Zoek.exe v5.0.0.0 Updated 26-11-2014
Tool run by HP on Thu 11/27/2014 at 20:26:34.43.
Microsoft Windows 7 Ultimate 6.1.7600 x86
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\HP\Downloads\zoek.exe [Scan all users] [Checkboxes used]
==== System Restore Info ======================
27/11/2014 08:27:50 م Zoek.exe System Restore Point Created Succesfully.
==== Empty Folders Check ======================
C:\Program Files\FastStone Capture deleted successfully
C:\Program Files\G Data deleted successfully
C:\PROGRA~2\Oracle deleted successfully
C:\Users\HP\AppData\Roaming\QuickScan deleted successfully
C:\Users\HP\AppData\Local\CrashDumps deleted successfully
C:\Users\HP\AppData\Local\VirtualStore deleted successfully
==== Deleting CLSID Registry Keys ======================
HKEY_USERS\S-1-5-21-2413816232-2589206037-1272404818-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{BFF1FF83-D72B-46DC-AC26-DEE8D1BD8B3F} deleted successfully
==== Deleting CLSID Registry Values ======================
==== Running Processes ======================
C:\Windows\System32\smss.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\winlogon.exe
c:\program files\kingsoft\kingsoft antivirus\kxescore.exe
C:\Windows\system32\WLANExt.exe
C:\Windows\system32\conhost.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\taskhost.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Windows\system32\Dwm.exe
c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\kingsoft\kingsoft antivirus\kxetray.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Users\HP\AppData\Local\Google\Update\GoogleUpdate.exe
C:\Users\HP\AppData\Local\Akamai\netsession_win.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Users\HP\AppData\Local\Akamai\netsession_win.exe
C:\Windows\system32\SearchIndexer.exe
c:\program files\kingsoft\kingsoft antivirus\kupdata.exe
C:\Users\HP\Downloads\zoek.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
==== Deleting Services ======================
==== Deleting Files \ Folders ======================
C:\
_@A797.tmp deleted
C:\
_@A7A8.tmp deleted
C:\
_@A7A9.tmp deleted
C:\
_@A7AA.tmp deleted
C:\
_@A7BA.tmp deleted
C:\
_@A7BB.tmp deleted
C:\found.000 deleted
C:\Windows\system32\GroupPolicy\Machine deleted
C:\Windows\system32\GroupPolicy\User deleted
C:\Windows\system32\GroupPolicy\gpt.ini deleted
"C:\Users\HP\AppData\Roaming\SPK\SPK.exe" deleted
"C:\Users\HP\AppData\Roaming\miaul\RJFC.exe" deleted
"C:\Users\HP\AppData\Roaming\SPK" deleted
"C:\Users\HP\AppData\Roaming\miaul" deleted
==== System Specs ======================
Windows: Windows 7 Ultimate Edition (Build 7600)
Memory (RAM): 2486 MB
CPU Info: Intel(R) Core(TM) i3 CPU M 350 @ 2.27GHz
CPU Speed: 2265.4 MHz
Sound Card: Speakers (Generic USB Audio Dev |
Speakers (High Definition Audio |
Display Adapters: Intel(R) HD Graphics | Intel(R) HD Graphics | RDPDD Chained DD | RDP Encoder Mirror Driver | RDP Reflector Display Driver
Monitors: 1x; Generic PnP Monitor |
Screen Resolution: 1366 X 768 - 32 bit
Network: Network Present
Network Adapters: Anchorfree HSS VPN Adapter #2 | Anchorfree HSS VPN Adapter | Bluetooth Device (Personal Area Network) #2 | Broadcom 4313GN 802.11b/g/n 1x1 Wi-Fi Adapter | Realtek RTL8102E/RTL8103E Family PCI-E Fast Ethernet NIC (NDIS 6.20)
CD / DVD Drives: 1x (E: | ) E: hp CDDVDW TS-L633N
Ports: COM Ports NOT Present. LPT Port NOT Present.
Mouse: 3 Button Wheel Mouse Present
Hard Disks: C: 151.3GB | D: 146.7GB
Hard Disks - Free: C: 52.9GB | D: 144.8GB
Manufacturer *: Hewlett-Packard
BIOS Info: AT/AT COMPATIBLE | 05/19/10 | HPQOEM - 1
Time Zone: السعودية - التوقيت الرسمي
Motherboard *: Hewlett-Packard 1439
Country: ںéèيï¢
Language: ARK
==== System Specs (Software) ======================
Anti-Virus: Kingsoft Antivirus System Defense On-access scanning disabled (Outdated)
Anti-Spyware: Kingsoft Antivirus System Defense disabled (Outdated)
Anti-Spyware: Windows Defender disabled (Outdated)
Default Browser: Firefox 33.1
Internet Explorer version: 8.0.7600.16385
Mozilla Firefox version: 33.1 (x86 ar)
Google Chrome version: 39.0.2171.71
Adobe Reader version: 11.0.9.29
Sun Java version: 1.7.0_55 (32-bit)
Flash Player version: 15.0.0.239
==== Files Recently Created / Modified ======================
====== C:\Windows ====
====== C:\Users\HP\AppData\Local\Temp ====
====== Java Cache =====
====== C:\Windows\system32 =====
2014-11-27 13:49:18 7117C3177B8E7C851FC01D2320C2A368 3852 ----a-w- C:\Windows\System32\.crusader
2014-11-21 03:22:36 AA358EDD2C78B233CCB9A1FF600EB653 100445232 ----a-w- C:\Windows\System32\MRT.exe
2014-11-21 03:19:48 EEDB427EAC109E0711642B65C229BC59 3957632 ----a-w- C:\Windows\System32\ntkrnlpa.exe
2014-11-21 03:19:48 D9FD1D6337F15AAF2012C69909615DB5 3901824 ----a-w- C:\Windows\System32\ntoskrnl.exe
2014-11-21 03:19:45 20104EA66332D24D7C65BBB087C56737 123904 ----a-w- C:\Windows\System32\poqexec.exe
2014-11-21 03:19:22 48744C796F25A52B2C229686EB86EDD5 541184 ----a-w- C:\Windows\System32\kerberos.dll
2014-11-20 12:31:18 FC3EC24FCE372C89423E015A2AC1A31E 1933848 ----a-w- C:\Windows\System32\wuaueng.dll
2014-11-20 12:31:18 BDC0C99E472176C8C2C853A68ADC5073 45080 ----a-w- C:\Windows\System32\wups2.dll
2014-11-20 12:31:18 2E0B0A051FFAA86E358465BB0880D453 53784 ----a-w- C:\Windows\System32\wuauclt.exe
2014-11-20 12:31:18 285C594C4913FA9DC7BB6BA3AD6F101A 2422272 ----a-w- C:\Windows\System32\wucltux.dll
2014-11-20 12:31:10 C480F0E968ECA0D80D0299D7F204E33B 88576 ----a-w- C:\Windows\System32\wudriver.dll
2014-11-20 12:31:10 3458EDA96E30FBD0477A2800D3FB1909 35864 ----a-w- C:\Windows\System32\wups.dll
2014-11-20 12:31:10 1A617835452EEE5060976C9B9F5FE635 577048 ----a-w- C:\Windows\System32\wuapi.dll
2014-11-20 12:31:01 98F94089E9C549E223AB05BE54BAB2ED 171904 ----a-w- C:\Windows\System32\wuwebv.dll
2014-11-20 12:31:01 069385484EA57B663D688894C88975C5 33792 ----a-w- C:\Windows\System32\wuapp.exe
====== C:\Windows\system32\drivers =====
2014-11-27 13:51:55 B3635FD088BA2F6F03A276A961BE6ED2 35992 ----a-w- C:\Windows\System32\drivers\hitmanpro37.sys
2014-11-27 12:38:51 E89B115E1DD297DCB694B22CFA90BF61 75480 ----a-w- C:\Windows\System32\drivers\mbamchameleon.sys
2014-11-27 12:38:51 D2DED3C333A5D9CB3F4C244B0F0DD877 23256 ----a-w- C:\Windows\System32\drivers\mbam.sys
2014-11-27 12:38:51 7A6526C8BD114DB7CA8930AB22D52A0B 51928 ----a-w- C:\Windows\System32\drivers\mwac.sys
====== C:\Windows\Tasks ======
2014-11-27 01:18:31 1242F3671547F454336298FF86014E22 3724 ----a-w- C:\Windows\system32\Tasks\keepup
2014-11-27 01:18:30 7104F20FF62E67722327F4369DB9B5E9 3200 ----a-w- C:\Windows\system32\Tasks\mium0d
2014-11-26 23:47:38 6B32605894B5D44C1E7030EA5B6ED74D 3130 ----a-w- C:\Windows\system32\Tasks\{D681F73A-D060-458E-8FF7-489FE0976FED}
2014-11-26 23:45:43 6B32605894B5D44C1E7030EA5B6ED74D 3130 ----a-w- C:\Windows\system32\Tasks\{750F43E7-58D6-4FDC-8702-F9CA9AF1EB6D}
2014-11-26 23:40:50 6B32605894B5D44C1E7030EA5B6ED74D 3130 ----a-w- C:\Windows\system32\Tasks\{A7CE5302-3743-4F0F-8DC5-D2EC04F171B5}
2014-11-26 23:36:05 B8F09ECCFA39EA6BC83C9EDB4BA27C04 3230 ----a-w- C:\Windows\system32\Tasks\Java Update
2014-11-26 23:36:05 A12A8AADD8CC98B29067953CC94885E6 3202 ----a-w- C:\Windows\system32\Tasks\9A5A8340-6B15
====== C:\Windows\Temp ======
======= C:\Program Files =====
2014-11-27 14:08:19 -------- d-----w- C:\Program Files\AnyCleaner
2014-11-27 11:42:24 -------- d-----w- C:\Program Files\Trend Micro
======= C: =====
====== C:\Users\HP\AppData\Roaming ======
2014-11-27 01:50:20 -------- d-----w- C:\Users\HP\AppData\Roaming\TS3Client
2014-11-27 01:50:13 -------- d-----w- C:\Users\HP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TeamSpeak 3 Client
2014-11-27 01:50:10 -------- d-----w- C:\Users\HP\AppData\Local\TeamSpeak 3 Client
2014-11-26 23:36:05 E2CC5ECBD15DF85E8E07DAC41A8FF776 193 ----a-w- C:\Users\HP\AppData\Roaming\r.reg
2014-11-26 23:36:01 -------- d-----w- C:\Users\HP\AppData\Roaming\Fixs
2014-11-26 23:22:49 -------- d-----w- C:\Users\HP\AppData\Roaming\Curse Client
2014-11-23 14:15:05 -------- d-s---w- C:\Windows\serviceprofiles\networkservice\AppData\Locallow\Microsoft
====== C:\Users\HP ======
2014-11-27 14:08:19 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AnyCleaner
2014-11-27 14:07:54 FCD9B946149250801353C80447BE2929 896554 ----a-w- C:\Users\HP\Downloads\anycleaner_1.05_x86_setup(1).exe
2014-11-27 14:07:28 2E08CB19F879964F79515F638DA5823A 230656 ----a-w- C:\Users\HP\Downloads\anycleaner_1.05_x86_setup.exe
2014-11-27 13:56:59 5A6F21141B846BD3CE1ED0BD0F19C3AF 2148864 ----a-w- C:\Users\HP\Downloads\adwcleaner_4.102.exe
2014-11-27 13:43:55 -------- d-----w- C:\ProgramData\HitmanPro
2014-11-27 13:43:22 BD6C3071F98A563989F99AC61BDDC925 10284408 ----a-w- C:\Users\HP\Downloads\HitmanPro.exe
2014-11-27 12:38:11 E90BF9E1562F40140161573B79CD5720 17292760 ----a-w- C:\Users\HP\Downloads\mbam-setup-2.0.2.1012.exe
2014-11-27 12:35:01 8685FAF50C04F9A9C2F56FF64B0B7ACB 1107968 ----a-w- C:\Users\HP\Downloads\RSIT.exe
2014-11-27 01:49:18 23DEAC9FBE97193CEC07942B6115CE31 28115400 ----a-w- C:\Users\HP\Downloads\TeamSpeak3-Client-win32-3.0.16.exe
2014-11-27 01:18:21 77A183F2EB427132967A2A2B96BE03F4 4606 --sha-r- C:\ProgramData\ntuser.pol
2014-11-26 23:21:27 4443676D1507439BA098485BF3EB591A 31012080 ----a-w- C:\Users\HP\Downloads\CurseClientSetup_r-y7H4.exe
2014-11-21 08:59:52 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\League of Legends
====== C: exe-files ==
2014-11-27 14:08:19 6D5609FD94B95283987F845FCCCC33ED 509440 ----a-w- C:\Program Files\AnyCleaner\AnyCleaner.exe
2014-11-27 14:08:19 594B230DF3042643A313A5705DE1D245 718497 ----a-w- C:\Program Files\AnyCleaner\unins000.exe
2014-11-27 14:07:54 FCD9B946149250801353C80447BE2929 896554 ----a-w- C:\Users\HP\Downloads\anycleaner_1.05_x86_setup(1).exe
2014-11-27 14:07:28 2E08CB19F879964F79515F638DA5823A 230656 ----a-w- C:\Users\HP\Downloads\anycleaner_1.05_x86_setup.exe
2014-11-27 13:56:59 5A6F21141B846BD3CE1ED0BD0F19C3AF 2148864 ----a-w- C:\Users\HP\Downloads\adwcleaner_4.102.exe
2014-11-27 13:43:22 BD6C3071F98A563989F99AC61BDDC925 10284408 ----a-w- C:\Users\HP\Downloads\HitmanPro.exe
2014-11-27 12:38:11 E90BF9E1562F40140161573B79CD5720 17292760 ----a-w- C:\Users\HP\Downloads\mbam-setup-2.0.2.1012.exe
2014-11-27 12:35:19 9A2347903D6EDB84C10F288BC0578C1C 388608 ----a-w- C:\Program Files\Trend Micro\HP.exe
2014-11-27 12:35:01 8685FAF50C04F9A9C2F56FF64B0B7ACB 1107968 ----a-w- C:\Users\HP\Downloads\RSIT.exe
2014-11-27 01:50:14 6E7E1560461A1B7741B062F7CF3B6276 126303 ----a-w- C:\Users\HP\AppData\Local\TeamSpeak 3 Client\Uninstall.exe
2014-11-27 01:49:18 23DEAC9FBE97193CEC07942B6115CE31 28115400 ----a-w- C:\Users\HP\Downloads\TeamSpeak3-Client-win32-3.0.16.exe
2014-11-26 23:22:51 D45CCDD124FA98669E2FCD6B2F898A53 295646 ----a-r- C:\Users\HP\AppData\Roaming\Microsoft\Installer\{DEE70742-F4E9-44CA-B2B9-EE95DCF37295}\CurseClient.exe
2014-11-26 23:21:27 4443676D1507439BA098485BF3EB591A 31012080 ----a-w- C:\Users\HP\Downloads\CurseClientSetup_r-y7H4.exe
2014-11-26 16:21:40 9D83E2859AC027E8C505CB4D1931AF47 1117264 ----a-w- C:\Users\HP\AppData\Local\Google\Update\Download\{4DC8B4CA-1BDA-483E-B5FA-D3C12E15B62D}\39.0.2171.71\39.0.2171.71_39.0.2171.65_chrome_updater.exe
2014-11-25 11:35:36 68B8513D3591E9509FE15F4A0CAF9E4B 4247544 ----a-w- C:\Riot Games\League of Legends\RADS\projects\lol_patcher\releases\0.0.0.13\deploy\LoLPatcher.exe
2014-11-25 11:35:36 642FF2C35ADB57870A6EB86DA6C21CCB 1704440 ----a-w- C:\Riot Games\League of Legends\RADS\projects\lol_patcher\releases\0.0.0.13\deploy\rPipe.exe
2014-11-21 10:38:10 957AD5B28823F3351CACD751B83B7D90 15973880 ----a-w- C:\Riot Games\League of Legends\RADS\solutions\lol_game_client_sln\releases\0.0.1.68\deploy\League of Legends.exe
2014-11-21 10:38:06 883C3A4367A58E4278BBF4A7ADD83572 282064 ----a-w- C:\Riot Games\League of Legends\RADS\solutions\lol_game_client_sln\releases\0.0.1.68\deploy\BsSndRpt.exe
2014-11-21 10:08:15 957AD5B28823F3351CACD751B83B7D90 15973880 ----a-w- C:\Riot Games\League of Legends\RADS\projects\lol_game_client\releases\0.0.1.7\deploy\League of Legends.exe
2014-11-21 09:30:23 883C3A4367A58E4278BBF4A7ADD83572 282064 ----a-w- C:\Riot Games\League of Legends\RADS\projects\lol_game_client\releases\0.0.1.7\deploy\BsSndRpt.exe
2014-11-21 09:22:17 5B93A9C1BB894EFA4D6429EEADA5007C 74752 ----a-w- C:\Riot Games\League of Legends\RADS\projects\lol_air_client\releases\0.0.1.119\deploy\LolClient.exe
2014-11-21 09:12:28 9FF9636041491F41439D766F846F53C0 59392 ----a-w- C:\Riot Games\League of Legends\RADS\projects\lol_air_client\releases\0.0.1.119\deploy\Adobe AIR\Versions\1.0\Resources\CaptiveAppEntry.exe
2014-11-21 09:04:41 87EC62C1190BB80F2664B98E8F1F73D4 107008 ----a-w- C:\Riot Games\League of Legends\RADS\projects\lol_patcher\releases\0.0.0.13\deploy\jpatch.exe
2014-11-21 09:04:39 883C3A4367A58E4278BBF4A7ADD83572 282064 ----a-w- C:\Riot Games\League of Legends\RADS\projects\lol_patcher\releases\0.0.0.13\deploy\BsSndRpt.exe
2014-11-21 09:02:25 4B9D1242B86A3676266A06C386B57676 2436600 ----a-w- C:\Riot Games\League of Legends\RADS\projects\lol_launcher\releases\0.0.0.229\deploy\LoLLauncher.exe
2014-11-21 09:02:24 E7DEB0F3285FC671EBFDC9BF2DC5AA01 114680 ----a-w- C:\Riot Games\League of Legends\RADS\projects\lol_launcher\releases\0.0.0.229\deploy\jpatch.exe
2014-11-21 03:22:36 AA358EDD2C78B233CCB9A1FF600EB653 100445232 ----a-w- C:\Windows\System32\MRT.exe
2014-11-21 03:19:48 EEDB427EAC109E0711642B65C229BC59 3957632 ----a-w- C:\Windows\System32\ntkrnlpa.exe
2014-11-21 03:19:48 D9FD1D6337F15AAF2012C69909615DB5 3901824 ----a-w- C:\Windows\System32\ntoskrnl.exe
2014-11-21 03:19:45 20104EA66332D24D7C65BBB087C56737 123904 ----a-w- C:\Windows\System32\poqexec.exe
2014-11-20 22:30:04 C6B2C393D08999FACD29AA4359B6B597 609544 ----a-w- C:\Users\HP\AppData\Roaming\Curse Client\Bin\CurseSetupHelper.exe
2014-11-20 22:30:01 275C00173C624A8628C11840B6561521 14600 ----a-w- C:\Users\HP\AppData\Roaming\Curse Client\Bin\Curse.OverlayHelper.exe
2014-11-20 22:29:59 8979A58F8D6E78F63B1D6B6B3A2CA6BE 6142216 ----a-w- C:\Users\HP\AppData\Roaming\Curse Client\Bin\Curse.exe
=== C: other files ==
2014-11-27 14:24:59 EA8A42F43906D365D48CC966D794DADF 392243 ----a-w- C:\Users\HP\AppData\Local\Temp\tmp-hjh.xpi
2014-11-27 13:51:55 B3635FD088BA2F6F03A276A961BE6ED2 35992 ----a-w- C:\Windows\System32\drivers\hitmanpro37.sys
2014-11-27 12:38:51 E89B115E1DD297DCB694B22CFA90BF61 75480 ----a-w- C:\Windows\System32\drivers\mbamchameleon.sys
2014-11-27 12:38:51 D2DED3C333A5D9CB3F4C244B0F0DD877 23256 ----a-w- C:\Windows\System32\drivers\mbam.sys
2014-11-27 12:38:51 7A6526C8BD114DB7CA8930AB22D52A0B 51928 ----a-w- C:\Windows\System32\drivers\mwac.sys
==== Startup Registry Enabled ======================
[HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun"
[HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun"
[HKEY_USERS\S-1-5-21-2413816232-2589206037-1272404818-1000\Software\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="C:\Users\HP\AppData\Local\Google\Update\GoogleUpdate.exe /c"
"Akamai NetSession Interface"="C:\Users\HP\AppData\Local\Akamai\netsession_win.exe"
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe /autoRun"
[HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"mctadmin"="C:\Windows\System32\mctadmin.exe"
[HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"mctadmin"="C:\Windows\System32\mctadmin.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\Windows\system32\igfxtray.exe"
"HotKeysCmds"="C:\Windows\system32\hkcmd.exe"
"Persistence"="C:\Windows\system32\igfxpers.exe"
"Adobe ARM"="C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"TkBellExe"="C:\Program Files\Real\RealPlayer\update\realsched.exe -osboot"
"BCSSync"="C:\Program Files\Microsoft Office\Office14\BCSSync.exe /DelayServices"
"kxesc"="c:\program files\kingsoft\kingsoft antivirus\kxetray.exe -autorun"
"SunJavaUpdateSched"="C:\Program Files\Common Files\Java\Java Update\jusched.exe"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="C:\Users\HP\AppData\Local\Google\Update\GoogleUpdate.exe /c"
"Akamai NetSession Interface"="C:\Users\HP\AppData\Local\Akamai\netsession_win.exe"
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe /autoRun"
==== Task Scheduler Jobs ======================
C:\Windows\tasks\Adobe Flash Player Updater.job --a------ C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [11/26/2014 07:07 PM]
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2413816232-2589206037-1272404818-1000Core.job --a------ C:\Users\HP\AppData\Local\Google\Update\GoogleUpdate.exe [02/12/2014 12:36 AM]
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2413816232-2589206037-1272404818-1000UA.job --a------ C:\Users\HP\AppData\Local\Google\Update\GoogleUpdate.exe [02/12/2014 12:36 AM]
==== Other Scheduled Tasks ======================
"C:\Windows\system32\tasks\9A5A8340-6B15" ["C:\Users\HP\AppData\Roaming\ARHome\Updater.exe"]
"C:\Windows\system32\tasks\Adobe Flash Player Updater" [C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe]
"C:\Windows\system32\tasks\GoogleUpdateTaskUserS-1-5-21-2413816232-2589206037-1272404818-1000Core" [C:\Users\HP\AppData\Local\Google\Update\GoogleUpdate.exe]
"C:\Windows\system32\tasks\GoogleUpdateTaskUserS-1-5-21-2413816232-2589206037-1272404818-1000UA" [C:\Users\HP\AppData\Local\Google\Update\GoogleUpdate.exe]
"C:\Windows\system32\tasks\Java Update" ["C:\Program Files\Java\Java.exe"]
"C:\Windows\system32\tasks\keepup" ["C:\Users\HP\AppData\Roaming\miaul\RJFC.exe"]
"C:\Windows\system32\tasks\mium0d" ["C:\Users\HP\AppData\Roaming\miaul\RJFC.exe"]
"C:\Windows\system32\tasks\{750F43E7-58D6-4FDC-8702-F9CA9AF1EB6D}" ["c:\program files\mozilla firefox\firefox.exe"]
"C:\Windows\system32\tasks\{A7CE5302-3743-4F0F-8DC5-D2EC04F171B5}" ["c:\program files\mozilla firefox\firefox.exe"]
"C:\Windows\system32\tasks\{D681F73A-D060-458E-8FF7-489FE0976FED}" ["c:\program files\mozilla firefox\firefox.exe"]
"C:\Windows\system32\tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask" [%systemroot%\system32\sc.exe start osppsvc]
==== Firefox Extensions Registry ======================
[HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions]
"{ABDE892B-13A8-4d1b-88E6-365A6E755758}"="C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext" [02/11/2014 03:50 PM]
==== Firefox Extensions ======================
AppDir: C:\Program Files\Mozilla Firefox
- Hotspot Shield Extension - %AppDir%\browser\extensions\
afproxy@anchorfree.com
- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
==== Firefox Plugins ======================
Profilepath: C:\Users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\683llyfe.default-1417097169234
8303B3CEC05500F763B4FA75210598BB - C:\Windows\system32\Macromed\Flash\NPSWF32_15_0_0_239.dll - Shockwave Flash
D2377C9458EFEB094E38B8C874AA214C - C:\Users\HP\AppData\Local\Google\Update\1.3.25.11\npGoogleUpdate3.dll - Google Update
64C4ADE063A9C93D3BAE09922AD90C27 - C:\Program Files\Adobe\Reader 11.0\Reader\browser\nppdf32.dll - Adobe Acrobat
446BCAE59E26321802E000FC3E0C390A - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll - Adobe Acrobat
025BBEF5A248B09BDC6684747F6EB5BC - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll - Java(TM) Platform SE 7 U55
290A0130C74ADCD4546BC6900D1665D9 - C:\Program Files\Java\jre7\bin\dtplugin\npdeployJava1.dll - Java Deployment Toolkit 7.0.550.14
0D5D73608555C9293D716A9F2DB275B4 - C:\Program Files\EagleGet\npEagleget.dll - EagleGet
65C1D9F74004E775F9A8598476ABE5EE - C:\Users\HP\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll - Unity Player
3A9E1940B4459CC97FDCBB24FCB69004 - C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll - RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit)
0FCEAA7D12B7B0BA825E5C770B1DCA48 - C:\Program Files\Real\RealPlayer\Netscape6\nprpplugin.dll - RealPlayer Download Plugin
BE126CB7049E89ED6F3038016668B502 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll - RealNetworks(tm) RealDownloader Chrome Background Extension Plug-In (32-bit)
EAC427FEF96A13058C1ACD17C38966CF - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll - RealNetworks(tm) RealDownloader PepperFlashVideoShim Plug-In (32-bit)
96B3689320E9B16EDF38B7A5001C35F0 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll - RealNetworks(tm) RealDownloader HTML5VideoShim Plug-In (32-bit)
F8CB60A5ACA5D73807ECBD9942A8BCB7 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll - RealDownloader Plugin
260488E2BC07C276D1EDD54CCA086809 - C:\Program Files\VideoLAN\VLC\npvlc.dll - VLC Web Plugin
==== Deleted Firefox Extensions ======================
C:\Program Files\Mozilla Firefox\browser\extensions\
afproxy@anchorfree.com deleted
==== Chromium Look ======================
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
idhngdhcfkoamngbedgpaokgjbnpdiji - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Chrome\Ext\realdownloader.crx[08/14/2013 03:24 PM]
kaebhgioafceeldhgjmendlfhbfjefmo - C:\Program Files\EagleGet\addon\
eagleget_cext@eagleget.com.crx[03/12/2014 09:20 AM]
HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\Extensions
kaebhgioafceeldhgjmendlfhbfjefmo - C:\Program Files\EagleGet\addon\
eagleget_cext@eagleget.com.crx[03/12/2014 09:20 AM]
HD for YouTubeâ„¢ - HP\AppData\Local\Google\Chrome\User Data\Default\Extensions\akjbfncbadcmnkopckegnmjgihagponf
Google Docs - HP\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake
Google Drive - HP\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf
YouTube - HP\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo
Google Search - HP\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf
EagleGet Downloader - HP\AppData\Local\Google\Chrome\User Data\Default\Extensions\kaebhgioafceeldhgjmendlfhbfjefmo
Google Wallet - HP\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda
Gmail - HP\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia
==== Chromium Fix ======================
C:\Users\HP\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_deals.souq.com_0.localstorage deleted successfully
==== Set IE to Default ======================
Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="
"
New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="
"
==== All HKCU SearchScopes ======================
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
"DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
{012E1000-F331-11DB-8314-0800200C9A66} Google Url="
"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="
"
==== Reset Google Chrome ======================
C:\Users\HP\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
==== Deleting Registry Keys ======================
HKEY_LOCAL_MACHINE\Software\Policies\Google deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Chromium deleted successfully
==== HijackThis Entries ======================
O2 - BHO: RealNetworks Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll
O2 - BHO: Windows Live OneCare Family Safety Browser Helper - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - (no file)
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: bteagleget.com - {824F251E-D74A-4d56-B998-CA05CF369A13} - C:\Program Files\EagleGet\eagleSniffer.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Real\RealPlayer\update\realsched.exe" -osboot
O4 - HKLM\..\Run: [BCSSync] "C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices
O4 - HKLM\..\Run: [kxesc] "c:\program files\kingsoft\kingsoft antivirus\kxetray.exe" -autorun
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [Google Update] "C:\Users\HP\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [Akamai NetSession Interface] "C:\Users\HP\AppData\Local\Akamai\netsession_win.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: Download all links with EagleGet - res://C:\Program Files\EagleGet\IEGraberBHO.dll/202
O8 - Extra context menu item: Download with EagleGet - res://C:\Program Files\EagleGet\IEGraberBHO.dll/201
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105
O9 - Extra button: إرسال إلى OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: إر&سال إلى OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: ملاحظات OneNote الم&رتبطة - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: ملاحظات OneNote الم&رتبطة - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Kingsoft Core Service (kxescore) - Kingsoft Corporation - c:\program files\kingsoft\kingsoft antivirus\kxescore.exe
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
O23 - Service: RealNetworks Downloader Resolver Service - Unknown owner - C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe
==== Empty IE Cache ======================
C:\Users\HP\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\HP\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot
==== Empty FireFox Cache ======================
C:\Users\HP\AppData\Local\Mozilla\Firefox\Profiles\683llyfe.default-1417097169234\cache2 emptied successfully
==== Empty Chrome Cache ======================
C:\Users\HP\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
==== Empty All Flash Cache ======================
Flash Cache Emptied Successfully
==== Empty All Java Cache ======================
Java Cache cleared successfully
==== C:\zoek_backup content ======================
C:\zoek_backup (files=39 folders=15 16179903 bytes)
==== Empty Temp Folders ======================
C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\HP\AppData\Local\Temp will be emptied at reboot
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot
==== After Reboot ======================
==== Empty Temp Folders ======================
C:\Windows\Temp successfully emptied
C:\Users\HP\AppData\Local\Temp successfully emptied
==== Empty Recycle Bin ======================
C:\$RECYCLE.BIN successfully emptied
==== Deleting Files / Folders ======================
"C:\Users\HP\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not found
==== EOF on Thu 11/27/2014 at 20:42:40.47 ======================