Zoek.exe v5.0.0.0 Updated 15-09-2015 Tool run by marleen on do 17/09/2015 at 7:53:30,60. Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x64 Running in: Normal Mode Internet Access Detected Launched: C:\Users\marleen\Downloads\zoek.exe [Scan all users] [Script inserted] [Checkboxes used] ==== System Restore Info ====================== 17/09/2015 7:55:14 Zoek.exe System Restore Point Created Successfully. ==== Deleting CLSID Registry Keys ====================== HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Extensions\{d8f67242-b229-4065-95fa-391b077ed6ca} deleted successfully HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{d8f67242-b229-4065-95fa-391b077ed6ca} deleted successfully ==== Deleting CLSID Registry Values ====================== ==== Deleting Services ====================== ==== Registry Fix Code x64 ====================== Windows Registry Editor Version 5.00 [-HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{c3c77255-42c0-499f-b664-6e981a0b1647}] ==== Deleting Files \ Folders ====================== C:\ProgramData\Fighters deleted C:\PROGRA~3\Package Cache deleted C:\Users\marleen\AppData\LocalLow\Unity deleted C:\Users\marleen\AppData\Roaming\Mozilla\Firefox\Profiles\RbRqinRD.default\extensions\abs@avira.com deleted ==== Files Recently Created / Modified ====================== ====== C:\Windows ==== ====== C:\Users\marleen\AppData\Local\Temp ==== 2015-09-15 16:21:12 A77A8EB5E9BA6D63A121811F0830F565 302080 ----a-w- C:\Users\marleen\AppData\Local\Temp\2A98FB72-752C-40B0-9316-A075A19C6EDA\UnattendProvider.dll 2015-09-15 16:21:12 8DF4C8E300C8D32468F6141D22BBAF24 271360 ----a-w- C:\Users\marleen\AppData\Local\Temp\2A98FB72-752C-40B0-9316-A075A19C6EDA\SmiProvider.dll 2015-09-15 16:21:12 7B38D7916A7CD058C16A0A6CA5077901 271360 ----a-w- C:\Users\marleen\AppData\Local\Temp\2A98FB72-752C-40B0-9316-A075A19C6EDA\wdscore.dll 2015-09-15 16:21:12 739968678548BA15F6B9372E8760C012 444416 ----a-w- C:\Users\marleen\AppData\Local\Temp\2A98FB72-752C-40B0-9316-A075A19C6EDA\TransmogProvider.dll 2015-09-15 16:21:12 26981358EA5F82938387F6998F861978 471040 ----a-w- C:\Users\marleen\AppData\Local\Temp\2A98FB72-752C-40B0-9316-A075A19C6EDA\WimProvider.dll 2015-09-15 16:21:11 F76D4ECF94DC677C13061EAEE9D6745A 312832 ----a-w- C:\Users\marleen\AppData\Local\Temp\2A98FB72-752C-40B0-9316-A075A19C6EDA\IntlProvider.dll 2015-09-15 16:21:11 F2B0771A7CD27F20689E0AB787B7EB7C 289792 ----a-w- C:\Users\marleen\AppData\Local\Temp\2A98FB72-752C-40B0-9316-A075A19C6EDA\DismCore.dll 2015-09-15 16:21:11 EC664AAB47C27667256DDFBD13986239 127488 ----a-w- C:\Users\marleen\AppData\Local\Temp\2A98FB72-752C-40B0-9316-A075A19C6EDA\OSProvider.dll 2015-09-15 16:21:11 CD564F5637BBBEB6E5F3464EDD573C80 438272 ----a-w- C:\Users\marleen\AppData\Local\Temp\2A98FB72-752C-40B0-9316-A075A19C6EDA\DmiProvider.dll 2015-09-15 16:21:11 C9D74156913061BE6C51D8FC3ACF8E93 53760 ----a-w- C:\Users\marleen\AppData\Local\Temp\2A98FB72-752C-40B0-9316-A075A19C6EDA\FolderProvider.dll 2015-09-15 16:21:11 9A821D8D62F4C60232B856E98CBA7E4F 96768 ----a-w- C:\Users\marleen\AppData\Local\Temp\2A98FB72-752C-40B0-9316-A075A19C6EDA\DismHost.exe 2015-09-15 16:21:11 8CA117CB9338C0351236939717CB7084 186368 ----a-w- C:\Users\marleen\AppData\Local\Temp\2A98FB72-752C-40B0-9316-A075A19C6EDA\DismProv.dll 2015-09-15 16:21:11 62DE64DC805FD98AF3ADA9D93209F6A9 107008 ----a-w- C:\Users\marleen\AppData\Local\Temp\2A98FB72-752C-40B0-9316-A075A19C6EDA\LogProvider.dll 2015-09-15 16:21:11 5488E381238FF19687FDD7AB2F44CFCC 111616 ----a-w- C:\Users\marleen\AppData\Local\Temp\2A98FB72-752C-40B0-9316-A075A19C6EDA\DismCorePS.dll 2015-09-15 16:21:11 45FF4FA5CA5432BFCCDED4433FE2A85B 216576 ----a-w- C:\Users\marleen\AppData\Local\Temp\2A98FB72-752C-40B0-9316-A075A19C6EDA\MsiProvider.dll 2015-09-15 16:21:11 3A9C49943047DE6C6F8DC68CB986A0EC 183296 ----a-w- C:\Users\marleen\AppData\Local\Temp\2A98FB72-752C-40B0-9316-A075A19C6EDA\CompatProvider.dll 2015-09-15 16:21:11 2961AB067AE61440ADF11C4BFE085151 1672192 ----a-w- C:\Users\marleen\AppData\Local\Temp\2A98FB72-752C-40B0-9316-A075A19C6EDA\CbsProvider.dll 2015-09-15 14:43:27 9CEC626BAED2B0504CF352D2B46D14EE 287120 ----a-w- C:\Users\marleen\AppData\Local\Temp\JavaIC.dll 2015-09-15 14:43:27 69809CDCF1F94CE88ECFF73E59CC540B 331488 ----a-w- C:\Users\marleen\AppData\Local\Temp\msscct32.dll 2015-09-15 14:43:27 6930B620D3D0E3F968837017E0E02A23 398800 ----a-w- C:\Users\marleen\AppData\Local\Temp\YSearchUtil.dll 2015-09-15 14:43:27 163D2CEDC9C4D41E45C7ABF6289C0A0A 96288 ----a-w- C:\Users\marleen\AppData\Local\Temp\cct.dll 2015-09-15 12:01:36 EC664AAB47C27667256DDFBD13986239 127488 ----a-w- C:\Users\marleen\AppData\Local\Temp\53E9775D-DAC0-4400-B284-0650AC431484\OSProvider.dll 2015-09-15 12:01:36 A77A8EB5E9BA6D63A121811F0830F565 302080 ----a-w- C:\Users\marleen\AppData\Local\Temp\53E9775D-DAC0-4400-B284-0650AC431484\UnattendProvider.dll 2015-09-15 12:01:36 8DF4C8E300C8D32468F6141D22BBAF24 271360 ----a-w- C:\Users\marleen\AppData\Local\Temp\53E9775D-DAC0-4400-B284-0650AC431484\SmiProvider.dll 2015-09-15 12:01:36 7B38D7916A7CD058C16A0A6CA5077901 271360 ----a-w- C:\Users\marleen\AppData\Local\Temp\53E9775D-DAC0-4400-B284-0650AC431484\wdscore.dll 2015-09-15 12:01:36 739968678548BA15F6B9372E8760C012 444416 ----a-w- C:\Users\marleen\AppData\Local\Temp\53E9775D-DAC0-4400-B284-0650AC431484\TransmogProvider.dll 2015-09-15 12:01:36 26981358EA5F82938387F6998F861978 471040 ----a-w- C:\Users\marleen\AppData\Local\Temp\53E9775D-DAC0-4400-B284-0650AC431484\WimProvider.dll 2015-09-15 12:01:35 F76D4ECF94DC677C13061EAEE9D6745A 312832 ----a-w- C:\Users\marleen\AppData\Local\Temp\53E9775D-DAC0-4400-B284-0650AC431484\IntlProvider.dll 2015-09-15 12:01:35 F2B0771A7CD27F20689E0AB787B7EB7C 289792 ----a-w- C:\Users\marleen\AppData\Local\Temp\53E9775D-DAC0-4400-B284-0650AC431484\DismCore.dll 2015-09-15 12:01:35 CD564F5637BBBEB6E5F3464EDD573C80 438272 ----a-w- C:\Users\marleen\AppData\Local\Temp\53E9775D-DAC0-4400-B284-0650AC431484\DmiProvider.dll 2015-09-15 12:01:35 C9D74156913061BE6C51D8FC3ACF8E93 53760 ----a-w- C:\Users\marleen\AppData\Local\Temp\53E9775D-DAC0-4400-B284-0650AC431484\FolderProvider.dll 2015-09-15 12:01:35 9A821D8D62F4C60232B856E98CBA7E4F 96768 ----a-w- C:\Users\marleen\AppData\Local\Temp\53E9775D-DAC0-4400-B284-0650AC431484\DismHost.exe 2015-09-15 12:01:35 8CA117CB9338C0351236939717CB7084 186368 ----a-w- C:\Users\marleen\AppData\Local\Temp\53E9775D-DAC0-4400-B284-0650AC431484\DismProv.dll 2015-09-15 12:01:35 62DE64DC805FD98AF3ADA9D93209F6A9 107008 ----a-w- C:\Users\marleen\AppData\Local\Temp\53E9775D-DAC0-4400-B284-0650AC431484\LogProvider.dll 2015-09-15 12:01:35 5488E381238FF19687FDD7AB2F44CFCC 111616 ----a-w- C:\Users\marleen\AppData\Local\Temp\53E9775D-DAC0-4400-B284-0650AC431484\DismCorePS.dll 2015-09-15 12:01:35 45FF4FA5CA5432BFCCDED4433FE2A85B 216576 ----a-w- C:\Users\marleen\AppData\Local\Temp\53E9775D-DAC0-4400-B284-0650AC431484\MsiProvider.dll 2015-09-15 12:01:35 3A9C49943047DE6C6F8DC68CB986A0EC 183296 ----a-w- C:\Users\marleen\AppData\Local\Temp\53E9775D-DAC0-4400-B284-0650AC431484\CompatProvider.dll 2015-09-15 12:01:35 2961AB067AE61440ADF11C4BFE085151 1672192 ----a-w- C:\Users\marleen\AppData\Local\Temp\53E9775D-DAC0-4400-B284-0650AC431484\CbsProvider.dll ====== Java Cache ===== 2015-09-15 14:40:38 27266DB268940A58180604BA1A7BE3E0 450735 ----a-w- C:\Users\marleen\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\36\6f20baa4-45d28eba 2015-09-15 14:40:38 C611538EFED63F122E4A07F748AC01B3 793 ----a-w- C:\Users\marleen\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\61\11dd5f3d-34fab382 2015-09-15 14:40:38 70C5D45FA55CA2D24F24631E742D3E52 442 ----a-w- C:\Users\marleen\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\61\11dd5f3d-866ea8a9a5e54c718f59857e9fb20e99af8e0c6c1540667a6358a78f78af6bf9-6.0.lap ====== C:\Windows\SysWOW64 ===== 2015-09-15 14:44:05 C05114B0BDF2470F7F4A1B2128540062 97888 ----a-w- C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2015-09-09 05:59:39 F5811FD860256CD6A1F19A168EBE0C80 216064 ----a-w- C:\Windows\SysWOW64\InkEd.dll 2015-09-09 05:59:27 449A5A6D6B6F1ECB27ADA3002382D3BC 2048 ----a-w- C:\Windows\SysWOW64\tzres.dll 2015-09-09 05:59:16 BFCB5A69B6D9EAB9D7B9B2B3BB9300B4 30720 ----a-w- C:\Windows\SysWOW64\iernonce.dll 2015-09-09 05:59:16 4C68C514F25379AC4B24739D6F93473A 47616 ----a-w- C:\Windows\SysWOW64\ieetwproxystub.dll 2015-09-09 05:59:15 DA47CED2032198A6E4739BB77C70EBA9 60416 ----a-w- C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2015-09-09 05:59:15 98733E7AA07BEDF523778FF3240CDB17 504832 ----a-w- C:\Windows\SysWOW64\vbscript.dll 2015-09-09 05:59:15 7C25F33E59D387DE06B11B8EC38CF26D 1310720 ----a-w- C:\Windows\SysWOW64\urlmon.dll 2015-09-09 05:59:15 3D24E0397BED00AFBB3DFA3A8AB98FD3 76288 ----a-w- C:\Windows\SysWOW64\mshtmled.dll 2015-09-09 05:59:15 3CF7BD2B4A046633CEE16F5A2522ADF4 285696 ----a-w- C:\Windows\SysWOW64\dxtrans.dll 2015-09-09 05:59:15 267305B4B170E15FFE905E2C5A1D3137 344168 ----a-w- C:\Windows\SysWOW64\iedkcs32.dll 2015-09-09 05:59:15 216C0B2B406534ADACF8CCEFD8E86837 689152 ----a-w- C:\Windows\SysWOW64\msfeeds.dll 2015-09-09 05:59:15 0056D5DECBC2CE89721DB380D0FD57BE 64000 ----a-w- C:\Windows\SysWOW64\MshtmlDac.dll 2015-09-09 05:59:14 1730F4B69593EB38072DAF273B5565AB 19856896 ----a-w- C:\Windows\SysWOW64\mshtml.dll 2015-09-09 05:59:13 FEEB3D195FEB6A2B05D5AADCB1900AF1 62464 ----a-w- C:\Windows\SysWOW64\iesetup.dll 2015-09-09 05:59:13 E5AC8290F6468070E9F664AA5CD34899 710144 ----a-w- C:\Windows\SysWOW64\ieapfltr.dll 2015-09-09 05:59:13 D47DB47A2C61664DAB00550EBB342AFA 2279424 ----a-w- C:\Windows\SysWOW64\iertutil.dll 2015-09-09 05:59:13 810525827BFE17A1E99C78C39A8D52BB 2052608 ----a-w- C:\Windows\SysWOW64\inetcpl.cpl 2015-09-09 05:59:13 682D51EC4E605249E5330BDD36569C67 620032 ----a-w- C:\Windows\SysWOW64\jscript9diag.dll 2015-09-09 05:59:13 5931961817E242BC8CB76E1F7EB2FA3F 665600 ----a-w- C:\Windows\SysWOW64\jscript.dll 2015-09-09 05:59:12 FDDB70F74F079760743BC3E6E2F1C69F 418304 ----a-w- C:\Windows\SysWOW64\dxtmsft.dll 2015-09-09 05:59:12 ED40CEA3833C5B0227B1B01B86D47393 479232 ----a-w- C:\Windows\SysWOW64\ieui.dll 2015-09-09 05:59:12 66B2A244152C78E4C298807BC544AA26 12857344 ----a-w- C:\Windows\SysWOW64\ieframe.dll 2015-09-09 05:59:12 5D5ACD27170DDD0E685820AF2650B7CE 47104 ----a-w- C:\Windows\SysWOW64\jsproxy.dll 2015-09-09 05:59:12 42175CD4FD54C02CA8419F4079D9C8B2 115712 ----a-w- C:\Windows\SysWOW64\ieUnatt.exe 2015-09-09 05:59:11 04FBC984859E0A0D15DDFBFD97198D07 2724864 ----a-w- C:\Windows\SysWOW64\mshtml.tlb 2015-09-09 05:59:10 CE982D0CBE88BEA12A74BA9FF70DDC88 4520448 ----a-w- C:\Windows\SysWOW64\jscript9.dll 2015-09-09 05:59:10 C137627A10341356036A84A717660669 1155072 ----a-w- C:\Windows\SysWOW64\mshtmlmedia.dll 2015-09-09 05:59:10 A8C80A92549AFDD6891C8159D4C0A107 1951232 ----a-w- C:\Windows\SysWOW64\wininet.dll 2015-09-09 05:59:09 B860385F95CDE86286A12FB3FAABAF7F 168960 ----a-w- C:\Windows\SysWOW64\msrating.dll 2015-09-09 05:59:09 4881F098B26356905039C1D9DC233690 341504 ----a-w- C:\Windows\SysWOW64\html.iec 2015-09-09 05:58:57 E08E3E101A15FF4966AA3B2E86CF9806 50688 ----a-w- C:\Windows\SysWOW64\appidapi.dll 2015-09-09 05:58:32 DD126C4EA72C9D55A7BAE2C9326C4704 34304 ----a-w- C:\Windows\SysWOW64\atmlib.dll 2015-09-09 05:58:32 68054F129D15CE0A50E1E3841222A166 10240 ----a-w- C:\Windows\SysWOW64\dciman32.dll 2015-09-09 05:58:32 4629ED2D48E8DBB78A87CA219DAE6513 299520 ----a-w- C:\Windows\SysWOW64\atmfd.dll 2015-09-09 05:58:32 415FB89174E6D8BFC885A00A01C3446B 25600 ----a-w- C:\Windows\SysWOW64\lpk.dll 2015-09-09 05:58:32 2748108963E56A7A0CF05F19501DF832 70656 ----a-w- C:\Windows\SysWOW64\fontsub.dll 2015-09-09 05:58:29 EA010D8C6C63EA28BA9EB360403E5F85 173056 ----a-w- C:\Windows\SysWOW64\wuwebv.dll 2015-09-09 05:58:29 DC45670BF6EB8D7472EEB1D544B51C6B 30208 ----a-w- C:\Windows\SysWOW64\wups.dll 2015-09-09 05:58:29 80DA9F3867192A12059906D742E22091 34816 ----a-w- C:\Windows\SysWOW64\wuapp.exe 2015-09-09 05:58:29 18703D7AD19222F508B83BFFC015D37D 93184 ----a-w- C:\Windows\SysWOW64\wudriver.dll 2015-09-09 05:58:29 0FC51CD52CB71243C4E5E291ED717C97 566784 ----a-w- C:\Windows\SysWOW64\wuapi.dll ====== C:\Windows\SysWOW64\drivers ===== ====== C:\Windows\Sysnative ===== 2015-09-09 05:59:39 E2B939D646418AC4F85C42F0E7790EC9 24576 ----a-w- C:\Windows\Sysnative\jnwmon.dll 2015-09-09 05:59:39 28CAE76925107A4D5FBB63EC0A7DCA51 275456 ----a-w- C:\Windows\Sysnative\InkEd.dll 2015-09-09 05:59:37 40686B59C127F0C93B4234E4A1E3472A 1110016 ----a-w- C:\Windows\Sysnative\schedsvc.dll 2015-09-09 05:59:27 532D9A504A429D4EECC12ABAEA3BB65F 2048 ----a-w- C:\Windows\Sysnative\tzres.dll 2015-09-09 05:59:15 DF38359BA1798DD42CD15F7207FDAFA6 48640 ----a-w- C:\Windows\Sysnative\ieetwproxystub.dll 2015-09-09 05:59:15 91AD7A275B3BA53B036C0D246E89EF3A 114688 ----a-w- C:\Windows\Sysnative\ieetwcollector.exe 2015-09-09 05:59:15 6D10EB9ED12B215B4523337F6291AF08 77824 ----a-w- C:\Windows\Sysnative\JavaScriptCollectionAgent.dll 2015-09-09 05:59:15 21B7BEC14F9D35ABF5F802B61E637EEE 720384 ----a-w- C:\Windows\Sysnative\ie4uinit.exe 2015-09-09 05:59:15 0C3341D5B70E5796BF622BC457DD3619 34304 ----a-w- C:\Windows\Sysnative\iernonce.dll 2015-09-09 05:59:13 BC83213ABAB473B99BF78848573514E0 4096 ----a-w- C:\Windows\Sysnative\ieetwcollectorres.dll 2015-09-09 05:59:13 5C29BE6B121490177978741FB1487F87 2724864 ----a-w- C:\Windows\Sysnative\mshtml.tlb 2015-09-09 05:59:13 5BF637520D37C06EBA8FF3AFAF11D961 393304 ----a-w- C:\Windows\Sysnative\iedkcs32.dll 2015-09-09 05:59:13 394A06EBC37283F59AA1F3E793DBFB8B 1545728 ----a-w- C:\Windows\Sysnative\urlmon.dll 2015-09-09 05:59:12 F7842D6C680AFED5656989BD0189C78C 968704 ----a-w- C:\Windows\Sysnative\MsSpellCheckingFacility.exe 2015-09-09 05:59:12 D8FE466B3EB5E290EF6B698367BC8FF6 801280 ----a-w- C:\Windows\Sysnative\msfeeds.dll 2015-09-09 05:59:12 357785E8D45614BEE7A340E58E149B34 316928 ----a-w- C:\Windows\Sysnative\dxtrans.dll 2015-09-09 05:59:11 ABEBE737EC3EDDAC560258ED86712961 66560 ----a-w- C:\Windows\Sysnative\iesetup.dll 2015-09-09 05:59:11 39AD1102270EB183B03AA5A0362201D1 2126336 ----a-w- C:\Windows\Sysnative\inetcpl.cpl 2015-09-09 05:59:11 2A161E2B7A37C7A18B6CF02B05804B1D 800768 ----a-w- C:\Windows\Sysnative\ieapfltr.dll 2015-09-09 05:59:10 B04F6C38F0D78E0DF23FE69813DB5464 2886144 ----a-w- C:\Windows\Sysnative\iertutil.dll 2015-09-09 05:59:10 A7D51FC9BF718F10AAD7E381C78D4CF4 54784 ----a-w- C:\Windows\Sysnative\jsproxy.dll 2015-09-09 05:59:10 90D77CFA7C7BA84EC1E8B06CF5F94C34 585216 ----a-w- C:\Windows\Sysnative\vbscript.dll 2015-09-09 05:59:09 ED10CF4AFE2BF66667A08A79EF5329E0 490496 ----a-w- C:\Windows\Sysnative\dxtmsft.dll 2015-09-09 05:59:09 A5ED86412F4A623FA2468C023CE6344E 144384 ----a-w- C:\Windows\Sysnative\ieUnatt.exe 2015-09-09 05:59:09 9AE595C539A180F8B267EB0697B38B2E 615936 ----a-w- C:\Windows\Sysnative\ieui.dll 2015-09-09 05:59:09 00059AAFAF28B362197B90D3FD5062BB 14451712 ----a-w- C:\Windows\Sysnative\ieframe.dll 2015-09-09 05:59:08 E850CB3A37F8A9117BE2FF263B7D0FD1 817664 ----a-w- C:\Windows\Sysnative\jscript.dll 2015-09-09 05:59:08 D7390AAB21AABF0B2E7D8B0793686512 5923328 ----a-w- C:\Windows\Sysnative\jscript9.dll 2015-09-09 05:59:08 C977CF244EE08E22F0F122591EE6420D 92160 ----a-w- C:\Windows\Sysnative\mshtmled.dll 2015-09-09 05:59:08 4AFF1DA04FC31C4E3E73ADA805BA57ED 814080 ----a-w- C:\Windows\Sysnative\jscript9diag.dll 2015-09-09 05:59:08 2A9F3C1F3D93EA4938B821FE241CB227 1359360 ----a-w- C:\Windows\Sysnative\mshtmlmedia.dll 2015-09-09 05:59:07 CA9B509F45E6C53A03C7D5D8359AEBDF 417792 ----a-w- C:\Windows\Sysnative\html.iec 2015-09-09 05:59:07 C2279FA9510104431A5936F4D64CC591 88064 ----a-w- C:\Windows\Sysnative\MshtmlDac.dll 2015-09-09 05:59:07 A55305B1CACD38EAC176CC532B2053AC 2427392 ----a-w- C:\Windows\Sysnative\wininet.dll 2015-09-09 05:59:06 2555DEF683BDF9B4947591827D6DE69A 25190400 ----a-w- C:\Windows\Sysnative\mshtml.dll 2015-09-09 05:59:06 17125243606DCACEE3AA12964B649ECF 199680 ----a-w- C:\Windows\Sysnative\msrating.dll 2015-09-09 05:58:58 65825DC78742A89C59C1184D9D36091B 147456 ----a-w- C:\Windows\Sysnative\appidpolicyconverter.exe 2015-09-09 05:58:58 2BFD9C958A2E08D6486FB2A688D2F2F4 616360 ----a-w- C:\Windows\Sysnative\winresume.efi 2015-09-09 05:58:58 21267F39EAB62396E79C80089E912DA9 692672 ----a-w- C:\Windows\Sysnative\winload.efi 2015-09-09 05:58:57 7EA98A87FBFCAD2E0650EA1F1AB51D88 17920 ----a-w- C:\Windows\Sysnative\appidcertstorecheck.exe 2015-09-09 05:58:57 1CE43325025DECB0035A55720814A7A3 59392 ----a-w- C:\Windows\Sysnative\appidapi.dll 2015-09-09 05:58:57 173C90AF5B243B4DD86F95CA154CB58A 32768 ----a-w- C:\Windows\Sysnative\appidsvc.dll 2015-09-09 05:58:56 056C9A75342F6545A4B864B9C703E380 63488 ----a-w- C:\Windows\Sysnative\setbcdlocale.dll 2015-09-09 05:58:32 AA9DF61A0B6A39EF36C3393DDE325F58 14336 ----a-w- C:\Windows\Sysnative\dciman32.dll 2015-09-09 05:58:32 92828C27E59DCC79AD70681DC70C3A41 100864 ----a-w- C:\Windows\Sysnative\fontsub.dll 2015-09-09 05:58:32 891D1D6C4B8D4E929F247F97C6214C9A 3209216 ----a-w- C:\Windows\Sysnative\win32k.sys 2015-09-09 05:58:32 774236E3A89C838E774241CD2B66791B 372736 ----a-w- C:\Windows\Sysnative\atmfd.dll 2015-09-09 05:58:32 5E258B6D3D1A6F038A757FB70BA78037 46080 ----a-w- C:\Windows\Sysnative\atmlib.dll 2015-09-09 05:58:32 0E8D254B70E880F032036BFD45266754 41984 ----a-w- C:\Windows\Sysnative\lpk.dll 2015-09-09 05:58:30 F8CE5FBDA334941FB1034D1DAF6F9301 3165696 ----a-w- C:\Windows\Sysnative\wucltux.dll 2015-09-09 05:58:30 39D604E190DFE2E483B637D6796ABAFF 2606080 ----a-w- C:\Windows\Sysnative\wuaueng.dll 2015-09-09 05:58:29 F78B95558E150F8DBA1DBE873C8FADCA 192000 ----a-w- C:\Windows\Sysnative\wuwebv.dll 2015-09-09 05:58:29 E466B59224B351EB0F51D30477F0FE59 696320 ----a-w- C:\Windows\Sysnative\wuapi.dll 2015-09-09 05:58:29 CE08490157D7C871A4F1E9D8057EC2A1 139776 ----a-w- C:\Windows\Sysnative\wuauclt.exe 2015-09-09 05:58:29 A6ACBEF520B03C4CF251C869B9912EDE 12288 ----a-w- C:\Windows\Sysnative\wu.upgrade.ps.dll 2015-09-09 05:58:29 6F53D7D35C390B8A1C8761A8BF307690 98304 ----a-w- C:\Windows\Sysnative\wudriver.dll 2015-09-09 05:58:29 292F9D085D79C09973C55007FBBDFB4B 36864 ----a-w- C:\Windows\Sysnative\wups.dll 2015-09-09 05:58:29 1559BBD74DA38146373727FE368A65C6 37888 ----a-w- C:\Windows\Sysnative\wups2.dll 2015-09-09 05:58:29 0C22CADE768D444A4CC0DA273486EDFA 91136 ----a-w- C:\Windows\Sysnative\WinSetupUI.dll 2015-09-09 05:58:29 04ABD36541EB9B8070CDAFF933EAB4E5 37376 ----a-w- C:\Windows\Sysnative\wuapp.exe ====== C:\Windows\Sysnative\drivers ===== 2015-09-15 12:34:22 390184FAD8FCC1B6DA25AEBAE928C3B6 28600 ----a-w- C:\Windows\Sysnative\drivers\avkmgr.sys 2015-09-15 12:34:22 13253E5E3B6BDF945B63B336A8C9489B 44088 ----a-w- C:\Windows\Sysnative\drivers\avnetflt.sys 2015-09-15 12:34:22 043E5F34C3878C844568658B79B3E55C 141416 ----a-w- C:\Windows\Sysnative\drivers\avipbb.sys 2015-09-15 12:34:21 24843902369DC82B4691F816F08F2938 162528 ----a-w- C:\Windows\Sysnative\drivers\avgntflt.sys 2015-09-09 05:58:55 A0711D119BA4B48A1470C768D301013E 61440 ----a-w- C:\Windows\Sysnative\drivers\appid.sys ====== C:\Windows\Tasks ====== 2015-09-15 12:39:04 3C93A0AC96BD46DA99A8C7F262DEB4AA 3432 ----a-w- C:\Windows\Sysnative\Tasks\Avira Browser Safety Updater Task 2015-09-15 11:54:27 E13FE0E9FFE74C5595CC19FFAD59C2AC 3140 ----a-w- C:\Windows\Sysnative\Tasks\{69A0A381-DEAB-45C7-A190-14ABFD91FB74} 2015-09-15 11:40:33 7AB9188F1311D74CD915577D6780A51C 3234 ----a-w- C:\Windows\Sysnative\Tasks\{7DC5FC2B-8CE1-47DB-9D70-ACD5F3F77D53} 2015-09-15 11:37:20 99967663D33438F1223E0EDDD6970E76 3134 ----a-w- C:\Windows\Sysnative\Tasks\{1C41B8D7-6D1C-48E8-9DCE-5CB7E34164D7} ====== C:\Windows\Temp ====== ======= C:\Program Files ===== ======= C:\PROGRA~2 ===== 2015-09-15 14:44:32 -------- d-----w- C:\PROGRA~2\COMMON~1\Java 2015-09-15 12:30:50 -------- d-----w- C:\PROGRA~2\Avira ======= C: ===== ====== C:\Users\marleen\AppData\Roaming ====== 2015-09-15 14:40:45 -------- d-----w- C:\Users\marleen\AppData\Roaming\Oracle 2015-09-15 13:42:03 -------- d-----w- C:\Windows\sysWoW64\config\systemprofile\AppData\Roaming\Fighters 2015-09-15 12:42:40 -------- d-----w- C:\Users\marleen\AppData\Roaming\Avira 2015-09-15 12:37:42 -------- d-----w- C:\Windows\sysWoW64\config\systemprofile\AppData\Roaming\Avira 2015-09-15 12:10:01 -------- d-----w- C:\Users\marleen\AppData\Roaming\Sun 2015-09-15 11:35:39 -------- d-----w- C:\Users\marleen\AppData\Locallow\Oracle 2015-09-14 13:35:53 6419DFBD7E8CB851AAA16EE9F7BC91B5 353118 ----a-w- C:\Users\marleen\AppData\Local\SquareClock.Production_Home_Ixina_WebIcon.ico ====== C:\Users\marleen ====== 2015-09-16 16:19:06 8045ABB21A3BDD66A48E1ED5C0F0EF6A 1222144 ----a-w- C:\Users\marleen\Downloads\RSITx64(1).exe 2015-09-15 14:44:04 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2015-09-15 14:42:32 CD8D0B237F2A599D4376FDFBA1460503 584288 ----a-w- C:\Users\marleen\Downloads\jxpiinstall.exe 2015-09-15 12:30:52 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira 2015-09-15 12:30:50 -------- d-----w- C:\ProgramData\Avira 2015-09-15 12:10:00 -------- d-----w- C:\Users\marleen\.oracle_jre_usage ====== C: exe-files == 2015-09-16 16:19:06 8045ABB21A3BDD66A48E1ED5C0F0EF6A 1222144 ----a-w- C:\Users\marleen\Downloads\RSITx64(1).exe 2015-09-15 16:21:11 9A821D8D62F4C60232B856E98CBA7E4F 96768 ----a-w- C:\Users\marleen\AppData\Local\Temp\2A98FB72-752C-40B0-9316-A075A19C6EDA\DismHost.exe 2015-09-15 14:44:05 BC949C957CEB9FAFDF0F3949CDDF1A72 0 ----a-we C:\ProgramData\Oracle\Java\javapath\java.exe 2015-09-15 14:44:05 7080B965215703EA1340C3C4903C7D73 0 ----a-we C:\ProgramData\Oracle\Java\javapath\javaws.exe 2015-09-15 14:44:05 5DC0128E8A2017E82289191820C736A5 0 ----a-we C:\ProgramData\Oracle\Java\javapath\javaw.exe 2015-09-15 14:43:55 E408E46C5DD2D03A7474AA12BAABEFEE 15968 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_60\bin\klist.exe 2015-09-15 14:43:55 D94C31E9C9C9A1273CC67DC6FFAF9984 15968 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_60\bin\policytool.exe 2015-09-15 14:43:55 BDFF5086FC1F20E631A070EEF43A7BEC 16480 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_60\bin\tnameserv.exe 2015-09-15 14:43:55 BC949C957CEB9FAFDF0F3949CDDF1A72 191584 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_60\bin\java.exe 2015-09-15 14:43:55 B9DE149653ED8B9C5C6CB68131AB66D2 15968 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_60\bin\jjs.exe 2015-09-15 14:43:55 B804A4E31F4BAD4D5BA05FE684756BA2 15968 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_60\bin\servertool.exe 2015-09-15 14:43:55 8C6BDB56CD4DEED1AF2790D37B54CFE9 68192 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_60\bin\javacpl.exe 2015-09-15 14:43:55 86CC77A8189758834CF83F7F2FEA5162 15968 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_60\bin\java-rmi.exe 2015-09-15 14:43:55 7A0DE452F677EF2971C7B75B0267B6ED 50784 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_60\bin\ssvagent.exe 2015-09-15 14:43:55 7080B965215703EA1340C3C4903C7D73 274016 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_60\bin\javaws.exe 2015-09-15 14:43:55 6A5A2FDB6D09E02A3283C55237DA10F6 159328 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_60\bin\unpack200.exe 2015-09-15 14:43:55 606A24A64E164B345A79F8F22A5DAC6F 15968 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_60\bin\pack200.exe 2015-09-15 14:43:55 5DC0128E8A2017E82289191820C736A5 191584 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_60\bin\javaw.exe 2015-09-15 14:43:55 5A503CFE5B553A9721A469FCC9CE8562 15968 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_60\bin\rmiregistry.exe 2015-09-15 14:43:55 3292748E640429C2682484BD23D43F6B 15968 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_60\bin\rmid.exe 2015-09-15 14:43:55 30387BE3E5D04FE969B731441C89D2D8 15968 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_60\bin\ktab.exe 2015-09-15 14:43:55 262BBCE84B9C8784CC5A5E1975898022 30304 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_60\bin\jabswitch.exe 2015-09-15 14:43:55 21B5D297A9191E4D833BB39456CEDAD0 15968 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_60\bin\kinit.exe 2015-09-15 14:43:55 0FCF9F3D9518B90FB58CC950FA33998C 76896 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_60\bin\jp2launcher.exe 2015-09-15 14:43:55 0F6E0DD1263ACB2A1AC559BB7742B54D 15968 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_60\bin\keytool.exe 2015-09-15 14:43:55 08427EADE480F21412696582170B1167 16480 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_60\bin\orbd.exe 2015-09-15 14:42:32 CD8D0B237F2A599D4376FDFBA1460503 584288 ----a-w- C:\Users\marleen\Downloads\jxpiinstall.exe 2015-09-15 12:34:53 B3A361678F0669A4632F519DBDD3475D 482296 ----a-w- C:\Program Files (x86)\Avira\Antivirus\wsctool.exe 2015-09-15 12:34:34 C5F22368CAB23D33FE8B052CFB4D3BF5 399896 ----a-w- C:\Program Files (x86)\Avira\Antivirus\updrgui.exe 2015-09-15 12:34:34 5F77516187B38639C90D5A7C2AEBA98C 1149224 ----a-w- C:\Program Files (x86)\Avira\Antivirus\update.exe 2015-09-15 12:34:32 E7AFD7169DF22989A84E5DF257A78380 457040 ----a-w- C:\Program Files (x86)\Avira\Antivirus\setuppending.exe 2015-09-15 12:34:32 2DD9EF0A2B46472502E9AB5006F0238E 2147824 ----a-w- C:\Program Files (x86)\Avira\Antivirus\setup.exe 2015-09-15 12:34:31 E20B4F23EB153635D67944F63454EC84 461672 ----a-w- C:\Program Files (x86)\Avira\Antivirus\sched.exe 2015-09-15 12:34:31 85488C95FAE93732C4675A642AA77423 467840 ----a-w- C:\Program Files (x86)\Avira\Antivirus\rscdwld.exe 2015-09-15 12:34:30 7003D23CA29C9D167CAAE90B2EC7FBF2 588368 ----a-w- C:\Program Files (x86)\Avira\Antivirus\licmgr.exe 2015-09-15 12:34:29 DDE8FB60E7837F5CA5B1927559C2456F 494656 ----a-w- C:\Program Files (x86)\Avira\Antivirus\inssda64.exe 2015-09-15 12:34:29 913148BACCBBA1AA5CFA5FC0A1AF39EA 475080 ----a-w- C:\Program Files (x86)\Avira\Antivirus\ipmgui.exe 2015-09-15 12:34:28 34E916B7CEC71AC34238FD6DF5D7E07C 709920 ----a-w- C:\Program Files (x86)\Avira\Antivirus\guardgui.exe 2015-09-15 12:34:28 0EC323D4CB5AC80F9F46AE808AECA283 930328 ----a-w- C:\Program Files (x86)\Avira\Antivirus\fact.exe 2015-09-15 12:34:27 A118B0109271D8943EB7F060FD30F662 407112 ----a-w- C:\Program Files (x86)\Avira\Antivirus\checkt.exe 2015-09-15 12:34:26 A91C46822926BA7D6C93DD08FE290495 503408 ----a-w- C:\Program Files (x86)\Avira\Antivirus\ccuac.exe 2015-09-15 12:34:25 7B1578913538386780DCDD7EAB6F6D2B 4718584 ----a-w- C:\Program Files (x86)\Avira\Antivirus\avira_nl____fm.exe 2015-09-15 12:34:24 D9A8EE3F4A1E604B9315B34A5AA4569E 1213072 ----a-w- C:\Program Files (x86)\Avira\Antivirus\avwebg7.exe 2015-09-15 12:34:24 B667AB46FA82FC246F9069D81BB1065C 1212048 ----a-w- C:\Program Files (x86)\Avira\Antivirus\avwebgrd.exe 2015-09-15 12:34:24 4B0D5053F8413D3A12CA97939A37DD4B 415352 ----a-w- C:\Program Files (x86)\Avira\Antivirus\avupgsvc.exe 2015-09-15 12:34:24 0A3DE2242A70F39A940436B5C2068803 818600 ----a-w- C:\Program Files (x86)\Avira\Antivirus\avwsc.exe 2015-09-15 12:34:24 094F3AC18AF083D542D96EBEF1F28161 632152 ----a-w- C:\Program Files (x86)\Avira\Antivirus\avshadow.exe 2015-09-15 12:34:23 B51019C2FD608008C7C288F21DA55479 1171384 ----a-w- C:\Program Files (x86)\Avira\Antivirus\avscan.exe 2015-09-15 12:34:23 1917470DE6390A546492D15C69CF9FF4 573424 ----a-w- C:\Program Files (x86)\Avira\Antivirus\avrestart.exe 2015-09-15 12:34:22 D84DAF58A56F5BCE7CAEB8E46DB844D6 555944 ----a-w- C:\Program Files (x86)\Avira\Antivirus\avmcdlg.exe 2015-09-15 12:34:22 C2C250888ADB92A2F62BFC773A0550FC 887128 ----a-w- C:\Program Files (x86)\Avira\Antivirus\avmailc.exe 2015-09-15 12:34:22 9FE1AC875A7AD7B7FF28FEC8B754968D 887128 ----a-w- C:\Program Files (x86)\Avira\Antivirus\avmailc7.exe 2015-09-15 12:34:22 4D6CB2823941FECA43D9443D7447E785 733616 ----a-w- C:\Program Files (x86)\Avira\Antivirus\avnotify.exe 2015-09-15 12:34:21 E20B4F23EB153635D67944F63454EC84 461672 ----a-w- C:\Program Files (x86)\Avira\Antivirus\avguard.exe 2015-09-15 12:34:21 27F8A7A78773427E5D931628F89D6839 782008 ----a-w- C:\Program Files (x86)\Avira\Antivirus\avgnt.exe 2015-09-15 12:34:20 B5FFD1810FF2295691C64505C28087B3 791296 ----a-w- C:\Program Files (x86)\Avira\Antivirus\avcenter.exe 2015-09-15 12:34:20 4A00D4B4906E6E0AB997259B099BBBBB 426664 ----a-w- C:\Program Files (x86)\Avira\Antivirus\avadmin.exe 2015-09-15 12:34:20 1B7800F8401652A914C5F07B8465537A 896344 ----a-w- C:\Program Files (x86)\Avira\Antivirus\avconfig.exe 2015-09-15 12:01:35 9A821D8D62F4C60232B856E98CBA7E4F 96768 ----a-w- C:\Users\marleen\AppData\Local\Temp\53E9775D-DAC0-4400-B284-0650AC431484\DismHost.exe === C: other files == 2015-09-15 14:43:55 4E221C69F3B103481534D1B6CB6A90DD 14130 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_60\lib\deploy\ffjcext.zip 2015-09-15 12:34:33 AAA918CAC945D36D64E27DE3D3E25F18 7776 ----a-w- C:\Program Files (x86)\Avira\Antivirus\sweb.zip 2015-09-15 12:34:22 390184FAD8FCC1B6DA25AEBAE928C3B6 28600 ----a-w- C:\Windows\System32\drivers\avkmgr.sys 2015-09-15 12:34:22 390184FAD8FCC1B6DA25AEBAE928C3B6 28600 ----a-w- C:\Program Files (x86)\Avira\Antivirus\avkmgr.sys 2015-09-15 12:34:22 13253E5E3B6BDF945B63B336A8C9489B 44088 ----a-w- C:\Windows\System32\drivers\avnetflt.sys 2015-09-15 12:34:22 13253E5E3B6BDF945B63B336A8C9489B 44088 ----a-w- C:\Program Files (x86)\Avira\Antivirus\avnetflt.sys 2015-09-15 12:34:22 043E5F34C3878C844568658B79B3E55C 141416 ----a-w- C:\Windows\System32\drivers\avipbb.sys 2015-09-15 12:34:22 043E5F34C3878C844568658B79B3E55C 141416 ----a-w- C:\Program Files (x86)\Avira\Antivirus\avipbb.sys 2015-09-15 12:34:21 24843902369DC82B4691F816F08F2938 162528 ----a-w- C:\Windows\System32\drivers\avgntflt.sys 2015-09-15 12:34:21 24843902369DC82B4691F816F08F2938 162528 ----a-w- C:\Program Files (x86)\Avira\Antivirus\avgntflt.sys ==== Startup Registry Enabled ====================== [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun" [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun" [HKEY_USERS\S-1-5-21-3574955231-1429911895-3831399447-1000\Software\Microsoft\Windows\CurrentVersion\Run] "CCleaner Monitoring"="C:\Program Files\CCleaner\CCleaner64.exe /MONITOR" [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce] "SPReview"="C:\Windows\System32\SPReview\SPReview.exe /sp:1 /errorfwlink:http://go.microsoft.com/fwlink/?LinkID=122915 /build:7601" [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce] "mctadmin"="C:\Windows\System32\mctadmin.exe" [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce] "mctadmin"="C:\Windows\System32\mctadmin.exe" [HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\RunOnce] "SPReview"="C:\Windows\System32\SPReview\SPReview.exe /sp:1 /errorfwlink:http://go.microsoft.com/fwlink/?LinkID=122915 /build:7601" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Avira SystrayStartTrigger"="C:\Program Files (x86)\Avira\Launcher\Avira.SystrayStartTrigger.exe" "avgnt"="C:\Program Files (x86)\Avira\Antivirus\avgnt.exe /min" "SunJavaUpdateSched"="C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "CCleaner Monitoring"="C:\Program Files\CCleaner\CCleaner64.exe /MONITOR" ==== Startup Registry Enabled x64 ====================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IgfxTray"="C:\Windows\system32\igfxtray.exe" "HotKeysCmds"="C:\Windows\system32\hkcmd.exe" "Persistence"="C:\Windows\system32\igfxpers.exe" ==== Task Scheduler Jobs ====================== C:\Windows\tasks\Adobe Flash Player Updater.job --a------ C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [12/08/2015 09:19] ==== Other Scheduled Tasks ====================== "C:\Windows\SysNative\tasks\Adobe Acrobat Update Task" [C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe] "C:\Windows\SysNative\tasks\Adobe Flash Player Updater" [C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe] "C:\Windows\SysNative\tasks\Avira Browser Safety Updater Task" ["C:\Program Files (x86)\Avira\Browser Safety\AviraBrowserSafetyUpdater.exe"] "C:\Windows\SysNative\tasks\CCleanerSkipUAC" ["C:\Program Files\CCleaner\CCleaner.exe"] "C:\Windows\SysNative\tasks\{3D8915F4-4973-40E0-B8C7-85516461D1CA}" [C:\Program Files (x86)\Mozilla Firefox\firefox.exe] ==== Firefox Start and Search pages ====================== ProfilePath: C:\Users\marleen\AppData\Roaming\Mozilla\Firefox\Profiles\8k1f2frf.default-1433585333261 user_pref("browser.startup.homepage", "http://www.google.be/"); ==== Firefox Extensions Registry ====================== [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions] "belgiumeid@eid.belgium.be"="C:\Program Files\Mozilla Firefox\extensions\belgiumeid@eid.belgium.be" [] ==== Firefox Extensions ====================== ProfilePath: C:\Users\marleen\AppData\Roaming\Mozilla\Firefox\Profiles\8k1f2frf.default-1433585333261 - Belgium eID - %ProfilePath%\extensions\belgiumeid@eid.belgium.be.xpi AppDir: C:\Program Files (x86)\Mozilla Firefox - Belgium eID - %AppDir%\extensions\belgiumeid@eid.belgium.be - Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} ==== Firefox Plugins ====================== Profilepath: C:\Users\marleen\AppData\Roaming\Mozilla\Firefox\Profiles\8k1f2frf.default-1433585333261 EC55112EDB2CE5BC2BFCACDB9C2150F4 - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_232.dll - Shockwave Flash CAF78E18A9E1380A0A38065B3B1210E0 - C:\Users\marleen\AppData\Roaming\VASCO\VascoCardReaderPlugin\3.2.3.4\npVascoCardReaderPlugin.dll - VASCO Card Reader Plugin 1CDD28B47D8198F868349BDFBCD1281B - C:\Users\marleen\AppData\Roaming\VASCO\VascoCardReaderPlugin\3.2.3.4\npVascoCardReaderPlugin64.dll - VASCO Card Reader Plugin Profilepath: C:\Users\marleen\AppData\Roaming\Mozilla\Firefox\Profiles\sq9ky3bc.default-1415452047738 D2B5242013356AF422A42B9FAA4056C2 - C:\Users\marleen\AppData\Roaming\VASCO\VascoCardReaderPlugin\3.2.3.2\npVascoCardReaderPlugin.dll - VASCO Card Reader Plugin FD63DE29FE0A7E738BD81CA0EDDD8020 - C:\Users\marleen\AppData\Roaming\VASCO\VascoCardReaderPlugin\3.2.3.2\npVascoCardReaderPlugin64.dll - VASCO Card Reader Plugin ==== Chromium Look ====================== HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions flliilndjeohchalpbbcdekjklbdgfkk - No path found[] Avira Browser Safety - marleen\AppData\Local\Google\Chrome\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk Google Wallet - marleen\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda ==== Chromium Startpages ====================== C:\Users\marleen\AppData\Local\Google\Chrome\User Data\Default\Preferences "startup_urls": [ "http://www.google.com/" ] ==== Set IE to Default ====================== Old Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://google/" New Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://google/" ==== All HKCU SearchScopes ====================== HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" {012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}" {0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC" ==== Deleting CLSID Registry Keys ====================== ==== Deleting CLSID Registry Values ====================== ==== Empty IE Cache ====================== C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\marleen\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\marleen\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully ==== Empty FireFox Cache ====================== C:\Users\marleen\AppData\Local\Mozilla\Firefox\Profiles\8k1f2frf.default-1433585333261\cache2 emptied successfully ==== Empty Chrome Cache ====================== C:\Users\marleen\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully ==== Empty All Flash Cache ====================== Flash Cache is not empty, a reboot is needed ==== Empty All Java Cache ====================== Java Cache cleared successfully ==== C:\zoek_backup content ====================== C:\zoek_backup (files=156 folders=42 12882017 bytes) ==== Empty Temp Folders ====================== C:\Users\Default\AppData\Local\Temp emptied successfully C:\Users\Default User\AppData\Local\Temp emptied successfully C:\Users\marleen\AppData\Local\Temp will be emptied at reboot C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully C:\Windows\Temp will be emptied at reboot ==== After Reboot ====================== ==== Empty Temp Folders ====================== C:\Windows\Temp successfully emptied C:\Users\marleen\AppData\Local\Temp successfully emptied ==== Empty Recycle Bin ====================== C:\$RECYCLE.BIN successfully emptied ==== Deleting Files / Folders ====================== "C:\Users\marleen\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\6D6GUSUL\dd1.midasplayer.com" not found ==== EOF on do 17/09/2015 at 13:26:28,59 ======================