Zoek.exe v5.0.0.0 Updated 16-June-2014 Tool run by j p on wo 18-06-2014 at 11:23:47,61. Microsoft® Windows Vista™ Home Premium 6.0.6002 Service Pack 2 x86 Running in: Normal Mode Internet Access Detected Launched: C:\Users\j p\Desktop\zoek.exe [Scan all users] [Script inserted] [Checkboxes used] ==== Older Logs ====================== C:\zoek-results2014-06-17-200537.log 841 bytes C:\zoek-results2014-06-17-211518.log 25846 bytes ==== Deleting CLSID Registry Keys ====================== ==== Deleting CLSID Registry Values ====================== ==== Deleting Services ====================== ==== Deleting Files \ Folders ====================== "C:\Users\j p~1\AppData\Roaming\Mozilla\Firefox\Profiles\38u81qaq.default\extensions\YoutubeDownloader@PeterOlayev.com.xpi" not found C:\Users\j p\AppData\Roaming\ACEStream\extensions\firefox\magicplayer@torrentstream.org deleted "C:\Users\j p\AppData\Roaming\ACEStream\extensions\chrome_new\magicplayer.crx" deleted ==== Files Recently Created / Modified ====================== ====== C:\Windows ==== ====== C:\Users\jP~1\AppData\Local\Temp ==== ====== Java Cache ===== ====== C:\Windows\system32 ===== 2014-06-17 20:35:11 C6A09FA46EF0123EE5485999D6D9607E 264600 ----a-w- C:\Windows\System32\javaws.exe 2014-06-17 20:35:00 9DFF2C8F4CE048322FCB10D38820D510 176024 ----a-w- C:\Windows\System32\javaw.exe 2014-06-17 20:35:00 743524979EF5F33BDB4DDEE63FD6C042 176024 ----a-w- C:\Windows\System32\java.exe 2014-06-17 20:33:57 EAE394724CDC4887E3CA29579F8B7DDE 96664 ----a-w- C:\Windows\System32\WindowsAccessBridge.dll 2014-06-12 07:09:46 FB3E5FD7F74BFC301AD3FB7DE670EDCB 502784 ----a-w- C:\Windows\System32\usp10.dll 2014-06-12 07:09:44 D0D44370770D491E6BA472C855883422 1248768 ----a-w- C:\Windows\System32\msxml3.dll 2014-06-12 07:09:44 1E06779EDB55D035DD3F4A2B7432A291 1401344 ----a-w- C:\Windows\System32\msxml6.dll 2014-06-12 07:09:42 B2D65154D4D36D6CA22BB586C016C1C1 142848 ----a-w- C:\Windows\System32\ieUnatt.exe 2014-06-12 07:09:42 AA5456C16D7F4B73177FD46AD63A12C4 1796096 ----a-w- C:\Windows\System32\iertutil.dll 2014-06-12 07:09:42 9F5AC4090D7C9F2591060DAC310FD294 1106432 ----a-w- C:\Windows\System32\urlmon.dll 2014-06-12 07:09:42 74DD13DF9DC59CCC5AE5528ECFA29BE9 10752 ----a-w- C:\Windows\System32\msfeedssync.exe 2014-06-12 07:09:42 0D7B6A0829874B057FF9D35F612B44F5 11776 ----a-w- C:\Windows\System32\mshta.exe 2014-06-12 07:09:41 BA7CC0D3170EB03FA610BA8EA3A01E9D 65536 ----a-w- C:\Windows\System32\jsproxy.dll 2014-06-12 07:09:41 B50E34870FC8F8CA79BCC2DC3183D691 421376 ----a-w- C:\Windows\System32\vbscript.dll 2014-06-12 07:09:41 60D2396F470C110B7FAB1CFA4AC0D34B 1427968 ----a-w- C:\Windows\System32\inetcpl.cpl 2014-06-12 07:09:41 4439087A375EFDD297DC470C3214D7D6 41472 ----a-w- C:\Windows\System32\msfeedsbs.dll 2014-06-12 07:09:41 0A3EF805B406103971F27B9597EB98BC 231936 ----a-w- C:\Windows\System32\url.dll 2014-06-12 07:09:38 CFD26829131439B71D0109F9D5345573 1129472 ----a-w- C:\Windows\System32\wininet.dll 2014-06-12 07:09:38 947DA106EE001900969D42425FBDA183 717824 ----a-w- C:\Windows\System32\jscript.dll 2014-06-12 07:09:38 61F727795CAA98C3FCDB48379B78E370 607744 ----a-w- C:\Windows\System32\msfeeds.dll 2014-06-12 07:09:38 32FE42E13195DEAF78D1E348F51A5AEE 353792 ----a-w- C:\Windows\System32\dxtmsft.dll 2014-06-12 07:09:38 23330909BD92B7611815365559860952 1810432 ----a-w- C:\Windows\System32\jscript9.dll 2014-06-12 07:09:37 3829D7D8B098F87C454E468DCAAE4912 2382848 ----a-w- C:\Windows\System32\mshtml.tlb 2014-06-12 07:09:36 2DCB8AEC38AE1427CB1CFE2432D05107 223232 ----a-w- C:\Windows\System32\dxtrans.dll 2014-06-12 07:09:36 148B2F103FD322A4B8AEB82D7B35D0AF 176640 ----a-w- C:\Windows\System32\ieui.dll 2014-06-12 07:09:35 AD2C67A381CC7148BB98A66BB04DDF5B 9711104 ----a-w- C:\Windows\System32\ieframe.dll 2014-06-12 07:09:35 9000CE8689BD16819AF8AFDB83B94CCE 73216 ----a-w- C:\Windows\System32\mshtmled.dll 2014-06-12 07:09:33 B7363143940197BD9F16FD957B4F8131 12356608 ----a-w- C:\Windows\System32\mshtml.dll ====== C:\Windows\system32\drivers ===== 2014-06-12 07:09:45 C7B0746FCD576D7EEBA6A2530B0B2966 905664 ----a-w- C:\Windows\System32\drivers\tcpip.sys ====== C:\Windows\Tasks ====== 2014-06-15 10:00:51 FDB5847AD367D3D3D3B037FA3655CDD8 562 ----a-w- C:\Windows\Tasks\MATLAB R2014a Startup Accelerator.job 2014-06-15 10:00:51 343150884F8B8C48C426AA1353947018 3740 ----a-w- C:\Windows\system32\Tasks\MATLAB R2014a Startup Accelerator ====== C:\Windows\Temp ====== ======= C:\Program Files ===== 2014-06-17 18:05:49 -------- d-----w- C:\Program Files\trend micro ======= C: ===== ====== C:\Users\j p\AppData\Roaming ====== 2014-06-17 21:05:55 -------- d-----w- C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp 2014-06-17 21:05:55 -------- d-----w- C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp 2014-06-17 21:05:55 -------- d-----w- C:\Users\Default\AppData\Local\Temp 2014-06-17 21:05:55 -------- d-----w- C:\Users\Default User\AppData\Local\Temp 2014-06-17 21:05:54 -------- d-----w- C:\Users\j p\AppData\Local\Temp 2014-06-15 10:07:25 -------- d-----w- C:\Users\j p\AppData\Roaming\Subversion 2014-06-15 10:07:19 -------- d-----w- C:\Users\j p\AppData\Local\MathWorks 2014-06-15 10:04:46 -------- d-----w- C:\Users\j p\AppData\Roaming\MathWorks 2014-05-29 19:45:32 -------- d-----w- C:\Users\j p\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Albelli Fotoboeken 2014-05-29 19:45:30 -------- d-----w- C:\Users\j p\AppData\Local\Albelli Fotoboeken ====== C:\Users\j p ====== 2014-06-17 20:35:16 -------- d-----w- C:\ProgramData\Oracle 2014-06-17 20:31:32 1BCD116BCE8235A031949FE58AA489D0 918952 ----a-w- C:\Users\j p\Downloads\chromeinstall-7u60.exe 2014-06-17 18:05:12 8685FAF50C04F9A9C2F56FF64B0B7ACB 1107968 ----a-w- C:\Users\j p\Downloads\RSIT.exe 2014-06-16 18:28:50 -------- d-----w- C:\ProgramData\HitmanPro 2014-05-29 17:43:19 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN ====== C: exe-files == 2014-06-17 20:35:11 C6A09FA46EF0123EE5485999D6D9607E 264600 ----a-w- C:\Windows\System32\javaws.exe 2014-06-17 20:35:00 9DFF2C8F4CE048322FCB10D38820D510 176024 ----a-w- C:\Windows\System32\javaw.exe 2014-06-17 20:35:00 743524979EF5F33BDB4DDEE63FD6C042 176024 ----a-w- C:\Windows\System32\java.exe 2014-06-17 20:31:48 3842C46F2FBC7522EF625F1833530804 145408 ----a-w- C:\Users\j p\AppData\LocalLow\Sun\Java\jre1.7.0_60\lzma.exe 2014-06-17 20:31:32 1BCD116BCE8235A031949FE58AA489D0 918952 ----a-w- C:\Users\j p\Downloads\chromeinstall-7u60.exe 2014-06-17 18:05:51 9A2347903D6EDB84C10F288BC0578C1C 388608 ----a-w- C:\Program Files\trend micro\j p.exe 2014-06-17 18:05:12 8685FAF50C04F9A9C2F56FF64B0B7ACB 1107968 ----a-w- C:\Users\j p\Downloads\RSIT.exe 2014-06-14 16:27:23 DF61864BA778845C6E725F7BF1EAEB0E 2675280 ----a-w- C:\Program Files\Google\Update\Download\{4DC8B4CA-1BDA-483E-B5FA-D3C12E15B62D}\35.0.1916.153\35.0.1916.153_35.0.1916.114_chrome_updater.exe 2014-06-12 07:09:42 D14CBA888EF2A88C28CB5E6396A295DA 22528 ----a-w- C:\Program Files\Internet Explorer\ExtExport.exe 2014-06-12 07:09:42 B2D65154D4D36D6CA22BB586C016C1C1 142848 ----a-w- C:\Windows\System32\ieUnatt.exe 2014-06-12 07:09:42 74DD13DF9DC59CCC5AE5528ECFA29BE9 10752 ----a-w- C:\Windows\System32\msfeedssync.exe 2014-06-12 07:09:42 0D7B6A0829874B057FF9D35F612B44F5 11776 ----a-w- C:\Windows\System32\mshta.exe 2014-06-12 07:09:40 7BA5B7DEDE25D44F3E664D5BA067E3CD 758000 ----a-w- C:\Program Files\Internet Explorer\iexplore.exe 2014-06-12 07:09:38 77AEB4008A5E1015599A4DC6AE50C33B 223232 ----a-w- C:\Program Files\Internet Explorer\ielowutil.exe 2014-06-12 07:09:37 054E45A74734CDBDDEFB503CBBA0E0DF 469504 ----a-w- C:\Program Files\Internet Explorer\ieinstal.exe === C: other files == 2014-06-12 07:09:45 C7B0746FCD576D7EEBA6A2530B0B2966 905664 ----a-w- C:\Windows\System32\drivers\tcpip.sys ==== Startup Registry Enabled ====================== [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run] "WindowsWelcomeCenter"="rundll32.exe oobefldr.dll,ShowWelcomeCenter" "Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /detectMem" [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run] "WindowsWelcomeCenter"="rundll32.exe oobefldr.dll,ShowWelcomeCenter" "Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /detectMem" [HKEY_USERS\S-1-5-21-174054273-4147652212-1534228181-1003\Software\Microsoft\Windows\CurrentVersion\Run] "ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup" "Akamai NetSession Interface"="C:\Users\j p\AppData\Local\Akamai\netsession_win.exe" "DAEMON Tools Lite"="D:\Program Files\DAEMON Tools Lite\DTLite.exe -autorun" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "AVG_UI"="D:\Program Files\AVG\AVG2014\avgui.exe /TRAYONLY" "ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe -start" "SecureW2 Tray"="C:\Program Files\SecureW2\sw2_tray.exe" "Adobe ARM"="C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" "RtHDVCpl"="RtHDVCpl.exe" "SunJavaUpdateSched"="C:\Program Files\Common Files\Java\Java Update\jusched.exe" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup" "Akamai NetSession Interface"="C:\Users\j p\AppData\Local\Akamai\netsession_win.exe" "DAEMON Tools Lite"="D:\Program Files\DAEMON Tools Lite\DTLite.exe -autorun" ==== Startup Registry Disabled ====================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\AceStream] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="AceStream" "hkey"="HKCU" "command"="C:\\Users\\j p\\AppData\\Roaming\\ACEStream\\engine\\ace_engine.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Adobe ARM] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="Adobe ARM" "hkey"="HKLM" "command"="\"C:\\Program Files\\Common Files\\Adobe\\ARM\\1.0\\AdobeARM.exe\"" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Akamai NetSession Interface] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="Akamai NetSession Interface" "hkey"="HKCU" "command"="\"C:\\Users\\j p\\AppData\\Local\\Akamai\\netsession_win.exe\"" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Autodesk Sync] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="Autodesk Sync" "hkey"="HKLM" "command"="C:\\Program Files\\Autodesk\\Autodesk Sync\\AdSync.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\DAEMON Tools Lite] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="DAEMON Tools Lite" "hkey"="HKCU" "command"="\"D:\\Program Files\\DAEMON Tools Lite\\DTLite.exe\" -autorun" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\GoogleDriveSync] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="GoogleDriveSync" "hkey"="HKCU" "command"="\"C:\\Program Files\\Google\\Drive\\googledrivesync.exe\" /autostart" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\GrooveMonitor] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="GrooveMonitor" "hkey"="HKLM" "command"="\"D:\\Program Files\\Microsoft Office\\Office12\\GrooveMonitor.exe\"" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\LanguageShortcut] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="LanguageShortcut" "hkey"="HKLM" "command"="\"C:\\Program Files\\CyberLink\\PowerDVD\\Language\\Language.exe\"" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\NvCplDaemon] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="NvCplDaemon" "hkey"="HKLM" "command"="RUNDLL32.EXE C:\\Windows\\system32\\NvCpl.dll,NvStartup" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\NvMediaCenter] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="NvMediaCenter" "hkey"="HKLM" "command"="RUNDLL32.EXE C:\\Windows\\system32\\NvMcTray.dll,NvTaskbarInit" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\RemoteControl] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="RemoteControl" "hkey"="HKLM" "command"="\"C:\\Program Files\\CyberLink\\PowerDVD\\PDVDServ.exe\"" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\RtHDVCpl] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="RtHDVCpl" "hkey"="HKLM" "command"="RtHDVCpl.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\SecureW2 Tray] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="SecureW2 Tray" "hkey"="HKLM" "command"="C:\\Program Files\\SecureW2\\sw2_tray.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\SunJavaUpdateSched] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="SunJavaUpdateSched" "hkey"="HKLM" "command"="\"C:\\Program Files\\Common Files\\Java\\Java Update\\jusched.exe\"" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\SynTPEnh] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="SynTPEnh" "hkey"="HKLM" "command"="C:\\Program Files\\Synaptics\\SynTP\\SynTPEnh.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\uTorrent] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="uTorrent" "hkey"="HKCU" "command"="\"C:\\Users\\j p\\AppData\\Roaming\\uTorrent\\uTorrent.exe\" /MINIMIZED" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Windows Defender] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="Windows Defender" "hkey"="HKLM" "command"="%ProgramFiles%\\Windows Defender\\MSASCui.exe -hide" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Bluetooth.lnk] "path"="C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\Bluetooth.lnk" "backup"="C:\\Windows\\pss\\Bluetooth.lnk.CommonStartup" "backupExtension"=".CommonStartup" "command"="C:\\PROGRA~1\\WIDCOMM\\BLUETO~1\\BTTray.exe " "item"="Bluetooth" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\AdobeARMservice] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\AdobeFlashPlayerUpdateSvc] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\AgereModemAudio] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\Autodesk Content Service] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\EvtEng] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\FLEXnet Licensing Service] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\LightScribeService] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\nvsvc] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\RegSrvc] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\RichVideo] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\Sony PC Companion] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\SW2SVC] ==== Task Scheduler Jobs ====================== C:\Windows\tasks\Adobe Flash Player Updater.job --a------ C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [01-01-2014 17:10] C:\Windows\tasks\GoogleUpdateTaskMachineCore.job --a------ C:\Program Files\Google\Update\GoogleUpdate.exe [01-11-2013 00:52] C:\Windows\tasks\GoogleUpdateTaskMachineUA.job --a------ [Undetermined Task] C:\Windows\tasks\MATLAB R2014a Startup Accelerator.job --a------ C:\Program Files\MATLAB\R2014a\bin\win32\MATLABStartupAccelerator.exe [] ==== Other Scheduled Tasks ====================== "C:\Windows\system32\tasks\Adobe Flash Player Updater" [C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe] "C:\Windows\system32\tasks\CCleanerSkipUAC" ["C:\Program Files\CCleaner\CCleaner.exe"] "C:\Windows\system32\tasks\EasyDisplayMgr" ["C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe"] "C:\Windows\system32\tasks\EasySpeedUpManager" [%programfiles%\SAMSUNG\EasySpeedUpManager\EasySpeedUpManager.exe] "C:\Windows\system32\tasks\GoogleUpdateTaskMachineCore" [C:\Program Files\Google\Update\GoogleUpdate.exe] "C:\Windows\system32\tasks\GoogleUpdateTaskMachineUA" [C:\Program Files\Google\Update\GoogleUpdate.exe] "C:\Windows\system32\tasks\MATLAB R2014a Startup Accelerator" [D:\Program Files\MATLAB\R2014a\bin\win32\MATLABStartupAccelerator.exe] "C:\Windows\system32\tasks\SecureW2 Task" [C:\Program Files\SecureW2\sw2_tray.exe] ==== Firefox Extensions Registry ====================== [HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions] "{20a82645-c095-46ed-80e3-08825760534b}"="C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension" [27-02-2013 22:37] [HKEY_CURRENT_USER\Software\Mozilla\Firefox\Extensions] "magicplayer@torrentstream.org"="C:\Users\j p\AppData\Roaming\ACEStream\extensions\firefox\magicplayer@torrentstream.org" [] ==== Firefox Extensions ====================== ProfilePath: C:\Users\jP~1\AppData\Roaming\Mozilla\Firefox\Profiles\38u81qaq.default - Microsoft .NET Framework Assistant - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension - Undetermined - C:\Users\j p\AppData\Roaming\ACEStream\extensions\firefox\magicplayer@torrentstream.org - 1-Click YouTube Video Downloader - %ProfilePath%\extensions\YoutubeDownloader@PeterOlayev.com.xpi - Adblock Plus - %ProfilePath%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi ProfilePath: C:\Users\jP~1\AppData\Roaming\Thunderbird\Profiles\20jh02eh.default - Instrument Test - %ProfilePath%\extensions\tbtestpilot@labs.mozilla.com.xpi ==== Firefox Plugins ====================== Profilepath: C:\Users\j p\AppData\Roaming\Mozilla\Firefox\Profiles\38u81qaq.default C694F47FB5870679B9C0D8D4BE97556B - C:\Users\j p\AppData\Roaming\ACEStream\player\npace_plugin.dll - Ace Stream P2P Multimedia Plug-in 6897943E58D779D1C7CB74191931B1D5 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll - Java(TM) Platform SE 7 U60 7BF7103176DBFC80A31E275F7ED7918C - C:\Program Files\Java\jre7\bin\dtplugin\npdeployJava1.dll - Java Deployment Toolkit 7.0.600.19 14365399E83D7BC15760E8676E890C87 - C:\Program Files\Adobe\Reader 11.0\Reader\browser\nppdf32.dll - Adobe Acrobat 14365399E83D7BC15760E8676E890C87 - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll - Adobe Acrobat 4B76EFB51EC0900B6459BA0F588CE8A1 - D:\Program Files\Veetle\plugins\npVeetle.dll - Veetle TV Core A1B2B09240361031D1D794D57FC7359C - D:\Program Files\Veetle\Player\npvlc.dll - Veetle TV Player AB87EEFFD18F2BAAFC274E7075EA6C67 - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll - Windows Presentation Foundation / Windows Presentation Foundation ==== Chrome Look ====================== HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\Extensions kpckgflgdapkpabemgkielbefdildaio - C:\Users\j p\AppData\Roaming\ACEStream\extensions\chrome_new\magicplayer.crx[] ==== Chrome Fix ====================== C:\Users\j p\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_epikbiglahnndfidencpcjhnefnmooeg_0.localstorage deleted successfully C:\Users\j p\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_epikbiglahnndfidencpcjhnefnmooeg_0.localstorage-journal deleted successfully ==== Set IE to Default ====================== Old Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="https://www.google.nl/" New Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="https://www.google.nl/" ==== All HKCU SearchScopes ====================== HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" {0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC" {6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}" ==== Deleting CLSID Registry Keys ====================== ==== Deleting CLSID Registry Values ====================== HKEY_USERS\S-1-5-21-174054273-4147652212-1534228181-1003\Software\Mozilla\Firefox\Extensions\magicplayer@torrentstream.org deleted successfully ==== Deleting Registry Keys ====================== HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\Extensions\Kpckgflgdapkpabemgkielbefdildaio deleted successfully ==== Empty IE Cache ====================== C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\j p\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot ==== Empty FireFox Cache ====================== No FireFox Cache found ==== Empty Chrome Cache ====================== C:\Users\j p\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully ==== Empty All Flash Cache ====================== Flash Cache Emptied Successfully ==== Empty All Java Cache ====================== Java Cache cleared successfully ==== C:\zoek_backup content ====================== C:\zoek_backup (files=1508 folders=221 168469224 bytes) ==== Empty Temp Folders ====================== C:\Users\Default\AppData\Local\Temp emptied successfully C:\Users\Default User\AppData\Local\Temp emptied successfully C:\Users\j p\AppData\Local\Temp will be emptied at reboot C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully C:\Windows\Temp will be emptied at reboot ==== After Reboot ====================== ==== Empty Temp Folders ====================== C:\Windows\Temp successfully emptied C:\Users\jP~1\AppData\Local\Temp successfully emptied ==== Empty Recycle Bin ====================== C:\$RECYCLE.BIN successfully emptied ==== Deleting Files / Folders ====================== "C:\Users\j p\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not deleted "C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not found "C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not found "C:\Users\j p\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not deleted "C:\Program Files\AVG SafeGuard toolbar" not found "C:\Program Files\AVG SafeGuard toolbar" not found ==== EOF on wo 18-06-2014 at 11:44:59,08 ======================