Zoek.exe v5.0.0.0 Updated 04-May-2015 Tool run by Cursist on za 06-06-2015 at 18:56:36,90. Microsoft Windows 7 Professional 6.1.7601 Service Pack 1 x86 Running in: Normal Mode Internet Access Detected Launched: C:\Users\Cursist\Desktop\zoek.exe [Scan all users] [Script inserted] ==== Older Logs ====================== C:\zoek-results2015-06-06-122958.log 26284 bytes ==== Deleting CLSID Registry Keys ====================== ==== Deleting CLSID Registry Values ====================== ==== Deleting Services ====================== ==== Deleting Files \ Folders ====================== C:\PROGRA~1\TabNav not found C:\Windows\system32\tasks\arg3002 deleted ==== Firefox Start and Search pages ====================== ProfilePath: C:\Users\Cursist\AppData\Roaming\Mozilla\Firefox\Profiles\pk07andz.default user_pref("browser.startup.homepage", "www.google.com"); ==== Firefox Extensions ====================== ProfilePath: C:\Users\Cursist\AppData\Roaming\Mozilla\Firefox\Profiles\pk07andz.default - KPN Servicetool - %ProfilePath%\extensions\{594657B4-413A-41D0-8F85-A6D3F35C9BDF} ==== Firefox Plugins ====================== Profilepath: C:\Users\Cursist\AppData\Roaming\Mozilla\Firefox\Profiles\pk07andz.default 0CA4180B21C6B728578F3B0433BB740E - C:\Program Files\VideoLAN\VLC\npvlc.dll - VLC Web Plugin 01D93217A9EE48DD37072B671378CC9C - C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll - Silverlight Plug-In 28986F0A2342A033345EF9E70D395E4F - C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrlui.dll - Microsoft® Silverlight ==== Chromium Look ====================== Google Chrome Version: 43.0.2357.81 Bookmark Manager - Cursist\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmlllbghnfkpflemihljekbapjopfjik ==== Chromium Startpages ====================== C:\Users\Cursist\AppData\Local\Google\Chrome\User Data\Default\Preferences uic"}],"network_stats":{"srtt":47033},"supports_spdy":true},"www.google.com:80":{"alternative_service":[{"port":80,"probability":0.0,"protocol_str":"quic"}]},"www.google.nl:443":{"alternative_service":[{"port":443,"probability":1.0,"protocol_str":"quic"}],"network_stats":{"srtt":62897},"supports_spdy":true},"www.google.nl:80":{"alternative_service":[{"port":80,"probability":0.0,"protocol_str":"quic"}]},"www.googleadservices.com:443":{"alternative_service":[{"port":443,"probability":1.0,"protocol_str":"quic"}],"network_stats":{"srtt":49287},"supports_spdy":true},"www.googleadservices.com:80":{"alternative_service":[{"port":80,"probability":1.0,"protocol_str":"quic"}],"network_stats":{"srtt":50213}},"www.googleapis.com:443":{"alternative_service":[{"port":443,"probability":1.0,"protocol_str":"quic"}],"network_stats":{"srtt":54312},"supports_spdy":true},"www.googletagmanager.com:443":{"alternative_service":[{"port":443,"probability":1.0,"protocol_str":"quic"}],"network_stats":{"srtt":45820},"supports_spdy":true},"www.googletagmanager.com:80":{"alternative_service":[{"port":80,"probability":0.0,"protocol_str":"quic"}]},"www.googletagservices.com:443":{"alternative_service":[{"port":443,"probability":1.0,"protocol_str":"quic"}],"network_stats":{"srtt":45799},"supports_spdy":true},"www.googletagservices.com:80":{"alternative_service":[{"port":80,"probability":1.0,"protocol_str":"quic"}],"network_stats":{"srtt":46664}},"www.groenegroninger.com:80":{"alternative_service":[{"port":80,"probability":0.0,"protocol_str":"quic"}]},"www.gstatic.com:443":{"alternative_service":[{"port":443,"probability":1.0,"protocol_str":"quic"}],"network_stats":{"srtt":45603},"supports_spdy":true},"www.gstatic.com:80":{"alternative_service":[{"port":80,"probability":0.0,"protocol_str":"quic"}]},"www.thepiratebay.se:443":{"supports_spdy":true},"www.youtube-nocookie.com:443":{"alternative_service":[{"port":443,"probability":1.0,"protocol_str":"quic"}],"network_stats":{"srtt":50651},"supports_spdy":true},"www.youtube-nocookie.com:80":{"alternative_service":[{"port":80,"probability":0.0,"protocol_str":"quic"}]},"www.youtube.com:443":{"alternative_service":[{"port":443,"probability":1.0,"protocol_str":"quic"}],"network_stats":{"srtt":53500},"supports_spdy":true},"www.youtube.com:80":{"alternative_service":[{"port":80,"probability":0.0,"protocol_str":"quic"}]},"www.zndsk.com:443":{"supports_spdy":true},"xocdnoption-cd7.kxcdn.com:443":{"supports_spdy":true},"yt3.ggpht.com:443":{"alternative_service":[{"port":443,"probability":1.0,"protocol_str":"quic"}],"network_stats":{"srtt":47730},"supports_spdy":true}},"supports_quic":{"address":"192.168.2.3","used_quic":true},"version":3}},"ntp":{"app_page_names":["Apps"],"most_visited_blacklist":{"5a5a4f252df01754dbefdc44a798829e":null,"cd79e23444e504a8a3baf788456370c0":null,"d3daa008cd452111945db50e6242550a":null,"fff2c78cdfd3a2370f9726ae438fe9d6":null}},"password_bubble":{"nopes":5},"plugins":{"migrated_to_pepper_flash":true,"plugins_list":[],"removed_old_component_pepper_flash_settings":true},"profile":{"avatar_index":0,"content_settings":{"clear_on_exit_migrated":true,"exceptions":{"app_banner":{},"auto_select_certificate":{},"automatic_downloads":{},"cookies":{},"fullscreen":{"https://[*.]www.youtube.com:443,*":{"setting":1}},"geolocation":{},"images":{},"javascript":{},"media_stream":{},"media_stream_camera":{},"media_stream_mic":{},"metro_switch_to_desktop":{},"midi_sysex":{},"mixed_script":{},"mouselock":{},"notifications":{},"plugins":{},"popups":{},"ppapi_broker":{},"protocol_handlers":{},"push_messaging":{},"ssl_cert_decisions":{}},"pattern_pairs":{"https://[*.]www.youtube.com:443,*":{"fullscreen":1}},"pref_version":1},"exit_type":"Crashed","exited_cleanly":true,"icon_version":3,"managed_user_id":"","migrated_content_settings_exceptions":true,"migrated_default_content_settings":true,"migrated_default_media_stream_content_settings":true,"name":"Eerste gebruiker","per_host_zoom_levels":{}},"protection":{"macs":{}},"savefile":{"default_directory":"C:\\Users\\Cursist\\Desktop"},"selectfile":{"last_directory":"C:\\Users\\Cursist\\Desktop\\Meuk\\Pics K"},"session":{"restore_on_startup_migrated":true,"startup_urls_migration_time":"13039635357361107"},"spellcheck":{"dictionary":"en-US"},"sync_promo":{"show_on_first_run_allowed":false},"translate_accepted_count":{"en":0},"translate_blocked_languages":["nl"],"translate_denied_count":{"en":143},"translate_last_denied_time":1423483469915.308,"translate_site_blacklist":["tankionline.com"],"translate_too_often_denied":true,"translate_whitelists":{},"zerosuggest":{"cachedresults":""}} 09B17F9047CEAF3F0E539452EFDDD26600877FD1CABBE0","ennkphjdgehloodpbhlhldgbnhmacadg":"EAC085C682752DFB3C2D63C1165CE47315894819D7AA1B46477B9DDC737F7071","gfdkimpbcpahaombhbimeihdjnejgicl":"E52EB8D50BFC20A3EB5403754FC7593F43989DCD80A8C033CCD0B11F866CBA70","gmlllbghnfkpflemihljekbapjopfjik":"B087334961AE2712E199AB2243B88BBE70CACBB4566850B942DCDC222BA681DE","kmendfapggjehodndflmmgagdbamhnfd":"3769C12C9BDD4B19E366888AC2F4885569A72B944C3E915CA318475FCD93C208","mfehgcgbbipciphmccgaenjidiccnmng":"4E9321D07FDE0D3F51FD971B25A41C11BEECF55C019BE53B8A92EB7D7EF69D6E","mgndgikekgjfcpckkfioiadnlibdjbkf":"D996E656890D16291658D637214557507405D8668D39C706A6E008B921336636","mhjfbmdgcfjbbpaeojofohoefgiehjai":"39F0815C4B33233871E51BB2CB928771874CD50DCD06D34E0C9119044FBE2654","neajdppkdcdipfabeoofebfddakdcjhd":"2474A4D32FEA7F4C979B403C5842D68367CA759C7E085AFA63572402E1C61A5A","nkeimhogjdpnpccoofpliimaahmaaome":"C36C3D66B64FA11B0C08126DAE44C307B6A2348B0DECA79D61D4E423385A54EC","nmmhkkegccagdldgiimedpiccmgmieda":"D98EA6CCC9A282CCDDCC4DB2042FDE1E338734E79FD90C04AFDD20B173678DAE","pafkbggdmjlpgkdkcbjmhmfcdpncadgh":"59E333E36FDD3243930537C905EB31CC2D564D4192DE5AC514ADFF5016C7BBF4","pjkljhegncpnkpknbcohdijeoejaedia":"4A8EE108383A0F33FBCA9C83574AEDB83C6713087BD22321E1C95C8B2705966F"}},"google":{"services":{"last_username":"0FBF04FCE3C3CF093E7B8CB49263E2FCC3EF94F2A3AC4A7C3EB29A15E7AB5B43","username":"0E9234DBEC22CE2C334B328EA4DD50A6C8EF3AB2888DEE6D102826759B95300E"}},"homepage":"A6CFB961E1CD209B25EC8A2C45BB898866028D10F3A99E3CB54EA1BFE4B41473","homepage_is_newtabpage":"D917BB6414BC6EDF12FDBA31174396C7FDCDDAE330A11EAE8F0C7F4F612348C1","pinned_tabs":"08F2E5B8616966A51896F844FC7A89B5B726BB276C5EFED3B4E12F0714AFAEAE","prefs":{"preference_reset_time":"726D60A31731E52C1CA2E9FBBE137D64137111C006C206D11E4A15E7717CE81F"},"profile":{"reset_prompt_memento":"EAA15E0C37098527A9C4F3DBF5ED6920232EEFDF90E065776F91FD599401ADF6"},"safebrowsing":{"incidents_sent":"DE1197170192A3DAF584FF7E92589361E93FCE53095EB1FE49829300B507958C"},"search_provider_overrides":"AB138BF149BD6B72E866D59AAD4933BCE7637414973D7CDFEF224314F2BDA36F","session":{"restore_on_startup":"283AEAC820AF9E1A101725DFD81B9D326768DFC6BFECFB073E12B18F54123692","startup_urls":"D935275DBCCE60ED0B0A55378D5D21992510B6FB2BE4499C94657D97116D53F2"},"software_reporter":{"prompt_reason":"B7CC771668F44C21CC85B6C093D58DB1EBE0EBC75F9F9EFFB51CC916E6083E2F","prompt_seed":"5F25011DC6BC152DBB1CE434CB48E0CBA539C34CA69B36DCFA9F2883E467E243","prompt_version":"AACDBEC5AC8AB40F3C1DC234677E34D36306CB7A45B66F35B0F80A8EC841F5E1"},"sync":{"remaining_rollback_tries":"191F2D43B8C548B2611FB278D90E1E9DB1F0C8789951C5CABEB8BB196789579B"}},"super_mac":"9A9604A135D7E88C62432BE5D457D782E111C60235E2B371EC1D6F04A041C94E"},"session":{"restore_on_startup":4,"startup_urls":["http://www.google.com/"]},"sync":{"remaining_rollback_tries":0}} ==== Set IE to Default ====================== Old Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157" New Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157" ==== All HKCU SearchScopes ====================== HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" {012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}" {0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC" ==== Empty IE Cache ====================== C:\Users\Cursist\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Cursist\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully ==== Empty FireFox Cache ====================== C:\Users\Cursist\AppData\Local\Mozilla\Firefox\Profiles\pk07andz.default\cache2 emptied successfully ==== Empty Chrome Cache ====================== C:\Users\Cursist\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully ==== Empty All Flash Cache ====================== Flash Cache Emptied Successfully ==== Empty All Java Cache ====================== Java Cache cleared successfully ==== C:\zoek_backup content ====================== C:\zoek_backup (files=27 folders=25 2441102 bytes) ==== Empty Temp Folders ====================== C:\Users\Cursist\AppData\Local\Temp will be emptied at reboot C:\Users\Default\AppData\Local\Temp emptied successfully C:\Users\Default User\AppData\Local\Temp emptied successfully C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully C:\Windows\Temp will be emptied at reboot ==== After Reboot ====================== ==== Empty Temp Folders ====================== C:\Windows\Temp successfully emptied C:\Users\Cursist\AppData\Local\Temp successfully emptied ==== Empty Recycle Bin ====================== C:\$RECYCLE.BIN successfully emptied ==== EOF on za 06-06-2015 at 19:16:18,78 ======================