Zoek.exe Version 4.0.0.5 Updated 09-October-2013 Tool run by Eigenaar on za 12-10-2013 at 17:25:38,82. Microsoft® Windows Vista™ Business 6.0.6002 Service Pack 2 x86 Running in: Normal Mode Internet Access Detected Launched: E:\zoek\zoek.exe [Script inserted] ==== Older Logs ====================== \zoek-results2013-10-05-155204.log 581 bytes \zoek-results2013-10-05-160443.log 43268 bytes \zoek-results2013-10-05-163831.log 483 bytes \zoek-results2013-10-06-063905.log 531 bytes \zoek-results2013-10-06-110912.log 50346 bytes ==== Deleting CLSID Registry Keys ====================== ==== Deleting CLSID Registry Values ====================== ==== Deleting Services ====================== ==== Deleting Files \ Folders ====================== "C:\Users\Eigenaar\Downloads\DownloadManagerSetup.exe" deleted "C:\Users\Eigenaar\Downloads\HKV-Coupon-481441.pdf" deleted "C:\Program Files\AVG Nation toolbar\vprot.exe" deleted "C:\Windows\system32\appdata" deleted "C:\Program Files\AVG Nation toolbar" deleted "C:\Program Files\MyFree Codec" deleted "C:\ProgramData\AVG Nation toolbar" deleted "C:\Users\Eigenaar\AppData\Local\AVG Nation toolbar" deleted "C:\Users\Jeremy\AppData\Local\AVG Nation toolbar" deleted "C:\Users\Noah Jaira\AppData\Local\AVG Nation toolbar" deleted "C:\Users\Eigenaar\AppData\LocalLow\AVG Nation toolbar" deleted "C:\Users\Jeremy\AppData\LocalLow\AVG Nation toolbar" deleted "C:\Users\Noah Jaira\AppData\LocalLow\AVG Nation toolbar" deleted "C:\Windows\system32\config\systemprofile\AppData\LocalLow\AVG Nation toolbar" deleted ==== Startup Registry Enabled ====================== [HKEY_USERS\S-1-5-21-2310077886-2185433429-3398584410-1000\Software\Microsoft\Windows\CurrentVersion\Run] "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" "AutoStartNPSAgent"="C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe" "Skype"="C:\Program Files\Skype\Phone\Skype.exe /minimized /regrun" "KPeerNexonEU"="C:\Nexon\NEXON_EU_Downloader\nxEULauncher.exe" "COMMUNICATOR"="C:\Program Files\Microsoft Office Communicator\Communicator.exe /silentRetrials /background" "KiesPreload"="C:\Program Files\Samsung\Kies\Kies.exe /preload" [HKEY_USERS\S-1-5-21-2310077886-2185433429-3398584410-1003\Software\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe /autoRun" "AutoStartNPSAgent"="C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe" "WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" "Akamai NetSession Interface"="C:\Users\Jeremy\AppData\Local\Akamai\netsession_win.exe" "Spybot-S&D Cleaning"="C:\Program Files\Spybot - Search & Destroy 2\SDCleaner.exe /autoclean" "Skype"="C:\Program Files\Skype\Phone\Skype.exe /minimized /regrun" "Softonic for Windows"="C:\Users\Jeremy\AppData\Local\Softonic\Softonic.exe -minimize" "COMMUNICATOR"="C:\Program Files\Microsoft Office Communicator\Communicator.exe /silentRetrials /background" "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" "KPeerNexonEU"="C:\Nexon\NEXON_EU_Downloader\nxEULauncher.exe" "KiesPreload"="C:\Program Files\Samsung\Kies\Kies.exe /preload" "KiesAirMessage"="C:\Program Files\Samsung\Kies\KiesAirMessage.exe -startup" @="C:\Windows\system32\External\FirmwareUpdate\KiesPDLR.exe" [HKEY_USERS\S-1-5-21-2310077886-2185433429-3398584410-1003\Software\Microsoft\Windows\CurrentVersion\RunOnce] "Shockwave Updater"="C:\Windows\system32\Adobe\Shockwave 11\SwHelper_1151601.exe -Update -1151601 -Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; Trident/4.0; BTRS122412; GTB7.3; SIMBAR={D382C689-670C-432D-80A6-C751941814B3}; SLCC1; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729; .NET4.0C) -http://static.funnygames.nl/games/8/2768/2768.dcr" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" "AppleSyncNotifier"="C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" "APSDaemon"="C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe" "ControlCenter4"="C:\Program Files\ControlCenter4\BrCcBoot.exe /autorun" "BrStsMon00"="C:\Program Files\Browny02\Brother\BrStMonW.exe /AUTORUN" "QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe -atboottime" "SunJavaUpdateSched"="C:\Program Files\Common Files\Java\Java Update\jusched.exe" "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" "TkBellExe"="C:\Program Files\Real\RealPlayer\Update\realsched.exe -osboot" "KiesTrayAgent"="C:\Program Files\Samsung\Kies\KiesTrayAgent.exe" "GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" "RtHDVCpl"="C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe" "Skytel"="C:\Program Files\Realtek\Audio\HDA\Skytel.exe" "IgfxTray"="C:\Windows\system32\igfxtray.exe" "HotKeysCmds"="C:\Windows\system32\hkcmd.exe" "Persistence"="C:\Windows\system32\igfxpers.exe" "vProt"="C:\Program Files\AVG Nation toolbar\vprot.exe" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" "AutoStartNPSAgent"="C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe" "Skype"="C:\Program Files\Skype\Phone\Skype.exe /minimized /regrun" "KPeerNexonEU"="C:\Nexon\NEXON_EU_Downloader\nxEULauncher.exe" "COMMUNICATOR"="C:\Program Files\Microsoft Office Communicator\Communicator.exe /silentRetrials /background" "KiesPreload"="C:\Program Files\Samsung\Kies\Kies.exe /preload" ==== Startup Registry Disabled ====================== [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run-] "MobileDocuments"="C:\\Program Files\\Common Files\\Apple\\Internet Services\\ubd.exe" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run-] "NPSStartup"="" "aaservice"="\"C:\\Program Files/Timeslot/servicets.exe\"" "Adobe ARM"="\"C:\\Program Files\\Common Files\\Adobe\\ARM\\1.0\\AdobeARM.exe\"" "QuickTime Task"="\"C:\\Program Files\\QuickTime\\QTTask.exe\" -atboottime" "iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\"" "SunJavaUpdateSched"="\"C:\\Program Files\\Common Files\\Java\\Java Update\\jusched.exe\"" ==== Startup Folders ====================== 2013-01-10 16:07:47 954 ----a-w- C:\Users\Eigenaar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk 2013-08-15 17:45:46 2117 ----a-w- C:\Users\Eigenaar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Mediacontrole Picture Motion Browser.lnk ==== Task Scheduler Jobs ====================== C:\Windows\tasks\GoogleUpdateTaskMachineCore.job --a------ [Undetermined Task] C:\Windows\tasks\GoogleUpdateTaskMachineUA.job --a------ C:\Program Files\Google\Update\GoogleUpdate.exe [13-10-2010 13:46] ==== Other Scheduled Tasks ====================== "C:\Windows\system32\tasks\Adobe-online actualiseringsprogramma" [C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe] "C:\Windows\system32\tasks\CreateChoiceProcessTask" [C:\Windows\System32\browserchoice.exe] "C:\Windows\system32\tasks\GoogleUpdateTaskMachineCore" [C:\Program Files\Google\Update\GoogleUpdate.exe] "C:\Windows\system32\tasks\GoogleUpdateTaskMachineUA" [C:\Program Files\Google\Update\GoogleUpdate.exe] "C:\Windows\system32\tasks\Java Update Scheduler" [C:\Program Files\Common Files\Java\Java Update\jusched.exe] "C:\Windows\system32\tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-2310077886-2185433429-3398584410-1000" [C:\Program Files\Real\RealUpgrade\RealUpgrade.exe] "C:\Windows\system32\tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-2310077886-2185433429-3398584410-1000" [C:\Program Files\Real\RealUpgrade\RealUpgrade.exe] "C:\Windows\system32\tasks\User_Feed_Synchronization-{1AA81BD2-C420-45CF-B1EE-8E3F334794CB}" [C:\Windows\system32\msfeedssync.exe] "C:\Windows\system32\tasks\User_Feed_Synchronization-{AEF7F1A7-0CB1-4482-AB62-D3FD1FBB024D}" [C:\Windows\system32\msfeedssync.exe] "C:\Windows\system32\tasks\User_Feed_Synchronization-{B1984ED4-027D-4C85-8DA8-BCCA61348330}" [C:\Windows\system32\msfeedssync.exe] "C:\Windows\system32\tasks\{955E0B07-7EE8-411F-B14A-A8AED4BADA1D}" [C:\Program Files\Skype\\Phone\Skype.exe] "C:\Windows\system32\tasks\{F2362619-883E-4AAF-A795-287C675DEAFD}" [C:\Program Files\Skype\\Phone\Skype.exe] "C:\Windows\system32\tasks\Apple\AppleSoftwareUpdate" [C:\Program Files\Apple Software Update\SoftwareUpdate.exe] "C:\Windows\system32\tasks\ASUS\ASUS RegRun Loader" [C:\Program Files\ASUS\AASP\1.00.95\AsLoader.exe] "C:\Windows\system32\tasks\ASUS\ASUS Update Checker" [C:\Program Files\ASUS\ASUSUpdate\UpdateChecker\UpdateChecker.exe] ==== Firefox Extensions Registry ====================== [HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions] "{DF153AFF-6948-45d7-AC98-4FC4AF8A08E2}"="C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext" [05-09-2013 09:49] ==== Chrome Look ====================== HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions idhngdhcfkoamngbedgpaokgjbnpdiji - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Chrome\Ext\realdownloader.crx[14-08-2013 15:24] kiplfnciaokpcennlkldkdaeaaomamof - C:\Users\Eigenaar\AppData\Local\Torch\Plugins\TorchPlugin.crx[03-01-2013 15:24] ndibdjnfmopecpmkdieinmbadjfpblof - C:\ProgramData\AVG Nation toolbar\ChromeExt\17.0.1.12\avg.crx[] RealDownloader - Eigenaar - Default\Extensions\idhngdhcfkoamngbedgpaokgjbnpdiji Torch Share - Eigenaar - Default\Extensions\kiplfnciaokpcennlkldkdaeaaomamof AVG Nation toolbar - Eigenaar - Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof Chrome In-App Payments service - Eigenaar - Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda RealDownloader - Jeremy - Default\Extensions\idhngdhcfkoamngbedgpaokgjbnpdiji AVG Nation toolbar - Jeremy - Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof Chrome In-App Payments service - Jeremy - Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda RealDownloader - Noah Jaira - Default\Extensions\idhngdhcfkoamngbedgpaokgjbnpdiji AVG Nation toolbar - Noah Jaira - Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof ==== Chrome Fix ====================== C:\Users\Eigenaar\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof deleted successfully C:\Users\Jeremy\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof deleted successfully C:\Users\Noah Jaira\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof deleted successfully C:\Users\Jeremy\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_ndibdjnfmopecpmkdieinmbadjfpblof_0.localstorage deleted successfully C:\Users\Jeremy\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_ndibdjnfmopecpmkdieinmbadjfpblof_0.localstorage-journal deleted successfully ==== Set IE to Default ====================== Old Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes] No DefaultScope Set For HKCU New Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes] "DefaultScope"="{6A1806CD-94D4-4689-BA73-E35EA1EA9990}" ==== All HKCU SearchScopes ====================== HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes {0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC" {6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}" ==== Reset Google Chrome ====================== C:\Users\Eigenaar\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully C:\Users\Gast\AppData\Local\Google\Chrome\User Data\Default\preferences was reset successfully C:\Users\Jeremy\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully C:\Users\Noah Jaira\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully C:\Users\Eigenaar\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully C:\Users\Gast\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully C:\Users\Jeremy\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully C:\Users\Noah Jaira\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully ==== Deleting Registry Keys ====================== HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof deleted successfully ==== Empty IE Cache ====================== C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Eigenaar\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully C:\Users\Eigenaar\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Jeremy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully C:\Users\Noah Jaira\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Noah Jaira\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Jeremy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0E9OK4N8 will be deleted at reboot C:\Users\Jeremy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5QX05UT0 will be deleted at reboot C:\Users\Jeremy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BQFXFTBF will be deleted at reboot C:\Users\Eigenaar\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot C:\Users\Jeremy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot ==== Empty FireFox Cache ====================== No FireFox Profiles found ==== Empty Chrome Cache ====================== C:\Users\Eigenaar\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully C:\Users\Gast\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully C:\Users\Jeremy\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully C:\Users\Jeremy\AppData\Local\Google\Chrome\User Data\Default\Application Cache\Cache emptied successfully C:\Users\Noah Jaira\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully ==== Empty All Flash Cache ====================== No Flash Cache Found ==== Empty All Java Cache ====================== Java Cache cleared successfully