Zoek.exe v5.0.0.0 Updated 21-09-2015 Tool run by Gunther on di 22/09/2015 at 23:39:55,07. Microsoft Windows 8.1 6.3.9600 x64 Running in: Normal Mode Internet Access Detected Launched: C:\Users\Gunther\zoek.exe [Scan all users] [Script inserted] [Checkboxes used] ==== System Restore Info ====================== 22/09/2015 23:41:09 Zoek.exe System Restore Point Created Successfully. ==== Empty Folders Check ====================== C:\PROGRA~2\AGEIA Technologies deleted successfully C:\Program Files\log deleted successfully C:\Users\Gunther\AppData\Local\EmieBrowserModeList deleted successfully C:\Users\Gunther\AppData\Local\EmieSiteList deleted successfully C:\Users\Gunther\AppData\Local\EmieUserList deleted successfully C:\Users\Gunther\AppData\Local\MediaShow deleted successfully C:\Users\Gunther\AppData\Local\VirtualStore deleted successfully ==== Deleting CLSID Registry Keys ====================== ==== Deleting CLSID Registry Values ====================== ==== Deleting Services ====================== ==== Registry Fix Code x64 ====================== Windows Registry Editor Version 5.00 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce] "Application Restart #3"=- ==== Deleting Files \ Folders ====================== C:\PROGRA~2\AGEIA Technologies not found C:\Users\Public\Pokki deleted C:\PROGRA~3\Pokki deleted C:\PROGRA~3\Package Cache deleted C:\Users\Default\AppData\Local\Pokki deleted C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Search.lnk deleted C:\Users\Gunther\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PC App Store.lnk deleted C:\Windows\SysNative\config\systemprofile\Searches deleted C:\Users\Gunther\JavaSetup8u60.exe deleted "C:\Windows\Installer\8ecbc.msi" deleted "C:\Users\Gunther\AppData\Local\Pokki\analytics.db" not deleted "C:\Users\Gunther\AppData\Local\Pokki\engine_update.db" not deleted "C:\Users\Gunther\AppData\Local\Pokki\notifications.db" deleted "C:\Users\Gunther\AppData\Local\Pokki\analytics.db" not deleted "C:\Users\Gunther\AppData\Local\Pokki\engine_update.db" not deleted "C:\Users\Gunther\AppData\Local\Pokki\notifications.db" deleted "C:\Users\Gunther\AppData\Local\Pokki\Engine\avcodec-54.dll" deleted "C:\Users\Gunther\AppData\Local\Pokki\Engine\avformat-54.dll" deleted "C:\Users\Gunther\AppData\Local\Pokki\Engine\avutil-51.dll" deleted "C:\Users\Gunther\AppData\Local\Pokki\Engine\chrome_100_percent.pak" deleted "C:\Users\Gunther\AppData\Local\Pokki\Engine\en-US.pak" deleted "C:\Users\Gunther\AppData\Local\Pokki\Engine\icudt.dll" deleted "C:\Users\Gunther\AppData\Local\Pokki\Engine\libPokki.dll" deleted "C:\Users\Gunther\AppData\Local\Pokki\Engine\ppGoogleNaClPluginChrome.dll" deleted "C:\Users\Gunther\AppData\Local\Pokki\Engine\resources.pak" deleted "C:\Users\Gunther\AppData\Local\Pokki\Engine\ServiceHostApp.exe" deleted "C:\Users\Gunther\AppData\Local\Pokki\Engine\ServiceHostAppUpdater.exe" deleted "C:\Users\Gunther\AppData\Local\Pokki\Engine\ServiceStartMenuIndexer.exe" deleted "C:\Users\Gunther\AppData\Local\Pokki\Pokkies\installed_pokkies.db" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\lockfile" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\Default\Cookies" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\Default\Network Action Predictor" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\Default\Shortcuts" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1\Cookies" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1\Network Action Predictor" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1\Visited Links" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1-websheet\Cookies" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1-websheet\Network Action Predictor" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\notifications\Cookies" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\notifications\Network Action Predictor" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\notifications\QuotaManager" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\notifications\QuotaManager-journal" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\notifications\Visited Links" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\notifications-websheet\Cookies" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\notifications-websheet\Network Action Predictor" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\Default\Cache\data_0" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\Default\Cache\data_1" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\Default\Cache\data_2" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\Default\Cache\data_3" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\Default\Cache\index" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\Default\Extension State\000017.log" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\Default\Extension State\LOCK" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\Default\Extension State\MANIFEST-000016" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1\Cache\data_0" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1\Cache\data_1" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1\Cache\data_2" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1\Cache\data_3" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1\Cache\index" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1\Extension State\000017.log" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1\Extension State\LOCK" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1\Extension State\MANIFEST-000016" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1\User StyleSheets\Custom.css" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1-websheet\Cache\data_0" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1-websheet\Cache\data_1" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1-websheet\Cache\data_2" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1-websheet\Cache\data_3" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1-websheet\Cache\index" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1-websheet\Extension State\000017.log" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1-websheet\Extension State\LOCK" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1-websheet\Extension State\MANIFEST-000016" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\notifications\Cache\data_0" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\notifications\Cache\data_1" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\notifications\Cache\data_2" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\notifications\Cache\data_3" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\notifications\Cache\index" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\notifications\databases\Databases.db" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\notifications\Extension State\000017.log" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\notifications\Extension State\LOCK" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\notifications\Extension State\MANIFEST-000016" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\notifications\User StyleSheets\Custom.css" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\notifications\databases\file__0\1" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\notifications-websheet\Cache\data_0" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\notifications-websheet\Cache\data_1" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\notifications-websheet\Cache\data_2" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\notifications-websheet\Cache\data_3" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\notifications-websheet\Cache\index" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\notifications-websheet\Extension State\000017.log" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\notifications-websheet\Extension State\LOCK" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\notifications-websheet\Extension State\MANIFEST-000016" deleted "C:\Users\Gunther\AppData\Local\Pokki\Engine\avcodec-54.dll" deleted "C:\Users\Gunther\AppData\Local\Pokki\Engine\avformat-54.dll" deleted "C:\Users\Gunther\AppData\Local\Pokki\Engine\avutil-51.dll" deleted "C:\Users\Gunther\AppData\Local\Pokki\Engine\chrome_100_percent.pak" deleted "C:\Users\Gunther\AppData\Local\Pokki\Engine\en-US.pak" deleted "C:\Users\Gunther\AppData\Local\Pokki\Engine\icudt.dll" deleted "C:\Users\Gunther\AppData\Local\Pokki\Engine\libPokki.dll" deleted "C:\Users\Gunther\AppData\Local\Pokki\Engine\ppGoogleNaClPluginChrome.dll" deleted "C:\Users\Gunther\AppData\Local\Pokki\Engine\resources.pak" deleted "C:\Users\Gunther\AppData\Local\Pokki\Engine\ServiceHostApp.exe" deleted "C:\Users\Gunther\AppData\Local\Pokki\Engine\ServiceHostAppUpdater.exe" deleted "C:\Users\Gunther\AppData\Local\Pokki\Engine\ServiceStartMenuIndexer.exe" deleted "C:\Users\Gunther\AppData\Local\Pokki\Pokkies\installed_pokkies.db" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\lockfile" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\Default\Cookies" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\Default\Network Action Predictor" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\Default\Shortcuts" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1\Cookies" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1\Network Action Predictor" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1\Visited Links" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1-websheet\Cookies" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1-websheet\Network Action Predictor" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\notifications\Cookies" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\notifications\Network Action Predictor" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\notifications\QuotaManager" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\notifications\QuotaManager-journal" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\notifications\Visited Links" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\notifications-websheet\Cookies" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\notifications-websheet\Network Action Predictor" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\Default\Cache\data_0" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\Default\Cache\data_1" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\Default\Cache\data_2" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\Default\Cache\data_3" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\Default\Cache\index" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\Default\Extension State\000017.log" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\Default\Extension State\LOCK" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\Default\Extension State\MANIFEST-000016" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1\Cache\data_0" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1\Cache\data_1" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1\Cache\data_2" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1\Cache\data_3" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1\Cache\index" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1\Extension State\000017.log" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1\Extension State\LOCK" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1\Extension State\MANIFEST-000016" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1\User StyleSheets\Custom.css" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1-websheet\Cache\data_0" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1-websheet\Cache\data_1" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1-websheet\Cache\data_2" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1-websheet\Cache\data_3" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1-websheet\Cache\index" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1-websheet\Extension State\000017.log" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1-websheet\Extension State\LOCK" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1-websheet\Extension State\MANIFEST-000016" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\notifications\Cache\data_0" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\notifications\Cache\data_1" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\notifications\Cache\data_2" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\notifications\Cache\data_3" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\notifications\Cache\index" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\notifications\databases\Databases.db" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\notifications\Extension State\000017.log" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\notifications\Extension State\LOCK" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\notifications\Extension State\MANIFEST-000016" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\notifications\User StyleSheets\Custom.css" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\notifications\databases\file__0\1" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\notifications-websheet\Cache\data_0" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\notifications-websheet\Cache\data_1" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\notifications-websheet\Cache\data_2" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\notifications-websheet\Cache\data_3" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\notifications-websheet\Cache\index" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\notifications-websheet\Extension State\000017.log" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\notifications-websheet\Extension State\LOCK" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\notifications-websheet\Extension State\MANIFEST-000016" deleted "C:\Users\Gunther\AppData\Local\Pokki" not deleted "C:\Users\Gunther\AppData\Local\Pokki" not deleted "C:\Users\Gunther\AppData\Local\Pokki\Engine" not deleted "C:\Users\Gunther\AppData\Local\Pokki\Pokkies" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\Default" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1-websheet" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\notifications" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\notifications-websheet" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\Default\Cache" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\Default\Extension State" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1\Cache" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1\Extension State" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1\User StyleSheets" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1-websheet\Cache" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1-websheet\Extension State" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\notifications\Cache" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\notifications\databases" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\notifications\Extension State" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\notifications\User StyleSheets" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\notifications\databases\file__0" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\notifications-websheet\Cache" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\notifications-websheet\Extension State" deleted "C:\Users\Gunther\AppData\Local\Pokki\Engine" not deleted "C:\Users\Gunther\AppData\Local\Pokki\Pokkies" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\Default" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1-websheet" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\notifications" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\notifications-websheet" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\Default\Cache" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\Default\Extension State" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1\Cache" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1\Extension State" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1\User StyleSheets" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1-websheet\Cache" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\f22abfeae27a67446927d078890381efc546d3e1-websheet\Extension State" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\notifications\Cache" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\notifications\databases" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\notifications\Extension State" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\notifications\User StyleSheets" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\notifications\databases\file__0" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\notifications-websheet\Cache" deleted "C:\Users\Gunther\AppData\Local\Pokki\UserData\notifications-websheet\Extension State" deleted ==== Files Recently Created / Modified ====================== ====== C:\Windows ==== 2015-08-24 15:28:26 FC2EA5BD5307D2CFA5AAA38E0C0DDCE9 221184 ----a-w- C:\Windows\notepad.exe ====== C:\Users\Gunther\AppData\Local\Temp ==== ====== Java Cache ===== 2015-09-22 21:17:44 415FC9732A3F4D89A0E01251CD66E136 646 ----a-w- C:\Users\Gunther\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\18\3cb32f52-6134a367 ====== C:\Windows\SysWOW64 ===== 2015-09-22 21:17:09 C05114B0BDF2470F7F4A1B2128540062 97888 ----a-w- C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2015-09-11 05:47:33 8EBAEAEF19E557506D9C7236281B79F4 124928 ----a-w- C:\Windows\SysWOW64\wuwebv.dll 2015-09-11 05:47:33 0EA1A0514316E500B4B6ABB816DA01DC 721920 ----a-w- C:\Windows\SysWOW64\wuapi.dll 2015-09-11 05:47:32 F34E095C602E105AAEB5762464A074D8 81920 ----a-w- C:\Windows\SysWOW64\wudriver.dll 2015-09-11 05:47:32 3EB61DA44BD70A70803CDFFC317C3525 29696 ----a-w- C:\Windows\SysWOW64\wuapp.exe 2015-09-11 05:46:51 0C0F9AAF13415DE6C9F73FF7BEF88314 230912 ----a-w- C:\Windows\SysWOW64\InkEd.dll 2015-09-11 05:46:45 164FE7DB9C7819F2F60A33F9BADD3B99 19856384 ----a-w- C:\Windows\SysWOW64\mshtml.dll 2015-09-11 05:46:40 DA36D4C0F6EF1C3A3FD848BB7A88A728 12857344 ----a-w- C:\Windows\SysWOW64\ieframe.dll 2015-09-11 05:46:39 7FE6E42911FCD9EA43AC111558E794C1 4520448 ----a-w- C:\Windows\SysWOW64\jscript9.dll 2015-09-11 05:46:38 C2CDCD4EFD66AF2DE22EBB1EDAD70A92 2279424 ----a-w- C:\Windows\SysWOW64\iertutil.dll 2015-09-11 05:46:38 9BCDFFECF276DBFB1EC8E2D3DD038E00 1951232 ----a-w- C:\Windows\SysWOW64\wininet.dll 2015-09-11 05:46:38 21FA5416257D628DE9100B22C6F4E011 665600 ----a-w- C:\Windows\SysWOW64\jscript.dll 2015-09-11 05:46:37 DB87011A9EA9E44EB716C472E09921F8 1310720 ----a-w- C:\Windows\SysWOW64\urlmon.dll 2015-09-11 05:46:37 912A76E83F974A8EE728A109C9905685 504832 ----a-w- C:\Windows\SysWOW64\vbscript.dll 2015-09-11 05:46:36 A030A4D208BB0FEA97702F56A75CE7D2 2052608 ----a-w- C:\Windows\SysWOW64\inetcpl.cpl 2015-09-11 05:46:36 59C13F923C30AE909129C1B28139E32B 327168 ----a-w- C:\Windows\SysWOW64\iedkcs32.dll 2015-09-11 05:46:36 12051337325500C8E68ADDE4E3706908 689152 ----a-w- C:\Windows\SysWOW64\msfeeds.dll 2015-09-11 05:46:35 BD197D0865A8C858BB9AB153D5B22EF7 230400 ----a-w- C:\Windows\SysWOW64\webcheck.dll 2015-09-11 05:46:35 97B61B2A69D381FB4B354A742D77438A 880128 ----a-w- C:\Windows\SysWOW64\inetcomm.dll 2015-09-11 05:46:34 7282DBD37A639459F907B8C9307D1041 710144 ----a-w- C:\Windows\SysWOW64\ieapfltr.dll 2015-09-11 05:46:19 F418F268721B183BB5C42DFA23D9D9C2 359936 ----a-w- C:\Windows\SysWOW64\taskeng.exe 2015-09-11 05:46:19 9FA27757540B4AAD5EDAAEE1E1D33FA9 182784 ----a-w- C:\Windows\SysWOW64\schtasks.exe 2015-09-11 05:46:18 A81B57D0157AC51C312BADB2D7153252 520192 ----a-w- C:\Windows\SysWOW64\SettingSync.dll 2015-09-11 05:46:18 70C34F5CC9B0E51B87C417FB65C120F9 1546752 ----a-w- C:\Windows\SysWOW64\Windows.UI.Immersive.dll 2015-09-11 05:46:18 560120EE098272BF187C9FC470F290FA 2461184 ----a-w- C:\Windows\SysWOW64\authui.dll 2015-09-11 05:46:18 4615D4A2D7990F604130002F48EE0B87 148480 ----a-w- C:\Windows\SysWOW64\shacct.dll 2015-09-11 05:46:18 2EE41D7C3CE1F2574DAF1FA72AD8564B 65600 ----a-w- C:\Windows\SysWOW64\appidapi.dll 2015-09-11 05:46:17 F1BB02F06DF4A6D37508A65E0A2EE881 301568 ----a-w- C:\Windows\SysWOW64\atmfd.dll 2015-09-11 05:46:17 78FE64758E3396A13EE8CBE0EF435B32 35840 ----a-w- C:\Windows\SysWOW64\atmlib.dll ====== C:\Windows\SysWOW64\drivers ===== ====== C:\Windows\Sysnative ===== 2015-09-21 20:49:23 08079E76DD10DDEC6FA4F92AFF1CD38D 118616 ----a-w- C:\Windows\Sysnative\consent.exe 2015-09-21 20:49:16 C437FBED45D3F2AEBA19CA3A9BA2348D 411455 ----a-w- C:\Windows\Sysnative\ApnDatabase.xml 2015-09-11 05:47:34 3F726FF7B1ACC7D5E89940EA5BFF0E61 3705344 ----a-w- C:\Windows\Sysnative\wuaueng.dll 2015-09-11 05:47:33 F3F53766701AB4B894DDB4F78D53321D 140288 ----a-w- C:\Windows\Sysnative\wuwebv.dll 2015-09-11 05:47:33 B4EAB9C15967EBD6E4569734892176D4 136904 ----a-w- C:\Windows\Sysnative\wuauclt.exe 2015-09-11 05:47:33 7AB01F304D40674D37CB7E7E8891B429 409088 ----a-w- C:\Windows\Sysnative\WUSettingsProvider.dll 2015-09-11 05:47:33 604010F2534A39FF7E043236FE296BA3 95744 ----a-w- C:\Windows\Sysnative\wudriver.dll 2015-09-11 05:47:33 57220D51A2650FEB323AA9E639714E4B 2240512 ----a-w- C:\Windows\Sysnative\wucltux.dll 2015-09-11 05:47:33 5106BAC2B4547B26C4B3A974615D2585 891904 ----a-w- C:\Windows\Sysnative\wuapi.dll 2015-09-11 05:47:32 5AD59ABE70AB621386E6E23A5EE221D1 35840 ----a-w- C:\Windows\Sysnative\wuapp.exe 2015-09-11 05:46:51 5AA5D3EE2A87385B6E567D6B48B13A84 268288 ----a-w- C:\Windows\Sysnative\InkEd.dll 2015-09-11 05:46:47 B73856CE663B16B980D635922B6A5EA6 25188352 ----a-w- C:\Windows\Sysnative\mshtml.dll 2015-09-11 05:46:42 06A02C37847A859E10EACE1A9032387C 14451712 ----a-w- C:\Windows\Sysnative\ieframe.dll 2015-09-11 05:46:39 CC4D00C985EC6E0F67EE3CF69FABAC4B 2886144 ----a-w- C:\Windows\Sysnative\iertutil.dll 2015-09-11 05:46:39 13FAD8FFBB0E85761B42594FDAE425F7 5923840 ----a-w- C:\Windows\Sysnative\jscript9.dll 2015-09-11 05:46:38 1F3DBB57E9EAC4E4BDD4DD523EEAC701 1545728 ----a-w- C:\Windows\Sysnative\urlmon.dll 2015-09-11 05:46:38 096A832FCF5A01003E96DD7FEE45618D 2427392 ----a-w- C:\Windows\Sysnative\wininet.dll 2015-09-11 05:46:37 F6EA92A7954C4BE5916BD791F1B2FA3F 720384 ----a-w- C:\Windows\Sysnative\ie4uinit.exe 2015-09-11 05:46:37 C3BBD7A0B4E8E4208E8C88D9D4D0E835 585216 ----a-w- C:\Windows\Sysnative\vbscript.dll 2015-09-11 05:46:37 9D7B2EBCE72DBF36A8B502ED7FF230A7 817664 ----a-w- C:\Windows\Sysnative\jscript.dll 2015-09-11 05:46:37 504D90662FEFEF8EA6E19BFE5C10229C 2126336 ----a-w- C:\Windows\Sysnative\inetcpl.cpl 2015-09-11 05:46:37 2ED806192EEB92E963B30B250F946C04 374784 ----a-w- C:\Windows\Sysnative\iedkcs32.dll 2015-09-11 05:46:35 FCE64E50B3E81A69C1CA767015AA1917 800768 ----a-w- C:\Windows\Sysnative\ieapfltr.dll 2015-09-11 05:46:35 F5886DC6A5386A1EC938C93A40554C15 801280 ----a-w- C:\Windows\Sysnative\msfeeds.dll 2015-09-11 05:46:35 C5760EA4180AD13CF49F04D2E806DE8F 1032704 ----a-w- C:\Windows\Sysnative\inetcomm.dll 2015-09-11 05:46:35 B0ED8AEF452E9294E73C0C70BD301A4F 262144 ----a-w- C:\Windows\Sysnative\webcheck.dll 2015-09-11 05:46:19 A21AC8D41E63CF1AA24EBC165AE82C9A 468992 ----a-w- C:\Windows\Sysnative\taskeng.exe 2015-09-11 05:46:19 3151A020E03DDE31AAC49F35C5EFB4DB 1265152 ----a-w- C:\Windows\Sysnative\schedsvc.dll 2015-09-11 05:46:19 2E9E198247BF0E9BD94B42286798A5AC 229376 ----a-w- C:\Windows\Sysnative\schtasks.exe 2015-09-11 05:46:18 FA3A2F366A8D4A2BFE2FBD6BF99D8BD2 2775552 ----a-w- C:\Windows\Sysnative\authui.dll 2015-09-11 05:46:18 F5A987C9AE37B5A0E596FD6C61B2786E 194048 ----a-w- C:\Windows\Sysnative\shacct.dll 2015-09-11 05:46:18 D29E5AA3BDB179B68BB80918008B6D55 655872 ----a-w- C:\Windows\Sysnative\SettingSync.dll 2015-09-11 05:46:18 88358135810B9DFD830A9D3A8C3D149A 39936 ----a-w- C:\Windows\Sysnative\appidsvc.dll 2015-09-11 05:46:18 3F44A679845792E68F1A6FDA59309E92 74928 ----a-w- C:\Windows\Sysnative\appidapi.dll 2015-09-11 05:46:18 3D50654EB342ED42EDA48F4CD8EF82B1 1728000 ----a-w- C:\Windows\Sysnative\Windows.UI.Immersive.dll 2015-09-11 05:46:17 BB13532E840F4B6842E789DDA8382FE2 358912 ----a-w- C:\Windows\Sysnative\atmfd.dll 2015-09-11 05:46:17 452F2B00E71FB1B216957539D15F3159 4175872 ----a-w- C:\Windows\Sysnative\win32k.sys 2015-09-11 05:46:17 447B30071910564528542F80343C74CB 44032 ----a-w- C:\Windows\Sysnative\atmlib.dll 2015-09-11 05:46:15 D2B6D2C64B74277FC27756F9C02FFB5F 63488 ----a-w- C:\Windows\Sysnative\tzsync.exe 2015-09-10 19:27:52 82446D358A9FB51CB9DA32A5C901D7A0 21040 ----a-w- C:\Windows\Sysnative\sdnclean64.exe ====== C:\Windows\Sysnative\drivers ===== 2015-09-11 16:35:49 8F22037D3F5A6BB676525D825A1388B9 113880 ----a-w- C:\Windows\Sysnative\drivers\MBAMSwissArmy.sys 2015-09-11 16:35:32 E681CE4AE5C09651D53CB4387CA3560E 109272 ----a-w- C:\Windows\Sysnative\drivers\mbamchameleon.sys 2015-09-11 16:35:32 A8D28D5B3E2A528D1EF0E338E44F2820 25816 ----a-w- C:\Windows\Sysnative\drivers\mbam.sys 2015-09-11 16:35:32 85CFE7AB85B43B6B7AC7961AA3983A9F 64216 ----a-w- C:\Windows\Sysnative\drivers\mwac.sys 2015-09-06 07:29:21 26B8FED3F3B85F5F0C4BD03FD00B9941 270168 ----a-w- C:\Windows\Sysnative\drivers\WdFilter.sys 2015-09-06 07:29:19 81285DDC994F03379DB46419300B2DCB 44560 ----a-w- C:\Windows\Sysnative\drivers\WdBoot.sys 2015-09-06 07:29:18 CE67080F00E0AF32755096CEA6430ABA 114520 ----a-w- C:\Windows\Sysnative\drivers\WdNisDrv.sys 2015-08-24 15:29:30 9A788037D768809DFD677F4BA08A224A 101720 ----a-w- C:\Windows\Sysnative\drivers\mountmgr.sys 2015-08-24 15:24:53 D41D8CD98F00B204E9800998ECF8427E 0 ---ha-w- C:\Windows\Sysnative\drivers\Msft_User_WpdFs_01_11_00.Wdf 2015-08-24 09:07:22 746DDF7D59AB8D721C88D48434597E8D 2476376 ----a-w- C:\Windows\Sysnative\drivers\tcpip.sys 2015-08-24 09:07:22 25991A1635AF725E9DC840A6A36824EC 428888 ----a-w- C:\Windows\Sysnative\drivers\FWPKCLNT.SYS 2015-08-24 09:07:21 97DC5967F65503213FD1F1B3E4A6F983 1113944 ----a-w- C:\Windows\Sysnative\drivers\ndis.sys ====== C:\Windows\Tasks ====== 2015-09-10 19:28:08 -------- d-----w- C:\Windows\Sysnative\Tasks\Safer-Networking 2015-08-24 09:37:12 6B09FDCDD867B468D6D2D1F038B27F0F 3334 ----a-w- C:\Windows\Sysnative\Tasks\AcerCloud ====== C:\Windows\Temp ====== ======= C:\Program Files ===== 2015-09-21 22:06:20 -------- d-----w- C:\Program Files\trend micro 2015-09-10 19:37:58 -------- d-----w- C:\Program Files\Common Files\AV ======= C:\PROGRA~2 ===== 2015-09-22 21:17:23 -------- d-----w- C:\PROGRA~2\COMMON~1\Java 2015-09-22 21:16:29 -------- d-----w- C:\PROGRA~2\Java ======= C: ===== ====== C:\Users\Gunther\AppData\Roaming ====== 2015-09-22 21:17:16 -------- d-----w- C:\Users\Gunther\AppData\Roaming\Sun 2015-09-22 21:15:31 -------- d-----w- C:\Users\Gunther\AppData\Locallow\Oracle 2015-09-20 17:36:43 -------- d-----w- C:\Users\Gunther\AppData\Local\Microsoft Help 2015-09-17 18:40:51 -------- d-----w- C:\Windows\SysNative\config\systemprofile\AppData\Local\CrashDumps 2015-09-10 19:37:36 -------- d-----w- C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Programs 2015-09-10 19:27:15 -------- d-----w- C:\Users\Gunther\AppData\Local\Programs 2015-09-10 18:28:16 -------- d-----w- C:\Users\Gunther\AppData\Local\NPE ====== C:\Users\Gunther ====== 2015-09-22 21:17:15 -------- d-----w- C:\Users\Gunther\.oracle_jre_usage 2015-09-22 21:17:08 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2015-09-21 22:05:42 8045ABB21A3BDD66A48E1ED5C0F0EF6A 1222144 ----a-w- C:\Users\Gunther\Documents\RSITx64.exe ====== C: exe-files == 2015-09-22 21:17:09 BC949C957CEB9FAFDF0F3949CDDF1A72 0 ----a-we C:\ProgramData\Oracle\Java\javapath\java.exe 2015-09-22 21:17:09 7080B965215703EA1340C3C4903C7D73 0 ----a-we C:\ProgramData\Oracle\Java\javapath\javaws.exe 2015-09-22 21:17:09 5DC0128E8A2017E82289191820C736A5 0 ----a-we C:\ProgramData\Oracle\Java\javapath\javaw.exe 2015-09-22 21:16:59 E408E46C5DD2D03A7474AA12BAABEFEE 15968 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_60\bin\klist.exe 2015-09-22 21:16:59 D94C31E9C9C9A1273CC67DC6FFAF9984 15968 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_60\bin\policytool.exe 2015-09-22 21:16:59 BDFF5086FC1F20E631A070EEF43A7BEC 16480 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_60\bin\tnameserv.exe 2015-09-22 21:16:59 BC949C957CEB9FAFDF0F3949CDDF1A72 191584 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_60\bin\java.exe 2015-09-22 21:16:59 B9DE149653ED8B9C5C6CB68131AB66D2 15968 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_60\bin\jjs.exe 2015-09-22 21:16:59 B804A4E31F4BAD4D5BA05FE684756BA2 15968 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_60\bin\servertool.exe 2015-09-22 21:16:59 8C6BDB56CD4DEED1AF2790D37B54CFE9 68192 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_60\bin\javacpl.exe 2015-09-22 21:16:59 86CC77A8189758834CF83F7F2FEA5162 15968 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_60\bin\java-rmi.exe 2015-09-22 21:16:59 7A0DE452F677EF2971C7B75B0267B6ED 50784 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_60\bin\ssvagent.exe 2015-09-22 21:16:59 7080B965215703EA1340C3C4903C7D73 274016 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_60\bin\javaws.exe 2015-09-22 21:16:59 6A5A2FDB6D09E02A3283C55237DA10F6 159328 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_60\bin\unpack200.exe 2015-09-22 21:16:59 606A24A64E164B345A79F8F22A5DAC6F 15968 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_60\bin\pack200.exe 2015-09-22 21:16:59 5DC0128E8A2017E82289191820C736A5 191584 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_60\bin\javaw.exe 2015-09-22 21:16:59 5A503CFE5B553A9721A469FCC9CE8562 15968 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_60\bin\rmiregistry.exe 2015-09-22 21:16:59 3292748E640429C2682484BD23D43F6B 15968 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_60\bin\rmid.exe 2015-09-22 21:16:59 30387BE3E5D04FE969B731441C89D2D8 15968 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_60\bin\ktab.exe 2015-09-22 21:16:59 262BBCE84B9C8784CC5A5E1975898022 30304 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_60\bin\jabswitch.exe 2015-09-22 21:16:59 21B5D297A9191E4D833BB39456CEDAD0 15968 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_60\bin\kinit.exe 2015-09-22 21:16:59 0FCF9F3D9518B90FB58CC950FA33998C 76896 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_60\bin\jp2launcher.exe 2015-09-22 21:16:59 0F6E0DD1263ACB2A1AC559BB7742B54D 15968 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_60\bin\keytool.exe 2015-09-22 21:16:59 08427EADE480F21412696582170B1167 16480 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_60\bin\orbd.exe 2015-09-22 20:18:51 5AEFDC9A7B05B060D3EC59FAA252E941 6365936 ----a-w- C:\Users\Gunther\AppData\Local\NVIDIA\NvBackend\Packages\00007f13\DAO.19986246.exe 2015-09-22 14:48:26 50C6C11F21C760154FA8DE5C974EA7E0 630200 ----a-w- C:\Users\Gunther\AppData\Local\NVIDIA\NvBackend\ApplicationOntology\NvOAWrapperCache.exe 2015-09-22 14:48:24 C01A35B494CB150D4D4479A321E44A7D 172984 ----a-w- C:\Users\Gunther\AppData\Local\NVIDIA\NvBackend\ApplicationOntology\OAWrapper.exe 2015-09-21 22:06:20 9A2347903D6EDB84C10F288BC0578C1C 388608 ----a-w- C:\Program Files\trend micro\Gunther.exe 2015-09-21 22:05:42 8045ABB21A3BDD66A48E1ED5C0F0EF6A 1222144 ----a-w- C:\Users\Gunther\Documents\RSITx64.exe 2015-09-21 20:49:23 08079E76DD10DDEC6FA4F92AFF1CD38D 118616 ----a-w- C:\Windows\System32\consent.exe 2015-09-21 20:18:35 D7705045038BA7CAFAFD2E3F2E740C96 525328 ----a-w- C:\Users\Gunther\AppData\Local\NVIDIA\NvBackend\Packages\00007efe\CoProc update.19981759.exe 2015-09-17 18:56:38 9E919FC6F2B5ED86E4726697136B3F5F 1072720 ----a-w- C:\Program Files (x86)\Google\Update\Install\{6F13B4E8-D925-4715-8D90-698D26731350}\45.0.2454.93_45.0.2454.85_chrome_updater.exe 2015-09-17 18:56:38 9E919FC6F2B5ED86E4726697136B3F5F 1072720 ----a-w- C:\Program Files (x86)\Google\Update\Download\{4DC8B4CA-1BDA-483E-B5FA-D3C12E15B62D}\45.0.2454.93\45.0.2454.93_45.0.2454.85_chrome_updater.exe 2015-09-17 18:51:34 FAC17E42199598C0352B9F5DC2EFFC85 88392 ----atw- C:\Program Files (x86)\Google\Update\1.3.28.15\GoogleUpdateOnDemand.exe 2015-09-17 18:51:34 E337785DA1958E9AB02DDB2369EF46E8 307016 ----atw- C:\Program Files (x86)\Google\Update\1.3.28.15\GoogleCrashHandler64.exe 2015-09-17 18:51:34 D9A15F83CB6E5901A63F24CD7D58DBAF 929872 ----a-w- C:\Program Files (x86)\Google\Update\1.3.28.15\GoogleUpdateSetup.exe 2015-09-17 18:51:34 BFDCC0375C492C524E78647CEED3F77D 130888 ----atw- C:\Program Files (x86)\Google\Update\1.3.28.15\GoogleUpdateComRegisterShell64.exe 2015-09-17 18:51:34 A72BB48D9014A7D7C05F02F595F52D60 245576 ----atw- C:\Program Files (x86)\Google\Update\1.3.28.15\GoogleCrashHandler.exe 2015-09-17 18:51:34 77352A5A0833B1CA3B771148DA535CB6 88392 ----atw- C:\Program Files (x86)\Google\Update\1.3.28.15\GoogleUpdateWebPlugin.exe 2015-09-17 18:51:34 61A77DDEF5E8D85E8B0955C4E5127B39 88392 ----atw- C:\Program Files (x86)\Google\Update\1.3.28.15\GoogleUpdateBroker.exe 2015-09-17 18:51:34 053EEEE1ABAE53F044F1E386E22AE525 144200 ----atw- C:\Program Files (x86)\Google\Update\1.3.28.15\GoogleUpdate.exe 2015-09-17 18:51:33 D9A15F83CB6E5901A63F24CD7D58DBAF 929872 ----a-w- C:\Program Files (x86)\Google\Update\Install\{DB5A4E0C-8C3B-473C-A0BB-4AB4FCAB3D50}\GoogleUpdateSetup.exe 2015-09-17 18:51:32 D9A15F83CB6E5901A63F24CD7D58DBAF 929872 ----a-w- C:\Program Files (x86)\Google\Update\Download\{430FD4D0-B729-4F61-AA34-91526481799D}\1.3.28.15\GoogleUpdateSetup.exe === C: other files == 2015-09-22 21:16:59 4E221C69F3B103481534D1B6CB6A90DD 14130 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_60\lib\deploy\ffjcext.zip ==== Startup Registry Enabled ====================== [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "abDocsDllLoader"="C:\Program Files (x86)\Acer\abDocs\abDocsDllLoaderMonitor.exe" [HKEY_USERS\S-1-5-21-3568499059-3940502318-736609096-1001\Software\Microsoft\Windows\CurrentVersion\Run] "Spotify Web Helper"="C:\Program Files (x86)\Spotify\Data\SpotifyWebHelper.exe" "SpybotPostWindows10UpgradeReInstall"="C:\Program Files\Common Files\AV\Spybot - Search and Destroy\Test.exe" [HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run] "abDocsDllLoader"="C:\Program Files (x86)\Acer\abDocs\abDocsDllLoaderMonitor.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "abDocsDllLoader"="C:\Program Files (x86)\Acer\abDocs\abDocsDllLoader.exe" "beid"="C:\Program Files (x86)\Belgium Identity Card\beid35gui.exe /startup" "SDTray"="C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe" "SunJavaUpdateSched"="C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "Spotify Web Helper"="C:\Program Files (x86)\Spotify\Data\SpotifyWebHelper.exe" "SpybotPostWindows10UpgradeReInstall"="C:\Program Files\Common Files\AV\Spybot - Search and Destroy\Test.exe" ==== Startup Registry Enabled x64 ====================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NvBackend"="C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe" "ShadowPlay"="C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart" "RTHDVCPL"="C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s" "RtHDVBg_Dolby"="C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe /FORPCEE4" ==== Task Scheduler Jobs ====================== C:\Windows\tasks\GoogleUpdateTaskMachineCore.job --a-------- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [09/07/2015 07:31] C:\Windows\tasks\GoogleUpdateTaskMachineUA.job --a-------- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [09/07/2015 07:31] ==== Other Scheduled Tasks ====================== "C:\Windows\SysNative\tasks\ACC" [C:\Program Files (x86)\Acer\Care Center\LiveUpdateChecker.exe] "C:\Windows\SysNative\tasks\ACCAgent" [C:\Program Files (x86)\Acer\Care Center\LiveUpdateAgent.exe] "C:\Windows\SysNative\tasks\AcerCloud" [C:\Program Files (x86)\Acer\Acer Portal\AcerPortal.exe] "C:\Windows\SysNative\tasks\BacKGroundAgent" [C:\Program Files (x86)\Acer\AOP Framework\BackgroundAgent.exe] "C:\Windows\SysNative\tasks\DolbySelectorTask" [%ProgramFiles%\Dolby Digital Plus\ddp.exe] "C:\Windows\SysNative\tasks\GoogleUpdateTaskMachineCore" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe] "C:\Windows\SysNative\tasks\GoogleUpdateTaskMachineUA" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe] "C:\Windows\SysNative\tasks\Launch Manager" ["C:\Program Files\Acer\Acer Launch Manager\LMLauncher.exe"] "C:\Windows\SysNative\tasks\Norton WSC Integration" ["C:\Program Files (x86)\Norton Security\Engine\22.5.2.15\WSCStub.exe"] "C:\Windows\SysNative\tasks\Pokki" [%LOCALAPPDATA%\Pokki\Engine\ServiceHostAppUpdater.exe] "C:\Windows\SysNative\tasks\Power Management" ["C:\Program Files\Acer\Acer Power Management\ePowerTrayLauncher.exe"] "C:\Windows\SysNative\tasks\Quick Access" ["C:\Program Files\Acer\Acer Quick Access\QALauncher.exe"] "C:\Windows\SysNative\tasks\Quick Access Quick Launcher" ["C:\Program Files\Acer\Acer Quick Access\QALauncher.exe"] "C:\Windows\SysNative\tasks\Software Update Application" ["C:\ProgramData\OEM\UpgradeTool\ListCheck.exe"] "C:\Windows\SysNative\tasks\UbtFrameworkService" ["C:\Program Files\Acer\User Experience Improvement Program\Framework\TriggerFramework.exe"] "C:\Windows\SysNative\tasks\User_Feed_Synchronization-{1B6C97AE-FFE0-4836-BA2E-B2CE7841FE43}" [C:\Windows\system32\msfeedssync.exe] "C:\Windows\SysNative\tasks\Norton Security\Norton Error Analyzer" [C:\Program Files (x86)\Norton Security\Engine\22.5.2.15\SymErr.exe] "C:\Windows\SysNative\tasks\Norton Security\Norton Error Processor" [C:\Program Files (x86)\Norton Security\Engine\22.5.2.15\SymErr.exe] "C:\Windows\SysNative\tasks\Recovery Management\Notification" [C:\Program Files\Acer\Acer Recovery Management\Notification\Notification.exe] "C:\Windows\SysNative\tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates" ["C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe"] "C:\Windows\SysNative\tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization" ["C:\Program Files (x86)\Spybot - Search & Destroy 2\SDImmunize.exe"] "C:\Windows\SysNative\tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system" ["C:\Program Files (x86)\Spybot - Search & Destroy 2\SDScan.exe"] ==== Firefox Extensions Registry ====================== [HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions] "{4ED1F68A-5463-4931-9384-8FFF5ED91D92}"="C:\Program Files (x86)\McAfee\SiteAdvisor" [24/05/2015 16:00] [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions] "belgiumeid@eid.belgium.be"="C:\Program Files\Mozilla Firefox\extensions\belgiumeid@eid.belgium.be" [] ==== Chromium Look ====================== Google Chrome Version: 45.0.2454.93 HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions cjabmdjcfcfdmffimndhafhblfmpjdpe - C:\Program Files (x86)\Norton Security\Engine\22.5.2.15\Exts\Chrome.crx[10/07/2015 06:03] fheoggkfdfchfphceeifdbepaooicaho - C:\Program Files (x86)\McAfee\SiteAdvisor\McChPlg.crx[17/04/2015 09:01] iikflkcanblccfahdhdonehdalibjnif - No path found[] Google Docs - Gunther\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake Google Drive - Gunther\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf YouTube - Gunther\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo Norton Security Toolbar - Gunther\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjabmdjcfcfdmffimndhafhblfmpjdpe Google Search - Gunther\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf SiteAdvisor - Gunther\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho Google Docs Offline - Gunther\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi Norton Identity Safe - Gunther\AppData\Local\Google\Chrome\User Data\Default\Extensions\iikflkcanblccfahdhdonehdalibjnif Chrome Web Store Payments - Gunther\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda Gmail - Gunther\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia ==== Set IE to Default ====================== Old Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://www.google.be/" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes] "DefaultScope"="{45196799-ACB6-4460-AA63-C47F2A0D647F}" New Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://www.google.be/" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes] "DefaultScope"="{012E1000-F331-11DB-8314-0800200C9A66}" ==== All HKCU SearchScopes ====================== HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes {012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}" {0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC" {45196799-ACB6-4460-AA63-C47F2A0D647F} Unknown Url="Not_Found" ==== Deleting CLSID Registry Keys ====================== HKEY_USERS\S-1-5-21-3568499059-3940502318-736609096-1001\Software\Microsoft\Internet Explorer\SearchScopes\{45196799-ACB6-4460-AA63-C47F2A0D647F} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{45196799-ACB6-4460-AA63-C47F2A0D647F} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{45196799-ACB6-4460-AA63-C47F2A0D647F} deleted successfully ==== Deleting CLSID Registry Values ====================== ==== Deleting Registry Keys ====================== HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\02F6486B12843E11F869800002C0A966 deleted successfully HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{B6846F20-4821-11E3-8F96-0800200C9A66} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\02F6486B12843E11F869800002C0A966 deleted successfully ==== Empty IE Cache ====================== C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Gunther\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\Users\Gunther\AppData\Local\Microsoft\Windows\INetCache\Low\Content.IE5 emptied successfully C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\Users\Gunther\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully C:\Users\Gunther\AppData\Local\Microsoft\Windows\INetCache\Low\IE emptied successfully C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully ==== Empty FireFox Cache ====================== No FireFox Profiles found ==== Empty Chrome Cache ====================== C:\Users\Gunther\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully ==== Empty All Flash Cache ====================== Flash Cache Emptied Successfully ==== Empty All Java Cache ====================== Java Cache cleared successfully ==== C:\zoek_backup content ====================== C:\zoek_backup (files=9559 folders=197 462609366 bytes) ==== Empty Temp Folders ====================== C:\Users\Default\AppData\Local\Temp emptied successfully C:\Users\Default User\AppData\Local\Temp emptied successfully C:\Users\Gunther\AppData\Local\Temp will be emptied at reboot C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully C:\Windows\Temp will be emptied at reboot ==== After Reboot ====================== ==== Empty Temp Folders ====================== C:\Windows\Temp successfully emptied C:\Users\Gunther\AppData\Local\Temp successfully emptied ==== Empty Recycle Bin ====================== C:\$RECYCLE.BIN successfully emptied ==== Deleting Files / Folders ====================== "C:\Users\Gunther\AppData\Local\Pokki\analytics.db" not found "C:\Users\Gunther\AppData\Local\Pokki\engine_update.db" not found "C:\Users\Gunther\AppData\Local\Pokki\analytics.db" not found "C:\Users\Gunther\AppData\Local\Pokki\engine_update.db" not found "C:\Users\Gunther\AppData\Local\Pokki" not found "C:\Users\Gunther\AppData\Local\Pokki" not found ==== EOF on wo 23/09/2015 at 0:28:28,03 ======================