Zoek.exe v5.0.0.1 Updated 19-September-2016 Tool run by Yoke on vr 21/10/2016 at 12:47:52,56. Microsoft Windows 10 Home 10.0.10586 x64 Running in: Normal Mode Internet Access Detected Launched: C:\Users\Yoke\Downloads\zoek.exe [Scan all users] [Script inserted] ==== System Restore Info ====================== 21/10/2016 12:48:43 Zoek.exe System Restore Point Created Successfully. ==== Empty Folders Check ====================== C:\PROGRA~2\Dashlane deleted successfully C:\PROGRA~2\McAfee deleted successfully C:\PROGRA~2\COMMON~1\Symantec Shared deleted successfully C:\Program Files\PDF Architect 4 deleted successfully C:\Program Files\Sound+ deleted successfully C:\Users\Yoke\AppData\Local\ActiveSync deleted successfully C:\Users\Yoke\AppData\Local\HP Quick Start deleted successfully C:\Users\Yoke\AppData\Local\NetworkTiles deleted successfully C:\WINDOWS\serviceprofiles\networkservice\AppData\Local\Maps deleted successfully C:\WINDOWS\serviceprofiles\Localservice\AppData\Local\NetworkTiles deleted successfully ==== Deleting CLSID Registry Keys ====================== HKEY_USERS\S-1-5-21-437695964-452967705-790082943-1001\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F05E0524-ED06-43A7-BB08-04FEF67C7D11} deleted successfully ==== Deleting CLSID Registry Values ====================== ==== Deleting Services ====================== ==== Deleting Files \ Folders ====================== C:\PROGRA~2\Dashlane not found C:\PROGRA~2\McAfee not found C:\Program Files\Sound+ not found C:\Program Files\Sound+ not found "C:\Windows\Installer\wix{526002E5-7D5B-4703-A4E3-BA566AED5D8A}" not found "C:\Windows\Installer\wix{7D84E343-A23D-451C-B123-0195B2D903A6}" not found "C:\Windows\Installer\wix{C1424923-74F7-4399-B9D9-5F72FB1B9481}" not found "C:\Windows\Installer\wix{FA00A3CC-7440-4938-A271-F186F50DD40D}" not found "C:\WINDOWS\Installer\MSI1A23.tmp" not found "C:\WINDOWS\Installer\MSI1DBE.tmp" not found "C:\WINDOWS\Installer\MSI1E8A.tmp" not found "C:\WINDOWS\Installer\MSI1F18.tmp" not found "C:\WINDOWS\Installer\MSI1F86.tmp" not found "C:\WINDOWS\Installer\MSI4D22.tmp" not found "C:\WINDOWS\Installer\MSI5A62.tmp" not found "C:\WINDOWS\Installer\MSI5FDC.tmp" not found "C:\WINDOWS\Installer\MSI6115.tmp" not found "C:\WINDOWS\Installer\MSI86A1.tmp" not found "C:\WINDOWS\Installer\MSI8B57.tmp" not found "C:\WINDOWS\Installer\MSIC5E8.tmp" not found "C:\WINDOWS\Installer\MSIEB64.tmp" not found "C:\Windows\Installer\wix{526002E5-7D5B-4703-A4E3-BA566AED5D8A}" not found "C:\Windows\Installer\wix{7D84E343-A23D-451C-B123-0195B2D903A6}" not found "C:\Windows\Installer\wix{C1424923-74F7-4399-B9D9-5F72FB1B9481}" not found "C:\Windows\Installer\wix{FA00A3CC-7440-4938-A271-F186F50DD40D}" not found "C:\WINDOWS\Installer\MSI1A23.tmp" not found "C:\WINDOWS\Installer\MSI1DBE.tmp" not found "C:\WINDOWS\Installer\MSI1E8A.tmp" not found "C:\WINDOWS\Installer\MSI1F18.tmp" not found "C:\WINDOWS\Installer\MSI1F86.tmp" not found "C:\WINDOWS\Installer\MSI4D22.tmp" not found "C:\WINDOWS\Installer\MSI5A62.tmp" not found "C:\WINDOWS\Installer\MSI5FDC.tmp" not found "C:\WINDOWS\Installer\MSI6115.tmp" not found "C:\WINDOWS\Installer\MSI86A1.tmp" not found "C:\WINDOWS\Installer\MSI8B57.tmp" not found "C:\WINDOWS\Installer\MSIC5E8.tmp" not found "C:\WINDOWS\Installer\MSIEB64.tmp" not found C:\found.000 deleted C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Shopping and Services deleted C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Search.lnk deleted C:\windows\SysNative\GroupPolicy\Adm deleted C:\windows\SysNative\GroupPolicy\Machine deleted C:\windows\SysNative\GroupPolicy\User deleted C:\windows\SysNative\GroupPolicy\gpt.ini deleted C:\WINDOWS\Syswow64\GroupPolicy\Adm deleted C:\WINDOWS\Syswow64\GroupPolicy\Machine deleted C:\WINDOWS\Syswow64\GroupPolicy\User deleted C:\WINDOWS\Syswow64\GroupPolicy\gpt.ini.old deleted "C:\Users\Yoke\Downloads\SimpleDriverUpdaterSetup_ppc.exe" deleted "C:\Users\Yoke\Downloads\SimpleDriverUpdaterSetup_ppc.exe" deleted ==== Firefox Start and Search pages ====================== ProfilePath: C:\Users\Yoke\AppData\Roaming\Mozilla\Firefox\Profiles\wnyjknxy.default-1476387040122 user_pref("browser.startup.homepage", "https://www.google.be/"); ==== Firefox Extensions Registry ====================== [HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions] "sp@avast.com"="C:\Program Files\AVAST Software\Avast\SafePrice\FF" [03/10/2016 11:50] [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions] "sp@avast.com"="C:\Program Files\AVAST Software\Avast\SafePrice\FF" [03/10/2016 11:50] ==== Firefox Extensions ====================== AppDir: C:\Program Files (x86)\Mozilla Firefox - Undetermined - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}.xpi ==== Firefox Plugins ====================== Profilepath: C:\Users\Yoke\AppData\Roaming\Mozilla\Firefox\Profiles\wnyjknxy.default-1476387040122 32534FFE70905DD87DDAAF7437897560 - C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_23_0_0_185.dll - Shockwave Flash ==== Set IE to Default ====================== Old Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="https://www.google.be/?hl=nl" New Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="https://www.google.be/?hl=nl" ==== All HKLM and HKCU SearchScopes ====================== HKLM\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" HKLM\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=HPDTDFJS HKLM\SearchScopes\{2F644012-0078-4383-98F9-7DAD6A15141C} - http://www.amazon.co.uk/s/ref=azs_osd_ieauk?ie=UTF-8&tag=hp-uk3-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms} HKLM\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC} - http://rover.ebay.com/rover/1/1553-29906-12136-18/4 HKLM\Wow6432Node\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" HKLM\Wow6432Node\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=HPDTDFJS HKLM\Wow6432Node\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC} - http://rover.ebay.com/rover/1/1553-29906-12136-18/4 HKCU\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" HKCU\SearchScopes\{012E1000-F331-11DB-8314-0800200C9A66} - http://www.google.com/search?q={searchTerms} HKCU\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02&pc=UE04 HKCU\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3C} - http://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1 HKCU\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC} - http://rover.ebay.com/rover/1/1553-29906-12136-18/4 ==== Empty IE Cache ====================== C:\WINDOWS\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Yoke\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\Users\Yoke\AppData\Local\Microsoft\Windows\INetCache\Low\Content.IE5 emptied successfully C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\Users\Yoke\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully C:\Users\Yoke\AppData\Local\Microsoft\Windows\INetCache\Low\IE emptied successfully C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully ==== Empty FireFox Cache ====================== C:\Users\Yoke\AppData\Local\Mozilla\Firefox\Profiles\wnyjknxy.default-1476387040122\cache2 emptied successfully ==== Empty Chrome Cache ====================== No Chrome User Data found ==== Empty All Flash Cache ====================== No Flash Cache Found ==== Empty All Java Cache ====================== Java Cache cleared successfully ==== C:\zoek_backup content ====================== C:\zoek_backup (files=14 folders=8 3992715 bytes) ==== Empty Temp Folders ====================== C:\WINDOWS\Temp will be emptied at reboot ==== After Reboot ====================== ==== Empty Temp Folders ====================== C:\WINDOWS\Temp successfully emptied C:\Users\Yoke\AppData\Local\Temp successfully emptied ==== Empty Recycle Bin ====================== C:\$RECYCLE.BIN successfully emptied ==== EOF on vr 21/10/2016 at 13:04:23,40 ======================