Zoek.exe v5.0.0.1 Updated 01-November-2015 Tool run by Olaf De Wit VolBeh on di 03/11/2015 at 12:56:36,17. Microsoft Windows 8.1 6.3.9600 x64 Running in: Normal Mode Internet Access Detected Launched: C:\Users\Olaf De Wit VolBeh\Downloads\zoek(1).exe [Scan all users] [Script inserted] [Checkboxes used] ==== System Restore Info ====================== 3/11/2015 12:57:54 Zoek.exe System Restore Point Created Successfully. ==== Torpig Check ====================== HKEY_CLASSES_ROOT\Directory\shellex\CopyHookHandlers\AutorunsDisabled\Ath_CopyHook {8e10a039-fe03-4f9c-b7e1-c5eeeaf53735} C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\FolderViewImpl.dll HKEY_CLASSES_ROOT\Directory\shellex\CopyHookHandlers\FileSystem {217FC9C0-3AEA-1069-A2DB-08002B30309D} %SystemRoot%\system32\shell32.dll HKEY_CLASSES_ROOT\Directory\shellex\CopyHookHandlers\Sharing {40dd6e20-7c17-11ce-a804-00aa003ca9f6} %SystemRoot%\system32\ntshrui.dll ==== Empty Folders Check ====================== C:\PROGRA~2\HostsMan deleted successfully C:\PROGRA~2\Malwarebytes' Anti-Malware deleted successfully C:\PROGRA~3\Malwarebytes' Anti-Malware (portable) deleted successfully C:\Users\Olaf De Wit VolBeh\AppData\Roaming\Malwarebytes deleted successfully C:\Users\Olaf De Wit VolBeh\AppData\Roaming\QuickScan deleted successfully C:\Users\Olaf De Wit VolBeh\AppData\Local\EmieSiteList deleted successfully C:\Users\Olaf De Wit VolBeh\AppData\Local\EmieUserList deleted successfully ==== Registry Fix Code x64 ====================== Windows Registry Editor Version 5.00 [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\AutorunsDisabled] ==== Deleting Files \ Folders ====================== C:\Users\Olaf De Wit VolBeh\AppData\Roaming\Mozilla\Firefox\Profiles\xe7710xq.default\extensions\artur.dubovoy@gmail.com deleted C:\Users\Olaf De Wit VolBeh\AppData\Roaming\Mozilla\Firefox\Profiles\xe7710xq.default\extensions\CLEO@guid.customsoftwareconsult.com deleted C:\Users\Olaf De Wit VolBeh\AppData\Roaming\Mozilla\Firefox\Profiles\xe7710xq.default\extensions\bingsearch.full@microsoft.com deleted C:\Users\Olaf De Wit VolBeh\AppData\Roaming\Mozilla\Firefox\Profiles\xe7710xq.default\extensions\clickclean@hotcleaner.com deleted C:\Users\Olaf De Wit VolBeh\AppData\Roaming\Mozilla\Firefox\Profiles\xe7710xq.default\extensions\paulsaintuzb@gmail.com deleted C:\Users\Olaf De Wit VolBeh\AppData\Roaming\Mozilla\Firefox\Profiles\xe7710xq.default\extensions\{4BBDD651-70CF-4821-84F8-2B918CF89CA3} deleted C:\Users\Olaf De Wit VolBeh\AppData\Roaming\Mozilla\Firefox\Profiles\xe7710xq.default\extensions\{bb6bc1bb-f824-4702-90cd-35e2fb24f25d} deleted C:\ProgramData\{AA6BF06E-316C-487A-9BC2-5F06A43C56B1} deleted ==== Files Recently Created / Modified ====================== ====== C:\WINDOWS ==== ====== C:\Users\OLAFDE~1\AppData\Local\Temp ==== ====== Java Cache ===== ====== C:\WINDOWS\SysWOW64 ===== 2015-10-29 14:02:22 B5EE32AABD5B5DCDB2D79FE460423953 102520 ----a-w- C:\WINDOWS\SysWOW64\nvStreaming.exe 2015-10-29 14:00:41 DD9079A97F809873289C83DF6EA60CAD 128696 ----a-w- C:\WINDOWS\SysWOW64\nvoglshim32.dll 2015-10-29 14:00:41 A7B9D5DACF0061F7AB9BE16DC833FD5D 15002304 ----a-w- C:\WINDOWS\SysWOW64\nvwgf2um.dll 2015-10-29 14:00:41 80AD32A30338C05DFE6F38434850BC2C 13518496 ----a-w- C:\WINDOWS\SysWOW64\nvopencl.dll 2015-10-29 14:00:41 7E0FA3285A2F5FCAA7A17755895376D0 673912 ----a-w- C:\WINDOWS\SysWOW64\NvIFR.dll 2015-10-29 14:00:41 748FC0100FE5132E5CA24314861FF6D1 369272 ----a-w- C:\WINDOWS\SysWOW64\NvIFROpenGL.dll 2015-10-29 14:00:41 60016082D57FF3057E4488A37EE62266 388024 ----a-w- C:\WINDOWS\SysWOW64\nvumdshim.dll 2015-10-29 14:00:41 40FC4AC106DB55953F535A652B7E7A66 155976 ----a-w- C:\WINDOWS\SysWOW64\nvinit.dll 2015-10-29 14:00:41 15C106B41C938B6BA0E2AA0225EEF428 18359928 ----a-w- C:\WINDOWS\SysWOW64\nvoglv32.dll 2015-10-29 14:00:40 E43145FEE9FCD787265C3D7F17B82B1D 37882488 ----a-w- C:\WINDOWS\SysWOW64\nvcompiler.dll 2015-10-29 14:00:40 C3E5CCF6A73F692C74967B12EB9AB0EE 2489976 ----a-w- C:\WINDOWS\SysWOW64\nvcuvid.dll 2015-10-29 14:00:40 97D223727F99CC872A777D802747FA75 12032200 ----a-w- C:\WINDOWS\SysWOW64\nvcuda.dll 2015-10-29 14:00:40 645E053F482FA25CAC8C1E7ADC133011 689456 ----a-w- C:\WINDOWS\SysWOW64\NvFBC.dll 2015-10-29 14:00:40 231B75611167001C0D10CE33BE4C4C69 422240 ----a-w- C:\WINDOWS\SysWOW64\nvEncodeAPI.dll 2015-10-27 20:22:37 2DA7EA34F8FC590EF04292E0A57774AB 53248 ----a-w- C:\WINDOWS\SysWOW64\CSVer.dll 2015-10-24 15:32:46 BD79285BF1821B8EB313F5BE4C1A30C7 367104 ----a-w- C:\WINDOWS\SysWOW64\puiobj.dll 2015-10-24 15:27:12 668AF48D5010DE968952BB4A8EEB6744 1096704 ----a-w- C:\WINDOWS\SysWOW64\gdi32.dll ====== C:\WINDOWS\SysWOW64\drivers ===== ====== C:\WINDOWS\Sysnative ===== 2015-10-29 14:00:41 F9F5643B5BC2DB095FE7F0FEEDFDB7B1 177416 ----a-w- C:\WINDOWS\Sysnative\nvinitx.dll 2015-10-29 14:00:41 F239588D4A3185AACCF2BD48EBB7146A 22306936 ----a-w- C:\WINDOWS\Sysnative\nvoglv64.dll 2015-10-29 14:00:41 5F036671376B3FF443C6A50EE5727570 414000 ----a-w- C:\WINDOWS\Sysnative\NvIFROpenGL.dll 2015-10-29 14:00:41 3F845D3E131F89C1A53CB22F1EA6F80D 861816 ----a-w- C:\WINDOWS\Sysnative\NvIFR64.dll 2015-10-29 14:00:41 32F7D679586BED9A0ECE27A10D01BE29 467912 ----a-w- C:\WINDOWS\Sysnative\nvumdshimx.dll 2015-10-29 14:00:41 1872672A66D7F4ECAC13E0053B67D2EB 151368 ----a-w- C:\WINDOWS\Sysnative\nvoglshim64.dll 2015-10-29 14:00:41 0A08F751E67CE3243510D73EB8C1AD08 16541040 ----a-w- C:\WINDOWS\Sysnative\nvopencl.dll 2015-10-29 14:00:40 CE8721EFF79A61DC4B6C8EF9A491CA57 15716648 ----a-w- C:\WINDOWS\Sysnative\nvd3dumx.dll 2015-10-29 14:00:40 9E9BBDB7D51C4EC2FF46C9136BA23DA8 14832968 ----a-w- C:\WINDOWS\Sysnative\nvcuda.dll 2015-10-29 14:00:40 97840DE99D1A3AB1D8DD7612462F84F1 1564976 ----a-w- C:\WINDOWS\Sysnative\nvdispgenco6435850.dll 2015-10-29 14:00:40 8C354FBC45770394E849B15759AC5141 1905456 ----a-w- C:\WINDOWS\Sysnative\nvdispco6435850.dll 2015-10-29 14:00:40 78D4994CD8BA0A2F26C41FF9E4D0E2A0 512720 ----a-w- C:\WINDOWS\Sysnative\nvEncodeAPI64.dll 2015-10-29 14:00:40 5FAB38629B6437F3D88FEC6C992F1F0F 877176 ----a-w- C:\WINDOWS\Sysnative\NvFBC64.dll 2015-10-29 14:00:40 42C15412420BD9B632CCEEA42AEEDD9B 2869880 ----a-w- C:\WINDOWS\Sysnative\nvcuvid.dll 2015-10-29 14:00:38 717F412E2DF3CDCAD8906142D4CBCD7D 42914096 ----a-w- C:\WINDOWS\Sysnative\nvcompiler.dll 2015-10-24 15:36:44 926C753C058B5E589CF38AAC72166702 414559 ----a-w- C:\WINDOWS\Sysnative\ApnDatabase.xml 2015-10-24 15:36:23 92B4B6CF81B02428A87441EF93AE21FD 4176384 ----a-w- C:\WINDOWS\Sysnative\win32k.sys 2015-10-24 15:32:47 C3838F0B943E21CB254568AD76C4E970 1091584 ----a-w- C:\WINDOWS\Sysnative\localspl.dll 2015-10-24 15:32:46 704A9947D4A8323FA8B1508340B3A27E 477184 ----a-w- C:\WINDOWS\Sysnative\puiobj.dll 2015-10-24 15:27:12 23E9833ADB8D04EBCCCC5BD28E072ACE 1380048 ----a-w- C:\WINDOWS\Sysnative\gdi32.dll 2015-10-24 15:26:48 1708E23F8FC2DDE8560A6EC60D942935 183368 ----a-w- C:\WINDOWS\Sysnative\AuthHost.exe ====== C:\WINDOWS\Sysnative\drivers ===== 2015-10-29 14:00:41 36BAB895547EA82892292F05FA02142E 11114616 ----a-w- C:\WINDOWS\Sysnative\drivers\nvlddmkm.sys 2015-10-29 14:00:41 2464570B44EAC56308669A04FBA1CD81 31352 ----a-w- C:\WINDOWS\Sysnative\drivers\nvpciflt.sys 2015-10-29 13:04:36 799F70FF787F4F68E7EA02FEABAC9FAB 307352 ----a-w- C:\WINDOWS\Sysnative\drivers\tmcomm.sys 2015-10-24 15:36:00 E85916632CD3B9E9B546968DB950BF42 154112 ----a-w- C:\WINDOWS\Sysnative\drivers\tunnel.sys 2015-10-24 15:33:37 80A2FC1A089A71F2DBE5D8394FFB009F 155480 -c--a-w- C:\WINDOWS\Sysnative\drivers\tpm.sys 2015-10-12 14:40:43 68F242EA45FF2AAC1012A9765A97DC7D 31328 ----a-w- C:\WINDOWS\Sysnative\drivers\rspSanity64.sys ====== C:\WINDOWS\Tasks ====== 2015-10-18 13:58:01 C3D4523284690A1255602B8611360EF0 4072 ----a-w- C:\WINDOWS\Sysnative\Tasks\GoogleUpdateTaskMachineUA 2015-10-18 13:58:01 A27042220A9466E7455A10A0170E6BAE 3836 ----a-w- C:\WINDOWS\Sysnative\Tasks\GoogleUpdateTaskMachineCore 2015-10-18 13:58:01 568EB28F0EE295650AA98B5D6A8D154A 1100 ----a-w- C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job 2015-10-18 13:58:00 59D596375FD6ECD5FA6A9628C31FA704 1096 ----a-w- C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job ====== C:\WINDOWS\Temp ====== ======= C:\Program Files ===== 2015-10-31 12:33:19 -------- d-----w- C:\Program Files\trend micro 2015-10-30 11:45:50 -------- d-----w- C:\Program Files\Speccy 2015-10-12 14:41:17 -------- d-----w- C:\Program Files\AntiFreeze 2015-10-12 14:40:43 -------- d-----w- C:\Program Files\SanityCheck 2015-10-12 11:18:11 -------- d-----w- C:\Program Files\Application Verifier 2015-10-12 11:08:35 -------- d-----w- C:\Program Files\DebugDiag 2015-10-05 22:11:53 -------- d-----w- C:\Program Files\Common Files\AV ======= C:\PROGRA~2 ===== 2015-10-29 12:54:05 -------- d-----w- C:\PROGRA~2\FileASSASSIN 2015-10-24 18:07:44 -------- d-----w- C:\PROGRA~2\NirSoft 2015-10-20 20:46:54 -------- d-----w- C:\PROGRA~2\VS Revo Group 2015-10-19 18:25:32 -------- d-----w- C:\PROGRA~2\TagScanner 2015-10-18 18:50:17 -------- d-----w- C:\PROGRA~2\Last.fm 2015-10-18 13:57:28 -------- d-----w- C:\PROGRA~2\Google 2015-10-13 13:12:11 -------- d-----w- C:\PROGRA~2\MozBackup 2015-10-12 14:12:16 -------- d-----w- C:\PROGRA~2\ESET 2015-10-12 11:18:13 -------- d-----w- C:\PROGRA~2\Microsoft SDKs 2015-10-12 11:18:11 -------- d-----w- C:\PROGRA~2\Application Verifier 2015-10-12 11:17:21 -------- d-----w- C:\PROGRA~2\Windows Kits 2015-10-12 11:17:21 -------- d-----w- C:\PROGRA~2\COMMON~1\Microsoft 2015-10-04 14:32:46 -------- d-----w- C:\PROGRA~2\VideoLAN ======= C: ===== ====== C:\Users\Olaf De Wit VolBeh\AppData\Roaming ====== 2015-11-01 13:36:05 -------- d-s---w- C:\Users\DefaultAppPool\AppData\Roaming\Microsoft 2015-11-01 13:36:05 -------- d-----w- C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance 2015-11-01 13:36:05 -------- d-----w- C:\Users\DefaultAppPool\AppData\Local\Temp 2015-11-01 13:36:05 -------- d-----w- C:\Users\DefaultAppPool\AppData\Local\Microsoft 2015-11-01 13:36:05 -------- d-----r- C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools 2015-11-01 13:36:05 -------- d-----r- C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories 2015-11-01 13:36:05 -------- d-----r- C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility 2015-10-29 14:08:12 -------- d-----w- C:\Users\Olaf De Wit VolBeh\AppData\Roaming\Leadertech 2015-10-29 14:05:30 1D76C988050213AF00E6B1DBF61ACAED 193032 ----a-w- C:\WINDOWS\serviceprofiles\Localservice\AppData\Local\FontCache3.0.0.0.dat 2015-10-29 13:53:34 -------- d-----w- C:\Users\Olaf De Wit VolBeh\AppData\Locallow\Apple Computer 2015-10-29 13:09:08 B656D6C6CA35384C36EEE7792935229E 10 ----a-w- C:\Users\Olaf De Wit VolBeh\AppData\Local\sponge.last.runtime.cache 2015-10-29 13:04:31 4E51A5A81972C170E0BB6DA92231B8F7 36 ----a-w- C:\Users\Olaf De Wit VolBeh\AppData\Local\housecall.guid.cache 2015-10-28 19:18:38 -------- d-----w- C:\Users\Olaf De Wit VolBeh\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dell 2015-10-27 21:14:28 CD5888C8E3E0416D10A50CFBA2424BEF 6642 ----a-w- C:\Users\Olaf De Wit VolBeh\AppData\Local\Temp20.html 2015-10-27 19:20:58 -------- d-----w- C:\Users\Olaf De Wit VolBeh\AppData\Locallow\PCDr 2015-10-24 18:07:44 -------- d-----w- C:\Users\Olaf De Wit VolBeh\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NirSoft WebBrowserPassView 2015-10-20 20:46:54 -------- d-----w- C:\Users\Olaf De Wit VolBeh\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller 2015-10-20 14:04:14 -------- d-----w- C:\Users\Olaf De Wit VolBeh\AppData\Local\Diagnostics 2015-10-19 18:25:35 -------- d-----w- C:\Users\Olaf De Wit VolBeh\AppData\Roaming\TagScanner 2015-10-18 18:50:17 -------- d-----w- C:\Users\Olaf De Wit VolBeh\AppData\Local\Last.fm 2015-10-18 13:58:13 -------- d-----w- C:\Users\Olaf De Wit VolBeh\AppData\Locallow\Google 2015-10-18 13:57:26 -------- d-----w- C:\Users\Olaf De Wit VolBeh\AppData\Local\Google 2015-10-12 14:47:45 9C1357D0F704E9D979BFD357744E1A30 1293 ----a-w- C:\Users\Olaf De Wit VolBeh\AppData\Local\Temp1.html 2015-10-08 18:36:03 -------- d-----w- C:\Users\Olaf De Wit VolBeh\AppData\Roaming\VASCO 2015-10-08 18:35:58 -------- d-----w- C:\Users\Olaf De Wit VolBeh\AppData\Local\Package Cache 2015-10-05 20:42:04 -------- d-----r- C:\Users\Olaf De Wit VolBeh\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BT Devices 2015-10-04 14:33:15 -------- d-----w- C:\Users\Olaf De Wit VolBeh\AppData\Roaming\vlc ====== C:\Users\Olaf De Wit VolBeh ====== 2015-11-02 19:44:21 7DB0062B983649071250EAA06662213D 157056744 ----a-w- C:\Users\Olaf De Wit VolBeh\Downloads\ExterminateItSetup.exe 2015-11-02 19:28:22 33A3664CFB2F39421C01363D1A0976E2 2198016 ----a-w- C:\Users\Olaf De Wit VolBeh\Downloads\FRST64.exe 2015-11-02 13:02:16 0170A4503F85F2D7ABCBEF0419B1C35A 4404952 ----a-w- C:\Users\Olaf De Wit VolBeh\Downloads\tdsskiller(2).exe 2015-11-02 12:59:53 3FE85FE8E673CC7C464A0F96774857AC 899072 ----a-w- C:\Users\Olaf De Wit VolBeh\Downloads\FSS.exe 2015-11-02 12:35:40 67B0906B68164E807BD5691C67696DA4 16563352 ----a-w- C:\Users\Olaf De Wit VolBeh\Downloads\mbar-1.09.3.1001(1).exe 2015-11-02 12:35:09 DF274465326DE9B3227B36BFFF49EDFF 16563304 ----a-w- C:\Users\Olaf De Wit VolBeh\Downloads\mbar-1.09.2.1008.exe 2015-11-01 14:09:06 0FF28E91F00CA285FB51C72388A8EDEE 417064 ----a-w- C:\Users\Olaf De Wit VolBeh\Downloads\DellSystemDetectLauncher.exe 2015-11-01 13:36:06 6FC234AD3752E1267B34FB12BCD6718B 20 --sh--w- C:\Users\DefaultAppPool\ntuser.ini 2015-11-01 13:36:05 -------- d--h--w- C:\Users\DefaultAppPool\AppData 2015-11-01 13:36:05 -------- d-----w- C:\Users\DefaultAppPool\Saved Games 2015-11-01 13:36:05 -------- d-----r- C:\Users\DefaultAppPool\Videos 2015-11-01 13:36:05 -------- d-----r- C:\Users\DefaultAppPool\Pictures 2015-11-01 13:36:05 -------- d-----r- C:\Users\DefaultAppPool\Music 2015-11-01 13:36:05 -------- d-----r- C:\Users\DefaultAppPool\Links 2015-11-01 13:36:05 -------- d-----r- C:\Users\DefaultAppPool\Favorites 2015-11-01 13:36:05 -------- d-----r- C:\Users\DefaultAppPool\Downloads 2015-11-01 13:36:05 -------- d-----r- C:\Users\DefaultAppPool\Documents 2015-11-01 13:36:05 -------- d-----r- C:\Users\DefaultAppPool\Desktop 2015-10-31 12:32:27 8045ABB21A3BDD66A48E1ED5C0F0EF6A 1222144 ----a-w- C:\Users\Olaf De Wit VolBeh\Downloads\RSITx64.exe 2015-10-30 11:45:51 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Speccy 2015-10-30 11:45:44 678AB0E8665345E72D11149A36F965BE 5127432 ----a-w- C:\Users\Olaf De Wit VolBeh\Downloads\spsetup128(1).exe 2015-10-30 11:45:27 678AB0E8665345E72D11149A36F965BE 5127432 ----a-w- C:\Users\Olaf De Wit VolBeh\Downloads\spsetup128.exe 2015-10-29 18:42:39 BCDD3B2A06D3CB474A5A6FA66AA54BFD 411280 ----a-w- C:\Users\Olaf De Wit VolBeh\Downloads\driver-updater-setup.exe 2015-10-29 13:53:21 82BFFBEB5515CB43089299D111125CE4 42096984 ----a-w- C:\Users\Olaf De Wit VolBeh\Downloads\QuickTimeInstaller.exe 2015-10-29 13:04:18 57E86EA1E1AEBF898496F38D10A57664 2494560 ----a-w- C:\Users\Olaf De Wit VolBeh\Downloads\HousecallLauncher64.exe 2015-10-29 12:54:05 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FileASSASSIN 2015-10-29 12:53:49 51FB1297571DF6454EF4AE9B94E86E81 167034 ----a-w- C:\Users\Olaf De Wit VolBeh\Downloads\fileassassin-setup-1.06.exe 2015-10-28 18:23:50 FFCFF1A3D604380ABE05E46706BE1F81 10402664 ----a-w- C:\Users\Olaf De Wit VolBeh\Downloads\DriverTalent_setup.exe 2015-10-27 21:05:27 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome 2015-10-27 21:03:27 B646E79945A670214BE6B285A3C4DCF3 929872 ----a-w- C:\Users\Olaf De Wit VolBeh\Downloads\ChromeSetup.exe 2015-10-27 20:23:21 B5C721C25688EAE177170AF951832DBE 23925040 ----a-w- C:\Users\Olaf De Wit VolBeh\Downloads\XPS-8700_Serial-ATA_Driver_89G40_WN_12.8.0.1016_A00(1).EXE 2015-10-27 20:23:01 8C2CA61CFC106F05618ADEEA6DCE53E4 15251504 ----a-w- C:\Users\Olaf De Wit VolBeh\Downloads\XPS-8700_Network_Driver_78K1K_WN_8.018_A00.EXE 2015-10-27 20:21:57 C1770D59556AAAF54CBFDC22BFCB6172 83218416 ----a-w- C:\Users\Olaf De Wit VolBeh\Downloads\XPS-8700_Chipset_Driver_DMNV3_WN_10.0.0.1126_A02.EXE 2015-10-27 20:21:50 A4898B916971B821A5258196BB76F96B 12170088 ----a-w- C:\Users\Olaf De Wit VolBeh\Downloads\XPS-8700_Chipset_Driver_V2D47_WN_9.4.0.1021_A00.EXE 2015-10-27 20:21:19 B9153D45576138C96879F2FDEB2C8062 13926088 ----a-w- C:\Users\Olaf De Wit VolBeh\Downloads\XPS_8700_BIOS_A11(1).EXE 2015-10-27 20:20:25 39E982DBE41AB8A14C5A39B9E716C50E 231285744 ----a-w- C:\Users\Olaf De Wit VolBeh\Downloads\XPS-8700_Audio_Driver_N4TKF_WN_6.0.1.7016_A00(2).EXE 2015-10-27 19:40:28 06D1F2BD3018BFDF91945F573ECA7682 5503236 ----a-w- C:\Users\Olaf De Wit VolBeh\Downloads\FurMark_1.17.0.0_Setup.exe 2015-10-27 10:30:26 B7B4656E0DB41DB4C677A324CC0F5DE5 6762072 ----a-w- C:\Users\Olaf De Wit VolBeh\Downloads\ccsetup511.exe 2015-10-24 22:33:04 7C1965DA9BE143B4B548F2FBE5A80F48 522600 ----a-w- C:\Users\Olaf De Wit VolBeh\Downloads\mvsuninst.exe 2015-10-24 18:07:12 E3FDE3353B3502CB5A4A66E02B61F706 283440 ----a-w- C:\Users\Olaf De Wit VolBeh\Downloads\webbrowserpassview_setup.exe 2015-10-22 10:15:39 6C00C7D6E5D14C6BCE59F82E5F5E4D1A 46834816 ----a-w- C:\Users\Olaf De Wit VolBeh\Downloads\SkypeSetupFull(2).exe 2015-10-20 20:46:08 4F99CAE27FFD46712E65C21444AACDFC 2623656 ----a-w- C:\Users\Olaf De Wit VolBeh\Downloads\revosetup.exe 2015-10-20 20:21:25 2BA431783A9799F716DB33C478C0CBC5 4765864 ----a-w- C:\Users\Olaf De Wit VolBeh\Downloads\MaxUninstaller_Setup.exe 2015-10-20 13:43:04 A0844C730F1091B491A8737404F4C914 347816 ----a-w- C:\Users\Olaf De Wit VolBeh\Downloads\MicrosoftFixit.Aero.Run.exe 2015-10-20 12:46:53 B5C721C25688EAE177170AF951832DBE 23925040 ----a-w- C:\Users\Olaf De Wit VolBeh\Downloads\XPS-8700_Serial-ATA_Driver_89G40_WN_12.8.0.1016_A00.EXE 2015-10-20 12:46:04 B9153D45576138C96879F2FDEB2C8062 13926088 ----a-w- C:\Users\Olaf De Wit VolBeh\Downloads\XPS_8700_BIOS_A11.EXE 2015-10-20 12:45:10 39E982DBE41AB8A14C5A39B9E716C50E 231285744 ----a-w- C:\Users\Olaf De Wit VolBeh\Downloads\XPS-8700_Audio_Driver_N4TKF_WN_6.0.1.7016_A00(1).EXE 2015-10-19 18:25:32 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TagScanner 2015-10-18 18:51:06 -------- d-----w- C:\ProgramData\Last.fm 2015-10-18 18:50:20 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Last.fm 2015-10-13 13:12:11 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MozBackup 2015-10-13 13:10:41 -------- d-----w- C:\ProgramData\Mozilla 2015-10-12 14:41:17 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AntiFreeze 2015-10-12 14:40:43 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SanityCheck 2015-10-12 11:18:27 -------- d-----w- C:\ProgramData\Windows App Certification Kit 2015-10-12 11:17:28 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Kits 2015-10-12 11:08:36 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Debug Diagnostics Tool 2 2015-10-04 14:32:54 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN ====== C: exe-files == 2015-11-02 19:44:21 7DB0062B983649071250EAA06662213D 157056744 ----a-w- C:\Users\Olaf De Wit VolBeh\Downloads\ExterminateItSetup.exe 2015-11-02 19:28:22 33A3664CFB2F39421C01363D1A0976E2 2198016 ----a-w- C:\Users\Olaf De Wit VolBeh\Downloads\FRST64.exe 2015-11-02 13:02:16 0170A4503F85F2D7ABCBEF0419B1C35A 4404952 ----a-w- C:\Users\Olaf De Wit VolBeh\Downloads\tdsskiller(2).exe 2015-11-02 12:59:53 3FE85FE8E673CC7C464A0F96774857AC 899072 ----a-w- C:\Users\Olaf De Wit VolBeh\Downloads\FSS.exe 2015-11-02 12:35:40 67B0906B68164E807BD5691C67696DA4 16563352 ----a-w- C:\Users\Olaf De Wit VolBeh\Downloads\mbar-1.09.3.1001(1).exe 2015-11-02 12:35:09 DF274465326DE9B3227B36BFFF49EDFF 16563304 ----a-w- C:\Users\Olaf De Wit VolBeh\Downloads\mbar-1.09.2.1008.exe 2015-11-01 14:09:06 0FF28E91F00CA285FB51C72388A8EDEE 417064 ----a-w- C:\Users\Olaf De Wit VolBeh\Downloads\DellSystemDetectLauncher.exe 2015-10-31 12:33:23 9A2347903D6EDB84C10F288BC0578C1C 388608 ----a-w- C:\Program Files\trend micro\Olaf De Wit VolBeh.exe 2015-10-31 12:32:27 8045ABB21A3BDD66A48E1ED5C0F0EF6A 1222144 ----a-w- C:\Users\Olaf De Wit VolBeh\Downloads\RSITx64.exe 2015-10-30 13:14:07 F82E1290E57237E37E3F1D420B5B77F3 353304 ----a-w- C:\Users\Olaf De Wit VolBeh\AppData\Local\NVIDIA\NvBackend\Packages\00007fa2\DRS update.20028384.exe 2015-10-30 13:14:07 35D3714B45238297DFA2A517D95F9BC2 6729440 ----a-w- C:\Users\Olaf De Wit VolBeh\AppData\Local\NVIDIA\NvBackend\Packages\000081f1\DAO.20116488.exe 2015-10-30 11:45:44 678AB0E8665345E72D11149A36F965BE 5127432 ----a-w- C:\Users\Olaf De Wit VolBeh\Downloads\spsetup128(1).exe 2015-10-30 11:45:27 678AB0E8665345E72D11149A36F965BE 5127432 ----a-w- C:\Users\Olaf De Wit VolBeh\Downloads\spsetup128.exe 2015-10-29 18:42:39 BCDD3B2A06D3CB474A5A6FA66AA54BFD 411280 ----a-w- C:\Users\Olaf De Wit VolBeh\Downloads\driver-updater-setup.exe 2015-10-29 14:02:22 C92D3FF896851D670F2117F28CD47A13 896120 ----a-w- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\NvStereoUtilityOGL.exe 2015-10-29 14:02:22 C368FAF3084E3978462159F1DDAFF54F 417400 ----a-w- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe 2015-10-29 14:02:22 BEB5304E5DFCDC6ED4B23005EBAA2570 2402936 ----a-w- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvsttest.exe 2015-10-29 14:02:22 B5EE32AABD5B5DCDB2D79FE460423953 102520 ----a-w- C:\Windows\SysWOW64\nvStreaming.exe 2015-10-29 14:02:22 881F692DABDD8E8A70D7D5085E8E24BE 7846008 ----a-w- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\NVStWiz.exe 2015-10-29 14:02:22 30D7D12AD020E246BC371EAD16546C23 596600 ----a-w- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvstlink.exe 2015-10-29 14:02:22 087D293FC553B2581991733CBB023943 316024 ----a-w- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvStInst.exe 2015-10-29 14:02:22 0551616785A2BAA1CFFDBAEBBEDBB40E 437368 ----a-w- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvstreg.exe 2015-10-29 14:02:22 022123738C242EDEC0714DABE0995172 1691256 ----a-w- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvstview.exe 2015-10-29 14:00:42 662DF9C8F85D78899BD6115CB7139F41 18169888 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\Display.3DVision.{A087B828-218F-4608-95CD-83ACE81124C3}\3DVision.exe 2015-10-29 14:00:38 9628B1202D594513D22CB429EEC43B8B 94908208 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\Display.Driver.{14E01C3F-39F8-43E2-BCC2-15FBE10F5209}\NvCplSetupInt.exe 2015-10-29 14:00:38 028ED92AC9D5EFCB26DADDBC9DC7773C 449144 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\Display.Driver.{14E01C3F-39F8-43E2-BCC2-15FBE10F5209}\dbInstaller.exe 2015-10-29 14:00:38 028ED92AC9D5EFCB26DADDBC9DC7773C 449144 ----a-w- C:\Program Files\NVIDIA Corporation\Drs\dbInstaller.exe 2015-10-29 14:00:20 5B886015E9D392FB2BFC2C93F7FF16F2 1872504 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\installer.{47F78174-D7BB-42B4-991E-E410E6CA1AD4}\NVNetworkService.exe 2015-10-29 13:53:21 82BFFBEB5515CB43089299D111125CE4 42096984 ----a-w- C:\Users\Olaf De Wit VolBeh\Downloads\QuickTimeInstaller.exe 2015-10-29 13:44:12 8B94E11034BAADEE1A6F8619265D0A1F 630200 ----a-w- C:\Users\Olaf De Wit VolBeh\AppData\Local\NVIDIA\NvBackend\ApplicationOntology\NvOAWrapperCache.exe 2015-10-29 13:44:08 98E64402F9C85AA1777DA5F6152A5EE4 172984 ----a-w- C:\Users\Olaf De Wit VolBeh\AppData\Local\NVIDIA\NvBackend\ApplicationOntology\OAWrapper.exe 2015-10-29 13:13:00 E4814E148EB1A44855252025D9A12C69 1873696 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\installer.{7BB919E7-B8F8-4A81-8A80-69F6C2987F72}\NVNetworkService.exe 2015-10-29 13:04:18 57E86EA1E1AEBF898496F38D10A57664 2494560 ----a-w- C:\Users\Olaf De Wit VolBeh\Downloads\HousecallLauncher64.exe 2015-10-29 12:54:05 0D4D1BA51BF0C1480AEAAF79E0EBE995 69223 ----a-w- C:\Program Files (x86)\FileASSASSIN\uninst.exe 2015-10-29 12:53:49 51FB1297571DF6454EF4AE9B94E86E81 167034 ----a-w- C:\Users\Olaf De Wit VolBeh\Downloads\fileassassin-setup-1.06.exe 2015-10-28 18:23:50 FFCFF1A3D604380ABE05E46706BE1F81 10402664 ----a-w- C:\Users\Olaf De Wit VolBeh\Downloads\DriverTalent_setup.exe 2015-10-28 17:49:06 B89A82FB10E98F2FDF51FA82C7366DD3 1067736 ----a-w- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe 2015-10-28 17:49:06 A052067B947DBFBB65921D01E290DD15 404712 ----a-w- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARMHelper.exe 2015-10-28 17:49:06 5DB2C6B908C50767E2EDAA294A7566B5 82128 ----a-w- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe 2015-10-28 12:21:17 5DB315E7300F28688D1D34CCC80F882F 217768 ----a-w- C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE15\MSOXMLED.EXE 2015-10-28 12:21:16 8967005E701E706F26C591FDAA93E4A0 842448 ----a-w- C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonX86\Microsoft Shared\DW\DW20.EXE 2015-10-28 12:21:16 6F822401C55D4855103C081DAC36D4FA 552024 ----a-w- C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonX86\Microsoft Shared\OFFICE15\MSOSQM.EXE 2015-10-28 12:21:16 1C7E035C643042A4B9A39902606E1C48 162912 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\MSOSREC.EXE 2015-10-28 12:21:15 9DF88D2F930F05E83716107664FEEE3E 39592 ----a-w- C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\AppSharingHookController64.exe 2015-10-28 12:21:15 6FC6BAEF5331AB01798E0845BFA7DB4A 85648 ----a-w- C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonX86\Microsoft Shared\OFFICE15\CSISYNCCLIENT.EXE 2015-10-28 12:21:15 306F8D7102574928D84E5392C4062476 7921880 ----a-w- C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE15\CMigrate.exe 2015-10-28 12:21:14 B93A4ACCBD65B22746547BB3951EA79C 208968 ----a-w- C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonX86\Microsoft Shared\OFFICE15\MSOXMLED.EXE 2015-10-28 12:21:14 4E5225DA5AF8890879EF8D49927F8484 5790936 ----a-w- C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonX86\Microsoft Shared\OFFICE15\CMigrate.exe 2015-10-28 12:21:12 D2C61021D86088294ED4656316382ABD 875088 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\protocolhandler.exe 2015-10-28 12:21:12 AFF9283E03168A138C65889F7FDDEB0C 475784 ----a-w- C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonX86\Microsoft Shared\DW\DWTRIG20.EXE 2015-10-28 12:21:06 51F2CF40E23F4D09C13AD36D616957A4 1137776 ----a-w- C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonX86\Microsoft Shared\OFFICE15\OLicenseHeartbeat.exe 2015-10-28 12:21:05 A11B3DDAC83426F4BCB974EC073E07BC 230488 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\CLVIEW.EXE 2015-10-28 12:21:05 844ACFA793A54B732F987CBEE1FEA1D8 51824 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\SETLANG.EXE 2015-10-28 12:21:05 3AF8D6CE60EA6BF2AC13D3AF32097D41 500320 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\MSOUC.EXE 2015-10-28 12:21:04 DBAD1B0DEB8A1A770046DEF27CE37231 518792 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\IEContentService.exe 2015-10-28 12:21:04 8BCDF5A7713004D23ED368FB17756194 22411936 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\excelcnv.exe 2015-10-28 12:21:04 896DAFAD1B52D5014C1773DEDA6505BD 4523616 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\GRAPH.EXE 2015-10-28 12:21:04 4A1A56C616BD56A650B8C677EB733312 569592 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\ORGCHART.EXE 2015-10-28 12:21:04 3338695CBCAFB36B80780C0AEF04077C 482416 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\SELFCERT.EXE 2015-10-28 12:21:03 963B82953E3634B488598DB3F6BF848A 530016 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\VPREVIEW.EXE 2015-10-28 12:20:55 D3694CC2F1D0A11048ED042638C4971A 632432 ----a-w- C:\Program Files\Microsoft Office 15\root\Integration\Integrator.exe 2015-10-28 12:20:43 A3EA1A5B1121F1DB0C99C3C3A842D4B8 18965160 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\OUTLOOK.EXE 2015-10-28 12:20:42 EAD7B17BA8989FA0DDD8F4AB30125FF7 1764424 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\ONENOTE.EXE 2015-10-28 12:20:37 56FD9A3AA67C7676717D64E3ADE5E030 1924672 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\WINWORD.EXE 2015-10-28 12:20:36 208C3BBEA648F93CA58622049FF680D5 26200736 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\EXCEL.EXE 2015-10-28 12:20:34 3E45AB9A253189CEAB896A8693EBFB71 991808 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\FIRSTRUN.EXE 2015-10-28 12:20:20 56F1644FE430EBB656874EE8AB3E27A3 592800 ----a-w- C:\Users\Olaf De Wit VolBeh\AppData\Local\NVIDIA\NvBackend\Packages\000081d0\CoProc update.20110886.exe 2015-10-27 21:05:21 76E6FD35E44C715E5DA9F99982E7513D 43326544 ----a-w- C:\Program Files (x86)\Google\Update\Install\{0284521B-A236-4186-A403-76C205CC25B8}\46.0.2490.80_chrome_installer.exe 2015-10-27 21:05:20 76E6FD35E44C715E5DA9F99982E7513D 43326544 ----a-w- C:\Program Files (x86)\Google\Update\Download\{8A69D345-D564-463C-AFF1-A69D9E530F96}\46.0.2490.80\46.0.2490.80_chrome_installer.exe 2015-10-27 21:03:27 B646E79945A670214BE6B285A3C4DCF3 929872 ----a-w- C:\Users\Olaf De Wit VolBeh\Downloads\ChromeSetup.exe 2015-10-27 20:23:21 B5C721C25688EAE177170AF951832DBE 23925040 ----a-w- C:\Users\Olaf De Wit VolBeh\Downloads\XPS-8700_Serial-ATA_Driver_89G40_WN_12.8.0.1016_A00(1).EXE 2015-10-27 20:23:01 8C2CA61CFC106F05618ADEEA6DCE53E4 15251504 ----a-w- C:\Users\Olaf De Wit VolBeh\Downloads\XPS-8700_Network_Driver_78K1K_WN_8.018_A00.EXE 2015-10-27 20:21:57 C1770D59556AAAF54CBFDC22BFCB6172 83218416 ----a-w- C:\Users\Olaf De Wit VolBeh\Downloads\XPS-8700_Chipset_Driver_DMNV3_WN_10.0.0.1126_A02.EXE 2015-10-27 20:21:50 A4898B916971B821A5258196BB76F96B 12170088 ----a-w- C:\Users\Olaf De Wit VolBeh\Downloads\XPS-8700_Chipset_Driver_V2D47_WN_9.4.0.1021_A00.EXE 2015-10-27 20:21:19 B9153D45576138C96879F2FDEB2C8062 13926088 ----a-w- C:\Users\Olaf De Wit VolBeh\Downloads\XPS_8700_BIOS_A11(1).EXE 2015-10-27 20:20:25 39E982DBE41AB8A14C5A39B9E716C50E 231285744 ----a-w- C:\Users\Olaf De Wit VolBeh\Downloads\XPS-8700_Audio_Driver_N4TKF_WN_6.0.1.7016_A00(2).EXE 2015-10-27 19:40:28 06D1F2BD3018BFDF91945F573ECA7682 5503236 ----a-w- C:\Users\Olaf De Wit VolBeh\Downloads\FurMark_1.17.0.0_Setup.exe === C: other files == 2015-11-02 19:21:29 F97DBEAABB2FA40CB5ED896FDDD399D9 987 ----a-w- C:\Windows\System32\RightClickFiles\HideFile.vbs 2015-11-02 19:21:29 F220DCB7B83BD58D292B83EFC2529193 386 ----a-w- C:\Windows\System32\RightClickFiles\SelectAll.vbs 2015-11-02 19:21:29 30CF9BBD8699FD9595F59AEA32A75CAD 1013 ----a-w- C:\Windows\System32\RightClickFiles\ShowFile.vbs 2015-11-02 19:21:29 174D8E8CF4E5DED063AEF64C455564A2 662 ----a-w- C:\Windows\System32\RightClickFiles\WallLocation.vbs 2015-11-02 19:20:45 24F389B9E71821CB4FCAF503D1E46C2D 467950 ----a-w- C:\Users\Olaf De Wit VolBeh\Downloads\Right-Click Extender.zip 2015-11-02 19:08:01 E19B79CBF1B4B5522A1B9B32FC61AC63 97609 ----a-w- C:\Users\Olaf De Wit VolBeh\Downloads\shexview-x64.zip 2015-11-02 19:07:39 26FB028497CD5F59C89BC091B38A9C83 76723 ----a-w- C:\Users\Olaf De Wit VolBeh\Downloads\whatishang-x64.zip 2015-11-02 12:53:08 9E0C9F71AC4823F3A28DDACA212423A8 120696 ----a-w- C:\Users\Olaf De Wit VolBeh\AppData\Roaming\Mozilla\Firefox\Profiles\xe7710xq.default\extensions\elemhidehelper@adblockplus.org.xpi 2015-10-29 14:00:42 5FAE3141271AAF8A43951487C973825D 454752 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\Display.NVIRUSB.{4CD519DA-D435-4512-9D90-E374D38F4923}\nvstusb32.sys 2015-10-29 14:00:42 43DB182DC821C322C9EE8E936B82D8FB 469688 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\Display.NVIRUSB.{4CD519DA-D435-4512-9D90-E374D38F4923}\nvstusb64.sys 2015-10-29 14:00:41 F38FA119FBFCEC7ADC062E6244440E44 136624 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\HDAudio.Driver.{80829745-32E7-4240-B322-8C09EB5F6252}\nvhda32.sys 2015-10-29 14:00:41 B9E5A80F646DDFEF158773722A466EA3 204648 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\HDAudio.Driver.{80829745-32E7-4240-B322-8C09EB5F6252}\nvhda64v.sys 2015-10-29 14:00:41 7F17CB0F4AD4B30703BBC0529D35D1F0 171352 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\HDAudio.Driver.{80829745-32E7-4240-B322-8C09EB5F6252}\nvhda32v.sys 2015-10-29 14:00:41 66BC79AEBAAA9B6B3ED4616E2F359B88 171352 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\HDAudio.Driver.{80829745-32E7-4240-B322-8C09EB5F6252}\nvhda64.sys 2015-10-29 14:00:41 36BAB895547EA82892292F05FA02142E 11114616 ----a-w- C:\Windows\System32\drivers\nvlddmkm.sys 2015-10-29 14:00:41 2464570B44EAC56308669A04FBA1CD81 31352 ----a-w- C:\Windows\System32\drivers\nvpciflt.sys 2015-10-29 13:13:07 C2A9985C97DF5946AEAE7C001625410C 44840 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\VirtualAudio.Driver.{1B892315-1AEE-4DB0-820B-26343BFB124B}\nvvad32v.sys 2015-10-29 13:13:07 9D9CAD70EA640AB8D3EB77BFAE6CABE2 28344 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\ShieldWirelessController.{4BA3181B-D5C5-412F-BE21-6CBEC4141C4A}\NVSWCFilter64.sys 2015-10-29 13:13:07 7ABD081BB7A1A8CF7E3B1E64183AB812 24760 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\ShieldWirelessController.{4BA3181B-D5C5-412F-BE21-6CBEC4141C4A}\NVSWCFilter32.sys 2015-10-29 13:13:07 35DFC12FD7E44B7CB8CCD7E5A2B3975A 50472 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\VirtualAudio.Driver.{1B892315-1AEE-4DB0-820B-26343BFB124B}\nvvad64v.sys 2015-10-29 13:04:36 799F70FF787F4F68E7EA02FEABAC9FAB 307352 ----a-w- C:\Windows\System32\drivers\tmcomm.sys 2015-10-29 12:44:07 E3E654800EEE285D905DE80B2C22DE78 627032 ----a-w- C:\Users\Olaf De Wit VolBeh\Documents\FEBE 2015 29.10 13.44.05\VideoDownloadHelper{5.4.1}.xpi 2015-10-29 12:44:07 D3C93C178B785C6D8B0CDBA5F25F422B 26366 ----a-w- C:\Users\Olaf De Wit VolBeh\Documents\FEBE 2015 29.10 13.44.05\DownloadYouTubeVideosasMP4{1.8.3.1-signed}.xpi 2015-10-29 12:44:07 D1FBD16E7BF09FEBC21758A7B261EBEB 962762 ----a-w- C:\Users\Olaf De Wit VolBeh\Documents\FEBE 2015 29.10 13.44.05\AdblockPlus{2.6.11}.xpi 2015-10-29 12:44:07 C3F52D591990E9B0D2BFF71D42DDD973 518450 ----a-w- C:\Users\Olaf De Wit VolBeh\Documents\FEBE 2015 29.10 13.44.05\UnMHT{8.0.0}.xpi 2015-10-29 12:44:07 B70DBD5BF4BDACB3DD97BAEE00430428 144873 ----a-w- C:\Users\Olaf De Wit VolBeh\Documents\FEBE 2015 29.10 13.44.05\BetterPrivacy{1.68.1-signed}.xpi 2015-10-29 12:44:07 B50E2A3525F9517801A2A348BCBE1E57 77410 ----a-w- C:\Users\Olaf De Wit VolBeh\Documents\FEBE 2015 29.10 13.44.05\CookiesManager+{1.5.2.1-signed}.xpi 2015-10-29 12:44:07 B04C6914BA719ECE6FC09D6864CE9AF3 90114 ----a-w- C:\Users\Olaf De Wit VolBeh\Documents\FEBE 2015 29.10 13.44.05\Self-DestructingCookies{0.4.8}.xpi 2015-10-29 12:44:07 A082B748A3A75E55E3A92F8E3C0B1A49 1338573 ----a-w- C:\Users\Olaf De Wit VolBeh\Documents\FEBE 2015 29.10 13.44.05\FEBE{8.7.1-signed}.xpi 2015-10-29 12:44:07 9B84654562853AFAFDDAC4CE82F3D214 10671483 ----a-w- C:\Users\Olaf De Wit VolBeh\Documents\FEBE 2015 29.10 13.44.05\YoutubeDownloader-4KDownload{5.8.1}.xpi 2015-10-29 12:44:07 929748795C9032982686EC54462F1D1D 1548404 ----a-w- C:\Users\Olaf De Wit VolBeh\Documents\FEBE 2015 29.10 13.44.05\Ghostery{5.4.8.1}.xpi 2015-10-29 12:44:07 926FE5534C8E9B60A608B4D45DB3757E 10525460 ----a-w- C:\Users\Olaf De Wit VolBeh\Documents\FEBE 2015 29.10 13.44.05\FlashVideoDownloader-YouTubeHDDownload4K{8.1.1}.xpi 2015-10-29 12:44:07 920C70BE04FCFE6AA9DF6997B9D55B2E 255799 ----a-w- C:\Users\Olaf De Wit VolBeh\Documents\FEBE 2015 29.10 13.44.05\OPIE{5.0.2.1-signed}.xpi 2015-10-29 12:44:07 810C9870745E6EDABF15D5671B1904A1 1441990 ----a-w- C:\Users\Olaf De Wit VolBeh\Documents\FEBE 2015 29.10 13.44.05\uBlockOrigin{1.3.2}.xpi 2015-10-29 12:44:07 80FCCF278B6ED615267C0CB11BC4B8F5 29160 ----a-w- C:\Users\Olaf De Wit VolBeh\Documents\FEBE 2015 29.10 13.44.05\TheAddonBarrestored{3.2.1-signed}.xpi 2015-10-29 12:44:07 7E5797DFCC98F52961CF2DED245A78D4 38608 ----a-w- C:\Users\Olaf De Wit VolBeh\Documents\FEBE 2015 29.10 13.44.05\FlashStopper{1.2.9}.xpi 2015-10-29 12:44:07 790FCAB67547D1D3149AE00783060F28 102426 ----a-w- C:\Users\Olaf De Wit VolBeh\Documents\FEBE 2015 29.10 13.44.05\ClickClean{4.1.1-signed}.xpi 2015-10-29 12:44:07 657F32D91E6D0006ABD32124BD0CBCD2 240579 ----a-w- C:\Users\Olaf De Wit VolBeh\Documents\FEBE 2015 29.10 13.44.05\CookieKeeper{1.8.5.1-signed}.xpi 2015-10-29 12:44:07 6413244D4BAD5CC06E379FFA7EEAF64F 557479 ----a-w- C:\Users\Olaf De Wit VolBeh\Documents\FEBE 2015 29.10 13.44.05\SessionManager{0.8.1.7}.xpi 2015-10-29 12:44:07 54B290893F2C3ADEAD17D8F4D2A98D36 562123 ----a-w- C:\Users\Olaf De Wit VolBeh\Documents\FEBE 2015 29.10 13.44.05\NoScript{2.6.9.39}.xpi 2015-10-29 12:44:07 46F414EFB606C7DD30AA7A29E770C398 11228 ----a-w- C:\Users\Olaf De Wit VolBeh\Documents\FEBE 2015 29.10 13.44.05\BingSearch{1.0.0.2}.xpi 2015-10-29 12:44:07 449655D670B5907420A27DD533341EE1 106549 ----a-w- C:\Users\Olaf De Wit VolBeh\Documents\FEBE 2015 29.10 13.44.05\CLEO{6.0.1-signed}.xpi 2015-10-29 12:44:07 3128A8FA70BA4AF7AD4B86D16D1C64ED 54245 ----a-w- C:\Users\Olaf De Wit VolBeh\Documents\FEBE 2015 29.10 13.44.05\YouTubeFlashPlayer{1.4.0}.xpi 2015-10-29 12:44:07 12637F01584BEFE2468A39D6FA335869 292441 ----a-w- C:\Users\Olaf De Wit VolBeh\Documents\FEBE 2015 29.10 13.44.05\SpeedDial{0.9.6.18}.xpi 2015-10-29 12:44:07 072E6A21093BCD1AC11E22FDDF497BAD 67294 ----a-w- C:\Users\Olaf De Wit VolBeh\Documents\FEBE 2015 29.10 13.44.05\YouTubeFlashVideoPlayer{41.0}.xpi 2015-10-29 12:44:07 04D1FF939D99759DAB64323B69167AFC 80248 ----a-w- C:\Users\Olaf De Wit VolBeh\Documents\FEBE 2015 29.10 13.44.05\FlashControl{2.0.5}.xpi 2015-10-29 12:44:07 031338DF85EEC8B021C5D6F171E9D8EA 403013 ----a-w- C:\Users\Olaf De Wit VolBeh\Documents\FEBE 2015 29.10 13.44.05\VideoDownloaderprofessional{1.97.37.1-signed}.xpi 2015-10-27 20:03:48 BC800CC98DCF78051725F861117FF360 45901882 ----a-w- C:\Users\Olaf De Wit VolBeh\AppData\Local\ElevatedDiagnostics\2560293460\2015102720.000\DataStoreAndWULogFiles.zip 2015-10-27 19:41:10 4C155D4AD8B9C4215A4814B66E9037F1 5378177 ----a-w- C:\Users\Olaf De Wit VolBeh\Downloads\p95v285.win64(1).zip 2015-10-27 14:04:01 E3E654800EEE285D905DE80B2C22DE78 627032 ----a-w- C:\Users\Olaf De Wit VolBeh\Documents\FEBE 2015 27.10 15.03.59\VideoDownloadHelper{5.4.1}.xpi 2015-10-27 14:04:01 D3C93C178B785C6D8B0CDBA5F25F422B 26366 ----a-w- C:\Users\Olaf De Wit VolBeh\Documents\FEBE 2015 27.10 15.03.59\DownloadYouTubeVideosasMP4{1.8.3.1-signed}.xpi 2015-10-27 14:04:01 D1FBD16E7BF09FEBC21758A7B261EBEB 962762 ----a-w- C:\Users\Olaf De Wit VolBeh\Documents\FEBE 2015 27.10 15.03.59\AdblockPlus{2.6.11}.xpi 2015-10-27 14:04:01 C3F52D591990E9B0D2BFF71D42DDD973 518450 ----a-w- C:\Users\Olaf De Wit VolBeh\Documents\FEBE 2015 27.10 15.03.59\UnMHT{8.0.0}.xpi 2015-10-27 14:04:01 B70DBD5BF4BDACB3DD97BAEE00430428 144873 ----a-w- C:\Users\Olaf De Wit VolBeh\Documents\FEBE 2015 27.10 15.03.59\BetterPrivacy{1.68.1-signed}.xpi 2015-10-27 14:04:01 B50E2A3525F9517801A2A348BCBE1E57 77410 ----a-w- C:\Users\Olaf De Wit VolBeh\Documents\FEBE 2015 27.10 15.03.59\CookiesManager+{1.5.2.1-signed}.xpi 2015-10-27 14:04:01 B04C6914BA719ECE6FC09D6864CE9AF3 90114 ----a-w- C:\Users\Olaf De Wit VolBeh\Documents\FEBE 2015 27.10 15.03.59\Self-DestructingCookies{0.4.8}.xpi 2015-10-27 14:04:01 A082B748A3A75E55E3A92F8E3C0B1A49 1338573 ----a-w- C:\Users\Olaf De Wit VolBeh\Documents\FEBE 2015 27.10 15.03.59\FEBE{8.7.1-signed}.xpi 2015-10-27 14:04:01 9B84654562853AFAFDDAC4CE82F3D214 10671483 ----a-w- C:\Users\Olaf De Wit VolBeh\Documents\FEBE 2015 27.10 15.03.59\YoutubeDownloader-4KDownload{5.8.1}.xpi 2015-10-27 14:04:01 929748795C9032982686EC54462F1D1D 1548404 ----a-w- C:\Users\Olaf De Wit VolBeh\Documents\FEBE 2015 27.10 15.03.59\Ghostery{5.4.8.1}.xpi 2015-10-27 14:04:01 926FE5534C8E9B60A608B4D45DB3757E 10525460 ----a-w- C:\Users\Olaf De Wit VolBeh\Documents\FEBE 2015 27.10 15.03.59\FlashVideoDownloader-YouTubeHDDownload4K{8.1.1}.xpi 2015-10-27 14:04:01 920C70BE04FCFE6AA9DF6997B9D55B2E 255799 ----a-w- C:\Users\Olaf De Wit VolBeh\Documents\FEBE 2015 27.10 15.03.59\OPIE{5.0.2.1-signed}.xpi 2015-10-27 14:04:01 80FCCF278B6ED615267C0CB11BC4B8F5 29160 ----a-w- C:\Users\Olaf De Wit VolBeh\Documents\FEBE 2015 27.10 15.03.59\TheAddonBarrestored{3.2.1-signed}.xpi 2015-10-27 14:04:01 7E5797DFCC98F52961CF2DED245A78D4 38608 ----a-w- C:\Users\Olaf De Wit VolBeh\Documents\FEBE 2015 27.10 15.03.59\FlashStopper{1.2.9}.xpi 2015-10-27 14:04:01 790FCAB67547D1D3149AE00783060F28 102426 ----a-w- C:\Users\Olaf De Wit VolBeh\Documents\FEBE 2015 27.10 15.03.59\ClickClean{4.1.1-signed}.xpi 2015-10-27 14:04:01 657F32D91E6D0006ABD32124BD0CBCD2 240579 ----a-w- C:\Users\Olaf De Wit VolBeh\Documents\FEBE 2015 27.10 15.03.59\CookieKeeper{1.8.5.1-signed}.xpi 2015-10-27 14:04:01 6413244D4BAD5CC06E379FFA7EEAF64F 557479 ----a-w- C:\Users\Olaf De Wit VolBeh\Documents\FEBE 2015 27.10 15.03.59\SessionManager{0.8.1.7}.xpi 2015-10-27 14:04:01 54B290893F2C3ADEAD17D8F4D2A98D36 562123 ----a-w- C:\Users\Olaf De Wit VolBeh\Documents\FEBE 2015 27.10 15.03.59\NoScript{2.6.9.39}.xpi 2015-10-27 14:04:01 4F1AE4B4B0102968C40BD93B167CC8BC 1440894 ----a-w- C:\Users\Olaf De Wit VolBeh\Documents\FEBE 2015 27.10 15.03.59\uBlockOrigin{1.3.1}.xpi 2015-10-27 14:04:01 46F414EFB606C7DD30AA7A29E770C398 11228 ----a-w- C:\Users\Olaf De Wit VolBeh\Documents\FEBE 2015 27.10 15.03.59\BingSearch{1.0.0.2}.xpi 2015-10-27 14:04:01 449655D670B5907420A27DD533341EE1 106549 ----a-w- C:\Users\Olaf De Wit VolBeh\Documents\FEBE 2015 27.10 15.03.59\CLEO{6.0.1-signed}.xpi 2015-10-27 14:04:01 3128A8FA70BA4AF7AD4B86D16D1C64ED 54245 ----a-w- C:\Users\Olaf De Wit VolBeh\Documents\FEBE 2015 27.10 15.03.59\YouTubeFlashPlayer{1.4.0}.xpi 2015-10-27 14:04:01 12637F01584BEFE2468A39D6FA335869 292441 ----a-w- C:\Users\Olaf De Wit VolBeh\Documents\FEBE 2015 27.10 15.03.59\SpeedDial{0.9.6.18}.xpi 2015-10-27 14:04:01 072E6A21093BCD1AC11E22FDDF497BAD 67294 ----a-w- C:\Users\Olaf De Wit VolBeh\Documents\FEBE 2015 27.10 15.03.59\YouTubeFlashVideoPlayer{41.0}.xpi 2015-10-27 14:04:01 04D1FF939D99759DAB64323B69167AFC 80248 ----a-w- C:\Users\Olaf De Wit VolBeh\Documents\FEBE 2015 27.10 15.03.59\FlashControl{2.0.5}.xpi 2015-10-27 14:04:01 031338DF85EEC8B021C5D6F171E9D8EA 403013 ----a-w- C:\Users\Olaf De Wit VolBeh\Documents\FEBE 2015 27.10 15.03.59\VideoDownloaderprofessional{1.97.37.1-signed}.xpi 2015-10-27 13:59:57 D3C93C178B785C6D8B0CDBA5F25F422B 26366 ----a-w- C:\Users\Olaf De Wit VolBeh\AppData\Roaming\Mozilla\Firefox\Profiles\xe7710xq.default\extensions\{b9bfaf1c-a63f-47cd-8b9a-29526ced9060}.xpi ==== Startup Registry Enabled ====================== [HKEY_USERS\S-1-5-21-3353583409-2322390238-1352878597-1002\Software\Microsoft\Windows\CurrentVersion\Run] "CCleaner Monitoring"="C:\Program Files\CCleaner\CCleaner64.exe /MONITOR" "Bitdefender Wallet Agent"="C:\Program Files\Bitdefender\Bitdefender 2015\bdwtxag.exe" "BingSvc"="C:\Users\Olaf De Wit VolBeh\AppData\Local\Microsoft\BingSvc\BingSvc.exe" "Skype"="C:\Program Files (x86)\Skype\Phone\Skype.exe /minimized /regrun" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "CCleaner Monitoring"="C:\Program Files\CCleaner\CCleaner64.exe /MONITOR" "Bitdefender Wallet Agent"="C:\Program Files\Bitdefender\Bitdefender 2015\bdwtxag.exe" "BingSvc"="C:\Users\Olaf De Wit VolBeh\AppData\Local\Microsoft\BingSvc\BingSvc.exe" "Skype"="C:\Program Files (x86)\Skype\Phone\Skype.exe /minimized /regrun" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] "BtvStack"="C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\BtvStack.exe" ==== Startup Registry Enabled x64 ====================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RTHDVCPL"="C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe -s" "RtHDVBg"="C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe /MAXX5REC" "Bdagent"="C:\Program Files\Bitdefender\Bitdefender 2015\bdagent.exe" "NvBackend"="C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe" "ShadowPlay"="C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\nvspcap64.dll,ShadowPlayOnSystemStart" "ShadowPlay"="C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\nvspcap64.dll,ShadowPlayOnSystemStart" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] "BtvStack"="C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\BtvStack.exe" ==== Startup Registry Disabled x64 ====================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\!SASCORE] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\BthHFSrv] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\bthserv] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\c2cautoupdatesvc] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\c2cpnrsvc] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\DellDataVault] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\Fax] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\MpsSvc] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\SkypeUpdate] ==== Task Scheduler Jobs ====================== C:\WINDOWS\tasks\Adobe Flash Player Updater.job --a-------- C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [17/10/2015 11:54] C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job --a-------- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [18/10/2015 14:57] C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job --a-------- [Undetermined Task] ==== Other Scheduled Tasks ====================== "C:\WINDOWS\SysNative\tasks\Adobe Acrobat Update Task" [C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe] "C:\WINDOWS\SysNative\tasks\Adobe Flash Player Updater" [C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe] "C:\WINDOWS\SysNative\tasks\Bitdefender Update Product Data_A17FD818A96743FAB28AC221BEB4B2C8" [C:\Program Files\Bitdefender\Bitdefender 2015\bdproductdata.exe] "C:\WINDOWS\SysNative\tasks\CCleanerSkipUAC" ["C:\Program Files\CCleaner\CCleaner.exe"] "C:\WINDOWS\SysNative\tasks\CLMLSvc_P2G8" [C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe] "C:\WINDOWS\SysNative\tasks\CLVDLauncher" [C:\Program Files (x86)\CyberLink\Power2Go8\CLVDLauncher.exe] "C:\WINDOWS\SysNative\tasks\Dell SupportAssistAgent AutoUpdate" [C:\Program Files (x86)\Dell\SupportAssistAgent\bin\SupportAssist.exe] "C:\WINDOWS\SysNative\tasks\GoogleUpdateTaskMachineCore" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe] "C:\WINDOWS\SysNative\tasks\GoogleUpdateTaskMachineUA" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe] "C:\WINDOWS\SysNative\tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d" ["c:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe"] "C:\WINDOWS\SysNative\tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon" ["c:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe"] "C:\WINDOWS\SysNative\tasks\JetCleanLoginCheckUpdate" [C:\Program Files (x86)\BlueSprig\JetClean\AutoUpdate.exe] "C:\WINDOWS\SysNative\tasks\PCDEventLauncherTask" ["C:\Program Files\Dell\SupportAssist\sessionchecker.exe"] "C:\WINDOWS\SysNative\tasks\PCDoctorBackgroundMonitorTask" ["C:\Program Files\Dell\SupportAssist\uaclauncher.exe"] "C:\WINDOWS\SysNative\tasks\SystemToolsDailyTest" ["uaclauncher.exe"] "C:\WINDOWS\SysNative\tasks\User_Feed_Synchronization-{AA65C752-0A8A-47BB-A0D0-F35E9AE8A4F0}" [C:\WINDOWS\system32\msfeedssync.exe] "C:\WINDOWS\SysNative\tasks\Dell\Dell System Registration" [C:\Program Files (x86)\System Registration\prodreg.exe] ==== Folders in C:\PROGRA~3 0-6 Months Old ====================== 2015-09-23 11:52:04 -------- d-----w- C:\PROGRA~3\Atheros 2015-09-23 12:17:07 -------- d-----w- C:\PROGRA~3\Package Cache 2015-09-23 14:51:41 -------- d-----w- C:\PROGRA~3\Bitdefender 2015-09-23 14:53:50 -------- d-----w- C:\PROGRA~3\BDLogging 2015-09-23 21:24:08 -------- d-----w- C:\PROGRA~3\NVIDIA Corporation 2015-09-23 21:24:33 -------- d-----w- C:\PROGRA~3\NVIDIA 2015-09-25 10:50:35 -------- d-----w- C:\PROGRA~3\Skype 2015-09-25 11:21:37 -------- d-----w- C:\PROGRA~3\PC-Doctor for Windows 2015-09-27 12:35:05 -------- d-----w- C:\PROGRA~3\SupportAssistAgent 2015-09-27 18:40:28 -------- d-----w- C:\PROGRA~3\Malwarebytes 2015-09-27 18:44:50 -------- d-----w- C:\PROGRA~3\Spybot - Search & Destroy 2015-09-27 18:51:05 -------- d-----w- C:\PROGRA~3\SUPERAntiSpyware.com 2015-09-29 10:51:24 -------- d-----w- C:\PROGRA~3\Microsoft SkyDrive 2015-09-30 16:12:21 -------- d-----w- C:\PROGRA~3\Adobe 2015-10-01 18:38:26 -------- d-----w- C:\PROGRA~3\abelhadigital.com 2015-10-12 11:18:27 -------- d-----w- C:\PROGRA~3\Windows App Certification Kit 2015-10-13 13:10:41 -------- d-----w- C:\PROGRA~3\Mozilla 2015-10-18 18:51:06 -------- d-----w- C:\PROGRA~3\Last.fm ==== Firefox Start and Search pages ====================== ProfilePath: C:\Users\OLAFDE~1\AppData\Roaming\Mozilla\Firefox\Profiles\xe7710xq.default user_pref("browser.startup.homepage", "https://addons.mozilla.org/nl/firefox/"); user_pref("browser.search.defaultenginename", "Bing "); user_pref("browser.search.selectedEngine", "Bing "); ==== Firefox Extensions Registry ====================== [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions] "bdwteff@bitdefender.com"="C:\Program Files\Bitdefender\Bitdefender 2015\antispam32\bdwteff" [24/03/2015 10:54] [HKEY_CURRENT_USER\Software\Mozilla\Firefox\Extensions] "MFVersion"="MF41.0 (x86 nl)" [] ==== Firefox Extensions ====================== ProfilePath: C:\Users\OLAFDE~1\AppData\Roaming\Mozilla\Firefox\Profiles\iyfy9ezv.Default User - FEBE - C:\Users\Olaf De Wit VolBeh\AppData\Roaming\Mozilla\Firefox\Profiles\iyfy9ezv.Default User\extensions\{4BBDD651-70CF-4821-84F8-2B918CF89CA3} - FEBE - %ProfilePath%\extensions\{4BBDD651-70CF-4821-84F8-2B918CF89CA3} ProfilePath: C:\Users\OLAFDE~1\AppData\Roaming\Mozilla\Firefox\Profiles\xe7710xq.default - Undetermined - C:\Users\Olaf De Wit VolBeh\AppData\Roaming\Mozilla\Firefox\Profiles\xe7710xq.default\extensions\{4BBDD651-70CF-4821-84F8-2B918CF89CA3} - Undetermined - C:\Users\Olaf De Wit VolBeh\AppData\Roaming\Mozilla\Firefox\Profiles\xe7710xq.default\extensions\CLEO@guid.customsoftwareconsult.com - Undetermined - C:\Users\Olaf De Wit VolBeh\AppData\Roaming\Mozilla\Firefox\Profiles\xe7710xq.default\extensions\clickclean@hotcleaner.com - Undetermined - C:\Users\Olaf De Wit VolBeh\AppData\Roaming\Mozilla\Firefox\Profiles\xe7710xq.default\extensions\artur.dubovoy@gmail.com - Undetermined - C:\Users\Olaf De Wit VolBeh\AppData\Roaming\Mozilla\Firefox\Profiles\xe7710xq.default\extensions\paulsaintuzb@gmail.com - CookieKeeper - %ProfilePath%\extensions\cookiekeeper@cookiekeeper.mozdev.org.xpi - Element Hiding Helper for Adblock Plus - %ProfilePath%\extensions\elemhidehelper@adblockplus.org.xpi - Video Downloader Professional - %ProfilePath%\extensions\ffext_basicvideoext@startpage24.xpi - Ghostery - %ProfilePath%\extensions\firefox@ghostery.com.xpi - FlashStopper - %ProfilePath%\extensions\flashstopper@byo.co.il.xpi - Self-Destructing Cookies - %ProfilePath%\extensions\jid0-9XfBwUWnvPx4wWsfBWMCm4Jj69E@jetpack.xpi - Undetermined - %ProfilePath%\extensions\jid1-HAV2inXAnQPIeA@jetpack.xpi - Flash Control - %ProfilePath%\extensions\jid1-sNL73VCI4UB0Fw@jetpack.xpi - OPIE - %ProfilePath%\extensions\OPIE@guid.customsoftwareconsult.com.xpi - The Addon Bar restored - %ProfilePath%\extensions\the-addon-bar@GeekInTraining-GiT.xpi - Undetermined - %ProfilePath%\extensions\uBlock0@raymondhill.net.xpi - Trnh Qun L Phin - %ProfilePath%\extensions\{1280606b-2510-4fe0-97ef-9b5a22eafe30}.xpi - Speed Dial - %ProfilePath%\extensions\{64161300-e22b-11db-8314-0800200c9a66}.xpi - NoScript - %ProfilePath%\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi - Download YouTube Videos as MP4 - %ProfilePath%\extensions\{b9bfaf1c-a63f-47cd-8b9a-29526ced9060}.xpi - Video DownloadHelper - %ProfilePath%\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi - Adblock Plus - %ProfilePath%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi - BetterPrivacy em:version1.68.1-signed em:type2 em:creatorGreg Yardley version 0.2 www.yardley.ca em:descriptionquot - %ProfilePath%\extensions\{d40f5e7b-d2cf-4856-b441-cc613eeffbe3}.xpi - YouTube Flash Video Player - %ProfilePath%\extensions\{f3bd3dd2-2888-44c5-91a2-2caeb33fb898}.xpi - UnMHT - %ProfilePath%\extensions\{f759ca51-3a91-4dd1-ae78-9db5eee9ebf0}.xpi AppDir: C:\Program Files (x86)\Mozilla Firefox - Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} - Skype Click to Call - %AppDir%\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi ==== Firefox Plugins ====================== Profilepath: C:\Users\Olaf De Wit VolBeh\AppData\Roaming\Mozilla\Firefox\Profiles\iyfy9ezv.Default User 18CF51689186AEB9D1D149AEB0E92D03 - C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL - Microsoft Office 2013 CAF78E18A9E1380A0A38065B3B1210E0 - C:\Users\Olaf De Wit VolBeh\AppData\Roaming\VASCO\VascoCardReaderPlugin\3.2.3.4\npVascoCardReaderPlugin.dll - VASCO Card Reader Plugin 1CDD28B47D8198F868349BDFBCD1281B - C:\Users\Olaf De Wit VolBeh\AppData\Roaming\VASCO\VascoCardReaderPlugin\3.2.3.4\npVascoCardReaderPlugin64.dll - VASCO Card Reader Plugin Profilepath: C:\Users\Olaf De Wit VolBeh\AppData\Roaming\Mozilla\Firefox\Profiles\xe7710xq.default 18CF51689186AEB9D1D149AEB0E92D03 - C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL - Microsoft Office 2013 863AF0003392FEBC2667A8A790DED955 - C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_19_0_0_226.dll - Shockwave Flash CAF78E18A9E1380A0A38065B3B1210E0 - C:\Users\Olaf De Wit VolBeh\AppData\Roaming\VASCO\VascoCardReaderPlugin\3.2.3.4\npVascoCardReaderPlugin.dll - VASCO Card Reader Plugin 1CDD28B47D8198F868349BDFBCD1281B - C:\Users\Olaf De Wit VolBeh\AppData\Roaming\VASCO\VascoCardReaderPlugin\3.2.3.4\npVascoCardReaderPlugin64.dll - VASCO Card Reader Plugin ==== Chromium Look ====================== Google Chrome Version: 46.0.2490.80 HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions fabcmochhfpldjekobfaaggijgohadih - No path found[] Google Slides - Olaf De Wit VolBeh\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek Google Docs - Olaf De Wit VolBeh\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake Google Drive - Olaf De Wit VolBeh\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf YouTube - Olaf De Wit VolBeh\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo selector is not a valid CSS selector - Olaf De Wit VolBeh\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb Google Search - Olaf De Wit VolBeh\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf Video Downloader professional - Olaf De Wit VolBeh\AppData\Local\Google\Chrome\User Data\Default\Extensions\elicpjhcidhpjomhibiffojpinpmmpil uBlock - Olaf De Wit VolBeh\AppData\Local\Google\Chrome\User Data\Default\Extensions\epcnnfbjfcgphgdmggkamkmgojdagdnn Bitdefender Wallet - Olaf De Wit VolBeh\AppData\Local\Google\Chrome\User Data\Default\Extensions\fabcmochhfpldjekobfaaggijgohadih Google Sheets - Olaf De Wit VolBeh\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap EditThisCookie - Olaf De Wit VolBeh\AppData\Local\Google\Chrome\User Data\Default\Extensions\fngmhnnpilhplaeedifhccceomclgfbg Google Docs Offline - Olaf De Wit VolBeh\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi AdBlock - Olaf De Wit VolBeh\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom Ghostery - Olaf De Wit VolBeh\AppData\Local\Google\Chrome\User Data\Default\Extensions\mlomiejdfkolichcflejclcbmpeaniij Chrome Web Store Payments - Olaf De Wit VolBeh\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda Gmail - Olaf De Wit VolBeh\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia ==== Deleting CLSID Registry Keys ====================== ==== Deleting CLSID Registry Values ====================== ==== C:\zoek_backup content ====================== C:\zoek_backup (files=861 folders=162 74829721 bytes) ==== EOF on di 03/11/2015 at 13:01:56,60 ======================