Zoek.exe v5.0.0.1 Updated 27-09-2015 Tool run by Pablo on ma 22-08-2016 at 17:48:18,65. Microsoft Windows 10 Home 10.0.10586 x64 Running in: Normal Mode No Internet Access Detected Launched: C:\Users\Pablo\Desktop\zoek.exe [Scan all users] [Script inserted] ==== Older Logs ====================== C:\zoek-results2016-05-25-121136.log 26454 bytes C:\zoek-results2016-06-03-062750.log 679 bytes C:\zoek-results2016-06-04-183406.log 727 bytes C:\zoek-results2016-06-06-174242.log 12880 bytes C:\zoek-results2016-06-07-202149.log 24565 bytes C:\zoek-results2016-07-03-174839.log 10473 bytes C:\zoek-results2016-07-03-230214.log 22245 bytes C:\zoek-results2016-08-06-130129.log 9117 bytes C:\zoek-results2016-08-06-155119.log 13255 bytes ==== Empty Folders Check ====================== C:\PROGRA~3\CanonIJPLM deleted successfully C:\Users\Pablo\AppData\Local\ActiveSync deleted successfully C:\WINDOWS\serviceprofiles\Localservice\AppData\Local\NetworkTiles deleted successfully ==== Deleting CLSID Registry Keys ====================== ==== Deleting CLSID Registry Values ====================== ==== Installed Programs ====================== Adobe Acrobat Reader DC Adobe Flash Player 22 NPAPI Adobe Refresh Manager ANIWZCS2 Service Bitdefender Agent Bitdefender Antivirus Plus 2016 Canon Easy-PhotoPrint EX Canon Easy-PhotoPrint Pro - Pro9000 series Extention Data Canon Easy-PhotoPrint Pro - Pro9500 series Extention Data Canon Easy-PhotoPrint Pro Canon Inkjet Printer/Scanner/Fax Extended Survey Program Canon MG6100 series MP Drivers Canon MP Navigator EX 4.0 Canon My Printer Canon Solution Menu EX CCleaner ControlCenter D-Link Wireless G DWL-G122_DWA-110 DAEMON Tools Lite Gebruikersregistratie voor Canon MG6100 series Google Toolbar for Internet Explorer Google Update Helper Java 8 Update 102 (64-bit) Java 8 Update 91 Java Auto Updater Liveupdate4 Microsoft .NET Framework 4.5.2 Microsoft .NET Framework 4.5.2 (NLD) Microsoft DVD App Installation for Microsoft.WindowsDVDPlayer_2019.6.13291.0_neutral_~_8wekyb3d8bbwe (x64) Microsoft Office Professional Edition 2003 Microsoft Silverlight Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 Mozilla Firefox 47.0 (x86 nl) Mozilla Maintenance Service NVIDIA-configuratiescherm 353.82 NVIDIA Display Control Panel NVIDIA Drivers NVIDIA Install Application NVIDIA PhysX NVIDIA Stereoscopic 3D Driver Revo Uninstaller Pro 3.1.5 Spybot - Search & Destroy Visual Studio C++ 10.0 Runtime VLC media player WinRAR 5.01 (64-bit) ==== Running Processes ====================== C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe C:\WINDOWS\SysWOW64\ANIWConnService.exe C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe C:\Program Files\Bitdefender Agent\ProductAgentService.exe C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe C:\Program Files (x86)\Google\Update\GoogleUpdate.exe C:\Users\Pablo\AppData\Local\Microsoft\OneDrive\OneDrive.exe C:\Program Files (x86)\ANI\ANIWZCS2 Service\WZCSLDR2.exe C:\Program Files (x86)\D-Link\DWL-G122_DWA-110\AirGCFG.exe C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe C:\Users\Pablo\Desktop\zoek.exe C:\WINDOWS\SysWOW64\cmd.exe C:\WINDOWS\SysWOW64\cmd.exe C:\WINDOWS\SysWOW64\cmd.exe C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe ==== Deleting Services ====================== ==== Deleting Files \ Folders ====================== C:\PROGRA~3\Avg deleted "C:\Users\Pablo\AppData\Local\{D2C67E30-4EF5-4DCC-94B5-A7D64A0DDF64}" deleted "C:\Users\Pablo\AppData\Local\{F1B24B9A-99DA-4457-B6FF-35FE0F6712C0}" deleted ==== System Specs ====================== Operating System: Microsoft Windows 10 Home 10.0.10586 64 bits Manufacturer: MSI - Model: MS-7588 Install Date: 13-11-2015 07:44:59 Last Boot: 22-8-2016 17:44:09 Processor: Intel(R) Core(TM) i5 CPU 750 @ 2.67GHz Number of Processors: 4 Work Station Bootmode: Normal boot Total RAM: 4086 MB ( - 0) Computername: PC Domain: WORKGROUP User: Pablo (Non-Administrator account) Local Disk: C:\ - NTFS - 199 GB (free 56 GB) Local Disk: D:\ - NTFS - 396 GB (free 89 GB) CD \ DVD Drive: E:\ Removable Disk: F:\ - - GB (free GB) Removable Disk: G:\ - - GB (free GB) Removable Disk: H:\ - - GB (free GB) Removable Disk: I:\ - - GB (free GB) CD \ DVD Drive: J:\ Bootdevice: \Device\HarddiskVolume1 Windows update: Country: Nederland Language: NLD ==== System Specs (Software) ====================== Default Browser: Firefox 47.0 Internet Explorer Version: 11.103.10586.0 Mozilla Firefox version: 47.0 (x86 nl) Adobe Reader version: 15.17.20050.192152 Sun Java version: 1.8.0_102 (32-bit) Sun Java version: 1.8.0_102 (64-bit) Flash Player version: 22.0.0.209 ==== Files Recently Created / Modified ====================== ====== C:\WINDOWS ==== 2016-08-13 09:20:27 3B9818878471200B01F8CABAA507D32A 401198691 ----a-w- C:\WINDOWS\MEMORY.DMP ====== C:\Users\Pablo\AppData\Local\Temp ==== ====== Java Cache ===== ====== C:\WINDOWS\SysWOW64 ===== ====== C:\WINDOWS\SysWOW64\drivers ===== ====== C:\WINDOWS\Sysnative ===== 2016-08-13 07:45:36 FC88BD97827EAD3BB22C46D3029B4C85 285248 ----a-w- C:\WINDOWS\Sysnative\FNTCACHE.DAT 2016-08-10 19:26:26 DF200F84AC4DFAA279A4C4100A39AC01 110144 ----a-w- C:\WINDOWS\Sysnative\WindowsAccessBridge-64.dll 2016-08-09 05:54:06 82446D358A9FB51CB9DA32A5C901D7A0 21040 ----a-w- C:\WINDOWS\Sysnative\sdnclean64.exe ====== C:\WINDOWS\Sysnative\drivers ===== ====== C:\WINDOWS\Tasks ====== 2016-08-09 17:13:16 40B7ECC4E78F61CCD3573D065C8458E1 214 ----a-w- C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job ====== C:\WINDOWS\Temp ====== ======= C:\Program Files ===== 2016-08-10 19:26:08 -------- d-----w- C:\Program Files\Java ======= C:\PROGRA~2 ===== ======= C: ===== ====== C:\Users\Pablo\AppData\Roaming ====== 2016-08-10 19:17:38 -------- d-----w- C:\Users\Pablo\AppData\Local\AvgSetupLog 2016-08-10 19:17:38 -------- d-----w- C:\Users\Pablo\AppData\Local\Avg 2016-07-28 19:39:37 -------- d-----w- C:\Users\Pablo\AppData\Local\Downloaded Installations ====== C:\Users\Pablo ====== 2016-08-16 03:41:47 -------- d-----w- C:\ProgramData\Microsoft 2016-08-10 19:17:38 -------- d--h--w- C:\ProgramData\Common Files 2016-08-10 19:15:30 -------- d-----w- C:\Users\Pablo\Doctor Web 2016-08-05 20:33:14 F4BB77A80DEBCADD997EB4A3C285E710 26212 ----a-w- C:\ProgramData\1470429192.bdinstall.bin ====== C: exe-files == 2016-08-22 05:41:46 4E95AB8BEB2C8FD53B348EF4AD5121C5 149184 ----a-w- C:\Users\Pablo\AppData\Local\Temp\4B975FFC-FBD2-4B1A-8731-E257A66817FF\DismHost.exe === C: other files == ==== Startup Registry Enabled ====================== [HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "OneDriveSetup"="C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup" [HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "OneDriveSetup"="C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup" [HKEY_USERS\S-1-5-21-245886207-1146603730-494075168-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "DAEMON Tools Lite"="C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe -autorun" "OneDrive"="C:\Users\Pablo\AppData\Local\Microsoft\OneDrive\OneDrive.exe /background" "TomTom MySports Connect.exe"="C:\Program Files (x86)\TomTom\MySportsConnect\TomTom MySports Connect.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ANIWZCS2Service"="C:\Program Files (x86)\ANI\ANIWZCS2 Service\WZCSLDR2.exe" "D-Link D-Link Wireless G DWL-G122_DWA-110"="C:\Program Files (x86)\D-Link\DWL-G122_DWA-110\AirGCFG.exe" "CanonSolutionMenuEx"="C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE /logon" "SunJavaUpdateSched"="C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" "SDTray"="C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "DAEMON Tools Lite"="C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe -autorun" "OneDrive"="C:\Users\Pablo\AppData\Local\Microsoft\OneDrive\OneDrive.exe /background" "TomTom MySports Connect.exe"="C:\Program Files (x86)\TomTom\MySportsConnect\TomTom MySports Connect.exe" ==== Startup Registry Enabled x64 ====================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "CanonMyPrinter"="C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon" ==== Task Scheduler Jobs ====================== C:\WINDOWS\tasks\Adobe Flash Player Updater.job --a-------- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [12-07-2016 23:59] C:\WINDOWS\tasks\Bitdefender Agent WatchDog_65D6944A0EF74FDAB96E31112AD39864.job --a-------- C:\Program Files\Bitdefender Agent\WatchDog.exe [18-04-2016 15:31] C:\WINDOWS\tasks\CreateExplorerShellUnelevatedTask.job --a-------- C:\WINDOWS\explorer.exe [29-01-2016 08:57] C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job --a-------- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [31-08-2015 06:11] C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job --a-------- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [31-08-2015 06:11] ==== Other Scheduled Tasks ====================== "C:\WINDOWS\SysNative\tasks\Adobe Acrobat Update Task" [C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe] "C:\WINDOWS\SysNative\tasks\Adobe Flash Player Updater" [C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe] "C:\WINDOWS\SysNative\tasks\CCleanerSkipUAC" ["C:\Program Files\CCleaner\CCleaner.exe"] "C:\WINDOWS\SysNative\tasks\CreateChoiceProcessTask" [C:\Windows\System32\browserchoice.exe] "C:\WINDOWS\SysNative\tasks\CreateExplorerShellUnelevatedTask" [C:\WINDOWS\explorer.exe] "C:\WINDOWS\SysNative\tasks\GoogleUpdateTaskMachineCore" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe] "C:\WINDOWS\SysNative\tasks\GoogleUpdateTaskMachineUA" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe] "C:\WINDOWS\SysNative\tasks\GridinSoft Anti-Malware" ["C:\Program Files\GridinSoft Anti-Malware\gsam.exe"] "C:\WINDOWS\SysNative\tasks\User_Feed_Synchronization-{85F87B36-B11F-45CC-AE88-BADB65EACF7A}" [C:\WINDOWS\system32\msfeedssync.exe] "C:\WINDOWS\SysNative\tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates" ["C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe"] "C:\WINDOWS\SysNative\tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization" ["C:\Program Files (x86)\Spybot - Search & Destroy 2\SDImmunize.exe"] "C:\WINDOWS\SysNative\tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system" ["C:\Program Files (x86)\Spybot - Search & Destroy 2\SDScan.exe"]