Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Zoek.exe Version 4.0.0.3 Updated 10-July-2013
- Tool run by Pedja on Sat 07/13/2013 at 18:08:33.54.
- Microsoft Windows XP Professional 5.1.2600 Service Pack 2 x86
- Running in: Normal Mode Internet Access Detected
- ==== Deleting CLSID Registry Keys ======================
- ==== Deleting CLSID Registry Values ======================
- ==== Deleting Services ======================
- ==== Registry Fix Code ======================
- Windows Registry Editor Version 5.00
- [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
- "help.vbe"=-
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
- "help.vbe"=-
- ==== Deleting Files \ Folders ======================
- "c:\documents and settings\pedja\start menu\programs\startup\help.vbe" deleted
- "c:\docume~1\pedja\locals~1\temp\help.vbe" deleted
- "C:\Documents and Settings\Pedja\Application Data\burnaware.ini" deleted
- "C:\Documents and Settings\Pedja\Application Data\desktop.ini" deleted
- "C:\WINDOWS\System32\NEW2C.tmp" deleted
- "C:\WINDOWS\System32\NEW32.tmp" deleted
- "C:\WINDOWS\System32\NEW5E.tmp" deleted
- "C:\Documents and Settings\All Users\Desktop\YTD Video Downloader.lnk" deleted
- "C:\Documents and Settings\Pedja\Application Data\IObit Apps" deleted
- ==== Files Recently Created / Modified ======================
- ====== C:\WINDOWS ====
- ====== C:\DOCUME~1\Pedja\LOCALS~1\Temp ====
- 2013-07-12 18:31:38 1B1D86A574E842946E5D5317892B45C5 31954536 ----a-w- C:\DOCUME~1\Pedja\LOCALS~1\Temp\SkypeSetup.exe
- ====== C:\WINDOWS\system32 =====
- 2013-07-11 12:33:36 1E02B25DF1767DBE2743EB73643E1669 188200 ----a-w- C:\WINDOWS\System32\FNTCACHE.DAT
- ====== C:\WINDOWS\system32\drivers =====
- 2013-07-08 09:08:28 4470E3C1E0C3378E4CAB137893C12C3A 22856 ----a-w- C:\WINDOWS\System32\drivers\mbam.sys
- ====== C:\WINDOWS\Tasks ======
- 2013-06-30 13:33:07 CAD12568B6B7110DE788481B86F819BC 320 ----a-w- C:\WINDOWS\Tasks\GlaryInitialize 3.job
- ====== C:\WINDOWS\Temp ======
- ======= C:\Program Files =====
- 2013-07-11 08:57:31 -------- d-----w- C:\Program Files\MCShield
- 2013-07-08 08:28:17 -------- d-----w- C:\Program Files\OpenAL
- 2013-07-07 09:25:24 -------- d-----w- C:\Program Files\NCH Software
- 2013-06-30 13:32:59 -------- d-----w- C:\Program Files\Glary Utilities 3
- ======= C: =====
- 2013-07-13 16:06:11 6CABD9FE600C4E3CCC225E7FF14C7C54 1338 ----a-w- C:\AdwCleaner[S2].txt
- 2013-07-10 12:20:24 43CB99094F313F945723A78BCD88E67D 10743 ----a-w- C:\AdwCleaner[S1].txt
- 2013-07-10 12:20:14 32EC5BBE0CCCC2E75822B002E5F6364C 10778 ----a-w- C:\AdwCleaner[R1].txt
- ====== C:\Documents and Settings\Pedja\Application Data ======
- 2013-07-12 12:04:09 3D2C0CADF6F4C90EBDE1AFEA7962FD50 42168 ----a-w- C:\Documents and Settings\Pedja\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
- 2013-07-11 08:57:34 -------- d-----w- C:\Documents and Settings\All Users\Start Menu\Programs\MCShield\Uninstall
- 2013-07-11 08:57:34 -------- d-----w- C:\Documents and Settings\All Users\Start Menu\Programs\MCShield
- 2013-07-11 08:57:32 -------- d-----w- C:\Documents and Settings\All Users\Application Data\MCShield
- 2013-07-10 07:55:20 -------- d-----r- C:\Documents and Settings\Pedja\Start Menu\Programs\Administrative Tools
- 2013-07-09 10:50:54 -------- d-----w- C:\Documents and Settings\All Users\Start Menu\Programs\Glary Utilities 3
- 2013-07-09 08:15:21 -------- d-----w- C:\Documents and Settings\All Users\Start Menu\Programs\AVG
- 2013-07-08 08:31:56 -------- d-----w- C:\Documents and Settings\All Users\Start Menu\Programs\YTD Video Downloader
- 2013-07-08 08:30:20 -------- d-----w- C:\Documents and Settings\All Users\Start Menu\Programs\K-Lite Codec Pack\Uninstall
- 2013-07-08 08:30:20 -------- d-----w- C:\Documents and Settings\All Users\Start Menu\Programs\K-Lite Codec Pack\Tools
- 2013-07-08 08:30:20 -------- d-----w- C:\Documents and Settings\All Users\Start Menu\Programs\K-Lite Codec Pack\Help
- 2013-07-08 08:30:19 -------- d-----w- C:\Documents and Settings\All Users\Start Menu\Programs\K-Lite Codec Pack\Configuration
- 2013-07-08 08:30:19 -------- d-----w- C:\Documents and Settings\All Users\Start Menu\Programs\K-Lite Codec Pack
- 2013-07-08 08:30:16 -------- d-----w- C:\Documents and Settings\Pedja\Application Data\Media Player Classic
- 2013-07-08 08:28:29 -------- d-----w- C:\Documents and Settings\All Users\Start Menu\Programs\Disney Interactive Studios\G-Force
- 2013-07-08 08:28:29 -------- d-----w- C:\Documents and Settings\All Users\Start Menu\Programs\Disney Interactive Studios
- 2013-07-08 08:28:28 -------- d-----w- C:\Documents and Settings\All Users\Start Menu\Programs\Alien Arena 7.60
- 2013-07-07 12:37:00 -------- d-----w- C:\Documents and Settings\Pedja\Application Data\avidemux
- 2013-07-07 09:25:35 -------- d-----w- C:\Documents and Settings\Pedja\Application Data\NCH Software
- 2013-07-07 08:34:44 -------- d-----w- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
- 2013-07-01 10:50:10 -------- d-----w- C:\Documents and Settings\All Users\Start Menu\Programs\YTD Video Downloader(2)
- ====== C:\Documents and Settings\Pedja ======
- 2013-07-12 11:11:45 60BF4AE8CC40B0E3E28613657ED2EED8 377856 ----a-w- C:\Documents and Settings\Pedja\Desktop\k50wfoo2.exe
- 2013-07-11 10:45:57 -------- d--h--r- C:\Documents and Settings\Pedja\Recent
- 2013-07-10 12:19:58 CC198634BCAEF99C50277CC81B14AB27 662345 ----a-w- C:\Documents and Settings\Pedja\Desktop\adwcleaner.exe
- 2013-06-30 13:58:44 -------- d-----w- C:\Documents and Settings\All Users\GlarySoft
- ====== C: exe-files ==
- 2013-07-12 18:45:35 A6F8D4FBC12177A75AB4C06D059229B6 784664 ----a-w- C:\Documents and Settings\Pedja\Local Settings\Application Data\Google\Update\1.3.21.153\GoogleUpdateSetup.exe
- 2013-07-12 18:45:35 6466C051022547489D3409205128881B 59784 ----atw- C:\Documents and Settings\Pedja\Local Settings\Application Data\Google\Update\1.3.21.153\GoogleUpdateBroker.exe
- 2013-07-12 18:45:35 1CA3976D1B1FE826ADF339F90AC25C60 59784 ----atw- C:\Documents and Settings\Pedja\Local Settings\Application Data\Google\Update\1.3.21.153\GoogleUpdateOnDemand.exe
- 2013-07-12 18:45:33 D9A08472D8D0218A0AE2C9D9F63EA531 290696 ----atw- C:\Documents and Settings\Pedja\Local Settings\Application Data\Google\Update\1.3.21.153\GoogleCrashHandler64.exe
- 2013-07-12 18:45:32 8726802EA4FBFFA3FD54FD2449BF51D4 217992 ----atw- C:\Documents and Settings\Pedja\Local Settings\Application Data\Google\Update\1.3.21.153\GoogleCrashHandler.exe
- 2013-07-12 18:45:32 506708142BC63DABA64F2D3AD1DCD5BF 116648 ----atw- C:\Documents and Settings\Pedja\Local Settings\Application Data\Google\Update\1.3.21.153\GoogleUpdate.exe
- 2013-07-12 18:45:31 A6F8D4FBC12177A75AB4C06D059229B6 784664 ----a-w- C:\Documents and Settings\Pedja\Local Settings\Application Data\Google\Update\Download\{430FD4D0-B729-4F61-AA34-91526481799D}\1.3.21.153\GoogleUpdateSetup.exe
- 2013-07-12 18:31:38 1B1D86A574E842946E5D5317892B45C5 31954536 ----a-w- C:\Documents and Settings\Pedja\Local Settings\Temp\SkypeSetup.exe
- 2013-07-12 11:46:43 31874CF517BD0D51DB5065F6C77F37AF 7256928 ----a-w- C:\Documents and Settings\Pedja\Local Settings\Application Data\Google\Update\Download\{4DC8B4CA-1BDA-483E-B5FA-D3C12E15B62D}\28.0.1500.71\28.0.1500.71_27.0.1453.116_chrome_updater.exe
- 2013-07-12 11:11:45 60BF4AE8CC40B0E3E28613657ED2EED8 377856 ----a-w- C:\Documents and Settings\Pedja\Desktop\k50wfoo2.exe
- 2013-07-11 08:57:34 6E902601D66C4C53606F1A1F3C89231A 212148 ----a-w- C:\Program Files\MCShield\MCS-uninstall.exe
- 2013-07-11 08:57:34 0E8A97B3BB3A58A55D40845D567DD2C3 2626084 ----a-w- C:\Documents and Settings\All Users\Application Data\MCShield\MCShield-Setup.exe
- 2013-07-10 12:19:58 CC198634BCAEF99C50277CC81B14AB27 662345 ----a-w- C:\Documents and Settings\Pedja\Desktop\adwcleaner.exe
- 2013-07-09 10:50:56 C54023BF92B84D83D3FCD8DE2A4F5555 173681 ----a-w- C:\Program Files\Glary Utilities 3\uninst.exe
- 2013-07-09 10:47:53 C5D7F89A25A2E028245EECEFE1FB08B6 15830992 ----a-w- C:\Documents and Settings\Pedja\My Documents\Downloads\gu3setup.exe
- 2013-07-09 10:39:29 C57324BDFE3063EDF7DFD1942242917E 21840856 ----a-w- C:\Documents and Settings\Pedja\My Documents\Downloads\Firefox Setup 22.0.exe
- 2013-07-09 08:15:36 0E8A97B3BB3A58A55D40845D567DD2C3 2626084 ----a-w- C:\Documents and Settings\Pedja\My Documents\Downloads\MCShield-Setup.exe
- 2013-07-09 08:14:04 0E10142276BE74CF0D6E91C0140F1274 7626512 ----a-w- C:\Program Files\AVG\AVG2013\avgmfapx.exe
- 2013-07-08 09:19:01 6E796AA88EEA7AFCE49680DA27E3B6A4 12977165 ----a-w- C:\Documents and Settings\Pedja\My Documents\Downloads\avidemux_2.6.3_32bits-skidajmo.com.exe
- 2013-07-08 09:05:22 683FDD3D773C58B262DC07CD0C6CE938 10285040 ----a-w- C:\Documents and Settings\Pedja\My Documents\Downloads\mbam-setup-1.75.0.1300.exe
- 2013-07-07 14:54:06 CE30B5DEBF4674833133652A39414FB7 403968 ----a-w- C:\Program Files\MCShield\MCShieldDS.exe
- 2013-07-07 14:49:28 A5F9D2319853D4168AD5D1650D5C83CD 607744 ----a-w- C:\Program Files\MCShield\MCShieldRTM.exe
- 2013-07-07 14:49:28 5C8694D0B8C7D1AA82FE9820CF271AB9 726016 ----a-w- C:\Program Files\MCShield\MCShieldCC.exe
- === C: other files ==
- 2013-07-09 08:15:40 D3191AD18930121834D0BF89A7AB9568 1389145 ----a-w- C:\Program Files\AVG\AVG2013\banners\banners.zip
- 2013-07-08 09:08:28 4470E3C1E0C3378E4CAB137893C12C3A 22856 ----a-w- C:\WINDOWS\system32\drivers\mbam.sys
- 2013-07-08 09:00:48 71A5C0195D65D431B90BC095A4E20222 171094 ----a-w- C:\Documents and Settings\Pedja\Application Data\Mozilla\Firefox\Profiles\spy0hywg.default\extensions\[email protected]
- 2013-07-07 08:36:20 803B5A01199430D4965C68A6BC53C92F 1298 ----a-w- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Quarantine\BurstMedia-0000.zip
- 2013-07-07 08:36:20 1FF7411E794E792FBB5A4C31B125C76F 1303 ----a-w- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Quarantine\DoubleClick-0000.zip
- ==== Startup Registry Enabled ======================
- [HKEY_USERS\S-1-5-21-839522115-1417001333-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Run]
- "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe"
- "Google Update"="C:\Documents and Settings\Pedja\Local Settings\Application Data\Google\Update\GoogleUpdate.exe /c"
- "Facebook Update"="C:\Documents and Settings\Pedja\Local Settings\Application Data\Facebook\Update\FacebookUpdate.exe /c /nocrashserver"
- "Skype"="C:\Program Files\Skype\Phone\Skype.exe /minimized /regrun"
- "MCShield Monitor"="C:\Program Files\MCShield\MCShieldRTM.exe"
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
- "nwiz"="C:\Program Files\NVIDIA Corporation\nView\nwiz.exe /install"
- "NvMediaCenter"="RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit"
- "NvCplDaemon"="RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup"
- "AVG_UI"="C:\Program Files\AVG\AVG2013\avgui.exe /TRAYONLY"
- "NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe"
- "RTHDCPL"="RTHDCPL.EXE"
- "Adobe ARM"="C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
- [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
- "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe"
- "Google Update"="C:\Documents and Settings\Pedja\Local Settings\Application Data\Google\Update\GoogleUpdate.exe /c"
- "Facebook Update"="C:\Documents and Settings\Pedja\Local Settings\Application Data\Facebook\Update\FacebookUpdate.exe /c /nocrashserver"
- "Skype"="C:\Program Files\Skype\Phone\Skype.exe /minimized /regrun"
- "MCShield Monitor"="C:\Program Files\MCShield\MCShieldRTM.exe"
- ==== Task Scheduler Jobs ======================
- C:\WINDOWS\tasks\Adobe Flash Player Updater.job --a------ C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe [06/18/2013 06:52 PM]
- C:\WINDOWS\tasks\FacebookUpdateTaskUserS-1-5-21-839522115-1417001333-725345543-1003Core.job --a------ C:\Documents and Settings\Pedja\Local Settings\Application Data\Facebook\Update\FacebookUpdate.exe [05/11/2013 03:18 PM]
- C:\WINDOWS\tasks\FacebookUpdateTaskUserS-1-5-21-839522115-1417001333-725345543-1003UA.job --a------ C:\Documents and Settings\Pedja\Local Settings\Application Data\Facebook\Update\FacebookUpdate.exe [05/11/2013 03:18 PM]
- C:\WINDOWS\tasks\GlaryInitialize 3.job --a------ C:\Program Files\Glary Utilities 3\Initialize.exe [07/06/2013 04:31 PM]
- C:\WINDOWS\tasks\GlaryInitialize.job --a------ :C:\Program Files\Glary Utilities\initialize.exe []
- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-839522115-1417001333-725345543-1003Core.job --a------ C:\Documents and Settings\Pedja\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [05/02/2013 10:25 PM]
- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-839522115-1417001333-725345543-1003UA.job --a------ [Undetermined Task]
- ==== Firefox Extensions ======================
- ProfilePath: C:\Documents and Settings\Pedja\Application Data\Mozilla\Firefox\Profiles\spy0hywg.default
- - Goo.gl Information - %ProfilePath%\extensions\[email protected]
- ==== Firefox Plugins ======================
- Profilepath: C:\Documents and Settings\Pedja\Application Data\Mozilla\Firefox\Profiles\spy0hywg.default
- 101700E93EB905992B518256CB441829 - C:\Documents and Settings\Pedja\Local Settings\Application Data\Google\Update\1.3.21.153\npGoogleUpdate3.dll - Google Update
- 3D76B5C0E02ECC19C1F5756E8FD97F72 - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_7_700_224.dll - Shockwave Flash
- 3A523765D795DB006C010B915C3A840A - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll - Adobe Acrobat
- 42A9B216A7A288512CE2F9A6BCCE96BC - C:\Program Files\Adobe\Reader 11.0\Reader\browser\nppdf32.dll - Adobe Acrobat
- 0B31B0F8FA99CFD009C8FBEA9E20C9DE - C:\Documents and Settings\Pedja\Local Settings\Application Data\Facebook\Video\Skype\npFacebookVideoCalling.dll - Facebook Video Calling Plugin
- 509335C61594A73AB32E1B572AEE61A8 - C:\Program Files\Windows Media Player\npdrmv2.dll - Microsoft® DRM
- 969983AB670681301F7A91DC4AD3D1F1 - C:\Program Files\Windows Media Player\npdsplay.dll - Windows Media Player Plug-in Dynamic Link Library
- 6D8F27BEE96589722EE485324FDD88D9 - C:\Program Files\Windows Media Player\npwmsdrm.dll - Microsoft® DRM
- D27CE4EAF23411589A33E0C99D176311 - C:\Program Files\Adobe\Acrobat 5.0\Reader\Browser\nppdf32.dll - Adobe Acrobat
- ==== Chrome Look ======================
- HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
- hbcennhacfaagdopikcegfcobcadeocj - C:\Program Files\Common Files\Spigot\GC\saebay_1.0.crx[]
- icdlfehblmklkikfigmjhbmmpmkmpooj - C:\Program Files\Common Files\Spigot\GC\errorassistant_1.1.crx[]
- mhkaekfpcppmmioggniknbnbdbcigpkk - C:\Program Files\Common Files\Spigot\GC\coupons_2.4.crx[]
- pfndaklgolladniicklehhancnlgocpp - C:\Program Files\Common Files\Spigot\GC\saamazon_1.0.crx[]
- ==== Set IE to Default ======================
- Old Values:
- [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
- "Start Page"="http://www.google.com"
- [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl]
- [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
- No DefaultScope Set For HKCU
- New Values:
- [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
- "Start Page"="http://www.google.com"
- [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl]
- "(Default)"="http://search.msn.com/results.asp?q=%s"
- [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
- "DefaultScope"="{6A1806CD-94D4-4689-BA73-E35EA1EA9990}"
- ==== All HKCU SearchScopes ======================
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
- {0633EE93-D776-472f-A0FF-E1416B8B2E3A} @ieframe.dll,-12512 Url="http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC"
- {6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}"
- ==== Deleting Registry Keys ======================
- HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\hbcennhacfaagdopikcegfcobcadeocj deleted successfully
- HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\icdlfehblmklkikfigmjhbmmpmkmpooj deleted successfully
- HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\mhkaekfpcppmmioggniknbnbdbcigpkk deleted successfully
- HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\pfndaklgolladniicklehhancnlgocpp deleted successfully
- ==== Empty IE Cache ======================
- C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5 emptied successfully
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5 emptied successfully
- C:\Documents and Settings\Pedja\Local Settings\Temp\acrord32_sbx\Temporary Internet Files\Content.IE5 emptied successfully
- C:\Documents and Settings\Pedja\Local Settings\Temp\Temporary Internet Files\Content.IE5 emptied successfully
- C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5 emptied successfully
- C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot
- C:\Documents and Settings\Pedja\Local Settings\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot
- ==== Empty FireFox Cache ======================
- C:\Documents and Settings\Pedja\Local Settings\Application Data\Mozilla\Firefox\Profiles\spy0hywg.default\Cache emptied successfully
- ==== Empty Chrome Cache ======================
- C:\Documents and Settings\Pedja\Local Settings\Application Data\Google\Chrome\User Data\Default\Cache emptied successfully
- ==== Empty All Flash Cache ======================
- Flash Cache Emptied Successfully
- ==== Empty All Java Cache ======================
- No Java Cache Found
- ==== After Reboot ======================
- ==== Empty Temp Folders ======================
- C:\WINDOWS\Temp successfully emptied
- C:\DOCUME~1\Pedja\LOCALS~1\Temp successfully emptied
- ==== Empty Recycle Bin ======================
- C:\RECYCLER successfully emptied
- ==== Deleting Files / Folders ======================
- "C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat" not found
- "C:\Documents and Settings\Pedja\Local Settings\Temporary Internet Files\Content.IE5\index.dat" not found
- ==== EOF on Sat 07/13/2013 at 18:18:57.37 ======================
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement