Zoek.exe v5.0.0.0 Updated 04-May-2015 Tool run by sjors on di 23-06-2015 at 11:09:02,11. Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x64 Running in: Normal Mode Internet Access Detected Launched: C:\Users\sjors\Downloads\zoek.exe [Scan all users] [Script inserted] ==== Older Logs ====================== C:\zoek-results2015-06-18-220631.log 37678 bytes C:\zoek-results2015-06-19-110511.log 45538 bytes ==== Deleting CLSID Registry Keys ====================== ==== Deleting CLSID Registry Values ====================== ==== Deleting Services ====================== ==== Deleting Files \ Folders ====================== C:\Users\sjors\.android deleted C:\Users\sjors\AppData\Roaming\appdataFr2.bin deleted ==== Chromium Look ====================== Playjack - Gast\AppData\Local\Google\Chrome\User Data\Default\Extensions\pljlekgobmkopcjnljkinpmppkekangd BTTV - sjors\AppData\Local\Google\Chrome\User Data\Default\Extensions\ajopnjidmegmdimjlfnijceegpefgped ==== Chromium Startpages ====================== C:\Users\sjors\AppData\Local\Google\Chrome\User Data\Default\Preferences "alternative_service":[{"port":443,"probability":1.0,"protocol_str":"quic"}],"network_stats":{"srtt":17348},"supports_spdy":true},"google.com:443":{"alternative_service":[{"port":443,"probability":1.0,"protocol_str":"quic"}],"network_stats":{"srtt":14789},"supports_spdy":true},"googleads.g.doubleclick.net:443":{"alternative_service":[{"port":443,"probability":1.0,"protocol_str":"quic"}],"network_stats":{"srtt":15255},"supports_spdy":true},"i.ytimg.com:443":{"alternative_service":[{"port":443,"probability":1.0,"protocol_str":"quic"}],"network_stats":{"srtt":19557},"supports_spdy":true},"i1.ytimg.com:443":{"alternative_service":[{"port":443,"probability":1.0,"protocol_str":"quic"}],"network_stats":{"srtt":21357},"supports_spdy":true},"id.google.nl:443":{"alternative_service":[{"port":443,"probability":1.0,"protocol_str":"quic"}],"network_stats":{"srtt":19429},"supports_spdy":true},"lh3.googleusercontent.com:443":{"network_stats":{"srtt":26137},"supports_spdy":true},"lh4.googleusercontent.com:443":{"alternative_service":[{"port":443,"probability":1.0,"protocol_str":"quic"}],"network_stats":{"srtt":32440},"supports_spdy":true},"lh5.googleusercontent.com:443":{"network_stats":{"srtt":26137},"supports_spdy":true},"lh6.googleusercontent.com:443":{"network_stats":{"srtt":26137},"supports_spdy":true},"login.wikimedia.org:443":{"supports_spdy":true},"manage.betterttv.net:443":{"supports_spdy":true},"notification.adblockplus.org:443":{"supports_spdy":true},"oauth.googleusercontent.com:443":{"network_stats":{"srtt":19873},"supports_spdy":true},"partner.googleadservices.com:443":{"alternative_service":[{"port":443,"probability":1.0,"protocol_str":"quic"}],"supports_spdy":true},"partner.googleadservices.com:80":{"alternative_service":[{"port":80,"probability":1.0,"protocol_str":"quic"}],"network_stats":{"srtt":13686}},"pixel.facebook.com:443":{"supports_spdy":true},"plus.google.com:443":{"alternative_service":[{"port":443,"probability":1.0,"protocol_str":"quic"}],"network_stats":{"srtt":25382},"supports_spdy":true},"pubads.g.doubleclick.net:80":{"alternative_service":[{"port":80,"probability":1.0,"protocol_str":"quic"}],"network_stats":{"srtt":18966}},"r5---sn-5hne6n7s.googlevideo.com:443":{"alternative_service":[{"port":443,"probability":0.01,"protocol_str":"quic"}]},"s.youtube.com:443":{"alternative_service":[{"port":443,"probability":1.0,"protocol_str":"quic"}],"network_stats":{"srtt":52949},"supports_spdy":true},"s.ytimg.com:443":{"alternative_service":[{"port":443,"probability":1.0,"protocol_str":"quic"}],"network_stats":{"srtt":19557},"supports_spdy":true},"s2.googleusercontent.com:443":{"network_stats":{"srtt":17868},"supports_spdy":true},"scontent-ams2-1.xx.fbcdn.net:443":{"supports_spdy":true},"sockets.betterttv.net:443":{"supports_spdy":true},"ssl.google-analytics.com:443":{"supports_spdy":true},"ssl.gstatic.com:443":{"alternative_service":[{"port":443,"probability":1.0,"protocol_str":"quic"}],"network_stats":{"srtt":21722},"supports_spdy":true},"stats.g.doubleclick.net:443":{"alternative_service":[{"port":443,"probability":1.0,"protocol_str":"quic"}],"network_stats":{"srtt":13900},"supports_spdy":true},"syndication.twitter.com:443":{"supports_spdy":true},"twitter.com:443":{"supports_spdy":true},"upload.wikimedia.org:443":{"supports_spdy":true},"video-ams2-1.xx.fbcdn.net:443":{"supports_spdy":true},"www.facebook.com:443":{"supports_spdy":true},"www.google-analytics.com:443":{"alternative_service":[{"port":443,"probability":1.0,"protocol_str":"quic"}],"network_stats":{"srtt":13852},"supports_spdy":true},"www.google-analytics.com:80":{"alternative_service":[{"port":80,"probability":0.0,"protocol_str":"quic"}]},"www.google.com:443":{"alternative_service":[{"port":443,"probability":1.0,"protocol_str":"quic"}],"network_stats":{"srtt":15399},"supports_spdy":true},"www.google.com:80":{"alternative_service":[{"port":80,"probability":0.0,"protocol_str":"quic"}]},"www.google.nl:443":{"alternative_service":[{"port":443,"probability":1.0,"protocol_str":"quic"}],"network_stats":{"srtt":16859},"supports_spdy":true},"www.googleapis.com:443":{"supports_spdy":true},"www.googletagservices.com:443":{"alternative_service":[{"port":443,"probability":1.0,"protocol_str":"quic"}],"network_stats":{"srtt":14674},"supports_spdy":true},"www.googletagservices.com:80":{"alternative_service":[{"port":80,"probability":1.0,"protocol_str":"quic"}],"network_stats":{"srtt":14392}},"www.gstatic.com:443":{"alternative_service":[{"port":443,"probability":1.0,"protocol_str":"quic"}],"network_stats":{"srtt":21722},"supports_spdy":true},"www.gstatic.com:80":{"alternative_service":[{"port":80,"probability":0.0,"protocol_str":"quic"}]},"www.yahoo.com:443":{"supports_spdy":true},"www.youtube-nocookie.com:443":{"alternative_service":[{"port":443,"probability":1.0,"protocol_str":"quic"}],"network_stats":{"srtt":14832},"supports_spdy":true},"www.youtube.com:443":{"alternative_service":[{"port":443,"probability":1.0,"protocol_str":"quic"}],"network_stats":{"srtt":16114},"supports_spdy":true},"www.youtube.com:80":{"alternative_service":[{"port":80,"probability":0.0,"protocol_str":"quic"}]},"yahoo.com:443":{"supports_spdy":true},"yt3.ggpht.com:443":{"alternative_service":[{"port":443,"probability":1.0,"protocol_str":"quic"}],"network_stats":{"srtt":30139},"supports_spdy":true}},"supports_quic":{"address":"192.168.178.11","used_quic":true},"version":3}},"partition":{"per_host_zoom_levels":{"2166136261":{"www.reddit.com":2.223901085741545}}},"plugins":{"migrated_to_pepper_flash":true,"plugins_list":[],"removed_old_component_pepper_flash_settings":true},"profile":{"avatar_bubble_tutorial_shown":1,"avatar_index":0,"content_settings":{"exceptions":{"app_banner":{},"auto_select_certificate":{},"automatic_downloads":{},"cookies":{},"fullscreen":{"https://www.youtube.com:443,http://www.rtlnieuws.nl:80":{"setting":1},"https://www.youtube.com:443,https://www.youtube.com:443":{"setting":1}},"geolocation":{},"images":{},"javascript":{},"media_stream":{},"media_stream_camera":{},"media_stream_mic":{},"metro_switch_to_desktop":{},"midi_sysex":{},"mixed_script":{},"mouselock":{},"notifications":{},"plugins":{},"popups":{},"ppapi_broker":{},"protocol_handlers":{},"push_messaging":{},"ssl_cert_decisions":{}},"pattern_pairs":{"https://www.youtube.com:443,http://www.rtlnieuws.nl:80":{"fullscreen":1},"https://www.youtube.com:443,https://www.youtube.com:443":{"fullscreen":1}},"pref_version":1},"exit_type":"Crashed","exited_cleanly":true,"icon_version":3,"managed_user_id":"","migrated_content_settings_exceptions":true,"migrated_default_content_settings":true,"migrated_default_media_stream_content_settings":true,"name":"Persoon 1","per_host_zoom_levels":{}},"protection":{"macs":{}},"selectfile":{"last_directory":"C:\\Users\\sjors\\Desktop"},"session":{"restore_on_startup_migrated":true,"startup_urls_migration_time":"13079454226895720"},"translate_accepted_count":{"en":0},"translate_blocked_languages":["nl"],"translate_denied_count":{"en":2},"translate_last_denied_time":1435050272399.878,"translate_too_often_denied":true,"translate_whitelists":{}} knbcohdijeoejaedia":{"ack_external":true,"active_permissions":{"api":["notifications"],"manifest_permissions":[]},"app_launcher_ordinal":"y","commands":{},"content_settings":[],"creation_flags":137,"events":[],"from_bookmark":false,"from_webstore":true,"granted_permissions":{"api":["notifications"],"manifest_permissions":[]},"incognito_content_settings":[],"incognito_preferences":{},"install_time":"13079185655877316","lastpingday":"13079430001185977","location":1,"manifest":{"app":{"launch":{"container":"tab","web_url":"https://mail.google.com/mail/ca"},"urls":["*://mail.google.com/mail/ca"]},"current_locale":"nl","default_locale":"en","description":"Een snelle, doorzoekbare e-mailfunctie met minder spam.","icons":{"128":"128.png"},"key":"MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDCuGglK43iAz3J9BEYK/Mz6ZhloIMMDqQSAaf3vJt4eHbTbSDsu4WdQ9dQDRcKlg8nwQdePBt0C3PSUBtiSNSS37Z3qEGfS7LCju3h6pI1Yr9MQtxw+jUa7kXXIS09VV73pEFUT/F7c6Qe8L5ZxgAcBvXBh1Fie63qb02I9XQ/CQIDAQAB","manifest_version":2,"name":"Gmail","options_page":"https://mail.google.com/mail/ca/#settings","permissions":["notifications"],"update_url":"http://clients2.google.com/service/update2/crx","version":"8.1"},"page_ordinal":"n","path":"pjkljhegncpnkpknbcohdijeoejaedia\\8.1_1","preferences":{},"regular_only_preferences":{},"state":1,"was_installed_by_default":true,"was_installed_by_oem":false}}},"pinned_tabs":[],"protection":{"macs":{"browser":{"show_home_button":"29DB425937A3337631415621E0BFCE5615627EF7161EBED2DC14610520AFF083"},"default_search_provider":{"keyword":"FE168FB1046D82F3EA8F125239FF3D000D39DA904DAB7DA63F272FCCF6E0298B","name":"2E93DAB4BC26F90F3713FE0BB554234BF540643DB35F06516AFD29A37892C6C2","search_url":"2EE4939FC15A15A01F7454406BC306195D0F6829F3880E02E2CF858A8CD693FF"},"default_search_provider_data":{"template_url_data":"320A7009B018A166E6DD4480D65BCA2BBB86A687AAEC3F8D4D3342B48227C6C2"},"extensions":{"settings":{"aapocclcgogkmnckokdopfmhonfmgoek":"8DB788FC1A4D6892C1BAC62712C983E965246AE763E0AA63659D705582140591","ahfgeienlihckogmohjhadlkjgocpleb":"6E3E1C012E0007F2BDBBCC1F1219568B2F11F322CD0AF3BD36D5D91B1867ED26","ajopnjidmegmdimjlfnijceegpefgped":"0418AB331B46CFB24C979A5FAA69CD74794D0594FA432F8DF60E1DEE80FC21D3","aohghmighlieiainnegkcijnfilokake":"612B14474CF1111D73B1D3100BD0313CB5297D6356A1FF2986ABFBD61E94C3AA","apdfllckaahabafndbhieahigkjlhalf":"17B36F2B37096E905396A39E4F3D46220EAD3CF624A2335364908A4CF2D4BFD1","bepbmhgboaologfdajaanbcjmnhjmhfn":"29E66963E9C0621892C2B265321DB3E0F3763B465633632316AC2EC64BF4BAB9","blpcfgokakmgnkcojhhkbfbldkacnbeo":"30369FB0ECF3737470E26607E48A12C39FA27043422D66D2BDB79F35C2380C8B","cfhdojbkjhnklbpkdaibdccddilifddb":"18C36E57D255C0C20B42AEF123735971BFDB339B9205293BD73B5DEBF11EF674","coobgpohoikkiipiblmjeljniedjpjpf":"F8790675C10D74E6B10D44CF11790617B6138A4F87B0CAEFA8962D226446AA23","eemcgdkfndhakfknompkggombfjjjeno":"FFC3E3F764805CB7B76FFDF056952FCBEFFE73FAF0871EEA053B9BFCD630CE2A","ennkphjdgehloodpbhlhldgbnhmacadg":"B4156CBADE335DC4F57E738A7A6C0A04FCFBA5D9DAC40C2F5DFCCA32A329A046","felcaaldnbdncclmgdcncolpebgiejap":"5DD355D7BA3FE51511CC04449331EBBD4D041F4DFD64010B753F7F9572587C73","gfdkimpbcpahaombhbimeihdjnejgicl":"14214312A512CBB04DB6442BA566097989C6C7457AF91C53B2251696AAB54E71","kmendfapggjehodndflmmgagdbamhnfd":"7F7770CAA6BEF19D0A46469B86FDB6EB9A139625AC6C169999C749FE4D4EA1C0","mfehgcgbbipciphmccgaenjidiccnmng":"DC9165B2FD322B2AF4A6542C71A3634C6302F312E0BC361615ADE516661B5671","mgndgikekgjfcpckkfioiadnlibdjbkf":"53315ACE878015174EE6EEE925242296231BFAD01AD6FED1DB0E3314FAF0575D","mhjfbmdgcfjbbpaeojofohoefgiehjai":"64BF67F0E6AD6A5075AB1F84E59D5D086EFA66E02605F8D5E0CB7916C303C66A","neajdppkdcdipfabeoofebfddakdcjhd":"0B25E3FF52F690717593AF6F22BC5CA76A8A1A4E93B2705CF290D9C2AFF37C6B","nkeimhogjdpnpccoofpliimaahmaaome":"20DE244E2F134C059AA9B4F2E1D9EC8114D119756267E0FAD9A280C401B9305E","nmmhkkegccagdldgiimedpiccmgmieda":"86E164C75C3E236E2D91CF00E23124C13F1C3400CCFC7E4EEF0D50393BEB51DC","pafkbggdmjlpgkdkcbjmhmfcdpncadgh":"8BA217F32F6EFC3984A9088FE241DAC683BF280D2BF87C16AD0310F3A3ED696F","pjkljhegncpnkpknbcohdijeoejaedia":"D14A1811742620A1C1DC5FFC4D52B50A27C2D266212ABE78D86798C984EC02AE"}},"google":{"services":{"last_username":"FA0534FC2A673AC1740012AF7684FDF25834CEBB0D528B798ED191A22CE3A142","username":"6E184D31882E577CA4D1F9A6306DCD7663A4CAA5D41787FFA42466749266E623"}},"homepage":"B18C0A6A6832DE67E73646CB9F038A1939C3C22F057E62FB2FE19A2E4F160FF0","homepage_is_newtabpage":"0EC25EEB5D0549160824BF957694D4F9DE5CBE453D9566C0A6312CEE3F4684AE","pinned_tabs":"506562A8B5F7E399592A67A2749ADE6012A4297C8434D8D33DC9D3F0EA4440F4","prefs":{"preference_reset_time":"72246F915DA1DA791BB208C550E8DCE83C7BC7DAFA764CC8A9DD553CFBA1B76C"},"profile":{"reset_prompt_memento":"64F2D3668DA5F954465B7596F964E674519B87BAA9796E99FA763C6DA01C5BF3"},"safebrowsing":{"incidents_sent":"6B5178BA30A4B2661C631E14564911FC7B7D857339424D93BF1D895B3A560DE4"},"search_provider_overrides":"333751D9C72CA457C18245C22686CE3BAD8F07DF6C35AD76A18C913271BB437E","session":{"restore_on_startup":"FA8CA70342D42A8E3B881E170256AF346027E31FC26023FEF2F4EDBB6A696C70","startup_urls":"137BC03136BEA0670D5B8BBDA774BDAB282B5F86A045B3AB390DAF8B9FC13696"},"software_reporter":{"prompt_reason":"78471D3666F10DC8683AB36E4B15FECFC5FFD5E32BB5F49F7C3C2B393FC68626","prompt_seed":"A11F1B4DB21CAEB7D91CCE039DD9BC6E648BDE82504AFE0F8856668DFB23CEDA","prompt_version":"3A7903A81088BF47FD853C1FB535616EC513310C07176FA54C6A422E4D5053AF"},"sync":{"remaining_rollback_tries":"9AF40C5E9D3AAA8A54D9875C17F9CFD4978DF53050F57B1A19DAB489BB1CBFBA"}},"super_mac":"DFBC9B85907D9A3F5A36275FD6105E00C48F9A7D2B3527813918B9BD9B7BD348"},"session":{"restore_on_startup":4,"startup_urls":["https://twitter.com/"]}} ==== Chromium Fix ====================== C:\Users\sjors\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.re-markit00.re-markit.co_0.localstorage deleted successfully C:\Users\sjors\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.re-markit00.re-markit.co_0.localstorage-journal deleted successfully C:\Users\sjors\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.re-markit00.re-markit.co_0.localstorage deleted successfully C:\Users\sjors\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.re-markit00.re-markit.co_0.localstorage-journal deleted successfully ==== Set IE to Default ====================== Old Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://www.google.com" New Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://www.google.com" ==== All HKCU SearchScopes ====================== HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" {012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}" {0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC" ==== Reset Google Chrome ====================== C:\Users\sjors\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully C:\Users\sjors\AppData\Local\Google\Chrome\User Data\Default\Preferences.bad was reset successfully C:\Users\sjors\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences was reset successfully C:\Users\Gast\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully C:\Users\sjors\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully C:\Users\sjors\AppData\Local\Google\Chrome\User Data\Default\Web Data-journal was reset successfully ==== Empty IE Cache ====================== C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Gast\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Gast\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully C:\Users\sjors\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\sjors\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully ==== Empty FireFox Cache ====================== No FireFox Cache found ==== Empty Chrome Cache ====================== C:\Users\Gast\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully C:\Users\sjors\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully ==== Empty All Flash Cache ====================== Flash Cache Emptied Successfully ==== Empty All Java Cache ====================== Java Cache cleared successfully ==== C:\zoek_backup content ====================== C:\zoek_backup (files=1682 folders=355 241873015 bytes) ==== Empty Temp Folders ====================== C:\Users\Default\AppData\Local\Temp emptied successfully C:\Users\Default User\AppData\Local\Temp emptied successfully C:\Users\Gast\AppData\Local\Temp emptied successfully C:\Users\sjors\AppData\Local\Temp will be emptied at reboot C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully C:\Windows\Temp will be emptied at reboot ==== After Reboot ====================== ==== Empty Temp Folders ====================== C:\Windows\Temp successfully emptied C:\Users\sjors\AppData\Local\Temp successfully emptied ==== Empty Recycle Bin ====================== C:\$RECYCLE.BIN successfully emptied ==== EOF on di 23-06-2015 at 11:22:24,35 ======================