Zoek.exe v5.0.0.0 Updated 18-01-2015 Tool run by ldv on di 20/01/2015 at 7:45:22,38. Microsoft® Windows Vista™ Business 6.0.6002 Service Pack 2 x86 Running in: Safe Mode NETWORK Internet Access Detected Launched: C:\Users\ldv\Desktop\zoek.exe [Scan all users] [Script inserted] [Checkboxes used] ==== Older Logs ====================== C:\zoek-results2014-03-22-091349.log 20812 bytes ==== Empty Folders Check ====================== C:\Users\ldv\AppData\Roaming\Malwarebytes deleted successfully C:\Users\ldv\AppData\Local\Acer PowerSaver deleted successfully C:\Users\ldv\AppData\Local\CrashDumps deleted successfully ==== Deleting CLSID Registry Keys ====================== ==== Deleting CLSID Registry Values ====================== HKEY_USERS\S-1-5-21-2361067941-1604562449-4282051081-1003\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\{5CBE3B7C-1E47-477e-A7DD-396DB0476E29} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{5CBE3B7C-1E47-477e-A7DD-396DB0476E29} deleted successfully ==== Running Processes ====================== C:\Windows\System32\smss.exe C:\Windows\system32\csrss.exe C:\Windows\system32\csrss.exe C:\Windows\system32\wininit.exe C:\Windows\system32\winlogon.exe C:\Windows\system32\services.exe C:\Windows\system32\lsass.exe C:\Windows\system32\lsm.exe C:\Windows\Explorer.EXE C:\Program Files\Malwarebytes Anti-Malware\mbam.exe C:\Program Files\AVAST Software\Avast\avastui.exe C:\Users\ldv\Desktop\zoek.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\system32\wbem\unsecapp.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k rpcss C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted ==== Deleting Services ====================== ==== Deleting Files \ Folders ====================== C:\found.000 deleted C:\found.001 deleted C:\found.002 deleted C:\Windows\system32\GroupPolicy\Machine deleted C:\Windows\system32\GroupPolicy\User deleted C:\Windows\system32\GroupPolicy\gpt.ini deleted C:\Users\ldv\Documents\Add-in Express deleted ==== System Specs ====================== Windows: Windows Vista Business Edition Service Pack 2 (Build 6002) Memory (RAM): 3037 MB CPU Info: Intel(R) Core(TM)2 Duo CPU E7300 @ 2.66GHz CPU Speed: 2733,1 MHz Sound Card: Not detected Display Adapters: | RDP Encoder Mirror Driver Monitors: 1x; Screen Resolution: 1024 X 768 - 32 bit Network: Network Present Network Adapters: Intel(R) 82567LM-3 Gigabit Network Connection CD / DVD Drives: 1x (E: | ) E: HL-DT-STDVDRAM GH40F Ports: COM Ports NOT Present. LPT Port NOT Present. Mouse: 8 Button Wheel Mouse Present Hard Disks: C: 113,4GB | D: 170,0GB Hard Disks - Free: C: 51,5GB | D: 99,1GB Manufacturer *: Acer BIOS Info: AT/AT COMPATIBLE | 11/20/08 | ACRSYS - 20081120 Time Zone: Romance (standaardtijd) Motherboard *: Acer EQ45M Country: Belgi‰ Language: NLB ==== System Specs (Software) ====================== Anti-Virus: avast! Antivirus On-access scanning disabled (Outdated) Anti-Spyware: Windows Defender disabled (Outdated) Anti-Spyware: avast! Antivirus disabled (Outdated) Default Browser: Firefox 35.0 Internet Explorer Version: 9.0.8112.16421 Mozilla Firefox version: 35.0 (x86 nl) Google Chrome version: 39.0.2171.99 Adobe Reader version: 10.1.13.16 Flash Player version: 16.0.0.257 ==== Files Recently Created / Modified ====================== ====== C:\Windows ==== 2014-12-24 11:43:12 65541F7F9075194CDA176FBAE8977560 308224 ----a-w- C:\Windows\IsUn0413.exe ====== C:\Users\ldv\AppData\Local\Temp ==== 2015-01-16 07:58:36 E0DC8C6BBC787B972A9A468648DBFD85 1008128 ----a-w- C:\Users\ldv\AppData\Local\Temp\jrt\libiconv2.dll 2015-01-16 07:58:36 D202BAA425176287017FFE1FB5D1B77C 103424 ----a-w- C:\Users\ldv\AppData\Local\Temp\jrt\libintl3.dll 2015-01-16 07:58:36 57CAC848FA14AE38F14F9441F8933282 140288 ----a-w- C:\Users\ldv\AppData\Local\Temp\jrt\pcre3.dll 2015-01-16 07:58:36 547C43567AB8C08EB30F6C6BACB479A3 79360 ----a-w- C:\Users\ldv\AppData\Local\Temp\jrt\regex2.dll 2015-01-16 06:48:17 2E0323A94915FAAB10A25F3BABF82584 157696 ----a-w- C:\Users\ldv\AppData\Local\Temp\jrt\erunt\ERUNT.EXE ====== Java Cache ===== ====== C:\Windows\system32 ===== ====== C:\Windows\system32\drivers ===== ====== C:\Windows\Tasks ====== 2015-01-17 06:23:51 8D83E8C20A20B6E4D0ABCA3204C2C70A 3162 ----a-w- C:\Windows\system32\Tasks\avastBCLRestartS-1-5-21-2361067941-1604562449-4282051081-1003 2014-12-26 10:05:18 939ED4A55880F970BB4B13513AD0358A 3874 ----a-w- C:\Windows\system32\Tasks\Adobe Acrobat Update Task ====== C:\Windows\Temp ====== ======= C:\Program Files ===== ======= C: ===== ====== C:\Users\ldv\AppData\Roaming ====== 2015-01-20 06:33:30 -------- d-----w- C:\Users\ldv\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink PowerDVD ====== C:\Users\ldv ====== 2015-01-17 06:29:06 8685FAF50C04F9A9C2F56FF64B0B7ACB 1107968 ----a-w- C:\Users\ldv\Downloads\RSIT(1).exe 2015-01-16 14:44:07 8685FAF50C04F9A9C2F56FF64B0B7ACB 1107968 ----a-w- C:\Users\ldv\Downloads\RSIT.exe 2015-01-07 06:36:36 B9E1BF24EF01A82701B09BE75D294085 1707939 ----a-w- C:\Users\ldv\Downloads\JRT.exe ====== C: exe-files == 2015-01-18 12:58:23 BA7DC0C9141BE7292CA7E744B6F19F26 897104 ----a-w- C:\Program Files\Google\Update\Install\{4C308190-CB82-472C-8676-11ACE2A2B090}\39.0.2171.99_39.0.2171.95_chrome_updater.exe 2015-01-18 12:58:23 BA7DC0C9141BE7292CA7E744B6F19F26 897104 ----a-w- C:\Program Files\Google\Update\Download\{4DC8B4CA-1BDA-483E-B5FA-D3C12E15B62D}\39.0.2171.99\39.0.2171.99_39.0.2171.95_chrome_updater.exe 2015-01-17 06:29:06 8685FAF50C04F9A9C2F56FF64B0B7ACB 1107968 ----a-w- C:\Users\ldv\Downloads\RSIT(1).exe 2015-01-16 14:44:07 8685FAF50C04F9A9C2F56FF64B0B7ACB 1107968 ----a-w- C:\Users\ldv\Downloads\RSIT.exe 2015-01-16 06:48:17 2E0323A94915FAAB10A25F3BABF82584 157696 ----a-w- C:\Users\ldv\AppData\Local\Temp\jrt\erunt\ERUNT.EXE === C: other files == 2015-01-17 06:23:31 76CDB2BAD9582D23C1F6F4D868218D6C 22 ----a-w- C:\Users\ldv\AppData\Local\Temp\avastBCLTMP\nppllibpnmahfaklnpggkibhkapjkeob.zip 2015-01-16 07:58:36 AA0C656F898523BEDF2DA6923197BB80 1264 ----a-w- C:\Users\ldv\AppData\Local\Temp\jrt\surfvox.bat 2015-01-16 07:58:36 080CFDE64F31E7B50EECF4552033E84D 9937 ----a-w- C:\Users\ldv\AppData\Local\Temp\jrt\mws.bat 2015-01-16 06:48:17 F720D6634E048B0AD485CEEF55263E6B 191092 ----a-w- C:\Users\ldv\AppData\Local\Temp\jrt\misc.bat 2015-01-16 06:48:17 F56A319979F631C141F5FF02DF87FDB1 43563 ----a-w- C:\Users\ldv\AppData\Local\Temp\jrt\prelim.bat 2015-01-16 06:48:17 DD1E4D974B1672ABD09EFFB225791C4A 1230 ----a-w- C:\Users\ldv\AppData\Local\Temp\jrt\TDL4.bat 2015-01-16 06:48:17 C4C784C659C27DB5ED395A7901611C71 14957 ----a-w- C:\Users\ldv\AppData\Local\Temp\jrt\get.bat 2015-01-16 06:48:17 AD2F52DC72B10AF331692E4A4DD80DFC 18670 ----a-w- C:\Users\ldv\AppData\Local\Temp\jrt\medfos.bat 2015-01-16 06:48:17 A87CD1BAC46CAC0EEEDB571F07077032 8104 ----a-w- C:\Users\ldv\AppData\Local\Temp\jrt\modules.bat 2015-01-16 06:48:17 A3945FA06DB607245C6A1D0629CE737E 11057 ----a-w- C:\Users\ldv\AppData\Local\Temp\jrt\runvalues.bat 2015-01-16 06:48:17 8E6020C14F982CF11B3FE7DBB0CB8EDE 24738 ----a-w- C:\Users\ldv\AppData\Local\Temp\jrt\searchlnk.bat 2015-01-16 06:48:17 86707BCE5CBB65D9B1C41E249B4423BA 152733 ----a-w- C:\Users\ldv\AppData\Local\Temp\jrt\firefox.bat 2015-01-16 06:48:17 83F691D8398F0E37E71E9355BF730DB9 719 ----a-w- C:\Users\ldv\AppData\Local\Temp\jrt\ev_clear.bat 2015-01-16 06:48:17 654E9FE74B930A454EE5BDE165794B65 85 ----a-w- C:\Users\ldv\AppData\Local\Temp\jrt\delorphans.bat 2015-01-16 06:48:17 38A0BDF322ACCC968B0A824C38D50157 29635 ----a-w- C:\Users\ldv\AppData\Local\Temp\jrt\ask.bat 2015-01-16 06:48:17 335DFF8F23E5EC02B5426362F0F8509B 31401 ----a-w- C:\Users\ldv\AppData\Local\Temp\jrt\iexplore.bat 2015-01-16 06:48:17 2F80D807DB405C8F6E0F3706B9FED710 10161 ----a-w- C:\Users\ldv\AppData\Local\Temp\jrt\JRT.bat 2015-01-16 06:48:17 0D08FBD2E6F6C6AC6A504712C4CE6CE3 1226 ----a-w- C:\Users\ldv\AppData\Local\Temp\jrt\FWPolicy.bat 2015-01-16 06:48:17 0C4649A62845AB5D5DBCC4998477FF6D 1813 ----a-w- C:\Users\ldv\AppData\Local\Temp\jrt\delfolders.bat 2015-01-16 06:48:17 048407135C9B1FB6A355E256BD96160D 14192 ----a-w- C:\Users\ldv\AppData\Local\Temp\jrt\chrome.bat ==== Startup Registry Enabled ====================== [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run] "WindowsWelcomeCenter"="rundll32.exe oobefldr.dll,ShowWelcomeCenter" "Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /detectMem" [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run] "WindowsWelcomeCenter"="rundll32.exe oobefldr.dll,ShowWelcomeCenter" "Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /detectMem" [HKEY_USERS\S-1-5-21-2361067941-1604562449-4282051081-1003\Software\Microsoft\Windows\CurrentVersion\Run] "EPLTarget\P0000000000000000"="C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATIHLE.EXE /EPT EPLTarget\P0000000000000000 /M Epson Stylus SX235" "CCleaner Monitoring"="C:\Program Files\CCleaner\CCleaner.exe /MONITOR" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "picon"="C:\Program Files\Common Files\Intel\Privacy Icon\PrivacyIconClient.exe -startup" "Acer Empowering Technology Monitor"="C:\Program Files\Acer\Empowering Technology\SysMonitor.exe" "EmpoweringTechnology"="C:\Program Files\Acer\Empowering Technology\Framework.Launcher.exe boot" "IAAnotif"="C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe" "Acer PowerSaver"="C:\Program Files\Acer\Acer PowerSaver\PowerSaverTray.exe" "Acer SmartBoot"="C:\Program Files\Acer\Acer SmartBoot\ASLTray.exe" "AutoLockProcess"="C:\Program Files\Acer\Empowering Technology\eLock\autolockprocess\autolockprocess.exe" "eDataSecurity Loader"="C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe" "BkupTray"="C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe" "RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" "LanguageShortcut"="C:\Program Files\CyberLink\PowerDVD\Language\Language.exe" "Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe /startup" "AdobeAAMUpdater-1.0"="C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" "IgfxTray"="C:\Windows\system32\igfxtray.exe" "HotKeysCmds"="C:\Windows\system32\hkcmd.exe" "Persistence"="C:\Windows\system32\igfxpers.exe" "AvastUI.exe"="C:\Program Files\AVAST Software\Avast\AvastUI.exe /nogui" "Windows Defender"="%ProgramFiles%\Windows Defender\MSASCui.exe -hide" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "EPLTarget\P0000000000000000"="C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATIHLE.EXE /EPT EPLTarget\P0000000000000000 /M Epson Stylus SX235" "CCleaner Monitoring"="C:\Program Files\CCleaner\CCleaner.exe /MONITOR" ==== Startup Folders ====================== 2014-12-24 11:45:38 1154 ----a-w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk ==== Task Scheduler Jobs ====================== C:\Windows\tasks\Adobe Flash Player Updater.job --a------ C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [15/01/2015 13:41] C:\Windows\tasks\GoogleUpdateTaskMachineCore.job --a------ C:\Program Files\Google\Update\GoogleUpdate.exe [05/02/2013 10:32] C:\Windows\tasks\GoogleUpdateTaskMachineUA.job --a------ C:\Program Files\Google\Update\GoogleUpdate.exe [05/02/2013 10:32] ==== Other Scheduled Tasks ====================== "C:\Windows\system32\tasks\Adobe Acrobat Update Task" [C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe] "C:\Windows\system32\tasks\Adobe Flash Player Updater" [C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe] "C:\Windows\system32\tasks\AdobeAAMUpdater-1.0-PC_van_ldv-ldv" [C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe] "C:\Windows\system32\tasks\avastBCLRestartS-1-5-21-2361067941-1604562449-4282051081-1003" [C:\Program Files\Mozilla Firefox\firefox.exe] "C:\Windows\system32\tasks\CCleanerSkipUAC" ["C:\Program Files\CCleaner\CCleaner.exe"] "C:\Windows\system32\tasks\GoogleUpdateTaskMachineCore" [C:\Program Files\Google\Update\GoogleUpdate.exe] "C:\Windows\system32\tasks\GoogleUpdateTaskMachineUA" [C:\Program Files\Google\Update\GoogleUpdate.exe] "C:\Windows\system32\tasks\Norton Identity Safe\Norton Error Analyzer" [C:\Program Files\Norton Identity Safe\Engine\2013.2.0.18\SymErr.exe] "C:\Windows\system32\tasks\Norton Identity Safe\Norton Error Processor" [C:\Program Files\Norton Identity Safe\Engine\2013.2.0.18\SymErr.exe] ==== Firefox Extensions Registry ====================== [HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions] "wrc@avast.com"="C:\Program Files\AVAST Software\Avast\WebRep\FF" [11/12/2014 17:01] ==== Firefox Extensions ====================== ProfilePath: C:\Users\ldv\AppData\Roaming\Mozilla\Firefox\Profiles\wiqftbrl.default - Undetermined - {195A3098-0BD5-4e90-AE22-BA1C540AFD1E} - Undetermined - {DDC359D1-844A-42a7-9AA1-88A850A938A8} - Garmin Communicator - %ProfilePath%\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E} - DownThemAll - %ProfilePath%\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}.xpi AppDir: C:\Program Files\Mozilla Firefox - Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} ==== Firefox Plugins ====================== Profilepath: C:\Users\ldv\AppData\Roaming\Mozilla\Firefox\Profiles\wiqftbrl.default 8560995C727974F27F2A1CE68909FEB9 - C:\Windows\system32\Macromed\Flash\NPSWF32_16_0_0_257.dll - Shockwave Flash 39309FEDDFA73FAE29EC99A07A55A3E8 - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll - Adobe Acrobat 647670C013AD60DA6F94B6881E6AC9E4 - C:\Program Files\Adobe\Reader 10.0\Reader\browser\nppdf32.dll - Adobe Acrobat D2377C9458EFEB094E38B8C874AA214C - C:\Program Files\Google\Update\1.3.25.11\npGoogleUpdate3.dll - Google Update 893BF7D2261C56C24F813405D9D018E0 - C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll - Silverlight Plug-In C517E5EA7CEE783F3681F62D2A362E5B - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll - Windows Live? Photo Gallery AB87EEFFD18F2BAAFC274E7075EA6C67 - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll - Windows Presentation Foundation / Windows Presentation Foundation 8DA2ED6B04EA33F2EAE8BA883F903729 - C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrlui.dll - Microsoft® Silverlight ==== Fake Chromium Profiles Check ====================== Fake profile C:\Windows\system32\config\systemprofile\AppData\Local\Google\Chrome deleted ==== Chromium Look ====================== Google Chrome Version: 39.0.2171.99 (Up to date, latest Stable version: 39.0.2171.99) HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions gomekmidlodglbbmalcneegieacbdmki - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx[11/12/2014 17:01] avast Online Security - ldv\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki Google Wallet - ldv\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda ==== Set IE to Default ====================== Old Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://www.google.com" New Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://www.google.com" ==== All HKCU SearchScopes ====================== HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" {012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}" {0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC" {67A2568C-7A0A-4EED-AECC-B5405DE63B64} Google Url="http://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ACAW" {6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}" {A22A38B4-65EB-444E-A73E-BD2DB6876F7C} Google Url="http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7ACAW_nlBE519" ==== Deleting CLSID Registry Keys ====================== ==== Deleting CLSID Registry Values ====================== HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\{20a82645-c095-46ed-80e3-08825760534b} deleted successfully ==== HijackThis Entries ====================== O1 - Hosts: ::1 localhost O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files\Windows Live\Companion\companioncore.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide O4 - HKLM\..\Run: [picon] "C:\Program Files\Common Files\Intel\Privacy Icon\PrivacyIconClient.exe" -startup O4 - HKLM\..\Run: [Acer Empowering Technology Monitor] C:\Program Files\Acer\Empowering Technology\SysMonitor.exe O4 - HKLM\..\Run: [EmpoweringTechnology] C:\Program Files\Acer\Empowering Technology\Framework.Launcher.exe boot O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe O4 - HKLM\..\Run: [Acer PowerSaver] C:\Program Files\Acer\Acer PowerSaver\PowerSaverTray.exe O4 - HKLM\..\Run: [Acer SmartBoot] C:\Program Files\Acer\Acer SmartBoot\ASLTray.exe O4 - HKLM\..\Run: [AutoLockProcess] C:\Program Files\Acer\Empowering Technology\eLock\autolockprocess\autolockprocess.exe O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe O4 - HKLM\..\Run: [BkupTray] "C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe" O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe" O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup O4 - HKLM\..\Run: [AdobeAAMUpdater-1.0] "C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui O4 - HKCU\..\Run: [EPLTarget\P0000000000000000] C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATIHLE.EXE /EPT "EPLTarget\P0000000000000000" /M "Epson Stylus SX235" O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner.exe" /MONITOR O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE') O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000 O9 - Extra button: @C:\Program Files\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files\Windows Live\Companion\companioncore.dll O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra 'Tools' menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe O23 - Service: Acer SmartBoot Service (ASLSvc) - Acer Incorporated - C:\Program Files\Acer\Acer SmartBoot\ASLSvc.exe O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe O23 - Service: NTI Backup Now 5 Agent Service (BUNAgentSvc) - NewTech Infosystems, Inc. - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe O23 - Service: eDataSecurity Service - Egis Incorporated - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe O23 - Service: eLock Service (eLockService) - Acer Inc. - C:\Program Files\Acer\Empowering Technology\eLock\Service\eLockServ.exe O23 - Service: Empowering Technology Service (ETService) - Unknown owner - C:\Program Files\Acer\Empowering Technology\Service\ETService.exe O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe O23 - Service: Google Desktop Manager 5.7.808.7150 (GoogleDesktopManager-080708-050100) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe O23 - Service: Google Update-service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe O23 - Service: Google Update-service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe O23 - Service: Intel(R) Active Management Technology Local Management Service (LMS) - Intel Corporation - C:\Program Files\Intel\AMT\LMS.exe O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe O23 - Service: NTI Backup Now 5 Backup Service (NTIBackupSvc) - NewTech InfoSystems, Inc. - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe O23 - Service: NTI Backup Now 5 Scheduler Service (NTISchedulerSvc) - Unknown owner - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe O23 - Service: Intel(R) Active Management Technology User Notification Service (UNS) - Intel Corporation - C:\Program Files\Common Files\Intel\Privacy Icon\UNS\UNS.exe O23 - Service: wampapache - Apache Software Foundation - c:\wamp\bin\apache\apache2.2.11\bin\httpd.exe O23 - Service: wampmysqld - Unknown owner - c:\wamp\bin\mysql\mysql5.1.36\bin\mysqld.exe ==== Empty IE Cache ====================== C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\ldv\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot ==== Empty FireFox Cache ====================== C:\Users\ldv\AppData\Local\Mozilla\Firefox\Profiles\wiqftbrl.default\cache2 emptied successfully ==== Empty Chrome Cache ====================== C:\Users\ldv\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully ==== Empty All Flash Cache ====================== Flash Cache Emptied Successfully ==== Empty All Java Cache ====================== No Java Cache Found ==== C:\zoek_backup content ====================== C:\zoek_backup (files=247 folders=38 16550665 bytes) ==== Empty Temp Folders ====================== C:\Users\Default\AppData\Local\Temp emptied successfully C:\Users\Default User\AppData\Local\Temp emptied successfully C:\Users\ldv\AppData\Local\Temp will be emptied at reboot C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully C:\Windows\Temp will be emptied at reboot ==== After Reboot ====================== ==== Empty Temp Folders ====================== C:\Windows\Temp successfully emptied C:\Users\ldv\AppData\Local\Temp successfully emptied ==== Empty Recycle Bin ====================== C:\$RECYCLE.BIN successfully emptied ==== Deleting Files / Folders ====================== "C:\Users\ldv\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not found ==== EOF on di 20/01/2015 at 8:00:55,65 ======================