Zoek.exe v5.0.0.0 Updated 05-Januari-2014 Tool run by Patrick on zo 05/01/2014 at 16:53:29,59. Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x64 Running in: Normal Mode Internet Access Detected Launched: C:\Users\Patrick\Pictures\zoek.com [Scan all users] [Script inserted] ==== Older Logs ====================== C:\zoek-results2014-01-03-110813.log 13360 bytes C:\zoek-results2014-01-03-123735.log 38257 bytes ==== VirusTotal Scan ====================== C:\Users\Patrick\AppData\Local\Temp\launchie.vbs not found ==== Running Processes ====================== C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe C:\Windows\SysWOW64\cmd.exe C:\Windows\SysWOW64\cmd.exe C:\Windows\SysWOW64\cmd.exe ==== System Specs ====================== Windows: Windows 7 Home Premium Edition (64-bit) Service Pack 1 (Build 7601) Memory (RAM): 4096 MB CPU Info: Intel(R) Core(TM)2 Quad CPU Q8200 @ 2.33GHz CPU Speed: 2330,2 MHz Sound Card: Luidsprekers (Realtek High Defi | Luidsprekers (WsAudio_Device) | Digitale audio (HDMI) (High Def | Realtek Digital Output (Realtek | Display Adapters: NVIDIA GeForce G100 | NVIDIA GeForce G100 | RDPDD Chained DD | RDP Encoder Mirror Driver | RDP Reflector Display Driver Monitors: 1x; Algemeen PnP-beeldscherm | Screen Resolution: 1680 X 1050 - 32 bit Network: Network Present Network Adapters: NVIDIA nForce-netwerkcontroller CD / DVD Drives: 1x (E: | ) E: HL-DT-STDVDRAM GH40F Ports: COM1 LPT Port NOT Present. Mouse: 8 Button Wheel Mouse Present Hard Disks: C: 297,9GB | D: 284,5GB Hard Disks - Free: C: 220,5GB | D: 284,3GB Manufacturer *: American Megatrends Inc. BIOS Info: AT/AT COMPATIBLE | 02/26/09 | ACRSYS - 20090226 Time Zone: Romance (standaardtijd) Motherboard *: ACER MCP73PV Country: Belgi‰ Language: NLB ==== System Specs (Software) ====================== Anti-Virus: Microsoft Security Essentials On-access scanning disabled (Outdated) Anti-Spyware: Windows Defender disabled (Outdated) Anti-Spyware: Spybot - Search and Destroy disabled (Outdated) Anti-Spyware: Microsoft Security Essentials disabled (Outdated) Internet Explorer Version: 11.0.9600.16476 Adobe Reader version: 10.1.8.24 Sun Java version: 1.7.0_45 (32-bit) Shockwave Player version: 12.0.6r147 ==== Files Recently Created / Modified ====================== ====== C:\Windows ==== ====== C:\Users\Patrick\AppData\Local\Temp ==== ====== Java Cache ===== ====== C:\Windows\SysWOW64 ===== 2013-12-23 18:40:47 4017040D75EA2163A8895F433D66A418 48617 ----a-w- C:\Windows\SysWOW64\ExampleCodeGeneratedCS.skm 2013-12-23 18:40:47 3EC8A60CBDAEB321A15A3740DD582F5C 45710 ----a-w- C:\Windows\SysWOW64\ExampleCodeGeneratedVB.skm ====== C:\Windows\SysWOW64\drivers ===== ====== C:\Windows\Sysnative ===== 2014-01-05 15:43:21 DA51F4458AB2A90AB60E1B9B2418523C 419064 ----a-w- C:\Windows\Sysnative\FNTCACHE.DAT ====== C:\Windows\Sysnative\drivers ===== 2013-12-11 08:21:34 E0D3CD5841E5C7BE7B94BA946AF1E498 116736 ----a-w- C:\Windows\Sysnative\drivers\drmk.sys 2013-12-11 08:21:34 1E0B4CBBA91C6B041A14ECC2186F7E24 230400 ----a-w- C:\Windows\Sysnative\drivers\portcls.sys ====== C:\Windows\Tasks ====== 2014-01-03 17:17:11 EACFDC2A18E1A1819F856D618F8AB2DC 4054 ----a-w- C:\Windows\Sysnative\Tasks\GoogleUpdateTaskMachineUA 2014-01-03 17:17:11 693A73798049B7630E885300434BAA9B 1058 ----a-w- C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-01-03 17:17:10 E64E6F1BB2CE7FF7CC995FFF67FC4082 3802 ----a-w- C:\Windows\Sysnative\Tasks\GoogleUpdateTaskMachineCore 2014-01-03 17:17:10 62B56018EC1B1521274DD0C3AFAC820B 1054 ----a-w- C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job ====== C:\Windows\Temp ====== ======= C:\Program Files ===== 2014-01-03 17:17:35 -------- d-----w- C:\Program Files\Google 2013-12-06 16:15:44 -------- d-----w- C:\Program Files\Unlocker ======= C:\PROGRA~2 ===== 2014-01-05 10:18:57 -------- d-----w- C:\PROGRA~2\Bit Che ======= C: ===== ====== C:\Users\Patrick\AppData\Roaming ====== 2014-01-05 10:18:57 -------- d-----w- C:\Users\Patrick\AppData\Roaming\Convivea 2014-01-05 09:59:41 162E29992374DDAF5868FA2B0B07EA17 109688 ----a-w- C:\Users\Patrick\AppData\Local\GDIPFONTCACHEV1.DAT 2014-01-03 11:51:50 -------- d-----w- C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp 2014-01-03 11:51:50 -------- d-----w- C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp 2014-01-03 11:51:50 -------- d-----w- C:\Users\UpdatusUser\AppData\Local\Temp 2014-01-03 11:51:50 -------- d-----w- C:\Users\Default\AppData\Local\Temp 2014-01-03 11:51:50 -------- d-----w- C:\Users\Default User\AppData\Local\Temp 2014-01-03 11:51:49 -------- d-----w- C:\Users\Patrick\AppData\Local\Temp 2013-12-27 15:50:04 -------- d-----w- C:\Users\Patrick\AppData\Roaming\Groovedown_Uninstall 2013-12-23 18:38:32 -------- d-----w- C:\Users\Patrick\AppData\Roaming\Petrax Software 2013-12-11 09:39:26 -------- d-----w- C:\Users\Patrick\AppData\Roaming\GetRightToGo 2013-12-06 16:15:44 -------- d-----w- C:\Users\Patrick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Unlocker ====== C:\Users\Patrick ====== 2014-01-05 10:18:59 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bit Che 2014-01-03 17:17:26 -------- d-----w- C:\ProgramData\Google 2014-01-02 17:08:33 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Orbit ====== C: exe-files == 2014-01-05 10:18:58 B021B9A818F7A6EE120AEA2D6FAB0BBD 428033 ----a-w- C:\Program Files (x86)\Bit Che\Bit_Che.exe 2014-01-05 10:18:57 EF3A5A022D46EF95D2C433A39612CA65 19456 ----a-w- C:\Users\Patrick\AppData\Roaming\Convivea\Bit_Che\2\languages\compare.exe 2014-01-05 10:18:57 C4E433F60F728C66EBEB11D50538BE9E 819464 ----a-w- C:\Program Files (x86)\Bit Che\unins000.exe 2014-01-03 17:36:22 6DD139BF3D3FEC03D7344FD9ABFB189B 401488 ----a-w- C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarUser_64_B8EC3A3F9520668F.exe 2014-01-03 17:36:18 BB4F6465EEB9ACAA5C60C36983740219 310352 ----a-w- C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarUser_32_4814EB429669E41D.exe 2014-01-03 17:36:14 B9D8842FF3EDAC918039C6F62F322E9A 1073232 ----a-w- C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarManager_08875ABF44579E20.exe 2014-01-03 17:35:37 A30351F539D71D6199BD2295CC234E96 531424 ----a-w- C:\Program Files (x86)\Google\Update\Download\{F69EABDD-A4BB-4555-BE7E-1EA5F59BBA24}\7.5.4601.54\GoogleToolbarInstaller_updater_signed.exe 2014-01-03 17:28:11 A91E39F475360E4C5C813EA845540644 17939808 ----a-w- C:\Program Files (x86)\Google\Update\Download\{4DC8B4CA-1BDA-483E-B5FA-D3C12E15B62D}\31.0.1650.63\31.0.1650.63_29.0.1547.66_chrome_updater.exe 2014-01-03 17:22:42 CA0A340ABCF0C14A09691CBC90186AB4 51080 ----atw- C:\Program Files (x86)\Google\Update\1.3.22.3\GoogleUpdateBroker.exe 2014-01-03 17:22:42 600B1A4BCC0823A96DC7B86F005ADBB8 51080 ----atw- C:\Program Files (x86)\Google\Update\1.3.22.3\GoogleUpdateOnDemand.exe 2014-01-03 17:22:41 C98E0215F7B65F0DDEE0591BD57EDFA6 847128 ----a-w- C:\Program Files (x86)\Google\Update\1.3.22.3\GoogleUpdateSetup.exe 2014-01-03 17:22:35 9CCBA5E2489E603BB1578D1D541252A8 273800 ----atw- C:\Program Files (x86)\Google\Update\1.3.22.3\GoogleCrashHandler64.exe 2014-01-03 17:22:35 465680BDE344CE4FF6646626AA3A9125 223112 ----atw- C:\Program Files (x86)\Google\Update\1.3.22.3\GoogleCrashHandler.exe 2014-01-03 17:22:33 506708142BC63DABA64F2D3AD1DCD5BF 116648 ----atw- C:\Program Files (x86)\Google\Update\1.3.22.3\GoogleUpdate.exe 2014-01-03 17:22:28 C98E0215F7B65F0DDEE0591BD57EDFA6 847128 ----a-w- C:\Program Files (x86)\Google\Update\Download\{430FD4D0-B729-4F61-AA34-91526481799D}\1.3.22.3\GoogleUpdateSetup.exe 2014-01-03 17:18:08 CB139AE37B93E21CD858D748B3DF0EEA 34509664 ----atw- C:\Program Files (x86)\Google\Update\Download\{8A69D345-D564-463C-AFF1-A69D9E530F96}\29.0.1547.66\chrome_installer.exe 2014-01-03 17:17:35 5D61BE7DB55B026A5D61A3EED09D0EAD 39408 ----a-w- C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe 2014-01-03 17:17:32 BB4F6465EEB9ACAA5C60C36983740219 310352 ----a-w- C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe 2014-01-03 17:17:32 6DD139BF3D3FEC03D7344FD9ABFB189B 401488 ----a-w- C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_64.exe 2014-01-03 17:17:31 4B78E9AE06F7C310E30EE2FA5B7EBC3C 1721296 ----a-w- C:\Program Files (x86)\Google\Google Toolbar\Component\SearchWithGoogleUpdate_C993F490EED40C1B.exe 2014-01-03 17:17:30 4BEAF576CB43358C4DB9F45AC7C09CDB 194032 ----a-w- C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleUpdaterService_B33FC4DD36A473C6.exe 2014-01-03 17:17:30 1F2AFAB903C0D48480561F3BBD4539C2 739640 ----a-w- C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleUpdateSetup_5CC4B0F53D73AD88.exe 2014-01-03 17:17:17 2040B57C08F7A97E4E44ACB324647CF2 6110688 ----atw- C:\Program Files (x86)\Google\Update\Download\{F69EABDD-A4BB-4555-BE7E-1EA5F59BBA24}\0.0.0.0\googletoolbarinstaller_full_signed.exe 2014-01-03 17:17:09 506708142BC63DABA64F2D3AD1DCD5BF 116648 ----atw- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe === C: other files == 2013-12-31 16:06:42 30DE744AC7A34CC3C7C049881335DA65 101786 ----a-w- C:\Users\Patrick\AppData\Roaming\Orbit\AdConfig\TipsAd.zip 2013-12-31 16:06:41 B1F82EEDD24E43AAFC0241E1DEC4E964 108917 ----a-w- C:\Users\Patrick\AppData\Roaming\Orbit\AdConfig\LeftAd.zip ==== Startup Registry Enabled ====================== [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun" [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun" [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce] "mctadmin"="C:\Windows\System32\mctadmin.exe" [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce] "mctadmin"="C:\Windows\System32\mctadmin.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NBAgent"="C:\Program Files (x86)\Nero\Nero 11\Nero BackItUp\NBAgent.exe /WinStart" "SDTray"="C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe" ==== Startup Registry Enabled x64 ====================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RtHDVCpl"="C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe " "Skytel"="C:\Program Files\Realtek\Audio\HDA\Skytel.exe " "MSC"="C:\Program Files\Microsoft Security Client\msseces.exe -hide -runkey" ==== Startup Registry Disabled ====================== [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run-] "Adobe ARM"="\"C:\\Program Files (x86)\\Common Files\\Adobe\\ARM\\1.0\\AdobeARM.exe\"" "SunJavaUpdateSched"="\"C:\\Program Files (x86)\\Common Files\\Java\\Java Update\\jusched.exe\"" ==== Startup Registry Disabled x64 ====================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\CanonMyPrinter] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="CanonMyPrinter" "hkey"="HKLM" "command"="C:\\Program Files\\Canon\\MyPrinter\\BJMyPrt.exe /logon" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\CanonSolutionMenu] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="CanonSolutionMenu" "hkey"="HKLM" "command"="C:\\Program Files (x86)\\Canon\\SolutionMenu\\CNSLMAIN.exe /logon" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\GrooveMonitor] "key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="GrooveMonitor" "hkey"="HKLM" "command"="\"C:\\Program Files (x86)\\Microsoft Office\\Office12\\GrooveMonitor.exe\"" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^CodecPackTrayMenu.lnk] "item"="CodecPackTrayMenu" "path"="C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\CodecPackTrayMenu.lnk" "backup"="C:\\Windows\\pss\\CodecPackTrayMenu.lnk.CommonStartup" "backupExtension"=".CommonStartup" "command"="C:\\Windows\\SysWOW64\\C2MP\\TrayMenu.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^CodecPackUpdateChecker.lnk] "item"="CodecPackUpdateChecker" "path"="C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\CodecPackUpdateChecker.lnk" "backup"="C:\\Windows\\pss\\CodecPackUpdateChecker.lnk.CommonStartup" "backupExtension"=".CommonStartup" "command"="C:\\Windows\\SysWOW64\\C2MP\\UPDATE~1.EXE" ==== Task Scheduler Jobs ====================== C:\Windows\tasks\Adobe Flash Player Updater.job --a------ C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [11/12/2013 10:10] C:\Windows\tasks\GoogleUpdateTaskMachineCore.job --a------ C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [03/01/2014 18:17] C:\Windows\tasks\GoogleUpdateTaskMachineUA.job --a------ C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [03/01/2014 18:17] ==== Other Scheduled Tasks ====================== "C:\Windows\SysNative\tasks\0" [c:\program files (x86)\internet explorer\iexplore.exe] "C:\Windows\SysNative\tasks\4899" [wscript.exe C:\Users\Patrick\AppData\Local\Temp\launchie.vbs //B] "C:\Windows\SysNative\tasks\Adobe Flash Player Updater" [C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe] "C:\Windows\SysNative\tasks\Adobe-online actualiseringsprogramma" [C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe] "C:\Windows\SysNative\tasks\CCleanerSkipUAC" ["C:\Program Files\CCleaner\CCleaner.exe"] "C:\Windows\SysNative\tasks\CreateChoiceProcessTask" [C:\Windows\System32\browserchoice.exe] "C:\Windows\SysNative\tasks\GoogleUpdateTaskMachineCore" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe] "C:\Windows\SysNative\tasks\GoogleUpdateTaskMachineUA" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe] "C:\Windows\SysNative\tasks\Java Update Scheduler" [C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe] "C:\Windows\SysNative\tasks\TuneUpUtilities_Task_BkGndMaintenance2012" [C:\Program Files (x86)\TuneUp Utilities 2012\OneClick.exe] "C:\Windows\SysNative\tasks\User_Feed_Synchronization-{545981D7-FB41-46E7-B4B3-EB3880D0449E}" [C:\Windows\system32\msfeedssync.exe] "C:\Windows\SysNative\tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask" [%systemroot%\system32\sc.exe start osppsvc] "C:\Windows\SysNative\tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates" ["C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe"] "C:\Windows\SysNative\tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization" ["C:\Program Files (x86)\Spybot - Search & Destroy 2\SDImmunize.exe"] "C:\Windows\SysNative\tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system" ["C:\Program Files (x86)\Spybot - Search & Destroy 2\SDScan.exe"] ==== HijackThis Entries ====================== C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe F2 - REG:system.ini: UserInit=userinit.exe, O2 - BHO: Increase performance and video formats for your HTML5