Zoek.exe v5.0.0.0 Updated 08-April-2015 Tool run by Laurens on di 14/04/2015 at 12:12:46,21. Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x64 Running in: Normal Mode Internet Access Detected Launched: C:\Users\Laurens\Desktop\zoek.exe [Scan all users] [Script inserted] ==== System Restore Info ====================== 14/04/2015 12:18:00 Zoek.exe System Restore Point Created Successfully. ==== Torpig Check ====================== HKEY_CLASSES_ROOT\Directory\shellex\CopyHookHandlers\FileSystem {217FC9C0-3AEA-1069-A2DB-08002B30309D} %SystemRoot%\system32\shell32.dll HKEY_CLASSES_ROOT\Directory\shellex\CopyHookHandlers\Sharing {40dd6e20-7c17-11ce-a804-00aa003ca9f6} %SystemRoot%\system32\ntshrui.dll ==== Registry Fix Code x64 ====================== Windows Registry Editor Version 5.00 [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ApnTBMon] [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\certunas] tools\msconfig\startupreg\lollipop] ==== Deleting Files \ Folders ====================== C:\Program Files (x86)\AskPartnerNetwork not found "C:\Users\Laurens\AppData\Roaming\i2KP16dgfO6HxP1w7u6.exe" not found c:\users\laurens\appdata\local\lollipop deleted C:\Program Files (x86)\ssavaernet deleted C:\Program Files (x86)\Page up top deleted C:\Program Files (x86)\dealsteRR deleted C:\Program Files (x86)\SaviunGGtooyou deleted C:\ProgramData\ApPtooU deleted C:\ProgramData\deaL4RReoal deleted C:\Program Files (x86)\deall4real deleted C:\Windows\syswow64\appdata deleted "C:\Windows\tasks\i2KP16dgfO6HxP1w7u6.job" deleted ==== Files Found In C:\ProgramData\7304566480615253663UL ====================== 2015-02-23 17:26:35 157 ----a-w- 3E6098FBFD0452161007417C86F99CAC C:\PROGRA~3\730456~1\F8EF2A~1.INI --- C:\ProgramData\7304566480615253663UL\f8ef2aa6bc56bc0a30cd85ea0e57591f.ini 2015-03-02 15:43:30 316 ----a-w- 0EAF4FF286F42D2E44CF6190A1B457D7 C:\PROGRA~3\730456~1\5B31CF~1.INI --- C:\ProgramData\7304566480615253663UL\5b31cf0f3a6595b530cd85ea0e57591f.ini 2015-03-02 15:43:38 672 ----a-w- 9439E352C110ACE91D1CE2470BEA94DC C:\PROGRA~3\730456~1\D36A95~1.INI --- C:\ProgramData\7304566480615253663UL\d36a95d0e9623ae330cd85ea0e57591f.ini 2015-03-02 15:43:52 544 ----a-w- CF72AC6A2187BD72C578C96C0339E3B9 C:\PROGRA~3\730456~1\0C680D~1.INI --- C:\ProgramData\7304566480615253663UL\0c680dc79a16060b30cd85ea0e57591f.ini 2015-03-02 15:44:05 544 ----a-w- 40B26E8E5FBD93D2D3E579009D105915 C:\PROGRA~3\730456~1\1B61FD~1.INI --- C:\ProgramData\7304566480615253663UL\1b61fd0709c3e5d930cd85ea0e57591f.ini 2015-03-06 09:53:18 534 ----a-w- 81D1706DC94D91AF611A9D3D4227727D C:\PROGRA~3\730456~1\7D7758~1.INI --- C:\ProgramData\7304566480615253663UL\7d7758bb23aa150330cd85ea0e57591f.ini 2015-03-16 16:34:50 549 ----a-w- 4D09A0200341327BAD6AF49F7A782044 C:\PROGRA~3\730456~1\C0B20D~1.INI --- C:\ProgramData\7304566480615253663UL\c0b20d2c8886023b30cd85ea0e57591f.ini 2015-03-16 16:35:07 544 ----a-w- 654462A8786AFEA86029BB661B378417 C:\PROGRA~3\730456~1\44774F~1.INI --- C:\ProgramData\7304566480615253663UL\44774fbbb3cd445930cd85ea0e57591f.ini 2015-03-16 16:35:12 658 ----a-w- 6383C2286B08FBA8BC7377763294089D C:\PROGRA~3\730456~1\DD20F8~1.INI --- C:\ProgramData\7304566480615253663UL\dd20f8c9fde812d330cd85ea0e57591f.ini 2015-03-16 16:35:16 317 ----a-w- 69705E031A68F9F4495AADEBC26ED939 C:\PROGRA~3\730456~1\4E87E1~1.INI --- C:\ProgramData\7304566480615253663UL\4e87e1ba2eb2a44a30cd85ea0e57591f.ini ==== Files Recently Created / Modified ====================== ====== C:\Windows ==== ====== C:\Users\Laurens\AppData\Local\Temp ==== 2015-04-13 12:34:57 962B85D5BC8945D80B4839E47EFE8FDD 152456 ------w- C:\Users\Laurens\AppData\Local\Temp\{A4DCF9F0-780F-4F65-960C-E8F35FA901A2}\ISBEW64.exe 2015-04-09 17:37:28 A082E5473B2A9A4D846ED7DDF637AC76 8704 ----a-w- C:\Users\Laurens\AppData\Local\Temp\SpOrder.dll 2015-04-09 17:34:52 EBE0FD9B62D5D25D4F3F9A6504F38ED4 7782704 ----a-w- C:\Users\Laurens\AppData\Local\Temp\87cb3ba8-e5dc-4aaf-8729-8ad13de51e5d.exe 2015-04-09 15:50:56 67614407088F2BE94C1A0EAC6B0B5902 23496 ----a-w- C:\Users\Laurens\AppData\Local\Temp\avgnt.exe\Avira.OE.ExtApi.dll ====== Java Cache ===== ====== C:\Windows\SysWOW64 ===== 2015-04-09 17:37:26 C85A2849F9E3389E70D5240D0EB77A0A 326288 ----a-w- C:\Windows\SysWOW64\LavasoftTcpService.dll ====== C:\Windows\SysWOW64\drivers ===== ====== C:\Windows\Sysnative ===== 2015-04-09 17:37:29 ADC083FC7EB215A8FC3D32482DC8F211 373864 ----a-w- C:\Windows\Sysnative\LavasoftTcpService64.dll ====== C:\Windows\Sysnative\drivers ===== 2015-04-09 21:08:41 2822B2CA0A86850D3F2B851D154C8B3A 76064 ----a-w- C:\Windows\Sysnative\drivers\McPvDrv.sys 2015-04-09 21:07:34 29F981739E50305128022CBE10B3659C 197704 ----a-w- C:\Windows\Sysnative\drivers\HipShieldK.sys 2015-04-08 15:54:25 853BF373351C40334C08544167973A89 51608 ----a-w- C:\Windows\Sysnative\drivers\asd2fsm.sys ====== C:\Windows\Tasks ====== 2015-04-09 20:17:54 D1BB03227C225660E5B57947886B1F53 3368 ----a-w- C:\Windows\Sysnative\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-3635746246-4039717782-239317034-1004 2015-04-03 14:04:00 A76EEB2260F84379ED17696C33E43EDC 3216 ----a-w- C:\Windows\Sysnative\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-3635746246-4039717782-239317034-1004 2015-04-03 14:03:55 B398F8D498104F738E6F9C685D3BF16A 3346 ----a-w- C:\Windows\Sysnative\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-3635746246-4039717782-239317034-1004 2015-04-03 13:43:43 7F4895F3FB68DDA8F40E2F057B193D5A 4352 ----a-w- C:\Windows\Sysnative\Tasks\disco_games_notification_service 2015-04-03 13:43:42 4BA8EE390627CC1CFBE267C77978178A 1324 ----a-w- C:\Windows\Tasks\disco_games_notification_service.job 2015-04-03 13:42:56 D9B2CCB411E7677041AEB06372A3A428 3238 ----a-w- C:\Windows\Sysnative\Tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-3635746246-4039717782-239317034-1004 ====== C:\Windows\Temp ====== ======= C:\Program Files ===== 2015-04-13 15:34:49 -------- d-----w- C:\Program Files\trend micro ======= C:\PROGRA~2 ===== 2015-04-13 21:41:14 -------- d-----w- C:\PROGRA~2\COMMON~1\Skype 2015-04-13 21:41:13 -------- d-----r- C:\PROGRA~2\Skype 2015-04-09 15:37:39 -------- d-----w- C:\PROGRA~2\Avira 2015-04-08 15:54:04 -------- d-----w- C:\PROGRA~2\Anvisoft 2015-04-03 13:43:38 -------- d-----w- C:\PROGRA~2\disco games ======= C: ===== ====== C:\Users\Laurens\AppData\Roaming ====== 2015-04-13 21:41:54 -------- d-----w- C:\Users\Laurens\AppData\Local\Skype 2015-04-13 21:39:50 -------- d-----w- C:\Users\Laurens\AppData\Roaming\OpenCandy 2015-04-09 17:38:14 -------- d-----w- C:\Users\Laurens\AppData\Roaming\LavasoftStatistics ====== C:\Users\Laurens ====== 2015-04-13 21:41:14 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype 2015-04-13 21:38:27 2FFBEE5B531686AA96B02F7D0DED208C 1740112 ----a-w- C:\Users\Laurens\Downloads\uTorrent(2).exe 2015-04-13 21:37:55 2FFBEE5B531686AA96B02F7D0DED208C 1740112 ----a-w- C:\Users\Laurens\Downloads\uTorrent(1).exe 2015-04-13 15:32:54 8045ABB21A3BDD66A48E1ED5C0F0EF6A 1222144 ----a-w- C:\Users\Laurens\Desktop\RSITx64.exe 2015-04-09 19:02:36 -------- d-----w- C:\Users\Laurens\Start Menu 2015-04-09 18:59:54 4531B3AE34E9A70CDD938F8F27203989 3107200 ----a-w- C:\Users\Laurens\Downloads\SpyHunter-Installer-k.com 2015-04-09 17:29:11 1B9F05E1C6FD84C13F703DA569136418 2057008 ----a-w- C:\Users\Laurens\Downloads\Adaware_Installer.exe 2015-04-09 15:37:39 -------- d-----w- C:\ProgramData\Avira 2015-04-09 15:36:36 44215DA62895A1909D68CBB6BEF2F593 4625104 ----a-w- C:\Users\Laurens\Downloads\avira_en_av_55269c014af40__wsm.exe 2015-04-09 15:29:44 FDC0E5B389A5097065CBA0F91D313277 1630952 ----a-w- C:\Users\Laurens\Downloads\PANDAFREEAV.exe 2015-04-08 15:58:28 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Anvisoft 2015-04-08 15:54:12 -------- d-----w- C:\ProgramData\Anvisoft ====== C: exe-files == 2015-04-13 21:40:01 5412F2551D2DEBA8F662E913C99362C9 41578080 ----a-w- C:\Users\Laurens\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8RTJJAWP\SkypeSetupFull[1].exe 2015-04-13 21:39:52 87EA9812FF1BD916BE99B6D444B8B293 73408 ----a-w- C:\Users\Laurens\AppData\Roaming\OpenCandy\OpenCandy_27FDD6D5E2B8423BB2843FCAC8C07793\dyesubd1_p3v0.exe 2015-04-13 21:39:51 2FFBEE5B531686AA96B02F7D0DED208C 1740112 ----a-w- C:\Users\Laurens\AppData\Roaming\uTorrent\uTorrent.exe 2015-04-13 21:38:44 2FFBEE5B531686AA96B02F7D0DED208C 1740112 ----a-w- C:\Users\Laurens\AppData\Roaming\uTorrent\updates\3.4.3_39944.exe 2015-04-13 21:38:27 2FFBEE5B531686AA96B02F7D0DED208C 1740112 ----a-w- C:\Users\Laurens\Downloads\uTorrent(2).exe 2015-04-13 21:37:55 2FFBEE5B531686AA96B02F7D0DED208C 1740112 ----a-w- C:\Users\Laurens\Downloads\uTorrent(1).exe 2015-04-13 15:34:50 9A2347903D6EDB84C10F288BC0578C1C 388608 ----a-w- C:\Program Files\trend micro\Laurens.exe 2015-04-13 15:33:47 74CB86C8CA869806D369999EB9A0EAE5 544 ----a-w- C:\$RECYCLE.BIN\S-1-5-21-3635746246-4039717782-239317034-1004\$I4Q1FB3.exe 2015-04-13 15:32:54 8045ABB21A3BDD66A48E1ED5C0F0EF6A 1222144 ----a-w- C:\Users\Laurens\Desktop\RSITx64.exe 2015-04-13 15:32:31 8685FAF50C04F9A9C2F56FF64B0B7ACB 1107968 ----a-w- C:\$RECYCLE.BIN\S-1-5-21-3635746246-4039717782-239317034-1004\$R4Q1FB3.exe 2015-04-13 12:34:57 962B85D5BC8945D80B4839E47EFE8FDD 152456 ------w- C:\Users\Laurens\AppData\Local\Temp\{A4DCF9F0-780F-4F65-960C-E8F35FA901A2}\ISBEW64.exe 2015-04-13 09:29:10 B7087D251D441311045381BEBBDD8F9E 243480 ----a-w- C:\Users\Laurens\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\N0UR2PKH\Firefox Setup Stub 37.0.1.exe 2015-04-13 09:15:17 727602958ADF261B5ABBCBA93C823980 102400 ----a-w- C:\Users\Laurens\AppData\Roaming\Mozilla\Firefox\Profiles\kic4cxak.default-1428649081503\CertUtils\certutil.exe 2015-04-10 06:58:10 727602958ADF261B5ABBCBA93C823980 102400 ----a-w- C:\Users\Laurens\Desktop\Oude Firefox-gegevens\ct49jm5d.default-1428592226600\CertUtils\certutil.exe 2015-04-09 17:34:52 EBE0FD9B62D5D25D4F3F9A6504F38ED4 7782704 ----a-w- C:\Users\Laurens\AppData\Local\Temp\87cb3ba8-e5dc-4aaf-8729-8ad13de51e5d.exe 2015-04-09 17:29:11 1B9F05E1C6FD84C13F703DA569136418 2057008 ----a-w- C:\Users\Laurens\Downloads\Adaware_Installer.exe 2015-04-09 15:36:36 44215DA62895A1909D68CBB6BEF2F593 4625104 ----a-w- C:\Users\Laurens\Downloads\avira_en_av_55269c014af40__wsm.exe 2015-04-09 15:29:44 FDC0E5B389A5097065CBA0F91D313277 1630952 ----a-w- C:\Users\Laurens\Downloads\PANDAFREEAV.exe 2015-04-09 15:21:40 A8AEA74C825FA59C0B2A93AB94F44E1B 544 ----a-w- C:\$RECYCLE.BIN\S-1-5-21-3635746246-4039717782-239317034-1004\$I2ZSVFF.exe 2015-04-09 15:21:12 52AD04D228B321E2D8326750E5E87FF9 544 ----a-w- C:\$RECYCLE.BIN\S-1-5-21-3635746246-4039717782-239317034-1004\$IZ67ZVY.exe 2015-04-08 15:53:14 A06ECC44992367D9A9F4C95BA5E71EC3 35947248 ----a-w- C:\$RECYCLE.BIN\S-1-5-21-3635746246-4039717782-239317034-1004\$RZ67ZVY.exe === C: other files == 2015-04-13 21:38:40 CFA95D80D873D12726261AF452D4E5E0 16 ----a-w- C:\Users\Laurens\AppData\Local\Temp\HYD932B.tmp.1428961119\HTA\install.1428961120.zip 2015-04-13 13:17:31 1BA7273113ED65D74F7F21265BFD75C7 103 ----a-w- C:\Users\Laurens\AppData\Local\Temp\utt7D8E.tmp.bat 2015-04-13 13:17:20 F2F18BC5529FFD6B9B22B18972E10202 68 ----a-w- C:\Users\Laurens\AppData\Local\Temp\HYD52C6.tmp.1428931040\HTA\install.1428931040.zip 2015-04-13 13:17:12 F2F18BC5529FFD6B9B22B18972E10202 68 ----a-w- C:\Users\Laurens\AppData\Local\Temp\HYD3519.tmp.1428931032\HTA\install.1428931032.zip 2015-04-13 09:15:08 AD2B8BC22259A8DBA5BDA074DBDD60D7 1840349 ----a-w- C:\Users\Laurens\AppData\Roaming\Mozilla\Firefox\Profiles\kic4cxak.default-1428649081503\CertUtils.zip 2015-04-10 06:58:14 AD2B8BC22259A8DBA5BDA074DBDD60D7 1840349 ----a-w- C:\Users\Laurens\Desktop\Oude Firefox-gegevens\ct49jm5d.default-1428592226600\CertUtils.zip 2015-04-09 21:08:41 2822B2CA0A86850D3F2B851D154C8B3A 76064 ----a-w- C:\Windows\System32\drivers\McPvDrv.sys 2015-04-09 21:07:34 29F981739E50305128022CBE10B3659C 197704 ----a-w- C:\Windows\System32\drivers\HipShieldK.sys 2015-04-09 18:59:54 4531B3AE34E9A70CDD938F8F27203989 3107200 ----a-w- C:\Users\Laurens\Downloads\SpyHunter-Installer-k.com 2015-04-08 15:54:25 853BF373351C40334C08544167973A89 51608 ----a-w- C:\Windows\System32\drivers\asd2fsm.sys ==== Startup Registry Enabled ====================== [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "TOSHIBA Online Product Information"="C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe" [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun" [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun" [HKEY_USERS\S-1-5-21-3635746246-4039717782-239317034-1004\Software\Microsoft\Windows\CurrentVersion\Run] "Web Companion"="C:\Program Files (x86)\Lavasoft\Web Companion\Application\WebCompanion.exe --minimize" [HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run] "TOSHIBA Online Product Information"="C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe" [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce] "mctadmin"="C:\Windows\System32\mctadmin.exe" [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce] "mctadmin"="C:\Windows\System32\mctadmin.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ToshibaServiceStation"="C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe /hide:60" "mcui_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey" "mcpltui_exe"="C:\Program Files\Common~1\McAfee\Platform\mcuicnt.exe /platui /runkey" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "Web Companion"="C:\Program Files (x86)\Lavasoft\Web Companion\Application\WebCompanion.exe --minimize" ==== Startup Registry Enabled x64 ====================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IgfxTray"="C:\Windows\system32\igfxtray.exe" "HotKeysCmds"="C:\Windows\system32\hkcmd.exe" "Persistence"="C:\Windows\system32\igfxpers.exe" "cAudioFilterAgent"="C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe" "SmartAudio"="C:\Program Files\CONEXANT\SAII\SAIICpl.exe /t" "TosVolRegulator"="C:\Program Files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe" "TPwrMain"="%ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE" "SmoothView"="%ProgramFiles%\Toshiba\SmoothView\SmoothView.exe " "00TCrdMain"="%ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe " "SynTPEnh"="%ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe " ==== Startup Registry Disabled x64 ====================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Adobe ARM] "key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="Adobe ARM" "hkey"="HKLM" "command"="\"C:\\Program Files (x86)\\Common Files\\Adobe\\ARM\\1.0\\AdobeARM.exe\"" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Adobe Reader Speed Launcher] "key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="Adobe Reader Speed Launcher" "hkey"="HKLM" "command"="\"C:\\Program Files (x86)\\Adobe\\Reader 9.0\\Reader\\Reader_sl.exe\"" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\APSDaemon] "key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="APSDaemon" "hkey"="HKLM" "command"="\"C:\\Program Files (x86)\\Common Files\\Apple\\Apple Application Support\\APSDaemon.exe\"" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Facebook Update] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="Facebook Update" "hkey"="HKCU" "command"="\"C:\\Users\\Laurens\\AppData\\Local\\Facebook\\Update\\FacebookUpdate.exe\" /c /nocrashserver" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\HP Officejet 6600 (NET)] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="HP Officejet 6600 (NET)" "hkey"="HKCU" "command"="\"C:\\Program Files\\HP\\HP Officejet 6600\\Bin\\ScanToPCActivationApp.exe\" -deviceID \"CN43R8R0N905RN:NW\" -scfn \"HP Officejet 6600 (NET)\" -AutoStart 1" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\HP Software Update] "key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="HP Software Update" "hkey"="HKLM" "command"="C:\\Program Files (x86)\\Hp\\HP Software Update\\HPWuSchd2.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\iTunesHelper] "key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="iTunesHelper" "hkey"="HKLM" "command"="\"C:\\Program Files (x86)\\iTunes\\iTunesHelper.exe\"" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\lollipop] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="lollipop" "hkey"="HKCU" "command"="\"c:\\users\\laurens\\appdata\\local\\lollipop\\lollipop.exe\" lollipop" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\NBAgent] "key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="NBAgent" "hkey"="HKLM" "command"="\"c:\\Program Files (x86)\\Nero\\Nero BackItUp & Burn\\Nero BackItUp\\NBAgent.exe\" /WinStart" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Optimizer Pro] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="Optimizer Pro" "hkey"="HKCU" "command"="C:\\Program Files (x86)\\Optimizer Pro\\OptProLauncher.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\OV3_Monitor] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="OV3_Monitor" "hkey"="HKCU" "command"="\"C:\\Program Files (x86)\\OLYMPUS\\OLYMPUS Viewer 3\\OV3Monitor.exe\" -NoStart" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\QuickTime Task] "key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="QuickTime Task" "hkey"="HKLM" "command"="\"C:\\Program Files (x86)\\QuickTime\\QTTask.exe\" -atboottime" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\SmartFaceVWatcher] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="SmartFaceVWatcher" "hkey"="HKLM" "command"="%ProgramFiles%\\Toshiba\\SmartFaceV\\SmartFaceVWatcher.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\SoMud] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="SoMud" "hkey"="HKCU" "command"="\"C:\\Program Files (x86)\\SoMud\\somud.exe\" /bg" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Spotify] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="Spotify" "hkey"="HKCU" "command"="\"C:\\Users\\Laurens\\AppData\\Roaming\\Spotify\\Spotify.exe\" /uri spotify:autostart" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Spotify Web Helper] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="Spotify Web Helper" "hkey"="HKCU" "command"="\"C:\\Users\\Laurens\\AppData\\Roaming\\Spotify\\Data\\SpotifyWebHelper.exe\"" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\TkBellExe] "key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="TkBellExe" "hkey"="HKLM" "command"="\"c:\\program files (x86)\\real\\realplayer\\Update\\realsched.exe\" -osboot" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\TOSHIBA Online Product Information] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="TOSHIBA Online Product Information" "hkey"="HKCU" "command"="C:\\Program Files (x86)\\TOSHIBA\\TOSHIBA Online Product Information\\topi.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Toshiba TEMPRO] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="Toshiba TEMPRO" "hkey"="HKLM" "command"="C:\\Program Files (x86)\\Toshiba TEMPRO\\TemproTray.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ToshibaServiceStation] "key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="ToshibaServiceStation" "hkey"="HKLM" "command"="\"C:\\Program Files (x86)\\TOSHIBA\\TOSHIBA Service Station\\ToshibaServiceStation.exe\" /hide:60" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\TosNC] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="TosNC" "hkey"="HKLM" "command"="%ProgramFiles%\\Toshiba\\BulletinBoard\\TosNcCore.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\TosReelTimeMonitor] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="TosReelTimeMonitor" "hkey"="HKLM" "command"="%ProgramFiles%\\TOSHIBA\\ReelTime\\TosReelTimeMonitor.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\TosSENotify] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="TosSENotify" "hkey"="HKLM" "command"="C:\\Program Files\\TOSHIBA\\TOSHIBA HDD SSD Alert\\TosWaitSrv.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\TWebCamera] "key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="TWebCamera" "hkey"="HKLM" "command"="\"C:\\Program Files (x86)\\TOSHIBA\\TOSHIBA Web Camera Application\\TWebCamera.exe\" autorun" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^RealPlayer Cloud Service UI.lnk] "path"="C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\RealPlayer Cloud Service UI.lnk" "backup"="C:\\Windows\\pss\\RealPlayer Cloud Service UI.lnk.CommonStartup" "backupExtension"=".CommonStartup" "command"="C:\\PROGRA~2\\Real\\REALPL~1\\RPDS\\Bin64\\RPSYST~1.EXE " "item"="RealPlayer Cloud Service UI" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Users^Laurens^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Facebook Messenger.lnk] "path"="C:\\Users\\Laurens\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\Facebook Messenger.lnk" "backup"="C:\\Windows\\pss\\Facebook Messenger.lnk.Startup" "backupExtension"=".Startup" "command"="C:\\Users\\Laurens\\AppData\\Local\\Facebook\\MESSEN~1\\214651~1.0\\FACEBO~1.EXE " "item"="Facebook Messenger" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Users^Laurens^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Inktwaarschuwingen controleren - HP Officejet 6500 E710a-f.lnk] "path"="C:\\Users\\Laurens\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\Inktwaarschuwingen controleren - HP Officejet 6500 E710a-f.lnk" "backup"="C:\\Windows\\pss\\Inktwaarschuwingen controleren - HP Officejet 6500 E710a-f.lnk.Startup" "backupExtension"=".Startup" "command"="C:\\Windows\\system32\\RunDll32.exe \"C:\\Program Files\\HP\\HP Officejet 6500 E710a-f\\bin\\HPStatusBL.dll\",RunDLLEntry SERIALNUMBER=CN07V122F205JZ;CONNECTION=USB;MONITOR=1;" "item"="Inktwaarschuwingen controleren - HP Officejet 6500 E710a-f" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Users^Laurens^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Inktwaarschuwingen controleren - HP Officejet 6600 (netwerk).lnk] "path"="C:\\Users\\Laurens\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\Inktwaarschuwingen controleren - HP Officejet 6600 (netwerk).lnk" "backup"="C:\\Windows\\pss\\Inktwaarschuwingen controleren - HP Officejet 6600 (netwerk).lnk.Startup" "backupExtension"=".Startup" "command"="C:\\Windows\\system32\\RunDll32.exe \"C:\\Program Files\\HP\\HP Officejet 6600\\bin\\HPStatusBL.dll\",RunDLLEntry SERIALNUMBER=CN43R8R0N905RN;CONNECTION=NW;MONITOR=1;" "item"="Inktwaarschuwingen controleren - HP Officejet 6600 (netwerk)" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Users^User^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^StartUp^Dropbox.lnk] "path"="C:\\Users\\User\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\StartUp\\Dropbox.lnk" "backup"="C:\\Windows\\pss\\Dropbox.lnk.Startup" "backupExtension"=".Startup" "command"="C:\\Users\\User\\AppData\\Roaming\\Dropbox\\bin\\Dropbox.exe /systemstartup" "item"="Dropbox" ==== Startup Folders ====================== 2010-04-20 13:39:23 1258 ----a-w- C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk 2010-04-20 13:39:23 1258 ----a-w- C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk 2011-12-22 13:32:14 1258 ----a-w- C:\Users\Gast\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk 2012-06-28 17:17:42 1272 ----a-w- C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk 2011-12-21 10:09:37 1517 ----a-w- C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Schermopname en Snel starten.lnk 2014-05-01 11:14:04 1938 ----a-w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk ==== Task Scheduler Jobs ====================== C:\Windows\tasks\Adobe Flash Player Updater.job --a------ C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [12/02/2015 20:06] C:\Windows\tasks\disco_games_notification_service.job --a------ C:\Program Files (x86)\disco games\disco_games_notification_service.exe [] C:\Windows\tasks\GoogleUpdateTaskMachineCore.job --a------ C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [02/12/2010 18:05] C:\Windows\tasks\GoogleUpdateTaskMachineUA.job --a------ C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [02/12/2010 18:05] C:\Windows\tasks\SDMsgUpdate (Local).job --a------ C:\PROGRA2\SMARTD1\Messages\SDNotify.exe [] C:\Windows\tasks\SDMsgUpdate (TE).job --a------ C:\PROGRA2\SMARTD1\Messages\SDNotify.exe [] ==== Other Scheduled Tasks ====================== "C:\Windows\SysNative\tasks\Ad-Aware Update (Weekly)" [C:\Program Files (x86)\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe] "C:\Windows\SysNative\tasks\Adobe Flash Player Updater" [C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe] "C:\Windows\SysNative\tasks\ConfigFree Startup Programs" [C:\Program Files (x86)\TOSHIBA\ConfigFree\NDSTray.exe] "C:\Windows\SysNative\tasks\disco_games_notification_service" [C:\Program Files (x86)\disco games\disco_games_notification_service.exe] "C:\Windows\SysNative\tasks\GoogleUpdateTaskMachineCore" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe] "C:\Windows\SysNative\tasks\GoogleUpdateTaskMachineUA" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe] "C:\Windows\SysNative\tasks\HPCustParticipation HP Officejet 6500 E710a-f" ["C:\Program Files\HP\HP Officejet 6500 E710a-f\Bin\HPCustPartic.exe"] "C:\Windows\SysNative\tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-3635746246-4039717782-239317034-1004" [C:\Program Files (x86)\RealNetworks\RealDownloader\realupgrade.exe] "C:\Windows\SysNative\tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-3635746246-4039717782-239317034-1004" [C:\Program Files (x86)\RealNetworks\RealDownloader\realupgrade.exe] "C:\Windows\SysNative\tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-3635746246-4039717782-239317034-1004" [C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe] "C:\Windows\SysNative\tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-3635746246-4039717782-239317034-1004" [C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe] "C:\Windows\SysNative\tasks\SDMsgUpdate (Local)" [C:\PROGRA~2\SMARTD~1\Messages\SDNotify.exe] "C:\Windows\SysNative\tasks\SDMsgUpdate (TE)" [C:\PROGRA~2\SMARTD~1\Messages\SDNotify.exe] "C:\Windows\SysNative\tasks\User NBAgent" ["C:\Program Files (x86)\Nero\Nero BackItUp & Burn\Nero BackItUp\NBAgent.exe"] "C:\Windows\SysNative\tasks\User_Feed_Synchronization-{6A8F88A5-2126-4DF0-A1F1-8A89E643191A}" [C:\Windows\system32\msfeedssync.exe] "C:\Windows\SysNative\tasks\Apple\AppleSoftwareUpdate" [C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe] "C:\Windows\SysNative\tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask" [%systemroot%\system32\sc.exe start osppsvc] ==== Folders in C:\PROGRA~3 0-6 Months Old ====================== 2015-02-23 17:26:35 -------- d-----w- C:\PROGRA~3\7304566480615253663UL 2015-04-08 15:54:12 -------- d-----w- C:\PROGRA~3\Anvisoft 2015-04-09 15:30:46 -------- d-----w- C:\PROGRA~3\Panda Security 2015-04-09 15:37:39 -------- d-----w- C:\PROGRA~3\Avira ==== Firefox Start and Search pages ====================== ProfilePath: C:\Users\Laurens\AppData\Roaming\Mozilla\Firefox\Profiles\kic4cxak.default-1428649081503 user_pref("browser.startup.homepage", "about:blank"); user_pref("browser.newtab.url", "about:blank"); ProfilePath: C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\tfx7kexd.default user_pref("browser.search.defaultenginename", "Ask.com"); user_pref("browser.search.defaultengine", "Ask.com"); user_pref("browser.search.selectedEngine", "Ask.com"); user_pref("extensions.asktb.ff-original-keyword-url", "http://search.yahoo.com/search?fr=mcafee&p="); ==== Firefox Extensions Registry ====================== [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions] "{9D2AA73B-6049-4799-B8AC-925723370070}"="C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext" [09/10/2014 19:25] [HKEY_CURRENT_USER\Software\Mozilla\Firefox\Extensions] "{e4f94d1e-2f53-401e-8885-681602c0ddd8}"="C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi" [04/04/2014 12:36] ==== Firefox Extensions ====================== ProfilePath: C:\Users\Gast\AppData\Roaming\Mozilla\Firefox\Profiles\vmdd5682.default - Undetermined - %ProfilePath%\extensions\staged ProfilePath: C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\tfx7kexd.default - McAfee SiteAdvisor - C:\Program Files (x86)\McAfee\SiteAdvisor - English Australian Dictionary - %ProfilePath%\extensions\en-AU@dictionaries.addons.mozilla.org - New Zealand English Dictionary - %ProfilePath%\extensions\en-NZ@dictionaries.addons.mozilla.org - Dictionnaires franais - %ProfilePath%\extensions\fr-dicollecte@dictionaries.addons.mozilla.org - Undetermined - %ProfilePath%\extensions\staged - Add-on Compatibility Reporter - %ProfilePath%\extensions\compatibility@addons.mozilla.org.xpi ProfilePath: C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\wn9dy8c0.Laurens - Undetermined - %ProfilePath%\extensions\staged - Instrument Test - %ProfilePath%\extensions\testpilot@labs.mozilla.com.xpi ProfilePath: C:\Users\Laurens\AppData\Roaming\Mozilla\Firefox\Profiles\tfx7kexd.default - Segurana do navegador Avira - %ProfilePath%\extensions\abs@avira.com AppDir: C:\Program Files (x86)\Mozilla Firefox - Belgium eID - %AppDir%\extensions\belgiumeid@eid.belgium.be - Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} ==== Firefox Plugins ====================== Profilepath: C:\Users\Laurens\AppData\Roaming\Mozilla\Firefox\Profiles\kic4cxak.default-1428649081503 20AF900395CA5AD66A9134CF032B0435 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll - RealPlayer Video Downloader for HTML5 (32-bit) C62322C77D1AAB77B1CF1130FCC3673A - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_305.dll - Shockwave Flash D2B5242013356AF422A42B9FAA4056C2 - C:\Users\Laurens\AppData\Roaming\VASCO\VascoCardReaderPlugin\3.2.3.2\npVascoCardReaderPlugin.dll - VASCO Card Reader Plugin FD63DE29FE0A7E738BD81CA0EDDD8020 - C:\Users\Laurens\AppData\Roaming\VASCO\VascoCardReaderPlugin\3.2.3.2\npVascoCardReaderPlugin64.dll - VASCO Card Reader Plugin ==== Chromium Look ====================== HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions bopakagnckmlgajfccecajhnimjiiedh - No path found[] fheoggkfdfchfphceeifdbepaooicaho - C:\Program Files (x86)\McAfee\SiteAdvisor\McChPlg.crx[24/03/2015 12:28] flliilndjeohchalpbbcdekjklbdgfkk - No path found[] jbolfgndggfhhpbnkgnpjkfhinclbigj - No path found[] lhmiofmipcpmhgihiecmpiekcacigpgb - C:\ProgramData\Anvisoft\Anvi Smart Defender 2\extensions\chrome.crx[] ==== Deleting CLSID Registry Keys ====================== ==== Deleting CLSID Registry Values ====================== ==== Empty IE Cache ====================== C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Gast\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Laurens\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Laurens\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully C:\Users\User\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\User\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully C:\Users\User\AppData\Local\Temp\acro_rd_dir\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\User\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully ==== Empty FireFox Cache ====================== C:\Users\Gast\AppData\Local\Mozilla\Firefox\Profiles\vmdd5682.default\Cache emptied successfully C:\Users\Laurens\AppData\Local\Mozilla\Firefox\Profiles\kic4cxak.default-1428649081503\cache2 emptied successfully C:\Users\User\AppData\Local\Mozilla\Firefox\Profiles\wn9dy8c0.Laurens\Cache emptied successfully ==== Empty Chrome Cache ====================== No Chrome User Data found ==== Empty All Flash Cache ====================== Flash Cache Emptied Successfully ==== Empty All Java Cache ====================== Java Cache cleared successfully ==== C:\zoek_backup content ====================== C:\zoek_backup (files=15 folders=12 75321 bytes) ==== Empty Temp Folders ====================== C:\Users\Default\AppData\Local\Temp emptied successfully C:\Users\Default User\AppData\Local\Temp emptied successfully C:\Users\Gast\AppData\Local\Temp emptied successfully C:\Users\Laurens\AppData\Local\Temp will be emptied at reboot C:\Users\User\AppData\Local\Temp emptied successfully C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully C:\Windows\Temp will be emptied at reboot ==== After Reboot ====================== ==== Empty Temp Folders ====================== C:\Windows\Temp successfully emptied C:\Users\Laurens\AppData\Local\Temp successfully emptied ==== Empty Recycle Bin ====================== C:\$RECYCLE.BIN successfully emptied ==== EOF on di 14/04/2015 at 12:41:09,00 ======================