Zoek.exe v5.0.0.1 Updated 18-October-2015 Tool run by Timur on di 20/10/2015 at 12:45:18,25. Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x64 Running in: Normal Mode Internet Access Detected Launched: C:\Users\Timur\Desktop\zoek.exe [Scan all users] [Script inserted] [Checkboxes used] ==== Older Logs ====================== C:\zoek-results2014-12-25-184247.log 40928 bytes C:\zoek-results2015-10-20-090351.log 1260 bytes C:\zoek-results2015-10-20-093144.log 938 bytes ==== Torpig Check ====================== HKEY_CLASSES_ROOT\Directory\shellex\CopyHookHandlers\FileSystem {217FC9C0-3AEA-1069-A2DB-08002B30309D} %SystemRoot%\system32\shell32.dll HKEY_CLASSES_ROOT\Directory\shellex\CopyHookHandlers\FileZilla3CopyHook {DB70412E-EEC9-479C-BBA9-BE36BFDDA41B} C:\Program Files\FileZilla FTP Client\fzshellext_64.dll HKEY_CLASSES_ROOT\Directory\shellex\CopyHookHandlers\Sharing {40dd6e20-7c17-11ce-a804-00aa003ca9f6} %SystemRoot%\system32\ntshrui.dll ==== Deleting CLSID Registry Keys ====================== HKEY_USERS\S-1-5-21-4130941160-3806457408-160441287-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F4E39681-15F8-4fda-B8A3-B5C98378F2F3} deleted successfully ==== Deleting CLSID Registry Values ====================== ==== Installed Programs ====================== Tools for .Net 3.5 ???? ???? ????? ???? Windows Live ????? Windows Live ?????? ??????? ???????? ?????????? Windows Live ?????????? ?????????? (????????????? ??????) Adobe AIR Adobe Community Help Adobe Download Assistant Adobe Flash Player 19 ActiveX Adobe Flash Player 19 NPAPI Adobe Shockwave Player 12.0 Alcor Micro USB Card Reader Apple Application Support Apple Mobile Device Support Apple Software Update Application Insights Tools for Visual Studio 2015 Arma 3 ASIO4ALL ASUS AI Recovery ASUS FancyStart ASUS LifeFrame3 ASUS Live Update ASUS Power4Gear Hybrid ASUS SmartLogon ASUS Splendid Video Enhancement Technology ASUS Virtual Camera ASUS WebStorage AsusScr_K3 Series_ENG_Basic AsusVibe2.0 ATK Package Avast Free Antivirus Azure AD Authentication Connected Service AzureTools.Notifications Battle.net BattlEye Uninstall Bing Bar Blend for Visual Studio SDK for .NET 4.5 Bonjour Bookworm Deluxe CCleaner Cisco EAP-FAST Module Cisco LEAP Module Cisco Packet Tracer 6.2 Student Cisco PEAP Module Command & ConquerT Red Alert 2 and Yuri's Revenge Command & ConquerT: Generals and Zero Hour Cooking Dash Counter-Strike: Global Offensive Counter-Strike: Source CyberLink LabelPrint CyberLink Power2Go D3DX10 DAEMON Tools Lite Dotfuscator and Analytics Community Edition 5.18.1 Dual-Core Optimizer EAX4 Unified Redist Emsisoft Anti-Malware Entity Framework 6.1.3 Tools for Visual Studio 2015 ESN Sonar ETDWare PS/2-X64 8.0.5.0_WHQL Factorio version 0.11.22 Fast Boot FileZilla Client 3.14.0 FL Studio 9 Fotogalerie Galeria de Fotografias Galerˇa de fotos Galerie de photos Game Park Console GIMP 2.6.11 Google Chrome Google Talk Plugin Google Toolbar for Internet Explorer Google Update Helper Governor of Poker Hardcore Hotel Dash Suite Success HP OrderReminder IIS 10.0 Express IIS Express Application Compatibility Database for x64 IIS Express Application Compatibility Database for x86 IL Download Manager Intel(R) Control Center Intel(R) Management Engine Components Intel(R) Processor Graphics Intel(R) Turbo Boost Technology Monitor 2.0 iTunes Java 8 Update 60 Java Auto Updater Jewel Quest 3 Junk Mail filter update LaserJet 1018 League of Legends Luxor 3 Mahjongg dimensions Malwarebytes Anti-Malware versie 2.2.0.1024 Microsoft .NET Framework 4 Multi-Targeting Pack Microsoft .NET Framework 4.5 Multi-Targeting Pack Microsoft .NET Framework 4.5.1 Multi-Targeting Pack Microsoft .NET Framework 4.5.1 Multi-Targeting Pack (ENU) Microsoft .NET Framework 4.5.1 RC Multi-Targeting Pack for Windows Store Apps Microsoft .NET Framework 4.5.1 RC Multi-Targeting Pack for Windows Store Apps (ENU) Microsoft .NET Framework 4.5.1 SDK Microsoft .NET Framework 4.5.2 (Nederlands) Microsoft .NET Framework 4.5.2 (NLD) Microsoft .NET Framework 4.5.2 Multi-Targeting Pack Microsoft .NET Framework 4.5.2 Multi-Targeting Pack (ENU) Microsoft .NET Framework 4.6 Microsoft .NET Framework 4.6 SDK Microsoft .NET Framework 4.6 Targeting Pack Microsoft .NET Framework 4.6 Targeting Pack (ENU) Microsoft .NET Version Manager (x64) 1.0.0-beta5 Microsoft Agents for Visual Studio 2015 Preview - ENU Microsoft Agents for Visual Studio 2015 Preview Microsoft Application Error Reporting Microsoft ASP.NET and Web Tools 2015 - Visual Studio 2015 Microsoft ASP.NET Web Frameworks and Tools - Visual Studio 2015 - ENU Microsoft Azure Mobile Services Connected Service Microsoft Azure Mobile Services SDK V2.0 Microsoft Azure Mobile Services Tools for Visual Studio - v1.4 Microsoft Azure Shared Components for Visual Studio 2015 - v1.5 Microsoft Azure Storage Connected Service Microsoft Blend for Visual Studio 2015 - ENU Microsoft Blend for Visual Studio 2015 Microsoft Build Tools 14.0 (amd64) Microsoft Build Tools 14.0 (x86) Microsoft Build Tools Language Resources 14.0 (amd64) Microsoft Build Tools Language Resources 14.0 (x86) Microsoft Chart Controls for Microsoft .NET Framework 3.5 (KB2500170) Microsoft Expression Blend SDK for .NET 4 Microsoft Games for Windows - LIVE Redistributable (PartnerNet) Microsoft Games for Windows Marketplace (Partnernet) Microsoft Help Viewer 2.2 Microsoft NuGet - Visual Studio 2015 Microsoft Office 365 ProPlus - nl-nl Microsoft Office Klik-en-Klaar 2010 Microsoft Office Starter 2010 - Nederlands Microsoft Portable Library Multi-Targeting Pack Microsoft Portable Library Multi-Targeting Pack Language Pack - enu Microsoft PowerPoint Viewer Microsoft Rekenmachine Plus Microsoft Silverlight Microsoft SkyDrive Microsoft SQL Server 2005 Compact Edition [ENU] Microsoft SQL Server 2012 Command Line Utilities Microsoft SQL Server 2012 Native Client Microsoft SQL Server 2014 Management Objects Microsoft SQL Server 2014 Management Objects (x64) Microsoft SQL Server 2014 T-SQL Language Service Microsoft SQL Server 2014 Transact-SQL ScriptDom Microsoft SQL Server Compact 4.0 SP1 x64 ENU Microsoft SQL Server Data Tools - enu (14.0.50616.0) Microsoft System CLR Types for SQL Server 2014 Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2005 Redistributable (x64) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.51106 Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.51106 Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.61030 Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.61030 Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61030 Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61030 Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005 Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.21005 Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.21005 Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.23026 Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.23026 Microsoft Visual C++ 2015 x64 Additional Runtime - 14.0.23026 Microsoft Visual C++ 2015 x64 Minimum Runtime - 14.0.23026 Microsoft Visual C++ 2015 x86 Additional Runtime - 14.0.23026 Microsoft Visual C++ 2015 x86 Minimum Runtime - 14.0.23026 Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - NLD Microsoft Visual Studio 2015 Devenv Microsoft Visual Studio 2015 Devenv Resources Microsoft Visual Studio 2015 Diagnostic Tools - amd64 Microsoft Visual Studio 2015 Diagnostic Tools - x86 Microsoft Visual Studio 2015 Performance Collection Tools - ENU Microsoft Visual Studio 2015 Performance Collection Tools Microsoft Visual Studio 2015 Performance Debugger Web Views Microsoft Visual Studio 2015 Preparation Microsoft Visual Studio 2015 Profiling Tools Microsoft Visual Studio 2015 SDK - ENU Microsoft Visual Studio 2015 Shell (Minimum) Microsoft Visual Studio 2015 Shell (Minimum) Interop Assemblies Microsoft Visual Studio 2015 Shell (Minimum) Resources Microsoft Visual Studio 2015 Team Explorer Language Pack - ENU Microsoft Visual Studio 2015 Test Tools Language Pack - ENU Microsoft Visual Studio 2015 VsGraphics Helper Dependencies Microsoft Visual Studio 2015 Windows Diagnostic Tools - ENU Microsoft Visual Studio 2015 Windows Diagnostic Tools Microsoft Visual Studio 2015 XAML Application Timeline - ENU Microsoft Visual Studio 2015 XAML Application Timeline Microsoft Visual Studio 2015 XAML Designer - ENU Microsoft Visual Studio 2015 XAML Designer Microsoft Visual Studio 2015 XAML Visual Diagnostics - ENU Microsoft Visual Studio 2015 XAML Visual Diagnostics Microsoft Visual Studio Community 2015 - ENU Microsoft Visual Studio Community 2015 Microsoft Visual Studio Connected Services Microsoft Visual Studio Services Hub Microsoft Visual Studio Team Foundation Server 2015 Office Integration (x64) Microsoft Visual Studio Team Foundation Server 2015 Office Integration Language Pack (x64) - ENU Microsoft Visual Studio Team Foundation Server 2015 Storyboarding (x64) Microsoft Visual Studio Team Foundation Server 2015 Storyboarding Language Pack (x64) - ENU Microsoft VisualStudio JavaScript Language Service Microsoft VisualStudio JavaScript Project System Microsoft Web Deploy 3.6 Microsoft XNA Framework Redistributable 4.0 Refresh Microsoft.VisualStudio.Office365 Microsoft_VC80_ATL_x86 Microsoft_VC80_ATL_x86_x64 Microsoft_VC80_CRT_x86 Microsoft_VC80_CRT_x86_x64 Microsoft_VC80_MFC_x86 Microsoft_VC80_MFC_x86_x64 Microsoft_VC80_MFCLOC_x86 Microsoft_VC80_MFCLOC_x86_x64 Microsoft_VC90_ATL_x86 Microsoft_VC90_ATL_x86_x64 Microsoft_VC90_CRT_x86 Microsoft_VC90_CRT_x86_x64 Microsoft_VC90_MFC_x86 Microsoft_VC90_MFC_x86_x64 Microsoft_VC90_MFCLOC_x86 Microsoft_VC90_MFCLOC_x86_x64 Movie Maker Mozilla Firefox 41.0 (x86 nl) Mozilla Maintenance Service MSVCRT MSVCRT_amd64 MSVCRT110 MSVCRT110_amd64 MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) MSXML4 Parser Multi-Device Hybrid Apps using C# - Templates - ENU My Game Long Name Notepad++ Nuance PDF Reader NVIDIA-configuratiescherm 320.49 NVIDIA 3D Vision stuurprogramma 320.49 NVIDIA GeForce Experience 1.5 NVIDIA Grafisch stuurprogramma 320.49 NVIDIA Install Application NVIDIA Optimus 4.11.9 NVIDIA PhysX NVIDIA Stereoscopic 3D Driver NVIDIA Update 4.11.9 NVIDIA Update Components Office 15 Click-to-Run Extensibility Component Office 15 Click-to-Run Licensing Component Office 15 Click-to-Run Localization Component OldSchool RuneScape Launcher 1.2.7 OpenAL OpenOffice.org 3.4.1 Oracle VM VirtualBox 5.0.6 Origin Photo Common Photo Gallery Plants vs Zombies PoiZone PreEmptive Analytics Visual Studio Components Prerequisites for SSDT Raccolta foto Ralink RT2860 Wireless LAN Card Realtek High Definition Audio Driver Roll Roslyn Language Services - x86 S?????? f?t???af??? Samsung Mobile phone USB driver Drive Software Samsung PC Studio 3 Sawer Security Update for Microsoft .NET Framework 4.6 (KB3074233) Security Update for Microsoft .NET Framework 4.6 (KB3074554) Security Update for Microsoft .NET Framework 4.6 (KB3083186) Skype Click to Call SkypeT 7.12 Sony Mobile Update Engine Sony PC Companion 2.10.236 SopCast 3.4.0 Spotify Square Enix Secure Launcher Steam swMSM syncables desktop SE System Requirements Lab System Requirements Lab CYRI Taalpakket voor Microsoft Visual Studio 2010 Tools for Office Runtime (x64) - NLD Team Explorer for Microsoft Visual Studio 2015 TeamSpeak 3 Client Test Tools for Microsoft Visual Studio 2015 Toxic Biohazard TypeScript Power Tool TypeScript Tools for Microsoft Visual Studio 2015 TypeScript Tools for Microsoft Visual Studio 2015 1.6.3.0 Ubisoft Game Launcher Update for (KB2504637) Update voor het stuurprogramma voor Windows Mobile Apparaatcentrum USB Multi-Channel Audio Device USB PnP Sound Device Visual C++ Compiler/Tools X86 Base Package Visual C++ Compiler/Tools X86 Base Resource Package Visual C++ IDE Base Package Visual C++ IDE Base Resource Package Visual C++ IDE Common Package Visual C++ IDE Common Resource Package Visual C++ IDE Core Professional Plus Resource Package Visual C++ IDE Debugger Package Visual C++ IDE Debugger Resource Package Visual C++ IDE Professional Core Package Visual C++ IDE x64 Package Visual C++ Library PGO X86 Package Visual C++ MSBuild ARM Package Visual C++ MSBuild Base Package Visual C++ MSBuild Base Resource Package Visual C++ MSBuild X64 Package Visual C++ MSBuild X86 Package Visual Studio 2008 x64 Redistributables Visual Studio 2010 x64 Redistributables Visual Studio 2012 x64 Redistributables Visual Studio 2012 x86 Redistributables Visual Studio 2015 Prerequisites - ENU Language Pack Visual Studio 2015 Prerequisites VisualRoute Lite Edition VLC media player WCF Data Services 5.6.4 Runtime WCF Data Services Tools for Microsoft Visual Studio 2015 WestwoodOnline Windows Espc Package Windows Espc Resource Package Windows Live ??? Windows Live Communications Platform Windows Live Essentials Windows Live Family Safety Windows Live ID Sign-in Assistant Windows Live Installer Windows Live Mail Windows Live Messenger Windows Live MIME IFilter Windows Live Photo Common Windows Live PIMT Platform Windows Live SOXE Windows Live SOXE Definitions Windows Live UX Platform Windows Live UX Platform Language Pack Windows Live Writer Windows Live Writer Resources Windows Media Player Firefox Plugin Windows Phone SDK 8.0 Assemblies for Visual Studio 2015 Windows Software Development Kit DirectX x64 Remote Windows Software Development Kit DirectX x86 Remote Windows Software Development Kit for Windows Store Apps DirectX x64 Remote Windows Software Development Kit for Windows Store Apps DirectX x86 Remote WinFlash WinPcap 4.1.3 WinRAR 5.01 (64-bit) Wireless Console 3 Wireshark 1.12.8 (64-bit) World of Goo ==== Deleting Services ====================== ==== Deleting Files \ Folders ====================== C:\PROGRA~2\Reg Organizer deleted C:\Users\Timur\AppData\Roaming\Factorio deleted C:\Users\Timur\AppData\Roaming\Natural Selection 2 deleted C:\PROGRA~3\{93E26451-CD9A-43A5-A2FA-C42392EA4001} deleted C:\PROGRA~3\Package Cache deleted C:\Users\Timur\AppData\Local\CrashRpt deleted C:\Users\Timur\AppData\LocalLow\Unity deleted C:\Windows\SysNative\config\systemprofile\Searches deleted C:\Windows\Syswow64\shoB116.tmp deleted C:\Windows\Syswow64\shoBF80.tmp deleted C:\Windows\Syswow64\shoDF33.tmp deleted C:\Windows\Syswow64\shoEAC6.tmp deleted C:\Windows\Syswow64\shoEB4C.tmp deleted ==== Files Recently Created / Modified ====================== ====== C:\Windows ==== 2015-09-29 10:43:10 F0ECBDA4D2FD129FF15C299AF8462FC8 43112 ----a-w- C:\Windows\avastSS.scr ====== C:\Users\Timur\AppData\Local\Temp ==== 2015-10-13 21:22:43 8311AE1208CD677AF5B6AB500A3496D3 1514984 ----a-w- C:\Users\Timur\AppData\Local\Temp\teamspeak_temp_0\update.exe 2015-10-13 21:22:43 3A59536B9461CE1C955658DF973130FB 1166336 ----a-w- C:\Users\Timur\AppData\Local\Temp\teamspeak_temp_0\platforms\qwindows.dll 2015-10-13 21:22:42 E08963774FD3A9403BD8BE34C05E6F0E 30208 ----a-w- C:\Users\Timur\AppData\Local\Temp\teamspeak_temp_0\imageformats\qgif.dll 2015-10-13 21:22:42 C7B5B9314AFE9FB50076D49BD44D4460 5626368 ----a-w- C:\Users\Timur\AppData\Local\Temp\teamspeak_temp_0\Qt5Core.dll 2015-10-13 21:22:42 BBA429E6087B652FAFE6D6C673AB50B7 1092608 ----a-w- C:\Users\Timur\AppData\Local\Temp\teamspeak_temp_0\Qt5Network.dll 2015-10-13 21:22:42 9818BB0BCFDD55A31EB52E9C52B50C21 3937280 ----a-w- C:\Users\Timur\AppData\Local\Temp\teamspeak_temp_0\Qt5Gui.dll 2015-10-13 21:22:42 3B5AA8BF764882791C4ABD5EB8331206 236544 ----a-w- C:\Users\Timur\AppData\Local\Temp\teamspeak_temp_0\imageformats\qjpeg.dll 2015-10-13 21:22:42 0CF36C778EB3E5C0C27F6C37A4B2279C 5424128 ----a-w- C:\Users\Timur\AppData\Local\Temp\teamspeak_temp_0\Qt5Widgets.dll ====== Java Cache ===== 2015-10-20 08:51:32 27266DB268940A58180604BA1A7BE3E0 450735 ----a-w- C:\Users\Timur\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\36\6f20baa4-5e652554 2015-10-20 08:51:32 C611538EFED63F122E4A07F748AC01B3 793 ----a-w- C:\Users\Timur\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\61\11dd5f3d-71b6fcd8 2015-10-20 08:51:32 5E83478FCDE87DC0CDE2E57BA4D2122E 100 ----a-w- C:\Users\Timur\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\61\11dd5f3d-866ea8a9a5e54c718f59857e9fb20e99af8e0c6c1540667a6358a78f78af6bf9-6.0.lap ====== C:\Windows\SysWOW64 ===== 2015-10-14 13:29:05 F811B932E3DBA308014F8C870F752F16 12875776 ----a-w- C:\Windows\SysWOW64\shell32.dll 2015-10-14 13:29:04 5CB2886338C82E388F68557E2745200F 1498624 ----a-w- C:\Windows\SysWOW64\ExplorerFrame.dll 2015-10-14 13:28:55 908BBA41A5B57DDB126B85EC14DD58EF 76288 ----a-w- C:\Windows\SysWOW64\mshtmled.dll 2015-10-14 13:28:55 0E036A353DB9D8F4F642AC0F9412F09E 47616 ----a-w- C:\Windows\SysWOW64\ieetwproxystub.dll 2015-10-14 13:28:54 D586CB95B4EADC0525E8929A241898F5 20357632 ----a-w- C:\Windows\SysWOW64\mshtml.dll 2015-10-14 13:28:54 C89372B642726F1CF3EB479397976DA3 279040 ----a-w- C:\Windows\SysWOW64\dxtrans.dll 2015-10-14 13:28:54 C848E013BB85C48C787001E1EA36905F 60416 ----a-w- C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2015-10-14 13:28:54 A7028D5D5E3DCF820B3C0AFE0137A87E 130048 ----a-w- C:\Windows\SysWOW64\occache.dll 2015-10-14 13:28:54 9F36964CDB9A920779314395E3911503 504832 ----a-w- C:\Windows\SysWOW64\vbscript.dll 2015-10-14 13:28:54 098F6097F919EE77EA490E16D11E427A 1311232 ----a-w- C:\Windows\SysWOW64\urlmon.dll 2015-10-14 13:28:54 060409834CC8FAC3F1231DA3F0648CC5 689152 ----a-w- C:\Windows\SysWOW64\msfeeds.dll 2015-10-14 13:28:54 04BB7AF8E0DAE83982155F0752308666 64000 ----a-w- C:\Windows\SysWOW64\MshtmlDac.dll 2015-10-14 13:28:54 00FBEDF0E74AD8815469A95271C0E562 345688 ----a-w- C:\Windows\SysWOW64\iedkcs32.dll 2015-10-14 13:28:53 B87A11C95703AB19ACB43993DDA0F1A3 62464 ----a-w- C:\Windows\SysWOW64\iesetup.dll 2015-10-14 13:28:53 9F4234838400CC3A964AF53DE4410A50 2279936 ----a-w- C:\Windows\SysWOW64\iertutil.dll 2015-10-14 13:28:53 816B489E2BBFE2479C844AAD486ABB42 2052608 ----a-w- C:\Windows\SysWOW64\inetcpl.cpl 2015-10-14 13:28:53 7E8EABA6A2B10FE11E2381378A57322B 2724864 ----a-w- C:\Windows\SysWOW64\mshtml.tlb 2015-10-14 13:28:53 12DCE9300FF5B74DC2F7DBAC96B0614E 710144 ----a-w- C:\Windows\SysWOW64\ieapfltr.dll 2015-10-14 13:28:52 F274AF14C7DB6C52C023BCBDA4197D17 47104 ----a-w- C:\Windows\SysWOW64\jsproxy.dll 2015-10-14 13:28:52 AFC4F34507B555D1C9C4F049CCA1475F 416256 ----a-w- C:\Windows\SysWOW64\dxtmsft.dll 2015-10-14 13:28:52 8C9BCE16E894D4FBCE151F4A5FE05F55 30720 ----a-w- C:\Windows\SysWOW64\iernonce.dll 2015-10-14 13:28:52 73189A2739491ABB556872737C501F8E 663552 ----a-w- C:\Windows\SysWOW64\jscript.dll 2015-10-14 13:28:52 584E6632F1F4027AB64DEB0F4139E7D7 620032 ----a-w- C:\Windows\SysWOW64\jscript9diag.dll 2015-10-14 13:28:52 4A3CA2C73C4D66A90C63E9E532746020 480256 ----a-w- C:\Windows\SysWOW64\ieui.dll 2015-10-14 13:28:50 BE1263EE0CB8CF942FC35CC86E0C3941 12853760 ----a-w- C:\Windows\SysWOW64\ieframe.dll 2015-10-14 13:28:48 E401E66CCB2AE219CF41F7F901C410C1 2011136 ----a-w- C:\Windows\SysWOW64\wininet.dll 2015-10-14 13:28:48 DE53F76D63CA64E172B336BC7CFF6EDA 4527616 ----a-w- C:\Windows\SysWOW64\jscript9.dll 2015-10-14 13:28:48 CEDBC9DBD9800E0EE81B0840EBC2BAC5 1155072 ----a-w- C:\Windows\SysWOW64\mshtmlmedia.dll 2015-10-14 13:28:48 A7012A7032207D1C16B7236EDF91F4BB 168960 ----a-w- C:\Windows\SysWOW64\msrating.dll 2015-10-14 13:28:48 A25C9DD040CA9799C2A7E41732D0752A 230400 ----a-w- C:\Windows\SysWOW64\webcheck.dll 2015-10-14 13:28:48 5EE17D52CAF79663211C01C614594620 341504 ----a-w- C:\Windows\SysWOW64\html.iec 2015-10-14 13:28:48 17B66052348D3A3681A9411EDD839E18 115712 ----a-w- C:\Windows\SysWOW64\ieUnatt.exe 2015-10-14 13:28:30 DDCABBADA6116E8E3472D93FDF56FE66 93696 ----a-w- C:\Windows\SysWOW64\wudriver.dll 2015-10-14 13:28:30 C4240CA64E6B3523110DE3CAF4066F07 566784 ----a-w- C:\Windows\SysWOW64\wuapi.dll 2015-10-14 13:28:30 7902FB8C129A6DCAA9E0002BD3600F00 35328 ----a-w- C:\Windows\SysWOW64\wuapp.exe 2015-10-14 13:28:30 6CE7ACA0022C27A3FAECB600E097F81B 30208 ----a-w- C:\Windows\SysWOW64\wups.dll 2015-10-14 13:28:30 693F6EC2312B8B3F57B7277B069B91A3 174080 ----a-w- C:\Windows\SysWOW64\wuwebv.dll 2015-10-14 13:28:14 C19537A50B723E0F7B53D413163B35EE 3936192 ----a-w- C:\Windows\SysWOW64\ntoskrnl.exe 2015-10-14 13:28:13 63FD03CED9739062E9B94F0D1E54A406 3990976 ----a-w- C:\Windows\SysWOW64\ntkrnlpa.exe 2015-10-14 13:28:09 9E83A4F6E776F7A3E5F7FB90180FBC0B 1114112 ----a-w- C:\Windows\SysWOW64\kernel32.dll 2015-10-14 13:28:08 CA504606753BD62FA3128D3056320264 552960 ----a-w- C:\Windows\SysWOW64\kerberos.dll 2015-10-14 13:28:07 D8269205300BB593C3698BB77178E8D3 17408 ----a-w- C:\Windows\SysWOW64\credssp.dll 2015-10-14 13:28:07 C7293C9340BDC8291F6718913F3F7B14 221184 ----a-w- C:\Windows\SysWOW64\ncrypt.dll 2015-10-14 13:28:07 C00E4CD3AC3A0D8E339635E06546B77D 50176 ----a-w- C:\Windows\SysWOW64\auditpol.exe 2015-10-14 13:28:07 8A4ED460B6557EDCA637236073794DFF 43008 ----a-w- C:\Windows\SysWOW64\srclient.dll 2015-10-14 13:28:07 6D16D1B9DB2526B985BBB9B27A56B70B 172032 ----a-w- C:\Windows\SysWOW64\wdigest.dll 2015-10-14 13:28:07 5FC0F48FD38D0AC7FC54EBEFBC3F69C5 25600 ----a-w- C:\Windows\SysWOW64\setup16.exe 2015-10-14 13:28:07 4EB6A0445891D56D56BB4580B3906BEA 1311768 ----a-w- C:\Windows\SysWOW64\ntdll.dll 2015-10-14 13:28:07 3FA49981A847AE62259E6AEB585C84B8 65536 ----a-w- C:\Windows\SysWOW64\TSpkg.dll 2015-10-14 13:28:07 2464CEAC16185B73774662AC625F695D 22016 ----a-w- C:\Windows\SysWOW64\secur32.dll 2015-10-14 13:28:07 2421C989BF8485B6A9EBBAC35ACADF1D 665088 ----a-w- C:\Windows\SysWOW64\rpcrt4.dll 2015-10-14 13:28:07 22BF275468F714A4F7E6F36449D1DCE2 259584 ----a-w- C:\Windows\SysWOW64\msv1_0.dll 2015-10-14 13:28:07 1ADCC4F94981430FE968EE992353C535 14336 ----a-w- C:\Windows\SysWOW64\ntvdm64.dll 2015-10-14 13:28:07 15192FC6BFCB37AE43A645A9C84AEF2F 36864 ----a-w- C:\Windows\SysWOW64\cryptbase.dll 2015-10-14 13:28:07 0834E70A068360D85CDC47697A4B7898 248832 ----a-w- C:\Windows\SysWOW64\schannel.dll 2015-10-14 13:28:06 D9F5F78F8EA5749CA651B71335A96421 5120 ----a-w- C:\Windows\SysWOW64\wow32.dll 2015-10-14 13:28:06 C142CBB756205146B88DDB66D00BFE66 274944 ----a-w- C:\Windows\SysWOW64\KernelBase.dll 2015-10-14 13:28:06 6848FA8B421A0CEC8990AFE7A615574F 96768 ----a-w- C:\Windows\SysWOW64\sspicli.dll 2015-10-14 13:28:05 B421B311420FD650BE3B25EAC217E685 7680 ----a-w- C:\Windows\SysWOW64\instnm.exe 2015-10-14 13:28:05 1BE5DF925C30D9D1FAD1212FB215E469 6656 ----a-w- C:\Windows\SysWOW64\apisetschema.dll 2015-10-14 13:28:04 FE7B23203C757148CBCCA0A39EAD3C59 60416 ----a-w- C:\Windows\SysWOW64\msobjs.dll 2015-10-14 13:28:04 D414A645F6853BB2C8A24B85C1C86581 686080 ----a-w- C:\Windows\SysWOW64\adtschema.dll 2015-10-14 13:28:04 64B92847AA0945992BB49B62D9B0440E 146432 ----a-w- C:\Windows\SysWOW64\msaudite.dll 2015-10-14 13:28:04 09BA6677E9CCBB1884CD0FB24F6EF584 2048 ----a-w- C:\Windows\SysWOW64\user.exe 2015-10-14 13:27:44 0D0FF2A38473552DDFF4F21756700F9B 50688 ----a-w- C:\Windows\SysWOW64\appidapi.dll 2015-10-14 13:27:02 CBF3CFC9EE1FD29707D95C63A5E7A78B 19808 ----a-w- C:\Windows\SysWOW64\api-ms-win-crt-multibyte-l1-1-0.dll 2015-10-14 13:27:02 C1096DA4634AD3356A10C00B24F53393 22368 ----a-w- C:\Windows\SysWOW64\api-ms-win-crt-math-l1-1-0.dll 2015-10-14 13:27:02 B23936CF83DAC4B64660A88711B5234A 12128 ----a-w- C:\Windows\SysWOW64\api-ms-win-crt-locale-l1-1-0.dll 2015-10-14 13:27:02 9F9FE5F52E9B2AD655C896B849883B1A 12128 ----a-w- C:\Windows\SysWOW64\api-ms-win-crt-utility-l1-1-0.dll 2015-10-14 13:27:02 9D66FCC681389EC619D4E801F1DDBB2F 17760 ----a-w- C:\Windows\SysWOW64\api-ms-win-crt-stdio-l1-1-0.dll 2015-10-14 13:27:02 94FEB4417CF3E39C8C58A1B73620687E 66400 ----a-w- C:\Windows\SysWOW64\api-ms-win-crt-private-l1-1-0.dll 2015-10-14 13:27:02 8E534F49C77D787DB69BABFF931A497A 12640 ----a-w- C:\Windows\SysWOW64\api-ms-win-crt-conio-l1-1-0.dll 2015-10-14 13:27:02 85CEBA9A21CE5D51B35EF2DE9EBFBAC4 12128 ----a-w- C:\Windows\SysWOW64\api-ms-win-crt-environment-l1-1-0.dll 2015-10-14 13:27:02 80BEB858D2EEE9CA657647B599E5D844 11616 ----a-w- C:\Windows\SysWOW64\api-ms-win-eventing-provider-l1-1-0.dll 2015-10-14 13:27:02 73CED8B30963E54D262DAE2559116E46 13664 ----a-w- C:\Windows\SysWOW64\api-ms-win-crt-filesystem-l1-1-0.dll 2015-10-14 13:27:02 6C7F782FDBF9AEFFE7663FA1579A610E 17760 ----a-w- C:\Windows\SysWOW64\api-ms-win-crt-string-l1-1-0.dll 2015-10-14 13:27:02 4669249FB01EA369C7FD40A530966FA1 12640 ----a-w- C:\Windows\SysWOW64\api-ms-win-crt-heap-l1-1-0.dll 2015-10-14 13:27:02 408019E57D3D2DA62A9F28389EED0AC1 16224 ----a-w- C:\Windows\SysWOW64\api-ms-win-crt-runtime-l1-1-0.dll 2015-10-14 13:27:02 39F9D0F1B698D53D78C79576C7C60526 14176 ----a-w- C:\Windows\SysWOW64\api-ms-win-crt-time-l1-1-0.dll 2015-10-14 13:27:02 33E8CCBE05123C8146CD16293B688417 15712 ----a-w- C:\Windows\SysWOW64\api-ms-win-crt-convert-l1-1-0.dll 2015-10-14 13:27:02 00A0A24BB2E9AADE11494B627EB164C4 12640 ----a-w- C:\Windows\SysWOW64\api-ms-win-crt-process-l1-1-0.dll 2015-10-14 13:27:01 5B55E9A1360A6C52CC988DA6804D6CA2 901264 ----a-w- C:\Windows\SysWOW64\ucrtbase.dll ====== C:\Windows\SysWOW64\drivers ===== ====== C:\Windows\Sysnative ===== 2015-10-19 20:39:20 FB100F653D86106DB081A342AA685ECD 5036680 ----a-w- C:\Windows\Sysnative\FNTCACHE.DAT 2015-10-15 10:42:27 F03EA93F045D009830C890010750B34A 25432 ----a-w- C:\Windows\Sysnative\CompatTelRunner.exe 2015-10-15 10:42:27 AFE7905DD772DEA54B9C443C6634740A 700416 ----a-w- C:\Windows\Sysnative\invagent.dll 2015-10-15 10:42:27 9F780E22C79AACBF3A93F6ACDE2A4E0A 766464 ----a-w- C:\Windows\Sysnative\generaltel.dll 2015-10-15 10:42:27 952D66DCA6CB744381B7298F8AAE994F 73216 ----a-w- C:\Windows\Sysnative\acmigration.dll 2015-10-15 10:42:27 21C89857E5671990BBF2B430BD75B9C9 1291264 ----a-w- C:\Windows\Sysnative\appraiser.dll 2015-10-15 10:42:27 1AC3E0E57844764B0CA6D2BF0F76C773 503808 ----a-w- C:\Windows\Sysnative\devinv.dll 2015-10-15 10:42:27 14A5CC0EE60278D483A88124B88F3524 1163776 ----a-w- C:\Windows\Sysnative\aeinv.dll 2015-10-14 13:29:06 885B08E5EC912D2680F533094B87770D 14176768 ----a-w- C:\Windows\Sysnative\shell32.dll 2015-10-14 13:29:05 0F08BB62CD162883E9A3004BBE7914BD 1866752 ----a-w- C:\Windows\Sysnative\ExplorerFrame.dll 2015-10-14 13:28:55 9AEE2A881FD10E6A463588303D8027AD 114688 ----a-w- C:\Windows\Sysnative\ieetwcollector.exe 2015-10-14 13:28:55 3A0773E21355B41176ACAD8BB099D9B3 48640 ----a-w- C:\Windows\Sysnative\ieetwproxystub.dll 2015-10-14 13:28:54 BF8A5B4E696F4E8F3B2B5E9902467418 720896 ----a-w- C:\Windows\Sysnative\ie4uinit.exe 2015-10-14 13:28:54 9E0D0522908C1106E0D77708CB9926FE 34304 ----a-w- C:\Windows\Sysnative\iernonce.dll 2015-10-14 13:28:54 80E9DF296F127B3BC965EBC5A2C8F044 2724864 ----a-w- C:\Windows\Sysnative\mshtml.tlb 2015-10-14 13:28:54 521E1A87D4F750FD9694DBF3AB37B38F 77824 ----a-w- C:\Windows\Sysnative\JavaScriptCollectionAgent.dll 2015-10-14 13:28:53 8A2A46DD0C51E5D2D0A2EF2AA289DA4D 1546752 ----a-w- C:\Windows\Sysnative\urlmon.dll 2015-10-14 13:28:53 4AEB3F2FB0CC23A18ED997F6C0476819 391784 ----a-w- C:\Windows\Sysnative\iedkcs32.dll 2015-10-14 13:28:53 3295B811A0260C0A5B346ECB73C5FCF0 152064 ----a-w- C:\Windows\Sysnative\occache.dll 2015-10-14 13:28:52 D661A17B4634171C58373699CBD6455B 315392 ----a-w- C:\Windows\Sysnative\dxtrans.dll 2015-10-14 13:28:52 2A898891EB7FBCF0774F0B96AAD05561 968704 ----a-w- C:\Windows\Sysnative\MsSpellCheckingFacility.exe 2015-10-14 13:28:52 12C1DECE9502828C0A5ADB50AB1673A0 4096 ----a-w- C:\Windows\Sysnative\ieetwcollectorres.dll 2015-10-14 13:28:51 6E1EEB1CE2F9F3AB14A9E8A6B1E82455 801280 ----a-w- C:\Windows\Sysnative\msfeeds.dll 2015-10-14 13:28:50 F6F91F217D760981017E4AA4F1C7E633 66560 ----a-w- C:\Windows\Sysnative\iesetup.dll 2015-10-14 13:28:50 0FA614470B3A78FC5B8F3F3F742B9837 800768 ----a-w- C:\Windows\Sysnative\ieapfltr.dll 2015-10-14 13:28:49 E91FD3ACC10C971CBA991FCD058ABB58 2886656 ----a-w- C:\Windows\Sysnative\iertutil.dll 2015-10-14 13:28:49 7C3050383491011FEDD40961A37A2D99 2126336 ----a-w- C:\Windows\Sysnative\inetcpl.cpl 2015-10-14 13:28:48 A865136AC6436533E0A4A3C67F259401 585728 ----a-w- C:\Windows\Sysnative\vbscript.dll 2015-10-14 13:28:48 84C63F3D2D488A918A947E06BD1105EF 54784 ----a-w- C:\Windows\Sysnative\jsproxy.dll 2015-10-14 13:28:47 88D3F690043A1AA43F33DEC6DDA82178 616960 ----a-w- C:\Windows\Sysnative\ieui.dll 2015-10-14 13:28:47 45A56A2CC2D6A4B649B7DC3B5DF259FF 489984 ----a-w- C:\Windows\Sysnative\dxtmsft.dll 2015-10-14 13:28:45 BC92D9D88959542FBAF1F8CF21F86B38 14458368 ----a-w- C:\Windows\Sysnative\ieframe.dll 2015-10-14 13:28:43 B0917E6238C1675E48CFE64947DD9FD9 144384 ----a-w- C:\Windows\Sysnative\ieUnatt.exe 2015-10-14 13:28:43 5175A9C2C71D49394424C07CA856B803 1359360 ----a-w- C:\Windows\Sysnative\mshtmlmedia.dll 2015-10-14 13:28:43 4A9FFAC9325EFFDEFD7E8C0830B0ABEC 92160 ----a-w- C:\Windows\Sysnative\mshtmled.dll 2015-10-14 13:28:43 454669BB12162610D93954BCC942A41C 817664 ----a-w- C:\Windows\Sysnative\jscript.dll 2015-10-14 13:28:43 373B3EFBBF1A2706F8660C4DE4202694 262144 ----a-w- C:\Windows\Sysnative\webcheck.dll 2015-10-14 13:28:43 1DE918244ED8AB9D3F2C4B9A1F91A24D 814080 ----a-w- C:\Windows\Sysnative\jscript9diag.dll 2015-10-14 13:28:42 E36C7069B9C56DF9A53DD4FA5DCDDE72 5990912 ----a-w- C:\Windows\Sysnative\jscript9.dll 2015-10-14 13:28:41 BEA081F4F2D507D6461B142AB11995B3 199680 ----a-w- C:\Windows\Sysnative\msrating.dll 2015-10-14 13:28:41 BD06D875FB79E92DAF724C91DE743AFA 2487808 ----a-w- C:\Windows\Sysnative\wininet.dll 2015-10-14 13:28:41 58DD42AC31D1F86D303BAAF5955A59BA 417792 ----a-w- C:\Windows\Sysnative\html.iec 2015-10-14 13:28:41 0783994A921469A6E97F3117AA0934DD 88064 ----a-w- C:\Windows\Sysnative\MshtmlDac.dll 2015-10-14 13:28:40 99BA96F5AC545D857E662A9FC576D919 25851904 ----a-w- C:\Windows\Sysnative\mshtml.dll 2015-10-14 13:28:32 291778E1A36716182AFBC1731B2DFEAB 2607104 ----a-w- C:\Windows\Sysnative\wuaueng.dll 2015-10-14 13:28:31 2FFBB9A44A8BA9CBC9589C31E0A36605 3168768 ----a-w- C:\Windows\Sysnative\wucltux.dll 2015-10-14 13:28:30 ECB1C858D9989C4F19FDCE3B7F8BA1F7 696320 ----a-w- C:\Windows\Sysnative\wuapi.dll 2015-10-14 13:28:30 DA4450EE180CBDFB800FB230978BBC58 98816 ----a-w- C:\Windows\Sysnative\wudriver.dll 2015-10-14 13:28:30 C64C6AA9F061E89AE6CA1B484AC3F94E 192512 ----a-w- C:\Windows\Sysnative\wuwebv.dll 2015-10-14 13:28:30 B322CE702FA01DA60876BC5D417B15FE 36864 ----a-w- C:\Windows\Sysnative\wups.dll 2015-10-14 13:28:30 96983751026F0940CAEEB15901B49FF2 37888 ----a-w- C:\Windows\Sysnative\wuapp.exe 2015-10-14 13:28:30 7A2E35CA7131819A8CCE1FA1368D7813 37888 ----a-w- C:\Windows\Sysnative\wups2.dll 2015-10-14 13:28:30 74F288D562E78E1062D4AA2A6C3AB74C 12288 ----a-w- C:\Windows\Sysnative\wu.upgrade.ps.dll 2015-10-14 13:28:30 64B432FB351118B222A5342A7A461696 140288 ----a-w- C:\Windows\Sysnative\wuauclt.exe 2015-10-14 13:28:30 5F1A7C984117F478F7411BDD98411B58 91136 ----a-w- C:\Windows\Sysnative\WinSetupUI.dll 2015-10-14 13:28:17 3FE5671328B8A655F766D872D12DC373 5569472 ----a-w- C:\Windows\Sysnative\ntoskrnl.exe 2015-10-14 13:28:10 11C18D613F66CB5CE829B821599ED339 1164800 ----a-w- C:\Windows\Sysnative\kernel32.dll 2015-10-14 13:28:09 CD349AD99C801523B55030AC234CC1EF 243712 ----a-w- C:\Windows\Sysnative\wow64.dll 2015-10-14 13:28:09 A06A96A26FE0BE22B08B641362296B68 424960 ----a-w- C:\Windows\Sysnative\KernelBase.dll 2015-10-14 13:28:09 91DDAFAFCEC3E360881FE35AF06B9EE4 1730496 ----a-w- C:\Windows\Sysnative\ntdll.dll 2015-10-14 13:28:09 6C190505923A971F0474F8BA8DA50789 1461760 ----a-w- C:\Windows\Sysnative\lsasrv.dll 2015-10-14 13:28:08 F337ACC4CF6B9DFBE46D9A7E54E10756 503808 ----a-w- C:\Windows\Sysnative\srcore.dll 2015-10-14 13:28:08 5401C9D2F4B0A98B60259C621DDF1EB6 338432 ----a-w- C:\Windows\Sysnative\conhost.exe 2015-10-14 13:28:08 4AD1C61152A0199E3D7F9A82C07AC629 215040 ----a-w- C:\Windows\Sysnative\winsrv.dll 2015-10-14 13:28:08 338FD40323ADD43B5C94B4A6CB91874B 1216512 ----a-w- C:\Windows\Sysnative\rpcrt4.dll 2015-10-14 13:28:07 FCFE939A325054DFC69E1D8C58751A62 13312 ----a-w- C:\Windows\Sysnative\wow64cpu.dll 2015-10-14 13:28:07 EE035334B7A58C7F748C3D0394574A35 342016 ----a-w- C:\Windows\Sysnative\schannel.dll 2015-10-14 13:28:07 E9CCB68290F27837A3D7058FEB51F7A8 136192 ----a-w- C:\Windows\Sysnative\sspicli.dll 2015-10-14 13:28:07 E91002F7EC3A9BF7F62BF1E215A32451 362496 ----a-w- C:\Windows\Sysnative\wow64win.dll 2015-10-14 13:28:07 E43F36D0B4C674FEA2C992564A3E0F28 210944 ----a-w- C:\Windows\Sysnative\wdigest.dll 2015-10-14 13:28:07 D2E2A613EBD0C959E72556C3A63A6B4A 112640 ----a-w- C:\Windows\Sysnative\smss.exe 2015-10-14 13:28:07 D2BF3CD0F66139B5F1BA1D35C6613E78 315392 ----a-w- C:\Windows\Sysnative\msv1_0.dll 2015-10-14 13:28:07 C0EC18A77CBE5505019AF1BEB6CE824D 22016 ----a-w- C:\Windows\Sysnative\credssp.dll 2015-10-14 13:28:07 96DE914D834FD7809A1720AF5D913C96 309760 ----a-w- C:\Windows\Sysnative\ncrypt.dll 2015-10-14 13:28:07 95E4E6C645175731B1DC8084329121AA 64000 ----a-w- C:\Windows\Sysnative\auditpol.exe 2015-10-14 13:28:07 8F15F0D6F42A2B8A58EDD1AA55D7FB98 50176 ----a-w- C:\Windows\Sysnative\srclient.dll 2015-10-14 13:28:07 8260FD420E49C1E3DD6539BCEA2B376E 28160 ----a-w- C:\Windows\Sysnative\secur32.dll 2015-10-14 13:28:07 78461527B753B9A6043038AEF25745D3 16384 ----a-w- C:\Windows\Sysnative\ntvdm64.dll 2015-10-14 13:28:07 5B9427E47B86AFDA813A8D252713FC35 296960 ----a-w- C:\Windows\Sysnative\rstrui.exe 2015-10-14 13:28:07 5424EC756808C1002457033D969115C7 31232 ----a-w- C:\Windows\Sysnative\lsass.exe 2015-10-14 13:28:07 4E10C0CD94FD2E9F04B0AA11C4DB1592 29184 ----a-w- C:\Windows\Sysnative\sspisrv.dll 2015-10-14 13:28:07 3CF93F8BA5016A86073F7ACE4A225D69 44032 ----a-w- C:\Windows\Sysnative\cryptbase.dll 2015-10-14 13:28:07 365480590A46ECB0E4BF1DBD7BC69713 729088 ----a-w- C:\Windows\Sysnative\kerberos.dll 2015-10-14 13:28:07 23682AD752DE308760672C84A7E74554 43520 ----a-w- C:\Windows\Sysnative\csrsrv.dll 2015-10-14 13:28:07 06AA22DBBD294BB40F01E23BF826AA9C 86528 ----a-w- C:\Windows\Sysnative\TSpkg.dll 2015-10-14 13:28:05 023394934150F7EC547EBCC2107EEA5F 6656 ----a-w- C:\Windows\Sysnative\apisetschema.dll 2015-10-14 13:28:04 DD01EBF9D35E614CAEA1BF4876B07134 686080 ----a-w- C:\Windows\Sysnative\adtschema.dll 2015-10-14 13:28:04 B5D2DF46AB955A070F67FF192C52E7BD 60416 ----a-w- C:\Windows\Sysnative\msobjs.dll 2015-10-14 13:28:04 7CDA2FE5F02370B5879DF8D35133B0E1 146432 ----a-w- C:\Windows\Sysnative\msaudite.dll 2015-10-14 13:27:45 87FEDB1FF42C3A10FFE2CE95AB2AF306 616360 ----a-w- C:\Windows\Sysnative\winresume.efi 2015-10-14 13:27:45 541B7C53EDA8F84790A593B13FB32E56 692672 ----a-w- C:\Windows\Sysnative\winload.efi 2015-10-14 13:27:44 B6C85437FDC8EC6464BE359D41BBC3F7 59392 ----a-w- C:\Windows\Sysnative\appidapi.dll 2015-10-14 13:27:44 B17B1E5FB5CE63DA4DB4D49E3683487F 17920 ----a-w- C:\Windows\Sysnative\appidcertstorecheck.exe 2015-10-14 13:27:44 ABC373B9C6275D45F17DB559408FFD1B 32768 ----a-w- C:\Windows\Sysnative\appidsvc.dll 2015-10-14 13:27:44 7503BAD9B2A08B8A95319F7C0CA9F869 63488 ----a-w- C:\Windows\Sysnative\setbcdlocale.dll 2015-10-14 13:27:44 7030F95F994B2F2CCC1C521E342369DB 147456 ----a-w- C:\Windows\Sysnative\appidpolicyconverter.exe 2015-10-14 13:27:02 F97E7878A2B372291B1269D80327BBF6 12640 ----a-w- C:\Windows\Sysnative\api-ms-win-crt-heap-l1-1-0.dll 2015-10-14 13:27:02 ED14B64C94F543974B7FDC592FA0594B 12640 ----a-w- C:\Windows\Sysnative\api-ms-win-crt-conio-l1-1-0.dll 2015-10-14 13:27:02 ECCF5973B80D771A79643732017CEA9A 17760 ----a-w- C:\Windows\Sysnative\api-ms-win-crt-string-l1-1-0.dll 2015-10-14 13:27:02 E9F6D776545843A9817D8ACF38D06D09 19808 ----a-w- C:\Windows\Sysnative\api-ms-win-crt-multibyte-l1-1-0.dll 2015-10-14 13:27:02 CC337898E64D9078CB697AC19F995C7F 12128 ----a-w- C:\Windows\Sysnative\api-ms-win-crt-utility-l1-1-0.dll 2015-10-14 13:27:02 BBAE7B5436D6D1B0FC967FF67E35415F 16224 ----a-w- C:\Windows\Sysnative\api-ms-win-crt-runtime-l1-1-0.dll 2015-10-14 13:27:02 AF851DFD0D9FECB76FF2B403F3C30F5B 12128 ----a-w- C:\Windows\Sysnative\api-ms-win-crt-environment-l1-1-0.dll 2015-10-14 13:27:02 761DDD8669A661D57D9CF9C335949C06 12128 ----a-w- C:\Windows\Sysnative\api-ms-win-crt-locale-l1-1-0.dll 2015-10-14 13:27:02 6631C212F79350458589A5281374B38B 12640 ----a-w- C:\Windows\Sysnative\api-ms-win-crt-process-l1-1-0.dll 2015-10-14 13:27:02 653CB5DF3CEC6A4A0E402B33D8AA5C08 63840 ----a-w- C:\Windows\Sysnative\api-ms-win-crt-private-l1-1-0.dll 2015-10-14 13:27:02 56556659C691DD043DBE24B0A195D64C 20832 ----a-w- C:\Windows\Sysnative\api-ms-win-crt-math-l1-1-0.dll 2015-10-14 13:27:02 53E9526AF1FDCE39F799BFE9217397A8 17760 ----a-w- C:\Windows\Sysnative\api-ms-win-crt-stdio-l1-1-0.dll 2015-10-14 13:27:02 32B2264317EA6200DA5DEEEC7DCB0EEB 11616 ----a-w- C:\Windows\Sysnative\api-ms-win-eventing-provider-l1-1-0.dll 2015-10-14 13:27:02 2381E189321EAD521FF71E72D08A6B17 984448 ----a-w- C:\Windows\Sysnative\ucrtbase.dll 2015-10-14 13:27:02 1908861649E67CDC20C563C234A89914 15712 ----a-w- C:\Windows\Sysnative\api-ms-win-crt-convert-l1-1-0.dll 2015-10-14 13:27:02 0F143310FADE4DE116070A3917A79C18 13664 ----a-w- C:\Windows\Sysnative\api-ms-win-crt-filesystem-l1-1-0.dll 2015-10-14 13:27:02 090DD0BB2BDDEE3EAAE5B6FF15FAE209 14176 ----a-w- C:\Windows\Sysnative\api-ms-win-crt-time-l1-1-0.dll ====== C:\Windows\Sysnative\drivers ===== 2015-10-14 13:28:09 C6330F7C2E92A00E6773E82F79078AFC 157016 ----a-w- C:\Windows\Sysnative\drivers\ksecpkg.sys 2015-10-14 13:28:09 ACB6782973BD93760D597FC7BB37E692 159232 ----a-w- C:\Windows\Sysnative\drivers\mrxsmb.sys 2015-10-14 13:28:09 3A8C03156C3E31E70EF84E48CA179B46 97112 ----a-w- C:\Windows\Sysnative\drivers\ksecdd.sys 2015-10-14 13:28:06 8C0376974AA28398FF501E78C04ACB30 129024 ----a-w- C:\Windows\Sysnative\drivers\mrxsmb20.sys 2015-10-14 13:28:06 262BF7BB7D0E44CFAA9B12A1E0A6EDF1 290816 ----a-w- C:\Windows\Sysnative\drivers\mrxsmb10.sys 2015-10-14 13:27:40 27DABFB4A6B0140C34DBEC713469592B 61440 ----a-w- C:\Windows\Sysnative\drivers\appid.sys 2015-10-06 10:40:21 B6FE8DF49002ADC20C3855D6CD5F0C39 964928 ----a-w- C:\Windows\Sysnative\drivers\VBoxDrv.sys 2015-10-06 10:39:49 2597753D837E0DDA62402157A2CACB1F 138904 ----a-w- C:\Windows\Sysnative\drivers\VBoxUSBMon.sys 2015-10-02 12:36:10 E1915B4B40F5F36E2FC9E8EBD2696B14 117768 ----a-w- C:\Windows\Sysnative\drivers\VBoxNetAdp6.sys 2015-10-02 12:36:10 14C3779E644462A69EF8BA82D6C66AE0 146584 ----a-w- C:\Windows\Sysnative\drivers\VBoxNetLwf.sys ====== C:\Windows\Tasks ====== ====== C:\Windows\Temp ====== ======= C:\Program Files ===== 2015-10-15 14:05:37 -------- d-----w- C:\Program Files\Wireshark 2015-10-06 10:39:35 -------- d-----w- C:\Program Files\Oracle 2015-10-01 12:19:59 -------- d-----w- C:\Program Files\FileZilla FTP Client 2015-09-20 23:04:31 -------- d-----w- C:\Program Files\Microsoft SQL Server Compact Edition 2015-09-20 22:58:54 -------- d-----w- C:\Program Files\Microsoft DNX 2015-09-20 22:51:59 -------- d-----w- C:\Program Files\IIS Express 2015-09-20 22:47:34 -------- d-----w- C:\Program Files\IIS 2015-09-20 22:40:25 -------- d-----w- C:\Program Files\Microsoft Visual Studio 12.0 2015-09-20 22:32:43 -------- d-----w- C:\Program Files\Microsoft SQL Server ======= C:\PROGRA~2 ===== 2015-10-20 08:47:51 -------- d-----w- C:\PROGRA~2\COMMON~1\Java 2015-10-15 14:07:26 -------- d-----w- C:\PROGRA~2\WinPcap 2015-10-15 14:05:00 -------- d-----w- C:\PROGRA~2\Cisco Packet Tracer 6.2sv 2015-09-25 08:46:01 -------- d-----w- C:\PROGRA~2\VisualRoute Lite Edition 2015-09-23 17:24:29 -------- d-----w- C:\PROGRA~2\Mozilla Maintenance Service 2015-09-23 17:22:35 -------- d-----w- C:\PROGRA~2\Notepad++ 2015-09-20 23:02:13 -------- d-----w- C:\PROGRA~2\ShellDir 2015-09-20 23:01:05 -------- d-----w- C:\PROGRA~2\Microsoft ASP.NET 2015-09-20 22:54:43 -------- d-----w- C:\PROGRA~2\Microsoft Web Tools 2015-09-20 22:51:59 -------- d-----w- C:\PROGRA~2\IIS Express 2015-09-20 22:51:11 -------- d-----w- C:\PROGRA~2\AppInsights 2015-09-20 22:50:41 -------- d-----w- C:\PROGRA~2\Microsoft Office365 Tools 2015-09-20 22:48:02 -------- d-----w- C:\PROGRA~2\NuGet 2015-09-20 22:47:51 -------- d-----w- C:\PROGRA~2\Microsoft WCF Data Services 2015-09-20 22:47:33 -------- d-----w- C:\PROGRA~2\IIS 2015-09-20 22:40:22 -------- d-----w- C:\PROGRA~2\Microsoft Visual Studio 12.0 2015-09-20 22:35:49 -------- d-----w- C:\PROGRA~2\Microsoft Help Viewer 2015-09-20 22:35:47 -------- d-----w- C:\PROGRA~2\Windows Kits 2015-09-20 22:32:44 -------- d-----w- C:\PROGRA~2\Microsoft SQL Server 2015-09-20 22:27:48 -------- d-----w- C:\PROGRA~2\Microsoft SDKs ======= C: ===== ====== C:\Users\Timur\AppData\Roaming ====== 2015-10-20 08:51:37 -------- d-----w- C:\Users\Timur\AppData\Roaming\Oracle 2015-10-20 08:47:26 -------- d-----w- C:\Users\Timur\AppData\Roaming\Sun 2015-10-20 08:45:53 -------- d-----w- C:\Users\Timur\AppData\Locallow\Oracle 2015-10-19 20:15:48 -------- d-----w- C:\Users\Timur\AppData\Local\Arma 3 2015-10-19 12:53:14 42ED928EE0A6E0B8FB5D2F8D0458AA16 127144 ----a-w- C:\Users\Timur\AppData\Local\GDIPFONTCACHEV1.DAT 2015-10-16 08:20:08 -------- d-----w- C:\Users\Timur\AppData\Roaming\Wireshark 2015-10-11 15:22:57 -------- d-----w- C:\Users\Timur\AppData\Local\CrashDumps 2015-10-05 14:03:41 -------- d-----w- C:\Windows\SysNative\config\systemprofile\AppData\Local\CrashDumps 2015-10-03 21:38:38 -------- d-s---w- C:\Windows\serviceprofiles\networkservice\AppData\Locallow\Microsoft 2015-10-01 12:20:09 -------- d-----w- C:\Users\Timur\AppData\Roaming\FileZilla 2015-09-23 17:22:38 -------- d-----w- C:\Users\Timur\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Notepad++ 2015-09-23 17:22:35 -------- d-----w- C:\Users\Timur\AppData\Roaming\Notepad++ 2015-09-21 12:58:01 -------- d-----w- C:\Users\Timur\AppData\Roaming\NuGet ====== C:\Users\Timur ====== 2015-10-20 09:18:20 -------- d-----w- C:\Windows\sysWoW64\config\systemprofile\.oracle_jre_usage 2015-10-20 08:47:25 -------- d-----w- C:\Users\Timur\.oracle_jre_usage 2015-10-19 20:33:56 8045ABB21A3BDD66A48E1ED5C0F0EF6A 1222144 ----a-w- C:\Users\Timur\Desktop\RSITx64.exe 2015-10-15 14:07:27 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinPcap 2015-10-15 14:05:40 E96600B2485ABA54FE7CD3559B405789 188 ----a-w- C:\Users\Timur\.packettracer 2015-10-15 14:05:40 -------- d-----w- C:\Users\Timur\Cisco Packet Tracer 6.2sv 2015-10-15 14:05:20 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cisco Packet Tracer Student 2015-10-06 10:43:22 -------- d-----w- C:\Users\Timur\VirtualBox VMs 2015-10-06 10:41:43 -------- d-----w- C:\Users\Timur\.VirtualBox 2015-10-06 10:40:24 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Oracle VM VirtualBox 2015-10-01 12:20:00 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FileZilla FTP Client 2015-09-28 23:22:33 DF61C2A2F8C9A6E73DDCECECC2055B22 2128 ----a-w- C:\Users\Timur\.recently-used.xbel 2015-09-25 08:46:14 -------- d-----w- C:\Users\Timur\vw 2015-09-25 08:46:14 -------- d-----w- C:\Users\Timur\VisualRoute 2015-09-25 08:46:02 F1FA4F1312E06D0269B85D6F1D4B2055 47 ----a-w- C:\Users\Timur\VisualRoute Lite Edition-Path 2015-09-25 08:46:02 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VisualRoute Lite Edition 2015-09-23 17:22:38 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Notepad++ 2015-09-20 23:02:31 -------- d-----w- C:\ProgramData\PreEmptive Solutions 2015-09-20 22:58:54 -------- d-----w- C:\ProgramData\Microsoft DNX 2015-09-20 22:48:02 -------- d-----w- C:\ProgramData\NuGet 2015-09-20 22:43:11 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Expression 2015-09-20 22:37:31 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Visual Studio 2015 2015-09-20 21:58:10 -------- d-----w- C:\ProgramData\VsTelemetry ====== C: exe-files == 2015-10-20 08:54:36 E3B5C0DE01FDEF1F01AF9399360A13DC 544 ----a-w- C:\$RECYCLE.BIN\S-1-5-21-4130941160-3806457408-160441287-1002\$I4Q73J4.exe 2015-10-20 08:53:49 1064746CA8DB8AFF56871120E359809E 544 ----a-w- C:\$RECYCLE.BIN\S-1-5-21-4130941160-3806457408-160441287-1002\$IBD04NU.exe 2015-10-20 08:52:36 7EA0260488F304D68067A50B33A23AC2 1309184 ----a-w- C:\$RECYCLE.BIN\S-1-5-21-4130941160-3806457408-160441287-1002\$RBD04NU.exe 2015-10-20 08:46:46 E408E46C5DD2D03A7474AA12BAABEFEE 15968 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_60\bin\klist.exe 2015-10-20 08:46:46 D94C31E9C9C9A1273CC67DC6FFAF9984 15968 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_60\bin\policytool.exe 2015-10-20 08:46:46 BDFF5086FC1F20E631A070EEF43A7BEC 16480 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_60\bin\tnameserv.exe 2015-10-20 08:46:46 BC949C957CEB9FAFDF0F3949CDDF1A72 191584 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_60\bin\java.exe 2015-10-20 08:46:46 B9DE149653ED8B9C5C6CB68131AB66D2 15968 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_60\bin\jjs.exe 2015-10-20 08:46:46 B804A4E31F4BAD4D5BA05FE684756BA2 15968 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_60\bin\servertool.exe 2015-10-20 08:46:46 8C6BDB56CD4DEED1AF2790D37B54CFE9 68192 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_60\bin\javacpl.exe 2015-10-20 08:46:46 86CC77A8189758834CF83F7F2FEA5162 15968 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_60\bin\java-rmi.exe 2015-10-20 08:46:46 7A0DE452F677EF2971C7B75B0267B6ED 50784 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_60\bin\ssvagent.exe 2015-10-20 08:46:46 7080B965215703EA1340C3C4903C7D73 274016 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_60\bin\javaws.exe 2015-10-20 08:46:46 6A5A2FDB6D09E02A3283C55237DA10F6 159328 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_60\bin\unpack200.exe 2015-10-20 08:46:46 606A24A64E164B345A79F8F22A5DAC6F 15968 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_60\bin\pack200.exe 2015-10-20 08:46:46 5DC0128E8A2017E82289191820C736A5 191584 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_60\bin\javaw.exe 2015-10-20 08:46:46 5A503CFE5B553A9721A469FCC9CE8562 15968 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_60\bin\rmiregistry.exe 2015-10-20 08:46:46 3292748E640429C2682484BD23D43F6B 15968 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_60\bin\rmid.exe 2015-10-20 08:46:46 30387BE3E5D04FE969B731441C89D2D8 15968 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_60\bin\ktab.exe 2015-10-20 08:46:46 262BBCE84B9C8784CC5A5E1975898022 30304 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_60\bin\jabswitch.exe 2015-10-20 08:46:46 21B5D297A9191E4D833BB39456CEDAD0 15968 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_60\bin\kinit.exe 2015-10-20 08:46:46 0FCF9F3D9518B90FB58CC950FA33998C 76896 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_60\bin\jp2launcher.exe 2015-10-20 08:46:46 0F6E0DD1263ACB2A1AC559BB7742B54D 15968 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_60\bin\keytool.exe 2015-10-20 08:46:46 08427EADE480F21412696582170B1167 16480 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_60\bin\orbd.exe 2015-10-20 08:45:38 55ABA352278DF8E17D6E4DD261207448 584288 ----a-w- C:\$RECYCLE.BIN\S-1-5-21-4130941160-3806457408-160441287-1002\$R4Q73J4.exe 2015-10-19 20:01:21 44FF7EC7027FB3071AA8DB387C57B9B9 544 ----a-w- C:\$RECYCLE.BIN\S-1-5-21-4130941160-3806457408-160441287-1002\$IUSK650.exe 2015-10-19 19:56:33 56805606D40B1EC96AE8442E21318C13 1125888 ----a-w- C:\Program Files (x86)\Common Files\BattlEye\BEService_x64.exe 2015-10-15 14:05:10 7217B684A2C8ADD312DFD0F28A2899F1 11776 ----a-w- C:\Program Files (x86)\Cisco Packet Tracer 6.2sv\extensions\upnp\upnpc.exe 2015-10-15 14:05:09 0BE71A8D6F65BE2058613E56773D6BE0 275456 ----a-w- C:\Program Files (x86)\Cisco Packet Tracer 6.2sv\extensions\upnp\upnp.exe 2015-10-15 14:05:08 83AF340778E7C353B9A2D2A788C3A13A 135168 ----a-w- C:\Program Files (x86)\Cisco Packet Tracer 6.2sv\bin\zip.exe 2015-10-15 14:05:08 75375C22C72F1BEB76BEA39C22A1ED68 167936 ----a-w- C:\Program Files (x86)\Cisco Packet Tracer 6.2sv\bin\unzip.exe 2015-10-15 14:05:08 6D4EEB6BF480ACECE99326AE40B6D128 1603072 ----a-w- C:\Program Files (x86)\Cisco Packet Tracer 6.2sv\extensions\meta.exe 2015-10-15 14:05:05 E9AB0B7683C36639AE94C7D3FB40FC29 48343048 ----a-w- C:\Program Files (x86)\Cisco Packet Tracer 6.2sv\bin\PacketTracer6.exe 2015-10-15 14:05:05 5CF78176B82DAB43FDD9207FD912DFD8 1622016 ----a-w- C:\Program Files (x86)\Cisco Packet Tracer 6.2sv\bin\linguist.exe 2015-10-15 14:05:00 DD44B6421C113809E89C1452B981982F 1193161 ----a-w- C:\Program Files (x86)\Cisco Packet Tracer 6.2sv\unins000.exe 2015-10-15 12:04:38 2378C5CC4237C2B561460C69580E8035 9064016 ----a-w- C:\Program Files (x86)\Google\Update\Install\{73A472D9-F7EB-441D-8DB0-1E3AFE3E10C3}\46.0.2490.71_45.0.2454.101_chrome_updater.exe 2015-10-15 12:04:37 2378C5CC4237C2B561460C69580E8035 9064016 ----a-w- C:\Program Files (x86)\Google\Update\Download\{4DC8B4CA-1BDA-483E-B5FA-D3C12E15B62D}\46.0.2490.71\46.0.2490.71_45.0.2454.101_chrome_updater.exe 2015-10-14 17:47:28 BD09B84734EF836E1462EFBBDEAB8543 3084888 ----a-w- C:\Program Files\Wireshark\Wireshark.exe 2015-10-14 17:47:28 B8AD59478E473F72E479E9E53C037E5F 341080 ----a-w- C:\Program Files\Wireshark\text2pcap.exe 2015-10-14 17:47:28 A330BCABE487F40281C31419AFFDE97C 546904 ----a-w- C:\Program Files\Wireshark\tshark.exe 2015-10-14 17:47:28 93353B2C474C04A681FE9B9C597B9A2C 417448 ----a-w- C:\Program Files\Wireshark\uninstall.exe 2015-10-14 17:47:28 41670EB14F97FBB7D2C168ECCDD32CE8 313432 ----a-w- C:\Program Files\Wireshark\mergecap.exe 2015-10-14 17:47:28 31ABC491C9F0FD5FBFA5E9A2EC7DFEF7 352856 ----a-w- C:\Program Files\Wireshark\rawshark.exe 2015-10-14 17:47:28 0AA47E75E9F686C84D14E450C8F9DB06 308312 ----a-w- C:\Program Files\Wireshark\reordercap.exe 2015-10-14 17:47:24 08E912D8D49E772D49542E40C0E82E9B 327768 ----a-w- C:\Program Files\Wireshark\editcap.exe 2015-10-14 17:47:22 FD68BE79489DB06C2F02E4C1999CCB1C 323672 ----a-w- C:\Program Files\Wireshark\capinfos.exe 2015-10-14 17:47:22 F37384CED06ECB614C512D0E1914464E 393304 ----a-w- C:\Program Files\Wireshark\dumpcap.exe 2015-10-14 13:29:02 D8AF0D6A806ADA9660C55DD891E80AF2 224768 ----a-w- C:\Program Files\Common Files\Microsoft Shared\ink\TabTip.exe 2015-10-14 13:29:02 4FCAED5CA1A9C704DBF172283A283B53 10240 ----a-w- C:\Program Files (x86)\Common Files\microsoft shared\ink\TabTip32.exe 2015-10-14 13:28:54 1A480EC5EFC71B92735BB420E2B92348 221184 ----a-w- C:\Program Files (x86)\Internet Explorer\ielowutil.exe 2015-10-14 13:28:53 2D59CD5D6C1DCB3507431281BDBF935F 222720 ----a-w- C:\Program Files\Internet Explorer\ielowutil.exe 2015-10-14 13:28:53 03AE49CC0AD731C579E4041921450266 473600 ----a-w- C:\Program Files (x86)\Internet Explorer\ieinstal.exe 2015-10-14 13:28:52 7FD2748E2B08B5E9FD6FF73669B2ECBF 818264 ----a-w- C:\Program Files (x86)\Internet Explorer\iexplore.exe 2015-10-14 13:28:50 E4509963A72F1941B17DA730BB94AD20 491008 ----a-w- C:\Program Files\Internet Explorer\ieinstal.exe 2015-10-14 13:28:49 5F95E34F57E2E85295510EEEF724012D 815720 ----a-w- C:\Program Files\Internet Explorer\iexplore.exe === C: other files == 2015-10-20 08:46:46 4E221C69F3B103481534D1B6CB6A90DD 14130 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_60\lib\deploy\ffjcext.zip ==== Startup Registry Enabled ====================== [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun" [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun" [HKEY_USERS\S-1-5-21-4130941160-3806457408-160441287-1000\Software\Microsoft\Windows\CurrentVersion\Run] "ISUSPM"="C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe -scheduler" "ROC_JAN2013_TB"="C:\Program Files (x86)\AVG Secure Search\ROC_JAN2013_TB.exe /PROMPT /CMPID=JAN2013_TB" "Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun" [HKEY_USERS\S-1-5-21-4130941160-3806457408-160441287-1002\Software\Microsoft\Windows\CurrentVersion\Run] "Google Update"="C:\Users\Timur\AppData\Local\Google\Update\GoogleUpdate.exe /c" "Viber"="C:\Users\Timur\AppData\Local\Viber\Viber.exe" [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce] "mctadmin"="C:\Windows\System32\mctadmin.exe" [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce] "mctadmin"="C:\Windows\System32\mctadmin.exe" [HKEY_USERS\S-1-5-21-4130941160-3806457408-160441287-1000\Software\Microsoft\Windows\CurrentVersion\RunOnce] "mctadmin"="C:\Windows\System32\mctadmin.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "AvastUI.exe"="C:\Program Files\AVAST Software\Avast\AvastUI.exe /nogui" "SunJavaUpdateSched"="C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "Google Update"="C:\Users\Timur\AppData\Local\Google\Update\GoogleUpdate.exe /c" "Viber"="C:\Users\Timur\AppData\Local\Viber\Viber.exe" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"="C:\\Windows\\SysWOW64\\nvinit.dll" ==== Startup Registry Enabled x64 ====================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RtHDVBg"="C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe /SF3 " "AmIcoSinglun64"="C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe" "Nvtmru"="C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe" "Cm108Sound"="C:\Windows\syswow64\RunDll32.exe C:\Windows\Syswow64\cm108.dll,CMICtrlWnd" "IgfxTray"="C:\Windows\system32\igfxtray.exe" "HotKeysCmds"="C:\Windows\system32\hkcmd.exe" "Persistence"="C:\Windows\system32\igfxpers.exe" "ETDCtrl"="%ProgramFiles%\Elantech\ETDCtrl.exe " [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"="C:\\Windows\\system32\\nvinitx.dll" ==== Startup Registry Disabled x64 ====================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ASUS Screen Saver Protector] "command"="C:\\Windows\\AsScrPro.exe" "hkey"="HKLM" "item"="ASUS Screen Saver Protector" "key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\CLMLServer] "command"="\"C:\\Program Files (x86)\\CyberLink\\Power2Go\\CLMLSvc.exe\"" "hkey"="HKLM" "item"="CLMLServer" "key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\RtHDVCpl] "command"="C:\\Program Files\\Realtek\\Audio\\HDA\\RAVCpl64.exe -s" "hkey"="HKLM" "item"="RtHDVCpl" "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Skype] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="Skype" "hkey"="HKCU" "command"="\"C:\\Program Files (x86)\\Skype\\Phone\\Skype.exe\" /minimized /regrun" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Sony PC Companion] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="Sony PC Companion" "hkey"="HKCU" "command"="\"C:\\Program Files (x86)\\Sony\\Sony PC Companion\\PCCompanion.exe\" /Background" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Spotify] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="Spotify" "hkey"="HKCU" "command"="\"C:\\Users\\Timur\\AppData\\Roaming\\Spotify\\spotify.exe\" /uri spotify:autostart" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Spotify Web Helper] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="Spotify Web Helper" "hkey"="HKCU" "command"="\"C:\\Users\\Timur\\AppData\\Roaming\\Spotify\\Data\\SpotifyWebHelper.exe\"" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Steam] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="Steam" "hkey"="HKCU" "command"="\"C:\\Program Files (x86)\\Steam\\steam.exe\" -silent" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Users^Timur^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 3.4.1.lnk] "item"="OpenOffice.org 3.4.1" "path"="C:\\Users\\Timur\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\OpenOffice.org 3.4.1.lnk" "backup"="C:\\Windows\\pss\\OpenOffice.org 3.4.1.lnk.Startup" "backupExtension"=".Startup" "command"="C:\\PROGRA~2\\OPENOF~1.ORG\\program\\QUICKS~1.EXE" ==== Task Scheduler Jobs ====================== C:\Windows\tasks\Adobe Flash Player Updater.job --a------ C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [17/10/2015 21:04] C:\Windows\tasks\ASUS SmartLogon Console Sensor.job --a------ C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe [15/11/2010 10:42] C:\Windows\tasks\GoogleUpdateTaskMachineCore1ce0b15e35ba8d.job --a------ C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [30/08/2015 11:16] C:\Windows\tasks\GoogleUpdateTaskMachineUA.job --a------ C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [30/08/2015 11:16] C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-4130941160-3806457408-160441287-1002Core1ce0bca8438bd5c.job --a------ C:\Users\Timur\AppData\Local\Google\Update\GoogleUpdate.exe [29/08/2015 02:21] C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-4130941160-3806457408-160441287-1002UA.job --a------ C:\Users\Timur\AppData\LoC:al\Google\Update\GoogleUpdate.exe [] ==== Other Scheduled Tasks ====================== "C:\Windows\SysNative\tasks\ACMON" [C:\Program Files (x86)\ASUS\Splendid\ACMON.exe] "C:\Windows\SysNative\tasks\Adobe Flash Player Updater" [C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe] "C:\Windows\SysNative\tasks\ASUS Live Update" [C:\Program Files (x86)\ASUS\ASUS Live Update\ALU.exe] "C:\Windows\SysNative\tasks\ASUS P4G" [C:\Program Files\P4G\BatteryLife.exe] "C:\Windows\SysNative\tasks\ASUS SmartLogon Console Sensor" [C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe] "C:\Windows\SysNative\tasks\ATKOSD2" [C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe] "C:\Windows\SysNative\tasks\CCleanerSkipUAC" ["C:\Program Files\CCleaner\CCleaner.exe"] "C:\Windows\SysNative\tasks\GoogleUpdateTaskMachineCore1ce0b15e35ba8d" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe] "C:\Windows\SysNative\tasks\GoogleUpdateTaskMachineUA" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe] "C:\Windows\SysNative\tasks\GoogleUpdateTaskUserS-1-5-21-4130941160-3806457408-160441287-1002Core1ce0bca8438bd5c" [C:\Users\Timur\AppData\Local\Google\Update\GoogleUpdate.exe] "C:\Windows\SysNative\tasks\GoogleUpdateTaskUserS-1-5-21-4130941160-3806457408-160441287-1002UA" [C:\Users\Timur\AppData\Local\Google\Update\GoogleUpdate.exe] "C:\Windows\SysNative\tasks\SidebarExecute" [C:\Program Files\Windows Sidebar\sidebar.exe] "C:\Windows\SysNative\tasks\User_Feed_Synchronization-{E1BB329B-03C9-4552-AED2-08A512F3D57F}" [C:\Windows\system32\msfeedssync.exe] "C:\Windows\SysNative\tasks\{160884E8-B0C0-4219-AE41-D190978243D3}" [C:\Program Files (x86)\Steam\steamapps\common\Max Payne\maxpayne.exe] "C:\Windows\SysNative\tasks\{410DAA62-A88E-4262-9451-8BAC9B33CC13}" [C:\Users\Timur\Desktop\Minecraft.exe] "C:\Windows\SysNative\tasks\{5A6D726B-ACF9-4231-A19D-9AC279FC61CB}" [C:\Program Files (x86)\Steam\steamapps\common\Max Payne 2 The Fall of Max Payne\maxpayne2.exe] "C:\Windows\SysNative\tasks\{7D1A0914-9801-44AD-ABA1-742E5B3FFFF5}" [C:\Program Files (x86)\Windows Live\Photo Gallery\MovieMaker.exe] "C:\Windows\SysNative\tasks\{7D812301-9B9F-443D-B742-1F387D15C8EB}" [C:\Program Files (x86)\Steam\steamapps\common\Max Payne\maxpayne.exe] "C:\Windows\SysNative\tasks\{8D7B11C0-2283-4BA2-9867-65FE63F0E09B}" [C:\Users\Timur\Desktop\Minecraft.exe] "C:\Windows\SysNative\tasks\{90249083-1400-4662-BE74-C43C389B5D3A}" [C:\Program Files (x86)\Steam\steamapps\common\Max Payne\maxpayne.exe] "C:\Windows\SysNative\tasks\Apple\AppleSoftwareUpdate" [C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe] "C:\Windows\SysNative\tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask" [%systemroot%\system32\sc.exe start osppsvc] ==== Folders in C:\PROGRA~3 0-6 Months Old ====================== 2015-06-19 18:04:46 -------- d-----w- C:\PROGRA~3\Battle.net 2015-06-19 18:05:37 -------- d-----w- C:\PROGRA~3\Blizzard Entertainment 2015-08-29 01:31:44 -------- d-----w- C:\PROGRA~3\Nexon 2015-09-20 21:58:10 -------- d-----w- C:\PROGRA~3\VsTelemetry 2015-09-20 22:48:02 -------- d-----w- C:\PROGRA~3\NuGet 2015-09-20 22:58:54 -------- d-----w- C:\PROGRA~3\Microsoft DNX 2015-09-20 23:02:31 -------- d-----w- C:\PROGRA~3\PreEmptive Solutions ==== Firefox Extensions Registry ====================== [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions] "wrc@avast.com"="C:\Program Files\AVAST Software\Avast\WebRep\FF" [29/09/2015 12:42] ==== Firefox Extensions ====================== ProfilePath: C:\Users\Timur\AppData\Roaming\Mozilla\Firefox\Profiles\7frs1857.default - Firebug - %ProfilePath%\extensions\firebug@software.joehewitt.com.xpi - Web Developer - %ProfilePath%\extensions\{c45c406e-ab73-11d8-be73-000a95be3b12}.xpi - Adblock Plus - %ProfilePath%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi AppDir: C:\Program Files (x86)\Mozilla Firefox - Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} ==== Firefox Plugins ====================== Profilepath: C:\Users\Timur\AppData\Roaming\Mozilla\Firefox\Profiles\7frs1857.default 18CF51689186AEB9D1D149AEB0E92D03 - C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL - Microsoft Office 2013 9291708CCD967887AF94BE708B43D64D - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll - Microsoft Office 2013 CF25FDD7CA6BC88442A58F74DBB6CFA6 - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1200112.dll - Shockwave for Director / Shockwave for Director 863AF0003392FEBC2667A8A790DED955 - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_19_0_0_226.dll - Shockwave Flash 7D127425BBE91DF37448A7F44C1DDA52 - C:\Users\Timur\AppData\Local\Google\Update\1.3.28.15\npGoogleUpdate3.dll - Google Update BB6EA6C984C82A210DB74AA988BE4CB9 - C:\Users\Timur\AppData\LocalLow\Square Enix\nprun3d.dll - Square Enix Secure Launcher 49D429EBF5305FC9ADD7545B7C914333 - C:\Users\Timur\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll - Google Talk Plugin 6BEAD7859E8A087BE04556AB5A78855C - C:\Users\Timur\AppData\Roaming\Mozilla\plugins\npo1d.dll - Google Talk Plugin Video Renderer ==== Chromium Look ====================== Google Chrome Version: 46.0.2490.71 HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions gomekmidlodglbbmalcneegieacbdmki - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx[22/04/2015 14:41] lifbcibllhkdhoafpjfnlhfpfgnpldfl - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx[12/10/2015 09:31] Google Docs - Timur\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake Google Drive - Timur\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf Raindrops - Timur\AppData\Local\Google\Chrome\User Data\Default\Extensions\bcipapbfhdnmgihoimbjiadmhpcgcnil Web Developer - Timur\AppData\Local\Google\Chrome\User Data\Default\Extensions\bfbameneiokkgbdmiekhjnmfkcnldhhm YouTube - Timur\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo Firebug Lite for Google Chrome™ - Timur\AppData\Local\Google\Chrome\User Data\Default\Extensions\bmagokdooijbeehmkpknfglimnifench Google Search - Timur\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf Google Docs Offline - Timur\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi AdBlock - Timur\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom Chrome Web Store Payments - Timur\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda Gmail - Timur\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia ==== Chromium Fix ====================== C:\Users\Timur\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.azlyrics.com_0.localstorage-journal deleted successfully C:\Users\Timur\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.moddb.com_0.localstorage-journal deleted successfully C:\Users\Timur\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.olark.com_0.localstorage-journal deleted successfully ==== Set IE to Default ====================== Old Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://asus.msn.com" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AboutURLs] "Tabs"="res://ieframe.dll/tabswelcome.htm" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\AboutURLs] "Tabs"="res://ieframe.dll/tabswelcome.htm" New Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://asus.msn.com" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AboutURLs] "Tabs"="about:newtab" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\AboutURLs] "Tabs"="about:newtab" ==== All HKCU SearchScopes ====================== HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" {012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}" {0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC" ==== Empty IE Cache ====================== C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Timur\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully ==== Empty FireFox Cache ====================== C:\Users\Timur\AppData\Local\Mozilla\Firefox\Profiles\7frs1857.default\cache2 emptied successfully ==== Empty Chrome Cache ====================== C:\Users\Timur\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully ==== Empty All Flash Cache ====================== Flash Cache Emptied Successfully ==== Empty All Java Cache ====================== Java Cache cleared successfully ==== C:\zoek_backup content ====================== C:\zoek_backup (files=2931 folders=635 1254794054 bytes) ==== Empty Temp Folders ====================== C:\Users\Default\AppData\Local\Temp emptied successfully C:\Users\Default User\AppData\Local\Temp emptied successfully C:\Users\Timur\AppData\Local\Temp will be emptied at reboot C:\Users\UpdatusUser\AppData\Local\Temp emptied successfully C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp will be emptied at reboot C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully C:\Windows\Temp will be emptied at reboot ==== After Reboot ====================== ==== Empty Temp Folders ====================== C:\Windows\Temp successfully emptied C:\Users\Timur\AppData\Local\Temp successfully emptied ==== Empty Recycle Bin ====================== C:\$RECYCLE.BIN successfully emptied ==== Deleting Files / Folders ====================== "C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp\Low" not deleted ==== EOF on di 20/10/2015 at 13:42:44,32 ======================