Zoek.exe v5.0.0.1 Updated 31-December-2015
Tool run by xXx on st 13.01.2016 at 16:08:17,87.
Running in: Normal Mode Internet Access Detected
Launched: F:\Users\xXx\Desktop\zoek.exe [Scan all users] [Script inserted]
==== System Restore Info ======================
==== Reset Hosts File ======================
# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host
# localhost name resolution is handled within DNS itself.
127.0.0.1 localhost
::1 localhost
==== Empty Folders Check ======================
F:\Program Files\Common Files\SolidWorks Shared deleted successfully
F:\PROGRA~2\CanonEPP deleted successfully
F:\PROGRA~2\CanonIJEPPEX2 deleted successfully
F:\Users\xXx\AppData\Roaming\MPC-HC deleted successfully
F:\Users\xXx\AppData\Local\LG Electronics deleted successfully
==== Deleting CLSID Registry Keys ======================
HKEY_USERS\S-1-5-21-4180440179-413253161-2612144775-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{075FB1A5-A992-41D0-9320-8C00A2BE5DE9} deleted successfully
HKEY_USERS\S-1-5-21-4180440179-413253161-2612144775-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{14E4D556-DEC8-4F65-9854-2D00434EDA3E} deleted successfully
HKEY_USERS\S-1-5-21-4180440179-413253161-2612144775-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{172C21D4-188D-4550-85C5-3F7C947CC8D3} deleted successfully
HKEY_USERS\S-1-5-21-4180440179-413253161-2612144775-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2BB8866D-67E0-427B-8057-FF91FA050DC9} deleted successfully
HKEY_USERS\S-1-5-21-4180440179-413253161-2612144775-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{3250B95B-4972-4653-8CBB-D9EED2DC189A} deleted successfully
HKEY_USERS\S-1-5-21-4180440179-413253161-2612144775-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5699BCA0-2EEE-4FDC-B812-4A9EF6B4F4B3} deleted successfully
HKEY_USERS\S-1-5-21-4180440179-413253161-2612144775-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{63E49BD6-707C-4946-933E-10D7A45E533F} deleted successfully
HKEY_USERS\S-1-5-21-4180440179-413253161-2612144775-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{65E4BE80-67CF-4BD1-B516-7CEF0D174731} deleted successfully
HKEY_USERS\S-1-5-21-4180440179-413253161-2612144775-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{675BB966-1F0B-4EB9-81AE-8275BDA73DD8} deleted successfully
HKEY_USERS\S-1-5-21-4180440179-413253161-2612144775-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{678CBE33-04C9-48B5-A20A-124520DC19C7} deleted successfully
HKEY_USERS\S-1-5-21-4180440179-413253161-2612144775-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{77797B33-DCB5-4615-BBED-387D67CB0EC0} deleted successfully
HKEY_USERS\S-1-5-21-4180440179-413253161-2612144775-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{79846349-EDBB-4B1A-A4AE-4A176FD26E6D} deleted successfully
HKEY_USERS\S-1-5-21-4180440179-413253161-2612144775-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7A89A7E3-6ADD-4ef9-8EE7-A3C3B7D83BB0} deleted successfully
HKEY_USERS\S-1-5-21-4180440179-413253161-2612144775-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8130A370-102F-47FF-9E66-6F78CC8F59B8} deleted successfully
HKEY_USERS\S-1-5-21-4180440179-413253161-2612144775-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{938CEFB0-6DE4-431E-814C-89C8445A7DFF} deleted successfully
HKEY_USERS\S-1-5-21-4180440179-413253161-2612144775-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{93E42B33-5B8A-443B-ADA8-CEE28D3335AA} deleted successfully
HKEY_USERS\S-1-5-21-4180440179-413253161-2612144775-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{96420514-7614-4081-B77A-012607049265} deleted successfully
HKEY_USERS\S-1-5-21-4180440179-413253161-2612144775-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9848B4AE-DDA9-4435-97CF-55783BE8CE5A} deleted successfully
HKEY_USERS\S-1-5-21-4180440179-413253161-2612144775-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B206346A-98AC-4E8D-B69C-2C045F16D810} deleted successfully
HKEY_USERS\S-1-5-21-4180440179-413253161-2612144775-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B4B9E08C-5846-4817-865D-6F4EE8A7D7E5} deleted successfully
HKEY_USERS\S-1-5-21-4180440179-413253161-2612144775-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{BFF1FF83-D72B-46DC-AC26-DEE8D1BD8B3F} deleted successfully
HKEY_USERS\S-1-5-21-4180440179-413253161-2612144775-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CC2949EA-C438-4828-80A7-51AA414FF513} deleted successfully
HKEY_USERS\S-1-5-21-4180440179-413253161-2612144775-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DAFD5B44-1DFD-4AC1-9747-1CD0FFF31D25} deleted successfully
HKEY_USERS\S-1-5-21-4180440179-413253161-2612144775-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E9C8C0C5-7258-40BA-B116-7562ED46C54E} deleted successfully
==== Deleting CLSID Registry Values ======================
==== Deleting Services ======================
==== FireFox Fix ======================
Deleted from F:\Users\xXx\AppData\Roaming\Mozilla\Firefox\Profiles\pm06ttbe.default\prefs.js:
user_pref("browser.startup.homepage", "http://seznam.cz/");
user_pref("browser.search.useDBForOrder", true);
Added to F:\Users\xXx\AppData\Roaming\Mozilla\Firefox\Profiles\pm06ttbe.default\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");
Deleted from F:\Users\xXx\AppData\Roaming\Mozilla\Firefox\Profiles\x0o2ntcq.default\prefs.js:
Added to F:\Users\xXx\AppData\Roaming\Mozilla\Firefox\Profiles\x0o2ntcq.default\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");
ProfilePath: F:\Users\xXx\AppData\Roaming\Mozilla\Firefox\Profiles\pm06ttbe.default
user.js not found
---- Lines suggestor removed from prefs.js ----
user_pref("extensions.WinToFlashSuggestor.aid", "10045");
user_pref("extensions.WinToFlashSuggestor.uid", "b50ea6b3a91065ef934884624174563f");
---- FireFox user.js and prefs.js backups ----
prefs_03.02.2015_1911_.backup
prefs_13.01.2016_1620_.backup
ProfilePath: F:\Users\xXx\AppData\Roaming\Mozilla\Firefox\Profiles\x0o2ntcq.default
user.js not found
---- Lines suggestor removed from prefs.js ----
user_pref("extensions.WinToFlashSuggestor.aid", "10045");
user_pref("extensions.WinToFlashSuggestor.uid", "b50ea6b3a91065ef934884624174563f");
---- FireFox user.js and prefs.js backups ----
prefs_13.01.2016_1620_.backup
==== Deleting Files \ Folders ======================
F:\PROGRA~2\Package Cache deleted
F:\Users\xXx\AppData\Local\HWVendorDetection.log deleted
F:\Users\xXx\AppData\Local\Unity deleted
F:\Windows\system32\GroupPolicy\Machine deleted
F:\Windows\system32\GroupPolicy\User deleted
F:\Windows\system32\GroupPolicy\gpt.ini deleted
"F:\Users\xXx\AppData\LocalLow\Unity" deleted
==== Firefox Start and Search pages ======================
ProfilePath: F:\Users\xXx\AppData\Roaming\Mozilla\Firefox\Profiles\pm06ttbe.default
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");
ProfilePath: F:\Users\xXx\AppData\Roaming\Mozilla\Firefox\Profiles\x0o2ntcq.default
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");
==== Firefox Extensions ======================
AppDir: F:\Program Files\Mozilla Firefox
- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
==== Firefox Plugins ======================
Profilepath: F:\Users\xXx\AppData\Roaming\Mozilla\Firefox\Profiles\pm06ttbe.default
E7AC2BFD4928D251DAF1E51176C9EDD0 - F:\Program Files\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll - Adobe Acrobat
A30C10E0C3542B7A87FF7D2DFF4C9294 - F:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll - NVIDIA 3D Vision
3118619EBBA4257109A3FBEE807790F4 - F:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll - NVIDIA 3D VISION
1B743D5B6FD001660FAB17DD7C347A38 - f:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrl.dll - Silverlight Plug-In
E7006BB5611298DBDD03FE3519C19AC2 - F:\Program Files\Java\jre1.8.0_25\bin\plugin2\npjp2.dll - Java(TM) Platform SE 8 U25
238F239EAEFF7E3E782913D599084E18 - F:\Program Files\Java\jre1.8.0_25\bin\dtplugin\npdeployJava1.dll - Java Deployment Toolkit 8.0.250.18
9C06DBC403F91D518ED117E460F03F85 - F:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL - CANON iMAGE GATEWAY Album Plugin Utility for IJ
70858ED7836E5C849D33576A84DC8CCF - F:\Windows\system32\Macromed\Flash\NPSWF32_20_0_0_267.dll - Shockwave Flash
221D0173E441CC841916E7B1B98FDD27 - F:\Program Files\Roblox\Versions\version-7d5a5b16f3354346\NPRobloxProxy.dll - Roblox Launcher Plugin
4F3F6B17B4A5BDB68B3CB0367A2C214E - f:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrlui.dll - Microsoft® Silverlight
4C3339535707992E4DEA0DD8A7CB7F52 - F:\Program Files\Roblox\Versions\version-7d5a5b16f3354346\NPRobloxProxy64.dll - Roblox Launcher Plugin
==== Chromium Look ======================
Google Chrome Version: 37.0.2062.120
mcceagdollnkjlogmdckgjakjapmkdjf - xXx\AppData\Local\Google\Chrome\User Data\Default\Extensions\mcceagdollnkjlogmdckgjakjapmkdjf
==== Chromium Startpages ======================
F:\Users\xXx\AppData\Local\Google\Chrome\User Data\Default\Preferences
"homepage": "http://www.istartsurf.com/?type=hp&ts=1443206071&z=453041540a758cc85f3b895g4z8z1cfo2ebq4ecm2g&from=cor&uid=wdcxwd5001aals-00l3b2_wd-wcasy631133411334",
"startup_urls": [ "http://www.istartsurf.com/?type=hp&ts=1443206071&z=453041540a758cc85f3b895g4z8z1cfo2ebq4ecm2g&from=cor&uid=wdcxwd5001aals-00l3b2_wd-wcasy631133411334" ],
==== Set IE to Default ======================
Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://go.microsoft.com/fwlink/?LinkID=617910&ResetID=130876799441068217&GUID=00000000-0000-0000-0000-000000000000"
"Start Page Before"="http://go.microsoft.com/fwlink/p/?LinkId=255141"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AboutURLs]
"Tabs"="res://ieframe.dll/tabswelcome.htm"
New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://go.microsoft.com/fwlink/?LinkID=617910&ResetID=130876799441068217&GUID=00000000-0000-0000-0000-000000000000"
"Start Page Before"="http://go.microsoft.com/fwlink/?LinkID=617910&ResetID=130876799441068217&GUID=00000000-0000-0000-0000-000000000000"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AboutURLs]
"Tabs"="about:newtab"
==== All HKLM and HKCU SearchScopes ======================
HKLM\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
HKLM\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} -
http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
HKCU\SearchScopes "DefaultScope"="{33BB0A4E-99AF-4226-BDF6-49120163DE86}"
HKCU\SearchScopes\{012E1000-F331-11DB-8314-0800200C9A66} -
http://www.google.com/search?q={searchTerms}
HKCU\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} -
http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
HKCU\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} -
http://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
HKCU\SearchScopes\{C358981A-BAF7-4EA7-A441-F8B141DB2093} -
http://tv.seznam.cz/hledej?w={searchTerms}&sourceid=QuickSearch_16194
==== Reset Google Chrome ======================
F:\Users\xXx\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
F:\Users\xXx\AppData\Local\Google\Chrome\User Data\Default\Preferences.bad was reset successfully
F:\Users\xXx\AppData\Local\Google\Chrome\User Data\Default\Preferences.bak was reset successfully
F:\Users\xXx\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences was reset successfully
F:\Users\xXx\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
==== Deleting Registry Keys ======================
HKEY_LOCAL_MACHINE\Software\Policies\Google deleted successfully
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\UnityWebPlayer deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cz.seznam.software.szndesktop deleted successfully
==== Empty IE Cache ======================
F:\Users\xXx\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
F:\Users\xXx\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
F:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
F:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
F:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
F:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
==== Empty FireFox Cache ======================
F:\Users\xXx\AppData\Local\Mozilla\Firefox\Profiles\pm06ttbe.default\cache2 emptied successfully
==== Empty Chrome Cache ======================
F:\Users\xXx\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
==== Empty All Flash Cache ======================
Flash Cache Emptied Successfully
==== Empty All Java Cache ======================
Java Cache cleared successfully
==== F:\zoek_backup content ======================
F:\zoek_backup (files=388 folders=188 1952487975 bytes)
==== Empty Temp Folders ======================
F:\Users\Default\AppData\Local\temp emptied successfully
F:\Users\Default User\AppData\Local\temp emptied successfully
F:\Users\xXx\AppData\Local\Temp will be emptied at reboot
F:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
F:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
F:\Windows\Temp will be emptied at reboot
==== After Reboot ======================
==== Empty Temp Folders ======================
F:\Windows\Temp successfully emptied
F:\Users\xXx\AppData\Local\Temp successfully emptied
==== Empty Recycle Bin ======================
F:\$RECYCLE.BIN successfully emptied
==== EOF on st 13.01.2016 at 16:25:29,29 ======================