Zoek.exe v5.0.0.1 Updated 31-December-2015
Tool run by claudia on zo 04-09-2016 at 15:09:22,22.
Microsoft Windows 10 Pro 10.0.10586 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\claudia\Desktop\zoek.exe [Scan all users] [Script inserted]
==== System Restore Info ======================
4-9-2016 15:12:51 Zoek.exe System Restore Point Created Successfully.
==== Deleting CLSID Registry Keys ======================
HKEY_USERS\S-1-5-21-154200054-2768028166-2276094714-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} deleted successfully
==== Deleting CLSID Registry Values ======================
==== Running Processes ======================
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\Program Files\AVAST Software\Avast\afwServ.exe
C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe
C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeHost.exe
C:\Users\claudia\AppData\Roaming\Dashlane\DashlanePlugin.exe
C:\Program Files\AVAST Software\Avast\avastui.exe
C:\Program Files (x86)\Launch Manager\LManager.exe
C:\Users\claudia\AppData\Roaming\Dashlane\Dashlane.exe
C:\Users\claudia\Desktop\zoek.exe
C:\WINDOWS\SysWOW64\cmd.exe
C:\WINDOWS\SysWOW64\cmd.exe
C:\WINDOWS\SysWOW64\ctfmon.exe
C:\WINDOWS\SysWOW64\cmd.exe
==== Deleting Services ======================
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LiveUpdateSvc deleted successfully
==== Registry Fix Code ======================
Windows Registry Editor Version 5.00
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Advanced SystemCare 9"=-
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"Uninstall C:\\Users\\claudia\\AppData\\Local\\Microsoft\\OneDrive\\17.3.6201.1019_1\\amd64"=-
"Uninstall C:\\Users\\claudia\\AppData\\Local\\Microsoft\\OneDrive\\17.3.6281.1202\\amd64"=-
"Uninstall C:\\Users\\claudia\\AppData\\Local\\Microsoft\\OneDrive\\17.3.6301.0127\\amd64"=-
"Uninstall C:\\Users\\claudia\\AppData\\Local\\Microsoft\\OneDrive\\17.3.6302.0225\\amd64"=-
==== Registry Fix Code x64 ======================
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"IObit Malware Fighter"=-
==== Deleting Files \ Folders ======================
C:\Program Files\Enigma Software Group not found
C:\Users\claudia\AppData\Roaming\Enigma Software Group not found
"C:\WINDOWS\tasks\ASC9_SkipUac_claudia.job" not found
"C:\WINDOWS\tasks\Uninstaller_SkipUac_claudia.job" not found
C:\Program Files (x86)\IObit deleted
C:\Program Files\ReviverSoft deleted
C:\WINDOWS\IObit deleted
C:\ProgramData\IObit deleted
==== System Specs ======================
Windows: Windows Version 6.2 (Build 9200)
Memory (RAM): 7659 MB
CPU Info: AMD A4-3300M APU with Radeon(tm) HD Graphics
CPU Speed: 1918.7 MHz
Sound Card: Luidsprekers (Realtek High Defi |
Display Adapters: AMD Radeon HD 6480G | AMD Radeon HD 6480G
Monitors: 1x; Generic PnP Monitor |
Screen Resolution: 1600 X 900 - 32 bit
Network: Network Present
Network Adapters: Microsoft Wi-Fi Direct Virtual Adapter | This Qualcomm Atheros network Controller connects you to the network. | Qualcomm Atheros AR5B97 Wireless Network Adapter
CD / DVD Drives: 1x (D: | ) D: SlimtypeDVD A DS8A5SH
Ports: COM Ports NOT Present. LPT Port NOT Present.
Mouse: 16 Button Wheel Mouse Present
Hard Disks: C: 678.5GB
Hard Disks - Free: C: 544.4GB
Manufacturer *: Packard Bell
BIOS Info: AT/AT COMPATIBLE | 07/01/11 | ACRSYS - 1
Time Zone: West-Europa (standaardtijd)
Motherboard *: Packard Bell SJV70-SB
Country: Nederland
Language: NLD
==== System Specs (Software) ======================
Internet Explorer Version: 11.545.10586.0
Google Chrome version: 52.0.2743.116
Sun Java version: 1.8.0_101 (32-bit)
Sun Java version: 1.8.0_101 (64-bit)
==== Files Recently Created / Modified ======================
====== C:\WINDOWS ====
====== C:\Users\claudia\AppData\Local\Temp ====
====== Java Cache =====
====== C:\WINDOWS\SysWOW64 =====
====== C:\WINDOWS\SysWOW64\drivers =====
====== C:\WINDOWS\Sysnative =====
2016-09-04 12:47:11 150A43E51A708A5F38C761F1A62F9D85 110144 ----a-w- C:\WINDOWS\Sysnative\WindowsAccessBridge-64.dll
====== C:\WINDOWS\Sysnative\drivers =====
2016-08-13 10:04:39 00171C6C15B481B6E4286EBFEFA8E5BD 83312 ----a-w- C:\WINDOWS\Sysnative\drivers\aswHdsKe.sys
2016-08-10 10:58:32 2442F8CED09E5E4A8F1AA04C5DB22771 954368 ----a-w- C:\WINDOWS\Sysnative\drivers\bthport.sys
2016-08-10 10:58:28 C2138FE291C8235C3A26CD04EE629163 161632 ----a-w- C:\WINDOWS\Sysnative\drivers\ksecpkg.sys
2016-08-10 10:58:28 570BA8E8E1E3064A7D92F862B7F59B60 604928 ----a-w- C:\WINDOWS\Sysnative\drivers\cng.sys
2016-08-10 10:58:27 72CC1F3397B4438C8B8830F004075038 112640 ----a-w- C:\WINDOWS\Sysnative\drivers\bthenum.sys
2016-08-10 10:58:25 5DCB6746E9880DED87EC2A239ED64EB4 181248 ----a-w- C:\WINDOWS\Sysnative\drivers\rfcomm.sys
2016-08-10 10:58:25 0A23A12396CE5AE78E13F8E2ADF9AE35 128512 ----a-w- C:\WINDOWS\Sysnative\drivers\bthpan.sys
2016-08-10 10:58:24 FA7EE4E3DCF4C1159D4E78147D8F1A7B 84992 ----a-w- C:\WINDOWS\Sysnative\drivers\BTHUSB.SYS
2016-08-10 10:58:23 E61E8025B3FC30906B9BFF0E1602B1E8 576864 ----a-w- C:\WINDOWS\Sysnative\drivers\dxgmms2.sys
2016-08-10 10:58:23 E5EF652F8C880EC48A4E827698416338 1988448 ----a-w- C:\WINDOWS\Sysnative\drivers\dxgkrnl.sys
2016-08-10 10:58:23 97269D0CF0C275A7DF5BFCA6692CC8B8 393056 ----a-w- C:\WINDOWS\Sysnative\drivers\dxgmms1.sys
2016-08-10 10:58:12 34DDBE73E42A4EDED7BEFF66F270C1A4 99680 ----a-w- C:\WINDOWS\Sysnative\drivers\pdc.sys
2016-08-10 10:58:07 FAEBE339AB36831B77DC8F3B81DEDF75 465248 ----a-w- C:\WINDOWS\Sysnative\drivers\storport.sys
2016-08-10 10:58:07 3F89E96BDA0A24A3D2DBB7CE1E625589 331616 ----a-w- C:\WINDOWS\Sysnative\drivers\pci.sys
2016-08-10 10:57:33 1BB74617AE07539EC7C31C93F98644C7 422744 ----a-w- C:\WINDOWS\Sysnative\drivers\rdbss.sys
====== C:\WINDOWS\Tasks ======
2016-09-01 10:12:02 C03550B4C032C5229597686CA8EE0C20 3032 ----a-w- C:\WINDOWS\Sysnative\Tasks\Driver Booster SkipUAC (claudia)
2016-08-25 11:40:58 6F4F906C51610E81D55321EE58651885 3348 ----a-w- C:\WINDOWS\Sysnative\Tasks\OneDrive Standalone Update Task
2016-08-23 08:52:26 1896E820481E20C664745AB9C52ECE31 3270 ----a-w- C:\WINDOWS\Sysnative\Tasks\HPCeeScheduleForclaudia
2016-08-23 08:52:23 02E6C74A3E657BCD928E1F1F9CCD134B 370 ----a-w- C:\WINDOWS\Tasks\HPCeeScheduleForclaudia.job
====== C:\WINDOWS\Temp ======
======= C:\Program Files =====
======= C:\PROGRA~2 =====
2016-08-06 21:15:36 -------- d-----w- C:\PROGRA~2\Dashlane
======= C: =====
2016-09-04 12:49:33 D41D8CD98F00B204E9800998ECF8427E 0 ---ha-w- C:\asc_rdflag
====== C:\Users\claudia\AppData\Roaming ======
2016-08-06 21:15:36 -------- d-----w- C:\Users\claudia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dashlane
====== C:\Users\claudia ======
2016-08-31 19:24:54 8045ABB21A3BDD66A48E1ED5C0F0EF6A 1222144 ----a-w- C:\Users\claudia\Downloads\RSITx64.exe
====== C: exe-files ==
2016-09-04 12:47:11 F5A8326F60A523701AEA7BEF036A7D37 0 ----a-we C:\ProgramData\Oracle\Java\javapath\java.exe
2016-09-04 12:47:11 62CA41748E1E18A4A50DEE097FAF0BFC 0 ----a-we C:\ProgramData\Oracle\Java\javapath\javaws.exe
2016-09-04 12:47:11 16D61617123CA3C2AB3E9727B3BCD55A 0 ----a-we C:\ProgramData\Oracle\Java\javapath\javaw.exe
=== C: other files ==
==== Startup Registry Enabled ======================
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"GarminExpressTrayApp"="C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe"
[HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"OneDriveSetup"="C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup"
[HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"OneDriveSetup"="C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup"
[HKEY_USERS\S-1-5-21-154200054-2768028166-2276094714-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CCleaner Monitoring"="C:\Program Files\CCleaner\CCleaner64.exe /MONITOR"
"Dashlane"="C:\Users\claudia\AppData\Roaming\Dashlane\Dashlane.exe autoLaunchAtStartup"
"HP Officejet 6600 (NET)"="C:\Program Files\HP\HP Officejet 6600\Bin\ScanToPCActivationApp.exe -deviceID CN2AV5KGCC05RN:NW -scfn HP Officejet 6600 (NET) -AutoStart 1"
"DashlanePlugin"="C:\Users\claudia\AppData\Roaming\Dashlane\DashlanePlugin.exe ws"
[HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run]
"GarminExpressTrayApp"="C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe"
[HKEY_USERS\S-1-5-21-154200054-2768028166-2276094714-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Uninstall C:\Users\claudia\AppData\Local\Microsoft\OneDrive\17.3.6386.0412\amd64"="C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q C:\Users\claudia\AppData\Local\Microsoft\OneDrive\17.3.6386.0412\amd64"
"Uninstall C:\Users\claudia\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64"="C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q C:\Users\claudia\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe MSRun"
"AvastUI.exe"="C:\Program Files\AVAST Software\Avast\AvastUI.exe /nogui"
"LManager"="C:\Program Files (x86)\Launch Manager\LManager.exe"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CCleaner Monitoring"="C:\Program Files\CCleaner\CCleaner64.exe /MONITOR"
"Dashlane"="C:\Users\claudia\AppData\Roaming\Dashlane\Dashlane.exe autoLaunchAtStartup"
"HP Officejet 6600 (NET)"="C:\Program Files\HP\HP Officejet 6600\Bin\ScanToPCActivationApp.exe -deviceID CN2AV5KGCC05RN:NW -scfn HP Officejet 6600 (NET) -AutoStart 1"
"DashlanePlugin"="C:\Users\claudia\AppData\Roaming\Dashlane\DashlanePlugin.exe ws"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"Uninstall C:\Users\claudia\AppData\Local\Microsoft\OneDrive\17.3.6386.0412\amd64"="C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q C:\Users\claudia\AppData\Local\Microsoft\OneDrive\17.3.6386.0412\amd64"
"Uninstall C:\Users\claudia\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64"="C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q C:\Users\claudia\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64"
==== Startup Registry Enabled x64 ======================
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"="C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s"
"ETDCtrl"="%ProgramFiles%\Elantech\ETDCtrl.exe "
==== Task Scheduler Jobs ======================
C:\WINDOWS\tasks\CreateExplorerShellUnelevatedTask.job --a-------- C:\WINDOWS\explorer.exe [01-07-2016 06:33]
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job --a-------- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [04-10-2015 15:12]
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job --a-------- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [04-10-2015 15:12]
C:\WINDOWS\tasks\HPCeeScheduleForclaudia.job --a-------- [Undetermined Task]
==== Other Scheduled Tasks ======================
"C:\WINDOWS\SysNative\tasks\AMD Updater" ["C:\Program Files\AMD\CIM\\Bin64\InstallManagerApp.exe"]
"C:\WINDOWS\SysNative\tasks\CCleanerSkipUAC" ["C:\Program Files\CCleaner\CCleaner.exe"]
"C:\WINDOWS\SysNative\tasks\Driver Booster SkipUAC (claudia)" [C:\Program Files (x86)\IObit\Driver Booster\DriverBooster.exe]
"C:\WINDOWS\SysNative\tasks\GarminUpdaterTask" [C:\Program Files (x86)\Garmin\Express SelfUpdater\ExpressSelfUpdater.exe]
"C:\WINDOWS\SysNative\tasks\GoogleUpdateTaskMachineCore" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe]
"C:\WINDOWS\SysNative\tasks\GoogleUpdateTaskMachineUA" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe]
"C:\WINDOWS\SysNative\tasks\HPCeeScheduleForclaudia" [C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe]
"C:\WINDOWS\SysNative\tasks\HPCustParticipation HP Officejet 6600" ["C:\Program Files\HP\HP Officejet 6600\Bin\HPCustPartic.exe"]
"C:\WINDOWS\SysNative\tasks\OneDrive Standalone Update Task" [C:\Users\claudia\AppData\Local\Microsoft\OneDrive\17.3.6517.0809\OneDriveStandaloneUpdater.exe]
"C:\WINDOWS\SysNative\tasks\SafeZone scheduled Autoupdate 1448670281" [C:\Program Files\AVAST Software\SZBrowser\launcher.exe]
"C:\WINDOWS\SysNative\tasks\User_Feed_Synchronization-{A4AC3707-E0E1-41E5-8A76-FA2626E8BD04}" [C:\WINDOWS\system32\msfeedssync.exe]
"C:\WINDOWS\SysNative\tasks\Hewlett-Packard\HP Active Health\HP Active Health Scan (HPSA)" [C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPActiveHealth\ActiveHealth.exe]
"C:\WINDOWS\SysNative\tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start" [C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe]
"C:\WINDOWS\SysNative\tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Report" [C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSFReport.exe]
"C:\WINDOWS\SysNative\tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater" [C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe]
"C:\WINDOWS\SysNative\tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater - Resources" [C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe]
"C:\WINDOWS\SysNative\tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis" [C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe]
"C:\WINDOWS\SysNative\tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_DeviceScan" [C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe]
==== Firefox Extensions Registry ======================
[HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions]
"
sp@avast.com"="C:\Program Files\AVAST Software\Avast\SafePrice\FF" [21-07-2016 10:28]
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions]
"
sp@avast.com"="C:\Program Files\AVAST Software\Avast\SafePrice\FF" [21-07-2016 10:28]
==== Chromium Look ======================
Google Chrome Version: 46.0.2490.86
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
eofcbnmajmjmplflapaojjnihcjkigck - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChromeSp.crx[08-05-2016 17:45]
gomekmidlodglbbmalcneegieacbdmki - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx[08-05-2016 17:45]
Google Slides - claudia\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek
Bejeweled - claudia\AppData\Local\Google\Chrome\User Data\Default\Extensions\adpkifcfcacgmnggcbpbjbkdijciiigm
Google Docs - claudia\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake
Google Drive - claudia\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf
YouTube - claudia\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo
Google Search - claudia\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf
Christmas Solitiare - claudia\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhcbjomfajlnldboplncbdhmdaagcpln
Gmelius for Gmail - claudia\AppData\Local\Google\Chrome\User Data\Default\Extensions\dheionainndbbpoacpnopgmnihkcmnkl
Avast SafePrice - claudia\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck
Dashlane - claudia\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdjamakpfbbddfjaooikfcpapjohcfmg
Google Sheets - claudia\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap
Google Docs Offline - claudia\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi
Whitelisted domains - claudia\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom
Avast Online Security - claudia\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki
Calculator - claudia\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdkgihpbaofhkiliohfepioflkkbapao
Google Play - claudia\AppData\Local\Google\Chrome\User Data\Default\Extensions\komhbcfkdcgmcdoenjcjheifdiabikfi
Twins - claudia\AppData\Local\Google\Chrome\User Data\Default\Extensions\mhpgjofdandajhcbkmilgfclhhnfpllc
Hearts - claudia\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkkbmdeidonbobilknidkpldmecbiilm
Chrome Web Store Payments - claudia\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda
Gmail - claudia\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia
Chrome Media Router - claudia\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm
Google Slides - infoa\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek
Bejeweled - infoa\AppData\Local\Google\Chrome\User Data\Default\Extensions\adpkifcfcacgmnggcbpbjbkdijciiigm
Google Docs - infoa\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake
Google Drive - infoa\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf
YouTube - infoa\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo
Google Search - infoa\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf
Christmas Solitiare - infoa\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhcbjomfajlnldboplncbdhmdaagcpln
Gmelius for Gmail - infoa\AppData\Local\Google\Chrome\User Data\Default\Extensions\dheionainndbbpoacpnopgmnihkcmnkl
Avast SafePrice - infoa\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck
Google Sheets - infoa\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap
Google Docs Offline - infoa\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi
AdBlock - infoa\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom
Avast Online Security - infoa\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki
Calculator - infoa\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdkgihpbaofhkiliohfepioflkkbapao
Google Play - infoa\AppData\Local\Google\Chrome\User Data\Default\Extensions\komhbcfkdcgmcdoenjcjheifdiabikfi
Twins - infoa\AppData\Local\Google\Chrome\User Data\Default\Extensions\mhpgjofdandajhcbkmilgfclhhnfpllc
Hearts - infoa\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkkbmdeidonbobilknidkpldmecbiilm
Application folder name for uploaded documents - infoa\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndjpnladcallmjemlbaebfadecfhkepb
Chrome Web Store Payments - infoa\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda
Gmail - infoa\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia
==== IE Start and Search Settings ======================
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="
http://www.1limburg.nl/"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
==== All HKLM and HKCU SearchScopes ======================
HKLM\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
HKLM\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} -
http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
HKLM\Wow6432Node\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
HKLM\Wow6432Node\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} -
http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
HKCU\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
HKCU\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} -
http://www.bing.com/search?q={searchTer ... ORM=IESR02
==== Deleting CLSID Registry Keys ======================
==== Deleting CLSID Registry Values ======================
HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\
pdfsam_enhanced_conv@pdfsam.com deleted successfully
==== HijackThis Entries ======================
F2 - REG:system.ini: UserInit=
O2 - BHO: Dashlane BHO - {42D79B50-CC4A-4A8E-860F-BE674AF053A2} - C:\Users\claudia\AppData\Roaming\Dashlane\ie\Dashlanei.dll
O3 - Toolbar: Dashlane Toolbar - {669695BC-A811-4A9D-8CDF-BA8C795F261C} - C:\Users\claudia\AppData\Roaming\Dashlane\ie\KWIEBar.dll
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKLM\..\Run: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O4 - HKCU\..\Run: [Dashlane] "C:\Users\claudia\AppData\Roaming\Dashlane\Dashlane.exe" autoLaunchAtStartup
O4 - HKCU\..\Run: [HP Officejet 6600 (NET)] "C:\Program Files\HP\HP Officejet 6600\Bin\ScanToPCActivationApp.exe" -deviceID "CN2AV5KGCC05RN:NW" -scfn "HP Officejet 6600 (NET)" -AutoStart 1
O4 - HKCU\..\Run: [DashlanePlugin] "C:\Users\claudia\AppData\Roaming\Dashlane\DashlanePlugin.exe" ws
O4 - HKCU\..\RunOnce: [Uninstall C:\Users\claudia\AppData\Local\Microsoft\OneDrive\17.3.6386.0412\amd64] C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\claudia\AppData\Local\Microsoft\OneDrive\17.3.6386.0412\amd64"
O4 - HKCU\..\RunOnce: [Uninstall C:\Users\claudia\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64] C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\claudia\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64"
O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [GarminExpressTrayApp] "C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe" (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [GarminExpressTrayApp] "C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe" (User 'Default user')
O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\Program Files (x86)\Microsoft Office\Office12\EXCEL.EXE/3000
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Protocol: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\WINDOWS\system32\atiesrxx.exe (file missing)
O23 - Service: AMD FUEL Service - Advanced Micro Devices, Inc. - C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
O23 - Service: Avast Antivirus (avast! Antivirus) - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Avast Firewall (avast! Firewall) - AVAST Software - C:\Program Files\AVAST Software\Avast\afwServ.exe
O23 - Service: @oem80.inf,%BcmBtRSupport.SVCNAME%;Bluetooth Driver Management Service (BcmBtRSupport) - Unknown owner - C:\WINDOWS\system32\BtwRSupportService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000 (diagnosticshub.standardcollector.service) - Unknown owner - C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe (file missing)
O23 - Service: Dritek WMI Service (DsiWMIService) - Dritek System Inc. - C:\Program Files (x86)\Launch Manager\dsiwmis.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: Elan Service (ETDService) - ELAN Microelectronics Corp. - C:\Program Files\Elantech\ETDService.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: Garmin Device Interaction Service - Garmin Ltd. or its subsidiaries - C:\Program Files (x86)\Garmin\Device Interaction Service\GarminService.exe
O23 - Service: Google Update-service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update-service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: HP Support Solutions Framework Service (HPSupportSolutionsFrameworkService) - HP Inc. - C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\WINDOWS\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: PDFsam Enhanced - Andrea Vacondio - C:\Program Files\PDFsam Enhanced\ws.exe
O23 - Service: PDFsam Enhanced CrashHandler - Andrea Vacondio - C:\Program Files\PDFsam Enhanced\crash-handler-ws.exe
O23 - Service: PDFsam Enhanced Creator - Andrea Vacondio - C:\Program Files\PDFsam Enhanced\creator-ws.exe
O23 - Service: PDFsam Manager - ANDREA VACONDIO - C:\ProgramData\ANDREA VACONDIO\PDFsam Manager\PDFsam Enhanced\PDFsam Manager.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SensorDataService.exe,-101 (SensorDataService) - Unknown owner - C:\WINDOWS\System32\SensorDataService.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: TeamViewer 10 (TeamViewer) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
O23 - Service: @%SystemRoot%\system32\TieringEngineService.exe,-702 (TieringEngineService) - Unknown owner - C:\WINDOWS\system32\TieringEngineService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
==== Empty IE Cache ======================
C:\WINDOWS\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\claudia\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\Users\claudia\AppData\Local\Microsoft\Windows\INetCache\Low\Content.IE5 emptied successfully
C:\Users\infoa\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\Users\infoa\AppData\Local\Microsoft\Windows\INetCache\Low\Content.IE5 emptied successfully
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\WINDOWS\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\Users\claudia\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully
C:\Users\claudia\AppData\Local\Microsoft\Windows\INetCache\Low\IE emptied successfully
C:\Users\infoa\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully
C:\Users\infoa\AppData\Local\Microsoft\Windows\INetCache\Low\IE emptied successfully
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully
C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully
==== Empty FireFox Cache ======================
No FireFox Profiles found
==== Empty Chrome Cache ======================
C:\Users\claudia\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
C:\Users\infoa\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
==== Empty All Flash Cache ======================
No Flash Cache Found
==== Empty All Java Cache ======================
Java Cache cleared successfully
==== C:\zoek_backup content ======================
C:\zoek_backup (files=164 folders=44 367134540 bytes)
==== EOF on zo 04-09-2016 at 15:22:57,08 ======================