Zoek.exe v5.0.0.0 Updated 04-May-2015 Tool run by Natalie on ma 20/07/2015 at 19:57:34,41. Microsoft® Windows Vista™ Home Premium 6.0.6002 Service Pack 2 x86 Running in: Normal Mode Internet Access Detected Launched: C:\Users\Natalie\Desktop\zoek.exe [Scan all users] [Script inserted] ==== System Restore Info ====================== 20/07/2015 20:00:23 Zoek.exe System Restore Point Created Successfully. ==== Empty Folders Check ====================== C:\Program Files\MSXML 4.0 deleted successfully C:\PROGRA~2\AOL deleted successfully C:\PROGRA~2\Symantec deleted successfully ==== Deleting CLSID Registry Keys ====================== HKEY_USERS\S-1-5-21-3312448686-1002137660-2220588962-1000\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233} deleted successfully HKEY_USERS\S-1-5-21-3312448686-1002137660-2220588962-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233} deleted successfully HKEY_USERS\S-1-5-21-3312448686-1002137660-2220588962-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{95B7759C-8C7F-4BF1-B163-73684A933233} deleted successfully HKEY_USERS\S-1-5-21-3312448686-1002137660-2220588962-1000\Software\Microsoft\Internet Explorer\SearchScopes\{9F489DCC-9873-4807-B59F-A15D807449E7} deleted successfully HKEY_CLASSES_ROOT\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9F489DCC-9873-4807-B59F-A15D807449E7} deleted successfully ==== Deleting CLSID Registry Values ====================== ==== Deleting Services ====================== HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WtuSystemSupport deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\vToolbarUpdater18.7.0 deleted successfully ==== Deleting Files \ Folders ====================== C:\Program Files\Video-Saver deleted C:\Windows\Tasks\Video-Saver update.job deleted C:\Windows\system32\Tasks\Video-Saver update deleted C:\Users\Natalie\AppData\Local\AVG Web TuneUp deleted C:\PROGRA~2\APN deleted C:\PROGRA~2\AVG Web TuneUp deleted C:\PROGRA~2\AVG Security Toolbar deleted C:\PROGRA~2\AVG Secure Search deleted "C:\Program Files\AVG Web TuneUp\avgcefrend.exe" deleted "C:\Program Files\AVG Web TuneUp\icudt.dll" deleted "C:\Program Files\AVG Web TuneUp\libcef.dll" deleted "C:\Program Files\AVG Web TuneUp\vprot.exe" deleted "C:\Program Files\AVG Web TuneUp\avgcefrend.exe" deleted "C:\Program Files\AVG Web TuneUp\icudt.dll" deleted "C:\Program Files\AVG Web TuneUp\libcef.dll" deleted "C:\Program Files\AVG Web TuneUp\vprot.exe" deleted "C:\Program Files\AVG Web TuneUp\locales\en-US.pak" deleted "C:\Program Files\AVG Web TuneUp\locales\en-US.pak" deleted "C:\Program Files\Common Files\AVG Secure Search\DNTInstaller\18.7.0\avgdttbx.dll" deleted "C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\18.7.0\log4cplusU.dll" deleted "C:\Program Files\AVG Web TuneUp" deleted "C:\Program Files\AVG Web TuneUp" deleted "C:\Program Files\Common Files\AVG Secure Search" deleted "C:\Program Files\AVG Web TuneUp\locales" deleted "C:\Program Files\AVG Web TuneUp\locales" deleted "C:\Program Files\Common Files\AVG Secure Search\DNTInstaller" deleted "C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater" deleted "C:\Program Files\Common Files\AVG Secure Search\DNTInstaller\18.7.0" deleted "C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\18.7.0" deleted ==== Firefox Extensions Registry ====================== [HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions] "belgiumeid@eid.belgium.be"="C:\Program Files\Mozilla Firefox\extensions\belgiumeid@eid.belgium.be" [13/07/2015 22:35] [HKEY_CURRENT_USER\Software\Mozilla\Firefox\Extensions] "{1962084f-3e91-4432-81ab-73d394b9e934}"="C:\Program Files\Video-Saver\150.xpi" [] ==== Chromium Look ====================== Google Chrome Version: 43.0.2357.134 HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions capekcnhbegaapfdadcjikcnnebplepa - C:\Program Files\Video-Saver\150.crx[] Google Drive - Natalie\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf YouTube - Natalie\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo selector is not a valid CSS selector - Natalie\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb AVG Web TuneUp - Natalie\AppData\Local\Google\Chrome\User Data\Default\Extensions\chfdnecihphmhljaaejmgoiahnihplgn Google Search - Natalie\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf Google Wallet - Natalie\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda Gmail - Natalie\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia ==== Chromium Startpages ====================== C:\Users\Natalie\AppData\Local\Google\Chrome\User Data\Default\Preferences 0F8D748354475DAEFAA5843C52E8B0363222441D9F72A7D50EA261","search_url":"88B8485F96EFD1D01758FCA8980DBCF40276D61B47DF7B385A9046618C191015"},"default_search_provider_data":{"template_url_data":"55F82028F5CF167DE2DF121023AEEF845E63106F3DBA6A2B2DE4EA41E74C5070"},"extensions":{"settings":{"ahfgeienlihckogmohjhadlkjgocpleb":"51F720CD89C20123C55F7B92650F87269E179FFA1CBCFB0303EA4E0E592BF24F","apdfllckaahabafndbhieahigkjlhalf":"AECFA4B351DE4E06ECBCEC0BD30CB9EB582030F836A1BFEDB91EFABB9994B71A","bepbmhgboaologfdajaanbcjmnhjmhfn":"50C780BA918997A0DBEE69B7B704C127891684933BFC383566140D2204719ACD","blpcfgokakmgnkcojhhkbfbldkacnbeo":"CD111091C9CC429EA78BF0CF592DC5C31667B37E4A951515EC462200DA5D5CB5","capekcnhbegaapfdadcjikcnnebplepa":"22A1BF5FEBEC515855907EFF73558A1F3DB313543F1D8D369361A5ABA64655B5","cfhdojbkjhnklbpkdaibdccddilifddb":"A152D04F21A7AA2FBABF98F210264ADFF33F99CEC7230AF2FBB721BDB4B41D22","chfdnecihphmhljaaejmgoiahnihplgn":"DC6805CD0C03E40E9B7263A992DF345B04AB0DE3B89F4E42CF91DDACD712ECFD","coobgpohoikkiipiblmjeljniedjpjpf":"C8B499E7018EC7AA7F0F774CCF121AFCE94F7ECE940D80A1326ED4C19A1B41AA","eemcgdkfndhakfknompkggombfjjjeno":"2DB64FA42531E124A4DE7E125DC3E3C94837A176E28B9BDA6B9C27A514ABE50F","ennkphjdgehloodpbhlhldgbnhmacadg":"84E9E8A79A54EC1987D1C14EEAADFB3BC41ED04CF0AA2E60B14514DEBCE76877","gfdkimpbcpahaombhbimeihdjnejgicl":"7C4085234B61C4EEE335FF83CC1524C3C4976A35B4D88B8DBEF724EF3FF6FEB6","kmendfapggjehodndflmmgagdbamhnfd":"85D8C35539066D161144916F7C26F27BAF243BD513254CBE89FA614260904E3B","mfehgcgbbipciphmccgaenjidiccnmng":"4E9511255E3BC3F76B8B090BDF6FC58A9B202D68C646B03FBD199EC1361CB750","mgndgikekgjfcpckkfioiadnlibdjbkf":"C132FB4E9A8F70E78738CE65671E5A1344818791B5B0CD0A116D5DE679D3F576","mhjfbmdgcfjbbpaeojofohoefgiehjai":"0B035C13C9FD411406E6AA2A244BC5509EDAF32373EE778E94EAC5AF04F2DEC8","neajdppkdcdipfabeoofebfddakdcjhd":"21AEED2E97F8F80BD5131BFC50592592757FA779BCF0891EAE394AE50B4461CA","nkeimhogjdpnpccoofpliimaahmaaome":"5A9B1878DA94B34B943D7D2A54CF32F93E5DBFE3A60CA579212CCB0434364FD5","nmmhkkegccagdldgiimedpiccmgmieda":"A320A8FA19F7B7B74C9F0096EAC09A7F17DB7FB3519CBAA21DEE0D0FCC6BC50B","pafkbggdmjlpgkdkcbjmhmfcdpncadgh":"9A84BF3B1DBB5C3A4D9378B522DAA0105B4328FA4AAFF350B98BAA4C7882383B","pjkljhegncpnkpknbcohdijeoejaedia":"75D7586A8CFE54C8F37405A3D8A91ED6C3DA67EAE91F012B5DD42F6A7B903AB6"}},"google":{"services":{"last_username":"54E575F3266985F3D04B6A7C854FB405785C4F465ACF044B9F3B5C81AD53D67D","username":"5EE99CECCFE2FCF0938AB3628002AE91A92C5ADBD65C65B009257A24BA653BA9"}},"homepage":"19C97C04D3EB0EE69595CCABC9B944FECB4AEAE74091566958C4C2EBF6082437","homepage_is_newtabpage":"9059689B8F110AD4D480557B018B67EAD18CC0A2E3560F8F4CF1A88E7782744A","pinned_tabs":"34474EA728D8643BBBD59BE04B884CEFA84FA668CC62B93DD67ED811CC61D0B6","prefs":{"preference_reset_time":"2ECA286A9B9F9C66EEB4B3A3F77DC7E3E7B471CE884CDCB56A1EA1D5374C305E"},"profile":{"reset_prompt_memento":"FDBF99DE97F459198112E1890797909F146F2D13B6CD6A28DF8BC0E8FAE96395"},"safebrowsing":{"incidents_sent":"7B6ACA3F08E3F8C7E5877D4161F8C10481A0B259E878C93B7F1EFB381FE63883"},"search_provider_overrides":"051086216D48C5F35AB5BB5C12215A27E541FC21A05CCC1CEE5147BC81170C72","session":{"restore_on_startup":"E4001D6CBC46F47A97A5D4341DBC03FA18E0B8CF7607BD270656EA815F7F89FD","startup_urls":"D35676CE68EEFF299908922281A957C3CE2BBB54ED19489425386B57EC0347FC"},"software_reporter":{"prompt_reason":"CC2BDECA44A4F8CEACB2BDEC9112541CEE4BFB32489712E148F30CDE083B0E35","prompt_seed":"D1057FBAA5EF836284C7EDF1C35B3DDBA38DF69ADE2EA376DA1F7AA422ADB4EB","prompt_version":"82BA93E44C9959B8873CDBE8FD0DC47FE4C2245972439510336401EB38CAB38D"},"sync":{"remaining_rollback_tries":"1DEEC73AD3AD1B7BD8CF5AA7121BA53427DAC967F5D71F0DB747F85E0C757E75"}},"super_mac":"4CBF9830DC2E564F3011CB09C72E836EC949C778CB80CA8170304A6FDCE30E87"},"session":{"restore_on_startup":4,"startup_urls":["http://www.turntubelist.com/"]}} ==== Chromium Fix ====================== C:\Users\Natalie\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_www.superfish.com_0.localstorage deleted successfully C:\Users\Natalie\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_www.superfish.com_0.localstorage-journal deleted successfully C:\Users\Natalie\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.superfish.com_0.localstorage deleted successfully C:\Users\Natalie\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.superfish.com_0.localstorage-journal deleted successfully C:\Users\Natalie\AppData\Local\Google\Chrome\User Data\Default\Extensions\chfdnecihphmhljaaejmgoiahnihplgn deleted successfully C:\Users\Natalie\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_chfdnecihphmhljaaejmgoiahnihplgn_0.localstorage deleted successfully C:\Users\Natalie\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_chfdnecihphmhljaaejmgoiahnihplgn_0.localstorage-journal deleted successfully ==== Set IE to Default ====================== Old Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="https://mysearch.avg.com/?cid={1A03D052-AB62-4572-8E95-B1267EF9E795}&mid=3a553015799047d38a23d16acd9efc5e-d82a494e421e3c865c1d0873c283b1d693e3a639&lang=nl&ds=AVG&coid=avgtbavg&cmpid=0715avt&pr=fr&d=2015-07-20 11:04:23&v=4.1.4.948&pid=wtu&sg=&sap=hp" "Default_Page_URL"="http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=nl_be&c=91&bd=Pavilion&pf=cnnb" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=nl_be&c=91&bd=Pavilion&pf=cnnb" "Default_Page_URL"="http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=nl_be&c=91&bd=Pavilion&pf=cnnb" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes] "DefaultScope"="{95B7759C-8C7F-4BF1-B163-73684A933233}" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}] not found New Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157" "Start Page"="http://www.google.com" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157" "Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes] "DefaultScope"="{012E1000-F331-11DB-8314-0800200C9A66}" ==== All HKCU SearchScopes ====================== HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes {012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}" {0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC" {5E0D11BD-8548-4325-AF6F-D30CBCF8F4F1} AOL Zoeken Url="http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=1547&query={searchTerms}&invocationType=tb50hpcnnbie7-nl-be" {662EA9F4-4001-4E65-8733-841618491485} Google Url="https://www.google.com/search?q={searchTerms}" {B3D8516A-CF3A-4052-BD18-6784164DA599} Kelkoo Url="http://nb.kelkoopartners.net/ctl/do/search?siteSearchQuery={searchTerms}&fromform=true&x=true&y=true&partner=hp&partnerId=96913938" ==== Reset Google Chrome ====================== C:\Users\Natalie\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully C:\Users\Natalie\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences was reset successfully C:\Users\Natalie\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully C:\Users\Natalie\AppData\Local\Google\Chrome\User Data\Default\Web Data-journal was reset successfully ==== Deleting CLSID Registry Keys ====================== ==== Deleting CLSID Registry Values ====================== HKEY_USERS\S-1-5-21-3312448686-1002137660-2220588962-1000\Software\Mozilla\Firefox\Extensions\{1962084f-3e91-4432-81ab-73d394b9e934} deleted successfully ==== Reset IE Proxy ====================== Value(s) before fix: "ProxyOverride"="*.local" "ProxyEnable"=dword:00000000 Value(s) after fix: "ProxyEnable"=dword:00000000 ==== Deleting Registry Keys ====================== HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\capekcnhbegaapfdadcjikcnnebplepa deleted successfully HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\AVG Web TuneUp deleted successfully ==== Empty IE Cache ====================== C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Natalie\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully C:\Users\Natalie\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Natalie\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot ==== Empty FireFox Cache ====================== No FireFox Profiles found ==== Empty Chrome Cache ====================== C:\Users\Natalie\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully ==== Empty All Flash Cache ====================== Flash Cache Emptied Successfully ==== Empty All Java Cache ====================== Java Cache cleared successfully ==== C:\zoek_backup content ====================== C:\zoek_backup (files=270 folders=82 87445510 bytes) ==== Empty Temp Folders ====================== C:\Users\Default\AppData\Local\Temp emptied successfully C:\Users\Default User\AppData\Local\Temp emptied successfully C:\Users\Natalie\AppData\Local\Temp will be emptied at reboot C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully C:\Windows\Temp will be emptied at reboot ==== After Reboot ====================== ==== Empty Temp Folders ====================== C:\Windows\Temp successfully emptied C:\Users\Natalie\AppData\Local\Temp successfully emptied ==== Empty Recycle Bin ====================== C:\$RECYCLE.BIN successfully emptied ==== Deleting Files / Folders ====================== "C:\Users\Natalie\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not found ==== EOF on ma 20/07/2015 at 20:39:31,82 ======================