Zoek.exe v5.0.0.0 Updated 06-December-2014 Tool run by Alexander on ma 08/12/2014 at 9:59:30,69. Microsoft Windows 7 Ultimate 6.1.7601 Service Pack 1 x64 Running in: Normal Mode Internet Access Detected Launched: C:\Users\Alexander\Downloads\zoek.exe [Scan all users] [Script inserted] [Checkboxes used] ==== System Restore Info ====================== 8/12/2014 10:01:50 Zoek.exe System Restore Point Created Succesfully. ==== Empty Folders Check ====================== C:\PROGRA~2\COMMON~1\Apple deleted successfully C:\PROGRA~3\cosstminn deleted successfully C:\Users\Alexander\AppData\Local\CrashDumps deleted successfully ==== Deleting CLSID Registry Keys ====================== HKEY_USERS\S-1-5-21-1013060330-820888083-383613911-1000\Software\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} deleted successfully HKEY_USERS\S-1-5-21-1013060330-820888083-383613911-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{114E2619-58CE-40FA-805D-B2F9E76856B8} deleted successfully HKEY_USERS\S-1-5-21-1013060330-820888083-383613911-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1902982C-6D62-4B4E-B453-9B2293C3631A} deleted successfully HKEY_USERS\S-1-5-21-1013060330-820888083-383613911-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{320FFE6C-1E8-4E5F-B4F8-A299D1BD2AE9} deleted successfully HKEY_USERS\S-1-5-21-1013060330-820888083-383613911-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{3621A921-36D5-457D-BC8B-89856968BBFF} deleted successfully HKEY_USERS\S-1-5-21-1013060330-820888083-383613911-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5C0D11B8-C5F6-4be3-AD2C-2B1A3EB94AB6} deleted successfully HKEY_USERS\S-1-5-21-1013060330-820888083-383613911-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9053E0E3-76C3-4FEB-A66D-3FE0A981A962} deleted successfully HKEY_USERS\S-1-5-21-1013060330-820888083-383613911-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A03E80C2-DA49-438C-91C6-B2D9AAEDB17C} deleted successfully HKEY_USERS\S-1-5-21-1013060330-820888083-383613911-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{AE618728-4DD8-492C-8DC7-C6C9BA1CC1E1} deleted successfully HKEY_USERS\S-1-5-21-1013060330-820888083-383613911-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B55C6F88-5DA3-4078-8C7C-AD7E239AC5D} deleted successfully HKEY_USERS\S-1-5-21-1013060330-820888083-383613911-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E8926318-E1F1-4CBB-AA1A-B3D8170855} deleted successfully HKEY_USERS\S-1-5-21-1013060330-820888083-383613911-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ECFFE401-A40E-4FFE-BDDD-349E6CF6A7} deleted successfully HKEY_USERS\S-1-5-21-1013060330-820888083-383613911-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F0F0B8A3-953A-419C-9624-E0B7D61B55C} deleted successfully HKEY_USERS\S-1-5-21-1013060330-820888083-383613911-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FCCA0EAE-939-4298-98A-91C43894326E} deleted successfully ==== Deleting CLSID Registry Values ====================== ==== Deleting Services ====================== ==== Registry Fix Code x64 ====================== Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run] ""=- "fst_be_56"=- ==== Deleting Files \ Folders ====================== C:\Program Files (x86)\AnyProtectEx not found "C:\Program Files (x86)\RCP" not found C:\Users\Alexander\AppData\Roaming\GoContactSyncMOD deleted C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 deleted C:\ProgramData\d0f61c06aa0bb420 deleted C:\Users\Alexander\AppData\LocalLow\{68B6A3A2-FCD2-41AB-6D4F-BB2CAC4D585D} deleted C:\Users\Alexander\AppData\Local\Packages\windows_ie_ac_001\AC\{68B6A3A2-FCD2-41AB-6D4F-BB2CAC4D585D} deleted C:\PROGRA~2\COMMON~1\DVDVideoSoft\bin deleted C:\PROGRA~2\globalUpdate deleted C:\Users\Alexander\AppData\Roaming\aps.uninstall.scan.results deleted C:\Users\Alexander\AppData\Roaming\systweak deleted C:\Users\Alexander\AppData\Roaming\OpenCandy deleted C:\PROGRA~3\Systweak deleted C:\PROGRA~3\Registry Helper deleted C:\Users\Alexander\AppData\Local\nsoCC76.tmp deleted C:\Users\Alexander\AppData\Local\globalUpdate deleted C:\Users\Alexander\AppData\Local\WebPlayer deleted C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced System Protector deleted C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RegClean Pro deleted C:\Windows\SysNative\roboot64.exe deleted C:\Windows\SysNative\sasnative64.exe deleted C:\Users\Alexander\Downloads\SoftonicDownloader_voor_virtual-dj.exe deleted C:\windows\SysNative\tasks\Advanced System Protector_startup deleted C:\Windows\tasks\APSnotifierPP1.job deleted C:\Windows\tasks\APSnotifierPP2.job deleted C:\Windows\tasks\APSnotifierPP3.job deleted C:\windows\SysNative\tasks\APSnotifierPP1 deleted C:\windows\SysNative\tasks\APSnotifierPP2 deleted C:\windows\SysNative\tasks\APSnotifierPP3 deleted C:\windows\SysNative\tasks\ASP deleted C:\windows\SysNative\tasks\RegClean Pro deleted C:\windows\SysNative\tasks\RegClean Pro_DEFAULT deleted C:\windows\SysNative\tasks\RegClean Pro_UPDATES deleted C:\Windows\tasks\RegClean Pro_DEFAULT.job deleted C:\Windows\tasks\RegClean Pro_UPDATES.job deleted C:\windows\SysNative\drivers\{ed7eb956-75ed-460d-8f69-29a93b07afd1}w64.sys deleted C:\Windows\SysNative\config\systemprofile\Searches deleted C:\windows\SysNative\GroupPolicy\User deleted C:\windows\SysNative\GroupPolicy\GPT.INI deleted C:\Windows\Syswow64\GroupPolicy\gpt.ini deleted C:\Windows\Syswow64\RegistryHelperLM.ocx deleted ==== Files Recently Created / Modified ====================== ====== C:\Windows ==== ====== C:\Users\ALEXAN~1\AppData\Local\Temp ==== ====== Java Cache ===== ====== C:\Windows\SysWOW64 ===== ====== C:\Windows\SysWOW64\drivers ===== ====== C:\Windows\Sysnative ===== ====== C:\Windows\Sysnative\drivers ===== 2014-11-13 11:57:41 41774FF331F609EF442B7398EE6202B1 155064 ----a-w- C:\Windows\Sysnative\drivers\ksecpkg.sys ====== C:\Windows\Tasks ====== ====== C:\Windows\Temp ====== ======= C:\Program Files ===== 2014-12-03 15:11:19 -------- d-----w- C:\Program Files\trend micro ======= C:\PROGRA~2 ===== 2014-12-08 08:57:28 -------- d-----w- C:\PROGRA~2\COMMON~1\Java 2014-11-17 13:28:37 -------- d-----w- C:\PROGRA~2\VirtualDJ ======= C: ===== ====== C:\Users\Alexander\AppData\Roaming ====== 2014-12-08 09:13:48 -------- d-----w- C:\Users\Alexander\AppData\Local\CrashDumps 2014-12-03 14:56:47 -------- d-----w- C:\Users\Alexander\AppData\Local\Deployment 2014-12-03 14:56:47 -------- d-----w- C:\Users\Alexander\AppData\Local\Apps 2014-12-03 14:45:15 -------- d-sh--w- C:\Users\Alexander\AppData\Local\EmieBrowserModeList 2014-11-17 13:28:40 -------- d-----w- C:\Users\Alexander\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VirtualDJ 2014-11-14 13:00:43 -------- d-sh--w- C:\Users\Alexander\AppData\Locallow\EmieBrowserModeList ====== C:\Users\Alexander ====== 2014-12-08 08:54:40 3A582BF6FD39DC6A52AAF316126B40BA 638888 ----a-w- C:\Users\Alexander\Downloads\chromeinstall-8u25.exe 2014-12-03 15:11:06 8045ABB21A3BDD66A48E1ED5C0F0EF6A 1222144 ----a-w- C:\Users\Alexander\Downloads\RSITx64.exe 2014-12-03 14:58:50 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome 2014-12-03 14:49:21 038B75662205880BE56A8FFA9930F830 5162080 ----a-w- C:\Users\Alexander\Downloads\ccsetup500.exe ====== C: exe-files == === C: other files == ==== Startup Registry Enabled ====================== [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun" [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun" [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce] "SPReview"="C:\Windows\System32\SPReview\SPReview.exe /sp:1 /errorfwlink:http://go.microsoft.com/fwlink/?LinkID=122915 /build:7601" [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce] "mctadmin"="C:\Windows\System32\mctadmin.exe" [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce] "mctadmin"="C:\Windows\System32\mctadmin.exe" [HKEY_USERS\S-1-5-21-1013060330-820888083-383613911-1000\Software\Microsoft\Windows\CurrentVersion\RunOnce] "Uninstall C:\Users\Alexander\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811\amd64"="C:\Windows\system32\cmd.exe /q /c rmdir /s /q C:\Users\Alexander\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811\amd64" [HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\RunOnce] "SPReview"="C:\Windows\System32\SPReview\SPReview.exe /sp:1 /errorfwlink:http://go.microsoft.com/fwlink/?LinkID=122915 /build:7601" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Adobe ARM"="C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" "HP Software Update"="C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce] "Uninstall C:\Users\Alexander\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811\amd64"="C:\Windows\system32\cmd.exe /q /c rmdir /s /q C:\Users\Alexander\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811\amd64" ==== Startup Folders ====================== 2013-09-08 11:13:00 1310 ----a-w- C:\Users\Alexander\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Schermopname en Snel starten.lnk ==== Task Scheduler Jobs ====================== C:\Windows\tasks\Adobe Flash Player Updater.job --a------ C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [26/11/2014 17:36] C:\Windows\tasks\GoogleUpdateTaskMachineCore.job --a------ C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [03/12/2014 15:58] C:\Windows\tasks\GoogleUpdateTaskMachineUA.job --a------ C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [03/12/2014 15:58] C:\Windows\tasks\MATLAB R2013b Startup Accelerator.job --a------ C:\Program Files\MATLAB\R2013b\bin\win64\MATLABStartupAccelerator.exe [05/08/2013 16:44] ==== Other Scheduled Tasks ====================== "C:\Windows\SysNative\tasks\Adobe Flash Player Updater" [C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe] "C:\Windows\SysNative\tasks\CCleanerSkipUAC" ["C:\Program Files\CCleaner\CCleaner.exe"] "C:\Windows\SysNative\tasks\GoogleUpdateTaskMachineCore" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe] "C:\Windows\SysNative\tasks\GoogleUpdateTaskMachineUA" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe] "C:\Windows\SysNative\tasks\HPCustParticipation HP Deskjet 3520 series" ["C:\Program Files\HP\HP Deskjet 3520 series\Bin\HPCustPartic.exe"] "C:\Windows\SysNative\tasks\MATLAB R2013b Startup Accelerator" [C:\Program Files\MATLAB\R2013b\bin\win64\MATLABStartupAccelerator.exe] "C:\Windows\SysNative\tasks\Norton WSC Integration" ["C:\Program Files (x86)\Norton 360 Premier Edition\Engine\21.6.0.32\WSCStub.exe"] "C:\Windows\SysNative\tasks\{6B927BE5-4526-4A07-A19E-B5620DDDBEC8}" [C:\Users\Alexander\Downloads\zoek.exe] "C:\Windows\SysNative\tasks\{7606B647-9039-497D-91ED-708C37BA97EC}" [C:\Users\Alexander\Downloads\zoek.exe] "C:\Windows\SysNative\tasks\{9431E18A-91E3-41A2-A8EA-E8883292249E}" [C:\Users\Alexander\Downloads\zoek.exe] "C:\Windows\SysNative\tasks\{EEA2E343-4789-4306-8D69-4934C80300FB}" [C:\Users\Alexander\Downloads\zoek.exe] "C:\Windows\SysNative\tasks\Norton 360\Norton Error Analyzer" [C:\Program Files (x86)\Norton 360 Premier Edition\Engine\21.6.0.32\SymErr.exe] "C:\Windows\SysNative\tasks\Norton 360\Norton Error Processor" [C:\Program Files (x86)\Norton 360 Premier Edition\Engine\21.6.0.32\SymErr.exe] "C:\Windows\SysNative\tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask" [%systemroot%\system32\sc.exe start osppsvc] ==== Firefox Extensions Registry ====================== [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions] "{BBDA0591-3099-440a-AA10-41764D9DB4DB}"="C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_21.1.0.18\IPSFF" [16/03/2014 23:36] ==== Fake Chromium Profiles Check ====================== Fake profile C:\Users\Alexander\AppData\Local\Torch deleted Fake profile C:\Users\Alexander\AppData\Local\Google\Chrome SxS deleted Fake profile C:\Users\Alexander\AppData\Local\Comodo\Dragon deleted Fake profile C:\Users\Alexander\AppData\Local\Chromatic Browser deleted ==== Chromium Look ====================== HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions iikflkcanblccfahdhdonehdalibjnif - No path found[] mkfokfffehpeedafpekjeddnmnjhmcmk - C:\Program Files (x86)\Norton 360 Premier Edition\Engine\21.6.0.32\Exts\Chrome.crx[20/09/2014 09:52] Google Drive - Alexander\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf YouTube - Alexander\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo Pushbullet - Alexander\AppData\Local\Google\Chrome\User Data\Default\Extensions\chlffgpmiacpedhhbkiomidkjlcfhogd Google Search - Alexander\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf cosstminn - Alexander\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekpdcejihjigkgnibjfomifhojialakp 1 out-of-date - Alexander\AppData\Local\Google\Chrome\User Data\Default\Extensions\gbchcmhmhahfdphkhkmpfmihenigjmpp Last updated at time on date - Alexander\AppData\Local\Google\Chrome\User Data\Default\Extensions\knebimhcckndhiglamoabbnifdkijidd Google Wallet - Alexander\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda Gmail - Alexander\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia ==== Chromium Fix ====================== C:\Users\Alexander\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_www.superfish.com_0.localstorage deleted successfully C:\Users\Alexander\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_www.superfish.com_0.localstorage-journal deleted successfully C:\Users\Alexander\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.superfish.com_0.localstorage deleted successfully C:\Users\Alexander\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.superfish.com_0.localstorage-journal deleted successfully C:\Users\Alexander\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekpdcejihjigkgnibjfomifhojialakp deleted successfully ==== Set IE to Default ====================== Old Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://www.google.be/" New Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://www.google.be/" ==== All HKCU SearchScopes ====================== HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes "DefaultScope"="{6A1806CD-94D4-4689-BA73-E35EA1EA9990}" {012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}" {0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02" {6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}&rlz=1I7NDKB_enBE543" ==== Deleting Registry Keys ====================== HKEY_LOCAL_MACHINE\Software\wow6432node\Policies\Google deleted successfully ==== Empty IE Cache ====================== C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Alexander\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Alexander\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully ==== Empty FireFox Cache ====================== No FireFox Profiles found ==== Empty Chrome Cache ====================== C:\Users\Alexander\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully ==== Empty All Flash Cache ====================== Flash Cache Emptied Successfully ==== Empty All Java Cache ====================== Java Cache cleared successfully ==== C:\zoek_backup content ====================== C:\zoek_backup (files=238 folders=71 222974757 bytes) ==== Empty Temp Folders ====================== C:\Users\Alexander\AppData\Local\Temp will be emptied at reboot C:\Users\Default\AppData\Local\Temp emptied successfully C:\Users\Default User\AppData\Local\Temp emptied successfully C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully C:\Windows\Temp will be emptied at reboot ==== After Reboot ====================== ==== Empty Temp Folders ====================== C:\Windows\Temp successfully emptied C:\Users\ALEXAN~1\AppData\Local\Temp successfully emptied ==== Empty Recycle Bin ====================== C:\$RECYCLE.BIN successfully emptied ==== EOF on ma 08/12/2014 at 10:23:57,21 ======================