Zoek.exe v5.0.0.1 Updated 31-December-2015 Tool run by Daems Jonas on vr 27/05/2016 at 7:41:38,24. Microsoft Windows 10 Home 10.0.10586 x64 Running in: Normal Mode Internet Access Detected Launched: d:\Users\Daems Jonas\Downloads\zoek (3).exe [Scan all users] [Script inserted] ==== Older Logs ====================== C:\zoek-results2016-05-26-092856.log 30015 bytes C:\zoek-results2016-05-26-110534.log 111667 bytes ==== Empty Folders Check ====================== C:\Users\Daems Jonas\AppData\Local\ActiveSync deleted successfully C:\Users\Daems Jonas\AppData\Local\VirtualStore deleted successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\NetworkTiles deleted successfully ==== Deleting CLSID Registry Keys ====================== HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{933B95E2-E7B7-4AD9-B952-7AC336682AE3} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B2BC04DF-EFBD-409A-95CA-36874E5AB92A} deleted successfully HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{B2BC04DF-EFBD-409A-95CA-36874E5AB92A} deleted successfully HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{B2BC04DF-EFBD-409A-95CA-36874E5AB92A} deleted successfully HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{CA3A5461-96B5-46DD-9341-5350D3C94615} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{4BC8AD89-AC5F-4DBD-A38F-C355C7DD33D7} deleted successfully HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{1152F8E0-69DB-4935-AFC3-59F8A5A86A30} deleted successfully ==== Deleting CLSID Registry Values ====================== ==== Deleting Services ====================== ==== Registry Fix Code ====================== Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B2BC04DF-EFBD-409A-95CA-36874E5AB92A}] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store] "C:\\Windows\\Temp\\7zS1B42.tmp\\AVG-Secure-Search-Update.exe"=- [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store] "C:\\Windows\\Temp\\7zS53D0.tmp\\AVG-Secure-Search-Update.exe"=- [HKEY_USERS\S-1-5-18\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store] "C:\\Windows\\Temp\\7zS1B42.tmp\\AVG-Secure-Search-Update.exe"=- [HKEY_USERS\S-1-5-18\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store] "C:\\Windows\\Temp\\7zS53D0.tmp\\AVG-Secure-Search-Update.exe"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Avg\AV\Features] "fea_TuneUp"=- "fea_TuneUp__QTune"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\40EA4B76D8AD8E1478BFED7FF9DBB066] "fea_TuneUp"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\40EA4B76D8AD8E1478BFED7FF9DBB066] "fea_TuneUp__QTune"=- [-HKEY_LOCAL_MACHINE\SOFTWARE\Avg Secure Update] [-HKEY_LOCAL_MACHINE\SOFTWARE\Avg Secure Update\0216pi] [-HKEY_LOCAL_MACHINE\SOFTWARE\AVG Tuneup] [-HKEY_LOCAL_MACHINE\SOFTWARE\AVG Web TuneUp\Initialize\DSP] [-HKEY_LOCAL_MACHINE\SOFTWARE\AVG Web TuneUp\Initialize\HOSTS] [-HKEY_LOCAL_MACHINE\SOFTWARE\AVG Web TuneUp] [-HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\NativeMessagingHosts\avgsh] [-HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{933B95E2-E7B7-4AD9-B952-7AC336682AE3}\LocalServer32] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B2BC04DF-EFBD-409A-95CA-36874E5AB92A}\LocalServer32] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CA3A5461-96B5-46DD-9341-5350D3C94615}\LocalServer32] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94}\1.0\0\win32] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94}\1.0\HELPDIR] [-HKEY_USERS\S-1-5-18\Software\Avg Secure Update] [-HKEY_USERS\S-1-5-18\Software\Avg Secure Update\0516av] [-HKEY_USERS\S-1-5-18\Software\Avg Secure Update\0516tb] [-HKEY_LOCAL_MACHINE\SOFTWARE\AVG Tuneup] [-HKEY_LOCAL_MACHINE\SOFTWARE\AVG Web TuneUp\CH] [-HKEY_LOCAL_MACHINE\SOFTWARE\AVG Web TuneUp\FF] [-HKEY_LOCAL_MACHINE\SOFTWARE\AVG Web TuneUp\IE] [-HKEY_LOCAL_MACHINE\SOFTWARE\AVG Web TuneUp\Initialize\CONFIGXML] [-HKEY_LOCAL_MACHINE\SOFTWARE\AVG Web TuneUp\Initialize\CP] [-HKEY_LOCAL_MACHINE\SOFTWARE\AVG Web TuneUp\Initialize\DSP] [-HKEY_LOCAL_MACHINE\SOFTWARE\AVG Web TuneUp\Initialize\General] [-HKEY_LOCAL_MACHINE\SOFTWARE\AVG Web TuneUp\Initialize\HOSTS] [-HKEY_LOCAL_MACHINE\SOFTWARE\AVG Web TuneUp\Initialize\HP] [-HKEY_LOCAL_MACHINE\SOFTWARE\AVG Web TuneUp\Initialize\IGTB] [-HKEY_LOCAL_MACHINE\SOFTWARE\AVG Web TuneUp\Initialize\NT] [-HKEY_LOCAL_MACHINE\SOFTWARE\AVG Web TuneUp\Initialize\STATS] [-HKEY_LOCAL_MACHINE\SOFTWARE\AVG Web TuneUp] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1152F8E0-69DB-4935-AFC3-59F8A5A86A30}\Elevation] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1152F8E0-69DB-4935-AFC3-59F8A5A86A30}\LocalServer32] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1152F8E0-69DB-4935-AFC3-59F8A5A86A30}] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{4BC8AD89-AC5F-4DBD-A38F-C355C7DD33D7}\1.0\0\win32] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{4BC8AD89-AC5F-4DBD-A38F-C355C7DD33D7}\1.0\0\win64] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{4BC8AD89-AC5F-4DBD-A38F-C355C7DD33D7}\1.0\HELPDIR] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{66694099-FBD8-4A98-AB9F-F19EAB4144C0}\1.0\0\win32] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{66694099-FBD8-4A98-AB9F-F19EAB4144C0}\1.0\HELPDIR] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WtuServer.WtuServerObj] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WtuServer.WtuServerObj.1] [-HKEY_USERS\S-1-5-21-3437685781-3899522879-2098296170-1001\SOFTWARE\AVG Web TuneUp\Campaigns\0516av] [-HKEY_USERS\S-1-5-21-3437685781-3899522879-2098296170-1001\SOFTWARE\AVG Web TuneUp\Campaigns\0516tb] [-HKEY_USERS\S-1-5-21-3437685781-3899522879-2098296170-1001\SOFTWARE\AVG Web TuneUp\Campaigns] [-HKEY_USERS\S-1-5-21-3437685781-3899522879-2098296170-1001\SOFTWARE\AVG Web TuneUp\CH] [-HKEY_USERS\S-1-5-21-3437685781-3899522879-2098296170-1001\SOFTWARE\AVG Web TuneUp\DNT\Settings] [-HKEY_USERS\S-1-5-21-3437685781-3899522879-2098296170-1001\SOFTWARE\AVG Web TuneUp\DNT\Tabs] [-HKEY_USERS\S-1-5-21-3437685781-3899522879-2098296170-1001\SOFTWARE\AVG Web TuneUp\DNT] [-HKEY_USERS\S-1-5-21-3437685781-3899522879-2098296170-1001\SOFTWARE\AVG Web TuneUp\FF] [-HKEY_USERS\S-1-5-21-3437685781-3899522879-2098296170-1001\SOFTWARE\AVG Web TuneUp\IE] [-HKEY_USERS\S-1-5-21-3437685781-3899522879-2098296170-1001\SOFTWARE\AVG Web TuneUp] ==== Registry Fix Code x64 ====================== Windows Registry Editor Version 5.00 [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{933B95E2-E7B7-4AD9-B952-7AC336682AE3}\LocalServer32] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{B2BC04DF-EFBD-409A-95CA-36874E5AB92A}\LocalServer32] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{CA3A5461-96B5-46DD-9341-5350D3C94615}\LocalServer32] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94}\1.0\0\win32] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94}\1.0\HELPDIR] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{1152F8E0-69DB-4935-AFC3-59F8A5A86A30}\Elevation] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{1152F8E0-69DB-4935-AFC3-59F8A5A86A30}\LocalServer32] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{1152F8E0-69DB-4935-AFC3-59F8A5A86A30}] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\TypeLib\{4BC8AD89-AC5F-4DBD-A38F-C355C7DD33D7}\1.0\0\win32] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\TypeLib\{4BC8AD89-AC5F-4DBD-A38F-C355C7DD33D7}\1.0\0\win64] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\TypeLib\{4BC8AD89-AC5F-4DBD-A38F-C355C7DD33D7}\1.0\HELPDIR] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\TypeLib\{66694099-FBD8-4A98-AB9F-F19EAB4144C0}\1.0\0\win32] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\TypeLib\{66694099-FBD8-4A98-AB9F-F19EAB4144C0}\1.0\HELPDIR] ==== Deleting Files \ Folders ====================== C:\Program Files (x86)\AVG\Av\Tuneup deleted ==== Chromium Look ====================== ==== Set IE to Default ====================== Old Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://www.google.com" New Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://www.google.com" ==== All HKLM and HKCU SearchScopes ====================== HKLM\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" HKLM\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC HKLM\Wow6432Node\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" HKLM\Wow6432Node\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC HKCU\SearchScopes "DefaultScope"="{012E1000-F331-11DB-8314-0800200C9A66}" HKCU\SearchScopes\{012E1000-F331-11DB-8314-0800200C9A66} - http://www.google.com/search?q={searchTerms} HKCU\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02 ==== Empty IE Cache ====================== C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Daems Jonas\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\Users\Daems Jonas\AppData\Local\Microsoft\Windows\INetCache\Low\Content.IE5 emptied successfully C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Daems Jonas\AppData\Local\Microsoft\Windows\INetCache\Low\IE emptied successfully C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully C:\Users\Daems Jonas\AppData\Local\Microsoft\Windows\INetCache\IE\FPS9GDEO will be deleted at reboot ==== Empty FireFox Cache ====================== No FireFox Profiles found ==== Empty Chrome Cache ====================== C:\Users\Daems Jonas\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully ==== Empty All Flash Cache ====================== No Flash Cache Found ==== Empty All Java Cache ====================== No Java Cache Found ==== C:\zoek_backup content ====================== C:\zoek_backup (files=491 folders=151 225314256 bytes) ==== Empty Temp Folders ====================== C:\Windows\Temp will be emptied at reboot ==== After Reboot ====================== ==== Empty Temp Folders ====================== C:\Windows\Temp successfully emptied C:\Users\DAEMSJ~1\AppData\Local\Temp successfully emptied ==== Empty Recycle Bin ====================== C:\$RECYCLE.BIN successfully emptied ==== Deleting Files / Folders ====================== "C:\Users\Daems Jonas\AppData\Local\Microsoft\Windows\INetCache\IE\FPS9GDEO" not found ==== EOF on vr 27/05/2016 at 12:51:30,25 ======================