Zoek.exe v5.0.0.0 Updated 04-May-2015 Tool run by fred on zo 30/08/2015 at 11:36:05,72. Microsoft Windows 7 Professional 6.1.7601 Service Pack 1 x86 Running in: Normal Mode Internet Access Detected Launched: C:\Users\fred\Desktop\zoek.exe [Scan all users] [Script inserted] ==== Older Logs ====================== C:\zoek-results2015-08-25-100533.log 26546 bytes C:\zoek-results2015-08-25-120714.log 381 bytes C:\zoek-results2015-08-26-132857.log 46377 bytes C:\zoek-results2015-08-28-175515.log 43463 bytes ==== Deleting CLSID Registry Keys ====================== ==== Deleting CLSID Registry Values ====================== ==== Deleting Services ====================== ==== Deleting Files \ Folders ====================== ==== Firefox Start and Search pages ====================== ProfilePath: C:\Users\fred\AppData\Roaming\Mozilla\Firefox\Profiles\p1l2hsr7.default user_pref("browser.startup.homepage", "http://www.msn.com/?pc=SK2M&ocid=SK2MDHP&osmkt=nl-be"); user_pref("browser.search.defaultenginename", "Bing "); user_pref("browser.search.selectedEngine", "Bing "); user_pref("keyword.URL", "http://www.bing.com/search?FORM=SK2MDF&PC=SK2M&q="); ==== Firefox Extensions Registry ====================== [HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions] "belgiumeid@eid.belgium.be"="C:\Program Files\Mozilla Firefox\extensions\belgiumeid@eid.belgium.be" [28/04/2015 17:57] ==== Firefox Extensions ====================== ProfilePath: C:\Users\fred\AppData\Roaming\Mozilla\Firefox\Profiles\p1l2hsr7.default - Undetermined - C:\Program Files\IObit Apps Toolbar\FF ProfilePath: C:\Users\fred\AppData\Roaming\TomTom\HOME\Profiles\i9noli0l.default - Map status indicator - C:\Program Files\TomTom HOME 2\xul\extensions\MapShare-status@tomtom.com - TomTom HOME default theme - C:\Program Files\TomTom HOME 2\xul\extensions\baseTheme@tomtom.com - Emulator - %ProfilePath%\extensions\Navcore.8.415.1240@tomtom.com - Emulator - %ProfilePath%\extensions\Navcore.9.510.1234792@tomtom.com AppDir: C:\Program Files\Mozilla Firefox - Belgium eID - %AppDir%\extensions\belgiumeid@eid.belgium.be ==== Firefox Plugins ====================== Profilepath: C:\Users\fred\AppData\Roaming\Mozilla\Firefox\Profiles\p1l2hsr7.default 6BEAD7859E8A087BE04556AB5A78855C - C:\Users\fred\AppData\Roaming\Mozilla\plugins\npo1d.dll - Google Talk Plugin Video Renderer 49D429EBF5305FC9ADD7545B7C914333 - C:\Users\fred\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll - Google Talk Plugin 0FFC7C7A12BD7B0465D97E7745287370 - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll - Adobe Acrobat A9E98D1FCB614713E87149FCBE8459F2 - C:\Program Files\Adobe\Reader 11.0\Reader\browser\nppdf32.dll - Adobe Acrobat 3B00376AE69AC2E815425E54DEBFF750 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll - Photo Gallery 15E298B5EC5B89C5994A59863969D9FF - C:\Windows\system32\npmproxy.dll - Microsoft® Windows® Operating System ==== Chromium Look ====================== Google Chrome Version: 44.0.2403.157 HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions lifbcibllhkdhoafpjfnlhfpfgnpldfl - C:\Program Files\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx[01/05/2015 11:17] HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\Extensions lmjegmlicamnimmfhcmpkclmigmmcbeh - No path found[] AdBlock - fred\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom ==== Chromium Startpages ====================== C:\Users\fred\AppData\Local\Google\Chrome\User Data\Default\Preferences "setting":1}},"ppapi_broker":{},"protocol_handlers":{},"push_messaging":{},"ssl_cert_decisions":{}},"pattern_pairs":{"*,*":{"per_plugin":{"npsitesafety.dll":1,"silverlight":1}},"[*.]java.com,*":{"plugins":1},"[*.]www.mobistar.be,*":{"popups":1},"[*.]www.voxopop.com,*":{"plugins":1},"https://[*.]mail.google.com:443,*":{"multiple-automatic-downloads":1},"https://[*.]plus.google.com:443,*":{"fullscreen":1},"https://[*.]www.youtube.com:443,*":{"fullscreen":1},"https://mail.google.com:443,*":{"notifications":1},"https://plus.google.com:443,https://plus.google.com:443":{"geolocation":1}},"plugin_whitelist":{"adobe-flash-player":false,"npsitesafety":{"dll":true},"silverlight":true},"pref_version":1},"created_by_version":"41.0.2272.89","exit_type":"Crashed","exited_cleanly":true,"gaia_info_picture_url":"https://lh6.googleusercontent.com/-KBwNKP0-YXM/AAAAAAAAAAI/AAAAAAAAB_s/mKq_2M7kZjM/s256-c/photo.jpg","gaia_info_update_time":"13085251519800921","icon_version":3,"managed_user_id":"","managed_users":{},"migrated_content_settings_exceptions":true,"migrated_default_content_settings":true,"migrated_default_media_stream_content_settings":true,"name":"Eerste gebruiker","password_manager_enabled":false,"per_host_zoom_levels":{}},"protection":{"macs":{}},"reverse_autologin":{"enabled":false},"savefile":{"default_directory":"C:\\Users\\fred\\Desktop"},"selectfile":{"last_directory":"C:\\Users\\fred\\Desktop"},"session":{"restore_on_startup_migrated":true,"startup_urls_migration_time":"13070569862007133"},"signin":{"signedin_time":"13072796624865858"},"spellcheck":{"dictionary":"en-GB"},"sync":{"acknowledged_types":["Bookmarks","Preferences","Passwords","Autofill Profiles","Autofill","Themes","Typed URLs","Extensions","Search Engines","Sessions","Apps","App settings","Extension settings","History Delete Directives","Dictionary","Favicon Images","Favicon Tracking","Device Info","Priority Preferences","Managed User Settings","Managed Users","Managed User Shared Settings","Articles","App List","WiFi Credentials","Managed User Whitelists","Tabs","Encryption keys"],"app_list":true,"app_settings":true,"apps":true,"autofill":true,"autofill_profile":true,"autofill_wallet":true,"bookmarks":true,"dictionary":true,"extension_settings":true,"extensions":true,"favicon_images":true,"favicon_tracking":true,"history_delete_directives":true,"keep_everything_synced":true,"managed_user_settings":true,"managed_user_shared_settings":true,"managed_user_whitelists":true,"managed_users":true,"memory_warning_count":362,"passwords":true,"preferences":true,"priority_preferences":true,"search_engines":true,"session_sync_guid":"session_syncN1bILSRTEZKhAciCStuoqA==","sessions":true,"shutdown_cleanly":true,"suppress_start":false,"tabs":true,"themes":true,"typed_urls":true},"sync_promo":{"user_skipped":true},"translate":{"enabled":true},"translate_accepted_count":{"be":0,"de":0,"en":1,"fr":0,"ru":0,"sk":2,"zh-TW":0},"translate_blocked_languages":["de","en","nl"],"translate_denied_count":{"be":2,"de":1,"en":0,"fr":7,"ru":1,"sk":0,"zh-TW":1},"translate_language_blacklist":["en"],"translate_last_denied_time":1.426165e+12,"translate_site_blacklist":["uk.groups.yahoo.com","uk.mg41.mail.yahoo.com","www.voxopop.com"],"translate_too_often_denied":true,"translate_whitelists":{"pl":"nl"},"zerosuggest":{"cachedresults":""}} fications.onShowSettings","runtime.onInstalled","runtime.onStartup","runtime.onSuspend","storage.onChanged"],"from_bookmark":false,"from_webstore":false,"incognito_content_settings":[],"incognito_preferences":{},"initial_keybindings_set":true,"install_time":"13085343696742666","location":5,"manifest":{"background":{"persistent":false,"scripts":["utility.js","cards.js","background.js"]},"description":"Integrates Google Now into Chrome.","icons":{"128":"images/icon128.png","16":"images/icon16.png","48":"images/icon48.png"},"key":"MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAkhqJr32OFD/bMXW4Md7jMfd7LbwHXVc6x5bBQG5U+dloofoxrICDR20yur/40mQ8O//0sS1b8srvbab1CRlSrxoNCr9T80NAkfzx0gHyVS+p1Zow+1FzLMu9PiGwwFyN80HIB7GI/dIa0wC9K/2OrrzcHEhVH96DacTtWQqjfDVtZPjT7Xwv23dgoWcpbkRC86jMJot3dmX9xnn0KzoVc9gDOHSIkBLbkkr6Sp3LGXCCM4L0DJgxdFwaLr5WBzgC3y5x0/wwPIwN4PtIaK3BhH6njlksfnKwwIJ9iRT41V4BqbWu4mszO/7VJ3HJyw2DBpIc2grU9ZRRxrV3fRQG4wIDAQAB","manifest_version":2,"name":"Google Now","oauth2":{"auto_approve":true,"scopes":["https://www.googleapis.com/auth/gcm","https://www.googleapis.com/auth/googlenow"]},"optional_permissions":["background"],"permissions":["alarms","gcm","identity","metricsPrivate","notifications","storage","tabs","webstorePrivate","*://*.google.com/*","*://*.gstatic.com/*","https://*.googleapis.com/chromenow/v1/*","https://*.googleapis.com/gcm/*","https://*.googleusercontent.com/*"],"version":"1.2.0.1"},"path":"C:\\Program Files\\Google\\Chrome\\Application\\44.0.2403.157\\resources\\google_now","preferences":{},"regular_only_preferences":{},"state":1,"was_installed_by_default":false,"was_installed_by_oem":false}}},"pinned_tabs":[],"protection":{"macs":{"browser":{"show_home_button":"1969C936E46E442EB012EB92EBD4357575A8674B7C090D57C6A1A1D3594A2828"},"default_search_provider":{"keyword":"4568854DA58F2C2ADA98CB37BBB1AD5C578C7A527093E8016A3FC94C551C2455","name":"19973E51387904FB81E24CAB611779BBF692050946D4F310EFFB819F8C5A0D46","search_url":"5F9DF3456776BFED92F10A341DFA2B530CB45D477422A56F48C4BB56B9E600E6"},"default_search_provider_data":{"template_url_data":"39220851C99DF540B99F69024C26959CFF2F02D0E688A0261710D10806E84A99"},"extensions":{"settings":{"ahfgeienlihckogmohjhadlkjgocpleb":"1C4B52306132021BD6D6E98FC78CE2ED0160E553C45738A5B57F85AF8948FF07","bepbmhgboaologfdajaanbcjmnhjmhfn":"3B55D7658C719273A5EC44F0BA3C41D4B2A5AF3E6CC12178095CD7B1C1A58F8D","eemcgdkfndhakfknompkggombfjjjeno":"3D1AB2A0914AF95D0BDA9366534B60A223EDE4949A7C2F5CB39D3085F264119C","ennkphjdgehloodpbhlhldgbnhmacadg":"EE76AAAFE662CD86FAFF6CD8620D34599E5A412AB01B20458C02B1563B5632DF","gfdkimpbcpahaombhbimeihdjnejgicl":"952D040AF42B7678483B4EF5B461B30A2B75A1FEAE5B15B9EDDE708C690AFEB8","kmendfapggjehodndflmmgagdbamhnfd":"9F56CCE3A087E8DA403ACDFC88B4ECEF4690CB6F93557AA76C08EEB8B8066DA6","lifbcibllhkdhoafpjfnlhfpfgnpldfl":"95116F6650251F11A5D67824310E43CE9738A4726C6B815B677FB607944ED6C6","lmjegmlicamnimmfhcmpkclmigmmcbeh":"009337C37C1F5B745E5D6CFC5E4B0FD0DFB3C7239C13162A24F8ECCA6524E8D0","mfehgcgbbipciphmccgaenjidiccnmng":"C006E666D2E9C0AB420C64FEE704BD5C6C83BB591B9379CBCDDD2158FEB4A693","mgndgikekgjfcpckkfioiadnlibdjbkf":"1088522C4ED9C46CA89D9CE26D3FD760B440299EB14609F35C70399E2BD0ED66","mhjfbmdgcfjbbpaeojofohoefgiehjai":"8298CD21BF3BC06E09B1BF08D12D42E586EF3AB730BD84E5B877B186C78D141D","neajdppkdcdipfabeoofebfddakdcjhd":"1E84F1FCDCC60CAB786D740870CD60BEFC277E3640CFB4F2EB4C897F026F4443","nkeimhogjdpnpccoofpliimaahmaaome":"41AE4D3632EAA7BC79C487D682E9DCA651D2F0FDEC2C0E29F2F2CB8C432CD31B","nmmhkkegccagdldgiimedpiccmgmieda":"D478190C114A1B5D7403DE8809182C8F7FBA40C3276D288EBB38CF48D7278961","pafkbggdmjlpgkdkcbjmhmfcdpncadgh":"74BABA213D26AB1A22A543B404747052EBA6482523A843DD166FFED8FAD79CB2"}},"google":{"services":{"account_id":"5D6C2185FA02D0B69669043B45F99C48F487577AD72D7BFA06C7A5AD042A3A02","last_username":"4158B8C75BED89225E9F49C2EEB2A21A242867BCA613FCCA198D24A17FF83A01","username":"31A0E66482BE9CCF240E909E365F65DB264C264A81900AD377CD5BABAC5F3D04"}},"homepage":"68CB534986BE226E4AD199F1E441472BB6605971BCA46DB5419D4EDD0FB0E741","homepage_is_newtabpage":"12BFFB5B91C2E9BA35686BCC4F9F9AECF48D93568F62E363C6529A3695B37468","pinned_tabs":"DB95EEC726C05A167DC85EBBA533331BC1E2480D16FC82977F8B4929811AF2C1","prefs":{"preference_reset_time":"A368A1D9E66C2CAE48B308710DFDE55F4AEC47734602E64290B11D1FA446DCF9"},"profile":{"reset_prompt_memento":"858DA79FACE4DB5BAB26E00A89800DE14C952A024BFF4D3B4C1BF09F51661457"},"safebrowsing":{"incidents_sent":"5DE9902B2A72BD9E1FD15FE16C6DA3741B5CE71E99BC3F54666C5B5648A44DFA"},"search_provider_overrides":"15A61BEC9642FFF6D2B8361CB375AC787E44CA9F5D7A0BBA22DF9E90BC362D74","session":{"restore_on_startup":"316A4710F4ABF9F19B64C1F189623BA7DF53A7A1B24A256368B28F89CB494083","startup_urls":"855C82CCB0D276980BCCDBF34BBB15C178F86D4A8781EDB01F8992649C9B40FB"},"software_reporter":{"prompt_reason":"D1BA9D6B95961E9285A115F3165B5578CAF6A69EB9CA8E7388EAFF6C192E5995","prompt_seed":"45702840C40CC8D22D0BFEDA0041CCB46E6D0E4011ADD0DFE20911C48E7864D1","prompt_version":"5705CA76BC0AC73C293212E6404D4C3FB5C13D41E4FA955AA3CE97DB8D974D2C"},"sync":{"remaining_rollback_tries":"BFFD50ED4CC136C820E4622131DDC029D71CCF75148459753503DBCF35BCDC97"}},"super_mac":"6768B8952B80E59C386D00D1EE726F6E16215C9B9AF59F4548C831E30F93C135"}} ==== Set IE to Default ====================== Old Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://www.standaard.be/" New Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://www.standaard.be/" ==== All HKCU SearchScopes ====================== HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes "DefaultScope"="{DE0A7B1E-E506-493E-814D-791E948C0259}" {012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}" {0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?FORM=SK2MDF&PC=SK2M&q={searchTerms}&src=IE-SearchBox" {DE0A7B1E-E506-493E-814D-791E948C0259} Google Url="http://www.google.be/search?hl=nl&q={searchTerms}&sourceid=ie8&rls=com.microsoft:{language}:{referrer:source}&ie={inputEncoding?}&oe={outputEncoding?}&rlz=1I7GGHP_nlBE519" ==== Reset Google Chrome ====================== C:\Users\fred\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully C:\Users\fred\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences was reset successfully C:\Users\fred\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences.bad was reset successfully C:\Users\fred\AppData\Roaming\Opera Software\Opera Stable\Preferences was reset successfully C:\Users\fred\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully C:\Users\fred\AppData\Local\Google\Chrome\User Data\Default\Web Data-journal was reset successfully C:\Users\fred\AppData\Roaming\Opera Software\Opera Stable\Web Data was reset successfully ==== Empty IE Cache ====================== C:\Users\fred\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\fred\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully ==== Empty FireFox Cache ====================== No FireFox Cache found ==== Empty Chrome Cache ====================== C:\Users\fred\AppData\Local\Opera Software\Opera Stable\Cache emptied successfully C:\Users\fred\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully ==== Empty All Flash Cache ====================== Flash Cache Emptied Successfully ==== Empty All Java Cache ====================== Java Cache cleared successfully ==== C:\zoek_backup content ====================== C:\zoek_backup (files=104 folders=53 50345738 bytes) ==== Empty Temp Folders ====================== C:\Users\Default\AppData\Local\temp emptied successfully C:\Users\Default User\AppData\Local\temp emptied successfully C:\Users\fred\AppData\Local\Temp will be emptied at reboot C:\Users\Public\AppData\Local\temp emptied successfully C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp will be emptied at reboot C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully C:\Windows\Temp will be emptied at reboot ==== After Reboot ====================== ==== Empty Temp Folders ====================== C:\Windows\Temp successfully emptied C:\Users\fred\AppData\Local\Temp successfully emptied ==== Empty Recycle Bin ====================== C:\$RECYCLE.BIN successfully emptied ==== Deleting Files / Folders ====================== "C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp\Low" not deleted ==== EOF on zo 30/08/2015 at 13:12:48,18 ======================