Zoek.exe v5.0.0.1 Updated 31-December-2015 Tool run by Pablo on di 02-02-2016 at 18:58:26,15. Microsoft Windows 10 Home 10.0.10586 x64 Running in: Normal Mode Internet Access Detected Launched: C:\Users\Pablo\Desktop\zoek.exe [Scan all users] [Checkboxes used] ==== Older Logs ====================== C:\zoek-results2015-01-12-155916.log 84989 bytes C:\zoek-results2015-01-14-115632.log 2837 bytes C:\zoek-results2015-01-18-133337.log 5940 bytes C:\zoek-results2016-01-27-073124.log 20915 bytes ==== Empty Folders Check ====================== C:\Users\Pablo\AppData\Local\ActiveSync deleted successfully C:\Users\Pablo\AppData\Local\NetworkTiles deleted successfully C:\WINDOWS\serviceprofiles\Localservice\AppData\Local\NetworkTiles deleted successfully ==== Deleting CLSID Registry Keys ====================== ==== Deleting CLSID Registry Values ====================== ==== Deleting Services ====================== ==== Files Recently Created / Modified ====================== ====== C:\WINDOWS ==== 2016-01-25 21:21:09 4E58A5742F64604B65D2DDD21E3AC6AC 467769027 ----a-w- C:\WINDOWS\MEMORY.DMP ====== C:\Users\Pablo\AppData\Local\Temp ==== ====== Java Cache ===== 2016-01-27 12:00:05 4F85459CEC4F78A3987FFFD5B6A816C5 605 ----a-w- C:\Users\Pablo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\37\52c00ce5-1c760d67 2016-01-27 12:00:05 D330AF89AE69A3542D48CBADA432787A 428 ----a-w- C:\Users\Pablo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\37\52c00ce5-78e96a5ccf5c5b6a29dcdffe1d16c989d010904d54059e7b28aad8dacf6a56c9-6.0.lap 2016-01-27 12:00:05 C9588417B10E1D770E3E5DA1F3510AE5 8425 ----a-w- C:\Users\Pablo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\45\298d42d-6a93ec81 2016-01-27 12:00:10 C1BBA7F1278F193AB584FFF460DB5E2A 17878 ----a-w- C:\Users\Pablo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\46\c8dc66e-7ae430c1 ====== C:\WINDOWS\SysWOW64 ===== 2016-01-29 01:28:20 D44345210CAC304817FAFBD4F0671E2C 6971752 ----a-w- C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll 2016-01-29 01:28:17 ADF1802719E1C3F5B3093EB2566F109E 18678272 ----a-w- C:\WINDOWS\SysWOW64\edgehtml.dll 2016-01-29 01:28:16 AE6803B8484965EB2B92E4B2AF016B43 19338752 ----a-w- C:\WINDOWS\SysWOW64\mshtml.dll 2016-01-29 01:28:13 8FA6855FCD9F683BC6761B97F7F48408 13018624 ----a-w- C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll 2016-01-29 01:28:08 E9FD92C0D2CD0DD877ECD086C6D6F99B 5238360 ----a-w- C:\WINDOWS\SysWOW64\windows.storage.dll 2016-01-29 01:28:07 C95A1EC1C230BCCF0984CEDFCBCF8836 12126208 ----a-w- C:\WINDOWS\SysWOW64\ieframe.dll 2016-01-29 01:28:06 8B160B088DA953EE6C16595AD5DA7787 9918976 ----a-w- C:\WINDOWS\SysWOW64\twinui.dll 2016-01-29 01:28:04 A1EB9EF86954DF012BD3A48803DB36C8 6297088 ----a-w- C:\WINDOWS\SysWOW64\mos.dll 2016-01-29 01:28:02 76D96571FE1FA529C3741B17B57F9696 21125400 ----a-w- C:\WINDOWS\SysWOW64\shell32.dll 2016-01-29 01:27:59 1C22BFBABCF389F2A985A32C01819467 5202944 ----a-w- C:\WINDOWS\SysWOW64\BingMaps.dll 2016-01-29 01:27:58 104ED5E318C5EED6178BE9F4B4E1E5A2 4759040 ----a-w- C:\WINDOWS\SysWOW64\d2d1.dll 2016-01-29 01:27:56 AFA5A77BB7F6FEFBDB9CAE34D3A215CF 1944576 ----a-w- C:\WINDOWS\SysWOW64\InputService.dll 2016-01-29 01:27:55 848606B6742D80BF6A7DD30E580BA7A9 1626624 ----a-w- C:\WINDOWS\SysWOW64\dwmcore.dll 2016-01-29 01:27:54 53F74B2F4AEA9C6A7BB9DABDCC3C7431 613888 ----a-w- C:\WINDOWS\SysWOW64\winhttp.dll 2016-01-29 01:27:53 A680339559FBC02BC0854D73DDE85C7B 1174008 ----a-w- C:\WINDOWS\SysWOW64\msctf.dll 2016-01-29 01:27:52 86128937B83E51BF543CBCB854AE4FFC 405568 ----a-w- C:\WINDOWS\SysWOW64\AudioSes.dll 2016-01-29 01:27:52 5E312BF7E912AAE9DA472B0027C4B8A9 709688 ----a-w- C:\WINDOWS\SysWOW64\mfsvr.dll 2016-01-29 01:27:52 2003BE1653553FBC9D809BA40AEE4D68 1542656 ----a-w- C:\WINDOWS\SysWOW64\quartz.dll 2016-01-29 01:27:50 DDC479FA1A36285BFC1EF25B547403C3 273408 ----a-w- C:\WINDOWS\SysWOW64\SensorsApi.dll 2016-01-29 01:27:50 5814754D92DBD471D5AB7437B20EE3F0 687616 ----a-w- C:\WINDOWS\SysWOW64\msfeeds.dll 2016-01-29 01:27:49 8A26A15B852AF385469AD62865CCAE7F 2050048 ----a-w- C:\WINDOWS\SysWOW64\inetcpl.cpl 2016-01-29 01:27:49 4A49EC3B4063CC569134D2BA64FA5022 350720 ----a-w- C:\WINDOWS\SysWOW64\CredProvDataModel.dll 2016-01-29 01:27:49 3F8B09A6D234877025A5EBECF9151F58 162816 ----a-w- C:\WINDOWS\SysWOW64\MTF.dll 2016-01-29 01:27:48 B44BC5CC78CF476028D1939A7712BD93 652312 ----a-w- C:\WINDOWS\SysWOW64\evr.dll 2016-01-29 01:27:48 7D81335F3FCD9C37DE3C8C9989428C99 431240 ----a-w- C:\WINDOWS\SysWOW64\WWanAPI.dll 2016-01-29 01:27:48 3A280280AEA583EAB0375C330F7A6CE9 335872 ----a-w- C:\WINDOWS\SysWOW64\iedkcs32.dll 2016-01-29 01:27:47 FAA5A3DE34FD44C220691C4527E88453 157696 ----a-w- C:\WINDOWS\SysWOW64\SimCfg.dll 2016-01-29 01:27:47 B3A8463C47E0E7007382A12176ACBD46 200704 ----a-w- C:\WINDOWS\SysWOW64\DisplayManager.dll 2016-01-29 01:27:47 559358D3C39A1EC0D944714C32FAD582 799744 ----a-w- C:\WINDOWS\SysWOW64\rasdlg.dll 2016-01-29 01:27:47 1C1DC38D8D6E075DE06ED174B9E81FE9 535040 ----a-w- C:\WINDOWS\SysWOW64\rastls.dll 2016-01-29 01:27:45 8880848DC5DEE8BF8FE34DBC57C5655C 129024 ----a-w- C:\WINDOWS\SysWOW64\SimAuth.dll 2016-01-29 01:27:43 A589CD44BDB433F727EE84792FCCF0C0 87040 ----a-w- C:\WINDOWS\SysWOW64\MapsBtSvc.dll 2016-01-29 01:27:43 9797BB52F1943B78CD245B41AE833E1F 653312 ----a-w- C:\WINDOWS\SysWOW64\rasapi32.dll 2016-01-29 01:27:42 A60B02C7D70EEBF8E362BA5C06339177 366224 ----a-w- C:\WINDOWS\SysWOW64\AUDIOKSE.dll 2016-01-29 01:27:40 DBE39E4BDCC3D8F49A2B0277652120D0 41984 ----a-w- C:\WINDOWS\SysWOW64\pcaui.exe 2016-01-29 01:27:38 CF17C8CA575EC10ACDE1671CDED01B73 17408 ----a-w- C:\WINDOWS\SysWOW64\rasautou.exe 2016-01-29 01:27:38 650A2E42A8965FEEF24105EF3D19780B 510976 ----a-w- C:\WINDOWS\SysWOW64\wlidcli.dll 2016-01-29 01:27:38 5A414B58FE411CC4F3F84CE0ABDB68F3 133632 ----a-w- C:\WINDOWS\SysWOW64\Windows.UI.Core.TextInput.dll 2016-01-29 01:27:38 4A2AD2C3B186FFE8EFE4DC7AB492F73E 79360 ----a-w- C:\WINDOWS\SysWOW64\winhttpcom.dll 2016-01-29 01:27:37 B7B67257F01B0B814066F245DAD34367 93696 ----a-w- C:\WINDOWS\SysWOW64\winbio.dll 2016-01-29 01:27:37 96D60277EF8CB48BD3D920298C9D7F83 11776 ----a-w- C:\WINDOWS\SysWOW64\rastlsext.dll 2016-01-29 01:27:37 27C3814755F5078A06B3B95CC6BAD111 13312 ----a-w- C:\WINDOWS\SysWOW64\rasadhlp.dll 2016-01-27 11:58:17 BD6CF5354EAE95D6C2807E6DAE79D3FF 111016 ----a-w- C:\WINDOWS\SysWOW64\WindowsAccessBridge-64.dll 2016-01-27 11:58:17 9BE834EEA24E39F5ED5069A560F41A40 97888 ----a-w- C:\WINDOWS\SysWOW64\WindowsAccessBridge-32.dll ====== C:\WINDOWS\SysWOW64\drivers ===== ====== C:\WINDOWS\Sysnative ===== 2016-01-29 01:28:19 E74825BF1F94A7B360FBF5CBE1FE7517 8728920 ----a-w- C:\WINDOWS\Sysnative\Windows.Media.Protection.PlayReady.dll 2016-01-29 01:28:18 70FC5A0F409D67604BA3B77E58876F47 22394368 ----a-w- C:\WINDOWS\Sysnative\edgehtml.dll 2016-01-29 01:28:15 2B5C192D5E93E7001B6926CCD111C6CB 24602624 ----a-w- C:\WINDOWS\Sysnative\mshtml.dll 2016-01-29 01:28:11 4F0263646FF401695E0C14FE81D3E6A5 16986112 ----a-w- C:\WINDOWS\Sysnative\Windows.UI.Xaml.dll 2016-01-29 01:28:10 595E6DA6C8E15CD9FE625306F9B7E482 6600904 ----a-w- C:\WINDOWS\Sysnative\windows.storage.dll 2016-01-29 01:28:09 ECD20531C75F820FA1B8EC8A975C65AC 11545088 ----a-w- C:\WINDOWS\Sysnative\twinui.dll 2016-01-29 01:28:09 A28210DEA1085BC5B7A5D90A10C2FD8B 13382656 ----a-w- C:\WINDOWS\Sysnative\ieframe.dll 2016-01-29 01:28:05 C8B7EB447B14D73E851C22AEB7A48000 22572624 ----a-w- C:\WINDOWS\Sysnative\shell32.dll 2016-01-29 01:28:04 186B00E5849DA43B2CEF58252105F3CE 5503488 ----a-w- C:\WINDOWS\Sysnative\d2d1.dll 2016-01-29 01:28:03 3FDFB93023689FBA65741B9D92C2D75A 7979008 ----a-w- C:\WINDOWS\Sysnative\mos.dll 2016-01-29 01:27:58 AB55C7400D8B5B79E299EA54BB3514A4 1946624 ----a-w- C:\WINDOWS\Sysnative\dwmcore.dll 2016-01-29 01:27:58 2D6128490CEBAC2499DA97B992E919DC 1053696 ----a-w- C:\WINDOWS\Sysnative\audiosrv.dll 2016-01-29 01:27:58 0B5BE1B40B2F4FA7B85752CA93819681 2624512 ----a-w- C:\WINDOWS\Sysnative\InputService.dll 2016-01-29 01:27:57 80AD89A1EF678960E13D977EF8C047A9 1750440 ----a-w- C:\WINDOWS\Sysnative\WpcMon.exe 2016-01-29 01:27:56 F202F182FF6046869E2995DF333C5B2A 7199232 ----a-w- C:\WINDOWS\Sysnative\BingMaps.dll 2016-01-29 01:27:55 FFD04E8263FC9CDB89BAD8C27C337223 794112 ----a-w- C:\WINDOWS\Sysnative\winhttp.dll 2016-01-29 01:27:55 E48BBF1363F843E030757EC190DD33E6 2057216 ----a-w- C:\WINDOWS\Sysnative\wlidsvc.dll 2016-01-29 01:27:55 BA4DB0DDCF88E0D609E085130773A034 2597888 ----a-w- C:\WINDOWS\Sysnative\NetworkMobileSettings.dll 2016-01-29 01:27:54 6BB898FE9AE437C3D9D1F4920B92B1C3 1500672 ----a-w- C:\WINDOWS\Sysnative\RecoveryDrive.exe 2016-01-29 01:27:53 FFE45E6684CD1628AC6ED60E3717ACA8 536256 ----a-w- C:\WINDOWS\Sysnative\AudioSes.dll 2016-01-29 01:27:53 F232BE986A85BA857E7C5FDBEFC71653 1415200 ----a-w- C:\WINDOWS\Sysnative\msctf.dll 2016-01-29 01:27:53 C42C500565DED5DEE31EF8A2A69F4DFF 1173344 ----a-w- C:\WINDOWS\Sysnative\aeinv.dll 2016-01-29 01:27:53 A1A4838C326E1C33AACAD537E84880D3 851456 ----a-w- C:\WINDOWS\Sysnative\MapsStore.dll 2016-01-29 01:27:51 BDAC897CF7F20BE4E858CC44A99D8A3C 848160 ----a-w- C:\WINDOWS\Sysnative\mfsvr.dll 2016-01-29 01:27:51 844EB2280A13842B9919DCD0113F5487 343552 ----a-w- C:\WINDOWS\Sysnative\SensorsApi.dll 2016-01-29 01:27:51 537DD2C51094543CE389A48341F2E00B 1318912 ----a-w- C:\WINDOWS\Sysnative\wifinetworkmanager.dll 2016-01-29 01:27:51 30A512F0E1F1F58938758CD33D69680E 590848 ----a-w- C:\WINDOWS\Sysnative\SmsRouterSvc.dll 2016-01-29 01:27:51 0307E9C189E8FD376109265BAD5E3475 784384 ----a-w- C:\WINDOWS\Sysnative\msfeeds.dll 2016-01-29 01:27:50 9C17CF2D05F8DA5AC66880B6BEE64E7D 190464 ----a-w- C:\WINDOWS\Sysnative\wscsvc.dll 2016-01-29 01:27:50 72534830694CCABA9A5CBA33F9771C63 260608 ----a-w- C:\WINDOWS\Sysnative\MTFServer.dll 2016-01-29 01:27:50 3A0DBC71CBA845AB06A68DBAA1C66CA7 369912 ----a-w- C:\WINDOWS\Sysnative\audiodg.exe 2016-01-29 01:27:50 2EC83C9326B6731398674C0C0CB1636F 1674240 ----a-w- C:\WINDOWS\Sysnative\quartz.dll 2016-01-29 01:27:50 285D92DAC2C93818615C70A5719DD1F8 440320 ----a-w- C:\WINDOWS\Sysnative\CredProvDataModel.dll 2016-01-29 01:27:49 642EFABF900374FA85639D83B5533AFD 621568 ----a-w- C:\WINDOWS\Sysnative\wbiosrvc.dll 2016-01-29 01:27:49 140201A765860592F320B6AD6AA35155 235008 ----a-w- C:\WINDOWS\Sysnative\MTF.dll 2016-01-29 01:27:48 BF53DA0A9C4BC6A0D8DCF529154DBF74 538632 ----a-w- C:\WINDOWS\Sysnative\WWanAPI.dll 2016-01-29 01:27:48 777F439F1E5989777805647F1684529D 2127360 ----a-w- C:\WINDOWS\Sysnative\inetcpl.cpl 2016-01-29 01:27:47 FEF120F66B71871C35DDC154C43EAD86 617984 ----a-w- C:\WINDOWS\Sysnative\StorSvc.dll 2016-01-29 01:27:47 8E3B324D6479A63B6F23D663307D53A1 477696 ----a-w- C:\WINDOWS\Sysnative\srcore.dll 2016-01-29 01:27:46 A84812FE1FC4EAE9BBD816A2AEE4830D 383488 ----a-w- C:\WINDOWS\Sysnative\iedkcs32.dll 2016-01-29 01:27:46 6FF8248F3A9D69A095C7F3F42BC29CB2 440152 ----a-w- C:\WINDOWS\Sysnative\services.exe 2016-01-29 01:27:46 467F2BD2CC73E322839B3AED763BA2DC 193024 ----a-w- C:\WINDOWS\Sysnative\SimCfg.dll 2016-01-29 01:27:46 446E107CFCFECA7EF4A79414E882D8C8 574976 ----a-w- C:\WINDOWS\Sysnative\Windows.Networking.UX.EapRequestHandler.dll 2016-01-29 01:27:45 85EB31A46D618AC52726253A32539082 221696 ----a-w- C:\WINDOWS\Sysnative\ie4uinit.exe 2016-01-29 01:27:45 7E1AE9B225DEA8A142BAE7AFFC2A78F5 160768 ----a-w- C:\WINDOWS\Sysnative\SimAuth.dll 2016-01-29 01:27:45 79F73D66F612FE53C8E5E607FCDCFAB1 884736 ----a-w- C:\WINDOWS\Sysnative\rasdlg.dll 2016-01-29 01:27:45 50FED971D0FAD2B990C0A05735761D62 733184 ----a-w- C:\WINDOWS\Sysnative\rasapi32.dll 2016-01-29 01:27:45 158D628D1073D42429CB25A6F47DAE17 275456 ----a-w- C:\WINDOWS\Sysnative\AudioEndpointBuilder.dll 2016-01-29 01:27:44 F2E3456FD405F9BEACA0B8CF2BBDF0DE 202472 ----a-w- C:\WINDOWS\Sysnative\wscapi.dll 2016-01-29 01:27:44 B3354E631DE8174E0C38EBEB024980CA 638464 ----a-w- C:\WINDOWS\Sysnative\enterprisecsps.dll 2016-01-29 01:27:44 4776D4D2D41F99CF9938A410E38FAFE3 73728 ----a-w- C:\WINDOWS\Sysnative\SMSRouter.dll 2016-01-29 01:27:43 D754BB9E00B5D305617461E9C3CB6057 120320 ----a-w- C:\WINDOWS\Sysnative\MapsBtSvc.dll 2016-01-29 01:27:43 AFFD518026BA3F904589961003B65BB2 408120 ----a-w- C:\WINDOWS\Sysnative\AUDIOKSE.dll 2016-01-29 01:27:43 6B058785608DAB0D191575E12A45201D 406528 ----a-w- C:\WINDOWS\Sysnative\MusUpdateHandlers.dll 2016-01-29 01:27:43 4BCE40BC42A874A57B0E1B3E0FED0ABA 475648 ----a-w- C:\WINDOWS\Sysnative\DDDS.dll 2016-01-29 01:27:43 32276D1150EB30B798BE24EB0946A9B3 457728 ----a-w- C:\WINDOWS\Sysnative\ipnathlp.dll 2016-01-29 01:27:42 D229D73154CD66884BEAD67393ABE5C7 726528 ----a-w- C:\WINDOWS\Sysnative\wlidcli.dll 2016-01-29 01:27:42 4BB6D13AB95409AB66C8D1F1D847D4A1 274944 ----a-w- C:\WINDOWS\Sysnative\DisplayManager.dll 2016-01-29 01:27:41 F93E9FA2A54843D6EC529E4754F12946 166400 ----a-w- C:\WINDOWS\Sysnative\MusNotification.exe 2016-01-29 01:27:41 CC1005B7209B407EAB23ABDDC2DAD926 3593216 ----a-w- C:\WINDOWS\Sysnative\win32kfull.sys 2016-01-29 01:27:41 5058E240BBD22D66CE29D9C3279C8A91 610816 ----a-w- C:\WINDOWS\Sysnative\rastls.dll 2016-01-29 01:27:41 44AEBB28BE7A26F5A4068337208B183B 713568 ----a-w- C:\WINDOWS\Sysnative\invagent.dll 2016-01-29 01:27:41 3FAD094B789D7D8C130D474A8FD479D6 785088 ----a-w- C:\WINDOWS\Sysnative\evr.dll 2016-01-29 01:27:40 F0BA42C8EB6ADB733E35D2EC7714408F 49152 ----a-w- C:\WINDOWS\Sysnative\pcaui.exe 2016-01-29 01:27:40 54C5C6E962A873A1D05394DFF553FD18 149504 ----a-w- C:\WINDOWS\Sysnative\FilterDS.dll 2016-01-29 01:27:40 18DF88220B196D0D45644BC2730D6757 55296 ----a-w- C:\WINDOWS\Sysnative\MusNotificationUx.exe 2016-01-29 01:27:40 0EF46CAA4154B54F75E6A52D4B47CFF6 513888 ----a-w- C:\WINDOWS\Sysnative\devinv.dll 2016-01-29 01:27:39 9CEBBE3FB11718F2B2B2086102711C2E 19456 ----a-w- C:\WINDOWS\Sysnative\rasautou.exe 2016-01-29 01:27:39 4A8EBDA840908BE9E41E845BA71A3BA9 175616 ----a-w- C:\WINDOWS\Sysnative\Windows.UI.Core.TextInput.dll 2016-01-29 01:27:38 52B49D01CE8F8EEC3D557D2CCD46548B 17408 ----a-w- C:\WINDOWS\Sysnative\rasadhlp.dll 2016-01-29 01:27:38 4F83D9D2478E3421BFA7B7F13FAD614B 130560 ----a-w- C:\WINDOWS\Sysnative\winbio.dll 2016-01-29 01:27:38 266B9C1CC212C255ED61CB13CE3A98A4 13824 ----a-w- C:\WINDOWS\Sysnative\sscoreext.dll 2016-01-29 01:27:37 F6D1F548315E07F98B6294940CCBE7FB 97280 ----a-w- C:\WINDOWS\Sysnative\winhttpcom.dll 2016-01-29 01:27:37 D60BA4C76D194472D6602FF3D2D51ADE 106496 ----a-w- C:\WINDOWS\Sysnative\rasauto.dll 2016-01-29 01:27:37 4E94E9C26B5CBA895D3F562A3F2F2017 1087488 ----a-w- C:\WINDOWS\Sysnative\reseteng.dll 2016-01-29 01:27:37 096671DD1AA23C708FC4493C41D5DB82 13824 ----a-w- C:\WINDOWS\Sysnative\rastlsext.dll 2016-01-21 22:50:37 4E73C2132E02EDC226518F2B9FFB1528 285248 ----a-w- C:\WINDOWS\Sysnative\FNTCACHE.DAT ====== C:\WINDOWS\Sysnative\drivers ===== 2016-01-29 01:27:56 DEE20E660C079BDAB5B7533826F99FA8 1998168 ----a-w- C:\WINDOWS\Sysnative\drivers\dxgkrnl.sys 2016-01-29 01:27:49 318E816717431D3C23DC82779900C744 1089880 ----a-w- C:\WINDOWS\Sysnative\drivers\http.sys 2016-01-29 01:27:47 38D6C7E380DB8EE2B3560A678EE85253 576864 ----a-w- C:\WINDOWS\Sysnative\drivers\dxgmms2.sys 2016-01-29 01:27:39 F259A45D6B555B14CC8365AA6BC8DC20 67072 ----a-w- C:\WINDOWS\Sysnative\drivers\usbser.sys ====== C:\WINDOWS\Tasks ====== 2016-01-26 12:08:38 F219DCA92C8D19BCD18BE5D457364D01 4170 ----a-w- C:\WINDOWS\Sysnative\Tasks\User_Feed_Synchronization-{85F87B36-B11F-45CC-AE88-BADB65EACF7A} ====== C:\WINDOWS\Temp ====== ======= C:\Program Files ===== ======= C:\PROGRA~2 ===== 2016-01-31 08:12:40 -------- d-----w- C:\PROGRA~2\ESET 2016-01-27 11:58:39 -------- d-----w- C:\PROGRA~2\COMMON~1\Java 2016-01-27 11:58:01 -------- d-----w- C:\PROGRA~2\Java ======= C: ===== ====== C:\Users\Pablo\AppData\Roaming ====== 2016-01-27 07:14:40 -------- d-----w- C:\Users\Pablo\AppData\Local\Temp ====== C:\Users\Pablo ====== 2016-02-01 15:50:38 2B9D3839F20C6F7B4ECAFDD49B98374E 25239 ----a-w- C:\ProgramData\1454341834.bdinstall.bin 2016-01-31 08:12:17 C5B68AC8EC40CAB217AB4F479B953B54 2870984 ----a-w- C:\Users\Pablo\Desktop\esetsmartinstaller_enu.exe 2016-01-28 20:03:06 4BDBDE3390E33154D8FF7DAE8BD5F034 19279 ----a-w- C:\ProgramData\1454011376.bdinstall.bin 2016-01-28 18:55:58 9D2EBC3941907EAF6D80C97111732F3C 19276 ----a-w- C:\ProgramData\1454007353.bdinstall.bin 2016-01-28 18:54:16 BDA0865153BF9FE2FC7A6AB0B6B63439 25239 ----a-w- C:\ProgramData\1454007253.bdinstall.bin 2016-01-28 18:53:53 B742367B474688828E57897385547814 25238 ----a-w- C:\ProgramData\1454007231.bdinstall.bin 2016-01-28 18:53:40 02980650E78F75F2AD7F4E0FCF8D9B2A 25238 ----a-w- C:\ProgramData\1454007217.bdinstall.bin 2016-01-27 21:27:29 F69FDB12057B593DC51157590E7BF56D 25239 ----a-w- C:\ProgramData\1453930046.bdinstall.bin 2016-01-27 20:59:39 AE8559E8EAAE10654C78141FDA146304 25239 ----a-w- C:\ProgramData\1453928376.bdinstall.bin 2016-01-27 20:55:07 F97E4D89B0855DD128335CFB42D0B19D 25238 ----a-w- C:\ProgramData\1453928104.bdinstall.bin 2016-01-27 20:52:54 8AAC88C3FC179084E6F6572D0FD011EA 25240 ----a-w- C:\ProgramData\1453927972.bdinstall.bin 2016-01-27 20:52:34 77D5A3659F5C7156F9B54AD46F4F9E68 25239 ----a-w- C:\ProgramData\1453927951.bdinstall.bin 2016-01-27 20:51:41 1B3A51828B90A7613CF9ACAD1DA5430E 25167 ----a-w- C:\ProgramData\1453927898.bdinstall.bin 2016-01-27 20:51:03 BC68F2D2FC033A61F38D79900C3C4293 9736920 ----a-w- C:\Users\Pablo\Desktop\bitdefender_windows_364b1bd1-1921-4f45-94e9-63b85fa0a50f.exe 2016-01-27 20:46:45 D495F354000E891412E5674EC6AA9857 25190 ----a-w- C:\ProgramData\1453927602.bdinstall.bin 2016-01-27 20:46:31 8696433C509D9DBF0D799C5B2F524014 26280 ----a-w- C:\ProgramData\1453927588.bdinstall.bin 2016-01-27 20:38:34 3D189A519F39AB0CDAFCACAB527C42DE 1507840 ----a-w- C:\Users\Pablo\Desktop\adwcleaner_5.031.exe 2016-01-27 11:58:20 -------- d-----w- C:\Users\Pablo\.oracle_jre_usage 2016-01-27 11:56:14 F23B0C3F53AD995DA7E7F555458543A0 643168 ----a-w- C:\Users\Pablo\Downloads\JavaSetup8u71.exe 2016-01-26 12:12:00 8045ABB21A3BDD66A48E1ED5C0F0EF6A 1222144 ----a-w- C:\Users\Pablo\Downloads\RSITx64.exe 2016-01-25 22:40:14 -------- d-----w- C:\ProgramData\GridinSoft 2016-01-25 22:38:52 C9F9C9373A9F16167BFC84975E1C1D3F 1214416 ----a-w- C:\Users\Pablo\Downloads\gsam-setup-hip.exe ====== C: exe-files == 2016-01-31 11:25:04 E6789E0217C49172E6ACC9B37D14CA29 146888 ----a-w- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice_tmp.exe 2016-01-31 08:12:48 F0B5FAE0268D84B1CE6EA3B98D4D69EB 331464 ----a-w- C:\Program Files (x86)\ESET\ESET Online Scanner\OnlineCmdLineScannerA.exe 2016-01-31 08:12:48 B23901621E5BD2EF1AAC3E6E6CB9E7FF 422600 ----a-w- C:\Program Files (x86)\ESET\ESET Online Scanner\OnlineCmdLineScanner.exe 2016-01-31 08:12:48 4B0F506ACF0A8AE6D6B3E4CF6778B722 122568 ----a-w- C:\Program Files (x86)\ESET\ESET Online Scanner\OnlineScannerUninstaller.exe 2016-01-31 08:12:48 21B9AB1916917F9476B767F605345E62 532168 ----a-w- C:\Program Files (x86)\ESET\ESET Online Scanner\OnlineScannerApp.exe 2016-01-31 08:12:47 E78517BD20C282FBCA150D2B3ACCC760 2870984 ----a-w- C:\Program Files (x86)\ESET\ESET Online Scanner\ESETSmartInstaller.exe 2016-01-31 08:12:17 C5B68AC8EC40CAB217AB4F479B953B54 2870984 ----a-w- C:\Users\Pablo\Desktop\esetsmartinstaller_enu.exe 2016-01-29 01:28:14 687B32B5B2A5DEFB85EA0583BA717DBE 7300464 ----a-w- C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe 2016-01-29 01:27:57 80AD89A1EF678960E13D977EF8C047A9 1750440 ----a-w- C:\Windows\System32\WpcMon.exe 2016-01-29 01:27:54 6BB898FE9AE437C3D9D1F4920B92B1C3 1500672 ----a-w- C:\Windows\System32\RecoveryDrive.exe 2016-01-29 01:27:50 3A0DBC71CBA845AB06A68DBAA1C66CA7 369912 ----a-w- C:\Windows\System32\audiodg.exe 2016-01-29 01:27:46 6FF8248F3A9D69A095C7F3F42BC29CB2 440152 ----a-w- C:\Windows\System32\services.exe 2016-01-29 01:27:45 85EB31A46D618AC52726253A32539082 221696 ----a-w- C:\Windows\System32\ie4uinit.exe 2016-01-29 01:27:42 3EE26A3CAC87E359F09E8F904741B79C 602624 ----a-w- C:\Windows\System32\IME\IMEJP\IMJPDCT.EXE 2016-01-29 01:27:42 22725026F4DA5E8B132235CE9D70DAFB 343040 ----a-w- C:\Windows\System32\IME\SHARED\ImeBroker.exe 2016-01-29 01:27:41 F93E9FA2A54843D6EC529E4754F12946 166400 ----a-w- C:\Windows\System32\MusNotification.exe 2016-01-29 01:27:40 F0BA42C8EB6ADB733E35D2EC7714408F 49152 ----a-w- C:\Windows\System32\pcaui.exe 2016-01-29 01:27:40 DBE39E4BDCC3D8F49A2B0277652120D0 41984 ----a-w- C:\Windows\SysWOW64\pcaui.exe 2016-01-29 01:27:40 18DF88220B196D0D45644BC2730D6757 55296 ----a-w- C:\Windows\System32\MusNotificationUx.exe 2016-01-29 01:27:39 9CEBBE3FB11718F2B2B2086102711C2E 19456 ----a-w- C:\Windows\System32\rasautou.exe 2016-01-29 01:27:39 69F62BD8BA07B6A9FFA5827361D88D12 138240 ----a-w- C:\Windows\System32\oobe\windeploy.exe 2016-01-29 01:27:39 5BD26C1FD29FE0A3A42141CCAF21D5B3 491520 ----a-w- C:\Windows\SysWOW64\IME\IMEJP\IMJPDCT.EXE 2016-01-29 01:27:38 CF17C8CA575EC10ACDE1671CDED01B73 17408 ----a-w- C:\Windows\SysWOW64\rasautou.exe 2016-01-27 20:51:03 BC68F2D2FC033A61F38D79900C3C4293 9736920 ----a-w- C:\Users\Pablo\Desktop\bitdefender_windows_364b1bd1-1921-4f45-94e9-63b85fa0a50f.exe 2016-01-27 20:38:34 3D189A519F39AB0CDAFCACAB527C42DE 1507840 ----a-w- C:\Users\Pablo\Desktop\adwcleaner_5.031.exe 2016-01-27 20:37:54 3EBF8F483097B07B85CD934886B12083 108 ----a-w- C:\$RECYCLE.BIN\S-1-5-21-245886207-1146603730-494075168-1000\$IYU783Z.exe 2016-01-27 11:58:11 F64E8F84D184DB9E1DAA06C468A96564 50784 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_71\bin\ssvagent.exe 2016-01-27 11:58:11 DFF3A99FE7DF7896A952B758A534364D 15968 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_71\bin\rmiregistry.exe 2016-01-27 11:58:11 D2702A2D5C98EB6E2524251099856954 15968 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_71\bin\servertool.exe 2016-01-27 11:58:11 B562AA86D55096C033BD0CE39BAEE6E7 16480 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_71\bin\tnameserv.exe 2016-01-27 11:58:11 A12B125D9D3CF87944E7E7A1BA0ED2A3 15968 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_71\bin\policytool.exe 2016-01-27 11:58:11 8F6A3DF8AEC9E79BF83472783C3EE86F 15968 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_71\bin\rmid.exe 2016-01-27 11:58:11 7E18299A2B425FB60E47E11DF13CD43E 159328 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_71\bin\unpack200.exe 2016-01-27 11:58:11 72A41AFF0F7041FEA03914E157C2E22E 15968 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_71\bin\pack200.exe 2016-01-27 11:58:11 4A94B0D6D2322581E0D8C6749AA5EA35 16480 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_71\bin\orbd.exe 2016-01-27 11:58:10 F9B4CC285D23A3CC144C5E2EB89413A9 68192 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_71\bin\javacpl.exe 2016-01-27 11:58:10 E1CCCE3EF4323A08240442EE6D8F9F23 76896 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_71\bin\jp2launcher.exe 2016-01-27 11:58:10 C1A4EED6CE27B89E3CF63839DDE14D98 278624 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_71\bin\javaws.exe 2016-01-27 11:58:10 6F93569D77CB789727C4E0F33F934741 15968 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_71\bin\jjs.exe 2016-01-27 11:58:10 5684DB15C4FDDD66CB41A238586C229E 15968 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_71\bin\klist.exe 2016-01-27 11:58:10 51FDBC4B82654F534D8AF5F39AE249DD 15968 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_71\bin\keytool.exe 2016-01-27 11:58:10 3C30DF6FF0EEA713F1F4D251696B93A7 191584 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_71\bin\javaw.exe 2016-01-27 11:58:10 3B25D8E78E7DC350FF489E814C8302FE 15968 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_71\bin\kinit.exe 2016-01-27 11:58:10 041F2531B37C13CE5211B860DF5EFC64 15968 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_71\bin\ktab.exe 2016-01-27 11:58:09 D317A632CFEE0ED03AAAF884B503421A 15968 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_71\bin\java-rmi.exe 2016-01-27 11:58:09 7F39A458F3F444973AF0EEE1035D533A 30816 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_71\bin\jabswitch.exe 2016-01-27 11:58:09 099E74EDE92C0B07E85AF3EE6A0C1248 191072 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_71\bin\java.exe 2016-01-27 11:56:14 F23B0C3F53AD995DA7E7F555458543A0 643168 ----a-w- C:\Users\Pablo\Downloads\JavaSetup8u71.exe === C: other files == 2016-01-31 08:14:00 560EDC0912BDB68290930E2542823A24 135760 ----a-w- C:\Users\Pablo\AppData\Local\Temp\ehdrv.sys 2016-01-29 01:27:56 DEE20E660C079BDAB5B7533826F99FA8 1998168 ----a-w- C:\Windows\System32\drivers\dxgkrnl.sys 2016-01-29 01:27:49 318E816717431D3C23DC82779900C744 1089880 ----a-w- C:\Windows\System32\drivers\http.sys 2016-01-29 01:27:47 38D6C7E380DB8EE2B3560A678EE85253 576864 ----a-w- C:\Windows\System32\drivers\dxgmms2.sys 2016-01-29 01:27:41 CC1005B7209B407EAB23ABDDC2DAD926 3593216 ----a-w- C:\Windows\System32\win32kfull.sys 2016-01-29 01:27:39 F259A45D6B555B14CC8365AA6BC8DC20 67072 ----a-w- C:\Windows\System32\drivers\usbser.sys 2016-01-27 11:58:11 61351FF4B83204E6477FBBCB7107B919 14130 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_71\lib\deploy\ffjcext.zip ==== Startup Registry Enabled ====================== [HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "OneDriveSetup"="C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup" [HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "OneDriveSetup"="C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup" [HKEY_USERS\S-1-5-21-245886207-1146603730-494075168-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "DAEMON Tools Lite"="C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe -autorun" "OneDrive"="C:\Users\Pablo\AppData\Local\Microsoft\OneDrive\OneDrive.exe /background" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ANIWZCS2Service"="C:\Program Files (x86)\ANI\ANIWZCS2 Service\WZCSLDR2.exe" "D-Link D-Link Wireless G DWL-G122_DWA-110"="C:\Program Files (x86)\D-Link\DWL-G122_DWA-110\AirGCFG.exe" "CanonSolutionMenuEx"="C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE /logon" "SunJavaUpdateSched"="C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "DAEMON Tools Lite"="C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe -autorun" "OneDrive"="C:\Users\Pablo\AppData\Local\Microsoft\OneDrive\OneDrive.exe /background" ==== Startup Registry Enabled x64 ====================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "CanonMyPrinter"="C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon" ==== Task Scheduler Jobs ====================== C:\WINDOWS\tasks\Adobe Flash Player Updater.job --a-------- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [20-01-2016 21:59] C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job --a-------- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [31-08-2015 05:11] C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job --a-------- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [31-08-2015 05:11] ==== Other Scheduled Tasks ====================== "C:\WINDOWS\SysNative\tasks\Adobe Acrobat Update Task" [C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe] "C:\WINDOWS\SysNative\tasks\Adobe Flash Player Updater" [C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe] "C:\WINDOWS\SysNative\tasks\Bitdefender Agent WatchDog_65D6944A0EF74FDAB96E31112AD39864" [C:\Program Files\Bitdefender Agent\WatchDog.exe] "C:\WINDOWS\SysNative\tasks\Bitdefender Update Product Data_A17FD818A96743FAB28AC221BEB4B2C8" [C:\Program Files\Bitdefender\Bitdefender 2015\bdproductdata.exe] "C:\WINDOWS\SysNative\tasks\CCleanerSkipUAC" ["C:\Program Files\CCleaner\CCleaner.exe"] "C:\WINDOWS\SysNative\tasks\CreateChoiceProcessTask" [C:\Windows\System32\browserchoice.exe] "C:\WINDOWS\SysNative\tasks\GoogleUpdateTaskMachineCore" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe] "C:\WINDOWS\SysNative\tasks\GoogleUpdateTaskMachineUA" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe] "C:\WINDOWS\SysNative\tasks\GridinSoft Anti-Malware" ["C:\Program Files\GridinSoft Anti-Malware\gsam.exe"] "C:\WINDOWS\SysNative\tasks\User_Feed_Synchronization-{85F87B36-B11F-45CC-AE88-BADB65EACF7A}" [C:\WINDOWS\system32\msfeedssync.exe] ==== Firefox Extensions ====================== AppDir: C:\Program Files (x86)\Mozilla Firefox - Undetermined - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}.xpi ==== Firefox Plugins ====================== Profilepath: C:\Users\Pablo\AppData\Roaming\Mozilla\Firefox\Profiles\naic4ewd.default A107920551356DAEE665F0884F34D2D7 - C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_20_0_0_286.dll - Shockwave Flash ==== Chromium Look ====================== HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions dhhejlifdlcgcmogbggeomfodgklfaem - No path found[] ==== Set IE to Default ====================== Old Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157" New Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157" ==== All HKLM and HKCU SearchScopes ====================== HKLM\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" HKLM\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC HKLM\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990} - http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7 HKLM\Wow6432Node\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" HKLM\Wow6432Node\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC HKLM\Wow6432Node\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990} - http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7 HKCU\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" HKCU\SearchScopes\{012E1000-F331-11DB-8314-0800200C9A66} - http://www.google.com/search?q={searchTerms} HKCU\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02 HKCU\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990} - http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7PRFD_nlBE611 ==== Empty IE Cache ====================== C:\WINDOWS\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Pablo\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\Users\Pablo\AppData\Local\Microsoft\Windows\INetCache\Low\Content.IE5 emptied successfully C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\WINDOWS\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\Users\Pablo\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully C:\Users\Pablo\AppData\Local\Microsoft\Windows\INetCache\Low\IE emptied successfully C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully ==== Empty FireFox Cache ====================== C:\Users\Pablo\AppData\Local\Mozilla\Firefox\Profiles\naic4ewd.default\cache2 emptied successfully ==== Empty Chrome Cache ====================== No Chrome User Data found ==== Empty All Flash Cache ====================== No Flash Cache Found ==== Empty All Java Cache ====================== Java Cache cleared successfully ==== C:\zoek_backup content ====================== C:\zoek_backup (files=151 folders=34 1891899 bytes) ==== Empty Temp Folders ====================== C:\WINDOWS\Temp will be emptied at reboot ==== After Reboot ====================== ==== Empty Temp Folders ====================== C:\WINDOWS\Temp successfully emptied C:\Users\Pablo\AppData\Local\Temp successfully emptied ==== Empty Recycle Bin ====================== C:\$RECYCLE.BIN successfully emptied ==== EOF on di 02-02-2016 at 19:39:20,18 ======================