Zoek.exe v5.0.0.0 Updated 30-09-2014 Tool run by xx on vr 03/10/2014 at 11:53:35,89. Microsoft Windows 8 6.2.9200 x86 Running in: Normal Mode Internet Access Detected Launched: C:\Users\xx\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\E6OQMZXT\zoek.exe [Scan all users] [Script inserted] [Checkboxes used] ==== System Restore Info ====================== 3/10/2014 11:55:49 Zoek.exe System Restore Point Created Succesfully. ==== Empty Folders Check ====================== C:\Users\xx\AppData\Roaming\Malwarebytes deleted successfully C:\Users\xx\AppData\Roaming\systweak deleted successfully C:\Users\xx\AppData\Roaming\YourFileDownloader deleted successfully C:\Users\xx\AppData\Local\Network_Me_07011037 deleted successfully ==== Deleting CLSID Registry Keys ====================== ==== Deleting CLSID Registry Values ====================== ==== Deleting Services ====================== ==== Registry Fix Code ====================== Windows Registry Editor Version 5.00 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "trpntye"=- ==== Deleting Files \ Folders ====================== C:\Program Files\YourFileDownloader deleted C:\Program Files\YourFileDownloader Updater deleted C:\Windows\system32\Tasks\LaunchSignup deleted C:\end deleted C:\Windows\system32\roboot.exe deleted "c:\users\xx\appdata\local\trpntye.exe" deleted "C:\Users\xx\AppData\Local\trpntye.exe" deleted ==== Files Recently Created / Modified ====================== ====== C:\Windows ==== ====== C:\Users\xx\AppData\Local\Temp ==== ====== Java Cache ===== ====== C:\Windows\system32 ===== ====== C:\Windows\system32\drivers ===== 2014-09-13 11:06:04 C97E0F487690FB0C7221168465982810 52440 ----a-w- C:\Windows\System32\drivers\hsbujbhw.sys ====== C:\Windows\Tasks ====== 2014-09-10 21:58:49 F81C28A253ACDEF8526C07C3F3F5A897 4020 ----a-w- C:\Windows\system32\Tasks\GoogleUpdateTaskMachineUA 2014-09-10 21:58:49 32AFEAB405BFDC85837AB6FBFBF17074 1048 ----a-w- C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-09-10 21:58:48 C2FB44A8D9CA0425701F4094BF1362B8 1044 ----a-w- C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-09-10 21:58:48 2CE50A62607E51F81F4575E45BD49BDE 3784 ----a-w- C:\Windows\system32\Tasks\GoogleUpdateTaskMachineCore ====== C:\Windows\Temp ====== ======= C:\Program Files ===== 2014-10-03 07:00:25 -------- d-----w- C:\Program Files\trend micro 2014-09-10 21:58:45 -------- d-----w- C:\Program Files\Google ======= C: ===== ====== C:\Users\xx\AppData\Roaming ====== 2014-10-01 17:23:23 C2F6292AFDF7B21D134DAE02C73D00A8 1233177 ----a-w- C:\Users\xx\AppData\Local\trpntye.gss 2014-10-01 17:23:23 6882884CF37D3B2FE909DCA61395F1E7 31744 ----a-w- C:\Users\xx\AppData\Local\trpntye.gdb 2014-09-10 22:03:31 -------- d-----w- C:\Windows\system32\config\systemprofile\AppData\Local\Google 2014-09-10 21:58:45 -------- d-----w- C:\Users\xx\AppData\Local\Google ====== C:\Users\xx ====== 2014-09-10 22:01:57 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome 2014-09-10 21:59:27 -------- d-----w- C:\ProgramData\Google 2014-09-03 11:26:04 -------- d-----r- C:\Windows\system32\config\systemprofile\Desktop ====== C: exe-files == === C: other files == ==== Startup Registry Enabled ====================== [HKEY_USERS\S-1-5-21-3965670995-3544941611-1494180988-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Windows\CurrentVersion\Run] "rcvate"="c:\users\xx\appdata\local\rcvate.exe /r" [HKEY_USERS\S-1-5-21-3965670995-3544941611-1494180988-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-1\Software\Microsoft\Windows\CurrentVersion\Run] "rcvate"="c:\users\xx\appdata\local\rcvate.exe /r" [HKEY_USERS\S-1-5-21-3965670995-3544941611-1494180988-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-2\Software\Microsoft\Windows\CurrentVersion\Run] "rcvate"="c:\users\xx\appdata\local\rcvate.exe /r" [HKEY_USERS\S-1-5-21-3965670995-3544941611-1494180988-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-3\Software\Microsoft\Windows\CurrentVersion\Run] "rcvate"="c:\users\xx\appdata\local\rcvate.exe /r" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IgfxTray"="C:\Windows\system32\igfxtray.exe" "HotKeysCmds"="C:\Windows\system32\hkcmd.exe" "Persistence"="C:\Windows\system32\igfxpers.exe" "Adobe ARM"="C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" "GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" ==== Startup Folders ====================== 2014-03-29 07:31:08 799 ----a-w- C:\Users\xx\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Ross-Tech VCDS DRV Updater-RKS.lnk 2014-09-01 12:52:22 774 ----a-w- C:\Users\xx\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\RT-Updater.lnk ==== Task Scheduler Jobs ====================== C:\Windows\tasks\GoogleUpdateTaskMachineCore.job --a-------- C:\Program Files\Google\Update\GoogleUpdate.exe [10/09/2014 23:58] C:\Windows\tasks\GoogleUpdateTaskMachineUA.job --a-------- C:\Program Files\Google\Update\GoogleUpdate.exe [10/09/2014 23:58] ==== Other Scheduled Tasks ====================== "C:\Windows\system32\tasks\CCleanerSkipUAC" ["C:\Program Files\CCleaner\CCleaner.exe"] "C:\Windows\system32\tasks\CreateChoiceProcessTask" [C:\Windows\BrowserChoice\browserchoice.exe] "C:\Windows\system32\tasks\GoogleUpdateTaskMachineCore" [C:\Program Files\Google\Update\GoogleUpdate.exe] "C:\Windows\system32\tasks\GoogleUpdateTaskMachineUA" [C:\Program Files\Google\Update\GoogleUpdate.exe] ==== Chromium Look ====================== Google Slides - xx\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek Google Docs - xx\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake Google Drive - xx\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf YouTube - xx\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo Google Search - xx\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf Google Sheets - xx\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap Google Wallet - xx\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda Gmail - xx\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia ==== Set IE to Default ====================== Old Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="https://www.google.be/" New Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="https://www.google.be/" ==== All HKCU SearchScopes ====================== HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" {012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}" {0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE10SR" ==== Empty IE Cache ====================== C:\Users\xx\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\xx\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\E6OQMZXT will be deleted at reboot ==== Empty FireFox Cache ====================== No FireFox Profiles found ==== Empty Chrome Cache ====================== C:\Users\xx\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully ==== Empty All Flash Cache ====================== Flash Cache Emptied Successfully ==== Empty All Java Cache ====================== No Java Cache Found ==== C:\zoek_backup content ====================== C:\zoek_backup (files=9 folders=3 5827699 bytes) ==== Empty Temp Folders ====================== C:\Users\Default\AppData\Local\Temp emptied successfully C:\Users\Default User\AppData\Local\Temp emptied successfully C:\Users\xx\AppData\Local\Temp will be emptied at reboot C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully C:\Windows\Temp will be emptied at reboot ==== After Reboot ====================== ==== Empty Temp Folders ====================== C:\Windows\Temp successfully emptied C:\Users\xx\AppData\Local\Temp successfully emptied ==== Empty Recycle Bin ====================== C:\$RECYCLE.BIN successfully emptied ==== Deleting Files / Folders ====================== "C:\Users\xx\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\E6OQMZXT" not found ==== EOF on vr 03/10/2014 at 12:14:03,90 ======================