Zoek.exe v5.0.0.1 Updated 31-December-2015 Tool run by wendy_000 on wo 31/08/2016 at 15:02:04,46. Microsoft Windows 10 Home 10.0.10586 x64 Running in: Normal Mode Internet Access Detected Launched: C:\Users\wendy_000\AppData\Local\Microsoft\Windows\INetCache\IE\HEP0N15Z\zoek.exe [Scan all users] [Script inserted] ==== Older Logs ====================== C:\zoek-results2016-06-30-095904.log 6551 bytes C:\zoek-results2016-07-01-121753.log 43964 bytes C:\zoek-results2016-08-30-124904.log 153107 bytes ==== Empty Folders Check ====================== C:\Users\UpdatusUser\AppData\LocalLow deleted successfully C:\Users\wendy_000\AppData\Local\ActiveSync deleted successfully C:\Users\wendy_000\AppData\Local\NetworkTiles deleted successfully C:\Users\wendy_000\AppData\Local\VirtualStore deleted successfully C:\WINDOWS\serviceprofiles\Localservice\AppData\Local\SharedWiFi deleted successfully ==== Deleting CLSID Registry Keys ====================== ==== Deleting CLSID Registry Values ====================== ==== Deleting Services ====================== ==== Deleting Files \ Folders ====================== C:\Program Files (x86)\AVG not found "C:\Users\wendy_000\AppData\Local\Microsoft\Windows\INetCache\IE\N2GPY7X6\logo-avg[1].png" not found "C:\Windows\Prefetch\AVGUIRNA.EXE-398FB3DD.pf" not found C:\ProgramData\Avg deleted C:\ProgramData\AVG2015 deleted C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG Zen deleted C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_avgsvca.exe_81d410e5b0b6aa24580ae8ae9c17fd77228369_6e0b5e8a_104b73e9 deleted C:\Users\wendy_000\AppData\Local\Avg deleted C:\Users\wendy_000\AppData\Local\Avg2015 deleted C:\Users\wendy_000\AppData\Local\AvgSetupLog deleted C:\Users\wendy_000\AppData\Roaming\AVG deleted C:\windows\SysNative\config\systemprofile\AppData\Local\Avg deleted C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Avg deleted C:\Windows\SysWOW64\config\systemprofile\AppData\Local\AvgSetupLog deleted C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\AVG deleted C:\Users\wendy_000\AppData\Local\FreeFixer deleted "C:\Users\wendy_000\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.avg.com_0.localstorage" deleted "C:\Users\wendy_000\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.avg.com_0.localstorage-journal" deleted "C:\Users\wendy_000\AppData\Local\MFAData\logs\avguiru.log" deleted "C:\Windows\Prefetch\AVG-SECURE-SEARCH-UPDATE_0116-81A77DC6.pf" deleted "C:\windows\SysNative\DriverStore\FileRepository\avgfwfd6.inf_amd64_5a3602f029ed748e" deleted ==== Folders Found ====================== 2016-08-27 15:35:49 2016-08-30 11:42:52 -------- d-----w- C:\Program Files\FreeFixer 2016-08-27 15:35:59 2016-08-27 16:37:39 -------- d-----w- C:\Users\wendy_000\AppData\Roaming\FreeFixer 2016-08-31 13:16:25 2016-08-31 13:16:26 -------- d---a-w- C:\zoek_backup\C_Users_wendy_000_AppData_Local_FreeFixer ==== Files Found ====================== --- C:\Users\wendy_000\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.freefixer.com_0.localstorage --- Company: ------ File Description: ------ File Version: ------ Product Name: ------ Copyright: ------ Original Filename: ------ File type: ----a-w- File size: 3072 Created time: 2016-08-27 15:34:28 Modified time: 2016-08-27 15:34:29 MD5: 379C29C4E1C9C7206CBEC8000187B9A0 SHA1: C6E49094577EBCE62130618BDA51E4DEE0200F07 --- C:\Users\wendy_000\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.freefixer.com_0.localstorage-journal --- Company: ------ File Description: ------ File Version: ------ Product Name: ------ Copyright: ------ Original Filename: ------ File type: ----a-w- File size: 0 Created time: 2016-08-27 15:34:28 Modified time: 2016-08-27 15:34:29 MD5: D41D8CD98F00B204E9800998ECF8427E SHA1: DA39A3EE5E6B4B0D3255BFEF95601890AFD80709 --- C:\Users\wendy_000\Downloads\freefixersetup.exe --- Company: Kephyr File Description: FreeFixer File Version: 1.13 Product Name: FreeFixer Copyright: © Roger Karlsson Original Filename: File type: ----a-w- File size: 2687418 Created time: 2016-08-27 15:34:46 Modified time: 2016-08-27 15:35:18 MD5: A8E13A1A6BF55BC385942B613BCDE214 SHA1: 10FC67D9061A9ACD2EF7E661B38BB30AF46006AD --- C:\Windows\Prefetch\FREEFIXER.EXE-9310FCB0.pf --- Company: ------ File Description: ------ File Version: ------ Product Name: ------ Copyright: ------ Original Filename: ------ File type: ----a-w- File size: 32906 Created time: 2016-08-27 15:36:01 Modified time: 2016-08-30 11:42:52 MD5: 9A26F96C8D2B50298E582E180613FBD8 SHA1: 320FF83CD8B434F311360DB7A7AF090A7B821A1E --- C:\Windows\Prefetch\FREEFIXERSETUP.EXE-C6EE06F9.pf --- Company: ------ File Description: ------ File Version: ------ Product Name: ------ Copyright: ------ Original Filename: ------ File type: ----a-w- File size: 8338 Created time: 2016-08-27 15:35:33 Modified time: 2016-08-27 15:35:33 MD5: AED6DFE11EEE0046C943A0C456F089FD SHA1: E522A2782BC02B6C3B7C9ED8DE4DE40074A3CFC5 ==== Firefox Extensions Registry ====================== [HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions] "wrc@avast.com"="C:\Program Files\AVAST Software\Avast\WebRep\FF" [28/08/2016 13:06] [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions] "wrc@avast.com"="C:\Program Files\AVAST Software\Avast\WebRep\FF" [28/08/2016 13:06] ==== Chromium Look ====================== Google Chrome Version: 46.0.2490.86 HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions eofcbnmajmjmplflapaojjnihcjkigck - No path found[] gomekmidlodglbbmalcneegieacbdmki - No path found[] lifbcibllhkdhoafpjfnlhfpfgnpldfl - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx[25/05/2016 10:31] Google Slides - wendy_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek Google Docs - wendy_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake Google Drive - wendy_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf YouTube - wendy_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo Adblock for Youtube - wendy_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\cmedhionkhpnakcndndgjdbohmhepckk Google Search - wendy_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf Avast SafePrice - wendy_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck Google Sheets - wendy_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap News Feed Eradicator for Facebook - wendy_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\fjcldmjmjhkklehbacihaiopjklihlgg Security Extensions - wendy_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\gdgjmpjhdjbcbbpfkbdjkjcjgkpjgdjm Google Docs Offline - wendy_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi Avast Online Security - wendy_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki Unseen - wendy_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\iicapmagmhahddefgokbabbgieiogjop Skype - wendy_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl Pocket - wendy_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\mjcnijlhddpbdemagnpefmlkjdagkogk Save to Pocket - wendy_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\niloccemoadcdkdjlinkgdfekeahmflj Chrome Web Store Payments - wendy_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda Gmail - wendy_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia Chrome Media Router - wendy_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm Skype Calling - wendy_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\poghlonenmjdkfghdpfomojhhfggildk ==== Chromium Fix ====================== C:\Users\wendy_000\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.cmptch.com_0.localstorage deleted successfully C:\Users\wendy_000\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.cmptch.com_0.localstorage-journal deleted successfully C:\Users\wendy_000\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.re-markit00.re-markit.co_0.localstorage deleted successfully C:\Users\wendy_000\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.re-markit00.re-markit.co_0.localstorage-journal deleted successfully C:\Users\wendy_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck deleted successfully ==== Set IE to Default ====================== Old Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=9&ar=msnhome" New Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=9&ar=msnhome" ==== All HKLM and HKCU SearchScopes ====================== HKLM\SearchScopes "DefaultScope"="{17FDD98E-3C09-4F2D-993A-1916B805D8F1}" HKLM\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC HKLM\SearchScopes\{17FDD98E-3C09-4F2D-993A-1916B805D8F1} - http://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=ACJB HKLM\Wow6432Node\SearchScopes "DefaultScope"="{17FDD98E-3C09-4F2D-993A-1916B805D8F1}" HKLM\Wow6432Node\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC HKLM\Wow6432Node\SearchScopes\{17FDD98E-3C09-4F2D-993A-1916B805D8F1} - http://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=ACJB HKCU\SearchScopes "DefaultScope"="{012E1000-F331-11DB-8314-0800200C9A66}" HKCU\SearchScopes\{012E1000-F331-11DB-8314-0800200C9A66} - http://www.google.com/search?q={searchTerms} HKCU\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC ==== Deleting Registry Keys ====================== HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\eofcbnmajmjmplflapaojjnihcjkigck deleted successfully ==== Empty IE Cache ====================== C:\WINDOWS\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\wendy_000\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\Users\wendy_000\AppData\Local\Microsoft\Windows\INetCache\Low\Content.IE5 emptied successfully C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\WINDOWS\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\Users\wendy_000\AppData\Local\Microsoft\Windows\INetCache\Low\IE emptied successfully C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully C:\Users\wendy_000\AppData\Local\Microsoft\Windows\INetCache\IE\HEP0N15Z will be deleted at reboot ==== Empty FireFox Cache ====================== No FireFox Profiles found ==== Empty Chrome Cache ====================== C:\Users\wendy_000\AppData\Local\Opera Software\Opera Stable\Cache emptied successfully C:\Users\wendy_000\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully ==== Empty All Flash Cache ====================== No Flash Cache Found ==== Empty All Java Cache ====================== No Java Cache Found ==== C:\zoek_backup content ====================== C:\zoek_backup (files=9729 folders=417 1182441800 bytes) ==== Empty Temp Folders ====================== C:\WINDOWS\Temp will be emptied at reboot ==== After Reboot ====================== ==== Empty Temp Folders ====================== C:\WINDOWS\Temp successfully emptied C:\Users\WENDY_~1\AppData\Local\Temp successfully emptied ==== Empty Recycle Bin ====================== C:\$RECYCLE.BIN successfully emptied ==== Deleting Files / Folders ====================== "C:\Users\wendy_000\AppData\Local\Microsoft\Windows\INetCache\IE\HEP0N15Z" not found ==== EOF on wo 31/08/2016 at 15:26:16,13 ======================