Zoek.exe v5.0.0.1 Updated 19-September-2016 Tool run by CvS on zo 06-11-2016 at 15:04:32,36. Microsoft Windows 7 Starter 6.1.7601 Service Pack 1 x86 Running in: Normal Mode Internet Access Detected Launched: C:\Users\CvS\Desktop\zoek.exe [Scan all users] [Script inserted] ==== Older Logs ====================== C:\zoek-results2016-11-04-120103.log 646 bytes C:\zoek-results2016-11-04-124247.log 2503 bytes C:\zoek-results2016-11-05-003038.log 2893 bytes C:\zoek-results2016-11-05-102428.log 67284 bytes C:\zoek-results2016-11-05-111517.log 1913 bytes ==== Empty Folders Check ====================== C:\Program Files\Plumbytes Software deleted successfully C:\Users\CvS\AppData\Roaming\Ckiruspclevient deleted successfully ==== Deleting CLSID Registry Keys ====================== ==== Deleting CLSID Registry Values ====================== ==== Deleting Services ====================== ==== FireFox Fix ====================== ProfilePath: C:\Users\ADMINI~1\AppData\Roaming\Mozilla\Firefox\Profiles\mzqsev8j.default user.js not found ---- FireFox user.js and prefs.js backups ---- prefs_06-11-2016_1546_.backup ProfilePath: C:\Users\CvS\AppData\Roaming\Profiles\hte5m4y1.default user.js not found ---- FireFox user.js and prefs.js backups ---- prefs_06-11-2016_1546_.backup ProfilePath: C:\Users\CvS\AppData\Roaming\Profiles\k552rsm0.default user.js not found ---- FireFox user.js and prefs.js backups ---- prefs_06-11-2016_1546_.backup ProfilePath: C:\Users\CvS\AppData\Roaming\Profiles\Mofigh.default user.js not found ---- Lines searchengine removed from prefs.js ---- user_pref("browser.search.searchengine.uid", "FUJITSUXMHZ2250BHXG2_K617T8427PUN"); ---- Lines searches removed from prefs.js ---- user_pref("browser.urlbar.suggest.searches", true); ---- Lines browser.startup.page removed from prefs.js ---- user_pref("browser.startup.page", 1); ---- FireFox user.js and prefs.js backups ---- prefs_06-11-2016_1546_.backup ProfilePath: C:\Users\CvS\AppData\Roaming\Profiles\ta4eiffb.default user.js not found ---- FireFox user.js and prefs.js backups ---- prefs_06-11-2016_1546_.backup ProfilePath: C:\Users\CvS\AppData\Roaming\Mozilla\Firefox\Profiles\n5b27ig3.default user.js not found ---- Lines searchengine removed from prefs.js ---- user_pref("browser.search.searchengine.uid", "FUJITSUXMHZ2250BHXG2_K617T8427PUN"); ---- Lines searches removed from prefs.js ---- user_pref("browser.urlbar.suggest.searches", true); ---- Lines browser.startup.page removed from prefs.js ---- user_pref("browser.startup.page", 1); ---- FireFox user.js and prefs.js backups ---- prefs_06-11-2016_1546_.backup ProfilePath: C:\Users\CvS\AppData\Roaming\Mozilla\Firefox\naweriweentcofise\Profiles\n5b27ig3.default user.js not found ---- FireFox user.js and prefs.js backups ---- prefs_06-11-2016_1546_.backup ==== Deleting Files \ Folders ====================== C:\Program Files\Plumbytes Software not found C:\Windows\system32\Tasks\{0EBD9984-17F5-4F05-86C6-83A044E4486D} not found C:\Windows\system32\Tasks\{8A90F171-F8F8-4918-8F23-3C6FA949A155} not found C:\Windows\system32\Tasks\{A478F310-E2DE-4868-B83A-2D8E8F9D85D0} not found C:\Users\Default\AppData\Roaming\IObit not found C:\Users\Default User\AppData\Roaming\IObit not found C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG PC TuneUp not found C:\Windows\system32\tasks\AutoPico Daily Restart not found C:\Program Files\KMSpico not found C:\Windows\system32\tasks\AVG EUpdate Task not found C:\Windows\system32\tasks\Uninstaller_SkipUac_CvS not found C:\Program Files\IObit\IObit Uninstaller not found C:\Windows\system32\Tasks\{0EBD9984-17F5-4F05-86C6-83A044E4486D} not found C:\Windows\system32\Tasks\{8A90F171-F8F8-4918-8F23-3C6FA949A155} not found C:\Windows\system32\Tasks\{A478F310-E2DE-4868-B83A-2D8E8F9D85D0} not found C:\Users\Default\AppData\Roaming\IObit not found C:\Users\Default User\AppData\Roaming\IObit not found C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG PC TuneUp not found C:\Windows\system32\tasks\AutoPico Daily Restart not found C:\Program Files\KMSpico not found C:\Windows\system32\tasks\AVG EUpdate Task not found C:\Windows\system32\tasks\Uninstaller_SkipUac_CvS not found C:\Program Files\IObit\IObit Uninstaller not found "C:\Users\CvS\AppData\Local\temp\Rar$EXa0.797\Adobe Dreamweaver CC 2015 Crack Free Download.exe" not found "C:\Users\CvS\AppData\Local\temp\Rar$EXa0.797\Adobe Dreamweaver CC 2015 Crack Free Download.exe" not found C:\Program Files\tixati deleted C:\Users\CvS\AppData\Roaming\tixati deleted C:\Users\CvS\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Tixati deleted C:\Windows\system32\Tasks\edd2563489cbb90cb69a57d7497f2e4b deleted C:\PROGRA~2\Kingsoft deleted ==== Orphaned Tasks deleted from Registry ====================== avast Emergency Update deleted edd2563489cbb90cb69a57d7497f2e4b deleted ==== Firefox Extensions Registry ====================== [HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions] "wrc@avast.com"="C:\Program Files\AVAST Software\Avast\WebRep\FF" [30-10-2016 23:50] ==== Firefox Extensions ====================== ProfilePath: C:\Users\CvS\AppData\Roaming\Profiles\Mofigh.default - Firefox Hotfix - %ProfilePath%\extensions\firefox-hotfix@mozilla.org.xpi ProfilePath: C:\Users\CvS\AppData\Roaming\Mozilla\Firefox\Profiles\n5b27ig3.default - Firefox Hotfix - %ProfilePath%\extensions\firefox-hotfix@mozilla.org.xpi AppDir: C:\Program Files\Mozilla Firefox - Undetermined - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}.xpi ==== Firefox Plugins ====================== Profilepath: C:\Users\CvS\AppData\Roaming\Mozilla\Firefox\Profiles\n5b27ig3.default 66FD5BFE5CE06B241F4588D234CD3123 - C:\Program Files\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll - AdobeAAMDetect 08C3C6B144EB5EBDE93263237C53DB14 - C:\Program Files\VideoLAN\VLC\npvlc.dll - VLC Web Plugin 3EE8AE0ECFE5D79DE1737A855AD1E84C - C:\Program Files\Google\Update\1.3.31.5\npGoogleUpdate3.dll - Google Update 83A6A74450758132AA7AB624645A7365 - C:\Program Files\Java\jre1.8.0_111\bin\plugin2\npjp2.dll - Java(TM) Platform SE 8 U111 6488CE92FB6A838F51AF255760053D39 - C:\Program Files\Java\jre1.8.0_111\bin\dtplugin\npdeployJava1.dll - Java Deployment Toolkit 8.0.1110.14 E288BCB3E135DAC497B49847CCDCED00 - C:\Windows\system32\Macromed\Flash\NPSWF32_23_0_0_205.dll - Shockwave Flash 04769DB3DD7835CFCFD3E0CAC95C3FAC - C:\Program Files\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll - AdobeAAMDetect ==== Fake Chromium Profiles Check ====================== Fake profile C:\Windows\system32\config\systemprofile\AppData\Local\Google\Chrome deleted ==== Chromium Look ====================== Google Chrome Version: 46.0.2490.86 HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions efaidnbmnnnibpcajpcglclefindmkaj - No path found[] eofcbnmajmjmplflapaojjnihcjkigck - No path found[] gomekmidlodglbbmalcneegieacbdmki - No path found[] oaocmnfllndpbbmjmniielgaanaifehp - No path found[] ==== Chromium Fix ====================== C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_c.betrad.com_0.localstorage deleted successfully C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_c.betrad.com_0.localstorage-journal deleted successfully C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_c.betrad.com_0.localstorage deleted successfully C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_c.betrad.com_0.localstorage-journal deleted successfully ==== Set IE to Default ====================== Old Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] New Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157" ==== All HKLM and HKCU SearchScopes ====================== HKLM\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" HKLM\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC HKCU\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" HKCU\SearchScopes\{012E1000-F331-11DB-8314-0800200C9A66} - http://www.google.com/search?q={searchTerms} HKCU\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02 HKCU\SearchScopes\{B3B3A6AC-74EC-BD56-BCDB-EFA4799FB9DF} - https://www.amazon.com/gp/bit/amazonserp/ref=bit_bds-p17_serp_ie_us_display?ie=UTF8&tagbase=bds-p17&tbrId=v1_abb-channel-17_c6ac4bd6_1201_1403_20160811_NL_ie_ds_&tag=bds-p17-serp-us-ie-20&query={searchTerms} ==== Deleting CLSID Registry Keys ====================== HKEY_USERS\S-1-5-21-3999796690-2714581427-440596665-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE7CD045-E861-484f-8273-0445EE161910} deleted successfully HKEY_USERS\S-1-5-21-3999796690-2714581427-440596665-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE7CD045-E861-484f-8273-0445EE161910} deleted successfully HKEY_USERS\S-1-5-21-3999796690-2714581427-440596665-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F4971EE7-DAA0-4053-9964-665D8EE6A077} deleted successfully HKEY_USERS\S-1-5-21-3999796690-2714581427-440596665-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{F4971EE7-DAA0-4053-9964-665D8EE6A077} deleted successfully HKEY_CLASSES_ROOT\CLSID\{AE7CD045-E861-484f-8273-0445EE161910} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE7CD045-E861-484f-8273-0445EE161910} deleted successfully HKEY_CLASSES_ROOT\CLSID\{F4971EE7-DAA0-4053-9964-665D8EE6A077} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F4971EE7-DAA0-4053-9964-665D8EE6A077} deleted successfully ==== Deleting CLSID Registry Values ====================== HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\web2pdfextension@web2pdf.adobedotcom deleted successfully ==== Empty IE Cache ====================== C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\CvS\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\CvS\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully ==== Empty FireFox Cache ====================== C:\Users\Administrator\AppData\Local\Mozilla\Firefox\Profiles\mzqsev8j.default\cache2 emptied successfully C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\mzqsev8j.default\storage\default\https+++templatemonstercom.sendpulse.com\cache emptied successfully C:\Users\CvS\AppData\Local\Mozilla\Firefox\Profiles\41A66E7E5EE1\cache2 emptied successfully C:\Users\CvS\AppData\Local\Mozilla\Firefox\Profiles\n5b27ig3.default\cache2 emptied successfully ==== Empty Chrome Cache ====================== C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully ==== Empty All Flash Cache ====================== Flash Cache Emptied Successfully ==== Empty All Java Cache ====================== No Java Cache Found ==== C:\zoek_backup content ====================== C:\zoek_backup (files=206 folders=62 112228329 bytes) ==== Empty Temp Folders ====================== C:\Users\Administrator\AppData\Local\temp emptied successfully C:\Users\CvS\AppData\Local\temp will be emptied at reboot C:\Users\Default\AppData\Local\temp emptied successfully C:\Users\Default User\AppData\Local\temp emptied successfully C:\Users\Public\AppData\Local\temp emptied successfully C:\Users\SYSTEM\AppData\Local\temp emptied successfully C:\Windows\system32\config\systemprofile\AppData\Local\temp emptied successfully C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully C:\Windows\Temp will be emptied at reboot ==== After Reboot ====================== ==== Empty Temp Folders ====================== C:\Windows\Temp successfully emptied C:\Users\CvS\AppData\Local\Temp successfully emptied ==== Empty Recycle Bin ====================== C:\$RECYCLE.BIN successfully emptied ==== Deleting Files / Folders ====================== "C:\Program Files\IObit\IObit Uninstaller" not found "C:\Program Files\IObit\IObit Uninstaller" not found ==== EOF on zo 06-11-2016 at 16:00:13,52 ======================