Zoek.exe v5.0.0.1 Updated 31-December-2015 Tool run by Cees on ma 11-01-2016 at 14:51:27,53. Microsoft Windows 8.1 6.3.9600 x64 Running in: Normal Mode Internet Access Detected Launched: C:\Users\Cees\Downloads\zoek.exe [Scan all users] [Script inserted] [Checkboxes used] ==== System Restore Info ====================== 11-1-2016 14:52:27 Zoek.exe System Restore Point Created Successfully. ==== Empty Folders Check ====================== C:\PROGRA~2\AGEIA Technologies deleted successfully C:\PROGRA~2\KeyFinder deleted successfully C:\PROGRA~2\Tbccint deleted successfully C:\PROGRA~2\COMMON~1\SWF Studio deleted successfully C:\PROGRA~3\374311380 deleted successfully C:\PROGRA~3\PlotSoft deleted successfully C:\Users\Cees\AppData\Local\EmieBrowserModeList deleted successfully C:\Users\Cees\AppData\Local\EmieSiteList deleted successfully C:\Users\Cees\AppData\Local\EmieUserList deleted successfully C:\Users\Cees\AppData\Local\PackageStaging deleted successfully ==== Deleting CLSID Registry Keys ====================== HKEY_USERS\S-1-5-21-3775048874-3341839493-1509096462-1001\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} deleted successfully HKEY_USERS\S-1-5-21-3775048874-3341839493-1509096462-1001\Software\Microsoft\Internet Explorer\SearchScopes\{E57AF1DB-1F15-4A3C-8DB2-E18E07FBAB0B} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} deleted successfully ==== Deleting CLSID Registry Values ====================== ==== Deleting Services ====================== HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Update service deleted successfully ==== FireFox Fix ====================== ProfilePath: C:\Users\Cees\AppData\Roaming\Mozilla\Firefox\Profiles\zwlaseht.default user.js not found ---- Lines CT3329621 removed from prefs.js ---- user_pref("CT3329621.FF19Solved", "true"); user_pref("CT3329621.UserID", "UN10813802823566146"); user_pref("CT3329621.dum", "2"); user_pref("CT3329621.fullUserID", "UN10813802823566146.IN.20141212135459"); user_pref("CT3329621.installDate", "12/12/2014 13:55:00"); user_pref("CT3329621.installSessionId", "e9068e8e-e66c-40d1-bba3-0ad00d065c9e"); user_pref("CT3329621.installSp", "false"); user_pref("CT3329621.installUsage", "03/01/2015 20:28:36"); user_pref("CT3329621.installUsageEarly", "03/01/2015 20:28:36"); user_pref("CT3329621.installerVersion", "1.11.0.11"); user_pref("CT3329621.searchRevert", "@searchrevert@"); user_pref("CT3329621.searchUninstallUserMode", "4"); user_pref("CT3329621.searchUserMode", "4"); user_pref("CT3329621.toolbarInstallDate", "12-12-2014 13:54:59"); user_pref("CT3329621.versionFromInstaller", "10.35.0.3"); user_pref("CT3329621.xpeMode", "1"); ---- Lines smartbar removed from prefs.js ---- user_pref("smartbar.machineId", "KNPUZNAIPYCLCDAF5LZYAE/PQMWJRTJDC9ENHPVHD9NTARBUSPDSOYDCL2QVJHP4LYAV4QCCHM0+OVTJV8YQVG"); ---- FireFox user.js and prefs.js backups ---- prefs_11-01-2016_1501_.backup ==== Registry Fix Code x64 ====================== Windows Registry Editor Version 5.00 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer] ""=- ==== Deleting Files \ Folders ====================== C:\PROGRA~2\AGEIA Technologies not found C:\PROGRA~2\KeyFinder not found C:\PROGRA~2\Tbccint not found C:\PROGRA~3\Tbccint deleted C:\Users\Cees\AppData\Local\Tbccint deleted C:\Program Files (x86)\Popcorn Time deleted C:\8b4b4632e18bafb560fb1437 deleted C:\Users\Cees\AppData\LocalLow\Tbccint deleted C:\PROGRA~2\ChrisPC Win Experience Index deleted C:\PROGRA~2\RelevantKnowledge deleted C:\install.exe deleted C:\Users\Cees\AppData\Roaming\ARCompanion.log deleted C:\Users\Cees\AppData\Roaming\pdfforge deleted C:\PROGRA~3\APN deleted C:\PROGRA~3\Package Cache deleted C:\Users\Cees\AppData\Local\cache deleted C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Search.lnk deleted C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RelevantKnowledge deleted C:\Users\Cees\Downloads\bsplayer267-1076 (1).exe deleted C:\Users\Cees\Downloads\bsplayer267-1076.exe deleted C:\Users\Cees\Downloads\bsplayer268.1077.exe deleted C:\Users\Cees\AppData\LocalLow\PriceGong deleted C:\END deleted C:\Windows\SysNative\rlls64.dll deleted C:\Windows\SysNative\config\systemprofile\Searches deleted C:\Windows\Syswow64\rlls.dll deleted C:\Users\Cees\AppData\Roaming\Mozilla\Firefox\Profiles\zwlaseht.default\CT3329621 deleted ==== Files Recently Created / Modified ====================== ====== C:\Windows ==== 2016-01-07 17:04:59 5AE11F3B167804DCA21BF64CA1E878FC 582 ----a-w- C:\Windows\eReg.dat ====== C:\Users\Cees\AppData\Local\Temp ==== 2016-01-08 15:04:11 BDE21EC1618633A32EE2ED984B3FEDD8 93008 ----a-w- C:\Users\Cees\AppData\Local\Temp\HouseCall\BPMNT.dll 2016-01-08 15:04:11 773A68DF25AC20BA9678C8924871D4C4 3341312 ----a-w- C:\Users\Cees\AppData\Local\Temp\HouseCall\tscdll64.dll 2016-01-08 15:04:11 2AC5F13876C9B3C544C5A43806F089DD 2436608 ----a-w- C:\Users\Cees\AppData\Local\Temp\HouseCall\vsapi64.dll 2016-01-08 15:04:01 F82469A1100DA72AB6071C45FA665E96 318464 ----a-w- C:\Users\Cees\AppData\Local\Temp\HouseCall\plugin\downloader.plugin.dll 2016-01-08 15:04:01 DCFC19032C60CCC660D4346295DA42B9 45320 ----a-w- C:\Users\Cees\AppData\Local\Temp\HouseCall\utilClientLoader.dll 2016-01-08 15:04:01 A6FF2533FCCCCC22E6FE7CCB4382D5EF 1908736 ----a-w- C:\Users\Cees\AppData\Local\Temp\HouseCall\libeay32.dll 2016-01-08 15:04:01 A5E4B3FF51CF5B7926D9651908FEB666 1558912 ----a-w- C:\Users\Cees\AppData\Local\Temp\HouseCall\dbghelp.dll 2016-01-08 15:04:01 A4A74365C700E005C49318C20C8D2EBF 1185296 ----a-w- C:\Users\Cees\AppData\Local\Temp\HouseCall\tmufeng.dll 2016-01-08 15:04:01 99559F8DE53EAC2C8DBC23595803A69D 46352 ----a-w- C:\Users\Cees\AppData\Local\Temp\HouseCall\TMEBC64.sys 2016-01-08 15:04:01 98D7D2F55A73A2F7640323572F68FD09 647728 ----a-w- C:\Users\Cees\AppData\Local\Temp\HouseCall\tmfbeng.dll 2016-01-08 15:04:01 86428A172571540ACFA1FEB4945DF2C1 239664 ----a-w- C:\Users\Cees\AppData\Local\Temp\HouseCall\perfiCrcPerfMonMgr.dll 2016-01-08 15:04:01 799F70FF787F4F68E7EA02FEABAC9FAB 307352 ----a-w- C:\Users\Cees\AppData\Local\Temp\HouseCall\Tmcomm.sys 2016-01-08 15:04:01 670DA175BF2CA93A60D243EA24CE8220 788480 ----a-w- C:\Users\Cees\AppData\Local\Temp\HouseCall\libcurl.dll 2016-01-08 15:04:01 65FB3391EB26F5AC647FC40501D8E21D 149264 ----a-w- C:\Users\Cees\AppData\Local\Temp\HouseCall\symsrv.dll 2016-01-08 15:04:01 381641E1625DD93D2855CFF095004C62 447488 ----a-w- C:\Users\Cees\AppData\Local\Temp\HouseCall\ssleay32.dll 2016-01-08 15:04:01 22B8266910C5CA0325CC7E27967A354A 4175408 ----a-w- C:\Users\Cees\AppData\Local\Temp\HouseCall\hc_core.dll 2016-01-08 15:04:01 227AAAE2B6E60ADD679F632C3BF51A61 148992 ----a-w- C:\Users\Cees\AppData\Local\Temp\HouseCall\libexpatw.dll 2016-01-08 15:04:01 2191B4A8011D73906BC2B8A6D4E8B351 2667536 ----a-w- C:\Users\Cees\AppData\Local\Temp\HouseCall\smv64.dll 2016-01-08 15:04:01 0DDC5509168F24D8248E103210890098 420400 ----a-w- C:\Users\Cees\AppData\Local\Temp\HouseCall\TmEngDrv.dll 2016-01-08 15:04:01 0C33A49F9125FAD652A72554394C03C3 2253872 ----a-w- C:\Users\Cees\AppData\Local\Temp\HouseCall\ICRCHdler.dll 2016-01-08 15:03:57 0EC28A809B853905C18AC008EF3086D6 4653544 ----a-w- C:\Users\Cees\AppData\Local\Temp\HCBackup\hcpackage64.exe 2016-01-07 17:37:12 78DBD6FF91FDD6C3E12B1D1F53A2C5C4 720160 ----a-w- C:\Users\Cees\AppData\Local\Temp\Opera_NI_stable.exe 2016-01-07 16:29:30 39E60156F79A46CA75E338B29D6A534F 4030464 ------w- C:\Users\Cees\AppData\Local\Temp\Temp1_the+sims+deluxe+edition+c.zip\the sims deluxe edition c_10924_i117097794_il345.exe 2016-01-07 15:57:45 679FF716052109392D870F6A6C4A3535 30264 ------w- C:\Users\Cees\AppData\Local\Temp\{75a60445-6412-694c-ae8b-2a0ec397b450}\dtlitescsibus.sys 2016-01-07 15:56:30 D43E12C4C5D319BADE804D984FC058E5 102912 ----a-w- C:\Users\Cees\AppData\Local\Temp\bitool.dll 2016-01-05 16:52:14 14D41ABEAC6F60786FC2F64FBC39F5D3 2241032 ----a-w- C:\Users\Cees\AppData\Local\Temp\HouseCall\tmase\Inspect.exe 2016-01-05 16:50:46 9DC28D984D319C58C0C6042A51A4FDC1 1303560 ----a-w- C:\Users\Cees\AppData\Local\Temp\HouseCall\tmase\tmptfb.dll 2016-01-05 16:49:56 9C91AF1CEB3D04DA36FDE3377BB1C505 376328 ----a-w- C:\Users\Cees\AppData\Local\Temp\HouseCall\tmase\PerfMonitor.exe ====== Java Cache ===== ====== C:\Windows\SysWOW64 ===== 2016-01-08 15:38:28 895ABED2A7C126EFA4D61AF24B0D5AE4 97888 ----a-w- C:\Windows\SysWOW64\WindowsAccessBridge-32.dll ====== C:\Windows\SysWOW64\drivers ===== 2016-01-07 17:17:00 C71394D99A04CA76484492F590C9CBA5 11376 ----a-w- C:\Windows\SysWOW64\drivers\SECDRV.SYS ====== C:\Windows\Sysnative ===== ====== C:\Windows\Sysnative\drivers ===== 2016-01-08 15:04:01 799F70FF787F4F68E7EA02FEABAC9FAB 307352 ----a-w- C:\Windows\Sysnative\drivers\tmcomm.sys 2016-01-07 15:57:51 DCAF642BF2091D9ED68AF3AE84306992 46392 ----a-w- C:\Windows\Sysnative\drivers\dtliteusbbus.sys 2016-01-07 15:57:45 679FF716052109392D870F6A6C4A3535 30264 ----a-w- C:\Windows\Sysnative\drivers\dtlitescsibus.sys ====== C:\Windows\Tasks ====== ====== C:\Windows\Temp ====== ======= C:\Program Files ===== 2016-01-08 17:10:04 -------- d-----w- C:\Program Files\trend micro ======= C:\PROGRA~2 ===== 2016-01-08 15:38:37 -------- d-----w- C:\PROGRA~2\COMMON~1\Java 2016-01-08 15:38:18 -------- d-----w- C:\PROGRA~2\Java 2016-01-07 16:16:48 -------- d--h--w- C:\PROGRA~2\InstallShield Installation Information 2016-01-07 16:16:01 -------- d-----w- C:\PROGRA~2\COMMON~1\InstallShield 2016-01-07 16:01:31 -------- d-----w- C:\PROGRA~2\Maxis ======= C: ===== ====== C:\Users\Cees\AppData\Roaming ====== 2016-01-08 15:38:31 -------- d-----w- C:\Users\Cees\AppData\Roaming\Sun 2016-01-08 15:38:31 -------- d-----w- C:\Users\Cees\AppData\Locallow\Sun 2016-01-08 15:35:20 -------- d-----w- C:\Users\Cees\AppData\Locallow\Oracle 2016-01-08 15:10:04 4926C3203BE37DB7D0F64C4D5D561D93 507601 ----a-w- C:\Users\Cees\AppData\Local\census.cache 2016-01-08 15:10:01 960AB8881C6B76D343559D88A2303327 193544 ----a-w- C:\Users\Cees\AppData\Local\ars.cache 2016-01-08 15:07:20 8455DD1D679B1C4CA71B856177D6F070 10 ----a-w- C:\Users\Cees\AppData\Local\sponge.last.runtime.cache 2016-01-08 15:03:57 BA9CCCF8B9D1B2A4F769347F3EE6D845 36 ----a-w- C:\Users\Cees\AppData\Local\housecall.guid.cache 2016-01-07 17:37:43 -------- d-----w- C:\Users\Cees\AppData\Roaming\Opera Software 2016-01-07 17:37:43 -------- d-----w- C:\Users\Cees\AppData\Local\Opera Software 2016-01-07 17:04:59 -------- d-----w- C:\Users\Cees\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maxis 2016-01-07 17:04:02 -------- d-----w- C:\Users\Cees\AppData\Locallow\uTorrent 2016-01-07 15:59:27 -------- d-----w- C:\Users\Cees\AppData\Local\Disc_Soft_Ltd 2016-01-07 15:57:45 -------- d-----w- C:\Users\Cees\AppData\Roaming\DAEMON Tools Lite ====== C:\Users\Cees ====== 2016-01-08 17:09:39 8045ABB21A3BDD66A48E1ED5C0F0EF6A 1222144 ----a-w- C:\Users\Cees\Downloads\RSITx64.exe 2016-01-08 15:38:31 -------- d-----w- C:\Users\Cees\.oracle_jre_usage 2016-01-08 15:38:28 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2016-01-08 15:38:20 -------- d-----w- C:\ProgramData\Oracle 2016-01-08 15:35:33 81EDCA9D9BFDDB931ED448078762A31A 584288 ----a-w- C:\Users\Cees\Downloads\chromeinstall-8u66 (1).exe 2016-01-08 15:35:08 81EDCA9D9BFDDB931ED448078762A31A 584288 ----a-w- C:\Users\Cees\Downloads\chromeinstall-8u66.exe 2016-01-08 15:03:52 57E86EA1E1AEBF898496F38D10A57664 2494560 ----a-w- C:\Users\Cees\Downloads\HousecallLauncher64.exe 2016-01-07 15:57:57 -------- d-----w- C:\Users\Public\Documents\Daemon Tools Images 2016-01-07 15:51:11 -------- d-----w- C:\ProgramData\DAEMON Tools Lite 2016-01-07 15:43:42 -------- d-----w- C:\Users\Public\Documents\EA Games ====== C: exe-files == 2016-01-11 11:42:52 E34182E2598C23A8B5C50FBA25549CE6 523144 ----a-w- C:\Users\Cees\AppData\Local\Autodesk\.AdskAppManager\R1\AdAppMgr.exe 2016-01-11 11:42:52 E118EF93DC6A1EF57001BD9B91B7D3C7 274312 ----a-w- C:\Users\Cees\AppData\Local\Autodesk\.AdskAppManager\R1\AdSdsCheck.exe 2016-01-11 11:42:52 DCAB688A519A66E27A438D1DE6386DF8 314760 ----a-w- C:\Users\Cees\AppData\Local\Autodesk\.AdskAppManager\R1\InstProxy.exe 2016-01-11 11:42:52 BEFFD334BE955FE9A6389E0F2694BF83 2375496 ----a-w- C:\Users\Cees\AppData\Local\Autodesk\.AdskAppManager\R1\CER\senddmp.exe 2016-01-11 11:42:52 B4B906887DCB244FC5849B986B0A3574 308104 ----a-w- C:\Users\Cees\AppData\Local\Autodesk\.AdskAppManager\R1\AdAppMgrSvcProxy.exe 2016-01-11 11:42:52 AAD4B37B594E9004AC728B075E7AE1B2 270216 ----a-w- C:\Users\Cees\AppData\Local\Autodesk\.AdskAppManager\R1\AdAppMgrSvcACLReset.exe 2016-01-11 11:42:52 AA8F93D56549DF069EB25BDE3D22ED9F 302472 ----a-w- C:\Users\Cees\AppData\Local\Autodesk\.AdskAppManager\R1\AdAppMgrSvcInstProxy.exe 2016-01-11 11:42:52 A31EC5255EAF6E23C4DBA321ADCBA83C 280968 ----a-w- C:\Users\Cees\AppData\Local\Autodesk\.AdskAppManager\R1\AdAppMgrTaskClean.exe 2016-01-11 11:42:52 8C55DC079572791E2974BE3C5C19E254 6552288 ----a-w- C:\Users\Cees\AppData\Local\Autodesk\.AdskAppManager\R1\vcredist_x86.exe 2016-01-11 11:42:52 5EEC5291B8446F51A3C914FA334B761F 271240 ----a-w- C:\Users\Cees\AppData\Local\Autodesk\.AdskAppManager\R1\AdAppMgrLauncher.exe 2016-01-11 11:42:52 5CBF0ED7F4DCE68292CE573013C7FAC9 1136520 ----a-w- C:\Users\Cees\AppData\Local\Autodesk\.AdskAppManager\R1\AdAppMgrSvc.exe 2016-01-11 11:42:52 0DCE65B1B7A145E51A7B2637CF9C3404 811912 ----a-w- C:\Users\Cees\AppData\Local\Autodesk\.AdskAppManager\R1\AdAppMgrUpdater.exe 2016-01-08 17:10:04 9A2347903D6EDB84C10F288BC0578C1C 388608 ----a-w- C:\Program Files\trend micro\Cees.exe 2016-01-08 17:09:39 8045ABB21A3BDD66A48E1ED5C0F0EF6A 1222144 ----a-w- C:\Users\Cees\Downloads\RSITx64.exe 2016-01-08 15:38:28 F003BBCB09CACF8A9F4CE0C67A2D6E63 0 ----a-we C:\ProgramData\Oracle\Java\javapath\javaws.exe 2016-01-08 15:38:28 A9E84AD3536425BC68263B723C2442E4 0 ----a-we C:\ProgramData\Oracle\Java\javapath\java.exe 2016-01-08 15:38:28 7BDD7F1BC2A20971DEE17B6920D61BBC 0 ----a-we C:\ProgramData\Oracle\Java\javapath\javaw.exe 2016-01-08 15:38:25 FDF059C05249FAEA0221ED65CD59A9C8 68192 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_66\bin\javacpl.exe 2016-01-08 15:38:25 F003BBCB09CACF8A9F4CE0C67A2D6E63 278624 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_66\bin\javaws.exe 2016-01-08 15:38:25 EFC80BC662BCC20B0B09700636FDC732 30816 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_66\bin\jabswitch.exe 2016-01-08 15:38:25 D8EEED21B06866E85DA30485F5059FF6 15968 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_66\bin\servertool.exe 2016-01-08 15:38:25 CA51FB3FE5012E21D9A14AC071527866 76896 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_66\bin\jp2launcher.exe 2016-01-08 15:38:25 ADAF1151B29D2D1691FA027B6C55B3D7 50784 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_66\bin\ssvagent.exe 2016-01-08 15:38:25 A9E84AD3536425BC68263B723C2442E4 191072 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_66\bin\java.exe 2016-01-08 15:38:25 8977B87AB10AB1DA8769CA0053B401B0 15968 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_66\bin\jjs.exe 2016-01-08 15:38:25 7BE9BE6E15653824A28F5CED6B273588 15968 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_66\bin\klist.exe 2016-01-08 15:38:25 7BDD7F1BC2A20971DEE17B6920D61BBC 191584 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_66\bin\javaw.exe 2016-01-08 15:38:25 73368169BFD965EC6257E77C23CED879 15968 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_66\bin\rmiregistry.exe 2016-01-08 15:38:25 525027DF51378DDA25F0F52C20BCB132 15968 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_66\bin\kinit.exe 2016-01-08 15:38:25 46AB480B01CD30801B3AE89B5AAE75A8 16480 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_66\bin\orbd.exe 2016-01-08 15:38:25 3B306D41F07396975ECE34A860BD9036 15968 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_66\bin\pack200.exe 2016-01-08 15:38:25 36A44033C6B970F95E2A1448F4481CEA 15968 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_66\bin\keytool.exe 2016-01-08 15:38:25 28FB06FC63D5817153B5502A49DF3F00 15968 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_66\bin\ktab.exe 2016-01-08 15:38:25 17A8DD2484DC26E38DFE3209C8B36980 15968 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_66\bin\policytool.exe 2016-01-08 15:38:25 0B82777B13B81417E5520DF7B1E8C319 15968 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_66\bin\rmid.exe 2016-01-08 15:38:25 0A3936FE18FC04350159A1E647201501 16480 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_66\bin\tnameserv.exe 2016-01-08 15:38:25 092F4D3C25F3086D4C7FDEC79DD71302 159328 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_66\bin\unpack200.exe 2016-01-08 15:38:25 04D67FF5044A605F1E7D923A1D6F1751 15968 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_66\bin\java-rmi.exe 2016-01-08 15:35:33 81EDCA9D9BFDDB931ED448078762A31A 584288 ----a-w- C:\Users\Cees\Downloads\chromeinstall-8u66 (1).exe 2016-01-08 15:35:08 81EDCA9D9BFDDB931ED448078762A31A 584288 ----a-w- C:\Users\Cees\Downloads\chromeinstall-8u66.exe 2016-01-08 15:26:07 4CF5202677178280793E7A7C8032E5C9 252856 ----a-w- C:\Users\Cees\AppData\Local\NVIDIA\NvBackend\Packages\000063f8\streaming-assets-steam.18914805.exe 2016-01-08 15:03:57 0EC28A809B853905C18AC008EF3086D6 4653544 ----a-w- C:\Users\Cees\AppData\Local\Temp\HCBackup\hcpackage64.exe 2016-01-08 15:03:52 57E86EA1E1AEBF898496F38D10A57664 2494560 ----a-w- C:\Users\Cees\Downloads\HousecallLauncher64.exe 2016-01-08 14:25:15 B7ECF9321C1EEB107830A230D13AEC48 180224 ----a-w- C:\Program Files (x86)\Steam\steamapps\common\Supreme Commander Forged Alliance\bin\BsSndRpt.exe 2016-01-08 14:04:35 9E970EB020EC22032DBBD0BD8C2C659F 525656 ----a-w- C:\Program Files (x86)\Steam\steamapps\common\Supreme Commander Forged Alliance\DirectX\DXSETUP.exe 2016-01-08 14:04:35 42E1F65F138F137C549C26CD587B350B 13213696 ----a-w- C:\Program Files (x86)\Steam\steamapps\common\Supreme Commander Forged Alliance\bin\SupremeCommander.exe 2016-01-07 18:26:54 F40A6604380A1327B8525D26CB0ECBC8 544 ----a-w- C:\$Recycle.Bin\S-1-5-21-3775048874-3341839493-1509096462-1001\$IH804XC.exe 2016-01-07 18:26:53 2B3EFF00046906F0777E39BF15D1FA39 544 ----a-w- C:\$Recycle.Bin\S-1-5-21-3775048874-3341839493-1509096462-1001\$I41MR1R.exe 2016-01-07 18:26:52 71491A0A54EF6AE1ED436A13DAD33A68 544 ----a-w- C:\$Recycle.Bin\S-1-5-21-3775048874-3341839493-1509096462-1001\$IVM65BE.exe 2016-01-07 18:13:21 083305A960E0D125CB75E88AA4985106 544 ----a-w- C:\$Recycle.Bin\S-1-5-21-3775048874-3341839493-1509096462-1001\$IHI3O46.exe 2016-01-07 18:13:15 E11D6BA17F74918A97F5BFB7389985A3 544 ----a-w- C:\$Recycle.Bin\S-1-5-21-3775048874-3341839493-1509096462-1001\$IGH85NR.EXE 2016-01-07 17:42:19 BB6B3B970AD029822933F63C114546D3 2715648 ----a-w- C:\$Recycle.Bin\S-1-5-21-3775048874-3341839493-1509096462-1001\$RGH85NR.EXE 2016-01-07 17:37:12 78DBD6FF91FDD6C3E12B1D1F53A2C5C4 720160 ----a-w- C:\Users\Cees\AppData\Local\Temp\Opera_NI_stable.exe 2016-01-07 17:04:01 233B5852363BFB41D73D219FA8528AF4 336896 ----a-w- C:\Users\Cees\AppData\Roaming\uTorrent\updates\3.4.5_41372\utorrentie.exe 2016-01-07 16:29:30 39E60156F79A46CA75E338B29D6A534F 4030464 ------w- C:\Users\Cees\AppData\Local\Temp\Temp1_the+sims+deluxe+edition+c.zip\the sims deluxe edition c_10924_i117097794_il345.exe 2016-01-07 16:29:30 39E60156F79A46CA75E338B29D6A534F 4030464 ------w- C:\Program Files (x86)\Maxis\The Sims\Music\the sims deluxe edition c_10924_i117097794_il345.exe 2016-01-07 16:17:03 225E0163EFD4B7E9ADD310269948211A 61440 ------w- C:\Program Files (x86)\Maxis\The Sims\UserData\Web Templates\Localization_Templates\Tokin.exe 2016-01-07 16:16:48 AECC6A163878CEEA3EC1BF8CF9FCFF28 165888 ----a-w- C:\Program Files (x86)\InstallShield Installation Information\{10798AE3-DCBB-43C3-9C93-C23512427E25}\Setup.exe 2016-01-07 16:16:01 D6CF8356C0CA84E02797EF0B09DAB058 602244 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe 2016-01-07 16:03:42 225E0163EFD4B7E9ADD310269948211A 61440 ----a-w- C:\Program Files (x86)\Maxis\The Sims\UserData\Other Web Templates\Localization_Templates\Tokin.exe 2016-01-07 15:56:33 CE116AF7F23A6F78C8DCED830299A028 430920 ----a-w- C:\Users\Cees\AppData\Local\Microsoft\Windows\INetCache\IE\HINEV9TQ\setup[1].exe 2016-01-07 15:55:51 E87CBD264A2CA9B80CC9883B3E6F3AA9 1709792 ----a-w- C:\$Recycle.Bin\S-1-5-21-3775048874-3341839493-1509096462-1001\$RVM65BE.exe 2016-01-07 15:52:02 E87CBD264A2CA9B80CC9883B3E6F3AA9 1709792 ----a-w- C:\$Recycle.Bin\S-1-5-21-3775048874-3341839493-1509096462-1001\$R41MR1R.exe 2016-01-07 15:50:54 D3AB99ACD4D9CDC3663D1B36F4064808 13146016 ----a-w- C:\$Recycle.Bin\S-1-5-21-3775048874-3341839493-1509096462-1001\$RH804XC.exe 2016-01-07 10:03:02 C355D12FA264B22BA44FC67323EBE819 2026520 ----a-w- C:\Users\Cees\AppData\Roaming\uTorrent\updates\3.4.5_41372.exe 2016-01-06 12:36:30 7B9BECE52B9A060B7BEAC6DA1E031086 601768 ----a-w- C:\Users\Cees\AppData\Local\NVIDIA\NvBackend\Packages\000084b4\CoProc update.20313796.exe 2016-01-05 16:52:14 14D41ABEAC6F60786FC2F64FBC39F5D3 2241032 ----a-w- C:\Users\Cees\AppData\Local\Temp\HouseCall\tmase\Inspect.exe 2016-01-05 16:49:56 9C91AF1CEB3D04DA36FDE3377BB1C505 376328 ----a-w- C:\Users\Cees\AppData\Local\Temp\HouseCall\tmase\PerfMonitor.exe === C: other files == 2016-01-08 15:38:25 4DB4B1F67E583B41F841F48254BE38E3 14130 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_66\lib\deploy\ffjcext.zip 2016-01-08 15:04:48 01F64DF93A3A534D06A85AE4FAE2CF1D 16269253 ----a-w- C:\Users\Cees\AppData\Local\Temp\HouseCall\tmase.zip 2016-01-08 15:04:01 99559F8DE53EAC2C8DBC23595803A69D 46352 ----a-w- C:\Users\Cees\AppData\Local\Temp\HouseCall\TMEBC64.sys 2016-01-08 15:04:01 799F70FF787F4F68E7EA02FEABAC9FAB 307352 ----a-w- C:\Windows\System32\drivers\tmcomm.sys 2016-01-08 15:04:01 799F70FF787F4F68E7EA02FEABAC9FAB 307352 ----a-w- C:\Users\Cees\AppData\Local\Temp\HouseCall\Tmcomm.sys 2016-01-08 15:04:01 09B4A816E83E9076BBC2F893F6D4C79E 2751 ----a-w- C:\Users\Cees\AppData\Local\Temp\HCBackup\AUCache\AU_Cache\housecall-ctp-p.activeupdate.trendmicro.com\ini_xml.zip 2016-01-07 18:13:20 E31956B9CAFCF95EBBE21E9689D9809C 544 ----a-w- C:\$Recycle.Bin\S-1-5-21-3775048874-3341839493-1509096462-1001\$IW5XMR9.zip 2016-01-07 17:35:35 EE30248EF9E1A9804ED379524F9229BF 544 ----a-w- C:\$Recycle.Bin\S-1-5-21-3775048874-3341839493-1509096462-1001\$IVRZAXS.zip 2016-01-07 17:30:28 7DBB25844A73BFF1945D48C740688993 4030666 ----a-w- C:\$Recycle.Bin\S-1-5-21-3775048874-3341839493-1509096462-1001\$RVRZAXS.zip 2016-01-07 17:17:00 C71394D99A04CA76484492F590C9CBA5 11376 ----a-w- C:\Windows\SysWOW64\drivers\SECDRV.SYS 2016-01-07 16:17:03 F85D7BD7AD8E3621B8F0B7B234B08E9E 4716 ------w- C:\Program Files (x86)\Maxis\The Sims\UserData\Web Templates\Localization_Templates\make-SimplifiedChinese.bat 2016-01-07 16:17:03 C7817B1E252114243C7264F7AEC61333 3896 ------w- C:\Program Files (x86)\Maxis\The Sims\UserData\Web Templates\Localization_Templates\make-japanese.bat 2016-01-07 16:17:03 C57198C273BDCB79C68D31FEC9601EE2 4060 ------w- C:\Program Files (x86)\Maxis\The Sims\UserData\Web Templates\Localization_Templates\make-englishUK.bat 2016-01-07 16:17:03 B3035188EFBFE7D768331EA7DC25D101 3732 ------w- C:\Program Files (x86)\Maxis\The Sims\UserData\Web Templates\Localization_Templates\make-french.bat 2016-01-07 16:17:03 AE5D4FCAC53DB04F623150DA359D1D16 4060 ------w- C:\Program Files (x86)\Maxis\The Sims\UserData\Web Templates\Localization_Templates\make-portuguese.bat 2016-01-07 16:17:03 A2843E9EACA905A3BC51BF2830709A52 3648 ------w- C:\Program Files (x86)\Maxis\The Sims\UserData\Web Templates\Localization_Templates\make-dutch.bat 2016-01-07 16:17:03 93A70D1D4F25C3CC9509FF42DDBF76B4 3814 ------w- C:\Program Files (x86)\Maxis\The Sims\UserData\Web Templates\Localization_Templates\make-spanish.bat 2016-01-07 16:17:03 8D7C72E7BE6467231C98A8008D4BC900 4798 ------w- C:\Program Files (x86)\Maxis\The Sims\UserData\Web Templates\Localization_Templates\make-TraditionalChinese.bat 2016-01-07 16:17:03 7D2F76CD1E254973166B99500826EA87 3568 ------w- C:\Program Files (x86)\Maxis\The Sims\UserData\Web Templates\Localization_Templates\make-thai.bat 2016-01-07 16:17:03 6F29A316CDE2C8F458D07E09DBEF064E 478 ------w- C:\Program Files (x86)\Maxis\The Sims\UserData\Web Templates\Localization_Templates\makeall.bat 2016-01-07 16:17:03 58C6FEF44D60343F2BA825D8EE8E1D73 28616 ------w- C:\Program Files (x86)\Maxis\The Sims\UserData\Web Templates\Localization_Templates\localize-all.bat 2016-01-07 16:17:03 508A6FCBF20A517D6D59960A2E4C9FEB 1323 ------w- C:\Program Files (x86)\Maxis\The Sims\UserData\Web Templates\Localization_Templates\localized-string-test.bat 2016-01-07 16:17:03 4C15FCE8783FE54D1E0C306CC0703CFC 3732 ------w- C:\Program Files (x86)\Maxis\The Sims\UserData\Web Templates\Localization_Templates\make-polish.bat 2016-01-07 16:17:03 2B2837DF8D63EF399F72BAC99142EA25 3814 ------w- C:\Program Files (x86)\Maxis\The Sims\UserData\Web Templates\Localization_Templates\make-english.bat 2016-01-07 16:17:03 0E53C35FD7F856510E00D702F07ECDF1 3732 ------w- C:\Program Files (x86)\Maxis\The Sims\UserData\Web Templates\Localization_Templates\make-german.bat 2016-01-07 16:17:03 0B338F81BAE409712E6183E6F59031B0 2360 ------w- C:\Program Files (x86)\Maxis\The Sims\UserData\Web Templates\Localization_Templates\testall.bat 2016-01-07 16:17:03 06F7B5565F4EFC702B51331F134887C8 3814 ------w- C:\Program Files (x86)\Maxis\The Sims\UserData\Web Templates\Localization_Templates\make-italian.bat 2016-01-07 16:17:03 0515D575FD693E77FEB06270CA5EFC75 3732 ------w- C:\Program Files (x86)\Maxis\The Sims\UserData\Web Templates\Localization_Templates\make-korean.bat 2016-01-07 16:17:03 0391C4BA070E98E744BDA397899DEB8D 3814 ------w- C:\Program Files (x86)\Maxis\The Sims\UserData\Web Templates\Localization_Templates\make-swedish.bat 2016-01-07 16:03:42 F85D7BD7AD8E3621B8F0B7B234B08E9E 4716 ----a-w- C:\Program Files (x86)\Maxis\The Sims\UserData\Other Web Templates\Localization_Templates\make-SimplifiedChinese.bat 2016-01-07 16:03:42 C7817B1E252114243C7264F7AEC61333 3896 ----a-w- C:\Program Files (x86)\Maxis\The Sims\UserData\Other Web Templates\Localization_Templates\make-japanese.bat 2016-01-07 16:03:42 C57198C273BDCB79C68D31FEC9601EE2 4060 ----a-w- C:\Program Files (x86)\Maxis\The Sims\UserData\Other Web Templates\Localization_Templates\make-englishUK.bat 2016-01-07 16:03:42 B3035188EFBFE7D768331EA7DC25D101 3732 ----a-w- C:\Program Files (x86)\Maxis\The Sims\UserData\Other Web Templates\Localization_Templates\make-french.bat 2016-01-07 16:03:42 AE5D4FCAC53DB04F623150DA359D1D16 4060 ----a-w- C:\Program Files (x86)\Maxis\The Sims\UserData\Other Web Templates\Localization_Templates\make-portuguese.bat 2016-01-07 16:03:42 A2843E9EACA905A3BC51BF2830709A52 3648 ----a-w- C:\Program Files (x86)\Maxis\The Sims\UserData\Other Web Templates\Localization_Templates\make-dutch.bat 2016-01-07 16:03:42 93A70D1D4F25C3CC9509FF42DDBF76B4 3814 ----a-w- C:\Program Files (x86)\Maxis\The Sims\UserData\Other Web Templates\Localization_Templates\make-spanish.bat 2016-01-07 16:03:42 8D7C72E7BE6467231C98A8008D4BC900 4798 ----a-w- C:\Program Files (x86)\Maxis\The Sims\UserData\Other Web Templates\Localization_Templates\make-TraditionalChinese.bat 2016-01-07 16:03:42 7D2F76CD1E254973166B99500826EA87 3568 ----a-w- C:\Program Files (x86)\Maxis\The Sims\UserData\Other Web Templates\Localization_Templates\make-thai.bat 2016-01-07 16:03:42 6F29A316CDE2C8F458D07E09DBEF064E 478 ----a-w- C:\Program Files (x86)\Maxis\The Sims\UserData\Other Web Templates\Localization_Templates\makeall.bat 2016-01-07 16:03:42 58C6FEF44D60343F2BA825D8EE8E1D73 28616 ----a-w- C:\Program Files (x86)\Maxis\The Sims\UserData\Other Web Templates\Localization_Templates\localize-all.bat 2016-01-07 16:03:42 508A6FCBF20A517D6D59960A2E4C9FEB 1323 ----a-w- C:\Program Files (x86)\Maxis\The Sims\UserData\Other Web Templates\Localization_Templates\localized-string-test.bat 2016-01-07 16:03:42 4C15FCE8783FE54D1E0C306CC0703CFC 3732 ----a-w- C:\Program Files (x86)\Maxis\The Sims\UserData\Other Web Templates\Localization_Templates\make-polish.bat 2016-01-07 16:03:42 2B2837DF8D63EF399F72BAC99142EA25 3814 ----a-w- C:\Program Files (x86)\Maxis\The Sims\UserData\Other Web Templates\Localization_Templates\make-english.bat 2016-01-07 16:03:42 0E53C35FD7F856510E00D702F07ECDF1 3732 ----a-w- C:\Program Files (x86)\Maxis\The Sims\UserData\Other Web Templates\Localization_Templates\make-german.bat 2016-01-07 16:03:42 0B338F81BAE409712E6183E6F59031B0 2360 ----a-w- C:\Program Files (x86)\Maxis\The Sims\UserData\Other Web Templates\Localization_Templates\testall.bat 2016-01-07 16:03:42 06F7B5565F4EFC702B51331F134887C8 3814 ----a-w- C:\Program Files (x86)\Maxis\The Sims\UserData\Other Web Templates\Localization_Templates\make-italian.bat 2016-01-07 16:03:42 0515D575FD693E77FEB06270CA5EFC75 3732 ----a-w- C:\Program Files (x86)\Maxis\The Sims\UserData\Other Web Templates\Localization_Templates\make-korean.bat 2016-01-07 16:03:42 0391C4BA070E98E744BDA397899DEB8D 3814 ----a-w- C:\Program Files (x86)\Maxis\The Sims\UserData\Other Web Templates\Localization_Templates\make-swedish.bat 2016-01-07 15:57:51 DCAF642BF2091D9ED68AF3AE84306992 46392 ----a-w- C:\Windows\System32\drivers\dtliteusbbus.sys 2016-01-07 15:57:45 679FF716052109392D870F6A6C4A3535 30264 ----a-w- C:\Windows\System32\drivers\dtlitescsibus.sys 2016-01-07 15:57:45 679FF716052109392D870F6A6C4A3535 30264 ------w- C:\Users\Cees\AppData\Local\Temp\{75a60445-6412-694c-ae8b-2a0ec397b450}\dtlitescsibus.sys 2016-01-07 15:41:00 9EDFBF3ED03A860A8720AA3C044FB670 292995285 ----a-w- C:\$Recycle.Bin\S-1-5-21-3775048874-3341839493-1509096462-1001\$RW5XMR9.zip 2016-01-07 14:15:24 30F2D2BA5D853D30F8B8E7766E7A0388 348855 ----a-w- C:\Users\Cees\Downloads\Concept adviesrapport groep 8 (1).zip 2016-01-05 17:03:02 D15426493411B2B278270211C62022E5 348855 ----a-w- C:\Users\Cees\Downloads\Concept adviesrapport groep 8.zip ==== Orphaned Tasks deleted from Registry ====================== avast Emergency Update deleted ==== Startup Registry Enabled ====================== [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "Autodesk Sync"="C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe" [HKEY_USERS\S-1-5-21-3775048874-3341839493-1509096462-1001\Software\Microsoft\Windows\CurrentVersion\Run] "Akamai NetSession Interface"="C:\Users\Cees\AppData\Local\Akamai\netsession_win.exe" "Spotify Web Helper"="C:\Users\Cees\AppData\Roaming\Spotify\SpotifyWebHelper.exe" "Spotify"="C:\Users\Cees\AppData\Roaming\Spotify\Spotify.exe -autostart -minimized" "Autodesk Sync"="C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe" "Dropbox Update"="C:\Users\Cees\AppData\Local\Dropbox\Update\DropboxUpdate.exe /c" "Steam"="C:\Program Files (x86)\Steam\steam.exe -silent" [HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run] "Autodesk Sync"="C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "AvastUI.exe"="C:\Program Files\AVAST Software\Avast\AvastUI.exe /nogui" "BCSSync"="C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe /DelayServices" "ADSKAppManager"="C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgr.exe -showminimized -checkautorun" "Adobe Creative Cloud"="C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe --showwindow=false --onOSstartup=true" "SunJavaUpdateSched"="C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "Akamai NetSession Interface"="C:\Users\Cees\AppData\Local\Akamai\netsession_win.exe" "Spotify Web Helper"="C:\Users\Cees\AppData\Roaming\Spotify\SpotifyWebHelper.exe" "Spotify"="C:\Users\Cees\AppData\Roaming\Spotify\Spotify.exe -autostart -minimized" "Autodesk Sync"="C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe" "Dropbox Update"="C:\Users\Cees\AppData\Local\Dropbox\Update\DropboxUpdate.exe /c" "Steam"="C:\Program Files (x86)\Steam\steam.exe -silent" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"="c:\\windows\\syswow64\\nvinit.dll,C:\\Windows\\SysWOW64\\nvinit.dll" ==== Startup Registry Enabled x64 ====================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NvBackend"="C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe" "ShadowPlay"="C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart" "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"="C:\\Windows\\system32\\nvinitx.dll" ==== Startup Folders ====================== 2014-10-03 15:02:47 1160 ----a-w- C:\Users\Cees\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ==== Task Scheduler Jobs ====================== C:\Windows\tasks\DropboxUpdateTaskUserS-1-5-21-3775048874-3341839493-1509096462-1001Core.job --a-------- C:\Users\Cees\AppData\Local\Dropbox\Update\DropboxUpdate.exe [16-06-2015 07:10] C:\Windows\tasks\DropboxUpdateTaskUserS-1-5-21-3775048874-3341839493-1509096462-1001UA.job --a-------- C:\Users\Cees\AppData\Local\Dropbox\Update\DropboxUpdate.exe [16-06-2015 07:10] C:\Windows\tasks\GoogleUpdateTaskMachineCore.job --a-------- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [29-08-2015 20:23] C:\Windows\tasks\GoogleUpdateTaskMachineUA.job --a-------- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [29-08-2015 20:23] ==== Other Scheduled Tasks ====================== "C:\Windows\SysNative\tasks\Adobe Acrobat Update Task" [C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe] "C:\Windows\SysNative\tasks\DropboxUpdateTaskUserS-1-5-21-3775048874-3341839493-1509096462-1001Core" [C:\Users\Cees\AppData\Local\Dropbox\Update\DropboxUpdate.exe] "C:\Windows\SysNative\tasks\DropboxUpdateTaskUserS-1-5-21-3775048874-3341839493-1509096462-1001UA" [C:\Users\Cees\AppData\Local\Dropbox\Update\DropboxUpdate.exe] "C:\Windows\SysNative\tasks\GoogleUpdateTaskMachineCore" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe] "C:\Windows\SysNative\tasks\GoogleUpdateTaskMachineUA" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe] "C:\Windows\SysNative\tasks\User_Feed_Synchronization-{9FC68A17-7DD6-4B80-B156-7E17DCD81FE2}" [C:\Windows\system32\msfeedssync.exe] "C:\Windows\SysNative\tasks\Apple\AppleSoftwareUpdate" [C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe] "C:\Windows\SysNative\tasks\AVAST Software\Avast settings backup" [C:\Program Files\Common Files\AV\avast Antivirus\backup.exe] "C:\Windows\SysNative\tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask" [%systemroot%\system32\sc.exe start osppsvc] ==== Firefox Extensions Registry ====================== [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions] "wrc@avast.com"="C:\Program Files\AVAST Software\Avast\WebRep\FF" [10-12-2015 15:57] ==== Firefox Extensions ====================== AppDir: C:\Program Files (x86)\Mozilla Firefox - Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} ==== Firefox Plugins ====================== Profilepath: C:\Users\Cees\AppData\Roaming\Mozilla\Firefox\Profiles\zwlaseht.default 1A62BB86D17B8DC0D4339BACC8D60635 - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_19_0_0_185.dll - Shockwave Flash ==== Chromium Look ====================== Google Chrome Version: 46.0.2490.86 HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions gomekmidlodglbbmalcneegieacbdmki - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx[20-07-2015 18:49] mkndcbhcgphcfkkddanakjiepeknbgle - C:\Program Files (x86)\RelevantKnowledge\rlcm.crx[] pfkfdlcdbajamklbneflfbcmfgddmpae - No path found[] HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\Extensions pfkfdlcdbajamklbneflfbcmfgddmpae - No path found[] Google Slides - Cees\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek Google Docs - Cees\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake Google Drive - Cees\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf YouTube - Cees\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo Google Search - Cees\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf Google Sheets - Cees\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap Google Docs Offline - Cees\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi AdBlock - Cees\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom Avast Online Security - Cees\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki Chrome Web Store Payments - Cees\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda Gmail - Cees\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia Google Slides - C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek Google Docs - C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake Google Drive - C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf YouTube - C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo Google Search - C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf Google Sheets - C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap Avast Online Security - C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki Chrome Web Store Payments - C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda Gmail - C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia ==== Chromium Fix ====================== C:\Users\Cees\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_nps.pastaleads.com_0.localstorage deleted successfully C:\Users\Cees\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_nps.pastaleads.com_0.localstorage-journal deleted successfully C:\Users\Cees\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_toolbar.yahoo.com_0.localstorage deleted successfully C:\Users\Cees\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_toolbar.yahoo.com_0.localstorage-journal deleted successfully C:\Users\Cees\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.azlyrics.com_0.localstorage deleted successfully C:\Users\Cees\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.azlyrics.com_0.localstorage-journal deleted successfully C:\Users\Cees\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.lyricsmode.com_0.localstorage deleted successfully C:\Users\Cees\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.lyricsmode.com_0.localstorage-journal deleted successfully C:\Users\Cees\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.marinetraffic.com_0.localstorage deleted successfully C:\Users\Cees\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.marinetraffic.com_0.localstorage-journal deleted successfully C:\Users\Cees\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_hdapp1008-a.akamaihd.net_0.localstorage deleted successfully C:\Users\Cees\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_hdapp1008-a.akamaihd.net_0.localstorage-journal deleted successfully C:\Users\Cees\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.superfish.com_0.localstorage deleted successfully C:\Users\Cees\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.superfish.com_0.localstorage-journal deleted successfully C:\Users\Cees\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_vacatures.trovit.nl_0.localstorage deleted successfully C:\Users\Cees\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_vacatures.trovit.nl_0.localstorage-journal deleted successfully C:\Users\Cees\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_gameslikefinder.com_0.localstorage deleted successfully C:\Users\Cees\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_gameslikefinder.com_0.localstorage-journal deleted successfully C:\Users\Cees\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_ads1.msads.net_0.localstorage deleted successfully C:\Users\Cees\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_ads1.msads.net_0.localstorage-journal deleted successfully C:\Users\Cees\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_c.betrad.com_0.localstorage deleted successfully C:\Users\Cees\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_c.betrad.com_0.localstorage-journal deleted successfully C:\Users\Cees\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_c.betrad.com_0.localstorage deleted successfully C:\Users\Cees\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_c.betrad.com_0.localstorage-journal deleted successfully C:\Users\Cees\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_mapsgalaxy.dl.tb.ask.com_0.localstorage deleted successfully C:\Users\Cees\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_mapsgalaxy.dl.tb.ask.com_0.localstorage-journal deleted successfully C:\Users\Cees\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_search.mynewtvsearch.com_0.localstorage deleted successfully C:\Users\Cees\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_search.mynewtvsearch.com_0.localstorage-journal deleted successfully C:\Users\Cees\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_search.tvplusnewtabsearch.com_0.localstorage deleted successfully C:\Users\Cees\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_search.tvplusnewtabsearch.com_0.localstorage-journal deleted successfully ==== Set IE to Default ====================== Old Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://www.msn.com/?PC=AV01" "Search Page"="http://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01" New Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896" "Start Page"="http://www.msn.com/?PC=AV01" ==== All HKLM and HKCU SearchScopes ====================== HKLM\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" HKLM\SearchScopes\{2E00D31D-D171-423D-836D-1A4D7EA7F1A9} - http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC HKLM\Wow6432Node\SearchScopes "DefaultScope"="{632F07F3-19A1-4d16-A23F-E6CE9486BAB5}" HKLM\Wow6432Node\SearchScopes\{632F07F3-19A1-4d16-A23F-E6CE9486BAB5} - http://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01 HKCU\SearchScopes "DefaultScope"="{632F07F3-19A1-4d16-A23F-E6CE9486BAB5}" HKCU\SearchScopes\{012E1000-F331-11DB-8314-0800200C9A66} - http://www.google.com/search?q={searchTerms} HKCU\SearchScopes\{2E00D31D-D171-423D-836D-1A4D7EA7F1A9} - http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02 HKCU\SearchScopes\{632F07F3-19A1-4d16-A23F-E6CE9486BAB5} - http://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01 HKCU\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B} - No_Url_Value ==== Reset Google Chrome ====================== C:\Users\Cees\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully C:\Users\Cees\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences was reset successfully C:\Users\Cees\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences.copy was reset successfully C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences was reset successfully C:\Users\Cees\AppData\Roaming\Opera Software\Opera Stable\Preferences was reset successfully C:\Users\Cees\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully C:\Users\Cees\AppData\Local\Google\Chrome\User Data\Default\Web Data-journal was reset successfully C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Web Data-journal was reset successfully C:\Users\Cees\AppData\Roaming\Opera Software\Opera Stable\Web Data was reset successfully C:\Users\Cees\AppData\Roaming\Opera Software\Opera Stable\Web Data-journal was reset successfully ==== Deleting CLSID Registry Keys ====================== ==== Deleting CLSID Registry Values ====================== HKEY_LOCAL_MACHINE\software\Wow6432Node\mozilla\Firefox\extensions\{C7AE725D-FA5C-4027-BB4C-787EF9F8248A} deleted successfully ==== Deleting Registry Keys ====================== HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\mkndcbhcgphcfkkddanakjiepeknbgle deleted successfully HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{d08d9f98-1c78-4704-87e6-368b0023d831} deleted successfully ==== Empty IE Cache ====================== C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Cees\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\Users\Cees\AppData\Local\Microsoft\Windows\INetCache\Low\Content.IE5 emptied successfully C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\Users\Cees\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully C:\Users\Cees\AppData\Local\Microsoft\Windows\INetCache\Low\IE emptied successfully C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully ==== Empty FireFox Cache ====================== C:\Users\Cees\AppData\Local\Mozilla\Firefox\Profiles\zwlaseht.default\cache2 emptied successfully ==== Empty Chrome Cache ====================== C:\Users\Cees\AppData\Local\Opera Software\Opera Stable\Cache emptied successfully C:\Users\Cees\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully ==== Empty All Flash Cache ====================== Flash Cache Emptied Successfully ==== Empty All Java Cache ====================== Java Cache cleared successfully ==== C:\zoek_backup content ====================== C:\zoek_backup (files=194 folders=65 42716500 bytes) ==== Empty Temp Folders ====================== C:\Users\Cees\AppData\Local\Temp will be emptied at reboot C:\Users\Default\AppData\Local\Temp emptied successfully C:\Users\Default User\AppData\Local\Temp emptied successfully C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully C:\Windows\Temp will be emptied at reboot ==== After Reboot ====================== ==== Empty Temp Folders ====================== C:\Windows\Temp successfully emptied C:\Users\Cees\AppData\Local\Temp successfully emptied ==== Empty Recycle Bin ====================== C:\$RECYCLE.BIN successfully emptied ==== EOF on ma 11-01-2016 at 15:10:48,95 ======================