Zoek.exe v5.0.0.1 Updated 31-December-2015 Tool run by Aziza on wo 16-03-2016 at 11:11:45,53. Microsoft Windows 10 Home 10.0.10586 x64 Running in: Normal Mode Internet Access Detected Launched: C:\Users\Aziza\Downloads\zoek (1).exe [Scan all users] [Script inserted] ==== Older Logs ====================== C:\zoek-results2016-03-16-094202.log 132787 bytes ==== Empty Folders Check ====================== C:\Users\Aziza\AppData\Local\ActiveSync deleted successfully ==== Deleting CLSID Registry Keys ====================== ==== Deleting CLSID Registry Values ====================== ==== Deleting Services ====================== ==== Deleting Files \ Folders ====================== C:\Users\Aziza\AppData\Roaming\AVAST Software deleted C:\ProgramData\CheckPoint deleted ==== Folders Found ====================== 2015-08-31 11:43:41 2016-03-03 21:26:33 -------- d-----w- C:\OEM\Preload\APP\AVASTSECURELINE 2016-03-03 20:23:44 2016-03-03 20:23:44 -------- d-----w- C:\Windows\WinSxS\x86_avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_1d37a43bbfe1dc9c 2015-08-31 10:50:47 2016-03-03 20:24:32 -------- d-----w- C:\Windows.old\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software 2016-03-03 20:47:40 2016-03-03 20:47:40 -------- d-----w- C:\Windows.old\Windows\WinSxS\x86_avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_1d37a43bbfe1dc9c 2016-03-16 10:27:41 2016-03-16 10:27:41 -------- d---a-w- C:\zoek_backup\C_Users_Aziza_AppData_Roaming_AVAST Software 2016-03-03 13:08:31 2016-03-15 14:34:19 -------- d-----w- C:\Users\Aziza\AppData\Local\Microsoft\InstallAgent\Checkpoints 2016-03-16 10:27:41 2016-03-16 10:27:41 -------- d---a-w- C:\zoek_backup\C_ProgramData_CheckPoint ==== Files Found ====================== --- C:\OEM\Preload\APP\AVASTSECURELINE\avast_secureline_setup.exe --- Company: AVAST Software File Description: Avast SecureLine Installer File Version: 1.0.239.4 Product Name: Avast SecureLine Copyright: © 2014 AVAST Software Original Filename: File type: ----a-w- File size: 22300632 Created time: 2015-08-31 11:43:41 Modified time: 2015-05-22 04:39:35 MD5: 1439AF415E265555FAA9621D702A8847 SHA1: A46828661B93EAF8889F9A0253C1CC0FC76E170C --- C:\Windows\WinSxS\Manifests\x86_avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_1d37a43bbfe1dc9c.cat --- Company: ------ File Description: ------ File Version: ------ Product Name: ------ Copyright: ------ Original Filename: ------ File type: ----a-w- File size: 9249 Created time: 2016-03-03 20:23:44 Modified time: 2016-03-03 20:23:44 MD5: F181BD5627947025E1254E2F786AE2BE SHA1: 26255562307B9F89B744F3F6A5CA115BDD1B89FE --- C:\Windows\WinSxS\Manifests\x86_avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_1d37a43bbfe1dc9c.manifest --- Company: ------ File Description: ------ File Version: ------ Product Name: ------ Copyright: ------ Original Filename: ------ File type: ------w- File size: 2376 Created time: 2016-03-03 20:23:44 Modified time: 2016-03-03 20:23:44 MD5: 176B3BE4AE48CC8A7FACBB8E89A2131E SHA1: E2DF6022A299B523C194D017A887C00EDB4567AB --- C:\Windows\WinSxS\Manifests\x86_policy.11.0.avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_b2556b4035446b41.cat --- Company: ------ File Description: ------ File Version: ------ Product Name: ------ Copyright: ------ Original Filename: ------ File type: ----a-w- File size: 9249 Created time: 2016-03-03 20:24:04 Modified time: 2016-03-03 20:24:04 MD5: 84E52D0B42207B15BC16A36298AE4110 SHA1: 7ADAEA12A8458CEEDC9D8742B45D5BE9C8D0F5BC --- C:\Windows\WinSxS\Manifests\x86_policy.11.0.avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_b2556b4035446b41.manifest --- Company: ------ File Description: ------ File Version: ------ Product Name: ------ Copyright: ------ Original Filename: ------ File type: ------w- File size: 608 Created time: 2016-03-03 20:24:04 Modified time: 2016-03-03 20:24:04 MD5: E479732F7B82161E923B0DF5B5D09C59 SHA1: F50646154ED92D53A8328B7DCB23E5717EEF249F --- C:\Windows.old\Windows\WinSxS\Manifests\x86_avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_1d37a43bbfe1dc9c.cat --- Company: ------ File Description: ------ File Version: ------ Product Name: ------ Copyright: ------ Original Filename: ------ File type: ----a-w- File size: 9249 Created time: 2016-03-03 21:33:36 Modified time: 2016-03-03 21:33:36 MD5: F181BD5627947025E1254E2F786AE2BE SHA1: 26255562307B9F89B744F3F6A5CA115BDD1B89FE --- C:\Windows.old\Windows\WinSxS\Manifests\x86_avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_1d37a43bbfe1dc9c.manifest --- Company: ------ File Description: ------ File Version: ------ Product Name: ------ Copyright: ------ Original Filename: ------ File type: ------w- File size: 2376 Created time: 2015-08-31 10:50:47 Modified time: 2016-03-03 21:33:36 MD5: 176B3BE4AE48CC8A7FACBB8E89A2131E SHA1: E2DF6022A299B523C194D017A887C00EDB4567AB --- C:\Windows.old\Windows\WinSxS\Manifests\x86_policy.11.0.avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_b2556b4035446b41.cat --- Company: ------ File Description: ------ File Version: ------ Product Name: ------ Copyright: ------ Original Filename: ------ File type: ----a-w- File size: 9249 Created time: 2016-03-03 21:33:45 Modified time: 2016-03-03 21:33:45 MD5: 84E52D0B42207B15BC16A36298AE4110 SHA1: 7ADAEA12A8458CEEDC9D8742B45D5BE9C8D0F5BC --- C:\Windows.old\Windows\WinSxS\Manifests\x86_policy.11.0.avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_b2556b4035446b41.manifest --- Company: ------ File Description: ------ File Version: ------ Product Name: ------ Copyright: ------ Original Filename: ------ File type: ------w- File size: 608 Created time: 2015-08-31 10:50:47 Modified time: 2016-03-03 21:33:45 MD5: E479732F7B82161E923B0DF5B5D09C59 SHA1: F50646154ED92D53A8328B7DCB23E5717EEF249F --- C:\$WINDOWS.~BT\Sources\Rollback\checkpoint.info --- Company: ------ File Description: ------ File Version: ------ Product Name: ------ Copyright: ------ Original Filename: ------ File type: ----a-w- File size: 512 Created time: 2016-03-03 19:02:51 Modified time: 2016-03-03 20:18:13 MD5: 67033176C4DE4066D4872B9FDC21FB1B SHA1: 4849526A92B483F9A0BD09CA86BD7F2721376D6B --- C:\Windows\Panther\Rollback\checkpoint.info --- Company: ------ File Description: ------ File Version: ------ Product Name: ------ Copyright: ------ Original Filename: ------ File type: -c--a-w- File size: 512 Created time: 2016-03-03 19:02:51 Modified time: 2016-03-03 20:18:13 MD5: 67033176C4DE4066D4872B9FDC21FB1B SHA1: 4849526A92B483F9A0BD09CA86BD7F2721376D6B ==== Firefox Start and Search pages ====================== ProfilePath: C:\Users\Aziza\AppData\Roaming\Mozilla\Firefox\Profiles\elijp0o8.default user_pref("browser.startup.homepage", "https://www.google.nl/?gws_rd=ssl"); user_pref("browser.search.defaultenginename", "Google"); ==== Firefox Extensions ====================== ProfilePath: C:\Users\Aziza\AppData\Roaming\Mozilla\Firefox\Profiles\elijp0o8.default - KPN Servicetool - %ProfilePath%\extensions\{594657B4-413A-41D0-8F85-A6D3F35C9BDF} - Nederlands NL Language Pack - %ProfilePath%\extensions\langpack-nl@firefox.mozilla.org.xpi AppDir: C:\Program Files (x86)\Mozilla Firefox - Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} ==== Firefox Plugins ====================== Profilepath: C:\Users\Aziza\AppData\Roaming\Mozilla\Firefox\Profiles\elijp0o8.default F627791AB91E01A9829A8D9B6E024D52 - C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_21_0_0_182.dll - Shockwave Flash ==== Set IE to Default ====================== Old Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://acer15.msn.com/?pc=ACTE" New Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://acer15.msn.com/?pc=ACTE" ==== All HKLM and HKCU SearchScopes ====================== HKLM\SearchScopes "DefaultScope"="{FDC0098C-4D41-487E-869A-D88AAFDACD58}" HKLM\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC HKLM\SearchScopes\{111C5162-7D27-4655-905F-BCCD3166F088} - http://www.bing.com/search?q={searchTerms}&form=PRACE1&src=IE11TR&pc=ACTE HKLM\SearchScopes\{FDC0098C-4D41-487E-869A-D88AAFDACD58} - http://www.bing.com/search?q={searchTerms}&form=PRACE1&src=IE11TR&pc=ACTE HKLM\Wow6432Node\SearchScopes "DefaultScope"="{FDC0098C-4D41-487E-869A-D88AAFDACD58}" HKLM\Wow6432Node\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC HKLM\Wow6432Node\SearchScopes\{111C5162-7D27-4655-905F-BCCD3166F088} - http://www.bing.com/search?q={searchTerms}&form=PRACE1&src=IE11TR&pc=ACTE HKLM\Wow6432Node\SearchScopes\{FDC0098C-4D41-487E-869A-D88AAFDACD58} - http://www.bing.com/search?q={searchTerms}&form=PRACE1&src=IE11TR&pc=ACTE HKCU\SearchScopes "DefaultScope"="{012E1000-F331-11DB-8314-0800200C9A66}" HKCU\SearchScopes\{012E1000-F331-11DB-8314-0800200C9A66} - http://www.google.com/search?q={searchTerms} HKCU\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02 HKCU\SearchScopes\{111C5162-7D27-4655-905F-BCCD3166F088} - No_Url_Value HKCU\SearchScopes\{FDC0098C-4D41-487E-869A-D88AAFDACD58} - No_Url_Value ==== Empty IE Cache ====================== C:\WINDOWS\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Aziza\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\Users\Aziza\AppData\Local\Microsoft\Windows\INetCache\Low\Content.IE5 emptied successfully C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\WINDOWS\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\Users\Aziza\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully C:\Users\Aziza\AppData\Local\Microsoft\Windows\INetCache\Low\IE emptied successfully C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully ==== Empty FireFox Cache ====================== No FireFox Cache found ==== Empty Chrome Cache ====================== No Chrome User Data found ==== Empty All Flash Cache ====================== No Flash Cache Found ==== Empty All Java Cache ====================== Java Cache cleared successfully ==== C:\zoek_backup content ====================== C:\zoek_backup (files=918 folders=329 402034124 bytes) ==== Empty Temp Folders ====================== C:\WINDOWS\Temp will be emptied at reboot ==== After Reboot ====================== ==== Empty Temp Folders ====================== C:\WINDOWS\Temp successfully emptied C:\Users\Aziza\AppData\Local\Temp successfully emptied ==== Empty Recycle Bin ====================== C:\$RECYCLE.BIN successfully emptied ==== EOF on wo 16-03-2016 at 11:35:08,88 ======================