Zoek.exe v5.0.0.0 Updated 28-10-2014 Tool run by Ries van Ool on wo 29-10-2014 at 20:43:40,12. Running in: Normal Mode Internet Access Detected Launched: C:\Users\Ries van Ool\Desktop\zoek.exe [Scan all users] [Script inserted] [Checkboxes used] ==== System Restore Info ====================== Failed to create System Restore Point ==== Empty Folders Check ====================== C:\Program Files\MSXML 4.0 deleted successfully C:\Program Files\Norton Security Scan deleted successfully C:\Program Files\Power4Gear eXtreme deleted successfully C:\Program Files\TomTom DesktopSuite deleted successfully C:\PROGRA~2\ALM deleted successfully C:\PROGRA~2\ZoomBrowser deleted successfully C:\Users\Ries van Ool\AppData\Roaming\Neoretix deleted successfully C:\Users\Ries van Ool\AppData\Roaming\WinRAR deleted successfully C:\Users\Ries van Ool\AppData\Roaming\ZoomBrowser EX deleted successfully ==== Deleting CLSID Registry Keys ====================== HKEY_USERS\S-1-5-21-589480253-1782796221-1050078968-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{ba14329e-9550-4989-b3f2-9732e92d17cc} deleted successfully HKEY_USERS\S-1-5-21-589480253-1782796221-1050078968-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{ba14329e-9550-4989-b3f2-9732e92d17cc} deleted successfully HKEY_USERS\S-1-5-21-589480253-1782796221-1050078968-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{25CEC205-B72D-295C-9F13-C26EF8A1C7A0} deleted successfully HKEY_USERS\S-1-5-21-589480253-1782796221-1050078968-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{25CEC205-B72D-295C-9F13-C26EF8A1C7A0} deleted successfully HKEY_USERS\S-1-5-21-589480253-1782796221-1050078968-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} deleted successfully HKEY_USERS\S-1-5-21-589480253-1782796221-1050078968-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A7DF592F-6E2A-45C4-9A87-4BD217D714ED} deleted successfully HKEY_USERS\S-1-5-21-589480253-1782796221-1050078968-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{A7DF592F-6E2A-45C4-9A87-4BD217D714ED} deleted successfully HKEY_USERS\S-1-5-21-589480253-1782796221-1050078968-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FEB703F7-E7B2-4AB0-9566-87658AC70095} deleted successfully HKEY_USERS\S-1-5-21-589480253-1782796221-1050078968-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FEB703F7-E7B2-4AB0-9566-87658AC70095} deleted successfully HKEY_CLASSES_ROOT\CLSID\{ba14329e-9550-4989-b3f2-9732e92d17cc} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{ba14329e-9550-4989-b3f2-9732e92d17cc} deleted successfully HKEY_CLASSES_ROOT\CLSID\{25CEC205-B72D-295C-9F13-C26EF8A1C7A0} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{25CEC205-B72D-295C-9F13-C26EF8A1C7A0} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{A7DF592F-6E2A-45C4-9A87-4BD217D714ED} deleted successfully HKEY_CLASSES_ROOT\CLSID\{A7DF592F-6E2A-45C4-9A87-4BD217D714ED} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A7DF592F-6E2A-45C4-9A87-4BD217D714ED} deleted successfully HKEY_CLASSES_ROOT\CLSID\{FEB703F7-E7B2-4AB0-9566-87658AC70095} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FEB703F7-E7B2-4AB0-9566-87658AC70095} deleted successfully ==== Deleting CLSID Registry Values ====================== HKEY_USERS\S-1-5-21-589480253-1782796221-1050078968-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{ba14329e-9550-4989-b3f2-9732e92d17cc} deleted successfully HKEY_USERS\S-1-5-21-589480253-1782796221-1050078968-1000\Software\Microsoft\Internet Explorer\URLSearchHooks\{ba14329e-9550-4989-b3f2-9732e92d17cc} deleted successfully HKEY_USERS\S-1-5-21-589480253-1782796221-1050078968-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} deleted successfully HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\urlsearchhooks\{ba14329e-9550-4989-b3f2-9732e92d17cc} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{ba14329e-9550-4989-b3f2-9732e92d17cc} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} deleted successfully ==== Running Processes ====================== C:\Windows\System32\smss.exe C:\Windows\system32\csrss.exe C:\Windows\system32\wininit.exe C:\Windows\system32\csrss.exe C:\Windows\system32\services.exe C:\Windows\system32\lsass.exe C:\Windows\system32\lsm.exe C:\Windows\system32\nvvsvc.exe C:\Windows\system32\winlogon.exe C:\Windows\system32\SLsvc.exe C:\Windows\system32\nvvsvc.exe C:\Program Files\ATK Hotkey\ASLDRSrv.exe C:\Program Files\ATKGFNEX\GFNEXSrv.exe C:\Windows\system32\WLANExt.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\taskeng.exe C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files\AVG\AVG2012\avgwdsvc.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Creative\Shared Files\CTDevSrv.exe C:\Program Files\Intel\Wireless\Bin\EvtEng.exe C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\Windows\system32\lxebcoms.exe C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe C:\Windows\system32\PnkBstrA.exe C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe C:\Program Files\Heutink ICT\deklas.nu Thuiswerken\USBDLM\USBDLM.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\Windows\system32\Dwm.exe C:\Windows\system32\taskeng.exe C:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\AsGHost.exe C:\Windows\Explorer.EXE C:\Program Files\Heutink ICT\deklas.nu Thuiswerken\USBDLM\USBDLM_usr.exe C:\Windows\system32\SearchIndexer.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\Program Files\ATK Hotkey\Hcontrol.exe C:\Program Files\ATKOSD2\ATKOSD2.exe C:\Program Files\Wireless Console 2\wcourier.exe C:\Program Files\ASUS\ASUS CopyProtect\aspg.exe C:\Program Files\P4G\BatteryLife.exe C:\Program Files\ASUS\Splendid\ACMON.exe C:\Windows\System32\ACEngSvr.exe C:\Windows\system32\taskeng.exe C:\Program Files\ATK Hotkey\ATKOSD.exe C:\Program Files\ASUS\ASUS Live Update\ALU.exe C:\Program Files\ASUS\SmartLogon\sensorsrv.exe C:\Program Files\ATK Hotkey\KBFiltr.exe C:\Program Files\Windows Defender\MSASCui.exe C:\Windows\RtHDVCpl.exe C:\Program Files\Intel\Intel Matrix Storage Manager\IAANOTIF.EXE C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\ASUS\ATK Media\DMedia.exe C:\Program Files\P4P\P4P.exe C:\Windows\ASScrPro.exe C:\Program Files\Winamp\winampa.exe C:\Program Files\Adobe\Acrobat 9.0\Acrobat\acrotray.exe C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe C:\Program Files\VirtualCloneDrive\VCDDaemon.exe C:\Program Files\AVG\AVG2012\avgtray.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Lexmark Pro200-S500 Series\lxebmon.exe C:\Program Files\Lexmark Pro200-S500 Series\ezprint.exe C:\Program Files\real\realplayer\Update\realsched.exe C:\Program Files\Samsung\Kies\KiesTrayAgent.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe C:\Windows\ehome\ehtray.exe C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe C:\ProgramData\Macrovision\FLEXnet Connect\6\ISUSPM.exe C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe C:\Program Files\Creative\Software Update 3\SoftAuto.exe C:\Program Files\DAEMON Tools Pro\DTAgent.exe C:\Program Files\Samsung\Kies\Kies.exe C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe C:\Users\Ries van Ool\AppData\Roaming\Dropbox\bin\Dropbox.exe C:\Windows\ehome\ehmsas.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe C:\Program Files\Common Files\Nokia\MPAPI\MPAPI3s.exe C:\Program Files\Synaptics\SynTP\SynTPHelper.exe C:\Windows\system32\wuauclt.exe C:\Program Files\AVG\AVG2012\avgcfgex.exe C:\Users\Ries van Ool\Desktop\zoek.exe C:\Windows\system32\conime.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\System32\svchost.exe -k Cognizance C:\Windows\system32\svchost.exe -k rpcss C:\Windows\System32\svchost.exe -k secsvcs C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k GPSvcGroup C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\system32\svchost.exe -k bthsvcs C:\Windows\System32\svchost.exe -k HPZ12 C:\Windows\System32\svchost.exe -k HPZ12 C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation ==== Deleting Services ====================== ==== FireFox Fix ====================== ProfilePath: C:\Users\RIESVA~1\AppData\Roaming\Flickr\Flickr Uploadr\Profiles\nod7waq7.default user.js not found ---- FireFox user.js and prefs.js backups ---- prefs_29-10-2014_2102_.backup ProfilePath: C:\Users\RIESVA~1\AppData\Roaming\Mozilla\Firefox\Profiles\oaq4cx52.default user.js not found ---- Lines CT2504091 removed from prefs.js ---- user_pref("CT2504091.AboutPrivacyUrl", "http://www.conduit.com/privacy/Default.aspx"); user_pref("CT2504091.CTID", "CT2504091"); user_pref("CT2504091.CurrentServerDate", "20-10-2013"); user_pref("CT2504091.DialogsAlignMode", "LTR"); user_pref("CT2504091.DownloadReferralCookieData", ""); user_pref("CT2504091.EMailNotifierPollDate", "Sun Oct 20 2013 12:25:03 GMT+0200"); user_pref("CT2504091.FeedLastCount129079840422964131", 10); user_pref("CT2504091.FeedPollDate128891351169457140", "Sun Oct 20 2013 12:25:04 GMT+0200"); user_pref("CT2504091.FeedPollDate129079840422964131", "Sun Oct 20 2013 12:25:05 GMT+0200"); user_pref("CT2504091.FeedTTL128891351169457140", 40); user_pref("CT2504091.FirstServerDate", "6-9-2010"); user_pref("CT2504091.FirstTime", true); user_pref("CT2504091.FirstTimeFF3", true); user_pref("CT2504091.FirstTimeSettingsDone", true); user_pref("CT2504091.FixPageNotFoundErrors", true); user_pref("CT2504091.GroupingServerCheckInterval", 1440); user_pref("CT2504091.GroupingServiceUrl", "http://grouping.services.conduit.com/"); user_pref("CT2504091.Initialize", true); user_pref("CT2504091.InitializeCommonPrefs", true); user_pref("CT2504091.InstallationAndCookieDataSentCount", 3); user_pref("CT2504091.InstallationType", "UnknownIntegration"); user_pref("CT2504091.InstalledDate", "Mon Sep 06 2010 15:32:55 GMT+0200"); user_pref("CT2504091.InvalidateCache", false); user_pref("CT2504091.IsGrouping", false); user_pref("CT2504091.IsMulticommunity", false); user_pref("CT2504091.IsOpenThankYouPage", false); user_pref("CT2504091.IsOpenUninstallPage", false); user_pref("CT2504091.LanguagePackLastCheckTime", "Sun Oct 20 2013 12:25:04 GMT+0200"); user_pref("CT2504091.LanguagePackReloadIntervalMM", 1440); user_pref("CT2504091.LanguagePackServiceUrl", "http://translation.users.conduit.com/Translation.ashx"); user_pref("CT2504091.LastLogin_2.7.2.0", "Sun Oct 20 2013 12:25:04 GMT+0200"); user_pref("CT2504091.LatestVersion", "3.20.0.4"); user_pref("CT2504091.Locale", "en-us"); user_pref("CT2504091.LoginCache", 4); user_pref("CT2504091.MCDetectTooltipHeight", "83"); user_pref("CT2504091.MCDetectTooltipUrl", "http://@EB_INSTALL_LINK@/rank/tooltip/?version=1"); user_pref("CT2504091.MCDetectTooltipWidth", "295"); user_pref("CT2504091.RadioIsPodcast", false); user_pref("CT2504091.RadioLastCheckTime", "Sat Feb 25 2012 14:35:52 GMT+0100"); user_pref("CT2504091.RadioLastUpdateIPServer", "3"); user_pref("CT2504091.RadioLastUpdateServer", "0"); user_pref("CT2504091.RadioMediaID", "8798"); user_pref("CT2504091.RadioMediaType", "Media Player"); user_pref("CT2504091.RadioMenuSelectedID", "EBRadioMenu_CT25040918798"); user_pref("CT2504091.RadioStationName", "Radio%20Netherlands%20-%20Dutch"); user_pref("CT2504091.RadioStationURL", "http://www.rnw.nl/distrib/realaudio/ram/live/rnw_live_1.asx"); user_pref("CT2504091.SearchEngine", "Search||http://search.conduit.com/Results.aspx?q=UCM_SEARCH_TERM&ctid=CT2504091&octid=EB_ORIGINAL_CTID&SearchSour user_pref("CT2504091.SearchFromAddressBarIsInit", true); user_pref("CT2504091.SearchFromAddressBarUrl", "http://search.conduit.com/ResultsExt.aspx?ctid=CT2504091&q="); user_pref("CT2504091.SearchInNewTabEnabled", true); user_pref("CT2504091.SearchInNewTabIntervalMM", 1440); user_pref("CT2504091.SearchInNewTabLastCheckTime", "Sun Oct 20 2013 12:25:03 GMT+0200"); user_pref("CT2504091.SearchInNewTabServiceUrl", "http://newtab.conduit-hosting.com/newtab/?ctid=EB_TOOLBAR_ID&UM=UM_ID"); user_pref("CT2504091.SearchInNewTabUsageUrl", "http://usage.hosting.toolbar.conduit-services.com/usage.ashx?ctid=EB_TOOLBAR_ID"); user_pref("CT2504091.SettingsCheckIntervalMin", 120); user_pref("CT2504091.SettingsLastCheckTime", "Sun Oct 20 2013 12:25:03 GMT+0200"); user_pref("CT2504091.SettingsLastUpdate", "1382256665"); user_pref("CT2504091.ThirdPartyComponentsInterval", 504); user_pref("CT2504091.ThirdPartyComponentsLastCheck", "Sun Oct 20 2013 12:25:03 GMT+0200"); user_pref("CT2504091.ThirdPartyComponentsLastUpdate", "1331805997"); user_pref("CT2504091.TrusteLinkUrl", "http://trust.conduit.com/EB_ORIGINAL_CTID"); user_pref("CT2504091.UserID", "UN18807248980220867"); user_pref("CT2504091.ValidationData_Search", 0); user_pref("CT2504091.ValidationData_Toolbar", 2); user_pref("CT2504091.WeatherNetwork", ""); user_pref("CT2504091.WeatherPollDate", "Mon Apr 30 2012 16:23:36 GMT+0200"); user_pref("CT2504091.WeatherUnit", "C"); user_pref("CT2504091.alertChannelId", "897164"); user_pref("CT2504091.backendstorage./9b+7e+x305", "247E27413334363379453A3D2A722C797A7E7A3128333B4D474549484C5952594B335E5356432C45333438334A414C54666 user_pref("CT2504091.backendstorage./9b+7e,x305", "247E28412F3F3E3779453A3D2A722C797B787D3128333C4748402C574C4F3C253E2C2E2B2F433A454E59505B57676A66426 user_pref("CT2504091.backendstorage./9b+7e-x305", "247E2936303C363679453A3D2A722C797A207B3128333D462B554A4D4B4749594D33535D4F432C45333439344A414C565B5 user_pref("CT2504091.backendstorage./9b+7e06cg5el8:", "6E6D6C72726E6E766F71"); user_pref("CT2504091.backendstorage./9b+7e06cg5el;8i:k", "247E2D2F226A747372787874747C7577242F4B49474F42357D5D5C3D"); user_pref("CT2504091.backendstorage./9b+7e31;cjc<=fbj#cf", "247E61393F236B25757674722A212C6E414F444D327A344F4849524E562F4F523E3540234F5059452E47364940 user_pref("CT2504091.backendstorage./9b+7e4x305", "247E302C407642373A276F29777B74762E2530413E4F494A522B55553A233C2B2F282941384354515E5D56615F56685C426 user_pref("CT2504091.backendstorage./9b+7ebe3g=;d9n9=d", "372C2D326975762E3A3C7B3A39434A494841434B265146492965504656496571734D334B57"); user_pref("CT2504091.backendstorage./9b-0?3g>d", "6770403C6F406E757A72727446207B794D4A257A7A4F242A5626572B562D252F5E30295E"); user_pref("CT2504091.backendstorage./9b-0?3g@6:5;", ""); user_pref("CT2504091.backendstorage./9b-0?3gfa7ef", "2B2E2C3D"); user_pref("CT2504091.backendstorage./9b-3=3eccja=f>", "247E333D2C452F4135276F292A212C393D44307832332A354448584C3A232E333E58604F6456604F6852645858635E6 user_pref("CT2504091.backendstorage./9b/>01=9a6k6@44i48?", "372C2D32697576334236334148477B213F3E484F4E4D4648502B564B4E2E5959595F4C564F3764535750"); user_pref("CT2504091.backendstorage./9b5ba==9cjag", "696C3F3D6F413F737A76477A4A48747E7B21794D4F"); user_pref("CT2504091.backendstorage./9b6b11g4c56b>f;p;anr@p", "6E6D6C72726E6E766E78747A78"); user_pref("CT2504091.backendstorage./9b9643g3/9e", "6A"); user_pref("CT2504091.backendstorage./9b<:222h64<", "393F352F3E"); user_pref("CT2504091.backendstorage./9b=+03eh8h8j?:", "4443"); user_pref("CT2504091.backendstorage./9b?+e2a52d8", "372C2D326975762E3A3C7B3A39434A494841434B2651464929655046566470727951555E5E52"); user_pref("CT2504091.backendstorage./9b?b0d:8aj62