Hi,
This is the result of the scan:
Zoek.exe v5.0.0.0 Updated 04-May-2015
Tool run by Yannick on zo 17/05/2015 at 22:00:21,92.
Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Yannick\Downloads\zoek.exe [Scan all users] [Script inserted]
==== System Restore Info ======================
17/05/2015 22:04:10 Zoek.exe System Restore Point Created Successfully.
==== Empty Folders Check ======================
C:\PROGRA~2\Applian Technologies deleted successfully
C:\PROGRA~2\MSXML 4.0 deleted successfully
C:\PROGRA~2\Pioneer deleted successfully
C:\Program Files\log deleted successfully
C:\Program Files\office.tmp deleted successfully
C:\PROGRA~3\Ableton deleted successfully
C:\PROGRA~3\EnergoTech deleted successfully
C:\PROGRA~3\Evernote deleted successfully
C:\Users\Yannick\AppData\Roaming\NetMedia Providers deleted successfully
C:\Users\Yannick\AppData\Roaming\Publish Providers deleted successfully
C:\Users\Yannick\AppData\Roaming\SendSpace deleted successfully
C:\Users\Yannick\AppData\Roaming\TP deleted successfully
C:\Users\Yannick\AppData\Roaming\uTorrent deleted successfully
C:\Users\Yannick\AppData\Roaming\Windows Live Writer deleted successfully
C:\Users\Yannick\AppData\Local\hflKhm9kwVNnnSU deleted successfully
C:\Users\Yannick\AppData\Local\Jaksta_Technologies_Pty_L deleted successfully
C:\Users\Yannick\AppData\Local\PACE Anti-Piracy deleted successfully
C:\Users\Yannick\AppData\Local\PSnvAXQsm deleted successfully
==== Deleting CLSID Registry Keys ======================
HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{4169044D-6BA4-4661-B7D6-E29274F1F458} deleted successfully
HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{4169044D-6BA4-4661-B7D6-E29274F1F458} deleted successfully
HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{4169044D-6BA4-4661-B7D6-E29274F1F458} deleted successfully
HKEY_USERS\S-1-5-21-3446734170-598574761-2879505128-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{4169044D-6BA4-4661-B7D6-E29274F1F458} deleted successfully
HKEY_USERS\S-1-5-21-3446734170-598574761-2879505128-1000\Software\Classes\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{4169044D-6BA4-4661-B7D6-E29274F1F458} deleted successfully
HKEY_USERS\S-1-5-21-3446734170-598574761-2879505128-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{4169044D-6BA4-4661-B7D6-E29274F1F458} deleted successfully
HKEY_USERS\S-1-5-21-3446734170-598574761-2879505128-1002\Software\Classes\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{4169044D-6BA4-4661-B7D6-E29274F1F458} deleted successfully
HKEY_USERS\S-1-5-21-3446734170-598574761-2879505128-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5C0D11B8-C5F6-4be3-AD2C-2B1A3EB94AB6} deleted successfully
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{4169044D-6BA4-4661-B7D6-E29274F1F458} deleted successfully
HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{4169044D-6BA4-4661-B7D6-E29274F1F458} deleted successfully
==== Deleting CLSID Registry Values ======================
==== Deleting Services ======================
==== Batch Command(s) Run By Tool======================
==== Deleting Files \ Folders ======================
C:\PROGRA~2\Applian Technologies not found
C:\PROGRA~2\Pioneer not found
C:\PROGRA~2\ASIO4ALL v2 deleted
C:\PROGRA~3\CloudSoft deleted
C:\Users\Yannick\daemonprocess.txt deleted
C:\Users\Yannick\.android deleted
C:\extensions.sqlite deleted
C:\extensions.ini deleted
C:\PROGRA~3\InstallMate deleted
C:\PROGRA~3\Package Cache deleted
C:\Users\Yannick\AppData\Local\cache deleted
C:\Users\Yannick\Downloads\FreeYouTubeToMP3Converter (1).exe deleted
C:\Users\Yannick\AppData\LocalLow\Protect deleted
C:\Users\Yannick\AppData\LocalLow\{9E025FF6-3AE4-3C14-4E27-2CB17B448718} deleted
C:\Windows\wininit.ini deleted
C:\END deleted
C:\Windows\SysNative\config\systemprofile\Searches deleted
C:\windows\SysNative\GroupPolicy\Machine deleted
C:\windows\SysNative\GroupPolicy\User deleted
C:\windows\SysNative\GroupPolicy\GPT.INI deleted
C:\Windows\Syswow64\GroupPolicy\gpt.ini deleted
C:\Windows\Syswow64\shoC927.tmp deleted
C:\Windows\Syswow64\shoFD11.tmp deleted
C:\Users\Yannick\Documents\Mobogenie deleted
"C:\PROGRA~3\452ac31bfa4cedd3\{CE681A67-9477-CBE6-EB9D-FE534875F98D}.20140703185933" deleted
"C:\PROGRA~3\452ac31bfa4cedd3\{CE681A67-9477-CBE6-EB9D-FE534875F98D}.20140703190101" deleted
"C:\PROGRA~2\PowerISO\PWRISOSH.DLL" deleted
"C:\PROGRA~3\452ac31bfa4cedd3" deleted
"C:\PROGRA~2\PowerISO" not deleted
==== Firefox Extensions Registry ======================
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions]
"
belgiumeid@eid.belgium.be"="C:\Program Files\Mozilla Firefox\extensions\
belgiumeid@eid.belgium.be" []
==== Fake Chromium Profiles Check ======================
Fake profile C:\Users\Administrator\AppData\Local\Torch deleted
Fake profile C:\Users\Administrator\AppData\Local\Google\Chrome deleted
Fake profile C:\Users\Administrator\AppData\Local\Google\Chrome SxS deleted
Fake profile C:\Users\Administrator\AppData\Local\Comodo\Dragon deleted
Fake profile C:\Users\Administrator\AppData\Local\Chromatic Browser deleted
Fake profile C:\Users\Gast\AppData\Local\Torch deleted
Fake profile C:\Users\Gast\AppData\Local\Google\Chrome deleted
Fake profile C:\Users\Gast\AppData\Local\Google\Chrome SxS deleted
Fake profile C:\Users\Gast\AppData\Local\Comodo\Dragon deleted
Fake profile C:\Users\Gast\AppData\Local\Chromatic Browser deleted
Fake profile C:\Users\HomeGroupUser$\AppData\Local\Torch deleted
Fake profile C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome deleted
Fake profile C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome SxS deleted
Fake profile C:\Users\HomeGroupUser$\AppData\Local\Comodo\Dragon deleted
Fake profile C:\Users\HomeGroupUser$\AppData\Local\Chromatic Browser deleted
Fake profile C:\Users\UpdatusUser\AppData\Local\Torch deleted
Fake profile C:\Users\UpdatusUser\AppData\Local\Google\Chrome deleted
Fake profile C:\Users\UpdatusUser\AppData\Local\Google\Chrome SxS deleted
Fake profile C:\Users\UpdatusUser\AppData\Local\Comodo\Dragon deleted
Fake profile C:\Users\UpdatusUser\AppData\Local\Chromatic Browser deleted
Fake profile C:\Users\Yannick\AppData\Local\Torch deleted
Fake profile C:\Users\Yannick\AppData\Local\Google\Chrome SxS deleted
Fake profile C:\Users\Yannick\AppData\Local\Comodo\Dragon deleted
Fake profile C:\Users\Yannick\AppData\Local\Chromatic Browser deleted
==== Chromium Look ======================
Google Chrome Version: 42.0.2311.152
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
beegdgjbpgcmghlpiiojjipjcifhfajb - C:\ProgramData\Browse2save\beegdgjbpgcmghlpiiojjipjcifhfajb.crx[]
AdBlock - Yannick\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom
Bookmark Manager - Yannick\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmlllbghnfkpflemihljekbapjopfjik
Adventure Time - Finn Jake and BMO - Yannick\AppData\Local\Google\Chrome\User Data\Default\Extensions\klmgldhndejkhjokapdbmcldedofhabl
==== Chromium Startpages ======================
C:\Users\Yannick\AppData\Local\Google\Chrome\User Data\Default\Preferences
"homepage": "
http://www.google.be/",
"startup_urls": [ "
http://facebook.com/", "
http://9gag.com/", "
http://soundcloud.com/", "
http://hotmail.com/", "
http://explosm.net/" ]
==== Set IE to Default ======================
Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="
http://www.google.com/"
New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="
http://www.google.com/"
==== All HKCU SearchScopes ======================
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
"DefaultScope"="{14392293-1057-4CA8-A813-FBC9498ED183}"
{012E1000-F331-11DB-8314-0800200C9A66} Google Url="
http://www.google.com/search?q={searchTerms}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Unknown Url="Not_Found"
{14392293-1057-4CA8-A813-FBC9498ED183} Google Url="
https://www.google.com/search?q={searchTerms}"
==== Deleting CLSID Registry Keys ======================
HKEY_USERS\S-1-5-21-3446734170-598574761-2879505128-1002\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} deleted successfully
==== Deleting CLSID Registry Values ======================
==== Deleting Registry Keys ======================
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{0B816DD8-4456-53AE-76BC-2B8288BC1BE7} deleted successfully
HKEY_LOCAL_MACHINE\Software\wow6432node\Policies\Google deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\beegdgjbpgcmghlpiiojjipjcifhfajb deleted successfully
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{EE171732-BEB4-4576-887D-CB62727F01CA} deleted successfully
==== Empty IE Cache ======================
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Yannick\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Yannick\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
C:\Users\Yannick\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
==== Empty FireFox Cache ======================
No FireFox Profiles found
==== Empty Chrome Cache ======================
C:\Users\Yannick\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
C:\Users\Yannick\AppData\Local\Google\Chrome\User Data\Profile 1\Cache emptied successfully
==== Empty All Flash Cache ======================
Flash Cache Emptied Successfully
==== Empty All Java Cache ======================
Java Cache cleared successfully
==== C:\zoek_backup content ======================
C:\zoek_backup (files=201 folders=64 36990040 bytes)
==== Empty Temp Folders ======================
C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\UpdatusUser\AppData\Local\Temp emptied successfully
C:\Users\Yannick\AppData\Local\Temp will be emptied at reboot
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp will be emptied at reboot
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot
==== After Reboot ======================
==== Empty Temp Folders ======================
C:\Windows\Temp successfully emptied
C:\Users\Yannick\AppData\Local\Temp successfully emptied
==== Empty Recycle Bin ======================
C:\$RECYCLE.BIN successfully emptied
==== Deleting Files / Folders ======================
"C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp\MpCmdRun.log" not found
"C:\PROGRA~2\PowerISO" not found
==== EOF on zo 17/05/2015 at 22:55:53,96 ======================