Zoek.exe v5.0.0.0 Updated 15-08-2014 Tool run by FM2A88 on zo 17/08/2014 at 10:00:29,14. Microsoft Windows 8.1 6.3.9600 x64 Running in: Normal Mode Internet Access Detected Launched: C:\Users\FM2A88\Desktop\zoek.exe [Scan all users] [Script inserted] [Checkboxes used] ==== Older Logs ====================== C:\zoek-results2014-08-16-001842.log 63106 bytes ==== Deleting CLSID Registry Keys ====================== HKEY_USERS\S-1-5-21-3437649926-2280246673-654014984-1001\Software\Microsoft\Internet Explorer\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5} deleted successfully ==== Deleting CLSID Registry Values ====================== ==== Deleting Services ====================== HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\nethfdrv deleted successfully ==== FireFox Fix ====================== ProfilePath: C:\Users\FM2A88\AppData\Roaming\Mozilla\Firefox\Profiles\t28rcbd9.default ---- Lines search.net removed from prefs.js ---- user_pref("browser.search.order.1", "default-search.net"); ---- FireFox user.js and prefs.js backups ---- user_20141708_1017_.backup prefs_20141708_1017_.backup ==== Registry Fix Code ====================== Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command] @="C:\\Program Files\\Internet Explorer\\iexplore.exe" ==== Deleting Files \ Folders ====================== C:\PROGRA~3\Tbccint deleted C:\PROGRA~2\Mozilla Firefox\browser\searchplugins\default-search.xml deleted C:\PROGRA~2\COMMON~1\Config\uninstinethnfd.exe deleted C:\PROGRA~2\Settings Manager deleted C:\PROGRA~2\Systweak Support Dock deleted C:\PROGRA~2\COMMON~1\Config deleted C:\Users\FM2A88\AppData\Roaming\SimpleFiles deleted C:\Users\FM2A88\AppData\Roaming\Settings Manager deleted C:\Users\FM2A88\AppData\Roaming\aps.uninstall.scan.results deleted C:\PROGRA~3\SPL453A.tmp deleted C:\PROGRA~3\MountainApp deleted C:\PROGRA~3\InstallMate deleted C:\PROGRA~3\Package Cache deleted C:\Users\FM2A88\AppData\Local\nsi1689.tmp deleted C:\Users\FM2A88\AppData\Local\nsu3906.tmp deleted C:\Users\FM2A88\AppData\Local\nsw3C1F.tmp deleted C:\Users\FM2A88\AppData\Local\Tbccint deleted C:\Users\FM2A88\AppData\Local\globalUpdate deleted C:\Users\FM2A88\AppData\Local\freeSOFTtoday deleted C:\Users\FM2A88\AppData\Local\Oxy deleted C:\Users\FM2A88\AppData\Local\cache deleted C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Search.lnk deleted C:\Windows\SysNative\roboot64.exe deleted C:\Users\FM2A88\Searches deleted C:\Users\FM2A88\AppData\LocalLow\DataMngr deleted C:\Users\FM2A88\AppData\LocalLow\PriceGong deleted C:\windows\SysNative\Tasks\GoforFilesUpdate deleted C:\Windows\Tasks\re-markit_wd.job deleted C:\windows\SysNative\tasks\Optimizer Pro Schedule deleted C:\windows\SysNative\tasks\YourFile DownloaderUpdate deleted C:\END deleted C:\windows\SysNative\drivers\{2635ac50-5488-40bf-9bfd-accb158f8f3f}w64.sys deleted C:\windows\SysNative\drivers\{2b929fe1-284b-4766-afb9-19b0915b99b0}Gw64.sys deleted C:\windows\SysNative\drivers\{a3f28269-ad17-41a8-b032-3e0313ef8979}Gw64.sys deleted C:\windows\SysNative\drivers\{f2dee4ac-05d0-4e54-80bc-2dc0ba61a2c7}Gw64.sys deleted C:\Windows\SysNative\config\systemprofile\Searches deleted C:\Users\FM2A88\AppData\Local\AnyProtectScannerSetup.exe deleted ==== Firefox Extensions Registry ====================== [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions] "{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}"="C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_21.2.0.38\coFFPlgn" [16/08/2014 02:18] ==== Firefox Extensions ====================== AppDir: C:\Program Files (x86)\Mozilla Firefox - Belgium eID - %AppDir%\extensions\belgiumeid@eid.belgium.be - Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} ==== Firefox Plugins ====================== ==== Chrome Look ====================== HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions iikflkcanblccfahdhdonehdalibjnif - No path found[] mkfokfffehpeedafpekjeddnmnjhmcmk - C:\Program Files (x86)\Norton 360\Engine\21.5.0.19\Exts\Chrome.crx[31/07/2014 07:47] Norton Identity Protection - FM2A88\AppData\Local\Chromium\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk AdBlock Premium - FM2A88\AppData\Local\Google\Chrome\User Data\Default\Extensions\fndlhnanhedoklpdaacidomdnplcjcpj Norton Identity Safe - FM2A88\AppData\Local\Google\Chrome\User Data\Default\Extensions\iikflkcanblccfahdhdonehdalibjnif Norton Security Toolbar - FM2A88\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk Ghostery - FM2A88\AppData\Local\Google\Chrome\User Data\Default\Extensions\mlomiejdfkolichcflejclcbmpeaniij ==== Chromium Startpages ====================== C:\Users\FM2A88\AppData\Local\Google\Chrome\User Data\Default\Preferences "startup_urls": [ "", "https://www.google.be/" ], ==== Chrome Fix ====================== C:\Users\FM2A88\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_www.superfish.com_0.localstorage deleted successfully C:\Users\FM2A88\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_www.superfish.com_0.localstorage-journal deleted successfully C:\Users\FM2A88\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.superfish.com_0.localstorage deleted successfully C:\Users\FM2A88\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.superfish.com_0.localstorage-journal deleted successfully C:\Users\FM2A88\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.visaversa.net_0.localstorage deleted successfully C:\Users\FM2A88\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.visaversa.net_0.localstorage-journal deleted successfully C:\Users\FM2A88\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_api.sqeedolphindeals.com_0.localstorage deleted successfully C:\Users\FM2A88\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_api.sqeedolphindeals.com_0.localstorage-journal deleted successfully C:\Users\FM2A88\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_en.softonic.com_0.localstorage deleted successfully C:\Users\FM2A88\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_en.softonic.com_0.localstorage-journal deleted successfully C:\Users\FM2A88\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_hackthegame.en.softonic.com_0.localstorage deleted successfully C:\Users\FM2A88\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_hackthegame.en.softonic.com_0.localstorage-journal deleted successfully C:\Users\FM2A88\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_install-creator.en.softonic.com_0.localstorage deleted successfully C:\Users\FM2A88\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_install-creator.en.softonic.com_0.localstorage-journal deleted successfully C:\Users\FM2A88\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_serialkey-builder.en.softonic.com_0.localstorage deleted successfully C:\Users\FM2A88\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_serialkey-builder.en.softonic.com_0.localstorage-journal deleted successfully C:\Users\FM2A88\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_steam.en.softonic.com_0.localstorage deleted successfully C:\Users\FM2A88\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_steam.en.softonic.com_0.localstorage-journal deleted successfully C:\Users\FM2A88\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma deleted successfully C:\Users\FM2A88\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_pelmeidfhdlhlbjimpabfcbnnojbboma_0.localstorage deleted successfully C:\Users\FM2A88\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_pelmeidfhdlhlbjimpabfcbnnojbboma_0.localstorage-journal deleted successfully C:\Users\FM2A88\AppData\Local\Google\Chrome\User Data\Default\Extensions\iikflkcanblccfahdhdonehdalibjnif deleted successfully C:\Users\FM2A88\AppData\Local\Chromium\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk deleted successfully C:\Users\FM2A88\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk deleted successfully ==== Set IE to Default ====================== Old Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://www.msn.be/" "Search Page"="http://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZQQWnwgkHH88J8gQeiMG-hmZBsrpaHaiv0Msc1dQG3ass_3e4uC6uFCHkOHJ1yFqknKTf5acwuE_deNsyZo_dWPmc2jmz8BvZKA0TUHh4w2Sri4J555XQMpaFMkGALlv9y5uOOiftYqBiVrV7OAm-nHasUQK9Qg,&q={searchTerms}" "Search Bar"="http://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZQQWnwgkHH88J8gQeiMG-hmZBsrpaHaiv0Msc1dQG3ass_3e4uC6uFCHkOHJ1yFqknKTf5acwuE_deNsyZo_dWPmc2jmz8BvZKA0TUHh4w2Sri4J555XQMpaFMkGALlv9y5uOOiftYqBiVrV7OAm-nHasUQK9Qg,&q={searchTerms}" "Default_Search_URL"="http://www.istartsurf.com/web/?type=ds&ts=1407522120&from=tugs&uid=WDCXWD10EZEX-00BN5A0_WD-WCC3F349869998699&q={searchTerms}" "Use Search Asst"="yes" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main] "Default_Search_URL"="http://istart.webssearches.com/web/?type=ds&ts=1407875124&from=obw&uid=WDCXWD10EZEX-00BN5A0_WD-WCC3F349869998699&q={searchTerms}" "Search Page"="http://istart.webssearches.com/web/?type=ds&ts=1407875124&from=obw&uid=WDCXWD10EZEX-00BN5A0_WD-WCC3F349869998699&q={searchTerms}" [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main] "Default_Search_URL"="http://istart.webssearches.com/web/?type=ds&ts=1407875124&from=obw&uid=WDCXWD10EZEX-00BN5A0_WD-WCC3F349869998699&q={searchTerms}" "Search Page"="http://istart.webssearches.com/web/?type=ds&ts=1407875124&from=obw&uid=WDCXWD10EZEX-00BN5A0_WD-WCC3F349869998699&q={searchTerms}" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchUrl] "Default"="http://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZQQWnwgkHH88J8gQeiMG-hmZBsrpaHaiv0Msc1dQG3ass_3e4uC6uFCHkOHJ1yFqknKTf5acwuE_deNsyZo_dWPmc2jmz8BvZKA0TUHh4w2Sri4J555XQMpaFMkGALlv9y5uOOiftYqBiVrV7OAm-nHasUQK9Q8,&q={searchTerms}" [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\SearchUrl] "Default"="http://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZQQWnwgkHH88J8gQeiMG-hmZBsrpaHaiv0Msc1dQG3ass_3e4uC6uFCHkOHJ1yFqknKTf5acwuE_deNsyZo_dWPmc2jmz8BvZKA0TUHh4w2Sri4J555XQMpaFMkGALlv9y5uOOiftYqBiVrV7OAm-nHasUQK9Q8,&q={searchTerms}" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl] @="http://www.google.com/search?q=%s" "Default"="http://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZQQWnwgkHH88J8gQeiMG-hmZBsrpaHaiv0Msc1dQG3ass_3e4uC6uFCHkOHJ1yFqknKTf5acwuE_deNsyZo_dWPmc2jmz8BvZKA0TUHh4w2Sri4J555XQMpaFMkGALlv9y5uOOiftYqBiVrV7OAm-nHasUQK9Qg,&q={searchTerms}" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search] "SearchAssistant"="http://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZQQWnwgkHH88J8gQeiMG-hmZBsrpaHaiv0Msc1dQG3ass_3e4uC6uFCHkOHJ1yFqknKTf5acwuE_deNsyZo_dWPmc2jmz8BvZKA0TUHh4w2Sri4J555XQMpaFMkGALlv9y5uOOiftYqBiVrV7OAm-nHasUQK9Qg,&q={searchTerms}" "Default_Search_URL"="http://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZQQWnwgkHH88J8gQeiMG-hmZBsrpaHaiv0Msc1dQG3ass_3e4uC6uFCHkOHJ1yFqknKTf5acwuE_deNsyZo_dWPmc2jmz8BvZKA0TUHh4w2Sri4J555XQMpaFMkGALlv9y5uOOiftYqBiVrV7OAm-nHasUQK9Qg,&q={searchTerms}" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes] "DefaultScope"="{006ee092-9658-4fd6-bd8e-a21a348e59f5}" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}] not found New Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896" "Search Bar"="http://go.microsoft.com/fwlink/?LinkId=54896" "Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896" "Start Page"="http://www.msn.be/" "Use Search Asst"="no" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main] "Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896" "Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896" [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main] "Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896" "Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchUrl] "(Default)"="http://search.msn.com/results.asp?q=%s" [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\SearchUrl] "(Default)"="http://search.msn.com/results.asp?q=%s" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl] "(Default)"="http://search.msn.com/results.asp?q=%s" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search] "Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896" "SearchAssistant"="http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes] "DefaultScope"="{012E1000-F331-11DB-8314-0800200C9A66}" ==== All HKCU SearchScopes ====================== HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes {012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}" {0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC" ==== Deleting Registry Keys ====================== HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{C9732730-08AD-41E1-A30A-408F129005C6} deleted successfully HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{D49758E8-1121-4D67-AF8C-59030F747A1E} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\iikflkcanblccfahdhdonehdalibjnif deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk deleted successfully ==== Empty IE Cache ====================== C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\FM2A88\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\Users\FM2A88\AppData\Local\Microsoft\Windows\INetCache\Low\Content.IE5 emptied successfully C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully ==== Empty FireFox Cache ====================== C:\Users\FM2A88\AppData\Local\Mozilla\Firefox\Profiles\t28rcbd9.default\Cache emptied successfully ==== Empty Chrome Cache ====================== C:\Users\FM2A88\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully ==== Empty All Flash Cache ====================== Flash Cache Emptied Successfully ==== Empty All Java Cache ====================== Java Cache cleared successfully ==== C:\zoek_backup content ====================== C:\zoek_backup (files=1324 folders=411 154640979 bytes) ==== Empty Temp Folders ====================== C:\Users\Default\AppData\Local\Temp emptied successfully C:\Users\Default User\AppData\Local\Temp emptied successfully C:\Users\FM2A88\AppData\Local\Temp will be emptied at reboot C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully C:\Windows\Temp will be emptied at reboot ==== After Reboot ====================== ==== Empty Temp Folders ====================== C:\Windows\Temp successfully emptied C:\Users\FM2A88\AppData\Local\Temp successfully emptied ==== Empty Recycle Bin ====================== C:\$RECYCLE.BIN successfully emptied ==== Deleting Files / Folders ====================== "C:\Program Files (x86)\Norton 360\Engine\21.5.0.19\Exts\Chrome.crx" not deleted ==== EOF on zo 17/08/2014 at 10:38:02,57 ======================