Zoek.exe v5.0.0.0 Updated 02-June-2014 Tool run by Administrator on za 14/06/2014 at 17:33:36,98. Microsoft Windows XP Professional 5.1.2600 Service Pack 3 x86 Running in: Normal Mode Internet Access Detected Launched: C:\Documents and Settings\Administrator\Bureaublad\zoek.exe [Scan all users] [Script inserted] ==== Older Logs ====================== C:\zoek-results2014-06-14-134734.log 23451 bytes ==== Deleting CLSID Registry Keys ====================== ==== Deleting CLSID Registry Values ====================== ==== Deleting Services ====================== ==== Deleting Files \ Folders ====================== "C:\autoexec.bat" deleted "C:\DECRYPT_INSTRUCTION.TXT" deleted "C:\DECRYPT_INSTRUCTION.URL" deleted "C:\DECRYPT_INSTRUCTION.HTML" deleted "C:\Documents and Settings\SASTD\Local Settings\Application Data\DECRYPT_INSTRUCTION.TXT" deleted "C:\Documents and Settings\SASTD\Local Settings\Application Data\DECRYPT_INSTRUCTION.URL" deleted "C:\Documents and Settings\SASTD\Local Settings\Application Data\DECRYPT_INSTRUCTION.HTML" deleted "C:\Documents and Settings\SASTD\Application Data\DECRYPT_INSTRUCTION.TXT" deleted "C:\Documents and Settings\SASTD\Application Data\DECRYPT_INSTRUCTION.URL" deleted "C:\Documents and Settings\SASTD\Application Data\DECRYPT_INSTRUCTION.HTML" deleted "C:\Documents and Settings\NetworkService\Local Settings\Application Data\DECRYPT_INSTRUCTION.TXT" deleted "C:\Documents and Settings\NetworkService\Local Settings\Application Data\DECRYPT_INSTRUCTION.URL" deleted "C:\Documents and Settings\NetworkService\Local Settings\Application Data\DECRYPT_INSTRUCTION.HTML" deleted "C:\Documents and Settings\NetworkService\Application Data\DECRYPT_INSTRUCTION.TXT" deleted "C:\Documents and Settings\NetworkService\Application Data\DECRYPT_INSTRUCTION.URL" deleted "C:\Documents and Settings\NetworkService\Application Data\DECRYPT_INSTRUCTION.HTML" deleted "C:\Documents and Settings\Gast\Local Settings\Application Data\DECRYPT_INSTRUCTION.TXT" deleted "C:\Documents and Settings\Gast\Local Settings\Application Data\DECRYPT_INSTRUCTION.URL" deleted "C:\Documents and Settings\Gast\Local Settings\Application Data\DECRYPT_INSTRUCTION.HTML" deleted "C:\Documents and Settings\Gast\Application Data\DECRYPT_INSTRUCTION.TXT" deleted "C:\Documents and Settings\Gast\Application Data\DECRYPT_INSTRUCTION.URL" deleted "C:\Documents and Settings\Gast\Application Data\DECRYPT_INSTRUCTION.HTML" deleted "C:\Documents and Settings\Default User\Local Settings\Application Data\DECRYPT_INSTRUCTION.TXT" deleted "C:\Documents and Settings\Default User\Local Settings\Application Data\DECRYPT_INSTRUCTION.URL" deleted "C:\Documents and Settings\Default User\Local Settings\Application Data\DECRYPT_INSTRUCTION.HTML" deleted "C:\Documents and Settings\Default User\Application Data\DECRYPT_INSTRUCTION.TXT" deleted "C:\Documents and Settings\Default User\Application Data\DECRYPT_INSTRUCTION.URL" deleted "C:\Documents and Settings\Default User\Application Data\DECRYPT_INSTRUCTION.HTML" deleted "C:\Documents and Settings\Administrator\Local Settings\Application Data\DECRYPT_INSTRUCTION.URL" deleted "C:\Documents and Settings\Administrator\Local Settings\Application Data\DECRYPT_INSTRUCTION.TXT" deleted "C:\Documents and Settings\Administrator\Local Settings\Application Data\DECRYPT_INSTRUCTION.HTML" deleted "C:\Documents and Settings\Administrator\Application Data\DECRYPT_INSTRUCTION.URL" deleted "C:\Documents and Settings\Administrator\Application Data\DECRYPT_INSTRUCTION.TXT" deleted "C:\Documents and Settings\Administrator\Application Data\DECRYPT_INSTRUCTION.HTML" deleted "C:\Documents and Settings\SASTD\DECRYPT_INSTRUCTION.TXT" deleted "C:\Documents and Settings\SASTD\DECRYPT_INSTRUCTION.URL" deleted "C:\Documents and Settings\SASTD\DECRYPT_INSTRUCTION.HTML" deleted "C:\Documents and Settings\NetworkService\DECRYPT_INSTRUCTION.TXT" deleted "C:\Documents and Settings\NetworkService\DECRYPT_INSTRUCTION.URL" deleted "C:\Documents and Settings\NetworkService\DECRYPT_INSTRUCTION.HTML" deleted "C:\Documents and Settings\LocalService\DECRYPT_INSTRUCTION.TXT" deleted "C:\Documents and Settings\LocalService\DECRYPT_INSTRUCTION.URL" deleted "C:\Documents and Settings\LocalService\DECRYPT_INSTRUCTION.HTML" deleted "C:\Documents and Settings\Gast\DECRYPT_INSTRUCTION.TXT" deleted "C:\Documents and Settings\Gast\DECRYPT_INSTRUCTION.URL" deleted "C:\Documents and Settings\Gast\DECRYPT_INSTRUCTION.HTML" deleted "C:\Documents and Settings\Default User\DECRYPT_INSTRUCTION.TXT" deleted "C:\Documents and Settings\Default User\DECRYPT_INSTRUCTION.URL" deleted "C:\Documents and Settings\Default User\DECRYPT_INSTRUCTION.HTML" deleted "C:\Documents and Settings\Administrator\DECRYPT_INSTRUCTION.TXT" deleted "C:\Documents and Settings\Administrator\DECRYPT_INSTRUCTION.URL" deleted "C:\Documents and Settings\Administrator\DECRYPT_INSTRUCTION.HTML" deleted "C:\Documents and Settings\Administrator\Menu Start\Programma's\Opstarten\DECRYPT_INSTRUCTION.TXT" deleted "C:\Documents and Settings\Administrator\Menu Start\Programma's\Opstarten\DECRYPT_INSTRUCTION.HTML" deleted "C:\Documents and Settings\Administrator\Menu Start\Programma's\Opstarten\DECRYPT_INSTRUCTION.URL" deleted ==== Firefox Extensions Registry ====================== [HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions] "{20a82645-c095-46ed-80e3-08825760534b}"="c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension" [15/02/2010 19:06] ==== Set IE to Default ====================== Old Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://www.netonline.be/ondernemen/btw-nummers.asp#" New Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://www.netonline.be/ondernemen/btw-nummers.asp#" ==== All HKCU SearchScopes ====================== HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes "DefaultScope"="{600A4320-A13A-4EC1-AAB8-5409B112F60A}" {600A4320-A13A-4EC1-AAB8-5409B112F60A} Google Url="http://www.google.be/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7GGIE_nl" {6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}" ==== Empty IE Cache ====================== C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5 emptied successfully C:\Documents and Settings\Gast\Local Settings\Temporary Internet Files\Content.IE5 emptied successfully C:\Documents and Settings\SASTD\Local Settings\Temporary Internet Files\Content.IE5 emptied successfully C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5 emptied successfully C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5 emptied successfully C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot ==== Empty FireFox Cache ====================== No FireFox Profiles found ==== Empty Chrome Cache ====================== C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Cache emptied successfully ==== Empty All Flash Cache ====================== Flash Cache Emptied Successfully ==== Empty All Java Cache ====================== Java Cache cleared successfully ==== C:\zoek_backup content ====================== C:\zoek_backup (files=244 folders=38 56219103 bytes) ==== Empty Temp Folders ====================== C:\Documents and Settings\Administrator\Local Settings\Temp will be emptied at reboot C:\Documents and Settings\Default User\Local Settings\Temp emptied successfully C:\Documents and Settings\Gast\Local Settings\Temp emptied successfully C:\Documents and Settings\LocalService\Local Settings\Temp will be emptied at reboot C:\Documents and Settings\NetworkService\Local Settings\Temp emptied successfully C:\Documents and Settings\SASTD\Local Settings\Temp emptied successfully C:\WINDOWS\Temp will be emptied at reboot ==== After Reboot ====================== ==== Empty Temp Folders ====================== C:\WINDOWS\Temp successfully emptied C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp successfully emptied ==== Deleting Files / Folders ====================== "C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\index.dat" not deleted "C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat" not found "C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat" not deleted "C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat" not found "C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies" deleted "C:\Documents and Settings\LocalService\Local Settings\Temp\History" deleted "C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files" deleted ==== EOF on zo 15/06/2014 at 3:41:56,59 ======================