Zoek.exe v5.0.0.0 Updated 26-10-2014 Tool run by giuseppe on ma 27/10/2014 at 10:26:42,13. Microsoft Windows 8.1 6.3.9600 x64 Running in: Normal Mode Internet Access Detected Launched: C:\Users\giuseppe\Downloads\zoek (7)\zoek.scr [Scan all users] [Script inserted] ==== Older Logs ====================== C:\zoek-results2014-10-26-211217.log 46396 bytes ==== Deleting CLSID Registry Keys ====================== HKEY_USERS\S-1-5-21-1687350831-1530992600-3121883764-1002\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} deleted successfully HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D3D233D5-9F6D-436C-B6C7-E63F77503B30} deleted successfully HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D3D233D5-9F6D-436C-B6C7-E63F77503B30} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} deleted successfully HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D7E97865-918F-41E4-9CD0-25AB1C574CE8} deleted successfully HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D7E97865-918F-41E4-9CD0-25AB1C574CE8} deleted successfully ==== Deleting CLSID Registry Values ====================== HKEY_USERS\S-1-5-21-1687350831-1530992600-3121883764-1002\Software\Microsoft\Internet Explorer\URLSearchHooks\{D3D233D5-9F6D-436C-B6C7-E63F77503B30} deleted successfully HKEY_USERS\S-1-5-21-1687350831-1530992600-3121883764-1002\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{D7E97865-918F-41E4-9CD0-25AB1C574CE8} deleted successfully ==== Deleting Services ====================== ==== Deleting Files \ Folders ====================== C:\Program Files (x86)\Common Files\DVDVideoSoft not found C:\Program Files (x86)\PC Speed Up not found "C:\Users\Public\Desktop\DVDVideoSoft Free Studio.lnk" not found C:\Users\giuseppe\AppData\Local\Avg2014 deleted C:\Users\Default\AppData\Roaming\IObit deleted C:\WINDOWS\SysNative\tasks\DTChk deleted C:\Users\Public\Util deleted ==== Files Recently Created / Modified ====================== ====== C:\WINDOWS ==== ====== C:\Users\giuseppe\AppData\Local\Temp ==== ====== Java Cache ===== ====== C:\WINDOWS\SysWOW64 ===== ====== C:\WINDOWS\SysWOW64\drivers ===== ====== C:\WINDOWS\Sysnative ===== ====== C:\WINDOWS\Sysnative\drivers ===== ====== C:\WINDOWS\Tasks ====== ====== C:\WINDOWS\Temp ====== ======= C:\Program Files ===== 2014-10-20 18:33:34 -------- d-----w- C:\Program Files\trend micro ======= C:\PROGRA~2 ===== ======= C: ===== ====== C:\Users\giuseppe\AppData\Roaming ====== 2014-10-26 21:13:35 -------- d-----w- C:\Users\giuseppe\AppData\Roaming\ProductData 2014-10-26 20:28:19 -------- d-----w- C:\WINDOWS\serviceprofiles\networkservice\AppData\Local\Temp 2014-10-26 20:28:19 -------- d-----w- C:\WINDOWS\serviceprofiles\Localservice\AppData\Local\Temp 2014-10-26 20:28:19 -------- d-----w- C:\Users\UpdatusUser\AppData\Local\Temp 2014-10-26 20:28:19 -------- d-----w- C:\Users\Default\AppData\Local\Temp 2014-10-26 20:28:19 -------- d-----w- C:\Users\Default User\AppData\Local\Temp 2014-10-26 20:28:18 -------- d-----w- C:\Users\giuseppe\AppData\Local\Temp 2014-10-19 18:06:01 -------- d-----w- C:\Users\giuseppe\AppData\Roaming\AVG2015 2014-10-19 18:03:57 -------- d-----w- C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Roaming\AVG2015 2014-10-19 18:03:02 -------- d-----w- C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Avg2015 2014-10-19 17:59:30 -------- d-----w- C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Avg 2014-10-19 17:59:09 -------- d-----w- C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Avg2015 2014-10-19 17:55:15 -------- d-----w- C:\Users\giuseppe\AppData\Local\Avg2015 ====== C:\Users\giuseppe ====== 2014-10-26 08:25:05 -------- d-----w- C:\WINDOWS\serviceprofiles\Localservice\winhttp 2014-10-23 19:18:03 0478ADC513968000E1F888ADE4EA83B6 4703560 ----a-w- C:\Users\giuseppe\Downloads\software_removal_tool.exe 2014-10-21 19:17:44 9C9CC9B0F81EF17AECF6F35B951FEFED 12527152 ----a-w- C:\Users\giuseppe\Desktop\mp10setupes.exe 2014-10-20 18:30:24 8045ABB21A3BDD66A48E1ED5C0F0EF6A 1222144 ----a-w- C:\Users\giuseppe\Downloads\RSITx64 (1).exe 2014-10-19 17:59:20 -------- d-----w- C:\ProgramData\AVG2015 2014-10-17 18:53:45 A61CC6EF608CBA78AA799836814E801F 86080 ----a-w- C:\Users\giuseppe\Downloads\OpenOffice-4-0-1.exe ====== C: exe-files == 2014-10-24 19:26:47 77ED3BFE03113FB4A2D674BC62080521 424248 ----a-w- C:\ProgramData\NVIDIA\Updatus\Packages\00006694\CoProc update.19000563.exe 2014-10-20 18:33:34 9A2347903D6EDB84C10F288BC0578C1C 388608 ----a-w- C:\Program Files\trend micro\giuseppe.exe === C: other files == ==== Startup Registry Enabled ====================== [HKEY_USERS\S-1-5-21-1687350831-1530992600-3121883764-1002\Software\Microsoft\Windows\CurrentVersion\Run] "Facebook Update"="C:\Users\giuseppe\AppData\Local\Facebook\Update\FacebookUpdate.exe /c /nocrashserver" "Google Update"="C:\Users\giuseppe\AppData\Local\Google\Update\GoogleUpdate.exe /c" "PCSpeedUp"="C:\Program Files (x86)\PC Speed Up\PCSUNotifier.exe" [HKEY_USERS\S-1-5-21-1687350831-1530992600-3121883764-1001\Software\Microsoft\Windows\CurrentVersion\RunOnce] "WAB Migrate"="%ProgramFiles%\Windows Mail\wab.exe /Upgrade" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "CLMLServer_For_P2G8"="C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe" "CLVirtualDrive"="C:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe /R" "RemoteControl10"="C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe" "YouCam Service"="C:\Program Files (x86)\CyberLink\YouCam\YouCamService.exe /s" "AVG_UI"="C:\Program Files (x86)\AVG\AVG2015\avgui.exe /TRAYONLY" "Online Vault"="C:\Program Files (x86)\OnlineVault\OVTray.exe" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "Facebook Update"="C:\Users\giuseppe\AppData\Local\Facebook\Update\FacebookUpdate.exe /c /nocrashserver" "Google Update"="C:\Users\giuseppe\AppData\Local\Google\Update\GoogleUpdate.exe /c" "PCSpeedUp"="C:\Program Files (x86)\PC Speed Up\PCSUNotifier.exe" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"="C:\\WINDOWS\\SysWOW64\\nvinit.dll" ==== Startup Registry Enabled x64 ====================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RtHDVCpl"="C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s" "RtHDVBg_Dolby"="C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe /FORPCEE4 " "BTMTrayAgent"="rundll32.exe C:\Program Files (x86)\Intel\Bluetooth\btmshellex.dll,TrayApp" "SynTPEnh"="%ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe " [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"="C:\\Windows\\system32\\nvinitx.dll,C:\\WINDOWS\\system32\\nvinitx.dll" ==== Task Scheduler Jobs ====================== C:\WINDOWS\tasks\FacebookUpdateTaskUserS-1-5-21-1687350831-1530992600-3121883764-1002Core.job --a-------- C:\Users\giuseppe\AppData\Local\Facebook\Update\FacebookUpdate.exe [07/08/2013 16:47] C:\WINDOWS\tasks\FacebookUpdateTaskUserS-1-5-21-1687350831-1530992600-3121883764-1002UA.job --a-------- [Undetermined Task] C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1687350831-1530992600-3121883764-1002Core.job --a-------- [Undetermined Task] C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1687350831-1530992600-3121883764-1002UA.job --a-------- [Undetermined Task] C:\WINDOWS\tasks\Synaptics TouchPad Enhancements.job --a-------- C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [21/09/2012 09:55] ==== Other Scheduled Tasks ====================== "C:\WINDOWS\SysNative\tasks\CreateChoiceProcessTask" [C:\Windows\BrowserChoice\browserchoice.exe] "C:\WINDOWS\SysNative\tasks\FacebookUpdateTaskUserS-1-5-21-1687350831-1530992600-3121883764-1002Core" [C:\Users\giuseppe\AppData\Local\Facebook\Update\FacebookUpdate.exe] "C:\WINDOWS\SysNative\tasks\FacebookUpdateTaskUserS-1-5-21-1687350831-1530992600-3121883764-1002UA" [C:\Users\giuseppe\AppData\Local\Facebook\Update\FacebookUpdate.exe] "C:\WINDOWS\SysNative\tasks\Google Updater and Installer" [C:\Users\giuseppe\AppData\Local\Google\Update\GoogleUpdate.exe] "C:\WINDOWS\SysNative\tasks\GoogleUpdateTaskUserS-1-5-21-1687350831-1530992600-3121883764-1002Core" [C:\Users\giuseppe\AppData\Local\Google\Update\GoogleUpdate.exe] "C:\WINDOWS\SysNative\tasks\GoogleUpdateTaskUserS-1-5-21-1687350831-1530992600-3121883764-1002UA" [C:\Users\giuseppe\AppData\Local\Google\Update\GoogleUpdate.exe] "C:\WINDOWS\SysNative\tasks\Synaptics TouchPad Enhancements" [\Program Files\Synaptics\SynTP\SynTPEnh.exe] "C:\WINDOWS\SysNative\tasks\User_Feed_Synchronization-{2C4A5706-7CF6-4735-B8EE-5B960B1D44B5}" [C:\Windows\system32\msfeedssync.exe] ==== Reset Google Chrome ====================== C:\Users\giuseppe\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully C:\Users\giuseppe\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully ==== C:\zoek_backup content ====================== C:\zoek_backup (files=906 folders=279 310749459 bytes) ==== EOF on ma 27/10/2014 at 10:36:16,20 ======================