Zoek.exe v5.0.0.0 Updated 10-February-2015 Tool run by Suzanne on wo 11/02/2015 at 13:41:21,05. Running in: Normal Mode No Internet Access Detected Launched: C:\Users\Suzanne\Desktop\zoek.exe [Scan all users] [Script inserted] [Checkboxes used] ==== Older Logs ====================== C:\zoek-results2015-02-10-223454.log 1326 bytes ==== Deleting CLSID Registry Keys ====================== HKEY_USERS\S-1-5-21-2292659053-1968452582-3063732707-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5C255C8A-E604-49b4-9D64-90988571CECB} deleted successfully HKEY_USERS\S-1-5-21-2292659053-1968452582-3063732707-1003\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{3B6A4AD4-D6EE-47dd-B308-0E0930A43853} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB} deleted successfully HKEY_CLASSES_ROOT\CLSID\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} deleted successfully ==== Deleting CLSID Registry Values ====================== ==== Deleting Services ====================== ==== FireFox Fix ====================== ProfilePath: C:\Users\Suzanne\AppData\Roaming\Mozilla\Firefox\Profiles\i2qximj0.default user.js not found ---- Lines CT2269050 removed from prefs.js ---- user_pref("CT2269050..clientLogIsEnabled", false); user_pref("CT2269050./9b+7e+x305.from_oldbar.enc", "JH4nQTM0NjN5RTo9KnIseXp+ejEoMztHSVNGLVhNUD0mPy0uMTVEO0ZOT1tWXmlbQm1iZVI7VEJDRklZUFtjfXN7blUhdXhlTm user_pref("CT2269050./9b+7e,x305.from_oldbar.enc", "JH4oQS8/Pjd5RTo9KnIseXt4fTEoMzxHSEAsV0xPPCU+LC4rL0M6RU5ZUFtXZ2pmQm1iRV5pVD1WREZDRltSXWZxbCFua1h9c2 user_pref("CT2269050./9b+7e-x305.from_oldbar.enc", "JH4pMnZBNjk3MzVFOX4/STsvdzF+ICUgNi04QkdKWFFaXFhdUF9ZOWRZXEkySzk6PzlQR1JcQXNoa2llZ3t5b217blUhdXhZJn user_pref("CT2269050./9b+7e06cg5el8:.from_oldbar.enc", "bm1pbW9xcnFueA=="); user_pref("CT2269050./9b+7e06cg5el;8i:k.from_oldbar.enc", "JH4tLyJqdHNvc3V3eHd0fiQvS0lHT0I1fV1cPQ=="); user_pref("CT2269050./9b+7e31;cjc<=fbj#om.from_oldbar.enc", "JH5hOT8jayVxd3J2KiEsbkFPRE0yejRPSElSTlYvW1k+NUAjT0tVYUYvSDpKQUwva2Fuc3BlaGZrc2V1fHh4cn5nY user_pref("CT2269050./9b+7e4x305.from_oldbar.enc", "JH4wLEB2Qjc6J28pd3t0di4lMEE+T0lKUitVVTojPCsvKClBOENUUV5dVmFfVmhcQm1iZVI7VENGSUpZUFtsaXp+IXAjcHZZJX user_pref("CT2269050./9b+7ebe3g=;d9n9=d.from_oldbar.enc", "NywtMml1di46PHs6OUNKSUhBQ0smUUZJKWVQRlZJZXFzTTNLVw=="); user_pref("CT2269050./9b-0?3g>d.from_oldbar.enc", "OW87bz4+dXZ6RkR6RyB4SUl6JVF7fX0qUSAmJSUrWVonLDEx"); user_pref("CT2269050./9b-0?3g@6:5;.from_oldbar.enc", "AA=="); user_pref("CT2269050./9b-0?3gfa7ef.from_oldbar.enc", "Ky4sPQ=="); user_pref("CT2269050./9b-3=3eccja=f>.from_oldbar.enc", "JH4zPSxFL0E1J28pKiEsOT1EMHgyMyo1REhYTDojKC4uMTIzNDU2O0ZgaFdsXmhXcFpsYGBrZmhWP3N5b2l4YQ=="); user_pref("CT2269050./9b/>01=9a6k6@44i48?.from_oldbar.enc", "NywtMml1djNCNjNBSEcgPj1HTk1MRUdPKlVKTS1YWFheS1VONmNSVk8="); user_pref("CT2269050./9b5ba==9cjag.from_oldbar.enc", "a3A/QWpzQEF6dXZ2SnV3fH5NentO"); user_pref("CT2269050./9b6b11g4c56b>f;p;anr@p.from_oldbar.enc", "bm1pbW9xcnB3d3Zzcw=="); user_pref("CT2269050./9b9643g3/9e.from_oldbar.enc", "ag=="); user_pref("CT2269050./9b;45>:bi9i7ie.from_oldbar.enc", "Ky4sPQ=="); user_pref("CT2269050./9b<:222h64<.from_oldbar.enc", "OT81Lz4="); user_pref("CT2269050./9b=+03eh8h8j?:.from_oldbar.enc", "REM="); user_pref("CT2269050./9b?+e2a52d8.from_oldbar.enc", "NywtMml1di46PHs6OUNKSUhBQ0smUUZJKWVQRlZkcHJ5UVVeXlI="); user_pref("CT2269050./9b?b0d:8aj62>rhiqs.from_oldbar.enc", "OT81Lz4="); user_pref("CT2269050._9b_7e.:2z527.from_oldbar.enc", "JH5ANUIqNjh5RTp8NkEsdC4gITEoM1RJVj5KTC5YWD0mPy4yQkc="); user_pref("CT2269050._key_cl_active", "%BF%E7%B8%B6%EB%E9%EB%E7%B3%E9%EA%BE%E9%B3%BA%B6%B9%B8%B3%BE%EC%B8%B8%B3%E8%EB%EA%BE%E9%E9%E9%BD%BE%E8%B6%BE"); user_pref("CT2269050._key_cl_active.enc", "OWEyMGVjZWEtY2Q4Yy00MDMyLThmMjItYmVkOGNjYzc4YjA4"); user_pref("CT2269050.addressBarTakeOverEnabledInHidden", "true"); user_pref("CT2269050.alertChannelId", "666138"); user_pref("CT2269050.approveUntrustedApps", false); user_pref("CT2269050.backendstorage./9b+7e-x305", "247E29327641363937333545397E3F493B2F77317E202520362D3842474A58515A5C585D505F593964595C49324B393A3F3 user_pref("CT2269050.backendstorage./9b+7e.:2z527", "247E4035422A363879453A7C36412C742E20213128335449563E4A4C2E58583D263F2E324247"); user_pref("CT2269050.backendstorage./9b+7e06cg5el8:", "6E6D696D6F7172716E78"); user_pref("CT2269050.backendstorage./9b+7e06cg5el;8i:k", "247E2D2F226A74736F7375777877747E242F4B49474F42357D5D5C3D"); user_pref("CT2269050.backendstorage./9b+7e4x305", "247E302C407642373A276F29777B74762E2530413E4F494A522B55553A233C2B2F282941384354515E5D56615F56685C426 user_pref("CT2269050.backendstorage./9b+7ebe3g=;d9n9=d", "372C2D326975762E3A3C7B3A39434A494841434B265146492965504656496571734D334B57"); user_pref("CT2269050.backendstorage./9b-0?3g>d", "396F3B6F3E3E75767A46447A47207849497A25517B7D7D2A51202625252B595A272C3131"); user_pref("CT2269050.backendstorage./9b-0?3g@6:5;", ""); user_pref("CT2269050.backendstorage./9b-0?3gfa7ef", "2B2E2C3D"); user_pref("CT2269050.backendstorage./9b-3=3eccja=f>", "247E333D2C452F4135276F292A212C393D44307832332A354448584C3A23282E2E3132333435363B466068576C5E685 user_pref("CT2269050.backendstorage./9b/>01=9a6k6@44i48?", "372C2D3269757633423633414847203E3D474E4D4C45474F2A554A4D2D5858585E4B554E366352564F"); user_pref("CT2269050.backendstorage./9b5ba==9cjag", "6B703F416A7340417A7576764A75777C7E4D7A7B4E"); user_pref("CT2269050.backendstorage./9b6b11g4c56b>f;p;anr@p", "6E6D696D6F7172707777767373"); user_pref("CT2269050.backendstorage./9b90e@.3c;7b=?ofb>>rhiqs", "393F352F3E"); user_pref("CT2269050.backendstorage./9b9643g3/9e", "6A"); user_pref("CT2269050.backendstorage./9b;45>:bi9i7ie", "2B2E2C3D"); user_pref("CT2269050.backendstorage./9b<:222h64<", "393F352F3E"); user_pref("CT2269050.backendstorage./9b=+03eh8h8j?:", "4443"); user_pref("CT2269050.backendstorage./9b?+e2a52d8", "372C2D326975762E3A3C7B3A39434A494841434B2651464929655046566470727951555E5E52"); user_pref("CT2269050.backendstorage./9b?b0d:8aj62