Zoek.exe v5.0.0.1 Updated 19-September-2016 Tool run by L‚on on za 01-10-2016 at 11:42:44,05. Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x64 Running in: Normal Mode Internet Access Detected Launched: C:\Users\LON~1\Desktop\zoek.exe [Scan all users] [Script inserted] ==== Older Logs ====================== C:\zoek-results2016-09-27-145132.log 13022 bytes C:\zoek-results2016-09-28-080434.log 853 bytes C:\zoek-results2016-09-29-080808.log 7687 bytes C:\zoek-results2016-09-29-092155.log 3604 bytes C:\zoek-results2016-09-30-073038.log 4571 bytes C:\zoek-results2016-10-01-074302.log 1913 bytes ==== Folders Found ====================== 2016-09-28 08:04:29 2016-09-05 12:53:35 -------- d---a-w- C:\zoek_backup\C_ProgramData_Norton 2016-09-28 08:04:29 2016-09-05 12:53:35 -------- d---a-w- C:\zoek_backup\C_Users_All Users_Norton 2016-09-28 08:04:29 2016-05-17 07:12:46 -------- d---a-w- C:\zoek_backup\C_ProgramData_G DATA 2016-09-28 08:04:30 2016-05-17 07:12:46 -------- d---a-w- C:\zoek_backup\C_Users_All Users_G DATA 2016-10-01 07:42:43 2016-09-06 18:05:52 -------- d---a-w- C:\zoek_backup\C_Windows_SysWOW64_config_systemprofile_AppData_Local_Zemana 2016-10-01 07:42:44 2016-08-08 13:59:40 -------- d---a-w- C:\zoek_backup\C_Windows_SysWOW64_config_systemprofile_AppData_Local_Zemana_Zemana AntiMalware 2016-10-01 07:42:44 2016-08-08 13:59:40 -------- d---a-w- C:\zoek_backup\C_Windows_SysWOW64_config_systemprofile_AppData_Local_Zemana\Zemana AntiMalware 2016-09-28 08:04:29 2016-09-05 12:53:35 -------- d---a-w- C:\zoek_backup\C_ProgramData_Norton 2016-09-28 08:04:29 2016-09-05 12:53:35 -------- d---a-w- C:\zoek_backup\C_Users_All Users_Norton 2016-09-28 08:04:29 2016-05-17 07:12:46 -------- d---a-w- C:\zoek_backup\C_ProgramData_G DATA 2016-09-28 08:04:30 2016-05-17 07:12:46 -------- d---a-w- C:\zoek_backup\C_Users_All Users_G DATA 2016-10-01 07:42:43 2016-09-06 18:05:52 -------- d---a-w- C:\zoek_backup\C_Windows_SysWOW64_config_systemprofile_AppData_Local_Zemana 2016-10-01 07:42:44 2016-08-08 13:59:40 -------- d---a-w- C:\zoek_backup\C_Windows_SysWOW64_config_systemprofile_AppData_Local_Zemana_Zemana AntiMalware 2016-10-01 07:42:44 2016-08-08 13:59:40 -------- d---a-w- C:\zoek_backup\C_Windows_SysWOW64_config_systemprofile_AppData_Local_Zemana\Zemana AntiMalware ==== Files Found ====================== --- C:\Windows\winsxs\Manifests\amd64_microsoft-windows-gwx-task_31bf3856ad364e35_6.1.7601.23538_none_ba618baef45f937a.manifest --- Company: ------ File Description: ------ File Version: ------ Product Name: ------ Copyright: ------ Original Filename: ------ File type: ------w- File size: 404 Created time: 2016-09-21 07:25:23 Modified time: 2016-09-01 16:03:35 MD5: 7632F2AEB84F8C23FC55457D1A0D7D1F SHA1: 8C3ADCC6211C786FB1BBFBCCF2BCB677063244F3 --- C:\Windows\winsxs\Manifests\amd64_microsoft-windows-gwx_31bf3856ad364e35_6.1.7601.23538_none_0f162766860b858c.manifest --- Company: ------ File Description: ------ File Version: ------ Product Name: ------ Copyright: ------ Original Filename: ------ File type: ------w- File size: 399 Created time: 2016-09-21 07:25:23 Modified time: 2016-09-01 16:03:35 MD5: F63E9118E5E2DA6AE38D3EF30FA0663E SHA1: B37768806C9EAC4E4E5853C4D11C0A1E4A7895B2 --- C:\Windows\winsxs\Manifests\wow64_microsoft-windows-gwx_31bf3856ad364e35_6.1.7601.23538_none_196ad1b8ba6c4787.manifest --- Company: ------ File Description: ------ File Version: ------ Product Name: ------ Copyright: ------ Original Filename: ------ File type: ------w- File size: 399 Created time: 2016-09-21 07:25:22 Modified time: 2016-09-01 15:24:06 MD5: 99FD59A01A47E0317528491404A00D55 SHA1: 4D603A94EC3059184B166C16D4CD2885FB4F5859 --- C:\zoek_backup\C_Draagbaar_GWX Control Panel.exe.vir --- Company: UltimateOutsider File Description: GWX Control Panel - Closes and configures the 'Get Windows 10' system tray application. File Version: 1.7.2.0 Product Name: GWX Control Panel Copyright: (c) 2016, Josh Mayfield/Ultimate Outsider. All rights reserved. Original Filename: GWX_control_panel.exe File type: ----a-w- File size: 4559944 Created time: 2016-09-29 08:53:46 Modified time: 2016-01-30 13:17:09 MD5: 3CBAA23AB6ED2824DC5D8BE8B6AFBCE9 SHA1: 519465821FF83471685E7D64D2B8E20B53969C76 --- C:\zoek_backup\C_Windows_winsxs_Manifests_amd64_microsoft-windows-gwx-task_31bf3856ad364e35_6.1.7601.23538_none_ba618baef45f937a.manifest.vir --- Company: ------ File Description: ------ File Version: ------ Product Name: ------ Copyright: ------ Original Filename: ------ File type: ----a-w- File size: 404 Created time: 2016-09-29 08:53:47 Modified time: 2016-09-01 16:03:35 MD5: 7632F2AEB84F8C23FC55457D1A0D7D1F SHA1: 8C3ADCC6211C786FB1BBFBCCF2BCB677063244F3 --- C:\zoek_backup\C_Windows_winsxs_Manifests_amd64_microsoft-windows-gwx_31bf3856ad364e35_6.1.7601.23538_none_0f162766860b858c.manifest.vir --- Company: ------ File Description: ------ File Version: ------ Product Name: ------ Copyright: ------ Original Filename: ------ File type: ----a-w- File size: 399 Created time: 2016-09-29 08:53:47 Modified time: 2016-09-01 16:03:35 MD5: F63E9118E5E2DA6AE38D3EF30FA0663E SHA1: B37768806C9EAC4E4E5853C4D11C0A1E4A7895B2 --- C:\zoek_backup\C_Windows_winsxs_Manifests_wow64_microsoft-windows-gwx_31bf3856ad364e35_6.1.7601.23538_none_196ad1b8ba6c4787.manifest.vir --- Company: ------ File Description: ------ File Version: ------ Product Name: ------ Copyright: ------ Original Filename: ------ File type: ----a-w- File size: 399 Created time: 2016-09-29 08:53:47 Modified time: 2016-09-01 15:24:06 MD5: 99FD59A01A47E0317528491404A00D55 SHA1: 4D603A94EC3059184B166C16D4CD2885FB4F5859 --- C:\Windows\winsxs\Manifests\amd64_microsoft-windows-gwx-task_31bf3856ad364e35_6.1.7601.23538_none_ba618baef45f937a.manifest --- Company: ------ File Description: ------ File Version: ------ Product Name: ------ Copyright: ------ Original Filename: ------ File type: ------w- File size: 404 Created time: 2016-09-21 07:25:23 Modified time: 2016-09-01 16:03:35 MD5: 7632F2AEB84F8C23FC55457D1A0D7D1F SHA1: 8C3ADCC6211C786FB1BBFBCCF2BCB677063244F3 --- C:\Windows\winsxs\Manifests\amd64_microsoft-windows-gwx_31bf3856ad364e35_6.1.7601.23538_none_0f162766860b858c.manifest --- Company: ------ File Description: ------ File Version: ------ Product Name: ------ Copyright: ------ Original Filename: ------ File type: ------w- File size: 399 Created time: 2016-09-21 07:25:23 Modified time: 2016-09-01 16:03:35 MD5: F63E9118E5E2DA6AE38D3EF30FA0663E SHA1: B37768806C9EAC4E4E5853C4D11C0A1E4A7895B2 --- C:\Windows\winsxs\Manifests\wow64_microsoft-windows-gwx_31bf3856ad364e35_6.1.7601.23538_none_196ad1b8ba6c4787.manifest --- Company: ------ File Description: ------ File Version: ------ Product Name: ------ Copyright: ------ Original Filename: ------ File type: ------w- File size: 399 Created time: 2016-09-21 07:25:22 Modified time: 2016-09-01 15:24:06 MD5: 99FD59A01A47E0317528491404A00D55 SHA1: 4D603A94EC3059184B166C16D4CD2885FB4F5859 --- C:\zoek_backup\C_Draagbaar_GWX Control Panel.exe.vir --- Company: UltimateOutsider File Description: GWX Control Panel - Closes and configures the 'Get Windows 10' system tray application. File Version: 1.7.2.0 Product Name: GWX Control Panel Copyright: (c) 2016, Josh Mayfield/Ultimate Outsider. All rights reserved. Original Filename: GWX_control_panel.exe File type: ----a-w- File size: 4559944 Created time: 2016-09-29 08:53:46 Modified time: 2016-01-30 13:17:09 MD5: 3CBAA23AB6ED2824DC5D8BE8B6AFBCE9 SHA1: 519465821FF83471685E7D64D2B8E20B53969C76 --- C:\zoek_backup\C_Windows_winsxs_Manifests_amd64_microsoft-windows-gwx-task_31bf3856ad364e35_6.1.7601.23538_none_ba618baef45f937a.manifest.vir --- Company: ------ File Description: ------ File Version: ------ Product Name: ------ Copyright: ------ Original Filename: ------ File type: ----a-w- File size: 404 Created time: 2016-09-29 08:53:47 Modified time: 2016-09-01 16:03:35 MD5: 7632F2AEB84F8C23FC55457D1A0D7D1F SHA1: 8C3ADCC6211C786FB1BBFBCCF2BCB677063244F3 --- C:\zoek_backup\C_Windows_winsxs_Manifests_amd64_microsoft-windows-gwx_31bf3856ad364e35_6.1.7601.23538_none_0f162766860b858c.manifest.vir --- Company: ------ File Description: ------ File Version: ------ Product Name: ------ Copyright: ------ Original Filename: ------ File type: ----a-w- File size: 399 Created time: 2016-09-29 08:53:47 Modified time: 2016-09-01 16:03:35 MD5: F63E9118E5E2DA6AE38D3EF30FA0663E SHA1: B37768806C9EAC4E4E5853C4D11C0A1E4A7895B2 --- C:\zoek_backup\C_Windows_winsxs_Manifests_wow64_microsoft-windows-gwx_31bf3856ad364e35_6.1.7601.23538_none_196ad1b8ba6c4787.manifest.vir --- Company: ------ File Description: ------ File Version: ------ Product Name: ------ Copyright: ------ Original Filename: ------ File type: ----a-w- File size: 399 Created time: 2016-09-29 08:53:47 Modified time: 2016-09-01 15:24:06 MD5: 99FD59A01A47E0317528491404A00D55 SHA1: 4D603A94EC3059184B166C16D4CD2885FB4F5859 ==== Registry Search Results for "norton" ====================== [HKEY_USERS\S-1-5-21-3985488779-3452437005-2477218925-1000\Software\VS Revo Group\Revo Uninstaller\Junk Files\Exclude] "*/norton antivirus/quarantine/"=dword:00000001 ==== Registry Search Results for "g data" ====================== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DA4E3DA0-D07D-11d0-BD50-00A0C911CE86}\Instance\{2EB07EA0-7E70-11D0-A5D6-28DB04C10000}] "FriendlyName"="WDM Streaming Data Transforms" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{DA4E3DA0-D07D-11d0-BD50-00A0C911CE86}\Instance\{2EB07EA0-7E70-11D0-A5D6-28DB04C10000}] "FriendlyName"="WDM Streaming Data Transforms" ==== Registry Search Results for "gdata" ====================== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0383751a-098b-11d8-9414-505054503030}] @="IApiTracingDataCollector" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{411F3E08-E6B1-4789-AB29-755C52E52AC4}] @="IDebugDataGrid" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{0383751a-098b-11d8-9414-505054503030}] @="IApiTracingDataCollector" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{411F3E08-E6B1-4789-AB29-755C52E52AC4}] @="IDebugDataGrid" ==== Registry Search Results for "gwx" ====================== No instances of string "gwx" found. ==== Registry Search Results for "zemana" ====================== No instances of string "zemana" found. ==== Registry Search Results for "norton" ====================== [HKEY_USERS\S-1-5-21-3985488779-3452437005-2477218925-1000\Software\VS Revo Group\Revo Uninstaller\Junk Files\Exclude] "*/norton antivirus/quarantine/"=dword:00000001 ==== Registry Search Results for "g data" ====================== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DA4E3DA0-D07D-11d0-BD50-00A0C911CE86}\Instance\{2EB07EA0-7E70-11D0-A5D6-28DB04C10000}] "FriendlyName"="WDM Streaming Data Transforms" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{DA4E3DA0-D07D-11d0-BD50-00A0C911CE86}\Instance\{2EB07EA0-7E70-11D0-A5D6-28DB04C10000}] "FriendlyName"="WDM Streaming Data Transforms" ==== Registry Search Results for "gdata" ====================== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0383751a-098b-11d8-9414-505054503030}] @="IApiTracingDataCollector" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{411F3E08-E6B1-4789-AB29-755C52E52AC4}] @="IDebugDataGrid" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{0383751a-098b-11d8-9414-505054503030}] @="IApiTracingDataCollector" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{411F3E08-E6B1-4789-AB29-755C52E52AC4}] @="IDebugDataGrid" ==== Registry Search Results for "gwx" ====================== No instances of string "gwx" found. ==== Registry Search Results for "zemana" ====================== No instances of string "zemana" found. ==== C:\zoek_backup content ====================== C:\zoek_backup (files=18 folders=14 4606876 bytes) ==== EOF on za 01-10-2016 at 11:52:05,29 ======================