Zoek.exe v5.0.0.1 Updated 31-December-2015 Tool run by ErikD on zo 31/07/2016 at 15:27:21,67. Microsoft Windows 7 Professional 6.1.7601 Service Pack 1 x86 Running in: Normal Mode Internet Access Detected Launched: C:\Users\ErikD\Documents\Mijn ontvangen bestanden\zoek.exe [Scan all users] [Script inserted] ==== Older Logs ====================== C:\zoek-results2016-07-28-194308.log 34178 bytes C:\zoek-results2016-07-30-122314.log 1789955 bytes C:\zoek-results2016-07-31-091656.log 18110 bytes ==== Deleting CLSID Registry Keys ====================== ==== Deleting CLSID Registry Values ====================== ==== Deleting Services ====================== ==== Registry Fix Code ====================== Windows Registry Editor Version 5.00 [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{CE234DE8-69D8-425C-8E33-8D81E4ADAEBD}\1.0\0\win32] [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Outlook\Addins\TMAS_OLA.OLAgent] [-HKEY_LOCAL_MACHINE\SOFTWARE\TrendMicro\AMSP] [-HKEY_LOCAL_MACHINE\SOFTWARE\TrendMicro\NSC\TmProxy\Scan\Common\AntiSpam\config] [-HKEY_LOCAL_MACHINE\SOFTWARE\TrendMicro\NSC\TmProxy\Scan\Common\MailManager\config] [-HKEY_LOCAL_MACHINE\SOFTWARE\TrendMicro\NSC\TmProxy] [-HKEY_LOCAL_MACHINE\SOFTWARE\TrendMicro\PC-cillinNTCorp\CurrentVersion\Misc.] [-HKEY_LOCAL_MACHINE\SOFTWARE\TrendMicro\PC-cillinNTCorp\CurrentVersion\Real Time Scan Configuration\Add PIDs] [-HKEY_LOCAL_MACHINE\SOFTWARE\TrendMicro\PC-cillinNTCorp\CurrentVersion\Real Time Scan Configuration] [-HKEY_LOCAL_MACHINE\SOFTWARE\TrendMicro\PC-cillinNTCorp\CurrentVersion\TMAS] [-HKEY_LOCAL_MACHINE\SOFTWARE\TrendMicro\PC-cillinNTCorp\CurrentVersion] [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_TMFILTER\0000] [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_TMPREFILTER\0000] [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_TMTDI\0000] [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_VSAPINT\0000] [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\eventlog\Application\Worry-Free Business Security] [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Perf_iCrcPerfMonMgr\Performance] [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\tmactmon] [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\tmcomm] [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\tmevtmgr] [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TmFilter] [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TmPreFilter] [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\tmtdi] [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\tmumh] [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSApiNt] [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_TMFILTER\0000] [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_TMPREFILTER\0000] [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_TMTDI\0000] [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_VSAPINT\0000] [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\eventlog\Application\Worry-Free Business Security] [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\Perf_iCrcPerfMonMgr\Performance] [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\tmactmon] [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\tmcomm] [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\tmevtmgr] [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\TmFilter] [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\TmPreFilter] [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\tmtdi] [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\tmumh] [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\VSApiNt] [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_TMFILTER\0000] [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_TMPREFILTER\0000] [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_TMTDI\0000] [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_VSAPINT\0000] [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\eventlog\Application\Worry-Free Business Security] [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\Perf_iCrcPerfMonMgr\Performance] [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\tmactmon] [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\tmcomm] [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\tmevtmgr] [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\TmFilter] [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\TmPreFilter] [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\tmtdi] [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\tmumh] [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\VSApiNt] [-HKEY_USERS\.DEFAULT\Software\Microsoft\Office\Outlook\Addins\TMAS_OLA.OLAgent] [-HKEY_USERS\S-1-5-18\Software\Microsoft\Office\Outlook\Addins\TMAS_OLA.OLAgent] [-HKEY_USERS\S-1-5-19\Software\Microsoft\Office\Outlook\Addins\TMAS_OLA.OLAgent] [-HKEY_USERS\S-1-5-20\Software\Microsoft\Office\Outlook\Addins\TMAS_OLA.OLAgent] [-HKEY_USERS\S-1-5-21-1619535343-1243465146-1099412663-1123\Software\Microsoft\Office\Outlook\Addins\TMAS_OLA.OLAgent] [-HKEY_USERS\S-1-5-21-1619535343-1243465146-1099412663-1123\Software\Classes\Software\Microsoft\Office\Outlook\Addins\TMAS_OLA.OLAgent] [-HKEY_USERS\S-1-5-21-1619535343-1243465146-1099412663-1123_Classes\Software\Microsoft\Office\Outlook\Addins\TMAS_OLA.OLAgent] [-HKEY_USERS\S-1-5-18\Software\Microsoft\Office\Outlook\Addins\TMAS_OLA.OLAgent] ==== Deleting Files \ Folders ====================== C:\ProgramData\Trend Micro deleted ==== Orphaned Tasks deleted from Registry ====================== avast Emergency Update deleted ==== Firefox Extensions Registry ====================== [HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions] "wrc@avast.com"="C:\Program Files\AVAST Software\Avast\WebRep\FF" [30/07/2016 14:55] ==== Chromium Look ====================== Google Chrome Version: 46.0.2490.86 HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions daanglpcpkjjlkhcbladppjphglbigam - No path found[] eofcbnmajmjmplflapaojjnihcjkigck - No path found[] fcoadmpfijfcmokecmkgolhbaeclfage - No path found[] gomekmidlodglbbmalcneegieacbdmki - No path found[] Avast Online Security (BETA) - ErikD\AppData\Local\Google\Chrome\User Data\Default\Extensions\daanglpcpkjjlkhcbladppjphglbigam Invite All (for Facebook) - ErikD\AppData\Local\Google\Chrome\User Data\Default\Extensions\eopekjehpibhfpjjcokfmhcaeiclddih Avast SafePrice (BETA) - ErikD\AppData\Local\Google\Chrome\User Data\Default\Extensions\fcoadmpfijfcmokecmkgolhbaeclfage Avast Online Security - ErikD\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki ==== Set IE to Default ====================== Old Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://www.google.be/" New Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://www.google.be/" ==== All HKLM and HKCU SearchScopes ====================== HKLM\SearchScopes "DefaultScope"="{6A1806CD-94D4-4689-BA73-E35EA1EA9990}" HKLM\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC HKLM\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990} - http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7 HKCU\SearchScopes "DefaultScope"="{6A1806CD-94D4-4689-BA73-E35EA1EA9990}" HKCU\SearchScopes\{012E1000-F331-11DB-8314-0800200C9A66} - http://www.google.com/search?q={searchTerms} HKCU\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02 HKCU\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990} - https://www.google.com/search?q={searchTerms}&rlz=1I7ADSA_nlBE481 ==== Empty IE Cache ====================== C:\Users\administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\bnsadmin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\erik\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\erik\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully C:\Users\ErikD\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\ErikD\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully ==== Empty FireFox Cache ====================== No FireFox Profiles found ==== Empty Chrome Cache ====================== C:\Users\ErikD\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully ==== Empty All Flash Cache ====================== Flash Cache Emptied Successfully ==== Empty All Java Cache ====================== Java Cache cleared successfully ==== C:\zoek_backup content ====================== C:\zoek_backup (files=9832 folders=343 4006145734 bytes) ==== Empty Temp Folders ====================== C:\Users\administrator\AppData\Local\Temp emptied successfully C:\Users\bnsadmin\AppData\Local\Temp emptied successfully C:\Users\Default\AppData\Local\Temp emptied successfully C:\Users\Default User\AppData\Local\Temp emptied successfully C:\Users\erik\AppData\Local\Temp emptied successfully C:\Users\ErikD\AppData\Local\Temp will be emptied at reboot C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully C:\Windows\Temp will be emptied at reboot ==== After Reboot ====================== ==== Empty Temp Folders ====================== C:\Windows\Temp successfully emptied C:\Users\ErikD\AppData\Local\Temp successfully emptied ==== Empty Recycle Bin ====================== C:\$RECYCLE.BIN successfully emptied ==== EOF on zo 31/07/2016 at 15:53:45,75 ======================