ----a-w- C:\Program Files\trend micro\Bakkers.exe 2015-02-19 12:32:01 8045ABB21A3BDD66A48E1ED5C0F0EF6A 1222144 ----a-w- C:\Users\Bakkers\Desktop\RSITx64.exe 2015-02-19 10:33:36 FC5D475D2F6E1A4BA7D9E546B9B6AF71 82968 ----a-w- C:\Program Files (x86)\Microsoft SQL Server\100\Setup Bootstrap\Update Cache\KB2977321\GDR\x86\setup\1033\pfiles\sqlservr\100\setup\release\x86\setuparp.exe 2015-02-19 10:33:36 F1E94CCCD90389F3613F6DDC32CA57F7 46952 ----a-w- C:\Program Files (x86)\Microsoft SQL Server\100\Setup Bootstrap\Update Cache\KB2977321\GDR\x86\setup\1033\pfiles\sqlservr\100\setup\release\x86\b0k-cfdu.exe 2015-02-19 10:33:36 F1E94CCCD90389F3613F6DDC32CA57F7 46952 ----a-w- C:\Program Files (x86)\Microsoft SQL Server\100\Setup Bootstrap\Update Cache\KB2977321\GDR\x86\fixsqlregistrykey_x64.exe 2015-02-19 10:33:36 F0331E8F6BEB9C259EB9DE522F97230F 73376 ----a-w- C:\Program Files (x86)\Microsoft SQL Server\100\Setup Bootstrap\Update Cache\KB2977321\GDR\x86\setup100.exe 2015-02-19 10:33:36 F0331E8F6BEB9C259EB9DE522F97230F 73376 ----a-w- C:\Program Files (x86)\Microsoft SQL Server\100\Setup Bootstrap\Update Cache\KB2977321\GDR\x86\setup\1033\pfiles\sqlservr\100\setup\release\x86\setup100.exe 2015-02-19 10:33:36 694418005D57D5B5533B527C372D36CF 46952 ----a-w- C:\Program Files (x86)\Microsoft SQL Server\100\Setup Bootstrap\Update Cache\KB2977321\GDR\x86\setup\1033\pfiles\sqlservr\100\setup\release\x86\7bfmduuq.exe 2015-02-19 10:33:36 694418005D57D5B5533B527C372D36CF 46952 ----a-w- C:\Program Files (x86)\Microsoft SQL Server\100\Setup Bootstrap\Update Cache\KB2977321\GDR\x86\fixsqlregistrykey_ia64.exe 2015-02-19 10:33:36 54C79E61CC188CC62580A33B7498B126 116384 ----a-w- C:\Program Files (x86)\Microsoft SQL Server\100\Setup Bootstrap\Update Cache\KB2977321\GDR\x86\setup\1033\pfiles\sqlservr\100\setup\release\setup.exe 2015-02-19 10:33:36 54C79E61CC188CC62580A33B7498B126 116384 ----a-w- C:\Program Files (x86)\Microsoft SQL Server\100\Setup Bootstrap\Update Cache\KB2977321\GDR\setup.exe 2015-02-19 10:33:36 4CB6F6EA33A563C88385D2854523E506 433824 ----a-w- C:\Program Files (x86)\Microsoft SQL Server\100\Setup Bootstrap\Update Cache\KB2977321\GDR\x86\setup\1033\pfiles\sqlservr\100\setup\release\x86\qphmbavs.exe 2015-02-19 10:33:36 4CB6F6EA33A563C88385D2854523E506 433824 ----a-w- C:\Program Files (x86)\Microsoft SQL Server\100\Setup Bootstrap\Update Cache\KB2977321\GDR\x86\landingpage.exe 2015-02-19 10:33:36 49CD68E8ABF40DD037F094B9C5A20906 51048 ----a-w- C:\Program Files (x86)\Microsoft SQL Server\100\Setup Bootstrap\Update Cache\KB2977321\GDR\x86\setup\1033\pfiles\sqlservr\100\setup\release\x86\oax0i8iu.exe 2015-02-19 10:33:36 49CD68E8ABF40DD037F094B9C5A20906 51048 ----a-w- C:\Program Files (x86)\Microsoft SQL Server\100\Setup Bootstrap\Update Cache\KB2977321\GDR\x86\fixsqlregistrykey_x86.exe 2015-02-19 09:34:54 6713E17AFCB3A28191A747DC8C475721 639912 ----a-w- C:\Users\Bakkers\Downloads\jxpiinstall.exe 2015-02-19 09:26:23 FC5D475D2F6E1A4BA7D9E546B9B6AF71 82968 ----a-w- C:\Program Files (x86)\Microsoft SQL Server\100\Setup Bootstrap\Update Cache\KB2546951\ServicePack\x86\setup\1033\pfiles\sqlservr\100\setup\release\x86\setuparp.exe 2015-02-19 09:26:23 F1E94CCCD90389F3613F6DDC32CA57F7 46952 ----a-w- C:\Program Files (x86)\Microsoft SQL Server\100\Setup Bootstrap\Update Cache\KB2546951\ServicePack\x86\setup\1033\pfiles\sqlservr\100\setup\release\x86\b0k-cfdu.exe 2015-02-19 09:26:23 EF3A0FCD010A24D6356F6AC9DDAA013C 423784 ----a-w- C:\Program Files (x86)\Microsoft SQL Server\100\Setup Bootstrap\Update Cache\KB2546951\ServicePack\x86\setup\1033\pfiles\sqlservr\100\setup\release\x86\qphmbavs.exe 2015-02-19 09:26:23 694418005D57D5B5533B527C372D36CF 46952 ----a-w- C:\Program Files (x86)\Microsoft SQL Server\100\Setup Bootstrap\Update Cache\KB2546951\ServicePack\x86\setup\1033\pfiles\sqlservr\100\setup\release\x86\7bfmduuq.exe 2015-02-19 09:26:23 596DA4B8942D5C82EC26DC9DD4BBE720 106344 ----a-w- C:\Program Files (x86)\Microsoft SQL Server\100\Setup Bootstrap\Update Cache\KB2546951\ServicePack\x86\setup\1033\pfiles\sqlservr\100\setup\release\setup.exe 2015-02-19 09:26:23 49CD68E8ABF40DD037F094B9C5A20906 51048 ----a-w- C:\Program Files (x86)\Microsoft SQL Server\100\Setup Bootstrap\Update Cache\KB2546951\ServicePack\x86\setup\1033\pfiles\sqlservr\100\setup\release\x86\oax0i8iu.exe 2015-02-19 09:26:23 0057CC444261EC608B32D626D4CC5A3F 63336 ----a-w- C:\Program Files (x86)\Microsoft SQL Server\100\Setup Bootstrap\Update Cache\KB2546951\ServicePack\x86\setup\1033\pfiles\sqlservr\100\setup\release\x86\setup100.exe 2015-02-19 09:26:10 0057CC444261EC608B32D626D4CC5A3F 63336 ----a-w- C:\Program Files (x86)\Microsoft SQL Server\100\Setup Bootstrap\Update Cache\KB2546951\ServicePack\x86\setup100.exe 2015-02-19 09:26:09 F1E94CCCD90389F3613F6DDC32CA57F7 46952 ----a-w- C:\Program Files (x86)\Microsoft SQL Server\100\Setup Bootstrap\Update Cache\KB2546951\ServicePack\x86\fixsqlregistrykey_x64.exe 2015-02-19 09:26:09 EF3A0FCD010A24D6356F6AC9DDAA013C 423784 ----a-w- C:\Program Files (x86)\Microsoft SQL Server\100\Setup Bootstrap\Update Cache\KB2546951\ServicePack\x86\landingpage.exe 2015-02-19 09:26:09 694418005D57D5B5533B527C372D36CF 46952 ----a-w- C:\Program Files (x86)\Microsoft SQL Server\100\Setup Bootstrap\Update Cache\KB2546951\ServicePack\x86\fixsqlregistrykey_ia64.exe 2015-02-19 09:26:09 596DA4B8942D5C82EC26DC9DD4BBE720 106344 ----a-w- C:\Program Files (x86)\Microsoft SQL Server\100\Setup Bootstrap\Update Cache\KB2546951\ServicePack\setup.exe 2015-02-19 09:26:09 49CD68E8ABF40DD037F094B9C5A20906 51048 ----a-w- C:\Program Files (x86)\Microsoft SQL Server\100\Setup Bootstrap\Update Cache\KB2546951\ServicePack\x86\fixsqlregistrykey_x86.exe === C: other files == 2015-02-19 15:52:08 3315140254247E248C3531F159C79109 14130 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_31\lib\deploy\ffjcext.zip 2015-02-19 09:00:51 29F981739E50305128022CBE10B3659C 197704 ----a-w- C:\Windows\System32\drivers\HipShieldK.sys ==== Startup Registry Enabled ====================== [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun" [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun" [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce] "mctadmin"="C:\Windows\System32\mctadmin.exe" [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce] "mctadmin"="C:\Windows\System32\mctadmin.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IAStorIcon"="C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" "ISBMgr.exe"="C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe" "mcui_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey" "ConnectionCenter"="C:\Program Files (x86)\Citrix\ICA Client\concentr.exe /startup" "mcpltui_exe"="C:\Program Files\Common~1\McAfee\Platform\mcuicnt.exe /platui /runkey" "SunJavaUpdateSched"="C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" ==== Startup Registry Enabled x64 ====================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "cAudioFilterAgent"="C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe" "AtherosBtStack"="C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe" "AthBtTray"="C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe" "Apoint"="%ProgramFiles%\Apoint\Apoint.exe " ==== Startup Registry Disabled x64 ====================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Adobe ARM] "key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="Adobe ARM" "hkey"="HKLM" "command"="\"C:\\Program Files (x86)\\Common Files\\Adobe\\ARM\\1.0\\AdobeARM.exe\"" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Adobe Reader Speed Launcher] "key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="Adobe Reader Speed Launcher" "hkey"="HKLM" "command"="\"C:\\Program Files (x86)\\Adobe\\Reader 10.0\\Reader\\Reader_sl.exe\"" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\APSDaemon] "key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="APSDaemon" "hkey"="HKLM" "command"="\"C:\\Program Files (x86)\\Common Files\\Apple\\Apple Application Support\\APSDaemon.exe\"" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\BCSSync] "key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="BCSSync" "hkey"="HKLM" "command"="\"C:\\Program Files (x86)\\Microsoft Office\\Office14\\BCSSync.exe\" /DelayServices" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\HP Update 3400C] "key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="HP Update 3400C" "hkey"="HKLM" "command"="C:\\sj652\\hpupdate.exe 3400C" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\BBSvc] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\BBUpdate] ==== Task Scheduler Jobs ====================== C:\Windows\tasks\GoogleUpdateTaskMachineCore.job --a------ C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [12-09-2012 09:56] C:\Windows\tasks\GoogleUpdateTaskMachineUA1cf27f9c18d731d.job --a------ C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [12-09-2012 09:56] C:\Windows\tasks\GoogleUpdateTaskMachineUA1d04210e3fa3007.job --a------ C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [12-09-2012 09:56] ==== Other Scheduled Tasks ====================== "C:\Windows\SysNative\tasks\CreateChoiceProcessTask" [C:\Windows\System32\browserchoice.exe] "C:\Windows\SysNative\tasks\GoogleUpdateTaskMachineCore" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe] "C:\Windows\SysNative\tasks\GoogleUpdateTaskMachineUA1cf27f9c18d731d" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe] "C:\Windows\SysNative\tasks\GoogleUpdateTaskMachineUA1d04210e3fa3007" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe] "C:\Windows\SysNative\tasks\User_Feed_Synchronization-{5C497AA6-8DA4-4F51-9231-255D2BE41896}" [C:\Windows\system32\msfeedssync.exe] "C:\Windows\SysNative\tasks\User_Feed_Synchronization-{6257A744-0681-4FBB-8226-C3AD44A9D16A}" [C:\Windows\system32\msfeedssync.exe] "C:\Windows\SysNative\tasks\Apple\AppleSoftwareUpdate" [C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe] "C:\Windows\SysNative\tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask" [%systemroot%\system32\sc.exe start osppsvc] "C:\Windows\SysNative\tasks\SONY\VAIO Gate\StartExecuteProxy" ["%programfiles%\Sony\VAIO Gate\ExecutionProxy.exe"] "C:\Windows\SysNative\tasks\SONY\VAIO Gate\VAIO Gate" [C:\Program Files\Sony\VAIO Gate\VAIO Gate.exe] "C:\Windows\SysNative\tasks\Sony Corporation\VAIO Care\VAIO Care" ["%ProgramFiles%\Sony\VAIO Care\VCsystray.exe"] "C:\Windows\SysNative\tasks\Sony Corporation\VAIO Care\VCOneClick" ["%ProgramFiles%\Sony\VAIO Care\VCOneClick.exe"] "C:\Windows\SysNative\tasks\Sony Corporation\VAIO Improvement\VAIOImprovementUploader" [C:\Program Files\Sony\VAIO Improvement\viuploader.exe] "C:\Windows\SysNative\tasks\Sony Corporation\VAIO Improvement Validation\VAIO Improvement Validation" [C:\Program Files\Sony\VAIO Improvement Validation\viv.exe] "C:\Windows\SysNative\tasks\Sony Corporation\VAIO Smart Network\VSN Logon Start" [C:\Program Files\Sony\VAIO Smart Network\VSNClient] "C:\Windows\SysNative\tasks\Sony Corporation\VAIO Update\VAIO Update 5" ["C:\Program Files\Sony\VAIO Update 5\VAIOUpdt.exe"] ==== Firefox Start and Search pages ====================== ProfilePath: C:\Users\Bakkers\AppData\Roaming\Mozilla\Firefox\Profiles\g0nrecc9.default user_pref("browser.startup.homepage", "about:home"); user_pref("browser.newtab.url", "about:blank"); ==== Firefox Extensions Registry ====================== [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions] "{4ED1F68A-5463-4931-9384-8FFF5ED91D92}"="C:\Program Files (x86)\McAfee\SiteAdvisor" [13-02-2015 15:44] [HKEY_CURRENT_USER\Software\Mozilla\Firefox\Extensions] "{e4f94d1e-2f53-401e-8885-681602c0ddd8}"="C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi" [04-04-2014 11:36] ==== Firefox Extensions ====================== ProfilePath: C:\Users\Bakkers\AppData\Roaming\Mozilla\Firefox\Profiles\g0nrecc9.default - McAfee SiteAdvisor - C:\Program Files (x86)\McAfee\SiteAdvisor - Undetermined - {4ED1F68A-5463-4931-9384-8FFF5ED91D92} AppDir: C:\Program Files (x86)\Mozilla Firefox - Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} ==== Firefox Plugins ====================== Profilepath: C:\Users\Bakkers\AppData\Roaming\Mozilla\Firefox\Profiles\g0nrecc9.default C62322C77D1AAB77B1CF1130FCC3673A - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_305.dll - Shockwave Flash ==== Chromium Look ====================== HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions bopakagnckmlgajfccecajhnimjiiedh - No path found[] fheoggkfdfchfphceeifdbepaooicaho - C:\Program Files (x86)\McAfee\SiteAdvisor\McChPlg.crx[28-01-2015 15:25] ==== Set IE to Default ====================== Old Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Default_Page_URL"="http://vaioportal.sony.eu" "Use Search Asst"="yes" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl] "Default"="" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes] "DefaultScope"="{006ee092-9658-4fd6-bd8e-a21a348e59f5}" New Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157" "Use Search Asst"="no" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl] "(Default)"="http://search.msn.com/results.asp?q=%s" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes] "DefaultScope"="{012E1000-F331-11DB-8314-0800200C9A66}" ==== All HKCU SearchScopes ====================== HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes {012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}" {0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC" ==== Deleting Registry Keys ====================== HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher deleted successfully HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Update 3400C deleted successfully ==== Empty IE Cache ====================== C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Bakkers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Bakkers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully ==== Empty FireFox Cache ====================== C:\Users\Bakkers\AppData\Local\Mozilla\Firefox\Profiles\g0nrecc9.default\cache2 emptied successfully ==== Empty Chrome Cache ====================== No Chrome User Data found ==== Empty All Flash Cache ====================== Flash Cache Emptied Successfully ==== Empty All Java Cache ====================== Java Cache cleared successfully ==== C:\zoek_backup content ====================== C:\zoek_backup (files=3961 folders=1165 22517459 bytes) ==== Empty Temp Folders ====================== C:\Users\Bakkers\AppData\Local\Temp will be emptied at reboot C:\Users\Default\AppData\Local\Temp emptied successfully C:\Users\Default User\AppData\Local\Temp emptied successfully C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully C:\Windows\Temp will be emptied at reboot ==== After Reboot ====================== ==== Empty Temp Folders ====================== C:\Windows\Temp successfully emptied C:\Users\Bakkers\AppData\Local\Temp successfully emptied ==== Empty Recycle Bin ====================== C:\$RECYCLE.BIN successfully emptied ==== EOF on do 19-02-2015 at 17:46:19,66 ======================