Zoek.exe v5.0.0.0 Updated 28-12-2014 Tool run by Erik Vanhoof 1 on ma 29/12/2014 at 7:01:05,08. Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x64 Running in: Normal Mode Internet Access Detected Launched: C:\Users\Erik Vanhoof 1\Desktop\zoek.exe [Scan all users] [Script inserted] ==== System Restore Info ====================== 29/12/2014 7:10:07 Zoek.exe System Restore Point Created Succesfully. ==== Empty Folders Check ====================== C:\PROGRA~2\GAMESVOORIEDEREEN.NL deleted successfully C:\PROGRA~2\iStonsoft deleted successfully C:\PROGRA~2\Movies App deleted successfully C:\PROGRA~2\OXXOGames deleted successfully C:\PROGRA~2\COMMON~1\PDF Architect deleted successfully C:\Program Files\Fotoservice deleted successfully C:\Program Files\Google deleted successfully C:\PROGRA~3\systemk deleted successfully C:\PROGRA~3\Yahoo! deleted successfully C:\Users\Jens Vanhoof\AppData\Roaming\Google deleted successfully C:\Users\Brecht Vanhoof\AppData\Local\VirtualStore deleted successfully C:\Users\Erik Vanhoof 1\AppData\Local\CutePDF Writer deleted successfully C:\Users\Erik Vanhoof 1\AppData\Local\genienext deleted successfully C:\Users\Erik Vanhoof 1\AppData\Local\Linkey deleted successfully C:\Users\Jens Vanhoof\AppData\Local\VirtualStore deleted successfully ==== Files Recently Created / Modified ====================== ====== C:\Windows ==== ====== C:\Users\ERIKVA~1\AppData\Local\Temp ==== ====== Java Cache ===== ====== C:\Windows\SysWOW64 ===== 2014-12-18 04:46:04 0481346D0EF668C0D4FF69A7BBEFA846 115712 ----a-w- C:\Windows\SysWOW64\ieUnatt.exe ====== C:\Windows\SysWOW64\drivers ===== ====== C:\Windows\Sysnative ===== 2014-12-18 04:46:04 5564883BFB523D5078A5B1FE3128FD63 144384 ----a-w- C:\Windows\Sysnative\ieUnatt.exe ====== C:\Windows\Sysnative\drivers ===== 2014-12-10 04:29:18 70988118145F5F10EF24720B97F35F65 119296 ----a-w- C:\Windows\Sysnative\drivers\tdx.sys ====== C:\Windows\Tasks ====== 2014-12-28 08:44:33 9A080A079935C8EB9A471689DADE877E 1374 ----a-w- C:\Windows\Tasks\MLMYMU.job 2014-12-28 08:44:33 1110334ADDEDAB64AA4863435A349A32 4416 ----a-w- C:\Windows\Sysnative\Tasks\MLMYMU ====== C:\Windows\Temp ====== ======= C:\Program Files ===== ======= C:\PROGRA~2 ===== 2014-12-28 08:44:34 -------- d-----w- C:\PROGRA~2\1422d3ef-b16f-41bc-b9c0-8d6315a98e1e 2014-12-24 07:17:55 -------- d-----w- C:\PROGRA~2\COMMON~1\Java 2014-12-20 05:16:16 -------- d-----w- C:\PROGRA~2\Mail Password ======= C: ===== 2014-12-28 09:50:57 D41D8CD98F00B204E9800998ECF8427E 0 ----a-w- C:\autoexec.bat ====== C:\Users\Erik Vanhoof 1\AppData\Roaming ====== 2014-12-28 08:52:19 -------- d-----w- C:\Users\Erik Vanhoof 1\AppData\Locallow\TornPlusTV_version1.11 2014-12-24 08:23:42 -------- d-----w- C:\Users\Jens Vanhoof\AppData\Roaming\java 2014-12-24 07:17:48 -------- d-----w- C:\Users\Erik Vanhoof 1\AppData\Locallow\Oracle 2014-12-03 16:46:25 -------- d-----w- C:\Users\Jens Vanhoof\AppData\Local\Torch ====== C:\Users\Erik Vanhoof 1 ====== 2014-12-28 09:48:44 -------- d-----w- C:\Users\Erik Vanhoof 1\Start Menu 2014-12-28 09:47:28 B4CD9E8513C17C32224C70330A235296 3044736 ----a-w- C:\Users\Erik Vanhoof 1\Downloads\SpyHunter-Installer.exe 2014-12-27 20:07:15 C4E927A4C29E3C16686F7D5DE6F14E9D 2934449 ----a-w- C:\Users\Jens Vanhoof\Downloads\liteloader-installer-1.7.10-04.exe 2014-12-20 05:16:16 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mail Password 2014-12-05 18:11:21 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\De Sims 4 2014-12-05 18:10:05 -------- d-----w- C:\ProgramData\Package Cache ====== C: exe-files == 2014-12-29 06:06:44 DCBD57273263E0382339AAD15CC2C635 544 ----a-w- C:\$RECYCLE.BIN\S-1-5-21-981637665-1960542106-3209509957-1005\$I479ZQ2.exe 2014-12-29 06:06:07 92ABBC6E52E32F8F66684F90BF4A25CE 1295360 ----a-w- C:\$RECYCLE.BIN\S-1-5-21-981637665-1960542106-3209509957-1005\$R479ZQ2.exe 2014-12-28 14:44:06 8045ABB21A3BDD66A48E1ED5C0F0EF6A 1222144 ----a-w- C:\Documents and Settings\Erik Vanhoof 1\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\K2AHWP3X\RSITx64.exe 2014-12-28 09:47:28 B4CD9E8513C17C32224C70330A235296 3044736 ----a-w- C:\Documents and Settings\Erik Vanhoof 1\Downloads\SpyHunter-Installer.exe 2014-12-28 09:16:59 3BD59D6C407AB1F6DDD7C5D9BD727469 20447072 ----a-w- C:\Documents and Settings\Erik Vanhoof 1\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XM3L4VXY\mbam-setup-2.0.4.1028.exe 2014-12-28 08:44:14 E876E34992E87644578F4E5D59F9D4A0 827648 ----a-w- C:\Documents and Settings\Erik Vanhoof 1\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HSRVDEYM\TornTVApp[1].exe 2014-12-27 20:07:38 C4E927A4C29E3C16686F7D5DE6F14E9D 2934449 ----a-w- C:\Documents and Settings\Jens Vanhoof\AppData\Roaming\.minecraft\mods\liteloader-installer-1.7.10-04.exe 2014-12-27 20:07:15 C4E927A4C29E3C16686F7D5DE6F14E9D 2934449 ----a-w- C:\Documents and Settings\Jens Vanhoof\Downloads\liteloader-installer-1.7.10-04.exe 2014-12-27 20:06:28 C4E927A4C29E3C16686F7D5DE6F14E9D 2934449 ----a-w- C:\Documents and Settings\Jens Vanhoof\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\668C374Q\liteloader-installer-1.7.10-04.exe 2014-12-24 06:02:16 AA3520FB0133A56BEE1DB34D74DBEF64 0 ----a-we C:\Documents and Settings\All Users\Oracle\Java\javapath\java.exe 2014-12-24 06:02:16 75D477E868CA51EC1B09D730570F322B 0 ----a-we C:\Documents and Settings\All Users\Oracle\Java\javapath\javaw.exe 2014-12-24 06:02:16 691D49FB44EDE9788288CABE4F7E0DAF 0 ----a-we C:\Documents and Settings\All Users\Oracle\Java\javapath\javaws.exe === C: other files == 2014-12-28 16:43:52 C00EB9F78FD3DF28269C8FA4D6C3DF57 120956590 ----a-w- C:\Documents and Settings\Jens Vanhoof\AppData\Roaming\.minecraft\resourcepacks\Knolpower Texturepack 2.0 NIEUWE.zip 2014-12-28 09:50:57 D41D8CD98F00B204E9800998ECF8427E 0 ----a-w- C:\autoexec.bat 2014-12-28 09:47:55 633BB002E3061041EE6B1D3136E773E7 7580544 ----a-w- C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter4.com 2014-12-28 09:47:51 7AEC5E76816178BF6C543A155D8208B6 15920 ----a-w- C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys 2014-12-28 09:47:51 3B32CAA07D672F8A2E0DF5CB3A873F45 22704 ----a-w- C:\Program Files\Enigma Software Group\SpyHunter\EsgScanner.sys 2014-12-28 08:45:41 2388A44CC62402E2E27C46800A2E4BBB 3072765 ----a-w- C:\Users\Erik Vanhoof 1\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HSRVDEYM\2[1].zip 2014-12-28 08:45:41 2388A44CC62402E2E27C46800A2E4BBB 3072765 ----a-w- C:\Documents and Settings\Erik Vanhoof 1\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HSRVDEYM\2[1].zip 2014-12-28 08:45:31 9B0D24DA0EF0117E0AAA6BD614EC470E 2138186 ----a-w- C:\Users\Erik Vanhoof 1\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6NVTPNCQ\1[1].zip 2014-12-28 08:45:31 9B0D24DA0EF0117E0AAA6BD614EC470E 2138186 ----a-w- C:\Documents and Settings\Erik Vanhoof 1\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6NVTPNCQ\1[1].zip 2014-12-24 06:01:56 CE44A9D4918DCDC7CCCF5503BF4D7A3D 14130 ----a-w- C:\Program Files (x86)\Java\jre1.8.0_25\lib\deploy\ffjcext.zip ==== Startup Registry Enabled ====================== [HKEY_USERS\S-1-5-21-981637665-1960542106-3209509957-1005\Software\Microsoft\Windows\CurrentVersion\Run] "LaCie Ethernet Agent Startup"="C:\Program Files (x86)\LaCie\Network Assistant\LaCie Network Assistant.exe" "KiesTrayAgent"="C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe" "uTorrent"="C:\Users\Erik Vanhoof 1\AppData\Roaming\uTorrent\uTorrent.exe /MINIMIZED" [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce] "IsMyWinLockerReboot"="msiexec.exe /qn /x{voidguid}" [HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\RunOnce] "IsMyWinLockerReboot"="msiexec.exe /qn /x{voidguid}" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SuiteTray"="C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe" "EgisTecPMMUpdate"="C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe" "EgisUpdate"="C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe -d" "Adobe Reader Speed Launcher"="C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" "IAStorIcon"="C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" "ArcadeMovieService"="C:\Program Files (x86)\Acer\clear.fi\Movie\clear.fiMovieService.exe" "Hotkey Utility"="C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe" "APSDaemon"="C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" "iTunesHelper"="C:\Program Files (x86)\iTunes\iTunesHelper.exe" "QuickTime Task"="C:\Program Files (x86)\QuickTime\QTTask.exe -atboottime" "Adobe ARM"="C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" "mobilegeni daemon"="C:\Program Files (x86)\Mobogenie\DaemonProcess.exe" "AVG_UI"="C:\Program Files (x86)\AVG\AVG2015\avgui.exe /TRAYONLY" "SunJavaUpdateSched"="C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "LaCie Ethernet Agent Startup"="C:\Program Files (x86)\LaCie\Network Assistant\LaCie Network Assistant.exe" "KiesTrayAgent"="C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe" "uTorrent"="C:\Users\Erik Vanhoof 1\AppData\Roaming\uTorrent\uTorrent.exe /MINIMIZED" ==== Startup Registry Enabled x64 ====================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RtHDVCpl"="C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s" "Logitech Download Assistant"="C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch" "EvtMgr6"="C:\Program Files\Logitech\SetPointP\SetPoint.exe /launchGaming" ==== Task Scheduler Jobs ====================== C:\Windows\tasks\0414bUpdateInfo.job --a------ C:\ProgramData\Avg_Update_0414b\0414b_AVG-Secure-Search-Update.exe [09/04/2014 08:48] C:\Windows\tasks\Adobe Flash Player Updater.job --a------ C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [10/12/2014 06:48] C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-981637665-1960542106-3209509957-1003Core.job --a------ C:\Users\Jens Vanhoof\AppData\Local\Facebook\Update\FacebookUpdate.exe [16/05/2014 17:27] C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-981637665-1960542106-3209509957-1003UA.job --a------ C:\Users\Jens Vanhoof\AppData\Local\Facebook\Update\FacebookUpdate.exe [16/05/2014 17:27] C:\Windows\tasks\GoogleUpdateTaskMachineCore.job --a------ [Undetermined Task] C:\Windows\tasks\GoogleUpdateTaskMachineUA.job --a------ C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [15/08/2013 10:01] C:\Windows\tasks\MLMYMU.job --a------ [Undetermined Task] ==== Other Scheduled Tasks ====================== "C:\Windows\SysNative\tasks\0" [c:\program files\internet explorer\iexplore.exe] "C:\Windows\SysNative\tasks\0414bUpdateInfo" [C:\ProgramData\Avg_Update_0414b\0414b_AVG-Secure-Search-Update.exe] "C:\Windows\SysNative\tasks\4464" [wscript.exe C:\Users\ACER\AppData\Local\Temp\launchie.vbs //B] "C:\Windows\SysNative\tasks\Adobe Flash Player Updater" [C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe] "C:\Windows\SysNative\tasks\clear.fi" ["C:\Program Files (x86)\Acer\clear.fi\MVP\clear.fi.exe"] "C:\Windows\SysNative\tasks\clear.fiAgent" ["C:\Program Files (x86)\Acer\clear.fi\MVP\clear.fiAgent.exe"] "C:\Windows\SysNative\tasks\CreateChoiceProcessTask" [C:\Windows\System32\browserchoice.exe] "C:\Windows\SysNative\tasks\DMREngine" ["C:\Program Files (x86)\Acer\clear.fi\MVP\.\Kernel\DMR\DMREngine.exe"] "C:\Windows\SysNative\tasks\FacebookUpdateTaskUserS-1-5-21-981637665-1960542106-3209509957-1003Core" [C:\Users\Jens Vanhoof\AppData\Local\Facebook\Update\FacebookUpdate.exe] "C:\Windows\SysNative\tasks\FacebookUpdateTaskUserS-1-5-21-981637665-1960542106-3209509957-1003UA" [C:\Users\Jens Vanhoof\AppData\Local\Facebook\Update\FacebookUpdate.exe] "C:\Windows\SysNative\tasks\GoogleUpdateTaskMachineCore" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe] "C:\Windows\SysNative\tasks\GoogleUpdateTaskMachineUA" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe] "C:\Windows\SysNative\tasks\MLMYMU" [C:\Users\Erik Vanhoof 1\AppData\Roaming\MLMYMU.exe] "C:\Windows\SysNative\tasks\SidebarExecute" [C:\Program Files\Windows Sidebar\sidebar.exe] "C:\Windows\SysNative\tasks\{F218DBF9-BB33-4227-805F-4E18DCDC7A94}" ["C:\Program Files\Internet Explorer\iexplore.exe" http://ui.skype.com/ui/0/6.6.0.106/en/abandoninstall?page=tsMain] "C:\Windows\SysNative\tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask" [%systemroot%\system32\sc.exe start osppsvc] ==== Firefox Extensions Registry ====================== [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions] "{F003DA68-8256-4b37-A6C4-350FA04494DF}"="C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt" [18/01/2014 15:58] ==== Chromium Look ====================== Google Chrome Version: 39.0.2171.95 (Up to date, latest Stable version: 39.0.2171.95) HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions lifbcibllhkdhoafpjfnlhfpfgnpldfl - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx[14/07/2014 17:22] Google Docs - Brecht Vanhoof\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake Google Drive - Brecht Vanhoof\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf YouTube - Brecht Vanhoof\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo Google Search - Brecht Vanhoof\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf Google Wallet - Brecht Vanhoof\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda Gmail - Brecht Vanhoof\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia Google Wallet - Erik Vanhoof 1\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda Google Docs - Jens Vanhoof\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake Google Drive - Jens Vanhoof\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf YouTube - Jens Vanhoof\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo Google Search - Jens Vanhoof\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf PlusHD-V1.9 - Jens Vanhoof\AppData\Local\Google\Chrome\User Data\Default\Extensions\cpgaepnhfockgofcejphihfafgmenofb Skype Click to Call - Jens Vanhoof\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl Google Wallet - Jens Vanhoof\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda Gmail - Jens Vanhoof\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia Ask Toolbar - Jens Vanhoof\AppData\Local\Torch\User Data\Default\Extensions\aaaalejpmnocmhmlbmlkjemekckoagne ThemeBeta.com - Jens Vanhoof\AppData\Local\Torch\User Data\Default\Extensions\bokadokfjkloipfpomljajlhcncgejoc DropToS - Jens Vanhoof\AppData\Local\Torch\User Data\Default\Extensions\cipmepknanmbbaneimacddfemfbfgpgo Torch New Tab - Jens Vanhoof\AppData\Local\Torch\User Data\Default\Extensions\dipchieogpecpggdacaaffcjemkggfbi Torch Shopping - Jens Vanhoof\AppData\Local\Torch\User Data\Default\Extensions\dmgjnkhnkblpmfjpdakehnaikgdjllic Torch Games - Jens Vanhoof\AppData\Local\Torch\User Data\Default\Extensions\elnodfjhjgpnmdhklbfeijeaehcgffnp Torch Music - Jens Vanhoof\AppData\Local\Torch\User Data\Default\Extensions\gcjbdjlojcomlphfchhihkigepfabcad FaceLift - Jens Vanhoof\AppData\Local\Torch\User Data\Default\Extensions\gimjmfipknpppbpmkdenjjpfhobiiojk Torch Games - Jens Vanhoof\AppData\Local\Torch\User Data\Default\Extensions\khkmhmmjbfailffpaicjgedkpboookjk Skype Click to Call - Jens Vanhoof\AppData\Local\Torch\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl Torch Torrent - Jens Vanhoof\AppData\Local\Torch\User Data\Default\Extensions\mpdmibcjecdaibcnlilhiopefjgegjjc Google Wallet - Jens Vanhoof\AppData\Local\Torch\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda Torch Music - Jens Vanhoof\AppData\Local\Torch\User Data\Default\Extensions\ohimbkoaphfnmekmfppijeblmkncneed Google Docs - Patricia Corstjens\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake Google Drive - Patricia Corstjens\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf YouTube - Patricia Corstjens\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo Google Search - Patricia Corstjens\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf Google Wallet - Patricia Corstjens\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda Gmail - Patricia Corstjens\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia ==== Chromium Startpages ====================== C:\Users\Jens Vanhoof\AppData\Local\Torch\User Data\Default\Preferences "homepage": "http://home.torchbrowser.com/?systemid=448&appid=285&ua=Torch", "startup_urls": [ "http://home.torchbrowser.com/?systemid=448&appid=285&ua=Torch" ], ==== C:\zoek_backup content ====================== C:\zoek_backup (files=0 folders=1 0 bytes) ==== EOF on ma 29/12/2014 at 7:16:31,26 ======================