Cant remove Priicechop

JMJ

New Member
Thread author
Aug 7, 2014
2
I have made a scan with Zoek and her is the results:


Zoek.exe v5.0.0.0 Updated 07-August-2014
Tool run by John on 07-08-2014 at 15:34:38,79.
Microsoft Windows 8 Pro 6.2.9200 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\John\Downloads\zoek.exe [Scan all users] [Script inserted]

==== System Restore Info ======================

07-08-2014 15:36:34 Zoek.exe System Restore Point Created Succesfully.

==== Installed Programs ======================

æTorrent
7-Zip 9.20
Adobe Flash Player 14 Plugin
Any Video Converter 5.0.6
Apple-programunderst›ttelse
Apple Mobile Device Support
Apple Software Update
Assassins Creed IV Black Flag
AuthenTec WinBio FingerPrint Software 64-bit
AVG 2014
AVG PC TuneUp 2014
AVG PC TuneUp 2014 (en-GB)
Bonjour
calibre
Connectify
Custom
CyberLink LabelPrint 2.5
CyberLink Media Suite 10
CyberLink Media Suite Essentials
CyberLink Power2Go 8
CyberLink PowerDirector 10
CyberLink PowerDVD 10
D3DX10
DAEMON Tools Pro
Dell Backup and Recovery
Dell Data Protection | Access
Dell Digital Delivery
Dell Feature Enhancement Pack
Dell Touchpad
DellAccess
Driver Tool
DriverTuner 3.1.0.1
Dropbox
DVDFab 9.1.2.2 (08/01/2014)
Easy2Convert DDS to BMP 1.3
EMBASSY Client Core
ERAS Connector
Farming Simulator 2013
Fjern kun CopyTrans Suite
Fraps
FULL-DISKfighter
Gemalto
GemCCIDWin8
GIANTS Editor 5.0.1
GIANTS Editor 5.0.3 64-bit
Google Drive
Google Update Helper
HandBrake 0.9.9.1
Harmony Browser Plug-in
HP Deskjet 3050 J610 series - basissoftware til enheden
HP Deskjet 3050 J610 series - unders›gelse med henblik p† produktforbedringer
HP Deskjet 3050 J610 series Hj‘lp
HP Photo Creations
HP Support Solutions Framework
HP Update
iCloud
ImgBurn
Intel(R) Control Center
Intel(R) Management Engine Components
Intel(R) Network Connections 17.3.57.00
Intel(R) PRO/Wireless Driver
Intel(R) Processor Graphics
Intel(R) Rapid Storage Technology
Intel(R) WiDi
Intel© PROSet/Wireless Software
Intel© PROSet/Wireless WiFi Software
Intel© Trusted Connect Service Client
iTunes
Java 7 Update 65
Java Auto Updater
LibreOffice 4.1.5.3
LogMeIn
Microsoft App Update for microsoft.windowscommunicationsapps_17.0.1119.516_x64__8wekyb3d8bbwe (x64)
Microsoft Application Error Reporting
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
MKVToolNix 6.7.0 [20140102-565]
Mobilt Bredb†nd
Movie Maker
Mozilla Maintenance Service
MSVCRT
MSVCRT110
MSVCRT110_amd64
Nightly 34.0a1 (x86 en-US)
Notepad++
novaPDF Standard Desktop 7.7 printer
O2Micro OZ776 SCR Driver
PBA Driver
Photo Common
Photo Gallery
Plantronics CSR Driver (64-bit)
Plantronics CsrDfu Installer
Plantronics HidDfu Installer
Plantronics MyHeadset Updater
Plantronics MyHeadset Updater Device Handlers (32-bit)
Plantronics MyHeadset Updater DFU Handlers (32-bit)
Plantronics MyHeadset Updater Install Check
Plantronics MyHeadset Updater MLS
Plantronics MyHeadset Updater Runtime
Plantronics MyHeadset Updater Startup
Preboot Manager
Private Information Manager
QuickTime 7
SI TSS
SkypeT 6.11
Smart Menu
SPBA (WBF) 5.9
ST Microelectronics 3 Axis Digital Accelerometer Solution
SubtitleCreator
Switch Sound File Converter
TeamViewer 8
TManager 5.4.6
TManager 5.6.5
Tombraider
toolkit32for64bit
Trusted Drive Manager
Visual Studio 2012 x64 Redistributables
Visual Studio 2012 x86 Redistributables
VLC media player 2.0.8
Wave Crypto Runtime 2.0.9.0 x64
Wave Crypto Runtime 2.0.9.0 x86
Wave Infrastructure Installer
Wave Support Software Installer
WIDCOMM Bluetooth Software
Windows-driverpakke - Cambridge Silicon Radio (CSRBC) USB (10/26/2012 2.4.0.0)
Windows Live Communications Platform
Windows Live Essentials
Windows Live Installer
Windows Live Photo Common
Windows Live PIMT Platform
Windows Live SOXE
Windows Live SOXE Definitions
Windows Live UX Platform
Windows Live UX Platform Language Pack
WinRAR 4.20 (64-bit)
Wondershare PDF Editor(Build 3.1.0)
XMedia Recode version 3.1.7.6

==== Running Processes ======================

C:\Program Files (x86)\Security Innovation\SI TSS\bin\tcsd_win32.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe
C:\Program Files (x86)\Hp\Common\HPSupportSolutionsFrameworkService.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
C:\Program Files (x86)\Mobile Broadband\AssistantServices.exe
C:\Program Files (x86)\Connectify\ConnectifyService.exe
C:\Program Files (x86)\Connectify\ConnectifyD.exe
C:\Program Files (x86)\DAEMON Tools Pro\DTShellHlp.exe
C:\Windows\TEMP\Smart Menu_v4.6.exe
C:\Program Files\Smart Menu\vcredist_x64.exe
C:\Program Files\Smart Menu\vcredist_x64.exe
C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe
C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
C:\Program Files (x86)\Google\Drive\googledrivesync.exe
C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe
C:\Program Files (x86)\Mobile Broadband\UIExec.exe
C:\Users\John\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Program Files (x86)\Fighters\Tray\FightersTray.exe
C:\Program Files (x86)\AVG\AVG2014\avgui.exe
C:\Windows\SysWOW64\ctfmon.exe
C:\Program Files (x86)\Google\Drive\googledrivesync.exe
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Windows\SysWOW64\RunDll32.exe
C:\Program Files\WIDCOMM\Bluetooth Software\Bluetooth Headset Helper.exe
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
C:\Program Files (x86)\Dell Backup and Recovery\SftService.exe
C:\Program Files (x86)\Dell Backup and Recovery\Components\DBRUpdate\DBRUpd.exe
C:\Program Files (x86)\Dell Backup and Recovery\TOASTER.EXE
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
C:\Users\John\AppData\Roaming\uTorrent\uTorrent.exe
C:\Program Files (x86)\Nightly\firefox.exe
C:\Program Files (x86)\Nightly\plugin-container.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_14_0_0_145.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_14_0_0_145.exe
C:\Windows\syswow64\wwahost.exe
C:\Users\John\Downloads\zoek.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\SysWOW64\cmd.exe

==== Services (whitelist) ======================
Powered by E Dev

R2 - [Apple Mobile Device] - Apple Mobile Device - "C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe"
R2 - [avgwd] - AVG WatchDog - "C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe"
R2 - [BcmBtRSupport] - Bluetooth Radio Control Service - C:\Windows\system32\BtwRSupportService.exe
R2 - [Bonjour Service] - Bonjour tjeneste - "C:\Program Files\Bonjour\mDNSResponder.exe"
R2 - [btwdins] - Bluetooth Service - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
R2 - [Connectify] - Connectify - "C:\Program Files (x86)\Connectify\ConnectifyService.exe"
R2 - [DFEPService] - Dell Feature Enhancement Pack Service - "C:\Program Files\Dell\Feature Enhancement Pack\DFEPService.exe"
R2 - [EmbassyService] - EmbassyService - "C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\EMBASSY Client Core\EmbassyServer.exe"
R2 - [EvtEng] - Intel(R) PROSet/Wireless Event Log - "C:\Program Files\Intel\WiFi\bin\EvtEng.exe"
R2 - [HPSupportSolutionsFrameworkService] - HP Support Solutions Framework Service - "C:\Program Files (x86)\Hp\Common\HPSupportSolutionsFrameworkService.exe"
R2 - [IAStorDataMgrSvc] - Intel® Rapid lagringsteknologi - "C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe"
R2 - [Intel(R) Capability Licensing Service Interface] - Intel(R) Capability Licensing Service Interface - "C:\Program Files\Intel\iCLS Client\HeciServer.exe"
R2 - [jhi_service] - Intel(R) Dynamic Application Loader Host Interface Service - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
R2 - [LMIGuardianSvc] - LMIGuardianSvc - "C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe"
R2 - [LMIMaint] - LogMeIn Maintenance Service - "C:\Program Files (x86)\LogMeIn\x64\RaMaint.exe"
R2 - [LMS] - Intel(R) Management and Security Application Local Management Service - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
R2 - [LogMeIn] - LogMeIn - "C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe"
R2 - [PbaDrvSvc_x64] - Dell PBA x64 Service - "C:\Program Files\Dell\Dell Data Protection\Access\Advanced\hapi64\pbadrvsvc.exe"
R2 - [RegSrvc] - Intel(R) PROSet/Wireless Registry Service - "C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe"
R2 - [RichVideo] - Cyberlink RichVideo Service(CRVS) - "C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe"
R2 - [SftService] - SoftThinks Agent Service - "C:\Program Files (x86)\Dell Backup and Recovery\SftService.exe"
R2 - [STacSV] - Audio Service - C:\Program Files\IDT\WDM\STacSV64.exe
R2 - [tcsd_win32.exe] - SI TSS v1.2.1.41 TCS - "C:\Program Files (x86)\Security Innovation\SI TSS\bin\tcsd_win32.exe"
R2 - [TdmService] - TdmService - "C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Trusted Drive Manager\TdmService.exe"
R2 - [TeamViewer8] - TeamViewer 8 - "C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe"
R2 - [TuneUp.UtilitiesSvc] - AVG PC TuneUp Service - "C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe"
R2 - [UNS] - Intel(R) Management and Security Application User Notification Service - "C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"
R2 - [Wave Authentication Manager Service] - Wave Authentication Manager Service - C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Authentication Manager\WaveAMService.exe
R2 - [WSearch] - Windows Search - C:\Windows\system32\SearchIndexer.exe /Embedding
R2 - [WvPCR] - WvPCR - "C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Common\WvPCR.exe"
R2 - [ZeroConfigService] - Intel(R) PROSet/Wireless Zero Configuration Service - "C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe"
R3 - [VSS] - Øjebliksbillede af diskenhed - C:\Windows\system32\vssvc.exe
S2 - [AVGIDSAgent] - AVGIDSAgent - "C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe"
S2 - [DellDigitalDelivery] - Dell Digital Delivery Service - "c:\Program Files (x86)\Dell Digital Delivery\DeliveryService.exe"
S2 - [gupdate] - Google Update Tjeneste (gupdate) - "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /svc
S2 - [SkypeUpdate] - Skype Updater - "C:\Program Files (x86)\Skype\Updater\Updater.exe"
S2 - [sppsvc] - Softwarebeskyttelse - C:\Windows\system32\sppsvc.exe
S2 - [Suite Service] - Suite Service - C:\Program Files (x86)\Fighters\FighterSuiteService.exe
S3 - [AdobeFlashPlayerUpdateSvc] - Adobe Flash Player Update Service - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
S3 - [ALG] - Gatewaytjeneste til programlaget - C:\Windows\System32\alg.exe
S3 - [Common Toolkit 2] - Common Toolkit 2 - "C:\Program Files (x86)\Common Files\Common Toolkit Suite\Tools\x64\CommonToolkit2.exe"
S3 - [COMSysApp] - COM+-systemprogram - C:\Windows\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235}
S3 - [cphs] - Intel(R) Content Protection HECI Service - C:\Windows\SysWow64\IntelCpHeciSvc.exe
S3 - [Fax] - Fax - C:\Windows\system32\fxssvc.exe
S3 - [FontCache3.0.0.0] - Windows Presentation Foundation Font Cache 3.0.0.0 - C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
S3 - [gupdatem] - Google Update Tjeneste (gupdatem) - "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /medsvc
S3 - [iPod Service] - iPod-tjeneste - "C:\Program Files\iPod\bin\iPodService.exe"
S3 - [MozillaMaintenance] - Mozilla Maintenance Service - "C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe"
S3 - [MSDTC] - DTC (Distributed Transaction Coordinator) - C:\Windows\System32\msdtc.exe
S3 - [msiserver] - Windows Installer - C:\Windows\system32\msiexec.exe /V
S3 - [MyWiFiDHCPDNS] - Wireless PAN DHCP Server - "C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe"
S3 - [PerfHost] - Performance Counter DLL Host - C:\Windows\SysWow64\perfhost.exe
S3 - [RpcLocator] - RPS-søger (Remote Procedure Call) - C:\Windows\system32\locator.exe
S3 - [SecureStorageService] - SecureStorageService - "C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Secure Storage Manager\SecureStorageService.exe"
S3 - [SNMPTRAP] - SNMP Trap - C:\Windows\System32\snmptrap.exe
S3 - [TrustedInstaller] - Installationsprogram til Windows-moduler - C:\Windows\servicing\TrustedInstaller.exe
S3 - [vds] - Virtuel disk - C:\Windows\System32\vds.exe
S3 - [wbengine] - Tjeneste til sikkerhedskopiering på blokniveau - "C:\Windows\system32\wbengine.exe"
S3 - [WinDefend] - Tjenesten Windows Defender - "C:\Program Files\Windows Defender\MsMpEng.exe"
S3 - [wmiApSrv] - WMI-ydelseskort - C:\Windows\system32\wbem\WmiApSrv.exe
S3 - [WMPNetworkSvc] - Windows Media Player Network Sharing Service - "C:\Program Files\Windows Media Player\wmpnetwk.exe"

==== Folders Found ======================


==== Files Found ======================


==== Folders Found In C:\Windows\System32\GroupPolicy ======================

2013-03-29 14:42:16 d-----w- C:\Windows\System32\GroupPolicy\Machine
2013-03-29 14:42:16 d-----w- C:\Windows\System32\GroupPolicy\User

==== Files Found In C:\Windows\System32\GroupPolicy ======================

2014-08-04 09:38:32 165 ----a-w- B81A8AAC7A26A27F7BAD531ACDD2A4D5 C:\Windows\System32\GroupPolicy\GPT.INI

==== Files Found In C:\Windows\SysWOW64\GroupPolicy ======================

2014-08-04 09:38:32 11 ----a-w- EC3584F3DB838942EC3669DB02DC908E C:\Windows\SysWOW64\GroupPolicy\gpt.ini

==== System Specs ======================

Windows: Windows Version 6.2 (Build 9200)
Memory (RAM): 8066 MB
CPU Info: Intel(R) Core(TM) i5-3320M CPU @ 2.60GHz
CPU Speed: 2594,9 MHz
Sound Card: Højttalere / Hovedtelefon (IDT |
Display Adapters: Intel(R) HD Graphics 4000 | Intel(R) HD Graphics 4000 | Intel(R) HD Graphics 4000 | LogMeIn Mirror Driver
Monitors: 1x; Standard PnP-skærm |
Screen Resolution: 1920 X 1080 - 32 bit
Network: Network Present
Network Adapters: Virtuelt kort til Microsoft Wi-Fi Direct | Bluetooth-enhed (Personal Area Network) | Intel(R) Centrino(R) Ultimate-N 6300 AGN | Intel(R) 82579LM Gigabit Network Connection
CD / DVD Drives: 3x (D: | E: | F: | ) D: TSSTcorpDVD+-RW SN-208DN | E: CyberLnkVirtualDrive | F: DTSOFT BDROM
Ports: COM3 LPT1
Mouse: 16 Button Wheel Mouse Present
Hard Disks: C: 289,3GB | G: 931,5GB | W: 500,0MB | X: 7,7GB
Hard Disks - Free: C: 83,1GB | G: 360,7GB | W: 212,3MB | X: 286,8MB
Manufacturer *: Dell Inc.
BIOS Info: AT/AT COMPATIBLE | | DELL - 1072009
Time Zone: Rom, normaltid
Motherboard *: Dell Inc. 0T5KR3
Country: Danmark
Language: DAN

==== System Specs (Software) ======================

Anti-Virus: AVG AntiVirus Free Edition 2014 On-access scanning disabled (Outdated)
Anti-Virus: Windows Defender On-access scanning disabled (Outdated)
Anti-Spyware: Windows Defender disabled (Outdated)
Anti-Spyware: AVG AntiVirus Free Edition 2014 disabled (Outdated)
Default Browser: Nightly 34.0a1
Internet Explorer Version: 10.0.9200.17028
Sun Java version: 1.7.0_65 (32-bit)
Flash Player version: 14.0.0.145

==== Files Recently Created / Modified ======================

====== C:\Windows ====
====== C:\Users\John\AppData\Local\Temp ====
2014-08-06 22:52:55 D8BE96BC224FB9A6034A01156A527271 43008 ----a-w- C:\Users\John\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpgozujr.dll
2014-08-06 22:35:17 FBB1E2E9A10C252D48CAE785CE2483AE 4321280 ----a-w- C:\Users\John\AppData\Local\Temp\Lang_en-GB.msi
2014-08-05 14:13:06 B6D89E1C9FF0E665414156FF5C7EA3DB 93184 ----a-w- C:\Users\John\AppData\Local\Temp\A6842E59.dll
====== Java Cache =====
2014-08-05 14:12:53 8D14D3FF6A1289EF36C41DD2133973B0 52561 ----a-w- C:\Users\John\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\28\21b6f89c-78d57056
2014-08-05 14:12:50 54244D1A2E43238D7F9AA2B6A8CB3698 408 ----a-w- C:\Users\John\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\32\5dd06fe0-94aa4fcd1964ef42d8ca13984086447b1f54b2543b9343e51dc2267eb21e5cca-6.0.lap
2014-08-05 14:12:54 151A988D0617F9444B66BD282C3776DA 16896 ----a-w- C:\Users\John\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\38\2fb889a6-460cab7a
====== C:\Windows\SysWOW64 =====
2014-08-06 22:36:55 244568416B6D59F39ADE671DD82B2659 25400 ----a-w- C:\Windows\SysWOW64\authuitu.dll
====== C:\Windows\SysWOW64\drivers =====
====== C:\Windows\Sysnative =====
2014-08-06 22:47:46 810785DACC57FC89B15FDC423554CEB7 346832 ----a-w- C:\Windows\Sysnative\FNTCACHE.DAT
2014-08-06 22:36:58 62507E599AE37E91C1BEED8DE35E5236 29496 ----a-w- C:\Windows\Sysnative\authuitu.dll
2014-08-06 22:36:58 40D653A452721F45F5FDCDF7C6A67569 40248 ----a-w- C:\Windows\Sysnative\TURegOpt.exe
====== C:\Windows\Sysnative\drivers =====
2014-07-10 10:41:06 3865C4E388B31940C8BB9F73D9738E93 71168 ----a-w- C:\Windows\Sysnative\drivers\hdaudbus.sys
2014-07-10 10:38:03 FE7FB9612D354EB41DF4F0FF5D6FB259 576512 ----a-w- C:\Windows\Sysnative\drivers\afd.sys
====== C:\Windows\Tasks ======
2014-08-06 22:52:28 3C0507EB01C3D078FA1A57C8EB921486 5014 ----a-w- C:\Windows\Sysnative\Tasks\WSCEAA
2014-08-06 22:44:02 997E4EE08F75AB3D2490882015030E0B 3704 ----a-w- C:\Windows\Sysnative\Tasks\Java Update Scheduler
2014-08-06 22:43:59 6DDF065623D9EE2C73E9D35E84ACDEC0 3676 ----a-w- C:\Windows\Sysnative\Tasks\HP online update program
====== C:\Windows\Temp ======
======= C:\Program Files =====
2014-07-12 09:32:49 -------- d-----w- C:\Program Files\iPod
2014-07-12 09:32:48 -------- d-----w- C:\Program Files\iTunes
======= C:\PROGRA~2 =====
2014-08-06 16:42:53 -------- d-----w- C:\PROGRA~2\AVG
2014-08-04 09:38:53 -------- d-----w- C:\PROGRA~2\PC_Booster
2014-08-04 09:38:39 -------- d-----w- C:\PROGRA~2\pricecehop
2014-07-18 02:08:58 -------- d-----w- C:\PROGRA~2\COMMON~1\Java
2014-07-12 09:32:48 -------- d-----w- C:\PROGRA~2\iTunes
======= C: =====
====== C:\Users\John\AppData\Roaming ======
2014-08-06 22:36:41 -------- d-----w- C:\Users\John\AppData\Roaming\AVG
2014-08-06 22:36:41 -------- d-----w- C:\Users\John\AppData\Local\AVG
2014-08-06 16:45:14 -------- d-----w- C:\Users\John\AppData\Roaming\AVG2014
2014-08-06 16:44:45 -------- d-----w- C:\Windows\sysWoW64\config\systemprofile\AppData\Roaming\AVG2014
2014-08-06 16:44:27 -------- d-----w- C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Avg2014
2014-08-06 16:44:27 -------- d-----w- C:\Users\John\AppData\Roaming\TuneUp Software
2014-08-06 16:42:55 -------- d-----w- C:\Windows\SysNative\config\systemprofile\AppData\Local\Avg2014
2014-08-06 16:40:15 -------- d-----w- C:\Users\John\AppData\Local\Avg2014
2014-08-04 09:38:40 -------- d-----w- C:\Users\John\AppData\Locallow\{6B237D8A-CD2F-9C10-3F99-B37BD4099603}
2014-08-04 09:38:32 -------- d-----w- C:\Users\John\AppData\Local\Torch
2014-08-04 09:38:32 -------- d-----w- C:\Users\John\AppData\Local\Comodo
2014-08-04 09:38:32 -------- d-----w- C:\Users\John\AppData\Local\Chromatic Browser
2014-08-04 09:38:32 -------- d-----w- C:\Users\GST~1\AppData\Local\Torch
2014-08-04 09:38:32 -------- d-----w- C:\Users\GST~1\AppData\Local\Comodo
2014-08-04 09:38:32 -------- d-----w- C:\Users\GST~1\AppData\Local\Chromatic Browser
2014-08-04 09:38:32 -------- d-----w- C:\Users\Administrator\AppData\Local\Torch
2014-08-04 09:38:32 -------- d-----w- C:\Users\Administrator\AppData\Local\Comodo
2014-08-04 09:38:32 -------- d-----w- C:\Users\Administrator\AppData\Local\Chromatic Browser
2014-08-04 09:38:31 -------- d-----w- C:\Users\GST~1\AppData\Local\Google
2014-08-04 09:38:31 -------- d-----w- C:\Users\Administrator\AppData\Local\Google
====== C:\Users\John ======
2014-08-06 22:34:37 -------- d-sh--w- C:\ProgramData\{01BD4FC9-2F86-4706-A62E-774BB7E9D308}
2014-08-06 22:34:37 -------- d-----w- C:\ProgramData\AVG
2014-08-06 16:44:27 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
2014-08-06 16:43:21 -------- d-----w- C:\ProgramData\AVG2014
2014-08-06 16:40:15 -------- d--h--w- C:\ProgramData\Common Files
2014-08-04 09:38:59 -------- d-----w- C:\ProgramData\Trusted Publisher
2014-08-04 09:38:41 -------- d-----w- C:\ProgramData\pricecehop
2014-08-04 09:38:33 -------- d-----w- C:\ProgramData\b94ca9efdff4b7d4
2014-08-04 09:38:31 -------- d-----w- C:\Users\GST~1\AppData
2014-08-04 09:38:31 -------- d-----w- C:\Users\Administrator\AppData
2014-07-18 02:08:54 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-07-12 09:33:42 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2014-07-12 09:32:48 -------- d-----w- C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69

====== C: exe-files ==
2014-08-06 00:27:56 EC75D74F2921CA818DB65F9F4E2DF811 544 ----a-w- C:\$Recycle.Bin\S-1-5-21-3022273834-2690704146-2914445167-1001\$I1KNU3W.exe
2014-08-06 00:27:56 E3CEE6C3EC33CDC767F76BC1E5DC6FAB 544 ----a-w- C:\$Recycle.Bin\S-1-5-21-3022273834-2690704146-2914445167-1001\$I8WGXGW.exe
2014-08-06 00:27:56 A5B4C21A4192909CBCB85880BF63D7A4 544 ----a-w- C:\$Recycle.Bin\S-1-5-21-3022273834-2690704146-2914445167-1001\$IQ9TGKL.exe
2014-08-06 00:27:56 9A87D94FF9F13825DECD85BEBD1EDB87 544 ----a-w- C:\$Recycle.Bin\S-1-5-21-3022273834-2690704146-2914445167-1001\$IDNXL4G.exe
2014-08-06 00:27:56 8B072B17B18E4ED325BFFD098B3D9418 544 ----a-w- C:\$Recycle.Bin\S-1-5-21-3022273834-2690704146-2914445167-1001\$IM4VNGD.exe
2014-08-06 00:27:56 6CE391CB1A268B46AE5B768EA9CD7711 544 ----a-w- C:\$Recycle.Bin\S-1-5-21-3022273834-2690704146-2914445167-1001\$IDQ4FVF.exe
2014-08-06 00:27:56 4F36D4A1082FD4239AE223D62DDD1AEC 544 ----a-w- C:\$Recycle.Bin\S-1-5-21-3022273834-2690704146-2914445167-1001\$I342FV9.exe
2014-08-06 00:27:56 4E72C3966FA2ED2FC163B91A7E53A8D6 544 ----a-w- C:\$Recycle.Bin\S-1-5-21-3022273834-2690704146-2914445167-1001\$IRDUHVV.exe
2014-08-06 00:27:56 33C3F424371004C16230B9ADE5C4B15E 544 ----a-w- C:\$Recycle.Bin\S-1-5-21-3022273834-2690704146-2914445167-1001\$I78WBEL.exe
2014-08-06 00:27:56 0702C513610FF2EDFA57757C4FBC0A84 544 ----a-w- C:\$Recycle.Bin\S-1-5-21-3022273834-2690704146-2914445167-1001\$IZ4OIA6.exe
2014-08-04 12:28:47 71A88D7A2B400A8296B848FDB63A9004 80517304 ----a-w- C:\$Recycle.Bin\S-1-5-21-3022273834-2690704146-2914445167-1001\$R1KNU3W.exe
=== C: other files ==
2014-08-06 22:59:35 AABDE142299853C2B551B54D97720D29 967685 ----a-w- C:\Users\John\AppData\Roaming\Mozilla\Firefox\Profiles\p9gwgkom.default-1403054086440\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
2014-08-06 22:51:39 82F5C942549405F61A8808D0EA0FA9E2 25575 ----a-w- C:\Users\John\AppData\Local\Temp\_MEI64282\resources\chrome_ext\apdfllckaahabafndbhieahigkjlhalf_live.crx
2014-08-06 15:40:04 CFA6BECE378315C3370183D1D561F871 912805 ----a-w- C:\Users\John\Documents\My Games\FarmingSimulator2013\mods\ZZZ_courseplay.zip
2014-08-06 15:09:40 D7CFF5B42200938BDECCDE02BAAE4C68 925755 ----a-w- C:\Users\John\Documents\My Games\Courseplay master\courseplay-master.zip
2014-08-06 00:27:56 D85CF3311DBA2F4CBA485A3C7456EF1C 544 ----a-w- C:\$Recycle.Bin\S-1-5-21-3022273834-2690704146-2914445167-1001\$IGOAE3O.zip
2014-08-05 12:06:37 4D83229B797CC4DB5B7EC498B8BAE865 328268474 ----a-w- C:\Users\John\Desktop\Ny mappe\PortaWestfalicaMap.zip
2014-08-05 09:25:01 4D83229B797CC4DB5B7EC498B8BAE865 328268474 ----a-w- C:\Users\John\Documents\My Games\FarmingSimulator2013\mods\PortaWestfalicaMap.zip
2014-08-05 09:21:46 447E2C04DB74569813A12AA5B6E7A510 331322002 ----a-w- C:\Users\John\Desktop\Ny mappe\Porta_WestfalicaMap_Entpacken.zip
2014-08-04 12:31:05 6B781C7503BBCE466C335F49E8C2C73E 174216986 ----a-w- C:\Users\John\Documents\My Games\FarmingSimulator2013\mods\NoName_Forst_Edition.zip
2014-08-04 12:29:31 3CF60999A286008CAF6A814363863EAC 80302112 ----a-w- C:\Users\John\Documents\My Games\FarmingSimulator2013\mods\Forestmapf2k.zip
2014-08-04 09:40:23 94ACC4203F8403C35A093A02B1548F3D 174262336 ----a-w- C:\Users\John\Documents\My Games\FarmingSimulator2013\mods\Talmap.zip
2014-08-04 09:35:23 EEED26F0B24D0CB669CCFEF13B5C05FF 197943 ----a-w- C:\Users\John\Documents\My Games\FarmingSimulator2013\mods\ZZZ_multiSprayer.zip

==== Startup Registry Enabled ======================

[HKEY_USERS\S-1-5-21-3022273834-2690704146-2914445167-1001\Software\Microsoft\Windows\CurrentVersion\Run]
"iCloudServices"="C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe"
"DAEMON Tools Pro Agent"="C:\Program Files (x86)\DAEMON Tools Pro\DTAgent.exe -autorun"
"GoogleDriveSync"="C:\Program Files (x86)\Google\Drive\googledrivesync.exe /autostart"
"Skype"="C:\Program Files (x86)\Skype\Phone\Skype.exe /minimized /regrun"
"uTorrent"="C:\Users\John\AppData\Roaming\uTorrent\uTorrent.exe /MINIMIZED"
"HP Deskjet 3050 J610 series (NET)"="C:\Program Files\HP\HP Deskjet 3050 J610 series\Bin\ScanToPCActivationApp.exe -deviceID CN0BG3B3MY05HX:NW -scfn HP Deskjet 3050 J610 series (NET) -AutoStart 1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMSS"="C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe"
"IAStorIcon"="C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe 60"
"RemoteControl10"="C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe"
"UIExec"="C:\Program Files (x86)\Mobile Broadband\UIExec.exe"
"APSDaemon"="C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
"DDS"="C:\Program Files (x86)\Digital Desktop Stickers\Digital Desktop Stickers.exe"
"QuickTime Task"="C:\Program Files (x86)\QuickTime\QTTask.exe -atboottime"
"HP Software Update"="C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe"
"Plantronics MyHeadset Updater"="C:\Program Files (x86)\Plantronics\MyHeadsetUpdater\MyHeadsetUpdater.exe"
"CommonToolkitTray"="C:\Program Files (x86)\Fighters\Tray\FightersTray.exe"
"iTunesHelper"="C:\Program Files (x86)\iTunes\iTunesHelper.exe"
"SunJavaUpdateSched"="C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
"AVG_UI"="C:\Program Files (x86)\AVG\AVG2014\avgui.exe /TRAYONLY"

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"iCloudServices"="C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe"
"DAEMON Tools Pro Agent"="C:\Program Files (x86)\DAEMON Tools Pro\DTAgent.exe -autorun"
"GoogleDriveSync"="C:\Program Files (x86)\Google\Drive\googledrivesync.exe /autostart"
"Skype"="C:\Program Files (x86)\Skype\Phone\Skype.exe /minimized /regrun"
"uTorrent"="C:\Users\John\AppData\Roaming\uTorrent\uTorrent.exe /MINIMIZED"
"HP Deskjet 3050 J610 series (NET)"="C:\Program Files\HP\HP Deskjet 3050 J610 series\Bin\ScanToPCActivationApp.exe -deviceID CN0BG3B3MY05HX:NW -scfn HP Deskjet 3050 J610 series (NET) -AutoStart 1"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="c:\\progra~2\\pc_boo~1\\assist~1.dll"

==== Startup Registry Enabled x64 ======================

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="C:\Program Files\DellTPad\Apoint.exe"
"TdmNotify"="C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Trusted Drive Manager\TdmNotify.exe"
"DFEPApplication"="C:\Program Files\Dell\Feature Enhancement Pack\DFEPApplication.exe"
"IgfxTray"="C:\Windows\system32\igfxtray.exe"
"HotKeysCmds"="C:\Windows\system32\hkcmd.exe"
"Persistence"="C:\Windows\system32\igfxpers.exe"
"LogMeIn GUI"="C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe"
"IntelPROSet"="C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe /tf Intel PROSet/Wireless"
"Connectify Dispatch"="C:\Program Files (x86)\Connectify\DispatchUI.exe"
"Connectify Hotspot"="C:\Program Files (x86)\Connectify\Connectify.exe"
"SysTrayApp"="C:\Program Files\IDT\WDM\sttray64.exe"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=" C:\\PROGRA~2\\PC_BOO~1\\ASSIST~2.DLL"

==== Startup Folders ======================

2013-03-29 14:46:46 1073 ----a-w- C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Smart Settings.lnk
2013-03-29 14:46:46 1073 ----a-w- C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Smart Settings.lnk
2013-07-11 12:55:11 1012 ----a-w- C:\Users\John\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
2013-05-26 15:06:53 1073 ----a-w- C:\Users\John\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Smart Settings.lnk
2013-11-11 16:19:48 1073 ----a-w- C:\Users\LogMeInRemoteUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Smart Settings.lnk
2013-03-29 14:37:30 834 ----a-w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk
2013-11-22 03:41:38 970 ----a-w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\TManager.lnk

==== Task Scheduler Jobs ======================

C:\Windows\tasks\Adobe Flash Player Updater.job --a-------- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [08-07-2014 20:09]
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job --a-------- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe []
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job --a-------- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe []

==== Other Scheduled Tasks ======================

"C:\Windows\SysNative\tasks\Adobe Flash Player Updater" [C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe]
"C:\Windows\SysNative\tasks\Apple Diagnostics" [C:\Program Files (x86)\Common Files\Apple\Internet Services\EReporter.exe]
"C:\Windows\SysNative\tasks\CLMLSvc_P2G8" [C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe]
"C:\Windows\SysNative\tasks\CLVDLauncher" [C:\Program Files (x86)\CyberLink\Power2Go8\CLVDLauncher.exe]
"C:\Windows\SysNative\tasks\DriverTuner Startup" ["C:\Program Files (x86)\DriverTuner\DriverTuner.exe"]
"C:\Windows\SysNative\tasks\GoogleUpdateTaskMachineCore" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe]
"C:\Windows\SysNative\tasks\GoogleUpdateTaskMachineUA" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe]
"C:\Windows\SysNative\tasks\HP online update program" [C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe]
"C:\Windows\SysNative\tasks\HPCustParticipation HP Deskjet 3050 J610 series" ["C:\Program Files\HP\HP Deskjet 3050 J610 series\Bin\HPCustPartic.exe"]
"C:\Windows\SysNative\tasks\Java Update Scheduler" [C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe]
"C:\Windows\SysNative\tasks\WSCEAA" [C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\RemoteManagement\WSCEAA.exe]
"C:\Windows\SysNative\tasks\Apple\AppleSoftwareUpdate" [C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe]

==== Firefox Extensions ======================

ProfilePath: C:\Users\John\AppData\Roaming\Mozilla\Firefox\Profiles\p9gwgkom.default-1403054086440
- priicechop - %ProfilePath%\extensions\ap2eyou8_pwo@dvcq-godbnd.net
- Adblock Plus - %ProfilePath%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi

==== Firefox Plugins ======================

Profilepath: C:\Users\John\AppData\Roaming\Mozilla\Firefox\Profiles\p9gwgkom.default-1403054086440
4390CCD3790F8D9C427C0C29590C62D7 - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_145.dll - Shockwave Flash


==== Chrome Look ======================

HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
omaonpoimgkmbllpdihbnmgphjoipdhf - C:\Program Files (x86)\Logitech\Harmony Remote Driver\harmony_chrome.crx[01-05-2012 22:45]

priicechop - Administrator\AppData\Local\Chromatic Browser\User Data\Default\Extensions\jeaelebblieamfneiojkilgbkcfnbkmc
priicechop - Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jeaelebblieamfneiojkilgbkcfnbkmc
priicechop - Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\jeaelebblieamfneiojkilgbkcfnbkmc
priicechop - Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jeaelebblieamfneiojkilgbkcfnbkmc
priicechop - Administrator\AppData\Local\Torch\User Data\Default\Extensions\jeaelebblieamfneiojkilgbkcfnbkmc
priicechop - John\AppData\Local\Chromatic Browser\User Data\Default\Extensions\jeaelebblieamfneiojkilgbkcfnbkmc
priicechop - John\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jeaelebblieamfneiojkilgbkcfnbkmc
priicechop - John\AppData\Local\Google\Chrome\User Data\Default\Extensions\jeaelebblieamfneiojkilgbkcfnbkmc
priicechop - John\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jeaelebblieamfneiojkilgbkcfnbkmc
priicechop - John\AppData\Local\Torch\User Data\Default\Extensions\jeaelebblieamfneiojkilgbkcfnbkmc
priicechop - LogMeInRemoteUser\AppData\Local\Chromatic Browser\User Data\Default\Extensions\jeaelebblieamfneiojkilgbkcfnbkmc
priicechop - LogMeInRemoteUser\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jeaelebblieamfneiojkilgbkcfnbkmc
priicechop - LogMeInRemoteUser\AppData\Local\Google\Chrome\User Data\Default\Extensions\jeaelebblieamfneiojkilgbkcfnbkmc
priicechop - LogMeInRemoteUser\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jeaelebblieamfneiojkilgbkcfnbkmc
priicechop - LogMeInRemoteUser\AppData\Local\Torch\User Data\Default\Extensions\jeaelebblieamfneiojkilgbkcfnbkmc
priicechop - GST~1\AppData\Local\Chromatic Browser\User Data\Default\Extensions\jeaelebblieamfneiojkilgbkcfnbkmc
priicechop - GST~1\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jeaelebblieamfneiojkilgbkcfnbkmc
priicechop - GST~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\jeaelebblieamfneiojkilgbkcfnbkmc
priicechop - GST~1\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jeaelebblieamfneiojkilgbkcfnbkmc
priicechop - GST~1\AppData\Local\Torch\User Data\Default\Extensions\jeaelebblieamfneiojkilgbkcfnbkmc

==== IE Start and Search Settings ======================

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://dell13-comm.msn.com"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{5940DB1A-F0D5-44B4-9C13-F043079979EE}"

==== All HKCU SearchScopes ======================

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
{5940DB1A-F0D5-44B4-9C13-F043079979EE} Unknown Url="Not_Found"

==== C:\zoek_backup content ======================

C:\zoek_backup (files=0 folders=0 0 bytes)

==== EOF on 07-08-2014 at 15:48:46,31 ======================
 

TwinHeadedEagle

Level 41
Verified
Mar 8, 2013
22,627
51a612a8b27e2-Zoek.png
Fix with ZOEK

icon_exclaim.gif
This fix was created for this user for use on that particular machine.
icon_exclaim.gif

icon_exclaim.gif
Running it on another one may cause damage and render the system unstable.
icon_exclaim.gif

Temporary disable your AntiVirus and AntiSpyware protection - instructions here.

  • Right-click on
    51a612a8b27e2-Zoek.png
    icon and select
    RunAsAdmin.jpg
    Run as Administrator to start the tool.
  • Wait patiently until the main console will appear, it may take a minute or two.
  • In the main box please paste in the following script:
    Code:
    createsrpoint;
    C:\Windows\System32\GroupPolicy\Machine;fs
    C:\Windows\System32\GroupPolicy\User;fs
    C:\Windows\System32\GroupPolicy\GPT.INI;f
    C:\Windows\SysWOW64\GroupPolicy\gpt.ini;f
    C:\PROGRA~2\PC_Booster;fs
    C:\PROGRA~2\pricecehop;fs
    C:\ProgramData\pricecehop;fs
    C:\ProgramData\b94ca9efdff4b7d4;fs
    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows];r
    "AppInit_DLLs"="";r
    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows];r64
    "AppInit_DLLs"="";r64
    priicechop;ff
    jeaelebblieamfneiojkilgbkcfnbkmc;chr
    autoclean;
    emptyalltemp;
    chrdefaults;
    ipconfig /flushdns;b
  • Make sure that Scan All Users option is checked.
  • Push Run Script and wait patiently. The scan may take a couple of minutes.
  • When the scan completes, a zoek-results logfile should open in notepad.
  • If a reboot is needed, it will be opened after it. You may also find it at your main drive (usually C:\ drive)

Post its content into your next reply.




adwcleaner_new.png
Fix with AdwCleaner

Please download AdwCleaner by Xplode and save the file to your desktop.

  • Right-click on
    adwcleaner_new.png
    icon and select
    RunAsAdmin.jpg
    Run as Administrator to start the tool.
  • Follow the prompts and click Scan.
  • When finished, please click Clean.
  • Upon completion, click Report. A log (AdwCleaner[S*].txt) will open.

Please include the contents of that file in your reply.
 

JMJ

New Member
Thread author
Aug 7, 2014
2
Here is the result of both and it looks like the problem is solved:

Zoek:

Zoek.exe v5.0.0.0 Updated 07-August-2014
Tool run by John on 07-08-2014 at 17:19:02,20.
Microsoft Windows 8 Pro 6.2.9200 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\John\Downloads\zoek.exe [Scan all users] [Script inserted]

==== Older Logs ======================

C:\zoek-results2014-08-07-134846.log 35939 bytes

==== System Restore Info ======================

07-08-2014 17:19:46 Zoek.exe System Restore Point Created Succesfully.

==== Deleting CLSID Registry Keys ======================


==== Deleting CLSID Registry Values ======================


==== Deleting Services ======================


==== FireFox Fix ======================

ProfilePath: C:\Users\John\AppData\Roaming\Mozilla\Firefox\Profiles\f9cfiwxn.default

user.js not found
---- FireFox user.js and prefs.js backups ----

prefs__1728_.backup

ProfilePath: C:\Users\John\AppData\Roaming\Mozilla\Firefox\Profiles\p9gwgkom.default-1403054086440

---- Lines extensions.xAinNJPpv removed from prefs.js ----
user_pref("extensions.xAinNJPpv.epoch", "1407501249");
user_pref("extensions.xAinNJPpv.url", "http://toolkitstyle.us/sync2/?q=hfZ...8wiGhGheDUojw9rdYEqda4rHYGpchIC7n0rjnEpda6rjs
---- FireFox user.js and prefs.js backups ----

user__1728_.backup
prefs__1728_.backup

ProfilePath: C:\Users\John\AppData\Roaming\Mozilla\MetroFirefox\Profiles\6goa6rfw.default

user.js not found
---- FireFox user.js and prefs.js backups ----

prefs__1728_.backup

==== Registry Fix Code ======================

Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=""

==== Registry Fix Code x64 ======================

Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=""

==== Batch Command(s) Run By Tool======================


==== Deleting Files \ Folders ======================

C:\windows\SysNative\GroupPolicy\Machine deleted
C:\windows\SysNative\GroupPolicy\User deleted
C:\PROGRA~2\PC_Booster deleted
C:\PROGRA~2\pricecehop deleted
C:\ProgramData\pricecehop deleted
C:\ProgramData\b94ca9efdff4b7d4 deleted
C:\PROGRA~3\{01BD4FC9-2F86-4706-A62E-774BB7E9D308} deleted
C:\Users\John\AppData\LocalLow\{6B237D8A-CD2F-9C10-3F99-B37BD4099603} deleted
C:\Users\John\AppData\Local\Packages\windows_ie_ac_001\AC\{6B237D8A-CD2F-9C10-3F99-B37BD4099603} deleted
C:\PROGRA~3\DAEMON Tools Pro deleted
C:\PROGRA~2\Wondershare deleted
C:\PROGRA~2\COMMON~1\Wondershare deleted
C:\Users\John\AppData\Roaming\Wondershare deleted
C:\PROGRA~3\Trusted Publisher deleted
C:\PROGRA~3\Package Cache deleted
C:\Users\John\AppData\Local\Wondershare deleted
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wondershare deleted
C:\Users\John\Downloads\avg_free_stb_all_2014_4744_cnet.exe deleted
C:\Users\John\Searches deleted
C:\Windows\Syswow64\RegistryHelperLM.ocx deleted
C:\Users\John\AppData\Roaming\Mozilla\Firefox\Profiles\p9gwgkom.default-1403054086440\extensions\ap2eyou8_pwo@dvcq-godbnd.net deleted
"C:\windows\SysNative\GroupPolicy\GPT.INI" deleted
"C:\Windows\SysWOW64\GroupPolicy\gpt.ini" deleted
"C:\Windows\Installer\1c8da26b.msi" deleted

==== Firefox Extensions ======================

ProfilePath: C:\Users\John\AppData\Roaming\Mozilla\Firefox\Profiles\p9gwgkom.default-1403054086440
- Adblock Plus - %ProfilePath%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi

==== Firefox Plugins ======================

Profilepath: C:\Users\John\AppData\Roaming\Mozilla\Firefox\Profiles\p9gwgkom.default-1403054086440
4390CCD3790F8D9C427C0C29590C62D7 - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_145.dll - Shockwave Flash


==== Chrome Look ======================

HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
omaonpoimgkmbllpdihbnmgphjoipdhf - C:\Program Files (x86)\Logitech\Harmony Remote Driver\harmony_chrome.crx[01-05-2012 22:45]

priicechop - Administrator\AppData\Local\Chromatic Browser\User Data\Default\Extensions\jeaelebblieamfneiojkilgbkcfnbkmc
priicechop - Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jeaelebblieamfneiojkilgbkcfnbkmc
priicechop - Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\jeaelebblieamfneiojkilgbkcfnbkmc
priicechop - Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jeaelebblieamfneiojkilgbkcfnbkmc
priicechop - Administrator\AppData\Local\Torch\User Data\Default\Extensions\jeaelebblieamfneiojkilgbkcfnbkmc
priicechop - John\AppData\Local\Chromatic Browser\User Data\Default\Extensions\jeaelebblieamfneiojkilgbkcfnbkmc
priicechop - John\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jeaelebblieamfneiojkilgbkcfnbkmc
priicechop - John\AppData\Local\Google\Chrome\User Data\Default\Extensions\jeaelebblieamfneiojkilgbkcfnbkmc
priicechop - John\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jeaelebblieamfneiojkilgbkcfnbkmc
priicechop - John\AppData\Local\Torch\User Data\Default\Extensions\jeaelebblieamfneiojkilgbkcfnbkmc
priicechop - LogMeInRemoteUser\AppData\Local\Chromatic Browser\User Data\Default\Extensions\jeaelebblieamfneiojkilgbkcfnbkmc
priicechop - LogMeInRemoteUser\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jeaelebblieamfneiojkilgbkcfnbkmc
priicechop - LogMeInRemoteUser\AppData\Local\Google\Chrome\User Data\Default\Extensions\jeaelebblieamfneiojkilgbkcfnbkmc
priicechop - LogMeInRemoteUser\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jeaelebblieamfneiojkilgbkcfnbkmc
priicechop - LogMeInRemoteUser\AppData\Local\Torch\User Data\Default\Extensions\jeaelebblieamfneiojkilgbkcfnbkmc
priicechop - GST~1\AppData\Local\Chromatic Browser\User Data\Default\Extensions\jeaelebblieamfneiojkilgbkcfnbkmc
priicechop - GST~1\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jeaelebblieamfneiojkilgbkcfnbkmc
priicechop - GST~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\jeaelebblieamfneiojkilgbkcfnbkmc
priicechop - GST~1\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jeaelebblieamfneiojkilgbkcfnbkmc
priicechop - GST~1\AppData\Local\Torch\User Data\Default\Extensions\jeaelebblieamfneiojkilgbkcfnbkmc

==== Chrome Fix ======================

C:\Users\Administrator\AppData\Local\Chromatic Browser\User Data\Default\Extensions\jeaelebblieamfneiojkilgbkcfnbkmc deleted successfully
C:\Users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jeaelebblieamfneiojkilgbkcfnbkmc deleted successfully
C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\jeaelebblieamfneiojkilgbkcfnbkmc deleted successfully
C:\Users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jeaelebblieamfneiojkilgbkcfnbkmc deleted successfully
C:\Users\Administrator\AppData\Local\Torch\User Data\Default\Extensions\jeaelebblieamfneiojkilgbkcfnbkmc deleted successfully
C:\Users\John\AppData\Local\Chromatic Browser\User Data\Default\Extensions\jeaelebblieamfneiojkilgbkcfnbkmc deleted successfully
C:\Users\John\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jeaelebblieamfneiojkilgbkcfnbkmc deleted successfully
C:\Users\John\AppData\Local\Google\Chrome\User Data\Default\Extensions\jeaelebblieamfneiojkilgbkcfnbkmc deleted successfully
C:\Users\John\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jeaelebblieamfneiojkilgbkcfnbkmc deleted successfully
C:\Users\John\AppData\Local\Torch\User Data\Default\Extensions\jeaelebblieamfneiojkilgbkcfnbkmc deleted successfully
C:\Users\LogMeInRemoteUser\AppData\Local\Chromatic Browser\User Data\Default\Extensions\jeaelebblieamfneiojkilgbkcfnbkmc deleted successfully
C:\Users\LogMeInRemoteUser\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jeaelebblieamfneiojkilgbkcfnbkmc deleted successfully
C:\Users\LogMeInRemoteUser\AppData\Local\Google\Chrome\User Data\Default\Extensions\jeaelebblieamfneiojkilgbkcfnbkmc deleted successfully
C:\Users\LogMeInRemoteUser\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jeaelebblieamfneiojkilgbkcfnbkmc deleted successfully
C:\Users\LogMeInRemoteUser\AppData\Local\Torch\User Data\Default\Extensions\jeaelebblieamfneiojkilgbkcfnbkmc deleted successfully
C:\Users\GST~1\AppData\Local\Chromatic Browser\User Data\Default\Extensions\jeaelebblieamfneiojkilgbkcfnbkmc deleted successfully
C:\Users\GST~1\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jeaelebblieamfneiojkilgbkcfnbkmc deleted successfully
C:\Users\GST~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\jeaelebblieamfneiojkilgbkcfnbkmc deleted successfully
C:\Users\GST~1\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jeaelebblieamfneiojkilgbkcfnbkmc deleted successfully
C:\Users\GST~1\AppData\Local\Torch\User Data\Default\Extensions\jeaelebblieamfneiojkilgbkcfnbkmc deleted successfully

==== Set IE to Default ======================

Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://dell13-comm.msn.com"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{5940DB1A-F0D5-44B4-9C13-F043079979EE}"

New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://dell13-comm.msn.com"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{012E1000-F331-11DB-8314-0800200C9A66}"

==== All HKCU SearchScopes ======================

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
{012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC"
{5940DB1A-F0D5-44B4-9C13-F043079979EE} Unknown Url="Not_Found"

==== Reset Google Chrome ======================

Nothing found to reset

==== Deleting CLSID Registry Keys ======================

HKEY_USERS\S-1-5-21-3022273834-2690704146-2914445167-1001\Software\Microsoft\Internet Explorer\SearchScopes\{5940DB1A-F0D5-44B4-9C13-F043079979EE} deleted successfully

==== Deleting CLSID Registry Values ======================


==== Deleting Registry Keys ======================

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\815699FA46F800445A2B703E64B521CA deleted successfully
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{9688ed96-eab4-4f16-ac76-52938afb0a05} deleted successfully
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{AF996518-8F64-4400-A5B2-07E3465B12AC} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\815699FA46F800445A2B703E64B521CA deleted successfully

==== Empty IE Cache ======================

C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\John\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\John\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

==== Empty FireFox Cache ======================

C:\Users\John\AppData\Local\Mozilla\Firefox\Profiles\f9cfiwxn.default\Cache emptied successfully
C:\Users\John\AppData\Local\Mozilla\Firefox\Profiles\p9gwgkom.default-1403054086440\Cache emptied successfully

==== Empty Chrome Cache ======================

No Chrome Cache found

==== Empty All Flash Cache ======================

Flash Cache Emptied Successfully

==== Empty All Java Cache ======================

Java Cache cleared successfully

==== C:\zoek_backup content ======================

C:\zoek_backup (files=565 folders=143 208576495 bytes)

==== Empty Temp Folders ======================

C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\John\AppData\Local\Temp will be emptied at reboot
C:\Users\LogMeInRemoteUser\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot

==== After Reboot ======================

==== Empty Temp Folders ======================

C:\Windows\Temp successfully emptied
C:\Users\John\AppData\Local\Temp successfully emptied

==== Empty Recycle Bin ======================

C:\$RECYCLE.BIN successfully emptied

==== EOF on 07-08-2014 at 17:37:11,81 ======================


AdWCleaner:

# AdwCleaner v3.303 - Report created 07/08/2014 at 17:41:43
# Updated 06/08/2014 by Xplode
# Operating System : Windows 8 Pro (64 bits)
# Username : John - DELL-BÆRBAR
# Running from : C:\Users\John\Downloads\AdwCleaner.exe
# Option : Clean

***** [ Services ] *****


***** [ Files / Folders ] *****

Folder Deleted : C:\ProgramData\NCH Software
Folder Deleted : C:\Program Files (x86)\NCH Software
Folder Deleted : C:\Users\Administrator\AppData\Local\Chromatic Browser
Folder Deleted : C:\Users\Administrator\AppData\Local\torch
Folder Deleted : C:\Users\Gæst\AppData\Local\Chromatic Browser
Folder Deleted : C:\Users\Gæst\AppData\Local\torch
Folder Deleted : C:\Users\John\AppData\Local\Chromatic Browser
Folder Deleted : C:\Users\John\AppData\Local\torch
Folder Deleted : C:\Users\John\AppData\Roaming\NCH Software
Folder Deleted : C:\Users\LogMeInRemoteUser\AppData\Local\Chromatic Browser
Folder Deleted : C:\Users\LogMeInRemoteUser\AppData\Local\torch
File Deleted : C:\Users\John\AppData\Roaming\Mozilla\Firefox\Profiles\p9gwgkom.default-1403054086440\user.js

***** [ Scheduled Tasks ] *****


***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Deleted : HKCU\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{00B11DA2-75ED-4364-ABA5-9A95B1F5E946}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{6E993643-8FBC-44FE-BC85-D318495C4D96}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{E2343056-CC08-46AC-B898-BFC7ACF4E755}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}
Key Deleted : HKCU\Software\RegisteredApplicationsEx
Key Deleted : HKCU\Software\Softonic
Key Deleted : HKLM\Software\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Key Deleted : HKLM\Software\{5F189DF5-2D05-472B-9091-84D9848AE48B}
Key Deleted : HKLM\Software\{77D46E27-0E41-4478-87A6-AABE6FBCF252}
Key Deleted : HKLM\Software\InstallIQ

***** [ Browsers ] *****

-\\ Internet Explorer v10.0.9200.17028


-\\ Mozilla Firefox v

[ File : C:\Users\John\AppData\Roaming\Mozilla\Firefox\Profiles\f9cfiwxn.default\prefs.js ]


[ File : C:\Users\John\AppData\Roaming\Mozilla\Firefox\Profiles\p9gwgkom.default-1403054086440\prefs.js ]


-\\ Google Chrome v

*************************

AdwCleaner[R0].txt - [2659 octets] - [07/08/2014 17:40:07]
AdwCleaner[S0].txt - [2447 octets] - [07/08/2014 17:41:43]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [2507 octets] ##########
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top