Zoek.exe v5.0.0.0 Updated 07-March-2014 Tool run by Brokken on wo 26/03/2014 at 16:32:53,38. Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x64 Running in: Normal Mode Internet Access Detected Launched: D:\Users\Brokken\Downloads\zoek.exe [Scan all users] [Script inserted] ==== System Restore Info ====================== 26/03/2014 16:35:59 Zoek.exe System Restore Point Created Succesfully. ==== Empty Folders Check ====================== C:\PROGRA~2\LyricsMonkey deleted successfully C:\PROGRA~2\OnlineHD.TV deleted successfully C:\PROGRA~2\SafeSaver deleted successfully C:\PROGRA~2\TornTV.com deleted successfully C:\PROGRA~2\VST deleted successfully C:\PROGRA~2\WebSearch deleted successfully C:\PROGRA~2\XingHaoLyrics deleted successfully C:\PROGRA~2\COMMON~1\Symantec Shared deleted successfully C:\PROGRA~3\4Sync deleted successfully C:\PROGRA~3\B1 Free Archiver deleted successfully C:\PROGRA~3\Babylon deleted successfully C:\PROGRA~3\blekko toolbars deleted successfully C:\PROGRA~3\Oracle deleted successfully C:\Users\Brokken\AppData\Roaming\PerformerSoft deleted successfully C:\Users\Brokken\AppData\Roaming\SendSpace deleted successfully C:\Users\Brokken\AppData\Roaming\SynthMaker deleted successfully C:\Users\Brokken\AppData\Roaming\Systweak deleted successfully C:\Users\Brokken\AppData\Roaming\Windows Live Writer deleted successfully C:\Users\Brokken\AppData\Local\Deals Plugin Extension deleted successfully C:\Users\Brokken\AppData\Local\Lollipop deleted successfully C:\Users\Brokken\AppData\Local\PackageAware deleted successfully C:\Users\Brokken\AppData\Local\SpacialAudio deleted successfully ==== Deleting CLSID Registry Keys ====================== HKEY_USERS\S-1-5-21-1256367049-2053008340-3862287469-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{3ad798d0-4642-4c55-bc14-cfe7dd19e0d1} deleted successfully HKEY_USERS\S-1-5-21-1256367049-2053008340-3862287469-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{dc4a8395-7bea-47fb-89cb-34aef53c19b2} deleted successfully HKEY_USERS\S-1-5-21-1256367049-2053008340-3862287469-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{dc4a8395-7bea-47fb-89cb-34aef53c19b2} deleted successfully HKEY_USERS\S-1-5-21-1256367049-2053008340-3862287469-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{6DB5C3C9-CFD6-259E-4126-BC84C60E5634} deleted successfully HKEY_USERS\S-1-5-21-1256367049-2053008340-3862287469-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{6DB5C3C9-CFD6-259E-4126-BC84C60E5634} deleted successfully HKEY_USERS\S-1-5-21-1256367049-2053008340-3862287469-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F70CF963-A244-3551-B441-0C5D1DBE8F61} deleted successfully HKEY_USERS\S-1-5-21-1256367049-2053008340-3862287469-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{F70CF963-A244-3551-B441-0C5D1DBE8F61} deleted successfully HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{dc4a8395-7bea-47fb-89cb-34aef53c19b2} deleted successfully HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{6DB5C3C9-CFD6-259E-4126-BC84C60E5634} deleted successfully HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{6DB5C3C9-CFD6-259E-4126-BC84C60E5634} deleted successfully HKEY_CLASSES_ROOT\CLSID\{6DB5C3C9-CFD6-259E-4126-BC84C60E5634} deleted successfully HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{6DB5C3C9-CFD6-259E-4126-BC84C60E5634} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6DB5C3C9-CFD6-259E-4126-BC84C60E5634} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6DB5C3C9-CFD6-259E-4126-BC84C60E5634} deleted successfully HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F70CF963-A244-3551-B441-0C5D1DBE8F61} deleted successfully HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F70CF963-A244-3551-B441-0C5D1DBE8F61} deleted successfully HKEY_CLASSES_ROOT\CLSID\{F70CF963-A244-3551-B441-0C5D1DBE8F61} deleted successfully HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{F70CF963-A244-3551-B441-0C5D1DBE8F61} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F70CF963-A244-3551-B441-0C5D1DBE8F61} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F70CF963-A244-3551-B441-0C5D1DBE8F61} deleted successfully ==== Deleting CLSID Registry Values ====================== HKEY_USERS\S-1-5-21-1256367049-2053008340-3862287469-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{3ad798d0-4642-4c55-bc14-cfe7dd19e0d1} deleted successfully HKEY_USERS\S-1-5-21-1256367049-2053008340-3862287469-1000\Software\Microsoft\Internet Explorer\URLSearchHooks\{3ad798d0-4642-4c55-bc14-cfe7dd19e0d1} deleted successfully HKEY_USERS\S-1-5-21-1256367049-2053008340-3862287469-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{dc4a8395-7bea-47fb-89cb-34aef53c19b2} deleted successfully HKEY_USERS\S-1-5-21-1256367049-2053008340-3862287469-1000\Software\Microsoft\Internet Explorer\URLSearchHooks\{dc4a8395-7bea-47fb-89cb-34aef53c19b2} deleted successfully HKEY_USERS\S-1-5-21-1256367049-2053008340-3862287469-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{872b5b88-9db5-4310-bdd0-ac189557e5f5} deleted successfully HKEY_USERS\S-1-5-21-1256367049-2053008340-3862287469-1000\Software\Microsoft\Internet Explorer\URLSearchHooks\{872b5b88-9db5-4310-bdd0-ac189557e5f5} deleted successfully ==== Deleting Services ====================== HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Aqhmnkph deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Aqhmnkph deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Niizjphf deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Niizjphf deleted successfully ==== Registry Fix Code x64 ====================== Windows Registry Editor Version 5.00 [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6DB5C3C9-CFD6-259E-4126-BC84C60E5634}] [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F70CF963-A244-3551-B441-0C5D1DBE8F61}] [-HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6DB5C3C9-CFD6-259E-4126-BC84C60E5634}] [-HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F70CF963-A244-3551-B441-0C5D1DBE8F61}] [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SearchSettings] [HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run] "Browser companion helper"=- "PlusService"=- "SweetIM"=- "MessengerPlusForSkypeService"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"=-