Zoek.exe v5.0.0.0 Updated 27-01-2015 Tool run by Ben on vr 30/01/2015 at 19:05:28,93. Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x64 Running in: Normal Mode Internet Access Detected Launched: C:\Users\Ben\Desktop\zoek.exe [Scan all users] [Script inserted] ==== Older Logs ====================== C:\zoek-results2015-01-30-005122.log 206426 bytes ==== Possible Rootkit Infection ====================== C:\Windows\installer\{c87c57b2-f838-e709-d6d3-6b3f00373896}\L C:\Windows\installer\{c87c57b2-f838-e709-d6d3-6b3f00373896}\U C:\Windows\installer\{c87c57b2-f838-e709-d6d3-6b3f00373896}\L\00000004.@ ==== Empty Folders Check ====================== C:\PROGRA~2\Ad-Aware Antivirus C:\PROGRA~2\Cisco C:\PROGRA~2\Garmin C:\PROGRA~2\Java C:\PROGRA~2\MSXML 4.0 C:\PROGRA~2\TuneUp Utilities 2013 ==== Deleting CLSID Registry Keys ====================== ==== Deleting CLSID Registry Values ====================== ==== Deleting Services ====================== ==== Deleting Files \ Folders ====================== C:\Program Files (x86)\Common Files\Wondershare not found C:\Windows\SysNative\tasks\0 deleted C:\Windows\SysNative\tasks\4458 deleted ==== Firefox Start and Search pages ====================== ProfilePath: C:\Users\Ben\AppData\Roaming\Mozilla\Firefox\Profiles\[opt]rs0 user_pref("browser.search.defaultenginename", "AVG Secure Search"); ==== Firefox Extensions Registry ====================== [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions] "{23fcfd51-4958-4f00-80a3-ae97e717ed8b}"="C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5" [24/05/2013 21:08] ==== Firefox Extensions ====================== ProfilePath: C:\Users\Ben\AppData\Roaming\Netscape\Navigator\Profiles\cm4w4udf.default - Undetermined - C:\Program Files (x86)\Netscape\Navigator 9\extensions\netscape9migrator@flock.com - Undetermined - C:\Program Files (x86)\Netscape\Navigator 9\extensions\netstripe@netscape.com AppDir: C:\Program Files (x86)\Mozilla Firefox - TrueSuite Website Logon - %AppDir%\extensions\websitelogon@truesuite.com - Undetermined - %AppDir%\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} - Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} ==== Firefox Plugins ====================== Profilepath: C:\Users\Ben\AppData\Roaming\Mozilla\Firefox\Profiles\7awumcyz.default 855B79451ECF62602F20EB4D5C71F99B - C:\Windows\SysWoW64\Adobe\Director\np32dsw.dll - Shockwave for Director / Shockwave for Director ==== Chromium Look ====================== HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions aepeildmfnnehghlknddebgjghlompfe - C:\Program Files (x86)\HP SimplePass 2011\tschrome.crx[11/02/2011 02:37] nneajnkjbffgblleaoojgaacokifdkhm - C:\Program Files (x86)\DivX\DivX Plus Web Player\chrome\DivXHTML5\DivXHTML5.crx[06/05/2013 09:12] Website Logon - Ben\AppData\Local\Google\Chrome\User Data\Default\Extensions\aepeildmfnnehghlknddebgjghlompfe ==== Chromium Startpages ====================== C:\Users\Ben\AppData\Local\Google\Chrome\User Data\Default\Preferences {"homepage":"http://www.google.com/","homepage_is_newtabpage":false,"distribution":{"skip_first_run_ui":false,"import_search_engine":false,"import_history":false,"create_all_shortcuts":true,"do_not_launch_chrome":true,"make_chrome_default":true,"verbose_logging":false,"ping_delay":-60},"sync_promo":{"show_on_first_run_allowed":false},"session":{"restore_on_startup":4,"urls_to_restore_on_startup":["http://www.google.com/"]},"first_run_tabs":["http://www.google.com/","http://welcome_page"]} ==== Set IE to Default ====================== Old Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://www.google.be/" New Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://www.google.be/" ==== All HKCU SearchScopes ====================== HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes "DefaultScope"="{012E1000-F331-11DB-8314-0800200C9A66}" {012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}" {0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC" {6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="https://www.google.com/search?q={searchTerms}" {d43b3890-80c7-4010-a95d-1e77b5924dc3} Wikipedia Url="http://nl.wikipedia.org/wiki/Special:Search?search={searchTerms}" {D944BB61-2E34-4DBF-A683-47E505C587DC} eBay Url="http://rover.ebay.com/rover/1/1553-111073-34115-5/4?mpre=http://shop.ebay.com/?_nkw={searchTerms}" {E5AD17B9-D5B8-44AB-8C8B-597C92746376} Bing Url="http://www.bing.com/search?FORM=UP74DF&PC=UP74&dt=082313&q={searchTerms}&src=IE-SearchBox" ==== Reset Google Chrome ====================== C:\Users\Ben\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully C:\Users\Ben\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully ==== Empty IE Cache ====================== C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Ben\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully C:\Users\Gast\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Gast\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Ben\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\93UDYCAI will be deleted at reboot ==== Empty FireFox Cache ====================== C:\Users\Ben\AppData\Local\Mozilla\Firefox\Profiles\7awumcyz.default\cache2 emptied successfully ==== Empty Chrome Cache ====================== C:\Users\Ben\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully ==== Empty All Flash Cache ====================== Flash Cache Emptied Successfully ==== Empty All Java Cache ====================== Java Cache cleared successfully ==== C:\zoek_backup content ====================== C:\zoek_backup (files=733 folders=169 140788927 bytes) ==== Empty Temp Folders ====================== C:\Users\Ben\AppData\Local\Temp will be emptied at reboot C:\Users\Default\AppData\Local\Temp emptied successfully C:\Users\Default User\AppData\Local\Temp emptied successfully C:\Users\Gast\AppData\Local\Temp emptied successfully C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully C:\Windows\Temp will be emptied at reboot ==== After Reboot ====================== ==== Empty Temp Folders ====================== C:\Windows\Temp successfully emptied C:\Users\Ben\AppData\Local\Temp successfully emptied ==== Empty Recycle Bin ====================== C:\$RECYCLE.BIN successfully emptied ==== Deleting Files / Folders ====================== "C:\PROGRA~2\Ad-Aware Antivirus" not deleted "C:\PROGRA~2\Cisco" not deleted "C:\PROGRA~2\Garmin" not deleted "C:\PROGRA~2\Java" not deleted "C:\PROGRA~2\MSXML 4.0" not deleted "C:\PROGRA~2\TuneUp Utilities 2013" not deleted "C:\Users\Ben\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\93UDYCAI" not found ==== EOF on vr 30/01/2015 at 19:23:00,69 ======================