Zoek.exe v5.0.0.1 Updated 31-December-2015 Tool run by Jive1 on di 19/01/2016 at 11:28:38,45. Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x64 Running in: Normal Mode Internet Access Detected Launched: C:\Users\Jive1\Desktop\zoek.exe [Scan all users] [Script inserted] ==== System Restore Info ====================== 19/01/2016 11:29:35 Zoek.exe System Restore Point Created Successfully. ==== Empty Folders Check ====================== C:\PROGRA~2\Advanced System Protector deleted successfully C:\PROGRA~3\MyDefrag deleted successfully C:\PROGRA~3\Systweak deleted successfully C:\Users\Jive1\AppData\Roaming\Gameo deleted successfully C:\Users\Jive1\AppData\Roaming\GoldenGate deleted successfully C:\Users\Jive1\AppData\Roaming\WarThunder deleted successfully C:\Users\Jive1\AppData\Local\eSupport.com deleted successfully C:\Users\Jive1\AppData\Local\Skype deleted successfully ==== Deleting CLSID Registry Keys ====================== ==== Deleting CLSID Registry Values ====================== ==== Installed Programs ====================== ACG's IWM Duxford ACG's IWM Duxford AI Pack 737-300 Pilot in Command ActiveSky Version 6 and ActiveSky Graphics ADF AI for FS2004 Adobe Acrobat Reader DC - Nederlands Adobe AIR Adobe Community Help Adobe Creative Suite 5 Master Collection Adobe Flash Player 20 ActiveX Adobe Flash Player 20 NPAPI Adobe Media Player Adobe Refresh Manager Advanced Driver Updater aerosoft's - Lissabon 2008 aerosoft's - Manhattan - FS2004 aerosoft's - Professional Flight Planner X aerosoft's - Sharm El-Sheikh 2012 - FS9 AI-Aircraft Editor Version 2.2.0.4 Aircraft Collection Alcor Micro USB Card Reader Driver Alleycode HTML Editor 2.2.1 Amberley Airport 2009 AUscene - Sydney Professional FS9 AUScene Adelaide International X v1.1 BitTorrent BullGuard Internet Security CCleaner Flight M‚diterran‚e Autogen Pack v1.0 FlightAlpes BasePack Nord FlightAlpes Nord AutogenPack FlightMediterranee BasePack FlightParis AutogenPack FlightParis CityPack FlightPyrenees Orientales AutogenPack FlightPyr‚n‚es Orientales BasePack FlightRiviera BasePack FlightSim Manager FPtoFMC 1.0.17 FS FlightTracker FS Sound Studio FSGenesis Australia 76.4m Terrain FSPLANET Spain VFR-Mesh Balearic Islands Google Update Helper Intel(R) Network Connections 18.7.28.0 Intel© Watchdog Timer Driver (Intel© WDT) Java 8 Update 66 Java Auto Updater La Baie du Mont-St-Michel La Guadeloupe La Martinique La R‚union Logitech Gaming Software 5.10 Mayotte Metric Collection SDK 35 Microsoft .NET Framework 4.5.2 Microsoft .NET Framework 4.5.2 (Nederlands) Microsoft .NET Framework 4.5.2 (NLD) Microsoft ASP.NET MVC 4 Runtime Microsoft Office 365 - nl-nl Microsoft OneDrive Microsoft Silverlight Microsoft Visual C++ 2005 Redistributable (x64) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.60610 Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.60610 Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.60610 Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.60610 Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.21005 Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.21005 Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - NLD Microsoft_VC80_ATL_x86 Microsoft_VC80_ATL_x86_x64 Microsoft_VC80_CRT_x86 Microsoft_VC80_CRT_x86_x64 Microsoft_VC80_MFC_x86 Microsoft_VC80_MFC_x86_x64 Microsoft_VC80_MFCLOC_x86 Microsoft_VC80_MFCLOC_x86_x64 Microsoft_VC90_ATL_x86 Microsoft_VC90_ATL_x86_x64 Microsoft_VC90_CRT_x86 Microsoft_VC90_CRT_x86_x64 Microsoft_VC90_MFC_x86 Microsoft_VC90_MFC_x86_x64 Military AI Works - RAAF 33 Squadron Mozilla Firefox 41.0.2 (x86 nl) Mozilla Maintenance Service Mozilla Thunderbird 38.5.0 (x86 nl) NVIDIA-configuratiescherm 361.43 NVIDIA 3D Vision controllerstuurprogramma 352.65 NVIDIA 3D Vision stuurprogramma 361.43 NVIDIA GeForce Experience 2.8.1.21 NVIDIA GeForce Experience Service NVIDIA Grafisch stuurprogramma 361.43 NVIDIA HD Audio-stuurprogramma 1.3.34.4 NVIDIA Install Application NVIDIA LED Visualizer 1.0 NVIDIA Network Service NVIDIA PhysX Systeem Software 9.15.0428 NVIDIA ShadowPlay 2.8.1.21 NVIDIA Stereoscopic 3D Driver NVIDIA Update 2.8.1.21 NVIDIA Update Core NVIDIA Virtual Audio 1.2.31 Office 15 Click-to-Run Extensibility Component Office 15 Click-to-Run Licensing Component Office 15 Click-to-Run Localization Component Office 16 Click-to-Run Licensing Component Orbx Tamworth Freeware 1.0 PDF Settings CS5 Pole to Pole FSX PrintKey2000 PxMergeModule RAF Waddington by John Young (UKMIL) FS2004 Realtek High Definition Audio Driver Rennes St-Jacques Riviera JetSet Security Update for Microsoft .NET Framework 4.5.2 (KB2972107) Security Update for Microsoft .NET Framework 4.5.2 (KB2972216) Security Update for Microsoft .NET Framework 4.5.2 (KB2978128) Security Update for Microsoft .NET Framework 4.5.2 (KB2979578v2) Security Update for Microsoft .NET Framework 4.5.2 (KB3023224) Security Update for Microsoft .NET Framework 4.5.2 (KB3035490) Security Update for Microsoft .NET Framework 4.5.2 (KB3037581) Security Update for Microsoft .NET Framework 4.5.2 (KB3074230) Security Update for Microsoft .NET Framework 4.5.2 (KB3074550) Security Update for Microsoft .NET Framework 4.5.2 (KB3097996) Security Update for Microsoft .NET Framework 4.5.2 (KB3098781) SHIELD Streaming SHIELD Wireless Controller Driver SkypeT 7.17 Sofia Airport (LBSF) South African Air Force Ai Package - 21 Squadron AFB Waterkloof Speccy Taalpakket voor Microsoft Visual Studio 2010 Tools for Office Runtime (x64) - NLD VC_CRT_x64 VOZ AI 1.2 WinImage WinRAR 5.10 (64-bit) WinZip 12.0 ==== Running Processes ====================== C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe C:\Program Files (x86)\Skype\Phone\Skype.exe C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe D:\FS9 Addon Programs\FMS Data Manager\NGFMSAgent.exe C:\Program Files (x86)\PrintKey2000\Printkey2000.exe C:\Program Files\Microsoft Office 15\root\office15\ONENOTEM.EXE C:\Program Files\BullGuard Ltd\BullGuard\Files32\Spamfilter\LittleHook.exe C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe C:\Program Files\Microsoft Office 15\root\office15\OUTLOOK.EXE C:\Users\Jive1\Desktop\zoek.exe C:\Windows\SysWOW64\cmd.exe C:\Windows\SysWOW64\cmd.exe C:\Windows\SysWOW64\cmd.exe ==== Deleting Services ====================== ==== Deleting Files \ Folders ====================== C:\PROGRA~2\Advanced System Protector not found C:\PROGRA~2\Advanced Driver Updater deleted C:\Users\Jive1\AppData\Roaming\Systweak deleted C:\Users\Jive1\AppData\Local\Gameo deleted "C:\Users\Jive1\AppData\Local\Systweak\Advanced System Protector\aspcontexthelper64.dll" deleted "C:\Users\Jive1\AppData\Local\Systweak" not deleted "C:\Users\Jive1\AppData\Local\Systweak\Advanced System Protector" not deleted ==== System Specs ====================== Windows: Windows 7 Home Premium Edition (64-bit) Service Pack 1 (Build 7601) Memory (RAM): 8170 MB CPU Info: Intel(R) Core(TM) i3-2120 CPU @ 3.30GHz CPU Speed: 3263,8 MHz Sound Card: Luidsprekers (Realtek High Defi | Realtek Digital Output (Realtek | Realtek Digital Output(Optical) | Display Adapters: NVIDIA GeForce GT 430 | NVIDIA GeForce GT 430 | RDPDD Chained DD | RDP Encoder Mirror Driver | RDP Reflector Display Driver Monitors: 2x; Algemeen PnP-beeldscherm | Algemeen PnP-beeldscherm | Screen Resolution: 1280 X 1024 - 32 bit Network: Network Present Network Adapters: Intel(R) 82579V Gigabit Network Connection CD / DVD Drives: 1x (F: | ) F: TSSTcorpCDDVDW SH-222AB Ports: COM1 LPT1 Mouse: 8 Button Wheel Mouse Present Hard Disks: C: 120,1GB | D: 596,2GB | E: 791,8GB | I: 232,9GB | J: 100,0MB Hard Disks - Free: C: 45,5GB | D: 483,4GB | E: 647,8GB | I: 212,4GB | J: 31,7MB Manufacturer *: Intel Corp. BIOS Info: AT/AT COMPATIBLE | 02/18/11 | INTEL - 1072009 Time Zone: Romance (standaardtijd) Motherboard *: Intel Corporation DH61BE Country: Belgi‰ Language: NLB ==== System Specs (Software) ====================== AV: BullGuard Antivirus *Disabled/Outdated* {EDBB5818-2352-E06B-028A-4E6873B92CC5} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} SP: BullGuard Antispyware *Disabled/Outdated* {56DAB9FC-0568-EFE5-383A-751A083E6678} FW: BullGuard Firewall *Enabled* {D580D93D-693D-E133-29D5-E75D8D6A6BBE} Default Browser: Internet Explorer 11.00.9600.16428 (winblue_gdr.131013-1700) Internet Explorer Version: 11.0.9600.18163 Mozilla Firefox version: 41.0.2 (x86 nl) Adobe Reader version: 15.10.20056.167417 Sun Java version: 1.8.0_66 (32-bit) Sun Java version: 1.8.0_66 (64-bit) Flash Player version: 20.0.0.267 ==== Files Recently Created / Modified ====================== ====== C:\Windows ==== 2016-01-17 08:00:29 FBEE1541BE67787ED5BB21E6FC65B479 776414946 ----a-w- C:\Windows\MEMORY.DMP 2015-12-24 07:37:36 84B4F61F59A421BD85D97B35D194B42B 86016 ----a-w- C:\Windows\unvise32.exe ====== C:\Users\Jive1\AppData\Local\Temp ==== ====== Java Cache ===== ====== C:\Windows\SysWOW64 ===== 2016-01-18 06:41:39 90E480789256D852FA3EADD39D56FDDA 6131200 ----a-w- C:\Windows\SysWOW64\mstscax.dll 2016-01-18 06:41:38 AF0EC95144F76EA4B40A7ED1DD34616C 856064 ----a-w- C:\Windows\SysWOW64\rdvidcrl.dll 2016-01-18 06:41:38 A27593907607A692D0DE105DE29BBC33 53248 ----a-w- C:\Windows\SysWOW64\tsgqec.dll 2016-01-15 06:52:47 AB5EFB103DB01C1912C9D2F545EA5621 17920 ----a-w- C:\Windows\SysWOW64\wksprtPS.dll 2016-01-15 06:52:47 4676AAA9DDF52A50C829FEDB4EA81E54 1068544 ----a-w- C:\Windows\SysWOW64\mstsc.exe 2016-01-15 06:52:47 2EFB1279E7BEA7D12D9F4D6508D27880 50176 ----a-w- C:\Windows\SysWOW64\MsRdpWebAccess.dll 2016-01-15 06:51:32 8999F18D38D55E34D356796507FFD639 192000 ----a-w- C:\Windows\SysWOW64\rdpendp_winip.dll 2016-01-13 12:57:38 76B7EC2E3BED892898A41D2553942063 103032 ----a-w- C:\Windows\SysWOW64\nvStreaming.exe 2016-01-13 12:55:19 E055A4CA94E125D16060C7F08BA6938D 24895792 ----a-w- C:\Windows\SysWOW64\nvoglv32.dll 2016-01-13 12:55:19 D86C3F63A3054D253F26AFCA6C99FDF9 734512 ----a-w- C:\Windows\SysWOW64\NvFBC.dll 2016-01-13 12:55:19 C8D4786D67016C1DCDC93633F97A3061 17561432 ----a-w- C:\Windows\SysWOW64\nvopencl.dll 2016-01-13 12:55:19 BD246B5D5288ACB98ACFA97F5A5DBAA6 128696 ----a-w- C:\Windows\SysWOW64\nvoglshim32.dll 2016-01-13 12:55:19 B1DD0BBBECA17DA468B53243AC974DB4 388560 ----a-w- C:\Windows\SysWOW64\nvumdshim.dll 2016-01-13 12:55:19 A5EDBC82F438509F18A67798A9201177 681592 ----a-w- C:\Windows\SysWOW64\NvIFR.dll 2016-01-13 12:55:19 9FC8BA86F48EF209C5F7204B12CC4AF2 17156968 ----a-w- C:\Windows\SysWOW64\nvcuda.dll 2016-01-13 12:55:19 89C6BCBEE38D38A3B9E5C3F02BB6E6CF 37609080 ----a-w- C:\Windows\SysWOW64\nvcompiler.dll 2016-01-13 12:55:19 27838AF5492771763D5766289B754162 14005408 ----a-w- C:\Windows\SysWOW64\nvd3dum.dll 2016-01-13 12:55:19 17BB951DC4985710F175458E0F8B8D16 2755704 ----a-w- C:\Windows\SysWOW64\nvcuvid.dll 2016-01-13 12:55:19 06892D99046A9DEB29C90D9E8CB02F5A 153392 ----a-w- C:\Windows\SysWOW64\nvinit.dll 2016-01-13 06:39:59 4489D5077C5D2396E3A94D652ADAE1CA 14336 ----a-w- C:\Windows\SysWOW64\fixmapi.exe 2016-01-13 06:39:59 2BB34CC2D6DF7194F46C6508589EF8FD 76800 ----a-w- C:\Windows\SysWOW64\mapistub.dll 2016-01-13 06:39:59 2BB34CC2D6DF7194F46C6508589EF8FD 76800 ----a-w- C:\Windows\SysWOW64\mapi32.dll 2016-01-13 06:39:56 BBCD95BC468665A596D7ED2D6233A34E 509952 ----a-w- C:\Windows\SysWOW64\qedit.dll 2016-01-13 06:39:54 EDCAA72A69E36517F1493F09B8A834F7 829952 ----a-w- C:\Windows\SysWOW64\MSMPEG2ENC.DLL 2016-01-13 06:39:54 D1450810490EB170A182C4AC915CB87C 1620992 ----a-w- C:\Windows\SysWOW64\WMVDECOD.DLL 2016-01-13 06:39:54 B049A75BD074FC465D2BCE2BF5B15D75 3209728 ----a-w- C:\Windows\SysWOW64\mf.dll 2016-01-13 06:39:54 A0448DC7978E550FE64B9A984522B963 815616 ----a-w- C:\Windows\SysWOW64\WMADMOE.DLL 2016-01-13 06:39:54 96FF617934E6A87AA810719D1D911DA9 541184 ----a-w- C:\Windows\SysWOW64\WMVSDECD.DLL 2016-01-13 06:39:54 7368176B23E9BE5D23ED9BFE1D58AC0C 902144 ----a-w- C:\Windows\SysWOW64\WMADMOD.DLL 2016-01-13 06:39:54 62851F0D13AD06F0042C8109E680421F 739328 ----a-w- C:\Windows\SysWOW64\WMSPDMOD.DLL 2016-01-13 06:39:54 3CC0EF43C256D0A28C908F36AD06963D 970240 ----a-w- C:\Windows\SysWOW64\msmpeg2adec.dll 2016-01-13 06:39:53 FEAEA5182DB9072EBD493466F8608EB8 1568768 ----a-w- C:\Windows\SysWOW64\WMVENCOD.DLL 2016-01-13 06:39:53 EDB8F80672DBF24C6C522A29F5854F14 153600 ----a-w- C:\Windows\SysWOW64\COLORCNV.DLL 2016-01-13 06:39:53 B25C60E9ED641AFF18198CBF6C288DB8 740352 ----a-w- C:\Windows\SysWOW64\wmpmde.dll 2016-01-13 06:39:53 89FBB1C25E02767572AB1F136EE8CD04 1329664 ----a-w- C:\Windows\SysWOW64\quartz.dll 2016-01-13 06:39:53 71C9DDA9ED939361C1CA2CE21EA84DBF 665088 ----a-w- C:\Windows\SysWOW64\WMVXENCD.DLL 2016-01-13 06:39:53 65EED8B27B02573948434B583DACFB39 489984 ----a-w- C:\Windows\SysWOW64\evr.dll 2016-01-13 06:39:52 D6A767B747F4D58EBDAAD1925DC863FA 206848 ----a-w- C:\Windows\SysWOW64\RESAMPLEDMO.DLL 2016-01-13 06:39:52 BE2D4165A6845FEE05CBD36D8B41E518 193536 ----a-w- C:\Windows\SysWOW64\ksproxy.ax 2016-01-13 06:39:52 A7FAA81D1622D6AF4467A81B42D30DBE 241152 ----a-w- C:\Windows\SysWOW64\MPG4DECD.DLL 2016-01-13 06:39:52 92BBFF13DE00F30DABC03CFF59D8678E 609280 ----a-w- C:\Windows\SysWOW64\MFWMAAEC.DLL 2016-01-13 06:39:52 8A2A7AA90CBA77DD44FBAE713B4B3877 415744 ----a-w- C:\Windows\SysWOW64\MP4SDECD.DLL 2016-01-13 06:39:52 7C135C38EC6586F7562CFBC184A514E2 2285056 ----a-w- C:\Windows\SysWOW64\msmpeg2vdec.dll 2016-01-13 06:39:52 78E7D511C9FB80ADC9A1DD22CCF66C0E 519680 ----a-w- C:\Windows\SysWOW64\qdvd.dll 2016-01-13 06:39:52 6B1BB70E72B573EBDF1235B77DF5706D 1325056 ----a-w- C:\Windows\SysWOW64\WMSPDMOE.DLL 2016-01-13 06:39:52 66EB4C814BF7BD76CF7CBC7F562234BA 67584 ----a-w- C:\Windows\SysWOW64\devenum.dll 2016-01-13 06:39:52 5DCE986C8D7E91B455FB3D57BF955A2A 79872 ----a-w- C:\Windows\SysWOW64\MP3DMOD.DLL 2016-01-13 06:39:52 5CF623B21998B8F1D081D55910A0BDA7 206848 ----a-w- C:\Windows\SysWOW64\qasf.dll 2016-01-13 06:39:52 5342DCCA8EA8ED193ACAAD14A5046982 354816 ----a-w- C:\Windows\SysWOW64\mfplat.dll 2016-01-13 06:39:52 2C838797F2F6138EF36C8964487775B9 358400 ----a-w- C:\Windows\SysWOW64\WMVSENCD.DLL 2016-01-13 06:39:52 24D74CF313DC62C65EEA4726AE2EB3F8 154112 ----a-w- C:\Windows\SysWOW64\VIDRESZR.DLL 2016-01-13 06:39:52 0697FF546D6D70AE7F77EF6398004153 241152 ----a-w- C:\Windows\SysWOW64\MP43DECD.DLL 2016-01-13 06:39:51 FEB2B13697D1C482D84FB626A0F1F73A 2048 ----a-w- C:\Windows\SysWOW64\mferror.dll 2016-01-13 06:39:51 BBE4D9B89B3FBC97C0F381C2F9C4ADEF 23040 ----a-w- C:\Windows\SysWOW64\mfpmp.exe 2016-01-13 06:39:51 A4C85F362EBB7815676F1CD9CFC5BA59 4608 ----a-w- C:\Windows\SysWOW64\ksuser.dll 2016-01-13 06:39:51 936E6F6F76136BC73B13D25A254BC84B 50176 ----a-w- C:\Windows\SysWOW64\rrinstaller.exe 2016-01-13 06:39:51 4FBCDC326769C31CB283981A51C867F3 53248 ----a-w- C:\Windows\SysWOW64\mfvdsp.dll 2016-01-13 06:39:51 41BAC1A440EAA15AD4CC15B0C7870AB0 103424 ----a-w- C:\Windows\SysWOW64\mfps.dll 2016-01-13 06:39:48 D47060A0923B50FB9E4DD5D9DE0C7402 76288 ----a-w- C:\Windows\SysWOW64\mshtmled.dll 2016-01-13 06:39:48 CA0F8D2342A719DEA69C7840B0BB5F4B 2280448 ----a-w- C:\Windows\SysWOW64\iertutil.dll 2016-01-13 06:39:48 C5B72E7048DEEE1B264D7155C77241C5 341192 ----a-w- C:\Windows\SysWOW64\iedkcs32.dll 2016-01-13 06:39:48 AB90455CBD34BDE95F463C02C4D3FF50 1311744 ----a-w- C:\Windows\SysWOW64\urlmon.dll 2016-01-13 06:39:48 A786A11EE4C05BC3AE924344F10275DE 496640 ----a-w- C:\Windows\SysWOW64\vbscript.dll 2016-01-13 06:39:48 67527FD222AD6842F98A733DF52C8416 130048 ----a-w- C:\Windows\SysWOW64\occache.dll 2016-01-13 06:39:48 49FBB053E3AC19EEE92AE8492CDA7E91 30720 ----a-w- C:\Windows\SysWOW64\iernonce.dll 2016-01-13 06:39:48 3C9399B72F7FFB9EE63BB173B481340E 64000 ----a-w- C:\Windows\SysWOW64\MshtmlDac.dll 2016-01-13 06:39:48 18B231ACA137116CF16DBE3EBD7FDB5D 47616 ----a-w- C:\Windows\SysWOW64\ieetwproxystub.dll 2016-01-13 06:39:48 06CEABA53DA48B45C2B23F52C8C9EA72 60416 ----a-w- C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2016-01-13 06:39:47 D120251F43699D6C08E13950C3C72978 20367360 ----a-w- C:\Windows\SysWOW64\mshtml.dll 2016-01-13 06:39:47 B26FB4205FDB1542166C1D8D7D1968C0 279040 ----a-w- C:\Windows\SysWOW64\dxtrans.dll 2016-01-13 06:39:47 8E5DD507EC43B5C738EB0289A9663670 687104 ----a-w- C:\Windows\SysWOW64\msfeeds.dll 2016-01-13 06:39:46 DAEFD0F03CA94242ACB5C3C1359176D3 62464 ----a-w- C:\Windows\SysWOW64\iesetup.dll 2016-01-13 06:39:45 9DA0FD6D5B8E2FAD8967A617FD142C6D 2050560 ----a-w- C:\Windows\SysWOW64\inetcpl.cpl 2016-01-13 06:39:44 D1348E7209031F20BC8864DA8CA2F955 47104 ----a-w- C:\Windows\SysWOW64\jsproxy.dll 2016-01-13 06:39:44 CFA5159B0C90A82D28314571E8B64775 416256 ----a-w- C:\Windows\SysWOW64\dxtmsft.dll 2016-01-13 06:39:44 C5BF6D661A8EFB996AD5E4B88FFBD7FD 476160 ----a-w- C:\Windows\SysWOW64\ieui.dll 2016-01-13 06:39:44 C2806F9A73E738CDC0718E5D7375BDCB 2724864 ----a-w- C:\Windows\SysWOW64\mshtml.tlb 2016-01-13 06:39:44 862FF89AEF127D001ADBF75095D5ECB1 12856320 ----a-w- C:\Windows\SysWOW64\ieframe.dll 2016-01-13 06:39:44 83F409B2EC14007F6D7E2EA485E6B7D9 620032 ----a-w- C:\Windows\SysWOW64\jscript9diag.dll 2016-01-13 06:39:44 73C47A23B212481ABF01924B5C74C140 663552 ----a-w- C:\Windows\SysWOW64\jscript.dll 2016-01-13 06:39:43 FFA261B9252C71A6910B4F19FDC1EA57 2011136 ----a-w- C:\Windows\SysWOW64\wininet.dll 2016-01-13 06:39:43 D5E9072573EEE8DFEF63CD38640F6D35 710144 ----a-w- C:\Windows\SysWOW64\ieapfltr.dll 2016-01-13 06:39:43 6D7983A5DFD58E54159D2A03558D4BCE 4610560 ----a-w- C:\Windows\SysWOW64\jscript9.dll 2016-01-13 06:39:43 424300DDB7A1B24199C9B481438F55E9 115712 ----a-w- C:\Windows\SysWOW64\ieUnatt.exe 2016-01-13 06:39:43 21784CDE61E83DBCB42DA6C2A374D69A 1155072 ----a-w- C:\Windows\SysWOW64\mshtmlmedia.dll 2016-01-13 06:39:43 0DABE887449758C9E70FFB253A787D44 230400 ----a-w- C:\Windows\SysWOW64\webcheck.dll 2016-01-13 06:39:42 2C10833C0180FEE2AEB6DAEB76FD16E7 341504 ----a-w- C:\Windows\SysWOW64\html.iec 2016-01-13 06:39:42 063A81A53400EA55D27AFC77C49A5B4B 168960 ----a-w- C:\Windows\SysWOW64\msrating.dll 2016-01-13 06:39:15 E8D68D619AAF4E78850DF96B5E53EA03 641536 ----a-w- C:\Windows\SysWOW64\advapi32.dll 2016-01-13 06:39:12 7FD1DCF4F11C61621AE9279E26FADCF3 312320 ----a-w- C:\Windows\SysWOW64\gdi32.dll 2016-01-13 06:39:05 68EC4300B8EF8D7E2B857FABB91F3EFB 552960 ----a-w- C:\Windows\SysWOW64\kerberos.dll 2016-01-13 06:39:04 D92212049589535FBB25B806FF8A20C5 665088 ----a-w- C:\Windows\SysWOW64\rpcrt4.dll 2016-01-13 06:39:04 AFCF45621028D4B6D252B1429A07A530 251392 ----a-w- C:\Windows\SysWOW64\schannel.dll 2016-01-13 06:39:04 A8D4C2B034947F2445F5099E6B3173C8 3938240 ----a-w- C:\Windows\SysWOW64\ntoskrnl.exe 2016-01-13 06:39:04 1615874D0262DA99E565D4FE6F74F7DD 3993536 ----a-w- C:\Windows\SysWOW64\ntkrnlpa.exe 2016-01-13 06:39:03 E149FE1FD23748986551F4E1F5752090 1114112 ----a-w- C:\Windows\SysWOW64\kernel32.dll 2016-01-13 06:39:03 DC9222A325ACFC29E019013505AE33DB 171520 ----a-w- C:\Windows\SysWOW64\wdigest.dll 2016-01-13 06:39:03 CE283E9E462E8FC95F7DC5DAF39D09FA 223232 ----a-w- C:\Windows\SysWOW64\ncrypt.dll 2016-01-13 06:39:03 9E02351A74A6F1FA0F46405583525959 1311768 ----a-w- C:\Windows\SysWOW64\ntdll.dll 2016-01-13 06:39:03 678A679C5E416A93A71DA3D4241692B0 259584 ----a-w- C:\Windows\SysWOW64\msv1_0.dll 2016-01-13 06:39:01 ED43479669D84DC8A4385E6AC2CF5A7F 22016 ----a-w- C:\Windows\SysWOW64\secur32.dll 2016-01-13 06:39:01 ECA0236432A1C2E695FD50C3AC4CAFCE 36352 ----a-w- C:\Windows\SysWOW64\cryptbase.dll 2016-01-13 06:39:01 BFDCF4944CC86AB5A59B605637C82090 43008 ----a-w- C:\Windows\SysWOW64\srclient.dll 2016-01-13 06:39:01 BC5142F61047916EA677908F98F3A7C2 274944 ----a-w- C:\Windows\SysWOW64\KernelBase.dll 2016-01-13 06:39:01 AE6E759632A0F931CFB626EED55C3E99 50176 ----a-w- C:\Windows\SysWOW64\auditpol.exe 2016-01-13 06:39:01 8E3915AF90315E4ED96D4CAE316E8F21 7680 ----a-w- C:\Windows\SysWOW64\instnm.exe 2016-01-13 06:39:01 69048141035DEDA0D3AFB28367622130 17408 ----a-w- C:\Windows\SysWOW64\credssp.dll 2016-01-13 06:39:01 5A3BF056627B6A7C348FD7AF420741E1 6656 ----a-w- C:\Windows\SysWOW64\apisetschema.dll 2016-01-13 06:39:01 4743B91B77F4B8CEF891ABF00C1E0055 14336 ----a-w- C:\Windows\SysWOW64\ntvdm64.dll 2016-01-13 06:39:01 41560C9C4CCA31FC3B0CA192B113F68F 96768 ----a-w- C:\Windows\SysWOW64\sspicli.dll 2016-01-13 06:39:01 16A3C3CCDB7ECFD2A72DAFED734B22BB 65536 ----a-w- C:\Windows\SysWOW64\TSpkg.dll 2016-01-13 06:39:01 1418C1A502A9540A4726B4935229E7B9 25600 ----a-w- C:\Windows\SysWOW64\setup16.exe 2016-01-13 06:39:01 119F46197BABD04BE1E2DDD50E782DAC 5120 ----a-w- C:\Windows\SysWOW64\wow32.dll 2016-01-13 06:39:00 EA5A0A356F6DB3D4177568FF084AD367 60416 ----a-w- C:\Windows\SysWOW64\msobjs.dll 2016-01-13 06:39:00 B9E8D6170C3325895EF3E1E5699A6F8B 686080 ----a-w- C:\Windows\SysWOW64\adtschema.dll 2016-01-13 06:39:00 80497842956847806BC7DAD11A18D9D4 146432 ----a-w- C:\Windows\SysWOW64\msaudite.dll 2016-01-13 06:39:00 59541469E828B311B1E5EEA77E6F6BE7 2048 ----a-w- C:\Windows\SysWOW64\user.exe 2016-01-09 09:20:06 2A76C952FF888B8F9AE7803E9D613EC4 19021504 ----a-w- C:\Windows\SysWOW64\FlashPlayerInstaller.exe ====== C:\Windows\SysWOW64\drivers ===== 2015-12-30 13:51:42 29CCFF428E5EB70AE429C3DA8968E1EC 20872 ----a-w- C:\Windows\SysWOW64\drivers\DrvAgent64.SYS ====== C:\Windows\Sysnative ===== 2016-01-18 06:41:39 C01DC60229F41D33AF2DF4162EDA0F44 7077376 ----a-w- C:\Windows\Sysnative\mstscax.dll 2016-01-18 06:41:39 2686F572B3CAF633C4A350A3671835F2 429568 ----a-w- C:\Windows\Sysnative\wksprt.exe 2016-01-18 06:41:38 CDA122FCC691D14D3971A83AB035156D 62976 ----a-w- C:\Windows\Sysnative\tsgqec.dll 2016-01-18 06:41:38 35A97817FDA4C8F421D8478DCCF045B1 1057792 ----a-w- C:\Windows\Sysnative\rdvidcrl.dll 2016-01-17 06:39:45 F6D23F6707CAEA235E4C84A4AC87EB2A 3180544 ----a-w- C:\Windows\Sysnative\rdpcorets.dll 2016-01-17 06:39:45 960D313FFBC9C4C14D9DFDB1FEB21CBD 16384 ----a-w- C:\Windows\Sysnative\RdpGroupPolicyExtension.dll 2016-01-17 06:39:45 15C3986C015EA186BCB4E6096528D656 243200 ----a-w- C:\Windows\Sysnative\rdpudd.dll 2016-01-17 06:39:18 2A9C3ADBC3B9D061CACDEFFBED67683C 87040 ----a-w- C:\Windows\Sysnative\TSWbPrxy.exe 2016-01-15 06:52:49 DDED7C5558B3AE09F568945281A9A6D1 44544 ----a-w- C:\Windows\Sysnative\TsUsbGDCoInstaller.dll 2016-01-15 06:52:48 FEC6178962DFF33074D39CA907971405 12800 ----a-w- C:\Windows\Sysnative\TsUsbRedirectionGroupPolicyExtension.dll 2016-01-15 06:52:48 108C257D765AAD2E6EC46557DA0B02BD 13824 ----a-w- C:\Windows\Sysnative\TsUsbRedirectionGroupPolicyControl.exe 2016-01-15 06:52:47 8E75B1112C374EBDF18FD640DA2F0655 1147392 ----a-w- C:\Windows\Sysnative\mstsc.exe 2016-01-15 06:52:47 7BD2E6E2458A5B95F8341244C7FC7DD4 18944 ----a-w- C:\Windows\Sysnative\wksprtPS.dll 2016-01-15 06:52:47 149A388C17F04AD1F99B477A43BE1A9F 56832 ----a-w- C:\Windows\Sysnative\MsRdpWebAccess.dll 2016-01-15 06:51:32 D346E07D62E3D4BEAB040939744EC31B 228864 ----a-w- C:\Windows\Sysnative\rdpendp_winip.dll 2016-01-15 06:49:31 2CE2E6C71FD01B1DF8992EE5768A8CAD 22528 ----a-w- C:\Windows\Sysnative\icaapi.dll 2016-01-13 12:56:53 AE80845BBD5CBF2BAA2C9E5B8E6FC253 523384 ----a-w- C:\Windows\Sysnative\nv3dappshext.dll 2016-01-13 12:56:53 0F2553D40638B74843CE2CC6CDB13A03 75056 ----a-w- C:\Windows\Sysnative\nv3dappshextr.dll 2016-01-13 12:55:19 F6FFEDA793E5CF0542E2771486E07800 3637352 ----a-w- C:\Windows\Sysnative\nvapi64.dll 2016-01-13 12:55:19 EED0C2F46A61858FB2BE98C40A3E8FEB 3168376 ----a-w- C:\Windows\Sysnative\nvcuvid.dll 2016-01-13 12:55:19 CC1B87A5937D76175D4195ADE3B3FEB8 469144 ----a-w- C:\Windows\Sysnative\nvumdshimx.dll 2016-01-13 12:55:19 CB566896D237AC5C226FA3E7CEFC4D11 21122456 ----a-w- C:\Windows\Sysnative\nvopencl.dll 2016-01-13 12:55:19 B4482ADF47BE0DD507C10B5802ACBCA4 31061624 ----a-w- C:\Windows\Sysnative\nvoglv64.dll 2016-01-13 12:55:19 9FDBC606671FBDF5092974A867E0F211 20663816 ----a-w- C:\Windows\Sysnative\nvcuda.dll 2016-01-13 12:55:19 8002D0464884782D90D2055F2E3A02B8 872056 ----a-w- C:\Windows\Sysnative\NvIFR64.dll 2016-01-13 12:55:19 7BD0E6BE3C471B5EFE25B65BD6EEB774 175368 ----a-w- C:\Windows\Sysnative\nvinitx.dll 2016-01-13 12:55:19 6DAC0C54199F6DD671273AED47479D70 938104 ----a-w- C:\Windows\Sysnative\NvFBC64.dll 2016-01-13 12:55:19 3A5F770A53230EBAB1AF9BFE689A43A2 16981976 ----a-w- C:\Windows\Sysnative\nvd3dumx.dll 2016-01-13 12:55:19 35C7532D4A276219D48CB645F0398ADE 151184 ----a-w- C:\Windows\Sysnative\nvoglshim64.dll 2016-01-13 12:55:19 2D59DBD3C07B0C735BD3B51B2D25244A 1915696 ----a-w- C:\Windows\Sysnative\nvdispco6436143.dll 2016-01-13 12:55:19 27DDB2ABC9025988C37B08BB0602AFEB 1564976 ----a-w- C:\Windows\Sysnative\nvdispgenco6436143.dll 2016-01-13 12:55:19 1D91530C02C02B2C199C2519C3CD09AD 42977072 ----a-w- C:\Windows\Sysnative\nvcompiler.dll 2016-01-13 06:39:59 73DC9840FE246158ECCBC8270847CCBC 91648 ----a-w- C:\Windows\Sysnative\mapistub.dll 2016-01-13 06:39:59 73DC9840FE246158ECCBC8270847CCBC 91648 ----a-w- C:\Windows\Sysnative\mapi32.dll 2016-01-13 06:39:58 2FFBA1EAE28B45A92E2EA70C61C66F14 17920 ----a-w- C:\Windows\Sysnative\fixmapi.exe 2016-01-13 06:39:57 EC1E743D4DB6C6EBEDCEB4B4C8E1905A 1164800 ----a-w- C:\Windows\Sysnative\aeinv.dll 2016-01-13 06:39:57 D33DF59002203FED8DE6087256DFDE89 624640 ----a-w- C:\Windows\Sysnative\qedit.dll 2016-01-13 06:39:55 27221616A71A25E0B7065926FCC417A7 1307136 ----a-w- C:\Windows\Sysnative\msmpeg2adec.dll 2016-01-13 06:39:54 FF5D49FAA86DBD9033DABC1ABCEA3429 1232896 ----a-w- C:\Windows\Sysnative\WMADMOD.DLL 2016-01-13 06:39:54 BF9CFEE3D22CE61E5B57C9B8A14F172D 1026048 ----a-w- C:\Windows\Sysnative\wmpmde.dll 2016-01-13 06:39:54 B7CBAC1F4175C1D59B197020268A290B 1153024 ----a-w- C:\Windows\Sysnative\WMADMOE.DLL 2016-01-13 06:39:54 91E1D7BE8513032B5CCA26AFD0BF0ADC 666112 ----a-w- C:\Windows\Sysnative\WMVSDECD.DLL 2016-01-13 06:39:54 5EA57A6AD59D0785C9A390DF14736899 978944 ----a-w- C:\Windows\Sysnative\WMSPDMOD.DLL 2016-01-13 06:39:54 5BAEB6D045DA253787F3F1984B712835 1888768 ----a-w- C:\Windows\Sysnative\WMVDECOD.DLL 2016-01-13 06:39:54 55C3F89354C086EFFF1C5AAD1E808134 1160192 ----a-w- C:\Windows\Sysnative\MSMPEG2ENC.DLL 2016-01-13 06:39:54 530B3A72692DB253DE8BB8E8C11468DD 1010688 ----a-w- C:\Windows\Sysnative\mcmde.dll 2016-01-13 06:39:54 3B6466686CDC57453592E6188C3FA4DC 4121600 ----a-w- C:\Windows\Sysnative\mf.dll 2016-01-13 06:39:53 E6A0093D872D860BEA437DF6C666DF89 632320 ----a-w- C:\Windows\Sysnative\evr.dll 2016-01-13 06:39:53 DB018B9F38BC34E9AE21C01448E810D2 1575424 ----a-w- C:\Windows\Sysnative\WMSPDMOE.DLL 2016-01-13 06:39:53 B62CEF4A731EE983D440804A2B9DA0B1 642048 ----a-w- C:\Windows\Sysnative\WMVXENCD.DLL 2016-01-13 06:39:53 A64D697EA82530530693AA2102FCA420 292352 ----a-w- C:\Windows\Sysnative\VIDRESZR.DLL 2016-01-13 06:39:53 9A2DCBE0A803AF0DF58D8B3EB041065E 447488 ----a-w- C:\Windows\Sysnative\WMVSENCD.DLL 2016-01-13 06:39:53 82AB148A0E747855F83F332FC83B254F 1573888 ----a-w- C:\Windows\Sysnative\quartz.dll 2016-01-13 06:39:53 759DF4479855EED0D78249798325D373 1955328 ----a-w- C:\Windows\Sysnative\WMVENCOD.DLL 2016-01-13 06:39:53 60957C2BD1C03CF395006FDBC29D2569 189952 ----a-w- C:\Windows\Sysnative\COLORCNV.DLL 2016-01-13 06:39:53 3AECE087DB6F663C2B7F538C81C60F64 432128 ----a-w- C:\Windows\Sysnative\mfplat.dll 2016-01-13 06:39:53 2A8760952F296D6208FE5FC358ECD59A 484864 ----a-w- C:\Windows\Sysnative\MFWMAAEC.DLL 2016-01-13 06:39:52 D66AE152C1EE7DA2548EC2AF4203025D 653824 ----a-w- C:\Windows\Sysnative\MP4SDECD.DLL 2016-01-13 06:39:52 D624DE0DED716916F69D495807C9D787 254464 ----a-w- C:\Windows\Sysnative\qasf.dll 2016-01-13 06:39:52 C62B3D8C69437192AA58AD6E380E4BC3 371712 ----a-w- C:\Windows\Sysnative\qdvd.dll 2016-01-13 06:39:52 BEFEDC65A88D44153983455C699F81C8 100864 ----a-w- C:\Windows\Sysnative\MP3DMOD.DLL 2016-01-13 06:39:52 ACA7F078CAD7D225D4F2D973C9812225 250880 ----a-w- C:\Windows\Sysnative\ksproxy.ax 2016-01-13 06:39:52 A54381C84F3CEBF4D339778339D141F0 2777088 ----a-w- C:\Windows\Sysnative\msmpeg2vdec.dll 2016-01-13 06:39:52 9524717B1B183A066E0516BFF2888D51 70144 ----a-w- C:\Windows\Sysnative\mfvdsp.dll 2016-01-13 06:39:52 6C6CF29B05DBCA772AED1551AF0DF6DF 76288 ----a-w- C:\Windows\Sysnative\devenum.dll 2016-01-13 06:39:52 65BA8738CC3C21C62E746A1DDF04EC74 223744 ----a-w- C:\Windows\Sysnative\MP43DECD.DLL 2016-01-13 06:39:52 2F0BA9348CB8D62FF8C28B4B83D57FA3 378880 ----a-w- C:\Windows\Sysnative\SysFxUI.dll 2016-01-13 06:39:52 294B7F30B70E0D7867F5EB69E630884A 225792 ----a-w- C:\Windows\Sysnative\RESAMPLEDMO.DLL 2016-01-13 06:39:52 18A11A96B3C1C9E2FD1E6137C8BD4018 224768 ----a-w- C:\Windows\Sysnative\MPG4DECD.DLL 2016-01-13 06:39:51 A2877C3165FCD229D1BFC9CC4FFC2B2E 2048 ----a-w- C:\Windows\Sysnative\mferror.dll 2016-01-13 06:39:51 8B995A315448ABFC6E41A200079E7DBA 55808 ----a-w- C:\Windows\Sysnative\rrinstaller.exe 2016-01-13 06:39:51 777654DB4C306B22A5A54690A258650D 24576 ----a-w- C:\Windows\Sysnative\mfpmp.exe 2016-01-13 06:39:51 6D21051C8EA17C1DD0A6FD07CCAB8232 5120 ----a-w- C:\Windows\Sysnative\ksuser.dll 2016-01-13 06:39:51 6727B79444C3C8362DB4045E86152707 206848 ----a-w- C:\Windows\Sysnative\mfps.dll 2016-01-13 06:39:50 F094FCE25E33140B5F7AEE2E5BDF6931 3211264 ----a-w- C:\Windows\Sysnative\win32k.sys 2016-01-13 06:39:48 FEB22838B5A1EA29FAEBBEEA14107049 114688 ----a-w- C:\Windows\Sysnative\ieetwcollector.exe 2016-01-13 06:39:48 E8CA48B9CB7F0ACEA28DDDE9EFF22C80 48640 ----a-w- C:\Windows\Sysnative\ieetwproxystub.dll 2016-01-13 06:39:48 E341F64F351629296178A872C7666620 718336 ----a-w- C:\Windows\Sysnative\ie4uinit.exe 2016-01-13 06:39:48 5794608757509D090F5B48B0A1F7A192 34304 ----a-w- C:\Windows\Sysnative\iernonce.dll 2016-01-13 06:39:48 16D24DE8CB771F481152CA186814CA16 2887168 ----a-w- C:\Windows\Sysnative\iertutil.dll 2016-01-13 06:39:47 DA52C6C0BA729466416B3F086C97B570 77824 ----a-w- C:\Windows\Sysnative\JavaScriptCollectionAgent.dll 2016-01-13 06:39:46 7A566BAD311137B88DDF444D13C1C594 2724864 ----a-w- C:\Windows\Sysnative\mshtml.tlb 2016-01-13 06:39:46 5794E3E7388205B0D7E87D665054A12A 152064 ----a-w- C:\Windows\Sysnative\occache.dll 2016-01-13 06:39:45 D9A22C7E960A41500D5B76C31D3222D0 1546752 ----a-w- C:\Windows\Sysnative\urlmon.dll 2016-01-13 06:39:45 4718E9DE3101969567EC0F148BF66006 387784 ----a-w- C:\Windows\Sysnative\iedkcs32.dll 2016-01-13 06:39:44 A32269075B35C5C9C2A3641A0E7AA0A5 315392 ----a-w- C:\Windows\Sysnative\dxtrans.dll 2016-01-13 06:39:44 359B81512F7A45213180DD3D821F11BB 968704 ----a-w- C:\Windows\Sysnative\MsSpellCheckingFacility.exe 2016-01-13 06:39:44 26509D490CC4DFE3291DC5E3847EBB14 798208 ----a-w- C:\Windows\Sysnative\msfeeds.dll 2016-01-13 06:39:44 20773DBF4A2DC49785831FDA12530A0A 4096 ----a-w- C:\Windows\Sysnative\ieetwcollectorres.dll 2016-01-13 06:39:43 CF6B70A265ADA05CC55D57D9DE8B06E0 2123264 ----a-w- C:\Windows\Sysnative\inetcpl.cpl 2016-01-13 06:39:43 B67D37636216B98F70064C3A2B295EF7 54784 ----a-w- C:\Windows\Sysnative\jsproxy.dll 2016-01-13 06:39:43 7300C7AB7EF1CDE5C19EEB6970C71473 571904 ----a-w- C:\Windows\Sysnative\vbscript.dll 2016-01-13 06:39:43 65CCD789E06B82989596D584D1AE6D46 66560 ----a-w- C:\Windows\Sysnative\iesetup.dll 2016-01-13 06:39:42 F66091A35F4810BD501CD7B65778D4B1 92160 ----a-w- C:\Windows\Sysnative\mshtmled.dll 2016-01-13 06:39:42 9C9E498EA2527F96EC7ADDF3634BF624 489984 ----a-w- C:\Windows\Sysnative\dxtmsft.dll 2016-01-13 06:39:42 80322AAB422075922A0EA3CFEA35061C 14457856 ----a-w- C:\Windows\Sysnative\ieframe.dll 2016-01-13 06:39:42 65E6158EF33AE88A412D3CEB33A20F47 615936 ----a-w- C:\Windows\Sysnative\ieui.dll 2016-01-13 06:39:41 F604E67A3B37B21485DEE9CC14AA2AAB 814080 ----a-w- C:\Windows\Sysnative\jscript9diag.dll 2016-01-13 06:39:41 AC8410A5877FFBC98D1ECFF949A2E0A4 144384 ----a-w- C:\Windows\Sysnative\ieUnatt.exe 2016-01-13 06:39:41 9E30C99BBB024E1CFC4B9A387132B0BE 262144 ----a-w- C:\Windows\Sysnative\webcheck.dll 2016-01-13 06:39:41 8100C63E02EC310C0E8712D6603E3DBA 800768 ----a-w- C:\Windows\Sysnative\ieapfltr.dll 2016-01-13 06:39:41 789E93204829D6519F55D5A61586B7B5 6051328 ----a-w- C:\Windows\Sysnative\jscript9.dll 2016-01-13 06:39:41 207D3D17F61029FD0FB7B6DF1244E5E2 817664 ----a-w- C:\Windows\Sysnative\jscript.dll 2016-01-13 06:39:41 1258BDEE548BCD771DD35485CDD176EA 2487808 ----a-w- C:\Windows\Sysnative\wininet.dll 2016-01-13 06:39:41 0236A801C4907B13E5BADEE62EB3284B 1359360 ----a-w- C:\Windows\Sysnative\mshtmlmedia.dll 2016-01-13 06:39:40 FB3047038F1800A0891B4D35F40E4F59 88064 ----a-w- C:\Windows\Sysnative\MshtmlDac.dll 2016-01-13 06:39:40 DD2AC5827D111001E805C19786D2DE41 199680 ----a-w- C:\Windows\Sysnative\msrating.dll 2016-01-13 06:39:40 6AEBA30A9AF45D0C83385F48EC943426 25837568 ----a-w- C:\Windows\Sysnative\mshtml.dll 2016-01-13 06:39:40 5F08FC1143F907E990F0E1EB4C8E77F2 417792 ----a-w- C:\Windows\Sysnative\html.iec 2016-01-13 06:39:15 35A6E891DF89085216F18F5B998D6CB4 879104 ----a-w- C:\Windows\Sysnative\advapi32.dll 2016-01-13 06:39:14 FD94F46A5B1A1F7638F52F0C98819DD4 705536 ----a-w- C:\Windows\Sysnative\invagent.dll 2016-01-13 06:39:14 CB1854DDBDDB963A5F189252E696BB43 1381376 ----a-w- C:\Windows\Sysnative\appraiser.dll 2016-01-13 06:39:14 C96B880CE00D71939A9E982307589029 210432 ----a-w- C:\Windows\Sysnative\aepic.dll 2016-01-13 06:39:14 3F4B89439044001B6E984DFA9A98B38C 792064 ----a-w- C:\Windows\Sysnative\generaltel.dll 2016-01-13 06:39:13 C2CA43A7E2B9D47B2DAC703CAC6281B5 505856 ----a-w- C:\Windows\Sysnative\devinv.dll 2016-01-13 06:39:13 BD09F16C81099AC527F1C9CD7DB8119F 76800 ----a-w- C:\Windows\Sysnative\acmigration.dll 2016-01-13 06:39:13 5510E75671B909D0D3FAB008144646B9 25024 ----a-w- C:\Windows\Sysnative\CompatTelRunner.exe 2016-01-13 06:39:12 AD46BED774CF502E9C0100CFC29C1F82 405504 ----a-w- C:\Windows\Sysnative\gdi32.dll 2016-01-13 06:39:06 1E22F3C99BB02A51179F9CCFEE242925 1214464 ----a-w- C:\Windows\Sysnative\rpcrt4.dll 2016-01-13 06:39:05 CD2249AEDD225CAB5CC88B40126C987F 344064 ----a-w- C:\Windows\Sysnative\schannel.dll 2016-01-13 06:39:05 35D570D5191EE48A6D5091033C71B7CE 729600 ----a-w- C:\Windows\Sysnative\kerberos.dll 2016-01-13 06:39:05 2E4FF62CC7B88ABBF59C242DED7F919F 5572544 ----a-w- C:\Windows\Sysnative\ntoskrnl.exe 2016-01-13 06:39:04 FE0C67D8D5D54F37B3A92E129A15C03A 1163264 ----a-w- C:\Windows\Sysnative\kernel32.dll 2016-01-13 06:39:04 6872BBF984E6FA0AA910926D2F127372 1461248 ----a-w- C:\Windows\Sysnative\lsasrv.dll 2016-01-13 06:39:04 28E55B4DA450C29326A25BE29C72FB1B 315392 ----a-w- C:\Windows\Sysnative\msv1_0.dll 2016-01-13 06:39:04 10DDB11D4451AAB9A32FFCEE8045BA6F 312320 ----a-w- C:\Windows\Sysnative\ncrypt.dll 2016-01-13 06:39:03 FAF7892DD731F0649046B3AA3A5166AA 1730496 ----a-w- C:\Windows\Sysnative\ntdll.dll 2016-01-13 06:39:03 F557804C926BE42B0DCF0CB2AC138156 210432 ----a-w- C:\Windows\Sysnative\wdigest.dll 2016-01-13 06:39:03 D55C59AD1C93B728AB508F4F6529ED8F 86528 ----a-w- C:\Windows\Sysnative\TSpkg.dll 2016-01-13 06:39:01 FACF1586F756E0B154EE6887FA017446 362496 ----a-w- C:\Windows\Sysnative\wow64win.dll 2016-01-13 06:39:01 FA792622268EE423FC5E6AE23FB43599 112640 ----a-w- C:\Windows\Sysnative\smss.exe 2016-01-13 06:39:01 FA3E172432AFA1A7D43847C7AC58812B 424448 ----a-w- C:\Windows\Sysnative\KernelBase.dll 2016-01-13 06:39:01 D23C252F866CE3599336D547722B4A9D 13312 ----a-w- C:\Windows\Sysnative\wow64cpu.dll 2016-01-13 06:39:01 CE14A4BBF890A7D4C898CF886D145EC9 215040 ----a-w- C:\Windows\Sysnative\winsrv.dll 2016-01-13 06:39:01 CB2A49FFC4390EC0C757B1FC07A07E17 135680 ----a-w- C:\Windows\Sysnative\sspicli.dll 2016-01-13 06:39:01 CB0E57424A776C51EF42469064ADBF08 30720 ----a-w- C:\Windows\Sysnative\lsass.exe 2016-01-13 06:39:01 B29C53B81C690394A2327AB2609B55FE 28160 ----a-w- C:\Windows\Sysnative\secur32.dll 2016-01-13 06:39:01 B25B3DE2FA73735074CA62AFEFE4AE47 16384 ----a-w- C:\Windows\Sysnative\ntvdm64.dll 2016-01-13 06:39:01 A582574464654555D17338C6657EF69B 6656 ----a-w- C:\Windows\Sysnative\apisetschema.dll 2016-01-13 06:39:01 928F79CDCE323CFEB221C7D2D539F86A 22016 ----a-w- C:\Windows\Sysnative\credssp.dll 2016-01-13 06:39:01 8645BD647D1ECEB0E6F90E01A4C412EA 43520 ----a-w- C:\Windows\Sysnative\cryptbase.dll 2016-01-13 06:39:01 7AC830607D940A3DABB8E5EB6EB22DF2 338432 ----a-w- C:\Windows\Sysnative\conhost.exe 2016-01-13 06:39:01 5EBDD597DDCD94AE47CEFE6AFE41874A 64000 ----a-w- C:\Windows\Sysnative\auditpol.exe 2016-01-13 06:39:01 5CB16703E4E4203C5B1D0717D16D48D6 503808 ----a-w- C:\Windows\Sysnative\srcore.dll 2016-01-13 06:39:01 56157CA130B661080B9DC97FE63F6D50 43520 ----a-w- C:\Windows\Sysnative\csrsrv.dll 2016-01-13 06:39:01 5124EA325CF0806FFA9514DC11593DA9 28672 ----a-w- C:\Windows\Sysnative\sspisrv.dll 2016-01-13 06:39:01 50AC63ADB9F92D5141703986C66AB61C 296960 ----a-w- C:\Windows\Sysnative\rstrui.exe 2016-01-13 06:39:01 499545FF756FA6AFFB4F6679EA88BCB1 50176 ----a-w- C:\Windows\Sysnative\srclient.dll 2016-01-13 06:39:01 2E479BB995A0C130D6FF9F55E7DDA61F 243712 ----a-w- C:\Windows\Sysnative\wow64.dll 2016-01-13 06:39:00 F6BD25ED678D2A5866FFC3355EC1E2C2 146432 ----a-w- C:\Windows\Sysnative\msaudite.dll 2016-01-13 06:39:00 BBF3E0FAFE3179FFED231D2266247476 686080 ----a-w- C:\Windows\Sysnative\adtschema.dll 2016-01-13 06:39:00 377FEC833CC924E83029A83F99230663 60416 ----a-w- C:\Windows\Sysnative\msobjs.dll ====== C:\Windows\Sysnative\drivers ===== 2016-01-15 06:52:48 E9981ECE8D894CEF7038FD1D040EB426 56832 ----a-w- C:\Windows\Sysnative\drivers\TsUsbFlt.sys 2016-01-15 06:51:35 AD64450A4ABE076F5CB34CC08EEACB07 30208 ----a-w- C:\Windows\Sysnative\drivers\TsUsbGD.sys 2016-01-15 06:51:35 313F68E1A3E6345A4F47A36B07062F34 19456 ----a-w- C:\Windows\Sysnative\drivers\rdpvideominiport.sys 2016-01-15 06:49:31 19BEDA57F3E0A06B8D5EB6D619BD5624 39936 ----a-w- C:\Windows\Sysnative\drivers\tssecsrv.sys 2016-01-13 12:55:19 506692268C5B1052B37528B5EAE4B967 12334200 ----a-w- C:\Windows\Sysnative\drivers\nvlddmkm.sys 2016-01-13 06:39:51 C51B07394A087DA666A410DBFD26663A 116736 ----a-w- C:\Windows\Sysnative\drivers\drmk.sys 2016-01-13 06:39:51 647599CAE8CA0EF2FB09C4B150BC97FF 230400 ----a-w- C:\Windows\Sysnative\drivers\portcls.sys 2016-01-13 06:39:51 26FE888505E5A945B0536AF9A2A27A6F 5632 ----a-w- C:\Windows\Sysnative\drivers\drmkaud.sys 2016-01-13 06:39:04 28E75F316CCCD79337E4957C53017D4B 154560 ----a-w- C:\Windows\Sysnative\drivers\ksecpkg.sys 2016-01-13 06:39:03 0F776895884B8DC430A307D57FD867BB 95680 ----a-w- C:\Windows\Sysnative\drivers\ksecdd.sys 2016-01-13 06:39:01 C49F1C4CA74FC52AFB2E892D8E50EA39 129024 ----a-w- C:\Windows\Sysnative\drivers\mrxsmb20.sys 2016-01-13 06:39:01 A572BEF41F3C55D7DAF24D2340C91FEC 290816 ----a-w- C:\Windows\Sysnative\drivers\mrxsmb10.sys 2016-01-13 06:39:01 32B85C4923D895B2FB35821A799BA38D 159232 ----a-w- C:\Windows\Sysnative\drivers\mrxsmb.sys ====== C:\Windows\Tasks ====== 2016-01-10 13:26:56 -------- d-----w- C:\Windows\Sysnative\Tasks\Taken voor Logboeken 2016-01-09 08:44:35 C9D400934CBC0CF893C5F9998280E8FA 3878 ----a-w- C:\Windows\Sysnative\Tasks\Adobe Flash Player Updater 2016-01-09 08:44:35 A2FA7CB0F9824C873F05425C63189D6B 940 ----a-w- C:\Windows\Tasks\Adobe Flash Player Updater.job 2016-01-07 10:10:34 2A70B4986C952011E5F62DD40056CD4E 2350 ----a-w- C:\Windows\Sysnative\Tasks\Advanced System Optimizer Scheduler 2016-01-07 10:10:33 A462DE36E52FA8ADB4FD56779EBC66A5 218 ----a-w- C:\Windows\Tasks\Advanced System Optimizer Scheduler.job 2016-01-06 17:54:46 3B5D71C91E08D6A666F95CA0175E4B49 3158 ----a-w- C:\Windows\Sysnative\Tasks\Advanced System Optimizer ====== C:\Windows\Temp ====== ======= C:\Program Files ===== 2016-01-12 06:36:09 -------- d-----w- C:\Program Files\Speccy 2016-01-06 14:58:20 -------- d-----w- C:\Program Files\Microsoft Silverlight 2015-12-30 14:02:58 -------- d-----w- C:\Program Files\Logitech 2015-12-30 14:02:58 -------- d-----w- C:\Program Files\Common Files\Logitech ======= C:\PROGRA~2 ===== 2016-01-17 07:01:39 -------- d-----w- C:\PROGRA~2\Microsoft Games 2016-01-15 10:03:58 -------- d-----w- C:\PROGRA~2\COMMON~1\Skype 2016-01-15 10:03:57 -------- d-----r- C:\PROGRA~2\Skype 2016-01-11 10:54:54 -------- d-----w- C:\PROGRA~2\eSupport.com 2016-01-07 14:16:50 -------- d-----w- C:\PROGRA~2\Mozilla Thunderbird 2016-01-07 10:13:03 -------- d-----w- C:\PROGRA~2\Microsoft ASP.NET 2016-01-06 14:58:19 -------- d-----w- C:\PROGRA~2\Microsoft Silverlight ======= C: ===== ====== C:\Users\Jive1\AppData\Roaming ====== 2016-01-17 14:31:22 -------- d-----w- C:\Users\Jive1\AppData\Local\ILS_GPS_Approach_Creator_ 2016-01-17 14:13:39 -------- d-----w- C:\Users\Jive1\AppData\Roaming\Apple Computer 2016-01-17 14:13:39 -------- d-----w- C:\Users\Jive1\AppData\Local\Apple Computer 2016-01-17 08:17:00 -------- d-----w- C:\Users\Jive1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FS Flight Tracker 2016-01-15 06:53:21 -------- d-----w- C:\Users\Jive1\AppData\Roaming\Skype 2016-01-14 15:23:57 -------- d-----w- C:\Users\Jive1\AppData\Local\CrashDumps 2016-01-10 10:28:06 -------- d-----w- C:\Users\Jive1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FS9NTV1 Northern Territory by Roger Leupold 2016-01-06 15:42:54 -------- d-----w- C:\Users\Jive1\AppData\Local\Systweak 2016-01-02 13:55:26 -------- d-----w- C:\Users\Jive1\AppData\Local\DHL 2015-12-31 15:22:20 420C23CD9AE55DAAC6CD78D87D58F860 132 ----a-w- C:\Users\Jive1\AppData\Roaming\Adobe BMP Format CS5 Prefs 2015-12-29 15:29:09 -------- d-----w- C:\Users\Jive1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FS Sound Studio 2015-12-25 07:19:27 -------- d-----w- C:\Users\Jive1\AppData\Local\Deployment 2015-12-25 07:19:27 -------- d-----w- C:\Users\Jive1\AppData\Local\Apps 2015-12-24 08:10:57 -------- d-----w- C:\Users\Jive1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Tasmanian Landclass Scenery 2015-12-24 07:44:27 -------- d-----w- C:\Users\Jive1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Tasmania - Australia 2015-12-23 10:19:14 -------- d-----w- C:\Users\Jive1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AUScene Adelaide International X v1.1 2015-12-22 11:49:08 -------- d-----w- C:\Users\Jive1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Military AI Works - RAAF 33 Squadron 2015-12-21 13:15:43 -------- d-----w- C:\Users\Jive1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ORBX 2015-12-21 10:35:25 -------- d-----w- C:\Users\Jive1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ADF AI for FS2004 2015-12-21 09:52:28 -------- d-----w- C:\Users\Jive1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VOZ AI 1.2 ====== C:\Users\Jive1 ====== 2016-01-19 06:40:54 8045ABB21A3BDD66A48E1ED5C0F0EF6A 1222144 ----a-w- C:\Users\Jive1\Desktop\RSITx64.exe 2016-01-17 13:28:40 -------- d-----w- C:\ProgramData\Navigraph 2016-01-15 10:03:58 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype 2016-01-15 08:05:44 -------- d-----w- C:\Users\Jive1\Tracing 2016-01-15 06:53:10 -------- d-----w- C:\ProgramData\Skype 2016-01-12 06:36:10 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Speccy 2016-01-09 12:11:40 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AUscene - Sydney Professional FS9 2016-01-08 14:50:05 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Amberley Airport 2009 2016-01-06 14:58:24 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 2015-12-30 14:02:58 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Logitech 2015-12-30 13:51:42 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DriverWhiz 2015-12-29 15:29:09 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FS Sound Studio 2015-12-24 07:37:36 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FSGenesis 2015-12-21 10:35:25 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ADF AI for FS2004 2015-12-21 09:52:28 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VOZ AI 1.2 ====== C: exe-files == 2016-01-19 06:40:54 8045ABB21A3BDD66A48E1ED5C0F0EF6A 1222144 ----a-w- C:\Users\Jive1\Desktop\RSITx64.exe 2016-01-18 16:00:01 A052067B947DBFBB65921D01E290DD15 404712 ----a-w- C:\ProgramData\Adobe\ARM\S\22402\AdobeARMHelper.exe 2016-01-18 13:04:28 C35FAEF2FCFBF73BF456CC45F59DACEF 602192 ----a-w- C:\Users\Jive1\AppData\Local\NVIDIA\NvBackend\Packages\00008512\CoProc update.20349022.exe 2016-01-18 10:46:29 A052067B947DBFBB65921D01E290DD15 404712 ----a-w- C:\ProgramData\Adobe\ARM\S\26506\AdobeARMHelper.exe 2016-01-18 07:22:45 A052067B947DBFBB65921D01E290DD15 404712 ----a-w- C:\ProgramData\Adobe\ARM\S\19356\AdobeARMHelper.exe 2016-01-18 06:43:10 A052067B947DBFBB65921D01E290DD15 404712 ----a-w- C:\ProgramData\Adobe\ARM\S\11600\AdobeARMHelper.exe 2016-01-18 06:41:39 2686F572B3CAF633C4A350A3671835F2 429568 ----a-w- C:\Windows\System32\wksprt.exe 2016-01-17 08:17:00 ED2B3A6E1D00119049C3574E117FA361 1078 ----a-r- C:\Users\Jive1\AppData\Roaming\Microsoft\Installer\{185FC180-2C4D-48E3-B68A-8A611AEE8AFA}\_25bd4a1.exe 2016-01-17 08:17:00 DEBA26962D943BFB028AD4E4A9510646 29926 ----a-r- C:\Users\Jive1\AppData\Roaming\Microsoft\Installer\{185FC180-2C4D-48E3-B68A-8A611AEE8AFA}\_4c3274a.exe 2016-01-17 08:17:00 D19A3DB274F764D3D0BC60FF7ECB25FB 23878 ----a-r- C:\Users\Jive1\AppData\Roaming\Microsoft\Installer\{185FC180-2C4D-48E3-B68A-8A611AEE8AFA}\_4235632d.exe 2016-01-17 08:17:00 7863D8DCD2F5A8F6DB176F931AD229CA 766 ----a-r- C:\Users\Jive1\AppData\Roaming\Microsoft\Installer\{185FC180-2C4D-48E3-B68A-8A611AEE8AFA}\_7cee4a0b.exe 2016-01-17 08:15:00 A052067B947DBFBB65921D01E290DD15 404712 ----a-w- C:\ProgramData\Adobe\ARM\S\9591\AdobeARMHelper.exe 2016-01-17 06:39:18 2A9C3ADBC3B9D061CACDEFFBED67683C 87040 ----a-w- C:\Windows\System32\TSWbPrxy.exe 2016-01-17 06:38:53 A052067B947DBFBB65921D01E290DD15 404712 ----a-w- C:\ProgramData\Adobe\ARM\S\23523\AdobeARMHelper.exe 2016-01-16 16:31:51 CB14BFE9F5B2B8558159DF017386A327 544 ----a-w- C:\$RECYCLE.BIN\S-1-5-21-1217702915-2185182410-1776734843-1000\$IQE3JOD.exe 2016-01-16 16:31:51 436FD094EA0B78FC8732821BA71C64DF 544 ----a-w- C:\$RECYCLE.BIN\S-1-5-21-1217702915-2185182410-1776734843-1000\$ILFM3BX.exe 2016-01-16 15:47:02 862C4A755C130390575C6A515C6ACAB6 6091056 ----a-w- C:\$RECYCLE.BIN\S-1-5-21-1217702915-2185182410-1776734843-1000\$RLFM3BX.exe 2016-01-16 15:45:26 0CD4A0CD4E79AFB25DF0A79D46A0DA59 1036404731 ----a-w- C:\$RECYCLE.BIN\S-1-5-21-1217702915-2185182410-1776734843-1000\$RQE3JOD.exe 2016-01-16 14:29:44 A052067B947DBFBB65921D01E290DD15 404712 ----a-w- C:\ProgramData\Adobe\ARM\S\30245\AdobeARMHelper.exe 2016-01-16 06:44:04 B6A5AA0D162C86D664F1AF626D2D7D8B 550584 ----a-w- C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonX86\Microsoft Shared\OFFICE15\msosqm.exe 2016-01-16 06:44:03 12A4E8F1D4AC0615CF770E3DDCD4F9DE 842448 ----a-w- C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonX86\Microsoft Shared\DW\DW20.EXE 2016-01-16 06:44:01 D0FCBFF69CF0EF3A23F777E07913C385 7931608 ----a-w- C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE15\CMigrate.exe 2016-01-16 06:43:59 89969E9A946B5E15B3E9C6853B5FD61D 195248 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\onenotem.exe 2016-01-16 06:43:59 53FC312F26DB43D6FCF8890426E6C2E4 1762984 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\onenote.exe 2016-01-16 06:43:59 53E09254F59E3993BFF59C6FB1CBF709 5798104 ----a-w- C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonX86\Microsoft Shared\OFFICE15\CMigrate.exe 2016-01-16 06:43:58 EA63400D17211654771B6889F3BD8EFC 474344 ----a-w- C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonX86\Microsoft Shared\DW\DWTRIG20.EXE 2016-01-16 06:43:58 54242C408D56B95A1397BF204015B769 874160 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\protocolhandler.exe 2016-01-16 06:43:34 6FAC12190E4BF7D66B023BD0EDCAF279 1136856 ----a-w- C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonX86\Microsoft Shared\OFFICE15\OLicenseHeartbeat.exe 2016-01-16 06:43:30 F3C2245428D6A03685CE2B6316801296 480984 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\SELFCERT.EXE 2016-01-16 06:43:30 96E1D1C174789A8D947E1E34F1635D4F 21941408 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\excelcnv.exe 2016-01-16 06:43:30 477236D15338F537BA7D341FEF3E16BF 517360 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\IEContentService.exe 2016-01-16 06:43:30 0AEF52A3D8A9C5CC9E3C7383294BBAE4 569592 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\ORGCHART.EXE 2016-01-16 06:43:29 F10C630A25DBF545F38AC9F8856D23DC 528584 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\VPREVIEW.EXE 2016-01-16 06:43:18 FAE17C01547C21D4E0E7A456DFAF642F 630992 ----a-w- C:\Program Files\Microsoft Office 15\root\Integration\Integrator.exe 2016-01-16 06:43:09 A052067B947DBFBB65921D01E290DD15 404712 ----a-w- C:\ProgramData\Adobe\ARM\S\4361\AdobeARMHelper.exe 2016-01-16 06:43:03 93C64C781C525F96DEED3DDF32493A43 18995880 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\OUTLOOK.EXE 2016-01-16 06:42:58 5C54C563351ADE0088D5F159CBD80DF2 1923232 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\WINWORD.EXE 2016-01-16 06:42:56 5FEAD863F85FCF39F81A3FA26FD4D0F1 25726624 ----a-w- C:\Program Files\Microsoft Office 15\root\office15\EXCEL.EXE 2016-01-15 13:01:42 740076FCF3170AA5C07EF870D84FD4A7 7089280 ----a-w- C:\Users\Jive1\AppData\Local\NVIDIA\NvBackend\Packages\000084fe\DAO.20342627.exe 2016-01-15 10:16:32 A052067B947DBFBB65921D01E290DD15 404712 ----a-w- C:\ProgramData\Adobe\ARM\S\26165\AdobeARMHelper.exe 2016-01-15 09:24:18 336AC362B98746254CD73AD15D93B351 630200 ----a-w- C:\Users\Jive1\AppData\Local\NVIDIA\NvBackend\ApplicationOntology\NvOAWrapperCache.exe 2016-01-15 09:24:14 E92199FBDEA7549FF74D7D7F93C365DC 172984 ----a-w- C:\Users\Jive1\AppData\Local\NVIDIA\NvBackend\ApplicationOntology\OAWrapper.exe 2016-01-15 08:10:11 A052067B947DBFBB65921D01E290DD15 404712 ----a-w- C:\ProgramData\Adobe\ARM\S\1411\AdobeARMHelper.exe 2016-01-15 07:27:53 A052067B947DBFBB65921D01E290DD15 404712 ----a-w- C:\ProgramData\Adobe\ARM\S\25891\AdobeARMHelper.exe 2016-01-15 06:52:48 108C257D765AAD2E6EC46557DA0B02BD 13824 ----a-w- C:\Windows\System32\TsUsbRedirectionGroupPolicyControl.exe 2016-01-15 06:52:47 8E75B1112C374EBDF18FD640DA2F0655 1147392 ----a-w- C:\Windows\System32\mstsc.exe 2016-01-15 06:52:47 4676AAA9DDF52A50C829FEDB4EA81E54 1068544 ----a-w- C:\Windows\SysWOW64\mstsc.exe 2016-01-15 06:42:08 A052067B947DBFBB65921D01E290DD15 404712 ----a-w- C:\ProgramData\Adobe\ARM\S\16849\AdobeARMHelper.exe 2016-01-13 19:03:12 E3B47507046421050EC21B46854384A8 18781632 ----a-w- C:\ProgramData\NVIDIA Corporation\GeForce Experience\Update\GFExperience.NvStreamSrv\x86\server\NvStreamUserAgent.exe 2016-01-13 19:03:12 774762F36F97F49D9C9FA24DA10FEFE3 420800 ----a-w- C:\ProgramData\NVIDIA Corporation\GeForce Experience\Update\setup.exe 2016-01-13 19:03:12 2680F51D94B4E510ECF2AD8FCBA0FC03 203200 ----a-w- C:\ProgramData\NVIDIA Corporation\GeForce Experience\Update\Update.Core\WLMerger.exe 2016-01-13 19:03:11 ECF15114221AE14B0911EBE8273A8ADD 321312 ----a-w- C:\ProgramData\NVIDIA Corporation\GeForce Experience\Update\ShadowPlay\nvsphelper64.exe 2016-01-13 19:03:11 E4C8A7B299A1C7E89AE868F7558C143B 3996608 ----a-w- C:\ProgramData\NVIDIA Corporation\GeForce Experience\Update\GFExperience.NvStreamSrv\x86\server\NvStreamService.exe 2016-01-13 19:03:11 E445C0DB7E5E89C657FC89C0C4CCEDE5 2787264 ----a-w- C:\ProgramData\NVIDIA Corporation\GeForce Experience\Update\Update.Core\NvBackend.exe 2016-01-13 19:03:11 DD3419FC1F22C16E860D0CFA9311A2F3 5178816 ----a-w- C:\ProgramData\NVIDIA Corporation\GeForce Experience\Update\GFExperience.NvStreamSrv\x86\server\NvStreamNetworkService.exe 2016-01-13 19:03:11 BEDDD391E843289DD7DBE1A202661DFC 4634560 ----a-w- C:\ProgramData\NVIDIA Corporation\GeForce Experience\Update\GFExperience.NvStreamSrv\x86\server\nvstreamer.exe 2016-01-13 19:03:11 9B4B3747C6756F49B986398A46EC1FE0 6308288 ----a-w- C:\ProgramData\NVIDIA Corporation\GeForce Experience\Update\GFExperience.NvStreamSrv\amd64\server\NvStreamNetworkService.exe 2016-01-13 19:03:11 99568D0E3064B540BE0B186D59DD29B0 1065408 ----a-w- C:\ProgramData\NVIDIA Corporation\GeForce Experience\Update\GFExperience\LaunchGFExperience.exe 2016-01-13 19:03:11 8C19428C0BBE189A7E844FB6B1F1F9B1 1879488 ----a-w- C:\ProgramData\NVIDIA Corporation\GeForce Experience\Update\NVI2\NVNetworkService.exe 2016-01-13 19:03:11 83435865CF7E7D8345669333421273DF 126584 ----a-w- C:\ProgramData\NVIDIA Corporation\GeForce Experience\Update\LEDVisualizer\NvLedVisualizer.exe 2016-01-13 19:03:11 742089B53DC52A3E25C506350D945C73 290304 ----a-w- C:\ProgramData\NVIDIA Corporation\GeForce Experience\Update\ShadowPlay\nvsphelper.exe 2016-01-13 19:03:11 6818ABE67E1EF0B1B5A75C1090D1AF2F 20069312 ----a-w- C:\ProgramData\NVIDIA Corporation\GeForce Experience\Update\GFExperience.NvStreamSrv\amd64\server\NvStreamUserAgent.exe 2016-01-13 19:03:11 648739FF87DC21E7DBEEFB78E84580B7 87160 ----a-w- C:\ProgramData\NVIDIA Corporation\GeForce Experience\Update\LEDVisualizer\NvLedServiceHost.exe 2016-01-13 19:03:11 5D4F333EA2E81C46AB22B7F99BDED6D8 5525440 ----a-w- C:\ProgramData\NVIDIA Corporation\GeForce Experience\Update\GFExperience.NvStreamSrv\amd64\server\nvstreamer.exe 2016-01-13 19:03:11 54908F7C825B3CADB3F2777B6E735504 646200 ----a-w- C:\ProgramData\NVIDIA Corporation\GeForce Experience\Update\GFExperience.NvStreamSrv\SteamLauncher\NVIDIA.SteamLauncher.exe 2016-01-13 19:03:11 266512CCC3B2E195CDE3A7A2C98A353A 4812736 ----a-w- C:\ProgramData\NVIDIA Corporation\GeForce Experience\Update\GFExperience.NvStreamSrv\amd64\server\NvStreamService.exe 2016-01-13 19:03:11 1E3277F1C9F62F90488D02869A9522B7 1879488 ----a-w- C:\ProgramData\NVIDIA Corporation\GeForce Experience\Update\Network.Service\NVNetworkService.exe 2016-01-13 19:03:11 1AE0576066597C27172AD88B615F2F75 6597056 ----a-w- C:\ProgramData\NVIDIA Corporation\GeForce Experience\Update\ShadowPlay\nvspcaps.exe 2016-01-13 19:03:11 143A5AA7183CF5B41C77BECFC0914B65 7621568 ----a-w- C:\ProgramData\NVIDIA Corporation\GeForce Experience\Update\ShadowPlay\nvspcaps64.exe 2016-01-13 19:03:10 B8AE99F363F109F6941699640C609A52 602560 ----a-w- C:\ProgramData\NVIDIA Corporation\GeForce Experience\Update\GFExperience\7z.exe 2016-01-13 19:03:10 52194DC424E75D12E164AAA308682747 929728 ----a-w- C:\ProgramData\NVIDIA Corporation\GeForce Experience\Update\GfExperienceService\GfExperienceService32.exe 2016-01-13 19:03:10 4AA9CF6509B4D34372FD6FA430DA37F8 4747712 ----a-w- C:\ProgramData\NVIDIA Corporation\GeForce Experience\Update\GFExperience\GFExperience.exe 2016-01-13 19:03:10 1FE288F701E7F01B663616180CDBC65C 526784 ----a-w- C:\ProgramData\NVIDIA Corporation\GeForce Experience\Update\ShadowPlay\DXSETUP.exe 2016-01-13 19:03:10 061CC5C12C39899D7398CFEBFD19F69F 1163200 ----a-w- C:\ProgramData\NVIDIA Corporation\GeForce Experience\Update\GfExperienceService\GfExperienceService64.exe 2016-01-13 19:02:52 318C6339E4473C852AF6CDA5637C5578 41850168 ----a-w- C:\ProgramData\NVIDIA Corporation\NetService\396c19da-b206-4419-bdb2-21f4c424db67\GeForce_Experience_Update_v2.9.1.22.exe 2016-01-13 12:57:38 E8DF3A1122E46B7F5FD9AC198B7E5AD4 7846008 ----a-w- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\NVStWiz.exe 2016-01-13 12:57:38 D96EF8868EC3EC318901703324690162 316536 ----a-w- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvStInst.exe 2016-01-13 12:57:38 CC4A1CCB2D41F4D6F6DA380BB6D8F355 437368 ----a-w- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvstreg.exe 2016-01-13 12:57:38 7DE0484FB332F22D443093281C0B08FF 597112 ----a-w- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvstlink.exe 2016-01-13 12:57:38 76B7EC2E3BED892898A41D2553942063 103032 ----a-w- C:\Windows\SysWOW64\nvStreaming.exe 2016-01-13 12:57:38 65ECE31511779EA4B5D660E98C4AF3BB 1697912 ----a-w- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvstview.exe 2016-01-13 12:57:38 081DDE7D8901FE8D24DEE320ABCC3DB1 2409592 ----a-w- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvsttest.exe 2016-01-13 12:57:37 2F77CF8116CEBED05E052A2227D68916 896120 ----a-w- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\NvStereoUtilityOGL.exe 2016-01-13 12:57:37 205C21F5812463A5EC73F6E8D0D97812 417400 ----a-w- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe 2016-01-13 12:55:19 FC55CDDEC6BC4BD75BF3AF05AF1DD380 18292768 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\Display.3DVision.{12C081ED-CC0D-4363-8E01-279CC0CF27BF}\3DVision.exe 2016-01-13 12:55:19 6E6F1767316B5D4BAC5FA872C461829A 449656 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\Display.Driver.{11A83B63-3FC9-4921-9C39-0D47E1EBAF90}\dbInstaller.exe 2016-01-13 12:55:19 6E6F1767316B5D4BAC5FA872C461829A 449656 ----a-w- C:\Program Files\NVIDIA Corporation\Drs\dbInstaller.exe 2016-01-13 12:55:19 4227A7211E2D59688CFE461FE21BBBC9 96803680 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\Display.Driver.{11A83B63-3FC9-4921-9C39-0D47E1EBAF90}\NvCplSetupInt.exe 2016-01-13 12:54:45 DEA3F34BDAC3F4D3C48E19B8C981D602 1872504 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\installer.{387E344C-0325-4550-B374-E483D1F2E12F}\NVNetworkService.exe 2016-01-13 12:54:45 7E235FA5346A9AF6B192DD0970A2128F 414000 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\CoreTemp.{6E6D319C-FC05-47C9-960A-D04B56B30D4F}\setup.exe 2016-01-13 06:39:59 4489D5077C5D2396E3A94D652ADAE1CA 14336 ----a-w- C:\Windows\SysWOW64\fixmapi.exe 2016-01-13 06:39:58 2FFBA1EAE28B45A92E2EA70C61C66F14 17920 ----a-w- C:\Windows\System32\fixmapi.exe 2016-01-13 06:39:51 BBE4D9B89B3FBC97C0F381C2F9C4ADEF 23040 ----a-w- C:\Windows\SysWOW64\mfpmp.exe 2016-01-13 06:39:51 936E6F6F76136BC73B13D25A254BC84B 50176 ----a-w- C:\Windows\SysWOW64\rrinstaller.exe 2016-01-13 06:39:51 8B995A315448ABFC6E41A200079E7DBA 55808 ----a-w- C:\Windows\System32\rrinstaller.exe 2016-01-13 06:39:51 777654DB4C306B22A5A54690A258650D 24576 ----a-w- C:\Windows\System32\mfpmp.exe 2016-01-13 06:39:48 FEB22838B5A1EA29FAEBBEEA14107049 114688 ----a-w- C:\Windows\System32\ieetwcollector.exe 2016-01-13 06:39:48 E341F64F351629296178A872C7666620 718336 ----a-w- C:\Windows\System32\ie4uinit.exe 2016-01-13 06:39:48 40234FBF2AC1FE6BB16BF967782C124C 221184 ----a-w- C:\Program Files (x86)\Internet Explorer\ielowutil.exe 2016-01-13 06:39:45 C9B76533B304B3FEE41ED5C2500A0668 222720 ----a-w- C:\Program Files\Internet Explorer\ielowutil.exe 2016-01-13 06:39:45 B778A5AAE66E7F1AC3414DDF41E4359E 473600 ----a-w- C:\Program Files (x86)\Internet Explorer\ieinstal.exe 2016-01-13 06:39:45 0E5C2FBD4CF9CB08DCDA586247195FF2 815304 ----a-w- C:\Program Files (x86)\Internet Explorer\iexplore.exe 2016-01-13 06:39:44 359B81512F7A45213180DD3D821F11BB 968704 ----a-w- C:\Windows\System32\MsSpellCheckingFacility.exe 2016-01-13 06:39:43 EDA0948BAA8ED2FCF64942026A0B3457 491008 ----a-w- C:\Program Files\Internet Explorer\ieinstal.exe 2016-01-13 06:39:43 CB76755799B821A9D8779DA004840E9C 814288 ----a-w- C:\Program Files\Internet Explorer\iexplore.exe 2016-01-13 06:39:43 424300DDB7A1B24199C9B481438F55E9 115712 ----a-w- C:\Windows\SysWOW64\ieUnatt.exe 2016-01-13 06:39:41 AC8410A5877FFBC98D1ECFF949A2E0A4 144384 ----a-w- C:\Windows\System32\ieUnatt.exe 2016-01-13 06:39:13 CCF0EAACC822EC72830AB56EA29D952F 88256 ----a-w- C:\Windows\System32\CompatTel\diagtrackrunner.exe 2016-01-13 06:39:13 5510E75671B909D0D3FAB008144646B9 25024 ----a-w- C:\Windows\System32\CompatTelRunner.exe 2016-01-13 06:39:05 2E4FF62CC7B88ABBF59C242DED7F919F 5572544 ----a-w- C:\Windows\System32\ntoskrnl.exe 2016-01-13 06:39:04 A8D4C2B034947F2445F5099E6B3173C8 3938240 ----a-w- C:\Windows\SysWOW64\ntoskrnl.exe 2016-01-13 06:39:04 1615874D0262DA99E565D4FE6F74F7DD 3993536 ----a-w- C:\Windows\SysWOW64\ntkrnlpa.exe 2016-01-13 06:39:01 FA792622268EE423FC5E6AE23FB43599 112640 ----a-w- C:\Windows\System32\smss.exe 2016-01-13 06:39:01 CB0E57424A776C51EF42469064ADBF08 30720 ----a-w- C:\Windows\System32\lsass.exe 2016-01-13 06:39:01 AE6E759632A0F931CFB626EED55C3E99 50176 ----a-w- C:\Windows\SysWOW64\auditpol.exe 2016-01-13 06:39:01 8E3915AF90315E4ED96D4CAE316E8F21 7680 ----a-w- C:\Windows\SysWOW64\instnm.exe 2016-01-13 06:39:01 7AC830607D940A3DABB8E5EB6EB22DF2 338432 ----a-w- C:\Windows\System32\conhost.exe 2016-01-13 06:39:01 5EBDD597DDCD94AE47CEFE6AFE41874A 64000 ----a-w- C:\Windows\System32\auditpol.exe 2016-01-13 06:39:01 50AC63ADB9F92D5141703986C66AB61C 296960 ----a-w- C:\Windows\System32\rstrui.exe 2016-01-13 06:39:01 1418C1A502A9540A4726B4935229E7B9 25600 ----a-w- C:\Windows\SysWOW64\setup16.exe 2016-01-13 06:39:00 59541469E828B311B1E5EEA77E6F6BE7 2048 ----a-w- C:\Windows\SysWOW64\user.exe === C: other files == 2016-01-17 12:42:30 A195604EB9C1D2079F2BF79DFE6FAF8D 544 ----a-w- C:\$RECYCLE.BIN\S-1-5-21-1217702915-2185182410-1776734843-1000\$IIE5J5G.zip 2016-01-17 12:42:30 21601486E5639DBADA077A37F4AAEC59 544 ----a-w- C:\$RECYCLE.BIN\S-1-5-21-1217702915-2185182410-1776734843-1000\$IVTUPH3.zip 2016-01-17 12:41:11 8F199BBC52A844FF5DF990EE27CC3FAD 3705389 ----a-w- C:\$RECYCLE.BIN\S-1-5-21-1217702915-2185182410-1776734843-1000\$RVTUPH3.zip 2016-01-17 07:36:54 CF0BC6280871375DDD5CE816763FC771 409239 ----a-w- C:\Users\Jive1\Downloads\af2_lpla.zip 2016-01-17 07:31:12 1370313F2291F6032F6CA255C4BD2C55 747109 ----a-w- C:\Users\Jive1\Downloads\af2_azores-pack_01.zip 2016-01-16 16:31:57 17AD9AE64F828E4D5AB58BD9E600E8A8 544 ----a-w- C:\$RECYCLE.BIN\S-1-5-21-1217702915-2185182410-1776734843-1000\$IRIDOPN.zip 2016-01-16 15:42:45 160E6384472BB6403F9BC7DD56EB911C 1072999372 ----a-w- C:\$RECYCLE.BIN\S-1-5-21-1217702915-2185182410-1776734843-1000\$RRIDOPN.zip 2016-01-15 06:52:48 E9981ECE8D894CEF7038FD1D040EB426 56832 ----a-w- C:\Windows\System32\drivers\TsUsbFlt.sys 2016-01-15 06:51:35 AD64450A4ABE076F5CB34CC08EEACB07 30208 ----a-w- C:\Windows\System32\drivers\TsUsbGD.sys 2016-01-15 06:51:35 313F68E1A3E6345A4F47A36B07062F34 19456 ----a-w- C:\Windows\System32\drivers\rdpvideominiport.sys 2016-01-15 06:49:31 19BEDA57F3E0A06B8D5EB6D619BD5624 39936 ----a-w- C:\Windows\System32\drivers\tssecsrv.sys 2016-01-14 09:44:09 7D91EF4016AB52CC088B3E2877B95B1D 5165046 ----a-w- C:\Users\Jive1\Downloads\m20blj.zip 2016-01-13 19:03:17 F895CCCC4DF4282DB632F31712B4BF0B 21440 ----a-w- C:\ProgramData\NVIDIA Corporation\GeForce Experience\Update\NVI2\NVI2SystemService32.sys 2016-01-13 19:03:17 D74E8117FCE069085B47FD6ACAF5D603 25536 ----a-w- C:\ProgramData\NVIDIA Corporation\GeForce Experience\Update\GFExperience.NvStreamSrv\x86\server\NvStreamKms.sys 2016-01-13 19:03:17 9D9CAD70EA640AB8D3EB77BFAE6CABE2 28344 ----a-w- C:\ProgramData\NVIDIA Corporation\GeForce Experience\Update\ShieldWirelessController\NVSWCFilter64.sys 2016-01-13 19:03:17 7ABD081BB7A1A8CF7E3B1E64183AB812 24760 ----a-w- C:\ProgramData\NVIDIA Corporation\GeForce Experience\Update\ShieldWirelessController\NVSWCFilter32.sys 2016-01-13 19:03:17 64E8275CEAD43D3CA8E3A311B2F4B64A 47760 ----a-w- C:\ProgramData\NVIDIA Corporation\GeForce Experience\Update\NvVAD\nvvad64v.sys 2016-01-13 19:03:17 59A8DE923619F3DC0C6C63DC33FB231E 26560 ----a-w- C:\ProgramData\NVIDIA Corporation\GeForce Experience\Update\GFExperience.NvStreamSrv\amd64\server\NvStreamKms.sys 2016-01-13 19:03:17 1DC51A2C46A4F8FD61DC7CAFDA68D0C0 22464 ----a-w- C:\ProgramData\NVIDIA Corporation\GeForce Experience\Update\NVI2\NVI2SystemService64.sys 2016-01-13 19:03:17 0AAE6C356F1F7C723BA99FB41E32DE12 42128 ----a-w- C:\ProgramData\NVIDIA Corporation\GeForce Experience\Update\NvVAD\nvvad32v.sys 2016-01-13 12:55:20 9D9CAD70EA640AB8D3EB77BFAE6CABE2 28344 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\ShieldWirelessController.{E256A049-E469-4C6C-ACB2-40A161F1136B}\NVSWCFilter64.sys 2016-01-13 12:55:20 7ABD081BB7A1A8CF7E3B1E64183AB812 24760 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\ShieldWirelessController.{E256A049-E469-4C6C-ACB2-40A161F1136B}\NVSWCFilter32.sys 2016-01-13 12:55:19 D812362E8AF615B521AD4DF19A93BD5A 205456 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\HDAudio.Driver.{BE4C53E3-ABA9-4C3C-A10D-A9B57BFCA068}\nvhda64v.sys 2016-01-13 12:55:19 C2A9985C97DF5946AEAE7C001625410C 44840 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\VirtualAudio.Driver.{EBE30004-5BFE-4001-B6D4-9A7E95729BE5}\nvvad32v.sys 2016-01-13 12:55:19 5FAE3141271AAF8A43951487C973825D 454752 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\Display.NVIRUSB.{66A871D7-7D08-4B09-B971-2BEE45658A0B}\nvstusb32.sys 2016-01-13 12:55:19 506692268C5B1052B37528B5EAE4B967 12334200 ----a-w- C:\Windows\System32\drivers\nvlddmkm.sys 2016-01-13 12:55:19 43DB182DC821C322C9EE8E936B82D8FB 469688 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\Display.NVIRUSB.{66A871D7-7D08-4B09-B971-2BEE45658A0B}\nvstusb64.sys 2016-01-13 12:55:19 40025FE1F8BF91EE3575D8469D0773F8 138040 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\HDAudio.Driver.{BE4C53E3-ABA9-4C3C-A10D-A9B57BFCA068}\nvhda32.sys 2016-01-13 12:55:19 35DFC12FD7E44B7CB8CCD7E5A2B3975A 50472 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\VirtualAudio.Driver.{EBE30004-5BFE-4001-B6D4-9A7E95729BE5}\nvvad64v.sys 2016-01-13 12:55:19 2E918562FE52470B166EC28081AE43CA 170128 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\HDAudio.Driver.{BE4C53E3-ABA9-4C3C-A10D-A9B57BFCA068}\nvhda32v.sys 2016-01-13 12:55:19 0743DBA6ABF06CC61F784D40BEF84CE3 170312 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\HDAudio.Driver.{BE4C53E3-ABA9-4C3C-A10D-A9B57BFCA068}\nvhda64.sys 2016-01-13 12:54:45 FC2F395707BA5850F2F363BF635D7C72 14456 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\CoreTemp.{6E6D319C-FC05-47C9-960A-D04B56B30D4F}\NVI2SystemService32.sys 2016-01-13 12:54:45 880AE3F620539FFA0F9CA839C36CA1BB 15480 ----a-w- C:\Program Files\NVIDIA Corporation\Installer2\CoreTemp.{6E6D319C-FC05-47C9-960A-D04B56B30D4F}\NVI2SystemService64.sys 2016-01-13 06:39:51 C51B07394A087DA666A410DBFD26663A 116736 ----a-w- C:\Windows\System32\drivers\drmk.sys 2016-01-13 06:39:51 647599CAE8CA0EF2FB09C4B150BC97FF 230400 ----a-w- C:\Windows\System32\drivers\portcls.sys 2016-01-13 06:39:51 26FE888505E5A945B0536AF9A2A27A6F 5632 ----a-w- C:\Windows\System32\drivers\drmkaud.sys 2016-01-13 06:39:50 F094FCE25E33140B5F7AEE2E5BDF6931 3211264 ----a-w- C:\Windows\System32\win32k.sys 2016-01-13 06:39:04 28E75F316CCCD79337E4957C53017D4B 154560 ----a-w- C:\Windows\System32\drivers\ksecpkg.sys 2016-01-13 06:39:03 0F776895884B8DC430A307D57FD867BB 95680 ----a-w- C:\Windows\System32\drivers\ksecdd.sys 2016-01-13 06:39:01 C49F1C4CA74FC52AFB2E892D8E50EA39 129024 ----a-w- C:\Windows\System32\drivers\mrxsmb20.sys 2016-01-13 06:39:01 A572BEF41F3C55D7DAF24D2340C91FEC 290816 ----a-w- C:\Windows\System32\drivers\mrxsmb10.sys 2016-01-13 06:39:01 32B85C4923D895B2FB35821A799BA38D 159232 ----a-w- C:\Windows\System32\drivers\mrxsmb.sys ==== Orphaned Tasks deleted from Registry ====================== Opera N deleted Opera N Saturday deleted Opera N Sunday deleted ==== Startup Registry Enabled ====================== [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun" [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun" [HKEY_USERS\S-1-5-21-1217702915-2185182410-1776734843-1000\Software\Microsoft\Windows\CurrentVersion\Run] "Skype"="C:\Program Files (x86)\Skype\Phone\Skype.exe /minimized /regrun" [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce] "mctadmin"="C:\Windows\System32\mctadmin.exe" [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce] "mctadmin"="C:\Windows\System32\mctadmin.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "AdobeCS5ServiceManager"="C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe -launchedbylogin" "SwitchBoard"="C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" "SunJavaUpdateSched"="C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" "Navigraph FMS Data Manager"="D:\FS9 Addon Programs\FMS Data Manager\NGFMSAgent.exe -autostart" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] "MEDIA"="C:\Users\Jive1\AppData\Local\Temp\in71125248\112FD7CC_stp.EXE" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "Skype"="C:\Program Files (x86)\Skype\Phone\Skype.exe /minimized /regrun" ==== Startup Registry Enabled x64 ====================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "BullGuard"="C:\Program Files\BullGuard Ltd\BullGuard\BullGuard.exe -boot" "BullGuardUpdate2"="c:\program files\bullguard ltd\bullguard\BullGuardUpdate2.exe" "NvBackend"="C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe" "ShadowPlay"="C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart" "AdobeAAMUpdater-1.0"="C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" "RTHDVCPL"="C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s" "Start WingMan Profiler"="C:\Program Files\Logitech\Gaming Software\LWEMon.exe /noui" ==== Startup Registry Disabled x64 ====================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\AdobeARMservice] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\AdobeFlashPlayerUpdateSvc] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\BsBhvScan] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\BsScanner] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\BsUpdate] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\GfExperienceService] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\Intel(R) PROSet Monitoring Service] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\MozillaMaintenance] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\NvNetworkService] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\NvStreamNetworkSvc] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\NvStreamSvc] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\nvsvc] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\Stereo Service] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\SwitchBoard] ==== Startup Folders ====================== 2016-01-15 09:39:04 1106 ----a-w- C:\Users\Jive1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Verzenden naar OneNote.lnk 2015-11-09 10:24:50 1005 ----a-w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Printkey2000.lnk ==== Task Scheduler Jobs ====================== C:\Windows\tasks\Adobe Flash Player Updater.job --a------ C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [09/01/2016 10:20] C:\Windows\tasks\Advanced System Optimizer Scheduler.job --a------ [Undetermined Task] ==== Other Scheduled Tasks ====================== "C:\Windows\SysNative\tasks\Adobe Acrobat Update Task" [C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe] "C:\Windows\SysNative\tasks\Adobe Flash Player Updater" [C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe] "C:\Windows\SysNative\tasks\AdobeAAMUpdater-1.0-Jive1-PC1-Jive1" [C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe] "C:\Windows\SysNative\tasks\Advanced System Optimizer" [C:\Program Files (x86)\Advanced System Optimizer 3\ASO3.exe] "C:\Windows\SysNative\tasks\CCleanerSkipUAC" ["C:\Program Files\CCleaner\CCleaner.exe"] "C:\Windows\SysNative\tasks\Lenovo\Lenovo Customer Feedback Program 64 35" ["%ProgramFiles(x86)%\Lenovo\Customer Feedback Program 35\Lenovo.TVT.CustomerFeedback.Agent35.exe"] "C:\Windows\SysNative\tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask" [%systemroot%\system32\sc.exe start osppsvc] ==== Firefox Extensions Registry ====================== [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions] "{01A8CA0A-4C96-465b-A49B-65C46FAD54F9}"="C:\Program Files (x86)\Adobe\Adobe Contribute CS5\Plugins\FirefoxPlugin\{01A8CA0A-4C96-465b-A49B-65C46FAD54F9}" [30/10/2015 16:02] ==== Firefox Extensions ====================== ProfilePath: C:\Users\Jive1\AppData\Roaming\Thunderbird\Profiles\vn0s15kb.default - BullGuard Spamfilter - C:\Program Files\BullGuard Ltd\BullGuard\Files32\Spamfilter\TbSpamfilter - Lightning - %ProfilePath%\extensions\{e2fda1a4-762b-4020-b5ad-a41df1933103} AppDir: C:\Program Files (x86)\Mozilla Firefox - Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} ==== Firefox Plugins ====================== Profilepath: C:\Users\Jive1\AppData\Roaming\Mozilla\Firefox\Profiles\jqdvbdgp.default 18CF51689186AEB9D1D149AEB0E92D03 - C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL - Microsoft Office 2013 70858ED7836E5C849D33576A84DC8CCF - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_20_0_0_267.dll - Shockwave Flash ==== Chromium Look ====================== Google Slides - Jive1\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek Google Docs - Jive1\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake Google Drive - Jive1\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf YouTube - Jive1\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo Google Search - Jive1\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf Google Sheets - Jive1\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap Google Docs Offline - Jive1\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi Chrome Web Store Payments - Jive1\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda Gmail - Jive1\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia ==== Set IE to Default ====================== Old Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://www.google.be/" New Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://www.google.be/" ==== All HKLM and HKCU SearchScopes ====================== HKLM\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" HKLM\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC HKLM\Wow6432Node\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" HKLM\Wow6432Node\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC HKCU\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" HKCU\SearchScopes\{012E1000-F331-11DB-8314-0800200C9A66} - http://www.google.com/search?q={searchTerms} HKCU\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02 ==== shortcuts on Users Desktops ====================== C:\Users\Jive1\Desktop\AirEd.exe - Snelkoppeling.lnk - D:\FS9 Addon Programs\AirEditNew\AirEd.exe C:\Users\Jive1\Desktop\BitTorrent.lnk - C:\Users\Jive1\AppData\Roaming\BitTorrent\BitTorrent.exe C:\Users\Jive1\Desktop\DXTBmp.lnk - C:\Graphics\MWGraphics\DXTBmp\DXTBmp.exe C:\Users\Jive1\Desktop\Er is maar 1 goede oplossing.doc - Snelkoppeling.lnk - E:\Jive1\Jive1\Teksten\Er is maar 1 goede oplossing.doc C:\Users\Jive1\Desktop\FlightSim Manager.lnk - D:\Programs\FlightSimManager\FlightSimManager.exe C:\Users\Jive1\Desktop\FlightTracker.lnk - D:\Programs\FS-Tracker\FlightTracker.exe C:\Users\Jive1\Desktop\FS9-Vlucht om de wereld.lnk - D:\FS9-Vlucht om de wereld C:\Users\Jive1\Desktop\fs9.CFG - Snelkoppeling.lnk - C:\Users\Jive1\AppData\Roaming\Microsoft\FS9\fs9.CFG C:\Users\Jive1\Desktop\Manual.pdf - Snelkoppeling.lnk - D:\FS9 Addon Programs\PFPX\Manual.pdf C:\Users\Jive1\Desktop\PFPX.exe - Snelkoppeling.lnk - D:\FS9 Addon Programs\PFPX\PFPX.exe C:\Users\Jive1\Desktop\Vlucht om de wereld.lnk - I:\FS\Vlucht om de wereld.doc ==== shortcuts on All Users Desktop ====================== C:\Users\Public\Desktop\Acrobat Reader DC.lnk - C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe C:\Users\Public\Desktop\Advanced Driver Updater.lnk - C:\Program Files (x86)\Advanced Driver Updater\adu.exe C:\Users\Public\Desktop\BullGuard.lnk - C:\Program Files\BullGuard Ltd\BullGuard\BullGuard.exe C:\Users\Public\Desktop\CCleaner.lnk - C:\Program Files\CCleaner\CCleaner64.exe C:\Users\Public\Desktop\GeForce Experience.lnk - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\LaunchGFExperience.exe C:\Users\Public\Desktop\Skype.lnk - C:\Windows\Installer\{FC965A47-4839-40CA-B618-18F486F042C6}\SkypeIcon.exe C:\Users\Public\Desktop\Speccy.lnk - C:\Program Files\Speccy\Speccy64.exe C:\Users\Public\Desktop\WinImage (administrator).lnk - C:\Program Files (x86)\WinImage\winimage.exe ==== shortcuts in Users Start Menu ====================== C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft OneDrive.lnk - C:\Program Files (x86)\Microsoft OneDrive\OneDriveSetup.exe C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft OneDrive.lnk - C:\Program Files (x86)\Microsoft OneDrive\OneDriveSetup.exe C:\Users\Jive1\AppData\Roaming\Microsoft\Windows\Start Menu\BitTorrent.lnk - C:\Users\Jive1\AppData\Roaming\BitTorrent\BitTorrent.exe C:\Users\Jive1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk - C:\Program Files (x86)\Internet Explorer\iexplore.exe C:\Users\Jive1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft OneDrive.lnk - C:\Users\Jive1\AppData\Local\Microsoft\OneDrive\OneDrive.exe C:\Users\Jive1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk - C:\Program Files (x86)\Internet Explorer\iexplore.exe -extoff C:\Users\Jive1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AUScene Adelaide International X v1.1\Uninstall AUScene Adelaide International X v1.1.lnk - D:\Extract\FS9\Uninstal.exe C:\Users\Jive1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Flight Méditerranée Autogen Pack v1.0\Readme.lnk - C:\Users\Jive1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Flight Méditerranée Autogen Pack v1.0\Uninstall Flight Méditerranée Autogen Pack v1.0.lnk - C:\Users\Jive1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FlightAlpes Nord AutogenPack\Uninstall FlightAlpes Nord AutogenPack.lnk - D:\FS9\Uninstal.exe C:\Users\Jive1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\France VFR\FlightParis CityPack\Manuel utilisateur.lnk - D:\FS9\France VFR\FlightParis CityPack\flightparis_citypack_FR.pdf C:\Users\Jive1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\France VFR\FlightParis CityPack\Objects chart.lnk - D:\FS9\France VFR\FlightParis CityPack\flightparis_citypack_carte.pdf C:\Users\Jive1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\France VFR\FlightParis CityPack\Uninstall FlightParis CityPack.lnk - D:\FS9\uninstal_fpcp.exe C:\Users\Jive1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\France VFR\FlightParis CityPack\User's manual.lnk - D:\FS9\France VFR\FlightParis CityPack\flightparis_citypack_EN.pdf C:\Users\Jive1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\France VFR\Riviera JetSet\Manuel utilisateur.lnk - D:\FS9\France VFR\Riviera JetSet\riviera_jetset_FR.pdf C:\Users\Jive1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\France VFR\Riviera JetSet\Uninstall Riviera JetSet.lnk - D:\FS9\uninstal_jetset.exe C:\Users\Jive1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\France VFR\Riviera JetSet\User's manual.lnk - D:\FS9\France VFR\Riviera JetSet\riviera_jetset_EN.pdf C:\Users\Jive1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FS Flight Tracker\Flight Log Converter.lnk - C:\Users\Jive1\AppData\Roaming\Microsoft\Installer\{185FC180-2C4D-48E3-B68A-8A611AEE8AFA}\_7cee4a0b.exe C:\Users\Jive1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FS Flight Tracker\FS Flight Tracker Help.lnk - C:\Users\Jive1\AppData\Roaming\Microsoft\Installer\{185FC180-2C4D-48E3-B68A-8A611AEE8AFA}\_4c3274a.exe C:\Users\Jive1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FS Flight Tracker\FS Flight Tracker.lnk - C:\Users\Jive1\AppData\Roaming\Microsoft\Installer\{185FC180-2C4D-48E3-B68A-8A611AEE8AFA}\_25bd4a1.exe C:\Users\Jive1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FS Flight Tracker\Read Me.lnk - C:\Users\Jive1\AppData\Roaming\Microsoft\Installer\{185FC180-2C4D-48E3-B68A-8A611AEE8AFA}\_4235632d.exe C:\Users\Jive1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FS9NTV1 Northern Territory by Roger Leupold\Uninstall FS9NTV1 Northern Territory by Roger Leupold.lnk - D:\Extract\Uninstal.exe C:\Users\Jive1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games\Microsoft Flight Simulator 2004™.lnk - C:\Users\Jive1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MW Graphics\DXTBmp.lnk - C:\Graphics\MWGraphics\DXTBmp\DXTBmp.exe C:\Users\Jive1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Nord 2501 NORATLAS\Désinstaller Nord 2501 NORATLAS.lnk - C:\Users\Jive1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ORBX\Tamworth User Manual.lnk - D:\Extract\ORBXT\ORBX\Tamworth Manual.pdf C:\Users\Jive1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ORBX\Uninstall Orbx Tamworth.lnk - D:\Extract\ORBXT\ORBX_Tamworth_Uninstaller C:\Users\Jive1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Rikoooo Add-ons\Sardinia Photorealistic Pack FS2004\immagini.lnk - D:\Extract\Scenery\Sardinia_Photorealistic_Pack_FS2004\immagini C:\Users\Jive1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Rikoooo Add-ons\Sardinia Photorealistic Pack FS2004\Leggimi.txt.lnk - D:\Extract\Scenery\Sardinia_Photorealistic_Pack_FS2004\Leggimi.txt C:\Users\Jive1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Rikoooo Add-ons\Sardinia Photorealistic Pack FS2004\Sardegna fotorealistica.jpg.lnk - D:\Extract\Scenery\Sardinia_Photorealistic_Pack_FS2004\Sardegna fotorealistica.jpg C:\Users\Jive1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Rikoooo Add-ons\Sardinia Photorealistic Pack FS2004\Sardinia_Photorealistic_Pack_FS2004.lnk - D:\Extract\Scenery\Sardinia_Photorealistic_Pack_FS2004 C:\Users\Jive1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Rikoooo Add-ons\Sardinia Photorealistic Pack FS2004\Uninstall Sardinia Photorealistic Pack FS2004.lnk - C:\ProgramData\InstallMate\{AED7D503-8364-49FF-9CCF-1E8632E43E45}\Setup.exe /remove C:\Users\Jive1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Sofia Airport (LBSF)\Uninstall Sofia Airport (LBSF).lnk - D:\Extract\Sofia Airport (LBSF)_Uninstal.exe C:\Users\Jive1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Verzenden naar OneNote.lnk - C:\Program Files\Microsoft Office 15\root\office15\ONENOTEM.EXE /tsr C:\Users\Jive1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Tasmania - Australia\Uninstall Tasmania - Australia.lnk - D:\Extract\Uninstal.exe C:\Users\Jive1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Tasmanian Landclass Scenery\Uninstall Tasmanian Landclass Scenery.lnk - D:\Extract\Uninstal.exe C:\Users\Jive1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR\Console RAR manual.lnk - C:\Program Files (x86)\WinRAR\Rar.txt C:\Users\Jive1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR\What is new in the latest version.lnk - C:\Program Files (x86)\WinRAR\WhatsNew.txt C:\Users\Jive1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR\WinRAR help.lnk - C:\Program Files (x86)\WinRAR\WinRAR.chm C:\Users\Jive1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR\WinRAR.lnk - C:\Program Files (x86)\WinRAR\WinRAR.exe C:\Users\Jive1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WS_FTP\Uninstall WS_FTP LE.lnk - C:\Program Files (x86)\WS_FTP\remove.exe C:\Users\Jive1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WS_FTP\WS_FTP LE Help.lnk - C:\Program Files (x86)\WS_FTP\WS_FTP.hlp C:\Users\Jive1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WS_FTP\WS_FTP LE Release Notes.lnk - C:\Program Files (x86)\WS_FTP\whatsnew.txt C:\Users\Jive1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WS_FTP\WS_FTP95 LE.lnk - C:\Program Files (x86)\WS_FTP\WS_FTP95.exe ==== shortcuts in All Users Start Menu ====================== C:\ProgramData\Microsoft\Windows\Start Menu\WinZip.lnk - C:\Program Files (x86)\WinZip\WINZIP32.EXE C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk - C:\Windows\Installer\{AC76BA86-7AD7-1043-7B44-AC0F074E4100}\SC_Reader.ico C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Help.lnk - C:\Program Files (x86)\Adobe\Adobe Help\Adobe Help.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk - C:\Windows\ehome\ehshell.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk - C:\Program Files (x86)\Mozilla Firefox\firefox.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Thunderbird.lnk - C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Math Input Panel.lnk - C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\mip.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Mobility Center.lnk - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Remote Desktop Connection.lnk - C:\Windows\system32\mstsc.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Snipping Tool.lnk - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Sticky Notes.lnk - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Tablet PC\ShapeCollector.lnk - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Tablet PC\TabTip.lnk - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Tablet PC\Windows Journal.lnk - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ActiveSky 6\ActiveSky Graphics.lnk - D:\FS9\Modules\ASGraphics\ASG.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ActiveSky 6\ARConnector for WideFS Users.lnk - D:\FS9\Modules\ASv6\ActiveRadarConnector.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ActiveSky 6\ASGraphics User Guide.lnk - D:\FS9\Modules\ASGraphics\User Guide\ASG_User_Guide.htm C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ActiveSky 6\ASv6 User Guide.lnk - D:\FS9\Modules\ASv6\User Guide\ASv6_User_Guide.htm C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ActiveSky 6\ASv6 Wx Engine.lnk - D:\FS9\Modules\ASv6\ASv6.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ActiveSky 6\Aviation Weather Guide.lnk - D:\FS9\Modules\ASv6\Aviation Weather Guide.pdf C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ActiveSky 6\Readme.lnk - D:\FS9\Modules\ASv6\readme.txt C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ActiveSky 6\Support FAQ.lnk - D:\FS9\Modules\ASv6\SupportFaq.rtf C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ADF AI for FS2004\Uninstall ADF AI for FS2004.lnk - D:\Extract\ADF\ADFAI_Uninstal.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe\Adobe Media Player.lnk - C:\Program Files (x86)\Adobe Media Player\Adobe Media Player.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Master Collection CS5\Adobe After Effects CS5.lnk - C:\Program Files\Adobe\Adobe After Effects CS5\Support Files\AfterFX.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Master Collection CS5\Adobe Bridge CS5.lnk - C:\Program Files (x86)\Adobe\Adobe Bridge CS5\Bridge.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Master Collection CS5\Adobe Contribute CS5.lnk - C:\Program Files (x86)\Adobe\Adobe Contribute CS5\App\Contribute.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Master Collection CS5\Adobe Device Central CS5.lnk - C:\Program Files (x86)\Adobe\Adobe Device Central CS5\DeviceCentral.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Master Collection CS5\Adobe Dreamweaver CS5.lnk - C:\Program Files (x86)\Adobe\Adobe Dreamweaver CS5\Dreamweaver.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Master Collection CS5\Adobe Encore CS5.lnk - C:\Program Files (x86)\Adobe\Adobe Encore CS5\Adobe Encore.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Master Collection CS5\Adobe ExtendScript Toolkit CS5.lnk - C:\Program Files (x86)\Adobe\Adobe Utilities - CS5\ExtendScript Toolkit CS5\ExtendScript Toolkit.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Master Collection CS5\Adobe Extension Manager CS5.lnk - C:\Program Files (x86)\Adobe\Adobe Extension Manager CS5\Adobe Extension Manager CS5.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Master Collection CS5\Adobe Fireworks CS5.lnk - C:\Program Files (x86)\Adobe\Adobe Fireworks CS5\Fireworks.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Master Collection CS5\Adobe Flash Builder 4.lnk - C:\Program Files (x86)\Adobe\Adobe Flash Builder 4\FlashBuilder.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Master Collection CS5\Adobe Flash Catalyst CS5.lnk - C:\Program Files (x86)\Adobe\Adobe Flash Catalyst CS5\Adobe Flash Catalyst.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Master Collection CS5\Adobe Flash Professional CS5.lnk - C:\Program Files (x86)\Adobe\Adobe Flash CS5\Flash.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Master Collection CS5\Adobe Illustrator CS5.lnk - C:\Program Files (x86)\Adobe\Adobe Illustrator CS5\Support Files\Contents\Windows\Illustrator.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Master Collection CS5\Adobe InDesign CS5.lnk - C:\Program Files (x86)\Adobe\Adobe InDesign CS5\InDesign.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Master Collection CS5\Adobe Media Encoder CS5.lnk - C:\Program Files\Adobe\Adobe Media Encoder CS5\Adobe Media Encoder.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Master Collection CS5\Adobe OnLocation CS5.lnk - C:\Program Files (x86)\Adobe\Adobe OnLocation CS5\Adobe OnLocation.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Master Collection CS5\Adobe Photoshop CS5 (64 Bit).lnk - C:\Program Files\Adobe\Adobe Photoshop CS5 (64 Bit)\Photoshop.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Master Collection CS5\Adobe Photoshop CS5.lnk - C:\Program Files (x86)\Adobe\Adobe Photoshop CS5\Photoshop.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Master Collection CS5\Adobe Pixel Bender Toolkit 2.lnk - C:\Program Files (x86)\Adobe\Adobe Utilities - CS5\Pixel Bender Toolkit 2\Pixel Bender Toolkit.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Master Collection CS5\Adobe Premiere Pro CS5.lnk - C:\Program Files\Adobe\Adobe Premiere Pro CS5\Adobe Premiere Pro.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Master Collection CS5\Adobe Soundbooth CS5.lnk - C:\Program Files (x86)\Adobe\Adobe Soundbooth CS5\Adobe Soundbooth CS5.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced Driver Updater\Advanced Driver Updater.lnk - C:\Program Files (x86)\Advanced Driver Updater\adu.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced Driver Updater\Verwijder Advanced Driver Updater.lnk - C:\Program Files (x86)\Advanced Driver Updater\unins000.exe /silent C:\ProgramData\Microsoft\Windows\Start Menu\Programs\aerosoft\Professional Flight Planner X\Handbuch.lnk - D:\FS9 Addon Programs\PFPX\Handbuch.pdf C:\ProgramData\Microsoft\Windows\Start Menu\Programs\aerosoft\Professional Flight Planner X\Manual.lnk - D:\FS9 Addon Programs\PFPX\Manual.pdf C:\ProgramData\Microsoft\Windows\Start Menu\Programs\aerosoft\Professional Flight Planner X\PFPX.lnk - D:\FS9 Addon Programs\PFPX\PFPX.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\aerosoft\Professional Flight Planner X\Support-Files.lnk - C:\Windows\explorer.exe "D:\FS9 Addon Programs\PFPX\SupportFiles" C:\ProgramData\Microsoft\Windows\Start Menu\Programs\aerosoft\Professional Flight Planner X\UninstallProfessional Flight Planner X.lnk - C:\Program Files (x86)\InstallShield Installation Information\{1A5D2729-4A3B-4CD5-85C8-4896FD44B78D}\setup.exe -runfromtemp -l0x0007 -uninst -removeonly C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Alleycode\Alleycode HTML Editor on the Web.lnk - C:\Program Files (x86)\Alleycode\alleycode.url C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Alleycode\Alleycode HTML Editor.lnk - C:\Program Files (x86)\Alleycode\alleycode.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Alleycode\Uninstall Alleycode HTML Editor.lnk - C:\Program Files (x86)\Alleycode\unins000.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Amberley Airport 2009\Uninstall Amberley Airport 2009.lnk - C:\Windows\Amberley Airport 2009\uninstall.exe "/U:C:\Windows\Uninstall\uninstall.xml" C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AUscene - Sydney Professional FS9\Uninstall AUscene - Sydney Professional FS9.lnk - D:\Extract\Uninstal.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BullGuard\BullGuard.lnk - C:\Program Files\BullGuard Ltd\BullGuard\BullGuard.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner\CCleaner.lnk - C:\Program Files\CCleaner\CCleaner64.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner\Uninstall CCleaner.lnk - C:\Program Files\CCleaner\uninst.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FPtoFMC\FP2FMC.lnk - D:\FS9 Addon Programs\FPtoFMC\FPtoFMC\FP2FMC.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\France VFR\Aircraft Collection\Désinstaller Aircraft Collection.lnk - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\France VFR\Aircraft Collection\Manuel utilisateur.lnk - D:\FS9\France VFR\Aircraft Collection\AircraftCollection_FR.pdf C:\ProgramData\Microsoft\Windows\Start Menu\Programs\France VFR\Aircraft Collection\User's manual.lnk - D:\FS9\France VFR\Aircraft Collection\AircraftCollection_EN.pdf C:\ProgramData\Microsoft\Windows\Start Menu\Programs\France VFR\FlightAlpes BasePack Nord\Désinstaller FlightAlpes BasePack Nord.lnk - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\France VFR\FlightParis AutogenPack\Désinstaller FlightParis AutogenPack.lnk - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\France VFR\FlightPyrenees Oriental AutogenPack\Désinstaller FlightPyrenees Oriental AutogenPack.lnk - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\France VFR\FlightPyrenees Oriental AutogenPack\Manuel utilisateur.lnk - D:\FS9\France VFR\FlightPyreneesOri AutogenPack\flightpyreneesoriAP_FR.pdf C:\ProgramData\Microsoft\Windows\Start Menu\Programs\France VFR\FlightPyrenees Oriental AutogenPack\User's manual.lnk - D:\FS9\France VFR\FlightPyreneesOri AutogenPack\flightpyreneesoriAP_EN.pdf C:\ProgramData\Microsoft\Windows\Start Menu\Programs\France VFR\FlightPyreneesOri BasePack\Cartes SIA-DIRCAM et documentation de vol.lnk - D:\FS9\France VFR\FlightPyreneesOri BasePack\flightpyreneesori_cartes.pdf C:\ProgramData\Microsoft\Windows\Start Menu\Programs\France VFR\FlightPyreneesOri BasePack\Désinstaller FlightPyrénées Orientales BasePack.lnk - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\France VFR\FlightPyreneesOri BasePack\Manuel utilisateur.lnk - D:\FS9\France VFR\FlightPyreneesOri BasePack\flightpyreneesori_FR.pdf C:\ProgramData\Microsoft\Windows\Start Menu\Programs\France VFR\FlightPyreneesOri BasePack\SIA-DIRCAM charts and flight documentation.lnk - D:\FS9\France VFR\FlightPyreneesOri BasePack\flightpyreneesori_charts.pdf C:\ProgramData\Microsoft\Windows\Start Menu\Programs\France VFR\FlightPyreneesOri BasePack\User's manual.lnk - D:\FS9\France VFR\FlightPyreneesOri BasePack\flightpyreneesori_EN.pdf C:\ProgramData\Microsoft\Windows\Start Menu\Programs\France VFR\FlightRiviera BasePack\Cartes et documentation de vol.lnk - D:\FS9\France VFR\FlightRiviera BasePack\flightriviera_cartes.pdf C:\ProgramData\Microsoft\Windows\Start Menu\Programs\France VFR\FlightRiviera BasePack\Charts and flight documentation.lnk - D:\FS9\France VFR\FlightRiviera BasePack\flightriviera_charts.pdf C:\ProgramData\Microsoft\Windows\Start Menu\Programs\France VFR\FlightRiviera BasePack\Désinstaller FlightRiviera BasePack.lnk - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\France VFR\FlightRiviera BasePack\Manuel utilisateur.lnk - D:\FS9\France VFR\FlightRiviera BasePack\flightriviera_FR.pdf C:\ProgramData\Microsoft\Windows\Start Menu\Programs\France VFR\FlightRiviera BasePack\User' manual.lnk - D:\FS9\France VFR\FlightRiviera BasePack\flightriviera_EN.pdf C:\ProgramData\Microsoft\Windows\Start Menu\Programs\France VFR\Guadeloupe\Cartes SIA - Croisière niveau inférieur.lnk - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\France VFR\Guadeloupe\Cartes SIA - Croisière niveau supérieur.lnk - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\France VFR\Guadeloupe\Cartes SIA - TFFA La Désirade – Grande Anse.lnk - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\France VFR\Guadeloupe\Cartes SIA - TFFB Basse Terre - Baillif.lnk - D:\FS9\France VFR\Guadeloupe\0704_AD 2.TFFB.pdf C:\ProgramData\Microsoft\Windows\Start Menu\Programs\France VFR\Guadeloupe\Cartes SIA - TFFC St-François.lnk - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\France VFR\Guadeloupe\Cartes SIA - TFFM Marie-Galante.lnk - D:\FS9\France VFR\Guadeloupe\0704_AD 2.TFFM.pdf C:\ProgramData\Microsoft\Windows\Start Menu\Programs\France VFR\Guadeloupe\Cartes SIA - TFFR Pointe A Pitre - Le Raizet.lnk - D:\FS9\France VFR\Guadeloupe\0704_AD 2.TFFR.pdf C:\ProgramData\Microsoft\Windows\Start Menu\Programs\France VFR\Guadeloupe\Cartes SIA - TFFS Les Saintes – Terre De Haut.lnk - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\France VFR\Guadeloupe\Désinstaller La Guadeloupe.lnk - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\France VFR\Guadeloupe\Manuel utilisateur.lnk - D:\FS9\France VFR\Guadeloupe\guadeloupe_FR.pdf C:\ProgramData\Microsoft\Windows\Start Menu\Programs\France VFR\Guadeloupe\User's manual.lnk - D:\FS9\France VFR\Guadeloupe\guadeloupe_EN.pdf C:\ProgramData\Microsoft\Windows\Start Menu\Programs\France VFR\LittoralMediterranee\Désinstaller FlightMediterranee BasePack.lnk - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\France VFR\Martinique\Cartes SIA - Croisière niveau inférieur.lnk - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\France VFR\Martinique\Désinstaller La Martinique.lnk - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\France VFR\Martinique\Manuel utilisateur.lnk - D:\FS9\France VFR\Martinique\martinique_FR.pdf C:\ProgramData\Microsoft\Windows\Start Menu\Programs\France VFR\Mayotte\Horaires AI (AI Time Table).lnk - D:\FS9\France VFR\Mayotte\TrafficMayotte.htm C:\ProgramData\Microsoft\Windows\Start Menu\Programs\France VFR\Mayotte\Manuel utilisateur.lnk - D:\FS9\France VFR\Mayotte\mayotte_FR.pdf C:\ProgramData\Microsoft\Windows\Start Menu\Programs\France VFR\Mayotte\SIA - AIP RUN AD 2 FMCZ.lnk - D:\FS9\France VFR\Mayotte\AIP RUN AD 2.FMCZ.pdf C:\ProgramData\Microsoft\Windows\Start Menu\Programs\France VFR\Mayotte\SIA - AIP RUN ENR FMCZ.lnk - D:\FS9\France VFR\Mayotte\AIP RUN ENR 6.1.pdf C:\ProgramData\Microsoft\Windows\Start Menu\Programs\France VFR\Mayotte\Uninstall Mayotte.lnk - D:\FS9\uninstal_mayotte.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\France VFR\Mayotte\User's manual.lnk - D:\FS9\France VFR\Mayotte\mayotte_EN.pdf C:\ProgramData\Microsoft\Windows\Start Menu\Programs\France VFR\MontStMichel\Checklist - EDA TB10 DGAC.lnk - D:\FS9\Aircraft\eda_tb10_dgac\Doc\eda_tb_check.pdf C:\ProgramData\Microsoft\Windows\Start Menu\Programs\France VFR\MontStMichel\Documentation - EDA TB10 DGAC.lnk - D:\FS9\Aircraft\eda_tb10_dgac\Doc\eda_tb_doc.pdf C:\ProgramData\Microsoft\Windows\Start Menu\Programs\France VFR\MontStMichel\Désinstaller La Baie du Mont-St-Michel.lnk - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\France VFR\Rennes\Désinstaller Rennes.lnk - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\France VFR\Rennes\Manuel utilisateur (FR).lnk - D:\FS9\France VFR\Rennes\rennes_FR.pdf C:\ProgramData\Microsoft\Windows\Start Menu\Programs\France VFR\Rennes\Preview.lnk - D:\FS9\France VFR\Rennes\rennes_preview.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\France VFR\Rennes\SIA - Cartes Aéroport.lnk - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\France VFR\Rennes\SIA - Cartes VAC.lnk - D:\FS9\France VFR\Rennes\LFRN-VAC.pdf C:\ProgramData\Microsoft\Windows\Start Menu\Programs\France VFR\Rennes\Traffic AI (Time Tables).lnk - D:\FS9\France VFR\Rennes\rennes_trf.pdf C:\ProgramData\Microsoft\Windows\Start Menu\Programs\France VFR\Rennes\User's manual (UK).lnk - D:\FS9\France VFR\Rennes\rennes_UK.pdf C:\ProgramData\Microsoft\Windows\Start Menu\Programs\France VFR\Reunion\Désinstaller La Réunion.lnk - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\France VFR\Reunion\Horaires AI (AI Time Table).lnk - D:\FS9\France VFR\Reunion\GrilleHoraires.htm C:\ProgramData\Microsoft\Windows\Start Menu\Programs\France VFR\Reunion\Manuel utilisateur.lnk - D:\FS9\France VFR\Reunion\reunion_FR.pdf C:\ProgramData\Microsoft\Windows\Start Menu\Programs\France VFR\Reunion\SIA - AIP RUN AD 2.FMEE.lnk - D:\FS9\France VFR\Reunion\AIP RUN AD 2.FMEE.pdf C:\ProgramData\Microsoft\Windows\Start Menu\Programs\France VFR\Reunion\SIA - AIP RUN AD 2.FMEP.lnk - D:\FS9\France VFR\Reunion\AIP RUN AD 2.FMEP.pdf C:\ProgramData\Microsoft\Windows\Start Menu\Programs\France VFR\Reunion\SIA - AIP RUN AD 3.1.pdf.lnk - D:\FS9\France VFR\Reunion\AIP RUN AD 3.1.pdf C:\ProgramData\Microsoft\Windows\Start Menu\Programs\France VFR\Reunion\SIA - AIP RUN ENR 6.1.pdf.lnk - D:\FS9\France VFR\Reunion\AIP RUN ENR 6.1.pdf C:\ProgramData\Microsoft\Windows\Start Menu\Programs\France VFR\Reunion\User's manual.lnk - D:\FS9\France VFR\Reunion\reunion_EN.pdf C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FS Sound Studio\FS Sound Studio Help.lnk - D:\Extract\Sound\fsss.chm C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FS Sound Studio\FS Sound Studio on the WWWW.lnk - D:\Extract\Sound\FS Sound Studio site.url C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FS Sound Studio\FS Sound Studio.lnk - D:\Extract\Sound\fsss.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FS Sound Studio\License Information.lnk - D:\Extract\Sound\License.txt C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FS Sound Studio\Uninstall.lnk - D:\Extract\Sound\Uninstal.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FSGenesis\Australia 76.4m Terrain\Remove FSGenesis Australia 76.4m Terrain.lnk - C:\Windows\unvise32.exe \Microsoft\Windows\CurrentVersion\SharedDlls C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\Chess.lnk - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\Internet Backgammon.lnk - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\Internet Checkers.lnk - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\Internet Spades.lnk - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\Mahjong.lnk - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\About Java.lnk - C:\Program Files (x86)\Java\jre1.8.0_66\bin\javacpl.exe -tab about C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\Check For Updates.lnk - C:\Program Files (x86)\Java\jre1.8.0_66\bin\javacpl.exe -tab update C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\Configure Java.lnk - C:\Program Files (x86)\Java\jre1.8.0_66\bin\javacpl.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Logitech\Launch Gaming Software Profiler.lnk - C:\Windows\Installer\{1444D2EE-C7AD-44A8-844F-2634B49353D1}\NewShortcut1_7E69263C626D4C569CA13522D79FEB7F.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Games\Microsoft Flight Simulator 2004\Flight Instructor.lnk - D:\FS9\fs9.exe /INSTRUCTOR C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Games\Microsoft Flight Simulator 2004\Microsoft Flight Simulator 2004 Readme.lnk - D:\FS9\Readme.rtf C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Games\Microsoft Flight Simulator 2004\Microsoft Flight Simulator 2004.lnk - D:\FS9\fs9.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Games\Microsoft Flight Simulator 2004\Uninstall Microsoft Flight Simulator 2004.lnk - D:\FS9\UNINSTAL.EXE /runtemp C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Games\Microsoft Flight Simulator 2004\Troubleshooting\Configuration Support.lnk - D:\FS9\Config\ConfigSupport.htm C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Games\Microsoft Flight Simulator 2004\Troubleshooting\Reset Defaults.lnk - D:\FS9\fs9.exe -RESETINI C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Games\Microsoft Flight Simulator 2004\Troubleshooting\Safe Mode.lnk - D:\FS9\fs9.exe -SWREND C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013\Access 2013.lnk - C:\Program Files (x86)\Microsoft Office 15\root\office15\MSACCESS.EXE C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013\Excel 2013.lnk - C:\Program Files (x86)\Microsoft Office 15\root\office15\EXCEL.EXE C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013\OneNote 2013.lnk - C:\Program Files (x86)\Microsoft Office 15\root\office15\ONENOTE.EXE C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013\Outlook 2013.lnk - C:\Program Files (x86)\Microsoft Office 15\root\office15\OUTLOOK.EXE C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013\PowerPoint 2013.lnk - C:\Program Files (x86)\Microsoft Office 15\root\office15\POWERPNT.EXE C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013\Publisher 2013.lnk - C:\Program Files (x86)\Microsoft Office 15\root\office15\MSPUB.EXE C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013\Verzenden naar OneNote 2013.lnk - C:\Program Files (x86)\Microsoft Office 15\root\office15\ONENOTEM.EXE C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013\Word 2013.lnk - C:\Program Files (x86)\Microsoft Office 15\root\office15\WINWORD.EXE C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013\Hulpprogramma's van Office 2013\Office 2013 Upload Center.lnk - C:\Program Files (x86)\Microsoft Office 15\root\office15\MSOUC.EXE C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013\Hulpprogramma's van Office 2013\Taalvoorkeuren voor Office 2013.lnk - C:\Program Files (x86)\Microsoft Office 15\root\office15\SETLANG.EXE C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight\Microsoft Silverlight.lnk - C:\Program Files (x86)\Microsoft Silverlight\5.1.41212.0\Silverlight.Configuration.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation\GeForce Experience.lnk - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\LaunchGFExperience.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation\3D Vision\3D Vision Photo Viewer.lnk - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvstview.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation\3D Vision\3D Vision preview pack 1.lnk - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvstlink.exe /show C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation\3D Vision\Disable 3D Vision.lnk - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvstlink.exe /disable C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation\3D Vision\Enable 3D Vision.lnk - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvstlink.exe /enable C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerISO\PowerISO Help.lnk - C:\Program Files\PowerISO\PowerISO.chm C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerISO\PowerISO Virtual Drive Manager.lnk - C:\Program Files\PowerISO\PWRISOVM.EXE C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerISO\PowerISO.lnk - C:\Program Files\PowerISO\PowerISO.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerISO\Uninstall PowerISO.lnk - C:\Program Files\PowerISO\uninstall.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PrintKey2000\Printkey2000.lnk - C:\Program Files (x86)\PrintKey2000\Printkey2000.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PrintKey2000\ReadMe.lnk - C:\Program Files (x86)\PrintKey2000\ReadMe.rtf C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype\Skype.lnk - C:\Program Files (x86)\Skype\Phone\Skype.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Speccy\Speccy.lnk - C:\Program Files\Speccy\Speccy64.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Printkey2000.lnk - C:\Program Files (x86)\PrintKey2000\Printkey2000.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\The Owl's Tools\AI-Aircraft Editor\AI-Aircraft Editor.lnk - D:\FS9 Addon Programs\AI-Aircraft Editor\AI-Aircraft-Editor.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\The Owl's Tools\AI-Aircraft Editor\Help\AI-Aircraft Editor Manual.lnk - D:\FS9 Addon Programs\AI-Aircraft Editor\Manuals\AI-Editor-Readme.pdf C:\ProgramData\Microsoft\Windows\Start Menu\Programs\The Owl's Tools\AI-Aircraft Editor\Help\nVidia Inspector Profile.lnk - D:\FS9 Addon Programs\AI-Aircraft Editor\AIAEModelViewer_nvidia_inspector.zip C:\ProgramData\Microsoft\Windows\Start Menu\Programs\The Owl's Tools\AI-Aircraft Editor\Help\Uninstall AI-Aircraft Editor.lnk - D:\FS9 Addon Programs\AI-Aircraft Editor\unins000.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VOZ AI 1.2\A Brief History.lnk - D:\Extract\VOZ\VOZ AI 1.2 Documentation\A Brief History.pdf C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VOZ AI 1.2\AI Credits.lnk - D:\Extract\VOZ\VOZ AI 1.2 Documentation\AI Credits.xls C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VOZ AI 1.2\AI Parking Codes.lnk - D:\Extract\VOZ\VOZ AI 1.2 Documentation\AI_parking_codes.xls C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VOZ AI 1.2\Uninstall VOZ AI 1.2.lnk - D:\Extract\Uninstall_VOZAI120.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VOZ AI 1.2\VOZ AI 120 Manual.lnk - D:\Extract\VOZ\VOZ AI 1.2 Documentation\VOZ_AI_120_Manual.pdf C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wilco Publishing\737-300 PIC\737PIC Setup Utility.lnk - D:\FS9\FeelThere\b737\737setup.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wilco Publishing\737-300 PIC\Uninstall 737-300 Pilot in Command.lnk - D:\FS9\Uninstal_737-300PIC.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinImage\WinImage (administrator).lnk - C:\Program Files (x86)\WinImage\winimage.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinImage\WinImage Ordering Web Page.lnk - C:\Program Files (x86)\WinImage\order.url C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinImage\WinImage Uninstall.lnk - C:\Program Files (x86)\WinImage\winimage.exe /uninstall C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinImage\WinImage Web Site.lnk - C:\Program Files (x86)\WinImage\winimage.url C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinImage\WinImage.lnk - C:\Program Files (x86)\WinImage\winimage.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR\Console RAR manual.lnk - C:\Program Files (x86)\WinRAR\Rar.txt C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR\What is new in the latest version.lnk - C:\Program Files (x86)\WinRAR\WhatsNew.txt C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR\WinRAR help.lnk - C:\Program Files (x86)\WinRAR\WinRAR.chm C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR\WinRAR.lnk - C:\Program Files (x86)\WinRAR\WinRAR.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinZip\Help Manual.lnk - C:\Windows\hh.exe C:\PROGRA~2\WinZip\winzip.chm C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinZip\WinZip 12.0.lnk - C:\Program Files (x86)\WinZip\WINZIP32.EXE ==== shortcuts in Quick Launch ====================== C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk - C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk - C:\Users\Default User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk - C:\Users\Default User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk - C:\Users\Jive1\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\FlightSim Manager.lnk - D:\Programs\FlightSimManager\FlightSimManager.exe C:\Users\Jive1\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Flight Simulator (Random Splashscreen).lnk - D:\Programs\FlightSimManager\FlightSimManager.exe -launchFS C:\Users\Jive1\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk - C:\Program Files (x86)\Internet Explorer\iexplore.exe C:\Users\Jive1\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Microsoft Outlook.lnk - C:\Program Files\Microsoft Office 15\root\office15\OUTLOOK.EXE /recycle C:\Users\Jive1\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk - C:\Users\Jive1\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\WarThunder.lnk - C:\Program Files\Internet Explorer\iexplore.exe http://mmotraffic.com/catalog/goplay/1000932/MTE3NjYvLy8xMDAwOTMy?click_id=tAzzyCtDyByBtCtA0BzytB0A0B0FyC0B2RtBtDtCyCtDtCtCtCtCyEyDyDtCyEzyzztB C:\Users\Jive1\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk - C:\Users\Jive1\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Word 2013.lnk - C:\Program Files (x86)\Microsoft Office 15\root\office15\WINWORD.EXE C:\Users\Jive1\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Adobe Photoshop CS5 (64 Bit).lnk - C:\Program Files\Adobe\Adobe Photoshop CS5 (64 Bit)\Photoshop.exe C:\Users\Jive1\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\AFX.lnk - D:\FS9 Addon Programs\AFX\AFX.exe C:\Users\Jive1\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Alleycode HTML Editor.lnk - C:\Program Files (x86)\Alleycode\alleycode.exe C:\Users\Jive1\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\ASv6.exe - Snelkoppeling.lnk - D:\FS9\Modules\ASv6\ASv6.exe C:\Users\Jive1\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\FlattEx.exe - Snelkoppeling.lnk - D:\Programs\Flattex\FlattEx.exe C:\Users\Jive1\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\fs9.exe - Snelkoppeling.lnk - D:\FS9\fs9.exe C:\Users\Jive1\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\FSNavDBC.exe - Snelkoppeling.lnk - D:\FS9\Modules\FSNavigator\Bin\FSNavDBC.exe C:\Users\Jive1\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk - C:\Program Files (x86)\Internet Explorer\iexplore.exe C:\Users\Jive1\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk - C:\Program Files (x86)\Mozilla Firefox\firefox.exe C:\Users\Jive1\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Thunderbird.lnk - C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe C:\Users\Jive1\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Outlook 2013.lnk - C:\Program Files (x86)\Microsoft Office 15\root\office15\OUTLOOK.EXE C:\Users\Jive1\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Windows Explorer.lnk - C:\Windows\explorer.exe ==== shortcuts After Repair ====================== C:\Users\Jive1\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\WarThunder.lnk - C:\Program Files\Internet Explorer\iexplore.exe ==== Deleting Registry Keys ====================== HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Advanced Driver Updater_is1 deleted successfully ==== HijackThis Entries ====================== F2 - REG:system.ini: UserInit=userinit.exe, O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL O3 - Toolbar: Contribute Toolbar - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files (x86)\Adobe\Adobe Contribute CS5\Plugins\IEPlugin\contributeieplugin.dll O4 - HKLM\..\Run: [AdobeCS5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" O4 - HKLM\..\Run: [Navigraph FMS Data Manager] D:\FS9 Addon Programs\FMS Data Manager\NGFMSAgent.exe -autostart O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE') O4 - Startup: Verzenden naar OneNote.lnk = C:\Program Files\Microsoft Office 15\root\office15\ONENOTEM.EXE O4 - Global Startup: Printkey2000.lnk = C:\Program Files (x86)\PrintKey2000\Printkey2000.exe O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIE.dll O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIE.dll O9 - Extra button: Report to BullGuard - {27FD17FB-CF63-486b-B2BE-8D8781CBEA01} - C:\Program Files\BullGuard Ltd\BullGuard\Files32\Antiphishing\IE\BGAntiphishingIE.dll O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIELinkedNotes.dll O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIELinkedNotes.dll O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing) O23 - Service: BullGuard Behavioural Detection (BsBhvScan) - BullGuard Ltd. - c:\program files\bullguard ltd\bullguard\BullGuardBhvScanner.exe O23 - Service: BullGuard scanning service (BsScanner) - BullGuard Ltd. - c:\program files\bullguard ltd\bullguard\BullGuardScanner.exe O23 - Service: BullGuard update service (BsUpdate) - BullGuard Ltd. - c:\program files\bullguard ltd\bullguard\BullGuardUpdate.exe O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing) O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing) O23 - Service: NVIDIA GeForce Experience Service (GfExperienceService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing) O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing) O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: NVIDIA Network Service (NvNetworkService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe O23 - Service: NVIDIA Streamer Network Service (NvStreamNetworkSvc) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe O23 - Service: NVIDIA Streamer Service (NvStreamSvc) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing) O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing) O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing) O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing) O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing) O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing) O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing) O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing) O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing) O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing) O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing) O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing) ==== Empty IE Cache ====================== C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Jive1\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Jive1\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully ==== Empty FireFox Cache ====================== C:\Users\Jive1\AppData\Local\Mozilla\Firefox\Profiles\jqdvbdgp.default\cache2 emptied successfully ==== Empty Chrome Cache ====================== No Chrome Cache found ==== Empty All Flash Cache ====================== Flash Cache Emptied Successfully ==== Empty All Java Cache ====================== Java Cache cleared successfully ==== C:\zoek_backup content ====================== C:\zoek_backup (files=134 folders=19 29601991 bytes) ==== Empty Temp Folders ====================== C:\Users\Default\AppData\Local\Temp emptied successfully C:\Users\Default User\AppData\Local\Temp emptied successfully C:\Users\Jive1\AppData\Local\Temp will be emptied at reboot C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully C:\Windows\Temp will be emptied at reboot ==== After Reboot ====================== ==== Empty Temp Folders ====================== C:\Windows\Temp successfully emptied C:\Users\Jive1\AppData\Local\Temp successfully emptied ==== Empty Recycle Bin ====================== C:\$RECYCLE.BIN successfully emptied ==== Deleting Files / Folders ====================== "C:\Users\Jive1\AppData\Local\Systweak" not found ==== EOF on di 19/01/2016 at 11:52:13,58 ======================