hier ben ik dan hoop dat het het gelukt is.....
oek.exe v5.0.0.0 Updated 22-Januari-2014
Tool run by poli on do 23/01/2014 at 19:43:00,33.
Microsoft Windows 8.1 Pro 6.3.9600 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\UpdatusUser\Desktop\zoek.exe [Scan all users] [Script inserted]
==== System Restore Info ======================
23/01/2014 19:44:09 Zoek.exe System Restore Point Created Succesfully.
==== Empty Folders Check ======================
C:\Users\Administrator\AppData\Roaming\Lenovo deleted successfully
C:\Users\UpdatusUser\AppData\Local\cache deleted successfully
C:\Users\UpdatusUser\AppData\Local\PackageStaging deleted successfully
C:\Users\UpdatusUser\AppData\Local\VirtualStore deleted successfully
C:\WINDOWS\serviceprofiles\networkservice\AppData\Local\PeerDistPub deleted successfully
C:\WINDOWS\serviceprofiles\networkservice\AppData\Local\PeerDistRepub deleted successfully
==== Deleting CLSID Registry Keys ======================
==== Deleting CLSID Registry Values ======================
==== Deleting Services ======================
==== Deleting Files \ Folders ======================
C:\Users\UpdatusUser\daemonprocess.txt deleted
C:\Users\UpdatusUser\.android deleted
C:\ProgramData\Package Cache deleted
C:\Users\UpdatusUser\AppData\Roaming\Mozilla\Firefox\Profiles\kgzgum1q.default\pandasecuritytb deleted
C:\Users\UpdatusUser\AppData\Roaming\Mozilla\Firefox\Profiles\kgzgum1q.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4} deleted
==== Files Recently Created / Modified ======================
====== C:\WINDOWS ====
2013-12-27 10:54:44 63DC38C3E4564B2405D562855643ABA2 2328872 ----a-w- C:\WINDOWS\explorer.exe
2013-12-26 22:37:49 F48EFB824D2751DA8EF2A0D78BEB38E9 41913 ----a-w- C:\WINDOWS\diagwrn.xml
2013-12-26 22:37:49 F48EFB824D2751DA8EF2A0D78BEB38E9 41913 ----a-w- C:\WINDOWS\diagerr.xml
====== C:\Users\UPDATU~1\AppData\Local\Temp ====
2014-01-23 07:55:52 FDE7A79272ECC488D997D1111FE04EC1 12012912 ----a-w- C:\Users\UpdatusUser\AppData\Local\Temp\gusetup5.exe
2014-01-20 14:14:35 4C6C24FF4BB842D35B1A14C909D9D091 10588160 ----a-w- C:\Users\UpdatusUser\AppData\Local\Temp\SkypeToolbars.msi
2014-01-20 14:13:59 A3AEEC9A9B6984F2E22B90FDC9A23AB8 24993792 ----a-w- C:\Users\UpdatusUser\AppData\Local\Temp\Skype.msi
2014-01-14 15:13:17 F37882F128EFACEFE353E0BAE2766909 1039360 ------w- C:\Users\UpdatusUser\AppData\Local\Temp\7zS2E21\HPSLPSVC64.DLL
====== C:\WINDOWS\SysWOW64 =====
2014-01-15 08:17:22 ED8ED1CE6CAB56103230E2097763DC2B 695808 ----a-w- C:\WINDOWS\SysWOW64\WSShared.dll
2014-01-15 08:17:21 B6D28E8DC13F9EAF8B74BDB4F3DD9781 174592 ----a-w- C:\WINDOWS\SysWOW64\WSClient.dll
2014-01-15 08:17:20 73D0837E97CD7368BCA7DE4E373B8503 103936 ----a-w- C:\WINDOWS\SysWOW64\OEMLicense.dll
====== C:\WINDOWS\SysWOW64\drivers =====
====== C:\WINDOWS\Sysnative =====
2014-01-15 08:17:22 E3E168E733B0E8383BA5635542FDB96F 848384 ----a-w- C:\WINDOWS\Sysnative\WSShared.dll
2014-01-15 08:17:22 D8E3A4701376CCFD0BE542D745FA4809 3395920 ----a-w- C:\WINDOWS\Sysnative\WSService.dll
2014-01-15 08:17:21 3E245CCA42D78B9626A79FE77E111D7B 84480 ----a-w- C:\WINDOWS\Sysnative\WSCollect.exe
2014-01-15 08:17:21 30AE1D2A418A6C128CF3BD6EA37354DB 138240 ----a-w- C:\WINDOWS\Sysnative\OEMLicense.dll
2014-01-15 08:17:21 294AAE73D0D7BDAACC5224BC7334077B 206336 ----a-w- C:\WINDOWS\Sysnative\WSClient.dll
2014-01-15 08:17:16 EF5A9D7523E4530D2030D4EA2D90FEC3 787968 ----a-w- C:\WINDOWS\Sysnative\uDWM.dll
====== C:\WINDOWS\Sysnative\drivers =====
2014-01-20 15:34:42 D6C6BAE38CFEDCF3F7E046A5A72528FD 58808 ----a-w- C:\WINDOWS\Sysnative\drivers\PSKMAD.sys
2014-01-18 19:45:04 DA8A612152441DDA63DA9C1480731838 137960 ----a-w- C:\WINDOWS\Sysnative\drivers\PSINProt.sys
2014-01-18 19:45:04 D751845E6CAC4B564977B518DFF6DF23 169192 ----a-w- C:\WINDOWS\Sysnative\drivers\PSINAflt.sys
2014-01-18 19:44:59 229B64294C3AE7A9E6BF27D11085B193 206056 ----a-w- C:\WINDOWS\Sysnative\drivers\PSINKNC.sys
2014-01-14 13:04:56 D41D8CD98F00B204E9800998ECF8427E 0 ---ha-w- C:\WINDOWS\Sysnative\drivers\Msft_User_WpdMtpDr_01_11_00.Wdf
2014-01-13 19:08:38 C0BA352412C002730831E83E69285BB6 17088 ----a-w- C:\WINDOWS\Sysnative\drivers\BootDefragDriver.sys
2013-12-27 10:54:45 6617F44D2432C529B2249A0498B6B40A 2551640 ----a-w- C:\WINDOWS\Sysnative\drivers\tcpip.sys
2013-12-27 10:54:41 3D30878A269D934100FA5F972E53AF39 523096 -c--a-w- C:\WINDOWS\Sysnative\drivers\acpi.sys
2013-12-27 10:54:40 847C6A08912C3515807049C93E526D65 258904 ----a-w- C:\WINDOWS\Sysnative\drivers\rdyboost.sys
2013-12-27 10:54:40 6B06E2D11E604BE2B1A406C4CB3B90DE 57176 -c--a-w- C:\WINDOWS\Sysnative\drivers\stornvme.sys
2013-12-27 10:54:40 2B78788A1485F9B99A578A299DF42C02 454656 ----a-w- C:\WINDOWS\Sysnative\drivers\srv.sys
2013-12-27 10:53:59 2E3E82D7B1076B90F4E228A8EF17B261 136536 ----a-w- C:\WINDOWS\Sysnative\drivers\wfplwfs.sys
2013-12-27 10:53:20 A3D1CB64DF885ACE126543E6D7067348 1530200 ----a-w- C:\WINDOWS\Sysnative\drivers\dxgkrnl.sys
2013-12-27 10:53:20 9E167CDB2AEEF7994434543D0543AEEB 382808 ----a-w- C:\WINDOWS\Sysnative\drivers\dxgmms1.sys
2013-12-27 10:53:20 139CFCDCD36B1B1782FD8C0014AC9B0E 39768 -c--a-w- C:\WINDOWS\Sysnative\drivers\intelpep.sys
2013-12-27 10:53:19 F6EBE514D13ECE7EDC23440039CDF9AB 372568 -c--a-w- C:\WINDOWS\Sysnative\drivers\spaceport.sys
2013-12-27 10:53:16 B9D968D8E2B0F9C6301CEB39CFC9B9E4 86872 ----a-w- C:\WINDOWS\Sysnative\drivers\pdc.sys
2013-12-27 10:53:16 3B44CB989757428208CCFCC028C13110 325464 -c--a-w- C:\WINDOWS\Sysnative\drivers\USBXHCI.SYS
2013-12-27 10:53:16 0044B31F93946D5D41982314381FE431 146776 ----a-w- C:\WINDOWS\Sysnative\drivers\SerCx2.sys
2013-12-27 08:58:36 D41D8CD98F00B204E9800998ECF8427E 0 ---ha-w- C:\WINDOWS\Sysnative\drivers\Msft_User_LocationProvider_01_11_00.Wdf
2013-12-27 08:31:51 0BB97D43299910CBFBA59C461B99B910 25928 ----a-w- C:\WINDOWS\Sysnative\drivers\mbam.sys
2013-12-26 22:33:25 D41D8CD98F00B204E9800998ECF8427E 0 ---ha-w- C:\WINDOWS\Sysnative\drivers\Msft_Kernel_iBtFltCoex_01009.Wdf
2013-12-26 22:33:23 D41D8CD98F00B204E9800998ECF8427E 0 ---ha-w- C:\WINDOWS\Sysnative\drivers\Msft_Kernel_SynTP_01009.Wdf
2013-12-26 22:26:07 433ECDE01A52691FA7ACA51C10C09B70 155480 -c--a-w- C:\WINDOWS\Sysnative\drivers\usbccgp.sys
====== C:\WINDOWS\Tasks ======
2014-01-13 19:08:39 E6F647276073388AFB3F179BD67C2454 2962 ----a-w- C:\WINDOWS\Sysnative\Tasks\GU4SkipUAC
2014-01-02 10:17:40 80A5ABC1066FB8907D2C811896F0E099 414 ----a-w- C:\WINDOWS\Tasks\DriverEasy Scheduled Scan.job
2013-12-29 15:31:46 7A31C270D30C935A3243CFA8C443A76D 3938 ----a-w- C:\WINDOWS\Sysnative\Tasks\User_Feed_Synchronization-{3B8F2D14-6604-436E-9287-34F955B59A1B}
2013-12-27 14:23:36 F5ADE6D27D3484B76280EBD0468C9E79 940 ----a-w- C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2013-12-27 14:23:36 4C385BE378441F8B4CC1B6B504B7395F 3828 ----a-w- C:\WINDOWS\Sysnative\Tasks\Adobe Flash Player Updater
2013-12-27 11:46:33 5F7A703E20E8E7EE25B9B82AC0338F4E 2596 ----a-w- C:\WINDOWS\Sysnative\Tasks\GlaryInitialize 4
2013-12-27 11:46:33 3F14E1C9A0E8BF55B0AD95231D64996B 330 ----a-w- C:\WINDOWS\Tasks\GlaryInitialize 4.job
2013-12-27 11:44:10 96BF764C46F4637D11081E197C58EBC8 284 ----a-w- C:\WINDOWS\Tasks\AutoKMS.job
2013-12-27 11:44:10 26870B5CD50655E759217BFD12E74918 2894 ----a-w- C:\WINDOWS\Sysnative\Tasks\AutoKMS
2013-12-27 11:33:53 -------- d-----w- C:\WINDOWS\Sysnative\Tasks\OfficeSoftwareProtectionPlatform
2013-12-26 22:33:24 A55A6BDCC7217B462B7F399F035516BA 264 ----a-w- C:\WINDOWS\Tasks\Synaptics TouchPad Enhancements.job
2013-12-26 18:18:50 9F2C48B99812FB80007921639C4E75D4 3600 ----a-w- C:\WINDOWS\Sysnative\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3439249676-3253818225-4033233602-1001
2013-12-26 18:13:36 -------- d-----w- C:\WINDOWS\Sysnative\Tasks\WPD
2013-12-26 17:58:37 E3641454AF1F324FFCBD4251AE313156 2302 ----a-w- C:\WINDOWS\Sysnative\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3439249676-3253818225-4033233602-500
====== C:\WINDOWS\Temp ======
======= C:\Program Files =====
2014-01-23 15:42:37 -------- d-----w- C:\Program Files\trend micro
2014-01-20 15:05:39 -------- d-----w- C:\Program Files\Adblock Plus for IE
2014-01-02 10:15:30 -------- d-----w- C:\Program Files\Easeware
2013-12-29 09:39:24 -------- d-----w- C:\Program Files\SUPERAntiSpyware
2013-12-29 09:31:11 -------- d-----w- C:\Program Files\Speccy
2013-12-27 11:33:09 -------- d-----w- C:\Program Files\Common Files\DESIGNER
2013-12-27 11:32:26 -------- d-----w- C:\Program Files\Microsoft Synchronization Services
2013-12-27 11:31:52 -------- d-----w- C:\Program Files\Microsoft SQL Server Compact Edition
2013-12-27 11:29:00 -------- d-----w- C:\Program Files\Microsoft Analysis Services
2013-12-27 11:28:43 -------- d-----w- C:\Program Files\Microsoft Office
2013-12-27 11:03:14 -------- d-----w- C:\Program Files\Microsoft Silverlight
2013-12-27 08:30:59 -------- d-----w- C:\Program Files\WinRAR
2013-12-26 22:33:20 -------- d-----w- C:\Program Files\Synaptics
2013-12-26 22:32:50 -------- d-----w- C:\Program Files\Realtek
2013-12-26 22:32:06 -------- d-----w- C:\Program Files\NVIDIA Corporation
2013-12-26 22:26:52 -------- d-----w- C:\Program Files\Reference Assemblies
2013-12-26 22:26:52 -------- d-----w- C:\Program Files\MSBuild
======= C:\PROGRA~2 =====
2014-01-23 09:27:10 -------- d-----w- C:\PROGRA~2\FinalWire
2014-01-22 12:10:29 -------- d-----w- C:\PROGRA~2\COMMON~1\Adobe
2014-01-20 16:25:15 -------- d-----w- C:\PROGRA~2\COMMON~1\Skype
2014-01-20 16:25:15 -------- d-----r- C:\PROGRA~2\Skype
2014-01-18 12:55:53 -------- d-----w- C:\PROGRA~2\NirSoft
2014-01-07 00:40:44 -------- d-----w- C:\PROGRA~2\Hp
2014-01-02 12:33:25 -------- d-----w- C:\PROGRA~2\FreeTime
2013-12-29 09:53:40 -------- d-----w- C:\PROGRA~2\COMMON~1\Innovative Solutions
2013-12-28 14:18:55 -------- d-----w- C:\PROGRA~2\DVDFab 9
2013-12-27 12:35:46 -------- d-----w- C:\PROGRA~2\Winamax Poker
2013-12-27 11:46:26 -------- d-----w- C:\PROGRA~2\Glary Utilities 4
2013-12-27 11:30:03 -------- d-----w- C:\PROGRA~2\Microsoft Visual Studio 8
2013-12-27 11:29:00 -------- d-----w- C:\PROGRA~2\Microsoft Analysis Services
2013-12-27 11:28:46 -------- d-----w- C:\PROGRA~2\Microsoft Office
2013-12-27 11:03:14 -------- d-----w- C:\PROGRA~2\Microsoft Silverlight
2013-12-27 10:24:39 -------- d-----w- C:\PROGRA~2\GrabIt
2013-12-27 10:12:22 -------- d-----w- C:\PROGRA~2\QuickPar
2013-12-27 09:36:00 -------- d-----w- C:\PROGRA~2\Spotnet
2013-12-26 22:56:18 -------- d-----w- C:\PROGRA~2\COMMON~1\Intel
2013-12-26 22:32:07 -------- d-----w- C:\PROGRA~2\NVIDIA Corporation
2013-12-26 22:26:53 -------- d-----w- C:\PROGRA~2\Reference Assemblies
2013-12-26 22:26:53 -------- d-----w- C:\PROGRA~2\MSBuild
2013-12-26 18:17:17 -------- d-----w- C:\PROGRA~2\Mozilla Maintenance Service
======= C: =====
2013-12-26 17:29:52 D41D8CD98F00B204E9800998ECF8427E 0 ----a-w- C:\Recovery.txt
====== C:\Users\UpdatusUser\AppData\Roaming ======
2014-01-22 12:11:03 -------- d-----w- C:\Users\UpdatusUser\AppData\Locallow\Adobe
2014-01-20 15:05:40 -------- d-----w- C:\Users\UpdatusUser\AppData\Locallow\Adblock Plus for IE
2014-01-20 14:06:04 -------- d-s---w- C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Locallow\Microsoft
2014-01-18 19:45:44 -------- d-----w- C:\Users\UpdatusUser\AppData\Local\panda4_1dn
2014-01-18 16:18:24 -------- d-----w- C:\Users\UpdatusUser\AppData\Roaming\Audacity
2014-01-18 12:55:53 -------- d-----w- C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NirSoft Network Password Recovery
2014-01-14 15:20:50 -------- d-----w- C:\Users\UpdatusUser\AppData\Roaming\HP PSC 1210 Driver Utility
2014-01-14 14:57:04 -------- d-----w- C:\Users\UpdatusUser\AppData\Local\ElevatedDiagnostics
2014-01-09 13:12:26 -------- d-----w- C:\Users\UpdatusUser\AppData\Roaming\ImgBurn
2014-01-06 14:29:39 -------- d-----w- C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows 7 downloadprogramma voor USB DVD
2014-01-06 14:29:39 -------- d-----w- C:\Users\UpdatusUser\AppData\Local\Apps
2014-01-04 12:19:47 -------- d-----w- C:\Users\UpdatusUser\AppData\Local\ashampoo
2014-01-04 12:15:11 -------- d-----w- C:\Users\UpdatusUser\AppData\Roaming\Ashampoo
2014-01-02 12:33:36 -------- d-----w- C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FormatFactory
2014-01-02 10:17:40 -------- d-----w- C:\Users\UpdatusUser\AppData\Roaming\Easeware
2013-12-30 19:06:48 -------- d-----w- C:\Users\UpdatusUser\AppData\Local\MetaGeek,_LLC
2013-12-29 09:55:57 -------- d-----w- C:\Users\UpdatusUser\AppData\Local\Innovative Solutions
2013-12-29 09:54:39 -------- d-----w- C:\Users\UpdatusUser\AppData\Local\Diagnostics
2013-12-29 09:47:26 -------- d-----w- C:\Users\Default\AppData\Local\Microsoft Help
2013-12-29 09:47:26 -------- d-----w- C:\Users\Default User\AppData\Local\Microsoft Help
2013-12-29 09:39:29 -------- d-----w- C:\Users\UpdatusUser\AppData\Roaming\SUPERAntiSpyware.com
2013-12-29 09:36:39 -------- d-----w- C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Gadwin Systems
2013-12-28 14:19:29 -------- d-----w- C:\Users\UpdatusUser\AppData\Roaming\NVIDIA
2013-12-27 17:53:33 407AAB8C27CF7081EECE071C90A65B83 17 ----a-w- C:\Users\UpdatusUser\AppData\Local\resmon.resmoncfg
2013-12-27 14:10:25 -------- d-----w- C:\Users\UpdatusUser\AppData\Roaming\dvdcss
2013-12-27 12:35:48 -------- d-----w- C:\Users\UpdatusUser\AppData\Roaming\wam
2013-12-27 11:46:32 -------- d-----w- C:\Users\UpdatusUser\AppData\Roaming\GlarySoft
2013-12-27 11:42:14 -------- d-----w- C:\Users\UpdatusUser\AppData\Local\Intel_Corporation
2013-12-27 11:28:47 -------- d-----w- C:\Users\UpdatusUser\AppData\Local\Microsoft Help
2013-12-27 10:40:42 -------- d-----w- C:\Users\UpdatusUser\AppData\Roaming\ESET
2013-12-27 10:40:42 -------- d-----w- C:\Users\UpdatusUser\AppData\Local\ESET
2013-12-27 10:39:31 -------- d-----w- C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\ESET
2013-12-27 10:33:27 -------- d-----w- C:\Users\UpdatusUser\AppData\Local\QuickPar
2013-12-27 10:12:23 -------- d-----w- C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\QuickPar
2013-12-27 10:09:49 -------- d-----w- C:\Users\UpdatusUser\AppData\Roaming\GrabIt
2013-12-27 10:06:44 -------- d-----w- C:\Users\UpdatusUser\AppData\Roaming\cef-cache
2013-12-27 10:06:42 -------- d-----w- C:\Users\UpdatusUser\AppData\Roaming\bwinbe
2013-12-27 10:06:00 -------- d-----w- C:\Users\UpdatusUser\AppData\Local\P5
2013-12-27 10:04:44 -------- d-----w- C:\Users\UpdatusUser\AppData\Roaming\Microgaming
2013-12-27 09:40:56 -------- d-----w- C:\Users\UpdatusUser\AppData\Local\Spotnet
2013-12-27 09:24:15 -------- d-----w- C:\Users\UpdatusUser\AppData\Roaming\vlc
2013-12-27 09:23:42 -------- d-----w- C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2013-12-27 08:31:51 -------- d-----w- C:\Users\UpdatusUser\AppData\Local\Programs
2013-12-27 08:31:13 -------- d-----w- C:\Users\UpdatusUser\AppData\Roaming\WinRAR
2013-12-26 23:58:54 -------- d-s---w- C:\WINDOWS\serviceprofiles\networkservice\AppData\Locallow\Microsoft
2013-12-26 22:53:19 -------- d-----w- C:\Users\UpdatusUser\AppData\Roaming\Identities
2013-12-26 22:51:43 -------- d-s---w- C:\WINDOWS\SysNative\config\systemprofile\AppData\Locallow\Microsoft
2013-12-26 22:49:52 -------- d-----w- C:\WINDOWS\SysNative\config\systemprofile\AppData\Roaming\Adobe
2013-12-26 22:44:21 -------- d-----w- C:\WINDOWS\SysNative\config\systemprofile\AppData\Roaming\Intel
2013-12-26 22:44:13 -------- d-----w- C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\MediaServer
2013-12-26 22:38:01 -------- d-s---w- C:\Users\UpdatusUser\AppData\Roaming\Microsoft
2013-12-26 22:38:01 -------- d-----w- C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2013-12-26 22:38:01 -------- d-----w- C:\Users\UpdatusUser\AppData\Local\Temp
2013-12-26 22:38:01 -------- d-----w- C:\Users\UpdatusUser\AppData\Local\Microsoft
2013-12-26 22:38:01 -------- d-----r- C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2013-12-26 22:38:01 -------- d-----r- C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2013-12-26 22:38:01 -------- d-----r- C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2013-12-26 22:38:00 -------- d-s---w- C:\Users\UpdatusUser.poli\AppData\Roaming\Microsoft
2013-12-26 22:38:00 -------- d-----w- C:\Users\UpdatusUser.poli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2013-12-26 22:38:00 -------- d-----w- C:\Users\UpdatusUser.poli\AppData\Local\Temp
2013-12-26 22:38:00 -------- d-----w- C:\Users\UpdatusUser.poli\AppData\Local\Microsoft
2013-12-26 22:38:00 -------- d-----r- C:\Users\UpdatusUser.poli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2013-12-26 22:38:00 -------- d-----r- C:\Users\UpdatusUser.poli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2013-12-26 22:38:00 -------- d-----r- C:\Users\UpdatusUser.poli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2013-12-26 22:37:59 -------- d-s---w- C:\Users\Administrator\AppData\Roaming\Microsoft
2013-12-26 22:37:59 -------- d-----w- C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2013-12-26 22:37:59 -------- d-----w- C:\Users\Administrator\AppData\Local\Temp
2013-12-26 22:37:59 -------- d-----w- C:\Users\Administrator\AppData\Local\Microsoft
2013-12-26 22:37:59 -------- d-----r- C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2013-12-26 22:37:59 -------- d-----r- C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2013-12-26 22:37:59 -------- d-----r- C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2013-12-26 22:32:22 -------- d-----w- C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Microsoft
2013-12-26 22:31:57 -------- d-s---w- C:\WINDOWS\SysNative\config\systemprofile\AppData\Roaming\Microsoft
2013-12-26 20:43:11 -------- d-----w- C:\Users\UpdatusUser\AppData\Roaming\CyberLink
2013-12-26 19:38:01 9E0247820E22734C8F85C035DEAEE259 28 ----a-w- C:\Users\UpdatusUser\AppData\Roaming\WB.CFG
2013-12-26 18:57:09 -------- d-s---w- C:\WINDOWS\serviceprofiles\Localservice\AppData\Locallow\Microsoft
2013-12-26 18:51:56 -------- d-----w- C:\Users\UpdatusUser\AppData\Local\PokerStars.BE
2013-12-26 18:48:18 -------- d-----w- C:\Users\UpdatusUser\AppData\Roaming\Skype
2013-12-26 18:31:15 -------- d-----w- C:\Users\UpdatusUser\AppData\Roaming\wam.04351C371E530C3762CBA45FA283ED972DCDEFB6.1
2013-12-26 18:31:10 -------- d-----w- C:\Users\UpdatusUser\AppData\Local\Adobe
2013-12-26 18:18:13 -------- d-----w- C:\WINDOWS\serviceprofiles\Localservice\AppData\Local\PnrpSqm
2013-12-26 18:17:27 -------- d-----w- C:\Users\UpdatusUser\AppData\Roaming\Mozilla
2013-12-26 18:17:27 -------- d-----w- C:\Users\UpdatusUser\AppData\Local\Mozilla
2013-12-26 18:15:38 -------- d-----w- C:\WINDOWS\serviceprofiles\Localservice\AppData\Roaming\PeerNetworking
2013-12-26 18:14:31 -------- d-----w- C:\Users\UpdatusUser\AppData\Local\CyberLink
2013-12-26 18:13:51 -------- d-----w- C:\Users\UpdatusUser\AppData\Local\Power2Go8
2013-12-26 18:13:23 -------- d-----r- C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-12-26 18:13:23 -------- d-----r- C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2013-12-26 18:13:20 -------- d-----w- C:\Users\UpdatusUser\AppData\Roaming\Adobe
2013-12-26 18:05:03 -------- d-----w- C:\Users\UpdatusUser\AppData\Local\Packages
2013-12-26 18:05:00 -------- d-----w- C:\Users\UpdatusUser\AppData\Roaming\Intel
====== C:\Users\UpdatusUser ======
2014-01-23 15:42:17 662C39FC1E27131551D557862CEC47F0 935175 ----a-w- C:\Users\UpdatusUser\Desktop\RSITx64.exe
2014-01-23 09:27:15 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FinalWire
2014-01-20 16:25:34 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2014-01-18 19:44:54 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Panda Cloud Antivirus
2014-01-18 13:20:51 63D747B9803DA584B55F7CA400EB0E26 4792 ----a-w- C:\Users\UpdatusUser\ipconfig.all.txt
2014-01-14 15:17:34 402498299A1AF19D240EACF9E87DA68B 2076420 ----a-w- C:\Users\UpdatusUser\Downloads\hp-psc-1210-driver-utility.exe
2014-01-14 15:13:35 -------- d-----w- C:\ProgramData\HP
2014-01-09 13:01:26 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ImgBurn
2014-01-04 12:19:19 -------- d-----w- C:\ProgramData\Ashampoo
2014-01-02 10:18:57 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DriverEasy
2013-12-29 09:39:27 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
2013-12-29 09:39:24 -------- d-----w- C:\ProgramData\SUPERAntiSpyware.com
2013-12-29 09:36:39 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Gadwin Systems
2013-12-29 09:31:12 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Speccy
2013-12-28 14:19:20 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDFab 9
2013-12-27 12:18:04 -------- d-----w- C:\WINDOWS\serviceprofiles\Localservice\winhttp
2013-12-27 11:46:33 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Glary Utilities 4
2013-12-27 11:33:41 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SharePoint
2013-12-27 11:33:41 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
2013-12-27 11:28:42 -------- d-----w- C:\ProgramData\Microsoft Help
2013-12-27 11:04:00 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2013-12-27 10:24:44 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GrabIt
2013-12-27 10:12:23 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickPar
2013-12-27 10:04:49 -------- d-----w- C:\ProgramData\MGS
2013-12-27 09:36:04 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spotnet
2013-12-27 09:36:00 -------- d-----w- C:\ProgramData\Spotnet
2013-12-27 09:23:42 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2013-12-26 23:05:26 -------- d-----w- C:\Users\UpdatusUser.poli\Searches
2013-12-26 22:57:33 -------- d---a-r- C:\Users\UpdatusUser\SkyDrive
2013-12-26 22:53:09 6FC234AD3752E1267B34FB12BCD6718B 20 --sh--w- C:\Users\UpdatusUser\ntuser.ini
2013-12-26 22:47:21 6FC234AD3752E1267B34FB12BCD6718B 20 --sh--w- C:\Users\UpdatusUser.poli\ntuser.ini
2013-12-26 22:41:34 -------- d-----w- C:\Users\Default\Roaming
2013-12-26 22:38:01 -------- d--h--w- C:\Users\UpdatusUser\AppData
2013-12-26 22:38:01 -------- d-----r- C:\Users\UpdatusUser\Favorites
2013-12-26 22:38:01 -------- d-----r- C:\Users\UpdatusUser\Documents
2013-12-26 22:38:01 -------- d-----r- C:\Users\UpdatusUser\Desktop
2013-12-26 22:38:00 -------- d--h--w- C:\Users\UpdatusUser.poli\AppData
2013-12-26 22:38:00 -------- d-----r- C:\Users\UpdatusUser.poli\Favorites
2013-12-26 22:38:00 -------- d-----r- C:\Users\UpdatusUser.poli\Documents
2013-12-26 22:38:00 -------- d-----r- C:\Users\UpdatusUser.poli\Desktop
2013-12-26 22:37:59 -------- d--h--w- C:\Users\Administrator\AppData
2013-12-26 22:37:59 -------- d-----r- C:\Users\Administrator\Favorites
2013-12-26 22:37:59 -------- d-----r- C:\Users\Administrator\Desktop
2013-12-26 22:32:49 -------- d-----w- C:\ProgramData\NVIDIA
2013-12-26 22:32:12 -------- d-----w- C:\ProgramData\NVIDIA Corporation
2013-12-26 18:48:08 -------- d-----w- C:\ProgramData\Skype
2013-12-26 18:17:19 -------- d-----w- C:\ProgramData\Mozilla
2013-12-26 18:00:46 -------- d-----w- C:\Users\UpdatusUser.poli\Roaming
2013-12-26 14:32:27 -------- d-----w- C:\Users\UpdatusUser\P5JavaClientSettings
====== C: exe-files ==
2014-01-23 15:42:37 9A2347903D6EDB84C10F288BC0578C1C 388608 ----a-w- C:\Program Files\trend micro\poli.exe
2014-01-23 15:42:17 662C39FC1E27131551D557862CEC47F0 935175 ----a-w- C:\Users\UpdatusUser\Desktop\RSITx64.exe
2014-01-23 09:27:11 F8FE8D0486D91DBEB011ED8FA5A4BB9A 3151168 ----a-w- C:\Program Files (x86)\FinalWire\AIDA64 Extreme\aida64.exe
2014-01-23 09:27:10 F3C8FBBE55D98DD4DFDDD06FF57E0068 721736 ----a-w- C:\Program Files (x86)\FinalWire\AIDA64 Extreme\unins000.exe
2014-01-23 07:55:52 FDE7A79272ECC488D997D1111FE04EC1 12012912 ----a-w- C:\Users\UpdatusUser\AppData\Local\Temp\gusetup5.exe
2014-01-18 19:42:55 BB264BF4D2BA7FDE62F2DD19CEB1EDF2 845944 ----a-w- C:\Users\UpdatusUser\Desktop\pc\PandaCloudAntivirus.exe
2014-01-18 14:34:12 522513A2CD9B0E3F677BF36D497BF9C0 1839376 ----a-w- C:\Users\UpdatusUser\Desktop\pc\Homedale.exe
2014-01-18 12:55:53 BAEF7A0E0817CF21CF76BDDE2CDCBBE0 47799 ----a-w- C:\Program Files (x86)\NirSoft\Network Password Recovery\uninst.exe
=== C: other files ==
2014-01-22 10:32:09 09DB6FDEA9A0F100C801C000C9D60880 15606 ----a-w- C:\Users\UpdatusUser\AppData\Local\panda4_1dn\data\temp.zip
2014-01-20 15:34:42 D6C6BAE38CFEDCF3F7E046A5A72528FD 58808 ----a-w- C:\Windows\System32\drivers\PSKMAD.sys
2014-01-18 19:45:04 DA8A612152441DDA63DA9C1480731838 137960 -c--a-w- C:\Windows\System32\DRVSTORE\PSINProt_DF181B06CF474EB63E2495BDE4AB33271E2DD45E\PSINProt.sys
2014-01-18 19:45:04 DA8A612152441DDA63DA9C1480731838 137960 ----a-w- C:\Windows\System32\drivers\PSINProt.sys
2014-01-18 19:45:04 D751845E6CAC4B564977B518DFF6DF23 169192 -c--a-w- C:\Windows\System32\DRVSTORE\PSINAflt_F43EFD8DCC6D9BDF596D8BF8B981DA647CE3D1C5\PSINAflt.sys
2014-01-18 19:45:04 D751845E6CAC4B564977B518DFF6DF23 169192 ----a-w- C:\Windows\System32\drivers\PSINAflt.sys
2014-01-18 19:44:59 229B64294C3AE7A9E6BF27D11085B193 206056 -c--a-w- C:\Windows\System32\DRVSTORE\PSINKnc_B2885A90FAB4F42974CA512C5CCBA1B99434BE6B\PSINKNC.sys
2014-01-18 19:44:59 229B64294C3AE7A9E6BF27D11085B193 206056 ----a-w- C:\Windows\System32\drivers\PSINKNC.sys
==== Startup Registry Enabled ======================
[HKEY_USERS\S-1-5-21-3439249676-3253818225-4033233602-1001\Software\Microsoft\Windows\CurrentVersion\Run]
"Gadwin PrintScreen"="G:\progs\PrintScreen\PrintScreen.exe /nosplash"
"Skype"="C:\Program Files (x86)\Skype\Phone\Skype.exe /minimized /regrun"
[HKEY_USERS\S-1-5-21-3439249676-3253818225-4033233602-1002\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"WAB Migrate"="%ProgramFiles%\Windows Mail\wab.exe /Upgrade"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CLMLServer_For_P2G8"="C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe"
"RemoteControl10"="C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe"
"PSUAMain"="C:\Program Files (x86)\Panda Security\Panda Cloud Antivirus\PSUAMain.exe /LaunchSysTray"
"Panda Security URL Filtering"="C:\ProgramData\Panda Security URL Filtering\Panda_URL_Filtering.exe"
"Adobe ARM"="C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Gadwin PrintScreen"="G:\progs\PrintScreen\PrintScreen.exe /nosplash"
"Skype"="C:\Program Files (x86)\Skype\Phone\Skype.exe /minimized /regrun"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="C:\\WINDOWS\\SysWOW64\\nvinit.dll"
==== Startup Registry Enabled x64 ======================
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s"
"RtHDVBg_Dolby"="C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe /FORPCEE4 "
"BTMTrayAgent"="rundll32.exe C:\Program Files (x86)\Intel\Bluetooth\btmshellex.dll,TrayApp"
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe"
"Persistence"="C:\WINDOWS\system32\igfxpers.exe"
"BCSSync"="C:\Program Files\Microsoft Office\Office14\BCSSync.exe /DelayServices"
"SynTPEnh"="%ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe "
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="C:\\Windows\\system32\\nvinitx.dll,C:\\WINDOWS\\system32\\nvinitx.dll"
==== Task Scheduler Jobs ======================
C:\WINDOWS\tasks\Adobe Flash Player Updater.job --a-------- C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [17/01/2014 19:28]
C:\WINDOWS\tasks\AutoKMS.job --a-------- C:\Windows\AutoKMS\AutoKMS.exe []
C:\WINDOWS\tasks\DriverEasy Scheduled Scan.job --a-------- C:\Program Files\Easeware\DriverEasy\DriverEasy.exe [23/12/2013 02:16]
C:\WINDOWS\tasks\GlaryInitialize 4.job --a-------- C:\Program Files (x86)\Glary Utilities 4\Initialize.exe [06/01/2014 09:37]
C:\WINDOWS\tasks\Synaptics TouchPad Enhancements.job --a-------- C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [05/09/2012 03:54]
==== Other Scheduled Tasks ======================
"C:\WINDOWS\SysNative\tasks\Adobe Flash Player Updater" [C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe]
"C:\WINDOWS\SysNative\tasks\AutoKMS" [C:\Windows\AutoKMS\AutoKMS.exe]
"C:\WINDOWS\SysNative\tasks\Dolby Selector" [C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe]
"C:\WINDOWS\SysNative\tasks\GlaryInitialize 4" [C:\Program Files (x86)\Glary Utilities 4\Initialize.exe]
"C:\WINDOWS\SysNative\tasks\GU4SkipUAC" [C:\Program Files (x86)\Glary Utilities 4\Integrator.exe]
"C:\WINDOWS\SysNative\tasks\Synaptics TouchPad Enhancements" [\Program Files\Synaptics\SynTP\SynTPEnh.exe]
"C:\WINDOWS\SysNative\tasks\User_Feed_Synchronization-{3B8F2D14-6604-436E-9287-34F955B59A1B}" [C:\WINDOWS\system32\msfeedssync.exe]
"C:\WINDOWS\SysNative\tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask" [%systemroot%\system32\sc.exe start osppsvc]
==== Firefox Extensions ======================
ProfilePath: C:\Users\UpdatusUser\AppData\Roaming\Mozilla\Firefox\Profiles\kgzgum1q.default
- Adblock Plus - %ProfilePath%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
AppDir: C:\Program Files (x86)\Mozilla Firefox
- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
==== Firefox Plugins ======================
Profilepath: C:\Users\UpdatusUser\AppData\Roaming\Mozilla\Firefox\Profiles\kgzgum1q.default
2557FBC582910A71CDEB0F22886D118D - C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_43.dll - Shockwave Flash
==== Set IE to Default ======================
Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.google.be/"
New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.google.be/"
==== All HKCU SearchScopes ======================
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
"DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE11SR"
{0A9D7685-EDCD-4AC8-8341-C0EDC56A94D7} Bing Url="http://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MALNJS"
{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}"
==== Empty IE Cache ======================
C:\WINDOWS\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\UpdatusUser\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\Users\UpdatusUser\AppData\Local\Microsoft\Windows\INetCache\Low\Content.IE5 emptied successfully
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\WINDOWS\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
==== Empty FireFox Cache ======================
C:\Users\UpdatusUser\AppData\Local\Mozilla\Firefox\Profiles\kgzgum1q.default\Cache emptied successfully
==== Empty Chrome Cache ======================
No Chrome User Data found
==== Empty All Flash Cache ======================
Flash Cache Emptied Successfully
==== Empty All Java Cache ======================
No Java Cache Found
==== C:\zoek_backup content ======================
C:\zoek_backup (files=440 folders=40 6253509 bytes)