Zoek.exe v5.0.0.0 Updated 05-July-2014 Tool run by Vanherle on wo 09/07/2014 at 14:57:18,64. Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x64 Running in: Normal Mode Internet Access Detected Launched: C:\Users\Vanherle\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\L0R3G5DR\zoek.exe [Scan all users] [Checkboxes used] ==== Older Logs ====================== C:\zoek-results2013-03-31-134702.log 16168 bytes C:\zoek-results2014-07-09-114756.log 44266 bytes ==== Deleting CLSID Registry Keys ====================== HKEY_USERS\S-1-5-21-219209752-1814971668-716802256-1000\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2476} deleted successfully ==== Deleting CLSID Registry Values ====================== ==== Running Processes ====================== C:\Program Files\AVAST Software\Avast\AvastSvc.exe C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe C:\Windows\SysWOW64\svchost.exe C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe C:\Program Files (x86)\Settings Manager\systemk\SystemkService.exe C:\Program Files (x86)\Settings Manager\systemk\SystemkService.exe C:\Program Files (x86)\Settings Manager\systemk\systemku.exe C:\Program Files (x86)\CyberLink\PowerRecover\Reminder.exe C:\Windows\Pixart\Pac7302\Monitor.exe C:\Program Files (x86)\MyTomTom 3\MyTomTomSA.exe C:\Users\Vanherle\AppData\Roaming\uTorrent\uTorrent.exe C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe C:\Program Files\AVAST Software\Avast\AvastUI.exe C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSTE08.exe C:\Program Files (x86)\HP\Digital Imaging\bin\hpqbam08.exe C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe C:\Users\Vanherle\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\L0R3G5DR\zoek.exe C:\Windows\SysWOW64\cmd.exe C:\Windows\SysWOW64\cmd.exe C:\Windows\SysWOW64\cmd.exe C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE ==== Deleting Services ====================== ==== Deleting Files \ Folders ====================== C:\Users\Vanherle\AppData\LocalLow\DataMngr deleted ==== System Specs ====================== Windows: Windows 7 Home Premium Edition (64-bit) Service Pack 1 (Build 7601) Memory (RAM): 8159 MB CPU Info: Intel(R) Core(TM) i5-3450 CPU @ 3.10GHz CPU Speed: 3162,3 MHz Sound Card: Speakers (Realtek High Definiti | Display Adapters: AMD Radeon HD 7450 | AMD Radeon HD 7450 | RDPDD Chained DD | RDP Encoder Mirror Driver | RDP Reflector Display Driver Monitors: 1x; Generic Non-PnP Monitor | Screen Resolution: 1280 X 800 - 32 bit Network: Network Present Network Adapters: Microsoft Virtual WiFi Miniport Adapter | Realtek RTL8191SU Wireless LAN 802.11n USB 2.0 Network Adapter | Realtek PCIe GBE Family Controller CD / DVD Drives: 1x (E: | ) E: TSSTcorpCDDVDW SH-216AB Ports: COM Ports NOT Present. LPT Port NOT Present. Mouse: 3 Button Wheel Mouse Present Hard Disks: C: 1346,2GB | D: 50,0GB Hard Disks - Free: C: 1253,4GB | D: 30,4GB Manufacturer *: American Megatrends Inc. BIOS Info: AT/AT COMPATIBLE | 04/18/12 | MEDION - 11112011 Time Zone: West-Europa (standaardtijd) Motherboard *: MEDION MS-7728 Country: Belgi‰ Language: NLB ==== System Specs (Software) ====================== Anti-Virus: avast! Antivirus On-access scanning disabled (Outdated) Anti-Spyware: Windows Defender disabled (Outdated) Anti-Spyware: avast! Antivirus disabled (Outdated) Default Browser: Google Chrome 35.0.1916.153 Internet Explorer Version: 11.0.9600.17126 Mozilla Firefox version: 30.0 (x86 nl) Google Chrome version: 35.0.1916.153 Adobe Reader version: 11.0.07.79 Sun Java version: 1.7.0_60 (64-bit) Flash Player version: 13.0.0.214 ==== Files Recently Created / Modified ====================== ====== C:\Windows ==== 2014-07-08 13:51:40 357CEBBCD99C8928A2D1A61A6CACC168 43152 ----a-w- C:\Windows\avastSS.scr ====== C:\Users\Vanherle\AppData\Local\Temp ==== ====== Java Cache ===== ====== C:\Windows\SysWOW64 ===== ====== C:\Windows\SysWOW64\drivers ===== ====== C:\Windows\Sysnative ===== 2014-07-08 14:05:43 80DD24235A7E13AFC9E9EBC55ACE1ACF 313256 ----a-w- C:\Windows\Sysnative\javaws.exe 2014-07-08 14:05:40 B139EECAC4B3B43949FA0E2EDB66B905 111016 ----a-w- C:\Windows\Sysnative\WindowsAccessBridge-64.dll 2014-07-08 14:05:40 75F20BEDF6B95AA316C08D9D3F247692 189352 ----a-w- C:\Windows\Sysnative\java.exe 2014-07-08 14:05:40 22AEEB5D70AFF7C6CB43D16E6F5E2FFF 189352 ----a-w- C:\Windows\Sysnative\javaw.exe ====== C:\Windows\Sysnative\drivers ===== 2014-07-08 13:51:42 FF1E537A3632CBB9A0BF72B9FD0878D5 79184 ----a-w- C:\Windows\Sysnative\drivers\aswMonFlt.sys 2014-07-08 13:51:42 D95E64416A4A3ED6986E0F474DA934BD 29208 ----a-w- C:\Windows\Sysnative\drivers\aswHwid.sys 2014-07-08 13:51:42 B8FDEDE963B82CFD23B3A53A3084666D 1041168 ----a-w- C:\Windows\Sysnative\drivers\aswSnx.sys 2014-07-08 13:51:42 A5757DE5F9C83AB40667A53D5126EA40 93568 ----a-w- C:\Windows\Sysnative\drivers\aswRdr2.sys 2014-07-08 13:51:42 645D97385F3F284FB5604F9B970F4D24 65776 ----a-w- C:\Windows\Sysnative\drivers\aswRvrt.sys 2014-07-08 13:51:42 48DED912CDE54FC0923B9858512366E1 92008 ----a-w- C:\Windows\Sysnative\drivers\aswStm.sys 2014-07-08 13:51:42 471A311745848B80339436688A8286E6 224896 ----a-w- C:\Windows\Sysnative\drivers\aswVmm.sys 2014-07-08 13:51:42 0DEDC041DF594AEC2C3BD00417CFAF60 427360 ----a-w- C:\Windows\Sysnative\drivers\aswsp.sys 2014-06-11 19:46:37 17F685B67C74B8F7BFED4308790B71DE 288192 ----a-w- C:\Windows\Sysnative\drivers\FWPKCLNT.SYS 2014-06-11 19:46:37 04ADD18EE5CC9FBEDAEC1DD1CD0CB45E 1903552 ----a-w- C:\Windows\Sysnative\drivers\tcpip.sys ====== C:\Windows\Tasks ====== 2014-07-08 13:52:04 446ED02ABEC7855E10B2F3F8763CE7F1 4182 ----a-w- C:\Windows\Sysnative\Tasks\avast! Emergency Update 2014-07-08 13:43:38 997E4EE08F75AB3D2490882015030E0B 3704 ----a-w- C:\Windows\Sysnative\Tasks\Java Update Scheduler ====== C:\Windows\Temp ====== ======= C:\Program Files ===== 2014-07-08 14:05:36 -------- d-----w- C:\Program Files\Java 2014-07-08 13:28:50 -------- d-----w- C:\Program Files\trend micro ======= C:\PROGRA~2 ===== 2014-07-08 14:06:30 -------- d-----w- C:\PROGRA~2\COMMON~1\Java 2014-06-16 16:11:00 -------- d-----w- C:\PROGRA~2\OpenOffice 4 2014-06-15 09:34:09 -------- d-----w- C:\PROGRA~2\GIMP-2.0 2014-06-15 08:57:58 -------- d-----w- C:\PROGRA~2\Linkey 2014-06-15 08:57:30 -------- d-----w- C:\PROGRA~2\Settings Manager 2014-06-15 08:57:21 -------- d-----w- C:\PROGRA~2\PhotoFiltre 7 2014-06-12 16:55:36 -------- d-----w- C:\PROGRA~2\Mozilla Thunderbird ======= C: ===== 2014-06-16 16:26:22 F23A62A687E1E1967F3CC7704A0DDA24 6 ----a-w- C:\ScrubRetValFile.txt ====== C:\Users\Vanherle\AppData\Roaming ====== 2014-07-09 11:23:42 -------- d-----w- C:\Windows\sysWoW64\config\systemprofile\AppData\Local\temp 2014-07-09 11:23:42 -------- d-----w- C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp 2014-07-09 11:23:42 -------- d-----w- C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp 2014-07-09 11:23:42 -------- d-----w- C:\Users\Vanherle\AppData\Local\Temp 2014-07-09 11:23:42 -------- d-----w- C:\Users\Default\AppData\Local\Temp 2014-07-09 11:23:42 -------- d-----w- C:\Users\Default User\AppData\Local\Temp 2014-07-08 13:53:45 -------- d-----w- C:\Users\Vanherle\AppData\Roaming\DropboxMaster 2014-07-08 13:53:40 -------- d-----w- C:\Users\Vanherle\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2014-07-08 13:53:24 -------- d-----w- C:\Users\Vanherle\AppData\Roaming\Dropbox 2014-07-08 13:40:39 -------- d-----w- C:\Users\Vanherle\AppData\Local\AVG 2014-07-06 18:24:28 -------- d-----w- C:\Users\Vanherle\AppData\Local\CrashRpt 2014-07-06 18:24:20 -------- d-----w- C:\Users\Vanherle\AppData\Roaming\GetnowUpdater 2014-07-06 18:23:39 -------- d-----w- C:\Users\Vanherle\AppData\Local\GetNowUpdater 2014-07-06 18:23:38 -------- d---a-w- C:\Users\Vanherle\AppData\Local\GetnowUninstall 2014-07-06 18:23:35 -------- d-----w- C:\Users\Vanherle\AppData\Roaming\PANASONIC SA-HE90 user guide 2014-06-16 16:12:46 -------- d-----w- C:\Users\Vanherle\AppData\Roaming\OpenOffice 2014-06-15 12:03:18 -------- d-----w- C:\Users\Vanherle\AppData\Local\Adobe 2014-06-15 09:47:27 -------- d-----w- C:\Users\Vanherle\AppData\Roaming\gtk-2.0 ====== C:\Users\Vanherle ====== 2014-07-08 13:52:12 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast 2014-07-08 05:09:27 -------- d-----w- C:\ProgramData\systemk 2014-06-16 16:11:40 -------- d-s---w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenOffice 4.1.0 2014-06-15 13:44:24 AEF50C788A615EF48B4D938BAF03E067 3604 ----a-w- C:\Users\Vanherle\.recently-used.xbel 2014-06-15 13:40:08 -------- d-----w- C:\ProgramData\Google 2014-06-15 09:47:24 -------- d-----w- C:\Users\Vanherle\.thumbnails 2014-06-15 09:34:32 -------- d-----w- C:\Users\Vanherle\.gimp-2.6 2014-06-15 09:34:21 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GIMP 2014-06-15 08:57:23 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PhotoFiltre 7 ====== C: exe-files == 2014-07-08 14:22:22 6AB8A0E822C47E922B094A38C18DCFF1 1853264 ----a-w- C:\Users\Vanherle\AppData\Roaming\uTorrent\updates\3.4.2_32239.exe 2014-07-08 14:06:27 ECB3AB701D6E26F5E54C58957E34E719 175528 ----a-w- C:\Program Files (x86)\Java\jre7\bin\javaw.exe 2014-07-08 14:06:27 E87885A59FDC241B6575943A75E495D9 182696 ----a-w- C:\Program Files (x86)\Java\jre7\bin\jqs.exe 2014-07-08 14:06:27 E2C8F178A57D011518785CF75044CD69 16296 ----a-w- C:\Program Files (x86)\Java\jre7\bin\keytool.exe 2014-07-08 14:06:27 CEE4C9E092168CEBD187491AF6FDA8FB 264616 ----a-w- C:\Program Files (x86)\Java\jre7\bin\javaws.exe 2014-07-08 14:06:27 AEA4E94FC2A2F88FA5EC7FB6BC349E1B 16296 ----a-w- C:\Program Files (x86)\Java\jre7\bin\klist.exe 2014-07-08 14:06:27 96777405AB93AF8FCF6C9B6F5C3F1E51 16296 ----a-w- C:\Program Files (x86)\Java\jre7\bin\java-rmi.exe 2014-07-08 14:06:27 82517DE5984F3EA3A49E0B5C8825DA63 68008 ----a-w- C:\Program Files (x86)\Java\jre7\bin\javacpl.exe 2014-07-08 14:06:27 62CA7ABA57A4FCDB3844F73A156BAE26 16296 ----a-w- C:\Program Files (x86)\Java\jre7\bin\kinit.exe 2014-07-08 14:06:27 235A2E87C34995F1837283FE76CD2E46 16296 ----a-w- C:\Program Files (x86)\Java\jre7\bin\ktab.exe 2014-07-08 14:06:27 2251971694E17BAC4E344DC2B7CD7ADD 175528 ----a-w- C:\Program Files (x86)\Java\jre7\bin\java.exe 2014-07-08 14:06:27 1EFC992CA271E6D40034FBE7BCEDB724 52648 ----a-w- C:\Program Files (x86)\Java\jre7\bin\jp2launcher.exe 2014-07-08 14:06:27 07643C3AF27179144C9800AF0819DE75 48040 ----a-w- C:\Program Files (x86)\Java\jre7\bin\jabswitch.exe 2014-07-08 14:05:43 80DD24235A7E13AFC9E9EBC55ACE1ACF 313256 ----a-w- C:\Windows\System32\javaws.exe 2014-07-08 14:05:40 75F20BEDF6B95AA316C08D9D3F247692 189352 ----a-w- C:\Windows\System32\java.exe 2014-07-08 14:05:40 22AEEB5D70AFF7C6CB43D16E6F5E2FFF 189352 ----a-w- C:\Windows\System32\javaw.exe 2014-07-08 14:05:38 B5C895A0CE2252C2BE13E4DB60059A67 16808 ----a-w- C:\Program Files\Java\jre7\bin\tnameserv.exe 2014-07-08 14:05:38 50D36E49C4FCF2F0936E55FC64F2C20A 180648 ----a-w- C:\Program Files\Java\jre7\bin\unpack200.exe 2014-07-08 14:05:38 0A7264A972A49FDBE00B4431DC2B101E 64424 ----a-w- C:\Program Files\Java\jre7\bin\ssvagent.exe 2014-07-08 14:05:38 0648CE22986703A3618C2F60D2B34EAC 16296 ----a-w- C:\Program Files\Java\jre7\bin\servertool.exe 2014-07-08 14:05:37 FEAEFB0DFC2A55F5E3670CFFD97B12E3 16296 ----a-w- C:\Program Files\Java\jre7\bin\keytool.exe 2014-07-08 14:05:37 DEB108631ED814878B4D0F8F66BA7D54 67496 ----a-w- C:\Program Files\Java\jre7\bin\jp2launcher.exe 2014-07-08 14:05:37 C8846A5A7613B2B9BFF678182A9B3676 16296 ----a-w- C:\Program Files\Java\jre7\bin\rmid.exe 2014-07-08 14:05:37 B6FE60CC39FC7CB597FBA0EB0A91AA97 16296 ----a-w- C:\Program Files\Java\jre7\bin\java-rmi.exe 2014-07-08 14:05:37 AF463A23D7F45C297BC7F0CF9AAE5C2F 76200 ----a-w- C:\Program Files\Java\jre7\bin\javacpl.exe 2014-07-08 14:05:37 80DD24235A7E13AFC9E9EBC55ACE1ACF 313256 ----a-w- C:\Program Files\Java\jre7\bin\javaws.exe 2014-07-08 14:05:37 75F20BEDF6B95AA316C08D9D3F247692 189352 ----a-w- C:\Program Files\Java\jre7\bin\java.exe 2014-07-08 14:05:37 6FC165F778DC7E3A0C573A555CAD5EE4 16296 ----a-w- C:\Program Files\Java\jre7\bin\kinit.exe 2014-07-08 14:05:37 66567DB2EDB5396F7839687F48CD9D6A 16296 ----a-w- C:\Program Files\Java\jre7\bin\rmiregistry.exe 2014-07-08 14:05:37 63943EF8CDC05D71AA3EDEFF14A8BA43 16296 ----a-w- C:\Program Files\Java\jre7\bin\ktab.exe 2014-07-08 14:05:37 5AD390906C2F6B84B93877E8DC30707E 55720 ----a-w- C:\Program Files\Java\jre7\bin\jabswitch.exe 2014-07-08 14:05:37 4E41FB38C3CE8A907F574217061B43DB 16296 ----a-w- C:\Program Files\Java\jre7\bin\pack200.exe 2014-07-08 14:05:37 4E40EEF592340030DE0FB62532238FD4 16296 ----a-w- C:\Program Files\Java\jre7\bin\policytool.exe 2014-07-08 14:05:37 354A7C881CC32CD63314B0BA7AA8DA24 16808 ----a-w- C:\Program Files\Java\jre7\bin\orbd.exe 2014-07-08 14:05:37 22AEEB5D70AFF7C6CB43D16E6F5E2FFF 189352 ----a-w- C:\Program Files\Java\jre7\bin\javaw.exe 2014-07-08 14:05:37 1EE4BEAA034A42AA91DD4ACB71800E97 16296 ----a-w- C:\Program Files\Java\jre7\bin\klist.exe 2014-07-08 14:03:17 EDF1B2E4E611CC9A0BF1D9E7EEA2D325 130208 ----a-w- C:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR Application Installer.exe 2014-07-08 14:03:17 C24EAC61FF481033893953386788A2A6 59392 ----a-w- C:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Resources\template.exe 2014-07-08 14:03:17 C113B2525CF0E7416C2F2CA7FBD7516E 96768 ----a-w- C:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Resources\Adobe AIR Updater.exe 2014-07-08 14:03:17 7B547F897E8A714512EEBC8A5E69324C 54432 ----a-w- C:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Resources\airappinstaller.exe 2014-07-08 14:03:17 7B547F897E8A714512EEBC8A5E69324C 54432 ----a-w- C:\Program Files (x86)\Adobe\Flash Player\AddIns\airappinstaller\airappinstaller.exe 2014-07-08 13:28:50 9A2347903D6EDB84C10F288BC0578C1C 388608 ----a-w- C:\Program Files\trend micro\Vanherle.exe 2014-07-06 18:24:35 C4E30279F768B5AF19B6AA606DE0D7E9 9433088 ----a-w- C:\Users\Vanherle\AppData\Roaming\GetnowUpdater\html_res\adbF\driver\AdbDriverInstaller.exe 2014-07-06 18:24:34 359CF602DD8C3FF457BCD91C0BF210CE 733184 ----a-w- C:\Users\Vanherle\AppData\Roaming\GetnowUpdater\html_res\setup.exe 2014-07-06 18:24:23 EB5425FDD219C3FFA503866D5651C1F2 819200 ----a-w- C:\Users\Vanherle\AppData\Roaming\GetnowUpdater\html_res\adbF\adb.exe 2014-07-06 18:24:20 6B03CADE5D6894FB39C5623651B88904 739496 ----a-w- C:\Users\Vanherle\AppData\Roaming\GetnowUpdater\bin\CrashSender1402.exe 2014-07-06 18:24:20 56C046D831A3BA7D583AE74AE232ACC2 3860136 ----a-w- C:\Users\Vanherle\AppData\Roaming\GetnowUpdater\bin\GetNowUpdater.exe 2014-07-06 18:23:39 742457A02803BE584BD87B648094EBF3 898816 ----a-w- C:\Users\Vanherle\AppData\Local\GetNowUpdater\inst\Bootstrapper\GetNowUpdaterUninstall.exe 2014-07-06 18:23:38 977AB9749B3958019FDD077B228FF06A 1133896 ----a-w- C:\Users\Vanherle\AppData\Local\GetnowUninstall\uninstall.exe 2014-07-06 14:20:40 6FFE137CFEAB8F329803584AA5015857 114416 ----a-w- C:\Program Files (x86)\Settings Manager\systemk\Uninstall.exe === C: other files == 2014-07-08 14:05:38 8C3C73B2287D15AD508BA3B78185EAC3 18619 ----a-w- C:\Program Files\Java\jre7\lib\deploy\ffjcext.zip 2014-07-08 13:51:42 FF1E537A3632CBB9A0BF72B9FD0878D5 79184 ----a-w- C:\Windows\System32\drivers\aswMonFlt.sys 2014-07-08 13:51:42 D95E64416A4A3ED6986E0F474DA934BD 29208 ----a-w- C:\Windows\System32\drivers\aswHwid.sys 2014-07-08 13:51:42 B8FDEDE963B82CFD23B3A53A3084666D 1041168 ----a-w- C:\Windows\System32\drivers\aswSnx.sys 2014-07-08 13:51:42 A5757DE5F9C83AB40667A53D5126EA40 93568 ----a-w- C:\Windows\System32\drivers\aswRdr2.sys 2014-07-08 13:51:42 645D97385F3F284FB5604F9B970F4D24 65776 ----a-w- C:\Windows\System32\drivers\aswRvrt.sys 2014-07-08 13:51:42 48DED912CDE54FC0923B9858512366E1 92008 ----a-w- C:\Windows\System32\drivers\aswStm.sys 2014-07-08 13:51:42 471A311745848B80339436688A8286E6 224896 ----a-w- C:\Windows\System32\drivers\aswVmm.sys 2014-07-08 13:51:42 0DEDC041DF594AEC2C3BD00417CFAF60 427360 ----a-w- C:\Windows\System32\drivers\aswsp.sys 2014-07-06 18:24:36 541DBDA3E0327C02938D867D82A3F104 31533088 ----a-w- C:\Users\Vanherle\AppData\Roaming\GetnowUpdater\bin\remoteSoft.zip ==== Startup Registry Enabled ====================== [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun" [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun" [HKEY_USERS\S-1-5-21-219209752-1814971668-716802256-1000\Software\Microsoft\Windows\CurrentVersion\Run] "MyTomTomSA.exe"="C:\Program Files (x86)\MyTomTom 3\MyTomTomSA.exe" "uTorrent"="C:\Users\Vanherle\AppData\Roaming\uTorrent\uTorrent.exe /MINIMIZED" [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce] "mctadmin"="C:\Windows\System32\mctadmin.exe" [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce] "mctadmin"="C:\Windows\System32\mctadmin.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IAStorIcon"="C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" "CLMLServer"="C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe" "StartCCC"="C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe MSRun" "AvastUI.exe"="C:\Program Files\AVAST Software\Avast\AvastUI.exe /nogui" "SunJavaUpdateSched"="C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "MyTomTomSA.exe"="C:\Program Files (x86)\MyTomTom 3\MyTomTomSA.exe" "uTorrent"="C:\Users\Vanherle\AppData\Roaming\uTorrent\uTorrent.exe /MINIMIZED" ==== Startup Registry Enabled x64 ====================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RTHDVCPL"="C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s" "MedionReminder"="C:\Program Files (x86)\CyberLink\PowerRecover\Reminder.exe" "PAC7302_Monitor"="C:\Windows\PixArt\PAC7302\Monitor.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] "MedionReminder"="C:\Program Files (x86)\CyberLink\PowerRecover\Reminder.exe /DeleteRunKey" ==== Startup Registry Disabled ====================== [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run-] "AVG-Secure-Search-Update_0913b"="C:\\Users\\Vanherle\\AppData\\Roaming\\AVG 0913b Campaign\\AVG-Secure-Search-Update-0913b.exe /PROMPT --mid f7bde612417147d080af5dc0e32914c1-84054593afe0a665300adccc011651f4cd7f9313 --CMPID 0913b" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run-] "Adobe ARM"="\"C:\\Program Files (x86)\\Common Files\\Adobe\\ARM\\1.0\\AdobeARM.exe\"" "HP Software Update"="C:\\Program Files (x86)\\HP\\HP Software Update\\HPWuSchd2.exe" "SunJavaUpdateSched"="\"C:\\Program Files (x86)\\Common Files\\Java\\Java Update\\jusched.exe\"" ==== Startup Registry Disabled x64 ====================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\NokiaSuite.exe] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="NokiaSuite.exe" "hkey"="HKCU" "command"="C:\\Program Files (x86)\\Nokia\\Nokia Suite\\NokiaSuite.exe -tray" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\VDownloader] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="VDownloader" "hkey"="HKLM" "command"="C:\\Program Files\\VDownloader\\VDownloader.exe /silent" ==== Startup Folders ====================== 2012-12-26 13:04:27 2103 ----a-w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk ==== Task Scheduler Jobs ====================== C:\Windows\tasks\Adobe Flash Player Updater.job --a------ C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [15/06/2014 10:58] C:\Windows\tasks\GoogleUpdateTaskMachineCore.job --a------ C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [20/12/2012 19:33] C:\Windows\tasks\GoogleUpdateTaskMachineUA.job --a------ C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [20/12/2012 19:33] ==== Other Scheduled Tasks ====================== "C:\Windows\SysNative\tasks\Adobe Flash Player Updater" [C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe] "C:\Windows\SysNative\tasks\Adobe-online actualiseringsprogramma" [C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe] "C:\Windows\SysNative\tasks\CCleanerSkipUAC" ["C:\Program Files\CCleaner\CCleaner.exe"] "C:\Windows\SysNative\tasks\GoogleUpdateTaskMachineCore" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe] "C:\Windows\SysNative\tasks\GoogleUpdateTaskMachineUA" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe] "C:\Windows\SysNative\tasks\HP-Online updateprogramma" [C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe] "C:\Windows\SysNative\tasks\Java Update Scheduler" [C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe] "C:\Windows\SysNative\tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask" [%systemroot%\system32\sc.exe start osppsvc] ==== Firefox Extensions Registry ====================== [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions] "wrc@avast.com"="C:\Program Files\AVAST Software\Avast\WebRep\FF" [08/07/2014 15:51] [HKEY_CURRENT_USER\Software\Mozilla\Firefox\Extensions] "smartwebprinting@hp.com"="C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3" [26/12/2012 15:05] ==== Firefox Extensions ====================== AppDir: C:\Program Files (x86)\Mozilla Firefox - Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} ==== Firefox Plugins ====================== Profilepath: C:\Users\Vanherle\AppData\Roaming\Mozilla\Firefox\Profiles\40a2bs16.default A58DE0A570148AF5FF3512B2A340D09F - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll - Shockwave Flash ==== Chrome Look ====================== HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions gomekmidlodglbbmalcneegieacbdmki - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx[08/07/2014 15:51] Google Docs - Vanherle\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake Google Drive - Vanherle\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf YouTube - Vanherle\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo Google Search - Vanherle\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf Google Wallet - Vanherle\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda Gmail - Vanherle\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia ==== Set IE to Default ====================== Old Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://www.google.be/" New Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://www.google.be/" ==== All HKCU SearchScopes ====================== HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes "DefaultScope"="{6A1806CD-94D4-4689-BA73-E35EA1EA9990}" {0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE11SR" {21CA3304-8E8A-4684-9501-CD8EB2011C79} (www.google.com) Google Url="https://www.google.com/search?q={searchTerms}" {6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}" {DA214047-4B08-4F71-9796-5C1090AEF4D3} Google Url="http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7MDNF_enDE393" ==== HijackThis Entries ====================== F2 - REG:system.ini: UserInit=userinit.exe O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll O4 - HKLM\..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe O4 - HKLM\..\Run: [CLMLServer] "C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe" O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" O4 - HKCU\..\Run: [MyTomTomSA.exe] C:\Program Files (x86)\MyTomTom 3\MyTomTomSA.exe O4 - HKCU\..\Run: [uTorrent] "C:\Users\Vanherle\AppData\Roaming\uTorrent\uTorrent.exe" /MINIMIZED O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE') O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe O9 - Extra button: eBay.be - {0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - http://rover.ebay.com/rover/1/1553-72747-17534-1/4 (file missing) O9 - Extra 'Tools' menuitem: eBay.be - {0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - http://rover.ebay.com/rover/1/1553-72747-17534-1/4 (file missing) O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra button: Toon of verberg HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing) O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing) O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing) O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing) O23 - Service: Google Update-service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe O23 - Service: Google Update-service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing) O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe O23 - Service: MemeoBackgroundService - Memeo - C:\Program Files (x86)\Memeo\AutoBackup\MemeoBackgroundService.exe O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing) O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing) O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: ServiceLayer - Nokia - C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing) O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing) O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing) O23 - Service: Systemk Service (SystemkService) - Aztec Media Inc - C:\Program Files (x86)\Settings Manager\systemk\SystemkService.exe O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing) O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing) O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing) O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing) O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing) O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing) O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing) ==== Empty IE Cache ====================== C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Vanherle\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Vanherle\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KRUEF3V6 will be deleted at reboot C:\Users\Vanherle\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\L0R3G5DR will be deleted at reboot ==== Empty FireFox Cache ====================== No FireFox Cache found ==== Empty Chrome Cache ====================== C:\Users\Vanherle\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully ==== Empty All Flash Cache ====================== Flash Cache Emptied Successfully ==== Empty All Java Cache ====================== Java Cache cleared successfully ==== C:\zoek_backup content ====================== C:\zoek_backup (files=991 folders=93 62684570 bytes) ==== Empty Temp Folders ====================== C:\Users\Default\AppData\Local\Temp emptied successfully C:\Users\Default User\AppData\Local\Temp emptied successfully C:\Users\Vanherle\AppData\Local\Temp will be emptied at reboot C:\Windows\sysWoW64\config\systemprofile\AppData\Local\temp emptied successfully C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully C:\Windows\Temp will be emptied at reboot ==== After Reboot ====================== ==== Empty Temp Folders ====================== C:\Windows\Temp successfully emptied C:\Users\Vanherle\AppData\Local\Temp successfully emptied ==== Empty Recycle Bin ====================== C:\$RECYCLE.BIN successfully emptied ==== Deleting Files / Folders ====================== "C:\Users\Vanherle\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KRUEF3V6" not found "C:\Users\Vanherle\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\L0R3G5DR" not found ==== EOF on wo 09/07/2014 at 15:11:51,89 ======================