Zoek.exe v5.0.0.0 Updated 02-June-2014 Tool run by Administrator on za 14/06/2014 at 14:16:51,98. Microsoft Windows XP Professional 5.1.2600 Service Pack 3 x86 Running in: Normal Mode Internet Access Detected Launched: C:\Documents and Settings\Administrator\Bureaublad\zoek.exe [Scan all users] [Script inserted] [Checkboxes used] ==== System Restore Info ====================== 14/06/2014 14:22:48 Zoek.exe System Restore Point Created Succesfully. ==== Empty Folders Check ====================== C:\Documents and Settings\Administrator\Application Data\SampleView deleted successfully C:\Documents and Settings\NetworkService\Application Data\Apple Computer deleted successfully ==== Deleting CLSID Registry Keys ====================== ==== Deleting CLSID Registry Values ====================== ==== Deleting Services ====================== ==== Deleting Files \ Folders ====================== C:\Program Files\Enigma Software Group deleted C:\DOCUME~1\ALLUSE~1\APPLIC~1\DECRYPT_INSTRUCTION.TXT deleted C:\WINDOWS\System32\SET48.tmp deleted C:\WINDOWS\System32\SET49.tmp deleted C:\WINDOWS\System32\SET4A.tmp deleted C:\WINDOWS\System32\SET4E.tmp deleted C:\WINDOWS\System32\SET4F.tmp deleted C:\WINDOWS\System32\SET50.tmp deleted C:\WINDOWS\System32\SET54.tmp deleted C:\WINDOWS\System32\SET55.tmp deleted C:\WINDOWS\System32\SET56.tmp deleted "C:\DelFix.txt" deleted ==== Files Recently Created / Modified ====================== ====== C:\WINDOWS ==== ====== C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp ==== 2014-06-14 12:05:12 5634C601025C31032A0AF1590B4C0CA6 43008 ----a-w- C:\Documents and Settings\Administrator\Local Settings\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpt_bol4.dll 2014-06-12 21:07:44 CC6CBBC56DEF66E021CFCDBE27CA008D 46212176 ----a-w- C:\Documents and Settings\Administrator\Local Settings\Temp\SHSetup.exe ====== Java Cache ===== 2014-06-14 11:43:34 7E366D7E5AEA9B3ADDCD9268BEBEFB43 62 ----a-w- C:\Documents and Settings\Administrator\Application Data\Sun\Java\Deployment\cache\6.0\17\49a00451-6.0.lap 2014-06-14 12:13:19 C1BBA7F1278F193AB584FFF460DB5E2A 17878 ----a-w- C:\Documents and Settings\Administrator\Local Settings\Application Data\Sun\Java\Deployment\cache\6.0\12\eef218c-75fa6374 2014-06-14 12:13:18 415FC9732A3F4D89A0E01251CD66E136 646 ----a-w- C:\Documents and Settings\Administrator\Local Settings\Application Data\Sun\Java\Deployment\cache\6.0\17\49a00451-14732fb3 2014-06-14 12:13:19 C958367CE6AECAAB35D81F0896B9993D 425 ----a-w- C:\Documents and Settings\Administrator\Local Settings\Application Data\Sun\Java\Deployment\cache\6.0\17\49a00451-aa56bb018d5de3a531ee91cc4857f0f479656e5370ebf87789e721aaaf530ebc-6.0.lap 2014-06-14 12:13:18 415FC9732A3F4D89A0E01251CD66E136 646 ----a-w- C:\Documents and Settings\Administrator\Local Settings\Application Data\Sun\Java\Deployment\cache\6.0\18\3cb32f52-4848e03d 2014-06-14 12:13:19 527E096E3C32E208158D43D38F9428CD 6860 ----a-w- C:\Documents and Settings\Administrator\Local Settings\Application Data\Sun\Java\Deployment\cache\6.0\43\1ca2666b-1c05b88f ====== C:\WINDOWS\system32 ===== 2014-06-14 12:12:42 E47CF14309493B894523F13C4E173073 145408 ----a-w- C:\WINDOWS\System32\javacpl.cpl 2014-06-14 12:12:42 CEE4C9E092168CEBD187491AF6FDA8FB 264616 ----a-w- C:\WINDOWS\System32\javaws.exe 2014-06-14 12:12:28 ECB3AB701D6E26F5E54C58957E34E719 175528 ----a-w- C:\WINDOWS\System32\javaw.exe 2014-06-14 12:12:28 B1799EE2C6B8435E7227844C5FC08BCC 96680 ----a-w- C:\WINDOWS\System32\WindowsAccessBridge.dll 2014-06-14 12:12:28 2251971694E17BAC4E344DC2B7CD7ADD 175528 ----a-w- C:\WINDOWS\System32\java.exe 2014-06-14 11:52:49 1819605022CACB5E0E2095B72F3417D8 114688 ----a-w- C:\WINDOWS\System32\chg.exe ====== C:\WINDOWS\system32\drivers ===== ====== C:\WINDOWS\Tasks ====== ====== C:\WINDOWS\Temp ====== ======= C:\Program Files ===== 2014-06-12 21:08:45 -------- d-----w- C:\Program Files\Common Files\Wise Installation Wizard ======= C: ===== 2014-06-12 21:11:20 D41D8CD98F00B204E9800998ECF8427E 0 ----a-w- C:\autoexec.bat 2014-06-11 15:05:59 E477264D25FDEC5D938049FD1EF00A2C 4064 ----a-w- C:\DECRYPT_INSTRUCTION.TXT 2014-06-11 15:05:59 342117E4FEC4A6AD0164D06935F5D005 266 ----a-w- C:\DECRYPT_INSTRUCTION.URL 2014-06-11 15:05:59 2FF10F05C220B5B2A062634364E7BF84 8118 ----a-w- C:\DECRYPT_INSTRUCTION.HTML ====== C:\Documents and Settings\Administrator\Application Data ====== 2014-06-14 12:13:17 -------- d-----w- C:\Documents and Settings\Administrator\Local Settings\Application Data\Sun 2014-06-12 18:50:56 -------- d-----w- C:\Documents and Settings\Administrator\Application Data\Help 2014-06-12 18:50:55 -------- d-----w- C:\Documents and Settings\Administrator\Local Settings\Application Data\Help 2014-06-11 14:59:12 E477264D25FDEC5D938049FD1EF00A2C 4064 ----a-w- C:\Documents and Settings\SASTD\Local Settings\Application Data\DECRYPT_INSTRUCTION.TXT 2014-06-11 14:59:12 342117E4FEC4A6AD0164D06935F5D005 266 ----a-w- C:\Documents and Settings\SASTD\Local Settings\Application Data\DECRYPT_INSTRUCTION.URL 2014-06-11 14:59:12 2FF10F05C220B5B2A062634364E7BF84 8118 ----a-w- C:\Documents and Settings\SASTD\Local Settings\Application Data\DECRYPT_INSTRUCTION.HTML 2014-06-11 14:59:11 E477264D25FDEC5D938049FD1EF00A2C 4064 ----a-w- C:\Documents and Settings\SASTD\Application Data\DECRYPT_INSTRUCTION.TXT 2014-06-11 14:59:11 342117E4FEC4A6AD0164D06935F5D005 266 ----a-w- C:\Documents and Settings\SASTD\Application Data\DECRYPT_INSTRUCTION.URL 2014-06-11 14:59:11 2FF10F05C220B5B2A062634364E7BF84 8118 ----a-w- C:\Documents and Settings\SASTD\Application Data\DECRYPT_INSTRUCTION.HTML 2014-06-11 14:59:06 E477264D25FDEC5D938049FD1EF00A2C 4064 ----a-w- C:\Documents and Settings\NetworkService\Local Settings\Application Data\DECRYPT_INSTRUCTION.TXT 2014-06-11 14:59:06 342117E4FEC4A6AD0164D06935F5D005 266 ----a-w- C:\Documents and Settings\NetworkService\Local Settings\Application Data\DECRYPT_INSTRUCTION.URL 2014-06-11 14:59:06 2FF10F05C220B5B2A062634364E7BF84 8118 ----a-w- C:\Documents and Settings\NetworkService\Local Settings\Application Data\DECRYPT_INSTRUCTION.HTML 2014-06-11 14:59:04 E477264D25FDEC5D938049FD1EF00A2C 4064 ----a-w- C:\Documents and Settings\NetworkService\Application Data\DECRYPT_INSTRUCTION.TXT 2014-06-11 14:59:04 342117E4FEC4A6AD0164D06935F5D005 266 ----a-w- C:\Documents and Settings\NetworkService\Application Data\DECRYPT_INSTRUCTION.URL 2014-06-11 14:59:04 2FF10F05C220B5B2A062634364E7BF84 8118 ----a-w- C:\Documents and Settings\NetworkService\Application Data\DECRYPT_INSTRUCTION.HTML 2014-06-11 14:59:02 E477264D25FDEC5D938049FD1EF00A2C 4064 ----a-w- C:\Documents and Settings\Gast\Local Settings\Application Data\DECRYPT_INSTRUCTION.TXT 2014-06-11 14:59:02 342117E4FEC4A6AD0164D06935F5D005 266 ----a-w- C:\Documents and Settings\Gast\Local Settings\Application Data\DECRYPT_INSTRUCTION.URL 2014-06-11 14:59:02 2FF10F05C220B5B2A062634364E7BF84 8118 ----a-w- C:\Documents and Settings\Gast\Local Settings\Application Data\DECRYPT_INSTRUCTION.HTML 2014-06-11 14:58:58 E477264D25FDEC5D938049FD1EF00A2C 4064 ----a-w- C:\Documents and Settings\Gast\Application Data\DECRYPT_INSTRUCTION.TXT 2014-06-11 14:58:58 342117E4FEC4A6AD0164D06935F5D005 266 ----a-w- C:\Documents and Settings\Gast\Application Data\DECRYPT_INSTRUCTION.URL 2014-06-11 14:58:58 2FF10F05C220B5B2A062634364E7BF84 8118 ----a-w- C:\Documents and Settings\Gast\Application Data\DECRYPT_INSTRUCTION.HTML 2014-06-11 14:58:50 E477264D25FDEC5D938049FD1EF00A2C 4064 ----a-w- C:\Documents and Settings\Default User\Local Settings\Application Data\DECRYPT_INSTRUCTION.TXT 2014-06-11 14:58:50 342117E4FEC4A6AD0164D06935F5D005 266 ----a-w- C:\Documents and Settings\Default User\Local Settings\Application Data\DECRYPT_INSTRUCTION.URL 2014-06-11 14:58:50 2FF10F05C220B5B2A062634364E7BF84 8118 ----a-w- C:\Documents and Settings\Default User\Local Settings\Application Data\DECRYPT_INSTRUCTION.HTML 2014-06-11 14:58:49 E477264D25FDEC5D938049FD1EF00A2C 4064 ----a-w- C:\Documents and Settings\Default User\Application Data\DECRYPT_INSTRUCTION.TXT 2014-06-11 14:58:49 342117E4FEC4A6AD0164D06935F5D005 266 ----a-w- C:\Documents and Settings\Default User\Application Data\DECRYPT_INSTRUCTION.URL 2014-06-11 14:58:49 2FF10F05C220B5B2A062634364E7BF84 8118 ----a-w- C:\Documents and Settings\Default User\Application Data\DECRYPT_INSTRUCTION.HTML 2014-06-10 13:57:00 C6A932D3C1D058832EFEE9606D1627E4 264 ----a-w- C:\Documents and Settings\Administrator\Local Settings\Application Data\DECRYPT_INSTRUCTION.URL 2014-06-10 13:57:00 48E6F7A2398505C35F66138187DA4EFB 4062 ----a-w- C:\Documents and Settings\Administrator\Local Settings\Application Data\DECRYPT_INSTRUCTION.TXT 2014-06-10 13:57:00 42D692F4B2A425B3B35E626BD150F388 8116 ----a-w- C:\Documents and Settings\Administrator\Local Settings\Application Data\DECRYPT_INSTRUCTION.HTML 2014-06-10 13:52:14 C6A932D3C1D058832EFEE9606D1627E4 264 ----a-w- C:\Documents and Settings\Administrator\Application Data\DECRYPT_INSTRUCTION.URL 2014-06-10 13:52:14 48E6F7A2398505C35F66138187DA4EFB 4062 ----a-w- C:\Documents and Settings\Administrator\Application Data\DECRYPT_INSTRUCTION.TXT 2014-06-10 13:52:14 42D692F4B2A425B3B35E626BD150F388 8116 ----a-w- C:\Documents and Settings\Administrator\Application Data\DECRYPT_INSTRUCTION.HTML ====== C:\Documents and Settings\Administrator ====== 2014-06-12 23:10:19 -------- d--h--r- C:\Documents and Settings\Administrator\Onlangs geopend 2014-06-11 14:59:13 E477264D25FDEC5D938049FD1EF00A2C 4064 ----a-w- C:\Documents and Settings\SASTD\DECRYPT_INSTRUCTION.TXT 2014-06-11 14:59:13 342117E4FEC4A6AD0164D06935F5D005 266 ----a-w- C:\Documents and Settings\SASTD\DECRYPT_INSTRUCTION.URL 2014-06-11 14:59:13 2FF10F05C220B5B2A062634364E7BF84 8118 ----a-w- C:\Documents and Settings\SASTD\DECRYPT_INSTRUCTION.HTML 2014-06-11 14:59:06 E477264D25FDEC5D938049FD1EF00A2C 4064 ----a-w- C:\Documents and Settings\NetworkService\DECRYPT_INSTRUCTION.TXT 2014-06-11 14:59:06 342117E4FEC4A6AD0164D06935F5D005 266 ----a-w- C:\Documents and Settings\NetworkService\DECRYPT_INSTRUCTION.URL 2014-06-11 14:59:06 2FF10F05C220B5B2A062634364E7BF84 8118 ----a-w- C:\Documents and Settings\NetworkService\DECRYPT_INSTRUCTION.HTML 2014-06-11 14:59:04 E477264D25FDEC5D938049FD1EF00A2C 4064 ----a-w- C:\Documents and Settings\LocalService\DECRYPT_INSTRUCTION.TXT 2014-06-11 14:59:04 342117E4FEC4A6AD0164D06935F5D005 266 ----a-w- C:\Documents and Settings\LocalService\DECRYPT_INSTRUCTION.URL 2014-06-11 14:59:04 2FF10F05C220B5B2A062634364E7BF84 8118 ----a-w- C:\Documents and Settings\LocalService\DECRYPT_INSTRUCTION.HTML 2014-06-11 14:59:03 E477264D25FDEC5D938049FD1EF00A2C 4064 ----a-w- C:\Documents and Settings\Gast\DECRYPT_INSTRUCTION.TXT 2014-06-11 14:59:03 342117E4FEC4A6AD0164D06935F5D005 266 ----a-w- C:\Documents and Settings\Gast\DECRYPT_INSTRUCTION.URL 2014-06-11 14:59:03 2FF10F05C220B5B2A062634364E7BF84 8118 ----a-w- C:\Documents and Settings\Gast\DECRYPT_INSTRUCTION.HTML 2014-06-11 14:58:51 E477264D25FDEC5D938049FD1EF00A2C 4064 ----a-w- C:\Documents and Settings\Default User\DECRYPT_INSTRUCTION.TXT 2014-06-11 14:58:51 342117E4FEC4A6AD0164D06935F5D005 266 ----a-w- C:\Documents and Settings\Default User\DECRYPT_INSTRUCTION.URL 2014-06-11 14:58:51 2FF10F05C220B5B2A062634364E7BF84 8118 ----a-w- C:\Documents and Settings\Default User\DECRYPT_INSTRUCTION.HTML 2014-06-11 14:17:25 E477264D25FDEC5D938049FD1EF00A2C 4064 ----a-w- C:\Documents and Settings\Administrator\DECRYPT_INSTRUCTION.TXT 2014-06-11 14:17:25 342117E4FEC4A6AD0164D06935F5D005 266 ----a-w- C:\Documents and Settings\Administrator\DECRYPT_INSTRUCTION.URL 2014-06-11 14:17:25 2FF10F05C220B5B2A062634364E7BF84 8118 ----a-w- C:\Documents and Settings\Administrator\DECRYPT_INSTRUCTION.HTML ====== C: exe-files == 2014-06-14 12:10:12 B1BA71EDE129F3D059571E0B8931E12C 918952 ----a-w- C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\ZC5RZ614\JavaSetup7u60[2].exe 2014-06-14 11:34:21 3842C46F2FBC7522EF625F1833530804 145408 ----a-w- C:\Documents and Settings\Administrator\Application Data\Sun\Java\jre1.7.0_60\lzma.exe 2014-06-14 11:30:02 B1BA71EDE129F3D059571E0B8931E12C 918952 ----a-w- C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\ZC5RZ614\JavaSetup7u60[1].exe 2014-06-13 06:43:39 8685FAF50C04F9A9C2F56FF64B0B7ACB 1107968 ----a-w- C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\ZC5RZ614\RSIT[1].exe 2014-06-12 21:07:44 CC6CBBC56DEF66E021CFCDBE27CA008D 46212176 ----a-w- C:\Documents and Settings\Administrator\Local Settings\Temp\SHSetup.exe === C: other files == 2014-06-14 12:12:07 8E29BBCCC8D802D36701633A7842FE74 18636 ----a-w- C:\Program Files\Java\jre7\lib\deploy\ffjcext.zip 2014-06-12 21:11:20 D41D8CD98F00B204E9800998ECF8427E 0 ----a-w- C:\autoexec.bat ==== Startup Registry Enabled ====================== [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [HKEY_USERS\S-1-5-21-2302939687-2342822692-2367873619-500\Software\Microsoft\Windows\CurrentVersion\Run] "swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" "AdobeUpdater"="C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe" "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" "GBMLite8AgentLaCie"="C:\Program Files\LaCie\Genie Backup Assistant\GBMAgent.exe" "WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" "Gadwin PrintScreen (32-bit)"="C:\Program Files\Gadwin\Gadwin PrintScreen\PrintScreen32.exe /nosplash" [HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce] "WUAppSetup"="C:\Program Files\Common Files\logishrd\WUApp32.exe -v 0x046d -p 0x08c1 -f video -m logitech -d 11.0.0.1217" [HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\RunOnce] "WUAppSetup"="C:\Program Files\Common Files\logishrd\WUApp32.exe -v 0x046d -p 0x08c1 -f video -m logitech -d 11.0.0.1217" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" "SoundMAX"="C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray" "AccelerometerSysTrayApplet"="C:\WINDOWS\system32\AccelerometerSt.exe" "PTHOSTTR"="C:\Program Files\HPQ\HP ProtectTools Security Manager\PTHOSTTR.EXE /Start" "DLA"="C:\WINDOWS\System32\DLA\DLACTRLW.EXE" "SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" "hpWirelessAssistant"="C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" "CognizanceTS"="rundll32.exe C:\PROGRA~1\HPQ\IAM\Bin\AsTsVcc.dll,RegisterModule" "Cpqset"="C:\Program Files\HPQ\Default Settings\cpqset.exe" "Recguard"="C:\WINDOWS\Sminst\Recguard.exe" "Reminder"="C:\WINDOWS\Creator\Remind_XP.exe" "Scheduler"="C:\WINDOWS\SMINST\Scheduler.exe" "ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\cli.exe runtime -Delay" "WatchDog"="C:\Program Files\InterVideo\DVD Check\DVDCheck.exe" "Acrobat Assistant 8.0"="C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" "Adobe_ID0EYTHM"="C:\PROGRA~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE" "ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" "Rkiwrtk"="C:\Program Files\PFU\Rack2\RKiwrtK.exe" "AppleSyncNotifier"="C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" "APSDaemon"="C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe" "GBMLite8AgentLaCie"="C:\Program Files\LaCie\Genie Backup Assistant\GBMAgent.exe" "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe -atboottime" "HP Software Update"="C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe" "StatusAlerts"="C:\Program Files\HP\StatusAlerts\bin\HPStatusAlerts.exe /enum:on /alerts:on /notifications:on /fl:on /fr:on /appData:on /tmcp:on" "SunJavaUpdateSched"="C:\Program Files\Common Files\Java\Java Update\jusched.exe" "MsmqIntCert"="regsvr32 /s mqrt.dll" "QlbCtrl"="%ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" "AdobeUpdater"="C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe" "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" "GBMLite8AgentLaCie"="C:\Program Files\LaCie\Genie Backup Assistant\GBMAgent.exe" "WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" "Gadwin PrintScreen (32-bit)"="C:\Program Files\Gadwin\Gadwin PrintScreen\PrintScreen32.exe /nosplash" ==== Startup Folders ====================== 2014-06-11 15:06:00 8118 ----a-w- C:\Documents and Settings\Administrator\Menu Start\Programma's\Opstarten\DECRYPT_INSTRUCTION.HTML 2014-06-11 15:06:00 4064 ----a-w- C:\Documents and Settings\Administrator\Menu Start\Programma's\Opstarten\DECRYPT_INSTRUCTION.TXT 2014-06-11 15:06:00 408 ----a-w- C:\Documents and Settings\Administrator\Menu Start\Programma's\Opstarten\DECRYPT_INSTRUCTION.URL 2013-11-06 08:08:02 1052 ----a-w- C:\Documents and Settings\Administrator\Menu Start\Programma's\Opstarten\Dropbox.lnk ==== Task Scheduler Jobs ====================== C:\WINDOWS\tasks\AppleSoftwareUpdate.job --a------ C:\Program Files\AppleC:oftware Update\SoftwareUpdate.exe [] C:\WINDOWS\tasks\ASC4_PerformanceMonitor.job --a------ C:\Program Files\IObit\Advanced SystemCare 4\PMonitor.exe [] C:\WINDOWS\tasks\Google Software Updater.job --a------ [Undetermined Task] C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job --a------ C:\Program Files\Google\Update\GoogleUpdate.exe [03/02/2009 21:50] C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job --a------ C:\Program Files\Google\Update\GoogleUpdate.exe [03/02/2009 21:50] C:\WINDOWS\tasks\Microsoft Windows XP - aanmelding voor kennisgeving over einde van service.job --a------ [Undetermined Task] C:\WINDOWS\tasks\Microsoft Windows XP - maandelijkse kennisgeving over einde van service.job --a------ C:\WINDOWS\system32\xp_eos.exe [27/02/2014 01:28] C:\WINDOWS\tasks\User_Feed_Synchronization-{3AD2A9C9-9243-48E5-B884-E4E17C15C431}.job --ah----- C:\WINDOWS\system32\msfeedssync.exe [08/03/2009 05:31] ==== Firefox Extensions Registry ====================== [HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions] "{20a82645-c095-46ed-80e3-08825760534b}"="c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension" [15/02/2010 19:06] ==== Set IE to Default ====================== Old Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://www.netonline.be/ondernemen/btw-nummers.asp#" New Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://www.netonline.be/ondernemen/btw-nummers.asp#" ==== All HKCU SearchScopes ====================== HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes "DefaultScope"="{600A4320-A13A-4EC1-AAB8-5409B112F60A}" {600A4320-A13A-4EC1-AAB8-5409B112F60A} Google Url="http://www.google.be/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7GGIE_nl" {6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}" ==== Empty IE Cache ====================== C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5 emptied successfully C:\Documents and Settings\Gast\Local Settings\Temporary Internet Files\Content.IE5 emptied successfully C:\Documents and Settings\NetworkService\Local Settings\Temp\Temporary Internet Files\Content.IE5 emptied successfully C:\Documents and Settings\SASTD\Local Settings\Temporary Internet Files\Content.IE5 emptied successfully C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5 emptied successfully C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5 emptied successfully C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot ==== Empty FireFox Cache ====================== No FireFox Profiles found ==== Empty Chrome Cache ====================== C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Cache emptied successfully ==== Empty All Flash Cache ====================== Flash Cache Emptied Successfully ==== Empty All Java Cache ====================== Java Cache cleared successfully ==== C:\zoek_backup content ====================== C:\zoek_backup (files=187 folders=33 55953312 bytes) ==== Empty Temp Folders ====================== C:\Documents and Settings\Administrator\Local Settings\Temp will be emptied at reboot C:\Documents and Settings\Default User\Local Settings\Temp emptied successfully C:\Documents and Settings\Gast\Local Settings\Temp emptied successfully C:\Documents and Settings\LocalService\Local Settings\Temp will be emptied at reboot C:\Documents and Settings\NetworkService\Local Settings\Temp emptied successfully C:\Documents and Settings\SASTD\Local Settings\Temp emptied successfully C:\WINDOWS\Temp will be emptied at reboot ==== After Reboot ====================== ==== Empty Temp Folders ====================== C:\WINDOWS\Temp successfully emptied C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp successfully emptied ==== Empty Recycle Bin ====================== C:\RECYCLER successfully emptied ==== Deleting Files / Folders ====================== "C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\index.dat" not deleted "C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat" not deleted "C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat" not deleted "C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat" not deleted "C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies" not deleted "C:\Documents and Settings\LocalService\Local Settings\Temp\History" not deleted "C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files" not deleted ==== EOF on za 14/06/2014 at 15:47:34,21 ======================