Zoek.exe v5.0.0.0 Updated 07-March-2015 Tool run by T on za 07-03-2015 at 17:50:08,94. Microsoft Windows 8.1 Pro 6.3.9600 x64 Running in: Normal Mode Internet Access Detected Launched: E:\zoek.exe [Scan all users] [Script inserted] ==== System Restore Info ====================== 7-3-2015 17:51:58 Zoek.exe System Restore Point Created Succesfully. ==== Torpig Check ====================== HKEY_CLASSES_ROOT\Directory\shellex\CopyHookHandlers\FileSystem {217FC9C0-3AEA-1069-A2DB-08002B30309D} %SystemRoot%\system32\shell32.dll HKEY_CLASSES_ROOT\Directory\shellex\CopyHookHandlers\Sharing {40dd6e20-7c17-11ce-a804-00aa003ca9f6} %SystemRoot%\system32\ntshrui.dll ==== Empty Folders Check ====================== C:\PROGRA~2\Razer deleted successfully C:\Users\T\AppData\Roaming\Windows Live Writer deleted successfully C:\Users\T\AppData\Local\GHISLER deleted successfully ==== Services(whitelist) ====================== Powered by [url=http://www.antimalwarehelp.be/EDev/]E Dev[/url] R2 - [AdobeARMservice] - Adobe Acrobat Update Service - c:\program files (x86)\common files\adobe\arm\1.0\armsvc.exe R2 - [AMD External Events Utility] - AMD External Events Utility - c:\windows\system32\atiesrxx.exe R2 - [AntiVirSchedulerService] - Avira Planner - c:\program files (x86)\avira\antivir desktop\sched.exe R2 - [AntiVirService] - Avira Real-Time Protection - c:\program files (x86)\avira\antivir desktop\avguard.exe R2 - [ETDService] - Elan Service - c:\program files\elantech\etdservice.exe R2 - [WSearch] - Windows Search - c:\windows\system32\searchindexer.exe R3 - [VSS] - Volume Shadow Copy - c:\windows\system32\vssvc.exe S2 - [gupdate] - Google Update-service (gupdate) - c:\program files (x86)\google\update\googleupdate.exe S2 - [sppsvc] - Software Protection - c:\windows\system32\sppsvc.exe S2 - [TrustedInstaller] - Windows Modules Installer - c:\windows\servicing\trustedinstaller.exe S3 - [AdobeFlashPlayerUpdateSvc] - Adobe Flash Player Update Service - c:\windows\syswow64\macromed\flash\flashplayerupdateservice.exe S3 - [ALG] - Application Layer Gateway Service - c:\windows\system32\alg.exe S3 - [aspnet_state] - ASP.NET State Service - c:\windows\microsoft.net\framework\v1.1.4322\aspnet_state.exe S3 - [COMSysApp] - COM+ System Application - c:\windows\system32\dllhost.exe S3 - [Fax] - Fax - c:\windows\system32\fxssvc.exe S3 - [FontCache3.0.0.0] - Windows Presentation Foundation Font Cache 3.0.0.0 - c:\windows\microsoft.net\framework64\v3.0\wpf\presentationfontcache.exe S3 - [gupdatem] - Google Update-service (gupdatem) - c:\program files (x86)\google\update\googleupdate.exe S3 - [IEEtwCollectorService] - Internet Explorer ETW Collector Service - c:\windows\system32\ieetwcollector.exe S3 - [Microsoft Office Groove Audit Service] - Microsoft Office Groove Audit Service - c:\program files (x86)\microsoft office\office12\grooveauditservice.exe S3 - [MozillaMaintenance] - Mozilla Maintenance Service - c:\program files (x86)\mozilla maintenance service\maintenanceservice.exe S3 - [MSDTC] - Distributed Transaction Coordinator - c:\windows\system32\msdtc.exe S3 - [msiserver] - Windows Installer - c:\windows\system32\msiexec.exe S3 - [odserv] - Microsoft Office Diagnostics Service - c:\program files (x86)\common files\microsoft shared\office12\odserv.exe S3 - [ose] - Office Source Engine - c:\program files (x86)\common files\microsoft shared\source engine\ose.exe S3 - [PerfHost] - Performance Counter DLL Host - c:\windows\syswow64\perfhost.exe S3 - [RpcLocator] - Remote Procedure Call (RPC) Locator - c:\windows\system32\locator.exe S3 - [SNMPTRAP] - SNMP Trap - c:\windows\system32\snmptrap.exe S3 - [vds] - Virtual Disk - c:\windows\system32\vds.exe S3 - [wbengine] - Block Level Backup Engine Service - c:\windows\system32\wbengine.exe S3 - [WdNisSvc] - Windows Defender Network Inspection Service - c:\program files\windows defender\nissrv.exe S3 - [WinDefend] - Windows Defender Service - c:\program files\windows defender\msmpeng.exe S3 - [wmiApSrv] - WMI Performance Adapter - c:\windows\system32\wbem\wmiapsrv.exe S3 - [WMPNetworkSvc] - Windows Media Player Network Sharing Service - c:\program files\windows media player\wmpnetwk.exe ==== Deleting Files \ Folders ====================== "C:\WINDOWS\UC.PIF" deleted "C:\WINDOWS\RAR.PIF" deleted "C:\WINDOWS\PKZIP.PIF" deleted "C:\WINDOWS\PKUNZIP.PIF" deleted "C:\WINDOWS\NOCLOSE.PIF" deleted "C:\WINDOWS\LHA.PIF" deleted "C:\WINDOWS\ARJ.PIF" deleted ==== Files Recently Created / Modified ====================== ====== C:\WINDOWS ==== ====== C:\Users\T\AppData\Local\Temp ==== ====== Java Cache ===== ====== C:\WINDOWS\SysWOW64 ===== 2015-03-03 08:17:30 4FD3763F3917201856B0CBCE310003EA 4300800 ----a-w- C:\WINDOWS\SysWOW64\jscript9.dll 2015-02-27 18:41:44 FFE2F54DA7DE767C943F18823913EC07 736768 ----a-w- C:\WINDOWS\SysWOW64\adtschema.dll 2015-02-27 18:41:44 6705E8543E628DE9877F726C6B4A1E39 324096 ----a-w- C:\WINDOWS\SysWOW64\certcli.dll 2015-02-27 18:41:44 53670AE50F15C82990FCF599B02C6B36 154112 ----a-w- C:\WINDOWS\SysWOW64\msaudite.dll 2015-02-27 18:41:11 74887EBB4777EC450EF167645C99163E 602776 ----a-w- C:\WINDOWS\SysWOW64\oleaut32.dll 2015-02-27 18:41:09 C9E243A14893E41E1EF6D3A31BAEF08A 359424 ----a-w- C:\WINDOWS\SysWOW64\schannel.dll 2015-02-27 18:41:09 332625D3A96613A7CBC66B04F307F2FA 393728 ----a-w- C:\WINDOWS\SysWOW64\scesrv.dll 2015-02-27 18:41:08 F7A9D2E57D357B36C11F1C8269F2B05F 25600 ----a-w- C:\WINDOWS\SysWOW64\setup16.exe 2015-02-27 18:41:08 ACC85159376F84F49F8FE6D860E39A4F 8704 ----a-w- C:\WINDOWS\SysWOW64\instnm.exe 2015-02-27 18:41:08 A7AA844B8C4F7A5A13D85201877C84E5 1498360 ----a-w- C:\WINDOWS\SysWOW64\ntdll.dll 2015-02-27 18:41:08 3C908C70D5876D6B55D742A665DC88C7 14336 ----a-w- C:\WINDOWS\SysWOW64\ntvdm64.dll 2015-02-27 18:41:08 20FE9408E23EC6486CD995759B0BE02B 5632 ----a-w- C:\WINDOWS\SysWOW64\wow32.dll 2015-02-27 18:41:08 1D4E9DD1CF2B3A280FCF26693FBBD299 4096 ----a-w- C:\WINDOWS\SysWOW64\user.exe 2015-02-27 18:41:07 E398551943ABF67B0849C3049140056B 200704 ----a-w- C:\WINDOWS\SysWOW64\GlobCollationHost.dll 2015-02-27 18:41:07 D4A564BABFF82F56E68835FBFDA7AB00 513488 ----a-w- C:\WINDOWS\SysWOW64\locale.nls 2015-02-27 18:41:07 A830881BBCDE47DB73E6EF2E0640C193 868352 ----a-w- C:\WINDOWS\SysWOW64\Windows.Globalization.dll 2015-02-27 18:41:07 96750B86DA18725EBAE201989AAD9B98 1489072 ----a-w- C:\WINDOWS\SysWOW64\WindowsCodecs.dll 2015-02-27 18:41:05 61C74D794C14E9FC94D93F5F0F72A3F9 19740160 ----a-w- C:\WINDOWS\SysWOW64\mshtml.dll 2015-02-27 18:41:02 78A1A938D51D4F83A772123B93EE1612 12829184 ----a-w- C:\WINDOWS\SysWOW64\ieframe.dll 2015-02-27 18:41:01 E4D2BC3DA34348662960E5C2A66DD2F4 664064 ----a-w- C:\WINDOWS\SysWOW64\jscript.dll 2015-02-27 18:41:01 9DEE691C8FDBC2DE6957F1AE873C78FC 503296 ----a-w- C:\WINDOWS\SysWOW64\vbscript.dll 2015-02-27 18:41:01 9A91F9B5035F54C2D0BA92CF9B16EE34 2277888 ----a-w- C:\WINDOWS\SysWOW64\iertutil.dll 2015-02-27 18:41:01 8E8137569741D3693F88DDF94CC38C20 1307136 ----a-w- C:\WINDOWS\SysWOW64\urlmon.dll 2015-02-27 18:41:00 F285D499EC42969D963CA49EADA63218 1888256 ----a-w- C:\WINDOWS\SysWOW64\wininet.dll 2015-02-27 18:41:00 EF05E63ACC834470A07A2E73D519B5FA 418304 ----a-w- C:\WINDOWS\SysWOW64\dxtmsft.dll 2015-02-27 18:41:00 AD3F5926EC2C1F21FB45D1CDED6E2A47 2052608 ----a-w- C:\WINDOWS\SysWOW64\inetcpl.cpl 2015-02-27 18:41:00 9947D49276026A96D8ACDE9CBAAFC807 230400 ----a-w- C:\WINDOWS\SysWOW64\webcheck.dll 2015-02-27 18:41:00 8FBC9680719ACDA9351B67D906C682F4 688640 ----a-w- C:\WINDOWS\SysWOW64\msfeeds.dll 2015-02-27 18:41:00 47893802431547E170D36E033F846882 327168 ----a-w- C:\WINDOWS\SysWOW64\iedkcs32.dll 2015-02-27 18:41:00 3B9EF1B8E154D202D32A7765E2F33554 64000 ----a-w- C:\WINDOWS\SysWOW64\MshtmlDac.dll 2015-02-27 18:40:59 FD6AF61AF029B9BC2CF4EFF57CDD5821 710144 ----a-w- C:\WINDOWS\SysWOW64\ieapfltr.dll 2015-02-27 18:40:59 E06ED042936F8D932748FACCB229A52C 128000 ----a-w- C:\WINDOWS\SysWOW64\iepeers.dll 2015-02-27 18:40:59 94BD6172078CFB71B59A7AF56CF77AF9 880128 ----a-w- C:\WINDOWS\SysWOW64\inetcomm.dll ====== C:\WINDOWS\SysWOW64\drivers ===== ====== C:\WINDOWS\Sysnative ===== 2015-03-03 08:17:31 16ACAA0C01F31B39F39446188F6A3593 6041600 ----a-w- C:\WINDOWS\Sysnative\jscript9.dll 2015-02-27 18:41:44 F5BC103612FE72C176C751721B874FA6 445440 ----a-w- C:\WINDOWS\Sysnative\certcli.dll 2015-02-27 18:41:44 A40E52EB03C793735C916FC2C58A015F 154112 ----a-w- C:\WINDOWS\Sysnative\msaudite.dll 2015-02-27 18:41:44 8E0AA77F379DEA510D8AC00102C8D509 736768 ----a-w- C:\WINDOWS\Sysnative\adtschema.dll 2015-02-27 18:41:44 461729186C7F280019E369ECD652D4DB 1441792 ----a-w- C:\WINDOWS\Sysnative\lsasrv.dll 2015-02-27 18:41:11 6835D94FDAAB39E008E8490BD3E88CA3 788680 ----a-w- C:\WINDOWS\Sysnative\oleaut32.dll 2015-02-27 18:41:09 F8A442ABBAB56529B625DB9D916EA46A 538624 ----a-w- C:\WINDOWS\Sysnative\scesrv.dll 2015-02-27 18:41:09 3D2E3A5CFCE65310134C11A00D6D32D0 430080 ----a-w- C:\WINDOWS\Sysnative\schannel.dll 2015-02-27 18:41:09 3A620A263DA883515786E68BE3CE23AA 7472960 ----a-w- C:\WINDOWS\Sysnative\ntoskrnl.exe 2015-02-27 18:41:08 BC9E947C4B1E166CE2237871CAA4BDC0 16896 ----a-w- C:\WINDOWS\Sysnative\ntvdm64.dll 2015-02-27 18:41:08 9EC0B4E613DB6002DEF0346208E433E7 1762840 ----a-w- C:\WINDOWS\Sysnative\WindowsCodecs.dll 2015-02-27 18:41:08 7162FD845D142C542C0D041F3B3D525F 1733440 ----a-w- C:\WINDOWS\Sysnative\ntdll.dll 2015-02-27 18:41:08 63274242700279852B5CFFE4E2E0C6D1 13312 ----a-w- C:\WINDOWS\Sysnative\wow64cpu.dll 2015-02-27 18:41:08 57D55B8D3387C51758C785C425922C0E 285184 ----a-w- C:\WINDOWS\Sysnative\wow64.dll 2015-02-27 18:41:07 D4A564BABFF82F56E68835FBFDA7AB00 513488 ----a-w- C:\WINDOWS\Sysnative\locale.nls 2015-02-27 18:41:07 43647B730E82998201C61CA7FF7B524A 391526 ----a-w- C:\WINDOWS\Sysnative\ApnDatabase.xml 2015-02-27 18:41:07 3B63AA6552F66B518F85BD3A8ED7C2F5 323072 ----a-w- C:\WINDOWS\Sysnative\GlobCollationHost.dll 2015-02-27 18:41:07 3A7D8742A6BE524A2165F93375AE1872 1200128 ----a-w- C:\WINDOWS\Sysnative\Windows.Globalization.dll 2015-02-27 18:41:06 CD726C899BD9A398E8420564A957320B 25056256 ----a-w- C:\WINDOWS\Sysnative\mshtml.dll 2015-02-27 18:41:03 E0F76B5B904E4F448641B2B506496351 14401024 ----a-w- C:\WINDOWS\Sysnative\ieframe.dll 2015-02-27 18:41:01 BF57C911895454A8874E9DFA5716C624 584192 ----a-w- C:\WINDOWS\Sysnative\vbscript.dll 2015-02-27 18:41:01 A7A3775B0014B165D75A00A1F632E4B5 2885632 ----a-w- C:\WINDOWS\Sysnative\iertutil.dll 2015-02-27 18:41:01 9DFE41A69DF70AAB75CB5BA8C1109EA2 2358272 ----a-w- C:\WINDOWS\Sysnative\wininet.dll 2015-02-27 18:41:01 505815B1967A504B077497D304239B4A 816128 ----a-w- C:\WINDOWS\Sysnative\jscript.dll 2015-02-27 18:41:00 D7922F3AC6BF1EA77240E0061D648174 490496 ----a-w- C:\WINDOWS\Sysnative\dxtmsft.dll 2015-02-27 18:41:00 CF1488FCA487516DB09E797F3AC49E4A 2865152 ----a-w- C:\WINDOWS\Sysnative\actxprxy.dll 2015-02-27 18:41:00 CB2528D522FF1F5A7BF9B27D2FB250FF 1548288 ----a-w- C:\WINDOWS\Sysnative\urlmon.dll 2015-02-27 18:41:00 A04F0C4A0B80C92F92E854E7157D6466 92160 ----a-w- C:\WINDOWS\Sysnative\mshtmled.dll 2015-02-27 18:41:00 907B558B742B1E52E9E37E3CAAF6508E 262144 ----a-w- C:\WINDOWS\Sysnative\webcheck.dll 2015-02-27 18:41:00 8076BB31004C1D763D5D4AEF9F0BDD4B 718848 ----a-w- C:\WINDOWS\Sysnative\ie4uinit.exe 2015-02-27 18:41:00 76DB5845E168173BBA2D3CCC4B363E42 801280 ----a-w- C:\WINDOWS\Sysnative\msfeeds.dll 2015-02-27 18:41:00 49FABD0144A3BBD59D5DA1A0180DCE6E 374272 ----a-w- C:\WINDOWS\Sysnative\iedkcs32.dll 2015-02-27 18:41:00 47162151E35EA0B7152B7C841FA21FDB 88064 ----a-w- C:\WINDOWS\Sysnative\MshtmlDac.dll 2015-02-27 18:41:00 15842FB41A3BF2A2F5071518B38C957A 2125824 ----a-w- C:\WINDOWS\Sysnative\inetcpl.cpl 2015-02-27 18:40:59 F86097CFDE7624DA2DE246F5B4BE3704 1032704 ----a-w- C:\WINDOWS\Sysnative\inetcomm.dll 2015-02-27 18:40:59 7A388AFC6885D22F4D988EE9B8D1291A 800768 ----a-w- C:\WINDOWS\Sysnative\ieapfltr.dll 2015-02-27 18:40:41 E6905909E7334990033CFDAF56920004 4175872 ----a-w- C:\WINDOWS\Sysnative\win32k.sys 2015-02-27 18:40:21 BA0ED854110D45E5D4A46BD250BAF4E0 1487976 ----a-w- C:\WINDOWS\Sysnative\sppobjs.dll ====== C:\WINDOWS\Sysnative\drivers ===== 2015-03-06 16:50:59 CFF660F4E0F66724E3B0D921C1A1A880 43064 ----a-w- C:\WINDOWS\Sysnative\drivers\avnetflt.sys 2015-03-06 16:47:31 AF61774060F277FE45CBD3A9A8E7D45A 131608 ----a-w- C:\WINDOWS\Sysnative\drivers\avipbb.sys 2015-03-06 16:47:31 390184FAD8FCC1B6DA25AEBAE928C3B6 28600 ----a-w- C:\WINDOWS\Sysnative\drivers\avkmgr.sys 2015-03-06 16:47:31 1B87A1F2FA5B91AC1A7D171B8D952441 119272 ----a-w- C:\WINDOWS\Sysnative\drivers\avgntflt.sys 2015-03-01 19:08:18 D41D8CD98F00B204E9800998ECF8427E 0 ---ha-w- C:\WINDOWS\Sysnative\drivers\Msft_User_WpdMtpDr_01_11_00.Wdf 2015-02-27 18:41:44 3930E508DDA46C1FF68FD963F350AA0A 563504 ----a-w- C:\WINDOWS\Sysnative\drivers\cng.sys 2015-02-27 18:41:44 15C8C65CEA018C02EA0F648448C491C5 177984 ----a-w- C:\WINDOWS\Sysnative\drivers\ksecpkg.sys ====== C:\WINDOWS\Tasks ====== ====== C:\WINDOWS\Temp ====== ======= C:\Program Files ===== 2015-03-07 10:37:19 -------- d-----w- C:\Program Files\trend micro ======= C:\PROGRA~2 ===== 2015-03-07 16:46:46 -------- d-----w- C:\PROGRA~2\E Dev 2015-03-07 16:46:37 -------- d-----w- C:\PROGRA~2\Microsoft Synchronization Services 2015-03-06 16:47:29 -------- d-----w- C:\PROGRA~2\Avira 2015-03-04 18:41:41 -------- d-----w- C:\PROGRA~2\e-Sword 2015-03-04 18:41:41 -------- d-----w- C:\PROGRA~2\COMMON~1\EzTools 2015-03-04 17:36:31 -------- d-----w- C:\PROGRA~2\ISA2 ======= C: ===== ====== C:\Users\T\AppData\Roaming ====== 2015-03-07 16:43:37 -------- d-----w- C:\Users\T\AppData\Roaming\E Dev 2015-03-06 16:48:40 -------- d-----w- C:\Users\T\AppData\Roaming\Avira 2015-03-02 09:47:30 -------- d-----w- C:\Users\T\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Total Commander 2015-03-02 09:47:29 -------- d-----w- C:\Users\T\AppData\Roaming\GHISLER 2015-02-27 18:38:33 -------- d-----w- C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Google ====== C:\Users\T ====== 2015-03-07 16:47:06 2948807522953C32DA577DB6294268BE 111 ----a-w- C:\ProgramData\Microsoft.SqlServer.Compact.351.64.bc 2015-03-07 10:36:34 8045ABB21A3BDD66A48E1ED5C0F0EF6A 1222144 ----a-w- C:\Users\T\Desktop\RSITx64.exe 2015-03-07 10:36:31 68AF0DEBC5CDFD53095F22A300E1FF33 39739064 ----a-w- C:\Users\T\Desktop\Windows-KB890830-x64-V5.21.exe 2015-03-06 16:48:17 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira 2015-03-06 16:47:29 -------- d-----w- C:\ProgramData\Avira 2015-03-06 13:15:41 84FB4395F8FAB05BF2D606DC6D032745 134803704 ----a-w- C:\Users\T\Downloads\msert(2).exe 2015-03-06 13:13:43 F6272409139E0F5FFDCBDF1F2F26F5A7 16777216 ----a-w- C:\Users\T\Downloads\msert(1).exe 2015-03-06 11:14:08 F6272409139E0F5FFDCBDF1F2F26F5A7 16777216 ----a-w- C:\Users\T\Downloads\msert.exe 2015-03-04 18:41:43 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\e-Sword 2015-03-04 18:35:13 -------- d-----w- C:\ProgramData\InstallMate 2015-03-04 17:36:35 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ISA2 basic ====== C: exe-files == 2015-03-07 10:37:20 9A2347903D6EDB84C10F288BC0578C1C 388608 ----a-w- C:\Program Files\trend micro\T.exe 2015-03-07 10:36:34 8045ABB21A3BDD66A48E1ED5C0F0EF6A 1222144 ----a-w- C:\Users\T\Desktop\RSITx64.exe 2015-03-07 10:36:31 68AF0DEBC5CDFD53095F22A300E1FF33 39739064 ----a-w- C:\Users\T\Desktop\Windows-KB890830-x64-V5.21.exe 2015-03-07 07:33:56 71F60476D78730F34B7E4B7E64D2DDAB 281256 ----a-w- C:\Users\T\AppData\Local\Microsoft\OneDrive\OneDrive.exe 2015-03-07 07:33:56 53B50539A84F009DD70ACB4274A172D8 7212712 ----a-w- C:\Users\T\AppData\Local\Microsoft\SkyDrive\Update\OneDriveSetup.exe 2015-03-07 07:33:56 53B50539A84F009DD70ACB4274A172D8 7212712 ----a-w- C:\Users\T\AppData\Local\Microsoft\OneDrive\17.3.4724.0224\OneDriveSetup.exe 2015-03-07 07:33:09 D0FA81AF0E12A4961D9687E6A43E6211 112808 ----a-w- C:\Users\T\AppData\Local\Microsoft\OneDrive\17.3.4724.0224\FileSyncConfig.exe 2015-03-06 16:47:37 1760501720176500A3FDD91A9AE4596F 494328 ----a-w- C:\Program Files (x86)\Avira\AntiVir Desktop\wsctool.exe 2015-03-06 16:47:33 C2700D35AA42311A32DF7EA09630B401 431920 ----a-w- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe 2015-03-06 16:47:33 B738781F55FD0DDA6CF698DB94398648 1063728 ----a-w- C:\Program Files (x86)\Avira\AntiVir Desktop\update.exe 2015-03-06 16:47:33 921427ED219D403273F3D4E4F0E61FB8 418096 ----a-w- C:\Program Files (x86)\Avira\AntiVir Desktop\setuppending.exe 2015-03-06 16:47:33 86F299E972EFC911D420B18DA0D4B286 485112 ----a-w- C:\Program Files (x86)\Avira\AntiVir Desktop\licmgr.exe 2015-03-06 16:47:33 83A79903B37B5FB7F2270556653D02B7 69880 ----a-w- C:\Program Files (x86)\Avira\AntiVir Desktop\toastnotifier.exe 2015-03-06 16:47:33 27D75D3B73AA23A02D5939CB75E96C21 394032 ----a-w- C:\Program Files (x86)\Avira\AntiVir Desktop\updrgui.exe 2015-03-06 16:47:33 1C1964F85EE571D788DC8330E1F0195B 452856 ----a-w- C:\Program Files (x86)\Avira\AntiVir Desktop\ipmgui.exe 2015-03-06 16:47:33 163AF349B309539B9737FC8EF9CD7DD6 1834288 ----a-w- C:\Program Files (x86)\Avira\AntiVir Desktop\setup.exe 2015-03-06 16:47:33 063381603B58FD09CF6C3E37E337F54B 489208 ----a-w- C:\Program Files (x86)\Avira\AntiVir Desktop\inssda64.exe 2015-03-06 16:47:32 F104799A40E954596D326E70846C8D5C 465200 ----a-w- C:\Program Files (x86)\Avira\AntiVir Desktop\ccuac.exe 2015-03-06 16:47:32 E20F64703B8CDCE036EBB03C7E99347D 880376 ----a-w- C:\Program Files (x86)\Avira\AntiVir Desktop\fact.exe 2015-03-06 16:47:32 C011EA41CAFC32B8454A90CD5C6D9985 401200 ----a-w- C:\Program Files (x86)\Avira\AntiVir Desktop\checkt.exe 2015-03-06 16:47:32 A4D96077263AF3442A13DE3CCE17A7B1 659704 ----a-w- C:\Program Files (x86)\Avira\AntiVir Desktop\guardgui.exe 2015-03-06 16:47:32 6BF71CFA3F441D83246EB555CE2E62AC 4583696 ----a-w- C:\Program Files (x86)\Avira\AntiVir Desktop\avira_nl____fm.exe 2015-03-06 16:47:31 FDFA68518DF393B67322562BF5AE077F 410360 ----a-w- C:\Program Files (x86)\Avira\AntiVir Desktop\avupgsvc.exe 2015-03-06 16:47:31 C2700D35AA42311A32DF7EA09630B401 431920 ----a-w- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe 2015-03-06 16:47:31 A9FF6304EABD4AED70BBA6349FF9CEA5 820472 ----a-w- C:\Program Files (x86)\Avira\AntiVir Desktop\avconfig.exe 2015-03-06 16:47:31 A162B967A88BF374A81E01EF6E7A2655 702768 ----a-w- C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe 2015-03-06 16:47:31 4A50A8CBFA1D6477A0ABCBE153523F03 624432 ----a-w- C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe 2015-03-06 16:47:31 4959D50AF27559BFCAC93601F32D5338 497400 ----a-w- C:\Program Files (x86)\Avira\AntiVir Desktop\avwebloader.exe 2015-03-06 16:47:31 45323697924B2FEB891B3EF5C888CCB3 703280 ----a-w- C:\Program Files (x86)\Avira\AntiVir Desktop\avcenter.exe 2015-03-06 16:47:31 27C5D1CB95D8E5B37297806A39762F3E 1015544 ----a-w- C:\Program Files (x86)\Avira\AntiVir Desktop\avscan.exe 2015-03-06 16:47:31 1D078D054F81CB58853CDF2BA7EE7DBA 702712 ----a-w- C:\Program Files (x86)\Avira\AntiVir Desktop\avnotify.exe 2015-03-06 16:47:31 0B7DA5867F7F7A7484411207FAA8D5E6 547576 ----a-w- C:\Program Files (x86)\Avira\AntiVir Desktop\avrestart.exe 2015-03-06 16:47:31 0AA9A452FA676F0DD09FFB8FA189430B 1043664 ----a-w- C:\Program Files (x86)\Avira\AntiVir Desktop\avwsc.exe 2015-03-06 16:47:31 051A7A9C035BBAB779E2C96E65C32600 992560 ----a-w- C:\Program Files (x86)\Avira\AntiVir Desktop\avwebgrd.exe 2015-03-06 16:47:31 027820FE847A7B4245234A4E6E825BE1 993584 ----a-w- C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe 2015-03-06 16:47:30 AAAF6BA1F7C06F931BFEB3E3743D0427 417072 ----a-w- C:\Program Files (x86)\Avira\AntiVir Desktop\avadmin.exe 2015-03-06 13:43:37 912EEEBA43664B4A714CF5A9BEAA679F 30979114 ----a-w- C:\$Recycle.Bin\S-1-5-21-3057933925-990916983-583638778-1001\$R5BZ0UI\MotorMaster+ International\setup\MMIntl14Setup.exe 2015-03-06 13:43:37 18F1662F60B17BD4949571C8FCABA0F7 9065110 ----a-w- C:\$Recycle.Bin\S-1-5-21-3057933925-990916983-583638778-1001\$R5BZ0UI\MotorMaster+ International\setup\Setup.exe 2015-03-06 13:43:34 3FFECAAA589979BE9DEC12B317B55B8B 1150688 ----a-w- C:\$Recycle.Bin\S-1-5-21-3057933925-990916983-583638778-1001\$R5BZ0UI\Jauffrey Abber\slib-3b4-1.exe 2015-03-06 13:43:32 8D852FF5AA1CFEF4C17A1B5DD1988CDD 2994176 ----a-w- C:\$Recycle.Bin\S-1-5-21-3057933925-990916983-583638778-1001\$R5BZ0UI\FSAT\FSAT2004setup.exe 2015-03-06 13:43:32 80D0B30282F137F515812CF54871F7B6 486788 ----a-w- C:\$Recycle.Bin\S-1-5-21-3057933925-990916983-583638778-1001\$R5BZ0UI\Jauffrey Abber\scm-5f1-1.exe 2015-03-06 13:43:31 F8A4DDDAEBFBCD63A742B29D003D9284 20290992 ----a-w- C:\$Recycle.Bin\S-1-5-21-3057933925-990916983-583638778-1001\$R5BZ0UI\Compressie\LogTool V2 Install.EXE 2015-03-06 13:43:29 15EF9E69C93E33BBF9DCB3D03E4EA579 12081509 ----a-w- C:\$Recycle.Bin\S-1-5-21-3057933925-990916983-583638778-1001\$R5BZ0UI\AirMaster\AIRMasterSetup.exe 2015-03-06 13:42:49 CF33003D6CF2BA5AAB830D0C36D57228 17581729 ----a-w- C:\$Recycle.Bin\S-1-5-21-3057933925-990916983-583638778-1001\$R5BZ0UI\PEPOffline\PEPOffline.exe 2015-03-06 13:42:46 234E1B5CC23959F6FD4B018CF5CA0337 1988096 ----a-w- C:\$Recycle.Bin\S-1-5-21-3057933925-990916983-583638778-1001\$R5BZ0UI\EnPI-v4.0\EnPI-v4.0\Visual Studio Runtime 3.0\vstor30.exe 2015-03-06 13:42:46 1C59142FB26D3CE83202A9E5BEE90F79 816640 ----a-w- C:\$Recycle.Bin\S-1-5-21-3057933925-990916983-583638778-1001\$R5BZ0UI\EnPI-v4.0\EnPI-v4.0\setup.exe 2015-03-06 13:42:43 CD4980DAABA0371AEDEE1247EBAF56A3 979886 ----a-w- C:\$Recycle.Bin\S-1-5-21-3057933925-990916983-583638778-1001\$R5BZ0UI\Mollier chart 2.1b.exe 2015-03-06 13:15:41 84FB4395F8FAB05BF2D606DC6D032745 134803704 ----a-w- C:\Users\T\Downloads\msert(2).exe 2015-03-06 13:13:43 F6272409139E0F5FFDCBDF1F2F26F5A7 16777216 ----a-w- C:\Users\T\Downloads\msert(1).exe 2015-03-06 11:14:08 F6272409139E0F5FFDCBDF1F2F26F5A7 16777216 ----a-w- C:\Users\T\Downloads\msert.exe 2015-03-04 19:44:40 7EA5D6C2CE669BBCCEF968DEDC37E2AF 9092688 ----a-w- C:\Program Files (x86)\Google\Update\Install\{E228B731-5EDC-4299-BF0C-A7BA00D068A9}\41.0.2272.76_40.0.2214.115_chrome_updater.exe 2015-03-04 19:44:39 7EA5D6C2CE669BBCCEF968DEDC37E2AF 9092688 ----a-w- C:\Program Files (x86)\Google\Update\Download\{4DC8B4CA-1BDA-483E-B5FA-D3C12E15B62D}\41.0.2272.76\41.0.2272.76_40.0.2214.115_chrome_updater.exe 2015-03-04 18:55:00 C7595A6E11F65E0FBA0456589B07B5DF 544 ----a-w- C:\$Recycle.Bin\S-1-5-21-3057933925-990916983-583638778-1001\$I5Z95L2.exe 2015-03-04 18:46:22 676747C8D3C39082592C1AAFAB6527F8 544 ----a-w- C:\$Recycle.Bin\S-1-5-21-3057933925-990916983-583638778-1001\$IRWG8A4.exe 2015-03-04 18:36:06 E717F6CE3A7429BFA6D7F3CF66737A4B 15968 --s-a-r- C:\ProgramData\InstallMate\{0915922B-7D64-4063-A8F4-312B7B9FDC3D}\Setup.exe 2015-03-04 18:35:54 81BB13DB404C3344FF40BFCF92F2AFFD 75776 --sh--r- C:\Program Files (x86)\ISA2\Setup.exe 2015-03-04 18:35:27 7C9A4B37EBCEE81A5520EBF9C3DA5A02 1162087 ----a-w- C:\$Recycle.Bin\S-1-5-21-3057933925-990916983-583638778-1001\$RRWG8A4.exe 2015-03-04 18:35:13 E717F6CE3A7429BFA6D7F3CF66737A4B 15968 --s-a-r- C:\ProgramData\InstallMate\{9E220BC7-409E-4AD7-9D46-11B353E51146}\Setup.exe 2015-03-04 17:36:31 571D3C1D482A757D73BC5527C1846D96 1196233 ----a-w- C:\Program Files (x86)\ISA2\unins000.exe 2015-03-04 17:36:31 06B6FCCD357F4A19A0DFDB7BD80664AC 4941824 ----a-w- C:\Program Files (x86)\ISA2\ISA.exe 2015-03-04 17:30:45 7C9A4B37EBCEE81A5520EBF9C3DA5A02 1162087 ----a-w- C:\Users\T\Downloads\gedownloade programma-zips&executables\bijbel\mod_ISA20_YLT.exe 2015-03-04 17:30:16 5928659FBB24FD422080FF2FC2DF4263 7138619 ----a-w- C:\Users\T\Downloads\gedownloade programma-zips&executables\bijbel\ISA_basic_v2_1_5.exe 2015-03-04 17:29:23 EBE9EFBE4820AE2BEC4322047D76DF5E 53354447 ----a-w- C:\Users\T\Downloads\gedownloade programma-zips&executables\bijbel\setup1040.exe 2015-03-02 09:47:30 E94764E624677F9B05DF8C9752254387 2106 ----a-w- C:\totalcmd\SHARE_NT.EXE 2015-03-02 09:47:30 E31F5989B8EA2EBAE157AF8F87BFA307 37592 ----a-w- C:\totalcmd\TCUNINST.EXE 2015-03-02 09:47:30 B52BFFE5AB8134A5C0139794F6B66A2F 115416 ----a-w- C:\totalcmd\TCMDX64.EXE 2015-03-02 09:47:30 AFB2E4EC9E32B7649486B1A69845DCF9 73432 ----a-w- C:\totalcmd\TCMADMIN.EXE 2015-03-02 09:47:30 704C7F7CC912D3BB8856A6B5D061A9DC 3514112 ----a-w- C:\totalcmd\TOTALCMD.EXE 2015-03-02 09:47:30 552B40663B6F22377AF1809AF85711E3 3328 ----a-w- C:\totalcmd\WC32TO16.EXE 2015-03-02 09:44:33 E2C2227B775B546BBDAB7F12960AC457 3204400 ----a-w- C:\Users\T\Downloads\Total Commander 7.50\tcmd750.exe 2015-03-02 09:44:32 38636D921622D1B691E090B43FEC8F42 3453024 ----a-w- C:\Users\T\Downloads\Total Commander 7.50\tcm801x32.exe 2015-03-01 01:39:28 23F9D4CAE5C1A90415F77E1E051B2A0F 11592 ----a-w- C:\Program Files (x86)\E Dev\E-Peek\E-Peek 1.9.9.0.vshost.exe 2015-03-01 01:39:02 846EB15AE6A63C65348EF85ECA0E85B2 1162752 ----a-w- C:\Program Files (x86)\E Dev\E-Peek\E-Peek 1.9.9.0.exe === C: other files == 2015-03-07 07:33:05 6DA967AC75C23FBFB920A54A40607812 5843 ----a-w- C:\Users\T\AppData\Local\Microsoft\OneDrive\17.3.4724.0224\CollectOneDriveLogs.bat 2015-03-06 16:50:59 CFF660F4E0F66724E3B0D921C1A1A880 43064 ----a-w- C:\Windows\System32\drivers\avnetflt.sys 2015-03-06 16:47:33 D66430ED8DF1E05D0F694B6BE3C1FB48 43040 ----a-w- C:\Program Files (x86)\Avira\AntiVir Desktop\sweb.zip 2015-03-06 16:47:31 CFF660F4E0F66724E3B0D921C1A1A880 43064 ----a-w- C:\Program Files (x86)\Avira\AntiVir Desktop\avnetflt.sys 2015-03-06 16:47:31 AF61774060F277FE45CBD3A9A8E7D45A 131608 ----a-w- C:\Windows\System32\drivers\avipbb.sys 2015-03-06 16:47:31 AF61774060F277FE45CBD3A9A8E7D45A 131608 ----a-w- C:\Program Files (x86)\Avira\AntiVir Desktop\avipbb.sys 2015-03-06 16:47:31 390184FAD8FCC1B6DA25AEBAE928C3B6 28600 ----a-w- C:\Windows\System32\drivers\avkmgr.sys 2015-03-06 16:47:31 390184FAD8FCC1B6DA25AEBAE928C3B6 28600 ----a-w- C:\Program Files (x86)\Avira\AntiVir Desktop\avkmgr.sys 2015-03-06 16:47:31 1B87A1F2FA5B91AC1A7D171B8D952441 119272 ----a-w- C:\Windows\System32\drivers\avgntflt.sys 2015-03-06 16:47:31 1B87A1F2FA5B91AC1A7D171B8D952441 119272 ----a-w- C:\Program Files (x86)\Avira\AntiVir Desktop\avgntflt.sys 2015-03-06 13:43:36 E0A1FE3B78A55F4D72862C24CC73D901 97 ----a-w- C:\$Recycle.Bin\S-1-5-21-3057933925-990916983-583638778-1001\$R5BZ0UI\programmas van internet\Jauffrey Abber\SimRoof\SimRoof\sr.bat 2015-03-06 13:43:32 56C43B1FE8D69A54C7237FEEB2E6ABCB 14840210 ----a-w- C:\$Recycle.Bin\S-1-5-21-3057933925-990916983-583638778-1001\$R5BZ0UI\Jauffrey Abber\SimRoof.zip 2015-03-06 13:43:32 52CCC18433050B535510911902EA1609 3272647 ----a-w- C:\$Recycle.Bin\S-1-5-21-3057933925-990916983-583638778-1001\$R5BZ0UI\FSAT\FSAT.zip 2015-03-06 13:43:28 F037E0D995105FE73DA512042CEA9F8D 1221079 ----a-w- C:\$Recycle.Bin\S-1-5-21-3057933925-990916983-583638778-1001\$R5BZ0UI\etmgeg_240.zip 2015-03-06 13:43:28 0F78C836837854CEECB955F4A68D9062 699338 ----a-w- C:\$Recycle.Bin\S-1-5-21-3057933925-990916983-583638778-1001\$R5BZ0UI\uurgeg_240_2011-2020.zip 2015-03-06 13:42:44 A1F0B6F2C331A428EEA03F6370314FB8 11055154 ----a-w- C:\$Recycle.Bin\S-1-5-21-3057933925-990916983-583638778-1001\$R5BZ0UI\EnPI-v4.0.zip 2015-03-06 13:42:44 7827A671539796D5DBA632DEA7CE5D13 18404624 ----a-w- C:\$Recycle.Bin\S-1-5-21-3057933925-990916983-583638778-1001\$R5BZ0UI\PEPOffline.zip 2015-03-06 13:42:43 603E0ABF26E8FFC3C447A34904CD80AD 2483743 ----a-w- C:\$Recycle.Bin\S-1-5-21-3057933925-990916983-583638778-1001\$R5BZ0UI\eGuide_Lite.zip 2015-03-02 09:47:30 C8B5858AEBB4782AE16533297EF1F9BE 7888 ----a-w- C:\totalcmd\CGLPTNT.SYS ==== Startup Registry Enabled ====================== [HKEY_USERS\S-1-5-21-3057933925-990916983-583638778-1001\Software\Microsoft\Windows\CurrentVersion\Run] "HydraVisionDesktopManager"="C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe" "msnmsgr"="C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe /background" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "StartCCC"="C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe MSRun" "SonicMasterTray"="C:\Program Files (x86)\ASUS\ASUS Sonic Focus\SonicFocusTray.exe" "GrooveMonitor"="C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" "SunJavaUpdateSched"="C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" "Adobe ARM"="C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" "avgnt"="C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe /min" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "HydraVisionDesktopManager"="C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe" "msnmsgr"="C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe /background" ==== Startup Registry Enabled x64 ====================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RtHDVCpl"="C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s" "RtHDVBg"="C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe /SF3 " "Logitech Download Assistant"="C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch" ==== Startup Folders ====================== 2014-11-04 22:27:23 1210 ----a-w- C:\Users\T\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\LibreOffice 4.3 .lnk 2015-03-07 12:44:58 1326 ----a-w- C:\Users\T\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Schermopname en Snel starten.lnk ==== Task Scheduler Jobs ====================== C:\WINDOWS\tasks\Adobe Flash Player Updater.job --a-------- C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [27-02-2015 19:48] C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job --a-------- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [13-11-2014 12:33] C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job --a-------- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [13-11-2014 12:33] ==== Other Scheduled Tasks ====================== "C:\WINDOWS\SysNative\tasks\Adobe Flash Player Updater" [C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe] "C:\WINDOWS\SysNative\tasks\GoogleUpdateTaskMachineCore" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe] "C:\WINDOWS\SysNative\tasks\GoogleUpdateTaskMachineUA" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe] "C:\WINDOWS\SysNative\tasks\{B373AC22-4C9D-424C-9165-7CB2C7332F28}" ["c:\program files (x86)\mozilla firefox\firefox.exe"] ==== Folders in C:\PROGRA~3 0-6 Months Old ====================== 2014-11-03 12:07:17 -------- d-sh--we C:\PROGRA~3\Bureaublad 2014-11-03 12:07:17 -------- d-sh--we C:\PROGRA~3\Documenten 2014-11-03 12:07:17 -------- d-sh--we C:\PROGRA~3\Menu Start 2014-11-03 12:07:17 -------- d-sh--we C:\PROGRA~3\Sjablonen 2014-11-03 12:09:33 -------- d-----w- C:\PROGRA~3\PRICache 2014-11-03 12:24:34 -------- d-----w- C:\PROGRA~3\AMD 2014-11-03 12:25:20 -------- d-----w- C:\PROGRA~3\Qualcomm Atheros 2014-11-03 12:25:34 -------- d-----w- C:\PROGRA~3\ATI 2014-11-03 12:37:53 -------- d-----w- C:\PROGRA~3\Microsoft Help 2014-11-03 13:23:15 -------- d-----w- C:\PROGRA~3\Mozilla 2014-11-05 12:29:09 -------- d--h--w- C:\PROGRA~3\CanonBJ 2014-11-13 12:15:40 -------- d-----w- C:\PROGRA~3\Oracle 2014-11-17 15:47:03 -------- d-----w- C:\PROGRA~3\SonicFocus 2014-11-17 15:47:11 -------- d-----w- C:\PROGRA~3\Package Cache 2014-11-18 14:49:00 -------- d-----w- C:\PROGRA~3\Razer 2014-11-30 18:52:42 -------- d-----w- C:\PROGRA~3\Microsoft OneDrive 2014-11-30 19:10:48 -------- d-----w- C:\PROGRA~3\Skype 2014-12-11 15:33:37 -------- d-----w- C:\PROGRA~3\Sun 2014-12-23 13:54:08 -------- d-----w- C:\PROGRA~3\Autodesk 2015-01-06 13:00:16 -------- d-----w- C:\PROGRA~3\Adobe 2015-03-04 18:35:13 -------- d-----w- C:\PROGRA~3\InstallMate 2015-03-06 16:47:29 -------- d-----w- C:\PROGRA~3\Avira ==== Firefox Start and Search pages ====================== ProfilePath: C:\Users\T\AppData\Roaming\Mozilla\Firefox\Profiles\uawlfi8e.default user_pref("services.sync.prefs.sync.browser.search.selectedEngine", true); ==== Firefox Extensions ====================== ProfilePath: C:\Users\T\AppData\Roaming\Mozilla\Firefox\Profiles\uawlfi8e.default - StartPage Site Search - %ProfilePath%\extensions\jid0-Ah0CrdmFQuvYtoNKD1ABdh39ysI@jetpack.xpi - Mp3Olimp widget - %ProfilePath%\extensions\jid0-SlJAN1IqVQffaO5onLnWK2zcA1Q@jetpack.xpi - Walnut pour Firefox em:descriptionWalnut pour Firefox bas sur des icnes de art.gnome.org. Inclut le support de DOM inspector downloadstatusbar QuickNote Offline Googlebar tabsidebar Stylish adblockplus DataManager Flagfox Forecast Weather Hide Caption ViewAbout TabMixPlus AllInOneSidebar StumbleUpon et Favicon Restorer. - %ProfilePath%\extensions\{5A170DD3-63CA-4c58-93B7-DE9FF536C2FF}.xpi AppDir: C:\Program Files (x86)\Mozilla Firefox - Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} ==== Firefox Plugins ====================== Profilepath: C:\Users\T\AppData\Roaming\Mozilla\Firefox\Profiles\uawlfi8e.default C62322C77D1AAB77B1CF1130FCC3673A - C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_305.dll - Shockwave Flash ==== Chromium Look ====================== Google Slides - T\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek Google Docs - T\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake Google Drive - T\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf YouTube - T\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo Google Search - T\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf Google Sheets - T\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap Elite Unzip - T\AppData\Local\Google\Chrome\User Data\Default\Extensions\gafhhbahpojnjfhpepjjfjojbphnogmn Google Wallet - T\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda Gmail - T\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia ==== C:\zoek_backup content ====================== C:\zoek_backup (files=8 folders=0 4190 bytes) ==== EOF on za 07-03-2015 at 17:55:12,47 ======================