Zoek.exe v5.0.0.0 Updated 08-December-2014 Tool run by Ronald on wo 10-12-2014 at 0:20:50,96. Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x86 Running in: Normal Mode Internet Access Detected Launched: C:\Users\Ronald\Downloads\zoek.exe\zoek.exe.scr [Scan all users] [Quick Scan] [Auto Clean] ==== System Restore Info ====================== 10-12-2014 0:21:41 Zoek.exe System Restore Point Created Succesfully. ==== Deleting CLSID Registry Keys ====================== HKEY_USERS\S-1-5-21-1713141829-3285270229-1384493382-1000\Software\Microsoft\Internet Explorer\SearchScopes\{75b4241f-171e-44a3-bf44-23613b6e3e03} deleted successfully ==== Deleting CLSID Registry Values ====================== ==== Deleting Services ====================== ==== Deleting Files \ Folders ====================== C:\Users\Ronald\AppData\LocalLow\IAC deleted C:\Windows\system32\config\systemprofile\Searches deleted C:\Windows\System32\REN47C9.tmp deleted C:\Windows\System32\REN47DA.tmp deleted "C:\Windows\System32\uxt2399.tmp" deleted "C:\Windows\System32\uxt2399.tmp" deleted ==== Files Recently Created / Modified ====================== ====== C:\Windows ==== ====== C:\Users\Ronald\AppData\Local\Temp ==== 2014-12-09 23:16:49 DF8718ACBBC30181EBDBA3BCE97D0B18 185144 ----a-w- C:\Users\Ronald\AppData\Local\Temp\TUUUninstallHelper.exe ====== Java Cache ===== ====== C:\Windows\system32 ===== ====== C:\Windows\system32\drivers ===== 2014-11-13 09:28:10 1E1845606C5A4579F7F3D95796CC1ED1 136632 ----a-w- C:\Windows\System32\drivers\ksecpkg.sys ====== C:\Windows\Tasks ====== 2014-11-15 13:54:11 11CB66AFBA6747006D52DE0ABCBB2EC8 3680 ----a-w- C:\Windows\system32\Tasks\Java Platform SE Auto Updater ====== C:\Windows\Temp ====== ======= C:\Program Files ===== 2014-12-08 13:34:39 -------- d-----w- C:\Program Files\Adblock Plus for IE 2014-11-12 20:34:31 -------- d-----w- C:\Program Files\Common Files\Java ======= C: ===== ====== C:\Users\Ronald\AppData\Roaming ====== 2014-12-08 13:34:45 -------- d-----w- C:\Users\Ronald\AppData\Locallow\Adblock Plus for IE 2014-12-08 13:33:11 -------- d-----w- C:\Users\Ronald\AppData\Local\Programs 2014-12-07 21:22:48 0C4B1ACB72943D8D024DABD9CDC37F85 7605 ----a-w- C:\Users\Ronald\AppData\Local\Resmon.ResmonCfg 2014-11-13 12:17:12 -------- d-sh--w- C:\Users\Ronald\AppData\Local\EmieBrowserModeList 2014-11-13 12:16:12 -------- d-sh--w- C:\Users\Ronald\AppData\Locallow\EmieBrowserModeList 2014-11-12 20:26:32 -------- d-----w- C:\Users\Ronald\AppData\Locallow\Oracle ====== C:\Users\Ronald ====== 2014-11-12 20:25:26 -------- d-----w- C:\ProgramData\Oracle ====== C: exe-files == 2014-12-09 23:16:49 DF8718ACBBC30181EBDBA3BCE97D0B18 185144 ----a-w- C:\Users\Ronald\AppData\Local\Temp\TUUUninstallHelper.exe 2014-12-08 13:32:57 058C9FDB7FF8DD9C62C2057FC54A218F 5952624 ----a-w- C:\Users\Ronald\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5G3HZWJV\adblockplusie-1.2.exe === C: other files == ==== Startup Registry Enabled ====================== [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun" [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun" [HKEY_USERS\S-1-5-21-1713141829-3285270229-1384493382-1000\Software\Microsoft\Windows\CurrentVersion\Run] "EPLTarget\P0000000000000000"="C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATIINE.EXE /EPT EPLTarget\P0000000000000000 /M XP-102 103 Series" [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce] "mctadmin"="C:\Windows\System32\mctadmin.exe" [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce] "mctadmin"="C:\Windows\System32\mctadmin.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RTHDVCPL"="C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s" "IgfxTray"="C:\Windows\system32\igfxtray.exe" "HotKeysCmds"="C:\Windows\system32\hkcmd.exe" "Persistence"="C:\Windows\system32\igfxpers.exe" "MSC"="c:\Program Files\Microsoft Security Client\msseces.exe -hide -runkey" "EEventManager"="C:\Program Files\Epson Software\Event Manager\EEventManager.exe" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "EPLTarget\P0000000000000000"="C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATIINE.EXE /EPT EPLTarget\P0000000000000000 /M XP-102 103 Series" ==== Startup Registry Disabled ====================== [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run-] "Adobe ARM"="\"C:\\Program Files\\Common Files\\Adobe\\ARM\\1.0\\AdobeARM.exe\"" "SunJavaUpdateSched"="\"C:\\Program Files\\Common Files\\Java\\Java Update\\jusched.exe\"" ==== Task Scheduler Jobs ====================== C:\Windows\tasks\Adobe Flash Player Updater.job --a------ C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [09-12-2014 19:06] ==== Other Scheduled Tasks ====================== "C:\Windows\system32\tasks\Adobe Flash Player Updater" [C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe] "C:\Windows\system32\tasks\Adobe Reader and Acrobat Manager" [C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe] "C:\Windows\system32\tasks\CreateChoiceProcessTask" [C:\Windows\System32\browserchoice.exe] "C:\Windows\system32\tasks\Java Platform SE Auto Updater" [C:\Program Files\Common Files\Java\Java Update\jusched.exe] "C:\Windows\system32\tasks\User_Feed_Synchronization-{4FF99BF0-2695-4B50-B75B-5A00AB39DC04}" [C:\Windows\system32\msfeedssync.exe] ==== Firefox Extensions Registry ====================== [HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions] "e-webprint@epson.com"="C:\Program Files\Epson Software\E-Web Print\Firefox Add-on" [17-10-2014 13:48] ==== Firefox Extensions ====================== ==== Firefox Plugins ====================== Profilepath: C:\Users\Ronald\AppData\Roaming\Mozilla\Firefox\Profiles\1iphvkxa.default 64C4ADE063A9C93D3BAE09922AD90C27 - C:\Program Files\Adobe\Reader 11.0\Reader\browser\nppdf32.dll - Adobe Acrobat 446BCAE59E26321802E000FC3E0C390A - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll - Adobe Acrobat 893BF7D2261C56C24F813405D9D018E0 - c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll - Silverlight Plug-In 8DA2ED6B04EA33F2EAE8BA883F903729 - c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrlui.dll - Microsoft® Silverlight ==== Set IE to Default ====================== Old Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://www.startpagina.nl/" New Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://www.startpagina.nl/" ==== All HKCU SearchScopes ====================== HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" {012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}" {0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02" ==== Empty IE Cache ====================== C:\Users\Ronald\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Ronald\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully ==== Empty FireFox Cache ====================== C:\Users\Ronald\AppData\Local\Mozilla\Firefox\Profiles\1iphvkxa.default\cache2 emptied successfully ==== Empty Chrome Cache ====================== No Chrome User Data found ==== Empty All Flash Cache ====================== Flash Cache Emptied Successfully ==== Empty All Java Cache ====================== No Java Cache Found ==== C:\zoek_backup content ====================== C:\zoek_backup (files=6 folders=3 36958 bytes) ==== Empty Temp Folders ====================== C:\Users\Default\AppData\Local\Temp emptied successfully C:\Users\Default User\AppData\Local\Temp emptied successfully C:\Users\Ronald\AppData\Local\Temp will be emptied at reboot C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully C:\Windows\Temp will be emptied at reboot ==== After Reboot ====================== ==== Empty Temp Folders ====================== C:\Windows\Temp successfully emptied C:\Users\Ronald\AppData\Local\Temp successfully emptied ==== Empty Recycle Bin ====================== C:\$RECYCLE.BIN successfully emptied ==== Deleting Files / Folders ====================== "C:\Windows\System32\uxt2399.tmpsearch" not found "C:\Windows\System32\uxt2399.tmpsearch" not found ==== EOF on wo 10-12-2014 at 0:34:32,84 ======================