Zoek.exe v5.0.0.0 Updated 07-March-2014 Tool run by AlineJan on do 10/04/2014 at 9:52:56,95. Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x64 Running in: Normal Mode Internet Access Detected Launched: C:\Users\AlineJan\Desktop\zoek.exe [Scan all users] [Script inserted] ==== Older Logs ====================== C:\zoek-results2014-04-08-092456.log 434 bytes C:\zoek-results2014-04-08-194737.log 402 bytes C:\zoek-results2014-04-09-193013.log 26475 bytes ==== Deleting CLSID Registry Keys ====================== HKEY_USERS\S-1-5-21-2635711567-3001363841-3105779589-1001\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} deleted successfully ==== Deleting CLSID Registry Values ====================== ==== Deleting Services ====================== ==== Registry Fix Code x64 ====================== Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"=- ==== Deleting Files \ Folders ====================== "C:\Program Files (x86)\TornTV.com\torntv10.crx" not found "C:\Users\AlineJan\AppData\Roaming\Media Finder\Extensions\gencrawler_gc.crx" not found "C:\Program Files (x86)\FTDownloader.com\FTDownloader10.crx" not found "C:\Users\AlineJan\AppData\Roaming\Media Finder\Extensions\mf_plugin_gc.crx" not found C:\PROGRA~2\Smart Driver Updater deleted C:\PROGRA~2\ExpressFiles deleted C:\PROGRA~2\Denzi deleted C:\Users\AlineJan\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\iLivid.lnk deleted C:\Users\AlineJan\AppData\Roaming\ExpressFiles deleted C:\Users\AlineJan\AppData\Roaming\eIntaller deleted C:\Users\AlineJan\AppData\Roaming\Smart Driver Updater deleted C:\Users\AlineJan\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\gencrawler@some.com deleted C:\PROGRA~3\Wincert deleted C:\PROGRA~3\Package Cache deleted C:\Users\AlineJan\AppData\Local\iLivid deleted C:\Users\AlineJan\AppData\Local\PutLockerDownloader deleted C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Systweak PhotoStudio deleted C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Smart Driver Updater deleted C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Finder deleted C:\Users\AlineJan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\iLivid.lnk deleted C:\Users\AlineJan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FTDownloader.com deleted C:\Windows\SysNative\roboot64.exe deleted C:\windows\SysNative\Tasks\LaunchApp deleted C:\windows\SysNative\dmwu.exe deleted C:\Users\AlineJan\AppData\LocalLow\ilividmoviestoolbarha deleted C:\Users\AlineJan\AppData\LocalLow\DataMngr deleted C:\Windows\wininit.ini deleted C:\windows\SysNative\Tasks\Express FilesUpdate deleted C:\windows\SysNative\Tasks\EPUpdater deleted C:\windows\SysNative\tasks\YourFile DownloaderUpdate deleted C:\windows\SysNative\ljkb deleted C:\Windows\SysWow64\searchplugins deleted C:\Windows\SysWow64\Extensions deleted C:\Users\AlineJan\Documents\Optimizer Pro deleted "C:\Users\AlineJan\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\trtv3@trtv.com.xpi" deleted ==== Firefox Extensions Registry ====================== [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions] "{DF153AFF-6948-45d7-AC98-4FC4AF8A08E2}"="C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext" [25/03/2014 19:45] ==== Firefox Extensions ====================== ExtDir: C:\Users\AlineJan\AppData\Roaming\Mozilla\Firefox\Profiles\extensions - FT Downloader - %ExtDir%\ftd@ftd.com.xpi AppDir: C:\Program Files (x86)\Mozilla Firefox - Belgium eID - %AppDir%\extensions\belgiumeid@eid.belgium.be ==== Firefox Plugins ====================== ==== Deleted Firefox Extensions ====================== C:\Users\AlineJan\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\ftd@ftd.com.xpi deleted ==== Chrome Look ====================== HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions bicnnkjibmphdeigoodpjlcklcnaobdj - C:\Program Files (x86)\TornTV.com\torntv10.crx[] dednnpigldgdbpgcdpfppmlcnnbjciel - C:\Users\AlineJan\AppData\Roaming\Media Finder\Extensions\gencrawler_gc.crx[] idhngdhcfkoamngbedgpaokgjbnpdiji - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Chrome\Ext\realdownloader.crx[14/08/2013 16:24] kanflfepiobnpjbljmngfgegijhdpljm - C:\Program Files (x86)\HP SimplePass\tschrome.crx[01/04/2013 03:25] lgnbhdnimikkoodkogjlcllngimhlapp - C:\Program Files (x86)\FTDownloader.com\FTDownloader10.crx[] lpmkgpnbiojfaoklbkpfneikocaobfai - C:\Users\AlineJan\AppData\Roaming\Media Finder\Extensions\mf_plugin_gc.crx[] YouTube - AlineJan\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo Google Search - AlineJan\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf RealDownloader - AlineJan\AppData\Local\Google\Chrome\User Data\Default\Extensions\idhngdhcfkoamngbedgpaokgjbnpdiji Website Logon - AlineJan\AppData\Local\Google\Chrome\User Data\Default\Extensions\kanflfepiobnpjbljmngfgegijhdpljm Gmail - AlineJan\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia Ask Toolbar - AlineJan\AppData\Local\Torch\User Data\Default\Extensions\aaaalejpmnocmhmlbmlkjemekckoagne Google Docs - AlineJan\AppData\Local\Torch\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake Google Drive - AlineJan\AppData\Local\Torch\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf YouTube - AlineJan\AppData\Local\Torch\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo DropToS - AlineJan\AppData\Local\Torch\User Data\Default\Extensions\cipmepknanmbbaneimacddfemfbfgpgo Google Search - AlineJan\AppData\Local\Torch\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf Torch Music - AlineJan\AppData\Local\Torch\User Data\Default\Extensions\gcjbdjlojcomlphfchhihkigepfabcad FaceLift - AlineJan\AppData\Local\Torch\User Data\Default\Extensions\gimjmfipknpppbpmkdenjjpfhobiiojk RealDownloader - AlineJan\AppData\Local\Torch\User Data\Default\Extensions\idhngdhcfkoamngbedgpaokgjbnpdiji Website Logon - AlineJan\AppData\Local\Torch\User Data\Default\Extensions\kanflfepiobnpjbljmngfgegijhdpljm Torch Helper - AlineJan\AppData\Local\Torch\User Data\Default\Extensions\lecpjhggilhbceadobnggaagnpfpafhg Google Wallet - AlineJan\AppData\Local\Torch\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda Torch Music - AlineJan\AppData\Local\Torch\User Data\Default\Extensions\ohimbkoaphfnmekmfppijeblmkncneed Hola for Torch - AlineJan\AppData\Local\Torch\User Data\Default\Extensions\pdehmppfilefbolgganhfihpbmjlgebh Gmail - AlineJan\AppData\Local\Torch\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia ==== Chrome Fix ====================== C:\Users\AlineJan\AppData\Local\Torch\User Data\Default\Extensions\aaaalejpmnocmhmlbmlkjemekckoagne deleted successfully ==== Set IE to Default ====================== Old Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://www.google.com/" "Default_Page_URL"="http://www.google.com" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main] "Default_Page_URL"="http://www.google.com" "Start Page"="http://www.google.com" [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main] "Default_Page_URL"="http://www.google.com" "Start Page"="http://www.google.com" New Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157" "Start Page"="http://www.google.com/" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main] "Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157" "Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157" [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main] "Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157" "Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157" ==== All HKCU SearchScopes ====================== HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes "DefaultScope"="{6A1806CD-94D4-4689-BA73-E35EA1EA9990}" {0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&form=HPNTDF&pc=HPNTDF&src=IE-SearchBox" {6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}" {d43b3890-80c7-4010-a95d-1e77b5924dc3} Unknown Url="Not_Found" {D944BB61-2E34-4DBF-A683-47E505C587DC} eBay Url="http://rover.ebay.com/rover/1/1553-111073-34115-5/4?mpre=http://www.benl.ebay.be/sch/i.html?_nkw={searchTerms}" ==== Reset Google Chrome ====================== C:\Users\AlineJan\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully C:\Users\AlineJan\AppData\Local\Torch\User Data\Default\Preferences was reset successfully C:\Users\AlineJan\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully C:\Users\AlineJan\AppData\Local\Torch\User Data\Default\Web Data was reset successfully ==== Deleting CLSID Registry Keys ====================== HKEY_USERS\S-1-5-21-2635711567-3001363841-3105779589-1001\Software\Microsoft\Internet Explorer\SearchScopes\{d43b3890-80c7-4010-a95d-1e77b5924dc3} deleted successfully ==== Deleting CLSID Registry Values ====================== ==== Deleting Registry Keys ====================== HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\Bicnnkjibmphdeigoodpjlcklcnaobdj deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\Dednnpigldgdbpgcdpfppmlcnnbjciel deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\Lgnbhdnimikkoodkogjlcllngimhlapp deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\Lpmkgpnbiojfaoklbkpfneikocaobfai deleted successfully HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\iLivid deleted successfully HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ilividmoviestoolbarhaIE deleted successfully HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Denzi deleted successfully HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iLivid deleted successfully HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr deleted successfully HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PC Speed Maximizer deleted successfully HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Smart Driver Updater deleted successfully ==== Empty IE Cache ====================== C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\AlineJan\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\AlineJan\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully ==== Empty FireFox Cache ====================== No FireFox Cache found ==== Empty Chrome Cache ====================== C:\Users\AlineJan\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully C:\Users\AlineJan\AppData\Local\Torch\User Data\Default\Cache emptied successfully ==== Empty All Flash Cache ====================== Flash Cache Emptied Successfully ==== Empty All Java Cache ====================== No Java Cache Found ==== C:\zoek_backup content ====================== C:\zoek_backup (files=3317 folders=463 377449620 bytes) ==== Empty Temp Folders ====================== C:\Users\AlineJan\AppData\Local\Temp will be emptied at reboot C:\Users\Default\AppData\Local\Temp emptied successfully C:\Users\Default User\AppData\Local\Temp emptied successfully C:\Users\UpdatusUser\AppData\Local\Temp emptied successfully C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully C:\Windows\Temp will be emptied at reboot ==== After Reboot ====================== ==== Empty Temp Folders ====================== C:\Windows\Temp successfully emptied C:\Users\AlineJan\AppData\Local\Temp successfully emptied ==== Empty Recycle Bin ====================== C:\$RECYCLE.BIN successfully emptied ==== EOF on do 10/04/2014 at 14:34:14,89 ======================